[FONT=Arial] [/FONT]
[FONT=Arial]DDS.txt:[/FONT]
[FONT=Arial]DDS (Ver_2012-11-20.01) - NTFS_AMD64 [/FONT]
[FONT=Arial]Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 1.6.0_37[/FONT]
[FONT=Arial]Run by Andre at 14:32:22 on 2012-12-07[/FONT]
[FONT=Arial]Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1787.573 [GMT -5:00][/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]AV: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}[/FONT]
[FONT=Arial]SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}[/FONT]
[FONT=Arial]SP: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]============== Running Processes ===============[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]C:\Windows\system32\lsm.exe[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k DcomLaunch[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k RPCSS[/FONT]
[FONT=Arial]C:\Windows\system32\atiesrxx.exe[/FONT]
[FONT=Arial]C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted[/FONT]
[FONT=Arial]C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k netsvcs[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k GPSvcGroup[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k LocalService[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k NetworkService[/FONT]
[FONT=Arial]C:\Windows\System32\spoolsv.exe[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork[/FONT]
[FONT=Arial]C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe[/FONT]
[FONT=Arial]C:\Windows\system32\atieclxx.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Bonjour\mDNSResponder.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Launch Manager\dsiwmis.exe[/FONT]
[FONT=Arial]C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation[/FONT]
[FONT=Arial]C:\Program Files (x86)\Acer\Registration\GREGsvc.exe[/FONT]
[FONT=Arial]C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt[/FONT]
[FONT=Arial]C:\Windows\System32\svchost.exe -k HPZ12[/FONT]
[FONT=Arial]C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe[/FONT]
[FONT=Arial]C:\Windows\System32\svchost.exe -k HPZ12[/FONT]
[FONT=Arial]C:\Program Files (x86)\Secunia\PSI\PSIA.exe[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k imgsvc[/FONT]
[FONT=Arial]C:\Program Files\Acer\Acer Updater\UpdaterService.exe[/FONT]
[FONT=Arial]C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[/FONT]
[FONT=Arial]C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[/FONT]
[FONT=Arial]C:\Windows\system32\taskhost.exe[/FONT]
[FONT=Arial]C:\Windows\system32\Dwm.exe[/FONT]
[FONT=Arial]C:\Windows\Explorer.EXE[/FONT]
[FONT=Arial]C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe[/FONT]
[FONT=Arial]C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[/FONT]
[FONT=Arial]C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[/FONT]
[FONT=Arial]C:\Program Files\Windows Sidebar\sidebar.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Launch Manager\LManager.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\iTunes\iTunesHelper.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\AVG\AVG2013\avgui.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Launch Manager\LMworker.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe[/FONT]
[FONT=Arial]C:\Windows\system32\wbem\unsecapp.exe[/FONT]
[FONT=Arial]C:\Program Files\iPod\bin\iPodService.exe[/FONT]
[FONT=Arial]C:\Windows\system32\SearchIndexer.exe[/FONT]
[FONT=Arial]C:\Windows\system32\wbem\wmiprvse.exe[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k HPService[/FONT]
[FONT=Arial]C:\Windows\System32\alg.exe[/FONT]
[FONT=Arial]C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted[/FONT]
[FONT=Arial]C:\Program Files\Windows Media Player\wmpnetwk.exe[/FONT]
[FONT=Arial]C:\Windows\System32\svchost.exe -k LocalServicePeerNet[/FONT]
[FONT=Arial]C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[/FONT]
[FONT=Arial]C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Secunia\PSI\sua.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbam.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Local\Google\Chrome\Application\chrome.exe[/FONT]
[FONT=Arial]C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe[/FONT]
[FONT=Arial]C:\Windows\System32\svchost.exe -k WerSvcGroup[/FONT]
[FONT=Arial]C:\Windows\system32\wbem\wmiprvse.exe[/FONT]
[FONT=Arial]C:\Windows\SysWOW64\WerFault.exe[/FONT]
[FONT=Arial]C:\Windows\System32\cscript.exe[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]============== Pseudo HJT Report ===============[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]uStart Page = hxxp://
www.google.com[/FONT]
[FONT=Arial]mStart Page = hxxp://
www.google.com[/FONT]
[FONT=Arial]BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll[/FONT]
[FONT=Arial]BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll[/FONT]
[FONT=Arial]BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - <orphaned>[/FONT]
[FONT=Arial]BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll[/FONT]
[FONT=Arial]BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll[/FONT]
[FONT=Arial]BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll[/FONT]
[FONT=Arial]BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll[/FONT]
[FONT=Arial]EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll[/FONT]
[FONT=Arial]uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun[/FONT]
[FONT=Arial]uRun: [Google Update] "C:\Users\Andre\AppData\Local\Google\Update\GoogleUpdate.exe" /c[/FONT]
[FONT=Arial]mRun: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"[/FONT]
[FONT=Arial]mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d[/FONT]
[FONT=Arial]mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"[/FONT]
[FONT=Arial]mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k[/FONT]
[FONT=Arial]mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun[/FONT]
[FONT=Arial]mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe[/FONT]
[FONT=Arial]mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"[/FONT]
[FONT=Arial]mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"[/FONT]
[FONT=Arial]mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe[/FONT]
[FONT=Arial]mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY[/FONT]
[FONT=Arial]mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"[/FONT]
[FONT=Arial]mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime[/FONT]
[FONT=Arial]mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"[/FONT]
[FONT=Arial]StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe[/FONT]
[FONT=Arial]StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[/FONT]
[FONT=Arial]uPolicies-Explorer: NoDrives = dword:0[/FONT]
[FONT=Arial]mPolicies-Explorer: NoDrives = dword:0[/FONT]
[FONT=Arial]mPolicies-System: ConsentPromptBehaviorAdmin = dword:5[/FONT]
[FONT=Arial]mPolicies-System: ConsentPromptBehaviorUser = dword:3[/FONT]
[FONT=Arial]mPolicies-System: EnableUIADesktopToggle = dword:0[/FONT]
[FONT=Arial]IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000[/FONT]
[FONT=Arial]IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll[/FONT]
[FONT=Arial]IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]INFO: HKCU has more than 50 listed domains.[/FONT]
[FONT=Arial]If you wish to scan all of them, select the 'Force scan all domains' option.[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab[/FONT]
[FONT=Arial]DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab[/FONT]
[FONT=Arial]DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab[/FONT]
[FONT=Arial]DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab[/FONT]
[FONT=Arial]TCP: NameServer = 192.168.1.1[/FONT]
[FONT=Arial]TCP: Interfaces\{99FAD201-D5A5-4844-905D-3B5500AE8C0C} : DHCPNameServer = 192.168.1.1[/FONT]
[FONT=Arial]TCP: Interfaces\{99FAD201-D5A5-4844-905D-3B5500AE8C0C}\14E6769656D2053402E4564777F627B6 : DHCPNameServer = 192.168.2.1[/FONT]
[FONT=Arial]TCP: Interfaces\{99FAD201-D5A5-4844-905D-3B5500AE8C0C}\341626C65675966496 : DHCPNameServer = 65.32.5.74 65.32.5.75[/FONT]
[FONT=Arial]TCP: Interfaces\{99FAD201-D5A5-4844-905D-3B5500AE8C0C}\3686964716479647F6 : DHCPNameServer = 65.32.5.111 65.32.5.112[/FONT]
[FONT=Arial]TCP: Interfaces\{99FAD201-D5A5-4844-905D-3B5500AE8C0C}\47D6F62696C656 : DHCPNameServer = 66.94.9.120 66.94.25.120[/FONT]
[FONT=Arial]Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>[/FONT]
[FONT=Arial]Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll[/FONT]
[FONT=Arial]x64-mStart Page = hxxp://searchfunmoods.com/?f=1&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyBzz0EyEtDtDtAtCyDyEyC0E0CyBtC0FtN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1127914451[/FONT]
[FONT=Arial]x64-BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - <orphaned>[/FONT]
[FONT=Arial]x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll[/FONT]
[FONT=Arial]x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s[/FONT]
[FONT=Arial]x64-Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe[/FONT]
[FONT=Arial]x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe[/FONT]
[FONT=Arial]x64-Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[/FONT]
[FONT=Arial]x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>[/FONT]
[FONT=Arial]x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>[/FONT]
[FONT=Arial]x64-Notify: PFW - <no file>[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]================= FIREFOX ===================[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]FF - ProfilePath - C:\Users\Andre\AppData\Roaming\Mozilla\Firefox\Profiles\sb105d98.default\[/FONT]
[FONT=Arial]FF - prefs.js: browser.startup.homepage - Google.com[/FONT]
[FONT=Arial]FF - prefs.js: keyword.URL - hxxp://
www.google.com/search?&q=[/FONT]
[FONT=Arial]FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll[/FONT]
[FONT=Arial]FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll[/FONT]
[FONT=Arial]FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll[/FONT]
[FONT=Arial]FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll[/FONT]
[FONT=Arial]FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll[/FONT]
[FONT=Arial]FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll[/FONT]
[FONT=Arial]FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll[/FONT]
[FONT=Arial]FF - plugin: C:\Users\Andre\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll[/FONT]
[FONT=Arial]FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll[/FONT]
[FONT=Arial]FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll[/FONT]
[FONT=Arial]FF - plugin: C:\Windows\SysWOW64\npmproxy.dll[/FONT]
[FONT=Arial]FF - ExtSQL: 2012-10-16 20:44; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; C:\Users\Andre\AppData\Roaming\Mozilla\Firefox\Profiles\sb105d98.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}[/FONT]
[FONT=Arial]FF - ExtSQL: 2012-10-21 23:34; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}[/FONT]
[FONT=Arial]FF - ExtSQL: 2012-11-23 10:51; {4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}; C:\Users\Andre\AppData\Roaming\Mozilla\Firefox\Profiles\sb105d98.default\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi[/FONT]
[FONT=Arial]FF - ExtSQL: 2012-11-25 11:58;
adblockpopups@jessehakanen.net; C:\Users\Andre\AppData\Roaming\Mozilla\Firefox\Profiles\sb105d98.default\extensions\
adblockpopups@jessehakanen.net.xpi[/FONT]
[FONT=Arial]FF - ExtSQL: 2012-12-01 14:50; {fe272bd1-5f76-4ea4-8501-a05d35d823fc}; C:\Users\Andre\AppData\Roaming\Mozilla\Firefox\Profiles\sb105d98.default\extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi[/FONT]
[FONT=Arial]FF - ExtSQL: 2012-12-01 14:52;
simpleadblock@wips.com; C:\Users\Andre\AppData\Roaming\Mozilla\Firefox\Profiles\sb105d98.default\extensions\
simpleadblock@wips.com.xpi[/FONT]
[FONT=Arial]FF - ExtSQL: !HIDDEN! 2011-04-16 23:40;
smartwebprinting@hp.com; C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]---- FIREFOX POLICIES ----[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.hmpg - true[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.hmpgUrl - hxxp://searchfunmoods.com/?f=1&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyBzz0EyEtDtDtAtCyDyEyC0E0CyBtC0FtN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1127914451[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.dfltSrch - true[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.srchPrvdr - Search[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.dnsErr - true[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods_i.newTab - true[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.newTabUrl - hxxp://searchfunmoods.com/?f=2&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyBzz0EyEtDtDtAtCyDyEyC0E0CyBtC0FtN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1127914451[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://searchfunmoods.com/?f=3&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyBzz0EyEtDtDtAtCyDyEyC0E0CyBtC0FtN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1127914451&q=[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.id - 78E40031546EC71F[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.instlDay - 15669[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.vrsn - 1.5.23.22[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.vrsni - 1.5.23.22[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2215:17:5[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.prtnrId - funmoods[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.prdct - funmoods[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.aflt - download[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods_i.smplGrp - none[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.tlbrId - base[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.instlRef - download[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.dfltLng - [/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.excTlbr - false[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.autoRvrt - false[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.envrmnt - production[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.isdcmntcmplt - true[/FONT]
[FONT=Arial]FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]============= SERVICES / DRIVERS ===============[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-10-15 63328][/FONT]
[FONT=Arial]R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120][/FONT]
[FONT=Arial]R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-10-5 111456][/FONT]
[FONT=Arial]R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800][/FONT]
[FONT=Arial]R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-10-22 154464][/FONT]
[FONT=Arial]R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696][/FONT]
[FONT=Arial]R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032][/FONT]
[FONT=Arial]R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2009-6-2 22576][/FONT]
[FONT=Arial]R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2009-6-2 20016][/FONT]
[FONT=Arial]R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2009-6-2 60464][/FONT]
[FONT=Arial]R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-4-2 202752][/FONT]
[FONT=Arial]R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664][/FONT]
[FONT=Arial]R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-4-2 325200][/FONT]
[FONT=Arial]R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-4-25 865824][/FONT]
[FONT=Arial]R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-1-8 23584][/FONT]
[FONT=Arial]R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-3-8 250368][/FONT]
[FONT=Arial]R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-5 144640][/FONT]
[FONT=Arial]R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2010-4-2 321064][/FONT]
[FONT=Arial]R3 PSI;PSI;C:\Windows\System32\drivers\psi_mf.sys [2010-9-1 17976][/FONT]
[FONT=Arial]R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2010-4-25 38456][/FONT]
[FONT=Arial]S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-6 5814392][/FONT]
[FONT=Arial]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384][/FONT]
[FONT=Arial]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576][/FONT]
[FONT=Arial]S3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-2-1 305520][/FONT]
[FONT=Arial]S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-5 50432][/FONT]
[FONT=Arial]S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-14 19456][/FONT]
[FONT=Arial]S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-4-2 239136][/FONT]
[FONT=Arial]S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-14 57856][/FONT]
[FONT=Arial]S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712][/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]=============== Created Last 30 ================[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]2012-12-06 02:05:56 -------- d-----w- C:\Program Files (x86)\SpeedFan[/FONT]
[FONT=Arial]2012-11-14 05:47:13 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui[/FONT]
[FONT=Arial]2012-11-14 05:47:12 9728 ----a-w- C:\Windows\System32\Wdfres.dll[/FONT]
[FONT=Arial]2012-11-14 05:47:12 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys[/FONT]
[FONT=Arial]2012-11-14 05:47:12 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys[/FONT]
[FONT=Arial]2012-11-14 05:43:59 4916224 ----a-w- C:\Windows\SysWow64\mstscax.dll[/FONT]
[FONT=Arial]2012-11-14 05:43:59 384000 ----a-w- C:\Windows\System32\wksprt.exe[/FONT]
[FONT=Arial]2012-11-14 05:43:59 3174912 ----a-w- C:\Windows\System32\rdpcorets.dll[/FONT]
[FONT=Arial]2012-11-14 05:43:59 228864 ----a-w- C:\Windows\System32\rdpendp_winip.dll[/FONT]
[FONT=Arial]2012-11-14 05:43:59 1123840 ----a-w- C:\Windows\System32\mstsc.exe[/FONT]
[FONT=Arial]2012-11-14 05:43:59 1048064 ----a-w- C:\Windows\SysWow64\mstsc.exe[/FONT]
[FONT=Arial]2012-11-14 05:43:58 5773824 ----a-w- C:\Windows\System32\mstscax.dll[/FONT]
[FONT=Arial]2012-11-14 05:14:43 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys[/FONT]
[FONT=Arial]2012-11-14 05:14:42 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys[/FONT]
[FONT=Arial]2012-11-14 05:14:41 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll[/FONT]
[FONT=Arial]2012-11-14 05:14:41 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll[/FONT]
[FONT=Arial]2012-11-14 05:14:40 744448 ----a-w- C:\Windows\System32\WUDFx.dll[/FONT]
[FONT=Arial]2012-11-14 05:14:40 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll[/FONT]
[FONT=Arial]2012-11-14 05:14:40 229888 ----a-w- C:\Windows\System32\WUDFHost.exe[/FONT]
[FONT=Arial]2012-11-14 05:10:59 340992 ----a-w- C:\Windows\System32\schannel.dll[/FONT]
[FONT=Arial]2012-11-14 05:10:59 247808 ----a-w- C:\Windows\SysWow64\schannel.dll[/FONT]
[FONT=Arial]2012-11-14 05:10:58 458712 ----a-w- C:\Windows\System32\drivers\cng.sys[/FONT]
[FONT=Arial]2012-11-14 05:10:58 307200 ----a-w- C:\Windows\System32\ncrypt.dll[/FONT]
[FONT=Arial]2012-11-14 05:10:58 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll[/FONT]
[FONT=Arial]2012-11-14 05:10:58 154480 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys[/FONT]
[FONT=Arial]2012-11-14 05:10:58 1448448 ----a-w- C:\Windows\System32\lsasrv.dll[/FONT]
[FONT=Arial]2012-11-14 05:10:57 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll[/FONT]
[FONT=Arial]2012-11-14 05:10:57 22016 ----a-w- C:\Windows\SysWow64\secur32.dll[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]==================== Find3M ====================[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]2012-11-13 04:23:49 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl[/FONT]
[FONT=Arial]2012-11-13 04:23:49 697272 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe[/FONT]
[FONT=Arial]2012-10-25 08:12:26 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx[/FONT]
[FONT=Arial]2012-10-25 08:12:26 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts[/FONT]
[FONT=Arial]2012-10-22 18:02:44 154464 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys[/FONT]
[FONT=Arial]2012-10-18 18:25:58 3149824 ----a-w- C:\Windows\System32\win32k.sys[/FONT]
[FONT=Arial]2012-10-16 08:38:37 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll[/FONT]
[FONT=Arial]2012-10-16 08:38:34 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll[/FONT]
[FONT=Arial]2012-10-16 07:39:52 561664 ----a-w- C:\Windows\apppatch\AcLayers.dll[/FONT]
[FONT=Arial]2012-10-15 08:48:50 63328 ----a-w- C:\Windows\System32\drivers\avgidsha.sys[/FONT]
[FONT=Arial]2012-10-09 18:17:13 55296 ----a-w- C:\Windows\System32\dhcpcsvc6.dll[/FONT]
[FONT=Arial]2012-10-09 18:17:13 226816 ----a-w- C:\Windows\System32\dhcpcore6.dll[/FONT]
[FONT=Arial]2012-10-09 17:40:31 44032 ----a-w- C:\Windows\SysWow64\dhcpcsvc6.dll[/FONT]
[FONT=Arial]2012-10-09 17:40:31 193536 ----a-w- C:\Windows\SysWow64\dhcpcore6.dll[/FONT]
[FONT=Arial]2012-10-08 22:34:08 10220472 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe[/FONT]
[FONT=Arial]2012-10-08 11:31:03 2312704 ----a-w- C:\Windows\System32\jscript9.dll[/FONT]
[FONT=Arial]2012-10-08 11:23:52 1392128 ----a-w- C:\Windows\System32\wininet.dll[/FONT]
[FONT=Arial]2012-10-08 11:22:55 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl[/FONT]
[FONT=Arial]2012-10-08 11:18:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe[/FONT]
[FONT=Arial]2012-10-08 11:17:35 599040 ----a-w- C:\Windows\System32\vbscript.dll[/FONT]
[FONT=Arial]2012-10-08 11:13:33 2382848 ----a-w- C:\Windows\System32\mshtml.tlb[/FONT]
[FONT=Arial]2012-10-08 07:56:24 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll[/FONT]
[FONT=Arial]2012-10-08 07:48:03 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll[/FONT]
[FONT=Arial]2012-10-08 07:47:44 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl[/FONT]
[FONT=Arial]2012-10-08 07:44:05 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe[/FONT]
[FONT=Arial]2012-10-08 07:43:21 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll[/FONT]
[FONT=Arial]2012-10-08 07:40:56 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb[/FONT]
[FONT=Arial]2012-10-05 08:32:50 111456 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys[/FONT]
[FONT=Arial]2012-10-03 17:56:54 1914248 ----a-w- C:\Windows\System32\drivers\tcpip.sys[/FONT]
[FONT=Arial]2012-10-03 17:44:21 70656 ----a-w- C:\Windows\System32\nlaapi.dll[/FONT]
[FONT=Arial]2012-10-03 17:44:21 303104 ----a-w- C:\Windows\System32\nlasvc.dll[/FONT]
[FONT=Arial]2012-10-03 17:44:17 246272 ----a-w- C:\Windows\System32\netcorehc.dll[/FONT]
[FONT=Arial]2012-10-03 17:44:17 18944 ----a-w- C:\Windows\System32\netevent.dll[/FONT]
[FONT=Arial]2012-10-03 17:44:16 216576 ----a-w- C:\Windows\System32\ncsi.dll[/FONT]
[FONT=Arial]2012-10-03 17:42:16 569344 ----a-w- C:\Windows\System32\iphlpsvc.dll[/FONT]
[FONT=Arial]2012-10-03 16:42:24 18944 ----a-w- C:\Windows\SysWow64\netevent.dll[/FONT]
[FONT=Arial]2012-10-03 16:42:24 175104 ----a-w- C:\Windows\SysWow64\netcorehc.dll[/FONT]
[FONT=Arial]2012-10-03 16:42:23 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll[/FONT]
[FONT=Arial]2012-10-03 16:07:26 45568 ----a-w- C:\Windows\System32\drivers\tcpipreg.sys[/FONT]
[FONT=Arial]2012-10-02 07:30:38 185696 ----a-w- C:\Windows\System32\drivers\avgldx64.sys[/FONT]
[FONT=Arial]2012-09-30 00:54:26 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys[/FONT]
[FONT=Arial]2012-09-25 22:47:43 78336 ----a-w- C:\Windows\SysWow64\synceng.dll[/FONT]
[FONT=Arial]2012-09-25 22:46:17 95744 ----a-w- C:\Windows\System32\synceng.dll[/FONT]
[FONT=Arial]2012-09-24 19:32:24 477168 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll[/FONT]
[FONT=Arial]2012-09-24 19:32:20 473072 ----a-w- C:\Windows\SysWow64\deployJava1.dll[/FONT]
[FONT=Arial]2012-09-21 07:46:04 200032 ----a-w- C:\Windows\System32\drivers\avgtdia.sys[/FONT]
[FONT=Arial]2012-09-21 07:46:00 225120 ----a-w- C:\Windows\System32\drivers\avgloga.sys[/FONT]
[FONT=Arial]2012-09-14 19:19:29 2048 ----a-w- C:\Windows\System32\tzres.dll[/FONT]
[FONT=Arial]2012-09-14 18:28:53 2048 ----a-w- C:\Windows\SysWow64\tzres.dll[/FONT]
[FONT=Arial]2012-09-14 07:05:18 40800 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys[/FONT]
[FONT=Arial].[/FONT]
[FONT=Arial]============= FINISH: 14:42:15.38 ===============[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial][/FONT]
[FONT=Arial]ADWcleaner:[/FONT]
[FONT=Arial]# AdwCleaner v2.011 - Logfile created 12/07/2012 at 15:11:38[/FONT]
[FONT=Arial]# Updated 02/12/2012 by Xplode[/FONT]
[FONT=Arial]# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)[/FONT]
[FONT=Arial]# User : Andre - HAL9000[/FONT]
[FONT=Arial]# Boot Mode : Normal[/FONT]
[FONT=Arial]# Running from : C:\Users\Andre\Downloads\adwcleaner.exe[/FONT]
[FONT=Arial]# Option [Delete][/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]***** [Services] *****[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]***** [Files / Folders] *****[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml[/FONT]
[FONT=Arial]File Deleted : C:\Users\Andre\AppData\Local\funmoods-speeddial_sf.crx[/FONT]
[FONT=Arial]Folder Deleted : C:\ProgramData\boost_interprocess[/FONT]
[FONT=Arial]Folder Deleted : C:\ProgramData\Partner[/FONT]
[FONT=Arial]Folder Deleted : C:\ProgramData\WeCareReminder[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]***** [Registry] *****[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider[/FONT]
[FONT=Arial]Key Deleted : HKCU\Software\Cr_Installer[/FONT]
[FONT=Arial]Key Deleted : HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj[/FONT]
[FONT=Arial]Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}[/FONT]
[FONT=Arial]Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}[/FONT]
[FONT=Arial]Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj[/FONT]
[FONT=Arial]Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]***** [Internet Browsers] *****[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]-\\ Internet Explorer v9.0.8112.16455[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://searchfunmoods.com/?f=2&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyBzz0EyEtDtDtAtCyDyEyC0E0CyBtC0FtN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1127914451 --> hxxp://
www.google.com[/FONT]
[FONT=Arial]Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://searchfunmoods.com/?f=1&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyBzz0EyEtDtDtAtCyDyEyC0E0CyBtC0FtN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1127914451 --> hxxp://
www.google.com[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]-\\ Mozilla Firefox v10.0.11 (en-US)[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]Profile name : default[/FONT]
[FONT=Arial]File : C:\Users\Andre\AppData\Roaming\Mozilla\Firefox\Profiles\sb105d98.default\prefs.js[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]C:\Users\Andre\AppData\Roaming\Mozilla\Firefox\Profiles\sb105d98.default\user.js ... Deleted ![/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]Deleted : user_pref("browser.search.defaultenginename", "Funmoods");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.aflt", "download");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.autoRvrt", false);[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.cntry", "US");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.cv", "cv5");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.dfltLng", "");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.dfltSrch", true);[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.dnsErr", true);[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.envrmnt", "production");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.excTlbr", false);[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.hdrMd5", "0D78F66DEEAD92AAF4D6DC9050F65F4B");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.hmpg", true);[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.hmpgUrl", "hxxp://searchfunmoods.com/?f=1&a=download&chnl=download&cd[...][/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.id", "78E40031546EC71F");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.instlDay", "15669");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.instlRef", "download");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.isdcmntcmplt", true);[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2215:17:5");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.newTab", true);[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.newTabUrl", "hxxp://searchfunmoods.com/?f=2&a=download&chnl=download&[...][/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.prdct", "funmoods");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.prtnrId", "funmoods");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.sg", "none");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.smplGrp", "none");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.srchPrvdr", "Search");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.tlbrId", "base");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://searchfunmoods.com/?f=3&a=download&chnl=downloa[...][/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.vrsn", "1.5.23.22");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2215:17:5");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.vrsni", "1.5.23.22");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods.xpestat\\xpereportdata", "25-10-2012");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods_i.newTab", true);[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");[/FONT]
[FONT=Arial]Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2215:17:5");[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]-\\ Google Chrome v23.0.1271.95[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]File : C:\Users\Andre\AppData\Local\Google\Chrome\User Data\Default\Preferences[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]Deleted [l.12] : homepage = "hxxp://searchfunmoods.com/?f=1&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyBzz0E[...][/FONT]
[FONT=Arial]Deleted [l.16] : urls_to_restore_on_startup = [ "hxxp://searchfunmoods.com/?f=1&a=download&chnl=download&cd[...][/FONT]
[FONT=Arial]Deleted [l.1699] : homepage = "hxxp://searchfunmoods.com/?f=1&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyBzz0EyEt[...][/FONT]
[FONT=Arial]Deleted [l.2029] : urls_to_restore_on_startup = [ "hxxp://searchfunmoods.com/?f=1&a=download&chnl=download&cd=2X[...][/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]*************************[/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]AdwCleaner[S1].txt - [9537 octets] - [07/12/2012 15:11:38][/FONT]
[FONT=Arial] [/FONT]
[FONT=Arial]########## EOF - C:\AdwCleaner[S1].txt - [9597 octets] ##########[/FONT]