Advertisement
Guest User

Untitled

a guest
Feb 18th, 2013
279
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 121.08 KB | None | 0 0
  1. Malwarebytes Anti-Malware 1.70.0.1100
  2. www.malwarebytes.org
  3.  
  4. Database version: v2013.02.18.11
  5.  
  6. Windows Vista Service Pack 2 x86 NTFS
  7. Internet Explorer 8.0.6001.19400
  8. Oni :: ONI-PC [administrator]
  9.  
  10. 2/18/2013 5:50:42 PM
  11. mbam-log-2013-02-18 (17-50-42).txt
  12.  
  13. Scan type: Quick scan
  14. Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
  15. Scan options disabled: P2P
  16. Objects scanned: 208162
  17. Time elapsed: 10 minute(s), 34 second(s)
  18.  
  19. Memory Processes Detected: 0
  20. (No malicious items detected)
  21.  
  22. Memory Modules Detected: 0
  23. (No malicious items detected)
  24.  
  25. Registry Keys Detected: 0
  26. (No malicious items detected)
  27.  
  28. Registry Values Detected: 0
  29. (No malicious items detected)
  30.  
  31. Registry Data Items Detected: 0
  32. (No malicious items detected)
  33.  
  34. Folders Detected: 0
  35. (No malicious items detected)
  36.  
  37. Files Detected: 1
  38. C:\Users\Oni\AppData\Local\temp\doehuzxdz\doehuzxdz.dll (Trojan.Labedo) -> Quarantined and deleted successfully.
  39.  
  40. (end)
  41.  
  42.  
  43. MiniToolBox by Farbar Version:10-01-2013
  44. Ran by Oni (administrator) on 18-02-2013 at 18:18:03
  45. Running from "C:\Users\Oni\Desktop"
  46. Windows Vista (TM) Home Basic Service Pack 2 (X86)
  47. Boot Mode: Normal
  48. ***************************************************************************
  49.  
  50. ========================= Flush DNS: ===================================
  51.  
  52. Windows IP Configuration
  53.  
  54. Successfully flushed the DNS Resolver Cache.
  55.  
  56. ========================= IE Proxy Settings: ==============================
  57.  
  58. Proxy is not enabled.
  59. No Proxy Server is set.
  60.  
  61. "Reset IE Proxy Settings": IE Proxy Settings were reset.
  62.  
  63. ========================= FF Proxy Settings: ==============================
  64.  
  65.  
  66. "Reset FF Proxy Settings": Firefox Proxy settings were reset.
  67.  
  68. ========================= Hosts content: =================================
  69.  
  70. 127.0.0.1 localhost
  71.  
  72. ========================= IP Configuration: ================================
  73.  
  74. Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter = Wireless Network Connection (Connected)
  75. Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0) = Local Area Connection (Media disconnected)
  76.  
  77.  
  78. # ----------------------------------
  79. # IPv4 Configuration
  80. # ----------------------------------
  81. pushd interface ipv4
  82.  
  83. reset
  84. set global icmpredirects=enabled
  85. add address name="Local Area Connection* 19" address=10.21.16.66
  86.  
  87.  
  88. popd
  89. # End of IPv4 configuration
  90.  
  91.  
  92.  
  93. Windows IP Configuration
  94.  
  95. Host Name . . . . . . . . . . . . : Oni-PC
  96. Primary Dns Suffix . . . . . . . :
  97. Node Type . . . . . . . . . . . . : Hybrid
  98. IP Routing Enabled. . . . . . . . : No
  99. WINS Proxy Enabled. . . . . . . . : No
  100. DNS Suffix Search List. . . . . . : Belkin
  101.  
  102. Ethernet adapter Local Area Connection* 19:
  103.  
  104. Media State . . . . . . . . . . . : Media disconnected
  105. Connection-specific DNS Suffix . :
  106. Description . . . . . . . . . . . : Anchorfree HSS Adapter
  107. Physical Address. . . . . . . . . : 00-FF-E5-C9-79-09
  108. DHCP Enabled. . . . . . . . . . . : No
  109. Autoconfiguration Enabled . . . . : Yes
  110.  
  111. Ethernet adapter Local Area Connection:
  112.  
  113. Media State . . . . . . . . . . . : Media disconnected
  114. Connection-specific DNS Suffix . :
  115. Description . . . . . . . . . . . : Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0)
  116. Physical Address. . . . . . . . . : 00-1E-33-D3-59-41
  117. DHCP Enabled. . . . . . . . . . . : Yes
  118. Autoconfiguration Enabled . . . . : Yes
  119.  
  120. Wireless LAN adapter Wireless Network Connection:
  121.  
  122. Connection-specific DNS Suffix . : Belkin
  123. Description . . . . . . . . . . . : Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter
  124. Physical Address. . . . . . . . . : 00-22-5F-CD-B8-FD
  125. DHCP Enabled. . . . . . . . . . . : Yes
  126. Autoconfiguration Enabled . . . . : Yes
  127. IPv4 Address. . . . . . . . . . . : 192.168.2.5(Preferred)
  128. Subnet Mask . . . . . . . . . . . : 255.255.255.0
  129. Lease Obtained. . . . . . . . . . : Monday, February 18, 2013 6:05:49 PM
  130. Lease Expires . . . . . . . . . . : Friday, March 28, 2149 12:46:45 AM
  131. Default Gateway . . . . . . . . . : 192.168.2.1
  132. DHCP Server . . . . . . . . . . . : 192.168.2.1
  133. DNS Servers . . . . . . . . . . . : 192.168.2.1
  134. NetBIOS over Tcpip. . . . . . . . : Enabled
  135. Server:
  136. Address: 192.168.2.1
  137.  
  138. Name: google.com
  139. Addresses: 2607:f8b0:4002:801::100e
  140. 74.125.134.113
  141. 74.125.134.138
  142. 74.125.134.139
  143. 74.125.134.100
  144. 74.125.134.101
  145. 74.125.134.102
  146.  
  147.  
  148.  
  149. Pinging google.com [74.125.134.102] with 32 bytes of data:
  150.  
  151. Reply from 74.125.134.102: bytes=32 time=28ms TTL=44
  152.  
  153. Reply from 74.125.134.102: bytes=32 time=28ms TTL=44
  154.  
  155.  
  156.  
  157. Ping statistics for 74.125.134.102:
  158.  
  159. Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
  160.  
  161. Approximate round trip times in milli-seconds:
  162.  
  163. Minimum = 28ms, Maximum = 28ms, Average = 28ms
  164.  
  165. Server:
  166. Address: 192.168.2.1
  167.  
  168. Name: yahoo.com
  169. Addresses: 98.138.253.109
  170. 98.139.183.24
  171. 206.190.36.45
  172.  
  173.  
  174.  
  175. Pinging yahoo.com [98.138.253.109] with 32 bytes of data:
  176.  
  177. Reply from 98.138.253.109: bytes=32 time=805ms TTL=43
  178.  
  179. Reply from 98.138.253.109: bytes=32 time=746ms TTL=43
  180.  
  181.  
  182.  
  183. Ping statistics for 98.138.253.109:
  184.  
  185. Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
  186.  
  187. Approximate round trip times in milli-seconds:
  188.  
  189. Minimum = 746ms, Maximum = 805ms, Average = 775ms
  190.  
  191.  
  192.  
  193. Pinging 127.0.0.1 with 32 bytes of data:
  194.  
  195. Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
  196.  
  197. Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
  198.  
  199.  
  200.  
  201. Ping statistics for 127.0.0.1:
  202.  
  203. Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
  204.  
  205. Approximate round trip times in milli-seconds:
  206.  
  207. Minimum = 0ms, Maximum = 0ms, Average = 0ms
  208.  
  209. ===========================================================================
  210. Interface List
  211. 23 ...00 ff e5 c9 79 09 ...... Anchorfree HSS Adapter
  212. 17 ...00 1e 33 d3 59 41 ...... Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0)
  213. 10 ...00 22 5f cd b8 fd ...... Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter
  214. 1 ........................... Software Loopback Interface 1
  215. ===========================================================================
  216.  
  217. IPv4 Route Table
  218. ===========================================================================
  219. Active Routes:
  220. Network Destination Netmask Gateway Interface Metric
  221. 0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.5 25
  222. 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
  223. 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
  224. 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
  225. 192.168.2.0 255.255.255.0 On-link 192.168.2.5 281
  226. 192.168.2.5 255.255.255.255 On-link 192.168.2.5 281
  227. 192.168.2.255 255.255.255.255 On-link 192.168.2.5 281
  228. 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
  229. 224.0.0.0 240.0.0.0 On-link 192.168.2.5 281
  230. 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
  231. 255.255.255.255 255.255.255.255 On-link 192.168.2.5 281
  232. ===========================================================================
  233. Persistent Routes:
  234. None
  235.  
  236. IPv6 Route Table
  237. ===========================================================================
  238. Active Routes:
  239. If Metric Network Destination Gateway
  240. 1 306 ::1/128 On-link
  241. 1 306 ff00::/8 On-link
  242. ===========================================================================
  243. Persistent Routes:
  244. None
  245. ========================= Winsock entries =====================================
  246.  
  247. Catalog5 01 C:\Windows\system32\NLAapi.dll [48128] (Microsoft Corporation)
  248. Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Microsoft Corporation)
  249. Catalog5 03 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation)
  250. Catalog5 04 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation)
  251. Catalog5 05 C:\Windows\System32\mswsock.dll [223232] (Microsoft Corporation)
  252. Catalog5 06 C:\Windows\System32\winrnr.dll [19968] (Microsoft Corporation)
  253. Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
  254. Catalog9 01 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  255. Catalog9 02 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  256. Catalog9 03 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  257. Catalog9 04 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  258. Catalog9 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  259. Catalog9 06 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  260. Catalog9 07 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  261. Catalog9 08 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  262. Catalog9 09 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  263. Catalog9 10 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  264. Catalog9 11 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  265. Catalog9 12 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  266. Catalog9 13 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  267. Catalog9 14 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  268. Catalog9 15 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  269. Catalog9 16 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  270. Catalog9 17 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  271. Catalog9 18 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  272. Catalog9 19 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  273. Catalog9 20 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  274. Catalog9 21 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  275. Catalog9 22 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  276. Catalog9 23 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  277. Catalog9 24 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  278. Catalog9 25 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  279. Catalog9 26 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  280. Catalog9 27 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  281. Catalog9 28 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
  282.  
  283. ========================= Event log errors: ===============================
  284.  
  285. Application errors:
  286. ==================
  287. Error: (02/18/2013 06:06:19 PM) (Source: WinMgmt) (User: )
  288. Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
  289.  
  290. Error: (02/18/2013 11:56:55 AM) (Source: Bonjour Service) (User: )
  291. Description: Task Scheduling Error: m->NextScheduledSPRetry 4727
  292.  
  293. Error: (02/18/2013 11:56:55 AM) (Source: Bonjour Service) (User: )
  294. Description: Task Scheduling Error: m->NextScheduledEvent 4727
  295.  
  296. Error: (02/18/2013 11:56:55 AM) (Source: Bonjour Service) (User: )
  297. Description: Task Scheduling Error: Continuously busy for more than a second
  298.  
  299. Error: (02/18/2013 11:56:54 AM) (Source: Bonjour Service) (User: )
  300. Description: Task Scheduling Error: m->NextScheduledSPRetry 3541
  301.  
  302. Error: (02/18/2013 11:56:54 AM) (Source: Bonjour Service) (User: )
  303. Description: Task Scheduling Error: m->NextScheduledEvent 3541
  304.  
  305. Error: (02/18/2013 11:56:54 AM) (Source: Bonjour Service) (User: )
  306. Description: Task Scheduling Error: Continuously busy for more than a second
  307.  
  308. Error: (02/18/2013 11:56:53 AM) (Source: Bonjour Service) (User: )
  309. Description: Task Scheduling Error: m->NextScheduledSPRetry 2137
  310.  
  311. Error: (02/18/2013 11:56:53 AM) (Source: Bonjour Service) (User: )
  312. Description: Task Scheduling Error: m->NextScheduledEvent 2137
  313.  
  314. Error: (02/18/2013 11:56:53 AM) (Source: Bonjour Service) (User: )
  315. Description: Task Scheduling Error: Continuously busy for more than a second
  316.  
  317.  
  318. System errors:
  319. =============
  320. Error: (02/18/2013 05:14:55 PM) (Source: bowser) (User: )
  321. Description: The master browser has received a server announcement from the computer DANIEL-PC
  322. that believes that it is the master browser for the domain on transport NetBT_Tcpip_{9D493B71-F767-4098-8252-DAA7B357.
  323. The master browser is stopping or an election is being forced.
  324.  
  325. Error: (02/18/2013 05:14:55 PM) (Source: netbt) (User: )
  326. Description: A duplicate name has been detected on the TCP network. The IP address of
  327. the computer that sent the message is in the data. Use nbtstat -n in a
  328. command window to see which name is in the Conflict state.
  329.  
  330. Error: (02/18/2013 05:14:55 PM) (Source: netbt) (User: )
  331. Description: A duplicate name has been detected on the TCP network. The IP address of
  332. the computer that sent the message is in the data. Use nbtstat -n in a
  333. command window to see which name is in the Conflict state.
  334.  
  335. Error: (02/18/2013 05:14:55 PM) (Source: netbt) (User: )
  336. Description: A duplicate name has been detected on the TCP network. The IP address of
  337. the computer that sent the message is in the data. Use nbtstat -n in a
  338. command window to see which name is in the Conflict state.
  339.  
  340. Error: (02/18/2013 05:14:55 PM) (Source: netbt) (User: )
  341. Description: A duplicate name has been detected on the TCP network. The IP address of
  342. the computer that sent the message is in the data. Use nbtstat -n in a
  343. command window to see which name is in the Conflict state.
  344.  
  345. Error: (02/18/2013 05:14:49 PM) (Source: BROWSER) (User: )
  346. Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{9D493B71-F767-4098-8252-DAA7B357177C}.
  347. The backup browser is stopping.
  348.  
  349. Error: (02/18/2013 11:23:05 AM) (Source: BROWSER) (User: )
  350. Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{9D493B71-F767-4098-8252-DAA7B357177C}.
  351. The backup browser is stopping.
  352.  
  353. Error: (02/18/2013 08:18:56 AM) (Source: DCOM) (User: )
  354. Description: {6295DF2D-35EE-11D1-8707-00C04FD93327}
  355.  
  356. Error: (02/18/2013 01:00:01 AM) (Source: BROWSER) (User: )
  357. Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{9D493B71-F767-4098-8252-DAA7B357177C}.
  358. The backup browser is stopping.
  359.  
  360. Error: (02/17/2013 05:16:36 PM) (Source: bowser) (User: )
  361. Description: The master browser has received a server announcement from the computer DANIEL-PC
  362. that believes that it is the master browser for the domain on transport NetBT_Tcpip_{9D493B71-F767-4098-8252-DAA7B357.
  363. The master browser is stopping or an election is being forced.
  364.  
  365.  
  366. Microsoft Office Sessions:
  367. =========================
  368. Error: (02/18/2013 06:02:51 PM) (Source: Microsoft Office 12 Sessions)(User: )
  369. Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 83250 seconds with 1020 seconds of active time. This session ended with a crash.
  370.  
  371.  
  372. CodeIntegrity Errors:
  373. ===================================
  374. Date: 2013-02-18 17:57:44.946
  375. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSEH.sys because the set of per-page image hashes could not be found on the system.
  376.  
  377. Date: 2013-02-18 17:57:44.355
  378. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSEH.sys because the set of per-page image hashes could not be found on the system.
  379.  
  380. Date: 2013-02-18 17:57:43.731
  381. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSEH.sys because the set of per-page image hashes could not be found on the system.
  382.  
  383. Date: 2013-02-18 17:57:43.113
  384. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSEH.sys because the set of per-page image hashes could not be found on the system.
  385.  
  386. Date: 2013-02-18 17:57:42.531
  387. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSEH.sys because the set of per-page image hashes could not be found on the system.
  388.  
  389. Date: 2013-02-18 17:57:41.952
  390. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSEH.sys because the set of per-page image hashes could not be found on the system.
  391.  
  392. Date: 2013-02-18 17:57:41.309
  393. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSDriver.sys because the set of per-page image hashes could not be found on the system.
  394.  
  395. Date: 2013-02-18 17:57:40.721
  396. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSDriver.sys because the set of per-page image hashes could not be found on the system.
  397.  
  398. Date: 2013-02-18 17:57:40.120
  399. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSDriver.sys because the set of per-page image hashes could not be found on the system.
  400.  
  401. Date: 2013-02-18 17:57:39.524
  402. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AVGIDSDriver.sys because the set of per-page image hashes could not be found on the system.
  403.  
  404.  
  405. =========================== Installed Programs ============================
  406.  
  407. Acrobat.com (Version: 0.0.0)
  408. Acrobat.com (Version: 1.1.377)
  409. Adobe AIR (Version: 1.5.3.9130)
  410. Adobe Flash Player 11 ActiveX (Version: 11.5.502.149)
  411. Adobe Flash Player 11 Plugin (Version: 11.5.502.149)
  412. Adobe Reader X (10.1.5) (Version: 10.1.5)
  413. Amazon Links (Version: 1.0)
  414. Apple Application Support (Version: 2.2.2)
  415. Apple Mobile Device Support (Version: 6.0.0.59)
  416. Apple Software Update (Version: 2.1.3.127)
  417. ASIO4ALL
  418. ASPCA Reminder V7F+AU by We-Care.com (Version: 4.0.5.5)
  419. AVG 2011 (Version: 10.0.1430)
  420. AVG 2011 (Version: 10.0.2639)
  421. AVG PC Tuneup 2011 10.0.0.24 (Version: 10.0.0.24)
  422. Bonjour (Version: 3.0.0.10)
  423. CD/DVD Drive Acoustic Silencer (Version: 2.02.03)
  424. Compatibility Pack for the 2007 Office system (Version: 12.0.4518.1014)
  425. Dell V505
  426. Dropbox (Version: 1.6.16)
  427. DVD Flick 1.3.0.6 (Version: 1.3.0.6)
  428. DVD MovieFactory for TOSHIBA (Version: 5.51)
  429. ESET Online Scanner v3
  430. Google Chrome (Version: 24.0.1312.57)
  431. Google Talk Plugin (Version: 3.13.2.11592)
  432. Google Update Helper (Version: 1.3.21.135)
  433. HiJackThis (Version: 1.0.0)
  434. HitmanPro 3.6 (Version: 3.6.0.160)
  435. Hotspot Shield 2.53 (Version: 2.53)
  436. ImgBurn (Version: 2.4.2.0)
  437. Intel(R) Graphics Media Accelerator Driver
  438. Intel® Matrix Storage Manager
  439. iTunes (Version: 10.7.0.21)
  440. Java Auto Updater (Version: 2.0.5.1)
  441. Java(TM) 6 Update 26 (Version: 6.0.260)
  442. League of Legends (Version: 1.3)
  443. LiveUpdate 2.6 (Symantec Corporation) (Version: 2.6.18.0)
  444. Malwarebytes Anti-Malware version 1.70.0.1100 (Version: 1.70.0.1100)
  445. Microsoft .NET Framework 3.5 SP1
  446. Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
  447. Microsoft Office Access MUI (English) 2007 (Version: 12.0.4518.1014)
  448. Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014)
  449. Microsoft Office Enterprise 2007 (Version: 12.0.4518.1014)
  450. Microsoft Office Excel MUI (English) 2007 (Version: 12.0.4518.1014)
  451. Microsoft Office Groove MUI (English) 2007 (Version: 12.0.4518.1014)
  452. Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014)
  453. Microsoft Office Home and Student 2007 (Version: 12.0.4518.1014)
  454. Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.4518.1014)
  455. Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.4518.1014)
  456. Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.4518.1014)
  457. Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.4518.1014)
  458. Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.4518.1014)
  459. Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014)
  460. Microsoft Office Proof (French) 2007 (Version: 12.0.4518.1014)
  461. Microsoft Office Proof (Spanish) 2007 (Version: 12.0.4518.1014)
  462. Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
  463. Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.4518.1014)
  464. Microsoft Office Shared MUI (English) 2007 (Version: 12.0.4518.1014)
  465. Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014)
  466. Microsoft Office Suite Activation Assistant (Version: 2.9)
  467. Microsoft Office Word MUI (English) 2007 (Version: 12.0.4518.1014)
  468. Microsoft Silverlight (Version: 4.0.50917.0)
  469. Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
  470. Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
  471. Microsoft Works (Version: 9.7.0621)
  472. Microsoft XML Parser (Version: 8.20.8730.4)
  473. Move Media Player
  474. Mozilla Firefox (3.6.6) (Version: 3.6.6 (en-US))
  475. MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0)
  476. MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
  477. MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
  478. Pando Media Booster (Version: 2.6.0.8)
  479. Picasa 3 (Version: 3.1)
  480. PowerISO (Version: 4.8)
  481. QuickBooks Financial Center (Version: 1.10.0000)
  482. QuickTime (Version: 7.72.80.56)
  483. Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
  484. Realtek High Definition Audio Driver (Version: 6.0.1.5599)
  485. REALTEK RTL8187B Wireless LAN Driver (Version: Package:1.00.0026 Driver:6.1116.1226.2007)
  486. Realtek USB 2.0 Card Reader (Version: 6.0.6000.20130)
  487. Realtek WiFi Protected Setup Library (Version: 1.00.0026)
  488. SafeConnect
  489. Skype Click to Call (Version: 5.6.8442)
  490. Skype™ 6.1 (Version: 6.1.129)
  491. Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
  492. Spotify (Version: 0.8.5.1333.g822e0de8)
  493. Synaptics Pointing Device Driver (Version: 10.1.8.0)
  494. TOSHIBA Assist (Version: 2.01.08)
  495. TOSHIBA ConfigFree (Version: 7.2.20)
  496. TOSHIBA Desktop Links (Version: 1.7)
  497. TOSHIBA Disc Creator (Version: 2.0.1.3)
  498. TOSHIBA DVD PLAYER (Version: 1.31.14)
  499. TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00)
  500. TOSHIBA Hardware Setup (Version: 2.00.08)
  501. TOSHIBA Recovery Disc Creator (Version: 2.0.0.2)
  502. Toshiba Registration (Version: 1.00.0000)
  503. TOSHIBA Service Station (Version: 1.1.14)
  504. TOSHIBA Speech System Applications
  505. TOSHIBA Speech System SR Engine(U.S.) Version1.0
  506. TOSHIBA Speech System TTS Engine(U.S.) Version1.0
  507. TOSHIBA Supervisor Password (Version: 2.00.04)
  508. TOSHIBA Value Added Package (Version: 1.1.24)
  509. Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
  510. Update for Office 2007 (KB934528)
  511. Update for Office System 2007 Setup (KB929722)
  512. VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
  513. VLC media player 2.0.1 (Version: 2.0.1)
  514. WildTangent Games (Version: 1.0.0.62)
  515. Windows Media Encoder 9 Series
  516. Windows Media Encoder 9 Series (Version: 9.00.3374)
  517. Windows Media Player Firefox Plugin (Version: 1.0.0.8)
  518. Yahoo! Software Update
  519.  
  520. ========================= Devices: ================================
  521.  
  522. Name: isatap.{0913D5A8-EAAD-4D04-821E-DF2C6404AAB0}
  523. Description: Microsoft ISATAP Adapter
  524. Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
  525. Manufacturer: Microsoft
  526. Service: tunnel
  527. Problem: : This device cannot start. (Code10)
  528. Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
  529. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
  530.  
  531. Name: Microsoft ISATAP Adapter #2
  532. Description: Microsoft ISATAP Adapter
  533. Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
  534. Manufacturer: Microsoft
  535. Service: tunnel
  536. Problem: : This device cannot start. (Code10)
  537. Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
  538. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
  539.  
  540. Name: Microsoft ISATAP Adapter #2
  541. Description: Microsoft ISATAP Adapter
  542. Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
  543. Manufacturer: Microsoft
  544. Service: tunnel
  545. Problem: : This device cannot start. (Code10)
  546. Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
  547. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
  548.  
  549. Name: isatap.launchmodem.com
  550. Description: Microsoft ISATAP Adapter
  551. Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
  552. Manufacturer: Microsoft
  553. Service: tunnel
  554. Problem: : This device cannot start. (Code10)
  555. Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
  556. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
  557.  
  558. Name: isatap.PBA.EDU
  559. Description: Microsoft ISATAP Adapter
  560. Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
  561. Manufacturer: Microsoft
  562. Service: tunnel
  563. Problem: : This device cannot start. (Code10)
  564. Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
  565. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
  566.  
  567.  
  568. ========================= Memory info: ===================================
  569.  
  570. Percentage of memory in use: 38%
  571. Total physical RAM: 2939.26 MB
  572. Available physical RAM: 1793.59 MB
  573. Total Pagefile: 5947.54 MB
  574. Available Pagefile: 4422.85 MB
  575. Total Virtual: 2047.88 MB
  576. Available Virtual: 1950.32 MB
  577.  
  578. ========================= Partitions: =====================================
  579.  
  580. 1 Drive c: (SQ004981V02) (Fixed) (Total:224.2 GB) (Free:85.38 GB) NTFS
  581.  
  582. ========================= Users: ========================================
  583.  
  584. User accounts for \\ONI-PC
  585.  
  586. Administrator Guest Oni
  587.  
  588.  
  589. **** End of log ****
  590.  
  591.  
  592. Farbar Service Scanner Version: 18-02-2013
  593. Ran by Oni (administrator) on 18-02-2013 at 18:21:25
  594. Running from "C:\Users\Oni\Desktop"
  595. Windows Vista (TM) Home Basic Service Pack 2 (X86)
  596. Boot Mode: Normal
  597. ****************************************************************
  598.  
  599. Internet Services:
  600. ============
  601.  
  602. Connection Status:
  603. ==============
  604. Localhost is accessible.
  605. LAN connected.
  606. Attempt to access Google IP returned error. Google IP is offline
  607. Google.com is accessible.
  608. Yahoo IP is accessible.
  609. Yahoo.com is accessible.
  610.  
  611.  
  612. Windows Firewall:
  613. =============
  614.  
  615. Firewall Disabled Policy:
  616. ==================
  617.  
  618.  
  619. System Restore:
  620. ============
  621.  
  622. System Restore Disabled Policy:
  623. ========================
  624.  
  625.  
  626. Security Center:
  627. ============
  628.  
  629. Windows Update:
  630. ============
  631.  
  632. Windows Autoupdate Disabled Policy:
  633. ============================
  634.  
  635.  
  636. Windows Defender:
  637. ==============
  638. WinDefend Service is not running. Checking service configuration:
  639. The start type of WinDefend service is OK.
  640. The ImagePath of WinDefend service is OK.
  641. The ServiceDll of WinDefend service is OK.
  642.  
  643.  
  644. Windows Defender Disabled Policy:
  645. ==========================
  646. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
  647. "DisableAntiSpyware"=DWORD:1
  648.  
  649.  
  650. Other Services:
  651. ==============
  652.  
  653.  
  654. File Check:
  655. ========
  656. C:\Windows\system32\nsisvc.dll => MD5 is legit
  657. C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
  658. C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
  659. C:\Windows\system32\Drivers\afd.sys => MD5 is legit
  660. C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
  661. C:\Windows\system32\Drivers\tcpip.sys
  662. [2013-02-13 12:04] - [2013-01-04 06:28] - 0905576 ____A (Microsoft Corporation) 74E2D020C47BB2B2FCCBA29A518A7EB4
  663.  
  664. C:\Windows\system32\dnsrslvr.dll => MD5 is legit
  665. C:\Windows\system32\mpssvc.dll => MD5 is legit
  666. C:\Windows\system32\bfe.dll => MD5 is legit
  667. C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
  668. C:\Windows\system32\SDRSVC.dll => MD5 is legit
  669. C:\Windows\system32\vssvc.exe => MD5 is legit
  670. C:\Windows\system32\wscsvc.dll => MD5 is legit
  671. C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
  672. C:\Windows\system32\wuaueng.dll => MD5 is legit
  673. C:\Windows\system32\qmgr.dll => MD5 is legit
  674. C:\Windows\system32\es.dll => MD5 is legit
  675. C:\Windows\system32\cryptsvc.dll => MD5 is legit
  676. C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
  677. C:\Windows\system32\ipnathlp.dll => MD5 is legit
  678. C:\Windows\system32\iphlpsvc.dll => MD5 is legit
  679. C:\Windows\system32\svchost.exe => MD5 is legit
  680. C:\Windows\system32\rpcss.dll => MD5 is legit
  681.  
  682.  
  683. **** End of log ****
  684.  
  685.  
  686. # AdwCleaner v2.112 - Logfile created 02/18/2013 at 18:22:59
  687. # Updated 10/02/2013 by Xplode
  688. # Operating system : Windows Vista (TM) Home Basic Service Pack 2 (32 bits)
  689. # User : Oni - ONI-PC
  690. # Boot Mode : Normal
  691. # Running from : C:\Users\Oni\Desktop\AdwCleaner.exe
  692. # Option [Search]
  693.  
  694.  
  695. ***** [Services] *****
  696.  
  697.  
  698. ***** [Files / Folders] *****
  699.  
  700. File Found : C:\Program Files\Mozilla Firefox\.autoreg
  701. File Found : C:\Users\Oni\AppData\Roaming\Mozilla\Firefox\Profiles\z4yq8eld.default\searchplugins\Conduit.xml
  702. Folder Found : C:\Program Files\Conduit
  703. Folder Found : C:\Program Files\Free Offers from Freeze.com
  704. Folder Found : C:\Program Files\Mozilla Firefox\Extensions\afurladvisor@anchorfree.com
  705. Folder Found : C:\ProgramData\InstallMate
  706. Folder Found : C:\ProgramData\Premium
  707. Folder Found : C:\ProgramData\WeCareReminder
  708. Folder Found : C:\Users\Oni\AppData\Local\Conduit
  709. Folder Found : C:\Users\Oni\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
  710. Folder Found : C:\Users\Oni\AppData\LocalLow\Conduit
  711. Folder Found : C:\Users\Oni\AppData\Roaming\Mozilla\Firefox\Profiles\z4yq8eld.default\Conduit
  712. Folder Found : C:\Users\Oni\AppData\Roaming\Mozilla\Firefox\Profiles\z4yq8eld.default\ConduitEngine
  713. Folder Found : C:\Users\Oni\AppData\Roaming\Mozilla\Firefox\Profiles\z4yq8eld.default\CT2765711
  714. Folder Found : C:\Users\Oni\AppData\Roaming\Mozilla\Firefox\Profiles\z4yq8eld.default\extensions\{f0381dbd-e018-4e07-ae40-d96ab15083f0}
  715. Folder Found : C:\Users\Oni\AppData\Roaming\Mozilla\Firefox\Profiles\z4yq8eld.default\extensions\wecarereminder@bryan
  716.  
  717. ***** [Registry] *****
  718.  
  719. Key Found : HKCU\Software\AppDataLow\Software\Conduit
  720. Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
  721. Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
  722. Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C99FDC39-A1AE-4B24-8D71-E5274F8D7C54}
  723. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
  724. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
  725. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
  726. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
  727. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
  728. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
  729. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
  730. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
  731. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
  732. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
  733. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
  734. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
  735. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
  736. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
  737. Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
  738. Key Found : HKCU\Software\wecarereminder
  739. Key Found : HKLM\Software\AVG Secure Search
  740. Key Found : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}
  741. Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
  742. Key Found : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL
  743. Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
  744. Key Found : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
  745. Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
  746. Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
  747. Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
  748. Key Found : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
  749. Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
  750. Key Found : HKLM\SOFTWARE\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3}
  751. Key Found : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
  752. Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
  753. Key Found : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder
  754. Key Found : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1
  755. Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
  756. Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
  757. Key Found : HKLM\SOFTWARE\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3}
  758. Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE}
  759. Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api
  760. Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
  761. Key Found : HKLM\Software\Conduit
  762. Key Found : HKLM\Software\Freeze.com
  763. Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
  764. Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
  765. Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}
  766. Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
  767. Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
  768. Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
  769. Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
  770. Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
  771. Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
  772. Key Found : HKLM\SOFTWARE\Software
  773. Key Found : HKU\S-1-5-21-1508737220-1151108484-2550500073-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
  774. Key Found : HKU\S-1-5-21-1508737220-1151108484-2550500073-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C99FDC39-A1AE-4B24-8D71-E5274F8D7C54}
  775. Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
  776.  
  777. ***** [Internet Browsers] *****
  778.  
  779. -\\ Internet Explorer v8.0.6001.19400
  780.  
  781. [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.hotspotshield.com/g/?c=h
  782.  
  783. -\\ Mozilla Firefox v3.6.6 (en-US)
  784.  
  785. File : C:\Users\Oni\AppData\Roaming\Mozilla\Firefox\Profiles\z4yq8eld.default\prefs.js
  786.  
  787. Found : user_pref("CT2765711..clientLogIsEnabled", false);
  788. Found : user_pref("CT2765711..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
  789. Found : user_pref("CT2765711..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
  790. Found : user_pref("CT2765711.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
  791. Found : user_pref("CT2765711.CTID", "CT2765711");
  792. Found : user_pref("CT2765711.Chat.Meebo.ServerLastCheckTime", "Sun Sep 25 2011 06:08:46 GMT-0400 (Eastern Da[...]
  793. Found : user_pref("CT2765711.Chat.Meebo.ServerLastResponseTime", "Sun Sep 25 2011 06:08:46 GMT-0400 (Eastern[...]
  794. Found : user_pref("CT2765711.Chat.Meebo.rooms.2030dff2c5edb1", 0);
  795. Found : user_pref("CT2765711.Chat.Meebo.rooms.30plusa87dca4f", 0);
  796. Found : user_pref("CT2765711.Chat.Meebo.rooms.communitychat7d6a306c", 0);
  797. Found : user_pref("CT2765711.Chat.Meebo.rooms.entertainmentc0ed09fb", 0);
  798. Found : user_pref("CT2765711.Chat.Meebo.rooms.health3693b665", 0);
  799. Found : user_pref("CT2765711.Chat.Meebo.rooms.musicj375cf270", 2);
  800. Found : user_pref("CT2765711.Chat.Meebo.rooms.newsxu117b840d", 3);
  801. Found : user_pref("CT2765711.Chat.Meebo.rooms.recreationab17d1f9", 0);
  802. Found : user_pref("CT2765711.Chat.Meebo.rooms.spirituality39155c53", 0);
  803. Found : user_pref("CT2765711.Chat.Meebo.rooms.sports522528d3", 4);
  804. Found : user_pref("CT2765711.Chat.Meebo.rooms.technology8bb9fd5b", 1);
  805. Found : user_pref("CT2765711.Chat.Meebo.rooms.teenagers833b8249", 0);
  806. Found : user_pref("CT2765711.Chat.Meebo.rooms.travel8c2e48db", 0);
  807. Found : user_pref("CT2765711.Chat.Meebo.rooms.videogames2fe066e0", 0);
  808. Found : user_pref("CT2765711.Chat.ServerLastCheckTime", "Sun Sep 25 2011 01:55:06 GMT-0400 (Eastern Daylight[...]
  809. Found : user_pref("CT2765711.CurrentServerDate", "2-9-2012");
  810. Found : user_pref("CT2765711.DialogsAlignMode", "LTR");
  811. Found : user_pref("CT2765711.DownloadReferralCookieData", "");
  812. Found : user_pref("CT2765711.FirstServerDate", "28-3-2011");
  813. Found : user_pref("CT2765711.FirstTime", true);
  814. Found : user_pref("CT2765711.FirstTimeFF3", true);
  815. Found : user_pref("CT2765711.FixPageNotFoundErrors", false);
  816. Found : user_pref("CT2765711.GroupingServerCheckInterval", 1440);
  817. Found : user_pref("CT2765711.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
  818. Found : user_pref("CT2765711.HasUserGlobalKeys", true);
  819. Found : user_pref("CT2765711.Initialize", true);
  820. Found : user_pref("CT2765711.InitializeCommonPrefs", true);
  821. Found : user_pref("CT2765711.InstallationAndCookieDataSentCount", 3);
  822. Found : user_pref("CT2765711.InstalledDate", "Sun Mar 27 2011 23:43:51 GMT-0400 (Eastern Daylight Time)");
  823. Found : user_pref("CT2765711.InvalidateCache", false);
  824. Found : user_pref("CT2765711.IsGrouping", false);
  825. Found : user_pref("CT2765711.IsMulticommunity", false);
  826. Found : user_pref("CT2765711.IsOpenThankYouPage", true);
  827. Found : user_pref("CT2765711.IsOpenUninstallPage", true);
  828. Found : user_pref("CT2765711.LanguagePackLastCheckTime", "Sun Sep 02 2012 16:45:04 GMT-0400 (Eastern Dayligh[...]
  829. Found : user_pref("CT2765711.LanguagePackReloadIntervalMM", 1440);
  830. Found : user_pref("CT2765711.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
  831. Found : user_pref("CT2765711.LastLogin_3.2.1.3", "Sun Sep 02 2012 16:45:04 GMT-0400 (Eastern Daylight Time)"[...]
  832. Found : user_pref("CT2765711.LatestVersion", "3.14.1.0");
  833. Found : user_pref("CT2765711.Locale", "en-us");
  834. Found : user_pref("CT2765711.MCDetectTooltipHeight", "83");
  835. Found : user_pref("CT2765711.MCDetectTooltipShow", false);
  836. Found : user_pref("CT2765711.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
  837. Found : user_pref("CT2765711.MCDetectTooltipWidth", "295");
  838. Found : user_pref("CT2765711.RadioIsPodcast", false);
  839. Found : user_pref("CT2765711.RadioLastCheckTime", "Tue Jan 31 2012 09:04:41 GMT-0500 (Eastern Standard Time)[...]
  840. Found : user_pref("CT2765711.RadioLastUpdateIPServer", "3");
  841. Found : user_pref("CT2765711.RadioLastUpdateServer", "3");
  842. Found : user_pref("CT2765711.RadioMediaID", "9962");
  843. Found : user_pref("CT2765711.RadioMediaType", "Media Player");
  844. Found : user_pref("CT2765711.RadioMenuSelectedID", "EBRadioMenu_CT27657119962");
  845. Found : user_pref("CT2765711.RadioStationName", "California%20Rock");
  846. Found : user_pref("CT2765711.RadioStationURL", "hxxp://feedlive.net/california.asx");
  847. Found : user_pref("CT2765711.SHRINK_TOOLBAR", 1);
  848. Found : user_pref("CT2765711.SearchBoxWidth", 138);
  849. Found : user_pref("CT2765711.SearchFromAddressBarIsInit", true);
  850. Found : user_pref("CT2765711.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT276[...]
  851. Found : user_pref("CT2765711.SearchInNewTabEnabled", true);
  852. Found : user_pref("CT2765711.SearchInNewTabIntervalMM", 1440);
  853. Found : user_pref("CT2765711.SearchInNewTabLastCheckTime", "Sun Sep 02 2012 16:45:01 GMT-0400 (Eastern Dayli[...]
  854. Found : user_pref("CT2765711.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
  855. Found : user_pref("CT2765711.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
  856. Found : user_pref("CT2765711.ServiceMapLastCheckTime", "Sun Sep 02 2012 16:45:01 GMT-0400 (Eastern Daylight [...]
  857. Found : user_pref("CT2765711.SettingsLastCheckTime", "Sun Sep 02 2012 16:45:00 GMT-0400 (Eastern Daylight Ti[...]
  858. Found : user_pref("CT2765711.SettingsLastUpdate", "1346236827");
  859. Found : user_pref("CT2765711.ThirdPartyComponentsInterval", 504);
  860. Found : user_pref("CT2765711.ThirdPartyComponentsLastCheck", "Sun Sep 02 2012 16:45:00 GMT-0400 (Eastern Day[...]
  861. Found : user_pref("CT2765711.ThirdPartyComponentsLastUpdate", "1331805997");
  862. Found : user_pref("CT2765711.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
  863. Found : user_pref("CT2765711.Uninstall", false);
  864. Found : user_pref("CT2765711.UserID", "UN24486662282570515");
  865. Found : user_pref("CT2765711.ValidationData_Search", 2);
  866. Found : user_pref("CT2765711.ValidationData_Toolbar", 2);
  867. Found : user_pref("CT2765711.alertChannelId", "1157832");
  868. Found : user_pref("CT2765711.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
  869. Found : user_pref("CT2765711.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
  870. Found : user_pref("CT2765711.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
  871. Found : user_pref("CT2765711.backendstorage./9b+7e.:2z527", "247E6F727174354379453A3D2A722C757A787D312833232[...]
  872. Found : user_pref("CT2765711.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
  873. Found : user_pref("CT2765711.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
  874. Found : user_pref("CT2765711.backendstorage./9b+7e06cg5el8:", "6E6D6F6F737273707572");
  875. Found : user_pref("CT2765711.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737575797879767B78242F4B4947[...]
  876. Found : user_pref("CT2765711.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
  877. Found : user_pref("CT2765711.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
  878. Found : user_pref("CT2765711.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
  879. Found : user_pref("CT2765711.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
  880. Found : user_pref("CT2765711.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
  881. Found : user_pref("CT2765711.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
  882. Found : user_pref("CT2765711.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
  883. Found : user_pref("CT2765711.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
  884. Found : user_pref("CT2765711.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
  885. Found : user_pref("CT2765711.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
  886. Found : user_pref("CT2765711.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
  887. Found : user_pref("CT2765711.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
  888. Found : user_pref("CT2765711.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
  889. Found : user_pref("CT2765711.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
  890. Found : user_pref("CT2765711.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
  891. Found : user_pref("CT2765711.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
  892. Found : user_pref("CT2765711.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
  893. Found : user_pref("CT2765711.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
  894. Found : user_pref("CT2765711.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
  895. Found : user_pref("CT2765711.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
  896. Found : user_pref("CT2765711.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
  897. Found : user_pref("CT2765711.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
  898. Found : user_pref("CT2765711.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
  899. Found : user_pref("CT2765711.backendstorage./9b-0?3g>d", "6A6A6B3F6C3F75437A747075472049784D7A25797D4F522A25[...]
  900. Found : user_pref("CT2765711.backendstorage./9b-0?3g@6:5;", "");
  901. Found : user_pref("CT2765711.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
  902. Found : user_pref("CT2765711.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...]
  903. Found : user_pref("CT2765711.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
  904. Found : user_pref("CT2765711.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484775213F3E484F4E4D464[...]
  905. Found : user_pref("CT2765711.backendstorage./9b5ba==9cjag", "3E6A3F6E3D3F43417A7844447B734878784D4F5120");
  906. Found : user_pref("CT2765711.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F6F737273707673777972");
  907. Found : user_pref("CT2765711.backendstorage./9b9643g3/9e", "6A");
  908. Found : user_pref("CT2765711.backendstorage./9b<:222h64<", "393F352F3E");
  909. Found : user_pref("CT2765711.backendstorage./9b=+03eh8h8j?:", "4443");
  910. Found : user_pref("CT2765711.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
  911. Found : user_pref("CT2765711.backendstorage./9b?b0d:8aj62<h", "6D");
  912. Found : user_pref("CT2765711.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
  913. Found : user_pref("CT2765711.backendstorage.cb_experience_000", "31");
  914. Found : user_pref("CT2765711.backendstorage.cb_firstuse0100", "31");
  915. Found : user_pref("CT2765711.backendstorage.cb_user_id_000", "43423537383839363039313833395F46697265666F78")[...]
  916. Found : user_pref("CT2765711.backendstorage.cbcountry_000", "5553");
  917. Found : user_pref("CT2765711.backendstorage.cbcountry_001", "5553");
  918. Found : user_pref("CT2765711.backendstorage.cbfirsttime", "5765642044656320323820323031312031333A31393A31332[...]
  919. Found : user_pref("CT2765711.backendstorage.gk_hsselite_notif_sent", "73656E74");
  920. Found : user_pref("CT2765711.backendstorage.gk_iolo_notif2_sent", "73656E74");
  921. Found : user_pref("CT2765711.backendstorage.gk_webroot_notif_sent", "73656E74");
  922. Found : user_pref("CT2765711.backendstorage.hss_gk_notif_sent", "73656E74");
  923. Found : user_pref("CT2765711.backendstorage.installationdate0.2180191645578123", "31333235303936333531343937[...]
  924. Found : user_pref("CT2765711.backendstorage.installationdate0.2646799591156723", "31333339363632383332303736[...]
  925. Found : user_pref("CT2765711.backendstorage.installationdate0.2690270998198123", "31333335303634393637393336[...]
  926. Found : user_pref("CT2765711.backendstorage.installationdate0.2690291778262231", "31333136383330333135363439[...]
  927. Found : user_pref("CT2765711.backendstorage.printitgreenstatus", "74727565");
  928. Found : user_pref("CT2765711.backendstorage.shoppingapp.gk.exipres", "4672692053657020303720323031322031363A[...]
  929. Found : user_pref("CT2765711.backendstorage.shoppingapp.gk.geolocation", "756E6974656420737461746573");
  930. Found : user_pref("CT2765711.backendstorage.toolbarappheartbeat", "7B223132393736363335343839303631323838342[...]
  931. Found : user_pref("CT2765711.backendstorage.toolbarnotificationheartbeat", "7B2274797065223A2268656172746265[...]
  932. Found : user_pref("CT2765711.backendstorage.toolbarnotificationqueue", "5B7B22617070223A302E3236343637393935[...]
  933. Found : user_pref("CT2765711.backendstorage.toolbarnotificationsettings", "7B2273656E644E6F74696669636174696[...]
  934. Found : user_pref("CT2765711.backendstorage.toolbarnotificationuserid", "3136313035353533363632");
  935. Found : user_pref("CT2765711.backendstorage.url_history", "687474703A2F2F7777772E676E632E636F6D2F70726F64756[...]
  936. Found : user_pref("CT2765711.backendstorage.url_history0001", "68747470733A2F2F7777772E676F6F676C652E636F6D3[...]
  937. Found : user_pref("CT2765711.backendstorage.url_history_time", "31333236303537343033373633");
  938. Found : user_pref("CT2765711.backendstorage.welcome_dialog_displayed", "646973706C61796564");
  939. Found : user_pref("CT2765711.components.1000034", false);
  940. Found : user_pref("CT2765711.components.1000082", false);
  941. Found : user_pref("CT2765711.components.1000234", false);
  942. Found : user_pref("CT2765711.myStuffEnabled", true);
  943. Found : user_pref("CT2765711.myStuffPublihserMinWidth", 400);
  944. Found : user_pref("CT2765711.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
  945. Found : user_pref("CT2765711.myStuffServiceIntervalMM", 1440);
  946. Found : user_pref("CT2765711.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
  947. Found : user_pref("CT2765711.testingCtid", "");
  948. Found : user_pref("CT2765711.toolbarAppMetaDataLastCheckTime", "Sun Sep 02 2012 16:45:03 GMT-0400 (Eastern D[...]
  949. Found : user_pref("CT2765711.toolbarContextMenuLastCheckTime", "Sun Mar 27 2011 23:43:51 GMT-0400 (Eastern D[...]
  950. Found : user_pref("CT2765711.usagesFlag", 2);
  951. Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2765711/CT2765711[...]
  952. Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1157832/1153519/US", "\"0\"[...]
  953. Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/US", "\"0\"")[...]
  954. Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2765711", [...]
  955. Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
  956. Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
  957. Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
  958. Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
  959. Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"c912886ea3ba02[...]
  960. Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
  961. Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
  962. Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2765711&octid=[...]
  963. Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2765711/CT2765711[...]
  964. Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...]
  965. Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...]
  966. Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...]
  967. Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...]
  968. Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...]
  969. Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
  970. Found : user_pref("CommunityToolbar.EngineOwner", "CT2765711");
  971. Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{f0381dbd-e018-4e07-ae40-d96ab15083f0}");
  972. Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "af-hss");
  973. Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
  974. Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
  975. Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2765711");
  976. Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{f0381dbd-e018-4e07-ae40-d96ab15083f0}");
  977. Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "af-hss");
  978. Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
  979. Found : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine,CT2765711");
  980. Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2765711");
  981. Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
  982. Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Sep 02 2012 16:44:59 GMT-0400 (Easte[...]
  983. Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
  984. Found : user_pref("CommunityToolbar.alert.locale", "en");
  985. Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
  986. Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun Sep 02 2012 16:44:59 GMT-0400 (Eastern D[...]
  987. Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
  988. Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
  989. Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
  990. Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
  991. Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
  992. Found : user_pref("CommunityToolbar.alert.userId", "a5ce8d29-6915-4a24-af2f-a1934459ab2c");
  993. Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2765711");
  994. Found : user_pref("ConduitEngine.FirstServerDate", "03/28/2011 06");
  995. Found : user_pref("ConduitEngine.FirstTime", true);
  996. Found : user_pref("ConduitEngine.FirstTimeFF3", true);
  997. Found : user_pref("ConduitEngine.HasUserGlobalKeys", true);
  998. Found : user_pref("ConduitEngine.Initialize", true);
  999. Found : user_pref("ConduitEngine.InitializeCommonPrefs", true);
  1000. Found : user_pref("ConduitEngine.InstalledDate", "Sun Mar 27 2011 23:43:49 GMT-0400 (Eastern Daylight Time)"[...]
  1001. Found : user_pref("ConduitEngine.IsMulticommunity", false);
  1002. Found : user_pref("ConduitEngine.IsOpenThankYouPage", false);
  1003. Found : user_pref("ConduitEngine.IsOpenUninstallPage", true);
  1004. Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Jun 27 2011 21:35:53 GMT-0400 (Eastern Day[...]
  1005. Found : user_pref("ConduitEngine.LastLogin_3.2.1.3", "Mon Jun 27 2011 21:35:53 GMT-0400 (Eastern Daylight Ti[...]
  1006. Found : user_pref("ConduitEngine.PublisherContainerWidth", 0);
  1007. Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
  1008. Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Jun 27 2011 21:35:48 GMT-0400 (Eastern Dayligh[...]
  1009. Found : user_pref("ConduitEngine.UserID", "UN87942782515198346");
  1010. Found : user_pref("ConduitEngine.engineLocale", "en-US");
  1011. Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Jun 27 2011 21:35:53 GMT-0400 (Easte[...]
  1012. Found : user_pref("ConduitEngine.initDone", true);
  1013. Found : user_pref("browser.search.defaultthis.engineName", "AF-HSS Customized Web Search");
  1014. Found : user_pref("browser.startup.homepage", "hxxp://search.hotspotshield.com/g/?c=h");
  1015.  
  1016. -\\ Google Chrome v24.0.1312.57
  1017.  
  1018. File : C:\Users\Oni\AppData\Local\Google\Chrome\User Data\Default\Preferences
  1019.  
  1020. [OK] File is clean.
  1021.  
  1022. *************************
  1023.  
  1024. AdwCleaner[R1].txt - [27585 octets] - [18/02/2013 18:22:59]
  1025.  
  1026. ########## EOF - C:\AdwCleaner[R1].txt - [27646 octets] ##########
  1027.  
  1028.  
  1029. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  1030. Junkware Removal Tool (JRT) by Thisisu
  1031. Version: 4.6.5 (02.18.2013:1)
  1032. OS: Windows Vista (TM) Home Basic x86
  1033. Ran by Oni on Mon 02/18/2013 at 18:36:49.64
  1034. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  1035.  
  1036.  
  1037.  
  1038.  
  1039. ~~~ Services
  1040.  
  1041.  
  1042.  
  1043. ~~~ Registry Values
  1044.  
  1045. Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\urlsearchhooks\\{f0381dbd-e018-4e07-ae40-d96ab15083f0}
  1046. Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page
  1047. Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page
  1048. Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page
  1049. Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page
  1050. Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page
  1051. Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1508737220-1151108484-2550500073-1000\software\microsoft\internet explorer\main\\Start Page
  1052. Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\\DefaultScope
  1053. Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\\DefaultScope
  1054. Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\searchscopes\\DefaultScope
  1055. Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\searchscopes\\DefaultScope
  1056. Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\searchscopes\\DefaultScope
  1057. Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\searchscopes\\DefaultScope
  1058. Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1508737220-1151108484-2550500073-1000\software\microsoft\internet explorer\searchscopes\\DefaultScope
  1059. Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\toolbar\webbrowser\\{d4027c7f-154a-4066-a1ad-4243d8127440}
  1060.  
  1061.  
  1062.  
  1063. ~~~ Registry Keys
  1064.  
  1065. Successfully deleted: [Registry Key] hkey_local_machine\software\conduit
  1066. Successfully deleted: [Registry Key] hkey_local_machine\software\freeze.com
  1067. Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduit
  1068. Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduitsearchscopes
  1069. Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\iehelperv2.5.0.dll
  1070. Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\yontooieclient.dll
  1071. Successfully deleted: [Registry Key] hkey_local_machine\software\classes\iehelperv250.wecarereminder
  1072. Successfully deleted: [Registry Key] hkey_local_machine\software\classes\iehelperv250.wecarereminder.1
  1073. Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.api
  1074. Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.api.1
  1075. Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1}
  1076. Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{6a1806cd-94d4-4689-ba73-e35ea1ea9990}
  1077. Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
  1078. Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
  1079. Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}
  1080. Successfully deleted: [Registry Key] hkey_classes_root\clsid\{d824f0de-3d60-4f57-9eb1-66033ecd8abb}
  1081. Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{d824f0de-3d60-4f57-9eb1-66033ecd8abb}
  1082. Successfully deleted: [Registry Key] hkey_classes_root\clsid\{f9e4a054-e9b1-4bc3-83a3-76a1ae736170}
  1083. Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{f9e4a054-e9b1-4bc3-83a3-76a1ae736170}
  1084.  
  1085.  
  1086.  
  1087. ~~~ Files
  1088.  
  1089.  
  1090.  
  1091. ~~~ Folders
  1092.  
  1093. Successfully deleted: [Folder] "C:\ProgramData\installmate"
  1094. Successfully deleted: [Folder] "C:\ProgramData\premium"
  1095. Successfully deleted: [Folder] "C:\ProgramData\wecarereminder"
  1096. Successfully deleted: [Folder] "C:\Users\Oni\appdata\local\conduit"
  1097. Successfully deleted: [Folder] "C:\Users\Oni\appdata\locallow\conduit"
  1098. Successfully deleted: [Folder] "C:\Users\Oni\appdata\locallow\whitesmoketoolbar"
  1099. Successfully deleted: [Folder] "C:\Program Files\conduit"
  1100. Successfully deleted: [Folder] "C:\Program Files\free offers from freeze.com"
  1101. Successfully deleted: [Folder] "C:\Program Files\whitesmoketoolbar"
  1102.  
  1103.  
  1104.  
  1105. ~~~ FireFox
  1106.  
  1107. Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\bing-zugo.xml"
  1108. Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\websearch.xml"
  1109. Successfully deleted: [File] C:\Users\Oni\AppData\Roaming\mozilla\firefox\profiles\z4yq8eld.default\searchplugins\conduit.xml
  1110. Successfully deleted: [Folder] C:\Users\Oni\AppData\Roaming\mozilla\firefox\profiles\z4yq8eld.default\extensions\wecarereminder@bryan
  1111. Successfully deleted the following from C:\Users\Oni\AppData\Roaming\mozilla\firefox\profiles\z4yq8eld.default\prefs.js
  1112.  
  1113. user_pref("CT2765711..clientLogIsEnabled", false);
  1114. user_pref("CT2765711..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
  1115. user_pref("CT2765711..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
  1116. user_pref("CT2765711.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
  1117. user_pref("CT2765711.CTID", "CT2765711");
  1118. user_pref("CT2765711.Chat.Meebo.ServerLastCheckTime", "Sun Sep 25 2011 06:08:46 GMT-0400 (Eastern Daylight Time)");
  1119. user_pref("CT2765711.Chat.Meebo.ServerLastResponseTime", "Sun Sep 25 2011 06:08:46 GMT-0400 (Eastern Daylight Time)");
  1120. user_pref("CT2765711.Chat.Meebo.rooms.2030dff2c5edb1", 0);
  1121. user_pref("CT2765711.Chat.Meebo.rooms.30plusa87dca4f", 0);
  1122. user_pref("CT2765711.Chat.Meebo.rooms.communitychat7d6a306c", 0);
  1123. user_pref("CT2765711.Chat.Meebo.rooms.entertainmentc0ed09fb", 0);
  1124. user_pref("CT2765711.Chat.Meebo.rooms.health3693b665", 0);
  1125. user_pref("CT2765711.Chat.Meebo.rooms.musicj375cf270", 2);
  1126. user_pref("CT2765711.Chat.Meebo.rooms.newsxu117b840d", 3);
  1127. user_pref("CT2765711.Chat.Meebo.rooms.recreationab17d1f9", 0);
  1128. user_pref("CT2765711.Chat.Meebo.rooms.spirituality39155c53", 0);
  1129. user_pref("CT2765711.Chat.Meebo.rooms.sports522528d3", 4);
  1130. user_pref("CT2765711.Chat.Meebo.rooms.technology8bb9fd5b", 1);
  1131. user_pref("CT2765711.Chat.Meebo.rooms.teenagers833b8249", 0);
  1132. user_pref("CT2765711.Chat.Meebo.rooms.travel8c2e48db", 0);
  1133. user_pref("CT2765711.Chat.Meebo.rooms.videogames2fe066e0", 0);
  1134. user_pref("CT2765711.Chat.ServerLastCheckTime", "Sun Sep 25 2011 01:55:06 GMT-0400 (Eastern Daylight Time)");
  1135. user_pref("CT2765711.CurrentServerDate", "2-9-2012");
  1136. user_pref("CT2765711.DialogsAlignMode", "LTR");
  1137. user_pref("CT2765711.DownloadReferralCookieData", "");
  1138. user_pref("CT2765711.FirstServerDate", "28-3-2011");
  1139. user_pref("CT2765711.FirstTime", true);
  1140. user_pref("CT2765711.FirstTimeFF3", true);
  1141. user_pref("CT2765711.FixPageNotFoundErrors", false);
  1142. user_pref("CT2765711.GroupingServerCheckInterval", 1440);
  1143. user_pref("CT2765711.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
  1144. user_pref("CT2765711.HasUserGlobalKeys", true);
  1145. user_pref("CT2765711.Initialize", true);
  1146. user_pref("CT2765711.InitializeCommonPrefs", true);
  1147. user_pref("CT2765711.InstallationAndCookieDataSentCount", 3);
  1148. user_pref("CT2765711.InstalledDate", "Sun Mar 27 2011 23:43:51 GMT-0400 (Eastern Daylight Time)");
  1149. user_pref("CT2765711.InvalidateCache", false);
  1150. user_pref("CT2765711.IsGrouping", false);
  1151. user_pref("CT2765711.IsMulticommunity", false);
  1152. user_pref("CT2765711.IsOpenThankYouPage", true);
  1153. user_pref("CT2765711.IsOpenUninstallPage", true);
  1154. user_pref("CT2765711.LanguagePackLastCheckTime", "Sun Sep 02 2012 16:45:04 GMT-0400 (Eastern Daylight Time)");
  1155. user_pref("CT2765711.LanguagePackReloadIntervalMM", 1440);
  1156. user_pref("CT2765711.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
  1157. user_pref("CT2765711.LastLogin_3.2.1.3", "Sun Sep 02 2012 16:45:04 GMT-0400 (Eastern Daylight Time)");
  1158. user_pref("CT2765711.LatestVersion", "3.14.1.0");
  1159. user_pref("CT2765711.Locale", "en-us");
  1160. user_pref("CT2765711.MCDetectTooltipHeight", "83");
  1161. user_pref("CT2765711.MCDetectTooltipShow", false);
  1162. user_pref("CT2765711.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
  1163. user_pref("CT2765711.MCDetectTooltipWidth", "295");
  1164. user_pref("CT2765711.RadioIsPodcast", false);
  1165. user_pref("CT2765711.RadioLastCheckTime", "Tue Jan 31 2012 09:04:41 GMT-0500 (Eastern Standard Time)");
  1166. user_pref("CT2765711.RadioLastUpdateIPServer", "3");
  1167. user_pref("CT2765711.RadioLastUpdateServer", "3");
  1168. user_pref("CT2765711.RadioMediaID", "9962");
  1169. user_pref("CT2765711.RadioMediaType", "Media Player");
  1170. user_pref("CT2765711.RadioMenuSelectedID", "EBRadioMenu_CT27657119962");
  1171. user_pref("CT2765711.RadioStationName", "California%20Rock");
  1172. user_pref("CT2765711.RadioStationURL", "hxxp://feedlive.net/california.asx");
  1173. user_pref("CT2765711.SHRINK_TOOLBAR", 1);
  1174. user_pref("CT2765711.SearchBoxWidth", 138);
  1175. user_pref("CT2765711.SearchFromAddressBarIsInit", true);
  1176. user_pref("CT2765711.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2765711&q=");
  1177. user_pref("CT2765711.SearchInNewTabEnabled", true);
  1178. user_pref("CT2765711.SearchInNewTabIntervalMM", 1440);
  1179. user_pref("CT2765711.SearchInNewTabLastCheckTime", "Sun Sep 02 2012 16:45:01 GMT-0400 (Eastern Daylight Time)");
  1180. user_pref("CT2765711.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
  1181. user_pref("CT2765711.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");
  1182. user_pref("CT2765711.ServiceMapLastCheckTime", "Sun Sep 02 2012 16:45:01 GMT-0400 (Eastern Daylight Time)");
  1183. user_pref("CT2765711.SettingsLastCheckTime", "Sun Sep 02 2012 16:45:00 GMT-0400 (Eastern Daylight Time)");
  1184. user_pref("CT2765711.SettingsLastUpdate", "1346236827");
  1185. user_pref("CT2765711.ThirdPartyComponentsInterval", 504);
  1186. user_pref("CT2765711.ThirdPartyComponentsLastCheck", "Sun Sep 02 2012 16:45:00 GMT-0400 (Eastern Daylight Time)");
  1187. user_pref("CT2765711.ThirdPartyComponentsLastUpdate", "1331805997");
  1188. user_pref("CT2765711.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
  1189. user_pref("CT2765711.Uninstall", false);
  1190. user_pref("CT2765711.UserID", "UN24486662282570515");
  1191. user_pref("CT2765711.ValidationData_Search", 2);
  1192. user_pref("CT2765711.ValidationData_Toolbar", 2);
  1193. user_pref("CT2765711.alertChannelId", "1157832");
  1194. user_pref("CT2765711.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D474549484C5952594B335E5356432C45333438334A414C546660576364676F6A5E4B766B6E5B
  1195. user_pref("CT2765711.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C4748402C574C4F3C253E2C2E2B2F433A454E59505B57676A66426D62455E69543D56444643465B
  1196. user_pref("CT2765711.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462B554A4D4B4749594D33535D4F432C45333439344A414C565B5E6C656E706C7164736D4D786D
  1197. user_pref("CT2765711.backendstorage./9b+7e.:2z527", "247E6F727174354379453A3D2A722C757A787D31283323242B4953542E594E513E27402A2B3230453C47323B3C5564606A436E6366533C553F4447445A
  1198. user_pref("CT2765711.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F564654524C474A595A4851505E51523964595C49324B393C3B3E5047525D6C6A6B6F786D6850
  1199. user_pref("CT2765711.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C4343534E2D585B3C253E2C302E34433A45515862695E675A416C6164513A5341454348584F5A66
  1200. user_pref("CT2765711.backendstorage./9b+7e06cg5el8:", "6E6D6F6F737273707572");
  1201. user_pref("CT2765711.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737575797879767B78242F4B49474F42357D5D5C3D");
  1202. user_pref("CT2765711.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E41295547484D515A4E5A59325D5255422B443237303749404B585E685E706E6E6674626E696B4D786D
  1203. user_pref("CT2765711.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473E454745482F5A4F523F2841302D2F33463D48566265685C6B675F6D70604873686B58415A49
  1204. user_pref("CT2765711.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D3229344356554E472E594E51325E4F412A4335373231483F4A59655F5F626C5B717369756975744D786D
  1205. user_pref("CT2765711.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352C37474B59574B4A4858584E5E3762573A535E49324B3A3D3F3B504752626C625D75786D766A
  1206. user_pref("CT2765711.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A522B55553A233C2B2F282941384354515E5D56615F56685C426D6265523B544346494A59505B
  1207. user_pref("CT2765711.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D49564A50592E594E314A55402942322E332F473E495B5D595A6A5E58707262674974696C59425B
  1208. user_pref("CT2765711.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B364953545259585A5A50524E36615659462F4838353D3C4D444F626C6D6B72716A77614D786D
  1209. user_pref("CT2765711.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A312833474745445159575B504B504B4D5E545553533A655A5D4A334C3C3B3A395148536775636367757567
  1210. user_pref("CT2765711.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E782332293449565540472E594E513E274030323533453C475C5558636A656E625E6C616B7068734B766B6E5B
  1211. user_pref("CT2765711.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4F44504C4754585C5048345F5457442D46373135344B424D636B5D5F5F73696B4A756A6D5A43
  1212. user_pref("CT2765711.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A30273249485545442C574C4F3C253E2F2A2D2D433A455C67555B5E3F6A5F624F3851423D403F564D586F7A68
  1213. user_pref("CT2765711.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354D462C574C4F3C253E2F2B2B31433A455D6356575C5C5A416C6164513A5344404045584F5A72
  1214. user_pref("CT2765711.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352C37502E4F4747315C5154412A4334313738483F4A635F5A6A645E625A4772676A5740594A47
  1215. user_pref("CT2765711.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B36505459574C554F515B345F5457442D46373637384B424D676B706E606F61666B63664D786D
  1216. user_pref("CT2765711.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A35504F5346482F5A4F523F28413233342F463D48635C5D66626A436E6366533C55464748425A51
  1217. user_pref("CT2765711.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3652504C5249555256525C35605558452E47383B38364C434E6A706F5F65635D736F67757868
  1218. user_pref("CT2765711.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2A554A2D46513C253E302B332C433A45626756516259655F5F436E63465F6A553E5749444C44
  1219. user_pref("CT2765711.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A52404548564F58315C5154412A4335342F37483F4A68646B645D5E626462616D6971726B6C78
  1220. user_pref("CT2765711.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57");
  1221. user_pref("CT2765711.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352C37565949484E4F51525C4E4C55535B54605A5A3E695E614E37503B3D41544B567575656D73
  1222. user_pref("CT2765711.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E3128335351565551575A4F584C5E335E5356432C4534383649404B6B59566C686B46716669563F58474B48
  1223. user_pref("CT2765711.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C484A2C574C2F48533E27403233433A45665B68505C5E406B6E4F38514343544B56776C79616D
  1224. user_pref("CT2765711.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215642542D584D503D263F2D2E2E2E443B4635645E6669595C6062686F5C7363716F696467764F
  1225. user_pref("CT2765711.backendstorage./9b-0?3g>d", "6A6A6B3F6C3F75437A747075472049784D7A25797D4F522A25295856242C2A59592C602B");
  1226. user_pref("CT2765711.backendstorage./9b-0?3g@6:5;", "");
  1227. user_pref("CT2765711.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
  1228. user_pref("CT2765711.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332A354448584C3A232C2F30313237425C6453685A64536C56685C5C676264523B6F756B65745D
  1229. user_pref("CT2765711.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
  1230. user_pref("CT2765711.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484775213F3E484F4E4D4648502B564B4E2E5959595F4C564F3764535750");
  1231. user_pref("CT2765711.backendstorage./9b5ba==9cjag", "3E6A3F6E3D3F43417A7844447B734878784D4F5120");
  1232. user_pref("CT2765711.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F6F737273707673777972");
  1233. user_pref("CT2765711.backendstorage./9b9643g3/9e", "6A");
  1234. user_pref("CT2765711.backendstorage./9b<:222h64<", "393F352F3E");
  1235. user_pref("CT2765711.backendstorage./9b=+03eh8h8j?:", "4443");
  1236. user_pref("CT2765711.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52");
  1237. user_pref("CT2765711.backendstorage./9b?b0d:8aj62<h", "6D");
  1238. user_pref("CT2765711.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
  1239. user_pref("CT2765711.backendstorage.cb_experience_000", "31");
  1240. user_pref("CT2765711.backendstorage.cb_firstuse0100", "31");
  1241. user_pref("CT2765711.backendstorage.cb_user_id_000", "43423537383839363039313833395F46697265666F78");
  1242. user_pref("CT2765711.backendstorage.cbcountry_000", "5553");
  1243. user_pref("CT2765711.backendstorage.cbcountry_001", "5553");
  1244. user_pref("CT2765711.backendstorage.cbfirsttime", "5765642044656320323820323031312031333A31393A313320474D542D3035303020284561737465726E205374616E646172642054696D6529");
  1245. user_pref("CT2765711.backendstorage.gk_hsselite_notif_sent", "73656E74");
  1246. user_pref("CT2765711.backendstorage.gk_iolo_notif2_sent", "73656E74");
  1247. user_pref("CT2765711.backendstorage.gk_webroot_notif_sent", "73656E74");
  1248. user_pref("CT2765711.backendstorage.hss_gk_notif_sent", "73656E74");
  1249. user_pref("CT2765711.backendstorage.installationdate0.2180191645578123", "31333235303936333531343937");
  1250. user_pref("CT2765711.backendstorage.installationdate0.2646799591156723", "31333339363632383332303736");
  1251. user_pref("CT2765711.backendstorage.installationdate0.2690270998198123", "31333335303634393637393336");
  1252. user_pref("CT2765711.backendstorage.installationdate0.2690291778262231", "31333136383330333135363439");
  1253. user_pref("CT2765711.backendstorage.printitgreenstatus", "74727565");
  1254. user_pref("CT2765711.backendstorage.shoppingapp.gk.exipres", "4672692053657020303720323031322031363A34353A313620474D542D3034303020284561737465726E204461796C696768742054696D652
  1255. user_pref("CT2765711.backendstorage.shoppingapp.gk.geolocation", "756E6974656420737461746573");
  1256. user_pref("CT2765711.backendstorage.toolbarappheartbeat", "7B22313239373636333534383930363132383834223A313333393636323833323036317D");
  1257. user_pref("CT2765711.backendstorage.toolbarnotificationheartbeat", "7B2274797065223A22686561727462656174222C2274696D65223A313333393636333438383433312C2275726C223A2268747470733
  1258. user_pref("CT2765711.backendstorage.toolbarnotificationqueue", "5B7B22617070223A302E323634363739393539313135363732332C2261726773223A7B226964223A302E323634363739393539313135363
  1259. user_pref("CT2765711.backendstorage.toolbarnotificationsettings", "7B2273656E644E6F74696669636174696F6E73223A7B22616C6C223A747275652C2261707073223A7B22302E32363930323931373738
  1260. user_pref("CT2765711.backendstorage.toolbarnotificationuserid", "3136313035353533363632");
  1261. user_pref("CT2765711.backendstorage.url_history", "687474703A2F2F7777772E676E632E636F6D2F70726F647563742F696E6465782E6A73703F70726F6475637449643D31313439393836322663703D333539
  1262. user_pref("CT2765711.backendstorage.url_history0001", "68747470733A2F2F7777772E676F6F676C652E636F6D3A3A3A636C69636B68616E646C65723A3A3A313333393636333932363833382C2C2C68747470
  1263. user_pref("CT2765711.backendstorage.url_history_time", "31333236303537343033373633");
  1264. user_pref("CT2765711.backendstorage.welcome_dialog_displayed", "646973706C61796564");
  1265. user_pref("CT2765711.components.1000034", false);
  1266. user_pref("CT2765711.components.1000082", false);
  1267. user_pref("CT2765711.components.1000234", false);
  1268. user_pref("CT2765711.myStuffEnabled", true);
  1269. user_pref("CT2765711.myStuffPublihserMinWidth", 400);
  1270. user_pref("CT2765711.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
  1271. user_pref("CT2765711.myStuffServiceIntervalMM", 1440);
  1272. user_pref("CT2765711.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
  1273. user_pref("CT2765711.testingCtid", "");
  1274. user_pref("CT2765711.toolbarAppMetaDataLastCheckTime", "Sun Sep 02 2012 16:45:03 GMT-0400 (Eastern Daylight Time)");
  1275. user_pref("CT2765711.toolbarContextMenuLastCheckTime", "Sun Mar 27 2011 23:43:51 GMT-0400 (Eastern Daylight Time)");
  1276. user_pref("CT2765711.usagesFlag", 2);
  1277. user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2765711/CT2765711", "\"3c0dfcc67fcf730e92b5ed03c477c1852\"");
  1278. user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1157832/1153519/US", "\"0\"");
  1279. user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/US", "\"0\"");
  1280. user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2765711", "\"1323697829\"");
  1281. user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en-us", "L+tncv4eqt6Qm5T3dzChdA==");
  1282. user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en-us", "0uSPYx+Kl2jpu8sJZMeHjw==");
  1283. user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en-us", "QmycQXJXVyFVAzIiNllWhQ==");
  1284. user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en-us", "K4Vqu91uAzWURlxJRdXJOg==");
  1285. user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"c912886ea3ba021d3a9ef2d6ad700899\"");
  1286. user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
  1287. user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000");
  1288. user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2765711&octid=CT2765711", "\"1322149503\"");
  1289. user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2765711/CT2765711", "\"1316671580\"");
  1290. user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer_dead.gif", "\"0a8c48d3330c81:0\"");
  1291. user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.gif", "\"0e2106f3030c81:0\"");
  1292. user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif", "\"0f475394430c81:0\"");
  1293. user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif", "\"08d9ef44430c81:0\"");
  1294. user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif", "\"066e8863030c81:0\"");
  1295. user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"42a238c571d281fb3cd99a6a8f620954\"");
  1296. user_pref("CommunityToolbar.EngineOwner", "CT2765711");
  1297. user_pref("CommunityToolbar.EngineOwnerGuid", "{f0381dbd-e018-4e07-ae40-d96ab15083f0}");
  1298. user_pref("CommunityToolbar.EngineOwnerToolbarId", "af-hss");
  1299. user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
  1300. user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_ext_msg_key_22210766", "356x332");
  1301. user_pref("CommunityToolbar.OriginalEngineOwner", "CT2765711");
  1302. user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{f0381dbd-e018-4e07-ae40-d96ab15083f0}");
  1303. user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "af-hss");
  1304. user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");
  1305. user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine,CT2765711");
  1306. user_pref("CommunityToolbar.ToolbarsList2", "CT2765711");
  1307. user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
  1308. user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Sep 02 2012 16:44:59 GMT-0400 (Eastern Daylight Time)");
  1309. user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
  1310. user_pref("CommunityToolbar.alert.locale", "en");
  1311. user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
  1312. user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun Sep 02 2012 16:44:59 GMT-0400 (Eastern Daylight Time)");
  1313. user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
  1314. user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
  1315. user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
  1316. user_pref("CommunityToolbar.alert.showTrayIcon", false);
  1317. user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
  1318. user_pref("CommunityToolbar.alert.userId", "a5ce8d29-6915-4a24-af2f-a1934459ab2c");
  1319. user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2765711");
  1320. user_pref("ConduitEngine.FirstServerDate", "03/28/2011 06");
  1321. user_pref("ConduitEngine.FirstTime", true);
  1322. user_pref("ConduitEngine.FirstTimeFF3", true);
  1323. user_pref("ConduitEngine.HasUserGlobalKeys", true);
  1324. user_pref("ConduitEngine.Initialize", true);
  1325. user_pref("ConduitEngine.InitializeCommonPrefs", true);
  1326. user_pref("ConduitEngine.InstalledDate", "Sun Mar 27 2011 23:43:49 GMT-0400 (Eastern Daylight Time)");
  1327. user_pref("ConduitEngine.IsMulticommunity", false);
  1328. user_pref("ConduitEngine.IsOpenThankYouPage", false);
  1329. user_pref("ConduitEngine.IsOpenUninstallPage", true);
  1330. user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Jun 27 2011 21:35:53 GMT-0400 (Eastern Daylight Time)");
  1331. user_pref("ConduitEngine.LastLogin_3.2.1.3", "Mon Jun 27 2011 21:35:53 GMT-0400 (Eastern Daylight Time)");
  1332. user_pref("ConduitEngine.PublisherContainerWidth", 0);
  1333. user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
  1334. user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Jun 27 2011 21:35:48 GMT-0400 (Eastern Daylight Time)");
  1335. user_pref("ConduitEngine.UserID", "UN87942782515198346");
  1336. user_pref("ConduitEngine.engineLocale", "en-US");
  1337. user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Jun 27 2011 21:35:53 GMT-0400 (Eastern Daylight Time)");
  1338. user_pref("ConduitEngine.initDone", true);
  1339. user_pref("browser.search.defaultthis.engineName", "AF-HSS Customized Web Search");
  1340. user_pref("browser.startup.homepage", "hxxp://search.hotspotshield.com/g/?c=h");
  1341. user_pref("extentions.y2layers.installId", "d9406a3e-c3df-4213-a3b3-cc198456737b");
  1342.  
  1343.  
  1344.  
  1345. ~~~ Chrome
  1346.  
  1347. Dumping contents of C:\Users\Oni\appdata\local\Google\Chrome\User Data\Default\Default
  1348. C:\Users\Oni\appdata\local\Google\Chrome\User Data\Default\Default\aadigfdidjdhgdgcdfgddgdidededagd
  1349. C:\Users\Oni\appdata\local\Google\Chrome\User Data\Default\Default\aadigfdidjdhgdgcdfgddgdidededagd\ContentScript.js
  1350. C:\Users\Oni\appdata\local\Google\Chrome\User Data\Default\Default\aadigfdidjdhgdgcdfgddgdidededagd\manifest.json
  1351.  
  1352. Successfully deleted: [Folder] C:\Users\Oni\appdata\local\Google\Chrome\User Data\Default\Default [Default Extension 1.0]
  1353. Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\niapdbllcanepiiimjjndipklodoedlc
  1354.  
  1355.  
  1356.  
  1357. ~~~ Event Viewer Logs were cleared
  1358.  
  1359.  
  1360.  
  1361.  
  1362.  
  1363. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  1364. Scan was completed on Mon 02/18/2013 at 18:44:11.95
  1365. End of JRT log
  1366. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  1367.  
  1368.  
  1369.  
  1370. Rkill 2.4.7 by Lawrence Abrams (Grinler)
  1371. http://www.bleepingcomputer.com/
  1372. Copyright 2008-2013 BleepingComputer.com
  1373. More Information about Rkill can be found at this link:
  1374. http://www.bleepingcomputer.com/forums/topic308364.html
  1375.  
  1376. Program started at: 02/18/2013 06:47:47 PM in x86 mode.
  1377. Windows Version: Windows Vista (TM) Home Basic Service Pack 2
  1378.  
  1379. Checking for Windows services to stop:
  1380.  
  1381. * No malware services found to stop.
  1382.  
  1383. Checking for processes to terminate:
  1384.  
  1385. * No malware processes found to kill.
  1386.  
  1387. Checking Registry for malware related settings:
  1388.  
  1389. * No issues found in the Registry.
  1390.  
  1391. Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
  1392. * HKCU\SOFTWARE\Classes\.exe "@" exists and is set to exefile!
  1393. * HKCU\SOFTWARE\Classes\.exe has been deleted!
  1394. * HKCU\SOFTWARE\Classes\.bat "@" exists and is set to batfile!
  1395. * HKCU\SOFTWARE\Classes\.bat has been deleted!
  1396. * HKCU\SOFTWARE\Classes\.com "@" exists and is set to comfile!
  1397. * HKCU\SOFTWARE\Classes\.com has been deleted!
  1398.  
  1399. Performing miscellaneous checks:
  1400.  
  1401. * Windows Defender Disabled
  1402.  
  1403. [HKLM\SOFTWARE\Microsoft\Windows Defender]
  1404. "DisableAntiSpyware" = dword:00000001
  1405.  
  1406. Checking Windows Service Integrity:
  1407.  
  1408. * Windows Defender (WinDefend) is not Running.
  1409. Startup Type set to: Automatic
  1410.  
  1411. * msiserver => %systemroot%\system32\msiexec.exe /V [Incorrect ImagePath]
  1412.  
  1413. Searching for Missing Digital Signatures:
  1414.  
  1415. * No issues found.
  1416.  
  1417. Checking HOSTS File:
  1418.  
  1419. * HOSTS file entries found:
  1420.  
  1421. 127.0.0.1 localhost
  1422.  
  1423. Program finished at: 02/18/2013 06:48:09 PM
  1424. Execution time: 0 hours(s), 0 minute(s), and 22 seconds(s)
  1425.  
  1426.  
  1427.  
  1428. "HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms" "" "" ""
  1429. + "rdpclip" "" "" "File not found: rdpclip"
  1430. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" "" "" ""
  1431. + "00TCrdMain" "TOSHIBA Flash Cards" "TOSHIBA Corporation" "c:\program files\toshiba\flashcards\tcrdmain.exe"
  1432. + "Adobe ARM" "Adobe Reader and Acrobat Manager" "Adobe Systems Incorporated" "c:\program files\common files\adobe\arm\1.0\adobearm.exe"
  1433. + "APSDaemon" "Apple Push" "Apple Inc." "c:\program files\common files\apple\apple application support\apsdaemon.exe"
  1434. + "AVG_TRAY" "AVG Tray Monitor" "AVG Technologies CZ, s.r.o." "c:\program files\avg\avg10\avgtray.exe"
  1435. + "Dell V505 Fax Server" "Fax Man Server" "" "c:\program files\dell v505\fm3032.exe"
  1436. + "dldwamon" "" "" "c:\program files\dell v505\dldwamon.exe"
  1437. + "dldwmon.exe" "Printer Device Monitor" "" "c:\program files\dell v505\dldwmon.exe"
  1438. + "GrooveMonitor" "GrooveMonitor Utility" "Microsoft Corporation" "c:\program files\microsoft office\office12\groovemonitor.exe"
  1439. + "HotKeysCmds" "hkcmd Module" "Intel Corporation" "c:\windows\system32\hkcmd.exe"
  1440. + "iTunesHelper" "iTunesHelper" "Apple Inc." "c:\program files\itunes\ituneshelper.exe"
  1441. + "Persistence" "persistence Module" "Intel Corporation" "c:\windows\system32\igfxpers.exe"
  1442. + "PWRISOVM.EXE" "PowerISO Virtual Drive Manager" "PowerISO Computing, Inc." "c:\program files\poweriso\pwrisovm.exe"
  1443. + "QuickTime Task" "QuickTime Task" "Apple Inc." "c:\program files\quicktime\qttask.exe"
  1444. + "RtHDVCpl" "HD Audio Control Panel" "Realtek Semiconductor" "c:\windows\rthdvcpl.exe"
  1445. + "SynTPEnh" "Synaptics TouchPad Enhancements" "Synaptics, Inc." "c:\program files\synaptics\syntp\syntpenh.exe"
  1446. + "TPwrMain" "TOSHIBA Power Saver" "TOSHIBA Corporation" "c:\program files\toshiba\power saver\tpwrmain.exe"
  1447. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup" "" "" ""
  1448. + "SafeConnect.lnk" "SafeConnect Client" "Impulse Point, LLC" "c:\program files\safeconnect\scclient.exe"
  1449. "C:\Users\Oni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" "" "" ""
  1450. + "Dropbox.lnk" "Dropbox" "Dropbox, Inc." "c:\users\oni\appdata\roaming\dropbox\bin\dropbox.exe"
  1451. + "OneNote 2007 Screen Clipper and Launcher.lnk" "Microsoft Office OneNote Quick Launcher" "Microsoft Corporation" "c:\program files\microsoft office\office12\onenotem.exe"
  1452. "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" "" "" ""
  1453. + "Microsoft Windows Mail 7" "Windows Mail" "Microsoft Corporation" "c:\program files\windows mail\winmail.exe"
  1454. "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" "" "" ""
  1455. + "Google Update" "Google Installer" "Google Inc." "c:\users\oni\appdata\local\google\update\googleupdate.exe"
  1456. + "Pando Media Booster" "Pando Media Booster" "" "c:\program files\pando networks\media booster\pmb.exe"
  1457. + "Skype" "Skype " "Skype Technologies S.A." "c:\program files\skype\phone\skype.exe"
  1458. + "Spotify Web Helper" "SpotifyWebHelper" "Spotify Ltd" "c:\users\oni\appdata\roaming\spotify\data\spotifywebhelper.exe"
  1459. "HKLM\SOFTWARE\Classes\Protocols\Filter" "" "" ""
  1460. + "text/xml" "Microsoft Office XML MIME Filter" "Microsoft Corporation" "c:\program files\common files\microsoft shared\office12\msoxmlmf.dll"
  1461. "HKLM\SOFTWARE\Classes\Protocols\Handler" "" "" ""
  1462. + "grooveLocalGWS" "GrooveSystemServices Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\groovesystemservices.dll"
  1463. + "linkscanner" "Safe Search pluggable protocol" "AVG Technologies CZ, s.r.o." "c:\program files\avg\avg10\avgpp.dll"
  1464. + "ms-help" "Microsoft® Help Data Services Module" "Microsoft Corporation" "c:\program files\common files\microsoft shared\help\hxds.dll"
  1465. + "ms-itss" "Microsoft® InfoTech Storage System Library" "Microsoft Corporation" "c:\program files\common files\microsoft shared\information retrieval\msitss.dll"
  1466. + "skype-ie-addon-data" "Skype Click to Call for Internet Explorer" "Skype Technologies S.A." "c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll"
  1467. + "skype4com" "Skype for COM API" "Skype Technologies" "c:\program files\common files\skype\skype4com.dll"
  1468. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks" "" "" ""
  1469. + "Groove GFS Stub Execution Hook" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1470. "HKCU\Software\Classes\*\ShellEx\ContextMenuHandlers" "" "" ""
  1471. + "DropboxExt" "Dropbox Shell Extension" "Dropbox, Inc." "c:\users\oni\appdata\roaming\dropbox\bin\dropboxext.17.dll"
  1472. "HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers" "" "" ""
  1473. + "AVG9 Shell Extension" "AVG Shell Extension" "AVG Technologies CZ, s.r.o." "c:\program files\avg\avg10\avgse.dll"
  1474. + "PowerISO" "PowerISOShell DLL" "PowerISO Computing, Inc." "c:\program files\poweriso\pwrisosh.dll"
  1475. + "XXX Groove GFS Context Menu Handler XXX" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1476. "HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers" "" "" ""
  1477. + "MBAMShlExt" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamext.dll"
  1478. + "XXX Groove GFS Context Menu Handler XXX" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1479. "HKCU\Software\Classes\Directory\ShellEx\ContextMenuHandlers" "" "" ""
  1480. + "DropboxExt" "Dropbox Shell Extension" "Dropbox, Inc." "c:\users\oni\appdata\roaming\dropbox\bin\dropboxext.17.dll"
  1481. "HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers" "" "" ""
  1482. + "PowerISO" "PowerISOShell DLL" "PowerISO Computing, Inc." "c:\program files\poweriso\pwrisosh.dll"
  1483. + "XXX Groove GFS Context Menu Handler XXX" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1484. "HKCU\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers" "" "" ""
  1485. + "DropboxExt" "Dropbox Shell Extension" "Dropbox, Inc." "c:\users\oni\appdata\roaming\dropbox\bin\dropboxext.17.dll"
  1486. "HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers" "" "" ""
  1487. + "igfxcui" "igfxpph Module" "Intel Corporation" "c:\windows\system32\igfxpph.dll"
  1488. + "XXX Groove GFS Context Menu Handler XXX" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1489. "HKLM\Software\Classes\Folder\Shellex\ColumnHandlers" "" "" ""
  1490. + "PDF Shell Extension" "PDF Shell Extension" "Adobe Systems, Inc." "c:\program files\common files\adobe\acrobat\activex\pdfshell.dll"
  1491. "HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers" "" "" ""
  1492. + "AVG9 Shell Extension" "AVG Shell Extension" "AVG Technologies CZ, s.r.o." "c:\program files\avg\avg10\avgse.dll"
  1493. + "MBAMShlExt" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamext.dll"
  1494. + "PowerISO" "PowerISOShell DLL" "PowerISO Computing, Inc." "c:\program files\poweriso\pwrisosh.dll"
  1495. + "XXX Groove GFS Context Menu Handler XXX" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1496. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers" "" "" ""
  1497. + "DropboxExt1" "Dropbox Shell Extension" "Dropbox, Inc." "c:\users\oni\appdata\roaming\dropbox\bin\dropboxext.17.dll"
  1498. + "DropboxExt2" "Dropbox Shell Extension" "Dropbox, Inc." "c:\users\oni\appdata\roaming\dropbox\bin\dropboxext.17.dll"
  1499. + "DropboxExt3" "Dropbox Shell Extension" "Dropbox, Inc." "c:\users\oni\appdata\roaming\dropbox\bin\dropboxext.17.dll"
  1500. + "DropboxExt4" "Dropbox Shell Extension" "Dropbox, Inc." "c:\users\oni\appdata\roaming\dropbox\bin\dropboxext.17.dll"
  1501. + "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1502. + "Groove Explorer Icon Overlay 2 (GFS Stub)" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1503. + "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1504. + "Groove Explorer Icon Overlay 3 (GFS Folder)" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1505. + "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1506. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" ""
  1507. + "Adobe PDF Link Helper" "Adobe PDF Helper for Internet Explorer" "Adobe Systems Incorporated" "c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll"
  1508. + "AVG Safe Search" "Safe Search for Internet Explorer" "AVG Technologies CZ, s.r.o." "c:\program files\avg\avg10\avgssie.dll"
  1509. + "Groove GFS Browser Helper" "GrooveShellExtensions Module" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveshellextensions.dll"
  1510. + "Java(tm) Plug-In 2 SSV Helper" "Java(TM) Platform SE binary" "Sun Microsystems, Inc." "c:\program files\java\jre6\bin\jp2ssv.dll"
  1511. + "Skype Browser Helper" "Skype Click to Call for Internet Explorer" "Skype Technologies S.A." "c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll"
  1512. "HKLM\Software\Microsoft\Internet Explorer\Extensions" "" "" ""
  1513. + "S&end to OneNote" "Microsoft Office OneNote Internet Explorer Add-in" "Microsoft Corporation" "c:\program files\microsoft office\office12\onbttnie.dll"
  1514. + "Skype Click to Call" "Skype Click to Call for Internet Explorer" "Skype Technologies S.A." "c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll"
  1515. "Task Scheduler" "" "" ""
  1516. + "\Adobe Flash Player Updater" "Adobe® Flash® Player Update Service 11.5 r502" "Adobe Systems Incorporated" "c:\windows\system32\macromed\flash\flashplayerupdateservice.exe"
  1517. + "\Apple\AppleSoftwareUpdate" "Apple Software Update" "Apple Inc." "c:\program files\apple software update\softwareupdate.exe"
  1518. + "\GoogleUpdateTaskMachineCore" "Google Installer" "Google Inc." "c:\program files\google\update\googleupdate.exe"
  1519. + "\GoogleUpdateTaskMachineUA" "Google Installer" "Google Inc." "c:\program files\google\update\googleupdate.exe"
  1520. + "\GoogleUpdateTaskUserS-1-5-21-1508737220-1151108484-2550500073-1000Core" "Google Installer" "Google Inc." "c:\users\oni\appdata\local\google\update\googleupdate.exe"
  1521. + "\GoogleUpdateTaskUserS-1-5-21-1508737220-1151108484-2550500073-1000UA" "Google Installer" "Google Inc." "c:\users\oni\appdata\local\google\update\googleupdate.exe"
  1522. + "\Installation App Launcher" "" "" "c:\program files\dell v505\dldwamon.exe"
  1523. + "\Microsoft\Windows\WindowsCalendar\Reminders - Oni" "Windows Calendar" "Microsoft Corporation" "c:\program files\windows calendar\wincal.exe"
  1524. + "\Microsoft\Windows\Wired\GatherWiredInfo" "" "" "c:\windows\system32\gatherwiredinfo.vbs"
  1525. + "\Microsoft\Windows\Wireless\GatherWirelessInfo" "" "" "c:\windows\system32\gatherwirelessinfo.vbs"
  1526. + "\ROC_REG_JAN_DELETE" "" "" "c:\programdata\avg january 2013 campaign\roc.exe"
  1527. + "\{8BAB8E71-854F-4718-8E73-E422FF8DE45D}" "Skype " "Skype Technologies S.A." "c:\program files\skype\phone\skype.exe"
  1528. + "\{D5AC6903-0B38-4DBF-B280-BB863F341CD6}" "Skype " "Skype Technologies S.A." "c:\program files\skype\phone\skype.exe"
  1529. "HKLM\System\CurrentControlSet\Services" "" "" ""
  1530. + "AdobeARMservice" "Adobe Acrobat Updater keeps your Adobe software up to date." "Adobe Systems Incorporated" "c:\program files\common files\adobe\arm\1.0\armsvc.exe"
  1531. + "AdobeFlashPlayerUpdateSvc" "This service keeps your Adobe Flash Player installation up to date with the latest enhancements and security fixes." "Adobe Systems Incorporated" "c:\windows\system32\macromed\flash\flashplayerupdateservice.exe"
  1532. + "Apple Mobile Device" "Provides the interface to Apple mobile devices." "Apple Inc." "c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe"
  1533. + "AVGIDSAgent" "Provides Identity Protection Against Cyber Crime." "AVG Technologies CZ, s.r.o." "c:\program files\avg\avg10\identity protection\agent\bin\avgidsagent.exe"
  1534. + "avgwd" "AVG Watchdog Service" "AVG Technologies CZ, s.r.o." "c:\program files\avg\avg10\avgwdsvc.exe"
  1535. + "Bonjour Service" "Enables hardware devices and software services to automatically configure themselves on the network and advertise their presence." "Apple Inc." "c:\program files\bonjour\mdnsresponder.exe"
  1536. + "ConfigFree Service" "You can't stop this service, if you want to keep ConfigFree functionality fine." "TOSHIBA CORPORATION" "c:\program files\toshiba\configfree\cfsvcs.exe"
  1537. + "dldw_device" "Printer Communication System" " " "c:\windows\system32\dldwcoms.exe"
  1538. + "dldwCATSCustConnectService" "Service Executable" "" "c:\windows\system32\spool\drivers\w32x86\3\dldwserv.exe"
  1539. + "GameConsoleService" "GameConsole management services" "WildTangent, Inc." "c:\program files\toshiba games\toshiba game console\gameconsoleservice.exe"
  1540. + "gupdate" "Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "Google Inc." "c:\program files\google\update\googleupdate.exe"
  1541. + "gupdatem" "Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "Google Inc." "c:\program files\google\update\googleupdate.exe"
  1542. + "gusvc" "Google Updater keeps your Google software up to date. If Google Updater Service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work." "Google" "c:\program files\google\common\google updater\googleupdaterservice.exe"
  1543. + "hshld" "" "" "c:\program files\hotspot shield\bin\openvpnas.exe"
  1544. + "HssSrv" "" "AnchorFree Inc." "c:\program files\hotspot shield\hsswpr\hsssrv.exe"
  1545. + "HssTrayService" "" "" "c:\program files\hotspot shield\bin\hsstrayservice.exe"
  1546. + "HssWd" "" "" "c:\program files\hotspot shield\bin\hsswd.exe"
  1547. + "IAANTMON" "RAID Monitor" "Intel Corporation" "c:\program files\intel\intel matrix storage manager\iaantmon.exe"
  1548. + "IDriverT" "Provides support for the Running Object Table for InstallShield Drivers" "Macrovision Corporation" "c:\program files\common files\installshield\driver\1150\intel 32\idrivert.exe"
  1549. + "iPod Service" "iPod hardware management services" "Apple Inc." "c:\program files\ipod\bin\ipodservice.exe"
  1550. + "MBAMScheduler" "Malwarebytes Anti-Malware scheduler" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamscheduler.exe"
  1551. + "MBAMService" "Malwarebytes Anti-Malware service" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamservice.exe"
  1552. + "Microsoft Office Groove Audit Service" "Groove Audit Service" "Microsoft Corporation" "c:\program files\microsoft office\office12\grooveauditservice.exe"
  1553. + "odserv" "Run portions of Microsoft Office Diagnostics." "Microsoft Corporation" "c:\program files\common files\microsoft shared\office12\odserv.exe"
  1554. + "ose" "Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports." "Microsoft Corporation" "c:\program files\common files\microsoft shared\source engine\ose.exe"
  1555. + "SCManager" "SafeConnect Service" "Impulse Point, LLC" "c:\program files\safeconnect\scmanager.sys"
  1556. + "SkypeUpdate" "Enables the detection, download and installation of updates for Skype." "Skype Technologies" "c:\program files\skype\updater\updater.exe"
  1557. + "TMachInfo" "TOSHIBA Machine Information Service" "TOSHIBA Corporation" "c:\program files\toshiba\toshiba service station\tmachinfo.exe"
  1558. + "TNaviSrv" "TOSHIBA Navi Support Service" "TOSHIBA Corporation" "c:\program files\toshiba\toshiba dvd player\tnavisrv.exe"
  1559. + "TODDSrv" "TDCSrv Application" "TOSHIBA Corporation" "c:\windows\system32\toddsrv.exe"
  1560. + "TosCoSrv" "TOSHIBA Power Saver manages power saving settings supported by TOSHIBA. These settings will not work if the service has stopped." "TOSHIBA Corporation" "c:\program files\toshiba\power saver\toscosrv.exe"
  1561. + "TOSHIBA SMART Log Service" "TosIPCSrv.exe" "TOSHIBA Corporation" "c:\program files\toshiba\smartlogservice\tosipcsrv.exe"
  1562. + "UleadBurningHelper" "ULCDRSvr" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\dvd\ulcdrsvr.exe"
  1563. + "WinDefend" "Scan your computer for unwanted software, schedule scans, and get the latest unwanted software definitions." "Microsoft Corporation" "c:\program files\windows defender\mpsvc.dll"
  1564. + "WMPNetworkSvc" "Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play" "Microsoft Corporation" "c:\program files\windows media player\wmpnetwk.exe"
  1565. + "YahooAUService" "Keeps your favorite Yahoo! software up-to-date with the latest features, tools, and enhancements." "Yahoo! Inc." "c:\program files\yahoo!\softwareupdate\yahooauservice.exe"
  1566. "HKLM\System\CurrentControlSet\Services" "" "" ""
  1567. + "AgereSoftModem" "SoftModem Device Driver" "Agere Systems" "c:\windows\system32\drivers\agrsm.sys"
  1568. + "AVGIDSDriver" "AVG Technologies IDS Application Activity Monitor Driver" "AVG Technologies CZ, s.r.o. " "c:\windows\system32\drivers\avgidsdriver.sys"
  1569. + "AVGIDSEH" "AVG Technologies IDS Application Activity Monitor Helper Driver" "AVG Technologies CZ, s.r.o. " "c:\windows\system32\drivers\avgidseh.sys"
  1570. + "AVGIDSFilter" "AVG Technologies IDS Application Activity Monitor Filter Driver" "AVG Technologies CZ, s.r.o. " "c:\windows\system32\drivers\avgidsfilter.sys"
  1571. + "AVGIDSShim" "AVG Technologies IDS Application Activity Monitor Shim Loader Driver" "AVG Technologies CZ, s.r.o. " "c:\windows\system32\drivers\avgidsshim.sys"
  1572. + "Avgldx86" "AVG AVI Loader Driver" "AVG Technologies CZ, s.r.o." "c:\windows\system32\drivers\avgldx86.sys"
  1573. + "Avgmfx86" "AVG Resident Shield Minifilter Driver" "AVG Technologies CZ, s.r.o." "c:\windows\system32\drivers\avgmfx86.sys"
  1574. + "Avgrkx86" "AVG Anti-Rootkit Driver" "AVG Technologies CZ, s.r.o." "c:\windows\system32\drivers\avgrkx86.sys"
  1575. + "Avgtdix" "AVG Network connection watcher" "AVG Technologies CZ, s.r.o." "c:\windows\system32\drivers\avgtdix.sys"
  1576. + "BrFiltLo" "Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver" "Brother Industries, Ltd." "c:\windows\system32\drivers\brfiltlo.sys"
  1577. + "BrFiltUp" "Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver" "Brother Industries, Ltd." "c:\windows\system32\drivers\brfiltup.sys"
  1578. + "BrUsbSer" "Brother USB Serial Driver" "Brother Industries Ltd." "c:\windows\system32\drivers\brusbser.sys"
  1579. + "E1G60" "Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver" "Intel Corporation" "c:\windows\system32\drivers\e1g60i32.sys"
  1580. + "FwLnk" "TOSHIBA Firmware Linkage 32-bit Driver" "TOSHIBA Corporation" "c:\windows\system32\drivers\fwlnk.sys"
  1581. + "GEARAspiWDM" "CD DVD Filter" "GEAR Software Inc." "c:\windows\system32\drivers\gearaspiwdm.sys"
  1582. + "HssDrv" "Hotspot Shield Routing Driver" "AnchorFree Inc." "c:\windows\system32\drivers\hssdrv.sys"
  1583. + "iaStor" "Intel Matrix Storage Manager driver - ia32" "Intel Corporation" "c:\windows\system32\drivers\iastor.sys"
  1584. + "igfx" "Intel Graphics Kernel Mode Driver" "Intel Corporation" "c:\windows\system32\drivers\igdkmd32.sys"
  1585. + "IntcAzAudAddService" "Realtek(r) High Definition Audio Function Driver" "Realtek Semiconductor Corp." "c:\windows\system32\drivers\rtkvhda.sys"
  1586. + "IO_Memory" "" "" "File not found: C:\Windows\System32\Drivers\IO_Memory.sys"
  1587. + "IpInIp" "IP in IP Tunnel Driver" "" "File not found: C:\Windows\System32\Drivers\IpInIp.sys"
  1588. + "LVUVC" "" "" "File not found: system32\DRIVERS\lvuvc.sys"
  1589. + "MBAMProtector" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\windows\system32\drivers\mbam.sys"
  1590. + "NwlnkFlt" "IPX Traffic Filter Driver" "" "File not found: C:\Windows\System32\Drivers\NwlnkFlt.sys"
  1591. + "NwlnkFwd" "IPX Traffic Forwarder Driver" "" "File not found: C:\Windows\System32\Drivers\NwlnkFwd.sys"
  1592. + "PxHelp20" "Px Engine Device Driver for Windows 2000/XP" "Sonic Solutions" "c:\windows\system32\drivers\pxhelp20.sys"
  1593. + "RTL8169" "Realtek 8101E/8168/8169 NDIS6 32-bit Driver " "Realtek Corporation " "c:\windows\system32\drivers\rtlh86.sys"
  1594. + "RTL8187B" "Realtek RTL8187B NDIS Driver" "Realtek Semiconductor Corporation " "c:\windows\system32\drivers\rtl8187b.sys"
  1595. + "RtlProt" "Realtke RtlProt WLAN Utility Protocol Driver" "Windows (R) Codename Longhorn DDK provider" "c:\windows\system32\drivers\rtlprot.sys"
  1596. + "RTSTOR" "Realtek USB Mass Storage Driver for Vista" "Realtek Semiconductor Corp." "c:\windows\system32\drivers\rtstor.sys"
  1597. + "SCDEmu" "PowerISO Virtual Drive" "PowerISO Computing, Inc." "c:\windows\system32\drivers\scdemu.sys"
  1598. + "secdrv" "Macrovision SECURITY Driver" "Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K." "c:\windows\system32\drivers\secdrv.sys"
  1599. + "SVRPEDRV" "Inventec Preinstall Environment Service" "Inventec Corporation" "c:\windows\system32\sysprep\pedrv.sys"
  1600. + "SynTP" "Synaptics Touchpad Driver" "Synaptics, Inc." "c:\windows\system32\drivers\syntp.sys"
  1601. + "taphss" "TAP-Win32 Virtual Network Driver" "AnchorFree Inc" "c:\windows\system32\drivers\taphss.sys"
  1602. + "tdcmdpst" "TOSHIBA ODD Writing Driver for x86." "TOSHIBA Corporation." "c:\windows\system32\drivers\tdcmdpst.sys"
  1603. + "tos_sps32" "tos_sps2" "TOSHIBA Corporation" "c:\windows\system32\drivers\tos_sps32.sys"
  1604. + "TVALZ" "TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver" "TOSHIBA Corporation" "c:\windows\system32\drivers\tvalz_o.sys"
  1605. + "USBAAPL" "Apple Mobile Device USB Driver" "Apple, Inc." "c:\windows\system32\drivers\usbaapl.sys"
  1606. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" ""
  1607. + "msacm.dvacm" "Ulead DV Audio ACM Driver" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\vio\dvacm.acm"
  1608. + "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\system32\l3codeca.acm"
  1609. + "msacm.vorbis" "Ogg Vorbis CODEC for MSACM" "HMS http://hp.vector.co.jp/authors/VA012897/" "c:\windows\system32\vorbis.acm"
  1610. + "vidc.cvid" "Cinepak® Codec" "Radius Inc." "c:\windows\system32\iccvid.dll"
  1611. + "vidc.i420" "" "" "File not found: lvcodec2.dll"
  1612. "HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" ""
  1613. + "9x8Resize" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1614. + "AAC Encoder" "AACEnc" "InterVider" "c:\program files\intervideo\common\bin\aacenc.ax"
  1615. + "Allocator Fix" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1616. + "Audio Source" "Windows Media Preview Object" "Microsoft Corporation" "c:\program files\windows media components\encoder\wmprevu.dll"
  1617. + "Bitmap" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1618. + "Capture ASF Writer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1619. + "Dib Output" "" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\filters\diboutput.ax"
  1620. + "Dib Receive" "" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\filters\dibreceive.ax"
  1621. + "DV ACM V/A Source Filter" "" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\filters\dvsf.ax"
  1622. + "DV V/A Source Filter" "" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\filters\dvsf.ax"
  1623. + "DV Video Source Filter" "" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\filters\dvsf.ax"
  1624. + "Frame Eater" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1625. + "Intervideo 3gFileSource" "Intervideo 3G File Source Filter" "Microsoft Corporation" "c:\program files\intervideo\common\bin\source3g.ax"
  1626. + "Intervideo 3gFileWrite" "Intervideo 3G File Write Filter" "Microsoft Corporation" "c:\program files\intervideo\common\bin\write3g.ax"
  1627. + "InterVideo AAC (XForm) Decoder" "InterVideo AAC Decoder" "InterVideo Inc." "c:\program files\intervideo\common\bin\iviaacdec.ax"
  1628. + "Intervideo AMR Decoder" "IVI AMR Decoding" "Intervideo, Inc." "c:\program files\intervideo\common\bin\amrdec.ax"
  1629. + "Intervideo AMR Encoder" "IVI AMR Encoding" "Intervideo, Inc." "c:\program files\intervideo\common\bin\amrenc.ax"
  1630. + "InterVideo Audio Encoder" "InterVideo?Audio Encoder Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\iviaenc.ax"
  1631. + "InterVideo Demux" "InterVideo® MPEG System Demultiplexer Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\ividemxx.ax"
  1632. + "InterVideo Down Scale Filter" "InterVideo® Down Scale Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\ividowns.ax"
  1633. + "InterVideo DV Pre-Process" "InterVideo DV Pre-Process Filter" "InterVideo" "c:\program files\intervideo\common\bin\dvprocs.ax"
  1634. + "InterVideo DVB DSM-CC Filter" "InterVideo DVB DSM-CC Decoder" "InterVideo, Inc." "c:\program files\intervideo\common\bin\dvbdsmcc.ax"
  1635. + "InterVideo DVB Subpicture Filter" "InterVideo DVB Subtitle Decoder" "InterVideo, Inc." "c:\program files\intervideo\common\bin\dvbspic.ax"
  1636. + "InterVideo File Writer" "InterVideo® File Writer Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\iviwrite.ax"
  1637. + "InterVideo MPEG4 Video Decoder" "InterVideo® MPEG4 Video Decoder Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\mp4vdec.ax"
  1638. + "InterVideo MPEG4 Video Encoder" "InterVideo® MPEG4 Video Encoder Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\mp4venc.ax"
  1639. + "InterVideo Multiplexer" "InterVideo® MPEG System Multiplexer Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\ivimux.ax"
  1640. + "InterVideo Pre-scaling Filter" "InterVideo® PreScale Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\iviscale.ax"
  1641. + "InterVideo PSIP/SI Filter" "InterVideo PSIP/SI Sections/Tables Filter" "InterVideo, Inc." "c:\program files\intervideo\common\bin\psidecod.ax"
  1642. + "InterVideo Still Capture" "InterVideo® Still Capture Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\iviscapt.ax"
  1643. + "InterVideo Stream Buffer Filter" "InterVideo Stream Buffer Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\smbuffer.ax"
  1644. + "InterVideo Stream Writer" "InterVideo© Stream File Writer" "InterVideo, Inc." "c:\program files\intervideo\common\bin\stmrite.ax"
  1645. + "InterVideo Time Shift" "InterVideo Time Shifting Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\ivits.ax"
  1646. + "InterVideo Transport to Program Stream" "InterVideo© Transport to Program Stream Converter" "InterVideo, Inc." "c:\program files\intervideo\common\bin\trtoprog.ax"
  1647. + "InterVideo VBI Decoder" "InterVideo VBI Decoder Filter" "InterVideo, Inc." "c:\program files\intervideo\common\bin\ivvbidec.ax"
  1648. + "InterVideo Video Encoder" "InterVideo® MPEG Video Encoder Filter" "InterVideo Inc." "c:\program files\intervideo\common\bin\ivivenc.ax"
  1649. + "MPEG2 TS Source" "" "" "c:\program files\intervideo\common\bin\mpgtsrdr.ax"
  1650. + "Multiple File Output" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1651. + "Proxy Sink" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1652. + "Proxy Source" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1653. + "Record Queue" "WME Record Queue" "Microsoft Corporation" "c:\program files\windows media components\encoder\wmedque.dll"
  1654. + "Record Queue" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1655. + "ShotDetect" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1656. + "Stetch" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1657. + "TOSHIBA Audio Decoder DVD" "TOSHIBA Audio Decoder DVD" "TOSHIBA Corporation" "c:\program files\toshiba\toshiba dvd player\tosauddecl.ax"
  1658. + "TOSHIBA Audio Rate Converter" "TOSHIBA Audio Rate Converter" "TOSHIBA Corporation" "c:\program files\common files\toshiba shared\tosarc.ax"
  1659. + "TOSHIBA DualMono" "TOSHIBA DualMono" "TOSHIBA Corporation" "c:\program files\common files\toshiba shared\tosdualmono.ax"
  1660. + "TOSHIBA DVD Navigator" "TOSHIBA DVD Navigator" "TOSHIBA Corporation" "c:\program files\toshiba\toshiba dvd player\tdvdnavi.ax"
  1661. + "TOSHIBA DVD VR Navigator" "TOSHIBA DVD Player" "TOSHIBA Corporation" "c:\program files\toshiba\toshiba dvd player\tvrnavi.ax"
  1662. + "TOSHIBA MPEG-2 Video Decoder (DVD)" "TOSHIBA DVD Video Decoder Filter" "TOSHIBA Corporation" "c:\program files\toshiba\toshiba dvd player\tosmp2dvd.ax"
  1663. + "TOSHIBA Progress Monitor" "TOSHIBA Progress Monitor" "TOSHIBA Corporation" "c:\program files\toshiba\toshiba disc creator\tprogmon.ax"
  1664. + "TOSHIBA WAV Converter" "TOSHIBA Wav Converter" "TOSHIBA Corporation" "c:\program files\toshiba\toshiba disc creator\twavconv.ax"
  1665. + "Ulead Audio Dual Channel Filter" "Ulead Audio Dual Channel Filter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uaudiodcfilter.ax"
  1666. + "Ulead DV Scene Detect" "ulDvScDt" "Ulead system Inc." "c:\program files\common files\ulead systems\capture\uldvscdt.ax"
  1667. + "Ulead DV Writer" "ulDVWriter" "Ulead System Inc." "c:\program files\common files\ulead systems\capture\uldvrite.ax"
  1668. + "Ulead DVB Parser" "Ulead DVB Parser Filter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uldvbparser.ax"
  1669. + "Ulead DVD Audio Decoder 2" "Audio Decoder" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uldvdaudio.ax"
  1670. + "Ulead DVD Navigator" "DVD Navigator filter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\dvd\uleaddvdnavigator.ax"
  1671. + "Ulead DVD Video decoder 2" "DVD Video Decoder with DxVA Support" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uldvdvideo.ax"
  1672. + "ULead File Source (Async.)" "Ulead Async Filter" "Ulead Systems" "c:\program files\common files\ulead systems\mpeg\ulasync.ax"
  1673. + "ULead File Writer" "File Dump Filter" "ULead Systems" "c:\program files\common files\ulead systems\filters\uldump.ax"
  1674. + "ULead Infinite Pin Tee" "Ulead Infinite Tee Filter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uinftee.ax"
  1675. + "Ulead MPEG Audio Decoder" "Audio Decoder" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uldvdaudio.ax"
  1676. + "Ulead MPEG Encoder" "MPEG Encoder and Muxer" "ULead Systems" "c:\program files\common files\ulead systems\mpeg\ulesmpeg.ax"
  1677. + "Ulead MPEG Muxer" "MPEG Muxer" "ULead Systems" "c:\program files\common files\ulead systems\mpeg\ulmxmpeg.ax"
  1678. + "Ulead MPEG Splitter" "ULead Mpeg I/II Splitter" "ULead Systems" "c:\program files\common files\ulead systems\mpeg\ulspmpeg.ax"
  1679. + "Ulead MPEG Transcoder" "ulMPGTrans" "Ulead com" "c:\program files\common files\ulead systems\mpeg\ulmpgtrans.ax"
  1680. + "Ulead MPEG Video Decoder" "MPEG Video and Audio Decoder" "ULead Systems" "c:\program files\common files\ulead systems\mpeg\uldsmpeg.ax"
  1681. + "Ulead MPEG-4 Audio Decoder" "MP4 AAC Audio Decoder Filter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uladmp4.ax"
  1682. + "Ulead MPEG-4 Splitter" "MP4 Splitter Filter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\ulspmp4.ax"
  1683. + "Ulead MPEG-4 Video Decoder" "MP4 Video Decoder Filter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\ulvdmp4.ax"
  1684. + "Ulead Ogg Parser" "ulOggParserFilter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uloggparserfilter.ax"
  1685. + "Ulead OggVorbis Decoder" "ulOggVorbisDecoderFilter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uloggvorbisdecoderfilter.ax"
  1686. + "Ulead OggVorbis Encoder" "ulOggVorbisEncoderFilter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\uloggvorbisencoderfilter.ax"
  1687. + "Ulead Push Source Filter" "Ulead Push Source Filter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\ulpushsource.ax"
  1688. + "Ulead Sub-Picture Push Source Filter" "Ulead Sub-Picture Push Source Filter" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\mpeg\ulsubpicpushsource.ax"
  1689. + "Ulead Video Deinterlace Filter" "" "Ulead Systems, Inc." "c:\program files\common files\ulead systems\filters\deinterlace.ax"
  1690. + "Video Source" "Windows Media Preview Object" "Microsoft Corporation" "c:\program files\windows media components\encoder\wmprevu.dll"
  1691. + "WM VIH2 Fix" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1692. + "WMEnc Screen Capture Filter" "WMESrcWp Module" "Microsoft Corporation" "c:\program files\windows media components\encoder\wmesrcwp.dll"
  1693. + "WMT Audio Analyzer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1694. + "WMT Black Frame Generator" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1695. + "WMT DV Extract Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1696. + "WMT FormatConversion" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1697. + "WMT Import Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1698. + "WMT Interlacer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1699. + "WMT Log Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1700. + "WMT MuxDeMux Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1701. + "WMT Sample Info Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1702. + "WMT Switch Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1703. + "WMT Virtual Renderer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1704. + "WMT Virtual Source" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1705. + "WMT Volume" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
  1706. "HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute" "" "" ""
  1707. + "C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync" "AVG Cache Server" "AVG Technologies CZ, s.r.o." "c:\program files\avg\avg10\avgchsvx.exe"
  1708. + "C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart" "AVG Resident Shield Service" "AVG Technologies CZ, s.r.o." "c:\program files\avg\avg10\avgrsx.exe"
  1709. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls" "" "" ""
  1710. + "C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll" "" "" "File not found: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll"
  1711. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify" "" "" ""
  1712. + "igfxcui" "igfxdev Module" "Intel Corporation" "c:\windows\system32\igfxdev.dll"
  1713. "HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries" "" "" ""
  1714. + "mdnsNSP" "Bonjour Namespace Provider" "Apple Inc." "c:\program files\bonjour\mdnsnsp.dll"
  1715. "HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors" "" "" ""
  1716. + "Canon BJ Language Monitor MP240 series" "IJ Language Monitor" "CANON INC." "c:\windows\system32\cnmlm9h.dll"
  1717. + "Fax Dell V505 Port" "Print Monitor (Win2k/WinXP)" "" "c:\windows\system32\dldwpmon.dll"
  1718. + "V505 Port" "Printer Communication System" " " "c:\windows\system32\dldwlmpm.dll"
  1719. "C:\Users\Oni\AppData\Local\Microsoft\Windows Sidebar\Settings.ini" "" "" ""
  1720. + "Clock" "Watch the clock in your own time zone or any city in the world." "Microsoft Corporation" "C:\Program Files\windows sidebar\gadgets\Clock.gadget\en-US\Gadget.xml"
  1721. + "Feed Headlines" "Track the latest news, sports, and entertainment headlines." "Microsoft Corporation" "C:\Program Files\windows sidebar\gadgets\RSSFeeds.Gadget\en-US\Gadget.xml"
  1722. + "Slide Show" "Show a continuous slide show of your pictures." "Microsoft Corporation" "C:\Program Files\windows sidebar\gadgets\SlideShow.Gadget\en-US\Gadget.xml"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement