Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Andrey on 01/06/2015 at 2:38:58,83.
Microsoft Windows 7 Home Basic 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Andrey\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
01/06/2015 02:41:29 Zoek.exe System Restore Point Created Successfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\Users\Andrey\AppData\Roaming\TP deleted successfully
C:\Users\Andrey\AppData\Local\CrashDumps deleted successfully
C:\Users\Andrey\AppData\Local\G9TiBwGuy8DFKo5 deleted successfully
C:\Users\Andrey\AppData\Local\MhkO3Qn2HGx4cu deleted successfully
C:\Users\Andrey\AppData\Local\PACE Anti-Piracy deleted successfully
C:\Users\Andrey\AppData\Local\Powercinema deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Andrey\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js:
Added to C:\Users\Andrey\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Andrey\AppData\Roaming\Mozilla\Firefox\Profiles\0
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_062015_0310_.backup
==== Deleting Files \ Folders ======================
C:\Users\Andrey\AppData\Roaming\0D0S1L2Z1P1B deleted
C:\Users\Andrey\AppData\Roaming\WB.CFG deleted
C:\PROGRA~3\FileSplitUpLoad.dll deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Andrey\AppData\Local\avgchrome deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\windows\SysNative\Tasks\pricemeterdownloader deleted
C:\windows\SysNative\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore deleted
C:\windows\SysNative\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA deleted
C:\windows\SysNative\Tasks\PriceMeterUpdater deleted
C:\Windows\Tasks\PriceMeterUpdater.job deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Toolbar4 deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Windows\Syswow64\InstallUtil.InstallLog deleted
C:\Windows\SysWow64\searchplugins deleted
C:\Windows\SysWow64\Extensions deleted
C:\Users\Andrey\AppData\Roaming\unins000.exe deleted
"C:\Users\Andrey\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\torntv@torntv.com.xpi" deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Andrey\AppData\Roaming\Mozilla\Firefox\Profiles\0
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [29/01/2015 18:16]
==== Firefox Extensions ======================
==== Firefox Plugins ======================
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[29/12/2014 23:53]
YouTube - Andrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Andrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Bookmark Manager - Andrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
GBBD Guardião - Itaú 30 horas - Andrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgmpojlddncminmkddkpoegdjhojjipg
Chrome Hotword Shared Module - Andrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
GBBD Banco do Brasil - Andrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkeabchhfifpaaoefpockjhaphjmoapp
Google Wallet - Andrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Andrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Chromium Startpages ======================
C:\Users\Andrey\AppData\Local\Google\Chrome\User Data\Default\Preferences
}],"network_stats":{"srtt":11868},"supports_spdy":true},"ssl.gstatic.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":11301},"supports_spdy":true},"stats.g.doubleclick.net:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":68283},"supports_spdy":true},"support.google.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":21187}},"sync.liverail.com:443":{"supports_spdy":true},"syndication.twitter.com:443":{"supports_spdy":true},"t0.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"t1.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"t2.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"t3.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"talkgadget.google.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":8936}},"thisis3d.files.wordpress.com:443":{"supports_spdy":true},"tpc.googlesyndication.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":92013},"supports_spdy":true},"tpc.googlesyndication.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":6332}},"translate.google.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"translate.googleapis.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":37684},"supports_spdy":true},"video-gru1-1.xx.fbcdn.net:443":{"supports_spdy":true},"www-fc-opensocial.googleusercontent.com:443":{"network_stats":{"srtt":14263}},"www.blogger.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":20229},"supports_spdy":true},"www.caixadedicas.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.facebook.com:443":{"supports_spdy":true},"www.google-analytics.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":23723}},"www.google-analytics.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.google.com.br:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":6435},"supports_spdy":true},"www.google.com.br:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.google.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":10832},"supports_spdy":true},"www.google.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.googleadservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":18628},"supports_spdy":true},"www.googleadservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":29920}},"www.googleapis.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":15846},"supports_spdy":true},"www.googletagmanager.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":17239},"supports_spdy":true},"www.googletagmanager.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.googletagservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":60700}},"www.googletagservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":9217}},"www.gstatic.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":9966},"supports_spdy":true},"www.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.youtube-nocookie.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":27752}},"www.youtube.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":22219},"supports_spdy":true},"www.youtube.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"yt3.ggpht.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":36238},"supports_spdy":true}},"supports_quic":{"address":"192.168.0.103","used_quic":true},"version":3}},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{},"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"gaia_info_picture_url":"https://lh3.googleusercontent.com/-XdUIqdMkCWA/AAAAAAAAAAI/AAAAAAAAAAA/4252rscbv5M/s256-c/photo.jpg","gaia_info_update_time":"13077606292806910","icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Andrey","per_host_zoom_levels":{}},"protection":{"macs":{}},"savefile":{"default_directory":"C:\\Users\\Andrey\\Documents\\maya\\Projeto - Estádio Braga - Prova"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13077519882457520"},"translate_blocked_languages":["pt"],"translate_whitelists":{}}
AD694EEB58BCCFAFA8579081D17","nbpagnldghgfoolbancepceaanlmhfmd":"819A8B2725B8D55FB9462F0435AC8DF91D94A1BC204D299DB7073777855E351F","neajdppkdcdipfabeoofebfddakdcjhd":"F616E8D271A48F540B850C75F5945C49006BFEF8838FB07DC5624C06A5F7A3AD","nkeimhogjdpnpccoofpliimaahmaaome":"3283AB0FC55D39BC35A5BC6BD0503D52F488C4707176DEE1A930CFD67A6235D5","nmmhkkegccagdldgiimedpiccmgmieda":"60DAA601ACD5D7AFEDE7AA560F85FBF82B8FDA8D19AC84236A3C6C483F5E31DA","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"2A813FFC2959FB283016845A1794D4DB06CBAABCA8D021E9F427646162BA9194","pjkljhegncpnkpknbcohdijeoejaedia":"AF34FE2E6AD48CFF97E3C90F55C219080A6C93B95EECE44779A4A83B25D349EC"}},"google":{"services":{"last_username":"0EBF9D5FEAA2CF5D92B15D5F9F04390AEC8FF00311DDB028744AC33727EF65B0","username":"B150925866170FEBC9FAB7798DF6D870AEA23069DA2CD8803B472F8C8BF820A5"}},"homepage":"2E93836E198C76693220002125E0CDF987488C3B0DF1C12B1976CA7C0F7EAFD6","homepage_is_newtabpage":"D4F88107006E1500C34FFCD39106FE02A3283804EAD54E1F1464083DBFA047E1","pinned_tabs":"70F6851684C55BD90F058383B3988726BA43AC94123F774FD4A8EE21972FEC15","prefs":{"preference_reset_time":"6166AF9E191CADCB923184EE89F1B74A3F206831CCA012529640E43A676DE5C2"},"profile":{"reset_prompt_memento":"42D03B1F3635B0E97FF64D94A9F49735F94FB9E3080025ABD27B735BE77D13F7"},"safebrowsing":{"incidents_sent":"FE214C58724044E10E7A9CEC7EFD4BEC5ABE3D843C144EFEC4C330AD0F9D1B0C"},"search_provider_overrides":"DC1E811BE40D98D5429A44E99111C781C7843CE9A31DF8BD8B500BC9251999E8","session":{"restore_on_startup":"F6962A469E45F336A6DA74DDB790F680F4D941F3EC8EC0A5822F3F1515209652","startup_urls":"FCD3511FAA61281B637C5AE37C5EB429845EE99A9276FB7EE0FF404B822322ED"},"software_reporter":{"prompt_reason":"6871F34EB1BD948C13EF12699912FDB4E695E645DFDF4392261EB695BDCE8EDD","prompt_seed":"E7B73666655EE53B1B1A9F1563C856E22D3E13EFBB60F85AE9236638DC00FF87","prompt_version":"E878BC95DE6C4D10EC2A4970328359590441F78E4EF26432269673AC8B718BC7"},"sync":{"remaining_rollback_tries":"8B1A120E107A04C129EA155E1B0E4A256E755BBDF3B4B2F980CA892C8FEF7724"}},"super_mac":"D8D98EDF779E19B2512816BB2E8E58B94A4C39813D26EE343EFCE404D1697EC5"},"session":{"startup_urls":["http://www.google.com.br/"]},"software_reporter":{"prompt_reason":0,"prompt_version":"3.21.0"},"sync":{"remaining_rollback_tries":0}}
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Old Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Search_URL"="http://www.istartsurf.com/web/?type=dspp&ts=1432946600&z=44384b62674fd89cb2d7a48g7z7cdoctfzbqcwcmae&from=smt&uid=ST9640423AS_5WS1LA1MXXXX5WS1LA1M&q={searchTerms}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.google.com"
"Old Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search"
==== Reset Google Chrome ======================
C:\Users\Andrey\AppData\Local\Google\Chrome\User Data\Default\ChromePreferences was reset successfully
C:\Users\Andrey\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Andrey\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\Andrey\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Andrey\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Andrey\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
==== shortcuts on Users Desktops ======================
C:\Users\Andrey\Desktop\Evernote.lnk - C:\Program Files (x86)\Evernote\Evernote\Evernote.exe
C:\Users\Andrey\Desktop\Google Chrome.lnk - C:\Users\Andrey\AppData\Local\Google\Chrome\Application\chrome.exe
www.321oyun.com?oem=smtov3&uid=5WS1LA1M_3AS&tm=1432961924
C:\Users\Andrey\Desktop\µTorrent.lnk -
==== shortcuts on All Users Desktop ======================
C:\Users\Public\Desktop\Avast Free Antivirus.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\Public\Desktop\Camtasia Studio 8.lnk - C:\Program Files (x86)\TechSmith\Camtasia Studio 8\CamtasiaStudio.exe
C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe
C:\Users\Public\Desktop\DAEMON Tools Lite.lnk - C:\Program Files\DAEMON Tools Lite\DTLauncher.exe
C:\Users\Public\Desktop\Maya 2015.lnk - C:\Program Files (x86)\Autodesk\Maya2015\bin\maya.exe
C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\McUICnt.exe SecurityScanner.dll
C:\Users\Public\Desktop\Steam.lnk - C:\Program Files (x86)\Valve\Steam\Steam.exe
C:\Users\Public\Desktop\VIVO INTERNET.lnk - C:\Program Files (x86)\VIVO INTERNET\VIVO INTERNET.exe
==== shortcuts in Users Start Menu ======================
C:\Users\Andrey\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk -
C:\Users\Andrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe
www.321oyun.com?oem=smtov3&uid=5WS1LA1M_3AS&tm=1432961924
C:\Users\Andrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe
www.123rede.com?oem=smtov3&uid=5WS1LA1M_3AS&tm=1432961923
C:\Users\Andrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Users\Andrey\AppData\Local\Google\Chrome\Application\chrome.exe
www.321oyun.com?oem=smtov3&uid=5WS1LA1M_3AS&tm=1432961924
==== shortcuts in All Users Start Menu ======================
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Uninstall Tool.lnk - C:\Program Files (x86)\Common Files\Autodesk Shared\Uninstall Tool\R1\UninstallTool.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Application Manager\Autodesk Application Manager.lnk - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Maya 2015\Autodesk Maya 2015.lnk - C:\Program Files (x86)\Autodesk\Maya2015\bin\maya.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Maya 2015\FCheck.lnk - C:\Program Files (x86)\Autodesk\Maya2015\bin\fcheck.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Maya 2015\License Transfer Utility.lnk - C:\Program Files (x86)\Common Files\Autodesk Shared\AdLM\R9\LTU.exe 657G1 2015.0.0.F -l en_US
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk - C:\Program Files\DAEMON Tools Lite\DTLauncher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\SupportAssist\PC Checkup.lnk - C:\Program Files\Dell\SupportAssist\pcdlauncher.exe -startingpage pccheckup -lloc pccheckup
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\SupportAssist\SupportAssist.lnk - C:\Program Files\Dell\SupportAssist\pcdlauncher.exe -lloc dsc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk - C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\Silverlight.Configuration.exe
==== shortcuts in Quick Launch ======================
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
www.123rede.com?oem=smtov3&uid=5WS1LA1M_3AS&tm=1432961923
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Maya 2015.lnk - C:\Program Files (x86)\Autodesk\Maya2015\bin\maya.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PC MEGA RAPIDO PRO.lnk - C:\Program Files (x86)\PC MEGA RAPIDO PRO 2.1\pcmega_registro.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Word Starter 2010.lnk - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE "Microsoft Word Starter 2010 9014006604160000"
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Paint.lnk - C:\Windows\system32\mspaint.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Welcome Center.lnk - C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Windows Anytime Upgrade.lnk -
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Wordpad.lnk - C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Users\Andrey\AppData\Local\Google\Chrome\Application\chrome.exe
www.321oyun.com?oem=smtov3&uid=5WS1LA1M_3AS&tm=1432961924
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
==== shortcuts After Repair ======================
C:\Users\Andrey\Desktop\Google Chrome.lnk - C:\Users\Andrey\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe -extoff
C:\Users\Andrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Users\Andrey\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Andrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Users\Andrey\AppData\Local\Google\Chrome\Application\chrome.exe
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyEnable"=dword:00000000
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== Deleting Registry Keys ======================
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Extractor Packages deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Andrey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\Andrey\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=34 folders=25 17161628 bytes)
==== Empty Temp Folders ======================
C:\Users\Andrey\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\USURIO~1\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Andrey\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 01/06/2015 at 3:20:11,29 ======================