Desative temporariamente seu antivírus para evitar conflitos.
* Acesse este link abaixo e clique no primeiro botão da esquerda que é o botão Download Zoek.exe:
http://www.hijackthis.nl/smeenk/
Para executá-lo corretamente siga as dicas deste tutorial:
Exclua adwares e outras ameaças de seu PC e browsers com o aplicativo Zoek
* Assim que ele concluir a limpeza dos problemas acesse o log (relatório) do Zoek que estará em C:\zoek-results.txt e copie todo seu conteúdo e poste em sua próxima resposta.
Executei o programa e o relatório está logo abaixo, mas adianto que o problema persiste! Já não sei mais o que fazer!
Zoek.exe v5.0.0.0 Updated 08-February-2015
Tool run by Ana_e_Luis on 09/02/2015 at 20:11:01,40.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Ana_e_Luis\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
09/02/2015 20:13:49 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~2\Avira deleted successfully
C:\PROGRA~2\TomTom DesktopSuite deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\Users\Ana_e_Luis\AppData\Roaming\Baidu Security deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\calibre-cache deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\ANA_E_~1\AppData\Roaming\Mozilla\Firefox\Profiles\hziutebs.default\prefs.js:
user_pref("browser.startup.homepage", "<a href="'http://www.jogostempo.com?oem=brsoftv3&uid=Z1D6JKFA_ST1000DM003-1CH162&tm=1423137466'" target="_blank">www.jogostempo.com?oem=brsoftv3&uid=Z1D6JKFA_ST1000DM003-1CH162&tm=1423137466</a>"
user_pref("browser.newtab.url", "<a href="'http://www.jogostempo.com?oem=brsoftv3&uid=Z1D6JKFA_ST1000DM003-1CH162&tm=1423137466'" target="_blank">www.jogostempo.com?oem=brsoftv3&uid=Z1D6JKFA_ST1000DM003-1CH162&tm=1423137466</a>"
Added to C:\Users\ANA_E_~1\AppData\Roaming\Mozilla\Firefox\Profiles\hziutebs.default\prefs.js:
user_pref("browser.startup.homepage", "about:home"
user_pref("browser.newtab.url", "about:newtab"
Deleted from C:\Users\ANA_E_~1\AppData\Roaming\Thunderbird\Profiles\su2vmi4y.default\prefs.js:
Added to C:\Users\ANA_E_~1\AppData\Roaming\Thunderbird\Profiles\su2vmi4y.default\prefs.js:
user_pref("browser.startup.homepage", "about:home"
user_pref("browser.newtab.url", "about:newtab"
Deleted from C:\Users\ANA_E_~1\AppData\Roaming\TomTom\HOME\Profiles\gb8dbc9i.default\prefs.js:
Added to C:\Users\ANA_E_~1\AppData\Roaming\TomTom\HOME\Profiles\gb8dbc9i.default\prefs.js:
user_pref("browser.startup.homepage", "about:home"
user_pref("browser.newtab.url", "about:newtab"
ProfilePath: C:\Users\ANA_E_~1\AppData\Roaming\Mozilla\Firefox\Profiles\hziutebs.default
user.js not found
---- Lines aOIBMBKA115048682HYKFIU97176590com69065 removed from prefs.js ----
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.active", true);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.addressbar", "NA"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.addressbarenhanced", ""
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.asyncdb.was_copied", "true"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.asyncinternaldb.was_copied", "true"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.backgroundver", 1);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.certdomaininstaller", ""
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.changeprevious", false);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Hora ofic
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.InstallationTime.value", "%221423137578%22"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Hora ofici
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22002161%22%2C%22sub_id%22%3
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.load_balancer.expiration", "Thu Feb 05 2015 16:45:17 GMT-0200 (Hora oficial
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%22%3A%201%2C%5C%22Endpoint%
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.previous_page.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Hora oficial
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.previous_page.value", "%22https%3A//<a href="'http://www.google.com/chrome/browser/thankyou'" target="_blank">www.google.com/chrome/browser/thankyou</a>.
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Hora oficial do Br
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.cookie.user_id.value", "%2214b59a0c6c0569619a0141d17f05d02d%22"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.description", "Lights out for YouTube"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.domain", ""
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.enablesearch", false);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.homepage", ""
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.iframe", false);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.InstallationThankYouPage", true);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.InstallationTime", 1423137578);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Ho
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.__defualt_browser__.value", "%22ch%22"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb._installer_additional_info.expiration", "Fri Feb 01 2030 00:00:00 GMT-0
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb._installer_additional_info.value", "%7B%22asw%22%3A%5B4%2C-2147483643%2
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Hora oficial
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (H
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%22DEA4A6BD4FA94
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Hora o
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%22002161%22%2C%22sub_id%
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (H
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22002161%22%2C%22su
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GM
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%22DEA4
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.monetization_plugin_bundledUrls.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.monetization_plugin_bundledWithHash.expiration", "Fri Feb 01 2030 00:00
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.monetization_plugin_bundledWithHash.value", "null"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.monetization_plugin_last_executable_request.expiration", "Thu Feb 05 20
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.monetization_plugin_last_executable_request.value", "%22https%3A//dl.go
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.monetization_plugin_notBundledArr_.expiration", "Fri Feb 01 2030 00:00:
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.monetization_plugin_regBundledWithSoftware.expiration", "Fri Feb 01 203
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.monetization_plugin_regBundledWithSoftware.value", "%7B%7D"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.reporting_user_key_index.expiration", "Sun Feb 02 2025 10:04:48 GMT-020
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.reporting_user_key_index.value", "428"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Hora
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_appVer.value", "57"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_lastVersion.value", "1"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Hora of
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_meta.value", "%7B%7D"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_nextCheck.expiration", "Thu Feb 05 2015 16:04:49 GMT-0200 (Ho
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_nextCheck.value", "true"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT-0200 (Hora o
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.internaldb.Resources_queue.value", "%7B%7D"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.lastDailyReport", "1423137885717"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.lastUpdate", "1423137884766"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.manifesturl", ""
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.name", "HQ_Vid_Quality_1.5vV05.02"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.newtab", ""
user_pref("[EMAIL]extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.OIBMBKA115048682@HYKFIU97176590.comaOIBMBKA[/EMAIL]115048682HYKFIU97176590com69065_dbWasSe
user_pref("[EMAIL]extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.OIBMBKA115048682@HYKFIU97176590.comaOIBMBKA[/EMAIL]115048682HYKFIU97176590com69065_dbWasSe
user_pref("[EMAIL]extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.OIBMBKA115048682@HYKFIU97176590.comasyncdb[/EMAIL]_dbWasSet", true);
user_pref("[EMAIL]extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.OIBMBKA115048682@HYKFIU97176590.comasyncdb[/EMAIL]_dbWasSet_FF25_FIX", true);
user_pref("[EMAIL]extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.OIBMBKA115048682@HYKFIU97176590.comasyncinternaldb[/EMAIL]_dbWasSet", true);
user_pref("[EMAIL]extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.OIBMBKA115048682@HYKFIU97176590.comasyncinternaldb[/EMAIL]_dbWasSet_FF25_FIX", true);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.opensearch", ""
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.pluginsurl", "<a href="http://js.ourdatagenserv.com/plugin/apps/69065/plugins/na/ff/plugins" target="_blank">http://js.ourdatagenserv.com/plugin/apps/69065/plugins/na/ff/plugins</a>
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.pluginsversion", 52);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.publisher", "HQ_Vid_Quality_1.5vV05.02"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.searchstatus", 0);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.setnewtab", false);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.thankyou", ""
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.updateinterval", 360);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.69065.ver", 57);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.apps", "69065"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.bic", "14b59a0c6c0569619a0141d17f05d02d"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.cid", 69065);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.firstrun", false);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.hadappinstalled", true);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.installationdate", 1423137884);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.installerAdditionalInfo", "{\"asw\":[4, -2147483643, 0, 0],\"browser_name\":\"ff\",\"pro
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.modetype", "production"
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.reportInstall", true);
user_pref("extensions.aOIBMBKA115048682HYKFIU97176590com69065.statsDailyCounter", 1);
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----
prefs_022015_2020_.backup
ProfilePath: C:\Users\ANA_E_~1\AppData\Roaming\Thunderbird\Profiles\su2vmi4y.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_022015_2020_.backup
ProfilePath: C:\Users\ANA_E_~1\AppData\Roaming\TomTom\HOME\Profiles\gb8dbc9i.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_022015_2020_.backup
==== Deleting Files \ Folders ======================
C:\Program Files (x86)\Acro Software\f6a9b4e3-3f12-4f0e-9991-944f02d096f0.dll deleted
C:\Program Files (x86)\Acro Software\d4583476-7694-4f7d-af0f-e36e7180d4f9.dll deleted
C:\Users\Ana_e_Luis\.android deleted
C:\PROGRA~2\SamsungPrinterLiveUpdateInstaller deleted
C:\PROGRA~2\d4583476-7694-4f7d-af0f-e36e7180d4f9 deleted
C:\install.exe deleted
C:\Users\Ana_e_Luis\AppData\Roaming\WB.CFG deleted
C:\Users\Ana_e_Luis\AppData\Roaming\alsoft.ini deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Ana_e_Luis\AppData\Local\BIT7501.tmp deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\ANA_E_~1\AppData\Roaming\Mozilla\Firefox\Profiles\hziutebs.default\extensions\[EMAIL]OIBMBKA115048682@HYKFIU97176590.com[/EMAIL] deleted
"C:\Users\Ana_e_Luis\AppData\Local\{A4039A48-C84D-4267-81C9-7A9C877221CA}" deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\ANA_E_~1\AppData\Roaming\Mozilla\Firefox\Profiles\hziutebs.default
user_pref("browser.startup.homepage", "about:home"
user_pref("browser.newtab.url", "about:newtab"
ProfilePath: C:\Users\ANA_E_~1\AppData\Roaming\Thunderbird\Profiles\su2vmi4y.default
user_pref("browser.startup.homepage", "about:home"
user_pref("browser.newtab.url", "about:newtab"
ProfilePath: C:\Users\ANA_E_~1\AppData\Roaming\TomTom\HOME\Profiles\gb8dbc9i.default
user_pref("browser.startup.homepage", "about:home"
user_pref("browser.newtab.url", "about:newtab"
==== Firefox Extensions ======================
ProfilePath: C:\Users\ANA_E_~1\AppData\Roaming\Mozilla\Firefox\Profiles\hziutebs.default
- Undetermined - C:\Users\Ana_e_Luis\AppData\Roaming\Mozilla\Firefox\Profiles\hziutebs.default\extensions\[EMAIL]OIBMBKA115048682@HYKFIU97176590.com[/EMAIL]
- ffext_basicvideoextstartpage24 - C:\Users\Ana_e_Luis\AppData\Roaming\Mozilla\Firefox\Profiles\hziutebs.default\extensions\ffext_basicvideoext@startpage24
- Undetermined - [EMAIL]OIBMBKA115048682@HYKFIU97176590.com[/EMAIL]
- ffext_basicvideoextstartpage24 - %ProfilePath%\extensions\ffext_basicvideoext@startpage24
ProfilePath: C:\Users\ANA_E_~1\AppData\Roaming\TomTom\HOME\Profiles\gb8dbc9i.default
- Map status indicator - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\[EMAIL]MapShare-status@tomtom.com[/EMAIL]
- TomTom HOME default theme - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\[EMAIL]baseTheme@tomtom.com[/EMAIL]
==== Firefox Plugins ======================
Profilepath: C:\Users\Ana_e_Luis\AppData\Roaming\Mozilla\Firefox\Profiles\hziutebs.default
C62322C77D1AAB77B1CF1130FCC3673A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash
==== Chromium Look ======================
Google Chrome Version: 40.0.2214.111 (Possible outdated, latest Stable version: 40.0.2214.94)
Google Docs - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
emafblcdglliigbabbcjbmeabppnecgj - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Extensions\emafblcdglliigbabbcjbmeabppnecgj
Google Wallet - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Google Slides - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Google Docs - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
emafblcdglliigbabbcjbmeabppnecgj - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\emafblcdglliigbabbcjbmeabppnecgj
Google Sheets - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Google Wallet - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Chromium Fix ======================
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_<a href="'http://www.superfish.com_0.localstorage'" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_<a href="'http://www.superfish.com_0.localstorage-journal'" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_<a href="'http://www.superfish.com_0.localstorage'" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_<a href="'http://www.superfish.com_0.localstorage-journal'" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_static.boostsaves.com_0.localstorage deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\https_static.boostsaves.com_0.localstorage-journal deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_offers.boostsaves.com_0.localstorage deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_offers.boostsaves.com_0.localstorage-journal deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_static.boostsaves.com_0.localstorage deleted successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_static.boostsaves.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="<a href="http://www.google.com" target="_blank">http://www.google.com</a>"
"Default_Page_URL"="<a href="http://www.google.com" target="_blank">http://www.google.com</a>"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="<a href="http://www.google.com" target="_blank">http://www.google.com</a>"
"Default_Page_URL"="<a href="http://www.google.com" target="_blank">http://www.google.com</a>"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="<a href="http://www.google.com" target="_blank">http://www.google.com</a>"
"Default_Page_URL"="<a href="http://www.google.com" target="_blank">http://www.google.com</a>"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"
"Start Page"="<a href="http://www.google.com" target="_blank">http://www.google.com</a>"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"
"Default_Page_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"
"Default_Page_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="<a href="http://www.google.com/search?q={searchTerms}" target="_blank">http://www.google.com/search?q={searchTerms}</a>"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="<a href="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" target="_blank">http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC</a>"
{79456162-BA89-4389-A927-AA814BC4E7EB} Google Url="<a href="https://www.google.com/search?q={searchTerms}" target="_blank">https://www.google.com/search?q={searchTerms}</a>"
==== Reset Google Chrome ======================
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
==== shortcuts on All Users Desktop ======================
C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==== shortcuts in All Users Start Menu ======================
C:\ProgramData\Microsoft\Windows\Start Menu\Program Updates.lnk - C:\Windows\Installer\{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\STREET FIGHTER IV.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gigabyte\App Center\APP Center.lnk - C:\Program Files (x86)\GIGABYTE\AppCenter\RunUpd.exe -sh
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gigabyte\App Center\Uninstall AppCenter.lnk - C:\Program Files (x86)\InstallShield Installation Information\{F3D47276-0E35-42CF-A677-B45118470E21}\setup.exe -uninst
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin\Origin Error Reporter.lnk - C:\Program Files (x86)\Origin\OriginER.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sigil\Sigil.lnk - C:\Program Files (x86)\Sigil\Sigil.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sigil\Uninstall Sigil.lnk - C:\Program Files (x86)\Sigil\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer\Assassin's Creed II\Atualizador Tribo Gamer.lnk - C:\Program Files (x86)\Tribo Gamer\Assassin's Creed II\Atualizador.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer\Assassin's Creed II\Créditos da Tradução.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer\Assassin's Creed II\Desinstalar a Tradução.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer\Assassin's Creed II\Notas da Tradução.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer\Borderlands 2 - GOTY Edition\Atualizador Tribo Gamer.lnk - C:\Program Files (x86)\Tribo Gamer\Borderlands 2 - GOTY Edition\Atualizador.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer\Borderlands 2 - GOTY Edition\Créditos da Tradução.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer\Borderlands 2 - GOTY Edition\Desinstalar a Tradução.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer\Borderlands 2 - GOTY Edition\Notas da Tradução.lnk -
==== shortcuts in Quick Launch ======================
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyEnable"=dword:00000000
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ana_e_Luis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ana_e_Luis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Ana_e_Luis\AppData\Local\Mozilla\Firefox\Profiles\hziutebs.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Ana_e_Luis\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=170 folders=28 13750160 bytes)
==== Empty Temp Folders ======================
C:\Users\Ana_e_Luis\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\USURIO~1\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\ANA_E_~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 09/02/2015 at 20:24:51,08 ======================