Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Delta-Search redirect virus, Need assistance...


  • Please log in to reply
12 replies to this topic

#1 Undesired_Hero

Undesired_Hero

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 08 February 2013 - 02:10 PM

Hey i got this Delta-Search virus hijacking my browsers since the beginning of the month.. I have removed it from my programs since i found a program there called delta search and removed the entry from my registry and restarted my computer but this didnt work.

So I have come here in search for help to remove it.

 

I know i can format my computer to get rid of it but i dont want to take that step just jet. Only  as a last resort if i cant remove it...

 

My windows operating system is Windows 7 64bit and I'm currently using Google Chrome as a webrowser. I have tried to remove all addons to chrome and made a system restore but it was not enough. Have also tried to change home screen in Chrome but each time i start it up or make a new tap Delta-Search comes up.

 

I have had something like this before it was callled babylon something but i could remove it alot easier. Think it was from something my sister installed.

 

Do anyone of you know good programs to use so I can remove this without formating my computer?


Edited by Undesired_Hero, 08 February 2013 - 02:11 PM.


BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:42 AM

Posted 08 February 2013 - 02:11 PM


  • Please download TDSSKiller from here and save it to your Desktop
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters




  • Check Loaded Modules  and Detect TDLFS file systemDo not check Verify file digital signatures (even though it is checked in the example)
  • If you are asked to reboot because an "Extended Monitoring Driver is required" please click Reboot now




  • Click Start Scan and allow the scan process to run

  • If threats are detected select Skip for all of them unless I instruct you otherwise
  • Click Continue




  • Click Reboot computer
  • Please post the contents of  TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically c:\)in your reply


===================================================


aswMBR

--------------------

  • Download aswMBR and save it to your desktop.
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily. They will interfere and may cause unexpected results.
  • If you need help to disable your protection programs see here and here.
  • Double click the aswMBR.exe file to run it. Please allow when you are asked to download AVAST antivirus engine defs.
  • Wait until the AV update is done, then click on the Scan button to start. The program will launch a scan.



  • When done, you will see Scan finished successfully. Please click on Save log and save the file to your desktop.



  • Please post the contents of the log in your next reply.

NOTE:  aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.


===================================================


ESET Online Scanner

--------------------

I'd like us to scan your machine with ESET OnlineScan  This process may may take several hours, that is normal

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the   button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.

  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:

    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Copy and paste the information in your next reply.   Note:  If no malware was found you will not get a log.
  • Click the Back button.
  • Click the Finish button.


===================================================


Things I would like to see in your next reply. Please be sure to copy and paste the information rather than send an attachment. :thumbsup2:

  • TDSSKiller log
  • aswMBR log
  • ESET results

 



#3 Undesired_Hero

Undesired_Hero
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 09 February 2013 - 01:53 PM

16:14:55.0859 7408  TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
16:14:56.0083 7408  ============================================================
16:14:56.0083 7408  Current date / time: 2013/02/09 16:14:56.0083
16:14:56.0083 7408  SystemInfo:
16:14:56.0083 7408  
16:14:56.0083 7408  OS Version: 6.1.7601 ServicePack: 1.0
16:14:56.0083 7408  Product type: Workstation
16:14:56.0083 7408  ComputerName: HOLLYWOOOD-TOSH
16:14:56.0084 7408  UserName: Johanna
16:14:56.0084 7408  Windows directory: C:\Windows
16:14:56.0084 7408  System windows directory: C:\Windows
16:14:56.0084 7408  Running under WOW64
16:14:56.0084 7408  Processor architecture: Intel x64
16:14:56.0084 7408  Number of processors: 8
16:14:56.0084 7408  Page size: 0x1000
16:14:56.0084 7408  Boot type: Normal boot
16:14:56.0084 7408  ============================================================
16:14:56.0599 7408  Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:14:56.0603 7408  ============================================================
16:14:56.0603 7408  \Device\Harddisk0\DR0:
16:14:56.0603 7408  MBR partitions:
16:14:56.0603 7408  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xC8000, BlocksNum 0xF36C000
16:14:56.0618 7408  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xF434800, BlocksNum 0x15F7A000
16:14:56.0618 7408  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x253AE800, BlocksNum 0x254A9800
16:14:56.0618 7408  ============================================================
16:14:56.0654 7408  C: <-> \Device\Harddisk0\DR0\Partition1
16:14:56.0721 7408  D: <-> \Device\Harddisk0\DR0\Partition3
16:14:56.0819 7408  F: <-> \Device\Harddisk0\DR0\Partition2
16:14:56.0819 7408  ============================================================
16:14:56.0819 7408  Initialize success
16:14:56.0819 7408  ============================================================
16:17:34.0192 9120  Deinitialize success


#4 Undesired_Hero

Undesired_Hero
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 09 February 2013 - 02:07 PM

C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll    a variant of Win32/Adware.Yontoo.B application    
C:\Users\All Users\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll    a variant of Win32/Adware.Yontoo.B application    
C:\Program Files (x86)\BrowserCompanion\BCHelper.exe    a variant of Win32/BrowserCompanion.A application    cleaned by deleting - quarantined
C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx    Win32/BrowserCompanion.G application    deleted - quarantined
C:\Program Files (x86)\BrowserCompanion\blabbers-ff-full.xpi    Win32/BrowserCompanion.G application    deleted - quarantined
C:\Program Files (x86)\BrowserCompanion\jsloader.dll    Win32/BrowserCompanion.B application    cleaned by deleting - quarantined
C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll    Win32/BrowserCompanion.C application    cleaned by deleting - quarantined
C:\Program Files (x86)\BrowserCompanion\toolbar.dll    Win32/BrowserCompanion.D application    cleaned by deleting - quarantined
C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll    Win32/BrowserCompanion.E application    cleaned by deleting - quarantined
C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll_1    Win32/BrowserCompanion.E application    cleaned by deleting - quarantined
C:\Program Files (x86)\BrowserCompanion\widgetserv.exe    Win32/BrowserCompanion.F application    cleaned by deleting - quarantined
C:\Program Files (x86)\Searchqu Toolbar\Datamngr\BrowserConnection.dll    Win32/Toolbar.SearchSuite application    cleaned by deleting - quarantined
C:\Program Files (x86)\Searchqu Toolbar\Datamngr\datamngr.dll    Win32/Toolbar.SearchSuite application    cleaned by deleting (after the next restart) - quarantined
C:\Program Files (x86)\Searchqu Toolbar\Datamngr\datamngrUI.exe    a variant of Win32/Toolbar.SearchSuite application    cleaned by deleting - quarantined
C:\Program Files (x86)\Searchqu Toolbar\Datamngr\DnsBHO.dll    Win32/Toolbar.SearchSuite application    cleaned by deleting - quarantined
C:\Program Files (x86)\Searchqu Toolbar\Datamngr\IEBHO.dll    Win32/Toolbar.SearchSuite application    cleaned by deleting - quarantined
C:\Program Files (x86)\Yontoo\YontooIEClient.dll    a variant of Win32/Adware.Yontoo.A application    cleaned by deleting - quarantined
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll    a variant of Win32/Adware.Yontoo.B application    cleaned by deleting - quarantined
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll    a variant of Win32/Adware.Yontoo.B application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\clbfjfbnelcflpgpklppgplejolacbej\1.0.5_0\witmain.js    Win32/BrowserCompanion.G application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\clbfjfbnelcflpgpklppgplejolacbej\1.0.5_0\witmain.js    Win32/BrowserCompanion.G application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\clbfjfbnelcflpgpklppgplejolacbej\1.0.5_0\witmain.js    Win32/BrowserCompanion.G application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\clbfjfbnelcflpgpklppgplejolacbej\1.0.5_0\witmain.js    Win32/BrowserCompanion.G application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4R28SF9E\utorrent[1].exe    Win32/Toggle.C application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\Local\Temp\DAEMONToolsPro520-0348.exe    Win32/OpenCandy application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\Local\Temp\DeltaTB.exe    a variant of Win32/Toolbar.Babylon.A application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\BCHelper.exe    a variant of Win32/BrowserCompanion.A application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\witmain.js    Win32/BrowserCompanion.G application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\bbrs_002@blabbers.com\chrome\content\witmain.js    Win32/BrowserCompanion.G application    cleaned by deleting - quarantined
C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\plugin@yontoo.com\content\overlay.js    Win32/Adware.Yontoo application    cleaned by deleting - quarantined
C:\Users\Johanna\Downloads\utorrent (3).exe    Win32/Toggle.D.Gen application    cleaned by deleting - quarantined
C:\Users\Johanna\Downloads\Adobe All Products Keygen\Keygen.exe    a variant of Win32/Keygen.BH application    cleaned by deleting - quarantined
C:\Users\Johanna\Downloads\Adobe Photoshop Extended CS5\cr-keygen.rar    a variant of Win32/Keygen.BH application    deleted - quarantined
C:\Windows\Installer\5bbfb5f.msi    a variant of Win32/Bundled.Toolbar.Ask application    deleted - quarantined

Edited by Undesired_Hero, 09 February 2013 - 02:07 PM.


#5 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:42 AM

Posted 09 February 2013 - 02:07 PM

.


Edited by narenxp, 09 February 2013 - 02:15 PM.


#6 Undesired_Hero

Undesired_Hero
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 09 February 2013 - 02:08 PM

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-02-09 16:32:40
-----------------------------
16:32:40.990    OS Version: Windows x64 6.1.7601 Service Pack 1
16:32:40.990    Number of processors: 8 586 0x2A07
16:32:40.990    ComputerName: HOLLYWOOOD-TOSH  UserName: Johanna
16:32:41.792    Initialize success
16:32:42.422    AVAST engine defs: 13020900
16:33:40.088    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:33:40.093    Disk 0 Vendor: TOSHIBA_ GT00 Size: 610480MB BusType: 3
16:33:40.131    Disk 0 MBR read successfully
16:33:40.136    Disk 0 MBR scan
16:33:40.141    Disk 0 Windows 7 default MBR code
16:33:40.154    Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS          399 MB offset 2048
16:33:40.168    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       124632 MB offset 819200
16:33:40.175    Disk 0 Partition - 00     0F Extended LBA            179957 MB offset 256065536
16:33:40.198    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       305491 MB offset 624617472
16:33:40.218    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS       179956 MB offset 256067584
16:33:40.253    Disk 0 scanning C:\Windows\system32\drivers
16:33:47.573    Service scanning
16:34:16.675    Modules scanning
16:34:16.697    Disk 0 trace - called modules:
16:34:16.744    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
16:34:16.751    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004f8d790]
16:34:16.759    3 CLASSPNP.SYS[fffff88001b9c43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004a40050]
16:34:17.176    AVAST engine scan C:\Windows
16:34:18.598    AVAST engine scan C:\Windows\system32
16:36:30.530    AVAST engine scan C:\Windows\system32\drivers
16:36:38.808    AVAST engine scan C:\Users\Johanna
16:46:33.450    AVAST engine scan C:\ProgramData
16:47:43.023    Scan finished successfully
16:48:43.213    Disk 0 MBR has been saved successfully to "C:\Users\Johanna\Desktop\MBR.dat"
16:48:43.217    The log file has been saved successfully to "C:\Users\Johanna\Desktop\aswMBR.txt"


#7 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:42 AM

Posted 09 February 2013 - 02:17 PM

Malwarebytes

--------------------

Please download Malwarebytes Anti-Malware and save it to your desktop.  If you already have it installed launch the program and update the database.

  • Important!! When you save the mbam-setup file, rename it to something random (such as 123abc.exe) before beginning the download.  You can also right click on the link and select Save Link As

Malwarebytes may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet and double-click on the renamed file to install the application.
    For instructions with screenshots, please refer to this Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings except to uncheck any offer for a free Pro trial version
  • Malwarebytes will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • Under the Scanner tab, make sure the "Perform Quick Scan" option is selected.
  • Click on the Scan button.
  • When finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box, then click the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked and then click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows the database version and your operating system.
  • Exit Malwarebytes when done.

Note: If Malwarebytes encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally will prevent Malwarebytes from removing all the malware.


===================================================


Farbar's MiniToolBox

--------------------

  • Please download MiniToolBox, save it to your desktop
  • Please close any Firefox browsers you may have open
  • Double click the icon to launch the program
  • Make sure the following options are checked:

    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List content of Hosts
    • List IP configuration
    • List Winsock Entries
    • List last 10 Event Viewer log
    • List Installed Programs
    • List Devices
    • List Users, Partitions and Memory size.
  • Click Go and once the scan is completed a Result.txt Notepad document will open on your desktop
  • Please copy and paste the contents in your reply


===================================================


Farbar's Service Scanner

--------------------

Please download Farbar Service Scanner, save it to your desktop, and run it.

  • Make sure the following options are checked:

    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


===================================================


AdwCleaner by Xplode - Search for Adware

-------------------

  • Please download AdwCleaner by Xplode onto your desktop.
  • Double click on AdwCleaner.exe, select OK, then Run
  • Click on Search
  • A logfile will automatically open after the scan has finished
  • Copy and paste the contents in your reply
  • You can find the logfile at C:\AdwCleaner[R1].txt as well


===================================================


Junkware Removal Tooll by thisisu

-------------------

  • Please download Junkware Removal Tool and save it to your desktop.
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Right-mouse click JRT.exe and select Run as administrator (Windows XP double click the icon)
  • Please allow the program time to run
  • Once completed a Notepad document will open on your desktop
  • Copy and paste the contents in your reply


===================================================


Rkill

-------------------

Please download Rkill by Grinler from one of the 4 links below (if one of them does not work try another...) and save it to your desktop:


  • In order for Rkill to run properly you must disable your anti-malware software.  Please refer to this page if you are not sure how.
  • Double-click on Rkill. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
    • Note:  You may have to run Rkill a few times before it is successful.  You may also have to download Rkill from a different link which will save it as a different file name.
  • A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
  • An Rkill.log will appear.  Please copy and paste the contents in your reply (file also located at c:\rkill.log)
  • Do not reboot your computer after running Rkill as the malware programs will start again.  If your computer reboots, run Rkill again before continuing on to the next step.
  • If nothing happens or if the tool does not run, please let me know in your next reply.


===================================================


Autoruns

--------------------

  • Please download AutoRuns and save it to your desktop
  • Double click the AutoRuns.zip folder
  • Double click autoruns.exe (not autorunsc.exe), select Run, then Run again and allow the information to populate
  • Select File, Save, Desktop (in the left hand pane), then Save filename as Autoruns.txt and change Save as type to  Text(*.txt).
  • Double click on the text file,copy and paste the contents in your reply


===================================================


Things I would like to see in your next reply. Please be sure to copy and paste the information rather than send an attachment. :thumbsup2:

  • Malwarebytes log
  • MiniToolBox log
  • Farbar's Service Scanner log
  • AdwCleaner log
  • Junkware Removal Tool log
  • Rkill log
  • Autoruns log


 


Edited by narenxp, 09 February 2013 - 02:19 PM.


#8 Undesired_Hero

Undesired_Hero
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 09 February 2013 - 02:55 PM

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
 
Databasversion: v2013.02.09.07
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Johanna :: HOLLYWOOOD-TOSH [administratör]
 
2013-02-09 20:16:00
mbam-log-2013-02-09 (20-16-00).txt
 
Skanningstyp: Snabbskanning
Aktiverade skanningsalternativ: Minne | Start | Register | Filsystem | Heuristik/Extra | Heuristik/Shuriken | PUP | PUM
Inaktiverade skanningsalternativ: P2P
Antal skannade objekt: 244043
Förfluten tid: 3 minut(er), 20 sekund(er)
 
Upptäckta minnesprocesser: 0
(Inga skadliga poster hittades)
 
Upptäckta minnesmoduler: 0
(Inga skadliga poster hittades)
 
Upptäckta registernycklar: 22
HKCR\CLSID\{00cbb66b-1d3b-46d3-9577-323a336acb50} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\TypeLib\{8830ddf0-3042-404d-a62c-384a85e34833} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\wit4ie.WitBHO.2 (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\wit4ie.WitBHO (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\tdataprotocol.CTData.1 (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\tdataprotocol.CTData (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\updatebho.TimerBHO.1 (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\updatebho.TimerBHO (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\PROTOCOLS\HANDLER\BASE64 (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\PROTOCOLS\HANDLER\CHROME (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKCR\PROTOCOLS\HANDLER\PROX (PUP.Blabbers) -> Sattes i karantän och togs bort.
HKLM\SOFTWARE\Google\chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki (PUP.Funmoods) -> Sattes i karantän och togs bort.
 
Upptäckta registervärden: 4
HKCR\protocols\Handler\base64|CLSID (PUP.Blabbers) -> Data: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Sattes i karantän och togs bort.
HKCR\protocols\Handler\chrome|CLSID (PUP.Blabbers) -> Data: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Sattes i karantän och togs bort.
HKCR\protocols\Handler\prox|CLSID (PUP.Blabbers) -> Data: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Sattes i karantän och togs bort.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Browser companion helper (PUP.Blabbers) -> Data: C:\Program Files (x86)\BrowserCompanion\BCHelper.exe /T=3 /CHI=clbfjfbnelcflpgpklppgplejolacbej -> Sattes i karantän och togs bort.
 
Upptäckta registerdataposter: 0
(Inga skadliga poster hittades)
 
Upptäckta mappar: 5
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\Funmoods (PUP.FunMoods) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\Funmoods\Funmoods (PUP.FunMoods) -> Sattes i karantän och togs bort.
 
Upptäckta filer: 63
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\fix2.js (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\fixJQ1_83.js (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\icon.png (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\jquery4toolbar.js (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\jquery4toolbar183.js (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\lock.js (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\witapi.js (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\wittoolbar.js (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\witwidgetapi.js (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\0324adea3b6ec02af09ea4ae9424591b (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\0324adea3b6ec02af09ea4ae9424591b_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\21d2bb231d3c04f5b6434220b2b1cb9e (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\21d2bb231d3c04f5b6434220b2b1cb9e_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\292124057d00cb0fa73db6b90d079658 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\292124057d00cb0fa73db6b90d079658_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\4d3d10bd28ff623813254a49b26be41f (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\4d3d10bd28ff623813254a49b26be41f_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\61e2ae11ba3d1cbe8887ea80f192e299 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\61e2ae11ba3d1cbe8887ea80f192e299_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\656bf02a99a3ba2fbf237f6152b7f3de (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\656bf02a99a3ba2fbf237f6152b7f3de_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\669fe6d390ab17fec690443b75f77e8b (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\669fe6d390ab17fec690443b75f77e8b_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\680670b86f0b67567a12d8162b67b978 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\680670b86f0b67567a12d8162b67b978_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\6ec88a37be1bea7fa99383e8b8c69afe (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\6ec88a37be1bea7fa99383e8b8c69afe_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\71c2900847ecd4f560699d72e185beff (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\71c2900847ecd4f560699d72e185beff_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\74f5f9727ab6e67552a69ed028cd1b37 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\74f5f9727ab6e67552a69ed028cd1b37_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\7ea68d56b27598b043b48c3ca385dcb7 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\7ea68d56b27598b043b48c3ca385dcb7_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\91f8dc1ced7799c19a127130dfaeb260 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\91f8dc1ced7799c19a127130dfaeb260_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\a621d11ddd9fe6bd0f9c716dc72a95bc (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\a621d11ddd9fe6bd0f9c716dc72a95bc_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\a7e0abb80dabcdbb6dbaec920aa126a0 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\a7e0abb80dabcdbb6dbaec920aa126a0_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\aa36bceec49c832079e270icmc219ats (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\aaff3303cdd7526dcb9cd1bc7f49fa7a (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\aaff3303cdd7526dcb9cd1bc7f49fa7a_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\b9dedd996f3959d08245e30e05b890b5 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\b9dedd996f3959d08245e30e05b890b5_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\ca77131df48836e70a4d44a407503347 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\ca77131df48836e70a4d44a407503347_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\ce55d6e3f8c8931b46cfc28c1c9a65a8 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\ce55d6e3f8c8931b46cfc28c1c9a65a8_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\e3cd5b2c64ca319aadec7c28c6c6feba_SE (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\e919434ec29526b28593c426e4264271 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\e919434ec29526b28593c426e4264271_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\ece71b71690fad200cbed95871ef4bb2 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\ece71b71690fad200cbed95871ef4bb2_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\f03527c67e08602d2e4c18ae7867300d (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\f03527c67e08602d2e4c18ae7867300d_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\f18484bd73a6ae0ba7428ebf39f9ee4d (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\f18484bd73a6ae0ba7428ebf39f9ee4d_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\fa74672918974682c82b8d91dfbe0d6b (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\fa74672918974682c82b8d91dfbe0d6b_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\fedc51a899de85ceaf2bc8535b683441 (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\fedc51a899de85ceaf2bc8535b683441_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f (PUP.Blabbers) -> Sattes i karantän och togs bort.
C:\Users\Johanna\AppData\LocalLow\bbrs_002.tb\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f_expire (PUP.Blabbers) -> Sattes i karantän och togs bort.
 
(klar)


# AdwCleaner v2.111 - Logfile created 02/09/2013 at 20:33:31
# Updated 05/02/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Johanna - HOLLYWOOOD-TOSH
# Boot Mode : Normal
# Running from : C:\Users\Johanna\Downloads\AdwCleaner.exe
# Option [Search]
 
 
***** [Services] *****
 
Found : WajamUpdater
 
***** [Files / Folders] *****
 
File Found : C:\END
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
File Found : C:\Program Files (x86)\Mozilla FireFox\searchplugins\Search_Results.xml
File Found : C:\user.js
File Found : C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_apps.conduit.com_0.localstorage
File Found : C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_apps.conduit.com_0.localstorage-journal
File Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\searchplugins\funmoods.xml
File Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\searchplugins\MyStart Search.xml
File Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\searchplugins\Search_Results.xml
File Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\searchplugins\Web Search.xml
Folder Found : C:\Program Files (x86)\AVG Secure Search
Folder Found : C:\Program Files (x86)\BrowserCompanion
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\Ilivid
Folder Found : C:\Program Files (x86)\Searchqu Toolbar
Folder Found : C:\Program Files (x86)\uTorrentControl_v2
Folder Found : C:\Program Files (x86)\Wajam
Folder Found : C:\Program Files (x86)\Yontoo
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\boost_interprocess
Folder Found : C:\ProgramData\InstallMate
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ilivid
Folder Found : C:\ProgramData\Partner
Folder Found : C:\ProgramData\Premium
Folder Found : C:\ProgramData\Tarma Installer
Folder Found : C:\Users\Johanna\AppData\Local\AVG Secure Search
Folder Found : C:\Users\Johanna\AppData\Local\Conduit
Folder Found : C:\Users\Johanna\AppData\Local\Ilivid Player
Folder Found : C:\Users\Johanna\AppData\Local\Temp\CT3220468
Folder Found : C:\Users\Johanna\AppData\Local\Wajam
Folder Found : C:\Users\Johanna\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Johanna\AppData\LocalLow\Conduit
Folder Found : C:\Users\Johanna\AppData\LocalLow\incredibar.com
Folder Found : C:\Users\Johanna\AppData\LocalLow\searchquband
Folder Found : C:\Users\Johanna\AppData\LocalLow\Searchqutoolbar
Folder Found : C:\Users\Johanna\AppData\LocalLow\uTorrentControl_v2
Folder Found : C:\Users\Johanna\AppData\Roaming\Babylon
Folder Found : C:\Users\Johanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\ConduitCommon
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\CT3072254
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\CT3220468
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\{1fd91a9c-410c-4090-bbcc-55d3450ef433}
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\{e9df9360-97f8-4690-afe6-996c80790da4}
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\bbrs_002@blabbers.com
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\ffxtlbr@funmoods.com
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\plugin@yontoo.com
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\staged
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\Searchqutoolbar
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\Smartbar
 
***** [Registry] *****
 
Data Found : [x64] HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll
Data Found : [x64] HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll
Data Found : HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll
Data Found : HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\searchqutoolbar
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\AVG Secure Search
Key Found : HKCU\Software\Blabbers
Key Found : HKCU\Software\BrowserCompanion
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\DataMngr_Toolbar
Key Found : HKCU\Software\ilivid
Key Found : HKCU\Software\IM
Key Found : HKCU\Software\ImInstaller
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\Wajam
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Found : HKLM\Software\AVG Secure Search
Key Found : HKLM\Software\Babylon
Key Found : HKLM\Software\BrowserCompanion
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
Key Found : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Found : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
Key Found : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Key Found : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll
Key Found : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Found : HKLM\SOFTWARE\Classes\BrowserConnection.Loader
Key Found : HKLM\SOFTWARE\Classes\BrowserConnection.Loader.1
Key Found : HKLM\SOFTWARE\Classes\DnsBHO.BHO
Key Found : HKLM\SOFTWARE\Classes\DnsBHO.BHO.1
Key Found : HKLM\SOFTWARE\Classes\ilivid
Key Found : HKLM\SOFTWARE\Classes\Incredibar.dskBnd
Key Found : HKLM\SOFTWARE\Classes\Incredibar.dskBnd.1
Key Found : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr
Key Found : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr.1
Key Found : HKLM\Software\Classes\Installer\Features\2B1E51D87B2D71A44BB42DDD5E894160
Key Found : HKLM\Software\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Key Found : HKLM\SOFTWARE\Classes\wajam.WajamBHO
Key Found : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1
Key Found : HKLM\SOFTWARE\Classes\wajam.WajamDownloader
Key Found : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\DataMngr
Key Found : HKLM\Software\ilivid
Key Found : HKLM\Software\Iminent
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\Software\SearchquMediabarTb
Key Found : HKLM\Software\uTorrentControl_v2
Key Found : HKLM\Software\Wajam
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\clbfjfbnelcflpgpklppgplejolacbej
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{73449E6D-E99C-44F6-9D81-5514F02C768F}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C5B99A2C-4940-463C-9B8D-0855940B8075}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v2 Toolbar
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wajam
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Found : HKLM\SOFTWARE\Software
Key Found : HKLM\SOFTWARE\Tarma Installer
Key Found : HKU\S-1-5-21-1025632964-579490387-1692577899-1000\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Found : HKU\S-1-5-21-1025632964-579490387-1692577899-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKU\S-1-5-21-1025632964-579490387-1692577899-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKU\S-1-5-21-1025632964-579490387-1692577899-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKU\S-1-5-21-1025632964-579490387-1692577899-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]
 
***** [Internet Browsers] *****
 
-\\ Internet Explorer v9.0.8112.16457
 
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=SE&userid=28531aba-c540-4613-9569-6b3971200d21&searchtype=ds&q={searchTerms}
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxps://isearch.avg.com/?cid={C8DC80C2-5EED-46ED-BC77-DE7D4E34CD09}&mid=f8a27cbf3d3147d094b5d5343deddd63-be68ca35e9556875d34514a2f4f59e1a492ed766&lang=en&ds=tt014&pr=sa&d=2012-09-30 21:13:37&v=13.0.0.7&sap=hp
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=SE&userid=28531aba-c540-4613-9569-6b3971200d21&searchtype=ds&q={searchTerms}
[HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=SE&userid=28531aba-c540-4613-9569-6b3971200d21&searchtype=ds&q={searchTerms}
[HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=SE&userid=28531aba-c540-4613-9569-6b3971200d21&searchtype=ds&q={searchTerms}
 
-\\ Mozilla Firefox v12.0 (sv-SE)
 
File : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\prefs.js
 
Found : user_pref("CT3072254..clientLogIsEnabled", false);
Found : user_pref("CT3072254..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT3072254..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT3072254.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT3072254.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT3072254.BrowserCompStateIsOpen_129572934028070084", true);
Found : user_pref("CT3072254.BrowserCompStateIsOpen_129573914344030086", true);
Found : user_pref("CT3072254.CTID", "CT3072254");
Found : user_pref("CT3072254.CurrentServerDate", "1-2-2013");
Found : user_pref("CT3072254.DSInstall", false);
Found : user_pref("CT3072254.DialogsAlignMode", "LTR");
Found : user_pref("CT3072254.DialogsGetterLastCheckTime", "Fri Feb 01 2013 19:30:21 GMT+0100");
Found : user_pref("CT3072254.DownloadReferralCookieData", "");
Found : user_pref("CT3072254.FirstServerDate", "19-3-2012");
Found : user_pref("CT3072254.FirstTime", true);
Found : user_pref("CT3072254.FirstTimeFF3", true);
Found : user_pref("CT3072254.FixPageNotFoundErrors", true);
Found : user_pref("CT3072254.GroupingServerCheckInterval", 1440);
Found : user_pref("CT3072254.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT3072254.HPInstall", false);
Found : user_pref("CT3072254.HasUserGlobalKeys", true);
Found : user_pref("CT3072254.Initialize", true);
Found : user_pref("CT3072254.InitializeCommonPrefs", true);
Found : user_pref("CT3072254.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT3072254.InstallationId", "ConduitXPEIntegration");
Found : user_pref("CT3072254.InstallationType", "ConduitXPEIntegration");
Found : user_pref("CT3072254.InstalledDate", "Mon Mar 19 2012 02:52:06 GMT+0100");
Found : user_pref("CT3072254.IsGrouping", false);
Found : user_pref("CT3072254.IsInitSetupIni", true);
Found : user_pref("CT3072254.IsMulticommunity", false);
Found : user_pref("CT3072254.IsOpenThankYouPage", true);
Found : user_pref("CT3072254.IsOpenUninstallPage", false);
Found : user_pref("CT3072254.LanguagePackLastCheckTime", "Fri Feb 01 2013 19:30:21 GMT+0100");
Found : user_pref("CT3072254.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT3072254.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT3072254.LastLogin_3.10.0.1", "Mon Mar 19 2012 02:52:06 GMT+0100");
Found : user_pref("CT3072254.LastLogin_3.12.2.3", "Mon Jun 11 2012 22:23:47 GMT+0200");
Found : user_pref("CT3072254.LastLogin_3.13.0.6", "Tue Aug 14 2012 05:51:27 GMT+0200");
Found : user_pref("CT3072254.LastLogin_3.14.1.0", "Mon Oct 29 2012 23:45:26 GMT+0100");
Found : user_pref("CT3072254.LastLogin_3.15.1.0", "Sun Dec 02 2012 20:19:29 GMT+0100");
Found : user_pref("CT3072254.LastLogin_3.16.0.3", "Fri Feb 01 2013 19:30:21 GMT+0100");
Found : user_pref("CT3072254.LatestVersion", "3.16.0.3");
Found : user_pref("CT3072254.Locale", "en");
Found : user_pref("CT3072254.MCDetectTooltipHeight", "83");
Found : user_pref("CT3072254.MCDetectTooltipShow", false);
Found : user_pref("CT3072254.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT3072254.MCDetectTooltipWidth", "295");
Found : user_pref("CT3072254.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT3072254.OriginalFirstVersion", "3.10.0.1");
Found : user_pref("CT3072254.SHRINK_TOOLBAR", 1);
Found : user_pref("CT3072254.SearchCaption", "uTorrentControl Customized Web Search");
Found : user_pref("CT3072254.SearchFromAddressBarIsInit", true);
Found : user_pref("CT3072254.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT307[...]
Found : user_pref("CT3072254.SearchInNewTabEnabled", true);
Found : user_pref("CT3072254.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT3072254.SearchInNewTabLastCheckTime", "Fri Feb 01 2013 19:30:20 GMT+0100");
Found : user_pref("CT3072254.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT3072254.SendProtectorDataViaLogin", true);
Found : user_pref("CT3072254.ServiceMapLastCheckTime", "Fri Feb 01 2013 19:30:19 GMT+0100");
Found : user_pref("CT3072254.SettingsLastCheckTime", "Fri Feb 01 2013 19:30:19 GMT+0100");
Found : user_pref("CT3072254.SettingsLastUpdate", "1359727900");
Found : user_pref("CT3072254.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3072254&SearchSource=13");
Found : user_pref("CT3072254.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT3072254.ThirdPartyComponentsLastCheck", "Mon Mar 19 2012 02:52:04 GMT+0100");
Found : user_pref("CT3072254.ThirdPartyComponentsLastUpdate", "1312887586");
Found : user_pref("CT3072254.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT3072254.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3072254");
Found : user_pref("CT3072254.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT3072254.UserID", "UN96939253106039895");
Found : user_pref("CT3072254.ValidationData_Toolbar", 0);
Found : user_pref("CT3072254.alertChannelId", "1463703");
Found : user_pref("CT3072254.approveUntrustedApps", false);
Found : user_pref("CT3072254.autoDisableScopes", -1);
Found : user_pref("CT3072254.backendstorage.cbfirsttime", "4D6F6E204D617220313920323031322030323A35323A31302[...]
Found : user_pref("CT3072254.components.129572934028070084", false);
Found : user_pref("CT3072254.components.129572934844292843", false);
Found : user_pref("CT3072254.components.129573914344030086", false);
Found : user_pref("CT3072254.components.129586117436877147", false);
Found : user_pref("CT3072254.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT3072254.globalFirstTimeInfoLastCheckTime", "Mon Mar 19 2012 02:52:06 GMT+0100");
Found : user_pref("CT3072254.homepageProtectorEnableByLogin", true);
Found : user_pref("CT3072254.initDone", true);
Found : user_pref("CT3072254.isAppTrackingManagerOn", true);
Found : user_pref("CT3072254.myStuffEnabled", true);
Found : user_pref("CT3072254.myStuffPublihserMinWidth", 400);
Found : user_pref("CT3072254.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT3072254.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT3072254.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT3072254.navigateToUrlOnSearch", false);
Found : user_pref("CT3072254.revertSettingsEnabled", true);
Found : user_pref("CT3072254.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT3072254.searchProtectorEnableByLogin", true);
Found : user_pref("CT3072254.testingCtid", "");
Found : user_pref("CT3072254.toolbarAppMetaDataLastCheckTime", "Fri Feb 01 2013 19:30:21 GMT+0100");
Found : user_pref("CT3072254.toolbarContextMenuLastCheckTime", "Mon Mar 19 2012 02:52:06 GMT+0100");
Found : user_pref("CT3072254.usagesFlag", 2);
Found : user_pref("CT3220468.BT_Stats.enc", "eyJsYXN0X2xvZyI6MTM1OTc0MzU0NiwidXVpZCI6MzE3NzQ0NDM5MjI4MDU2LCJ[...]
Found : user_pref("CT3220468.CBOpenMAMSettings.enc", "MA==");
Found : user_pref("CT3220468.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3220468.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Found : user_pref("CT3220468.FirstTime", "true");
Found : user_pref("CT3220468.FirstTimeFF3", "true");
Found : user_pref("CT3220468.LoginRevertSettingsEnabled", false);
Found : user_pref("CT3220468.RevertSettingsEnabled", true);
Found : user_pref("CT3220468.UserID", "UN65754710505070555");
Found : user_pref("CT3220468.addressBarTakeOverEnabledInHidden", "true");
Found : user_pref("CT3220468.autoDisableScopes", 14);
Found : user_pref("CT3220468.cbcountry_001.enc", "U0U=");
Found : user_pref("CT3220468.cbfirsttime.enc", "TW9uIE9jdCAyOSAyMDEyIDIzOjQ1OjQxIEdNVCswMTAw");
Found : user_pref("CT3220468.defaultSearch", "FALSE");
Found : user_pref("CT3220468.embeddedsData", "[{\"appId\":\"129813684258939747\",\"apiPermissions\":{\"cross[...]
Found : user_pref("CT3220468.enableAlerts", "always");
Found : user_pref("CT3220468.enableSearchFromAddressBar", "FALSE");
Found : user_pref("CT3220468.firstTimeDialogOpened", "true");
Found : user_pref("CT3220468.fixPageNotFoundError", "true");
Found : user_pref("CT3220468.fixPageNotFoundErrorInHidden", "true");
Found : user_pref("CT3220468.fixUrls", true);
Found : user_pref("CT3220468.installId", "fft9007.tmp.exe");
Found : user_pref("CT3220468.installType", "XPE");
Found : user_pref("CT3220468.isCheckedStartAsHidden", true);
Found : user_pref("CT3220468.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3220468.isFirstTimeToolbarLoading", "false");
Found : user_pref("CT3220468.isNewTabEnabled", true);
Found : user_pref("CT3220468.isPerformedSmartBarTransition", "true");
Found : user_pref("CT3220468.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Found : user_pref("CT3220468.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Found : user_pref("CT3220468.migrateAppsAndComponents", true);
Found : user_pref("CT3220468.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"file%3A%2F%2F%2FC%3A%2FProgra[...]
Found : user_pref("CT3220468.openThankYouPage", "true");
Found : user_pref("CT3220468.openUninstallPage", "FALSE");
Found : user_pref("CT3220468.search.searchAppId", "129813684258939747");
Found : user_pref("CT3220468.search.searchCount", "0");
Found : user_pref("CT3220468.searchInNewTabEnabledInHidden", "true");
Found : user_pref("CT3220468.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3220468.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Found : user_pref("CT3220468.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Found : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Found : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Found : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Found : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Found : user_pref("CT3220468.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1354476217210");
Found : user_pref("CT3220468.serviceLayer_services_appsMetadata_lastUpdate", "1354476097125");
Found : user_pref("CT3220468.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1354476217003");
Found : user_pref("CT3220468.serviceLayer_services_login_10.10.27.6_lastUpdate", "1354476097307");
Found : user_pref("CT3220468.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1354476217097");
Found : user_pref("CT3220468.serviceLayer_services_searchAPI_lastUpdate", "1354476097373");
Found : user_pref("CT3220468.serviceLayer_services_serviceMap_lastUpdate", "1354476096861");
Found : user_pref("CT3220468.serviceLayer_services_toolbarContextMenu_lastUpdate", "1354476217063");
Found : user_pref("CT3220468.serviceLayer_services_toolbarSettings_lastUpdate", "1354476097141");
Found : user_pref("CT3220468.serviceLayer_services_translation_lastUpdate", "1354476097201");
Found : user_pref("CT3220468.settingsINI", true);
Found : user_pref("CT3220468.shouldFirstTimeDialog", "false");
Found : user_pref("CT3220468.smartbar.CTID", "CT3220468");
Found : user_pref("CT3220468.smartbar.Uninstall", "0");
Found : user_pref("CT3220468.smartbar.toolbarName", "uTorrentControl_v2 ");
Found : user_pref("CT3220468.toolbarBornServerTime", "30-10-2012");
Found : user_pref("CT3220468.toolbarCurrentServerTime", "2-12-2012");
Found : user_pref("CT3220468.upgradeFromClearSBVersion", true);
Found : user_pref("CT3220468.url_history0001", "hxxp://thepiratebay.se/search/Austin%20Powers%20Internationa[...]
Found : user_pref("CT3220468_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3072254/CT3072254[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1463703/1459357/SE", "\"0\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3072254", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3072254",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"096[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Johanna\\AppData\\Roaming\\Mozilla\[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.10.0.1");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://dts.search-results.com/sr?src=ffb[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT3072254");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT3072254");
Found : user_pref("CommunityToolbar.ToolbarsList4", "CT3072254");
Found : user_pref("CommunityToolbar.globalUserId", "9181adc9-f9c0-41c9-8691-83f717bbd6a0");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3072254");
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Mon Mar 19 2012 02:52:0[...]
Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 60);
Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Mon Mar 19 2012 02:52:14 GMT+010[...]
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Mon Mar 19 2012 02:52:06 GMT+0100");
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "ae7bbdaa-7419-402c-993c-1e2d91ecd77a");
Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.searchnu.com/406");
Found : user_pref("CommunityToolbar.originalSearchEngine", "Search");
Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Found : user_pref("browser.startup.homepage", "hxxp://www.searchnu.com/406");
Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Found : user_pref("extensions.BabylonToolbar_i.babExt", "");
Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108298");
Found : user_pref("extensions.BabylonToolbar_i.hardId", "6e7a96be000000000000e0ca9488c749");
Found : user_pref("extensions.BabylonToolbar_i.id", "6e7a96be000000000000e0ca9488c749");
Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15361");
Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Found : user_pref("extensions.BabylonToolbar_i.newTab", true);
Found : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.delta-search.com/?affID=119529&babsrc[...]
Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1718:00:14");
Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Found : user_pref("extensions.enabledAddons", "ffxtlbr@funmoods.com:1.5.0,plugin@yontoo.com:1.20.00,{99079a2[...]
Found : user_pref("extensions.funmoods.SimilarSitesStorage-pid2", "9f329b90e1e41bcc");
Found : user_pref("extensions.funmoods.admin", false);
Found : user_pref("extensions.funmoods.aflt", "ironto");
Found : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
Found : user_pref("extensions.funmoods.cntry", "SE");
Found : user_pref("extensions.funmoods.cv", "cv5");
Found : user_pref("extensions.funmoods.dfltLng", "EN");
Found : user_pref("extensions.funmoods.dfltSrch", true);
Found : user_pref("extensions.funmoods.dfltlng", "EN");
Found : user_pref("extensions.funmoods.dfltsrch", true);
Found : user_pref("extensions.funmoods.excTlbr", false);
Found : user_pref("extensions.funmoods.hdrMd5", "55E81B957D62326AFD47F841BE38BE25");
Found : user_pref("extensions.funmoods.hmpg", true);
Found : user_pref("extensions.funmoods.hrdid", "6e7a96be000000000000e0ca9488c749");
Found : user_pref("extensions.funmoods.id", "6e7a96be000000000000e0ca9488c749");
Found : user_pref("extensions.funmoods.instlDay", "15375");
Found : user_pref("extensions.funmoods.instlRef", "");
Found : user_pref("extensions.funmoods.instlday", "15375");
Found : user_pref("extensions.funmoods.instlref", "");
Found : user_pref("extensions.funmoods.isDcmntCmplt", false);
Found : user_pref("extensions.funmoods.keywordurl", "");
Found : user_pref("extensions.funmoods.lastVrsnTs", "1.5.11.1621:30:56");
Found : user_pref("extensions.funmoods.logicsMngrDailyReportTime", "03-07-2012");
Found : user_pref("extensions.funmoods.newTab", true);
Found : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ironto");
Found : user_pref("extensions.funmoods.newtab", true);
Found : user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a=ironto");
Found : user_pref("extensions.funmoods.noFFXTlbr", false);
Found : user_pref("extensions.funmoods.prdct", "funmoods");
Found : user_pref("extensions.funmoods.propectorlck", 69887226);
Found : user_pref("extensions.funmoods.prtnrId", "funmoods");
Found : user_pref("extensions.funmoods.prtnrid", "funmoods");
Found : user_pref("extensions.funmoods.sg", "none");
Found : user_pref("extensions.funmoods.smplGrp", "none");
Found : user_pref("extensions.funmoods.smplgrp", "none");
Found : user_pref("extensions.funmoods.srch", "");
Found : user_pref("extensions.funmoods.srchPrvdr", "Search");
Found : user_pref("extensions.funmoods.srchprvdr", "Search");
Found : user_pref("extensions.funmoods.tlbrId", "base");
Found : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ironto&q="[...]
Found : user_pref("extensions.funmoods.tlbrid", "base");
Found : user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://start.funmoods.com/results.php?f=3&a=ironto&q="[...]
Found : user_pref("extensions.funmoods.vrsn", "1.5.11.16");
Found : user_pref("extensions.funmoods.vrsnTs", "1.5.11.1621:30:56");
Found : user_pref("extensions.funmoods.vrsni", "1.5.11.16");
Found : user_pref("extensions.funmoods.vrsnts", "1.5.11.1621:30:56");
Found : user_pref("extensions.funmoods_i.aflt", "ironto");
Found : user_pref("extensions.funmoods_i.dfltLng", "");
Found : user_pref("extensions.funmoods_i.dfltSrch", true);
Found : user_pref("extensions.funmoods_i.dnsErr", true);
Found : user_pref("extensions.funmoods_i.excTlbr", false);
Found : user_pref("extensions.funmoods_i.hmpg", true);
Found : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=ironto");
Found : user_pref("extensions.funmoods_i.id", "6e7a96be000000000000e0ca9488c749");
Found : user_pref("extensions.funmoods_i.instlDay", "15375");
Found : user_pref("extensions.funmoods_i.instlRef", "");
Found : user_pref("extensions.funmoods_i.newTab", true);
Found : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ironto");
Found : user_pref("extensions.funmoods_i.prdct", "funmoods");
Found : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
Found : user_pref("extensions.funmoods_i.smplGrp", "none");
Found : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
Found : user_pref("extensions.funmoods_i.tlbrId", "base");
Found : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ironto&q[...]
Found : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1621:30:56");
Found : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
Found : user_pref("extensions.helperbar.SmartbarDisabled", false);
Found : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Found : user_pref("extensions.incredibar_i.aflt", "orgnl");
Found : user_pref("extensions.incredibar_i.dfltLng", "");
Found : user_pref("extensions.incredibar_i.did", "10595");
Found : user_pref("extensions.incredibar_i.excTlbr", false);
Found : user_pref("extensions.incredibar_i.id", "6e7a96be000000000000e0ca9488c749");
Found : user_pref("extensions.incredibar_i.installerproductid", "26");
Found : user_pref("extensions.incredibar_i.instlDay", "15418");
Found : user_pref("extensions.incredibar_i.instlRef", "");
Found : user_pref("extensions.incredibar_i.ms_url_id", "");
Found : user_pref("extensions.incredibar_i.newTab", false);
Found : user_pref("extensions.incredibar_i.ppd", "");
Found : user_pref("extensions.incredibar_i.prdct", "incredibar");
Found : user_pref("extensions.incredibar_i.productid", "26");
Found : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Found : user_pref("extensions.incredibar_i.smplGrp", "none");
Found : user_pref("extensions.incredibar_i.tlbrId", "base");
Found : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8nhURDP1&loc=IB[...]
Found : user_pref("extensions.incredibar_i.upn2", "6R8nhURDP1");
Found : user_pref("extensions.incredibar_i.upn2n", "92824040610366319");
Found : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
Found : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1411:36:23");
Found : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");
 
-\\ Google Chrome v24.0.1312.57
 
File : C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Preferences
 
Found [l.19] : urls_to_restore_on_startup = [ "hxxp://www.delta-search.com/?affID=119529&babsrc=HP_ss&mntrId=6e7a96be000000000000e0ca9488c749" ]
Found [l.3216] : urls_to_restore_on_startup = [ "hxxp://www.delta-search.com/?affID=119529&babsrc=HP_ss&mntrId=6e7a96be000000000000e0ca9488c749" ]
 
*************************
 
AdwCleaner[R1].txt - [49801 octets] - [09/02/2013 20:33:31]
 
########## EOF - C:\AdwCleaner[R1].txt - [49862 octets] ##########


#9 Undesired_Hero

Undesired_Hero
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 09 February 2013 - 03:00 PM

Farbar Service Scanner Version: 30-01-2013
Ran by Johanna (administrator) on 09-02-2013 at 20:32:19
Running from "C:\Users\Johanna\Downloads"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
 
Internet Services:
============
 
Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
 
 
Windows Firewall:
=============
 
Firewall Disabled Policy: 
==================
 
 
System Restore:
============
 
System Restore Disabled Policy: 
========================
 
 
Action Center:
============
 
Windows Update:
============
 
Windows Autoupdate Disabled Policy: 
============================
 
 
Windows Defender:
==============
 
Other Services:
==============
 
 
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
 
 
**** End of log ****


MiniToolBox by Farbar  Version:10-01-2013
Ran by Johanna (administrator) on 09-02-2013 at 20:30:44
Running from "C:\Users\Johanna\Downloads"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
IP-konfiguration f”r Windows
 
DNS-matcharens cacheminne har rensats.
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
 
========================= FF Proxy Settings: ============================== 
 
 
"Reset FF Proxy Settings": Firefox Proxy settings were reset.
 
========================= Hosts content: =================================
255.255.255.255    easyanticheat.se    255.255.255.255    www.easyanticheat.se    255.255.255.255    easyanticheat.com    255.255.255.255    www.easyanticheat.com    255.255.255.255    easyanticheat.info    255.255.255.255    www.easyanticheat.info    255.255.255.255    easyanticheat.org    255.255.255.255    www.easyanticheat.org    
 
 
========================= IP Configuration: ================================
 
Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20) = Anslutning till lokalt nätverk (Connected)
Atheros AR9002WB-1NG Wireless Network Adapter = Trådlös nätverksanslutning (Connected)
 
 
# ----------------------------------
# IPv4-konfiguration
# ----------------------------------
pushd interface ipv4
 
reset
set global icmpredirects=enabled
 
 
popd
# Slut p† IPv4-konfigurationen
 
 
 
IP-konfiguration f”r Windows
 
   V„rddatornamn . . . . . . . . . . : Hollywoood-TOSH
   Prim„rt DNS-suffix. . . . . . . . : 
   Nodtyp. . . . . . . . . . . . . . : Hybrid
   IP-routning aktiverat . . . . . . : Nej
   WINS-proxy aktiverat. . . . . . . : Nej
   S”klista f”r DNS-suffix . . . . . : lan
 
Tr†dl”s anslutning Tr†dl”s n„tverksanslutning:
 
   Anslutningsspecifika DNS-suffix . : lan
   Beskrivning . . . . . . . . . . . : Atheros AR9002WB-1NG Wireless Network Adapter
   Fysisk adress . . . . . . . . . . : E0-CA-94-88-C7-49
   DHCP aktiverat. . . . . . . . . . : Ja
   Autokonfiguration aktiverat . . . : Ja
   L„nklokal IPv6-adress . . . . . . : fe80::a421:40de:b74d:fb7%15(Standard) 
   IPv4-adress . . . . . . . . . . . : 192.168.1.86(Standard) 
   N„tmask . . . . . . . . . . . . . : 255.255.255.0
   L†net erh”lls . . . . . . . . . . : den 9 februari 2013 20:25:01
   L†net upph”r. . . . . . . . . . . : den 10 februari 2013 20:25:00
   Standard-gateway. . . . . . . . . : 192.168.1.254
   DHCP-server . . . . . . . . . . . : 192.168.1.254
   IAID f”r DHCPv6 . . . . . . . . . : 467716756
   DUID f”r DHCPv6-klient. . . . . . : 00-01-00-01-16-46-5F-C8-04-7D-7B-09-34-90
   DNS-servrar . . . . . . . . . . . : 192.168.1.254
   NetBIOS ”ver TCP/IP . . . . . . . : Aktiverat
 
Ethernet-anslutning Anslutning till lokalt n„tverk:
 
   Anslutningsspecifika DNS-suffix . : lan
   Beskrivning . . . . . . . . . . . : Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
   Fysisk adress . . . . . . . . . . : 04-7D-7B-09-34-90
   DHCP aktiverat. . . . . . . . . . : Ja
   Autokonfiguration aktiverat . . . : Ja
   L„nklokal IPv6-adress . . . . . . : fe80::34ab:355b:575b:e707%11(Standard) 
   IPv4-adress . . . . . . . . . . . : 192.168.1.73(Standard) 
   N„tmask . . . . . . . . . . . . . : 255.255.255.0
   L†net erh”lls . . . . . . . . . . : den 9 februari 2013 20:24:56
   L†net upph”r. . . . . . . . . . . : den 10 februari 2013 20:24:56
   Standard-gateway. . . . . . . . . : 192.168.1.254
   DHCP-server . . . . . . . . . . . : 192.168.1.254
   IAID f”r DHCPv6 . . . . . . . . . : 241232745
   DUID f”r DHCPv6-klient. . . . . . : 00-01-00-01-16-46-5F-C8-04-7D-7B-09-34-90
   DNS-servrar . . . . . . . . . . . : 192.168.1.254
   NetBIOS ”ver TCP/IP . . . . . . . : Aktiverat
 
Tunnelanslutning: Anslutning till lokalt n„tverk* 9:
 
   Anslutningsspecifika DNS-suffix . : 
   Beskrivning . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Fysisk adress . . . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP aktiverat. . . . . . . . . . : Nej
   Autokonfiguration aktiverat . . . : Ja
   IPv6-adress . . . . . . . . . . . : 2001:0:5ef5:79fb:88:295f:aa1f:fc8d(Standard) 
   L„nklokal IPv6-adress . . . . . . : fe80::88:295f:aa1f:fc8d%12(Standard) 
   Standard-gateway. . . . . . . . . : ::
   NetBIOS ”ver TCP/IP . . . . . . . : Inaktiverat
 
Tunnelanslutning: Anslutning till lokalt n„tverk* 4:
 
   Tillst†nd . . . . . . . . . . . . : Fr†nkopplad
   Anslutningsspecifika DNS-suffix . : 
   Beskrivning . . . . . . . . . . . : Microsoft 6to4 Adapter
   Fysisk adress . . . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP aktiverat. . . . . . . . . . : Nej
   Autokonfiguration aktiverat . . . : Ja
 
Tunnelanslutning: isatap.lan:
 
   Tillst†nd . . . . . . . . . . . . : Fr†nkopplad
   Anslutningsspecifika DNS-suffix . : lan
   Beskrivning . . . . . . . . . . . : Microsoft ISATAP Adapter #3
   Fysisk adress . . . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP aktiverat. . . . . . . . . . : Nej
   Autokonfiguration aktiverat . . . : Ja
Server:  UnKnown
Address:  192.168.1.254
 
Namn:    google.com
Addresses:  2a00:1450:400f:801::1004
      173.194.32.41
      173.194.32.33
      173.194.32.46
      173.194.32.35
      173.194.32.34
      173.194.32.36
      173.194.32.32
      173.194.32.37
      173.194.32.40
      173.194.32.39
      173.194.32.38
 
 
Skickar ping-signal till google.com [173.194.32.38] med 32 byte data:
Svar fr†n 173.194.32.38: byte=32 tid=33ms TTL=55
Svar fr†n 173.194.32.38: byte=32 tid=36ms TTL=55
 
Ping-statistik f”r 173.194.32.38:
    Paket: Skickade = 2, Mottagna = 2, F”rlorade = 0 (0 %),
Ungef„rlig ”verf”ringstid i millisekunder:
    L„gsta = 33 ms, H”gsta = 36 ms, Medel = 34 ms
Server:  UnKnown
Address:  192.168.1.254
 
Namn:    yahoo.com
Addresses:  206.190.36.45
      98.138.253.109
      98.139.183.24
 
 
Skickar ping-signal till yahoo.com [98.139.183.24] med 32 byte data:
Svar fr†n 98.139.183.24: byte=32 tid=175ms TTL=50
Svar fr†n 98.139.183.24: byte=32 tid=193ms TTL=50
 
Ping-statistik f”r 98.139.183.24:
    Paket: Skickade = 2, Mottagna = 2, F”rlorade = 0 (0 %),
Ungef„rlig ”verf”ringstid i millisekunder:
    L„gsta = 175 ms, H”gsta = 193 ms, Medel = 184 ms
 
Skickar ping-signal till 127.0.0.1 med 32 byte data:
Svar fr†n 127.0.0.1: byte=32 tid < 1 ms TTL=128
Svar fr†n 127.0.0.1: byte=32 tid < 1 ms TTL=128
 
Ping-statistik f”r 127.0.0.1:
    Paket: Skickade = 2, Mottagna = 2, F”rlorade = 0 (0 %),
Ungef„rlig ”verf”ringstid i millisekunder:
    L„gsta = 0 ms, H”gsta = 0 ms, Medel = 0 ms
===========================================================================
Gr„nssnittslista
 15...e0 ca 94 88 c7 49 ......Atheros AR9002WB-1NG Wireless Network Adapter
 11...04 7d 7b 09 34 90 ......Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
  1...........................Software Loopback Interface 1
 12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 14...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
 17...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
===========================================================================
 
V„gtabell f”r IPv4
===========================================================================
Aktiva v„gar:
   N„tverksadress          N„tmask   Gateway-adress      Gr„nssnitt    M†tt
          0.0.0.0          0.0.0.0    192.168.1.254     192.168.1.73     20
          0.0.0.0          0.0.0.0    192.168.1.254     192.168.1.86     25
        127.0.0.0        255.0.0.0         Vid lan         127.0.0.1    306
        127.0.0.1  255.255.255.255         Vid lan         127.0.0.1    306
  127.255.255.255  255.255.255.255         Vid lan         127.0.0.1    306
      192.168.1.0    255.255.255.0         Vid lan      192.168.1.73    276
      192.168.1.0    255.255.255.0         Vid lan      192.168.1.86    281
     192.168.1.73  255.255.255.255         Vid lan      192.168.1.73    276
     192.168.1.86  255.255.255.255         Vid lan      192.168.1.86    281
    192.168.1.255  255.255.255.255         Vid lan      192.168.1.73    276
    192.168.1.255  255.255.255.255         Vid lan      192.168.1.86    281
        224.0.0.0        240.0.0.0         Vid lan         127.0.0.1    306
        224.0.0.0        240.0.0.0         Vid lan      192.168.1.73    276
        224.0.0.0        240.0.0.0         Vid lan      192.168.1.86    281
  255.255.255.255  255.255.255.255         Vid lan         127.0.0.1    306
  255.255.255.255  255.255.255.255         Vid lan      192.168.1.73    276
  255.255.255.255  255.255.255.255         Vid lan      192.168.1.86    281
===========================================================================
Best„ndiga v„gar:
  Inga
 
V„gtabell f”r IPv6
===========================================================================
Aktiva v„gar:
 Gr M†tt   N„tverk M†l              Gateway
 12     58 ::/0                     Vid lan
  1    306 ::1/128                  Vid lan
 12     58 2001::/32                Vid lan
 12    306 2001:0:5ef5:79fb:88:295f:aa1f:fc8d/128
                                    Vid lan
 11    276 fe80::/64                Vid lan
 15    281 fe80::/64                Vid lan
 12    306 fe80::/64                Vid lan
 12    306 fe80::88:295f:aa1f:fc8d/128
                                    Vid lan
 11    276 fe80::34ab:355b:575b:e707/128
                                    Vid lan
 15    281 fe80::a421:40de:b74d:fb7/128
                                    Vid lan
  1    306 ff00::/8                 Vid lan
 12    306 ff00::/8                 Vid lan
 11    276 ff00::/8                 Vid lan
 15    281 ff00::/8                 Vid lan
===========================================================================
Best„ndiga v„gar:
  Inga
========================= Winsock entries =====================================
 
Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 09 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (02/09/2013 08:26:33 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/09/2013 08:11:12 PM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext för C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1. Det finns ett fel i manifest- eller principfilen C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 på rad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
En komponentversion som begärs av programmet står i konflikt med en annan komponentversion som redan är aktiv.
Följande komponenter orsakar konflikten:
Komponent 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponent 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (02/09/2013 04:50:09 PM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext för C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1. Det finns ett fel i manifest- eller principfilen C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 på rad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
En komponentversion som begärs av programmet står i konflikt med en annan komponentversion som redan är aktiv.
Följande komponenter orsakar konflikten:
Komponent 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponent 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (02/09/2013 04:50:04 PM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext för C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1. Det finns ett fel i manifest- eller principfilen C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 på rad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
En komponentversion som begärs av programmet står i konflikt med en annan komponentversion som redan är aktiv.
Följande komponenter orsakar konflikten:
Komponent 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponent 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (02/09/2013 04:23:06 PM) (Source: Application Error) (User: )
Description: Felet uppstod i programmet med namn: NDSTray.exe, version 8.0.0.48, tidsstämpel 0x4cf8869a
, felet uppstod i modulen med namn: ntdll.dll, version 6.1.7601.17725, tidsstämpel 0x4ec49b8f
Undantagskod: 0xc0000005
Felförskjutning: 0x0002e066
Process-ID: 0x1124
Programmets starttid: 0xNDSTray.exe0
Sökväg till program: NDSTray.exe1
Sökväg till modul: NDSTray.exe2
Rapport-ID: NDSTray.exe3
 
Error: (02/09/2013 04:22:18 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/09/2013 10:06:54 AM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext för Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8"1.
Den beroende sammansättningen Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8" kunde inte hittas.
Använd sxstrace.exe om du vill diagnostisera ytterligare.
 
Error: (02/09/2013 10:06:35 AM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext för Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8"1.
Den beroende sammansättningen Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8" kunde inte hittas.
Använd sxstrace.exe om du vill diagnostisera ytterligare.
 
Error: (02/09/2013 10:05:09 AM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext för Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8"1.
Den beroende sammansättningen Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8" kunde inte hittas.
Använd sxstrace.exe om du vill diagnostisera ytterligare.
 
Error: (02/09/2013 10:04:58 AM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext för Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8"1.
Den beroende sammansättningen Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8" kunde inte hittas.
Använd sxstrace.exe om du vill diagnostisera ytterligare.
 
 
System errors:
=============
Error: (02/09/2013 08:23:40 PM) (Source: DCOM) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
 
Error: (02/09/2013 05:45:00 PM) (Source: volsnap) (User: )
Description: Skuggkopiorna för volymen C: avbröts eftersom lagringsutrymmet för skuggkopian inte kunde växa på grund av en begränsning som angetts av användaren.
 
Error: (02/09/2013 04:18:20 PM) (Source: DCOM) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
 
Error: (02/07/2013 06:07:35 PM) (Source: EventLog) (User: )
Description: Den senaste avstängningen av datorn vid 18:05:43 den ?2013-?02-?07 skedde oväntat.
 
Error: (02/06/2013 07:02:44 AM) (Source: DCOM) (User: )
Description: {4EB61BAC-A3B6-4760-9581-655041EF4D69}
 
Error: (02/06/2013 07:02:14 AM) (Source: Service Control Manager) (User: )
Description: Tjänsten Google Update Service (gupdate) avslutades oväntat. Detta har skett 1 gånger.
 
Error: (02/04/2013 07:40:18 PM) (Source: DCOM) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
 
Error: (02/03/2013 02:41:01 PM) (Source: Schannel) (User: NT instans)
Description: Följande allvarliga fel genererades: 10. Intern felstatus är 10.
 
Error: (02/02/2013 02:22:28 PM) (Source: Schannel) (User: NT instans)
Description: Följande allvarliga fel genererades: 10. Intern felstatus är 10.
 
Error: (02/01/2013 11:10:13 AM) (Source: volsnap) (User: )
Description: Skuggkopiorna för volymen C: avbröts eftersom lagringsutrymmet för skuggkopian inte kunde växa på grund av en begränsning som angetts av användaren.
 
 
Microsoft Office Sessions:
=========================
Error: (02/09/2013 08:26:33 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/09/2013 08:11:12 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Johanna\Downloads\esetsmartinstaller_enu.exe
 
Error: (02/09/2013 04:50:09 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Johanna\Downloads\esetsmartinstaller_enu.exe
 
Error: (02/09/2013 04:50:04 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Johanna\Downloads\esetsmartinstaller_enu.exe
 
Error: (02/09/2013 04:23:06 PM) (Source: Application Error)(User: )
Description: NDSTray.exe8.0.0.484cf8869antdll.dll6.1.7601.177254ec49b8fc00000050002e066112401ce06d95a832245C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exeC:\Windows\SysWOW64\ntdll.dll99c6b875-72cc-11e2-b98d-047d7b093490
 
Error: (02/09/2013 04:22:18 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/09/2013 10:06:54 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\adbeape.dll
 
Error: (02/09/2013 10:06:35 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\adbeape.dll
 
Error: (02/09/2013 10:05:09 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\adbeape.dll
 
Error: (02/09/2013 10:04:58 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.21022.8"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\adbeape.dll
 
 
=========================== Installed Programs ============================
 
ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (Version: 15.4.5722.2)
Adobe AIR (Version: 3.4.0.2540)
Adobe Flash Media Live Encoder 3.2 (Version: 3.2.0)
Adobe Flash Player 11 ActiveX (Version: 11.4.402.278)
Adobe Flash Player 11 Plugin (Version: 11.5.502.146)
Adobe Photoshop CS5 (Version: 12.0)
Adobe Reader X (10.1.4) MUI (Version: 10.1.4)
Adobe Shockwave Player 11.6 (Version: 11.6.8.638)
Alan Wake
Amnesia: The Dark Descent
Apple Application Support (Version: 2.1.7)
Apple Mobile Device Support (Version: 4.0.0.97)
Apple Software Update (Version: 2.1.3.127)
Arctic Combat
Assassin's Creed II
Atheros Bluetooth Filter Driver Package (Version: 1.00.007)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (Version: 1.0.0.36)
Atheros Driver Installation Program (Version: 9.2)
µTorrent (Version: 3.2.2.28595)
avast! Free Antivirus (Version: 7.0.1466.0)
AVG Security Toolbar (Version: 13.0.0.7)
AVS Screen Capture version 2.0.1
AVS Update Manager 1.0
AVS Video Editor 6
AVS Video Recorder 2.5
Battlefield 3™ (Version: 1.4.0.0)
Battlelog Web Plugins (Version: 1.138.0)
Bejeweled 2 Deluxe (Version: 2.2.0.95)
Bejeweled 3 (Version: 2.2.0.97)
Bluetooth Stack for Windows by Toshiba (Version: v8.00.04(T))
Bonjour (Version: 3.0.0.10)
BrowserCompanion
Call of Duty: Black Ops II
Call of Duty: Black Ops II - Multiplayer
Call of Duty: Black Ops II - Zombies
Chicken Invaders 3 - Revenge of the Yolk (Version: 2.2.0.95)
Chuzzle Deluxe (Version: 2.2.0.95)
Clownfish for Skype
Company of Heroes 2 - Alpha
Conexant HD Audio (Version: 8.51.1.0)
Counter-Strike: Global Offensive Beta
Counter-Strike: Source
CyberLink YouCam 5 (Version: 5.0.1129)
D3DX10 (Version: 15.4.2368.0902)
DAEMON Tools Pro (Version: 5.2.0.0348)
Dead Island
Diner Dash 2 Restaurant Rescue (Version: 2.2.0.95)
Dota 2
Dungeon Defenders
ESET Online Scanner v3
ESN Sonar (Version: 0.70.4)
Euro Truck Simulator 2 (Version: 1.1.3)
Facebook Messenger 2.1.4651.0 (Version: 2.1.4651.0)
Facebook Video Calling 1.2.0.287 (Version: 1.2.287)
Fallen Earth
FATE (Version: 2.2.0.97)
FFsplit version Alpha (Version: Alpha)
Final Drive: Nitro (Version: 2.2.0.95)
Fraps (remove only)
Fraps v3.4.7  PRO (Version: PRO)
Google Chrome (Version: 24.0.1312.57)
Google Talk Plugin (Version: 3.13.2.11592)
Google Update Helper (Version: 1.3.21.135)
Half-Life 2: Deathmatch
Half-Life 2: Lost Coast
High-Definition Video Playback (Version: 7.3.10900.8.0)
Homefront
iLivid (Version: 1.92.0.121952)
Insaniquarium Deluxe (Version: 2.2.0.97)
Insurgency
Intel® Management Engine Components (Version: 7.0.0.1144)
Intel® Rapid Storage Technology (Version: 10.1.2.1004)
iTunes (Version: 10.5.3.3)
Java 7 Update 7 (Version: 7.0.70)
Java Auto Updater (Version: 2.1.9.0)
Java™ 6 Update 31 (64-bit) (Version: 6.0.310)
Java™ 6 Update 31 (Version: 6.0.310)
JavaFX 2.1.1 (Version: 2.1.1)
Junk Mail filter update (Version: 15.4.3502.0922)
Left 4 Dead
Left 4 Dead 2
Logitech G35 (Version: 1.1.178)
Malwarebytes Anti-Malware version 1.70.0.1100 (Version: 1.70.0.1100)
MediaGet (Version: )
Mesh Runtime (Version: 15.4.5722.2)
Messenger-kumppani (Version: 15.4.3502.0922)
Messenger Assistent (Version: 15.4.3502.0922)
Messenger Companion (Version: 15.4.3502.0922)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile Language Pack - SVE (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile SVE Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended Language Pack - SVE (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended SVE Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 (Version: 14.0.4763.1000)
Microsoft Office Klicka-och-kör 2010 (Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - svenska (Version: 14.0.5128.5002)
Microsoft Primary Interoperability Assemblies 2005 (Version: 9.0.21022)
Microsoft Silverlight (Version: 5.1.10411.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (Version: 9.0.30411)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0)
Monday Night Combat
Mozilla Firefox 12.0 (x86 sv-SE) (Version: 12.0)
Mozilla Maintenance Service (Version: 12.0)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT Redists (Version: 1.0)
MSVCRT_amd64 (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Nation Red
Natural Selection 2
Nero 10 Movie ThemePack Basic (Version: 10.6.10000.1.0)
Nero BackItUp 10 (Version: 5.8.10900.8.100)
Nero BackItUp 10 Help (CHM) (Version: 10.6.10700)
Nero BurnRights 10 (Version: 4.4.10400.2.100)
Nero BurnRights 10 Help (CHM) (Version: 10.6.10700)
Nero Control Center 10 (Version: 10.6.12700.0.7)
Nero ControlCenter 10 Help (CHM) (Version: 10.6.10800)
Nero Core Components 10 (Version: 2.0.20000.9.12)
Nero Express 10 (Version: 10.6.10700.5.100)
Nero Express 10 Help (CHM) (Version: 10.6.10700)
Nero InfoTool 10 (Version: 7.4.10300.1.100)
Nero InfoTool 10 Help (CHM) (Version: 10.6.10700)
Nero Multimedia Suite 10 Essentials (Version: 10.6.10300)
Nero RescueAgent 10 (Version: 3.6.10500.3.100)
Nero RescueAgent 10 Help (CHM) (Version: 10.6.10800)
Nero StartSmart 10 (Version: 10.6.10500.3.100)
Nero StartSmart 10 Help (CHM) (Version: 10.6.10700)
Nero Update (Version: 1.0.10900.31.0)
NeroKwikMedia Help (CHM) (Version: 10.6.10900)
NVIDIA-uppdatering 1.5.20 (Version: 1.5.20)
NVIDIA 3D Vision drivrutin 285.62 (Version: 285.62)
NVIDIA Grafikdrivrutin 285.62 (Version: 285.62)
NVIDIA HD audiodrivrutin 1.2.24.0 (Version: 1.2.24.0)
NVIDIA Install Application (Version: 2.1002.46.235)
NVIDIA PhysX (Version: 9.11.0621)
NVIDIA PhysX systemprogramvara 9.11.0621 (Version: 9.11.0621)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.12.8562)
NVIDIA Update Components (Version: 1.5.20)
NVIDIAs kontrollpanel 285.62 (Version: 285.62)
Orcs Must Die!
Orcs Must Die! 2
Origin (Version: 8.5.0.4550)
PAYDAY: The Heist
Penguins! (Version: 2.2.0.95)
Plants vs. Zombies - Game of the Year (Version: 2.2.0.95)
PlayReady PC Runtime amd64 (Version: 1.3.0)
Polar Bowler (Version: 2.2.0.97)
Portal: First Slice
PunkBuster Services (Version: 0.991)
QuickTime (Version: 7.72.80.56)
Realtek USB 2.0 Reader Driver (Version: 1.0.0.15)
Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.0.32.0)
Rock of Ages
Searchqu Toolbar (Version: 3.0.0.121921)
Skype Click to Call (Version: 5.9.9216)
Skype™ 6.1 (Version: 6.1.129)
Slingo Deluxe (Version: 2.2.0.95)
Source SDK Base 2006
Source SDK Base 2007
Spotify (Version: 0.8.5.1333.g822e0de8)
Steam (Version: 1.0.0.0)
swMSM (Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 15.2.11.1)
Team Fortress 2
TeamSpeak 3 Client (Version: 3.0.9.2)
TeamViewer 7 (Version: 7.0.13989)
The Binding of Isaac
The Ship Single Player
The Sims 3 Complete Edition version 1.02 (Version: 1.02)
The Sims™ 3 (Version: 1.34.27)
The Sims™ 3 Ambitions (Version: 4.10.1)
The Sims™ 3 Fast Lane Stuff (Version: 5.8.1)
The Sims™ 3 Generations (Version: 8.0.152)
The Sims™ 3 High-End Loft Stuff (Version: 3.13.1)
The Sims™ 3 Katy Perry's Sweet Treats (Version: 13.0.62)
The Sims™ 3 Late Night (Version: 6.5.1)
The Sims™ 3 Master Suite Stuff (Version: 11.0.84)
The Sims™ 3 Outdoor Living Stuff (Version: 7.3.2)
The Sims™ 3 Pets (Version: 10.0.96)
The Sims™ 3 Showtime (Version: 12.0.273)
The Sims™ 3 Town Life Stuff (Version: 9.0.73)
The Sims™ 3 World Adventures (Version: 2.17.2)
Tinychat Updater (Version: 1.0.0)
Torchlight
TOSHIBA Assist (Version: 4.02.02)
TOSHIBA Bulletin Board (Version: 2.1.10.64)
TOSHIBA ConfigFree (Version: 8.0.37)
TOSHIBA Disc Creator (Version: 2.1.0.6 for x64)
TOSHIBA eco Utility (Version: 1.2.25.64)
TOSHIBA Face Recognition (Version: 3.1.8.64)
TOSHIBA Hardware Setup (Version: 4.08.06.00)
TOSHIBA HDD/SSD Alert (Version: 3.1.64.7)
Toshiba Manuals (Version: 10.02)
TOSHIBA Online Product Information (Version: 4.01.0000)
TOSHIBA PC Health Monitor (Version: 1.7.9.64M)
TOSHIBA Places Icon Utility (Version: 1.0.2.4)
TOSHIBA Recovery Media Creator (Version: 2.1.3.10010)
TOSHIBA Recovery Media Creator Reminder (Version: 1.00.0019)
TOSHIBA ReelTime (Version: 1.7.17.64)
TOSHIBA Service Station (Version: 2.1.52)
TOSHIBA Sleep Utility (Version: 1.4.2.7)
TOSHIBA Supervisor Password (Version: 4.08.06.00)
TOSHIBA TEMPRO (Version: 3.35)
TOSHIBA Value Added Package (Version: 1.5.4.64)
TOSHIBA Web Camera Application (Version: 2.0.0.19)
TOSHIBA Wireless LAN Indicator (Version: 1.0.3)
TRORMCLauncher (Version: )
TRORMCLauncher (Version: 1.0.0.10)
Ubisoft Game Launcher (Version: 1.0.0.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update Installer for WildTangent Games App
uTorrentControl_v2 Toolbar (Version: 6.9.0.16)
Wajam (Version: 1.51)
War Inc. Battlezone
Wedding Dash 2 - Rings Around the World (Version: 2.2.0.95)
Veetle TV (Version: 0.9.19)
Ventrilo Client (Version: 3.0.8)
VH Toolkit 1.0.15.0
WildTangent Games (Version: 1.0.2.5)
WildTangent Games App (Toshiba Games) (Version: 4.0.10.5)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalleri (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (Version: 15.4.5722.2)
Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
Windows Live Meshin etäyhteyksien ActiveX-komponentti (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows Liven asennustyökalu (Version: 15.4.3502.0922)
Windows Liven sähköposti (Version: 15.4.3502.0922)
Windows Liven valokuvavalikoima (Version: 15.4.3502.0922)
WinRAR 4.11 (32-bit) (Version: 4.11.0)
VLC media player 1.1.11 (Version: 1.1.11)
Worms Revolution
X-Chat 2.8.6-2 (Version: 2.8.6-2)
XSplit (Version: 1.0.1204.1301)
Xvid MPEG-4 Video Codec
Yontoo 1.10.02 (Version: 1.10.02)
Zombie Driver HD Demo
Zombie Panic Source
Zuma Deluxe (Version: 2.2.0.95)
 
========================= Devices: ================================
 
 
========================= Memory info: ===================================
 
Percentage of memory in use: 55%
Total physical RAM: 4077.86 MB
Available physical RAM: 1803.57 MB
Total Pagefile: 8153.91 MB
Available Pagefile: 5767.48 MB
Total Virtual: 4095.88 MB
Available Virtual: 3959.88 MB
 
========================= Partitions: =====================================
 
1 Drive c: (WINDOWS) (Fixed) (Total:121.71 GB) (Free:19.21 GB) NTFS
2 Drive d: (Data) (Fixed) (Total:298.33 GB) (Free:76.97 GB) NTFS
4 Drive f: (DamnIt) (Fixed) (Total:175.74 GB) (Free:105.16 GB) NTFS
5 Drive g: (The Sims 3 Complete Edition) (CDROM) (Total:17.6 GB) (Free:0 GB) UDF
 
========================= Users: ========================================
 
Anv„ndarkonton f”r \\HOLLYWOOOD-TOSH
 
Administrat”r            ASPNET                   G„st                     
Johanna                  UpdatusUser              
Kommandot har utf”rts.
 
 
**** End of log ****


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.6.2 (02.02.2013:2)
OS: Windows 7 Home Premium x64
Ran by Johanna on 2013-02-09 at 20:38:13,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
Successfully stopped: [Service] wajamupdater 
Successfully deleted: [Service] wajamupdater 
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\windows\currentversion\run\\datamngr
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\windows nt\currentversion\windows\\AppInit_DLLs
Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\urlsearchhooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} 
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} 
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\urlsearchhooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} 
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{95b7759c-8c7f-4bf1-b163-73684a933233} 
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} 
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} 
Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\toolbar\webbrowser\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} 
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1025632964-579490387-1692577899-1000\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1025632964-579490387-1692577899-1000\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Search Bar
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1025632964-579490387-1692577899-1000\software\microsoft\internet explorer\main\\Search Bar
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Search Page
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1025632964-579490387-1692577899-1000\software\microsoft\internet explorer\main\\Search Page
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\search\\Default_Search_URL
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1025632964-579490387-1692577899-1000\software\microsoft\internet explorer\search\\Default_Search_URL
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchurl\\Default
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1025632964-579490387-1692577899-1000\software\microsoft\internet explorer\searchurl\\Default
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\search\\SearchAssistant
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1025632964-579490387-1692577899-1000\software\microsoft\internet explorer\search\\SearchAssistant
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] hkey_current_user\software\1clickdownload
Successfully deleted: [Registry Key] hkey_local_machine\software\babylon
Successfully deleted: [Registry Key] hkey_current_user\software\blabbers
Successfully deleted: [Registry Key] hkey_current_user\software\browsercompanion
Successfully deleted: [Registry Key] hkey_local_machine\software\browsercompanion
Successfully deleted: [Registry Key] hkey_current_user\software\conduit
Successfully deleted: [Registry Key] hkey_local_machine\software\conduit
Successfully deleted: [Registry Key] hkey_current_user\software\datamngr
Successfully deleted: [Registry Key] hkey_local_machine\software\datamngr
Successfully deleted: [Registry Key] hkey_current_user\software\datamngr_toolbar
Successfully deleted: [Registry Key] hkey_current_user\software\ilivid
Successfully deleted: [Registry Key] hkey_local_machine\software\ilivid
Successfully deleted: [Registry Key] hkey_current_user\software\im
Successfully deleted: [Registry Key] hkey_local_machine\software\iminent
Successfully deleted: [Registry Key] hkey_current_user\software\iminstaller
Successfully deleted: [Registry Key] hkey_local_machine\software\searchqumediabartb
Successfully deleted: [Registry Key] hkey_current_user\software\softonic
Successfully deleted: [Registry Key] hkey_current_user\software\sweetim
Successfully deleted: [Registry Key] hkey_local_machine\software\sweetim
Successfully deleted: [Registry Key] hkey_current_user\software\wajam
Successfully deleted: [Registry Key] hkey_local_machine\software\wajam
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduit
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\searchqutoolbar
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\smartbar
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\toolbar
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\browserconnection.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\dnsbho.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\nctaudiocdgrabber2.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\scripthelper.exe
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\tdataprotocol.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\updatebho.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\viprotocol.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\wit4ie.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\yontooieclient.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\applications\ilividsetupv1.exe
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\browserconnection.loader
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\browserconnection.loader.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\dnsbho.bho
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\dnsbho.bho.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibar.dskbnd
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibar.dskbnd.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibar.incredibarhlpr
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibar.incredibarhlpr.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\prod.cap
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\protocols\handler\viprotocol
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\scripthelper.scripthelperapi
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\scripthelper.scripthelperapi.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\searchquiehelper.dnsguard
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\searchquiehelper.dnsguard.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\viprotocol.viprotocolole
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\viprotocol.viprotocolole.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\wajam.wajambho
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\wajam.wajambho.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\wajam.wajamdownloader
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\wajam.wajamdownloader.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.api
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.api.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.layers
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.layers.1
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\incredibartoolbar_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\incredibartoolbar_rasmancs
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasmancs
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\searchqumediabar_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\searchqumediabar_rasmancs
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\setupdatamngr_searchqu_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\setupdatamngr_searchqu_rasmancs
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\microsoft\tracing\ilividsetupv1_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\microsoft\tracing\ilividsetupv1_rasmancs
Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT3220468
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{2eecd738-5844-4a99-b4b6-146bf802613b}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{6e13dde1-2b6e-46ce-8b66-dc8bf36f6b99}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{95b7759c-8c7f-4bf1-b163-73684a933233}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{95b7759c-8c7f-4bf1-b163-73684a933233}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{99079a25-328f-4bd4-be04-00955acaa0a7}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{99079a25-328f-4bd4-be04-00955acaa0a7}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{9bb47c17-9c68-4bb3-b188-dd9af0fd2406}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{9bb47c17-9c68-4bb3-b188-dd9af0fd2406}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{9d717f81-9148-4f12-8568-69135f087db0}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{9d717f81-9148-4f12-8568-69135f087db0}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{a40dc6c5-79d0-4ca8-a185-8ff989af1115}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{a7a6995d-6ee1-4fd1-a258-49395d5bf99c}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{a7a6995d-6ee1-4fd1-a258-49395d5bf99c}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{ae07101b-46d4-4a98-af68-0333ea26e113}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{cc1ac828-bb47-4361-afb5-96eee259dd87}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{cff4db9b-135f-47c0-9269-b4c6572fd61a}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{e46c8196-b634-44a1-af6e-957c64278ab1}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{f9639e4a-801b-4843-aee3-03d9da199e77}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{fd72061e-9fde-484d-a58a-0bab4151cad8}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{fd72061e-9fde-484d-a58a-0bab4151cad8}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{fefd3af5-a346-4451-aa23-a3ad54915515}
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\installmate"
Successfully deleted: [Folder] "C:\ProgramData\partner"
Successfully deleted: [Folder] "C:\ProgramData\premium"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\Users\Johanna\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\local\ilivid player"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\local\torch"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\local\wajam"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\locallow\incredibar.com"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\locallow\searchquband"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\locallow\searchqutoolbar"
Successfully deleted: [Folder] "C:\Users\Johanna\appdata\locallow\utorrentcontrol_v2"
Successfully deleted: [Folder] "C:\Program Files (x86)\browsercompanion"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\fbphotozoom"
Successfully deleted: [Folder] "C:\Program Files (x86)\ilivid"
Successfully deleted: [Folder] "C:\Program Files (x86)\searchqu toolbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\utorrentcontrol_v2"
Successfully deleted: [Folder] "C:\Program Files (x86)\wajam"
Successfully deleted: [Folder] "C:\Program Files (x86)\yontoo"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ilivid"
Successfully deleted: [Folder] "C:\Users\Johanna\AppData\Roaming\microsoft\windows\start menu\programs\wajam"
 
 
 
~~~ FireFox
 
Successfully deleted: [File] C:\user.js
Successfully deleted: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml"
Successfully deleted: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\search_results.xml"
Successfully deleted: [File] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\user.js
Successfully deleted: [File] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\searchplugins\delta.xml
Successfully deleted: [File] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\searchplugins\funmoods.xml
Successfully deleted: [File] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\searchplugins\mystart search.xml
Successfully deleted: [File] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\searchplugins\search_results.xml
Failed to delete: [Folder] "C:\Program Files (x86)\Mozilla Firefox\extensions\{1fd91a9c-410c-4090-bbcc-55d3450ef433}"
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\conduitcommon
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\searchqutoolbar
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\smartbar
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\extensions\ffxtlbr@funmoods.com
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\extensions\bbrs_002@blabbers.com
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\extensions\ffxtlbr@delta.com
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\extensions\plugin@yontoo.com
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\extensions\staged
Failed to delete: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\extensions\{1fd91a9c-410c-4090-bbcc-55d3450ef433}
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Folder] C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
Successfully deleted the following from C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\prefs.js
 
user_pref("CT3072254..clientLogIsEnabled", false);
user_pref("CT3072254..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
user_pref("CT3072254..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
user_pref("CT3072254.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
user_pref("CT3072254.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
user_pref("CT3072254.BrowserCompStateIsOpen_129572934028070084", true);
user_pref("CT3072254.BrowserCompStateIsOpen_129573914344030086", true);
user_pref("CT3072254.CTID", "CT3072254");
user_pref("CT3072254.CurrentServerDate", "1-2-2013");
user_pref("CT3072254.DSInstall", false);
user_pref("CT3072254.DialogsAlignMode", "LTR");
user_pref("CT3072254.DialogsGetterLastCheckTime", "Fri Feb 01 2013 19:30:21 GMT+0100");
user_pref("CT3072254.DownloadReferralCookieData", "");
user_pref("CT3072254.FirstServerDate", "19-3-2012");
user_pref("CT3072254.FirstTime", true);
user_pref("CT3072254.FirstTimeFF3", true);
user_pref("CT3072254.FixPageNotFoundErrors", true);
user_pref("CT3072254.GroupingServerCheckInterval", 1440);
user_pref("CT3072254.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
user_pref("CT3072254.HPInstall", false);
user_pref("CT3072254.HasUserGlobalKeys", true);
user_pref("CT3072254.Initialize", true);
user_pref("CT3072254.InitializeCommonPrefs", true);
user_pref("CT3072254.InstallationAndCookieDataSentCount", 3);
user_pref("CT3072254.InstallationId", "ConduitXPEIntegration");
user_pref("CT3072254.InstallationType", "ConduitXPEIntegration");
user_pref("CT3072254.InstalledDate", "Mon Mar 19 2012 02:52:06 GMT+0100");
user_pref("CT3072254.IsGrouping", false);
user_pref("CT3072254.IsInitSetupIni", true);
user_pref("CT3072254.IsMulticommunity", false);
user_pref("CT3072254.IsOpenThankYouPage", true);
user_pref("CT3072254.IsOpenUninstallPage", false);
user_pref("CT3072254.LanguagePackLastCheckTime", "Fri Feb 01 2013 19:30:21 GMT+0100");
user_pref("CT3072254.LanguagePackReloadIntervalMM", 1440);
user_pref("CT3072254.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
user_pref("CT3072254.LastLogin_3.10.0.1", "Mon Mar 19 2012 02:52:06 GMT+0100");
user_pref("CT3072254.LastLogin_3.12.2.3", "Mon Jun 11 2012 22:23:47 GMT+0200");
user_pref("CT3072254.LastLogin_3.13.0.6", "Tue Aug 14 2012 05:51:27 GMT+0200");
user_pref("CT3072254.LastLogin_3.14.1.0", "Mon Oct 29 2012 23:45:26 GMT+0100");
user_pref("CT3072254.LastLogin_3.15.1.0", "Sun Dec 02 2012 20:19:29 GMT+0100");
user_pref("CT3072254.LastLogin_3.16.0.3", "Fri Feb 01 2013 19:30:21 GMT+0100");
user_pref("CT3072254.LatestVersion", "3.16.0.3");
user_pref("CT3072254.Locale", "en");
user_pref("CT3072254.MCDetectTooltipHeight", "83");
user_pref("CT3072254.MCDetectTooltipShow", false);
user_pref("CT3072254.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
user_pref("CT3072254.MCDetectTooltipWidth", "295");
user_pref("CT3072254.MyStuffEnabledAtInstallation", true);
user_pref("CT3072254.OriginalFirstVersion", "3.10.0.1");
user_pref("CT3072254.SHRINK_TOOLBAR", 1);
user_pref("CT3072254.SearchCaption", "uTorrentControl Customized Web Search");
user_pref("CT3072254.SearchFromAddressBarIsInit", true);
user_pref("CT3072254.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3072254&SearchSource=2&q=");
user_pref("CT3072254.SearchInNewTabEnabled", true);
user_pref("CT3072254.SearchInNewTabIntervalMM", 1440);
user_pref("CT3072254.SearchInNewTabLastCheckTime", "Fri Feb 01 2013 19:30:20 GMT+0100");
user_pref("CT3072254.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
user_pref("CT3072254.SendProtectorDataViaLogin", true);
user_pref("CT3072254.ServiceMapLastCheckTime", "Fri Feb 01 2013 19:30:19 GMT+0100");
user_pref("CT3072254.SettingsLastCheckTime", "Fri Feb 01 2013 19:30:19 GMT+0100");
user_pref("CT3072254.SettingsLastUpdate", "1359727900");
user_pref("CT3072254.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3072254&SearchSource=13");
user_pref("CT3072254.ThirdPartyComponentsInterval", 504);
user_pref("CT3072254.ThirdPartyComponentsLastCheck", "Mon Mar 19 2012 02:52:04 GMT+0100");
user_pref("CT3072254.ThirdPartyComponentsLastUpdate", "1312887586");
user_pref("CT3072254.ToolbarShrinkedFromSetup", false);
user_pref("CT3072254.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3072254");
user_pref("CT3072254.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com
user_pref("CT3072254.UserID", "UN96939253106039895");
user_pref("CT3072254.ValidationData_Toolbar", 0);
user_pref("CT3072254.alertChannelId", "1463703");
user_pref("CT3072254.approveUntrustedApps", false);
user_pref("CT3072254.autoDisableScopes", -1);
user_pref("CT3072254.backendstorage.cbfirsttime", "4D6F6E204D617220313920323031322030323A35323A313020474D542B30313030");
user_pref("CT3072254.components.129572934028070084", false);
user_pref("CT3072254.components.129572934844292843", false);
user_pref("CT3072254.components.129573914344030086", false);
user_pref("CT3072254.components.129586117436877147", false);
user_pref("CT3072254.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlP
user_pref("CT3072254.globalFirstTimeInfoLastCheckTime", "Mon Mar 19 2012 02:52:06 GMT+0100");
user_pref("CT3072254.homepageProtectorEnableByLogin", true);
user_pref("CT3072254.initDone", true);
user_pref("CT3072254.isAppTrackingManagerOn", true);
user_pref("CT3072254.myStuffEnabled", true);
user_pref("CT3072254.myStuffPublihserMinWidth", 400);
user_pref("CT3072254.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
user_pref("CT3072254.myStuffServiceIntervalMM", 1440);
user_pref("CT3072254.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
user_pref("CT3072254.navigateToUrlOnSearch", false);
user_pref("CT3072254.revertSettingsEnabled", true);
user_pref("CT3072254.searchProtectorDialogDelayInSec", 10);
user_pref("CT3072254.searchProtectorEnableByLogin", true);
user_pref("CT3072254.testingCtid", "");
user_pref("CT3072254.toolbarAppMetaDataLastCheckTime", "Fri Feb 01 2013 19:30:21 GMT+0100");
user_pref("CT3072254.toolbarContextMenuLastCheckTime", "Mon Mar 19 2012 02:52:06 GMT+0100");
user_pref("CT3072254.usagesFlag", 2);
user_pref("CT3220468.BT_Stats.enc", "eyJsYXN0X2xvZyI6MTM1OTc0MzU0NiwidXVpZCI6MzE3NzQ0NDM5MjI4MDU2LCJzZXFfaWQiOjUsInNzYiI6MTM1MTU1MDc0Mn0=");
user_pref("CT3220468.CBOpenMAMSettings.enc", "MA==");
user_pref("CT3220468.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3220468.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3220468.FirstTime", "true");
user_pref("CT3220468.FirstTimeFF3", "true");
user_pref("CT3220468.LoginRevertSettingsEnabled", false);
user_pref("CT3220468.RevertSettingsEnabled", true);
user_pref("CT3220468.UserID", "UN65754710505070555");
user_pref("CT3220468.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT3220468.autoDisableScopes", 14);
user_pref("CT3220468.cbcountry_001.enc", "U0U=");
user_pref("CT3220468.cbfirsttime.enc", "TW9uIE9jdCAyOSAyMDEyIDIzOjQ1OjQxIEdNVCswMTAw");
user_pref("CT3220468.defaultSearch", "FALSE");
user_pref("CT3220468.embeddedsData", "[{\"appId\":\"129813684258939747\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"get
user_pref("CT3220468.enableAlerts", "always");
user_pref("CT3220468.enableSearchFromAddressBar", "FALSE");
user_pref("CT3220468.firstTimeDialogOpened", "true");
user_pref("CT3220468.fixPageNotFoundError", "true");
user_pref("CT3220468.fixPageNotFoundErrorInHidden", "true");
user_pref("CT3220468.fixUrls", true);
user_pref("CT3220468.installId", "fft9007.tmp.exe");
user_pref("CT3220468.installType", "XPE");
user_pref("CT3220468.isCheckedStartAsHidden", true);
user_pref("CT3220468.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3220468.isFirstTimeToolbarLoading", "false");
user_pref("CT3220468.isNewTabEnabled", true);
user_pref("CT3220468.isPerformedSmartBarTransition", "true");
user_pref("CT3220468.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT3220468.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3220468.migrateAppsAndComponents", true);
user_pref("CT3220468.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"file%3A%2F%2F%2FC%3A%2FProgram%2520Files%2520(x86)%2FWajam%2FFirefox%2Ffirefox_trigger_extension.htm\",\
user_pref("CT3220468.openThankYouPage", "true");
user_pref("CT3220468.openUninstallPage", "FALSE");
user_pref("CT3220468.search.searchAppId", "129813684258939747");
user_pref("CT3220468.search.searchCount", "0");
user_pref("CT3220468.searchInNewTabEnabledInHidden", "true");
user_pref("CT3220468.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3220468.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3220468.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3220468\"}");
user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://uTorrentControlv2.OurToolbar.com//xpi\"}");
user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentControl_v2\"}");
user_pref("CT3220468.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3220468.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1354476217210");
user_pref("CT3220468.serviceLayer_services_appsMetadata_lastUpdate", "1354476097125");
user_pref("CT3220468.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1354476217003");
user_pref("CT3220468.serviceLayer_services_login_10.10.27.6_lastUpdate", "1354476097307");
user_pref("CT3220468.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1354476217097");
user_pref("CT3220468.serviceLayer_services_searchAPI_lastUpdate", "1354476097373");
user_pref("CT3220468.serviceLayer_services_serviceMap_lastUpdate", "1354476096861");
user_pref("CT3220468.serviceLayer_services_toolbarContextMenu_lastUpdate", "1354476217063");
user_pref("CT3220468.serviceLayer_services_toolbarSettings_lastUpdate", "1354476097141");
user_pref("CT3220468.serviceLayer_services_translation_lastUpdate", "1354476097201");
user_pref("CT3220468.settingsINI", true);
user_pref("CT3220468.shouldFirstTimeDialog", "false");
user_pref("CT3220468.smartbar.CTID", "CT3220468");
user_pref("CT3220468.smartbar.Uninstall", "0");
user_pref("CT3220468.smartbar.toolbarName", "uTorrentControl_v2 ");
user_pref("CT3220468.toolbarBornServerTime", "30-10-2012");
user_pref("CT3220468.toolbarCurrentServerTime", "2-12-2012");
user_pref("CT3220468.upgradeFromClearSBVersion", true);
user_pref("CT3220468.url_history0001", "hxxp://thepiratebay.se/search/Austin%20Powers%20International%20Man%20of%20Mystery/0/7/0:::clickhandler:::1351804049796,,,hxxp://thepir
user_pref("CT3220468_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1359743418047,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}
user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3072254/CT3072254", "\"72ac8b961355b4bc2570788b383115c03\"");
user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1463703/1459357/SE", "\"0\"");
user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3072254", "\"1312917834\"");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "m4Df43NZ+9lr21ZNdyYrjA==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "0uSPYx+Kl2jpu8sJZMeHjw==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "Dclc8oo4TTv7+mAkSlUSWg==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "K4Vqu91uAzWURlxJRdXJOg==");
user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"d229fa25f6c9cc1:0\"");
user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10.0.1", "\"801a319dd78ccc1:0\"");
user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.2.3", "\"4ead38b3e6bcd1:0\"");
user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0e0a4327275cd1:0\"");
user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14.1.0", "\"0343677cfb1cd1:0\"");
user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15.1.0", "\"0343677cfb1cd1:0\"");
user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16.0.3", "\"0343677cfb1cd1:0\"");
user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3072254", "\"0697a2066791d3f9dfa6c976583f2c5c\"");
user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"096904b8436d653b95d45476eee9a383\"");
user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Johanna\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qif8ppgt.default\\conduitCommon\\modules\\3.10.0.1");
user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.10.0.1");
user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://dts.search-results.com/sr?src=ffb&appid=164&systemid=406&sr=0&q=");
user_pref("CommunityToolbar.ToolbarsList", "CT3072254");
user_pref("CommunityToolbar.ToolbarsList2", "CT3072254");
user_pref("CommunityToolbar.ToolbarsList4", "CT3072254");
user_pref("CommunityToolbar.globalUserId", "9181adc9-f9c0-41c9-8691-83f717bbd6a0");
user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3072254");
user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Mon Mar 19 2012 02:52:06 GMT+0100");
user_pref("CommunityToolbar.notifications.alertInfoInterval", 60);
user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Mon Mar 19 2012 02:52:14 GMT+0100");
user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
user_pref("CommunityToolbar.notifications.locale", "en");
user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Mon Mar 19 2012 02:52:06 GMT+0100");
user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
user_pref("CommunityToolbar.notifications.showTrayIcon", false);
user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
user_pref("CommunityToolbar.notifications.userId", "ae7bbdaa-7419-402c-993c-1e2d91ecd77a");
user_pref("CommunityToolbar.originalHomepage", "hxxp://www.searchnu.com/406");
user_pref("CommunityToolbar.originalSearchEngine", "Search");
user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
user_pref("browser.search.selectedEngine", "Delta Search");
user_pref("browser.startup.homepage", "hxxp://www.searchnu.com/406");
user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108298");
user_pref("extensions.BabylonToolbar_i.hardId", "6e7a96be000000000000e0ca9488c749");
user_pref("extensions.BabylonToolbar_i.id", "6e7a96be000000000000e0ca9488c749");
user_pref("extensions.BabylonToolbar_i.instlDay", "15361");
user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
user_pref("extensions.BabylonToolbar_i.newTab", true);
user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.delta-search.com/?affID=119529&babsrc=NT_ss&mntrId=6e7a96be000000000000e0ca9488c749");
user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1718:00:14");
user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
user_pref("extensions.delta.admin", false);
user_pref("extensions.delta.aflt", "babsst");
user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
user_pref("extensions.delta.autoRvrt", "false");
user_pref("extensions.delta.dfltLng", "en");
user_pref("extensions.delta.excTlbr", false);
user_pref("extensions.delta.id", "6e7a96be000000000000e0ca9488c749");
user_pref("extensions.delta.instlDay", "15737");
user_pref("extensions.delta.instlRef", "sst");
user_pref("extensions.delta.lastVrsnTs", "1.8.10.019:24:34");
user_pref("extensions.delta.newTab", false);
user_pref("extensions.delta.prdct", "delta");
user_pref("extensions.delta.prtnrId", "delta");
user_pref("extensions.delta.rvrt", "false");
user_pref("extensions.delta.smplGrp", "none");
user_pref("extensions.delta.tlbrId", "base");
user_pref("extensions.delta.tlbrSrchUrl", "");
user_pref("extensions.delta.vrsn", "1.8.10.0");
user_pref("extensions.delta.vrsnTs", "1.8.10.019:24:34");
user_pref("extensions.delta.vrsni", "1.8.10.0");
user_pref("extensions.funmoods.SimilarSitesStorage-pid2", "9f329b90e1e41bcc");
user_pref("extensions.funmoods.admin", false);
user_pref("extensions.funmoods.aflt", "ironto");
user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
user_pref("extensions.funmoods.cntry", "SE");
user_pref("extensions.funmoods.cv", "cv5");
user_pref("extensions.funmoods.dfltLng", "EN");
user_pref("extensions.funmoods.dfltSrch", true);
user_pref("extensions.funmoods.dfltlng", "EN");
user_pref("extensions.funmoods.dfltsrch", true);
user_pref("extensions.funmoods.excTlbr", false);
user_pref("extensions.funmoods.hdrMd5", "55E81B957D62326AFD47F841BE38BE25");
user_pref("extensions.funmoods.hmpg", true);
user_pref("extensions.funmoods.hrdid", "6e7a96be000000000000e0ca9488c749");
user_pref("extensions.funmoods.id", "6e7a96be000000000000e0ca9488c749");
user_pref("extensions.funmoods.instlDay", "15375");
user_pref("extensions.funmoods.instlRef", "");
user_pref("extensions.funmoods.instlday", "15375");
user_pref("extensions.funmoods.instlref", "");
user_pref("extensions.funmoods.isDcmntCmplt", false);
user_pref("extensions.funmoods.keywordurl", "");
user_pref("extensions.funmoods.lastVrsnTs", "1.5.11.1621:30:56");
user_pref("extensions.funmoods.logicsMngrDailyReportTime", "03-07-2012");
user_pref("extensions.funmoods.newTab", true);
user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ironto");
user_pref("extensions.funmoods.newtab", true);
user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a=ironto");
user_pref("extensions.funmoods.noFFXTlbr", false);
user_pref("extensions.funmoods.prdct", "funmoods");
user_pref("extensions.funmoods.propectorlck", 69887226);
user_pref("extensions.funmoods.prtnrId", "funmoods");
user_pref("extensions.funmoods.prtnrid", "funmoods");
user_pref("extensions.funmoods.sg", "none");
user_pref("extensions.funmoods.smplGrp", "none");
user_pref("extensions.funmoods.smplgrp", "none");
user_pref("extensions.funmoods.srch", "");
user_pref("extensions.funmoods.srchPrvdr", "Search");
user_pref("extensions.funmoods.srchprvdr", "Search");
user_pref("extensions.funmoods.tlbrId", "base");
user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ironto&q=");
user_pref("extensions.funmoods.tlbrid", "base");
user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://start.funmoods.com/results.php?f=3&a=ironto&q=");
user_pref("extensions.funmoods.vrsn", "1.5.11.16");
user_pref("extensions.funmoods.vrsnTs", "1.5.11.1621:30:56");
user_pref("extensions.funmoods.vrsni", "1.5.11.16");
user_pref("extensions.funmoods.vrsnts", "1.5.11.1621:30:56");
user_pref("extensions.funmoods_i.aflt", "ironto");
user_pref("extensions.funmoods_i.dfltLng", "");
user_pref("extensions.funmoods_i.dfltSrch", true);
user_pref("extensions.funmoods_i.dnsErr", true);
user_pref("extensions.funmoods_i.excTlbr", false);
user_pref("extensions.funmoods_i.hmpg", true);
user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=ironto");
user_pref("extensions.funmoods_i.id", "6e7a96be000000000000e0ca9488c749");
user_pref("extensions.funmoods_i.instlDay", "15375");
user_pref("extensions.funmoods_i.instlRef", "");
user_pref("extensions.funmoods_i.newTab", true);
user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=ironto");
user_pref("extensions.funmoods_i.prdct", "funmoods");
user_pref("extensions.funmoods_i.prtnrId", "funmoods");
user_pref("extensions.funmoods_i.smplGrp", "none");
user_pref("extensions.funmoods_i.srchPrvdr", "Search");
user_pref("extensions.funmoods_i.tlbrId", "base");
user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=ironto&q=");
user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1621:30:56");
user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
user_pref("extensions.helperbar.SmartbarDisabled", false);
user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
user_pref("extensions.incredibar_i.aflt", "orgnl");
user_pref("extensions.incredibar_i.dfltLng", "");
user_pref("extensions.incredibar_i.did", "10595");
user_pref("extensions.incredibar_i.excTlbr", false);
user_pref("extensions.incredibar_i.id", "6e7a96be000000000000e0ca9488c749");
user_pref("extensions.incredibar_i.installerproductid", "26");
user_pref("extensions.incredibar_i.instlDay", "15418");
user_pref("extensions.incredibar_i.instlRef", "");
user_pref("extensions.incredibar_i.ms_url_id", "");
user_pref("extensions.incredibar_i.newTab", false);
user_pref("extensions.incredibar_i.ppd", "");
user_pref("extensions.incredibar_i.prdct", "incredibar");
user_pref("extensions.incredibar_i.productid", "26");
user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
user_pref("extensions.incredibar_i.smplGrp", "none");
user_pref("extensions.incredibar_i.tlbrId", "base");
user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8nhURDP1&loc=IB_TB&i=26&search=");
user_pref("extensions.incredibar_i.upn2", "6R8nhURDP1");
user_pref("extensions.incredibar_i.upn2n", "92824040610366319");
user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1411:36:23");
user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");
user_pref("extentions.y2layers.defaultEnableAppsList", "DropDownDeals,BestVideoDownloader,EzLooker,TwitTube,TopRelatedTopics,Buzzdock,");
user_pref("extentions.y2layers.installId", "bb7c7136-fca3-4fdb-b058-de32a294e844");
user_pref("extentions.y2layers.lastDnsTest", 372068);
Emptied folder: C:\Users\Johanna\AppData\Roaming\mozilla\firefox\profiles\qif8ppgt.default\minidumps [13 files]
 
 
 
~~~ Chrome
 
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\clbfjfbnelcflpgpklppgplejolacbej
Successfully deleted: [Registry Key] hkey_current_user\software\google\chrome\extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\niapdbllcanepiiimjjndipklodoedlc
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2013-02-09 at 20:46:13,91
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Rkill 2.4.6 by Lawrence Abrams (Grinler)
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 02/09/2013 08:48:49 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * No malware processes found to kill.
 
Checking Registry for malware related settings:
 
 * Explorer Policy Removed:  NoActiveDesktopChanges [HKLM]
 
Backup Registry file created at:
 C:\Users\Johanna\Desktop\rkill\rkill-02-09-2013-08-48-54.reg
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * No issues found.
 
Checking Windows Service Integrity: 
 
 * No issues found.
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * HOSTS file entries found: 
 
  255.255.255.255    easyanticheat.se    # misleading site
  255.255.255.255    www.easyanticheat.se    # misleading site
  255.255.255.255    easyanticheat.com    # misleading site
  255.255.255.255    www.easyanticheat.com    # misleading site
  255.255.255.255    easyanticheat.info    # misleading site
  255.255.255.255    www.easyanticheat.info    # misleading site
  255.255.255.255    easyanticheat.org    # misleading site
  255.255.255.255    www.easyanticheat.org    # misleading site
 
Program finished at: 02/09/2013 08:49:03 PM
Execution time: 0 hours(s), 0 minute(s), and 14 seconds(s)


"HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms"    ""    ""    ""
+ "rdpclip"    ""    ""    "File not found: rdpclip"
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"    ""    ""    ""
+ "SmartAudio"    "SmartAudio Control Panel application"    "Conexant systems, Inc."    "c:\program files\conexant\saii\saiicpl.exe"
+ "SynTPEnh"    "Synaptics TouchPad Enhancements"    "Synaptics Incorporated"    "c:\program files\synaptics\syntp\syntpenh.exe"
+ "TCrdMain"    "TOSHIBA Flash Cards Main Module"    "TOSHIBA Corporation"    "c:\program files\toshiba\flashcards\tcrdmain.exe"
+ "Teco"    "TOSHIBA eco Utility"    "TOSHIBA Corporation"    "c:\program files\toshiba\teco\teco.exe"
+ "Toshiba Registration"    "Toshiba Notebook Registration Reminder"    "Toshiba Europe GmbH"    "c:\program files\toshiba\registration\toshibareminder.exe"
+ "Toshiba TEMPRO"    "Toshiba TEMPRO"    "Toshiba Europe GmbH"    "c:\program files (x86)\toshiba tempro\temprotray.exe"
+ "TosNC"    "Message Center"    "TOSHIBA Corporation"    "c:\program files\toshiba\bulletinboard\tosnccore.exe"
+ "TosReelTimeMonitor"    "Monitor of TOSHIBA ReelTime"    "TOSHIBA Corporation"    "c:\program files\toshiba\reeltime\tosreeltimemonitor.exe"
+ "TosSENotify"    ""    "TOSHIBA Corporation"    "c:\program files\toshiba\toshiba hdd ssd alert\toswaitsrv.exe"
+ "TosVolRegulator"    " Toshiba Volume Regulator"    "TOSHIBA Corporation"    "c:\program files\toshiba\tosvolregulator\tosvolregulator.exe"
+ "TosWaitSrv"    ""    "TOSHIBA Corporation"    "c:\program files\toshiba\tphm\toswaitsrv.exe"
+ "TPwrMain"    "TOSHIBA Power Saver"    "TOSHIBA Corporation"    "c:\program files\toshiba\power saver\tpwrmain.exe"
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run"    ""    ""    ""
+ "AdobeCS5ServiceManager"    "Adobe CS5 Service Manager"    "Adobe Systems Incorporated"    "c:\program files (x86)\common files\adobe\cs5servicemanager\cs5servicemanager.exe"
+ "APSDaemon"    "Apple Push"    "Apple Inc."    "c:\program files (x86)\common files\apple\apple application support\apsdaemon.exe"
+ "avast"    "avast! Antivirus"    "AVAST Software"    "c:\program files\avast software\avast\avastui.exe"
+ "ITSecMng"    "IT Security Manager for Toshiba Stack"    "TOSHIBA CORPORATION"    "c:\program files (x86)\toshiba\bluetooth toshiba stack\itsecmng.exe"
+ "Logitech G35"    "Logitech© G35 Headset"    "Logitech©"    "d:\headset\g35.exe"
+ "SwitchBoard"    "SwitchBoard Server (32 bit)"    "Adobe Systems Incorporated"    "c:\program files (x86)\common files\adobe\switchboard\switchboard.exe"
+ "ToshibaServiceStation"    "TOSHIBA Service Station"    "TOSHIBA Corporation"    "c:\program files (x86)\toshiba\toshiba service station\toshibaservicestation.exe"
+ "TSleepSrv"    "TOSHIBA Sleep Service"    "TOSHIBA"    "c:\program files (x86)\toshiba\toshiba sleep utility\tsleepsrv.exe"
+ "vProt"    "VProtect Application"    ""    "c:\program files (x86)\avg secure search\vprot.exe"
+ "YouCam Service"    "CyberLink YouCam Service"    "CyberLink Corp."    "f:\youcam\youcamservice.exe"
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup"    ""    ""    ""
+ "Bluetooth Manager.lnk"    "Bluetooth Manager"    "TOSHIBA CORPORATION."    "c:\program files (x86)\toshiba\bluetooth toshiba stack\tosbtmng.exe"
+ "Toshiba Places Icon Utility.lnk"    "Toshiba Places Icon Utility"    "Toshiba"    "c:\program files\toshiba\toshiba places icon utility\tosdimonitor.exe"
"C:\Users\Johanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup"    ""    ""    ""
+ "Logitech blank Produktregistrering.lnk"    "Product Registration"    "Leader Technologies/Logitech"    "d:\headset\ereg.exe"
+ "TRDCReminder.lnk"    "TOSHIBA Recovery Reminder"    "TOSHIBA Europe"    "c:\program files (x86)\toshiba\trdcreminder\trdcreminder.exe"
"HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components"    ""    ""    ""
+ "Microsoft Windows"    "Windows Mail"    "Microsoft Corporation"    "c:\program files\windows mail\winmail.exe"
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components"    ""    ""    ""
+ "Google Chrome"    "Google Chrome"    "Google Inc."    "c:\program files (x86)\google\chrome\application\24.0.1312.57\installer\chrmstp.exe"
+ "Microsoft Windows"    "Windows Mail"    "Microsoft Corporation"    "c:\program files (x86)\windows mail\winmail.exe"
"HKCU\Software\Microsoft\Windows\CurrentVersion\Run"    ""    ""    ""
+ "Clownfish"    "Clownfish for Skype"    "Bogdan Sharkov"    "c:\program files (x86)\clownfish\clownfish.exe"
+ "DAEMON Tools Pro Agent"    "DAEMON Tools Pro Agent"    "DT Soft Ltd"    "c:\program files (x86)\daemon tools pro\dtagent.exe"
+ "Facebook Update"    "Facebook Installer"    "Facebook Inc."    "c:\users\johanna\appdata\local\facebook\update\facebookupdate.exe"
+ "Google Update"    "Google Installer"    "Google Inc."    "c:\users\johanna\appdata\local\google\update\googleupdate.exe"
+ "msnmsgr"    "Windows Live Messenger"    "Microsoft Corporation"    "c:\program files (x86)\windows live\messenger\msnmsgr.exe"
+ "Skype"    "Skype "    "Skype Technologies S.A."    "c:\program files (x86)\skype\phone\skype.exe"
+ "Spotify Web Helper"    "SpotifyWebHelper"    "Spotify Ltd"    "c:\users\johanna\appdata\roaming\spotify\data\spotifywebhelper.exe"
+ "Steam"    "Steam"    "Valve Corporation"    "d:\steam\steam.exe"
+ "TOPI.EXE"    "TOSHIBA Online Product Information"    "TOSHIBA"    "c:\program files (x86)\toshiba\toshiba online product information\topi.exe"
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "avast"    "avast! Shell Extension"    "AVAST Software"    "c:\program files\avast software\avast\ashsha64.dll"
+ "DaemonShellExtImage"    "DAEMON Tools Pro"    "DT Soft Ltd"    "c:\program files (x86)\daemon tools pro\dtshl64.dll"
+ "tosBtShllExt"    "TosBtShell"    "TOSHIBA"    "c:\program files (x86)\toshiba\bluetooth toshiba stack\sys\x64\tosbtshell.dll"
+ "WinRAR"    ""    ""    "c:\program files (x86)\winrar\rarext64.dll"
"HKLM\Software\Wow6432Node\Classes\*\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "avast"    "avast! Shell Extension"    "AVAST Software"    "c:\program files\avast software\avast\ashshell.dll"
+ "DaemonShellExtImage"    "DAEMON Tools Pro"    "DT Soft Ltd"    "c:\program files (x86)\daemon tools pro\dtshl32.dll"
+ "NBShellHook Class"    "Nero BackItUp"    "Nero AG"    "c:\program files (x86)\nero\nero 10\nero backitup\nbshell.dll"
+ "NeroShellExt Class"    "Nero Burning ROM Shell Extension"    "Nero AG"    "c:\program files (x86)\common files\nero\neroshellext\neroshellext.dll"
+ "WinRAR32"    ""    ""    "c:\program files (x86)\winrar\rarext.dll"
"HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "00avast"    "avast! Shell Extension"    "AVAST Software"    "c:\program files\avast software\avast\ashsha64.dll"
+ "MBAMShlExt"    "Malwarebytes Anti-Malware"    "Malwarebytes Corporation"    "c:\program files (x86)\malwarebytes' anti-malware\mbamext.dll"
"HKLM\Software\Wow6432Node\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "00avast"    "avast! Shell Extension"    "AVAST Software"    "c:\program files\avast software\avast\ashshell.dll"
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "tosBtShllExt"    "TosBtShell"    "TOSHIBA"    "c:\program files (x86)\toshiba\bluetooth toshiba stack\sys\x64\tosbtshell.dll"
+ "WinRAR"    ""    ""    "c:\program files (x86)\winrar\rarext64.dll"
"HKLM\Software\Wow6432Node\Classes\Directory\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "NeroShellExt Class"    "Nero Burning ROM Shell Extension"    "Nero AG"    "c:\program files (x86)\common files\nero\neroshellext\neroshellext.dll"
+ "WinRAR32"    ""    ""    "c:\program files (x86)\winrar\rarext.dll"
"HKLM\Software\Classes\Directory\Shellex\DragDropHandlers"    ""    ""    ""
+ "WinRAR"    ""    ""    "c:\program files (x86)\winrar\rarext64.dll"
"HKLM\Software\Wow6432Node\Classes\Directory\Shellex\DragDropHandlers"    ""    ""    ""
+ "WinRAR32"    ""    ""    "c:\program files (x86)\winrar\rarext.dll"
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "Gadgets"    "Släppmål för Sidpanelen"    "Microsoft Corporation"    "c:\program files\windows sidebar\sbdrop.dll"
+ "NvCplDesktopContext"    ""    "NVIDIA Corporation"    "c:\windows\system32\nvshext.dll"
"HKLM\Software\Wow6432Node\Classes\Directory\Background\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "Gadgets"    "Släppmål för Sidpanelen"    "Microsoft Corporation"    "c:\program files (x86)\windows sidebar\sbdrop.dll"
"HKLM\Software\Wow6432Node\Classes\Folder\Shellex\ColumnHandlers"    ""    ""    ""
+ "PDF Shell Extension"    "PDF Shell Extension"    "Adobe Systems, Inc."    "c:\program files (x86)\common files\adobe\acrobat\activex\pdfshell.dll"
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "avast"    "avast! Shell Extension"    "AVAST Software"    "c:\program files\avast software\avast\ashsha64.dll"
+ "MBAMShlExt"    "Malwarebytes Anti-Malware"    "Malwarebytes Corporation"    "c:\program files (x86)\malwarebytes' anti-malware\mbamext.dll"
+ "WinRAR"    ""    ""    "c:\program files (x86)\winrar\rarext64.dll"
"HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\ContextMenuHandlers"    ""    ""    ""
+ "avast"    "avast! Shell Extension"    "AVAST Software"    "c:\program files\avast software\avast\ashshell.dll"
+ "NBShellHook Class"    "Nero BackItUp"    "Nero AG"    "c:\program files (x86)\nero\nero 10\nero backitup\nbshell.dll"
+ "WinRAR32"    ""    ""    "c:\program files (x86)\winrar\rarext.dll"
"HKCU\Software\Classes\Folder\ShellEx\DragDropHandlers"    ""    ""    ""
+ "tosBtExt"    "TosBtExt"    "TOSHIBA"    "c:\program files (x86)\toshiba\bluetooth toshiba stack\sys\x64\tosbtext.dll"
"HKLM\Software\Classes\Folder\ShellEx\DragDropHandlers"    ""    ""    ""
+ "WinRAR"    ""    ""    "c:\program files (x86)\winrar\rarext64.dll"
"HKLM\Software\Wow6432Node\Classes\Folder\ShellEx\DragDropHandlers"    ""    ""    ""
+ "NBShellHook"    "Nero BackItUp"    "Nero AG"    "c:\program files (x86)\nero\nero 10\nero backitup\nbshell.dll"
+ "WinRAR32"    ""    ""    "c:\program files (x86)\winrar\rarext.dll"
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers"    ""    ""    ""
+ "00avast"    "avast! Shell Extension"    "AVAST Software"    "c:\program files\avast software\avast\ashsha64.dll"
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects"    ""    ""    ""
+ "avast! WebRep"    "avast! WebRep Plugin"    "AVAST Software"    "c:\program files\avast software\avast\aswwebrepie64.dll"
+ "DataMngr"    ""    ""    "File not found: C:\PROGRA~2\SEARCH~1\Datamngr\x64\BROWSE~1.DLL"
+ "Java™ Plug-In 2 SSV Helper"    "Java™ Platform SE binary"    "Sun Microsystems, Inc."    "c:\program files\java\jre6\bin\jp2ssv.dll"
+ "Java™ Plug-In SSV Helper"    "Java™ Platform SE binary"    "Sun Microsystems, Inc."    "c:\program files\java\jre6\bin\ssv.dll"
+ "Windows Live ID Sign-in Helper"    "Microsoft® Windows Live ID Login Helper"    "Microsoft Corp."    "c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll"
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects"    ""    ""    ""
+ "Adobe PDF Link Helper"    "Adobe PDF Helper for Internet Explorer"    "Adobe Systems Incorporated"    "c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll"
+ "avast! WebRep"    "avast! WebRep Plugin"    "AVAST Software"    "c:\program files\avast software\avast\aswwebrepie.dll"
+ "Java™ Plug-In 2 SSV Helper"    "Java™ Platform SE binary"    "Oracle Corporation"    "c:\program files (x86)\java\jre7\bin\jp2ssv.dll"
+ "Java™ Plug-In SSV Helper"    "Java™ Platform SE binary"    "Oracle Corporation"    "c:\program files (x86)\java\jre7\bin\ssv.dll"
+ "Skype Browser Helper"    "Skype Click to Call for Internet Explorer"    "Skype Technologies S.A."    "c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll"
+ "Windows Live ID Sign-in Helper"    "Microsoft® Windows Live ID Login Helper"    "Microsoft Corp."    "c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll"
+ "Windows Live Messenger Companion Helper"    "Windows Live Messenger Companion Core"    "Microsoft Corporation"    "c:\program files (x86)\windows live\companion\companioncore.dll"
"HKLM\Software\Microsoft\Internet Explorer\Toolbar"    ""    ""    ""
+ "avast! WebRep"    "avast! WebRep Plugin"    "AVAST Software"    "c:\program files\avast software\avast\aswwebrepie64.dll"
"HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar"    ""    ""    ""
+ "avast! WebRep"    "avast! WebRep Plugin"    "AVAST Software"    "c:\program files\avast software\avast\aswwebrepie.dll"
"HKLM\Software\Microsoft\Internet Explorer\Extensions"    ""    ""    ""
+ "Lägg till på TOSHIBA Bulletin Board"    "TODO: <ファイルの説明>"    "TODO: <会社名>"    "c:\program files\toshiba\bulletinboard\tosbbcom64.dll"
"HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions"    ""    ""    ""
+ "&Blogga om detta i Windows Live Writer"    "Windows Live Writer Blog This Extension"    "Microsoft Corporation"    "c:\program files (x86)\windows live\writer\writerbrowserextension.dll"
+ "Lägg till på TOSHIBA Bulletin Board"    "TODO: <ファイルの説明>"    "TODO: <会社名>"    "c:\program files\toshiba\bulletinboard\tosbbcom.dll"
+ "Messenger Companion (Ctrl+Skift+C)"    "Windows Live Messenger Companion Core"    "Microsoft Corporation"    "c:\program files (x86)\windows live\companion\companioncore.dll"
+ "Skype Click to Call"    "Skype Click to Call for Internet Explorer"    "Skype Technologies S.A."    "c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll"
"Task Scheduler"    ""    ""    ""
+ "\Adobe Flash Player Updater"    "Adobe® Flash® Player Update Service 11.5 r502"    "Adobe Systems Incorporated"    "c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe"
+ "\Adobe online update program"    "Adobe Reader and Acrobat Manager"    "Adobe Systems Incorporated"    "c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe"
+ "\Apple\AppleSoftwareUpdate"    "Apple Software Update"    "Apple Inc."    "c:\program files (x86)\apple software update\softwareupdate.exe"
+ "\avast! Emergency Update"    "avast! Emergency Update"    "AVAST Software"    "c:\program files\avast software\avast\avastemupdate.exe"
+ "\ConfigFree Startup Programs"    "ConfigFree Task Tray Menu"    "TOSHIBA CORPORATION"    "c:\program files (x86)\toshiba\configfree\ndstray.exe"
+ "\Express Files Updater"    ""    ""    "File not found: C:\Program Files (x86)\ExpressFiles\EFupdater.exe"
+ "\FacebookUpdateTaskUserS-1-5-21-1025632964-579490387-1692577899-1000Core"    "Facebook Installer"    "Facebook Inc."    "c:\users\johanna\appdata\local\facebook\update\facebookupdate.exe"
+ "\FacebookUpdateTaskUserS-1-5-21-1025632964-579490387-1692577899-1000UA"    "Facebook Installer"    "Facebook Inc."    "c:\users\johanna\appdata\local\facebook\update\facebookupdate.exe"
+ "\GoogleUpdateTaskMachineCore"    "Google Installer"    "Google Inc."    "c:\program files (x86)\google\update\googleupdate.exe"
+ "\GoogleUpdateTaskMachineUA"    "Google Installer"    "Google Inc."    "c:\program files (x86)\google\update\googleupdate.exe"
+ "\GoogleUpdateTaskUserS-1-5-21-1025632964-579490387-1692577899-1000Core"    "Google Installer"    "Google Inc."    "c:\users\johanna\appdata\local\google\update\googleupdate.exe"
+ "\GoogleUpdateTaskUserS-1-5-21-1025632964-579490387-1692577899-1000UA"    "Google Installer"    "Google Inc."    "c:\users\johanna\appdata\local\google\update\googleupdate.exe"
+ "\Java Update Scheduler"    "Java™ Update Scheduler"    "Sun Microsystems, Inc."    "c:\program files (x86)\common files\java\java update\jusched.exe"
+ "\Microsoft\Windows Defender\MP Scheduled Scan"    "Microsoft Malware Protection Command Line Utility"    "Microsoft Corporation"    "c:\program files\windows defender\mpcmdrun.exe"
+ "\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task"    "Windows Live Social Object Extractor Engine"    "Microsoft Corporation"    "c:\program files (x86)\windows live\soxe\wlsoxe.dll"
+ "\Microsoft\Windows\NetTrace\GatherNetworkInfo"    ""    ""    "c:\windows\system32\gathernetworkinfo.vbs"
+ "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary"    "Konfigurationsprogram för nätverksdelning i Windows Media Player"    "Microsoft Corporation"    "c:\program files\windows media player\wmpnscfg.exe"
"HKLM\System\CurrentControlSet\Services"    ""    ""    ""
+ "avast! Antivirus"    "Hanterar och implementerar avast! antivirustjänsten på denna dator. Detta inkluderar realtidsskydd, viruskarantänen och schemaläggaren."    "AVAST Software"    "c:\program files\avast software\avast\avastsvc.exe"
+ "Bonjour Service"    "Gör det möjligt för hårdvaruenheter och programvarutjänster att automatiskt konfigurera sig själva på nätverket och annonsera sin närvaro."    "Apple Inc."    "c:\program files\bonjour\mdnsresponder.exe"
+ "cfWiMAXService"    "This is WiMAX Control Service of ConfigFree. Please do not stop this servce when you are using ConfigFree with Intel WiMAX device."    "TOSHIBA CORPORATION"    "c:\program files (x86)\toshiba\configfree\cfiwmxsvcs64.exe"
+ "ConfigFree Service"    "You can't stop this service, if you want to keep ConfigFree functionality fine."    "TOSHIBA CORPORATION"    "c:\program files (x86)\toshiba\configfree\cfsvcs.exe"
+ "cvhsvc"    "Client Virtualization Handler Service (unlocalized description)"    "Microsoft Corporation"    "c:\program files (x86)\common files\microsoft shared\virtualization handler\cvhsvc.exe"
+ "fsssvc"    "This service enables Family Safety on the computer. If this service is not running, Family Safety will not work."    "Microsoft Corporation"    "c:\program files (x86)\windows live\family safety\fsssvc.exe"
+ "gupdate"    "Ser till att programvaran från Google är uppdaterad. Om tjänsten inaktiveras eller stoppas uppdateras inte programvaran från Google. Det betyder att vissa funktioner kanske inte fungerar och att eventuella säkerhetsrisker inte kan åtgärdas. Tjänsten avinstalleras automatiskt om den inte används av någon programvara från Google."    "Google Inc."    "c:\program files (x86)\google\update\googleupdate.exe"
+ "gupdatem"    "Ser till att programvaran från Google är uppdaterad. Om tjänsten inaktiveras eller stoppas uppdateras inte programvaran från Google. Det betyder att vissa funktioner kanske inte fungerar och att eventuella säkerhetsrisker inte kan åtgärdas. Tjänsten avinstalleras automatiskt om den inte används av någon programvara från Google."    "Google Inc."    "c:\program files (x86)\google\update\googleupdate.exe"
+ "IDriverT"    "Provides support for the Running Object Table for InstallShield Drivers"    "Macrovision Corporation"    "c:\program files (x86)\common files\installshield\driver\1150\intel 32\idrivert.exe"
+ "iPod Service"    "iPod hardware management services"    "Apple Inc."    "c:\program files\ipod\bin\ipodservice.exe"
+ "LMS"    "Allows applications to access the local Intel® Management and Security Application using its locally-available selected network interfaces."    "Intel Corporation"    "c:\program files (x86)\intel\intel® management engine components\lms\lms.exe"
+ "NVSvc"    "Provides system and desktop level support to the NVIDIA display driver"    "NVIDIA Corporation"    "c:\windows\system32\nvvsvc.exe"
+ "nvUpdatusService"    "NVIDIA Settings Update Manager service, used to check new updates from NVIDIA server."    "NVIDIA Corporation"    "c:\program files (x86)\nvidia corporation\nvidia updatus\daemonu.exe"
+ "ose"    "Sparar installationsfiler som används för uppdateringar och reparationer och krävs för att hämta installationsuppdateringar och Watson-felrapporter."    "Microsoft Corporation"    "c:\program files (x86)\common files\microsoft shared\source engine\ose.exe"
+ "osppsvc"    "Office Software Protection Platform Service (unlocalized description)"    "Microsoft Corporation"    "c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe"
+ "PnkBstrA"    "PunkBuster Service Component [v1036] http://www.evenbalance.com"    ""    "c:\windows\syswow64\pnkbstra.exe"
+ "sftlist"    "Streams and manages applications."    "Microsoft Corporation"    "c:\program files (x86)\microsoft application virtualization client\sftlist.exe"
+ "sftvsa"    "Monitors global service events and launches virtual services."    "Microsoft Corporation"    "c:\program files (x86)\microsoft application virtualization client\sftvsa.exe"
+ "SkypeUpdate"    "Enables the detection, download and installation of updates for Skype."    "Skype Technologies"    "c:\program files (x86)\skype\updater\updater.exe"
+ "Steam Client Service"    "Steam Client Service monitors and updates Steam content"    "Valve Corporation"    "c:\program files (x86)\common files\steam\steamservice.exe"
+ "Stereo Service"    "Provides system support for NVIDIA Stereoscopic 3D driver"    "NVIDIA Corporation"    "c:\program files (x86)\nvidia corporation\3d vision\nvscpapisvr.exe"
+ "SwitchBoard"    "SwitchBoard Server (32 bit)"    "Adobe Systems Incorporated"    "c:\program files (x86)\common files\adobe\switchboard\switchboard.exe"
+ "TeamViewer7"    "TeamViewer Remote Software"    "TeamViewer GmbH"    "c:\program files (x86)\teamviewer\version7\teamviewer_service.exe"
+ "TemproMonitoringService"    "Toshiba Notebook Performance Tuning Service"    "Toshiba Europe GmbH"    "c:\program files (x86)\toshiba tempro\temprosvc.exe"
+ "TMachInfo"    "TOSHIBA Machine Information Service"    "TOSHIBA Corporation"    "c:\program files (x86)\toshiba\toshiba service station\tmachinfo.exe"
+ "TODDSrv"    "TDCSrv Application"    "TOSHIBA Corporation"    "c:\windows\system32\toddsrv.exe"
+ "TosCoSrv"    "Toshiba Power Saver används för energisparinställningar som stöds av Toshiba. Inställningarna fungerar inte om tjänsten stoppas."    "TOSHIBA Corporation"    "c:\program files\toshiba\power saver\toscosrv.exe"
+ "TOSHIBA Bluetooth Service"    "TOSHIBA Bluetooth Service"    "TOSHIBA CORPORATION"    "c:\program files (x86)\toshiba\bluetooth toshiba stack\tosbtsrv.exe"
+ "TOSHIBA eco Utility Service"    "TOSHIBA eco Utility Service"    "TOSHIBA Corporation"    "c:\program files\toshiba\teco\tecoservice.exe"
+ "TOSHIBA HDD SSD Alert Service"    "TOSHIBA HDD SSD Alert"    "TOSHIBA Corporation"    "c:\program files\toshiba\toshiba hdd ssd alert\tossmartsrv.exe"
+ "TPCHSrv"    "TOSHIBA PC Health Monitor"    "TOSHIBA Corporation"    "c:\program files\toshiba\tphm\tpchsrv.exe"
+ "UNS"    "Intel® Management and Security Application User Notification Service - Updates the Windows Event Log with notifications of pre defined events received from the local Intel® Management and Security Application Device."    "Intel Corporation"    "c:\program files (x86)\intel\intel® management engine components\uns\uns.exe"
+ "WinDefend"    "Skydd mot spionprogram och oönskad programvara"    "Microsoft Corporation"    "c:\program files\windows defender\mpsvc.dll"
+ "wlidsvc"    "Enables Windows Live ID authentication."    "Microsoft Corp."    "c:\program files\common files\microsoft shared\windows live\wlidsvc.exe"
+ "WMPNetworkSvc"    "Delar Windows Media Player-bibliotek med andra spelare och enheter i nätverket som använder Universal Plug and Play"    "Microsoft Corporation"    "c:\program files\windows media player\wmpnetwk.exe"
"HKLM\System\CurrentControlSet\Services"    ""    ""    ""
+ "adp94xx"    "Adaptec Windows SAS/SATA Storport Driver"    "Adaptec, Inc."    "c:\windows\system32\drivers\adp94xx.sys"
+ "adpahci"    "Adaptec Windows SATA Storport Driver"    "Adaptec, Inc."    "c:\windows\system32\drivers\adpahci.sys"
+ "adpu320"    "Adaptec StorPort Ultra320 SCSI Driver (X64)"    "Adaptec, Inc."    "c:\windows\system32\drivers\adpu320.sys"
+ "aliide"    "ALi mini IDE Driver"    "Acer Laboratories Inc."    "c:\windows\system32\drivers\aliide.sys"
+ "amdsata"    "AHCI 1.2 Device Driver"    "Advanced Micro Devices"    "c:\windows\system32\drivers\amdsata.sys"
+ "amdsbs"    "AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform"    "AMD Technologies Inc."    "c:\windows\system32\drivers\amdsbs.sys"
+ "amdxata"    "Storage Filter Driver"    "Advanced Micro Devices"    "c:\windows\system32\drivers\amdxata.sys"
+ "androidusb"    "ADB Interface"    "Google Inc"    "c:\windows\system32\drivers\ssadadb.sys"
+ "arc"    "Adaptec RAID Storport Driver"    "Adaptec, Inc."    "c:\windows\system32\drivers\arc.sys"
+ "arcsas"    "Adaptec SAS RAID WS03 Driver"    "Adaptec, Inc."    "c:\windows\system32\drivers\arcsas.sys"
+ "aswFsBlk"    "avast! mini-filter driver (aswFsBlk)"    "AVAST Software"    "c:\windows\system32\drivers\aswfsblk.sys"
+ "aswMonFlt"    "avast! mini-filter driver (aswMonFlt)"    "AVAST Software"    "c:\windows\system32\drivers\aswmonflt.sys"
+ "aswRdr"    "avast! WFP Redirect driver"    "AVAST Software"    "c:\windows\system32\drivers\aswrdr2.sys"
+ "aswSnx"    "avast! virtualization driver (aswSnx)"    "AVAST Software"    "c:\windows\system32\drivers\aswsnx.sys"
+ "aswSP"    "avast! Self Protection"    "AVAST Software"    "c:\windows\system32\drivers\aswsp.sys"
+ "aswTdi"    "avast! Network Shield TDI driver"    "AVAST Software"    "c:\windows\system32\drivers\aswtdi.sys"
+ "athr"    "Atheros Extensible Wireless LAN device driver"    "Atheros Communications, Inc."    "c:\windows\system32\drivers\athrx.sys"
+ "avgtp"    ""    "AVG Technologies"    "c:\windows\system32\drivers\avgtpx64.sys"
+ "b06bdrv"    "Broadcom NetXtreme II GigE VBD"    "Broadcom Corporation"    "c:\windows\system32\drivers\bxvbda.sys"
+ "b57nd60a"    "Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver."    "Broadcom Corporation"    "c:\windows\system32\drivers\b57nd60a.sys"
+ "BrFiltLo"    "Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver"    "Brother Industries, Ltd."    "c:\windows\system32\drivers\brfiltlo.sys"
+ "BrFiltUp"    "Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver"    "Brother Industries, Ltd."    "c:\windows\system32\drivers\brfiltup.sys"
+ "Brserid"    "Brother Serial I/F Driver (WDM)"    "Brother Industries Ltd."    "c:\windows\system32\drivers\brserid.sys"
+ "BrSerWdm"    "Brother Serial driver (WDM version)"    "Brother Industries Ltd."    "c:\windows\system32\drivers\brserwdm.sys"
+ "BrUsbMdm"    "Brother USB MDM Driver "    "Brother Industries Ltd."    "c:\windows\system32\drivers\brusbmdm.sys"
+ "BrUsbSer"    "Brother USB Serial Driver"    "Brother Industries Ltd."    "c:\windows\system32\drivers\brusbser.sys"
+ "BtFilter"    "Filter Driver for the Bluetooth"    "Atheros"    "c:\windows\system32\drivers\btfilter.sys"
+ "clwvd"    "CyberLink WebCam Virtual Driver"    "CyberLink Corporation"    "c:\windows\system32\drivers\clwvd.sys"
+ "cmdide"    "CMD PCI IDE Bus Driver"    "CMD Technology, Inc."    "c:\windows\system32\drivers\cmdide.sys"
+ "CnxtHdAudService"    "64-bit High Definition Audio Function Driver"    "Conexant Systems Inc."    "c:\windows\system32\drivers\chdrt64.sys"
+ "dtsoftbus01"    "DAEMON Tools Virtual Bus Driver"    "DT Soft Ltd"    "c:\windows\system32\drivers\dtsoftbus01.sys"
+ "EagleX64"    ""    ""    "File not found: C:\Windows\system32\drivers\EagleX64.sys"
+ "ebdrv"    "Broadcom NetXtreme II 10 GigE VBD"    "Broadcom Corporation"    "c:\windows\system32\drivers\evbda.sys"
+ "elxstor"    "Storport Miniport Driver for LightPulse HBAs"    "Emulex"    "c:\windows\system32\drivers\elxstor.sys"
+ "GEARAspiWDM"    "CD DVD Filter"    "GEAR Software Inc."    "c:\windows\system32\drivers\gearaspiwdm.sys"
+ "hcw85cir"    "Hauppauge WinTV 885 Consumer IR Driver for eHome"    "Hauppauge Computer Works, Inc."    "c:\windows\system32\drivers\hcw85cir.sys"
+ "HpSAMD"    "Smart Array SAS/SATA Controller Media Driver"    "Hewlett-Packard Company"    "c:\windows\system32\drivers\hpsamd.sys"
+ "iaStor"    "Intel Rapid Storage Technology driver - x64"    "Intel Corporation"    "c:\windows\system32\drivers\iastor.sys"
+ "iaStorV"    "Intel Matrix Storage Manager driver - x64"    "Intel Corporation"    "c:\windows\system32\drivers\iastorv.sys"
+ "iirsp"    "Intel/ICP Raid Storport Driver"    "Intel Corp./ICP vortex GmbH"    "c:\windows\system32\drivers\iirsp.sys"
+ "L1C"    "Atheros L1c PCI-E Gigabit Ethernet Controller"    "Atheros Communications, Inc."    "c:\windows\system32\drivers\l1c62x64.sys"
+ "LADF_DHP2"    "DPL2/DHP2 Filter Driver"    "Logitech"    "c:\windows\system32\drivers\ladfdhp2amd64.sys"
+ "LADF_SBVM"    "SBVM Filter Driver"    "Logitech"    "c:\windows\system32\drivers\ladfsbvmamd64.sys"
+ "LSI_FC"    "LSI Fusion-MPT FC Driver (StorPort)"    "LSI Corporation"    "c:\windows\system32\drivers\lsi_fc.sys"
+ "LSI_SAS"    "LSI Fusion-MPT SAS Driver (StorPort)"    "LSI Corporation"    "c:\windows\system32\drivers\lsi_sas.sys"
+ "LSI_SAS2"    "LSI SAS Gen2 Driver (StorPort)"    "LSI Corporation"    "c:\windows\system32\drivers\lsi_sas2.sys"
+ "LSI_SCSI"    "LSI Fusion-MPT SCSI Driver (StorPort)"    "LSI Corporation"    "c:\windows\system32\drivers\lsi_scsi.sys"
+ "megasas"    "MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for x64"    "LSI Corporation"    "c:\windows\system32\drivers\megasas.sys"
+ "MegaSR"    "LSI MegaRAID Software RAID Driver"    "LSI Corporation, Inc."    "c:\windows\system32\drivers\megasr.sys"
+ "MEIx64"    "Intel® Management Engine Interface"    "Intel Corporation"    "c:\windows\system32\drivers\hecix64.sys"
+ "nfrd960"    "IBM ServeRAID Controller Driver"    "IBM Corporation"    "c:\windows\system32\drivers\nfrd960.sys"
+ "nusb3hub"    "USB 3.0 Hub Driver"    "Renesas Electronics Corporation"    "c:\windows\system32\drivers\nusb3hub.sys"
+ "nusb3xhc"    "USB 3.0 Host Controller Driver"    "Renesas Electronics Corporation"    "c:\windows\system32\drivers\nusb3xhc.sys"
+ "NVHDA"    "NVIDIA HDMI Audio Driver"    "NVIDIA Corporation"    "c:\windows\system32\drivers\nvhda64v.sys"
+ "nvlddmkm"    "NVIDIA Windows Kernel Mode Driver, Version 285.62 "    "NVIDIA Corporation"    "c:\windows\system32\drivers\nvlddmkm.sys"
+ "nvraid"    "NVIDIA® nForce™ RAID Driver"    "NVIDIA Corporation"    "c:\windows\system32\drivers\nvraid.sys"
+ "nvstor"    "NVIDIA® nForce™ Sata Performance Driver"    "NVIDIA Corporation"    "c:\windows\system32\drivers\nvstor.sys"
+ "PGEffect"    "TOSHIBA Universal Camera Filter Driver"    "TOSHIBA Corporation"    "c:\windows\system32\drivers\pgeffect.sys"
+ "QIOMem"    "Generic IO & Memory Access"    "TOSHIBA"    "c:\windows\system32\drivers\qiomem.sys"
+ "ql2300"    "QLogic Fibre Channel Stor Miniport Driver"    "QLogic Corporation"    "c:\windows\system32\drivers\ql2300.sys"
+ "ql40xx"    "QLogic iSCSI Storport Miniport Driver"    "QLogic Corporation"    "c:\windows\system32\drivers\ql40xx.sys"
+ "RSUSBSTOR"    "Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7"    "Realtek Semiconductor Corp."    "c:\windows\system32\drivers\rtsustor.sys"
+ "RSUSBVSTOR"    "Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7"    "Realtek Semiconductor Corp."    "c:\windows\system32\drivers\rtsuvstor.sys"
+ "ScreamBAudioSvc"    "Screaming Bee Audio Driver"    "Screaming Bee LLC"    "c:\windows\system32\drivers\screamingbaudio64.sys"
+ "secdrv"    "Macrovision SECURITY Driver"    "Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K."    "c:\windows\system32\drivers\secdrv.sys"
+ "Serial"    "Brother Serial I/F Driver (WDM)"    "Brother Industries Ltd."    "c:\windows\system32\drivers\serial.sys"
+ "SiSRaid2"    "SiS RAID Stor Miniport Driver"    "Silicon Integrated Systems Corp."    "c:\windows\system32\drivers\sisraid2.sys"
+ "SiSRaid4"    "SiS AHCI Stor-Miniport Driver"    "Silicon Integrated Systems"    "c:\windows\system32\drivers\sisraid4.sys"
+ "SrvHsfHDA"    "HSF_HWAZL WDM driver"    "Conexant Systems, Inc."    "c:\windows\system32\drivers\vstazl6.sys"
+ "SrvHsfV92"    "HSF_DP driver"    "Conexant Systems, Inc."    "c:\windows\system32\drivers\vstdpv6.sys"
+ "SrvHsfWinac"    "HSF_CNXT driver"    "Conexant Systems, Inc."    "c:\windows\system32\drivers\vstcnxt6.sys"
+ "ssadbus"    "SAMSUNG Android USB Composite Device Driver"    "MCCI Corporation"    "c:\windows\system32\drivers\ssadbus.sys"
+ "ssadmdfl"    "SAMSUNG Android USB Modem (Filter)"    "MCCI Corporation"    "c:\windows\system32\drivers\ssadmdfl.sys"
+ "ssadmdm"    "SAMSUNG Android USB Modem Drivers"    "MCCI Corporation"    "c:\windows\system32\drivers\ssadmdm.sys"
+ "ssadserd"    "SAMSUNG Android USB Diagnostic Serial Port (WDM)"    "MCCI Corporation"    "c:\windows\system32\drivers\ssadserd.sys"
+ "stexstor"    "Promise  SuperTrak EX Series Driver for Windows "    "Promise Technology"    "c:\windows\system32\drivers\stexstor.sys"
+ "SynTP"    "Synaptics Touchpad Driver"    "Synaptics Incorporated"    "c:\windows\system32\drivers\syntp.sys"
+ "tdcmdpst"    "TOSHIBA ODD Writing Driver for x64."    "TOSHIBA Corporation."    "c:\windows\system32\drivers\tdcmdpst.sys"
+ "tosporte"    "TOSHIBA Bluetooth Port Emulation Driver"    "TOSHIBA Corporation"    "c:\windows\system32\drivers\tosporte.sys"
+ "tosrfbd"    "Bluetooth RF Bus Driver"    "TOSHIBA CORPORATION"    "c:\windows\system32\drivers\tosrfbd.sys"
+ "tosrfbnp"    "Bluetooth RFBNEP Driver"    "TOSHIBA Corporation"    "c:\windows\system32\drivers\tosrfbnp.sys"
+ "Tosrfcom"    "Bluetooth RFCOMM Driver"    "TOSHIBA Corporation"    "c:\windows\system32\drivers\tosrfcom.sys"
+ "tosrfec"    "TOSHIBA Bluetooth EC Driver"    "TOSHIBA Corporation"    "c:\windows\system32\drivers\tosrfec.sys"
+ "Tosrfhid"    "Bluetooth HID Driver from TOSHIBA"    "TOSHIBA Corporation."    "c:\windows\system32\drivers\tosrfhid.sys"
+ "tosrfnds"    "Bluetooth BNEP Driver"    "TOSHIBA Corporation."    "c:\windows\system32\drivers\tosrfnds.sys"
+ "TosRfSnd"    "Bluetooth Audio Driver (WDM)"    "TOSHIBA Corporation"    "c:\windows\system32\drivers\tosrfsnd.sys"
+ "Tosrfusb"    "Bluetooth USB Miniport Driver"    "TOSHIBA CORPORATION"    "c:\windows\system32\drivers\tosrfusb.sys"
+ "TVALZ"    "TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver"    "TOSHIBA Corporation"    "c:\windows\system32\drivers\tvalz_o.sys"
+ "TVALZFL"    "TOSHIBA TVALZ Filter Driver for x64"    "TOSHIBA Corporation"    "c:\windows\system32\drivers\tvalzfl.sys"
+ "VCSVADHWSer"    "Avnex Ltd. Virtual Audio Device (WDM)"    "Avnex"    "c:\windows\system32\drivers\vcsvad.sys"
+ "viaide"    "VIA Generic PCI IDE Bus Driver"    "VIA Technologies, Inc."    "c:\windows\system32\drivers\viaide.sys"
+ "vsmraid"    "VIA RAID DRIVER FOR AMD-X86-64"    "VIA Technologies Inc.,Ltd"    "c:\windows\system32\drivers\vsmraid.sys"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32"    ""    ""    ""
+ "msacm.l3acm"    "MPEG Layer-3 Audio Codec for MSACM"    "Fraunhofer Institut Integrierte Schaltungen IIS"    "c:\windows\system32\l3codeca.acm"
+ "VIDC.FPS1"    "Fraps"    "Beepa P/L"    "c:\windows\system32\frapsv64.dll"
"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32"    ""    ""    ""
+ "msacm.l3acm"    "MPEG Layer-3 Audio Codec for MSACM"    "Fraunhofer Institut Integrierte Schaltungen IIS"    "c:\windows\syswow64\l3codeca.acm"
+ "vidc.cvid"    "Cinepak®-codec"    "Radius Inc."    "c:\windows\syswow64\iccvid.dll"
+ "VIDC.FPS1"    "Fraps"    "Beepa P/L"    "c:\windows\syswow64\frapsvid.dll"
+ "vidc.VP60"    "VP6 VIDEO FOR WINDOWS CODEC "    "On2.com"    "c:\windows\syswow64\vp6vfw.dll"
+ "vidc.VP61"    "VP6 VIDEO FOR WINDOWS CODEC "    "On2.com"    "c:\windows\syswow64\vp6vfw.dll"
+ "vidc.XVID"    ""    ""    "c:\windows\syswow64\xvidvfw.dll"
"HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance"    ""    ""    ""
+ "MS PR Source Filter"    "PlayReady DirectShow Source Filter DLL"    "Microsoft Corporation"    "c:\program files\playready\prsource.dll"
+ "PlayReady DMO Wrapper"    "PlayReady DirectShow DMO Wrapper Filter DLL"    "Microsoft Corporation"    "c:\program files\playready\prdmowrapper.dll"
+ "SFVCaptureFilter"    "SmartFaceVCapt"    "TOSHIBA Corporation"    "c:\program files\toshiba\smartfacev\smartfacevcapt.dll"
"HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance"    ""    ""    ""
+ "AVS Video Out"    "AVSVideoOutFilter DirectShow Filter"    "Online Media Technologies Ltd"    "c:\program files (x86)\common files\avsmedia\activex\avsvideooutfilter3.ax"
+ "AVSMediaGrabber"    "AVSMediaGrabber4 DirectShow Filter"    "Online Media Technologies Ltd."    "c:\program files (x86)\common files\avsmedia\activex\avsmediagrabber4.ax"
+ "Capture File Writer"    "Windows Live Video Acquisition Filters"    "Microsoft Corporation"    "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "Image Effects"    "TimeStam Dynamic Link Library"    "TOSHIBA CORPORATION."    "c:\program files (x86)\toshiba\toshiba web camera application\pgtimefilter.dll"
+ "Memory Buffered Filter"    ""    ""    "d:\steam\steamapps\common\wormsrevolution\redist\memorybufferedfilter.dll"
+ "Record Queue"    "Windows Live Video Acquisition Filters"    "Microsoft Corporation"    "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "TOSHIBA Progress Monitor"    "TOSHIBA Progress Monitor"    "TOSHIBA Corporation"    "c:\program files (x86)\toshiba\toshiba disc creator\tprogmon.ax"
+ "TOSHIBA WAV Converter"    "TOSHIBA Wav Converter"    "TOSHIBA Corporation"    "c:\program files (x86)\toshiba\toshiba disc creator\twavconv.ax"
+ "VHAudioGain"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "VHCropResize"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "VHDeinterlace"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "VHFrameRateConv"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "VHMixerSource"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "VHMultiReader"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "VHMultiWriter"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "VHScreenDecoder"    "VHScreenDecoder"    "Hmelyoff Labs"    "c:\program files (x86)\hmelyofflabs\vhscrcap\vhscreendecoder.ax"
+ "VHSplitProcSource"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "VHYV12Decoder"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "VHYV12Encoder"    "VHMediaLib COM implementation"    "SplitmediaLabs Limited"    "d:\vhmediacom.dll"
+ "WM VIH2 Fix"    "Windows Live Video Acquisition Filters"    "Microsoft Corporation"    "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT DV Extract Filter"    "Windows Live Video Acquisition Filters"    "Microsoft Corporation"    "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Sample Info Filter"    "Windows Live Video Acquisition Filters"    "Microsoft Corporation"    "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Switch Filter"    "Windows Live Video Acquisition Filters"    "Microsoft Corporation"    "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Virtual Renderer"    "Windows Live Video Acquisition Filters"    "Microsoft Corporation"    "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Virtual Source"    "Windows Live Video Acquisition Filters"    "Microsoft Corporation"    "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "Xvid MPEG-4 Video Decoder"    ""    ""    "c:\windows\syswow64\xvid.ax"
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls"    ""    ""    ""
+ "C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll "    ""    ""    "File not found: C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll "
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers"    ""    ""    ""
+ "CLCredProv"    "CyberLink Credential Provider"    "CyberLink"    "f:\youcam\clcredprov\x64\clcredprov.dll"
+ "SmartFaceVCP"    "SmartFaceVCP"    "TOSHIBA Corporation"    "c:\program files\toshiba\smartfacev\smartfacevcp.dll"
+ "tosWirelessLANIndicatorCP"    "Credential Provider Dll for TOSHIBA Wireless LAN Indicator"    "TOSHIBA CORPORATION"    "c:\windows\system32\toswirelesslanindicatorcp.dll"
+ "WLIDCredentialProvider"    "Microsoft® Windows Live ID Credential Provider"    "Microsoft Corp."    "c:\program files\common files\microsoft shared\windows live\wlidcredprov.dll"
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters"    ""    ""    ""
+ "CLCredProv"    "CyberLink Credential Provider"    "CyberLink"    "f:\youcam\clcredprov\x64\clcredprov.dll"
"HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries"    ""    ""    ""
+ "mdnsNSP"    "Bonjour Namespace Provider"    "Apple Inc."    "c:\program files (x86)\bonjour\mdnsnsp.dll"
+ "WindowsLive Local NSP"    "Microsoft® Windows Live ID Namespace Provider"    "Microsoft Corp."    "c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll"
+ "WindowsLive NSP"    "Microsoft® Windows Live ID Namespace Provider"    "Microsoft Corp."    "c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll"
"HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64"    ""    ""    ""
+ "mdnsNSP"    "Bonjour Namespace Provider"    "Apple Inc."    "c:\program files\bonjour\mdnsnsp.dll"
+ "WindowsLive Local NSP"    "Microsoft® Windows Live ID Namespace Provider"    "Microsoft Corp."    "c:\program files\common files\microsoft shared\windows live\wlidnsp.dll"
+ "WindowsLive NSP"    "Microsoft® Windows Live ID Namespace Provider"    "Microsoft Corp."    "c:\program files\common files\microsoft shared\windows live\wlidnsp.dll"
"HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors"    ""    ""    ""
+ "Toshiba Bluetooth Monitor"    ""    "TOSHIBA CORPORATION."    "c:\windows\system32\tbtmon.dll"
"C:\Users\Johanna\AppData\Local\Microsoft\Windows Sidebar\Settings.ini"    ""    ""    ""
+ "Avast! antivirus monitor"    "Avast! antivirus sidebar gadget."    "AVAST Software"    "C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget\Gadget.xml"


#10 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:42 AM

Posted 09 February 2013 - 03:05 PM

Launch Adware cleaner and click on DELETE,System should reboot,post the generated log

 

Run malwarebytes again and post the clean log

 

Current issues?



#11 Undesired_Hero

Undesired_Hero
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 09 February 2013 - 03:49 PM

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
 
Databasversion: v2013.02.09.07
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Johanna :: HOLLYWOOOD-TOSH [administratör]
 
2013-02-09 21:29:11
mbam-log-2013-02-09 (21-29-11).txt
 
Skanningstyp: Snabbskanning
Aktiverade skanningsalternativ: Minne | Start | Register | Filsystem | Heuristik/Extra | Heuristik/Shuriken | PUP | PUM
Inaktiverade skanningsalternativ: P2P
Antal skannade objekt: 244006
Förfluten tid: 3 minut(er), 42 sekund(er)
 
Upptäckta minnesprocesser: 0
(Inga skadliga poster hittades)
 
Upptäckta minnesmoduler: 0
(Inga skadliga poster hittades)
 
Upptäckta registernycklar: 0
(Inga skadliga poster hittades)
 
Upptäckta registervärden: 0
(Inga skadliga poster hittades)
 
Upptäckta registerdataposter: 0
(Inga skadliga poster hittades)
 
Upptäckta mappar: 0
(Inga skadliga poster hittades)
 
Upptäckta filer: 0
(Inga skadliga poster hittades)
 
(klar)


# AdwCleaner v2.111 - Logfile created 02/09/2013 at 21:35:51
# Updated 05/02/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Johanna - HOLLYWOOOD-TOSH
# Boot Mode : Normal
# Running from : C:\Users\Johanna\Downloads\AdwCleaner (1).exe
# Option [Search]
 
 
***** [Services] *****
 
 
***** [Files / Folders] *****
 
File Found : C:\END
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Found : C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_apps.conduit.com_0.localstorage
File Found : C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_apps.conduit.com_0.localstorage-journal
File Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\searchplugins\Web Search.xml
Folder Found : C:\Program Files (x86)\AVG Secure Search
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\Users\Johanna\AppData\Local\AVG Secure Search
Folder Found : C:\Users\Johanna\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\CT3072254
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\{1fd91a9c-410c-4090-bbcc-55d3450ef433}
Folder Found : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\{e9df9360-97f8-4690-afe6-996c80790da4}
 
***** [Registry] *****
 
Data Found : [x64] HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll
Data Found : [x64] HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll
Key Found : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Found : HKCU\Software\AVG Secure Search
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Found : HKLM\Software\AVG Secure Search
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
Key Found : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Found : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
Key Found : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Found : HKLM\SOFTWARE\Classes\ilivid
Key Found : HKLM\Software\Classes\Installer\Features\2B1E51D87B2D71A44BB42DDD5E894160
Key Found : HKLM\Software\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\Software\uTorrentControl_v2
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{73449E6D-E99C-44F6-9D81-5514F02C768F}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C5B99A2C-4940-463C-9B8D-0855940B8075}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v2 Toolbar
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Found : HKLM\SOFTWARE\Software
Key Found : HKLM\SOFTWARE\Tarma Installer
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]
 
***** [Internet Browsers] *****
 
-\\ Internet Explorer v9.0.8112.16457
 
[OK] Registry is clean.
 
-\\ Mozilla Firefox v12.0 (sv-SE)
 
File : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\prefs.js
 
Found : user_pref("CT3072254.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT3220468.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3220468.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Found : user_pref("CT3220468.embeddedsData", "[{\"appId\":\"129813684258939747\",\"apiPermissions\":{\"cross[...]
Found : user_pref("CT3220468.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3220468.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Found : user_pref("CT3220468.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Found : user_pref("CT3220468.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"file%3A%2F%2F%2FC%3A%2FProgra[...]
Found : user_pref("CT3220468.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3220468.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Found : user_pref("CT3220468.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Found : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Found : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Found : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Found : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Found : user_pref("CT3220468_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3072254/CT3072254[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1463703/1459357/SE", "\"0\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3072254", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3072254",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"096[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Johanna\\AppData\\Roaming\\Mozilla\[...]
Found : user_pref("extensions.enabledAddons", "ffxtlbr@funmoods.com:1.5.0,plugin@yontoo.com:1.20.00,{99079a2[...]
 
-\\ Google Chrome v24.0.1312.57
 
File : C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Preferences
 
Found [l.19] : urls_to_restore_on_startup = [ "hxxp://www.delta-search.com/?affID=119529&babsrc=HP_ss&mntrId=6e7a96be000000000000e0ca9488c749" ]
Found [l.3176] : urls_to_restore_on_startup = [ "hxxp://www.delta-search.com/?affID=119529&babsrc=HP_ss&mntrId=6e7a96be000000000000e0ca9488c749" ]
 
*************************
 
AdwCleaner[R1].txt - [49874 octets] - [09/02/2013 20:33:31]
AdwCleaner[R2].txt - [16273 octets] - [09/02/2013 21:35:51]
 
########## EOF - C:\AdwCleaner[R2].txt - [16334 octets] ##########


# AdwCleaner v2.111 - Logfile created 02/09/2013 at 21:36:53
# Updated 05/02/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Johanna - HOLLYWOOOD-TOSH
# Boot Mode : Normal
# Running from : C:\Users\Johanna\Downloads\AdwCleaner (1).exe
# Option [Delete]
 
 
***** [Services] *****
 
 
***** [Files / Folders] *****
 
Deleted on reboot : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\{1fd91a9c-410c-4090-bbcc-55d3450ef433}
File Deleted : C:\END
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_apps.conduit.com_0.localstorage
File Deleted : C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_apps.conduit.com_0.localstorage-journal
File Deleted : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\searchplugins\Web Search.xml
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\Users\Johanna\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Johanna\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\CT3072254
Folder Deleted : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\extensions\{e9df9360-97f8-4690-afe6-996c80790da4}
 
***** [Registry] *****
 
Data Deleted : [x64] HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll
Data Deleted : [x64] HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\ilivid
Key Deleted : HKLM\Software\Classes\Installer\Features\2B1E51D87B2D71A44BB42DDD5E894160
Key Deleted : HKLM\Software\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\Software\uTorrentControl_v2
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{73449E6D-E99C-44F6-9D81-5514F02C768F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C5B99A2C-4940-463C-9B8D-0855940B8075}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v2 Toolbar
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKLM\SOFTWARE\Software
Key Deleted : HKLM\SOFTWARE\Tarma Installer
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]
 
***** [Internet Browsers] *****
 
-\\ Internet Explorer v9.0.8112.16457
 
[OK] Registry is clean.
 
-\\ Mozilla Firefox v12.0 (sv-SE)
 
File : C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\qif8ppgt.default\prefs.js
 
Deleted : user_pref("CT3072254.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT3220468.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Deleted : user_pref("CT3220468.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Deleted : user_pref("CT3220468.embeddedsData", "[{\"appId\":\"129813684258939747\",\"apiPermissions\":{\"cross[...]
Deleted : user_pref("CT3220468.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Deleted : user_pref("CT3220468.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Deleted : user_pref("CT3220468.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Deleted : user_pref("CT3220468.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"file%3A%2F%2F%2FC%3A%2FProgra[...]
Deleted : user_pref("CT3220468.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Deleted : user_pref("CT3220468.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Deleted : user_pref("CT3220468.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Deleted : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Deleted : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Deleted : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Deleted : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Deleted : user_pref("CT3220468_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3072254/CT3072254[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1463703/1459357/SE", "\"0\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3072254", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3072254",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"096[...]
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Johanna\\AppData\\Roaming\\Mozilla\[...]
Deleted : user_pref("extensions.enabledAddons", "ffxtlbr@funmoods.com:1.5.0,plugin@yontoo.com:1.20.00,{99079a2[...]
 
-\\ Google Chrome v24.0.1312.57
 
File : C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Preferences
 
Deleted [l.19] : urls_to_restore_on_startup = [ "hxxp://www.delta-search.com/?affID=119529&babsrc=HP_ss&mnt[...]
Deleted [l.3176] : urls_to_restore_on_startup = [ "hxxp://www.delta-search.com/?affID=119529&babsrc=HP_ss&mntrId[...]
 
*************************
 
AdwCleaner[R1].txt - [49874 octets] - [09/02/2013 20:33:31]
AdwCleaner[R2].txt - [16356 octets] - [09/02/2013 21:35:51]
AdwCleaner[S1].txt - [16598 octets] - [09/02/2013 21:36:53]
 
########## EOF - C:\AdwCleaner[S1].txt - [16659 octets] ##########


Thank you for the help, everything looks ok now! 



#12 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:42 AM

Posted 09 February 2013 - 03:53 PM

That looks good

Remove temporary and junk files

Download

TFC

Launch it,it will close all running programs

click on START,it should ask for reboot.If TFC locks up the system,run it in safemode


Create a new restore point

Follow this guide to turn off and turn on your restore points

XP- http://support.microsoft.com/kb/310405

Vista & windows 7- http://windows.microsoft.com/en-US/windows7/Turn-System-Restore-on-or-off

Turn off your system restore-It deletes old infected restore points

Turn on system restore and create a new restore point

Update JAVA and Flash player

Uninstall old version of java from control panel-Add or remove programs.Download the latest version from here

http://java.com/en/

Update your flash player

Antivirus recommendations

Update your antivirus frequently.Two free antivirus that i would suggest are

Microsoft security essentials or Avast.You can select either one of them.

If you have a paid one,make sure to update it frequently.Do not use multiple security softwares.

Informative guides that could prevent you from being infected again

How did I get infected?

http://www.bleepingcomputer.com/forums/topic2520.html

Best Practices for Safe Computing - Prevention of Malware Infection

http://www.bleepingcomputer.com/forums/topic407147.html

Simple and easy ways to keep your computer safe and secure on the Internet

http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

Safe surfing :)



#13 Delta_Search

Delta_Search

    Confirmed Delta Search Rep


  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:42 AM

Posted 25 February 2013 - 04:30 AM

Hello 

 

I am writing today on behalf of the Delta Search Support Department. I am sorry
to hear about your frustrations with the removal of Delta Search,

but I can assure you that it is not a virus. I can help you take care of it right away.
Please send me an email at support@delta-search.com
and I will send you the removal instructions.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users