Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windows Vista - multiple consistent Application Errors - Hijackthis


  • This topic is locked This topic is locked
11 replies to this topic

#1 ConnJohnn

ConnJohnn

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 28 February 2013 - 11:01 PM

Hey guys.  I frequent the forum often for all the modern up-to-date info.  Been a while since I've posted, hoping to seek some assistance with a problem I am experiencing.

 

I'm working with an HP desktop running Vista.  I am encountering more Application Errors than I've ever seen before.  They're present as soon as Windows boots up, before logging in and continue constantly throughout the time of use.  From what I notice, WerFault.exe seems to show the most but there are multiple.  Most of which relate to Windows components.

 

I've run a variety of virus, malware, and registry fixes as well as sfc scan with not much help.  I can provide the programs I've used if needed.

 

Hoping that someone more experienced in this area can provide me with some help, it'd be greatly appreciated!

 

I have attached the most recent Hijackthis log.

 

Thanks!

 

 

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:16:15 PM, on 2/28/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Safe mode
 
Running processes:
C:\Users\angel\Desktop\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mycenturylink.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?ilc=8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll
R3 - URLSearchHook: NetAssistantBHO Class - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\My.Freeze.com Toolbar\NetAssistant.dll
R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:\Program Files\SGPSA\mtwb3sh.dll
R3 - URLSearchHook: AmigoBar Toolbar - {c54a4bc4-2966-40ac-9ca4-ad863d6148ee} - C:\Program Files (x86)\AmigoBar\tbAmi2.dll
R3 - URLSearchHook: (no name) - {313a832a-aaf3-4880-a8d0-c42bee319c02} - (no file)
R3 - URLSearchHook: (no name) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - (no file)
R3 - URLSearchHook: YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll
R3 - URLSearchHook: FCToolbarURLSearchHook Class - {f78bf7a8-cf12-4de7-a6da-c463d1b539a7} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Helper.dll
R3 - URLSearchHook: (no name) -  - (no file)
R3 - URLSearchHook: A Free Ride Games Bar Toolbar - {f92a9fe4-2850-4198-b9d5-279880e49b16} - C:\Program Files (x86)\A_Free_Ride_Games_Bar\prxtbA_Fr.dll
R3 - URLSearchHook: (no name) - {0696f815-a3a9-490a-bb14-9ec3350b1276} - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64SrcAs.dll
F2 - REG:system.ini: UserInit=c:\windows\syswow64\userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: My.Freeze.com Toolbar - {0bd6f992-62ad-47f7-aca6-299729be4e2b} - C:\Program Files (x86)\myfreezetoolbar\myfreezedx.dll
O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.1.0\PriceGongIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Elf 1 - {22e03916-85c5-44b0-8dc9-1830c11238d9} - C:\Program Files (x86)\Elf_1\prxtbElf2.dll
O2 - BHO: RivalGaming Games - {26D675AC-D925-4bbf-A720-62C2AA4A81EB} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Conduit Engine  - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: Smiley Help BHO - {41403228-8910-4CA2-9939-DA9C9A6A58A7} - C:\PROGRA~1\SMILEY~1\SMILES~1.DLL
O2 - BHO: Search Assistant BHO - {5d79f641-c168-40df-a32f-bacea7509e75} - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64SrcAs.dll
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
O2 - BHO: File2LinkRH - {6a14e93a-dde3-4b64-8381-f3b68243d8f4} - C:\Program Files (x86)\file2linkrh\file2linkibX.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Norton AntiVirus\Engine\19.9.1.14\IPS\IPSBHO.DLL
O2 - BHO: Bewiki_IE_Extension - {732e5459-a239-4e08-a411-2c6ccf313f1d} - C:\Program Files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files (x86)\eMail ID\IEAddOn\IconixBHO_46.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Searchqu Toolbar - {7FF99715-3016-4381-84CE-E4E4C9673020} - (no file)
O2 - BHO: CenturyLink Toolbar - {83453B9B-B889-4659-9144-20F081542BDC} - C:\Program Files (x86)\centurytoolbar\centurytoolbarDx.dll
O2 - BHO: blekko search bar - {8769adce-dba5-48e9-afb5-67b12cdf2e61} - C:\Program Files (x86)\blekkotb_031\blekkotb_019X.dll
O2 - BHO: Fantapper - {8A86D350-37AB-410A-8531-7D1363F317B3} - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\SEARCH~2\Datamngr\BROWSE~1.DLL
O2 - BHO: AW Gaming Software - {9F531FB1-7C1F-4e1a-8C0C-E8D6177130E2} - (no file)
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: CenturyLink - {A317CB83-299C-4FC8-9ED7-2D64117D98EE} - C:\Program Files (x86)\qwesttoolbar\qwesttoolbarDx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Searchcore Toolbar - {af6ac4f2-9825-4fb6-a600-92bc5361f209} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll
O2 - BHO: FCTBPos00Pos - {BFE4B5CB-63F7-4A51-9266-6167655D5B4F} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll
O2 - BHO: Updater For My.Freeze.com Toolbar - {C26CD490-5F01-41E3-B150-EB29F19DA056} - C:\Program Files (x86)\myfreezetoolbar\auxi\myfreezetoolbAu.dll
O2 - BHO: AmigoBar Toolbar - {c54a4bc4-2966-40ac-9ca4-ad863d6148ee} - C:\Program Files (x86)\AmigoBar\tbAmi2.dll
O2 - BHO: Big Fish Games Toolbar - {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files (x86)\BfgBar\bfg.dll
O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files (x86)\GamesBar\2.0.1.109\oberontb.dll
O2 - BHO: Toolbar BHO - {cb41fc95-f1b3-4797-8bb6-1012ff62abba} - C:\PROGRA~2\TELEVI~2\bar\1.bin\64bar.dll
O2 - BHO: (no name) - {CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\My.Freeze.com Toolbar\NetAssistant.dll
O2 - BHO: QuickNet - {EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7} - C:\Program Files (x86)\RegTweaker\key.dll (file missing)
O2 - BHO: A Free Ride Games Bar - {f92a9fe4-2850-4198-b9d5-279880e49b16} - C:\Program Files (x86)\A_Free_Ride_Games_Bar\prxtbA_Fr.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn6\YTSingleInstance.dll
O3 - Toolbar: (no name) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: My.Freeze.com Toolbar - {0bd6f992-62ad-47f7-aca6-299729be4e2b} - C:\Program Files (x86)\myfreezetoolbar\myfreezedx.dll
O3 - Toolbar: AmigoBar Toolbar - {c54a4bc4-2966-40ac-9ca4-ad863d6148ee} - C:\Program Files (x86)\AmigoBar\tbAmi2.dll
O3 - Toolbar: Conduit Engine  - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: Elf 1 Toolbar - {22e03916-85c5-44b0-8dc9-1830c11238d9} - C:\Program Files (x86)\Elf_1\prxtbElf2.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: (no name) - {7FF99715-3016-4381-84CE-E4E4C9673020} - (no file)
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
O3 - Toolbar: File2LinkRH - {6a14e93a-dde3-4b64-8381-f3b68243d8f4} - C:\Program Files (x86)\file2linkrh\file2linkibX.dll
O3 - Toolbar: Searchcore Toolbar - {af6ac4f2-9825-4fb6-a600-92bc5361f209} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll
O3 - Toolbar: Big Fish Games Toolbar - {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files (x86)\BfgBar\bfg.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll" (file missing)
O3 - Toolbar: Dogpile Bundle Toolbar - {C80BDEB2-8735-44C6-BD55-A1CCD555667A} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll
O3 - Toolbar: &SmileysToolbar - {120B1DC9-20CC-498F-9ABA-455FB2B8E18F} - C:\PROGRA~1\SMILEY~1\SMILES~1.DLL
O3 - Toolbar: blekko search bar - {8769adce-dba5-48e9-afb5-67b12cdf2e61} - C:\Program Files (x86)\blekkotb_031\blekkotb_019X.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: CenturyLink - {A317CB83-299C-4FC8-9ED7-2D64117D98EE} - C:\Program Files (x86)\qwesttoolbar\qwesttoolbarDx.dll
O3 - Toolbar: A Free Ride Games Bar Toolbar - {f92a9fe4-2850-4198-b9d5-279880e49b16} - C:\Program Files (x86)\A_Free_Ride_Games_Bar\prxtbA_Fr.dll
O3 - Toolbar: CenturyLink Toolbar - {83453B9B-B889-4659-9144-20F081542BDC} - C:\Program Files (x86)\centurytoolbar\centurytoolbarDx.dll
O3 - Toolbar: TelevisionFanatic - {c98d5b61-b0ea-4d48-9839-1079d352d880} - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64bar.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files (x86)\GamesBar\2.0.1.109\oberontb.dll
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [1157840481] C:\PROGRA~2\eGames\TWISTI~1\Register\EGAMES~1.EXE /r "C:\PROGRA~2\eGames\TWISTI~1\Register\EGAMES~1.rpd"
O4 - HKLM\..\Run: [408809432] C:\PROGRA~2\eGames\SHOOTT~1\Register\EGAMES~1.EXE /r "C:\PROGRA~2\eGames\SHOOTT~1\Register\EGAMES~1.rpd"
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] "C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
O4 - HKLM\..\Run: [IconixOEAddOn] "C:\Program Files (x86)\eMail ID\OEAddOn\OEdmn_6.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I
O4 - HKLM\..\Run: [Anti-phishing Domain Advisor] "C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe"
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKLM\..\Run: [TelevisionFanatic Search Scope Monitor] "C:\PROGRA~2\TELEVI~2\bar\1.bin\64srchmn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~2\SEARCH~2\Datamngr\DATAMN~1.EXE
O4 - HKLM\..\Run: [CenturyLinkTouchPointAgent] "C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe" /autostart
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~2\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [DW7] "C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe"
O4 - HKCU\..\Run: [Exetender_179] "C:\Program Files (x86)\qZone Games Player\GPlayer.exe" /runonstartup
O4 - HKCU\..\Run: [SearchEngineProtection] C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}] C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe /m (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}] C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe /m (User 'Default user')
O4 - Startup: HP SimpleSave Monitor.lnk = angel\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files (x86)\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: Recipe Feeder - {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - C:\Program Files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files (x86)\GamesBar\2.0.1.109\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files (x86)\GamesBar\2.0.1.109\oberontb.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files (x86)\eMail ID\IEAddOn\IconixBHO_46.dll
O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files (x86)\eMail ID\IEAddOn\IconixBHO_46.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files (x86)\eMail ID\IEAddOn\IconixBHO_46.dll
O9 - Extra 'Tools' menuitem: About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files (x86)\eMail ID\IEAddOn\IconixBHO_46.dll
O9 - Extra button: Fantapper - {AB745E88-1BAD-4B80-A83E-7C964EAC9804} - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O12 - Plugin for .spop: C:\Program Files (x86)\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - 
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~2\SEARCH~2\Datamngr\datamngr.dll C:\PROGRA~2\SEARCH~2\Datamngr\IEBHO.dll protector.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: BackupService - ArcSoft, Inc. - C:\Users\angel\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Unknown owner - C:\Program Files (x86)\VIRUSfighter\Npm\Bin\eLogsvc.exe (file missing)
O23 - Service: Fantapper Player Update Service (FTSvc) - Brand Affinity Technologies - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: Updater Service (IBUpdaterService) - Unknown owner - C:\ProgramData\IBUpdaterService\ibsvc.exe
O23 - Service: Iconix Update Service (IconixService) - Unknown owner - C:\Program Files (x86)\Common Files\eMail ID\IconixService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: Norton Management (MCLIENT) - Symantec Corporation - C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files (x86)\Norton AntiVirus\Norton AntiVirus\Engine\19.9.1.14\ccSvcHst.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norman ZANDA - Unknown owner - C:\Program Files (x86)\VIRUSfighter\Npm\Bin\Zanda.exe (file missing)
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.7.49\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.7.49\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: SupportSoft Listener Service (sprtlisten) - SupportSoft, Inc. - C:\Program Files (x86)\Common Files\supportsoft\bin\sprtlisten.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe
O23 - Service: SupportSoft RemoteAssist - Unknown owner - C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
 
--
End of file - 24918 bytes

Attached Files


Edited by nasdaq, 02 March 2013 - 10:12 AM.
HijackThis log posted.


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,936 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:29 AM

Posted 02 March 2013 - 10:15 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.
 
If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===
Please download ComboFix from any of the links below, and save it to your desktop. For information regarding this download, please visit this web page: http://www.bleepingcomputer.com/combofix/how-to-use-combofix
 
IMPORTANT !!! Save ComboFix.exe to your Desktop
 
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Do not install any other programs until this if fixed.
 
How to : Disable Anti-virus and Firewall...
http://www.bleepingcomputer.com/forums/topic114351.html
 
Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt
Note: Do not mouse click ComboFix's window while it's running. That may cause it to stall
 
Note: If you have difficulty properly disabling your protective programs, refer to this link --> http://www.bleepingcomputer.com/forums/topic114351.html
 
Note: If after running ComboFix you get this error message "Illegal operation attempted on a registry key that has been marked for deletion." when attempting to run a program all you need to do is restart the computer to reset the registry.
===
 
Third party programs if not up to date can be the cause of infiltration an infection.
 
Please run this security check for my review.
 
Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===
 
Search and delete the AdWare, PUP (Potentially Unwanted Program) installed on your computer.
 
Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete tab follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Rn].txt (n is a number).
===
 

HijackThis doesn't handle Windows 7 well. In your case I need to see a final DDS Log.
I would remove HijackThis using the Add/Remove Programs list.
 
 
Please download and run this DDS Scanning Tool. Nothing will be deleted. It will just give me some additional information about your system.
 
  •  
  • Download DDS by sUBs from one of the following links if you no longer have it available.  Save it to your desktop.
    •  
  • DDS.scr <- not recommended if you use Chrome to download this .scr file. Use the other options.
  •  
  • Double click on the DDS icon, allow it to run. 
  • A small box will open, with an explanation about the tool.  No input is needed, the scan is running. 
  • Notepad will open with the results. 
  • Follow the instructions that pop up for posting the results. 
  • Please note:  You may have to disable any script protection running if the scan fails to run.
     
     
    Please just paste the contents of the DDS.txt log in your next post. DO NOT attach the log.
     
    Please post the logs and let me know if the problem persists.


    #3 ConnJohnn

    ConnJohnn
    • Topic Starter

    • Members
    • 15 posts
    • OFFLINE
    •  
    • Local time:09:29 PM

    Posted 03 March 2013 - 03:21 AM

    Thank you for your help.

     

    ComboFix Log

     

    ComboFix 13-03-02.01 - angel 03/02/2013  22:07:10.1.4 - x64 MINIMAL
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.6014.5066 [GMT -8:00]
    Running from: C:\Users\angel\Desktop\ComboFix.exe
    AV: AVG Anti-Virus 2012 *Disabled/Outdated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus 2012 *Disabled/Outdated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
     * Created a new restore point


    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\Program Files (x86)\AV7
    C:\Program Files (x86)\AV7\antivirus7.exe.tmp1
    C:\Program Files (x86)\Blinkx
    C:\Program Files (x86)\Blinkx\blinkx.ico
    C:\Program Files (x86)\Blinkx\blinkxss.exe
    C:\Program Files (x86)\Blinkx\blinkxstop.exe
    C:\Program Files (x86)\Blinkx\lang.dll
    C:\Program Files (x86)\Blinkx\templates\beat.ico
    C:\Program Files (x86)\Blinkx\templates\index.html
    C:\Program Files (x86)\Blinkx\templates\noflash.html
    C:\Program Files (x86)\Blinkx\templates\offline.html
    C:\Program Files (x86)\Blinkx\templates\offline.swf
    C:\Program Files (x86)\Blinkx\templates\uninstall.exe
    C:\Program Files (x86)\Brand Affinity Technologies
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\ChromeInstaller.dll
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\ChromeInstaller.InstallState
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\Fantapper.crx
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\Fantapper.xpi
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\FirefoxInstaller.dll
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\FirefoxInstaller.InstallState
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\FT_Enabled.ico
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\FT_Plugin_Installer.jpg
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\IEInstaller.dll
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\OpenIE.dll
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\OpenIE.InstallState
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.InstallState
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FT_Enabled.ico
    C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FT_Plugin_Installer.jpg
    C:\Program Files (x86)\CouponAlert_2pEI
    C:\Program Files (x86)\facemoods.com
    C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
    C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoods.crx
    C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoods.png
    C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsApp.dll
    C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsEng.dll
    C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe
    C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
    C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\uninstall.exe
    C:\Program Files (x86)\HeadlineAlley_29EI
    C:\Program Files (x86)\TelevisionFanatic
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64bar.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64dlghk.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64hkstub.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64Plugin.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64radio.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64reghk.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64sknlcr.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64SrcAs.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64SrchMn.exe
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64tpinst.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\BOOTSTRAP.JS
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\CHROME.MANIFEST
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\chrome\64ffxtbr.jar
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\CREXT.DLL
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\CrExtP64.exe
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\INSTALL.RDF
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\installKeys.js
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\LOGO.BMP
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\NP64Stub.dll
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\T8EXTEX.DLL
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\T8EXTPEX.DLL
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\T8HTML.DLL
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\T8RES.DLL
    C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\T8TICKER.DLL
    C:\Program Files (x86)\TelevisionFanatic\bar\gen1\COMMON.T8S
    C:\Program Files (x86)\TelevisionFanatic\bar\IE9Mesg\COMMON.T8S
    C:\Program Files (x86)\TelevisionFanatic\bar\Message\COMMON.T8S
    C:\Program Files (x86)\TelevisionFanatic\bar\Settings\s_pid.dat
    C:\Program Files (x86)\Windows Searchqu Toolbar
    C:\Program Files (x86)\Windows Searchqu Toolbar\uninstall.exe
    C:\ProgramData\bProtector
    C:\ProgramData\Herofy
    C:\ProgramData\Herofy\save.aps
    C:\Users\angel\AppData\Local\assembly\tmp
    C:\Users\angel\AppData\Local\assembly\tmp\0H8KL0UV\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\0H8KL0UV\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\0SF705OE\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\0SF705OE\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\13CAIXBV\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\13CAIXBV\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\18GTP9A9\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\18GTP9A9\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\1GCTMKNZ\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\1GCTMKNZ\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\1KPGV8MQ\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\1KPGV8MQ\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\1L3QXOC3\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\1L3QXOC3\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\1RGCC5VH\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\1RGCC5VH\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\22XB7TQW\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\22XB7TQW\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\273SU7FW\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\273SU7FW\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\2CDH784H\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\2CDH784H\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\2FSX27XI\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\2FSX27XI\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\2JOJEVXK\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\2JOJEVXK\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\2JS2TVWE\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\2JS2TVWE\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\2MXHF5WV\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\2MXHF5WV\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\3072BXP7\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\3072BXP7\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\3372E7Z8\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\3372E7Z8\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\34ORVSUD\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\34ORVSUD\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\3IX7LHRL\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\3IX7LHRL\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\3TQHOYEX\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\3TQHOYEX\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\417SAXTQ\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\417SAXTQ\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\42YPIL5I\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\42YPIL5I\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\46JD3QP5\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\46JD3QP5\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\4ADHF3PM\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\4ADHF3PM\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\4MPFV0ZD\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\4MPFV0ZD\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\4V9JTHH3\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\4V9JTHH3\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\4VY1NTT4\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\4VY1NTT4\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\57KJF6EE\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\57KJF6EE\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\5CEDMUXU\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\5CEDMUXU\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\5OUR7V3S\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\5OUR7V3S\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\6K2PS5Y9\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\6K2PS5Y9\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\6RIELMJF\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\6RIELMJF\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\6S4WJZP8\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\6S4WJZP8\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\76Q4FGW4\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\76Q4FGW4\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\7B7A6I2A\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\7B7A6I2A\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\7HW8EH14\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\7HW8EH14\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\7UFEE01E\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\7UFEE01E\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\8FNBH8VK\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\8FNBH8VK\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\8KWNPY2W\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\8KWNPY2W\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\8MYZE8NY\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\8MYZE8NY\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\8ZFACHNN\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\8ZFACHNN\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\91ZHA43F\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\91ZHA43F\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\9EBJQIC5\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\9EBJQIC5\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\9S3XRUAK\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\9S3XRUAK\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\9X6N2586\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\9X6N2586\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\A4FAAOIU\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\A4FAAOIU\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\AKOALI22\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\AKOALI22\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\APMDSEZ0\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\APMDSEZ0\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\ARU1U7RN\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\ARU1U7RN\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\B1HESDT5\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\B1HESDT5\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\BVV0AOE0\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\BVV0AOE0\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\BYBN7KD9\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\BYBN7KD9\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\C18J54E7\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\C18J54E7\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\C6BX6QQ8\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\C6BX6QQ8\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\CCRO2JPT\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\CCRO2JPT\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\CNR56DW5\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\CNR56DW5\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\D3VI3SGW\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\D3VI3SGW\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\D8I66753\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\D8I66753\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\D93M1VSO\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\D93M1VSO\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\DFK22MLG\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\DFK22MLG\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\DK7W3T66\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\DK7W3T66\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\DQTIBK27\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\DQTIBK27\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\DVFC91QQ\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\DVFC91QQ\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\E4QDKYH0\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\E4QDKYH0\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\FDMXX31J\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\FDMXX31J\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\FEFGP4LO\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\FEFGP4LO\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\FIDXNY3S\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\FIDXNY3S\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\G7U56N8B\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\G7U56N8B\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\GI79AAER\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\GI79AAER\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\GJ3S7MSJ\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\GJ3S7MSJ\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\GOYNP4P4\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\GOYNP4P4\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\GQI30BH6\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\GQI30BH6\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\GYDJ91TS\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\GYDJ91TS\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\H9UKBZUY\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\H9UKBZUY\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\IF0S7VRU\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\IF0S7VRU\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\IFUQIXYH\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\IFUQIXYH\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\IUPMNTGS\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\IUPMNTGS\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\IWB3UM5M\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\IWB3UM5M\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\JLKKUBXK\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\JLKKUBXK\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\JZ8Y81Z9\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\JZ8Y81Z9\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\KQ0QCNWN\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\KQ0QCNWN\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\KROJEK0E\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\KROJEK0E\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\KZWS32XZ\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\KZWS32XZ\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\LAX5Y7HO\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\LAX5Y7HO\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\LKBJWAWL\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\LKBJWAWL\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\LMFWH32T\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\LMFWH32T\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\MLJZI02R\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\MLJZI02R\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\MSEXQ5KW\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\MSEXQ5KW\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\MTENUMYX\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\MTENUMYX\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\N86N4RYM\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\N86N4RYM\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\O6RU0M1A\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\O6RU0M1A\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\O9SG38FA\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\O9SG38FA\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\OHVN00UJ\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\OHVN00UJ\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\OMO1XSJ1\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\OMO1XSJ1\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\OTGX2QYK\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\OTGX2QYK\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\P1R4PIDF\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\P1R4PIDF\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\P4GFUJ64\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\P4GFUJ64\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\PCESLSDV\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\PCESLSDV\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\Q150BXZA\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\Q150BXZA\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\Q90YSHUK\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\Q90YSHUK\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\Q937OS6F\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\Q937OS6F\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\QK9CWBZN\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\QK9CWBZN\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\QTHET99T\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\QTHET99T\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\R69AMVGT\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\R69AMVGT\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\R8GKWUIJ\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\R8GKWUIJ\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\RH3FO939\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\RH3FO939\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\RTMQCOBW\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\RTMQCOBW\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\RU3Q2B3W\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\RU3Q2B3W\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\SBQHNWQ4\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\SBQHNWQ4\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\SN1CG27X\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\SN1CG27X\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\SO7WIKL9\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\SO7WIKL9\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\UMCMDK7T\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\UMCMDK7T\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\UR0T76H2\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\UR0T76H2\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\UVNY5XXB\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\UVNY5XXB\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\VAYFLY6L\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\VAYFLY6L\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\W044KZFX\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\W044KZFX\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\WADIE9OV\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\WADIE9OV\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\WAYP2ZS1\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\WAYP2ZS1\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\WJ37C8WJ\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\WJ37C8WJ\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\WKIFG1L5\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\WKIFG1L5\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\WUNKTWO5\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\WUNKTWO5\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\WWPRZF9W\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\WWPRZF9W\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\X2BNCS9H\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\X2BNCS9H\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\X6BA0CYH\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\X6BA0CYH\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\XSDK2LY8\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\XSDK2LY8\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\YBXQIUNF\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\YBXQIUNF\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\Z3CHCJAB\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\Z3CHCJAB\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\ZV732QLB\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\ZV732QLB\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Local\assembly\tmp\ZYL4CFDU\__AssemblyInfo__.ini
    C:\Users\angel\AppData\Local\assembly\tmp\ZYL4CFDU\AddinExpress.IE.DLL
    C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com
    C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\bootstrap.js
    C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\chrome.manifest
    C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\chrome\64ffxtbr.jar
    C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\install.rdf
    C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\META-INF\manifest.mf
    C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\META-INF\zigbert.rsa
    C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\META-INF\zigbert.sf
    C:\Windows\security\Database\tmp.edb
    C:\Windows\XSxS


    (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_FTSvc
    -------\Service_FTSvc


    (((((((((((((((((((((((((   Files Created from 2013-02-03 to 2013-03-03  )))))))))))))))))))))))))))))))


    2013-03-03 06:19:18 . 2013-03-03 06:24:33    --------    d-----w-    C:\Users\angel\AppData\Local\temp
    2013-02-27 00:04:51 . 2013-02-27 00:04:53    --------    d-----w-    C:\Program Files\CCleaner
    2013-02-25 05:05:25 . 2013-02-25 05:05:30    --------    d-----w-    C:\Program Files (x86)\Malwarebytes' Anti-Malware
    .


    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2013-02-08 00:28:29 . 2013-02-28 06:05:52    9162192    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F65BEF3D-4D06-4D66-83E5-4FA0633DBA9D}\mpengine.dll
    2013-01-17 09:28:58 . 2009-10-05 21:49:08    273840    ------w-    C:\Windows\system32\MpSigStub.exe
    2012-12-23 11:05:08 . 2006-11-02 12:35:00    67413224    ----a-w-    C:\Windows\system32\mrt.exe
    2012-12-16 13:31:20 . 2012-12-23 11:00:49    48128    ----a-w-    C:\Windows\system32\atmlib.dll
    2012-12-16 13:12:54 . 2012-12-23 11:00:49    34304    ----a-w-    C:\Windows\SysWow64\atmlib.dll
    2012-12-16 11:08:21 . 2012-12-23 11:00:49    368128    ----a-w-    C:\Windows\system32\atmfd.dll
    2012-12-16 10:50:29 . 2012-12-23 11:00:49    293376    ----a-w-    C:\Windows\SysWow64\atmfd.dll


    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))


    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{c54a4bc4-2966-40ac-9ca4-ad863d6148ee}"= "C:\Program Files (x86)\AmigoBar\tbAmi2.dll" [2010-10-18 10:26:36 3908192]
    "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll" [2012-06-11 19:08:00 1524056]
    "{f78bf7a8-cf12-4de7-a6da-c463d1b539a7}"= "C:\Program Files (x86)\Dogpile Bundle Toolbar\Helper.dll" [2012-03-17 18:03:25 378880]
    "{f92a9fe4-2850-4198-b9d5-279880e49b16}"= "C:\Program Files (x86)\A_Free_Ride_Games_Bar\prxtbA_Fr.dll" [2011-05-09 08:49:38 176936]

    [HKEY_CLASSES_ROOT\clsid\{c54a4bc4-2966-40ac-9ca4-ad863d6148ee}]

    [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
    [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
    [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
    [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]

    [HKEY_CLASSES_ROOT\clsid\{f78bf7a8-cf12-4de7-a6da-c463d1b539a7}]
    [HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
    [HKEY_CLASSES_ROOT\TypeLib\{C766F9AD-E91E-43DE-91DC-D007680ED4AF}]
    [HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]

    [HKEY_CLASSES_ROOT\clsid\{f92a9fe4-2850-4198-b9d5-279880e49b16}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{0bd6f992-62ad-47f7-aca6-299729be4e2b}]
    2009-05-12 21:41:02    91608    ----a-w-    C:\Program Files (x86)\myfreezetoolbar\myfreezedx.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}]
    2010-03-28 19:53:16    353656    ----a-w-    C:\Program Files (x86)\PriceGong\2.1.0\PriceGongIE.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{22e03916-85c5-44b0-8dc9-1830c11238d9}]
    2011-05-09 09:49:38    176936    ----a-w-    C:\Program Files (x86)\Elf_1\prxtbElf2.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
    2011-01-17 14:54:02    175912    ----a-w-    C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41403228-8910-4CA2-9939-DA9C9A6A58A7}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6a14e93a-dde3-4b64-8381-f3b68243d8f4}]
    2011-12-28 09:25:58    85288    ----a-w-    C:\Program Files (x86)\file2linkrh\file2linkibX.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{732e5459-a239-4e08-a411-2c6ccf313f1d}]
    2008-11-25 17:01:08    315392    ----a-w-    C:\Program Files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{83453B9B-B889-4659-9144-20F081542BDC}]
    2011-04-20 17:29:58    81920    ----a-w-    C:\Program Files (x86)\centurytoolbar\centurytoolbarDx.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{8769adce-dba5-48e9-afb5-67b12cdf2e61}]
    2012-05-18 19:44:32    85288    ----a-w-    C:\Program Files (x86)\blekkotb_031\blekkotb_019X.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{af6ac4f2-9825-4fb6-a600-92bc5361f209}]
    2011-12-22 07:44:06    87488    ----a-w-    C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{BFE4B5CB-63F7-4A51-9266-6167655D5B4F}]
    2012-03-17 18:03:25    1615360    ----a-w-    C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C26CD490-5F01-41E3-B150-EB29F19DA056}]
    2009-10-20 15:50:46    258008    ----a-w-    C:\Program Files (x86)\myfreezetoolbar\auxi\myfreezetoolbAu.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{c54a4bc4-2966-40ac-9ca4-ad863d6148ee}]
    2010-10-18 10:26:36    3908192    ----a-w-    C:\Program Files (x86)\AmigoBar\tbAmi2.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{CB0D163C-E9F4-4236-9496-0597E24B23A5}]
    2011-11-01 15:24:34    894616    ----a-w-    C:\Program Files (x86)\GamesBar\2.0.1.109\oberontb.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}]
    2008-11-27 02:40:20    253048    ----a-w-    C:\Program Files (x86)\My.Freeze.com Toolbar\NetAssistant.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{f92a9fe4-2850-4198-b9d5-279880e49b16}]
    2011-05-09 08:49:38    176936    ----a-w-    C:\Program Files (x86)\A_Free_Ride_Games_Bar\prxtbA_Fr.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
    2011-07-22 23:53:55    787744    ----a-w-    C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{0bd6f992-62ad-47f7-aca6-299729be4e2b}"= "C:\Program Files (x86)\myfreezetoolbar\myfreezedx.dll" [2009-05-12 21:41:02 91608]
    "{c54a4bc4-2966-40ac-9ca4-ad863d6148ee}"= "C:\Program Files (x86)\AmigoBar\tbAmi2.dll" [2010-10-18 10:26:36 3908192]
    "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll" [2011-01-17 14:54:02 175912]
    "{22e03916-85c5-44b0-8dc9-1830c11238d9}"= "C:\Program Files (x86)\Elf_1\prxtbElf2.dll" [2011-05-09 09:49:38 176936]
    "{6a14e93a-dde3-4b64-8381-f3b68243d8f4}"= "C:\Program Files (x86)\file2linkrh\file2linkibX.dll" [2011-12-28 09:25:58 85288]
    "{af6ac4f2-9825-4fb6-a600-92bc5361f209}"= "C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll" [2011-12-22 07:44:06 87488]
    "{C80BDEB2-8735-44C6-BD55-A1CCD555667A}"= "C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll" [2012-03-17 18:03:25 1615360]
    "{8769adce-dba5-48e9-afb5-67b12cdf2e61}"= "C:\Program Files (x86)\blekkotb_031\blekkotb_019X.dll" [2012-05-18 19:44:32 85288]
    "{f92a9fe4-2850-4198-b9d5-279880e49b16}"= "C:\Program Files (x86)\A_Free_Ride_Games_Bar\prxtbA_Fr.dll" [2011-05-09 08:49:38 176936]
    "{83453B9B-B889-4659-9144-20F081542BDC}"= "C:\Program Files (x86)\centurytoolbar\centurytoolbarDx.dll" [2011-04-20 17:29:58 81920]
    "{6F282B65-56BF-4BD1-A8B2-A4449A05863D}"= "C:\Program Files (x86)\GamesBar\2.0.1.109\oberontb.dll" [2011-11-01 15:24:34 894616]

    [HKEY_CLASSES_ROOT\clsid\{0bd6f992-62ad-47f7-aca6-299729be4e2b}]

    [HKEY_CLASSES_ROOT\clsid\{c54a4bc4-2966-40ac-9ca4-ad863d6148ee}]

    [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

    [HKEY_CLASSES_ROOT\clsid\{22e03916-85c5-44b0-8dc9-1830c11238d9}]

    [HKEY_CLASSES_ROOT\clsid\{6a14e93a-dde3-4b64-8381-f3b68243d8f4}]

    [HKEY_CLASSES_ROOT\clsid\{af6ac4f2-9825-4fb6-a600-92bc5361f209}]

    [HKEY_CLASSES_ROOT\clsid\{c80bdeb2-8735-44c6-bd55-a1ccd555667a}]
    [HKEY_CLASSES_ROOT\FCTB000060231.IEToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{CCBDEEA9-517A-4862-B0A1-862AE9532228}]
    [HKEY_CLASSES_ROOT\FCTB000060231.IEToolbar]

    [HKEY_CLASSES_ROOT\clsid\{8769adce-dba5-48e9-afb5-67b12cdf2e61}]

    [HKEY_CLASSES_ROOT\clsid\{f92a9fe4-2850-4198-b9d5-279880e49b16}]

    [HKEY_CLASSES_ROOT\clsid\{83453b9b-b889-4659-9144-20f081542bdc}]

    [HKEY_CLASSES_ROOT\clsid\{6f282b65-56bf-4bd1-a8b2-a4449a05863d}]
    [HKEY_CLASSES_ROOT\Oberontb.Band.1]
    [HKEY_CLASSES_ROOT\TypeLib\{AD76633E-E50D-4844-9E7F-4DFBC7C18467}]
    [HKEY_CLASSES_ROOT\Oberontb.Band]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Power2GoExpress"="NA" [X]
    "PhotoShow Deluxe Media Manager"="C:\PROGRA~2\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe" [2004-06-01 18:05:17 184320]
    "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-21 02:51:33 138240]
    "DW7"="C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe" [2012-06-02 21:23:40 10555904]
    "Exetender_179"="C:\Program Files (x86)\qZone Games Player\GPlayer.exe" [2010-12-05 23:57:42 4892672]
    "SearchEngineProtection"="C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe" [2011-11-01 15:24:46 616088]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Malwarebytes Anti-Malware (reboot)"="C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2011-09-01 01:00:48 1047208]
    "Conime"="C:\Windows\system32\conime.exe" [2009-04-11 06:27:28 69120]
    "ArcSoft Connection Service"="C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 03:17:52 207424]
    "IconixOEAddOn"="C:\Program Files (x86)\eMail ID\OEAddOn\OEdmn_6.exe" [2010-05-10 23:57:01 342872]
    "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-10-21 14:15:43 273528]
    "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 07:25:58 59240]
    "Anti-phishing Domain Advisor"="C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 18:07:40 217256]
    "YMailAdvisor"="C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 10:53:34 174424]
    "CenturyLinkTouchPointAgent"="C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe" [2011-12-02 17:31:49 46208]
    "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 07:37:53 843712]
    "Malwarebytes' Anti-Malware (reboot)"="C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2011-09-01 01:00:48 1047208]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}"="C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe" [2012-10-11 02:29:13 143928]

    C:\Users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    HP SimpleSave Monitor.lnk - C:\Users\angel\AppData\Roaming\HP SimpleSave Application\StartHelper.exe [2010-12-26 477080]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2010-6-12 1207312]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\syswow64\userinit.exe,"

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=C:\PROGRA~2\SEARCH~2\Datamngr\datamngr.dll C:\PROGRA~2\SEARCH~2\Datamngr\IEBHO.dll protector.dll
    "LoadAppInit_DLLs"=1 (0x1)

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute    REG_MULTI_SZ       autocheck autochk *\0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
    @="Service"

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - ECACHE

    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
    Themes

    Contents of the 'Scheduled Tasks' folder

    2013-02-28 C:\Windows\Tasks\Adobe Flash Player Updater.job
    - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-29 13:00:07 . 2012-07-17 15:10:41]

    2013-03-03 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-05 17:01:51 . 2010-02-05 17:01:43]

    2013-02-28 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-05 17:01:51 . 2010-02-05 17:01:43]

    2012-12-24 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-794020852-758203237-1877864742-1000Core.job
    - C:\Users\angel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 14:47:15 . 2012-02-01 22:09:34]

    2013-02-28 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-794020852-758203237-1877864742-1000UA.job
    - C:\Users\angel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 14:47:15 . 2012-02-01 22:09:34]

    2012-10-23 C:\Windows\Tasks\HPCeeScheduleForangel.job
    - C:\Program Files (x86)\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2008-08-28 18:52:15 . 2007-12-18 03:03:48]

    2013-03-03 C:\Windows\Tasks\RegistryBooster.job
    - C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe [2011-12-06 16:52:29 . 2011-11-07 08:26:14]


    --------- X64 Entries -----------


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-22 14:49:00 15851040]
    "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-22 14:49:00 82464]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 16:53:26 130576]
    "EKIJ5000StatusMonitor"="C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2010-09-02 15:37:46 2045440]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=c:\PROGRA~2\SEARCH~2\Datamngr\x64\IEBHO.dll

    ------- Supplementary Scan -------

    uLocal Page = C:\Windows\system32\blank.htm
    uStart Page = hxxp://www.mycenturylink.com/
    mStart Page = hxxp://www.yahoo.com/?ilc=8
    mDefault_Page_URL = hxxp://www.yahoo.com/?ilc=8
    mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    mLocal Page = C:\Windows\SysWOW64\blank.htm
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = <local>;*.local
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant =
    IE: &Windows Live Search - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: {{14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - C:\Program Files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
    IE: {{1A93C934-025B-4c3a-B38E-9654A7003239} - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files (x86)\GamesBar\2.0.1.109\oberontb.dll
    Trusted Zone: hp.com\pavilion.buttonredirect
    Trusted Zone: hp.com\presario.buttonredirect
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    TCP: DhcpNameServer = 192.168.2.1
    FF - ProfilePath - C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.mycenturylink.com/
    FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3222437&SearchSource=2&q=
    FF - ExtSQL: !HIDDEN! 1970-01-16 04:44; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; C:\Program Files (x86)\Searchqu Toolbar\Datamngr\FirefoxExtension
    FF - ExtSQL: !HIDDEN! 2009-06-24 11:45; {20a82645-c095-46ed-80e3-08825760534b}; c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - ExtSQL: !HIDDEN! 2012-07-19 05:44; 64ffxtbr@TelevisionFanatic.com; C:\Program Files (x86)\TelevisionFanatic\bar\1.bin

    - - - - ORPHANS REMOVED - - - -

    URLSearchHooks-{313a832a-aaf3-4880-a8d0-c42bee319c02} - (no file)
    URLSearchHooks-{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - (no file)
    BHO-{26D675AC-D925-4bbf-A720-62C2AA4A81EB} - (no file)
    BHO-{5d79f641-c168-40df-a32f-bacea7509e75} - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64SrcAs.dll
    BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
    BHO-{7FF99715-3016-4381-84CE-E4E4C9673020} - (no file)
    BHO-{8A86D350-37AB-410A-8531-7D1363F317B3} - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll
    BHO-{9F531FB1-7C1F-4e1a-8C0C-E8D6177130E2} - (no file)
    BHO-{cb41fc95-f1b3-4797-8bb6-1012ff62abba} - C:\PROGRA~2\TELEVI~2\bar\1.bin\64bar.dll
    BHO-{CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
    BHO-{EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7} - C:\Program Files (x86)\RegTweaker\key.dll
    Toolbar-{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - (no file)
    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    Toolbar-{7FF99715-3016-4381-84CE-E4E4C9673020} - (no file)
    Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
    Toolbar-{c98d5b61-b0ea-4d48-9839-1079d352d880} - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64bar.dll
    Toolbar-10 - (no file)
    ShellIconOverlayIdentifiers-{04cd1f3e-81d5-4904-a3ab-e0f99a7d769d} - (no file)
    Wow6432Node-HKLM-Run-facemoods - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe
    Wow6432Node-HKLM-Run-TelevisionFanatic Search Scope Monitor - C:\PROGRA~2\TELEVI~2\bar\1.bin\64srchmn.exe
    SafeBoot-WudfPf
    SafeBoot-WudfRd
    Toolbar-10 - (no file)
    WebBrowser-{C54A4BC4-2966-40AC-9CA4-AD863D6148EE} - (no file)
    WebBrowser-{313A832A-AAF3-4880-A8D0-C42BEE319C02} - (no file)
    WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
    WebBrowser-{22E03916-85C5-44B0-8DC9-1830C11238D9} - (no file)
    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    WebBrowser-{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - (no file)
    WebBrowser-{C80BDEB2-8735-44C6-BD55-A1CCD555667A} - (no file)
    WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
    ShellIconOverlayIdentifiers-{04cd1f3e-81d5-4904-a3ab-e0f99a7d769d} - (no file)
    AddRemove-BFG-Pirate Mysteries - A Tale of Monkeys, Masks, and Hidden Objects - C:\Program Files (x86)\Pirate Mysteries - A Tale of Monkeys
    AddRemove-facemoods - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\uninstall.exe
    AddRemove-Shockwave - C:\Windows\System32\Macromed\SHOCKW~1\UNWISE.EXE
    AddRemove-blinkx beat - C:\Program Files (x86)\Blinkx\templates\uninstall.exe
    AddRemove-FoxTab Media Player - C:\Program Files (x86)\FoxTabFLVPlayer\Uninstall\Uninstall.exe


    SecurityCheck Log

     

     Results of screen317's Security Check version 0.99.60  
     Windows Vista Service Pack 2 x64 (UAC is enabled)  
     Internet Explorer 9  
    ``````````````Antivirus/Firewall Check:``````````````
     Windows Security Center service is not running! This report may not be accurate!
    AVG Anti-Virus 2012   
     Antivirus out of date! (On Access scanning disabled!)
    `````````Anti-malware/Other Utilities Check:`````````
     CA Yahoo! Anti-Spy (remove only)
     Spyware Terminator    
     JavaFX 2.1.1    
     Java™ 6 Update 31  
     Java™ 7 Update 5  
     Java™ SE Runtime Environment 6 Update 1
     Java version out of Date!
     Adobe Flash Player     11.3.300.265  
     Adobe Reader 10.1.3 Adobe Reader out of Date!  
     Mozilla Firefox 14.0.1 Firefox out of Date!  
     Google Chrome 20.0.1132.57  
     Google Chrome 21.0.1180.89  
     Google Chrome 22.0.1229.94  
    ````````Process Check: objlist.exe by Laurent````````  
    `````````````````System Health check`````````````````
     Total Fragmentation on Drive C: 3 % Defragment your hard drive soon! (Do NOT defrag if SSD!)
    ````````````````````End of Log``````````````````````
     

     

    AdwCleaner[R1] Log - before deleting

     

    # AdwCleaner v2.113 - Logfile created 03/02/2013 at 22:45:42
    # Updated 23/02/2013 by Xplode
    # Operating system : Windows ™ Vista Home Premium Service Pack 2 (64 bits)
    # User : angel - ANGEL-PC
    # Boot Mode : Safe mode
    # Running from : C:\Users\angel\Desktop\adwcleaner.exe
    # Option [Search]


    ***** [Services] *****

    Found : IBUpdaterService

    ***** [Files / Folders] *****

    File Found : C:\Program Files (x86)\Mozilla FireFox\searchplugins\Search_Results.xml
    File Found : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\searchplugins\Conduit.xml
    File Found : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\searchplugins\mywebsearch.xml
    File Found : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\searchplugins\Search_Results.xml
    File Found : C:\Users\angel\Desktop\Free Dolphin Screensaver.lnk
    File Found : C:\Users\Public\Desktop\iLivid.lnk
    File Found : C:\Windows\SysWOW64\conduitEngine.tmp
    Folder Found : C:\Program Files (x86)\A_Free_Ride_Games_Bar
    Folder Found : C:\Program Files (x86)\AmigoBar
    Folder Found : C:\Program Files (x86)\centurytoolbar
    Folder Found : C:\Program Files (x86)\Conduit
    Folder Found : C:\Program Files (x86)\ConduitEngine
    Folder Found : C:\Program Files (x86)\Crawler
    Folder Found : C:\Program Files (x86)\Dogpile Bundle Toolbar
    Folder Found : C:\Program Files (x86)\Elf_1
    Folder Found : C:\Program Files (x86)\Free Offers from Freeze.com
    Folder Found : C:\Program Files (x86)\Freeze.com
    Folder Found : C:\Program Files (x86)\GamesBar
    Folder Found : C:\Program Files (x86)\Ilivid
    Folder Found : C:\Program Files (x86)\Inbox
    Folder Found : C:\Program Files (x86)\Inbox Toolbar
    Folder Found : C:\Program Files (x86)\PriceGong
    Folder Found : C:\Program Files (x86)\searchcore toolbar
    Folder Found : C:\Program Files (x86)\Searchqu Toolbar
    Folder Found : C:\Program Files (x86)\Yontoo Layers Runtime
    Folder Found : C:\Program Files\Fast Browser Search
    Folder Found : C:\Program Files\SGPSA
    Folder Found : C:\ProgramData\Anti-phishing Domain Advisor
    Folder Found : C:\ProgramData\Bandoo
    Folder Found : C:\ProgramData\blekko toolbars
    Folder Found : C:\ProgramData\boost_interprocess
    Folder Found : C:\ProgramData\GamesBar
    Folder Found : C:\ProgramData\IBUpdaterService
    Folder Found : C:\ProgramData\Iminent
    Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freeze.com
    Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GamesBar
    Folder Found : C:\ProgramData\Tarma Installer
    Folder Found : C:\ProgramData\Trymedia
    Folder Found : C:\Users\angel\AppData\Local\APN
    Folder Found : C:\Users\angel\AppData\Local\Conduit
    Folder Found : C:\Users\angel\AppData\Local\Ilivid Player
    Folder Found : C:\Users\angel\AppData\Local\TempDir
    Folder Found : C:\Users\angel\AppData\LocalLow\A_Free_Ride_Games_Bar
    Folder Found : C:\Users\angel\AppData\LocalLow\AmigoBar
    Folder Found : C:\Users\angel\AppData\LocalLow\AVG Security Toolbar
    Folder Found : C:\Users\angel\AppData\LocalLow\Bandoo
    Folder Found : C:\Users\angel\AppData\LocalLow\centurytoolbar
    Folder Found : C:\Users\angel\AppData\LocalLow\Conduit
    Folder Found : C:\Users\angel\AppData\LocalLow\ConduitEngine
    Folder Found : C:\Users\angel\AppData\LocalLow\Elf_1
    Folder Found : C:\Users\angel\AppData\LocalLow\facemoods.com
    Folder Found : C:\Users\angel\AppData\LocalLow\FunWebProducts
    Folder Found : C:\Users\angel\AppData\LocalLow\MyWebSearch
    Folder Found : C:\Users\angel\AppData\LocalLow\PriceGong
    Folder Found : C:\Users\angel\AppData\LocalLow\ShoppingReport
    Folder Found : C:\Users\angel\AppData\LocalLow\Toolbar4
    Folder Found : C:\Users\angel\AppData\Roaming\Bandoo
    Folder Found : C:\Users\angel\AppData\Roaming\Filesubmit
    Folder Found : C:\Users\angel\AppData\Roaming\Inbox Toolbar
    Folder Found : C:\Users\angel\AppData\Roaming\iWin
    Folder Found : C:\Users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dogpile Bundle Toolbar
    Folder Found : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\1opnxdf1.default\extensions\64ffxtbr@TelevisionFanatic.com
    Folder Found : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\centurytoolbar
    Folder Found : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\ConduitCommon
    Folder Found : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\{1fd91a9c-410c-4090-bbcc-55d3450ef433}
    Folder Found : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\{83453B9B-B889-4659-9144-20F081542BDC}
    Folder Found : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\{f92a9fe4-2850-4198-b9d5-279880e49b16}

    ***** [Registry] *****

    Data Found : HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~2\Datamngr\datamngr.dll
    Data Found : HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~2\Datamngr\IEBHO.dll
    Key Found : HKCU\Software\AppDataLow\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
    Key Found : HKCU\Software\AppDataLow\Software\A_Free_Ride_Games_Bar
    Key Found : HKCU\Software\AppDataLow\Software\AmigoBar
    Key Found : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
    Key Found : HKCU\Software\AppDataLow\Software\Conduit
    Key Found : HKCU\Software\AppDataLow\Software\conduitEngine
    Key Found : HKCU\Software\AppDataLow\Software\conduitEngine
    Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
    Key Found : HKCU\Software\AppDataLow\Software\CouponAlert_2p
    Key Found : HKCU\Software\AppDataLow\Software\Elf_1
    Key Found : HKCU\Software\AppDataLow\Software\Fun Web Products
    Key Found : HKCU\Software\AppDataLow\Software\FunWebProducts
    Key Found : HKCU\Software\AppDataLow\Software\iWon
    Key Found : HKCU\Software\AppDataLow\Software\MyWebSearch
    Key Found : HKCU\Software\AppDataLow\Software\PriceGong
    Key Found : HKCU\Software\AppDataLow\Software\searchqutb
    Key Found : HKCU\Software\AppDataLow\Software\SmartBar
    Key Found : HKCU\Software\AppDataLow\Toolbar
    Key Found : HKCU\Software\bProtector
    Key Found : HKCU\Software\CToolbar
    Key Found : HKCU\Software\facemoods.com
    Key Found : HKCU\Software\Freeze.com
    Key Found : HKCU\Software\IGearSettings
    Key Found : HKCU\Software\ilivid
    Key Found : HKCU\Software\IM
    Key Found : HKCU\Software\Iminent
    Key Found : HKCU\Software\ImInstaller
    Key Found : HKCU\Software\InstallCore
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\A_Free_Ride_Games_Bar Toolbar
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AmigoBar Toolbar
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Anti-phishing Domain Advisor
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Elf_1 Toolbar
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\facemoods
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilivid
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\mywebsearch bar uninstall
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PriceGong
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Searchqu Toolbar
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Updater Service
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Searchcore Toolbar
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{22E03916-85C5-44B0-8DC9-1830C11238D9}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BFE4B5CB-63F7-4A51-9266-6167655D5B4F}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C80BDEB2-8735-44C6-BD55-A1CCD555667A}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F92A9FE4-2850-4198-B9D5-279880E49B16}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{046C4B86-AAD7-4188-B51E-E69B736989C9}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{05DDD334-AA5F-4CA8-9CC0-D37C34A507FE}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D110574-046A-43BB-A64C-4219E6A097DA}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{22E03916-85C5-44B0-8DC9-1830C11238D9}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BFE4B5CB-63F7-4A51-9266-6167655D5B4F}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C80BDEB2-8735-44C6-BD55-A1CCD555667A}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB35C569-5624-4CFC-8043-E5139F55A073}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F92A9FE4-2850-4198-B9D5-279880E49B16}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43B7-BEA3-87217BDA74C8}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8B63A8D6-BBED-4341-8867-790E5F524C96}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
    Key Found : HKLM\Software\A_Free_Ride_Games_Bar
    Key Found : HKLM\Software\AmigoBar
    Key Found : HKLM\Software\AVG Security Toolbar
    Key Found : HKLM\Software\Bandoo
    Key Found : HKLM\SOFTWARE\Classes\AppID\{055069F3-F78B-4BD1-A277-FE66648D3300}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
    Key Found : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE
    Key Found : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
    Key Found : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll
    Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
    Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
    Key Found : HKLM\SOFTWARE\Classes\AppID\PriceGongIE.DLL
    Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
    Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
    Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore
    Key Found : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1
    Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr
    Key Found : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1
    Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr
    Key Found : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1
    Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr
    Key Found : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1
    Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
    Key Found : HKLM\SOFTWARE\Classes\CShared.TB4Client
    Key Found : HKLM\SOFTWARE\Classes\CShared.TB4Script
    Key Found : HKLM\SOFTWARE\Classes\CShared.TB4Server
    Key Found : HKLM\SOFTWARE\Classes\CShared.TB4Server2
    Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
    Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
    Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
    Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl
    Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
    Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
    Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
    Key Found : HKLM\SOFTWARE\Classes\FCTB000060231.FCTB000060231Pos
    Key Found : HKLM\SOFTWARE\Classes\FCTB000060231.FCTB000060231Pos.1
    Key Found : HKLM\SOFTWARE\Classes\FCTB000060231.IEToolbar
    Key Found : HKLM\SOFTWARE\Classes\FCTB000060231.IEToolbar.1
    Key Found : HKLM\SOFTWARE\Classes\FCTB000060231.JSOptionsImpl
    Key Found : HKLM\SOFTWARE\Classes\FCTB000060231.JSOptionsImpl.1
    Key Found : HKLM\SOFTWARE\Classes\FreeCauseURLSearchHook.FCToolbarURLSearchHook
    Key Found : HKLM\SOFTWARE\Classes\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1
    Key Found : HKLM\SOFTWARE\Classes\ilivid
    Key Found : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
    Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
    Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
    Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1320680
    Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2421531
    Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2856415
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
    Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api
    Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
    Key Found : HKLM\Software\Conduit
    Key Found : HKLM\Software\conduitEngine
    Key Found : HKLM\Software\conduitEngine
    Key Found : HKLM\Software\CToolbar
    Key Found : HKLM\Software\DataMngr
    Key Found : HKLM\Software\Elf_1
    Key Found : HKLM\Software\facemoods.com
    Key Found : HKLM\Software\Freeze.com
    Key Found : HKLM\Software\GamesBarSetup
    Key Found : HKLM\Software\ilivid
    Key Found : HKLM\Software\Iminent
    Key Found : HKLM\Software\ImInstaller
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{1A93C934-025B-4C3A-B38E-9654A7003239}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{046C4B86-AAD7-4188-B51E-E69B736989C9}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{04D2B915-19FF-41E9-994D-95DC898BEA43}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{05DDD334-AA5F-4CA8-9CC0-D37C34A507FE}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D110574-046A-43BB-A64C-4219E6A097DA}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8867AC9B-4426-44A2-A693-C95850D3405C}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F02C0832-C85C-4B93-8C6F-9DF20121A10D}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\72fe24ac3f81ced2107a1b2b8f23524c
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\e31cb9e6d5ac1eda0528e6a649b0012e
    Key Found : HKLM\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin
    Key Found : HKLM\Software\SearchcoreMediabarTb
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{046C4B86-AAD7-4188-B51E-E69B736989C9}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{04D2B915-19FF-41E9-994D-95DC898BEA43}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{05DDD334-AA5F-4CA8-9CC0-D37C34A507FE}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1D110574-046A-43BB-A64C-4219E6A097DA}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{22E03916-85C5-44B0-8DC9-1830C11238D9}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5D79F641-C168-40DF-A32F-BACEA7509E75}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{91C18ED5-5E1C-4AE5-A148-A861DE8C8E16}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AF6AC4F2-9825-4FB6-A600-92BC5361F209}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BFE4B5CB-63F7-4A51-9266-6167655D5B4F}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C80BDEB2-8735-44C6-BD55-A1CCD555667A}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C98D5B61-B0EA-4D48-9839-1079D352D880}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DB35C569-5624-4CFC-8043-E5139F55A073}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F02C0832-C85C-4B93-8C6F-9DF20121A10D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F78BF7A8-CF12-4DE7-A6DA-C463D1B539A7}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F92A9FE4-2850-4198-B9D5-279880E49B16}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23119123-0854-469D-807A-171568457991}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
    Key Found : HKLM\SOFTWARE\Wow6432Node\FCTB000060231
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16FE2505-F2A0-4782-B035-AF0E5188C02C}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1791C1B5-FFD0-4D4B-ABCD-7A7DF6EAA89C}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2AF08E71-3657-462F-898C-F7E791948F94}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56965DCF-718F-4148-BECF-5A2B466F4556}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F99D2AE-5C90-43C2-A2FE-81DBE512E2FC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7225F6C9-CF64-4D6D-AE8A-169779FD7B4D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7746796B-6F44-4984-8A05-56B7EB72C18A}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{988AE641-451D-4E5D-AA7C-47591606ED1B}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF6AC4F2-9825-4FB6-A600-92BC5361F209}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B288D7F1-EFFA-40B9-BC91-2FE6F8E93CEE}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B30A1A29-E7BB-4AB8-9E2A-67E1892A2052}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA3E7798-2690-440F-B7F8-A00A3013DBA3}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CB36F0E0-717C-4927-BBC7-F6A521B7BECD}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22E03916-85C5-44B0-8DC9-1830C11238D9}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5D79F641-C168-40DF-A32F-BACEA7509E75}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7FF99715-3016-4381-84CE-E4E4C9673020}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF6AC4F2-9825-4FB6-A600-92BC5361F209}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BFE4B5CB-63F7-4A51-9266-6167655D5B4F}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F92A9FE4-2850-4198-B9D5-279880E49B16}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\A_Free_Ride_Games_Bar Toolbar
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AmigoBar Toolbar
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Anti-phishing Domain Advisor
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Elf_1 Toolbar
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\facemoods
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PriceGong
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Searchcore Toolbar
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43B7-BEA3-87217BDA74C8}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{8B63A8D6-BBED-4341-8867-790E5F524C96}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
    Key Found : HKU\S-1-5-21-794020852-758203237-1877864742-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{22E03916-85C5-44B0-8DC9-1830C11238D9}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C80BDEB2-8735-44C6-BD55-A1CCD555667A}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{F78BF7A8-CF12-4DE7-A6DA-C463D1B539A7}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{F92A9FE4-2850-4198-B9D5-279880E49B16}]
    Value Found : HKCU\Software\Mozilla\Firefox\Extensions [{8a9386b4-e958-4c4c-adf4-8f26db3e4829}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{22E03916-85C5-44B0-8DC9-1830C11238D9}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{F92A9FE4-2850-4198-B9D5-279880E49B16}]
    Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Anti-phishing Domain Advisor]
    Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr]
    Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [facemoods]
    Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [m3ffxtbr@mywebsearch.com]
    Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [webbooster@iminent.com]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{22E03916-85C5-44B0-8DC9-1830C11238D9}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7FF99715-3016-4381-84CE-E4E4C9673020}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{83453B9B-B889-4659-9144-20F081542BDC}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AF6AC4F2-9825-4FB6-A600-92BC5361F209}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{C80BDEB2-8735-44C6-BD55-A1CCD555667A}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{C98D5B61-B0EA-4D48-9839-1079D352D880}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{F92A9FE4-2850-4198-B9D5-279880E49B16}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v9.0.8112.16457

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - bProtector Start Page] = hxxp://www.goonsearch.com/?source=RH-IB-PDP-VIS-HP

    -\\ Mozilla Firefox v14.0.1 (en-US)

    File : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\prefs.js

    Found : user_pref("CT1320680..clientLogIsEnabled", false);
    Found : user_pref("CT1320680..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
    Found : user_pref("CT1320680..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
    Found : user_pref("CT1320680.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
    Found : user_pref("CT1320680.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
    Found : user_pref("CT1320680.BrowserCompStateIsOpen_5295060317045962640", true);
    Found : user_pref("CT1320680.BrowserCompStateIsOpen_6103217173235939216", true);
    Found : user_pref("CT1320680.CTID", "CT1320680");
    Found : user_pref("CT1320680.CurrentServerDate", "26-7-2012");
    Found : user_pref("CT1320680.DSInstall", true);
    Found : user_pref("CT1320680.DialogsAlignMode", "LTR");
    Found : user_pref("CT1320680.DialogsGetterLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standa[...]
    Found : user_pref("CT1320680.DownloadReferralCookieData", "");
    Found : user_pref("CT1320680.FirstServerDate", "5-7-2012");
    Found : user_pref("CT1320680.FirstTime", true);
    Found : user_pref("CT1320680.FirstTimeFF3", true);
    Found : user_pref("CT1320680.FirstTimeHiddenVer", true);
    Found : user_pref("CT1320680.FixPageNotFoundErrors", true);
    Found : user_pref("CT1320680.GroupingServerCheckInterval", 1440);
    Found : user_pref("CT1320680.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
    Found : user_pref("CT1320680.HPInstall", true);
    Found : user_pref("CT1320680.HPProtectChoice", true);
    Found : user_pref("CT1320680.HPProtectCount", 1);
    Found : user_pref("CT1320680.HasUserGlobalKeys", true);
    Found : user_pref("CT1320680.HomePageProtectorEnabled", false);
    Found : user_pref("CT1320680.HomepageBeforeUnload", "hxxp://www.mycenturylink.com/");
    Found : user_pref("CT1320680.Initialize", true);
    Found : user_pref("CT1320680.InitializeCommonPrefs", true);
    Found : user_pref("CT1320680.InstallationAndCookieDataSentCount", 3);
    Found : user_pref("CT1320680.InstallationType", "Unknown");
    Found : user_pref("CT1320680.InstalledDate", "Thu Jul 05 2012 07:09:20 GMT-0700 (Pacific Daylight Time)");
    Found : user_pref("CT1320680.IsAlertDBUpdated", true);
    Found : user_pref("CT1320680.IsGrouping", false);
    Found : user_pref("CT1320680.IsInitSetupIni", true);
    Found : user_pref("CT1320680.IsMulticommunity", false);
    Found : user_pref("CT1320680.IsOpenThankYouPage", false);
    Found : user_pref("CT1320680.IsOpenUninstallPage", true);
    Found : user_pref("CT1320680.IsProtectorsInit", true);
    Found : user_pref("CT1320680.LanguagePackLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standar[...]
    Found : user_pref("CT1320680.LanguagePackReloadIntervalMM", 1440);
    Found : user_pref("CT1320680.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
    Found : user_pref("CT1320680.LastLogin_3.13.0.6", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standard Time)[...]
    Found : user_pref("CT1320680.LatestVersion", "3.13.0.6");
    Found : user_pref("CT1320680.Locale", "en");
    Found : user_pref("CT1320680.MCDetectTooltipHeight", "83");
    Found : user_pref("CT1320680.MCDetectTooltipShow", false);
    Found : user_pref("CT1320680.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
    Found : user_pref("CT1320680.MCDetectTooltipWidth", "295");
    Found : user_pref("CT1320680.MyStuffEnabledAtInstallation", true);
    Found : user_pref("CT1320680.OriginalFirstVersion", "3.13.0.6");
    Found : user_pref("CT1320680.SHRINK_TOOLBAR", 1);
    Found : user_pref("CT1320680.SavedHomepage", "hxxp://www.yahoo.com/");
    Found : user_pref("CT1320680.SearchCaption", "A Free Ride Games Bar Customized Web Search");
    Found : user_pref("CT1320680.SearchEngineBeforeUnload", "Google");
    Found : user_pref("CT1320680.SearchFromAddressBarIsInit", true);
    Found : user_pref("CT1320680.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT322[...]
    Found : user_pref("CT1320680.SearchInNewTabEnabled", true);
    Found : user_pref("CT1320680.SearchInNewTabIntervalMM", 1440);
    Found : user_pref("CT1320680.SearchInNewTabLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Stand[...]
    Found : user_pref("CT1320680.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
    Found : user_pref("CT1320680.SearchInNewTabUserEnabled", false);
    Found : user_pref("CT1320680.SearchProtectorEnabled", true);
    Found : user_pref("CT1320680.SearchProtectorToolbarDisabled", false);
    Found : user_pref("CT1320680.SendProtectorDataViaLogin", true);
    Found : user_pref("CT1320680.ServiceMapLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standard [...]
    Found : user_pref("CT1320680.SettingsLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standard Ti[...]
    Found : user_pref("CT1320680.SettingsLastUpdate", "1339926577");
    Found : user_pref("CT1320680.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3222437&SearchSource=13");
    Found : user_pref("CT1320680.ThirdPartyComponentsInterval", 504);
    Found : user_pref("CT1320680.ThirdPartyComponentsLastCheck", "Thu Jul 05 2012 07:09:15 GMT-0700 (Pacific Day[...]
    Found : user_pref("CT1320680.ThirdPartyComponentsLastUpdate", "1331805997");
    Found : user_pref("CT1320680.ToolbarShrinkedFromSetup", false);
    Found : user_pref("CT1320680.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3222437");
    Found : user_pref("CT1320680.UserID", "UN31167979688839625");
    Found : user_pref("CT1320680.ValidationData_Search", 1);
    Found : user_pref("CT1320680.ValidationData_Toolbar", 2);
    Found : user_pref("CT1320680.alertChannelId", "1652210");
    Found : user_pref("CT1320680.approveUntrustedApps", false);
    Found : user_pref("CT1320680.backendstorage.cbcountry_001", "5553");
    Found : user_pref("CT1320680.backendstorage.cbfirsttime", "546875204A756C20303520323031322030373A30393A32382[...]
    Found : user_pref("CT1320680.backendstorage.hxxp://api15_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Found : user_pref("CT1320680.backendstorage.hxxp://api18_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Found : user_pref("CT1320680.backendstorage.hxxp://api21_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Found : user_pref("CT1320680.backendstorage.hxxp://api28_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Found : user_pref("CT1320680.backendstorage.hxxp://api32_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Found : user_pref("CT1320680.backendstorage.printitgreenstatus", "74727565");
    Found : user_pref("CT1320680.backendstorage.shoppingapp.gk.exipres", "4D6F6E204A756C20333020323031322031333A[...]
    Found : user_pref("CT1320680.backendstorage.shoppingapp.gk.geolocation", "756E6974656420737461746573");
    Found : user_pref("CT1320680.backendstorage.url_history0001", "687474703A2F2F7777772E796F75747562652E636F6D2[...]
    Found : user_pref("CT1320680.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
    Found : user_pref("CT1320680.globalFirstTimeInfoLastCheckTime", "Thu Jul 26 2012 07:07:33 GMT-0700 (Pacific [...]
    Found : user_pref("CT1320680.homepageProtectorEnableByLogin", true);
    Found : user_pref("CT1320680.initDone", true);
    Found : user_pref("CT1320680.isAppTrackingManagerOn", true);
    Found : user_pref("CT1320680.myStuffEnabled", true);
    Found : user_pref("CT1320680.myStuffPublihserMinWidth", 400);
    Found : user_pref("CT1320680.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
    Found : user_pref("CT1320680.myStuffServiceIntervalMM", 1440);
    Found : user_pref("CT1320680.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
    Found : user_pref("CT1320680.navigateToUrlOnSearch", false);
    Found : user_pref("CT1320680.oldAppsList", "129819884490310076,129819884492028827,111,129819884492810078,129[...]
    Found : user_pref("CT1320680.revertSettingsEnabled", false);
    Found : user_pref("CT1320680.searchProtectorDialogDelayInSec", 10);
    Found : user_pref("CT1320680.searchProtectorEnableByLogin", true);
    Found : user_pref("CT1320680.testingCtid", "CT3222437");
    Found : user_pref("CT1320680.toolbarAppMetaDataLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific S[...]
    Found : user_pref("CT1320680.toolbarContextMenuLastCheckTime", "Thu Jul 26 2012 07:07:34 GMT-0700 (Pacific D[...]
    Found : user_pref("CT1320680.usagesFlag", 2);
    Found : user_pref("CT3222437.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
    Found : user_pref("CT3222437.autoDisableScopes", -1);
    Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3222437&Search[...]
    Found : user_pref("CommunityToolbar.ConduitSearchList", "A Free Ride Games Bar Customized Web Search");
    Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3222437/CT3222437[...]
    Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3222437", [...]
    Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
    Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
    Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
    Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
    Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
    Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
    Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3222437",[...]
    Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"3b6[...]
    Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\angel\\AppData\\Roaming\\Mozilla\\F[...]
    Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6");
    Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.yahoo.com/search?ei=UTF-8&[...]
    Found : user_pref("CommunityToolbar.ToolbarsList", "CT1320680");
    Found : user_pref("CommunityToolbar.ToolbarsList2", "CT1320680");
    Found : user_pref("CommunityToolbar.ToolbarsList4", "CT1320680");
    Found : user_pref("CommunityToolbar.globalUserId", "447d4972-6725-4b44-91ec-8bf1aa954213");
    Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
    Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
    Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT1320680");
    Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Jul 25 2012 13:47:4[...]
    Found : user_pref("CommunityToolbar.notifications.alertEnabled", false);
    Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
    Found : user_pref("CommunityToolbar.notifications.locale", "en");
    Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
    Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Jul 25 2012 13:47:46 GMT-0700 (P[...]
    Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
    Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
    Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
    Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
    Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
    Found : user_pref("CommunityToolbar.notifications.userId", "db031f84-d60f-4e81-a688-d6bdbff4a136");
    Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.yahoo.com/");
    Found : user_pref("CommunityToolbar.originalSearchEngine", "Google");
    Found : user_pref("browser.search.defaultthis.engineName", "A Free Ride Games Bar Customized Web Search");
    Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&Sea[...]
    Found : user_pref("extensions.toolbar.mindspark._64Members_.homepage", "hxxp://home.mywebsearch.com/index.jh[...]
    Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3222437&SearchSource=2&q=[...]

    -\\ Google Chrome v22.0.1229.94

    File : C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Preferences

    Found [l.20] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/406" ]
    Found [l.77] : search_url = "hxxp://dts.search-results.com/sr?src=crb&appid=394&systemid=406&sr=0&q={searchTerms}",
    Found [l.1652] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/406" ]

    *************************

    AdwCleaner[R1].txt - [64047 octets] - [02/03/2013 22:45:42]

    ########## EOF - C:\AdwCleaner[R1].txt - [64108 octets] ##########
     

     

    AdwCleaner[S1] Log - after deleting

     

    # AdwCleaner v2.113 - Logfile created 03/02/2013 at 22:47:18
    # Updated 23/02/2013 by Xplode
    # Operating system : Windows ™ Vista Home Premium Service Pack 2 (64 bits)
    # User : angel - ANGEL-PC
    # Boot Mode : Safe mode
    # Running from : C:\Users\angel\Desktop\adwcleaner.exe
    # Option [Delete]


    ***** [Services] *****

    Stopped & Deleted : IBUpdaterService

    ***** [Files / Folders] *****

    Deleted on reboot : C:\Program Files (x86)\A_Free_Ride_Games_Bar
    Deleted on reboot : C:\Program Files (x86)\AmigoBar
    Deleted on reboot : C:\Program Files (x86)\centurytoolbar
    Deleted on reboot : C:\Program Files (x86)\Conduit
    Deleted on reboot : C:\Program Files (x86)\ConduitEngine
    Deleted on reboot : C:\Program Files (x86)\Crawler
    Deleted on reboot : C:\Program Files (x86)\Dogpile Bundle Toolbar
    Deleted on reboot : C:\Program Files (x86)\Elf_1
    Deleted on reboot : C:\Program Files (x86)\Free Offers from Freeze.com
    Deleted on reboot : C:\Program Files (x86)\Freeze.com
    Deleted on reboot : C:\Program Files (x86)\GamesBar
    Deleted on reboot : C:\Program Files (x86)\Ilivid
    Deleted on reboot : C:\Program Files (x86)\Inbox
    Deleted on reboot : C:\Program Files (x86)\Inbox Toolbar
    Deleted on reboot : C:\Program Files (x86)\PriceGong
    Deleted on reboot : C:\Program Files (x86)\searchcore toolbar
    Deleted on reboot : C:\Program Files (x86)\Searchqu Toolbar
    Deleted on reboot : C:\Program Files (x86)\Yontoo Layers Runtime
    Deleted on reboot : C:\Program Files\Fast Browser Search
    Deleted on reboot : C:\Program Files\SGPSA
    Deleted on reboot : C:\ProgramData\Anti-phishing Domain Advisor
    Deleted on reboot : C:\ProgramData\Bandoo
    Deleted on reboot : C:\ProgramData\blekko toolbars
    Deleted on reboot : C:\ProgramData\boost_interprocess
    Deleted on reboot : C:\ProgramData\GamesBar
    Deleted on reboot : C:\ProgramData\IBUpdaterService
    Deleted on reboot : C:\ProgramData\Iminent
    Deleted on reboot : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freeze.com
    Deleted on reboot : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GamesBar
    Deleted on reboot : C:\ProgramData\Tarma Installer
    Deleted on reboot : C:\ProgramData\Trymedia
    Deleted on reboot : C:\Users\angel\AppData\Local\APN
    Deleted on reboot : C:\Users\angel\AppData\Local\Conduit
    Deleted on reboot : C:\Users\angel\AppData\Local\Ilivid Player
    Deleted on reboot : C:\Users\angel\AppData\Local\TempDir
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\A_Free_Ride_Games_Bar
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\AmigoBar
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\AVG Security Toolbar
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\Bandoo
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\centurytoolbar
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\Conduit
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\ConduitEngine
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\Elf_1
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\facemoods.com
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\FunWebProducts
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\MyWebSearch
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\PriceGong
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\ShoppingReport
    Deleted on reboot : C:\Users\angel\AppData\LocalLow\Toolbar4
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Bandoo
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Filesubmit
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Inbox Toolbar
    Deleted on reboot : C:\Users\angel\AppData\Roaming\iWin
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dogpile Bundle Toolbar
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\1opnxdf1.default\extensions\64ffxtbr@TelevisionFanatic.com
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\centurytoolbar
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\ConduitCommon
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\{1fd91a9c-410c-4090-bbcc-55d3450ef433}
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\{83453B9B-B889-4659-9144-20F081542BDC}
    Deleted on reboot : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\{f92a9fe4-2850-4198-b9d5-279880e49b16}
    File Deleted : C:\Program Files (x86)\Mozilla FireFox\searchplugins\Search_Results.xml
    File Deleted : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\searchplugins\Conduit.xml
    File Deleted : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\searchplugins\mywebsearch.xml
    File Deleted : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\searchplugins\Search_Results.xml
    File Deleted : C:\Users\angel\Desktop\Free Dolphin Screensaver.lnk
    File Deleted : C:\Users\Public\Desktop\iLivid.lnk
    File Deleted : C:\Windows\SysWOW64\conduitEngine.tmp

    ***** [Registry] *****

    Data Deleted : HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~2\Datamngr\datamngr.dll
    Data Deleted : HKLM\..\Windows [AppInit_DLLs] = C:\PROGRA~2\SEARCH~2\Datamngr\IEBHO.dll
    Key Deleted : HKCU\Software\AppDataLow\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
    Key Deleted : HKCU\Software\AppDataLow\Software\A_Free_Ride_Games_Bar
    Key Deleted : HKCU\Software\AppDataLow\Software\AmigoBar
    Key Deleted : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
    Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
    Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine
    Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
    Key Deleted : HKCU\Software\AppDataLow\Software\CouponAlert_2p
    Key Deleted : HKCU\Software\AppDataLow\Software\Elf_1
    Key Deleted : HKCU\Software\AppDataLow\Software\Fun Web Products
    Key Deleted : HKCU\Software\AppDataLow\Software\FunWebProducts
    Key Deleted : HKCU\Software\AppDataLow\Software\iWon
    Key Deleted : HKCU\Software\AppDataLow\Software\MyWebSearch
    Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
    Key Deleted : HKCU\Software\AppDataLow\Software\searchqutb
    Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
    Key Deleted : HKCU\Software\AppDataLow\Toolbar
    Key Deleted : HKCU\Software\bProtector
    Key Deleted : HKCU\Software\CToolbar
    Key Deleted : HKCU\Software\facemoods.com
    Key Deleted : HKCU\Software\Freeze.com
    Key Deleted : HKCU\Software\IGearSettings
    Key Deleted : HKCU\Software\ilivid
    Key Deleted : HKCU\Software\IM
    Key Deleted : HKCU\Software\Iminent
    Key Deleted : HKCU\Software\ImInstaller
    Key Deleted : HKCU\Software\InstallCore
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\A_Free_Ride_Games_Bar Toolbar
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AmigoBar Toolbar
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Anti-phishing Domain Advisor
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Elf_1 Toolbar
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\facemoods
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilivid
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\mywebsearch bar uninstall
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PriceGong
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Searchqu Toolbar
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Updater Service
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Searchcore Toolbar
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{22E03916-85C5-44B0-8DC9-1830C11238D9}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BFE4B5CB-63F7-4A51-9266-6167655D5B4F}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C80BDEB2-8735-44C6-BD55-A1CCD555667A}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F92A9FE4-2850-4198-B9D5-279880E49B16}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{046C4B86-AAD7-4188-B51E-E69B736989C9}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{05DDD334-AA5F-4CA8-9CC0-D37C34A507FE}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D110574-046A-43BB-A64C-4219E6A097DA}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{22E03916-85C5-44B0-8DC9-1830C11238D9}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BFE4B5CB-63F7-4A51-9266-6167655D5B4F}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C80BDEB2-8735-44C6-BD55-A1CCD555667A}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB35C569-5624-4CFC-8043-E5139F55A073}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F92A9FE4-2850-4198-B9D5-279880E49B16}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43B7-BEA3-87217BDA74C8}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8B63A8D6-BBED-4341-8867-790E5F524C96}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
    Key Deleted : HKLM\Software\A_Free_Ride_Games_Bar
    Key Deleted : HKLM\Software\AmigoBar
    Key Deleted : HKLM\Software\AVG Security Toolbar
    Key Deleted : HKLM\Software\Bandoo
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{055069F3-F78B-4BD1-A277-FE66648D3300}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\PriceGongIE.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
    Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore
    Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1
    Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr
    Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1
    Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr
    Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1
    Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr
    Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1
    Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
    Key Deleted : HKLM\SOFTWARE\Classes\CShared.TB4Client
    Key Deleted : HKLM\SOFTWARE\Classes\CShared.TB4Script
    Key Deleted : HKLM\SOFTWARE\Classes\CShared.TB4Server
    Key Deleted : HKLM\SOFTWARE\Classes\CShared.TB4Server2
    Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
    Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
    Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
    Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl
    Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
    Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
    Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
    Key Deleted : HKLM\SOFTWARE\Classes\FCTB000060231.FCTB000060231Pos
    Key Deleted : HKLM\SOFTWARE\Classes\FCTB000060231.FCTB000060231Pos.1
    Key Deleted : HKLM\SOFTWARE\Classes\FCTB000060231.IEToolbar
    Key Deleted : HKLM\SOFTWARE\Classes\FCTB000060231.IEToolbar.1
    Key Deleted : HKLM\SOFTWARE\Classes\FCTB000060231.JSOptionsImpl
    Key Deleted : HKLM\SOFTWARE\Classes\FCTB000060231.JSOptionsImpl.1
    Key Deleted : HKLM\SOFTWARE\Classes\FreeCauseURLSearchHook.FCToolbarURLSearchHook
    Key Deleted : HKLM\SOFTWARE\Classes\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1
    Key Deleted : HKLM\SOFTWARE\Classes\ilivid
    Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
    Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
    Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1320680
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2421531
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2856415
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api
    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\Software\conduitEngine
    Key Deleted : HKLM\Software\CToolbar
    Key Deleted : HKLM\Software\DataMngr
    Key Deleted : HKLM\Software\Elf_1
    Key Deleted : HKLM\Software\facemoods.com
    Key Deleted : HKLM\Software\Freeze.com
    Key Deleted : HKLM\Software\GamesBarSetup
    Key Deleted : HKLM\Software\ilivid
    Key Deleted : HKLM\Software\Iminent
    Key Deleted : HKLM\Software\ImInstaller
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{1A93C934-025B-4C3A-B38E-9654A7003239}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{046C4B86-AAD7-4188-B51E-E69B736989C9}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{04D2B915-19FF-41E9-994D-95DC898BEA43}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{05DDD334-AA5F-4CA8-9CC0-D37C34A507FE}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D110574-046A-43BB-A64C-4219E6A097DA}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8867AC9B-4426-44A2-A693-C95850D3405C}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F02C0832-C85C-4B93-8C6F-9DF20121A10D}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\72fe24ac3f81ced2107a1b2b8f23524c
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\e31cb9e6d5ac1eda0528e6a649b0012e
    Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin
    Key Deleted : HKLM\Software\SearchcoreMediabarTb
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{046C4B86-AAD7-4188-B51E-E69B736989C9}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{04D2B915-19FF-41E9-994D-95DC898BEA43}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{05DDD334-AA5F-4CA8-9CC0-D37C34A507FE}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1D110574-046A-43BB-A64C-4219E6A097DA}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{22E03916-85C5-44B0-8DC9-1830C11238D9}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5D79F641-C168-40DF-A32F-BACEA7509E75}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{91C18ED5-5E1C-4AE5-A148-A861DE8C8E16}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AF6AC4F2-9825-4FB6-A600-92BC5361F209}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BFE4B5CB-63F7-4A51-9266-6167655D5B4F}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C80BDEB2-8735-44C6-BD55-A1CCD555667A}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C98D5B61-B0EA-4D48-9839-1079D352D880}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DB35C569-5624-4CFC-8043-E5139F55A073}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F02C0832-C85C-4B93-8C6F-9DF20121A10D}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F78BF7A8-CF12-4DE7-A6DA-C463D1B539A7}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F92A9FE4-2850-4198-B9D5-279880E49B16}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\FCTB000060231
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16FE2505-F2A0-4782-B035-AF0E5188C02C}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1791C1B5-FFD0-4D4B-ABCD-7A7DF6EAA89C}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2AF08E71-3657-462F-898C-F7E791948F94}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56965DCF-718F-4148-BECF-5A2B466F4556}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F99D2AE-5C90-43C2-A2FE-81DBE512E2FC}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7225F6C9-CF64-4D6D-AE8A-169779FD7B4D}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7746796B-6F44-4984-8A05-56B7EB72C18A}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{988AE641-451D-4E5D-AA7C-47591606ED1B}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF6AC4F2-9825-4FB6-A600-92BC5361F209}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B288D7F1-EFFA-40B9-BC91-2FE6F8E93CEE}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B30A1A29-E7BB-4AB8-9E2A-67E1892A2052}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA3E7798-2690-440F-B7F8-A00A3013DBA3}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CB36F0E0-717C-4927-BBC7-F6A521B7BECD}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22E03916-85C5-44B0-8DC9-1830C11238D9}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5D79F641-C168-40DF-A32F-BACEA7509E75}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7FF99715-3016-4381-84CE-E4E4C9673020}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83453B9B-B889-4659-9144-20F081542BDC}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF6AC4F2-9825-4FB6-A600-92BC5361F209}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BFE4B5CB-63F7-4A51-9266-6167655D5B4F}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F92A9FE4-2850-4198-B9D5-279880E49B16}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\A_Free_Ride_Games_Bar Toolbar
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AmigoBar Toolbar
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Anti-phishing Domain Advisor
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Elf_1 Toolbar
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\facemoods
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PriceGong
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Searchcore Toolbar
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{22E03916-85C5-44B0-8DC9-1830C11238D9}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C80BDEB2-8735-44C6-BD55-A1CCD555667A}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{F78BF7A8-CF12-4DE7-A6DA-C463D1B539A7}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{F92A9FE4-2850-4198-B9D5-279880E49B16}]
    Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{8a9386b4-e958-4c4c-adf4-8f26db3e4829}]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{22E03916-85C5-44B0-8DC9-1830C11238D9}]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{F92A9FE4-2850-4198-B9D5-279880E49B16}]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Anti-phishing Domain Advisor]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [facemoods]
    Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [m3ffxtbr@mywebsearch.com]
    Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [webbooster@iminent.com]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{22E03916-85C5-44B0-8DC9-1830C11238D9}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7FF99715-3016-4381-84CE-E4E4C9673020}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{83453B9B-B889-4659-9144-20F081542BDC}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AF6AC4F2-9825-4FB6-A600-92BC5361F209}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{C80BDEB2-8735-44C6-BD55-A1CCD555667A}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{C98D5B61-B0EA-4D48-9839-1079D352D880}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{F92A9FE4-2850-4198-B9D5-279880E49B16}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v9.0.8112.16457

    Deleted : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - bProtector Start Page]

    -\\ Mozilla Firefox v14.0.1 (en-US)

    File : C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\prefs.js

    Deleted : user_pref("CT1320680..clientLogIsEnabled", false);
    Deleted : user_pref("CT1320680..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
    Deleted : user_pref("CT1320680..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
    Deleted : user_pref("CT1320680.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
    Deleted : user_pref("CT1320680.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
    Deleted : user_pref("CT1320680.BrowserCompStateIsOpen_5295060317045962640", true);
    Deleted : user_pref("CT1320680.BrowserCompStateIsOpen_6103217173235939216", true);
    Deleted : user_pref("CT1320680.CTID", "CT1320680");
    Deleted : user_pref("CT1320680.CurrentServerDate", "26-7-2012");
    Deleted : user_pref("CT1320680.DSInstall", true);
    Deleted : user_pref("CT1320680.DialogsAlignMode", "LTR");
    Deleted : user_pref("CT1320680.DialogsGetterLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standa[...]
    Deleted : user_pref("CT1320680.DownloadReferralCookieData", "");
    Deleted : user_pref("CT1320680.FirstServerDate", "5-7-2012");
    Deleted : user_pref("CT1320680.FirstTime", true);
    Deleted : user_pref("CT1320680.FirstTimeFF3", true);
    Deleted : user_pref("CT1320680.FirstTimeHiddenVer", true);
    Deleted : user_pref("CT1320680.FixPageNotFoundErrors", true);
    Deleted : user_pref("CT1320680.GroupingServerCheckInterval", 1440);
    Deleted : user_pref("CT1320680.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
    Deleted : user_pref("CT1320680.HPInstall", true);
    Deleted : user_pref("CT1320680.HPProtectChoice", true);
    Deleted : user_pref("CT1320680.HPProtectCount", 1);
    Deleted : user_pref("CT1320680.HasUserGlobalKeys", true);
    Deleted : user_pref("CT1320680.HomePageProtectorEnabled", false);
    Deleted : user_pref("CT1320680.HomepageBeforeUnload", "hxxp://www.mycenturylink.com/");
    Deleted : user_pref("CT1320680.Initialize", true);
    Deleted : user_pref("CT1320680.InitializeCommonPrefs", true);
    Deleted : user_pref("CT1320680.InstallationAndCookieDataSentCount", 3);
    Deleted : user_pref("CT1320680.InstallationType", "Unknown");
    Deleted : user_pref("CT1320680.InstalledDate", "Thu Jul 05 2012 07:09:20 GMT-0700 (Pacific Daylight Time)");
    Deleted : user_pref("CT1320680.IsAlertDBUpdated", true);
    Deleted : user_pref("CT1320680.IsGrouping", false);
    Deleted : user_pref("CT1320680.IsInitSetupIni", true);
    Deleted : user_pref("CT1320680.IsMulticommunity", false);
    Deleted : user_pref("CT1320680.IsOpenThankYouPage", false);
    Deleted : user_pref("CT1320680.IsOpenUninstallPage", true);
    Deleted : user_pref("CT1320680.IsProtectorsInit", true);
    Deleted : user_pref("CT1320680.LanguagePackLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standar[...]
    Deleted : user_pref("CT1320680.LanguagePackReloadIntervalMM", 1440);
    Deleted : user_pref("CT1320680.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
    Deleted : user_pref("CT1320680.LastLogin_3.13.0.6", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standard Time)[...]
    Deleted : user_pref("CT1320680.LatestVersion", "3.13.0.6");
    Deleted : user_pref("CT1320680.Locale", "en");
    Deleted : user_pref("CT1320680.MCDetectTooltipHeight", "83");
    Deleted : user_pref("CT1320680.MCDetectTooltipShow", false);
    Deleted : user_pref("CT1320680.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
    Deleted : user_pref("CT1320680.MCDetectTooltipWidth", "295");
    Deleted : user_pref("CT1320680.MyStuffEnabledAtInstallation", true);
    Deleted : user_pref("CT1320680.OriginalFirstVersion", "3.13.0.6");
    Deleted : user_pref("CT1320680.SHRINK_TOOLBAR", 1);
    Deleted : user_pref("CT1320680.SavedHomepage", "hxxp://www.yahoo.com/");
    Deleted : user_pref("CT1320680.SearchCaption", "A Free Ride Games Bar Customized Web Search");
    Deleted : user_pref("CT1320680.SearchEngineBeforeUnload", "Google");
    Deleted : user_pref("CT1320680.SearchFromAddressBarIsInit", true);
    Deleted : user_pref("CT1320680.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT322[...]
    Deleted : user_pref("CT1320680.SearchInNewTabEnabled", true);
    Deleted : user_pref("CT1320680.SearchInNewTabIntervalMM", 1440);
    Deleted : user_pref("CT1320680.SearchInNewTabLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Stand[...]
    Deleted : user_pref("CT1320680.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
    Deleted : user_pref("CT1320680.SearchInNewTabUserEnabled", false);
    Deleted : user_pref("CT1320680.SearchProtectorEnabled", true);
    Deleted : user_pref("CT1320680.SearchProtectorToolbarDisabled", false);
    Deleted : user_pref("CT1320680.SendProtectorDataViaLogin", true);
    Deleted : user_pref("CT1320680.ServiceMapLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standard [...]
    Deleted : user_pref("CT1320680.SettingsLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific Standard Ti[...]
    Deleted : user_pref("CT1320680.SettingsLastUpdate", "1339926577");
    Deleted : user_pref("CT1320680.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3222437&SearchSource=13");
    Deleted : user_pref("CT1320680.ThirdPartyComponentsInterval", 504);
    Deleted : user_pref("CT1320680.ThirdPartyComponentsLastCheck", "Thu Jul 05 2012 07:09:15 GMT-0700 (Pacific Day[...]
    Deleted : user_pref("CT1320680.ThirdPartyComponentsLastUpdate", "1331805997");
    Deleted : user_pref("CT1320680.ToolbarShrinkedFromSetup", false);
    Deleted : user_pref("CT1320680.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3222437");
    Deleted : user_pref("CT1320680.UserID", "UN31167979688839625");
    Deleted : user_pref("CT1320680.ValidationData_Search", 1);
    Deleted : user_pref("CT1320680.ValidationData_Toolbar", 2);
    Deleted : user_pref("CT1320680.alertChannelId", "1652210");
    Deleted : user_pref("CT1320680.approveUntrustedApps", false);
    Deleted : user_pref("CT1320680.backendstorage.cbcountry_001", "5553");
    Deleted : user_pref("CT1320680.backendstorage.cbfirsttime", "546875204A756C20303520323031322030373A30393A32382[...]
    Deleted : user_pref("CT1320680.backendstorage.hxxp://api15_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Deleted : user_pref("CT1320680.backendstorage.hxxp://api18_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Deleted : user_pref("CT1320680.backendstorage.hxxp://api21_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Deleted : user_pref("CT1320680.backendstorage.hxxp://api28_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Deleted : user_pref("CT1320680.backendstorage.hxxp://api32_starwebnet_com.pid2", "3932383139623539383861393636[...]
    Deleted : user_pref("CT1320680.backendstorage.printitgreenstatus", "74727565");
    Deleted : user_pref("CT1320680.backendstorage.shoppingapp.gk.exipres", "4D6F6E204A756C20333020323031322031333A[...]
    Deleted : user_pref("CT1320680.backendstorage.shoppingapp.gk.geolocation", "756E6974656420737461746573");
    Deleted : user_pref("CT1320680.backendstorage.url_history0001", "687474703A2F2F7777772E796F75747562652E636F6D2[...]
    Deleted : user_pref("CT1320680.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
    Deleted : user_pref("CT1320680.globalFirstTimeInfoLastCheckTime", "Thu Jul 26 2012 07:07:33 GMT-0700 (Pacific [...]
    Deleted : user_pref("CT1320680.homepageProtectorEnableByLogin", true);
    Deleted : user_pref("CT1320680.initDone", true);
    Deleted : user_pref("CT1320680.isAppTrackingManagerOn", true);
    Deleted : user_pref("CT1320680.myStuffEnabled", true);
    Deleted : user_pref("CT1320680.myStuffPublihserMinWidth", 400);
    Deleted : user_pref("CT1320680.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
    Deleted : user_pref("CT1320680.myStuffServiceIntervalMM", 1440);
    Deleted : user_pref("CT1320680.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
    Deleted : user_pref("CT1320680.navigateToUrlOnSearch", false);
    Deleted : user_pref("CT1320680.oldAppsList", "129819884490310076,129819884492028827,111,129819884492810078,129[...]
    Deleted : user_pref("CT1320680.revertSettingsEnabled", false);
    Deleted : user_pref("CT1320680.searchProtectorDialogDelayInSec", 10);
    Deleted : user_pref("CT1320680.searchProtectorEnableByLogin", true);
    Deleted : user_pref("CT1320680.testingCtid", "CT3222437");
    Deleted : user_pref("CT1320680.toolbarAppMetaDataLastCheckTime", "Mon Feb 25 2013 17:41:06 GMT-0800 (Pacific S[...]
    Deleted : user_pref("CT1320680.toolbarContextMenuLastCheckTime", "Thu Jul 26 2012 07:07:34 GMT-0700 (Pacific D[...]
    Deleted : user_pref("CT1320680.usagesFlag", 2);
    Deleted : user_pref("CT3222437.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
    Deleted : user_pref("CT3222437.autoDisableScopes", -1);
    Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3222437&Search[...]
    Deleted : user_pref("CommunityToolbar.ConduitSearchList", "A Free Ride Games Bar Customized Web Search");
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3222437/CT3222437[...]
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3222437", [...]
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3222437",[...]
    Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"3b6[...]
    Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\angel\\AppData\\Roaming\\Mozilla\\F[...]
    Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6");
    Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.yahoo.com/search?ei=UTF-8&[...]
    Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT1320680");
    Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT1320680");
    Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT1320680");
    Deleted : user_pref("CommunityToolbar.globalUserId", "447d4972-6725-4b44-91ec-8bf1aa954213");
    Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
    Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
    Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT1320680");
    Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Jul 25 2012 13:47:4[...]
    Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", false);
    Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
    Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
    Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
    Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Jul 25 2012 13:47:46 GMT-0700 (P[...]
    Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
    Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
    Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
    Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
    Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
    Deleted : user_pref("CommunityToolbar.notifications.userId", "db031f84-d60f-4e81-a688-d6bdbff4a136");
    Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.yahoo.com/");
    Deleted : user_pref("CommunityToolbar.originalSearchEngine", "Google");
    Deleted : user_pref("browser.search.defaultthis.engineName", "A Free Ride Games Bar Customized Web Search");
    Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&Sea[...]
    Deleted : user_pref("extensions.toolbar.mindspark._64Members_.homepage", "hxxp://home.mywebsearch.com/index.jh[...]
    Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3222437&SearchSource=2&q=[...]

    -\\ Google Chrome v22.0.1229.94

    File : C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Preferences

    Deleted [l.20] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/406" ]
    Deleted [l.77] : search_url = "hxxp://dts.search-results.com/sr?src=crb&appid=394&systemid=406&sr=0&q={searchT[...]
    Deleted [l.1652] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/406" ]

    *************************

    AdwCleaner[R1].txt - [63984 octets] - [02/03/2013 22:45:42]
    AdwCleaner[S1].txt - [55798 octets] - [02/03/2013 22:47:18]

    ########## EOF - C:\AdwCleaner[S1].txt - [55859 octets] ##########
     

     

    DDS Log

     

    DDS (Ver_2012-11-20.01) - NTFS_AMD64 MINIMAL
    Internet Explorer: 9.0.8112.16457  BrowserJavaVersion: 10.5.1
    Run by angel at 22:53:50 on 2013-03-02
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.6014.5303 [GMT -8:00]
    .
    AV: AVG Anti-Virus 2012 *Disabled/Outdated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus 2012 *Disabled/Outdated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\Explorer.EXE
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.mycenturylink.com/
    mStart Page = hxxp://www.yahoo.com/?ilc=8
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    mDefault_Page_URL = hxxp://www.yahoo.com/?ilc=8
    mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    uProxyOverride = <local>;*.local
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    uURLSearchHooks: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll
    uURLSearchHooks: {313a832a-aaf3-4880-a8d0-c42bee319c02} - <orphaned>
    uURLSearchHooks: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - <orphaned>
    uURLSearchHooks: YTNavAssistPlugin Class: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll
    uURLSearchHooks: <No Name>:  - LocalServer32 - <no file>
    dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned>
    dURLSearchHooks: YTNavAssistPlugin Class: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll
    dURLSearchHooks: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - <orphaned>
    mWinlogon: Userinit = c:\windows\syswow64\userinit.exe,
    BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    BHO: My.Freeze.com Toolbar: {0bd6f992-62ad-47f7-aca6-299729be4e2b} - C:\Program Files (x86)\myfreezetoolbar\myfreezedx.dll
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: {26D675AC-D925-4bbf-A720-62C2AA4A81EB} - <orphaned>
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
    BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
    BHO: Smiley Help BHO: {41403228-8910-4CA2-9939-DA9C9A6A58A7} - C:\Program Files\SmileysToolbar\SmilesBHO.dll
    BHO: File2LinkRH: {6a14e93a-dde3-4b64-8381-f3b68243d8f4} - C:\Program Files (x86)\file2linkrh\file2linkibX.dll
    BHO: Bewiki_IE_Extension: {732e5459-a239-4e08-a411-2c6ccf313f1d} - C:\Program Files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
    BHO: IconixBHOClass Class: {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files (x86)\eMail ID\IEAddOn\IconixBHO_46.dll
    BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
    BHO: Fantapper: {8A86D350-37AB-410A-8531-7D1363F317B3} -
    BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: {9F531FB1-7C1F-4e1a-8C0C-E8D6177130E2} - <orphaned>
    BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO: CenturyLink: {A317CB83-299C-4FC8-9ED7-2D64117D98EE} - C:\Program Files (x86)\qwesttoolbar\qwesttoolbarDx.dll
    BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    BHO: Updater For My.Freeze.com Toolbar: {C26CD490-5F01-41E3-B150-EB29F19DA056} - C:\Program Files (x86)\myfreezetoolbar\auxi\myfreezetoolbAu.dll
    BHO: Big Fish Games Toolbar: {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files (x86)\BfgBar\bfg.dll
    BHO: GamesBarBHO Class: {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files (x86)\GamesBar\2.0.1.109\oberontb.dll
    BHO: {CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - <orphaned>
    BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll
    BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
    BHO: QuickNet BHO: {EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7} -
    BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn6\YTSingleInstance.dll
    TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    TB: My.Freeze.com Toolbar: {0bd6f992-62ad-47f7-aca6-299729be4e2b} - C:\Program Files (x86)\myfreezetoolbar\myfreezedx.dll
    TB: File2LinkRH: {6a14e93a-dde3-4b64-8381-f3b68243d8f4} - C:\Program Files (x86)\file2linkrh\file2linkibX.dll
    TB: Big Fish Games Toolbar: {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files (x86)\BfgBar\bfg.dll
    TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
    TB: &SmileysToolbar: {120B1DC9-20CC-498F-9ABA-455FB2B8E18F} - C:\Program Files\SmileysToolbar\SmilesBHO.dll
    TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll
    TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    TB: CenturyLink: {A317CB83-299C-4FC8-9ED7-2D64117D98EE} - C:\Program Files (x86)\qwesttoolbar\qwesttoolbarDx.dll
    EB: Recipe Feeder: {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - C:\Program Files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
    EB: Recipe Feeder: {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - C:\Program Files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
    uRun: [PhotoShow Deluxe Media Manager] C:\PROGRA~2\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
    uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    uRun: [Power2GoExpress] NA
    uRun: [DW7] "C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe"
    uRun: [Exetender_179] "C:\Program Files (x86)\qZone Games Player\GPlayer.exe" /runonstartup
    uRun: [SearchEngineProtection] C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe
    uRunOnce: [DeleteOnReboot] C:\Windows\DeleteOnReboot.bat
    uRunOnce: [Report] C:\AdwCleaner[S1].txt
    mRun: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    mRun: [1157840481] C:\PROGRA~2\eGames\TWISTI~1\Register\EGAMES~1.EXE /r "C:\PROGRA~2\eGames\TWISTI~1\Register\EGAMES~1.rpd"
    mRun: [408809432] C:\PROGRA~2\eGames\SHOOTT~1\Register\EGAMES~1.EXE /r "C:\PROGRA~2\eGames\SHOOTT~1\Register\EGAMES~1.rpd"
    mRun: [Conime] C:\Windows\System32\conime.exe
    mRun: [ArcSoft Connection Service] "C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
    mRun: [IconixOEAddOn] "C:\Program Files (x86)\eMail ID\OEAddOn\OEdmn_6.exe"
    mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun: [YMailAdvisor] "C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe"
    mRun: [TelevisionFanatic Search Scope Monitor] "C:\PROGRA~2\TELEVI~2\bar\1.bin\64srchmn.exe" /m=2 /w /h
    mRun: [CenturyLinkTouchPointAgent] "C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe" /autostart
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    dRun: [Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}] C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe /m
    StartupFolder: C:\Users\angel\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\HPSIMP~1.LNK - C:\Users\angel\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files\Logitech\SetPoint\SetPoint.exe
    uPolicies-Explorer: NoDrives = dword:0
    mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
    mPolicies-Explorer: NoDrives = dword:0
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: &Windows Live Search - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    IE: {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5}
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - {44E212AB-13EA-4CA4-BE65-197FBA170412} - C:\Program Files (x86)\eMail ID\IEAddOn\IconixBHO_46.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    IE: {BC3F6B6D-2E49-4603-B028-7411655713F3} - {0CC2F28D-D415-4FC6-A2E4-54B4D983609A} - C:\Program Files (x86)\eMail ID\IEAddOn\IconixBHO_46.dll
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    Trusted Zone: mcafee.com
    DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} - hxxp://offers.e-centives.com/cif/download/bin/actxcab.cab
    DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: NameServer = 192.168.2.1
    TCP: Interfaces\{A204FC89-260F-49B0-9B54-74DAB8E8C19C} : DHCPNameServer = 192.168.2.1
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    AppInit_DLLs=  protector.dll
    LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg
    x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll
    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
    x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
    x64-Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\System32\NvCpl.dll,NvStartup
    x64-Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\System32\NvMcTray.dll,NvTaskbarInit
    x64-Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    x64-Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe
    x64-mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
    x64-mPolicies-Explorer: NoDrives = dword:0
    x64-mPolicies-System: EnableUIADesktopToggle = dword:0
    x64-DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    x64-DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/SmileyCentralInitialSetup1.0.1.1.cab
    x64-DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll
    x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - LocalServer32 - <no file>
    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.mycenturylink.com/
    FF - ExtSQL: !HIDDEN! 1970-01-16 04:44; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; C:\Program Files (x86)\Searchqu Toolbar\Datamngr\FirefoxExtension
    FF - ExtSQL: !HIDDEN! 2009-06-24 11:45; {20a82645-c095-46ed-80e3-08825760534b}; c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - ExtSQL: !HIDDEN! 2012-07-19 05:44; 64ffxtbr@TelevisionFanatic.com; C:\Program Files (x86)\TelevisionFanatic\bar\1.bin
    .
    ============= SERVICES / DRIVERS ===============
    .
    S1 ccSet_MCLIENT;Norton Management Settings Manager;C:\Windows\System32\drivers\MCLIENTx64\0302000.013\ccsetx64.sys [2012-11-8 168096]
    S2 BackupService;BackupService;C:\Users\angel\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe [2010-12-26 83512]
    S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE [2012-2-10 193816]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 FontCache;Windows Font Cache Service;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
    S2 fssfltr;FssFltr;C:\Windows\System32\drivers\fssfltr.sys [2010-10-12 48488]
    S2 IconixService;Iconix Update Service;C:\Program Files (x86)\Common Files\eMail ID\IconixService.exe [2009-4-1 283992]
    S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe [2010-9-13 308656]
    S2 MCLIENT;Norton Management;C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccsvchst.exe [2012-11-8 143928]
    S2 Norman ZANDA;Norman ZANDA;"C:\Program Files (x86)\VIRUSfighter\Npm\Bin\Zanda.exe" --> C:\Program Files (x86)\VIRUSfighter\Npm\Bin\Zanda.exe [?]
    S2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.7.49\SymcPCCULaunchSvc.exe [2010-12-6 124856]
    S2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.7.49\ccSvcHst.exe [2010-12-6 126392]
    S2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-7-5 3048136]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
    S2 sprtlisten;SupportSoft Listener Service;C:\Program Files (x86)\Common Files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
    S2 X5XSEx_Pr179;X5XSEx_Pr179;C:\Program Files (x86)\qZone Games Player\X5XSEx.sys [2012-6-7 55400]
    S3 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
    S3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE [2012-2-10 240408]
    S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
    S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
    S3 MatSvc;Microsoft Automated Troubleshooting Service;C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2011-6-13 343856]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-6-17 237008]
    S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
    S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-8-18 89920]
    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
    .
    =============== File Associations ===============
    .
    FileExt: .jse: JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
    .
    =============== Created Last 30 ================
    .
    .
    ==================== Find3M  ====================
    .
    2013-03-03 06:47:32    3752    ----a-w-    C:\Windows\DeleteOnReboot.bat
    2013-01-17 09:28:58    273840    ------w-    C:\Windows\System32\MpSigStub.exe
    2012-12-23 11:05:08    67413224    ----a-w-    C:\Windows\System32\mrt.exe
    2012-12-16 13:31:20    48128    ----a-w-    C:\Windows\System32\atmlib.dll
    2012-12-16 13:12:54    34304    ----a-w-    C:\Windows\SysWow64\atmlib.dll
    2012-12-16 11:08:21    368128    ----a-w-    C:\Windows\System32\atmfd.dll
    2012-12-16 10:50:29    293376    ----a-w-    C:\Windows\SysWow64\atmfd.dll
    .
    ============= FINISH: 22:55:46.27 ===============
     



    #4 nasdaq

    nasdaq

    • Malware Response Team
    • 38,936 posts
    • OFFLINE
    •  
    • Gender:Male
    • Location:Montreal, QC. Canada
    • Local time:01:29 AM

    Posted 03 March 2013 - 10:28 AM

    AVG Anti-Virus 2012   
     Antivirus out of date!
    This is important. You should keep your Anti-Virus up-to-date.
    ===
     
    Secure your system by updating 3rd party programs.
     
    Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
     
    Be careful not to install malware posing as Java update!
    Important read this blog.
     
    Quoted from the page.
    "In light of the recent events surrounding Java, users must seriously consider their use of Java. Do they really need it? If yes, make sure that users follow the steps we recommended and get the security update directly from the official oracle website." at:
     
    How to disable Java in your browsers
     
    You can manually check your present version and update as recommended.
     
    If present remove the old version(s) of Java using the Add/Remove Programs applet.
     
     
     Java™ 6 Update 31  
     Java™ 7 Update 5 
     
     
    Java 7 update 10 introduced important new security controls
    You can read about it here.
     
    Note
    Java security update installs Ask Toolbar by default -- a single click in a multi-step installer.
    I suggest that your un-check the box "Install the Ask Toolbar" before proceeding.
    ===
     
    Critical vulnerabilities have been identified in old version of Adobe Flash Player please get the latest version.
     
    Adobe has released security updates for Adobe Flash Player 11.6.602.168 and earlier versions for Windows, Adobe Flash Player 11.6.602.167 and earlier versions for Macintosh, and Adobe Flash Player 11.2.202.270 and earlier versions for Linux. 
     
     
    On the top of the page you will be given an opportunity to download the version for your operating system.
    Make sure you select appropriate version.
     
    You will also have an option to install the Free! McAfee Security Scan Plus Un-check the box if you are NOT using McAfee's virus protection software.
     
    For the users of Internet Explorer download version 11.
    ===
     
    Adobe Reader/Acrobat 11.0.02 released Feb 21. 2013.
     
    Get the latest version of the Adobe Reader.
    Before your download I suggest you unckeck the box on the top right "Yes, install McAfee Security Scan Plus - optional" this is not required if you are not a McAfee subscriber. While the installation is in progress you can also deny the installation of any other programs that may be suggested.
     
    When installed remove your old version of the Reader using the Add/Remove Programs applet if present.
    ===
     
    Open notepad and copy/paste the text in the quote box below into it:
     
    Folder::
    C:\Program Files (x86)\myfreezetoolbar
    C:\Program Files (x86)\file2linkrh
    C:\Program Files (x86)\Recipe Feeder
     
    DDS::
    BHO: Updater For My.Freeze.com Toolbar: {C26CD490-5F01-41E3-B150-EB29F19DA056} - C:\Program Files (x86)\myfreezetoolbar\auxi\myfreezetoolbAu.dll
    IE: {{14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - C:\Program Files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
     
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{0bd6f992-62ad-47f7-aca6-299729be4e2b}"=-
    "{6a14e93a-dde3-4b64-8381-f3b68243d8f4}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{732e5459-a239-4e08-a411-2c6ccf313f1d}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C26CD490-5F01-41E3-B150-EB29F19DA056}]
    [-HKEY_CLASSES_ROOT\clsid\{0bd6f992-62ad-47f7-aca6-299729be4e2b}]
    [-HKEY_CLASSES_ROOT\clsid\{6a14e93a-dde3-4b64-8381-f3b68243d8f4}]
     
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
     
    ClearJavaCache::
    
     
     
    Save this as CFScript.txt on your desktop.
     
     
    Referring to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.
     
    Let me know what problem persists.


    #5 ConnJohnn

    ConnJohnn
    • Topic Starter

    • Members
    • 15 posts
    • OFFLINE
    •  
    • Local time:09:29 PM

    Posted 03 March 2013 - 10:41 PM

    Thank you for all your help so far.  I didn't get to updating the programs as you requested, but I did run ComboFix with the the posted script.  So far, no sign of an application error.  It is running noticeably slow, but no errors yet.

     

    Updated ComboFix Log..

     

    ComboFix 13-03-02.01 - angel 03/03/2013  14:33:25.1.4 - x64 MINIMAL
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.6014.5268 [GMT -8:00]
    Running from: c:\users\angel\Desktop\ComboFix.exe
    Command switches used :: J:\CFScript.txt
    AV: AVG Anti-Virus 2012 *Disabled/Outdated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus 2012 *Disabled/Outdated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
     * Created a new restore point
    .
    .
    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files (x86)\file2linkrh
    c:\program files (x86)\file2linkrh\chrome\content\lib\about.xml
    c:\program files (x86)\file2linkrh\chrome\content\lib\dtxpanel.xul
    c:\program files (x86)\file2linkrh\chrome\content\lib\dtxpaneltransparent.xul
    c:\program files (x86)\file2linkrh\chrome\content\lib\dtxpanelwin.xul
    c:\program files (x86)\file2linkrh\chrome\content\lib\dtxprefwin.xul
    c:\program files (x86)\file2linkrh\chrome\content\lib\dtxtransparentwin.xul
    c:\program files (x86)\file2linkrh\chrome\content\lib\dtxwin.xul
    c:\program files (x86)\file2linkrh\chrome\content\lib\emailnotifierproviders.xml
    c:\program files (x86)\file2linkrh\chrome\content\lib\external.js
    c:\program files (x86)\file2linkrh\chrome\content\lib\neterror.xhtml
    c:\program files (x86)\file2linkrh\chrome\content\lib\rsspreview.html
    c:\program files (x86)\file2linkrh\chrome\content\lib\rsswin.xml
    c:\program files (x86)\file2linkrh\chrome\content\lib\rsswin.xsl
    c:\program files (x86)\file2linkrh\chrome\content\lib\vmncode.js
    c:\program files (x86)\file2linkrh\chrome\content\lib\wmpstreamer.html
    c:\program files (x86)\file2linkrh\chrome\content\modules\datastore.jsm
    c:\program files (x86)\file2linkrh\chrome\content\modules\nsDragAndDrop.js
    c:\program files (x86)\file2linkrh\chrome\content\neterror.xhtml
    c:\program files (x86)\file2linkrh\chrome\content\newtab\images\btn_search.gif
    c:\program files (x86)\file2linkrh\chrome\content\newtab\images\bullet.gif
    c:\program files (x86)\file2linkrh\chrome\content\newtab\images\field_bg.gif
    c:\program files (x86)\file2linkrh\chrome\content\newtab\images\powered_by_yahoo.gif
    c:\program files (x86)\file2linkrh\chrome\content\newtab\newtab.html
    c:\program files (x86)\file2linkrh\chrome\content\newtab\newtab_mystart.html
    c:\program files (x86)\file2linkrh\chrome\content\newtab\newtab_yahoo.html
    c:\program files (x86)\file2linkrh\chrome\content\preferences.xml
    c:\program files (x86)\file2linkrh\chrome\content\template.xml
    c:\program files (x86)\file2linkrh\chrome\content\toolbar.htm
    c:\program files (x86)\file2linkrh\chrome\content\toolbar.xul
    c:\program files (x86)\file2linkrh\chrome\content\vmncode.js
    c:\program files (x86)\file2linkrh\chrome\content\vmnrsswin.xml
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\.#widget.xml.1.2
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\alert_coupon.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-next-off.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-next.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-previous-off.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-previous.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\bg-coupon-blue.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\bg-save.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\border-radius.htc
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-getcoupon.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-next-blue.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-previous-blue.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-wide-close-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-wide-close.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\coupon-activated.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\couponTooltip.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\css\dialog.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\css\ie7style.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\css\IE7Styles.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\ico-coupon.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\ico-dollar.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrow-grey.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrows_grey-left.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrows_grey-right.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\bg_top.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-back.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-getcoupon.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-search.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\coupon-activated.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\delete.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\loader.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\save.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollb-disable.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollb-down.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollb.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollt-disable.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollt-down.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollt.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\sprite.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-arrow-hover.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-arrow.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-l_BAK.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-r_BAK.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-on-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-on-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-over-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-over-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-white-left.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-white-mdl.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-white-right.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\images\vid-bg.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\index.html
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\jquery.contextMenu.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\jquery.contextMenu.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery-1.4.2.min.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery.event.wheel.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery.pagination.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery.scrollTo-min.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\js\JSON.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\js\listnav.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\js\main.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\page_white_copy.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\panel.html
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\partner.xml
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\placeholder-logo.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\css\dialog.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\bg.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-disablealert-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-disablealert.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-enablealert-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-enablealert.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-help-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-help.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-managealerts-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-managealerts.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-showalert-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-showalert.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-wide-close-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-wide-close.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\default.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\power-couponcamp.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\poweredby-couponwinner.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\transparent.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-left.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-left_old.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-mdl.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-mdl_old.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-right-resize.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-right.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-right_old.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\main.html
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\main.html.bak
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\scripts\defscript.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\tb_icon.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\widget.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\widget.jsw
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\widget.xml
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.Coupons_v2\widget_version.txt
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\css\dialog.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrow-grey.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrows_grey-left.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrows_grey-right.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\back.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\btn-search-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\btn-search.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\delete.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollb-disable.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollb-down.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollb.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollt-disable.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollt-down.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollt.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-arrow-hover.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-arrow.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-off-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-off-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-on-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-on-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-over-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-over-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-red-left.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-red-mdl.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-red-right.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-white-left.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-white-mdl.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-white-right.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\throbber.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\vid-bg.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\youtube.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\index.html
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\js\function.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\js\jquery-1.4.2.min.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\js\JSON.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css\dialog.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\bg-facebook.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\blank.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\btn-wide-close-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\btn-wide-close.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\default.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\transparent.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-left.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-mdl.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-right-resize.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-right.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\main.html
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts\defscript.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts\jquery-1.4.2.min.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\tb_icon.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\widget.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\widget.xml
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.MyStartFacebook\widget_version.txt
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.PPCBullyIbario\tb_icon.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.PPCBullyIbario\widget.jsw
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.PPCBullyIbario\widget.xml
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.PPCBullyIbario\widget_version
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\.#widget.xml.1.1
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\radiobeta-buffering.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\radiobeta-connecting.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\radiobeta-ico.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\radiobeta-playing.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\radiobeta-stopped.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\radiobeta.ico
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\radiobeta.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\tb_icon.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\widget.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\widget.jsw
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.RadioBeta\widget.xml
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\css\autocomplete.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\css\dialog.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrow-grey.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrows_grey-left.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrows_grey-right.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\bg.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\btn-search-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\btn-search.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\powered-by-youtube.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-off-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-off-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-on-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-on-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-red-left.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-red-mdl.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-red-right.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-white-left.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-white-mdl.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-white-right.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\throbber.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\vid-bg.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\images\youtube.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\index.html
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\js\autocomplete.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\js\jquery-1.4.3.min.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\js\paginator.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\js\youtube.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\net.vmn.www.YouTube_v2.zip
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\css\dialog.css
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\bg.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-search.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-wide-close-over.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-wide-close.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\default.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-off-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-off-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-on-l.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-on-r.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\transparent.gif
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-left.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-mdl.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-right-resize.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-right.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\main.html
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\scripts\defscript.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\tb_icon.png
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\widget.js
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\widget.jsw
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\widget.xml
    c:\program files (x86)\file2linkrh\chrome\content\widgets\net.vmn.www.YouTube_v2\widget_version.txt
    c:\program files (x86)\file2linkrh\chrome\data\dynamicElements\vmntoolbar.xsl
    c:\program files (x86)\file2linkrh\chrome\data\rss\rss.xml
    c:\program files (x86)\file2linkrh\chrome\data\search\engines.xml
    c:\program files (x86)\file2linkrh\chrome\data\search\search.xsl
    c:\program files (x86)\file2linkrh\chrome\data\weather\icons.xml
    c:\program files (x86)\file2linkrh\chrome\skin\about.gif
    c:\program files (x86)\file2linkrh\chrome\skin\about_logo.png
    c:\program files (x86)\file2linkrh\chrome\skin\babylon_logo.png
    c:\program files (x86)\file2linkrh\chrome\skin\bluelite.gif
    c:\program files (x86)\file2linkrh\chrome\skin\bluesky.gif
    c:\program files (x86)\file2linkrh\chrome\skin\btn-search-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\btn-search.png
    c:\program files (x86)\file2linkrh\chrome\skin\btn-settings-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\btn-settings.png
    c:\program files (x86)\file2linkrh\chrome\skin\btn-widgets-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\btn-widgets.png
    c:\program files (x86)\file2linkrh\chrome\skin\btn_settings.png
    c:\program files (x86)\file2linkrh\chrome\skin\ca.png
    c:\program files (x86)\file2linkrh\chrome\skin\dictionary.png
    c:\program files (x86)\file2linkrh\chrome\skin\divider.png
    c:\program files (x86)\file2linkrh\chrome\skin\downloadcom.png
    c:\program files (x86)\file2linkrh\chrome\skin\dtxlogo.png
    c:\program files (x86)\file2linkrh\chrome\skin\email.png
    c:\program files (x86)\file2linkrh\chrome\skin\email_on.png
    c:\program files (x86)\file2linkrh\chrome\skin\facebook.png
    c:\program files (x86)\file2linkrh\chrome\skin\games.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphna.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred0.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred0_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred1.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred1_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred2.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred2_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred3.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred3_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred4.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred4_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphred5.png
    c:\program files (x86)\file2linkrh\chrome\skin\graphredna.png
    c:\program files (x86)\file2linkrh\chrome\skin\grey.gif
    c:\program files (x86)\file2linkrh\chrome\skin\ico-shield.png
    c:\program files (x86)\file2linkrh\chrome\skin\images.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\add.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\alexabutton.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\aol.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\arrow-dn.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\arrow-right-disabled.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\arrow-right.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\arrow-up.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btn-divider.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btn-end.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btn-mdl.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btn-mdl_ff.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btn-start.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btnover-divider.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btnover-end.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btnover-mdl.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btnover-mdl_ff.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\bg-btnover-start.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\blank.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\btn-widgets-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\btn-widgets.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\btn_slider.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\btnback-down-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\btnback-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\btnleft-down-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\btnleft-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\btnright-down-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\btnright-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\button-splitter-down-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\button-splitter-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\button-splitter.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\checkmark.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\chevron.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\collapse.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\comcast.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\debugbar\debug.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\dtx-test.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\dtx.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\edit-back-hot.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\edit-back.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\embarq.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\expand.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\fast.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\found.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\gmail.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\gripper.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\highlight.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\highlight_blue.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\highlight_cyan.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\highlight_lime.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\highlight_magenta.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\highlight_yellow.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\hotmail.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\ico-check.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\imap.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\lastsearch-thumb-back.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\launchers.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\loadingMid.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\lock.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\logo-separator.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\mailcom.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menu_bg-basic.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menu_separator_bar.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menu_separator_white.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menuitem-splitter.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menuitemback-down-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menuitemback-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menuitemleft-down-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menuitemleft-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menuitemleft.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menuitemright-down-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\menuitemright-vista.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\minus.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\modify.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\move.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\movetarget.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\newsitem.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\css\panels.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\css\popupAbout.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\css\popupGames.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\css\popupRSS.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\css\popupWidgets.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\css\dialog.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\bg.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\btn-search.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\btn-wide-close-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\btn-wide-close.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\default.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\tab-off-l.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\tab-off-r.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\tab-on-l.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\tab-on-r.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\transparent.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\ttlbar-left.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\ttlbar-mdl.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\ttlbar-right.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\win-btm-left.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\win-btm-mdl.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\win-btm-right-resize.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\win-btm-right.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\win-left.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\images\win-right.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\main.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\default\scripts\defscript.js
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\footer.htm
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\gamecategory.xsl
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\gameData.js
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\gameList.xsl
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\games.xsl
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\gametype.xsl
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\.#btn-search-pnlbtm-over.png.1.1
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\.#btn-search-pnlbtm.png.1.1
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\arrow-dn.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\arrow-sml-drop.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\arrow-sml.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\arrow-up.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\arrowr-bluew5.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\bg-aboutbox.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\bg-btnover.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\bg-pnl520x390.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-addtoolbar-left-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-addtoolbar-left.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-addtoolbar-right.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-back.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-close-grey.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-close-greyover.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-drag.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-mdl-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-mdl.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-moredetails.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-next-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-next.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-play-left-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-play-left.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-previous-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-previous.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-right-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-search-pnlbtm.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-try-left-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\btn-try-left.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\bullet-orange.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\gamethumb-on.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\gamethumb2-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\ico-calendar.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\ico-dollar.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\ico-download.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\ico-joystick24.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\ico-news24.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\ico-play.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\ico-tags.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\icon-Add.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\icon-download.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\icon-Info.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\icon-play.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\icon-shop.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\menul-bgon.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\menul-bgover.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\panel-botm-noscroll.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scroll-bg-206.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scroll-bg.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scroll-topwin.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scrollb-disable.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scrollb-down.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scrollb-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scrollb.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scrollt-disable.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scrollt-down.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scrollt-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\scrollt.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\searchbox-pnlbtm.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\star_x_grey.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\star_x_orange.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\TRUSTe_about.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\view-detailed-on.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\view-detailed-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\view-thumb-on.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\view-thumb-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\widgets-square-16px.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\widgets-square-24px.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\images\widgets.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\initHTML.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\popupGames.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\popupHTML.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\popupRSS.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\popupWidgets.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\panels\scroll.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\plus.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\pop.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\css\manager.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\css\slider.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\bg-pnl.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\btn-close-grey.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\btn-close-greyover.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\collapsed_button.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\expanded_button.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\ico-playstation-down.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\ico-playstation-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\ico-playstation.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\ico-radio.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\music-note.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-btn-pause-on.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-btn-pause.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-btn-play-on.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-btn-play.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-eq-bg.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-eq-buffer.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-eq-busy.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-eq-off.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-eq-on.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-eq-warning.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-options-design-on.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-options-design.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-options-on.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-options.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-volume-0.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-volume-1.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-volume-2.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-volume-3.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\radio-volume-mute.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\scrollbar-handle.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\scrollbar-track.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\slider.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\slideron.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\images\track.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\managerpanel.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\radio\volumeslider.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank0.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank0_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank1.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank1_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank2.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank2_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank3.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank3_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank4.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank4_5.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rank5.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rankna.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\reload.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\remove.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rename.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\resize-box.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rss.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rsschannelback.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\RSSLogo.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\rsstabdivider.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\scroll-left.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\scroll-right.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\search-go.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\search.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\separator.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\text-ellipsis.xml
    c:\program files (x86)\file2linkrh\chrome\skin\lib\throbber.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\toolbarsplitter.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\transparent_1px.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_02.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_03.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_04.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_06.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_07.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_08.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_09.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_10.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_11.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_12.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_13.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_14.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_15.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_16.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_18.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_19.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_20.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\border_21.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\btn-close-grey.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\btn-close-greyover.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\close-hot.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\close-normal.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\loadingMid.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\paneltemplate.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\proxy.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\template.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\template.xml
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\templateFF.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\uwa\throbber.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\icons\cond999.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\icons\icons.xml
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\icons\na-s.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\icons\na-t.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\icons\na.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\icons\weather.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\add.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\box-check.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\ico-check.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\options-weather.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\over-blue.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\over-orange.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\popupWeather.css
    c:\program files (x86)\file2linkrh\chrome\skin\lib\weatherbutton\panels\popupWeather.html
    c:\program files (x86)\file2linkrh\chrome\skin\lib\websiteinspector-highrisk-user.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\websiteinspector-highrisk.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\websiteinspector-lowrisk.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\websiteinspector-norating.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\websiteinspector-verified-user.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\websiteinspector-verified.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\websiteinspector-verifying.gif
    c:\program files (x86)\file2linkrh\chrome\skin\lib\yahoo.png
    c:\program files (x86)\file2linkrh\chrome\skin\lichen.gif
    c:\program files (x86)\file2linkrh\chrome\skin\logo-about.png
    c:\program files (x86)\file2linkrh\chrome\skin\logo-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\logo-separator.png
    c:\program files (x86)\file2linkrh\chrome\skin\logo.png
    c:\program files (x86)\file2linkrh\chrome\skin\mail.png
    c:\program files (x86)\file2linkrh\chrome\skin\menuseparatorback.gif
    c:\program files (x86)\file2linkrh\chrome\skin\modify-save.png
    c:\program files (x86)\file2linkrh\chrome\skin\modify.png
    c:\program files (x86)\file2linkrh\chrome\skin\modifyhot.png
    c:\program files (x86)\file2linkrh\chrome\skin\music.png
    c:\program files (x86)\file2linkrh\chrome\skin\namespacetoolbar.css
    c:\program files (x86)\file2linkrh\chrome\skin\news.png
    c:\program files (x86)\file2linkrh\chrome\skin\options-main.png
    c:\program files (x86)\file2linkrh\chrome\skin\options-search.png
    c:\program files (x86)\file2linkrh\chrome\skin\options\options-main.png
    c:\program files (x86)\file2linkrh\chrome\skin\options\options-search.png
    c:\program files (x86)\file2linkrh\chrome\skin\options\options-weather.gif
    c:\program files (x86)\file2linkrh\chrome\skin\options\options-weather.png
    c:\program files (x86)\file2linkrh\chrome\skin\options\options-widgets.png
    c:\program files (x86)\file2linkrh\chrome\skin\orange.gif
    c:\program files (x86)\file2linkrh\chrome\skin\p_yahoo.png
    c:\program files (x86)\file2linkrh\chrome\skin\pixsy.png
    c:\program files (x86)\file2linkrh\chrome\skin\ppcbully.png
    c:\program files (x86)\file2linkrh\chrome\skin\protect-id.png
    c:\program files (x86)\file2linkrh\chrome\skin\relatedlinks.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-collapse.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-delete.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-expand.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-feed.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-folder-remove.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-folder-rename.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-folder.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-found.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-reload.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss-subscribe.png
    c:\program files (x86)\file2linkrh\chrome\skin\rss.png
    c:\program files (x86)\file2linkrh\chrome\skin\rssback.gif
    c:\program files (x86)\file2linkrh\chrome\skin\rsstopback.gif
    c:\program files (x86)\file2linkrh\chrome\skin\search-over.png
    c:\program files (x86)\file2linkrh\chrome\skin\search.png
    c:\program files (x86)\file2linkrh\chrome\skin\searchbar\searchbar-background-left.png
    c:\program files (x86)\file2linkrh\chrome\skin\searchbar\searchbar-background-middle.png
    c:\program files (x86)\file2linkrh\chrome\skin\searchbar\searchbar-background-right.png
    c:\program files (x86)\file2linkrh\chrome\skin\settings.png
    c:\program files (x86)\file2linkrh\chrome\skin\shopping.png
    c:\program files (x86)\file2linkrh\chrome\skin\siteinfo.png
    c:\program files (x86)\file2linkrh\chrome\skin\skin-bluelite.png
    c:\program files (x86)\file2linkrh\chrome\skin\skin-bluesky.png
    c:\program files (x86)\file2linkrh\chrome\skin\skin-grey.png
    c:\program files (x86)\file2linkrh\chrome\skin\skin-lichen.png
    c:\program files (x86)\file2linkrh\chrome\skin\skin-orange.png
    c:\program files (x86)\file2linkrh\chrome\skin\skin-yellow.png
    c:\program files (x86)\file2linkrh\chrome\skin\skin.xml
    c:\program files (x86)\file2linkrh\chrome\skin\technorati.png
    c:\program files (x86)\file2linkrh\chrome\skin\throbber.gif
    c:\program files (x86)\file2linkrh\chrome\skin\toolbarsplitter.png
    c:\program files (x86)\file2linkrh\chrome\skin\translate.png
    c:\program files (x86)\file2linkrh\chrome\skin\TRUSTe_about.png
    c:\program files (x86)\file2linkrh\chrome\skin\vmn.css
    c:\program files (x86)\file2linkrh\chrome\skin\vmn.png
    c:\program files (x86)\file2linkrh\chrome\skin\web.png
    c:\program files (x86)\file2linkrh\chrome\skin\websearch.png
    c:\program files (x86)\file2linkrh\chrome\skin\wikipedia.png
    c:\program files (x86)\file2linkrh\chrome\skin\yahoosearch.png
    c:\program files (x86)\file2linkrh\chrome\skin\yellow.gif
    c:\program files (x86)\file2linkrh\chrome\skin\youtube.png
    c:\program files (x86)\file2linkrh\chrome\skin\zoom.png
    c:\program files (x86)\file2linkrh\components\windowmediator.js
    c:\program files (x86)\file2linkrh\file2linkib.dll
    c:\program files (x86)\file2linkrh\file2linkibX.dll
    c:\program files (x86)\file2linkrh\install.ico
    c:\program files (x86)\file2linkrh\manifest.xml
    c:\program files (x86)\file2linkrh\toolbar.xml
    c:\program files (x86)\file2linkrh\uninstall.exe
    c:\program files (x86)\myfreezetoolbar
    c:\program files (x86)\myfreezetoolbar\auxi\config.xml
    c:\program files (x86)\myfreezetoolbar\auxi\myfreezetoolbAu.dll
    c:\program files (x86)\myfreezetoolbar\chrome.manifest
    c:\program files (x86)\myfreezetoolbar\chrome\content\about.xml
    c:\program files (x86)\myfreezetoolbar\chrome\content\generic.js
    c:\program files (x86)\myfreezetoolbar\chrome\content\lib\dtxpanelwin.xul
    c:\program files (x86)\myfreezetoolbar\chrome\content\lib\dtxprefwin.xul
    c:\program files (x86)\myfreezetoolbar\chrome\content\lib\dtxwin.xul
    c:\program files (x86)\myfreezetoolbar\chrome\content\lib\emailnotifierproviders.xml
    c:\program files (x86)\myfreezetoolbar\chrome\content\lib\external.js
    c:\program files (x86)\myfreezetoolbar\chrome\content\lib\neterror.xhtml
    c:\program files (x86)\myfreezetoolbar\chrome\content\lib\rsspreview.html
    c:\program files (x86)\myfreezetoolbar\chrome\content\lib\rsswin.xml
    c:\program files (x86)\myfreezetoolbar\chrome\content\lib\windowmediator.js
    c:\program files (x86)\myfreezetoolbar\chrome\content\modules\datastore.jsm
    c:\program files (x86)\myfreezetoolbar\chrome\content\myfreezetoolbar.js
    c:\program files (x86)\myfreezetoolbar\chrome\content\myfreezetoolbarabout.xml
    c:\program files (x86)\myfreezetoolbar\chrome\content\myfreezetoolbarpreferences.xml
    c:\program files (x86)\myfreezetoolbar\chrome\content\myfreezetoolbarrsswin.xml
    c:\program files (x86)\myfreezetoolbar\chrome\content\neterror.xhtml
    c:\program files (x86)\myfreezetoolbar\chrome\content\newtab\images\3quency_search_headbg.gif
    c:\program files (x86)\myfreezetoolbar\chrome\content\newtab\images\g5_q_s.gif
    c:\program files (x86)\myfreezetoolbar\chrome\content\newtab\images\g5_q_s2.gif
    c:\program files (x86)\myfreezetoolbar\chrome\content\newtab\images\pb_yahoo.gif
    c:\program files (x86)\myfreezetoolbar\chrome\content\newtab\images\pb_yahoo_t2.gif
    c:\program files (x86)\myfreezetoolbar\chrome\content\newtab\images\search_btn.gif
    c:\program files (x86)\myfreezetoolbar\chrome\content\newtab\newtab.html
    c:\program files (x86)\myfreezetoolbar\chrome\content\newtab\newtab_passionup.html
    c:\program files (x86)\myfreezetoolbar\chrome\content\passionuptoolbar.js
    c:\program files (x86)\myfreezetoolbar\chrome\content\passionuptoolbarabout.xml
    c:\program files (x86)\myfreezetoolbar\chrome\content\passionuptoolbarpreferences.xml
    c:\program files (x86)\myfreezetoolbar\chrome\content\passsionupneterror.xhtml
    c:\program files (x86)\myfreezetoolbar\chrome\content\sstest.js
    c:\program files (x86)\myfreezetoolbar\chrome\content\toolbar.htm
    c:\program files (x86)\myfreezetoolbar\chrome\content\toolbar.xul
    c:\program files (x86)\myfreezetoolbar\chrome\data\dynamicElements\freezetoolbar.xsl
    c:\program files (x86)\myfreezetoolbar\chrome\data\rss\rss.xml
    c:\program files (x86)\myfreezetoolbar\chrome\data\search\engine.xml
    c:\program files (x86)\myfreezetoolbar\chrome\data\search\enginePassionUp.xml
    c:\program files (x86)\myfreezetoolbar\chrome\data\search\engines.xml
    c:\program files (x86)\myfreezetoolbar\chrome\data\search\enginet1.xml
    c:\program files (x86)\myfreezetoolbar\chrome\data\search\enginet2.xml
    c:\program files (x86)\myfreezetoolbar\chrome\data\search\enginet3.xml
    c:\program files (x86)\myfreezetoolbar\chrome\data\search\enginet4.xml
    c:\program files (x86)\myfreezetoolbar\chrome\data\search\search.xsl
    c:\program files (x86)\myfreezetoolbar\chrome\skin\amazon.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\bizrate.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\blinkx.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\blue_arrow_preferences.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\bluelite.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\bluesky.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\btn-prefalone-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\btn-prefalone.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\btn-search-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\btn-search.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\btn-settings-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\btn-settings.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\btn-widgets-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\btn-widgets.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\dictionary.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\digg.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\dtxlogo.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\ebay.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\email.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\enthsports.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\facebook.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\freeze-logo-about.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\freeze-logo-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\freeze-logo.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\freeze-simpull-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\freeze-simpull.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\games.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred0.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred0_5.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred1.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred1_5.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred2.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred2_5.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred3.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred3_5.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred4.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred4_5.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphred5.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\graphredna.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\grey.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\ico-shield.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\ico-widgets2-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\ico-widgets2.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\images.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\imdb.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\imdb_search.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\add.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\aol.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\arrow-dn.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\arrow-right.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\arrow-up.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\bg-btn-end.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\bg-btn-mdl.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\bg-btn-start.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\bg-btnover-divider.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\bg-btnover-end.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\bg-btnover-mdl.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\bg-btnover-mdl_ff.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\bg-btnover-start.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\blank.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\btn-widgets-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\btn-widgets.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\btn_slider.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\btnback-down-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\btnback-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\btnleft-down-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\btnleft-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\btnright-down-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\btnright-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\button-splitter-down-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\button-splitter-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\checkmark.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\chevron.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\collapse.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\comcast.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\dtx.css
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\edit-back-hot.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\edit-back.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\expand.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\found.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\gmail.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\highlight.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\highlight_blue.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\highlight_cyan.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\highlight_lime.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\highlight_magenta.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\highlight_yellow.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\hotmail.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\imap.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\lastsearch-thumb-back.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\loadingMid.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\lock.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\mailcom.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menu_bg-basic.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menu_separator_bar.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menu_separator_white.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menuitem-splitter.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menuitemback-down-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menuitemback-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menuitemleft-down-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menuitemleft-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menuitemright-down-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\menuitemright-vista.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\modify.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\move.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\movetarget.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\css\popupGames.css
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\css\popupRSS.css
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\footer.htm
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\gamecategory.xsl
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\gameData.js
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\gameList.xsl
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\games.xsl
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\gametype.xsl
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\arrow-dn.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\arrow-sml-drop.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\arrow-sml.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\arrow-up.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\arrowr-bluew5.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\bg-btnover.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\bg-pnl520x390.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\btn-close-grey.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\btn-close-greyover.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\btn-next-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\btn-next.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\btn-previous-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\btn-previous.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\btn-search-pnlbtm.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\bullet-orange.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\gamethumb-on.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\gamethumb2-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\ico-joystick24.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\ico-news24.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\ico-play.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\icon-download.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\icon-Info.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\icon-play.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\icon-shop.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\menul-bgon.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\menul-bgover.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\panel-botm-noscroll.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scroll-bg-206.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scroll-bg.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scroll-topwin.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scrollb-disable.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scrollb-down.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scrollb-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scrollb.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scrollt-disable.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scrollt-down.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scrollt-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\scrollt.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\images\searchbox-pnlbtm.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\popupGames.html
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\panels\popupRSS.html
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\pop.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\radio.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\reload.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\remove.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\rename.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\resize-box.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\rss.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\rsschannelback.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\RSSLogo.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\rsstabdivider.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\scroll-left.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\scroll-right.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\search-go.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\search.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\text-ellipsis.xml
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\toolbarsplitter.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\transparent_1px.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_02.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_03.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_04.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_06.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_07.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_08.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_09.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_10.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_11.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_12.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_13.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_14.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_15.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_16.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_18.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_19.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_20.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\border_21.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\btn-close-grey.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\btn-close-greyover.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\close-hot.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\close-normal.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\loadingMid.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\proxy.html
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\template.html
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\template.xml
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\templateFF.html
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\uwa\throbber.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\alert-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\alert.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\clearnight-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\clearnight.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\clouds-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\clouds.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\cond051.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\cond999.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\drizzle-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\drizzle.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\flurries-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\flurries.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\flurriesday-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\flurriesday.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\fog-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\fog.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\freezingdrizzle-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\freezingdrizzle.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\freezingrain-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\freezingrain.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\frozenmix-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\frozenmix.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\haze-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\haze.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\hazenight-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\hazenight.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\heavyrain-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\heavyrain.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\heavysnow-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\heavysnow.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\hotandhumid-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\hotandhumid.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\icons.xml
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\lightsnow-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\lightsnow.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\mostlycloudynight-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\mostlycloudynight.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\na-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\na.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\partlycloudnight-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\partlycloudnight.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\partlysunny-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\partlysunny.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\rain-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\rain.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\scatteredcloudsday-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\scatteredcloudsday.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\scatteredcloudsnight-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\scatteredcloudsnight.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\scatteredshowersday-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\scatteredshowersday.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\scatteredthunderstorms-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\scatteredthunderstorms.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\showers-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\showers.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\showersday-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\showersday.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\sleet-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\sleet.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\snow-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\snow.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\snowshowers-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\snowshowers.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\snowshowersday-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\snowshowersday.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\sunny-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\sunny.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\thunders-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\thunders.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\thundersday-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\thundersday.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\verycoldday-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\verycoldday.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\verycoldnight-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\verycoldnight.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\veryhot-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\veryhot.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\weather.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\wind-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\icons\wind.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\add.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\box-check.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\ico-check.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\options-weather.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\over-blue.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\over-orange.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\popupWeather.css
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\weatherbutton\panels\popupWeather.html
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lib\yahoo.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\lichen.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\modify-save.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\music.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\music2.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\myfreezetoolbar.css
    c:\program files (x86)\myfreezetoolbar\chrome\skin\myspace.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\news.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\nextag.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\options\options-main.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\options\options-search.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\options\options-weather.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\orange.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\pandora.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\passionuptoolbar.css
    c:\program files (x86)\myfreezetoolbar\chrome\skin\pup-logo-over.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\pup-logo.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\relatedlinks.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\ringtones.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-collapse.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-delete.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-expand.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-feed.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-folder-remove.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-folder-rename.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-folder.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-found.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-reload.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rss-subscribe.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\rsstopback.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\screensavers.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\searchbar\searchbar-background-left.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\searchbar\searchbar-background-middle.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\searchbar\searchbar-background-right.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\searchbar\searchbar-sm-background-left.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\searchme-video.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\searchmemusic.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\settings.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\shopping.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\shopzilla.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\siteinfo.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\skin-bluelite.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\skin-bluesky.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\skin-grey.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\skin-lichen.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\skin-orange.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\skin-yellow.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\thesaurus.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\throbber.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\tmz.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\tmz_trans.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\translate.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\tv.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\twitter.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\user1_add.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\web.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\wikipedia.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\y_icon.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yahoo-local_v3.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yahoo-shopping.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yahoo-video.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yahoo-video_v3.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yahoo.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yahoolocal.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yahoomusic.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yahoonews.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yahoosearch.png
    c:\program files (x86)\myfreezetoolbar\chrome\skin\yellow.gif
    c:\program files (x86)\myfreezetoolbar\chrome\skin\youtube.png
    c:\program files (x86)\myfreezetoolbar\freezetoolbar.xml
    c:\program files (x86)\myfreezetoolbar\install.ico
    c:\program files (x86)\myfreezetoolbar\install.rdf
    c:\program files (x86)\myfreezetoolbar\manifest.xml
    c:\program files (x86)\myfreezetoolbar\myfreezedx.dll
    c:\program files (x86)\myfreezetoolbar\myfreezetoolbar.dll
    c:\program files (x86)\myfreezetoolbar\paramString.dat
    c:\program files (x86)\myfreezetoolbar\setupCfg.xml
    c:\program files (x86)\myfreezetoolbar\uninstall.exe
    c:\program files (x86)\Recipe Feeder
    c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\AddinExpress.IE.dll
    c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
    c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll.manifest
    c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxregext.exe
    c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\Bewiki_IE_Extension.dll
    c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\Bewiki_IE_Extension.IEModule.31914638(Active).ico
    c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\Bewiki_IE_Extension.IEModule.31914638(Inactive).ico
    c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\Interop.SHDocVw.dll
    J:\Autorun.inf
    J:\Setup.exe
    .
    ---- Previous Run -------
    .
    c:\program files (x86)\AV7\antivirus7.exe.tmp1
    c:\program files (x86)\Blinkx\blinkx.ico
    c:\program files (x86)\Blinkx\blinkxss.exe
    c:\program files (x86)\Blinkx\blinkxstop.exe
    c:\program files (x86)\Blinkx\lang.dll
    c:\program files (x86)\Blinkx\templates\beat.ico
    c:\program files (x86)\Blinkx\templates\index.html
    c:\program files (x86)\Blinkx\templates\noflash.html
    c:\program files (x86)\Blinkx\templates\offline.html
    c:\program files (x86)\Blinkx\templates\offline.swf
    c:\program files (x86)\Blinkx\templates\uninstall.exe
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\ChromeInstaller.dll
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\ChromeInstaller.InstallState
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\Fantapper.crx
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\Fantapper.xpi
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\FirefoxInstaller.dll
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\FirefoxInstaller.InstallState
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\FT_Enabled.ico
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\FT_Plugin_Installer.jpg
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\IEInstaller.dll
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\OpenIE.dll
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\OpenIE.InstallState
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.InstallState
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Updater\FT_Enabled.ico
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Updater\FT_Plugin_Installer.jpg
    c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
    c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoods.crx
    c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoods.png
    c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsApp.dll
    c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsEng.dll
    c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe
    c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
    c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\uninstall.exe
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64bar.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64dlghk.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64hkstub.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64Plugin.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64radio.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64reghk.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64sknlcr.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64SrcAs.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64SrchMn.exe
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\64tpinst.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\BOOTSTRAP.JS
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\CHROME.MANIFEST
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\chrome\64ffxtbr.jar
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\CREXT.DLL
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\CrExtP64.exe
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\INSTALL.RDF
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\installKeys.js
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\LOGO.BMP
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\NP64Stub.dll
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\T8EXTEX.DLL
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\T8EXTPEX.DLL
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\T8HTML.DLL
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\T8RES.DLL
    c:\program files (x86)\TelevisionFanatic\bar\1.bin\T8TICKER.DLL
    c:\program files (x86)\TelevisionFanatic\bar\gen1\COMMON.T8S
    c:\program files (x86)\TelevisionFanatic\bar\IE9Mesg\COMMON.T8S
    c:\program files (x86)\TelevisionFanatic\bar\Message\COMMON.T8S
    c:\program files (x86)\TelevisionFanatic\bar\Settings\s_pid.dat
    c:\program files (x86)\Windows Searchqu Toolbar\uninstall.exe
    c:\programdata\Herofy\save.aps
    c:\users\angel\AppData\Local\assembly\tmp\0H8KL0UV\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\0H8KL0UV\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\0SF705OE\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\0SF705OE\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\13CAIXBV\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\13CAIXBV\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\18GTP9A9\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\18GTP9A9\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\1GCTMKNZ\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\1GCTMKNZ\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\1KPGV8MQ\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\1KPGV8MQ\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\1L3QXOC3\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\1L3QXOC3\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\1RGCC5VH\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\1RGCC5VH\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\22XB7TQW\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\22XB7TQW\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\273SU7FW\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\273SU7FW\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\2CDH784H\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\2CDH784H\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\2FSX27XI\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\2FSX27XI\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\2JOJEVXK\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\2JOJEVXK\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\2JS2TVWE\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\2JS2TVWE\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\2MXHF5WV\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\2MXHF5WV\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\3072BXP7\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\3072BXP7\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\3372E7Z8\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\3372E7Z8\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\34ORVSUD\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\34ORVSUD\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\3IX7LHRL\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\3IX7LHRL\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\3TQHOYEX\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\3TQHOYEX\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\417SAXTQ\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\417SAXTQ\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\42YPIL5I\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\42YPIL5I\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\46JD3QP5\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\46JD3QP5\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\4ADHF3PM\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\4ADHF3PM\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\4MPFV0ZD\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\4MPFV0ZD\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\4V9JTHH3\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\4V9JTHH3\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\4VY1NTT4\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\4VY1NTT4\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\57KJF6EE\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\57KJF6EE\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\5CEDMUXU\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\5CEDMUXU\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\5OUR7V3S\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\5OUR7V3S\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\6K2PS5Y9\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\6K2PS5Y9\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\6RIELMJF\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\6RIELMJF\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\6S4WJZP8\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\6S4WJZP8\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\76Q4FGW4\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\76Q4FGW4\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\7B7A6I2A\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\7B7A6I2A\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\7HW8EH14\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\7HW8EH14\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\7UFEE01E\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\7UFEE01E\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\8FNBH8VK\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\8FNBH8VK\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\8KWNPY2W\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\8KWNPY2W\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\8MYZE8NY\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\8MYZE8NY\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\8ZFACHNN\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\8ZFACHNN\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\91ZHA43F\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\91ZHA43F\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\9EBJQIC5\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\9EBJQIC5\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\9S3XRUAK\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\9S3XRUAK\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\9X6N2586\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\9X6N2586\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\A4FAAOIU\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\A4FAAOIU\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\AKOALI22\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\AKOALI22\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\APMDSEZ0\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\APMDSEZ0\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\ARU1U7RN\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\ARU1U7RN\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\B1HESDT5\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\B1HESDT5\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\BVV0AOE0\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\BVV0AOE0\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\BYBN7KD9\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\BYBN7KD9\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\C18J54E7\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\C18J54E7\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\C6BX6QQ8\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\C6BX6QQ8\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\CCRO2JPT\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\CCRO2JPT\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\CNR56DW5\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\CNR56DW5\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\D3VI3SGW\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\D3VI3SGW\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\D8I66753\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\D8I66753\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\D93M1VSO\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\D93M1VSO\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\DFK22MLG\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\DFK22MLG\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\DK7W3T66\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\DK7W3T66\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\DQTIBK27\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\DQTIBK27\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\DVFC91QQ\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\DVFC91QQ\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\E4QDKYH0\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\E4QDKYH0\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\FDMXX31J\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\FDMXX31J\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\FEFGP4LO\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\FEFGP4LO\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\FIDXNY3S\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\FIDXNY3S\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\G7U56N8B\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\G7U56N8B\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\GI79AAER\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\GI79AAER\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\GJ3S7MSJ\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\GJ3S7MSJ\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\GOYNP4P4\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\GOYNP4P4\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\GQI30BH6\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\GQI30BH6\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\GYDJ91TS\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\GYDJ91TS\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\H9UKBZUY\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\H9UKBZUY\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\IF0S7VRU\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\IF0S7VRU\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\IFUQIXYH\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\IFUQIXYH\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\IUPMNTGS\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\IUPMNTGS\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\IWB3UM5M\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\IWB3UM5M\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\JLKKUBXK\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\JLKKUBXK\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\JZ8Y81Z9\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\JZ8Y81Z9\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\KQ0QCNWN\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\KQ0QCNWN\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\KROJEK0E\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\KROJEK0E\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\KZWS32XZ\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\KZWS32XZ\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\LAX5Y7HO\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\LAX5Y7HO\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\LKBJWAWL\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\LKBJWAWL\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\LMFWH32T\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\LMFWH32T\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\MLJZI02R\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\MLJZI02R\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\MSEXQ5KW\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\MSEXQ5KW\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\MTENUMYX\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\MTENUMYX\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\N86N4RYM\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\N86N4RYM\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\O6RU0M1A\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\O6RU0M1A\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\O9SG38FA\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\O9SG38FA\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\OHVN00UJ\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\OHVN00UJ\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\OMO1XSJ1\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\OMO1XSJ1\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\OTGX2QYK\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\OTGX2QYK\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\P1R4PIDF\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\P1R4PIDF\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\P4GFUJ64\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\P4GFUJ64\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\PCESLSDV\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\PCESLSDV\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\Q150BXZA\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\Q150BXZA\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\Q90YSHUK\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\Q90YSHUK\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\Q937OS6F\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\Q937OS6F\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\QK9CWBZN\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\QK9CWBZN\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\QTHET99T\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\QTHET99T\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\R69AMVGT\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\R69AMVGT\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\R8GKWUIJ\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\R8GKWUIJ\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\RH3FO939\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\RH3FO939\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\RTMQCOBW\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\RTMQCOBW\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\RU3Q2B3W\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\RU3Q2B3W\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\SBQHNWQ4\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\SBQHNWQ4\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\SN1CG27X\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\SN1CG27X\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\SO7WIKL9\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\SO7WIKL9\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\UMCMDK7T\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\UMCMDK7T\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\UR0T76H2\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\UR0T76H2\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\UVNY5XXB\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\UVNY5XXB\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\VAYFLY6L\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\VAYFLY6L\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\W044KZFX\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\W044KZFX\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\WADIE9OV\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\WADIE9OV\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\WAYP2ZS1\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\WAYP2ZS1\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\WJ37C8WJ\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\WJ37C8WJ\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\WKIFG1L5\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\WKIFG1L5\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\WUNKTWO5\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\WUNKTWO5\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\WWPRZF9W\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\WWPRZF9W\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\X2BNCS9H\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\X2BNCS9H\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\X6BA0CYH\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\X6BA0CYH\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\XSDK2LY8\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\XSDK2LY8\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\YBXQIUNF\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\YBXQIUNF\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\Z3CHCJAB\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\Z3CHCJAB\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\ZV732QLB\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\ZV732QLB\AddinExpress.IE.DLL
    c:\users\angel\AppData\Local\assembly\tmp\ZYL4CFDU\__AssemblyInfo__.ini
    c:\users\angel\AppData\Local\assembly\tmp\ZYL4CFDU\AddinExpress.IE.DLL
    c:\users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\bootstrap.js
    c:\users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\chrome.manifest
    c:\users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\chrome\64ffxtbr.jar
    c:\users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\install.rdf
    c:\users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\META-INF\manifest.mf
    c:\users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\META-INF\zigbert.rsa
    c:\users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\extensions\64ffxtbr@TelevisionFanatic.com\META-INF\zigbert.sf
    c:\windows\security\Database\tmp.edb
    .
    .
    (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Service_FTSvc
    -------\Service_FTSvc
    .
    .
    (((((((((((((((((((((((((   Files Created from 2013-02-03 to 2013-03-03  )))))))))))))))))))))))))))))))
    .
    .
    2013-03-03 22:47 . 2013-03-03 22:52    --------    d-----w-    c:\users\angel\AppData\Local\temp
    2013-02-28 06:01 . 2013-01-05 05:37    4695400    ----a-w-    c:\windows\system32\ntoskrnl.exe
    2013-02-27 00:04 . 2013-02-27 00:04    --------    d-----w-    c:\program files\CCleaner
    2013-02-25 05:05 . 2013-02-25 05:05    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-02-08 00:28 . 2013-02-28 06:05    9162192    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{F65BEF3D-4D06-4D66-83E5-4FA0633DBA9D}\mpengine.dll
    2013-01-17 09:28 . 2009-10-05 21:49    273840    ------w-    c:\windows\system32\MpSigStub.exe
    2012-12-23 11:05 . 2006-11-02 12:35    67413224    ----a-w-    c:\windows\system32\mrt.exe
    2012-12-16 13:31 . 2012-12-23 11:00    48128    ----a-w-    c:\windows\system32\atmlib.dll
    2012-12-16 13:12 . 2012-12-23 11:00    34304    ----a-w-    c:\windows\SysWow64\atmlib.dll
    2012-12-16 11:08 . 2012-12-23 11:00    368128    ----a-w-    c:\windows\system32\atmfd.dll
    2012-12-16 10:50 . 2012-12-23 11:00    293376    ----a-w-    c:\windows\SysWow64\atmfd.dll
    .
    .
    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll" [2012-06-11 1524056]
    .
    [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
    [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
    [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
    [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41403228-8910-4CA2-9939-DA9C9A6A58A7}]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{8A86D350-37AB-410A-8531-7D1363F317B3}]
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll [BU]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{CB0D163C-E9F4-4236-9496-0597E24B23A5}]
    2011-11-01 15:24    894616    ----a-w-    c:\program files (x86)\GamesBar\2.0.1.109\oberontb.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7}]
    c:\program files (x86)\RegTweaker\key.dll [BU]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Power2GoExpress"="NA" [X]
    "PhotoShow Deluxe Media Manager"="c:\progra~2\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe" [2004-06-01 184320]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
    "DW7"="c:\program files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe" [2012-06-02 10555904]
    "Exetender_179"="c:\program files (x86)\qZone Games Player\GPlayer.exe" [2010-12-05 4892672]
    "SearchEngineProtection"="c:\program files (x86)\GamesBar\SearchEngineProtection.exe" [2011-11-01 616088]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2011-09-01 1047208]
    "Conime"="c:\windows\system32\conime.exe" [2009-04-11 69120]
    "ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
    "IconixOEAddOn"="c:\program files (x86)\eMail ID\OEAddOn\OEdmn_6.exe" [2010-05-10 342872]
    "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-10-21 273528]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
    "YMailAdvisor"="c:\program files (x86)\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
    "TelevisionFanatic Search Scope Monitor"="c:\progra~2\TELEVI~2\bar\1.bin\64srchmn.exe" [BU]
    "CenturyLinkTouchPointAgent"="c:\program files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe" [2011-12-02 46208]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}"="c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe" [2012-10-11 143928]
    .
    c:\users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    HP SimpleSave Monitor.lnk - c:\users\angel\AppData\Roaming\HP SimpleSave Application\StartHelper.exe [2010-12-26 477080]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-6-12 1207312]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\syswow64\userinit.exe,"
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "LoadAppInit_DLLs"=1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute    REG_MULTI_SZ       autocheck autochk *\0
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
    @="Service"
    .
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
    Themes
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2013-03-03 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-29 15:10]
    .
    2013-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-05 17:01]
    .
    2013-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-05 17:01]
    .
    2012-12-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-794020852-758203237-1877864742-1000Core.job
    - c:\users\angel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 22:09]
    .
    2013-03-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-794020852-758203237-1877864742-1000UA.job
    - c:\users\angel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 22:09]
    .
    2012-10-23 c:\windows\Tasks\HPCeeScheduleForangel.job
    - c:\program files (x86)\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2008-08-28 03:03]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 15851040]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 82464]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
    "EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2010-09-02 2045440]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=c:\progra~2\SEARCH~2\Datamngr\x64\IEBHO.dll
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.mycenturylink.com/
    mStart Page = hxxp://www.yahoo.com/?ilc=8
    mDefault_Page_URL = hxxp://www.yahoo.com/?ilc=8
    mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = <local>;*.local
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant =
    IE: &Windows Live Search - c:\program files (x86)\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: {{14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
    Trusted Zone: hp.com\pavilion.buttonredirect
    Trusted Zone: hp.com\presario.buttonredirect
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    TCP: DhcpNameServer = 192.168.2.1
    FF - ProfilePath - c:\users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.mycenturylink.com/
    FF - ExtSQL: !HIDDEN! 1970-01-16 04:44; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files (x86)\Searchqu Toolbar\Datamngr\FirefoxExtension
    FF - ExtSQL: !HIDDEN! 2009-06-24 11:45; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - ExtSQL: !HIDDEN! 2012-07-19 05:44; 64ffxtbr@TelevisionFanatic.com; c:\program files (x86)\TelevisionFanatic\bar\1.bin
    .
    - - - - ORPHANS REMOVED - - - -
    .
    URLSearchHooks-{313a832a-aaf3-4880-a8d0-c42bee319c02} - (no file)
    URLSearchHooks-{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - (no file)
    BHO-{0bd6f992-62ad-47f7-aca6-299729be4e2b} - c:\program files (x86)\myfreezetoolbar\myfreezedx.dll
    BHO-{26D675AC-D925-4bbf-A720-62C2AA4A81EB} - (no file)
    BHO-{6a14e93a-dde3-4b64-8381-f3b68243d8f4} - c:\program files (x86)\file2linkrh\file2linkibX.dll
    BHO-{732e5459-a239-4e08-a411-2c6ccf313f1d} - c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
    BHO-{9F531FB1-7C1F-4e1a-8C0C-E8D6177130E2} - (no file)
    BHO-{C26CD490-5F01-41E3-B150-EB29F19DA056} - c:\program files (x86)\myfreezetoolbar\auxi\myfreezetoolbAu.dll
    BHO-{CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
    Toolbar-{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - (no file)
    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    ShellIconOverlayIdentifiers-{04cd1f3e-81d5-4904-a3ab-e0f99a7d769d} - (no file)
    Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
    WebBrowser-{313A832A-AAF3-4880-A8D0-C42BEE319C02} - (no file)
    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    WebBrowser-{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - (no file)
    ShellIconOverlayIdentifiers-{04cd1f3e-81d5-4904-a3ab-e0f99a7d769d} - (no file)
    AddRemove-BFG-Pirate Mysteries - A Tale of Monkeys, Masks, and Hidden Objects - c:\program files (x86)\Pirate Mysteries - A Tale of Monkeys
    AddRemove-file2linkrh - c:\program files (x86)\file2linkrh\uninstall.exe
    AddRemove-myfreezetoolbar - c:\program files (x86)\myfreezetoolbar\uninstall.exe
    AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MCLIENT]
    "ImagePath"="\"c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe\" /s \"MCLIENT\" /m \"c:\program files (x86)\Norton Management\Engine\3.2.0.19\diMaster.dll\" /prefetch:1"
    --
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PCCUJobMgr]
    "ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.7.49\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.7.49\diMaster.dll\" /prefetch:1"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
    @Denied: (2) (LocalSystem)
    "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=hex:51,66,7a,6c,4c,1d,38,12,5c,be,8a,
       eb,c9,8f,bc,54,f6,39,43,d0,22,43,0b,9c
    "{07B18EA9-A523-4961-B6BB-170DE4475CCA}"=hex:51,66,7a,6c,4c,1d,38,12,c7,8d,a2,
       03,11,eb,0f,0c,c9,ad,54,4d,e1,19,18,de
    "{C7C9FC25-88B0-4682-9C9F-2608E9117647}"=hex:51,66,7a,6c,4c,1d,38,12,4b,ff,da,
       c3,82,c6,ec,03,e3,89,65,48,ec,4f,32,53
    "{0BD6F992-62AD-47F7-ACA6-299729BE4E2B}"=hex:51,66,7a,6c,4c,1d,38,12,fc,fa,c5,
       0f,9f,2c,99,02,d3,b0,6a,d7,2c,e0,0a,3f
    "{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}"=hex:51,66,7a,6c,4c,1d,38,12,aa,48,59,
       c1,54,67,c2,05,e3,b2,ee,c6,38,3f,0c,fa
    "{30F9B915-B755-4826-820B-08FBA6BD249D}"=hex:51,66,7a,6c,4c,1d,38,12,7b,ba,ea,
       34,67,f9,48,0d,fd,1d,4b,bb,a3,e3,60,89
    "{22E03916-85C5-44B0-8DC9-1830C11238D9}"=hex:51,66,7a,6c,4c,1d,38,12,78,3a,f3,
       26,f7,cb,de,01,f2,df,5b,70,c4,4c,7c,cd
    "{7FF99715-3016-4381-84CE-E4E4C9673020}"=hex:51,66,7a,6c,4c,1d,38,12,7b,94,ea,
       7b,24,7e,ef,06,fb,d8,a7,a4,cc,39,74,34
    "{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,
       0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70
    "{A317CB83-299C-4FC8-9ED7-2D64117D98EE}"=hex:51,66,7a,6c,4c,1d,38,12,ed,c8,04,
       a7,ae,67,a6,0a,e1,c1,6e,24,14,23,dc,fa
    "{6F282B65-56BF-4BD1-A8B2-A4449A05863D}"=hex:51,66,7a,6c,4c,1d,38,12,0b,28,3b,
       6b,8d,18,bf,0e,d7,a4,e7,04,9f,5b,c2,29
    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
       27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
    "{3462C343-BE19-4143-AF70-CEFB56F46FC6}"=hex:51,66,7a,6c,4c,1d,38,12,2d,c0,71,
       30,2b,f0,2d,04,d0,66,8d,bb,53,aa,2b,d2
    "{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4,
       91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27
    "{00A6FAF1-072E-44CF-8957-5838F569A31D}"=hex:51,66,7a,6c,4c,1d,38,12,9f,f9,b5,
       04,1c,49,a1,01,f6,41,1b,78,f0,37,e7,09
    "{02478D38-C3F9-4EFB-9B51-7695ECA05670}"=hex:51,66,7a,6c,4c,1d,38,12,56,8e,54,
       06,cb,8d,95,0b,e4,47,35,d5,e9,fe,12,64
    "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,38,12,f1,9d,97,
       02,e5,86,37,08,c7,6b,3b,0b,78,35,a4,a7
    "{07B18EA1-A523-4961-B6BB-170DE4475CCA}"=hex:51,66,7a,6c,4c,1d,38,12,cf,8d,a2,
       03,11,eb,0f,0c,c9,ad,54,4d,e1,19,18,de
    "{1631550F-191D-4826-B069-D9439253D926}"=hex:51,66,7a,6c,4c,1d,38,12,61,56,22,
       12,2f,57,48,0d,cf,7f,9a,03,97,0d,9d,32
    "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
       1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
    "{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a,
       34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de
    "{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}"=hex:51,66,7a,6c,4c,1d,38,12,e1,1f,51,
       3e,0a,ac,85,0f,f7,62,fb,f5,f7,92,03,66
    "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,
       38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4
    "{60E91567-EF8A-4520-BCE2-83ABA5256799}"=hex:51,66,7a,6c,4c,1d,38,12,09,16,fa,
       64,b8,a1,4e,00,c3,f4,c0,eb,a0,7b,23,8d
    "{6D53EC84-6AAE-4787-AEEE-F4628F01010C}"=hex:51,66,7a,6c,4c,1d,38,12,ea,ef,40,
       69,9c,24,e9,02,d1,f8,b7,22,8a,5f,45,18
    "{6EBF7485-159F-4BFF-A14F-B9E3AAC4465B}"=hex:51,66,7a,6c,4c,1d,38,12,eb,77,ac,
       6a,ad,5b,91,0e,de,59,fa,a3,af,9a,02,4f
    "{732E5459-A239-4E08-A411-2C6CCF313F1D}"=hex:51,66,7a,6c,4c,1d,38,12,37,57,3d,
       77,0b,ec,66,0b,db,07,6f,2c,ca,6f,7b,09
    "{761233B6-F228-49E4-8F6B-668499D4E55A}"=hex:51,66,7a,6c,4c,1d,38,12,d8,30,01,
       72,1a,bc,8a,0c,f0,7d,25,c4,9c,8a,a1,4e
    "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
       94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
    "{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
       9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
    "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
       ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
    "{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,
       b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb
    "{C26CD490-5F01-41E3-B150-EB29F19DA056}"=hex:51,66,7a,6c,4c,1d,38,12,fe,d7,7f,
       c6,33,11,8d,04,ce,46,a8,69,f4,c3,e4,42
    "{CB0D163C-E9F4-4236-9496-0597E24B23A5}"=hex:51,66,7a,6c,4c,1d,38,12,52,15,1e,
       cf,c6,a7,58,07,eb,80,46,d7,e7,15,67,b1
    "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
       df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
    "{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}"=hex:51,66,7a,6c,4c,1d,38,12,e0,a3,9c,
       e7,58,bb,07,04,d4,e3,1f,31,e6,9f,17,b5
    "{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}"=hex:51,66,7a,6c,4c,1d,38,12,cf,4e,be,
       f9,90,2f,b6,0a,e3,01,c5,b7,a9,7a,14,95
    "{14528701-EB26-4DDD-BDF3-5B3A3BF85CA5}"=hex:51,66,7a,6c,4c,1d,38,12,6f,84,41,
       10,14,a5,b3,08,c2,e5,18,7a,3e,a6,18,b1
    "{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}"=hex:51,66,7a,6c,4c,1d,38,12,49,e1,1e,
       1a,d6,12,cd,0b,d4,1a,c8,43,e4,f4,32,a8
    "{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,38,12,e4,48,13,
       36,9b,0a,89,06,fb,ff,c3,c8,3d,de,d1,0d
    .
    [HKEY_USERS\S-1-5-21-794020852-758203237-1877864742-1000\Software\SecuROM\License information*]
    "datasecu"=hex:4e,e3,fb,d8,e4,b3,bb,f9,d0,71,e5,18,7c,6a,1a,6b,31,5f,94,ad,eb,
       c4,0f,f0,7a,e2,d2,28,67,73,ea,43,9b,85,1e,3d,59,1c,dc,3c,f7,6d,58,fa,42,a4,\
    "rkeysecu"=hex:af,20,be,c1,13,3c,d2,93,b7,47,0f,fe,50,30,7e,79
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
    @="Shockwave Flash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
    @Denied: (A 2) (Everyone)
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
    @="FlashBroker"
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
       00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    c:\users\angel\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
    c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe
    c:\program files (x86)\Common Files\eMail ID\IconixService.exe
    c:\program files (x86)\Kodak\AiO\Center\ekdiscovery.exe
    c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
    c:\program files (x86)\Norton PC Checkup\Engine\2.0.7.49\ccSvcHst.exe
    c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe
    c:\program files (x86)\Common Files\supportsoft\bin\sprtlisten.exe
    c:\program files (x86)\Spyware Terminator\sp_rsser.exe
    c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\program files (x86)\Norton PC Checkup\Engine\2.0.7.49\ccSvcHst.exe
    c:\program files (x86)\Simple Star\PhotoShow Deluxe 3\data\Xtras\mssysmgr.exe
    c:\program files (x86)\Norton PC Checkup\Engine\2.0.7.49\SymcPCCULaunchSvc.exe
    c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe
    c:\program files (x86)\real\realplayer\RealPlay.exe
    .
    **************************************************************************
    .
    Completion time: 2013-03-03  15:01:16 - machine was rebooted
    ComboFix-quarantined-files.txt  2013-03-03 23:01
    .
    Pre-Run: 337,723,535,360 bytes free
    Post-Run: 334,519,160,832 bytes free
    .
    - - End Of File - - 651AFF02C9F704F07255896E21577EED
     



    #6 nasdaq

    nasdaq

    • Malware Response Team
    • 38,936 posts
    • OFFLINE
    •  
    • Gender:Male
    • Location:Montreal, QC. Canada
    • Local time:01:29 AM

    Posted 04 March 2013 - 11:38 AM

    Lets continue.
     
    Open notepad and copy/paste the text in the quote box below into it:
     
    DDS::
    IE: {{14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
     
    Firefox::
    FF - ExtSQL: !HIDDEN! 1970-01-16 04:44; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files (x86)\Searchqu Toolbar\Datamngr\FirefoxExtension
    FF - ExtSQL: !HIDDEN! 2012-07-19 05:44; 64ffxtbr@TelevisionFanatic.com; c:\program files (x86)\TelevisionFanatic\bar\1.bin
     
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{CB0D163C-E9F4-4236-9496-0597E24B23A5}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SearchEngineProtection"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=-
    
     
     
    Save this as CFScript.txt on your desktop.
     
     
    Referring to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.
     
    Let me know what problem persists.


    #7 ConnJohnn

    ConnJohnn
    • Topic Starter

    • Members
    • 15 posts
    • OFFLINE
    •  
    • Local time:09:29 PM

    Posted 05 March 2013 - 12:30 AM

    Still no sign of application errors.  Seems to be runnnig a bit slow still, but a bit quicker than before as I defragmented the hdd.  Upon booting into Windows, the desktop takes an awful long time to load; taskbar is visible but the wallpaper is just white for a few minutes beofre loading fully.  I forgot to mention before that rundll32.exe is a process always running.  I attempt to End Process but I get Access Denied; this is still happening.

     

    Update ComboFix Log..

     

    ComboFix 13-03-02.01 - angel 03/04/2013  20:58:34.1.4 - x64
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.6014.3718 [GMT -8:00]
    Running from: c:\users\angel\Desktop\ComboFix.exe
    Command switches used :: c:\users\angel\Desktop\CFScript.txt
    AV: AVG Anti-Virus 2012 *Disabled/Outdated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus 2012 *Disabled/Outdated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\SysWow64\BSTIEPrintCtl1.dll
    c:\windows\SysWow64\jucheck.exe
    c:\windows\SysWow64\jusched.exe
    .
    .
    (((((((((((((((((((((((((   Files Created from 2013-02-05 to 2013-03-05  )))))))))))))))))))))))))))))))
    .
    .
    2013-03-05 05:08 . 2013-03-05 05:08    --------    d-----w-    c:\windows\system32\config\systemprofile\AppData\Local\temp
    2013-03-05 05:08 . 2013-03-05 05:08    --------    d-----w-    c:\users\Default\AppData\Local\temp
    2013-03-04 00:20 . 2013-01-09 01:10    996352    ----a-w-    c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
    2013-03-04 00:20 . 2013-01-08 22:01    768000    ----a-w-    c:\program files (x86)\Common Files\Microsoft Shared\vgx\VGX.dll
    2013-03-03 23:11 . 2013-03-03 23:11    --------    d-----w-    C:\6eabc6d4ce0ffe0dc03b47054026d6
    2013-03-03 23:01 . 2013-03-05 05:08    --------    d-----w-    c:\users\angel\AppData\Local\temp
    2013-03-03 06:47 . 2013-03-03 06:47    3752    ----a-w-    c:\windows\DeleteOnReboot.bat
    2013-02-28 06:05 . 2013-02-08 00:28    9162192    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{F65BEF3D-4D06-4D66-83E5-4FA0633DBA9D}\mpengine.dll
    2013-02-28 06:04 . 2013-01-04 11:31    1417576    ----a-w-    c:\windows\system32\drivers\tcpip.sys
    2013-02-28 06:04 . 2013-01-04 02:23    40448    ----a-w-    c:\windows\system32\drivers\tcpipreg.sys
    2013-02-28 06:04 . 2013-01-04 01:59    2773504    ----a-w-    c:\windows\system32\win32k.sys
    2013-02-28 06:02 . 2012-11-08 04:26    1570816    ----a-w-    c:\windows\system32\quartz.dll
    2013-02-28 06:02 . 2012-11-08 03:48    1314816    ----a-w-    c:\windows\SysWow64\quartz.dll
    2013-02-28 06:01 . 2013-01-05 05:37    4695400    ----a-w-    c:\windows\system32\ntoskrnl.exe
    2013-02-27 00:04 . 2013-02-27 00:04    --------    d-----w-    c:\program files\CCleaner
    2013-02-25 05:05 . 2013-02-25 05:05    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-02-05 06:49 . 2006-11-02 12:35    70004024    ----a-w-    c:\windows\system32\mrt.exe
    2013-01-17 09:28 . 2009-10-05 21:49    273840    ------w-    c:\windows\system32\MpSigStub.exe
    2012-12-16 13:31 . 2012-12-23 11:00    48128    ----a-w-    c:\windows\system32\atmlib.dll
    2012-12-16 13:12 . 2012-12-23 11:00    34304    ----a-w-    c:\windows\SysWow64\atmlib.dll
    2012-12-16 11:08 . 2012-12-23 11:00    368128    ----a-w-    c:\windows\system32\atmfd.dll
    2012-12-16 10:50 . 2012-12-23 11:00    293376    ----a-w-    c:\windows\SysWow64\atmfd.dll
    .
    .
    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn9\yt.dll" [2012-06-11 1524056]
    .
    [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
    [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
    [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
    [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{0bd6f992-62ad-47f7-aca6-299729be4e2b}]
    c:\program files (x86)\myfreezetoolbar\myfreezedx.dll [BU]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41403228-8910-4CA2-9939-DA9C9A6A58A7}]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6a14e93a-dde3-4b64-8381-f3b68243d8f4}]
    c:\program files (x86)\file2linkrh\file2linkibX.dll [BU]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{732e5459-a239-4e08-a411-2c6ccf313f1d}]
    c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll [BU]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{8A86D350-37AB-410A-8531-7D1363F317B3}]
    c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll [BU]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C26CD490-5F01-41E3-B150-EB29F19DA056}]
    c:\program files (x86)\myfreezetoolbar\auxi\myfreezetoolbAu.dll [BU]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{CB0D163C-E9F4-4236-9496-0597E24B23A5}]
    2011-11-01 15:24    894616    ----a-w-    c:\program files (x86)\GamesBar\2.0.1.109\oberontb.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7}]
    c:\program files (x86)\RegTweaker\key.dll [BU]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Power2GoExpress"="NA" [X]
    "PhotoShow Deluxe Media Manager"="c:\progra~2\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe" [2004-06-01 184320]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
    "DW7"="c:\program files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe" [2012-06-02 10555904]
    "Exetender_179"="c:\program files (x86)\qZone Games Player\GPlayer.exe" [2010-12-05 4892672]
    "WMPNSCFG"="c:\program files (x86)\Windows Media Player\WMPNSCFG.exe" [BU]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2011-09-01 1047208]
    "Conime"="c:\windows\system32\conime.exe" [2009-04-11 69120]
    "ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
    "IconixOEAddOn"="c:\program files (x86)\eMail ID\OEAddOn\OEdmn_6.exe" [2010-05-10 342872]
    "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-10-21 273528]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
    "YMailAdvisor"="c:\program files (x86)\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
    "TelevisionFanatic Search Scope Monitor"="c:\progra~2\TELEVI~2\bar\1.bin\64srchmn.exe" [BU]
    "CenturyLinkTouchPointAgent"="c:\program files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe" [2011-12-02 46208]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}"="c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe" [2012-10-11 143928]
    .
    c:\users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    HP SimpleSave Monitor.lnk - c:\users\angel\AppData\Roaming\HP SimpleSave Application\StartHelper.exe [2010-12-26 477080]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-6-12 1207312]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "LoadAppInit_DLLs"=1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
    @="Service"
    .
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
    Themes
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2013-03-05 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-29 15:10]
    .
    2013-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-05 17:01]
    .
    2013-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-05 17:01]
    .
    2012-12-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-794020852-758203237-1877864742-1000Core.job
    - c:\users\angel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 22:09]
    .
    2013-03-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-794020852-758203237-1877864742-1000UA.job
    - c:\users\angel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 22:09]
    .
    2012-10-23 c:\windows\Tasks\HPCeeScheduleForangel.job
    - c:\program files (x86)\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2008-08-28 03:03]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 15851040]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 82464]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
    "EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2010-09-02 2045440]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.mycenturylink.com/
    mStart Page = hxxp://www.yahoo.com/?ilc=8
    mDefault_Page_URL = hxxp://www.yahoo.com/?ilc=8
    mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = <local>;*.local
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant =
    IE: &Windows Live Search - c:\program files (x86)\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: {{14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - {14528701-EB26-4DDD-BDF3-5B3A3BF85CA5} - c:\program files (x86)\Recipe Feeder\Recipe Feeder Explorer Bar\adxloader.dll
    Trusted Zone: hp.com\pavilion.buttonredirect
    Trusted Zone: hp.com\presario.buttonredirect
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    TCP: DhcpNameServer = 192.168.2.1
    FF - ProfilePath - c:\users\angel\AppData\Roaming\Mozilla\Firefox\Profiles\c3jc1uum.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.mycenturylink.com/
    FF - ExtSQL: !HIDDEN! 1970-01-16 04:44; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files (x86)\Searchqu Toolbar\Datamngr\FirefoxExtension
    FF - ExtSQL: !HIDDEN! 2009-06-24 11:45; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - ExtSQL: !HIDDEN! 2012-07-19 05:44; 64ffxtbr@TelevisionFanatic.com; c:\program files (x86)\TelevisionFanatic\bar\1.bin
    .
    - - - - ORPHANS REMOVED - - - -
    .
    BHO-{26D675AC-D925-4bbf-A720-62C2AA4A81EB} - (no file)
    BHO-{9F531FB1-7C1F-4e1a-8C0C-E8D6177130E2} - (no file)
    BHO-{CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
    Toolbar-{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - (no file)
    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    ShellIconOverlayIdentifiers-{04cd1f3e-81d5-4904-a3ab-e0f99a7d769d} - (no file)
    AddRemove-BFG-Pirate Mysteries - A Tale of Monkeys, Masks, and Hidden Objects - c:\program files (x86)\Pirate Mysteries - A Tale of Monkeys
    AddRemove-file2linkrh - c:\program files (x86)\file2linkrh\uninstall.exe
    AddRemove-myfreezetoolbar - c:\program files (x86)\myfreezetoolbar\uninstall.exe
    AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MCLIENT]
    "ImagePath"="\"c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe\" /s \"MCLIENT\" /m \"c:\program files (x86)\Norton Management\Engine\3.2.0.19\diMaster.dll\" /prefetch:1"
    --
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PCCUJobMgr]
    "ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.7.49\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.7.49\diMaster.dll\" /prefetch:1"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
    @Denied: (2) (LocalSystem)
    "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=hex:51,66,7a,6c,4c,1d,38,12,5c,be,8a,
       eb,c9,8f,bc,54,f6,39,43,d0,22,43,0b,9c
    "{07B18EA9-A523-4961-B6BB-170DE4475CCA}"=hex:51,66,7a,6c,4c,1d,38,12,c7,8d,a2,
       03,11,eb,0f,0c,c9,ad,54,4d,e1,19,18,de
    "{C7C9FC25-88B0-4682-9C9F-2608E9117647}"=hex:51,66,7a,6c,4c,1d,38,12,4b,ff,da,
       c3,82,c6,ec,03,e3,89,65,48,ec,4f,32,53
    "{0BD6F992-62AD-47F7-ACA6-299729BE4E2B}"=hex:51,66,7a,6c,4c,1d,38,12,fc,fa,c5,
       0f,9f,2c,99,02,d3,b0,6a,d7,2c,e0,0a,3f
    "{C54A4BC4-2966-40AC-9CA4-AD863D6148EE}"=hex:51,66,7a,6c,4c,1d,38,12,aa,48,59,
       c1,54,67,c2,05,e3,b2,ee,c6,38,3f,0c,fa
    "{30F9B915-B755-4826-820B-08FBA6BD249D}"=hex:51,66,7a,6c,4c,1d,38,12,7b,ba,ea,
       34,67,f9,48,0d,fd,1d,4b,bb,a3,e3,60,89
    "{22E03916-85C5-44B0-8DC9-1830C11238D9}"=hex:51,66,7a,6c,4c,1d,38,12,78,3a,f3,
       26,f7,cb,de,01,f2,df,5b,70,c4,4c,7c,cd
    "{7FF99715-3016-4381-84CE-E4E4C9673020}"=hex:51,66,7a,6c,4c,1d,38,12,7b,94,ea,
       7b,24,7e,ef,06,fb,d8,a7,a4,cc,39,74,34
    "{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,
       0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70
    "{A317CB83-299C-4FC8-9ED7-2D64117D98EE}"=hex:51,66,7a,6c,4c,1d,38,12,ed,c8,04,
       a7,ae,67,a6,0a,e1,c1,6e,24,14,23,dc,fa
    "{6F282B65-56BF-4BD1-A8B2-A4449A05863D}"=hex:51,66,7a,6c,4c,1d,38,12,0b,28,3b,
       6b,8d,18,bf,0e,d7,a4,e7,04,9f,5b,c2,29
    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
       27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
    "{3462C343-BE19-4143-AF70-CEFB56F46FC6}"=hex:51,66,7a,6c,4c,1d,38,12,2d,c0,71,
       30,2b,f0,2d,04,d0,66,8d,bb,53,aa,2b,d2
    "{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4,
       91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27
    "{00A6FAF1-072E-44CF-8957-5838F569A31D}"=hex:51,66,7a,6c,4c,1d,38,12,9f,f9,b5,
       04,1c,49,a1,01,f6,41,1b,78,f0,37,e7,09
    "{02478D38-C3F9-4EFB-9B51-7695ECA05670}"=hex:51,66,7a,6c,4c,1d,38,12,56,8e,54,
       06,cb,8d,95,0b,e4,47,35,d5,e9,fe,12,64
    "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,38,12,f1,9d,97,
       02,e5,86,37,08,c7,6b,3b,0b,78,35,a4,a7
    "{07B18EA1-A523-4961-B6BB-170DE4475CCA}"=hex:51,66,7a,6c,4c,1d,38,12,cf,8d,a2,
       03,11,eb,0f,0c,c9,ad,54,4d,e1,19,18,de
    "{1631550F-191D-4826-B069-D9439253D926}"=hex:51,66,7a,6c,4c,1d,38,12,61,56,22,
       12,2f,57,48,0d,cf,7f,9a,03,97,0d,9d,32
    "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
       1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
    "{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a,
       34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de
    "{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}"=hex:51,66,7a,6c,4c,1d,38,12,e1,1f,51,
       3e,0a,ac,85,0f,f7,62,fb,f5,f7,92,03,66
    "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,
       38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4
    "{60E91567-EF8A-4520-BCE2-83ABA5256799}"=hex:51,66,7a,6c,4c,1d,38,12,09,16,fa,
       64,b8,a1,4e,00,c3,f4,c0,eb,a0,7b,23,8d
    "{6D53EC84-6AAE-4787-AEEE-F4628F01010C}"=hex:51,66,7a,6c,4c,1d,38,12,ea,ef,40,
       69,9c,24,e9,02,d1,f8,b7,22,8a,5f,45,18
    "{6EBF7485-159F-4BFF-A14F-B9E3AAC4465B}"=hex:51,66,7a,6c,4c,1d,38,12,eb,77,ac,
       6a,ad,5b,91,0e,de,59,fa,a3,af,9a,02,4f
    "{732E5459-A239-4E08-A411-2C6CCF313F1D}"=hex:51,66,7a,6c,4c,1d,38,12,37,57,3d,
       77,0b,ec,66,0b,db,07,6f,2c,ca,6f,7b,09
    "{761233B6-F228-49E4-8F6B-668499D4E55A}"=hex:51,66,7a,6c,4c,1d,38,12,d8,30,01,
       72,1a,bc,8a,0c,f0,7d,25,c4,9c,8a,a1,4e
    "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
       94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
    "{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
       9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
    "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
       ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
    "{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,
       b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb
    "{C26CD490-5F01-41E3-B150-EB29F19DA056}"=hex:51,66,7a,6c,4c,1d,38,12,fe,d7,7f,
       c6,33,11,8d,04,ce,46,a8,69,f4,c3,e4,42
    "{CB0D163C-E9F4-4236-9496-0597E24B23A5}"=hex:51,66,7a,6c,4c,1d,38,12,52,15,1e,
       cf,c6,a7,58,07,eb,80,46,d7,e7,15,67,b1
    "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
       df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
    "{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}"=hex:51,66,7a,6c,4c,1d,38,12,e0,a3,9c,
       e7,58,bb,07,04,d4,e3,1f,31,e6,9f,17,b5
    "{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}"=hex:51,66,7a,6c,4c,1d,38,12,cf,4e,be,
       f9,90,2f,b6,0a,e3,01,c5,b7,a9,7a,14,95
    "{14528701-EB26-4DDD-BDF3-5B3A3BF85CA5}"=hex:51,66,7a,6c,4c,1d,38,12,6f,84,41,
       10,14,a5,b3,08,c2,e5,18,7a,3e,a6,18,b1
    "{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}"=hex:51,66,7a,6c,4c,1d,38,12,49,e1,1e,
       1a,d6,12,cd,0b,d4,1a,c8,43,e4,f4,32,a8
    "{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,38,12,e4,48,13,
       36,9b,0a,89,06,fb,ff,c3,c8,3d,de,d1,0d
    .
    [HKEY_USERS\S-1-5-21-794020852-758203237-1877864742-1000\Software\SecuROM\License information*]
    "datasecu"=hex:4e,e3,fb,d8,e4,b3,bb,f9,d0,71,e5,18,7c,6a,1a,6b,31,5f,94,ad,eb,
       c4,0f,f0,7a,e2,d2,28,67,73,ea,43,9b,85,1e,3d,59,1c,dc,3c,f7,6d,58,fa,42,a4,\
    "rkeysecu"=hex:af,20,be,c1,13,3c,d2,93,b7,47,0f,fe,50,30,7e,79
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
    @="Shockwave Flash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
    @Denied: (A 2) (Everyone)
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
    @="FlashBroker"
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
       00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
    .
    Completion time: 2013-03-04  21:11:46
    ComboFix-quarantined-files.txt  2013-03-05 05:11
    ComboFix2.txt  2013-03-03 23:01
    .
    Pre-Run: 302,200,082,432 bytes free
    Post-Run: 302,302,732,288 bytes free
    .
    - - End Of File - - 1F4D282FDADA277BDC1DA890184FE651
     



    #8 nasdaq

    nasdaq

    • Malware Response Team
    • 38,936 posts
    • OFFLINE
    •  
    • Gender:Male
    • Location:Montreal, QC. Canada
    • Local time:01:29 AM

    Posted 05 March 2013 - 10:09 AM

    What are the remaining issues with this computer?



    #9 ConnJohnn

    ConnJohnn
    • Topic Starter

    • Members
    • 15 posts
    • OFFLINE
    •  
    • Local time:09:29 PM

    Posted 06 March 2013 - 01:52 AM

    Thanks again.

     

    Updates as of now..

    Still haven't had availability to connect it to internet and update the needed programs.

    No sign of any error messages.

    The desktop, besides taskbar/startmenu, still takes 10-15 seconds to load fully; assuming it's due to all the BS installed programs and what not.

    Runs much quicker than before once desktop loads.  Able to execute and run programs without problem.

    NO sign of rundll32 in processes.

    In process of removing the multiple accounts of anti-virus and old version software.

     

    Any other operations to perform?

     

    If not, I can relay back with updated info after performing suggested updates.

     

    Thanks.



    #10 nasdaq

    nasdaq

    • Malware Response Team
    • 38,936 posts
    • OFFLINE
    •  
    • Gender:Male
    • Location:Montreal, QC. Canada
    • Local time:01:29 AM

    Posted 06 March 2013 - 08:38 AM

     
    I did suggest that these be fixed in a previous script.
     
    Try this again.
     
    Open notepad and copy/paste the text in the quote box below into it:
     
    Firefox::
    FF - ExtSQL: !HIDDEN! 1970-01-16 04:44; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files (x86)\Searchqu Toolbar\Datamngr\FirefoxExtension
    FF - ExtSQL: !HIDDEN! 2012-07-19 05:44; 64ffxtbr@TelevisionFanatic.com; c:\program files (x86)\TelevisionFanatic\bar\1.bin
     
    Folder::
    c:\program files (x86)\Searchqu Toolbar
    c:\program files (x86)\TelevisionFanatic
    
     
     
    Save this as CFScript.txt on your desktop.
     
     
    Referring to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.
     
    Let me know what problem persists.
     
    p.s.
    If the Wallpaper is taking a long time to show I would remove it.


    #11 nasdaq

    nasdaq

    • Malware Response Team
    • 38,936 posts
    • OFFLINE
    •  
    • Gender:Male
    • Location:Montreal, QC. Canada
    • Local time:01:29 AM

    Posted 12 March 2013 - 09:10 AM

    Are you still with me?



    #12 nasdaq

    nasdaq

    • Malware Response Team
    • 38,936 posts
    • OFFLINE
    •  
    • Gender:Male
    • Location:Montreal, QC. Canada
    • Local time:01:29 AM

    Posted 18 March 2013 - 09:41 AM

    Due to the lack of feedback, this topic is now closed.

    In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

    Please include a link to your topic in the Private Message. Thank you.




    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users