'Annoying sodding ADS'.. HELP

talismanpr

New Member
I use 'Windows 7 .. When I open my home page or my e-mail which are 'Google', I get an annoying new page ad.. either for shoes... furniture..etc etc etc. I have tried googleing the prob... for instance,.. they say look for the ''whats this'' icon...but there aint anything like that on the pages.. Can you help... thanx

Tally
 
Do the following in order.

1.

Please download AdwCleaner by Xplode onto your Desktop.



•Please close all open programs and internet browsers.
•Double click on adwcleaner.exe to run the tool.
•Click on Delete.
•Confirm each time with OK
•Your computer will be rebooted automatically. A text file will open after the restart.
•Please post the content of that logfile in your reply.
•You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

2.

Please download Malwarebytes' Anti-Malware from here or here and save it to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version. Please keep updating until it says you have the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • A log will be saved automatically which you can access by clicking on the Logs tab within Malwarebytes' Anti-Malware

If for some reason Malwarebytes will not install or run please download and run Rkill.scr, Rkill.exe, or Rkill.com. If you are still having issues running rkill then try downloading these renamed versions of the same program.

EXPLORER.EXE
IEXPLORE.EXE
USERINIT.EXE
WINLOGON.EXE

But DO NOT reboot the system and then try installing or running Malwarebytes. If Rkill (which is a black box) appears and then disappears right away or you get a message saying rkill is infected, keep trying to run rkill until it over powers the infection and temporarily kills it. Once a log appears on the screen, you can try running malwarebytes or downloading other programs.



Download the HijackThis installer from here.
Run the installer and choose Install, indicating that you accept the licence agreement. The installer will place a shortcut on your desktop and launch HijackThis.

Vista and Windows 7 users must right click on the hijackthis icon and click on run as. If the run as option doesn't appear then press and hold the shift key while right clicking on the icon to get it to appear.


Click Do a system scan and save a logfile

Most of what HijackThis lists will be harmless or even essential, don't fix anything yet.

When the hijackthis log appears in a notepad file, click on the edit menu, click select all, then click on the edit menu again and click on copy. Come back to your reply and right click on your mouse and click on paste.

Post the logfile that HijackThis produces along with the Malwarebytes Anti-Malware log
 
..hi again,.. John B gave me about 9 paragraphs with about 6 links,.. do I have to go through all of that, or just one of them.. seems very complicated to me.
Something should be done with these parrasites intruding,.. how come it's been fine for 2 years,..then this happens??? :mad:
 
Download and run adware cleaner first and post the log that it gives you. Then download mawlarebytes, update it, run a quick scan and post the log that it gives you. Then download and run hijackthis, then post the log that it gives you. Very straightforward and very simple to do. You only have to run rkill if malwarebytes won't run.
 
goto add/remove files in control panel and check for browser add ons like doubleclick/coupon things, happens to my wife all the time.
 
goto add/remove files in control panel and check for browser add ons like doubleclick/coupon things, happens to my wife all the time.

You don't need to do that. ADWCleaner will take care of that.
 
i double clicked on log, and this opened in notepad.. is this what you meant?

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2013.09.03.06

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
ad :: PAUL [administrator]

Protection: Enabled

03/09/2013 18:55:42
mbam-log-2013-09-03 (18-55-42).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 201695
Time elapsed: 57 minute(s), 54 second(s)

Memory Processes Detected: 3
C:\Program Files\RelevantKnowledge\rlservice.exe (PUP.Adware.RelevantKnowledge) -> 1880 -> Delete on reboot.
C:\Users\ad\AppData\Roaming\Movdap\WebCakeDesktop.exe (PUP.WebCake.A) -> 560 -> Delete on reboot.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe (PUP.Optional.DefaultTab.A) -> 1620 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 59
HKLM\SYSTEM\CurrentControlSet\Services\RelevantKnowledge (PUP.Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
HKCR\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKCR\TypeLib\{FEB62B15-CC00-4736-AAEC-BA046C9DFF73} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKCR\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKCR\DefaultTabBHO.DefaultTabBrowser.1 (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKCR\DefaultTabBHO.DefaultTabBrowser (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKCR\AppID\{186E19A3-B909-4F48-B687-BB81EB8BC7CE} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\AppID\{38495740-0035-4471-851E-F5BBB86AB085} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
HKCR\AppID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8} (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7} (PUP.Optional.SearchQu) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Quarantined and deleted successfully.
HKCR\CLSID\{A1E28287-1A31-4b0f-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\DefaultTabBHO.DefaultTabBrowserActiveX.1 (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\DefaultTabBHO.DefaultTabBrowserActiveX (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\funmoodsApp.appCore.1 (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\funmoodsApp.appCore (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B} (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.
HKCR\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0} (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.
HKCR\esrv.mysearchdialESrvc.1 (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.
HKCR\esrv.mysearchdialESrvc (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\f (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
HKCR\PricePeep.PricePeepBho.1 (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
HKCR\PricePeep.PricePeepBho (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
HKCR\Typelib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2D33ED6-EBBD-467C-BF6F-F175D9B51363} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAD84EE2-624D-4e7c-A8BB-41EFD720FD77} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Quarantined and deleted successfully.
HKCR\PricePeep.PricePeepBho.1 (Adware.Agent) -> Quarantined and deleted successfully.
HKCR\PricePeep.PricePeepBho (Adware.Agent) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\DefaultTabUpdate (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.

Registry Values Detected: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WebCake Desktop (PUP.WebCake.A) -> Data: C:\Users\ad\AppData\Roaming\Movdap\WebCakeDesktop.exe -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Data: Searchqu Toolbar -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{99079a25-328f-4bd4-be04-00955acaa0a7} (PUP.Optional.SearchQu) -> Data: -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab (PUP.Optional.DefaultTab.A) -> Delete on reboot.

Files Detected: 39
C:\Program Files\RelevantKnowledge\rlservice.exe (PUP.Adware.RelevantKnowledge) -> Delete on reboot.
C:\Users\ad\AppData\Roaming\Movdap\WebCakeDesktop.exe (PUP.WebCake.A) -> Delete on reboot.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\Program Files\PricePeep\pricepeep.dll (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
C:\Program Files\PricePeep\pricepeep.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\RelevantKnowledge\rlls.dll_old (PUP.Adware.RelevantKnowledge) -> Delete on reboot.
C:\Program Files\Uninstall Information\ib_uninst_0\uninstall.exe (Adware.InstallBrain) -> Quarantined and deleted successfully.
C:\Program Files\Uninstall Information\ib_uninst_358\uninstall.exe (Adware.InstallBrain) -> Quarantined and deleted successfully.
C:\Program Files\Uninstall Information\ib_uninst_361\uninstall.exe (Adware.InstallBrain) -> Quarantined and deleted successfully.
C:\Program Files\Uninstall Information\ib_uninst_442\uninstall.exe (Adware.InstallBrain) -> Quarantined and deleted successfully.
C:\Program Files\Uninstall Information\ib_uninst_447\uninstall.exe (Adware.InstallBrain) -> Quarantined and deleted successfully.
C:\Program Files\Uninstall Information\ib_uninst_514\uninstall.exe (Adware.InstallBrain) -> Quarantined and deleted successfully.
C:\Program Files\Uninstall Information\ib_uninst_515\uninstall.exe (Adware.InstallBrain) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart64.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap.dll (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap64.dll (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\update.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\stub_data\stubinst_pkg_en-uk.cab (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\Web Cake\WebCakeDesktop.exe (PUP.WebCake.A) -> Quarantined and deleted successfully.
C:\Users\ad\Downloads\Setup.exe (PUP.Optional.IBryte.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.cfg (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\addon.ico (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\amazon_ie.ico (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabUninstaller.exe (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DT.ico (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe (PUP.Optional.DefaultTab.A) -> Delete on reboot.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\ebay_ie.ico (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\facebook_ie.ico (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\searchhere.ico (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\search_here_ie.ico (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\twitter_ie.ico (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Roaming\DefaultTab\DefaultTab\wikipedia_ie.ico (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\Users\ad\AppData\Local\funmoods.crx (PUP.Funmoods) -> Quarantined and deleted successfully.
C:\Users\ad\Local Settings\Application Data\funmoods.crx (PUP.Funmoods) -> Quarantined and deleted successfully.

(end)
 
also this log..

2013/09/03 18:54:08 +0100 PAUL ad MESSAGE Starting protection
2013/09/03 18:54:08 +0100 PAUL ad MESSAGE Protection started successfully
2013/09/03 18:54:08 +0100 PAUL ad MESSAGE Starting IP protection
2013/09/03 18:54:35 +0100 PAUL ad MESSAGE IP Protection started successfully
2013/09/03 18:54:57 +0100 PAUL ad MESSAGE Starting database refresh
2013/09/03 18:54:57 +0100 PAUL ad MESSAGE Stopping IP protection
2013/09/03 18:55:05 +0100 PAUL ad MESSAGE IP Protection stopped successfully
2013/09/03 18:55:08 +0100 PAUL ad MESSAGE Database refreshed successfully
2013/09/03 18:55:08 +0100 PAUL ad MESSAGE Starting IP protection
2013/09/03 18:55:16 +0100 PAUL ad MESSAGE IP Protection started successfully
2013/09/03 19:00:24 +0100 PAUL ad MESSAGE Executing scheduled update: Daily
2013/09/03 19:00:27 +0100 PAUL ad MESSAGE Database already up-to-date
2013/09/03 20:03:32 +0100 PAUL ad MESSAGE Starting protection
2013/09/03 20:03:32 +0100 PAUL ad MESSAGE Protection started successfully
2013/09/03 20:03:32 +0100 PAUL ad MESSAGE Starting IP protection
2013/09/03 20:03:39 +0100 PAUL ad MESSAGE IP Protection started successfully
 
The first log is what I needed. Also still would like to see the adaware scan results and the hijackthis log.
 
I had the threats removed, and they are quarrentined.. dont know hot to send you the scan results?? sorry but I am very basic..

tally
 
Have you ran adaware cleaner and hijackthis yet? If you have ran adaware then the log will be located in the root directory of your C drive. example C:\AdwCleaner[Sn].txt

Then we need a fresh scan of hijackthis. Use the instructions in my post up top to get the log.
 
is this it?

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 11:10:34, on 05/09/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!

FIREFOX: 24.0 (en-GB)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrchMn.exe
C:\Program Files\GorillaPrice\GorillaPrice.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Users\ad\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.tb.ask.com/index.jhtml?n=77DE8857&p2=^HJ^xdm005^YYA^gb&ptb=4F8E74C7-C6F7-4EA2-B91A-5B64E7C53AC8&si=CPbkjsist7gCFXTItAodn0oAgw
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=QuickOB&dpid=QuickOB&co=GB&userid=5a1788f9-0b1d-4cba-a8bd-87b0cd98377d&searchtype=ds&q={searchTerms}&installDate={installDate}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.cybermoor.org:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Toolbar BHO - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbar.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: TidyNetwork.com - {7736C7FA-512D-11E2-B871-DEC36088709B} - C:\Users\ad\AppData\Local\TidyNetwork.com\tidy2ie.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Search Assistant BHO - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {cdf97ee2-ded0-4369-835e-99dd08225fa5} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: VideoDownloadConverter - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
O4 - HKLM\..\Run: [btbb_McciTrayApp] "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"
O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [GorillaPrice] "C:\Program Files\GorillaPrice\GorillaPrice.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files\real\realplayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [GorillaPrice] "C:\Program Files\GorillaPrice\GorillaPrice.exe"
O4 - HKUS\S-1-5-18\..\Run: [SearchProtect] \SearchProtect\bin\cltmng.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [SearchProtect] \SearchProtect\bin\cltmng.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: pcCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\pcCMService.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Skype C2C Service - Unknown owner - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Cryptainer service (ssoftservice) - Cypherix Software (India) Pvt. Ltd. - C:\Windows\system32\cryptainersrv.exe
O23 - Service: VideoDownloadConverterService (VideoDownloadConverter_4zService) - COMPANYVERS_NAME - C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbarsvc.exe
O23 - Service: WatGorp - Unknown owner - C:\ProgramData\GorillaPrice\WatGorp.exe

--
End of file - 8125 bytes
 
You have not ran adware cleaner yet, you have lots of adware on your system. Please do both of the following.

1.

Please download AdwCleaner by Xplode onto your Desktop.



•Please close all open programs and internet browsers.
•Double click on adwcleaner.exe to run the tool.
•Click on Scan.
•After the scan you will need to click on the clean for it to delete the adware.
•Your computer will be rebooted automatically. A text file will open after the restart.
•Please post the content of that logfile in your reply.
•You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

2.

Please download Junkware Removal Tool to your desktop.

•Shutdown your antivirus to avoid any conflicts.

•Very important that you run the tool in this manner:
Right-mouse click JRT.exe and select Run as administrator
Do NOT just double-click it.

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Post the contents of JRT.txt in your next message.
 
..hi.. came up in 'Notepad'.. hope this helps.. then what next?

# AdwCleaner v3.002 - Report created 05/09/2013 at 15:15:54
# Updated 01/09/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : ad - PAUL
# Running from : C:\Users\ad\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : VideoDownloadConverter_4zService

***** [ Files / Folders ] *****

Folder Deleted : C:\SearchProtect
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Ilivid
Folder Deleted : C:\Program Files\MyPC Backup
Folder Deleted : C:\Program Files\Nation Toolbar
Folder Deleted : C:\Program Files\PricePeep
Folder Deleted : C:\Program Files\RelevantKnowledge
Folder Deleted : C:\Program Files\SearchProtect
Folder Deleted : C:\Program Files\SearchYa!
Folder Deleted : C:\Program Files\VideoDownloadConverter_4z
Folder Deleted : C:\Users\ad\AppData\Local\Conduit
Folder Deleted : C:\Users\ad\AppData\Local\iac
Folder Deleted : C:\Users\ad\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\ad\AppData\Local\PackageAware
Folder Deleted : C:\Users\ad\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\ad\AppData\Local\TidyNetwork.com
Folder Deleted : C:\Users\ad\AppData\Local\VideoDownloadConverter_4z
Folder Deleted : C:\Users\ad\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\ad\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\ad\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\ad\AppData\LocalLow\Funmoods
Folder Deleted : C:\Users\ad\AppData\LocalLow\iac
Folder Deleted : C:\Users\ad\AppData\LocalLow\VideoDownloadConverter_4z
Folder Deleted : C:\Users\ad\AppData\Roaming\DefaultTab
Folder Deleted : C:\Users\ad\AppData\Roaming\Funmoods
Folder Deleted : C:\Users\ad\AppData\Roaming\Movdap
Folder Deleted : C:\Users\ad\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\ad\AppData\Roaming\Web Cake
Folder Deleted : C:\Users\ad\AppData\Roaming\Mozilla\Firefox\Profiles\yerqady9.default\Searchqutoolbar
Folder Deleted : C:\Users\ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Folder Deleted : C:\Users\ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki
Folder Deleted : C:\Users\ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff
File Deleted : C:\END
File Deleted : C:\Users\ad\AppData\Local\funmoods-speeddial.crx
File Deleted : C:\Users\ad\AppData\Local\mysearchdial.crx
File Deleted : C:\Users\ad\AppData\Roaming\Mozilla\Firefox\Profiles\yerqady9.default\\invalidprefs.js
File Deleted : C:\Users\ad\AppData\Roaming\Mozilla\Firefox\Profiles\yerqady9.default\searchplugins\ask-web-search.xml
File Deleted : C:\Users\ad\AppData\Roaming\Mozilla\Firefox\Profiles\yerqady9.default\searchplugins\Babylon.xml
File Deleted : C:\Users\ad\AppData\Roaming\Mozilla\Firefox\Profiles\yerqady9.default\searchplugins\Mysearchdial.xml
File Deleted : C:\Users\ad\AppData\Roaming\Mozilla\Firefox\Profiles\yerqady9.default\user.js
File Deleted : C:\Users\ad\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage
File Deleted : C:\Users\ad\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Google\Chrome\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl
Key Deleted : HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Key Deleted : HKCU\Software\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh
Key Deleted : HKCU\Software\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [Backup.old.Start Page]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Key Deleted : HKLM\SOFTWARE\Classes\bho_project.bho_object
Key Deleted : HKLM\SOFTWARE\Classes\bho_project.bho_object.1
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.dskBnd
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.dskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\I Want This_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\I Want This_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKCU\Software\582da88b13ee945
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2724386
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3198785
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3227975
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289847
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_regcleaner_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_regcleaner_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_text-osterone_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_text-osterone_RASMANCS
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VideoDownloadConverter Search Scope Monitor]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1973277F-87B0-4EA3-9ED2-470A91D284CF}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2A1260C1-2964-453F-B0BA-FA429472EB5F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{363D5C92-10DC-4287-93E5-1832EECC48EC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B41BE90-F731-4137-AFF3-2CA951E7F0D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4128C64D-F0DD-4811-9405-D22294E8151F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66292684-B2C2-4C7C-B3D2-BF446E30744C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69407823-3494-4400-8D49-612549E8F4EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6BFF4BCB-7A73-45A7-AC4C-389A34E1D1EF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8FCA5302-6D6D-4645-BF99-D43CF76CE474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A0B10EBE-4E51-4CAE-949B-E6B9E7D68CEA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD385519-22E7-4BE2-8A8D-35C66DF4858E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F511AFDB-726E-4458-90E7-1ECB97406544}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D3826A1-F3E8-45D6-94B5-C26D8EC0073B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3EE17DD1-E28B-4AED-A3B2-9C29CB2C19D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{886F93AD-3CBB-4424-8442-A7340243540F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AA289DBC-59B6-40A5-AC7D-C90DF850289C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CA723163-6FAD-43D4-8B93-0D8C52BD9974}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F1F328EB-F5A5-432B-A54C-05F3EF5B0BD8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FB0E8A09-F08C-44CF-9E15-97ADAC016248}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FE8DBB09-C3D3-4477-80CB-D38914B94BB8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7736C7FA-512D-11E2-B871-DEC36088709B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7736C7FA-512D-11E2-B871-DEC36088709B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7736C7FA-512D-11E2-B871-DEC36088709B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AF94B35C-3AC5-4030-9F9C-15FB4E3DC339}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{93A3111F-4F74-4ED8-895E-D9708497629E}]
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\BrowserMngr
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\Default Tab
Key Deleted : HKCU\Software\delta LTD
Key Deleted : HKCU\Software\distromatic
Key Deleted : HKCU\Software\Funmoods
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\mysearchdial
Key Deleted : HKCU\Software\mysearchdial.com
Key Deleted : HKCU\Software\Nation Toolbar
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\searchya.com
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\DefaultTab
Key Deleted : HKCU\Software\AppDataLow\Software\HappyLyrics
Key Deleted : HKCU\Software\AppDataLow\Software\I Want This
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\BrowserMngr
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Default Tab
Key Deleted : HKLM\Software\DomaIQ
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\ImInstaller
Key Deleted : HKLM\Software\Nation Toolbar
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D08D9F98-1C78-4704-87E6-368B0023D831}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PricePeep
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Product Deleted : Google Update Helper

***** [ Browsers ] *****

-\\ Internet Explorer v0.0.0.0

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Backup.Old.Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]

-\\ Mozilla Firefox v24.0 (en-GB)

[ File : C:\Users\ad\AppData\Roaming\Mozilla\Firefox\Profiles\yerqady9.default\prefs.js ]

Line Deleted : user_pref("CT3198785_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1362947976599,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("CT3282134_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1362229910000,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("CT3289847.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"about%3Aaddons\",\"EB_MAIN_FRAME_TITLE\":\"\"}");
Line Deleted : user_pref("CT3289847_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1366408764034,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("Smartbar.ConduitHomepagesList", "");
Line Deleted : user_pref("Smartbar.ConduitSearchEngineList", "WhiteSmoke New Customized Web Search");
Line Deleted : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN38538259459896477&UM=2&q=");
Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://feed.snap.do/?publisher=QuickOB&dpid=QuickOB&co=GB&userid=5a1788f9-0b1d-4cba-a8bd-87b0cd98377d&searchtype=ds&installDate={installDate}&q=");
Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3289847");
Line Deleted : user_pref("avg.install.userHPSettings", "hxxp://search.conduit.com/?ctid=CT3227975&SearchSource=13");
Line Deleted : user_pref("avg.install.userSPSettings", "appbario2 Customized Web Search");
Line Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "WhiteSmoke New Customized Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI=UN38538259459896477&UM=2&SearchSource=3&q={searchTerms}");
Line Deleted : user_pref("extensions.BabylonToolbar.admin", false);
Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
Line Deleted : user_pref("extensions.BabylonToolbar.autoRvrt", "false");
Line Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Line Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar.id", "344a5254000000000000bcaec562ec79");
Line Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15695");
Line Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Line Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar.rvrt", "false");
Line Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Line Deleted : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=344a5254000000000000bcaec562ec79&q=");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.8.7.2");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.8.7.2");
Line Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=115038&tt=5112_3");
Line Deleted : user_pref("extensions.BabylonToolbar_i.excTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "344a5254000000000000bcaec562ec79");
Line Deleted : user_pref("extensions.BabylonToolbar_i.id", "344a5254000000000000bcaec562ec79");
Line Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15524");
Line Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Line Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false);
Line Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Line Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.7.21:46:52");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Line Deleted : user_pref("extensions.crossrider.bic", "13bbd47a1843729f6608d8e052a7459b");
Line Deleted : user_pref("[email protected]", true);
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.bbDpng", "3");
Line Deleted : user_pref("extensions.delta.cntry", "GB");
Line Deleted : user_pref("extensions.delta.dfltLng", "en");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.hdrMd5", "A827D5EF81C4ED15B7F5792375E57272");
Line Deleted : user_pref("extensions.delta.id", "344a5254000000000000bcaec562ec79");
Line Deleted : user_pref("extensions.delta.instlDay", "15920");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.lastVrsnTs", "1.8.22.013:42:08");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.sg", "azb");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.22.0");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.22.013:42:08");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.22.0");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=119842&tsp=4963");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");
Line Deleted : user_pref("[email protected]", true);
Line Deleted : user_pref("[email protected]", true);
Line Deleted : user_pref("extensions.funmoods.aflt", "grupo");
Line Deleted : user_pref("extensions.funmoods.autoRvrt", false);
Line Deleted : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
Line Deleted : user_pref("extensions.funmoods.cntry", "GB");
Line Deleted : user_pref("extensions.funmoods.cv", "cv5");
Line Deleted : user_pref("extensions.funmoods.dfltlng", "en");
Line Deleted : user_pref("extensions.funmoods.dfltsrch", true);
Line Deleted : user_pref("extensions.funmoods.dnsErr", true);
Line Deleted : user_pref("extensions.funmoods.envrmnt", "production");
Line Deleted : user_pref("extensions.funmoods.excTlbr", false);
Line Deleted : user_pref("extensions.funmoods.fmupdtFirst", false);
Line Deleted : user_pref("extensions.funmoods.hdrMd5", "DACEE1002A42CA41555BE48FE78BC538");
Line Deleted : user_pref("extensions.funmoods.hmpg", true);
Line Deleted : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=grupo&chnl=grupo&cd=2XzutAtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0TzutBtDtCtBtDyCtBtD&cr=1629798696");
Line Deleted : user_pref("extensions.funmoods.hrdid", "344a5254000000000000bcaec562ec79");
Line Deleted : user_pref("extensions.funmoods.id", "344a5254000000000000bcaec562ec79");
Line Deleted : user_pref("extensions.funmoods.instlday", "15511");
Line Deleted : user_pref("extensions.funmoods.instlref", "grupo");
Line Deleted : user_pref("extensions.funmoods.isdcmntcmplt", true);
Line Deleted : user_pref("extensions.funmoods.keywordurl", "");
Line Deleted : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2214:47:21");
Line Deleted : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
Line Deleted : user_pref("extensions.funmoods.monitorreport", true);
Line Deleted : user_pref("extensions.funmoods.newtab", true);
Line Deleted : user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a=grupo&chnl=grupo&cd=2XzutAtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0TzutBtDtCtBtDyCtBtD&cr=1629798696");
Line Deleted : user_pref("extensions.funmoods.prdct", "funmoods");
Line Deleted : user_pref("extensions.funmoods.prtnrid", "funmoods");
Line Deleted : user_pref("extensions.funmoods.savedVrsnTs", "1");
Line Deleted : user_pref("extensions.funmoods.sg", "none");
Line Deleted : user_pref("extensions.funmoods.smplgrp", "none");
Line Deleted : user_pref("extensions.funmoods.srch", "");
Line Deleted : user_pref("extensions.funmoods.srchprvdr", "Search");
Line Deleted : user_pref("extensions.funmoods.tlbrid", "base");
Line Deleted : user_pref("extensions.funmoods.tlbrsrchurl", "");
Line Deleted : user_pref("extensions.funmoods.vrsn", "1.5.23.22");
Line Deleted : user_pref("extensions.funmoods.vrsni", "1.5.23.22");
Line Deleted : user_pref("extensions.funmoods.vrsnts", "1.5.23.2214:47:21");
Line Deleted : user_pref("extensions.funmoods_i.newTab", true);
Line Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
Line Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2214:47:21");
Line Deleted : user_pref("extensions.helperbar.Country", "United Kingdom");
Line Deleted : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Deleted : user_pref("extensions.helperbar.LastHiddenTime", 22745416);
Line Deleted : user_pref("extensions.helperbar.SmartbarDisabled", true);
Line Deleted : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Line Deleted : user_pref("extensions.helperbar.UserID", "5a1788f9-0b1d-4cba-a8bd-87b0cd98377d");
Line Deleted : user_pref("extensions.helperbar.Visibility", false);
Line Deleted : user_pref("[email protected]", true);
Line Deleted : user_pref("extensions.mysearchdial.aflt", "tightmsd");
Line Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
Line Deleted : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0Tzu0CyDyCyBtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q");
Line Deleted : user_pref("extensions.mysearchdial.cntry", "GB");
Line Deleted : user_pref("extensions.mysearchdial.cr", "1480746619");
Line Deleted : user_pref("extensions.mysearchdial.dfltLng", "");
Line Deleted : user_pref("extensions.mysearchdial.dfltSrch", true);
Line Deleted : user_pref("extensions.mysearchdial.dnsErr", true);
Line Deleted : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...]
Line Deleted : user_pref("extensions.mysearchdial.excTlbr", false);
Line Deleted : user_pref("extensions.mysearchdial.hdrMd5", "13E49B9BFB97F39952A1313206BD95DE");
Line Deleted : user_pref("extensions.mysearchdial.hmpg", true);
Line Deleted : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=tightmsd&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0Tzu0CyDyCzztN1L2XzutBtFtBtFtCtFyDyByEtN1L1Czu2Z1L1N1[...]
Line Deleted : user_pref("extensions.mysearchdial.id", "BCAEC562EC795254");
Line Deleted : user_pref("extensions.mysearchdial.instlDay", "15907");
Line Deleted : user_pref("extensions.mysearchdial.instlRef", "");
Line Deleted : user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=tightmsd&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0Tzu0CyDyCzztN1L2XzutBtFtBtFtCtFyDyByEtN1L1Czu2Z1L1N1M2[...]
Line Deleted : user_pref("extensions.mysearchdial.lastVrsnTs", "13:2:27");
Line Deleted : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=tightmsd&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0Tzu0CyDyCzztN1L2XzutBtFtBtFtCtFyDyByEtN1L1Czu2Z1L1[...]
Line Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
Line Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
Line Deleted : user_pref("extensions.mysearchdial.sg", "none");
Line Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
Line Deleted : user_pref("extensions.mysearchdial.tlbrId", "base");
Line Deleted : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=tightmsd&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0Tzu0CyDyCzztN1L2XzutBtFtBtFtCtFyDyByEtN1L1Czu2Z1[...]
Line Deleted : user_pref("extensions.mysearchdial.vrsn", "");
Line Deleted : user_pref("extensions.mysearchdial.vrsni", "");
Line Deleted : user_pref("extensions.mysearchdial_i.hmpg", true);
Line Deleted : user_pref("extensions.mysearchdial_i.newTab", false);
Line Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none");
Line Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "13:2:27");
Line Deleted : user_pref("extensions.mywebsearch.prevDefaultEngine", "Mysearchdial");
Line Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Deleted : user_pref("extensions.mywebsearch.prevSelectedEngine", "Google");
Line Deleted : user_pref("extensions.searchya.aflt", "foxtab");
Line Deleted : user_pref("extensions.searchya.autoRvrt", false);
Line Deleted : user_pref("extensions.searchya.cntry", "GB");
Line Deleted : user_pref("extensions.searchya.dfltLng", "");
Line Deleted : user_pref("extensions.searchya.dfltSrch", true);
Line Deleted : user_pref("extensions.searchya.dnsErr", true);
Line Deleted : user_pref("extensions.searchya.envrmnt", "production");
Line Deleted : user_pref("extensions.searchya.excTlbr", false);
Line Deleted : user_pref("extensions.searchya.hdrMd5", "1DD87A572A64EF013155FB50565C6ED8");
Line Deleted : user_pref("extensions.searchya.hmpg", true);
Line Deleted : user_pref("extensions.searchya.hmpgUrl", "hxxp://www.searchya.com/?s=0&a=foxtab&chnl=ft-174&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0Tzu0CtBtByCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1766259420"[...]
Line Deleted : user_pref("extensions.searchya.id", "BCAEC562EC795254");
Line Deleted : user_pref("extensions.searchya.instlDay", "15565");
Line Deleted : user_pref("extensions.searchya.instlRef", "ft-174");
Line Deleted : user_pref("extensions.searchya.isdcmntcmplt", true);
Line Deleted : user_pref("extensions.searchya.lastVrsnTs", "1.5.25.018:18:27");
Line Deleted : user_pref("extensions.searchya.mntrvrsn", "1.3.0");
Line Deleted : user_pref("extensions.searchya.newTab", true);
Line Deleted : user_pref("extensions.searchya.newTabUrl", "hxxp://www.searchya.com/?s=2&a=foxtab&chnl=ft-174&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0Tzu0CtBtByCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=176625942[...]
Line Deleted : user_pref("extensions.searchya.pnu_base", "{\"newVrsn\":\"35\",\"lastVrsn\":\"35\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
Line Deleted : user_pref("extensions.searchya.prdct", "searchya");
Line Deleted : user_pref("extensions.searchya.prtnrId", "searchya");
Line Deleted : user_pref("extensions.searchya.sg", "none");
Line Deleted : user_pref("extensions.searchya.smplGrp", "none");
Line Deleted : user_pref("extensions.searchya.srchPrvdr", "Search");
Line Deleted : user_pref("extensions.searchya.tlbrId", "base");
Line Deleted : user_pref("extensions.searchya.tlbrSrchUrl", "hxxp://www.searchya.com/?s=3&a=foxtab&chnl=ft-174&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDyCtB0E0CyBzyyDtByDyEtN0D0Tzu0CtBtByCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1766259[...]
Line Deleted : user_pref("extensions.searchya.vrsn", "1.5.25.0");
Line Deleted : user_pref("extensions.searchya.vrsnTs", "1.5.25.018:18:27");
Line Deleted : user_pref("extensions.searchya.vrsni", "1.5.25.0");
Line Deleted : user_pref("extensions.searchya_i.newTab", true);
Line Deleted : user_pref("extensions.searchya_i.smplGrp", "none");
Line Deleted : user_pref("extensions.searchya_i.vrsnTs", "1.5.25.018:18:27");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=4F8E74C7-C6F7-4EA2-B91A-5B64E7C53AC8&n=77fd0969&p2=^HJ^xdm005^YYA^gb&si=CPbkjsist7gCFXTItAodn0oAg[...]
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.hp.enabled", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.hp.lastGuardTime", -296843306);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.hp.numGuards", 1);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.hp.user.defined", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.initialized", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.contextKey", "");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.installDate", "2013071721");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerId", "^HJ^xdm005^YYA^gb");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerSubId", "CPbkjsist7gCFXTItAodn0oAgw");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.success", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.toolbarId", "4F8E74C7-C6F7-4EA2-B91A-5B64E7C53AC8");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1374092344588");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.defaultSearch", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.homePageEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.keywordEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.tabEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "[email protected]");
Line Deleted : user_pref("extentions.webcake.defaultEnableAppsList", "layers/banner,layers/inline,layers/search,layers/shopping,newOffers/wc");
Line Deleted : user_pref("extentions.webcake.installId", "20d23ac2-0c36-4a61-b627-3235456a9ff3");
Line Deleted : user_pref("smartbar.machineId", "+WD0OCSOGHB+LPI2TA7+S5HA70LAJ6TZJT2KIESSOXPQYB+N9WMH1FD1WIWW4HMPRZPVJ6QEAW7VPLDKR6TVVW");

-\\ Google Chrome v

[ File : C:\Users\ad\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : search_url
Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [44120 octets] - [05/09/2013 15:14:07]
AdwCleaner[S0].txt - [44571 octets] - [05/09/2013 15:15:54]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [44632 octets] ##########
 
hello again.. tell me what next.. sorry taken so long.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.7 (09.01.2013:1)
OS: Windows 7 Professional x86
Ran by ad on 05/09/2013 at 18:50:02.54
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{cdf97ee2-ded0-4369-835e-99dd08225fa5}



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1918124089-1961447528-648128019-1000\Software\SweetIM
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011301126}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\5aSkPlay_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\5aSkPlay_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\GorillaPrice_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\GorillaPrice_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011301126}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{03E5E768-3C26-4FB5-7EB3-2AA58A6EF020}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{443FA2B8-3E8F-47A3-8298-6277F9F38749}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{45E6F411-47D7-419D-7367-2128AC3F0138}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}



~~~ Files

Successfully deleted: [File] "C:\Users\ad\appdata\local\mysearchdial_speedial_v9.0.2.crx"



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\fighters"
Successfully deleted: [Folder] "C:\Users\ad\AppData\Roaming\fighters"
Successfully deleted: [Folder] "C:\Program Files\video download converter"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\free window registry repair"
Successfully deleted: [Folder] "C:\Users\ad\AppData\Roaming\microsoft\windows\start menu\programs\free window registry repair"
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{02370E31-50CB-423C-BD7D-5187CEC50B34}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{03A579D8-9E50-4E19-BCDE-D8483E1A6B91}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{05A6E2D8-54B7-4315-872A-9948CD83CABE}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{08F4C510-9E9E-4017-A265-ED6AE1CEFAA2}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{0B304965-6CEC-4148-A545-34CEFBCA8683}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{0B99A0C0-65E8-44D9-8179-DF74101087DE}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{0C65940B-D37D-4811-AF14-1CCB88669563}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{0EE6C495-3418-48B1-8242-E7AFD07B2669}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{0FB11144-1232-4356-B887-FBF0A823F256}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{10748880-3710-4015-85A2-0A45D3A2E064}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{11C2E42A-1E37-472B-A527-25431D643D1F}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{149E3F2E-4B74-4E5B-9F3B-BF64B0CD6ADB}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{14C248D5-EB95-4EF3-ABD6-BEA52E6FC13D}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{18120514-2E5E-4CBD-A803-2CFDAB76FFB7}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{19F704CA-D8BC-40DD-8F0B-0DF21B6626B8}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{1CC49821-8107-41E2-A615-7F7A3282A9A8}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{1D271B2B-FD5E-44BD-82A6-78A57D09ED2A}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{2046AE8C-AF34-4179-9727-0835F44ABDD1}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{22ADC458-454F-4604-BC2A-88F761F118C2}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{2BADB8B4-535B-4B16-B574-8E4D21625899}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{2C6B25BD-5105-4D9D-8F80-0CCEDBE73221}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{2EE8DE1C-F155-4035-9DD3-E49CD4A31313}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{32C18015-6198-4F8B-93E1-906294972171}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{365F9070-0C9D-44A5-B0B9-95EE973C0026}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{3951CBD5-4531-43BB-806C-BAE69D16DFF9}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{3C371760-1D93-48E2-A987-4CAE19F75EFB}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{3CBC90CF-F665-4521-ACEB-FB4457A0A3C9}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{3E4B7811-C420-45E7-B4F0-10AF33E423A0}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{3E8596E1-9E2E-45C8-B35E-870C4798733C}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{42219E3B-6368-4FC1-9D46-7BCB7D07EEBD}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{43BA8AE9-1614-48B1-A951-0DE6D5EFD77D}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{468F938D-C3E7-4AA7-9365-5BC471D77823}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{46BE05B3-685B-4843-AC5A-92AF5C116528}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{47E35CB1-7784-4660-9170-963AAAC5ABFE}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{493097D2-FDF2-4873-8295-7536972147EC}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{49467CAD-B116-4D46-9BDF-59F87EA6BF2C}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{4B396B8A-A317-4E70-8C84-349ADE2E98C1}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{4C7D73C6-D71E-43DA-81C3-6A80FD7B22E9}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{4CEC37C6-77FE-4398-AEE6-906A643EE8A2}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{4D4DD275-7A5B-4D71-AF1D-1F391A082239}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{4F0FB529-1074-4931-9F77-888D5A66290D}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{50404EC8-A018-4271-8D03-1D854FC95F08}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{56CC0604-1E19-4972-8E0A-90341A0A9589}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{5CB60697-5E96-4286-96B8-959575B6E818}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{5CCE5020-5160-42B7-B326-B7E529BA49F8}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{684DA66C-0304-4D2A-B813-218021816C23}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{69B588D0-77A3-4619-ACD0-5C50229480DF}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{6B16A038-A2AE-4C00-B8D5-7D19FE751E00}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{6EA55802-52EB-4BBF-8E9F-2836E7AD3AA3}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{6EF52818-60ED-445A-97C2-11073941C1B4}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{717CC145-D05B-4391-9417-C79FFFE0E524}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{71CEA347-9214-4FEA-A6A7-62310F183AE9}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{71F2F8D4-5FA0-4381-A9C7-FD2AD963DAE2}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{73723AD0-F419-407F-B7DE-61A6ED2C91CD}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{7668BF14-9EEB-4D89-A351-4D8BB961865B}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{77D590FE-35E4-4AD1-89F5-6E0A0433B34E}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{7AA52725-DF72-498C-8575-11CDFDC0E857}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{7E7EB481-E04A-41A7-8D88-CAE93D461B52}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{7FA0812C-B935-4F83-B425-8C804726E40B}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{80303334-606D-4770-B51D-21571A7AE3A3}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{80AC2DCC-9124-4B82-8ED6-5190569FFEC8}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{85BFC17A-C942-41CF-9172-6217DEC13FCD}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{8650C2C2-CB55-4481-8B1B-CBB432F9ED0A}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{8A3E56B0-0AD4-4273-81EC-273EA3AAA287}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{8A766D45-21F4-4D53-BD19-6992BA5C64D0}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{8EC0969A-BCFA-4C8C-A2A2-8E0E0FA35B6B}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{9044750C-B267-43ED-858E-A1B4A5E6EAF8}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{9174B5A5-05FA-42FF-8B2C-408E76F7A868}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{969BDAAC-4680-4DC4-9FDA-DBAA6FFB26DF}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{9D282935-71C9-4B5D-A99E-277D5F13212B}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{9F1B0097-B9F8-4930-877B-801C02F4A374}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{9F44DB97-7C97-41FA-9D47-9AD6A90086E1}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{A10772E9-44B2-4E1D-9F75-EB08F0DEA78A}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{A510EA22-FAA6-42AE-A7DB-5AE336B51FFF}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{A7B99130-5C44-4248-8FAA-0ADC3CF30B49}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{A98DD712-3655-4FF6-9785-70ABE0A5A448}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{B1BBA13F-B039-4316-A305-591776CEC957}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{B48D9D7E-A17F-4536-8ABE-DBC6FF363B7B}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{B576E4D4-DCB6-44D2-AD3E-450E9DE2BAB8}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{C011A98B-80BC-470A-BB12-B7AEDBCD164C}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{C1F802DE-03D8-46C7-8691-30F948F1E6A2}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{C36216DC-CA58-40DF-ACA7-DAB2DAD78846}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{C39C5524-3A52-4466-8749-39813B714637}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{C3BDF3EB-6803-41D9-8E17-E8AF1971649E}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{C4A036C2-F3BB-459F-AFDF-CD1811A5A4C0}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{C59830A3-0D46-4BAB-8167-CA1D90C95507}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{CAB3ED07-2399-44AD-A984-009C5F462292}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{D975FC81-BBE4-4526-9660-C03336248EB2}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{DC259110-5506-4B4E-9B62-1EAFE5A05184}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{DC274DE8-062C-4FAE-888B-9BDEFA83F687}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{DCEBE6D4-DE51-4FE4-ABD5-2E98FB022C36}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{DDF189A2-7E69-471D-AAC9-C66DCAF2A99A}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{DDFEC479-CA3C-44FA-B2B2-842F40F178BF}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{DF4EE028-6EF5-4493-A34F-0CCB7777EA2B}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{E74286B9-94F5-4910-9087-B9BE8A2FEDD5}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{E7835EE5-651B-44D6-9845-614A5A74DEDB}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{E896DE5F-CCE5-4808-BCE6-69322E6BA6F1}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{E9822BE9-7497-4007-A18A-D6705E70B5B4}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{EAED58EB-596B-4133-8BD1-9E76317D02CA}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{EBF25881-92E7-443C-8736-15080D3DA796}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{EBF9E003-727E-4B78-9CF9-B08049B236DE}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{EC08531C-23F6-4798-979B-5EADEE610BB3}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{ED79CF58-E809-40CF-A0E7-F21B4E40DD1C}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{EDD4C079-2244-4EB3-B57F-E017074B5A95}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{F0E65841-FC3B-4862-8D2E-445087C7EEDD}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{F358D282-F596-4485-96E0-8FE47AF56A22}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{F781293D-517D-4E28-87AA-E384A07D535C}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{F81F6640-4C24-4AA2-B7A5-4720CE2C6228}
Successfully deleted: [Empty Folder] C:\Users\ad\appdata\local\{FAACF40C-F535-46FF-9CFD-5962AC6D1020}



~~~ FireFox

Successfully deleted: [File] C:\user.js
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\4zffxtbr@videodownloadconverter_4z.com
Successfully deleted the following from C:\Users\ad\AppData\Roaming\mozilla\firefox\profiles\yerqady9.default\prefs.js

user_pref("extensions.AMAZONNEW_NS_PH.searchconf", "{\n \"google\" : {\n \"urlexp\" : \"hxxp(s)?:\\\\/\\\\/www\\\\.google\\\\..*\\\\/.*[?#&]q=([^&]+)\",\n \"rankometer\
user_pref("iminent.webbooster.scripts.minibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar");
user_pref("iminent.webbooster.scripts.minibar.ShowThankyouPixel", "0");
user_pref("iminent.webbooster.scripts.minibar.displayFavLinks", "1");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent101", "1364652338011");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent109", "1364656167372");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent111", "1364656167380");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent112", "1364656208139");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent122", "1364656167387");
user_pref("iminent.webbooster.scripts.sslminibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar");
user_pref("iminent.webbooster.scripts.sslminibar.ShowThankyouPixel", "0");
user_pref("iminent.webbooster.scripts.sslminibar.displayFavLinks", "1");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent102", "1364656013755");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent109", "1364656102980");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent111", "1364656102988");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent112", "1364656106505");
user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent122", "1364656102993");
Emptied folder: C:\Users\ad\AppData\Roaming\mozilla\firefox\profiles\yerqady9.default\minidumps [122 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05/09/2013 at 18:55:11.02
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Please start reading my posts fully so all information is known before you post your next reply.

I asked for the junkware removal tool log and a fresh hijackthis log. So what I need next is a fresh hijackthis log.
 
sorry,.. gonna have to get someone on my pc to help.. its too complicated for me... will get back to you when i have the info... sorry.

Tally
 
Back
Top