# AdwCleaner v5.106 - Logfile created 28/03/2016 at 09:18:59
# Updated 27/03/2016 by Xplode
# Database : 2016-03-28.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Hayley - HAYLEY-VAIO
# Running from : C:\Users\Hayley\Downloads\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
Service Found : cherimoya
Service Found : MPCProtectService
Service Found : nebynugyzbt
***** [ Folders ] *****
Folder Found : C:\Program Files (x86)\MPC Cleaner
Folder Found : C:\Program Files (x86)\FA70F400-1459123002-11DF-8101-5442497890B6
Folder Found : C:\Program Files (x86)\Primary Color
Folder Found : C:\ProgramData\FlashBeat
Folder Found : C:\ProgramData\Partner
Folder Found : C:\ProgramData\CloudPrinter
Folder Found : C:\ProgramData\WindowsMsg
Folder Found : C:\ProgramData\47f0877f-0653-0
Folder Found : C:\ProgramData\47f0877f-1ae7-1
Folder Found : C:\ProgramData\47f0877f-4445-1
Folder Found : C:\ProgramData\ed51621d-1b67-1
Folder Found : C:\ProgramData\ed51621d-3ac3-1
Folder Found : C:\ProgramData\ed51621d-6315-0
Folder Found : C:\ProgramData\Service1291
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
Folder Found : C:\Users\Hayley\AppData\Local\DeskBar
Folder Found : C:\Users\Hayley\AppData\Local\PackageAware
Folder Found : C:\Users\Hayley\AppData\Local\PriceFountain
Folder Found : C:\Users\Hayley\AppData\Local\TheBrowser
Folder Found : C:\Users\Hayley\AppData\Local\Temp\MPC
Folder Found : C:\Users\Hayley\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Users\Hayley\AppData\LocalLow\oovootoolbar
Folder Found : C:\Users\Hayley\AppData\Roaming\Yahoo!\Companion
Folder Found : C:\Users\Hayley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TheBrowser
Folder Found : C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\oovootoolbar
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\PackageAware
***** [ Files ] *****
File Found : C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bmnlcjabgnpnenekpadlanbbkooimhnj
File Found : C:\Windows\SysNative\roboot64.exe
***** [ DLL ] *****
***** [ Shortcuts ] *****
Shortcut Infected : C:\Users\boinc_master\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( %SNP% )
***** [ Scheduled tasks ] *****
Task Found : snp
Task Found : snf
Task Found : IBUpd
Task Found : SystemHealer Monitor
Task Found : SystemHealer Run Delay
Task Found : System HealerStartUp
Task Found : System HealerPeriod
Task Found : System Healer Task
Task Found : IBUpd2
Task Found : DNS Monitoring
Task Found : osTip
***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SEARCHSCOPES\IELNKSRCH
Key Found : HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
Key Found : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
Key Found : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKCU\Software\Classes\CLSID\{17EF1FFB-0545-4C9A-BE64-78FF53338475}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{79F768ED-0B12-42EF-8257-36751A0ECF3A}]
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\DAILYPCCLEAN
Key Found : HKCU\Software\Microsoft\Tinstalls
Key Found : HKCU\Software\Yahoo\Companion
Key Found : HKCU\Software\Yahoo\YFriendsBar
Key Found : HKCU\Software\Zugo
Key Found : HKCU\Software\osTip
Key Found : HKCU\Software\AppDataLow\Software\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\SecureWebChannel
Key Found : HKLM\SOFTWARE\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Conduit
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\DAILYPCCLEAN
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Microsoft\Tinstalls
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Yahoo\Companion
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Yahoo\YFriendsBar
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Zugo
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\osTip
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\AppDataLow\Software\Yahoo\Companion
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Conduit
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\DAILYPCCLEAN
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Tinstalls
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Yahoo\Companion
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Yahoo\YFriendsBar
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Zugo
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\osTip
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AppDataLow\Software\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\4E30E037E0535E84D9E3349209D354D4
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\4E30E037E0535E84D9E3349209D354D4
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4E30E037E0535E84D9E3349209D354D4
Key Found : [x64] HKLM\SOFTWARE\Classes\Installer\Products\4E30E037E0535E84D9E3349209D354D4
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ielnksrch
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
***** [ Web browsers ] *****
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.aflt", "axl");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.autoRvrt", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.cntry", "US");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.cv", "cv5");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dfltLng", "");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dfltSrch", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dfltlng", "en");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dfltsrch", "false");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dnsErr", true);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.envrmnt", "production");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.excTlbr", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.hdrMd5", "3372B2A4E32032646C9262D50ECF3137");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.hmpg", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.hrdid", "5442497890B6D485");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.id", "5442497890B6D485");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.instlDay", "15557");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.instlRef", "axl");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.instlday", "15557");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.instlref", "axl");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.isdcmntcmplt", true);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.keywordurl", "");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2219:20:27");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.newTab", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.newtab", "false");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.pnu_base", "{\"newVrsn\":\"259\",\"lastVrsn\":\"259\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.prdct", "funmoods");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.prtnrId", "funmoods");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.prtnrid", "funmoods");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.savedVrsnTs", "1");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.sg", "none");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.similarsitesstorage-pid2", "da79d91d0047f945");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.smplGrp", "none");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.smplgrp", "none");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.srch", "");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.srchPrvdr", "Search");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.srchprvdr", "Search");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.tlbrId", "base");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136&q[...]
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.tlbrid", "base");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136&q[...]
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.vrsn", "1.5.23.22");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2219:20:27");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.vrsni", "1.5.23.22");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.vrsnts", "1.5.23.2219:20:27");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.xpestat\\xpereportdata", "1-8-2012");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods_i.newTab", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods_i.smplGrp", "none");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2219:20:27");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("browser.startup.homepage", "hxxp://www-mysearch.com/?site=shyosffdefault&prd=set_ff&s=G3Szamotn11427AD,cc136634-49f9-4006-ae59-4ea5d1238cf5,");
[C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : feed.sonic-search.com
*************************
C:\AdwCleaner\AdwCleaner[S1].txt - [20343 bytes] - [28/03/2016 09:18:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [20417 bytes] ##########
# AdwCleaner v5.106 - Logfile created 28/03/2016 at 09:24:31
# Updated 27/03/2016 by Xplode
# Database : 2016-03-28.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Hayley - HAYLEY-VAIO
# Running from : C:\Users\Hayley\Downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
[-] Service Deleted : cherimoya
[-] Service Deleted : MPCProtectService
[-] Service Deleted : nebynugyzbt
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files (x86)\MPC Cleaner
[-] Folder Deleted : C:\Program Files (x86)\FA70F400-1459123002-11DF-8101-5442497890B6
[-] Folder Deleted : C:\Program Files (x86)\Primary Color
[-] Folder Deleted : C:\ProgramData\FlashBeat
[-] Folder Deleted : C:\ProgramData\Partner
[-] Folder Deleted : C:\ProgramData\CloudPrinter
[-] Folder Deleted : C:\ProgramData\WindowsMsg
[-] Folder Deleted : C:\ProgramData\47f0877f-0653-0
[-] Folder Deleted : C:\ProgramData\47f0877f-1ae7-1
[-] Folder Deleted : C:\ProgramData\47f0877f-4445-1
[-] Folder Deleted : C:\ProgramData\ed51621d-1b67-1
[-] Folder Deleted : C:\ProgramData\ed51621d-3ac3-1
[-] Folder Deleted : C:\ProgramData\ed51621d-6315-0
[-] Folder Deleted : C:\ProgramData\Service1291
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\DeskBar
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\PackageAware
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\PriceFountain
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\TheBrowser
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\Temp\MPC
[-] Folder Deleted : C:\Users\Hayley\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
[-] Folder Deleted : C:\Users\Hayley\AppData\LocalLow\oovootoolbar
[-] Folder Deleted : C:\Users\Hayley\AppData\Roaming\Yahoo!\Companion
[-] Folder Deleted : C:\Users\Hayley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TheBrowser
[-] Folder Deleted : C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\oovootoolbar
[-] Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\PackageAware
***** [ Files ] *****
[-] File Deleted : C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bmnlcjabgnpnenekpadlanbbkooimhnj
[-] File Deleted : C:\Windows\SysNative\roboot64.exe
***** [ DLLs ] *****
***** [ Shortcuts ] *****
[-] Shortcut Disinfected : C:\Users\boinc_master\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
***** [ Scheduled tasks ] *****
[-] Task Deleted : snp
[-] Task Deleted : snf
[-] Task Deleted : IBUpd
[-] Task Deleted : SystemHealer Monitor
[-] Task Deleted : SystemHealer Run Delay
[-] Task Deleted : System HealerStartUp
[-] Task Deleted : System HealerPeriod
[-] Task Deleted : System Healer Task
[-] Task Deleted : IBUpd2
[-] Task Deleted : DNS Monitoring
[-] Task Deleted : osTip
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SEARCHSCOPES\IELNKSRCH
[-] Key Deleted : HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
[-] Key Deleted : HKCU\Software\Classes\CLSID\{17EF1FFB-0545-4C9A-BE64-78FF53338475}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{79F768ED-0B12-42EF-8257-36751A0ECF3A}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\DAILYPCCLEAN
[-] Key Deleted : HKCU\Software\Microsoft\Tinstalls
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\Zugo
[-] Key Deleted : HKCU\Software\osTip
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\SecureWebChannel
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Conduit
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\DAILYPCCLEAN
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Tinstalls
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Yahoo\Companion
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Zugo
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\osTip
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\4E30E037E0535E84D9E3349209D354D4
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\4E30E037E0535E84D9E3349209D354D4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4E30E037E0535E84D9E3349209D354D4
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
***** [ Web browsers ] *****
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.aflt", "axl");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.autoRvrt", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.cntry", "US");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.cv", "cv5");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dfltLng", "");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dfltSrch", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dfltlng", "en");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dfltsrch", "false");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dnsErr", true);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.envrmnt", "production");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.excTlbr", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.hdrMd5", "3372B2A4E32032646C9262D50ECF3137");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.hmpg", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.hrdid", "5442497890B6D485");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.id", "5442497890B6D485");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.instlDay", "15557");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.instlRef", "axl");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.instlday", "15557");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.instlref", "axl");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.isdcmntcmplt", true);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.keywordurl", "");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2219:20:27");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.newTab", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.newtab", "false");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.pnu_base", "{\"newVrsn\":\"259\",\"lastVrsn\":\"259\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.prdct", "funmoods");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.prtnrId", "funmoods");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.prtnrid", "funmoods");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.savedVrsnTs", "1");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.sg", "none");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.similarsitesstorage-pid2", "da79d91d0047f945");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.smplGrp", "none");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.smplgrp", "none");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.srch", "");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.srchPrvdr", "Search");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.srchprvdr", "Search");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.tlbrId", "base");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136&q[...]
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.tlbrid", "base");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136&q[...]
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.vrsn", "1.5.23.22");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2219:20:27");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.vrsni", "1.5.23.22");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.vrsnts", "1.5.23.2219:20:27");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.xpestat\\xpereportdata", "1-8-2012");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods_i.newTab", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2219:20:27");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxp://www-mysearch.com/?site=shyosffdefault&prd=set_ff&s=G3Szamotn11427AD,cc136634-49f9-4006-ae59-4ea5d1238cf5,");
[-] [C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : feed.sonic-search.com
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [19435 bytes] - [28/03/2016 09:24:31]
C:\AdwCleaner\AdwCleaner[S1].txt - [20537 bytes] - [28/03/2016 09:18:59]
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [19583 bytes] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 7 Home Premium x64
Ran by Hayley (Administrator) on Mon 03/28/2016 at 9:52:14.41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 33
Failed to delete: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ERZGJ40 (Temporary Internet Files Folder)
Successfully deleted: C:\ProgramData\28341ff220e0446c9fff27c4493d622e (Folder)
Successfully deleted: C:\Users\Hayley\Appdata\LocalLow\company (Folder)
Successfully deleted: C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\searchplugins\bing-zugo.xml (File)
Successfully deleted: C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\user.js (File)
Successfully deleted: C:\Users\Hayley\AppData\Roaming\nico mak computing (Folder)
Successfully deleted: C:\Program Files (x86)\GUTFE19.tmp (File)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ERZGJ40 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4MV35QRW (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86N2NB1O (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AIZF3ECN (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EX46214F (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NZ1JNMB1 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q6X9DVQO (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YBOT4SBM (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZC2TND0Z (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\system32\Drivers\{552ca813-de15-4dfe-937d-e33fb2b3d476}Gw64.sys (File)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4MV35QRW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86N2NB1O (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AIZF3ECN (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EX46214F (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NZ1JNMB1 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q6X9DVQO (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YBOT4SBM (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZC2TND0Z (Temporary Internet Files Folder)
Registry: 4
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\{552ca813-de15-4dfe-937d-e33fb2b3d476}Gw64 (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0a28f54-b08f-4049-a9bf-8d33bd1e9222} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0a28f54-b08f-4049-a9bf-8d33bd1e9222} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 03/28/2016 at 9:56:31.67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 7 Home Premium x64
Ran by Hayley (Administrator) on Mon 03/28/2016 at 17:42:54.57
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 10
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ERZGJ40 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86GW8JD7 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OLV1LLJ3 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PNG9ANNJ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TU378WHB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ERZGJ40 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86GW8JD7 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OLV1LLJ3 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PNG9ANNJ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TU378WHB (Temporary Internet Files Folder)
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 03/28/2016 at 17:47:37.30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~