Hello everyone at GeekPolice, first let me introduce myself. I am BuffyAnimated this is a pretty cool site and I am very excited by finding it and learning more from others. The GeekPolice Academy sounds pretty awesome. I would like to learn more about it later after I get my current problem out of the way. I am currently posting these logs to the forum from my Windows XP Computer, but my Windows 7 Computer is the one which is infected with the Trojan. It can startup fine however, and I wouldn't have known I had a virus if it wasn't for scanning it.
Now to get to my problem I am having, I have AVG 2013 installed on my Windows 7 (64-bit Pc) It gave me back some suspicious results that it never displayed before while running a scan in, "Safe Mode" Below are those results, it said a lot of my files including "My Documents, Pictures, Videos " were locked and could not be tested. Which is unusual and never happened in the past to me while running a AVG scan in Safemode.
------------------------------------------------------------
Test started: 6.7.2013 4:14:30
Duration of test: 50 minute(s) 59 second(s)
------------------------------------------------------------
Objects scanned : 280837
Found infections : 656
Found high severity : 0
Found med severity : 0
Found info severity : 656
Fixed high severity : 0
Fixed med severity : 0
Fixed info severity : 0
------------------------------------------------------------
The other thing it did was told me it found " Info Severity " infections.
I looked into the AVG Manual and it told me, " Information Severity: Information or warnings, not real threats. Typically documents containing Macros, Documents or Archives Protected by a pssword, locked files, ect. " So, still being curious as to why these are showing up now when they never showed up before I ran the " Windows Defender " Virus scan which came with Windows 7.
It told me, " Trojan:Win32/Sirefef.AB Alert Level Severe, this program is dangerous and executes commands from an attacker.
Resources: File: C:\Windows\assembly\GAC_32\ "However, when I clicked to remove the Virus it said it had been removed, I re-ran the scan after a restart and it found the same Virus.
Below are the Scan Logs from what I read in the " Read this Before Posting " Section of this forum.
----
AWCLEANER SCAN LOG.
----
# AdwCleaner v2.304 - Logfile created 07/06/2013 at 13:06:33
# Updated 03/07/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : B-Websites - FAMILY-PC
# Boot Mode : Normal
# Running from : C:\Users\B-Websites\Downloads\fix_xp\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search
File Deleted : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\ox1380kb.default\searchplugins\CouponAlert_2p.xml
File Deleted : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\ox1380kb.default\searchplugins\mywebsearch.xml
File Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\searchplugins\Conduit.xml
File Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\searchplugins\CouponAlert_2p.xml
File Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\searchplugins\MyStart Search.xml
File Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\searchplugins\mywebsearch.xml
Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Users\Administrator\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\B-Websites\AppData\Local\APN
Folder Deleted : C:\Users\B-Websites\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\CouponAlert_2p
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\B-Websites\Documents\DealRunner
Folder Deleted : C:\Users\ginzu\AppData\Local\APN
Folder Deleted : C:\Users\ginzu\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\CouponAlert_2p
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\IncrediMail_MediaBar_2
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\GM Project\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\M\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\M\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\M\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\M\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\M\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\M\AppData\LocalLow\CouponAlert_2p
Folder Deleted : C:\Users\M\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\M\AppData\LocalLow\IncrediMail_MediaBar_2
Folder Deleted : C:\Users\M\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\Sis\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Sis\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Sis\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Sis\AppData\LocalLow\CouponAlert_2p
Folder Deleted : C:\Users\Sis\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\Sis\AppData\LocalLow\IncrediMail_MediaBar_2
Folder Deleted : C:\Users\Sis\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\Conduit
Folder Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\CT2724386
Folder Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}
***** [Registry] *****
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine
Key Deleted : HKCU\Software\AppDataLow\Software\CouponAlert_2p
Key Deleted : HKCU\Software\AppDataLow\Software\Fun Web Products
Key Deleted : HKCU\Software\AppDataLow\Software\FunWebProducts
Key Deleted : HKCU\Software\AppDataLow\Software\IncrediMail_MediaBar_2
Key Deleted : HKCU\Software\AppDataLow\Software\MyWebSearch
Key Deleted : HKCU\Software\AppDataLow\Software\Toolbar
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2559647
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2724386
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FFDF636-0D87-4B33-B9E9-79A53F6E1DAE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C7E7FB02-C4FD-446E-8F5B-463A049935BF}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\Software\ImInstaller
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{004EB151-885B-4A9E-A22D-CA98DD998D75}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{21D9997E-5D2A-4737-BCBA-C958C0590295}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5F701D7D-C869-41F0-B0E2-8136F02B539C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A786F51D-B3C7-4F52-91EF-E1A892C2A2AE}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC4DAE-7794-4E16-9A98-F6001303DCD0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EAB77009-B974-48DF-8229-E70CFAA11C69}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EBAA6283-B61F-4DDD-9659-56635433A307}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFB4F034-3EB5-48D5-84DD-89BBCF9A182F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16FE2505-F2A0-4782-B035-AF0E5188C02C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2AF08E71-3657-462F-898C-F7E791948F94}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56965DCF-718F-4148-BECF-5A2B466F4556}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F99D2AE-5C90-43C2-A2FE-81DBE512E2FC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7225F6C9-CF64-4D6D-AE8A-169779FD7B4D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{004EB151-885B-4A9E-A22D-CA98DD998D75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{21D9997E-5D2A-4737-BCBA-C958C0590295}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5F701D7D-C869-41F0-B0E2-8136F02B539C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A786F51D-B3C7-4F52-91EF-E1A892C2A2AE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC4DAE-7794-4E16-9A98-F6001303DCD0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAB77009-B974-48DF-8229-E70CFAA11C69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EBAA6283-B61F-4DDD-9659-56635433A307}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFB4F034-3EB5-48D5-84DD-89BBCF9A182F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [m3ffxtbr@mywebsearch.com]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
***** [Internet Browsers] *****
-\\ Internet Explorer v10.0.9200.16611
[OK] Registry is clean.
-\\ Mozilla Firefox v20.0.1 (en-US)
File : C:\Users\B-Websites\AppData\Roaming\Mozilla\Firefox\Profiles\cyhw0vo6.default\prefs.js
C:\Users\B-Websites\AppData\Roaming\Mozilla\Firefox\Profiles\cyhw0vo6.default\user.js ... Deleted !
Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("extensions.CouponAlert_2p.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/open[...]
Deleted : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid={F09576C6-1C26-4A31-A7C3-5C94875AFD88}&m[...]
File : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\prefs.js
Deleted : user_pref("CT2559647..clientLogIsEnabled", true);
Deleted : user_pref("CT2559647..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2559647..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2559647.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2559647.AppTrackingLastCheckTime", "Sun May 22 2011 13:23:07 GMT-0600 (Central America [...]
Deleted : user_pref("CT2559647.CTID", "CT2559647");
Deleted : user_pref("CT2559647.CurrentServerDate", "22-5-2011");
Deleted : user_pref("CT2559647.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2559647.DialogsGetterLastCheckTime", "Thu Apr 07 2011 05:40:47 GMT-0600 (Central Americ[...]
Deleted : user_pref("CT2559647.DownloadReferralCookieData", "");
Deleted : user_pref("CT2559647.ExternalComponentPollDate129404749084494749", "Sun May 22 2011 13:53:02 GMT-060[...]
Deleted : user_pref("CT2559647.ExternalComponentPollDate129404791544181654", "Sun May 22 2011 13:53:02 GMT-060[...]
Deleted : user_pref("CT2559647.ExternalComponentPollDate129413165572169584", "Sun May 22 2011 13:53:02 GMT-060[...]
Deleted : user_pref("CT2559647.FirstServerDate", "7-4-2011");
Deleted : user_pref("CT2559647.FirstTime", true);
Deleted : user_pref("CT2559647.FirstTimeFF3", true);
Deleted : user_pref("CT2559647.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2559647.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2559647.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2559647.HasUserGlobalKeys", true);
Deleted : user_pref("CT2559647.Initialize", true);
Deleted : user_pref("CT2559647.InitializeCommonPrefs", true);
Deleted : user_pref("CT2559647.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2559647.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2559647.InstalledDate", "Thu Apr 07 2011 05:40:47 GMT-0600 (Central America Standard Ti[...]
Deleted : user_pref("CT2559647.IsGrouping", false);
Deleted : user_pref("CT2559647.IsMulticommunity", false);
Deleted : user_pref("CT2559647.IsOpenThankYouPage", false);
Deleted : user_pref("CT2559647.IsOpenUninstallPage", false);
Deleted : user_pref("CT2559647.LanguagePackLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central America[...]
Deleted : user_pref("CT2559647.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2559647.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2559647.LastLogin_3.3.3.2", "Sun May 22 2011 13:22:53 GMT-0600 (Central America Standar[...]
Deleted : user_pref("CT2559647.LatestVersion", "3.3.3.2");
Deleted : user_pref("CT2559647.Locale", "en");
Deleted : user_pref("CT2559647.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2559647.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2559647.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2559647.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2559647.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2559647.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT255[...]
Deleted : user_pref("CT2559647.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2559647.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2559647.SearchInNewTabLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central Ameri[...]
Deleted : user_pref("CT2559647.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2559647.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2559647.ServiceMapLastCheckTime", "Sun May 22 2011 13:23:02 GMT-0600 (Central America S[...]
Deleted : user_pref("CT2559647.SettingsLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central America Sta[...]
Deleted : user_pref("CT2559647.SettingsLastUpdate", "1304242869");
Deleted : user_pref("CT2559647.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2559647.ThirdPartyComponentsLastCheck", "Sun May 22 2011 13:22:53 GMT-0600 (Central Ame[...]
Deleted : user_pref("CT2559647.ThirdPartyComponentsLastUpdate", "1246786978");
Deleted : user_pref("CT2559647.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2559647");
Deleted : user_pref("CT2559647.Uninstall", true);
Deleted : user_pref("CT2559647.UserID", "UN93731113908383962");
Deleted : user_pref("CT2559647.ValidationData_Search", 2);
Deleted : user_pref("CT2559647.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2559647.alertChannelId", "952537");
Deleted : user_pref("CT2559647.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Deleted : user_pref("CT2559647.globalFirstTimeInfoLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central [...]
Deleted : user_pref("CT2559647.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2559647.myStuffEnabled", true);
Deleted : user_pref("CT2559647.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2559647.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2559647.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2559647.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2559647.oldAppsList", "129126535051871363,129126535052027614,129404749084494749,1294047[...]
Deleted : user_pref("CT2559647.testingCtid", "");
Deleted : user_pref("CT2559647.toolbarAppMetaDataLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central A[...]
Deleted : user_pref("CT2559647.toolbarContextMenuLastCheckTime", "Thu Apr 07 2011 05:40:48 GMT-0600 (Central A[...]
Deleted : user_pref("CT2559647.usagesFlag", 2);
Deleted : user_pref("CT2724386.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2724386.CT2724407.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2724431.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727162.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727622.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727646.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727678.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727750.CommunityChanged", true);
Deleted : user_pref("CT2724386.CTID", "ct2724386");
Deleted : user_pref("CT2724386.CommunitiesChangesLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central A[...]
Deleted : user_pref("CT2724386.CommunityChanged", true);
Deleted : user_pref("CT2724386.CurrentServerDate", "27-1-2011");
Deleted : user_pref("CT2724386.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2724386.DownloadReferralCookieData", "");
Deleted : user_pref("CT2724386.FirstServerDate", "16-1-2011");
Deleted : user_pref("CT2724386.FirstTime", true);
Deleted : user_pref("CT2724386.FirstTimeFF3", true);
Deleted : user_pref("CT2724386.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2724386.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2724386.GroupingLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central America Sta[...]
Deleted : user_pref("CT2724386.GroupingLastErrorCode", "");
Deleted : user_pref("CT2724386.GroupingLastResponse", true);
Deleted : user_pref("CT2724386.GroupingLastServerUpdateTime", "129404259370830000");
Deleted : user_pref("CT2724386.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2724386.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2724386.Initialize", true);
Deleted : user_pref("CT2724386.InitializeCommonPrefs", true);
Deleted : user_pref("CT2724386.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2724386.InstallationId", "IncrediMail_MediaBar_2.exe");
Deleted : user_pref("CT2724386.InstallationType", "ConduitIntegration");
Deleted : user_pref("CT2724386.InstalledDate", "Sat Jan 15 2011 22:39:56 GMT-0600 (Central America Standard Ti[...]
Deleted : user_pref("CT2724386.IsGrouping", true);
Deleted : user_pref("CT2724386.IsMulticommunity", false);
Deleted : user_pref("CT2724386.IsOpenThankYouPage", false);
Deleted : user_pref("CT2724386.IsOpenUninstallPage", true);
Deleted : user_pref("CT2724386.LanguagePackLastCheckTime", "Sat Jan 15 2011 22:39:58 GMT-0600 (Central America[...]
Deleted : user_pref("CT2724386.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2724386.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2724386.LastLogin_2.7.2.0", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central America Standar[...]
Deleted : user_pref("CT2724386.LatestVersion", "3.2.5.2");
Deleted : user_pref("CT2724386.Locale", "en");
Deleted : user_pref("CT2724386.LoginCache", 4);
Deleted : user_pref("CT2724386.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2724386.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2724386.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2724386.RadioIsPodcast", false);
Deleted : user_pref("CT2724386.RadioMediaID", "21080102");
Deleted : user_pref("CT2724386.RadioMediaType", "Media Player");
Deleted : user_pref("CT2724386.RadioMenuSelectedID", "EBRadioMenu_CT272438621080102");
Deleted : user_pref("CT2724386.RadioStationName", "Mix%201620%20Am");
Deleted : user_pref("CT2724386.RadioStationURL", "hxxp://69.115.65.9:8000");
Deleted : user_pref("CT2724386.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2724386.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2724386.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT272[...]
Deleted : user_pref("CT2724386.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2724386.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2724386.SearchInNewTabLastCheckTime", "Sat Jan 15 2011 22:39:57 GMT-0600 (Central Ameri[...]
Deleted : user_pref("CT2724386.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2724386.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2724386.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2724386.SettingsLastCheckTime", "Sat Jan 15 2011 22:39:55 GMT-0600 (Central America Sta[...]
Deleted : user_pref("CT2724386.SettingsLastUpdate", "1294298391");
Deleted : user_pref("CT2724386.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2724386.ThirdPartyComponentsLastCheck", "Sat Jan 15 2011 22:39:55 GMT-0600 (Central Ame[...]
Deleted : user_pref("CT2724386.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT2724386.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Deleted : user_pref("CT2724386.UserID", "UN09292349458301119");
Deleted : user_pref("CT2724386.ValidationData_Toolbar", 1);
Deleted : user_pref("CT2724386.WeatherNetwork", "");
Deleted : user_pref("CT2724386.WeatherPollDate", "Thu Jan 27 2011 02:13:14 GMT-0600 (Central America Standard [...]
Deleted : user_pref("CT2724386.WeatherUnit", "C");
Deleted : user_pref("CT2724386.clientLogIsEnabled", false);
Deleted : user_pref("CT2724386.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2724386.ct2724386.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2724386.ct2724386.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2724386.ct2724386.GroupingInvalidateCache", false);
Deleted : user_pref("CT2724386.ct2724386.GroupingLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central A[...]
Deleted : user_pref("CT2724386.ct2724386.GroupingLastErrorCode", "");
Deleted : user_pref("CT2724386.ct2724386.GroupingLastResponse", true);
Deleted : user_pref("CT2724386.ct2724386.GroupingLastServerUpdateTime", "129404259370830000");
Deleted : user_pref("CT2724386.ct2724386.InvalidateCache", false);
Deleted : user_pref("CT2724386.ct2724386.LanguagePackLastCheckTime", "Thu Jan 27 2011 01:43:13 GMT-0600 (Centr[...]
Deleted : user_pref("CT2724386.ct2724386.Locale", "en");
Deleted : user_pref("CT2724386.ct2724386.RadioLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central Amer[...]
Deleted : user_pref("CT2724386.ct2724386.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2724386.ct2724386.RadioLastUpdateServer", "129249036863500000");
Deleted : user_pref("CT2724386.ct2724386.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_[...]
Deleted : user_pref("CT2724386.ct2724386.SearchInNewTabLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Cen[...]
Deleted : user_pref("CT2724386.ct2724386.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2724386.ct2724386.SettingsLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central A[...]
Deleted : user_pref("CT2724386.ct2724386.SettingsLastUpdate", "1294298391");
Deleted : user_pref("CT2724386.ct2724386.ThirdPartyComponentsLastCheck", "Sat Jan 15 2011 22:39:56 GMT-0600 (C[...]
Deleted : user_pref("CT2724386.ct2724386.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT2724386.myStuffEnabled", true);
Deleted : user_pref("CT2724386.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2724386.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2724386.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2724386.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2724386.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/952537/948310/US", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2559647", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2559647",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2559647/CT2559647[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634[...]
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://mystart.incredimail.com/?loc=ff_a[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2724386,CT2559647");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2724386,CT2559647");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Thu Apr 07 2011 05:40:47 GMT-06[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun May 22 2011 13:23:01 GMT-0600 (Centr[...]
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central A[...]
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "20498835-bc99-45af-bbae-808b387d9a8b");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Cen[...]
Deleted : user_pref("CommunityToolbar.globalUserId", "c8150399-a995-4940-b00d-d5d378cdee16");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2559647");
Deleted : user_pref("browser.search.defaultthis.engineName", "Coupons.com Customized Web Search");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2559647&Sea[...]
Deleted : user_pref("browser.startup.homepage", "hxxp://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=CDxd[...]
Deleted : user_pref("extensions.CouponAlert_2p.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/open[...]
Deleted : user_pref("extensions.CouponAlert_2p.prevKwdURL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.[...]
Deleted : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensea[...]
Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://mystart.incredimail.com/?loc=ff_address_bar&a[...]
Deleted : user_pref("extensions.sahtb.url.merchants.data", " Deleted : user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZKxdm4897HUS&ptb[...]
File : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\ox1380kb.default\prefs.js
Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
Deleted : user_pref("extensions.CouponAlert_2p.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/open[...]
Deleted : user_pref("extensions.CouponAlert_2p.prevKwdURL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.[...]
Deleted : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensea[...]
Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "chrome://browser-region/locale/region.properties");
Deleted : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid={F09576C6-1C26-4A31-A7C3-5C94875AFD88}&m[...]
File : C:\Users\ginzu\AppData\Roaming\Mozilla\Firefox\Profiles\ncyxn3nj.default\prefs.js
Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid={F09576C6-1C26-4A31-A7C3-5C94875AFD88}&m[...]
File : C:\Users\GM Project\AppData\Roaming\Mozilla\Firefox\Profiles\mu58k4ht.default\prefs.js
[OK] File is clean.
-\\ Google Chrome v28.0.1500.71
File : C:\Users\B-Websites\AppData\Local\Google\Chrome\User Data\Default\Preferences
Deleted [l.2392] : homepage = "hxxp://isearch.avg.com/?cid={BF846267-4F53-4CFD-B454-41C763C17A96}&mid=75c6c48021bf4[...]
File : C:\Users\Sis\AppData\Local\Google\Chrome\User Data\Default\Preferences
Deleted [l.2252] : homepage = "hxxp://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=CDxdm014YYus&ptb=6E3149F0-B[...]
Deleted [l.2889] : urls_to_restore_on_startup = [ "hxxp://www.hotmail.com/?rru=inbox", "hxxp://doctoroz.com/", "[...]
File : C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
File : C:\Users\ginzu\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
File : C:\Users\GM Project\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [36611 octets] - [06/07/2013 12:37:46]
AdwCleaner[S1].txt - [37069 octets] - [06/07/2013 13:06:33]
########## EOF - C:\AdwCleaner[S1].txt - [37130 octets] ##########
----
====
FOR SOME UNKNOWN REASON I COULD NOT GET MBAM TO DOWNLOAD FROM THIS FORUM SHOULD I DOWNLOAD IT FROM ANOTHER WEBSITE SUCH AS WWW.DOWNLOADS.COM?
====
====
SECURITY CHECK LOG FILE.
====
Results of screen317's Security Check version 0.99.68
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2013
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
JavaFX 2.1.1
Java(TM) 6 Update 29
Java(TM) 7 Update 5
Java version out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox 20.0.1 Firefox out of Date!
Google Chrome 28.0.1500.63
Google Chrome 28.0.1500.71
````````Process Check: objlist.exe by Laurent````````
AVG avgwdsvc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
Now to get to my problem I am having, I have AVG 2013 installed on my Windows 7 (64-bit Pc) It gave me back some suspicious results that it never displayed before while running a scan in, "Safe Mode" Below are those results, it said a lot of my files including "My Documents, Pictures, Videos " were locked and could not be tested. Which is unusual and never happened in the past to me while running a AVG scan in Safemode.
------------------------------------------------------------
Test started: 6.7.2013 4:14:30
Duration of test: 50 minute(s) 59 second(s)
------------------------------------------------------------
Objects scanned : 280837
Found infections : 656
Found high severity : 0
Found med severity : 0
Found info severity : 656
Fixed high severity : 0
Fixed med severity : 0
Fixed info severity : 0
------------------------------------------------------------
The other thing it did was told me it found " Info Severity " infections.
I looked into the AVG Manual and it told me, " Information Severity: Information or warnings, not real threats. Typically documents containing Macros, Documents or Archives Protected by a pssword, locked files, ect. " So, still being curious as to why these are showing up now when they never showed up before I ran the " Windows Defender " Virus scan which came with Windows 7.
It told me, " Trojan:Win32/Sirefef.AB Alert Level Severe, this program is dangerous and executes commands from an attacker.
Resources: File: C:\Windows\assembly\GAC_32\ "However, when I clicked to remove the Virus it said it had been removed, I re-ran the scan after a restart and it found the same Virus.
Below are the Scan Logs from what I read in the " Read this Before Posting " Section of this forum.
----
AWCLEANER SCAN LOG.
----
# AdwCleaner v2.304 - Logfile created 07/06/2013 at 13:06:33
# Updated 03/07/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : B-Websites - FAMILY-PC
# Boot Mode : Normal
# Running from : C:\Users\B-Websites\Downloads\fix_xp\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search
File Deleted : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\ox1380kb.default\searchplugins\CouponAlert_2p.xml
File Deleted : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\ox1380kb.default\searchplugins\mywebsearch.xml
File Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\searchplugins\Conduit.xml
File Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\searchplugins\CouponAlert_2p.xml
File Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\searchplugins\MyStart Search.xml
File Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\searchplugins\mywebsearch.xml
Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Users\Administrator\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\B-Websites\AppData\Local\APN
Folder Deleted : C:\Users\B-Websites\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\CouponAlert_2p
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\B-Websites\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\B-Websites\Documents\DealRunner
Folder Deleted : C:\Users\ginzu\AppData\Local\APN
Folder Deleted : C:\Users\ginzu\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\CouponAlert_2p
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\IncrediMail_MediaBar_2
Folder Deleted : C:\Users\ginzu\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\GM Project\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\M\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\M\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\M\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\M\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\M\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\M\AppData\LocalLow\CouponAlert_2p
Folder Deleted : C:\Users\M\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\M\AppData\LocalLow\IncrediMail_MediaBar_2
Folder Deleted : C:\Users\M\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\Sis\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Sis\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Sis\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Sis\AppData\LocalLow\CouponAlert_2p
Folder Deleted : C:\Users\Sis\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\Sis\AppData\LocalLow\IncrediMail_MediaBar_2
Folder Deleted : C:\Users\Sis\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\Conduit
Folder Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\CT2724386
Folder Deleted : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}
***** [Registry] *****
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine
Key Deleted : HKCU\Software\AppDataLow\Software\CouponAlert_2p
Key Deleted : HKCU\Software\AppDataLow\Software\Fun Web Products
Key Deleted : HKCU\Software\AppDataLow\Software\FunWebProducts
Key Deleted : HKCU\Software\AppDataLow\Software\IncrediMail_MediaBar_2
Key Deleted : HKCU\Software\AppDataLow\Software\MyWebSearch
Key Deleted : HKCU\Software\AppDataLow\Software\Toolbar
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2559647
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2724386
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FFDF636-0D87-4B33-B9E9-79A53F6E1DAE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C7E7FB02-C4FD-446E-8F5B-463A049935BF}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\Software\ImInstaller
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{004EB151-885B-4A9E-A22D-CA98DD998D75}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{21D9997E-5D2A-4737-BCBA-C958C0590295}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5F701D7D-C869-41F0-B0E2-8136F02B539C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A786F51D-B3C7-4F52-91EF-E1A892C2A2AE}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC4DAE-7794-4E16-9A98-F6001303DCD0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EAB77009-B974-48DF-8229-E70CFAA11C69}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EBAA6283-B61F-4DDD-9659-56635433A307}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFB4F034-3EB5-48D5-84DD-89BBCF9A182F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16FE2505-F2A0-4782-B035-AF0E5188C02C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2AF08E71-3657-462F-898C-F7E791948F94}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56965DCF-718F-4148-BECF-5A2B466F4556}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F99D2AE-5C90-43C2-A2FE-81DBE512E2FC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7225F6C9-CF64-4D6D-AE8A-169779FD7B4D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{004EB151-885B-4A9E-A22D-CA98DD998D75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{21D9997E-5D2A-4737-BCBA-C958C0590295}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5F701D7D-C869-41F0-B0E2-8136F02B539C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A786F51D-B3C7-4F52-91EF-E1A892C2A2AE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC4DAE-7794-4E16-9A98-F6001303DCD0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAB77009-B974-48DF-8229-E70CFAA11C69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EBAA6283-B61F-4DDD-9659-56635433A307}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFB4F034-3EB5-48D5-84DD-89BBCF9A182F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [m3ffxtbr@mywebsearch.com]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
***** [Internet Browsers] *****
-\\ Internet Explorer v10.0.9200.16611
[OK] Registry is clean.
-\\ Mozilla Firefox v20.0.1 (en-US)
File : C:\Users\B-Websites\AppData\Roaming\Mozilla\Firefox\Profiles\cyhw0vo6.default\prefs.js
C:\Users\B-Websites\AppData\Roaming\Mozilla\Firefox\Profiles\cyhw0vo6.default\user.js ... Deleted !
Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("extensions.CouponAlert_2p.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/open[...]
Deleted : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid={F09576C6-1C26-4A31-A7C3-5C94875AFD88}&m[...]
File : C:\Users\Sis\AppData\Roaming\Mozilla\Firefox\Profiles\8mxyghj3.default\prefs.js
Deleted : user_pref("CT2559647..clientLogIsEnabled", true);
Deleted : user_pref("CT2559647..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2559647..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2559647.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2559647.AppTrackingLastCheckTime", "Sun May 22 2011 13:23:07 GMT-0600 (Central America [...]
Deleted : user_pref("CT2559647.CTID", "CT2559647");
Deleted : user_pref("CT2559647.CurrentServerDate", "22-5-2011");
Deleted : user_pref("CT2559647.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2559647.DialogsGetterLastCheckTime", "Thu Apr 07 2011 05:40:47 GMT-0600 (Central Americ[...]
Deleted : user_pref("CT2559647.DownloadReferralCookieData", "");
Deleted : user_pref("CT2559647.ExternalComponentPollDate129404749084494749", "Sun May 22 2011 13:53:02 GMT-060[...]
Deleted : user_pref("CT2559647.ExternalComponentPollDate129404791544181654", "Sun May 22 2011 13:53:02 GMT-060[...]
Deleted : user_pref("CT2559647.ExternalComponentPollDate129413165572169584", "Sun May 22 2011 13:53:02 GMT-060[...]
Deleted : user_pref("CT2559647.FirstServerDate", "7-4-2011");
Deleted : user_pref("CT2559647.FirstTime", true);
Deleted : user_pref("CT2559647.FirstTimeFF3", true);
Deleted : user_pref("CT2559647.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2559647.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2559647.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2559647.HasUserGlobalKeys", true);
Deleted : user_pref("CT2559647.Initialize", true);
Deleted : user_pref("CT2559647.InitializeCommonPrefs", true);
Deleted : user_pref("CT2559647.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2559647.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2559647.InstalledDate", "Thu Apr 07 2011 05:40:47 GMT-0600 (Central America Standard Ti[...]
Deleted : user_pref("CT2559647.IsGrouping", false);
Deleted : user_pref("CT2559647.IsMulticommunity", false);
Deleted : user_pref("CT2559647.IsOpenThankYouPage", false);
Deleted : user_pref("CT2559647.IsOpenUninstallPage", false);
Deleted : user_pref("CT2559647.LanguagePackLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central America[...]
Deleted : user_pref("CT2559647.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2559647.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2559647.LastLogin_3.3.3.2", "Sun May 22 2011 13:22:53 GMT-0600 (Central America Standar[...]
Deleted : user_pref("CT2559647.LatestVersion", "3.3.3.2");
Deleted : user_pref("CT2559647.Locale", "en");
Deleted : user_pref("CT2559647.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2559647.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2559647.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2559647.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2559647.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2559647.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT255[...]
Deleted : user_pref("CT2559647.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2559647.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2559647.SearchInNewTabLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central Ameri[...]
Deleted : user_pref("CT2559647.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2559647.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2559647.ServiceMapLastCheckTime", "Sun May 22 2011 13:23:02 GMT-0600 (Central America S[...]
Deleted : user_pref("CT2559647.SettingsLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central America Sta[...]
Deleted : user_pref("CT2559647.SettingsLastUpdate", "1304242869");
Deleted : user_pref("CT2559647.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2559647.ThirdPartyComponentsLastCheck", "Sun May 22 2011 13:22:53 GMT-0600 (Central Ame[...]
Deleted : user_pref("CT2559647.ThirdPartyComponentsLastUpdate", "1246786978");
Deleted : user_pref("CT2559647.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2559647");
Deleted : user_pref("CT2559647.Uninstall", true);
Deleted : user_pref("CT2559647.UserID", "UN93731113908383962");
Deleted : user_pref("CT2559647.ValidationData_Search", 2);
Deleted : user_pref("CT2559647.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2559647.alertChannelId", "952537");
Deleted : user_pref("CT2559647.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Deleted : user_pref("CT2559647.globalFirstTimeInfoLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central [...]
Deleted : user_pref("CT2559647.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2559647.myStuffEnabled", true);
Deleted : user_pref("CT2559647.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2559647.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2559647.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2559647.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2559647.oldAppsList", "129126535051871363,129126535052027614,129404749084494749,1294047[...]
Deleted : user_pref("CT2559647.testingCtid", "");
Deleted : user_pref("CT2559647.toolbarAppMetaDataLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central A[...]
Deleted : user_pref("CT2559647.toolbarContextMenuLastCheckTime", "Thu Apr 07 2011 05:40:48 GMT-0600 (Central A[...]
Deleted : user_pref("CT2559647.usagesFlag", 2);
Deleted : user_pref("CT2724386.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2724386.CT2724407.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2724431.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727162.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727622.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727646.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727678.CommunityChanged", true);
Deleted : user_pref("CT2724386.CT2727750.CommunityChanged", true);
Deleted : user_pref("CT2724386.CTID", "ct2724386");
Deleted : user_pref("CT2724386.CommunitiesChangesLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central A[...]
Deleted : user_pref("CT2724386.CommunityChanged", true);
Deleted : user_pref("CT2724386.CurrentServerDate", "27-1-2011");
Deleted : user_pref("CT2724386.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2724386.DownloadReferralCookieData", "");
Deleted : user_pref("CT2724386.FirstServerDate", "16-1-2011");
Deleted : user_pref("CT2724386.FirstTime", true);
Deleted : user_pref("CT2724386.FirstTimeFF3", true);
Deleted : user_pref("CT2724386.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2724386.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2724386.GroupingLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central America Sta[...]
Deleted : user_pref("CT2724386.GroupingLastErrorCode", "");
Deleted : user_pref("CT2724386.GroupingLastResponse", true);
Deleted : user_pref("CT2724386.GroupingLastServerUpdateTime", "129404259370830000");
Deleted : user_pref("CT2724386.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2724386.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2724386.Initialize", true);
Deleted : user_pref("CT2724386.InitializeCommonPrefs", true);
Deleted : user_pref("CT2724386.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2724386.InstallationId", "IncrediMail_MediaBar_2.exe");
Deleted : user_pref("CT2724386.InstallationType", "ConduitIntegration");
Deleted : user_pref("CT2724386.InstalledDate", "Sat Jan 15 2011 22:39:56 GMT-0600 (Central America Standard Ti[...]
Deleted : user_pref("CT2724386.IsGrouping", true);
Deleted : user_pref("CT2724386.IsMulticommunity", false);
Deleted : user_pref("CT2724386.IsOpenThankYouPage", false);
Deleted : user_pref("CT2724386.IsOpenUninstallPage", true);
Deleted : user_pref("CT2724386.LanguagePackLastCheckTime", "Sat Jan 15 2011 22:39:58 GMT-0600 (Central America[...]
Deleted : user_pref("CT2724386.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2724386.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2724386.LastLogin_2.7.2.0", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central America Standar[...]
Deleted : user_pref("CT2724386.LatestVersion", "3.2.5.2");
Deleted : user_pref("CT2724386.Locale", "en");
Deleted : user_pref("CT2724386.LoginCache", 4);
Deleted : user_pref("CT2724386.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2724386.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2724386.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2724386.RadioIsPodcast", false);
Deleted : user_pref("CT2724386.RadioMediaID", "21080102");
Deleted : user_pref("CT2724386.RadioMediaType", "Media Player");
Deleted : user_pref("CT2724386.RadioMenuSelectedID", "EBRadioMenu_CT272438621080102");
Deleted : user_pref("CT2724386.RadioStationName", "Mix%201620%20Am");
Deleted : user_pref("CT2724386.RadioStationURL", "hxxp://69.115.65.9:8000");
Deleted : user_pref("CT2724386.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2724386.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2724386.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT272[...]
Deleted : user_pref("CT2724386.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2724386.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2724386.SearchInNewTabLastCheckTime", "Sat Jan 15 2011 22:39:57 GMT-0600 (Central Ameri[...]
Deleted : user_pref("CT2724386.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2724386.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2724386.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2724386.SettingsLastCheckTime", "Sat Jan 15 2011 22:39:55 GMT-0600 (Central America Sta[...]
Deleted : user_pref("CT2724386.SettingsLastUpdate", "1294298391");
Deleted : user_pref("CT2724386.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2724386.ThirdPartyComponentsLastCheck", "Sat Jan 15 2011 22:39:55 GMT-0600 (Central Ame[...]
Deleted : user_pref("CT2724386.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT2724386.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Deleted : user_pref("CT2724386.UserID", "UN09292349458301119");
Deleted : user_pref("CT2724386.ValidationData_Toolbar", 1);
Deleted : user_pref("CT2724386.WeatherNetwork", "");
Deleted : user_pref("CT2724386.WeatherPollDate", "Thu Jan 27 2011 02:13:14 GMT-0600 (Central America Standard [...]
Deleted : user_pref("CT2724386.WeatherUnit", "C");
Deleted : user_pref("CT2724386.clientLogIsEnabled", false);
Deleted : user_pref("CT2724386.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2724386.ct2724386.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2724386.ct2724386.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2724386.ct2724386.GroupingInvalidateCache", false);
Deleted : user_pref("CT2724386.ct2724386.GroupingLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central A[...]
Deleted : user_pref("CT2724386.ct2724386.GroupingLastErrorCode", "");
Deleted : user_pref("CT2724386.ct2724386.GroupingLastResponse", true);
Deleted : user_pref("CT2724386.ct2724386.GroupingLastServerUpdateTime", "129404259370830000");
Deleted : user_pref("CT2724386.ct2724386.InvalidateCache", false);
Deleted : user_pref("CT2724386.ct2724386.LanguagePackLastCheckTime", "Thu Jan 27 2011 01:43:13 GMT-0600 (Centr[...]
Deleted : user_pref("CT2724386.ct2724386.Locale", "en");
Deleted : user_pref("CT2724386.ct2724386.RadioLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central Amer[...]
Deleted : user_pref("CT2724386.ct2724386.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2724386.ct2724386.RadioLastUpdateServer", "129249036863500000");
Deleted : user_pref("CT2724386.ct2724386.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_[...]
Deleted : user_pref("CT2724386.ct2724386.SearchInNewTabLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Cen[...]
Deleted : user_pref("CT2724386.ct2724386.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2724386.ct2724386.SettingsLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Central A[...]
Deleted : user_pref("CT2724386.ct2724386.SettingsLastUpdate", "1294298391");
Deleted : user_pref("CT2724386.ct2724386.ThirdPartyComponentsLastCheck", "Sat Jan 15 2011 22:39:56 GMT-0600 (C[...]
Deleted : user_pref("CT2724386.ct2724386.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT2724386.myStuffEnabled", true);
Deleted : user_pref("CT2724386.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2724386.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2724386.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2724386.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2724386.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/952537/948310/US", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2559647", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2559647",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2559647/CT2559647[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634[...]
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://mystart.incredimail.com/?loc=ff_a[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2724386,CT2559647");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2724386,CT2559647");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Thu Apr 07 2011 05:40:47 GMT-06[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun May 22 2011 13:23:01 GMT-0600 (Centr[...]
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun May 22 2011 13:22:53 GMT-0600 (Central A[...]
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "20498835-bc99-45af-bbae-808b387d9a8b");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Jan 27 2011 01:43:12 GMT-0600 (Cen[...]
Deleted : user_pref("CommunityToolbar.globalUserId", "c8150399-a995-4940-b00d-d5d378cdee16");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2559647");
Deleted : user_pref("browser.search.defaultthis.engineName", "Coupons.com Customized Web Search");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2559647&Sea[...]
Deleted : user_pref("browser.startup.homepage", "hxxp://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=CDxd[...]
Deleted : user_pref("extensions.CouponAlert_2p.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/open[...]
Deleted : user_pref("extensions.CouponAlert_2p.prevKwdURL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.[...]
Deleted : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensea[...]
Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://mystart.incredimail.com/?loc=ff_address_bar&a[...]
Deleted : user_pref("extensions.sahtb.url.merchants.data", "
File : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\ox1380kb.default\prefs.js
Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
Deleted : user_pref("extensions.CouponAlert_2p.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/open[...]
Deleted : user_pref("extensions.CouponAlert_2p.prevKwdURL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.[...]
Deleted : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensea[...]
Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "chrome://browser-region/locale/region.properties");
Deleted : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid={F09576C6-1C26-4A31-A7C3-5C94875AFD88}&m[...]
File : C:\Users\ginzu\AppData\Roaming\Mozilla\Firefox\Profiles\ncyxn3nj.default\prefs.js
Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid={F09576C6-1C26-4A31-A7C3-5C94875AFD88}&m[...]
File : C:\Users\GM Project\AppData\Roaming\Mozilla\Firefox\Profiles\mu58k4ht.default\prefs.js
[OK] File is clean.
-\\ Google Chrome v28.0.1500.71
File : C:\Users\B-Websites\AppData\Local\Google\Chrome\User Data\Default\Preferences
Deleted [l.2392] : homepage = "hxxp://isearch.avg.com/?cid={BF846267-4F53-4CFD-B454-41C763C17A96}&mid=75c6c48021bf4[...]
File : C:\Users\Sis\AppData\Local\Google\Chrome\User Data\Default\Preferences
Deleted [l.2252] : homepage = "hxxp://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=CDxdm014YYus&ptb=6E3149F0-B[...]
Deleted [l.2889] : urls_to_restore_on_startup = [ "hxxp://www.hotmail.com/?rru=inbox", "hxxp://doctoroz.com/", "[...]
File : C:\Users\M\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
File : C:\Users\ginzu\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
File : C:\Users\GM Project\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [36611 octets] - [06/07/2013 12:37:46]
AdwCleaner[S1].txt - [37069 octets] - [06/07/2013 13:06:33]
########## EOF - C:\AdwCleaner[S1].txt - [37130 octets] ##########
----
====
FOR SOME UNKNOWN REASON I COULD NOT GET MBAM TO DOWNLOAD FROM THIS FORUM SHOULD I DOWNLOAD IT FROM ANOTHER WEBSITE SUCH AS WWW.DOWNLOADS.COM?
====
====
SECURITY CHECK LOG FILE.
====
Results of screen317's Security Check version 0.99.68
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2013
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
JavaFX 2.1.1
Java(TM) 6 Update 29
Java(TM) 7 Update 5
Java version out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox 20.0.1 Firefox out of Date!
Google Chrome 28.0.1500.63
Google Chrome 28.0.1500.71
````````Process Check: objlist.exe by Laurent````````
AVG avgwdsvc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````