Jump to content

im infected.. and it freaking sucks


Recommended Posts

so i have a bunch of ads, like snickers commercials and music BLASTING out of my speakers.. from the "host process for windows service" tab in my sound mixer.. so i ran malwarebytes twice.. two nights ago... the first time got rid of all my malware.. but i heard it again.. so i ran it again for a second time that night and there it was.. THE STRAGLER... one infected file that i missed i guess... that had to be the problem.. RIGHT? WRONG... because after a full day of silence i was on my pc just kicking it on face book, and my pc said somthing was terminated.. and it just restarted on me.. soon after that, the noise came back.. SO i ran malwarebytes for a third time.. and ive no infected files.. atleast according to malwarebytes.. HELP MY...BROTHERS HELP ME! WHAT AM I MISSING HERE.. 

 

Link to post
Share on other sites

Hello and post-32477-1261866970.gif

 

P2P/Piracy Warning:

 

   

If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

 

Download Farbar Recovery Scan Tool and save it to your desktop.

 

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

 

Kevin

Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-01-2014

Ran by Brice Ortiz (administrator) on BRICEORTIZ-PC on 10-01-2014 19:43:57

Running from C:\Users\Brice Ortiz\Desktop

Windows 7 Ultimate (X64) OS Language: English(US)

Internet Explorer Version 8

Boot Mode: Normal

 

==================== Processes (Whitelisted) =================

 

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe

(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

() C:\Windows\SysWOW64\PnkBstrA.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe

(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe

(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe

(Spotify Ltd) C:\Users\Brice Ortiz\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe

(Cyberlink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe

(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe

(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe

(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe

(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

 

==================== Registry (Whitelisted) ==================

 

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor)

HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1012000 2013-05-16] (NVIDIA Corporation)

HKLM-x32\...\Run: [RemoteControl] - C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe [30208 2005-12-07] (Cyberlink Corp.)

HKLM-x32\...\Run: [LanguageShortcut] - C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe [49152 2006-04-13] ()

HKLM-x32\...\Run: [ApnTBMon] - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"

HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2013-04-29] (RealNetworks, Inc.)

HKLM-x32\...\Run: [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)

HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443408 2013-09-09] (Research In Motion Limited)

HKCU\...\Run: [] - [x]

HKCU\...\Run: [spotify Web Helper] - C:\Users\Brice Ortiz\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-04] (Spotify Ltd)

HKCU\...\Run: [RIMDeviceManager] - C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe [2469392 2013-11-05] (Research In Motion Limited)

HKCU\...\Run: [Google Update] - C:\Users\Brice Ortiz\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-01-18] (Google Inc.)

MountPoints2: F - F:\Installer.exe

MountPoints2: {620ebddd-4a01-11e2-bce2-902b34adc190} - E:\Installer.exe

HKU\mom\...\Run: [spotify Web Helper] - C:\Users\mom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-08] (Spotify Ltd)

HKU\mom\...\Run: [spotify] - C:\Users\mom\AppData\Roaming\Spotify\spotify.exe [5951488 2013-12-08] (Spotify Ltd)

AppInit_DLLs-x32: c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll [ ] ()

 

==================== Internet (Whitelisted) ====================

 

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7C786AA02EF1CD01

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.00000

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe

SearchScopes: HKLM-x32 - DefaultScope {8133387F-10FE-4676-8F7B-BB24F93FE16E} URL = 

SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=4de38d54-31dd-4203-ba13-f6edee8604c5&searchtype=ds&q={searchTerms}

SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3242576

SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.00000

SearchScopes: HKCU - DefaultScope {8133387F-10FE-4676-8F7B-BB24F93FE16E} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3315010&CUI=UN30924395681510516&UM=2

SearchScopes: HKCU - 328EBD1CBBB44E4BBD97BEE577910C5A URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.00000


SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 

SearchScopes: HKCU - {794FD6B8-374C-4EF5-A7E7-080FFA74AD50} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=714647&p={searchTerms}

SearchScopes: HKCU - {8133387F-10FE-4676-8F7B-BB24F93FE16E} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3315010&CUI=UN30924395681510516&UM=2

SearchScopes: HKCU - {D6719141-CF3E-4854-9186-B827C35F3380} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000031&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=^TV&apn_dtid=^YYYYYY^YY^US&apn_uid=EBBFAB01-4A88-44DC-AE52-B9AF179F8DBC&apn_sauid=901C79CC-316D-4F7F-9290-13F841370898

BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)

BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)

BHO-x32: No Name - {0FB6A909-6086-458F-BD92-1F8EE10042A0} -  No File

BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)

BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

BHO-x32: Desktop Animated Toolbar - {ba997733-32e8-407c-a157-6abef22ee411} - C:\Program Files (x86)\Desktop_Animated\prxtbDes0.dll (Conduit Ltd.)

BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)

BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File

Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File

Toolbar: HKLM-x32 - Desktop Animated Toolbar - {ba997733-32e8-407c-a157-6abef22ee411} - C:\Program Files (x86)\Desktop_Animated\prxtbDes0.dll (Conduit Ltd.)

Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)

Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)

Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

Tcpip\..\Interfaces\{48413AA4-1B0F-460A-82CB-3B8ED0224CF4}: [NameServer]167.206.251.129,167.206.251.130

 

FireFox:

========

FF ProfilePath: C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default

FF user.js: detected! => C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\user.js

FF DefaultSearchEngine: KeyBar 1.29 Customized Web Search

FF SearchEngineOrder.1: Ask Search

FF SearchEngineOrder.3: Bing 

FF SelectedSearchEngine: KeyBar 1.29 Customized Web Search



FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()

FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()

FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)

FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)

FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)

FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)

FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)

FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)

FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)

FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF Plugin-x32: @real.com/nppl3260;version=16.0.1.18 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprpplugin;version=16.0.1.18 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)

FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)

FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()

FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)

FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)

FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)

FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()

FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Brice Ortiz\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)

FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Brice Ortiz\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)

FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()

FF SearchPlugin: C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\ask-search.xml

FF SearchPlugin: C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\askcom.xml

FF SearchPlugin: C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\babylon1.xml

FF SearchPlugin: C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\bingp.xml

FF SearchPlugin: C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\conduit.xml

FF SearchPlugin: C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\sweetim.xml

FF SearchPlugin: C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\Web Search.xml

FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml

FF Extension: Ask Toolbar - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Extensions\toolbar@ask.com

FF Extension: Yahoo! Toolbar - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

FF Extension: KeyBar 1.29  - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Extensions\{8a184644-a171-4b05-bc9a-28d75ffc9505}

FF Extension: BitTorrentControl_v12  - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}

FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

FF HKLM-x32\...\Firefox\Extensions: [ocr@babylon.com] - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\ocr@babylon.com

FF HKLM-x32\...\Firefox\Extensions: [{DAC3F861-B30D-40dd-9166-F4E75327FAC7}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\

FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\

FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

 

Chrome: 

=======



CHR DefaultSearchKeyword: search.conduit.com

CHR DefaultSearchProvider: Conduit

CHR DefaultSearchURL: http://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN23353245872373516&ctid=CT3315010&UM=2

CHR DefaultNewTabURL: 

CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()

CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer

CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()

CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()

CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)

CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)

CHR Plugin: (Java Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File

CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)

CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)

CHR Plugin: (RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)

CHR Plugin: (RealNetworks RealDownloader Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)

CHR Plugin: (RealNetworks RealDownloader HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)

CHR Plugin: (RealNetworks RealDownloader PepperFlashVideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)

CHR Plugin: (RealDownloader Plugin) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)

CHR Plugin: (Google Update) - C:\Users\Brice Ortiz\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File

CHR Plugin: (Google Talk Plugin) - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)

CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()

CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)

CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File

CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)

CHR Extension: (Google Docs) - C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0

CHR Extension: (Google Drive) - C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0

CHR Extension: (YouTube) - C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0

CHR Extension: (Google Search) - C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0

CHR Extension: (GFACE Experience Plugin) - C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdlfmdbdibkbfdpjocdaolcheehmpol\0.38.0_0

CHR Extension: (Chrome In-App Payments service) - C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0

CHR Extension: (Battlefield Play4Free) - C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh\1.0.96.0_0

CHR Extension: (Gmail) - C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

CHR HKCU\...\Chrome\Extension: [bolmicibdhjnmppjidlkppdaeplaphpi] - C:\Users\Brice Ortiz\AppData\Local\CRE\bolmicibdhjnmppjidlkppdaeplaphpi.crx

CHR HKCU\...\Chrome\Extension: [dknkjnkhedbanphkkpbpcgoblmkbfhlf] - C:\Users\Brice Ortiz\AppData\Local\CRE\dknkjnkhedbanphkkpbpcgoblmkbfhlf.crx

CHR HKCU\...\Chrome\Extension: [jadmiphpbpjbfngipbjmjaajaeiflhkc] - C:\Users\Brice Ortiz\AppData\Local\CRE\jadmiphpbpjbfngipbjmjaajaeiflhkc.crx

CHR HKLM-x32\...\Chrome\Extension: [aaaaojmikegpiepcfdkkjaplodkpfmlo] - C:\Users\Brice Ortiz\AppData\Local\APN\GoogleCRXs\apnorjtoolbar.crx

CHR HKLM-x32\...\Chrome\Extension: [anmphbplcihjjkljdofccokpafageioj] - C:\Users\Brice Ortiz\AppData\Local\Lucky Savings\Chrome\Lucky Savings.crx

CHR HKLM-x32\...\Chrome\Extension: [bolmicibdhjnmppjidlkppdaeplaphpi] - C:\Users\Brice Ortiz\AppData\Local\CRE\bolmicibdhjnmppjidlkppdaeplaphpi.crx

CHR HKLM-x32\...\Chrome\Extension: [cjolcfnbehgbbodlpklcogifnnfklkfo] - C:\Users\mom\AppData\Local\CRE\cjolcfnbehgbbodlpklcogifnnfklkfo.crx

CHR HKLM-x32\...\Chrome\Extension: [dknkjnkhedbanphkkpbpcgoblmkbfhlf] - C:\Users\Brice Ortiz\AppData\Local\CRE\dknkjnkhedbanphkkpbpcgoblmkbfhlf.crx

CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx

CHR HKLM-x32\...\Chrome\Extension: [jadmiphpbpjbfngipbjmjaajaeiflhkc] - C:\Users\Brice Ortiz\AppData\Local\CRE\jadmiphpbpjbfngipbjmjaajaeiflhkc.crx

CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

 

==================== Services (Whitelisted) =================

 

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)

R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-10-31] (Avira Operations GmbH & Co. KG)

S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-18] (Avira Operations GmbH & Co. KG)

S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-01-05] ()

R3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2013-09-09] (Research In Motion Limited)

S3 EvoSvc; C:\Program Files\Echobit\Evolve\EvoSvc.exe [1501144 2013-09-21] (Echobit LLC)

R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)

R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)

S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.)

R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-12-09] ()

R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()

R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [167936 2006-05-04] ()

R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2148216 2012-08-23] (AVG)

 

==================== Drivers (Whitelisted) ====================

 

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] ()

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)

R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)

R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-31] (Avira Operations GmbH & Co. KG)

R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG)

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-19] (DT Soft Ltd)

R3 EvolveVirtualAdapter; C:\Windows\System32\DRIVERS\evolve.sys [21656 2013-09-21] (Echobit, LLC)

R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()

S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()

R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)

S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2013-06-27] (Research In Motion Limited)

R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)

R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [11880 2012-07-04] (TuneUp Software)

S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]

S3 gdrv; \??\C:\Windows\gdrv.sys [x]

 

==================== NetSvcs (Whitelisted) ===================

 

 

==================== One Month Created Files and Folders ========

 

2014-01-10 19:43 - 2014-01-10 19:44 - 00027464 _____ C:\Users\Brice Ortiz\Desktop\FRST.txt

2014-01-10 19:39 - 2014-01-10 19:40 - 00039481 _____ C:\Users\Brice Ortiz\Downloads\FRST.txt

2014-01-10 19:39 - 2014-01-10 19:39 - 00000000 ____D C:\FRST

2014-01-10 19:38 - 2014-01-10 19:38 - 01932166 _____ (Farbar) C:\Users\Brice Ortiz\Desktop\FRST64.exe

2014-01-09 11:15 - 2014-01-09 11:15 - 00109192 _____ () C:\Users\mom\Downloads\Setup.exe

2014-01-09 00:50 - 2014-01-09 00:53 - 00000000 ____D C:\Users\Brice Ortiz\Desktop\RK_Quarantine

2014-01-09 00:49 - 2014-01-09 00:50 - 04406784 _____ C:\Users\Brice Ortiz\Downloads\RogueKillerX64.exe

2014-01-09 00:14 - 2014-01-09 00:14 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2014-01-09 00:09 - 2014-01-09 00:09 - 00037376 _____ C:\Windows\system32\gjdi.agz

2014-01-08 23:59 - 2014-01-10 19:23 - 00000083 _____ C:\Windows\system32\otebi.efg

2014-01-08 23:58 - 2014-01-09 00:09 - 00000096 _____ C:\Windows\system32\dnmy.soq

2014-01-08 23:58 - 2014-01-08 23:58 - 00000064 _____ C:\Windows\system32\hwwz.pji

2014-01-08 23:42 - 2014-01-08 23:42 - 00219314 ____S C:\Windows\system32\cnsbatm.nsj

2014-01-08 14:36 - 2014-01-08 14:36 - 00118149 _____ C:\Users\Brice Ortiz\Downloads\wmpChrome (2).crx

2013-12-31 13:28 - 2013-12-31 13:28 - 00000222 _____ C:\Users\Brice Ortiz\Desktop\Age of Empires II HD Edition.url

2013-12-31 13:25 - 2013-12-31 13:25 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Local\ArchiveInvalidation

2013-12-31 13:23 - 2013-12-31 13:23 - 00000000 ____D C:\Users\Brice Ortiz\Desktop\New folder (3)

2013-12-31 13:22 - 2013-12-31 13:22 - 03045384 _____ C:\Users\Brice Ortiz\Desktop\ArchiveInvalidation File Generator v3_2-52402-3-2.zip

2013-12-30 15:28 - 2013-12-30 15:28 - 00000000 ____D C:\Users\Brice Ortiz\Downloads\Fallout New Vegas DLC

2013-12-29 23:38 - 2013-12-29 23:42 - 203145992 _____ C:\Users\Brice Ortiz\Downloads\weapon_retexture_project_1dot95-38285-1-95.7z

2013-12-29 23:28 - 2013-12-29 23:49 - 1188594344 _____ C:\Users\Brice Ortiz\Downloads\NMCs Textures NV LARGE Pack Part 3 of 3 FOR NMM-43135-1-0.7z

2013-12-29 23:13 - 2013-12-29 23:13 - 00000000 ____D C:\Users\Brice Ortiz\Downloads\Facebook_files

2013-12-29 23:12 - 2013-12-29 23:13 - 01113067 _____ C:\Users\Brice Ortiz\Downloads\Facebook.htm

2013-12-29 22:52 - 2013-12-29 23:15 - 1110471037 _____ C:\Users\Brice Ortiz\Desktop\NMCs Textures NV LARGE Pack Part 2 of 3 FOR NMM -43135-1-0.7z

2013-12-29 22:29 - 2013-12-29 22:50 - 1132280378 _____ C:\Users\Brice Ortiz\Downloads\NMCs Textures NV LARGE Pack Part 1 of 3 FOR NMM -43135-1-0.7z

2013-12-29 17:58 - 2013-12-29 17:58 - 00000221 _____ C:\Users\Brice Ortiz\Desktop\Fallout New Vegas.url

2013-12-26 17:26 - 2013-12-26 17:26 - 00000222 _____ C:\Users\Brice Ortiz\Desktop\Rust.url

2013-12-26 17:21 - 2014-01-10 00:14 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Local\DayZ

2013-12-26 17:21 - 2013-12-26 17:21 - 00000000 ____D C:\Users\Brice Ortiz\Documents\DayZ

2013-12-26 16:08 - 2013-12-26 16:08 - 00000222 _____ C:\Users\Brice Ortiz\Desktop\DayZ.url

2013-12-22 21:02 - 2013-12-22 21:02 - 00055639 _____ C:\Users\Brice Ortiz\Downloads\Yog-Sothoth_couleur.jpeg

2013-12-21 10:14 - 2013-12-21 10:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2013-12-18 23:53 - 2013-12-18 23:53 - 00007678 _____ C:\Users\Brice Ortiz\Downloads\cute-face-meme-66287433884.jpeg

2013-12-16 00:14 - 2013-12-16 00:14 - 00000653 _____ C:\Users\Brice Ortiz\Downloads\ce0dc23a1bbf66c19100881f36547778.htm

2013-12-13 01:41 - 2013-12-13 01:41 - 01741678 _____ C:\Users\Brice Ortiz\Downloads\Coat_of_Arms_of_Puerto_Rico.svg

2013-12-13 01:41 - 2013-12-13 01:41 - 01741678 _____ C:\Users\Brice Ortiz\Downloads\Coat_of_Arms_of_Puerto_Rico (1).svg

 

==================== One Month Modified Files and Folders =======

 

2014-01-10 19:44 - 2014-01-10 19:43 - 00027464 _____ C:\Users\Brice Ortiz\Desktop\FRST.txt

2014-01-10 19:41 - 2013-01-18 21:27 - 00000904 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2014-01-10 19:41 - 2012-12-17 23:11 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs

2014-01-10 19:41 - 2012-12-17 19:41 - 00347496 _____ C:\Windows\PFRO.log

2014-01-10 19:41 - 2012-12-17 19:41 - 00083321 _____ C:\Windows\setupact.log

2014-01-10 19:41 - 2012-12-17 18:18 - 00000000 ____D C:\ProgramData\NVIDIA

2014-01-10 19:41 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2014-01-10 19:40 - 2014-01-10 19:39 - 00039481 _____ C:\Users\Brice Ortiz\Downloads\FRST.txt

2014-01-10 19:40 - 2012-12-18 09:29 - 01548728 _____ C:\Windows\WindowsUpdate.log

2014-01-10 19:39 - 2014-01-10 19:39 - 00000000 ____D C:\FRST

2014-01-10 19:38 - 2014-01-10 19:38 - 01932166 _____ (Farbar) C:\Users\Brice Ortiz\Desktop\FRST64.exe

2014-01-10 19:36 - 2009-07-13 23:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2014-01-10 19:36 - 2009-07-13 23:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2014-01-10 19:30 - 2013-02-14 13:54 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-264361256-2442009338-2428154096-1000UA.job

2014-01-10 19:30 - 2013-02-14 13:54 - 00000880 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-264361256-2442009338-2428154096-1000Core.job

2014-01-10 19:23 - 2014-01-08 23:59 - 00000083 _____ C:\Windows\system32\otebi.efg

2014-01-10 19:11 - 2012-12-22 12:18 - 00000000 ____D C:\Users\mom\AppData\Roaming\Spotify

2014-01-10 19:02 - 2013-01-18 21:27 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2014-01-10 18:57 - 2013-11-30 18:50 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job

2014-01-10 16:57 - 2012-12-18 03:14 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Roaming\Spotify

2014-01-10 02:58 - 2012-12-19 01:23 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Roaming\Skype

2014-01-10 00:14 - 2013-12-26 17:21 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Local\DayZ

2014-01-10 00:14 - 2012-12-22 20:46 - 00000000 ____D C:\Program Files (x86)\Steam

2014-01-09 11:15 - 2014-01-09 11:15 - 00109192 _____ () C:\Users\mom\Downloads\Setup.exe

2014-01-09 00:53 - 2014-01-09 00:50 - 00000000 ____D C:\Users\Brice Ortiz\Desktop\RK_Quarantine

2014-01-09 00:50 - 2014-01-09 00:49 - 04406784 _____ C:\Users\Brice Ortiz\Downloads\RogueKillerX64.exe

2014-01-09 00:45 - 2013-09-30 21:00 - 00000000 ____D C:\ProgramData\Conduit

2014-01-09 00:45 - 2013-08-18 15:35 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Roaming\Search Protection

2014-01-09 00:14 - 2014-01-09 00:14 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2014-01-09 00:14 - 2012-12-17 18:38 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware

2014-01-09 00:09 - 2014-01-09 00:09 - 00037376 _____ C:\Windows\system32\gjdi.agz

2014-01-09 00:09 - 2014-01-08 23:58 - 00000096 _____ C:\Windows\system32\dnmy.soq

2014-01-08 23:58 - 2014-01-08 23:58 - 00000064 _____ C:\Windows\system32\hwwz.pji

2014-01-08 23:42 - 2014-01-08 23:42 - 00219314 ____S C:\Windows\system32\cnsbatm.nsj

2014-01-08 20:02 - 2013-07-16 21:17 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Roaming\TS3Client

2014-01-08 17:37 - 2013-12-05 17:43 - 00000000 ____D C:\Users\Brice Ortiz\Documents\Infestation Survivor Stories

2014-01-08 14:36 - 2014-01-08 14:36 - 00118149 _____ C:\Users\Brice Ortiz\Downloads\wmpChrome (2).crx

2014-01-07 19:00 - 2012-12-22 21:53 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.xtr

2014-01-07 19:00 - 2012-12-22 21:47 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.exe

2014-01-04 23:23 - 2012-12-22 21:47 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.ex0

2014-01-01 15:52 - 2013-06-19 13:46 - 00000000 ____D C:\ProgramData\Package Cache

2013-12-31 13:28 - 2013-12-31 13:28 - 00000222 _____ C:\Users\Brice Ortiz\Desktop\Age of Empires II HD Edition.url

2013-12-31 13:25 - 2013-12-31 13:25 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Local\ArchiveInvalidation

2013-12-31 13:23 - 2013-12-31 13:23 - 00000000 ____D C:\Users\Brice Ortiz\Desktop\New folder (3)

2013-12-31 13:22 - 2013-12-31 13:22 - 03045384 _____ C:\Users\Brice Ortiz\Desktop\ArchiveInvalidation File Generator v3_2-52402-3-2.zip

2013-12-30 17:11 - 2012-12-19 17:27 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Roaming\BitTorrent

2013-12-30 16:30 - 2009-07-14 00:13 - 00778278 _____ C:\Windows\system32\PerfStringBackup.INI

2013-12-30 15:28 - 2013-12-30 15:28 - 00000000 ____D C:\Users\Brice Ortiz\Downloads\Fallout New Vegas DLC

2013-12-30 10:41 - 2012-12-22 12:18 - 00000000 ____D C:\Users\mom\AppData\Local\Spotify

2013-12-29 23:49 - 2013-12-29 23:28 - 1188594344 _____ C:\Users\Brice Ortiz\Downloads\NMCs Textures NV LARGE Pack Part 3 of 3 FOR NMM-43135-1-0.7z

2013-12-29 23:42 - 2013-12-29 23:38 - 203145992 _____ C:\Users\Brice Ortiz\Downloads\weapon_retexture_project_1dot95-38285-1-95.7z

2013-12-29 23:17 - 2013-01-22 23:56 - 00000000 ____D C:\Users\Brice Ortiz\Documents\Nexus Mod Manager

2013-12-29 23:15 - 2013-12-29 22:52 - 1110471037 _____ C:\Users\Brice Ortiz\Desktop\NMCs Textures NV LARGE Pack Part 2 of 3 FOR NMM -43135-1-0.7z

2013-12-29 23:13 - 2013-12-29 23:13 - 00000000 ____D C:\Users\Brice Ortiz\Downloads\Facebook_files

2013-12-29 23:13 - 2013-12-29 23:12 - 01113067 _____ C:\Users\Brice Ortiz\Downloads\Facebook.htm

2013-12-29 22:50 - 2013-12-29 22:29 - 1132280378 _____ C:\Users\Brice Ortiz\Downloads\NMCs Textures NV LARGE Pack Part 1 of 3 FOR NMM -43135-1-0.7z

2013-12-29 17:58 - 2013-12-29 17:58 - 00000221 _____ C:\Users\Brice Ortiz\Desktop\Fallout New Vegas.url

2013-12-29 17:58 - 2013-01-03 16:05 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Local\FalloutNV

2013-12-29 17:05 - 2012-12-17 18:49 - 00610518 _____ C:\Windows\DirectX.log

2013-12-26 17:26 - 2013-12-26 17:26 - 00000222 _____ C:\Users\Brice Ortiz\Desktop\Rust.url

2013-12-26 17:21 - 2013-12-26 17:21 - 00000000 ____D C:\Users\Brice Ortiz\Documents\DayZ

2013-12-26 16:08 - 2013-12-26 16:08 - 00000222 _____ C:\Users\Brice Ortiz\Desktop\DayZ.url

2013-12-22 21:02 - 2013-12-22 21:02 - 00055639 _____ C:\Users\Brice Ortiz\Downloads\Yog-Sothoth_couleur.jpeg

2013-12-21 15:38 - 2012-12-19 19:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2013-12-21 10:14 - 2013-12-21 10:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2013-12-21 09:17 - 2009-07-14 00:08 - 00032600 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2013-12-18 23:53 - 2013-12-18 23:53 - 00007678 _____ C:\Users\Brice Ortiz\Downloads\cute-face-meme-66287433884.jpeg

2013-12-18 16:54 - 2012-12-18 03:14 - 00000000 ____D C:\Users\Brice Ortiz\AppData\Local\Spotify

2013-12-18 15:20 - 2013-11-15 13:38 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys

2013-12-18 15:20 - 2013-11-15 13:38 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys

2013-12-18 15:20 - 2013-11-15 13:38 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys

2013-12-16 00:14 - 2013-12-16 00:14 - 00000653 _____ C:\Users\Brice Ortiz\Downloads\ce0dc23a1bbf66c19100881f36547778.htm

2013-12-13 01:41 - 2013-12-13 01:41 - 01741678 _____ C:\Users\Brice Ortiz\Downloads\Coat_of_Arms_of_Puerto_Rico.svg

2013-12-13 01:41 - 2013-12-13 01:41 - 01741678 _____ C:\Users\Brice Ortiz\Downloads\Coat_of_Arms_of_Puerto_Rico (1).svg

2013-12-11 01:57 - 2013-11-30 18:50 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2013-12-11 01:57 - 2013-11-30 18:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2013-12-11 01:57 - 2013-11-30 18:50 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

 

Some content of TEMP:

====================

C:\Users\Brice Ortiz\AppData\Local\Temp\70c100fa4ed8d220df9dc57f3e585506.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\APNSetup.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\avgnt.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\avguidx.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\bfginstaller.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\conduitinstaller.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\drm_dyndata_7410004.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\F5038T1L1.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\fp_pl_pfs_installer.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\gtalkwmp1.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\GUninstaller.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\Gw2.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\lowproc.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\lvid_lvid.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\Nexus%20Mod%20Manager-0.41.0.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\Nexus%20Mod%20Manager-0.45.6.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\nsj9029.tmp.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\nvSCPAPI.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\nvStInst.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\oi_{D173C716-7387-4130-AAB5-97485E7F65FD}.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\qc_a402013b_7656_4f6f_b57f_5a8ef69f5fc4_64.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\safeguard.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\setup.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SetupAuto.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SetupUpdater.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SIMEEI2Installer.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SIMEEIInstaller.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SkypeSetup.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\sonarinst.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\stubhelper.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\swat4_update_en_10_11.EXE

C:\Users\Brice Ortiz\AppData\Local\Temp\swt-win32-3349.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\tbedrs.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\tbKeyB.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\Tsu34DF5C16.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\Tsu4C55749F.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\TsuBA3B178B.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\TsuD1F908E7.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\TsuE9FA1790.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\uninst1.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\UNINSTALL.EXE

C:\Users\Brice Ortiz\AppData\Local\Temp\uninstall_flash_player.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\uttAA75.tmp.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\uttE528.tmp.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\VidSaver_20121217.exe

C:\Users\mom\AppData\Local\Temp\avgnt.exe

C:\Users\mom\AppData\Local\Temp\avguidx.dll

C:\Users\mom\AppData\Local\Temp\TB_87C5.exe

C:\Users\mom\AppData\Local\Temp\uninst1.exe

 

 

==================== Bamital & volsnap Check =================

 

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\rpcss.dll

[2009-07-13 19:00] - [2009-07-13 20:41] - 0510464 ____A (Microsoft Corporation) 5D06C291B1EF52C19673E007263ACD59

 

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

 

 

LastRegBack: 2014-01-09 13:15

 

==================== End Of Log ============================

Addition.txt

Link to post
Share on other sites

was afraid of that but it was.. holy crap its obvious.. haha.. and here it is.. 

 

Farbar Recovery Scan Tool (x64) Version: 10-01-2014

Ran by Brice Ortiz at 2014-01-10 20:22:13

Running from C:\Users\Brice Ortiz\Desktop

Boot Mode: Normal

 

================== Search: "rpcss.dll" ===================

 

C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7600.16385_none_c5bfcda3579104e3\rpcss.dll

[2009-07-13 19:00] - [2009-07-13 20:41] - 0509440 ____A (Microsoft Corporation) 7266972E86890E2B30C0C322E906B027

 

C:\Windows\System32\rpcss.dll

[2009-07-13 19:00] - [2009-07-13 20:41] - 0510464 ____A (Microsoft Corporation) 5D06C291B1EF52C19673E007263ACD59

 

====== End Of Search ======

Link to post
Share on other sites

Download attached fixlist.txt file and save it to the Desktop, or the folder you saved FRST into.

NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

 

Run FRST and press the Fix button just once and wait.


The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

 

Next,

 

Download AdwCleaner by Xplode from here: http://www.bleepingcomputer.com/download/adwcleaner/ and save to your Desktop.

 

  • Double click on AdwCleaner.exe to run the tool.
  • Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Uncheck any elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review.
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted (if necessary):
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.

 

Next,

 

Run Malwarebytes,  Open > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a Quick scan

Make sure that everything is checked, and click Remove Selected on any found items.

 

Post the produced logs, let me know if there is any improvement...

 

Kevin

 

 

 

Fixlist.txt

Link to post
Share on other sites

HERE IT IS 

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-01-2014

Ran by Brice Ortiz at 2014-01-10 20:43:29 Run:1

Running from C:\Users\Brice Ortiz\Desktop\New folder (4)

Boot Mode: Normal

==============================================

 

Content of fixlist:

*****************

Start

MountPoints2: F - F:\Installer.exe

MountPoints2: {620ebddd-4a01-11e2-bce2-902b34adc190} - E:\Installer.exe

AppInit_DLLs-x32: c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll [ ] ()

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim....3.1010000.00000

SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://search.yahoo....&type=714647&p={searchTerms}


BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)

C:\Program Files (x86)\Ask.com

Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File

Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File

Toolbar: HKLM-x32 - Desktop Animated Toolbar - {ba997733-32e8-407c-a157-6abef22ee411} - C:\Program Files (x86)\Desktop_Animated\prxtbDes0.dll (Conduit Ltd.)

Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)

Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File

2014-01-09 00:09 - 2014-01-09 00:09 - 00037376 _____ C:\Windows\system32\gjdi.agz

2014-01-08 23:59 - 2014-01-10 19:23 - 00000083 _____ C:\Windows\system32\otebi.efg

2014-01-08 23:58 - 2014-01-09 00:09 - 00000096 _____ C:\Windows\system32\dnmy.soq

2014-01-08 23:58 - 2014-01-08 23:58 - 00000064 _____ C:\Windows\system32\hwwz.pji

2014-01-08 23:42 - 2014-01-08 23:42 - 00219314 ____S C:\Windows\system32\cnsbatm.nsj

C:\Users\Brice Ortiz\AppData\Local\Temp\70c100fa4ed8d220df9dc57f3e585506.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\APNSetup.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\avgnt.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\avguidx.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\bfginstaller.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\conduitinstaller.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\drm_dyndata_7410004.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\F5038T1L1.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\fp_pl_pfs_installer.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\gtalkwmp1.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\GUninstaller.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\Gw2.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\lowproc.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\lvid_lvid.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\Nexus%20Mod%20Manager-0.41.0.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\Nexus%20Mod%20Manager-0.45.6.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\nsj9029.tmp.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\nvSCPAPI.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\nvStInst.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\oi_{D173C716-7387-4130-AAB5-97485E7F65FD}.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\qc_a402013b_7656_4f6f_b57f_5a8ef69f5fc4_64.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\safeguard.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\setup.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SetupAuto.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SetupUpdater.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SIMEEI2Installer.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SIMEEIInstaller.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\SkypeSetup.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\sonarinst.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\stubhelper.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\swat4_update_en_10_11.EXE

C:\Users\Brice Ortiz\AppData\Local\Temp\swt-win32-3349.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\tbedrs.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\tbKeyB.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\Tsu34DF5C16.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\Tsu4C55749F.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\TsuBA3B178B.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\TsuD1F908E7.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\TsuE9FA1790.dll

C:\Users\Brice Ortiz\AppData\Local\Temp\uninst1.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\UNINSTALL.EXE

C:\Users\Brice Ortiz\AppData\Local\Temp\uninstall_flash_player.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\uttAA75.tmp.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\uttE528.tmp.exe

C:\Users\Brice Ortiz\AppData\Local\Temp\VidSaver_20121217.exe

C:\Users\mom\AppData\Local\Temp\avgnt.exe

C:\Users\mom\AppData\Local\Temp\avguidx.dll

C:\Users\mom\AppData\Local\Temp\TB_87C5.exe

C:\Users\mom\AppData\Local\Temp\uninst1.exe

Ask Toolbar (x32 Version: 1.15.25.0 - Ask.com) <==== ATTENTION

Ask Toolbar Updater (HKCU Version: 1.2.4.36191 - Ask.com) <==== ATTENTION

AlternateDataStreams: C:\ProgramData\TEMP:B1FBBD09

Replace: C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7600.16385_none_c5bfcda3579104e3\rpcss.dll C:\Windows\System32\rpcss.dll

End

 

*****************

 

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F => Key deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{620ebddd-4a01-11e2-bce2-902b34adc190} => Key deleted successfully.

HKCR\CLSID\{620ebddd-4a01-11e2-bce2-902b34adc190} => Key not found.

HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key deleted successfully.

HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found.

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully.

HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found.

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully.

HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found.

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\328EBD1CBBB44E4BBD97BEE577910C5A => Key deleted successfully.

HKCR\CLSID\328EBD1CBBB44E4BBD97BEE577910C5A => Key not found.

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key deleted successfully.

HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found.

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.

HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{794FD6B8-374C-4EF5-A7E7-080FFA74AD50} => Key deleted successfully.

HKCR\CLSID\{794FD6B8-374C-4EF5-A7E7-080FFA74AD50} => Key not found.

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8133387F-10FE-4676-8F7B-BB24F93FE16E} => Key deleted successfully.

HKCR\CLSID\{8133387F-10FE-4676-8F7B-BB24F93FE16E} => Key not found.

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D6719141-CF3E-4854-9186-B827C35F3380} => Key deleted successfully.

HKCR\CLSID\{D6719141-CF3E-4854-9186-B827C35F3380} => Key not found.

HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully.

HKCR\Wow6432Node\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully.

C:\Program Files (x86)\Ask.com => Moved successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => Value deleted successfully.

HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => Key deleted successfully.

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => Value deleted successfully.

HKCR\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => Key deleted successfully.

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ba997733-32e8-407c-a157-6abef22ee411} => Value deleted successfully.

HKCR\Wow6432Node\CLSID\{ba997733-32e8-407c-a157-6abef22ee411} => Key deleted successfully.

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully.

HKCR\Wow6432Node\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found.

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully.

HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found.

C:\Windows\system32\gjdi.agz => Moved successfully.

C:\Windows\system32\otebi.efg => Moved successfully.

Could not move "C:\Windows\system32\dnmy.soq" => Scheduled to move on reboot.

C:\Windows\system32\hwwz.pji => Moved successfully.

Could not move "C:\Windows\system32\cnsbatm.nsj" => Scheduled to move on reboot.

C:\Users\Brice Ortiz\AppData\Local\Temp\70c100fa4ed8d220df9dc57f3e585506.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\APNSetup.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\avgnt.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\avguidx.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\bfginstaller.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\conduitinstaller.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\drm_dyndata_7410004.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\F5038T1L1.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\fp_pl_pfs_installer.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\gtalkwmp1.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\GUninstaller.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\Gw2.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\lowproc.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\lvid_lvid.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\Nexus%20Mod%20Manager-0.41.0.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\Nexus%20Mod%20Manager-0.45.6.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\nsj9029.tmp.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\nvSCPAPI.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\nvStInst.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\oi_{D173C716-7387-4130-AAB5-97485E7F65FD}.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\qc_a402013b_7656_4f6f_b57f_5a8ef69f5fc4_64.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\safeguard.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\setup.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\SetupAuto.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\SetupUpdater.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\SIMEEI2Installer.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\SIMEEIInstaller.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\SkypeSetup.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\sonarinst.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\stubhelper.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\swat4_update_en_10_11.EXE => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\swt-win32-3349.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\tbedrs.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\tbKeyB.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\Tsu34DF5C16.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\Tsu4C55749F.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\TsuBA3B178B.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\TsuD1F908E7.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\TsuE9FA1790.dll => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\uninst1.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\UNINSTALL.EXE => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\uninstall_flash_player.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\uttAA75.tmp.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\uttE528.tmp.exe => Moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Temp\VidSaver_20121217.exe => Moved successfully.

C:\Users\mom\AppData\Local\Temp\avgnt.exe => Moved successfully.

C:\Users\mom\AppData\Local\Temp\avguidx.dll => Moved successfully.

C:\Users\mom\AppData\Local\Temp\TB_87C5.exe => Moved successfully.

C:\Users\mom\AppData\Local\Temp\uninst1.exe => Moved successfully.

C:\ProgramData\TEMP => ":B1FBBD09" ADS removed successfully.

C:\Windows\System32\rpcss.dll => Moved successfully.

C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7600.16385_none_c5bfcda3579104e3\rpcss.dll copied successfully to C:\Windows\System32\rpcss.dll

 

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-01-10 20:45:13)<=

 

C:\Windows\system32\dnmy.soq => Is moved successfully.

C:\Windows\system32\cnsbatm.nsj => Is moved successfully.

 

==== End of Fixlog ====

Link to post
Share on other sites

and here is the log file from the malware removal 

 

# AdwCleaner v3.016 - Report created 10/01/2014 at 20:53:06
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Ultimate  (64 bits)
# Username : Brice Ortiz - BRICEORTIZ-PC
# Running from : C:\Users\Brice Ortiz\Desktop\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\ProgramData\StarApp
Folder Deleted : C:\ProgramData\WinterSoft
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\BitTorrentControl_v12
Folder Deleted : C:\Program Files (x86)\Desktop_Animated
Folder Deleted : C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}
Folder Deleted : C:\Program Files\Babylon
Folder Deleted : C:\Users\Brice Ortiz\AppData\Local\Conduit
Folder Deleted : C:\Users\Brice Ortiz\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Brice Ortiz\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Brice Ortiz\AppData\LocalLow\BitTorrentControl_v12
Folder Deleted : C:\Users\Brice Ortiz\AppData\LocalLow\Desktop_Animated
Folder Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Search Protection
Folder Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Searchprotect
Folder Deleted : C:\Users\Brice Ortiz\AppData\Roaming\strongvault
Folder Deleted : C:\Users\mom\AppData\Local\Conduit
Folder Deleted : C:\Users\mom\AppData\Local\Deal Vault
Folder Deleted : C:\Users\mom\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\mom\AppData\LocalLow\AVG SafeGuard toolbar
Folder Deleted : C:\Users\mom\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\mom\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\mom\AppData\LocalLow\Desktop_Animated
Folder Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Smartbar
Folder Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\CT3315010
Folder Deleted : C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\7sspa14p.default\Smartbar
Folder Deleted : C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\7sspa14p.default\ValueApps
Folder Deleted : C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\7sspa14p.default\CT3242576
Folder Deleted : C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\7sspa14p.default\Extensions\{33E0DAA6-3AF3-D8B5-6752-10E949C61516}
Folder Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Folder Deleted : C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\7sspa14p.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Folder Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Extensions\toolbar@ask.com
Folder Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Extensions\{8a184644-a171-4b05-bc9a-28d75ffc9505}
Folder Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}
Folder Deleted : C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\7sspa14p.default\Extensions\{ba997733-32e8-407c-a157-6abef22ee411}
Folder Deleted : C:\Users\mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Folder Deleted : C:\Users\mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bolmicibdhjnmppjidlkppdaeplaphpi
Folder Deleted : C:\Users\mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjolcfnbehgbbodlpklcogifnnfklkfo
Folder Deleted : C:\Users\mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Folder Deleted : C:\Users\mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jadmiphpbpjbfngipbjmjaajaeiflhkc
File Deleted : C:\END
File Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\ask-search.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Babylon.xml
File Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\babylon1.xml
File Deleted : C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\7sspa14p.default\searchplugins\babylon1.xml
File Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\bingp.xml
File Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\Conduit.xml
File Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\SweetIm.xml
File Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\searchplugins\Web Search.xml
File Deleted : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\user.js
File Deleted : C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\7sspa14p.default\user.js
File Deleted : C:\Users\mom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.babylon.com_0.localstorage
File Deleted : C:\Users\mom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.babylon.com_0.localstorage-journal
File Deleted : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ocr@babylon.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Key Deleted : HKCU\Software\Google\Chrome\Extensions\bolmicibdhjnmppjidlkppdaeplaphpi
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bolmicibdhjnmppjidlkppdaeplaphpi
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\cjolcfnbehgbbodlpklcogifnnfklkfo
Key Deleted : HKCU\Software\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Key Deleted : HKCU\Software\Google\Chrome\Extensions\jadmiphpbpjbfngipbjmjaajaeiflhkc
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jadmiphpbpjbfngipbjmjaajaeiflhkc
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Deal Vault_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Deal Vault_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Deal Vault-InternalInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Deal Vault-InternalInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Lucky Savings-InternalInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Lucky Savings-InternalInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\525388dfb235ea17
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3225826
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3242576
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3315010
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_graffiti-studio_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_graffiti-studio_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4C836512-BB70-11D2-A5A7-00105A9C91C6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DB797690-40E0-11D2-9BD5-0060082AE372}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{267FCDDB-764E-4265-8791-64071172F246}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB797681-40E0-11D2-9BD5-0060082AE372}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA997733-32E8-407C-A157-6ABEF22EE411}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA997733-32E8-407C-A157-6ABEF22EE411}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{267FCDDB-764E-4265-8791-64071172F246}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA997733-32E8-407C-A157-6ABEF22EE411}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{267FCDDB-764E-4265-8791-64071172F246}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDE2AAA8-DBBA-4935-B291-8B9F8220B9A2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D25152F5-F4F5-4CDC-9A24-8403DC9A0FCB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E69FC883-1A2B-4D62-A6A8-8765C343CBD3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95D337B6-36A3-4CD2-8B73-ACD05179C327}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0BF91075-F457-4A8B-99EF-140B52D2F22A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{37425600-CB21-49A0-8659-476FBAB0F8E8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{431FB0E5-2CBB-4602-9FE6-F1D64488ADD7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{5C9A230D-70A5-11D5-AFB0-0050DAC67890}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{5F339F0B-716F-408F-A627-DEEB5DEB4020}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8911483C-C00A-4183-9FBC-6C9C00946C15}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B7EA2226-F876-4BE4-B478-76EBAE2A668A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C3F058A9-407D-4CD1-8F66-B75605B54B69}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EFDCAF05-D29C-4D4D-9836-8CDCD606A6B2}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\powerpack
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\BitTorrentControl_v12
Key Deleted : HKCU\Software\AppDataLow\Software\Desktop_Animated
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\InstallIQ
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\SimplyGen
Key Deleted : HKLM\Software\TENCENT
Key Deleted : HKLM\Software\BitTorrentControl_v12
Key Deleted : HKLM\Software\Desktop_Animated
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrentControl_v12 Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Desktop_Animated Toolbar
Key Deleted : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v8.0.7600.16385
 
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
 
-\\ Mozilla Firefox v26.0 (en-US)
 
[ File : C:\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\prefs.js ]
 
Line Deleted : user_pref("CT3225826.autoDisableScopes", 0);
Line Deleted : user_pref("CT3315010.1000082.isPlayDisplay", "true");
Line Deleted : user_pref("CT3315010.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3315010.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3315010.FF19Solved", "true");
Line Deleted : user_pref("CT3315010.FirstTime", "true");
Line Deleted : user_pref("CT3315010.FirstTimeFF3", "true");
Line Deleted : user_pref("CT3315010.LAST_CLIENT_STATS_SUBMIT_2.enc", "MTM4MTA4Nzk4OA==");
Line Deleted : user_pref("CT3315010.LOCAL_COOKIE_STATS_LAST_SUBMIT_6.enc", "MTM4MTA4ODAxMA==");
Line Deleted : user_pref("CT3315010.LOCAL_COOKIE_STATS_STATS_SITE_SUPPORTED.enc", "MQ==");
Line Deleted : user_pref("CT3315010.LOCAL_COOKIE_THROTTLE_BASEadd_stats|0|LOCAL_COOKIE_STATS_STATS_SITE_SUPPORTED.enc", "MTM4MTA4ODAxMA==");
Line Deleted : user_pref("CT3315010.PG_ENABLE", "dHJ1ZQ==");
Line Deleted : user_pref("CT3315010.SF_JUST_INSTALLED.enc", "RkFMU0U=");
Line Deleted : user_pref("CT3315010.SF_STATUS.enc", "RU5BQkxFRA==");
Line Deleted : user_pref("CT3315010.SF_USER_ID.enc", "Y2lkXzYxMDIwMTMxNTMzNzQxODMxNTc=");
Line Deleted : user_pref("CT3315010.UserID", "UN38370126891692121");
Line Deleted : user_pref("CT3315010._key_edilia__uID", "%BA%B7%E9%EC%EC%BC%B7%B9%B3%EC%EC%BB%B8%B3%BA%E7%BE%B6%B3%E7%BC%B7%BF%B3%E9%B6%B7%BB%EC%B8%BF%E8%BC%BC%BC%E8");
Line Deleted : user_pref("CT3315010._key_edilia__uID.enc", "NDFjZmY2MTMtZmY1Mi00YTgwLWE2MTktYzAxNWYyOWI2NjZi");
Line Deleted : user_pref("CT3315010.acp_personal.appstate.enc", "ZW5hYmxl");
Line Deleted : user_pref("CT3315010.addressBarTakeOverEnabledInHidden", "true");
Line Deleted : user_pref("CT3315010.browser.search.defaultthis.engineName", "true");
Line Deleted : user_pref("CT3315010.cbfirsttime.enc", "U3VuIE9jdCAwNiAyMDEzIDE1OjMzOjAyIEdNVC0wNDAwIChFYXN0ZXJuIFN0YW5kYXJkIFRpbWUp");
Line Deleted : user_pref("CT3315010.countryCode", "US");
Line Deleted : user_pref("CT3315010.defaultSearch", "true");
Line Deleted : user_pref("CT3315010.discover-experiments-photopop", "ā%A8%F4%E7%F3%EB%A8%C0%A8%F6%EE%F5%FA%F5%F6%F5%F6%E5%F4%E7%A8%B2%A8%FC%EB%F8%F9%EF%F5%F4%A8%C0%B7%B6ă");
Line Deleted : user_pref("CT3315010.discover-experiments-photopop.enc", "eyJuYW1lIjoicGhvdG9wb3BfbmEiLCJ2ZXJzaW9uIjoxMH0=");
Line Deleted : user_pref("CT3315010.discover-periodic-reports", "ā%A8%F6%EF%F4%ED%E5%B6%A8%C0%E1%B7%B9%BE%BA%B8%BE%BB%B9%BE%BF%B6%BF%BB%B2%B7%BA%BA%B6%B6%B6%B6%B6%E3ă");
Line Deleted : user_pref("CT3315010.discover-periodic-reports.enc", "eyJwaW5nXzAiOlsxMzg0Mjg1Mzg5MDk1LDE0NDAwMDAwXX0=");
Line Deleted : user_pref("CT3315010.discover-user-id", "%A8%BA%BA%B9%E8%E9%B9%BB%BF%B3%B9%EC%B6%BD%B3%BA%EC%E8%EA%B3%BF%EA%EB%BB%B3%BD%EC%B6%B7%BC%BD%B7%B8%BD%BE%EB%B6%A8");
Line Deleted : user_pref("CT3315010.discover-user-id.enc", "IjQ0M2JjMzU5LTNmMDctNGZiZC05ZGU1LTdmMDE2NzEyNzhlMCI=");
Line Deleted : user_pref("CT3315010.embeddedsData", "[{\"appId\":\"130238727266306057\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
Line Deleted : user_pref("CT3315010.enableAlerts", "true");
Line Deleted : user_pref("CT3315010.enableSearchFromAddressBar", "true");
Line Deleted : user_pref("CT3315010.firstTimeDialogOpened", "true");
Line Deleted : user_pref("CT3315010.fixPageNotFoundError", "true");
Line Deleted : user_pref("CT3315010.fixPageNotFoundErrorByUser", "true");
Line Deleted : user_pref("CT3315010.fixPageNotFoundErrorInHidden", "true");
Line Deleted : user_pref("CT3315010.fullUserID", "UN38370126891692121.IN.20130930220008");
Line Deleted : user_pref("CT3315010.ground-country-code", "%A8%DB%D9%A8");
Line Deleted : user_pref("CT3315010.ground-country-code.enc", "IlVTIg==");
Line Deleted : user_pref("CT3315010.impression_session_counter", "%B6");
Line Deleted : user_pref("CT3315010.impression_session_counter.enc", "MA==");
Line Deleted : user_pref("CT3315010.impression_session_id", "%A8%E7%EA%EA%EB%EC%E8%BC%EA%B3%B9%B6%B9%B6%B3%BA%B6%B8%EB%B3%BE%EB%E8%BF%B3%EA%B8%EC%E7%B8%BC%B9%EB%BF%BE%B6%B8%A8");
Line Deleted : user_pref("CT3315010.impression_session_id.enc", "ImFkZGVmYjZkLTMwMzAtNDAyZS04ZWI5LWQyZmEyNjNlOTgwMiI=");
Line Deleted : user_pref("CT3315010.impression_session_last_active", "%B7%B9%BE%BA%B8%BE%BB%B9%BF%B6%B7%BD%BB");
Line Deleted : user_pref("CT3315010.impression_session_last_active.enc", "MTM4NDI4NTM5MDE3NQ==");
Line Deleted : user_pref("CT3315010.installDate", "30/09/2013 22:00:09");
Line Deleted : user_pref("CT3315010.installId", "stub.exe");
Line Deleted : user_pref("CT3315010.installSessionId", "{71989043-B757-4821-9FFE-C5A4EAEEC360}");
Line Deleted : user_pref("CT3315010.installSp", "TRUE");
Line Deleted : user_pref("CT3315010.installType", "conduitnsisintegration");
Line Deleted : user_pref("CT3315010.installUsage", "2013-10-06T22:32:52.2296966+03:00");
Line Deleted : user_pref("CT3315010.installUsageEarly", "2013-10-06T22:32:49.8584662+03:00");
Line Deleted : user_pref("CT3315010.installerVersion", "1.7.1.4");
Line Deleted : user_pref("CT3315010.isCheckedStartAsHidden", true);
Line Deleted : user_pref("CT3315010.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3315010.isFirstTimeToolbarLoading", "false");
Line Deleted : user_pref("CT3315010.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT3315010.keyword", "true");
Line Deleted : user_pref("CT3315010.lastVersion", "10.20.1.8");
Line Deleted : user_pref("CT3315010.mam_gk_appStateReportTime", "%B7%B9%BE%BA%B8%BE%BB%B9%B6%B8%B7%BE%BC");
Line Deleted : user_pref("CT3315010.mam_gk_appStateReportTime.enc", "MTM4NDI4NTMwMjE4Ng==");
Line Deleted : user_pref("CT3315010.mam_gk_appState_ACplus.enc", "b24=");
Line Deleted : user_pref("CT3315010.mam_gk_appState_CouponBuddy.enc", "b24=");
Line Deleted : user_pref("CT3315010.mam_gk_appState_Discover.enc", "b24=");
Line Deleted : user_pref("CT3315010.mam_gk_appState_Easytobook.enc", "b24=");
Line Deleted : user_pref("CT3315010.mam_gk_appState_Easytobook_targeted.enc", "b24=");
Line Deleted : user_pref("CT3315010.mam_gk_appState_Find-a-Pro.enc", "b24=");
Line Deleted : user_pref("CT3315010.mam_gk_appState_PriceGong.enc", "b24=");
Line Deleted : user_pref("CT3315010.mam_gk_appState_WindowShopper.enc", "b24=");
Line Deleted : user_pref("CT3315010.mam_gk_appsConfig.enc", "eyJBcHBzQ29uZmlndXJhdGlvbiI6W3siaWQiOiJhcHAxMyIsInVybCI6Imh0dHA6Ly9zdG9yYWdlLmNvbmR1aXQuY29tL21hbS8zcmRwYXJ0eWFwcHMvZWRpbGlhL2VkaWxpYS5odG1sIiwic2NyaXB0VX[...]
Line Deleted : user_pref("CT3315010.mam_gk_appsDefaultEnabled", "%F4%FB%F2%F2");
Line Deleted : user_pref("CT3315010.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");
Line Deleted : user_pref("CT3315010.mam_gk_calledSetupService.enc", "MQ==");
Line Deleted : user_pref("CT3315010.mam_gk_currentVersion", "%B7%B4%B7%B7%B4%BA%B4%B8");
Line Deleted : user_pref("CT3315010.mam_gk_currentVersion.enc", "MS4xMS40LjI=");
Line Deleted : user_pref("CT3315010.mam_gk_existingUsersRecoveryDone.enc", "MQ==");
Line Deleted : user_pref("CT3315010.mam_gk_first_time", "%B7");
Line Deleted : user_pref("CT3315010.mam_gk_first_time.enc", "MQ==");
Line Deleted : user_pref("CT3315010.mam_gk_globalKeysMigratedToLocalStorage", "%B7");
Line Deleted : user_pref("CT3315010.mam_gk_globalKeysMigratedToLocalStorage.enc", "MQ==");
Line Deleted : user_pref("CT3315010.mam_gk_installer_preapproved.enc", "ZmFsc2U=");
Line Deleted : user_pref("CT3315010.mam_gk_lastLoginTime", "%B7%B9%BE%BA%B8%BE%BB%B9%B6%B8%B9%B8%BF");
Line Deleted : user_pref("CT3315010.mam_gk_lastLoginTime.enc", "MTM4NDI4NTMwMjMyOQ==");
Line Deleted : user_pref("CT3315010.mam_gk_localization", "ā%A8%ED%E7%EA%ED%EB%FA%C9%F5%F4%FA%EB%F4%FA%D6%F5%F2%EF%E9%FF%A8%C0ā%A8%DA%EB%FE%FA%A8%C0%A8%C9%F5%F4%FA%EB%F4%FA%A6%D6%F5%F2%EF%E9%FF%A8ă%B2[...]
Line Deleted : user_pref("CT3315010.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50IFBvbGljeSJ9LCJnYWRnZXREZXNjcmlwdGlvblByaW1hcnkiOnsiVGV4dCI6IlZhbHVlIEFwcHMgZW5yaWNoZXMgeW91ciB3ZWIg[...]
Line Deleted : user_pref("CT3315010.mam_gk_mamEnabled.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3315010.mam_gk_new_welcome_experience.enc", "MQ==");
Line Deleted : user_pref("CT3315010.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3315010.mam_gk_settings1.10.4.0.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMzVfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiVVMiLCJpc1dlbGNvbWVFeHBl[...]
Line Deleted : user_pref("CT3315010.mam_gk_settings1.11.4.2", "ā%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0ā%A8%E9%FB%F8%F8%EB%F4%FA%CA%E7%FA%EB%A8%C0%A8%B8%B6%B7%B[...]
Line Deleted : user_pref("CT3315010.mam_gk_settings1.11.4.2.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzExMTIiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6Ijg2XzAiLCJpc1Rlc3QiOnRydWUsIlVzZXJDb3VudHJ5[...]
Line Deleted : user_pref("CT3315010.mam_gk_showWelcomeGadget", "%EC%E7%F2%F9%EB");
Line Deleted : user_pref("CT3315010.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
Line Deleted : user_pref("CT3315010.mam_gk_stamp", "%BE%BC%E5%B6");
Line Deleted : user_pref("CT3315010.mam_gk_stamp.enc", "ODZfMA==");
Line Deleted : user_pref("CT3315010.mam_gk_userId", "%BF%EC%E8%BA%BF%E9%B7%E9%B3%BE%B7%B7%EC%B3%BA%BA%BA%BD%B3%E8%BC%E9%B8%B3%E9%B6%B6%E9%EA%BB%EA%B8%B9%B9%EB%EC");
Line Deleted : user_pref("CT3315010.mam_gk_userId.enc", "OWZiNDljMWMtODExZi00NDQ3LWI2YzItYzAwY2Q1ZDIzM2Vm");
Line Deleted : user_pref("CT3315010.mam_gk_user_approval_interacted", "%B7");
Line Deleted : user_pref("CT3315010.mam_gk_user_approval_interacted.enc", "MQ==");
Line Deleted : user_pref("CT3315010.mam_gk_welcomeDialogMode", "%B7");
Line Deleted : user_pref("CT3315010.mam_gk_welcomeDialogMode.enc", "MQ==");
Line Deleted : user_pref("CT3315010.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.dailymotion.com%2Fus%3Fff%3D1%26urlback%3D%252Fvideo%252Fxf78qr_maria-moore-2010-10-12-33-mb-12-min_redband\",\"[...]
Line Deleted : user_pref("CT3315010.openThankYouPage", "false");
Line Deleted : user_pref("CT3315010.openUninstallPage", "true");
Line Deleted : user_pref("CT3315010.originalSearchAddressUrl", "");
Line Deleted : user_pref("CT3315010.originalSearchEngine", "Yahoo");
Line Deleted : user_pref("CT3315010.originalSearchEngineName", "");
Line Deleted : user_pref("CT3315010.price-gong.isManagedApp", "true");
Line Deleted : user_pref("CT3315010.rematchagent-periodic-reports", "ā%A8%F6%EF%F4%ED%E5%B6%A8%C0%E1%B7%B9%BE%BA%B8%BE%BB%B9%B9%B7%BC%BF%B6%B2%B7%BA%BA%B6%B6%B6%B6%B6%E3ă");
Line Deleted : user_pref("CT3315010.rematchagent-periodic-reports.enc", "eyJwaW5nXzAiOlsxMzg0Mjg1MzMxNjkwLDE0NDAwMDAwXX0=");
Line Deleted : user_pref("CT3315010.rematchagent-user-id", "%A8%BF%BE%BB%B7%E8%B6%E9%B8%B3%BB%BB%BB%E7%B3%BA%B6%EB%EC%B3%E8%BA%B6%B7%B3%EC%E9%E7%B7%EC%B9%B9%E9%BE%BE%BC%EB%A8");
Line Deleted : user_pref("CT3315010.rematchagent-user-id.enc", "Ijk4NTFiMGMyLTU1NWEtNDBlZi1iNDAxLWZjYTFmMzNjODg2ZSI=");
Line Deleted : user_pref("CT3315010.response_cache.enc", "eyJjaGFubmVsIjp7ImxpbmsiOiJodHRwOi8vd3d3LmRhaWx5bW90aW9uLmNvbS91cyIsImRlc2NyaXB0aW9uIjoiVHJ1ZmZsZXMgQnkgQ29uZHVpdCIsInNvdXJjZSI6eyJ1cmwiOiJodHRwOi8vd3d3LmRha[...]
Line Deleted : user_pref("CT3315010.revertSettingsEnabled", "false");
Line Deleted : user_pref("CT3315010.search.searchAppId", "130238727266306057");
Line Deleted : user_pref("CT3315010.search.searchCount", "0");
Line Deleted : user_pref("CT3315010.searchFromAddressBarEnabledByUser", "true");
Line Deleted : user_pref("CT3315010.searchInNewTabEnabledByUser", "true");
Line Deleted : user_pref("CT3315010.searchInNewTabEnabledInHidden", "true");
Line Deleted : user_pref("CT3315010.searchRevert", "false");
Line Deleted : user_pref("CT3315010.searchSuggestEnabledByUser", "true");
Line Deleted : user_pref("CT3315010.searchUserMode", "2");
Line Deleted : user_pref("CT3315010.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3315010.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3315010.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT3315010.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3315010\"}");
Line Deleted : user_pref("CT3315010.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"KeyBar 1.29 \"}");
Line Deleted : user_pref("CT3315010.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3315010.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT3315010.serviceLayer_services_Configuration_lastUpdate", "1384146647984");
Line Deleted : user_pref("CT3315010.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1384146647779");
Line Deleted : user_pref("CT3315010.serviceLayer_services_appsMetadata_lastUpdate", "1384146647907");
Line Deleted : user_pref("CT3315010.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1384146647510");
Line Deleted : user_pref("CT3315010.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1381087971186");
Line Deleted : user_pref("CT3315010.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1381087973641");
Line Deleted : user_pref("CT3315010.serviceLayer_services_login_10.20.1.8_lastUpdate", "1384146647655");
Line Deleted : user_pref("CT3315010.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1384146647609");
Line Deleted : user_pref("CT3315010.serviceLayer_services_searchAPI_lastUpdate", "1384146647955");
Line Deleted : user_pref("CT3315010.serviceLayer_services_serviceMap_lastUpdate", "1384146647803");
Line Deleted : user_pref("CT3315010.serviceLayer_services_toolbarContextMenu_lastUpdate", "1384146647553");
Line Deleted : user_pref("CT3315010.serviceLayer_services_toolbarSettings_lastUpdate", "1384146647916");
Line Deleted : user_pref("CT3315010.serviceLayer_services_translation_lastUpdate", "1384146647769");
Line Deleted : user_pref("CT3315010.settingsINI", true);
Line Deleted : user_pref("CT3315010.shouldFirstTimeDialog", "false");
Line Deleted : user_pref("CT3315010.showToolbarPermission", "false");
Line Deleted : user_pref("CT3315010.smartbar.CTID", "CT3315010");
Line Deleted : user_pref("CT3315010.smartbar.Uninstall", "0");
Line Deleted : user_pref("CT3315010.smartbar.homepage", "true");
Line Deleted : user_pref("CT3315010.smartbar.toolbarName", "KeyBar 1.29 ");
Line Deleted : user_pref("CT3315010.startPage", "true");
Line Deleted : user_pref("CT3315010.toolbarBornServerTime", "6-10-2013");
Line Deleted : user_pref("CT3315010.toolbarCurrentServerTime", "11-11-2013");
Line Deleted : user_pref("CT3315010.toolbarLoginClientTime", "Sun Oct 06 2013 15:32:53 GMT-0400 (Eastern Standard Time)");
Line Deleted : user_pref("CT3315010.url_history0001", "%EE%FA%FA%F6%C0%B5%B5%F0%F5%E8%F9%B4%F2%EB%ED%F5%B4%E9%F5%F3%B5%EB%F4%B3%FB%F9%B5%EA%EB%EC%E7%FB%F2%FA%B4%E7%F9%F6%FE%C0%C0%C0%E9%F2%EF%E9%F1%EE%E7%F4%EA%F2%EB%[...]
Line Deleted : user_pref("CT3315010.url_history0001.enc", "aHR0cDovL2pvYnMubGVnby5jb20vZW4tdXMvZGVmYXVsdC5hc3B4Ojo6Y2xpY2toYW5kbGVyOjo6MTM4MTA4Nzk5Mjc1OSwsLGh0dHA6Ly9qb2JzLmxlZ28uY29tL2VuLXVzL2RlZmF1bHQuYXNweDo6OmNs[...]
Line Deleted : user_pref("CT3315010.versionFromInstaller", "10.20.1.8");
Line Deleted : user_pref("CT3315010.xpeMode", "0");
Line Deleted : user_pref("CT3315010_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1384285295368,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("Smartbar.ConduitSearchEngineList", "KeyBar 1.29 Customized Web Search");
Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3315010");
Line Deleted : user_pref("browser.search.defaultenginename", "KeyBar 1.29 Customized Web Search");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "KeyBar 1.29 Customized Web Search");
Line Deleted : user_pref("browser.search.selectedEngine", "KeyBar 1.29 Customized Web Search");
Line Deleted : user_pref("extensions.BabylonToolbar.admin", false);
Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
Line Deleted : user_pref("extensions.BabylonToolbar.autoRvrt", "false");
Line Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Line Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar.id", "9ef6696f000000000000902b34adc190");
Line Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15717");
Line Deleted : user_pref("extensions.BabylonToolbar.instlRef", "na");
Line Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar.rvrt", "false");
Line Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.8.7.2");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.8.7.2");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=100318&tt=0213_4");
Line Deleted : user_pref("extensions.BabylonToolbar_i.excTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false);
Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "def");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.7.218:26:01");
Line Deleted : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\");
Line Deleted : user_pref("extensions.asktb.abar-war-regex", "conduit\\.com");
Line Deleted : user_pref("extensions.asktb.apn_dbr", "cr_25.0.1364.172");
Line Deleted : user_pref("extensions.asktb.autofill-competitor-query-enabled", true);
Line Deleted : user_pref("extensions.asktb.browser.search.defaultenginename", "Ask.com");
Line Deleted : user_pref("extensions.asktb.cbid", "^TV");
Line Deleted : user_pref("extensions.asktb.config-updated", true);
Line Deleted : user_pref("extensions.asktb.cr-o", "100000031cr");
Line Deleted : user_pref("extensions.asktb.crumb", "2013.03.16+14.14.31-toolbar012iad-US-TmV3IFlvcmssTlksVW5pdGVkIFN0YXRlcw%3D%3D");
Line Deleted : user_pref("extensions.asktb.displaybehavior", "");
Line Deleted : user_pref("extensions.asktb.displaytext", "");
Line Deleted : user_pref("extensions.asktb.dtid", "^YYYYYY^YY^US");
Line Deleted : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);
Line Deleted : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "USNY0996");
Line Deleted : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "F");
Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");
Line Deleted : user_pref("extensions.asktb.ff19-config-first-run", "true");
Line Deleted : user_pref("extensions.asktb.first-restart-after-config-update", true);
Line Deleted : user_pref("extensions.asktb.fresh-install", false);
Line Deleted : user_pref("extensions.asktb.guid", "EBBFAB01-4A88-44DC-AE52-B9AF179F8DBC");
Line Deleted : user_pref("extensions.asktb.if", "su");
Line Deleted : user_pref("extensions.asktb.keyword-toggled-in-session", false);
Line Deleted : user_pref("extensions.asktb.l", "dis");
Line Deleted : user_pref("extensions.asktb.last-config-req", "1384285294452");
Line Deleted : user_pref("extensions.asktb.locale", "en_US");
Line Deleted : user_pref("extensions.asktb.location", "New York,NY,United States");
Line Deleted : user_pref("extensions.asktb.lstation", "");
Line Deleted : user_pref("extensions.asktb.new-tab-opt-out", true);
Line Deleted : user_pref("extensions.asktb.news-native-on", true);
Line Deleted : user_pref("extensions.asktb.o", "100000031");
Line Deleted : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Line Deleted : user_pref("extensions.asktb.pstate", "");
Line Deleted : user_pref("extensions.asktb.qsrc", "2871");
Line Deleted : user_pref("extensions.asktb.r", "22");
Line Deleted : user_pref("extensions.asktb.sa", "YES");
Line Deleted : user_pref("extensions.asktb.sa-enabled", "false");
Line Deleted : user_pref("extensions.asktb.saguid", "901C79CC-316D-4F7F-9290-13F841370898");
Line Deleted : user_pref("extensions.asktb.search-suggestions-enabled", true);
Line Deleted : user_pref("extensions.asktb.silent-upgrade", true);
Line Deleted : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Line Deleted : user_pref("extensions.asktb.socialmini-first", true);
Line Deleted : user_pref("extensions.asktb.socialmini-interval", "1200000");
Line Deleted : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
Line Deleted : user_pref("extensions.asktb.socialmini-max-items", "30");
Line Deleted : user_pref("extensions.asktb.socialmini-native-on", true);
Line Deleted : user_pref("extensions.asktb.socialmini-speed", "10000");
Line Deleted : user_pref("extensions.asktb.socialmini-transition-first-open", false);
Line Deleted : user_pref("extensions.asktb.themeid", "");
Line Deleted : user_pref("extensions.asktb.timeinstalled", "5/26/2013 3:07:26 PM");
Line Deleted : user_pref("extensions.asktb.to", "");
Line Deleted : user_pref("extensions.asktb.v", "3.15.25.100013");
Line Deleted : user_pref("extensions.asktb.version", "5.15.25.36191");
Line Deleted : user_pref("extensions.asktb.volume", "");
Line Deleted : user_pref("extensions.enabledItems", "helperbar@helperbar.com:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.8");
Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3315010");
Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3315010");
Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3315010");
Line Deleted : user_pref("smartbar.machineId", "S7MAOJQEUL97QZLYGNJJP5NRY3R6SG0M1HDLH5V5G4GNPGBY+FPOIS7WA0ULFP7X0FEV6NOSTDLX2WPGS+6YSG");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "Web Search");
 
[ File : C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\7sspa14p.default\prefs.js ]
 
Line Deleted : user_pref("CT3242576.1000082.isDisplayHidden", "true");
Line Deleted : user_pref("CT3242576.1000082.isPlayDisplay", "true");
Line Deleted : user_pref("CT3242576.1000082.muteState", "off");
Line Deleted : user_pref("CT3242576.1000234.TWC_TMP_city", "NORWALK");
Line Deleted : user_pref("CT3242576.1000234.TWC_TMP_country", "US");
Line Deleted : user_pref("CT3242576.1000234.TWC_locId", "USCA0782");
Line Deleted : user_pref("CT3242576.1000234.TWC_location", "Norwalk, CA");
Line Deleted : user_pref("CT3242576.1000234.TWC_region", "US");
Line Deleted : user_pref("CT3242576.1000234.TWC_temp_dis", "f");
Line Deleted : user_pref("CT3242576.1000234.TWC_wind_dis", "mph");
Line Deleted : user_pref("CT3242576.1000234.weatherData", "{\"icon\":\"28.png\",\"temperature\":\"68°F\",\"temperatureClear\":\"68°F\",\"highTemperature\":\"78°F\",\"lowTemperature\":\"65°F\",\"feelsLike\":\"68°F\",[...]
Line Deleted : user_pref("CT3242576.3242576a129903865128181458000000paramsGK0.enc", "eyJ1cGRhdGVSZXFUaW1lIjoxMzU5MzI0MDc0MTE5LCJ1cGRhdGVSZXNwVGltZSI6MTM1OTMyNDA3NjA0MiwiZGF0YSI6eyJzZXR0aW5ncyI6eyJpY29uIjoiaHR0cDovL3[...]
Line Deleted : user_pref("CT3242576.3242576a129903865128181458000000paramsGK1.enc", "eyJ1cGRhdGVSZXFUaW1lIjoxMzg4OTQyNjAxMTkxLCJ1cGRhdGVSZXNwVGltZSI6MTM4ODk0MjYwMjYwNCwiZGF0YSI6eyJzZXR0aW5ncyI6eyJpY29uIjoiaHR0cDovL3[...]
Line Deleted : user_pref("CT3242576.3242576a129903866302407727000000paramsGK1.enc", "eyJ1cGRhdGVSZXFUaW1lIjoxMzU5MzI0MDc0OTg3LCJ1cGRhdGVSZXNwVGltZSI6MTM1OTMyNDA3NjA0NiwiZGF0YSI6eyJzZXR0aW5ncyI6eyJpY29uIjoiaHR0cDovL3[...]
Line Deleted : user_pref("CT3242576.3242576a129903866302407727000000paramsGK2.enc", "eyJ1cGRhdGVSZXFUaW1lIjoxMzg4OTQyNjAyNjY2LCJ1cGRhdGVSZXNwVGltZSI6MTM4ODk0MjYwMzE4NCwiZGF0YSI6eyJzZXR0aW5ncyI6eyJpY29uIjoiaHR0cDovL3[...]
Line Deleted : user_pref("CT3242576.CBOpenMAMSettings.enc", "MA==");
Line Deleted : user_pref("CT3242576.CT3242576ads1.enc", "JTdCJTIyYWRzJTIyJTNBJTVCJTdCJTIyYWlkJTIyJTNBJTIyMTA2NzgzJTIyJTJDJTIydGl0bGUlMjIlM0ElMjJZb3UlMjBIYXZlJTIwJTI4MSUyOSUyMFNwZWVkJTIwVGVzdCUyMiUyQyUyMmFkdGV4dDElMj[...]
Line Deleted : user_pref("CT3242576.CT3242576current_term.enc", "aG93JTI1MjBtYW55JTI1MjBjZW50aW1ldGVycyUyNTIwaW4lMjUyMGFuJTI1MjBpbmNo");
Line Deleted : user_pref("CT3242576.CT3242576sdate.enc", "NA==");
Line Deleted : user_pref("CT3242576.Calendar_App_HeartBit.enc", "MTM4ODk0NjA3OTQ2NA==");
Line Deleted : user_pref("CT3242576.Calendar_DaysActivity.enc", "MTM4Nzg5MDAwNTc4NQ==");
Line Deleted : user_pref("CT3242576.Calendar_firstTimeNotification_130037766751907870.enc", "bm8=");
Line Deleted : user_pref("CT3242576.Calendar_lang.enc", "RU4=");
Line Deleted : user_pref("CT3242576.Calendar_lastOpenApp.enc", "MTM4ODk0NTYyOTEyOQ==");
Line Deleted : user_pref("CT3242576.Calendar_user_location.enc", "eyJpcEFkZHJlc3MiOiI2OS4xMjAuODcuMTg1IiwiY291bnRyeVNob3J0IjoiVVMiLCJjb3VudHJ5TG9uZyI6IlVOSVRFRCBTVEFURVMiLCJyZWdpb24iOiJDT05ORUNUSUNVVCIsImNpdHkiOiJTV[...]
Line Deleted : user_pref("CT3242576.Calendar_welcome_popup_text.enc", "Q2xpY2sgdG8gc3RhcnQgcnVubmluZyB5b3VyIHNjaGVkdWxlLCBldmVudHMsIGJpcnRoZGF5cywgYW5kIFRvIERvXMgcmlnaHQgaGVyZS4gIFN5bmMgd2l0aCBHb29nbGUgQ2FsZW5kYXIh"[...]
Line Deleted : user_pref("CT3242576.Calendar_welcome_popup_title.enc", "V2VsY29tZSB0byBDYWxlbmRhcis=");
Line Deleted : user_pref("CT3242576.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3242576.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3242576.FirstTime", "true");
Line Deleted : user_pref("CT3242576.FirstTimeFF3", "true");
Line Deleted : user_pref("CT3242576.InstallDate", "12/1/2013 19:29:06");
Line Deleted : user_pref("CT3242576.LAST_CLIENT_STATS_SUBMIT_2.enc", "MTM3MTMwMTIyOA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_STATS_LAST_SUBMIT_6.enc", "MTM4MzQwMzgwMA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_STATS_STATS_SITE_IRRELEVANT.enc", "MjM=");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_STATS_STATS_SITE_NEW.enc", "MA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_STATS_STATS_SITE_NOT_SUPPORTED.enc", "MA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_STATS_STATS_SITE_SUPPORTED.enc", "MQ==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_STATS_STATS_USE_HISTORY.enc", "MA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_STATS_STATS_USE_POP.enc", "MA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_STATS_STATS_USE_RELATED.enc", "MA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_STATS_STATS_USE_TYPED.enc", "MA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_THROTTLE_BASEadd_stats|0|LOCAL_COOKIE_STATS_STATS_SITE_IRRELEVANT.enc", "MTM4MzQ4OTM5Mg==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_THROTTLE_BASEadd_stats|0|LOCAL_COOKIE_STATS_STATS_SITE_NOT_SUPPORTED.enc", "MTM4MjgzMjYzNA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_THROTTLE_BASEadd_stats|0|LOCAL_COOKIE_STATS_STATS_SITE_SUPPORTED.enc", "MTM4MzQwOTg5OA==");
Line Deleted : user_pref("CT3242576.LOCAL_COOKIE_THROTTLE_BASEadd_stats|LOCAL_COOKIE_STATS_STATS_USE_TYPED.enc", "MTM3NTgzNTEyOA==");
Line Deleted : user_pref("CT3242576.LoginRevertSettingsEnabled", true);
Line Deleted : user_pref("CT3242576.PG_ENABLE", "dHJ1ZQ==");
Line Deleted : user_pref("CT3242576.PG_ENABLE.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3242576.RevertSettingsEnabled", true);
Line Deleted : user_pref("CT3242576.SF_JUST_INSTALLED.enc", "RkFMU0U=");
Line Deleted : user_pref("CT3242576.SF_STATUS.enc", "RU5BQkxFRA==");
Line Deleted : user_pref("CT3242576.SF_USER_ID.enc", "Y2lkXzI5NDIwMTMxODEyMDExMzY4MjY=");
Line Deleted : user_pref("CT3242576.UserID", "UN71739221018189188");
Line Deleted : user_pref("CT3242576.YouTubeTemplate_LastOpenAppDate3242576a129903866302407727000000.enc", "MTM1NzQxNjEwNzU0MA==");
Line Deleted : user_pref("CT3242576.YouTubeTemplate_param_f.enc", "MA==");
Line Deleted : user_pref("CT3242576.YouTubeTemplate_username_3242576a129903866302407727000000.enc", "RGVza3RvcEFuaW1hdGVk");
Line Deleted : user_pref("CT3242576._key_cl_active", "%E7%B9%EC%BF%B6%B7%BD%BF%B3%BD%E8%BA%BC%B3%BA%B6%E9%BB%B3%BE%B6%BF%E7%B3%B8%E8%E7%BB%E9%B7%B6%BB%EB%B9%BA%EB");
Line Deleted : user_pref("CT3242576._key_cl_active.enc", "YTNmOTAxNzktN2I0Ni00MGM1LTgwOWEtMmJhNWMxMDVlMzRl");
Line Deleted : user_pref("CT3242576.acp_personal.appstate.enc", "ZW5hYmxl");
Line Deleted : user_pref("CT3242576.addressBarTakeOverEnabledInHidden", "true");
Line Deleted : user_pref("CT3242576.autoDisableScopes", 0);
Line Deleted : user_pref("CT3242576.browser.search.defaultthis.engineName", true);
Line Deleted : user_pref("CT3242576.calendar_close_popup_130037766751907870.enc", "MTIz");
Line Deleted : user_pref("CT3242576.cb_experience_000", "%BB%B6");
Line Deleted : user_pref("CT3242576.cb_experience_000.enc", "NTA=");
Line Deleted : user_pref("CT3242576.cb_firstuse0100", "%B7");
Line Deleted : user_pref("CT3242576.cb_firstuse0100.enc", "MQ==");
Line Deleted : user_pref("CT3242576.cb_user_id_000.enc", "Q0IzMjQxNTA5NjE0NzJfMTM1OTM4NDk4NjEyMV9GaXJlZm94");
Line Deleted : user_pref("CT3242576.cbcountry_001.enc", "VVM=");
Line Deleted : user_pref("CT3242576.cbfirsttime.enc", "U3VuIEphbiAyNyAyMDEzIDE3OjE5OjUxIEdNVC0wNTAwIChFYXN0ZXJuIFN0YW5kYXJkIFRpbWUp");
Line Deleted : user_pref("CT3242576.countryCode", "US");
Line Deleted : user_pref("CT3242576.defaultSearch", "true");
Line Deleted : user_pref("CT3242576.discover-experiments-design.enc", "eyJuYW1lIjoidW5wYXJ0aWNpcGF0aW5nIiwidmVyc2lvbiI6MX0=");
Line Deleted : user_pref("CT3242576.discover-experiments-photopop.enc", "eyJuYW1lIjoicGhvdG9wb3BfbmEiLCJ2ZXJzaW9uIjoxMH0=");
Line Deleted : user_pref("CT3242576.discover-periodic-reports", "ā%A8%F6%EF%F4%ED%E5%B6%A8%C0%E1%B7%B9%BE%BA%BF%B6%BE%B9%BA%B8%BD%B7%BF%B2%B7%BA%BA%B6%B6%B6%B6%B6%E3ă");
Line Deleted : user_pref("CT3242576.discover-periodic-reports.enc", "eyJwaW5nXzAiOlsxMzg0OTA4MzQyNzE5LDE0NDAwMDAwXX0=");
Line Deleted : user_pref("CT3242576.discover-user-id.enc", "ImI1MzFlZWRkLTA1NWItNDM0MS04ZGQxLTk4YTI5MGFlOTYwOSI=");
Line Deleted : user_pref("CT3242576.embeddedsData", "[{\"appId\":\"10000002\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"instantAlert\":[...]
Line Deleted : user_pref("CT3242576.enableAlerts", "always");
Line Deleted : user_pref("CT3242576.enableFix404ByUser", "FALSE");
Line Deleted : user_pref("CT3242576.enableSearchFromAddressBar", "true");
Line Deleted : user_pref("CT3242576.firstTimeDialogOpened", "true");
Line Deleted : user_pref("CT3242576.fixPageNotFoundError", "true");
Line Deleted : user_pref("CT3242576.fixPageNotFoundErrorByUser", "true");
Line Deleted : user_pref("CT3242576.fixPageNotFoundErrorInHidden", "true");
Line Deleted : user_pref("CT3242576.fixUrls", true);
Line Deleted : user_pref("CT3242576.fullUserID", "UN71739221018189188.UP.20130629092213");
Line Deleted : user_pref("CT3242576.ground-country-code.enc", "IlVTIg==");
Line Deleted : user_pref("CT3242576.hover_counter", "%B9%BB");
Line Deleted : user_pref("CT3242576.hover_counter.enc", "MzU=");
Line Deleted : user_pref("CT3242576.hxxp___calendar_conduitapps_com_v1.APP_WIN_FEATURES.enc", "cmVzaXphYmxlPTAsaHNjcm9sbD0wLHZzY3JvbGw9MCx0aXRsZWJhcj0wLGNsb3NlYnV0dG9uPTAsc2F2ZXJlc2l6ZWRzaXplPTAsb3BlbnBvc2l0aW9uPW9m[...]
Line Deleted : user_pref("CT3242576.hxxp___conduit_s3_amazonaws_com.APP_WIN_FEATURES.enc", "cmVzaXphYmxlPW5vLGNsb3Nlb25leHRlcm5hbGNsaWNrPW5vLGhzY3JvbGw9bm8sdnNjcm9sbD1ubyxjbG9zZWJ1dHRvbj1ubyxzYXZlbG9jYXRpb249bm8sb3B[...]
Line Deleted : user_pref("CT3242576.hxxp___www_socialgrowthtechnologies_com_couponbuddy_v001.APP_WIN_FEATURES.enc", "b3BlbnBvc2l0aW9uPW9mZnNldDo1MDs1MCxzYXZlbG9jYXRpb249MCxyZXNpemFibGU9bm8sc2Nyb2xsYmFycz1ubyx0aXRsZW[...]
Line Deleted : user_pref("CT3242576.hxxp___youtubetemplate_conduitapps_com.APP_WIN_FEATURES.enc", "c2F2ZXJlc2l6ZWRzaXplPTAsaHNjcm9sbD0wLHZzY3JvbGw9MCxvcGVucG9zaXRpb249YWxpZ25tZW50OkIsY2xvc2VvbmV4dGVybmFsY2xpY2s9bm8s[...]
Line Deleted : user_pref("CT3242576.impression_counter", "%B7%B6%BE");
Line Deleted : user_pref("CT3242576.impression_counter.enc", "MTA4");
Line Deleted : user_pref("CT3242576.impression_session_counter", "%B7%BA");
Line Deleted : user_pref("CT3242576.impression_session_counter.enc", "MTQ=");
Line Deleted : user_pref("CT3242576.impression_session_id", "%A8%BF%B6%EB%B9%B8%BE%E8%BC%B3%BC%BB%EC%BD%B3%BA%B6%E8%E7%B3%E7%BF%BB%BC%B3%BB%E7%EC%EB%E9%EC%EB%BD%E9%B7%BB%B6%A8");
Line Deleted : user_pref("CT3242576.impression_session_id.enc", "IjkwZTMyOGI2LTY1ZjctNDBiYS1hOTU2LTVhZmVjZmU3YzE1MCI=");
Line Deleted : user_pref("CT3242576.impression_session_last_active", "%B7%B9%BE%BA%BD%B7%BB%B7%B6%B6%BF%B9%B8");
Line Deleted : user_pref("CT3242576.impression_session_last_active.enc", "MTM4NDcxNTEwMDkzMg==");
Line Deleted : user_pref("CT3242576.installId", "desk_toolbar.exe");
Line Deleted : user_pref("CT3242576.installType", "conduitnsisintegration");
Line Deleted : user_pref("CT3242576.introductionShown.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3242576.isCheckedStartAsHidden", true);
Line Deleted : user_pref("CT3242576.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3242576.isFirstTimeToolbarLoading", "false");
Line Deleted : user_pref("CT3242576.isNewTabEnabled", true);
Line Deleted : user_pref("CT3242576.isPerformedSmartBarTransition", "true");
Line Deleted : user_pref("CT3242576.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT3242576.keyword", true);
Line Deleted : user_pref("CT3242576.lastVersion", "10.23.0.822");
Line Deleted : user_pref("CT3242576.mam_gk_appStateReportTime", "%B7%B9%BE%BB%B8%B7%BA%BF%B8%BF%BA%B8%BB");
Line Deleted : user_pref("CT3242576.mam_gk_appStateReportTime.enc", "MTM4NTIxNDkyOTQyNQ==");
Line Deleted : user_pref("CT3242576.mam_gk_appState_Clarity_Active", "%F5%F4");
Line Deleted : user_pref("CT3242576.mam_gk_appState_Clarity_Active.enc", "b24=");
Line Deleted : user_pref("CT3242576.mam_gk_appState_CouponBuddy.enc", "b24=");
Line Deleted : user_pref("CT3242576.mam_gk_appState_Easytobook.enc", "b24=");
Line Deleted : user_pref("CT3242576.mam_gk_appState_Easytobook_targeted.enc", "b24=");
Line Deleted : user_pref("CT3242576.mam_gk_appState_PriceGong.enc", "b24=");
Line Deleted : user_pref("CT3242576.mam_gk_appState_WindowShopper.enc", "b24=");
Line Deleted : user_pref("CT3242576.mam_gk_appsConfig.enc", "eyJBcHBzQ29uZmlndXJhdGlvbiI6W3siaWQiOiJDbGFyaXR5X0FjdGl2ZSIsInVybCI6Imh0dHA6Ly9zdG9yYWdlLmNvbmR1aXQuY29tL21hbS8zcmRwYXJ0eWFwcHMvY2xhcml0eVJheS9jcl9hY3Rpdm[...]
Line Deleted : user_pref("CT3242576.mam_gk_appsDefaultEnabled", "%F4%FB%F2%F2");
Line Deleted : user_pref("CT3242576.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");
Line Deleted : user_pref("CT3242576.mam_gk_calledSetupService.enc", "MQ==");
Line Deleted : user_pref("CT3242576.mam_gk_currentBadgeValue", "%B7");
Line Deleted : user_pref("CT3242576.mam_gk_currentBadgeValue.enc", "MQ==");
Line Deleted : user_pref("CT3242576.mam_gk_currentVersion", "%B7%B4%B7%B7%B4%BA%B4%B8");
Line Deleted : user_pref("CT3242576.mam_gk_currentVersion.enc", "MS4xMS40LjI=");
Line Deleted : user_pref("CT3242576.mam_gk_existingUsersRecoveryDone.enc", "MQ==");
Line Deleted : user_pref("CT3242576.mam_gk_first_time", "%B7");
Line Deleted : user_pref("CT3242576.mam_gk_first_time.enc", "MQ==");
Line Deleted : user_pref("CT3242576.mam_gk_globalKeysMigratedToLocalStorage", "%B7");
Line Deleted : user_pref("CT3242576.mam_gk_globalKeysMigratedToLocalStorage.enc", "MQ==");
Line Deleted : user_pref("CT3242576.mam_gk_lastLoginTime", "%B7%B9%BE%BB%B8%B7%BA%BF%B8%BF%BC%BA%B6");
Line Deleted : user_pref("CT3242576.mam_gk_lastLoginTime.enc", "MTM4NTIxNDkyOTY0MA==");
Line Deleted : user_pref("CT3242576.mam_gk_localization.enc", "eyJkaWFsb2dPSyI6eyJUZXh0IjoiT0sifSwiZG1ib3gxIjp7IlRleHQiOiJEZWFsXHJcbm9mIHRoZSBkYXkifSwiZG1ib3gyIjp7IlRleHQiOiJGcmVlXHJcblNoaXBtZW50In0sImRtYnVsbGV0MSI6[...]
Line Deleted : user_pref("CT3242576.mam_gk_mamEnabled.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3242576.mam_gk_newApps", "%E1%E3");
Line Deleted : user_pref("CT3242576.mam_gk_newApps.enc", "W10=");
Line Deleted : user_pref("CT3242576.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3242576.mam_gk_settings1.10.2.5.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMzVfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiVVMiLCJpc1dlbGNvbWVFeHBl[...]
Line Deleted : user_pref("CT3242576.mam_gk_settings1.10.4.0.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzExMDMiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6IjM1XzAiLCJpc1Rlc3QiOnRydWUsIlVzZXJDb3VudHJ5[...]
Line Deleted : user_pref("CT3242576.mam_gk_settings1.11.4.2", "ā%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0ā%A8%E9%FB%F8%F8%EB%F4%FA%CA%E7%FA%EB%A8%C0%A8%B8%B6%B7%B[...]
Line Deleted : user_pref("CT3242576.mam_gk_settings1.11.4.2.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzExMjMiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6IjEwNDNfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50[...]
Line Deleted : user_pref("CT3242576.mam_gk_settings1.4.4.6.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsd[...]
Line Deleted : user_pref("CT3242576.mam_gk_settings1.6.0.1.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsd[...]
Line Deleted : user_pref("CT3242576.mam_gk_settings1.8.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMzVfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiVVMiLCJpc1dlbGNvbWVFeHBlc[...]
Line Deleted : user_pref("CT3242576.mam_gk_settings1.9.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMzVfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiVVMiLCJpc1dlbGNvbWVFeHBlc[...]
Line Deleted : user_pref("CT3242576.mam_gk_showCloseButton.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3242576.mam_gk_showWelcomeGadget", "%EC%E7%F2%F9%EB");
Line Deleted : user_pref("CT3242576.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
Line Deleted : user_pref("CT3242576.mam_gk_stamp", "%B7%B6%BA%B9%E5%B6");
Line Deleted : user_pref("CT3242576.mam_gk_stamp.enc", "MTA0M18w");
Line Deleted : user_pref("CT3242576.mam_gk_userId", "%BA%B8%B8%E9%BC%B6%B8%EA%B3%B9%EC%BB%BB%B3%BA%BC%E7%BF%B3%E8%BD%B7%EA%B3%BC%B8%BD%E8%EC%E7%E8%BA%E8%B9%B6%E9");
Line Deleted : user_pref("CT3242576.mam_gk_userId.enc", "NDIyYzYwMmQtM2Y1NS00NmE5LWI3MWQtNjI3YmZhYjRiMzBj");
Line Deleted : user_pref("CT3242576.mam_gk_user_approval_interacted", "%B7");
Line Deleted : user_pref("CT3242576.mam_gk_user_approval_interacted.enc", "MQ==");
Line Deleted : user_pref("CT3242576.mam_gk_welcomeDialogMode", "%B7");
Line Deleted : user_pref("CT3242576.mam_gk_welcomeDialogMode.enc", "MQ==");
Line Deleted : user_pref("CT3242576.migrateAppsAndComponents", true);
Line Deleted : user_pref("CT3242576.openThankYouPage", "false");
Line Deleted : user_pref("CT3242576.openUninstallPage", "true");
Line Deleted : user_pref("CT3242576.price-gong.isManagedApp", "true");
Line Deleted : user_pref("CT3242576.rematchagent-periodic-reports.enc", "eyJwaW5nXzAiOlsxMzgzNDE0MTg5OTUyLDE0NDAwMDAwXX0=");
Line Deleted : user_pref("CT3242576.rematchagent-user-id.enc", "ImY3YmU2MGNlLTFiY2MtNGJlZi1iMTk2LWQ2M2ZmNWY3MzEzOSI=");
Line Deleted : user_pref("CT3242576.response_cache.enc", "eyJjaGFubmVsIjp7ImxpbmsiOiJodHRwOi8vd3d3LnlvdXR1YmUuY29tLyIsImRlc2NyaXB0aW9uIjoiVHJ1ZmZsZXMgQnkgQ29uZHVpdCIsInNvdXJjZSI6eyJ1cmwiOiJodHRwOi8vd3d3LnlvdXR1YmUuY[...]
Line Deleted : user_pref("CT3242576.revertSettingsEnabled", "true");
Line Deleted : user_pref("CT3242576.sac-country-code.enc", "IlVTIg==");
Line Deleted : user_pref("CT3242576.sac-experiments-aaTest.enc", "eyJuYW1lIjoiYTEiLCJ2ZXJzaW9uIjoxfQ==");
Line Deleted : user_pref("CT3242576.sac-experiments-animation.enc", "eyJuYW1lIjoiMC43NSIsInZlcnNpb24iOjN9");
Line Deleted : user_pref("CT3242576.sac-experiments-hover_effect.enc", "eyJuYW1lIjoic2hvcnQiLCJ2ZXJzaW9uIjoyfQ==");
Line Deleted : user_pref("CT3242576.sac-experiments-image_analysis.enc", "eyJuYW1lIjoid2l0aG91dFN1YnRpdGxlIiwidmVyc2lvbiI6MX0=");
Line Deleted : user_pref("CT3242576.sac-experiments-peoplebar_call_to_action.enc", "eyJuYW1lIjoiMyIsInZlcnNpb24iOjR9");
Line Deleted : user_pref("CT3242576.sac-experiments-placement.enc", "eyJuYW1lIjoiYnJhbmRlZC1iYXIiLCJ2ZXJzaW9uIjoxM30=");
Line Deleted : user_pref("CT3242576.sac-experiments-play_icon.enc", "eyJuYW1lIjoibm8iLCJ2ZXJzaW9uIjoyfQ==");
Line Deleted : user_pref("CT3242576.sac-experiments-taboola_config.enc", "eyJuYW1lIjoiYWxsVHlwZXMiLCJ2ZXJzaW9uIjozfQ==");
Line Deleted : user_pref("CT3242576.sac-periodic-reports.enc", "eyJwaW5nXzAiOlsxMzcxMzAxMjM0Mjg4LDE0NDAwMDAwXX0=");
Line Deleted : user_pref("CT3242576.sac-user-id.enc", "IjUxYzg2ZjQwLTI4N2EtNDBiMS05NWRiLTEzMzM0NGJkMTI5MyI=");
Line Deleted : user_pref("CT3242576.sac-yt-first-ping.enc", "MTM3MTMwMTIzNDI4Mg==");
Line Deleted : user_pref("CT3242576.search.searchAppId", "10000002");
Line Deleted : user_pref("CT3242576.search.searchCount", "0");
Line Deleted : user_pref("CT3242576.searchInNewTabEnabledByUser", "true");
Line Deleted : user_pref("CT3242576.searchInNewTabEnabledInHidden", "true");
Line Deleted : user_pref("CT3242576.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3242576.searchSuggestEnabledByUser", "true");
Line Deleted : user_pref("CT3242576.searchUserMode", "false");
Line Deleted : user_pref("CT3242576.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3242576.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3242576.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT3242576.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3242576\"}");
Line Deleted : user_pref("CT3242576.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Desktop Animated \"}");
Line Deleted : user_pref("CT3242576.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3242576.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT3242576.serviceLayer_services_Configuration_lastUpdate", "1388942599096");
Line Deleted : user_pref("CT3242576.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1388332231006");
Line Deleted : user_pref("CT3242576.serviceLayer_services_appTracking_lastUpdate", "1377181775495");
Line Deleted : user_pref("CT3242576.serviceLayer_services_appsMetadata_lastUpdate", "1388942597253");
Line Deleted : user_pref("CT3242576.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1388848088572");
Line Deleted : user_pref("CT3242576.serviceLayer_services_location_lastUpdate", "1372449373450");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.13.40.15_lastUpdate", "1362523844471");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.14.65.43_lastUpdate", "1364224141484");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.15.0.562_lastUpdate", "1372449373815");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.15.2.523_lastUpdate", "1370201444428");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.16.4.519_lastUpdate", "1374593024673");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.16.70.505_lastUpdate", "1378218972583");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.19.2.505_lastUpdate", "1378851287444");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.20.0.513_lastUpdate", "1380462017923");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.20.1.508_lastUpdate", "1382567069163");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.21.1.507_lastUpdate", "1384611039336");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.22.3.518_lastUpdate", "1385214922318");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.22.5.510_lastUpdate", "1386978796376");
Line Deleted : user_pref("CT3242576.serviceLayer_services_login_10.23.0.822_lastUpdate", "1388942596694");
Line Deleted : user_pref("CT3242576.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1388848088608");
Line Deleted : user_pref("CT3242576.serviceLayer_services_searchAPI_lastUpdate", "1388942598847");
Line Deleted : user_pref("CT3242576.serviceLayer_services_serviceMap_lastUpdate", "1388942598603");
Line Deleted : user_pref("CT3242576.serviceLayer_services_setupAPI_lastUpdate", "1364224141907");
Line Deleted : user_pref("CT3242576.serviceLayer_services_toolbarContextMenu_lastUpdate", "1388942598335");
Line Deleted : user_pref("CT3242576.serviceLayer_services_toolbarSettings_lastUpdate", "1388942598373");
Line Deleted : user_pref("CT3242576.serviceLayer_services_translation_lastUpdate", "1388942598313");
Line Deleted : user_pref("CT3242576.settingsINI", true);
Line Deleted : user_pref("CT3242576.shouldFirstTimeDialog", "false");
Line Deleted : user_pref("CT3242576.showToolbarPermission", "false");
Line Deleted : user_pref("CT3242576.smartbar.CTID", "CT3242576");
Line Deleted : user_pref("CT3242576.smartbar.Uninstall", "0");
Line Deleted : user_pref("CT3242576.smartbar.homepage", true);
Line Deleted : user_pref("CT3242576.smartbar.toolbarName", "Desktop Animated ");
Line Deleted : user_pref("CT3242576.superCalendar_close_popup_130037766751907870.enc", "MC44MTAzMzg5Njk3NTE1MTg5");
Line Deleted : user_pref("CT3242576.super_Calendar_show_welcome_popup_130037766751907870.enc", "eWVz");
Line Deleted : user_pref("CT3242576.toolbarBornServerTime", "13-1-2013");
Line Deleted : user_pref("CT3242576.toolbarCurrentServerTime", "5-1-2014");
Line Deleted : user_pref("CT3242576.toolbarLoginClientTime", "Tue Mar 26 2013 10:24:38 GMT-0400 (Eastern Daylight Time)");
Line Deleted : user_pref("CT3242576.url_history0001", "%EE%FA%FA%F6%F9%C0%B5%B5%FD%FD%FD%B4%EC%E7%E9%EB%E8%F5%F5%F1%B4%E9%F5%F3%B5%C5%F8%EB%EC%C3%FA%F4%E5%FA%F4%F3%F4%C0%C0%C0%E9%F2%EF%E9%F1%EE%E7%F4%EA%F2%EB%F8%C0%[...]
Line Deleted : user_pref("CT3242576.url_history0001.enc", "aHR0cHM6Ly93d3cuZmFjZWJvb2suY29tLz9yZWY9dG5fdG5tbjo6OmNsaWNraGFuZGxlcjo6OjEzODUyMTU4NDcwODMsLCxodHRwczovL3d3dy5mYWNlYm9vay5jb20vP3JlZj10bl90bm1uOjo6Y2xpY2to[...]
Line Deleted : user_pref("CT3242576.wreck-experiments-design.enc", "eyJuYW1lIjoibGlnaHQiLCJ2ZXJzaW9uIjo0fQ==");
Line Deleted : user_pref("CT3242576.wreck-experiments-feed.enc", "eyJuYW1lIjoidHJ1ZmZsZXMiLCJ2ZXJzaW9uIjozfQ==");
Line Deleted : user_pref("CT3242576.wreck-experiments-hover_effect.enc", "eyJuYW1lIjoiaGFsZiIsInZlcnNpb24iOjF9");
Line Deleted : user_pref("CT3242576.wreck-experiments-trigger.enc", "eyJuYW1lIjoieDAuNSIsInZlcnNpb24iOjF9");
Line Deleted : user_pref("CT3242576.wreck-periodic-reports.enc", "eyJwaW5nXzAiOlsxMzcxMzAxMjM0MzYyLDE0NDAwMDAwXX0=");
Line Deleted : user_pref("CT3242576.wreck-user-id.enc", "ImIyM2QxMzc3LWU5YTItNDJjMS1iZDkyLTE2ZTE4NjhkYTI4MSI=");
Line Deleted : user_pref("CT3242576.youtubetemplate_3242576a129903866302407727000000_lang.enc", "RU4=");
Line Deleted : user_pref("CT3242576_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1388945625274,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("Smartbar.ConduitSearchEngineList", "Desktop Animated Customized Web Search");
Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3242576");
Line Deleted : user_pref("avg.install.userSPSettings", "Desktop Animated Customized Web Search");
Line Deleted : user_pref("avg.userPreferences.URLBarFocus.whiteList", "bing\\.com|google\\.\\w+|yahoo\\.\\w+|gmail\\.\\w+|hotmail\\.\\w+|live\\.\\w+|isearch\\.avg\\.com|mysearch\\.avg\\.com");
Line Deleted : user_pref("browser.search.defaultenginename", "Desktop Animated Customized Web Search");
Line Deleted : user_pref("browser.search.selectedEngine", "Desktop Animated Customized Web Search");
Line Deleted : user_pref("extensions.BabylonToolbar.admin", false);
Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
Line Deleted : user_pref("extensions.BabylonToolbar.autoRvrt", "false");
Line Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Line Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar.id", "9ef6696f000000000000902b34adc190");
Line Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15734");
Line Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Line Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar.rvrt", "false");
Line Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.8.7.2");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.8.7.2");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=119256");
Line Deleted : user_pref("extensions.BabylonToolbar_i.excTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false);
Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.7.221:13:34");
Line Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 2);
Line Deleted : user_pref("smartBar.searchInNewTabOwner", "CT3242576");
Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3242576");
Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3242576");
Line Deleted : user_pref("smartbar.machineId", "S7MAOJQEUL97QZLYGNJJP5NRY3R6SG0M1HDLH5V5G4GNPGBY+FPOIS7WA0ULFP7X0FEV6NOSTDLX2WPGS+6YSG");
Line Deleted : user_pref("smartbar.originalSearchEngine", false);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E+x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E,x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E-x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E.:2z527", "247E4035422A363879453A7C36412C742E20213128335449563E4A4C2E58583D263F2E324247");
Line Deleted : user_pref("valueApps.CT3242576./9B+7E.:2z527.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E.x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E/x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E06CG5EL8:", "6E6D696A6A7073707774");
Line Deleted : user_pref("valueApps.CT3242576./9B+7E06CG5EL8:.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E06CG5EL;8I:K", "247E2D2F226A74736F70707679767D7A242F4B49474F42357D5D5C3D");
Line Deleted : user_pref("valueApps.CT3242576./9B+7E06CG5EL;8I:K.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E0x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E1x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E2x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ1<=5!LAD.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ7FK;KG#8QKEF)TIL.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ7FK;KG#NCEP@MC+VKN.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ:F::?AOEI9OQGEJXMVNIK2]RU", "247E61393F236B25767171767B2B222D6F4250454E337B35475347474C4E5C5256465C5E545257655A635B56583F6A5F624F465134716661696467615A435C2A2[...]
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ:F::?AOEI9OQGEJXMVNIK2]RU.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ:F::?AOEI9SAMHJLYOP0[PS.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ:F::?AOEOAOTBNIKG.YNQ.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ:J3AI<=$ODG.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ>BJH<;7D=??TJ*UJM", "247E61393F236B25766F7177722B222D6F4250454E337B354B4F5755494844514A4C4C61573762575A473E492C695E59615C5F59523B542225574E593C68646E7A5F48615[...]
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ>BJH<;7D=??TJ*UJM.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ@699HNN$ODG.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ@BJCMM#NCF", "247E61393F236B2575737275762B222D6F4250454E337B354D4F57505A5A305B50534037422551525B4730493A394C434E605F636F5F7262563F5E593C69786C69777E7D624B644F[...]
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJ@BJCMM#NCF.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJEIK4!LAD.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJGJFH>=K>?&QFI.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJHB>F!LAD.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJI8A K@C.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJIG=KI\"MBE.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E31;CJII=8:\"MBE.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E3x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E4x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E5x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E6x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E7x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E8x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E9x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E:x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E;x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E<x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E=x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E>x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E?x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7E@x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7EAx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7EBE3G=;D9N9=D", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57");
Line Deleted : user_pref("valueApps.CT3242576./9B+7EBE3G=;D9N9=D.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B+7EBx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7ECx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7EDx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B+7Etx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576./9B-0?3G>D", "3E673B413F716E737A7145787620797C7E2125517C7D532A20275554592A27592B5C2D2A");
Line Deleted : user_pref("valueApps.CT3242576./9B-0?3G>D.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B-0?3G@6:5;", "");
Line Deleted : user_pref("valueApps.CT3242576./9B-0?3G@6:5;.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B-0?3GFA7EF", "2B2E2C3D");
Line Deleted : user_pref("valueApps.CT3242576./9B-0?3GFA7EF.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B-3=3ECCJA=F>", "247E333D2C452F4135276F292A212C393D44307832332A354448584C3A23282E2E3132333435363B466068576C5E6857705A6C60606B6668563F73796F697861");
Line Deleted : user_pref("valueApps.CT3242576./9B-3=3ECCJA=F>.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B/>01=9A6K6<IM;KRIE@PDAWM", "6A696B7273747576");
Line Deleted : user_pref("valueApps.CT3242576./9B/>01=9A6K6<IM;KRIE@PDAWM.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B3=>@44I48?", "372C2D3269757633423633414847203E3D474E4D4C45474F2A554A4D2D5858585E4B554E366352564F");
Line Deleted : user_pref("valueApps.CT3242576./9B3=>@44I48?.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B5BA==9CJAG", "666D3C3F726F6F457A7743737647747B7A79787B23");
Line Deleted : user_pref("valueApps.CT3242576./9B5BA==9CJAG.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B6B11G4C56B>F;P;ANR@P", "6E6D696A6A7073707773777378");
Line Deleted : user_pref("valueApps.CT3242576./9B6B11G4C56B>F;P;ANR@P.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B90E@.3C;7B=?OFB>>RHIQS", "393F352F3E");
Line Deleted : user_pref("valueApps.CT3242576./9B90E@.3C;7B=?OFB>>RHIQS.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B9643G3/9E", "6A");
Line Deleted : user_pref("valueApps.CT3242576./9B9643G3/9E.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B;45>:BI9I7IE", "2B2E2C3D");
Line Deleted : user_pref("valueApps.CT3242576./9B;45>:BI9I7IE.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B<:222H64<", "393F352F3E");
Line Deleted : user_pref("valueApps.CT3242576./9B<:222H64<.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B<:222H64<L8DAJ", "6D70706F7673747975752A7977727C7D757C21");
Line Deleted : user_pref("valueApps.CT3242576./9B<:222H64<L8DAJ.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B=+03EH8H8J?:", "4443");
Line Deleted : user_pref("valueApps.CT3242576./9B=+03EH8H8J?:.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B?+E2A52D8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52");
Line Deleted : user_pref("valueApps.CT3242576./9B?+E2A52D8.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9B?B0D:8AJ62<H", "6D");
Line Deleted : user_pref("valueApps.CT3242576./9B?B0D:8AJ62<H.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576./9BA@0<0BI6A7GN:6@L?", "6C");
Line Deleted : user_pref("valueApps.CT3242576./9BA@0<0BI6A7GN:6@L?.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.PG_ENABLE", "74727565");
Line Deleted : user_pref("valueApps.CT3242576.PG_ENABLE.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.SF_JUST_INSTALLED", "46414C5345");
Line Deleted : user_pref("valueApps.CT3242576.SF_JUST_INSTALLED.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.SF_USER_ID", "6369645F32393432303133313831323031313336383236");
Line Deleted : user_pref("valueApps.CT3242576.SF_USER_ID.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576._key_cl_active", "61336639303137392D376234362D343063352D383039612D326261356331303565333465");
Line Deleted : user_pref("valueApps.CT3242576._key_cl_active.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.cb_experience_000", "3939");
Line Deleted : user_pref("valueApps.CT3242576.cb_experience_000.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.cb_firstuse0100", "31");
Line Deleted : user_pref("valueApps.CT3242576.cb_firstuse0100.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.cb_user_id_000", "43423332343135303936313437325F313335393338343938363132315F46697265666F78");
Line Deleted : user_pref("valueApps.CT3242576.cb_user_id_000.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.cbfirsttime", "53756E204A616E20323720323031332031373A31393A353120474D542D3035303020284561737465726E205374616E646172642054696D6529");
Line Deleted : user_pref("valueApps.CT3242576.cbfirsttime.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.discover-experiments-photopop", "7B226E616D65223A2270686F746F706F705F6E61222C2276657273696F6E223A31307D");
Line Deleted : user_pref("valueApps.CT3242576.discover-experiments-photopop.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.discover-periodic-reports", "7B2270696E675F30223A5B313338383934353638343138372C31343430303030305D7D");
Line Deleted : user_pref("valueApps.CT3242576.discover-periodic-reports.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.discover-user-id", "2262353331656564642D303535622D343334312D386464312D39386132393061653936303922");
Line Deleted : user_pref("valueApps.CT3242576.discover-user-id.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.ground-country-code", "22555322");
Line Deleted : user_pref("valueApps.CT3242576.ground-country-code.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.hover_counter", "3432");
Line Deleted : user_pref("valueApps.CT3242576.hover_counter.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.impression_counter", "313239");
Line Deleted : user_pref("valueApps.CT3242576.impression_counter.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.impression_session_counter", "3233");
Line Deleted : user_pref("valueApps.CT3242576.impression_session_counter.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.impression_session_id", "2232653534303264632D383833612D343963372D613464632D35633530373766343437646222");
Line Deleted : user_pref("valueApps.CT3242576.impression_session_id.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.impression_session_last_active", "31333838393435363834343837");
Line Deleted : user_pref("valueApps.CT3242576.impression_session_last_active.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appStateReportTime", "31333838393432363032333033");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appStateReportTime.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_Clarity_Active", "6F6E");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_Clarity_Active.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_CouponBuddy", "6F6E");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_CouponBuddy.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_Easytobook", "6F6E");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_Easytobook.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_Easytobook_targeted", "6F6E");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_Easytobook_targeted.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_PriceGong", "6F6E");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_PriceGong.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_WindowShopper", "6F6E");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appState_WindowShopper.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appsConfig.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appsDefaultEnabled", "6E756C6C");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_appsDefaultEnabled.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_calledSetupService", "31");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_calledSetupService.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_currentBadgeValue", "31");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_currentBadgeValue.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_currentVersion", "312E31322E302E35");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_currentVersion.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_existingUsersRecoveryDone", "31");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_existingUsersRecoveryDone.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_first_time", "31");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_first_time.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_globalKeysMigratedToLocalStorage", "31");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_globalKeysMigratedToLocalStorage.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_lastLoginTime", "31333838393432363032373032");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_lastLoginTime.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_localization.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_mamEnabled", "74727565");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_mamEnabled.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_migrated_from_ls", "31");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_migrated_from_ls.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_newApps", "5B5D");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_newApps.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_pgUnloadedOnce", "74727565");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_pgUnloadedOnce.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_settings1.10.4.0.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_settings1.11.4.2.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_settings1.11.5.1.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_settings1.12.0.5.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_showWelcomeGadget", "66616C7365");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_showWelcomeGadget.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_stamp", "313034335F30");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_stamp.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_userId", "34323263363032642D336635352D343661392D623731642D363237626661623462333063");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_userId.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_user_approval_interacted", "31");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_user_approval_interacted.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_welcomeDialogMode", "31");
Line Deleted : user_pref("valueApps.CT3242576.mam_gk_welcomeDialogMode.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3242576.response_cache.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3242576.url_history0001.storedInFile", true);
 
-\\ Google Chrome v31.0.1650.63
 
[ File : C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted : icon_url
Deleted : search_url
Deleted : suggest_url
Deleted : keyword
 
[ File : C:\Users\mom\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted : homepage
Deleted : urls_to_restore_on_startup
Deleted : search_url
Deleted : suggest_url
 
*************************
 
AdwCleaner[R0].txt - [107929 octets] - [10/01/2014 20:48:33]
AdwCleaner[s0].txt - [109091 octets] - [10/01/2014 20:53:06]
 
########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [109153 octets] ##########
Link to post
Share on other sites

Malwarebytes Anti-Malware 1.75.0.1300

www.malwarebytes.org

 

Database version: v2014.01.11.01

 

Windows 7 x64 NTFS

Internet Explorer 8.0.7600.16385

Brice Ortiz :: BRICEORTIZ-PC [administrator]

 

1/10/2014 9:05:41 PM

mbam-log-2014-01-10 (21-05-41).txt

 

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 274712

Time elapsed: 8 minute(s), 31 second(s)

 

Memory Processes Detected: 0

(No malicious items detected)

 

Memory Modules Detected: 0

(No malicious items detected)

 

Registry Keys Detected: 0

(No malicious items detected)

 

Registry Values Detected: 0

(No malicious items detected)

 

Registry Data Items Detected: 0

(No malicious items detected)

 

Folders Detected: 0

(No malicious items detected)

 

Files Detected: 0

(No malicious items detected)

 

(end)
Link to post
Share on other sites

Before we clean up remove tools etc we still need to run an online AV scan to ensure there are no remnants of any infection left on your system that we may have missed. This scan is very thorough and well worth running, it can take several hours please be patient and let it complete:

 

Run Eset Online Scanner

 

**Note** You will need to use Internet explorer for this scan - Vista and win 7 right click on IE shortcut and run as admin

 

Go to Eset web page http://www.eset.com/us/online-scanner/ to run an online scan from ESET.

 

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • click on the Run ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
    Click Start
  • When asked, allow the add/on to be installed
    Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings, ensure the options
  • Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
    Click Scan
  • wait for the virus definitions to be downloaded
  • Wait for the scan to finish

 

When the scan is complete

 

  • If no threats were found
  • put a checkmark in "Uninstall application on close"
  • close program
  • report to me that nothing was found

 

If threats were found

 

  • click on "list of threats found"
  • click on "export to text file" and save it as ESET SCAN and save to the desktop
  • Click on back
  • put a checkmark in "Uninstall application on close"
  • click on finish

 

close program

 

copy and paste the report in next reply

 

Kevin.... ;)

Link to post
Share on other sites

LONGEST FREAKING WAIT EVER.. BUT THANK YOU! what now

 

 

 

 

C:\$Recycle.Bin\S-1-5-21-264361256-2442009338-2428154096-1002\$R53R91X.exe a variant of Win32/InstallCore.BB application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\BitTorrentControl_v12\BitTorrentControl_v12ToolbarHelper.exe.vir Win32/Toolbar.Conduit.Q application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\BitTorrentControl_v12\ldrtbBitT.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\BitTorrentControl_v12\prxtbBitT.dll.vir Win32/Toolbar.Conduit.O application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\BitTorrentControl_v12\tbBitT.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Desktop_Animated\ldrtbDes0.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Desktop_Animated\ldrtbDes2.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Desktop_Animated\ldrtbDesk.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Desktop_Animated\prxtbDesk.dll.vir Win32/Toolbar.Conduit.O application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Desktop_Animated\tbDes0.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Desktop_Animated\tbDes2.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Desktop_Animated\tbDesk.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Users\Brice Ortiz\AppData\Local\Conduit\CT3225826\BitTorrentControl_v12AutoUpdateHelper.exe.vir Win32/Toolbar.Conduit.Q application

C:\AdwCleaner\Quarantine\C\Users\Brice Ortiz\AppData\LocalLow\BitTorrentControl_v12\ldrtbBitT.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Users\Brice Ortiz\AppData\LocalLow\BitTorrentControl_v12\tbBitT.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Users\Brice Ortiz\AppData\LocalLow\Desktop_Animated\ldrtbDes0.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Users\Brice Ortiz\AppData\LocalLow\Desktop_Animated\ldrtbDesk.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Users\Brice Ortiz\AppData\LocalLow\Desktop_Animated\tbDes0.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Users\Brice Ortiz\AppData\LocalLow\Desktop_Animated\tbDesk.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Users\Brice Ortiz\AppData\Roaming\Mozilla\Firefox\Profiles\0vn9fp5p.default\Extensions\toolbar@ask.com\chrome\temp\askToolbar.exe.vir a variant of Win32/Bundled.Toolbar.Ask application

C:\AdwCleaner\Quarantine\C\Users\Brice Ortiz\AppData\Roaming\Search Protection\Uninstall.exe.vir probably a variant of Win32/Toolbar.Widgi application

C:\AdwCleaner\Quarantine\C\Users\mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo\7.15.27.55142_0\background\setup.exe.vir a variant of Win32/Bundled.Toolbar.Ask application

C:\AdwCleaner\Quarantine\C\Users\mom\AppData\LocalLow\Desktop_Animated\ldrtbDes0.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Users\mom\AppData\LocalLow\Desktop_Animated\ldrtbDes2.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Users\mom\AppData\LocalLow\Desktop_Animated\ldrtbDesk.dll.vir a variant of Win32/Toolbar.Conduit.P application

C:\AdwCleaner\Quarantine\C\Users\mom\AppData\LocalLow\Desktop_Animated\tbDes0.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Users\mom\AppData\LocalLow\Desktop_Animated\tbDes2.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Users\mom\AppData\LocalLow\Desktop_Animated\tbDesk.dll.vir a variant of Win32/Toolbar.Conduit.B application

C:\AdwCleaner\Quarantine\C\Users\mom\AppData\LocalLow\Desktop_Animated\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.8\bin\PriceGongIE.dll.vir a variant of Win32/PriceGong.A application

C:\FRST\Quarantine\APNSetup.exe a variant of Win32/Bundled.Toolbar.Ask.E application

C:\FRST\Quarantine\rpcss.dll Win64/Patched.H trojan

C:\FRST\Quarantine\setup.exe a variant of Win32/Bundled.Toolbar.Ask application

C:\FRST\Quarantine\tbedrs.dll a variant of Win32/Toolbar.Conduit.B application

C:\FRST\Quarantine\tbKeyB.dll a variant of Win32/Toolbar.Conduit.B application

C:\FRST\Quarantine\VidSaver_20121217.exe multiple threats

C:\Games\The Elder Scrolls V Skyrim\steam_api.dll Win32/HackTool.Crack.BQ application

C:\Program Files (x86)\Avira\AntiVir Desktop\offercast_avirav7_.exe a variant of Win32/Bundled.Toolbar.Ask.D application

C:\Users\Brice Ortiz\AppData\Local\Mozilla\Firefox\Profiles\0vn9fp5p.default\Cache\6\DE\D19C3d01 a variant of Win32/Bundled.Toolbar.Ask application

C:\Users\Brice Ortiz\AppData\Local\Temp\OIC28D8.tmp a variant of Win32/OpenInstall application

C:\Users\Brice Ortiz\AppData\Local\Temp\OIC7FB2.tmp a variant of Win32/OpenInstall application

C:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\installer_util.exe a variant of Win32/Toolbar.CrossRider.E application

C:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\mixer.exe Win32/Packed.ScrambleWrapper.B application

C:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\main.exe Win32/Toolbar.Zugo.C application

C:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\OIAssistWTD.exe a variant of Win32/OpenInstall application

C:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\main.exe Win32/Toolbar.Zugo.C application

C:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\OIAssistWTD.exe a variant of Win32/OpenInstall application

C:\Users\Brice Ortiz\AppData\Local\Temp\RarSFX0\offercast_avirav7_.exe a variant of Win32/Bundled.Toolbar.Ask.D application

C:\Users\Brice Ortiz\Desktop\FIFA 13\__Installer\FIFA 13\Game\rldea.dll Win32/HackTool.Crack.BA application

C:\Users\Brice Ortiz\Desktop\MISC DESK TOP\rars\New folder (3)\Space_Travel_Animated_Wallpaper.exe a variant of Win32/Toolbar.Babylon.A application

C:\Users\Brice Ortiz\Downloads\avira_free_antivirus_en.exe a variant of Win32/Bundled.Toolbar.Ask.D application

C:\Users\Brice Ortiz\Downloads\VLC.exe a variant of Win32/OpenInstall application

C:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM.part1.exe a variant of Win32/HackTool.Crack.BQ application

C:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM\Binaries\Win32\steam_api.dll a variant of Win32/HackTool.Crack.BQ application

C:\Users\mom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUPF3JU9\html_comp[1].htm Win32/PriceGong.B application

C:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\ccp.exe Win32/Toolbar.Babylon.M application

C:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\IEHelper.dll Win32/Toolbar.Babylon.E application

C:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\Setup.exe a variant of Win32/Toolbar.Babylon.H application

C:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ.exe a variant of Win32/DomaIQ.A application

C:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ10.exe a variant of Win32/DomaIQ.A application

C:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\Dealvault.exe multiple threats

C:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\FlashPlayer.exe Win32/DomaIQ.M application

C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (1).exe multiple threats

C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (2).exe multiple threats

C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (3).exe multiple threats

C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1(1).exe multiple threats

C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1.exe multiple threats

C:\Users\mom\Downloads\Setup.exe Win32/OutBrowse.G application
Link to post
Share on other sites

Download OTM from either of the following links and save to your Desktop: (If your security alerts to OTM, either accept the alert or turn off security to allow OTM to run)

http://oldtimer.geekstogo.com/OTM.exe.
http://www.itxassociates.com/OT-Tools/OTM.com
http://www.itxassociates.com/OT-Tools/OTM.exe  

Double click OTM.exe to start the tool. Vista or Windows 7 users accepy UAC alert. Be aware all processes will be stopped during run, also Desktop will disappear, this will be put back on completion.... If your security alerts to OTM either, accept the alert or turn off security until OTM completes...

  • Copy the text from the code box belowbelow to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy). Ensure to start with and include the colon before Files :Files

    :FilesC:\$Recycle.Bin\S-1-5-21-264361256-2442009338-2428154096-1002\$R53R91X.exe a variant of Win32/InstallCore.BB applicationC:\Games\The Elder Scrolls V Skyrim\steam_api.dll Win32/HackTool.Crack.BQ applicationC:\Users\Brice Ortiz\AppData\Local\Mozilla\Firefox\Profiles\0vn9fp5p.default\Cache\6\DE\D19C3d01C:\Users\Brice Ortiz\AppData\Local\Temp\OIC28D8.tmpC:\Users\Brice Ortiz\AppData\Local\Temp\OIC7FB2.tmpC:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\installer_util.exeC:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\mixer.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\main.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\OIAssistWTD.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\main.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\OIAssistWTD.exeC:\Users\Brice Ortiz\AppData\Local\Temp\RarSFX0\offercast_avirav7_.exeC:\Users\Brice Ortiz\Desktop\FIFA 13\__Installer\FIFA 13\Game\rldea.dllC:\Users\Brice Ortiz\Desktop\MISC DESK TOP\rars\New folder (3)\Space_Travel_Animated_Wallpaper.exeC:\Users\Brice Ortiz\Downloads\avira_free_antivirus_en.exeC:\Users\Brice Ortiz\Downloads\VLC.exeC:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM.part1.exeC:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM\Binaries\Win32\steam_api.dllC:\Users\mom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUPF3JU9\html_comp[1].htmC:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\ccp.exeC:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\IEHelper.dllC:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\Setup.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ10.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\Dealvault.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\FlashPlayer.exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (1).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (2).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (3).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1(1).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1.exeC:\Users\mom\Downloads\Setup.exe:Commands[EmptyTemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red btnmoveit.png button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM


Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

If the machine reboots, the Results log can be found here:

c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log

Where mmddyyyy_hhmmss is the date of the tool run.

Post OTM log in next reply, let me know if any remaining issues or concerns...

 

Kevin

Link to post
Share on other sites

The script must start with :Files on the first line, then each line follows underneath:

:FilesC:\$Recycle.Bin\S-1-5-21-264361256-2442009338-2428154096-1002\$R53R91X.exe a variant of Win32/InstallCore.BB applicationC:\Games\The Elder Scrolls V Skyrim\steam_api.dll Win32/HackTool.Crack.BQ applicationC:\Users\Brice Ortiz\AppData\Local\Mozilla\Firefox\Profiles\0vn9fp5p.default\Cache\6\DE\D19C3d01C:\Users\Brice Ortiz\AppData\Local\Temp\OIC28D8.tmpC:\Users\Brice Ortiz\AppData\Local\Temp\OIC7FB2.tmpC:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\installer_util.exeC:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\mixer.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\main.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\OIAssistWTD.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\main.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\OIAssistWTD.exeC:\Users\Brice Ortiz\AppData\Local\Temp\RarSFX0\offercast_avirav7_.exeC:\Users\Brice Ortiz\Desktop\FIFA 13\__Installer\FIFA 13\Game\rldea.dllC:\Users\Brice Ortiz\Desktop\MISC DESK TOP\rars\New folder (3)\Space_Travel_Animated_Wallpaper.exeC:\Users\Brice Ortiz\Downloads\avira_free_antivirus_en.exeC:\Users\Brice Ortiz\Downloads\VLC.exeC:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM.part1.exeC:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM\Binaries\Win32\steam_api.dllC:\Users\mom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUPF3JU9\html_comp[1].htmC:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\ccp.exeC:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\IEHelper.dllC:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\Setup.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ10.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\Dealvault.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\FlashPlayer.exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (1).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (2).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (3).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1(1).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1.exeC:\Users\mom\Downloads\Setup.exe:Commands[EmptyTemp]
Link to post
Share on other sites

OK, close out OTM, then re-run again.....

 

Copy the script once again, (I muck up first two lines)  then use the "move it" button...

:FilesC:\$Recycle.Bin\S-1-5-21-264361256-2442009338-2428154096-1002\$R53R91X.exeC:\Games\The Elder Scrolls V Skyrim\steam_api.dllC:\Users\Brice Ortiz\AppData\Local\Mozilla\Firefox\Profiles\0vn9fp5p.default\Cache\6\DE\D19C3d01C:\Users\Brice Ortiz\AppData\Local\Temp\OIC28D8.tmpC:\Users\Brice Ortiz\AppData\Local\Temp\OIC7FB2.tmpC:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\installer_util.exeC:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\mixer.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\main.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\OIAssistWTD.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\main.exeC:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\OIAssistWTD.exeC:\Users\Brice Ortiz\AppData\Local\Temp\RarSFX0\offercast_avirav7_.exeC:\Users\Brice Ortiz\Desktop\FIFA 13\__Installer\FIFA 13\Game\rldea.dllC:\Users\Brice Ortiz\Desktop\MISC DESK TOP\rars\New folder (3)\Space_Travel_Animated_Wallpaper.exeC:\Users\Brice Ortiz\Downloads\avira_free_antivirus_en.exeC:\Users\Brice Ortiz\Downloads\VLC.exeC:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM.part1.exeC:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM\Binaries\Win32\steam_api.dllC:\Users\mom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUPF3JU9\html_comp[1].htmC:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\ccp.exeC:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\IEHelper.dllC:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\Setup.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ10.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\Dealvault.exeC:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\FlashPlayer.exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (1).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (2).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (3).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1(1).exeC:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1.exeC:\Users\mom\Downloads\Setup.exe:Commands[EmptyTemp]

Cheers...

Link to post
Share on other sites

ok this is what happened 

 

 

All processes killed

Error: Unable to interpret <C:\$Recycle.Bin\S-1-5-21-264361256-2442009338-2428154096-1002\$R53R91X.exe a variant of Win32/InstallCore.BB application> in the current context!

Error: Unable to interpret <C:\Games\The Elder Scrolls V Skyrim\steam_api.dll Win32/HackTool.Crack.BQ application> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Mozilla\Firefox\Profiles\0vn9fp5p.default\Cache\6\DE\D19C3d01> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Temp\OIC28D8.tmp> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Temp\OIC7FB2.tmp> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\installer_util.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Temp\nsa1992.tmp\mixer.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\main.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Temp\oi_arEvTvWRUd\OIAssistWTD.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\main.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Temp\oi_tA6b8zNYNk\OIAssistWTD.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\AppData\Local\Temp\RarSFX0\offercast_avirav7_.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\Desktop\FIFA 13\__Installer\FIFA 13\Game\rldea.dll> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\Desktop\MISC DESK TOP\rars\New folder (3)\Space_Travel_Animated_Wallpaper.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\Downloads\avira_free_antivirus_en.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\Downloads\VLC.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM.part1.exe> in the current context!

Error: Unable to interpret <C:\Users\Brice Ortiz\Downloads\Dishonored PC full game + DLC ^^nosTEAM^^\Dishonored nosTEAM\Binaries\Win32\steam_api.dll> in the current context!

Error: Unable to interpret <C:\Users\mom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUPF3JU9\html_comp[1].htm> in the current context!

Error: Unable to interpret <C:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\ccp.exe> in the current context!

Error: Unable to interpret <C:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\IEHelper.dll> in the current context!

Error: Unable to interpret <C:\Users\mom\AppData\Local\Temp\28D0E8A5-BAB0-7891-84CA-C176032EC998\Latest\Setup.exe> in the current context!

Error: Unable to interpret <C:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ.exe> in the current context!

Error: Unable to interpret <C:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\DomaIQ10.exe> in the current context!

Error: Unable to interpret <C:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\Dealvault.exe> in the current context!

Error: Unable to interpret <C:\Users\mom\AppData\Local\Temp\DM\FlashPlayer_084\software\FlashPlayer.exe> in the current context!

Error: Unable to interpret <C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (1).exe> in the current context!

Error: Unable to interpret <C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (2).exe> in the current context!

Error: Unable to interpret <C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1 (3).exe> in the current context!

Error: Unable to interpret <C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1(1).exe> in the current context!

Error: Unable to interpret <C:\Users\mom\Downloads\FlashPlayer_transaction_id=10260e7ae15377eb8544292d6fd1e1.exe> in the current context!

Error: Unable to interpret <C:\Users\mom\Downloads\Setup.exe> in the current context!

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: All Users

 

User: Brice Ortiz

->Temp folder emptied: 2136360795 bytes

->Temporary Internet Files folder emptied: 12020042 bytes

->Java cache emptied: 25856 bytes

->FireFox cache emptied: 385481825 bytes

->Google Chrome cache emptied: 339845380 bytes

->Flash cache emptied: 12618 bytes

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: Desktop

 

User: mom

->Temp folder emptied: 44678626 bytes

->Temporary Internet Files folder emptied: 49325320 bytes

->FireFox cache emptied: 343958362 bytes

->Google Chrome cache emptied: 402837462 bytes

->Flash cache emptied: 34083 bytes

 

User: Public

 

User: UpdatusUser

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

%systemdrive% .tmp files removed: 4257 bytes

%systemroot% .tmp files removed: 401408 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 325675330 bytes

%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 19537905 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 364002640 bytes

RecycleBin emptied: 20411474 bytes

 

Total Files Cleaned = 4,239.00 mb

 

 

OTM by OldTimer - Version 3.1.21.0 log created on 01112014_171420

 

Files moved on Reboot...

C:\Users\Brice Ortiz\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3 moved successfully.

C:\Users\Brice Ortiz\AppData\Local\Google\Chrome\User Data\Default\Cache\index moved successfully.

File move failed. C:\Windows\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot.

File move failed. C:\Windows\temp\logishrd\LVPrcInj02.dll scheduled to be moved on reboot.

 

Registry entries deleted on Reboot...
Link to post
Share on other sites

mmm script you paste in is different to what I posted this time... Leave OTM we try different scanner...

 

Download Dr Web Cureit from here http://www.freedrweb.com/cureit save to your desktop. (Scroll to bottom of page)

 

  • The file will be randomly named
  • Reboot to safe mode
  • Run Dr Web
  • Tick the I agree box and select continue
  • Click select objects for scanning
     
    drwebselect.JPG
     
  • Tick all boxes as shown
  • Click the wrench and select automatically apply actions to threats
     
    drwebfolders.JPG
     
  • Press start scan
  • The scan will now commence
     
    drwebscan.JPG
     
  • Once the scan has finished click open report
     
    drwebscancomplete.JPG
     
  • A notepad will open
  • Select File > Save as..
  • Save it to your desktop

 

This log will be excessive,  Attach it to your next reply…

Link to post
Share on other sites

Thanks for the log, Adobe Reader is outdated...

 

Visit http://get.adobe.com/uk/reader/otherversions/ and download the latest version of Acrobat Reader

 

Step 1 - Select your Operating System.

Step 2 - Select your Langauge.

Step 3 - Select latest version.

 

Untick the option for any security scanner or toolbar if offered.

 

Download and install.

 

Having the latest updates ensures there are no security vulnerabilities in your system.

 

Let me know if there are any remaining issues or concerns..

 

Kevin

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.