Hi all, my machine has been acting somewhat strangely for the past few days as detailed in my post here
http://www.techsupportforum.com/foru...ml#post6338386. It seems to be working better now after running sfcfix but I was told I should post over here just to be sure. Here are my DDS logs
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.17801 BrowserJavaVersion: 11.25.2
Run by Matthew at 18:06:42 on 2015-05-26
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3510.1858 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: Trend Micro Client/Server Security Agent Antivirus *Enabled/Updated* {48929DFC-7A52-A34F-8351-C4DBEDBD9C50}
SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Trend Micro Client/Server Security Agent Anti-spyware *Enabled/Updated* {F3F37C18-5C68-ACC1-B9E1-FFA9963AD6ED}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\Program Files\SafeConnect\scManager.sys
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Users\Matthew\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Users\Matthew\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Users\Matthew\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Users\Matthew\AppData\Local\WindowsSys2.exe
C:\Program Files\SafeConnect\SafeConnectClient.exe
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Trend Micro\Client Server Security Agent\CNTAoSMgr.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
uStart Page =
Google
BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\program files\trend micro\client server security agent\bho\1006\TmIEPlg.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_25\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_25\bin\jp2ssv.dll
uRun: [Google Update] "c:\users\matthew\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [GoogleDriveSync] "c:\program files\google\drive\googledrivesync.exe" /autostart
uRun: [Spotify Web Helper] "c:\users\matthew\appdata\roaming\spotify\SpotifyWebHelper.exe"
uRun: [Spotify] "c:\users\matthew\appdata\roaming\spotify\Spotify.exe" -autostart -minimized
uRun: [f.lux] "c:\users\matthew\appdata\local\fluxsoftware\flux\flux.exe" /noshow
uRun: [System Alert] c:\windows\system32\System Alert.exe
uRun: [D5DB7544-3EC2-44AF-B067-F5ED965A51BC] "c:\users\matthew\appdata\local\WindowsSys2.exe" /STARTUP
uRun: [CCleaner Monitoring] "c:\program files\ccleaner\CCleaner.exe" /MONITOR
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [Broadcom Wireless Manager UI] c:\program files\dell\dw wlan card\WLTRAY.exe
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [OfficeScanNT Monitor] "c:\program files\trend micro\client server security agent\pccntmon.exe" -HideWindow
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [ROC_ROC_NT] "c:\program files\avg secure search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
StartupFolder: c:\users\matthew\appdata\roaming\micros~1\windows\startm~1\programs\startup\facebo~1.lnk - c:\users\matthew\appdata\local\facebook\messenger\2.1.4814.0\FacebookMessenger.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\safeco~1.lnk - c:\program files\safeconnect\scClient.exe
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~1\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} - hxxps://8.19.48.111/CACHE/stc/5/binaries/vpnweb.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{1073343B-1FAB-4179-B69A-2D781B34A266} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{1073343B-1FAB-4179-B69A-2D781B34A266}\144545139333 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{1073343B-1FAB-4179-B69A-2D781B34A266}\36F6C6F6271646F6D27657563747 : DHCPNameServer = 75.75.76.76 75.75.75.75 192.168.33.1
TCP: Interfaces\{1073343B-1FAB-4179-B69A-2D781B34A266}\4556C626F6F583443413 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{94C38BF9-485C-487C-B0AB-898FE16DD0C8} : DHCPNameServer = 128.197.253.188 128.197.253.126
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\program files\trend micro\client server security agent\bho\1006\TmIEPlg.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\43.0.2357.81\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 analytics.microsoft.com
Hosts: 127.0.0.1 metrics.bitdefender.com
Hosts: 127.0.0.1 metrics.mcafee.com
Hosts: 127.0.0.1 om.symantec.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2015-3-4 245096]
R2 DiagTrack;Diagnostics Tracking Service;c:\windows\system32\svchost.exe -k utcsvc [2009-7-13 20992]
R2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);c:\program files\common files\epson\epw!3 ssrp\E_JT50RP.EXE [2014-9-11 142432]
R2 SCManager;SafeConnect Manager;c:\program files\safeconnect\scManager.sys [2012-11-19 176520]
R2 TmFilter;Trend Micro Filter;c:\program files\trend micro\client server security agent\tmxpflt.sys [2010-4-21 281400]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\trend micro\client server security agent\tmpreflt.sys [2010-4-21 38200]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k6232.sys [2012-1-27 214696]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2012-2-24 132480]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2012-2-24 269824]
R3 TmProxy;Trend Micro Client/Server Security Agent Proxy Service;c:\program files\trend micro\client server security agent\tmproxy.exe [2010-4-21 689416]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2014-4-12 103608]
S2 insvc_1.10.0.13;Infonaut 1.10.0.13 Client Service;"c:\program files\infonaut_1.10.0.13\service\insvc.exe" --> c:\program files\infonaut_1.10.0.13\service\insvc.exe [?]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2015-5-13 102912]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-3-7 20464]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 95408]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2015-4-30 284504]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2010-4-21 50704]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2012-2-22 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-1-27 1343400]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S4 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-3-7 652360]
.
=============== Created Last 30 ================
.
2015-05-26 21:37:23 -------- d-----w- C:\AdwCleaner
2015-05-26 21:35:58 9265072 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{017c9874-12a3-4e7d-a7b1-635f66548c11}\mpengine.dll
2015-05-26 21:35:41 -------- d-----w- C:\RegBackup
2015-05-26 21:29:40 -------- d-----w- C:\SFCFix
2015-05-26 21:28:58 -------- d-----w- c:\users\matthew\appdata\local\niemiro
2015-05-21 19:34:12 -------- d-----w- c:\users\matthew\appdata\roaming\4C4C4544-1432236852-5910-8057-C4C04F324D31
2015-05-21 19:34:04 -------- d-----w- c:\users\matthew\appdata\roaming\4C4C4544-1432236844-5910-8057-C4C04F324D31
2015-05-21 19:23:58 -------- d-----w- c:\program files\CCleaner
2015-05-21 17:32:24 -------- d-----w- c:\program files\TECHHUBBYSOL
2015-05-21 17:31:42 -------- d-----w- c:\users\matthew\appdata\local\Techhubby
2015-05-21 17:24:31 -------- d-----w- c:\users\matthew\appdata\local\15357
2015-05-21 17:05:12 128512 ----a-w- c:\users\matthew\appdata\local\WindowsSys2.exe
2015-05-21 17:00:41 -------- d-----w- c:\users\matthew\appdata\roaming\4C4C4544-1432227641-5910-8057-C4C04F324D31
2015-05-21 17:00:17 -------- d-----w- c:\program files\System Alert
2015-05-21 16:57:00 -------- d-----w- c:\users\matthew\appdata\local\Arun Programs
2015-05-21 16:44:23 908832 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{3a6a1fa2-ad3f-4d0d-b322-3549c4b6ec58}\gapaengine.dll
2015-05-21 16:43:50 9265072 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2015-05-14 22:42:39 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 18:30:47 259072 ----a-w- c:\windows\system32\services.exe
2015-05-13 18:28:35 62464 ----a-w- c:\windows\system32\aelupsvc.dll
2015-05-04 05:52:30 -------- d-----w- c:\users\matthew\appdata\local\FluxSoftware
.
==================== Find3M ====================
.
2015-05-26 21:54:39 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-05-26 21:54:39 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-05-05 01:12:49 248832 ----a-w- c:\windows\system32\schannel.dll
2015-04-27 19:11:55 3934144 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-04-27 19:11:54 3989440 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-04-27 19:11:53 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-04-27 19:11:53 137664 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2015-04-27 19:08:02 1307648 ----a-w- c:\windows\system32\ntdll.dll
2015-04-27 19:05:40 172032 ----a-w- c:\windows\system32\wdigest.dll
2015-04-27 19:05:39 851456 ----a-w- c:\windows\system32\diagtrack.dll
2015-04-27 19:05:35 65536 ----a-w- c:\windows\system32\TSpkg.dll
2015-04-27 19:05:34 635392 ----a-w- c:\windows\system32\tdh.dll
2015-04-27 19:05:33 15872 ----a-w- c:\windows\system32\sspisrv.dll
2015-04-27 19:05:33 100352 ----a-w- c:\windows\system32\sspicli.dll
2015-04-27 19:05:32 43008 ----a-w- c:\windows\system32\srclient.dll
2015-04-27 19:05:32 400896 ----a-w- c:\windows\system32\srcore.dll
2015-04-27 19:05:29 92160 ----a-w- c:\windows\system32\sechost.dll
2015-04-27 19:05:29 22016 ----a-w- c:\windows\system32\secur32.dll
2015-04-27 19:05:17 221184 ----a-w- c:\windows\system32\ncrypt.dll
2015-04-27 19:05:11 259584 ----a-w- c:\windows\system32\msv1_0.dll
2015-04-27 19:04:47 1061376 ----a-w- c:\windows\system32\lsasrv.dll
2015-04-27 19:04:45 550912 ----a-w- c:\windows\system32\kerberos.dll
2015-04-27 19:04:37 38912 ----a-w- c:\windows\system32\csrsrv.dll
2015-04-27 19:04:37 17408 ----a-w- c:\windows\system32\credssp.dll
2015-04-27 19:04:33 641536 ----a-w- c:\windows\system32\advapi32.dll
2015-04-27 19:04:24 40448 ----a-w- c:\windows\system32\typeperf.exe
2015-04-27 19:04:24 364544 ----a-w- c:\windows\system32\tracerpt.exe
2015-04-27 19:04:21 69632 ----a-w- c:\windows\system32\smss.exe
2015-04-27 19:04:14 262656 ----a-w- c:\windows\system32\rstrui.exe
2015-04-27 19:04:12 37888 ----a-w- c:\windows\system32\relog.exe
2015-04-27 19:04:05 22528 ----a-w- c:\windows\system32\lsass.exe
2015-04-27 19:04:04 82944 ----a-w- c:\windows\system32\logman.exe
2015-04-27 19:03:58 17408 ----a-w- c:\windows\system32\diskperf.exe
2015-04-27 19:03:52 50176 ----a-w- c:\windows\system32\auditpol.exe
2015-04-27 19:01:33 60416 ----a-w- c:\windows\system32\msobjs.dll
2015-04-27 19:01:22 146432 ----a-w- c:\windows\system32\msaudite.dll
2015-04-27 18:59:41 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-04-27 18:59:36 686080 ----a-w- c:\windows\system32\adtschema.dll
2015-04-27 18:00:30 36864 ----a-w- c:\windows\system32\UtcResources.dll
2015-04-21 16:25:34 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2015-04-21 16:25:20 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2015-04-21 16:11:10 504320 ----a-w- c:\windows\system32\vbscript.dll
2015-04-21 16:11:07 62464 ----a-w- c:\windows\system32\iesetup.dll
2015-04-21 16:10:12 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll
2015-04-21 16:09:57 341504 ----a-w- c:\windows\system32\html.iec
2015-04-21 16:08:41 64000 ----a-w- c:\windows\system32\MshtmlDac.dll
2015-04-21 15:58:45 115712 ----a-w- c:\windows\system32\ieUnatt.exe
2015-04-21 15:58:44 102912 ----a-w- c:\windows\system32\ieetwcollector.exe
2015-04-21 15:57:57 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2015-04-21 15:51:54 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2015-04-21 15:43:28 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2015-04-21 15:31:13 4305920 ----a-w- c:\windows\system32\jscript9.dll
2015-04-21 15:25:45 2052608 ----a-w- c:\windows\system32\inetcpl.cpl
2015-04-21 15:24:48 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll
2015-04-21 15:02:00 1882112 ----a-w- c:\windows\system32\wininet.dll
2015-04-20 02:56:29 909312 ----a-w- c:\windows\system32\FntCache.dll
2015-04-20 02:56:29 1250816 ----a-w- c:\windows\system32\DWrite.dll
2015-04-20 02:03:22 2382336 ----a-w- c:\windows\system32\win32k.sys
2015-04-18 02:56:57 342016 ----a-w- c:\windows\system32\certcli.dll
2015-04-14 07:38:52 1217192 ----a-w- c:\windows\system32\FM20.DLL
2015-04-08 03:14:07 22528 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
2015-04-08 03:14:07 216064 ----a-w- c:\windows\system32\InkEd.dll
2015-04-08 03:14:07 19968 ----a-w- c:\windows\system32\jnwmon.dll
2015-03-25 03:00:57 92672 ----a-w- c:\windows\system32\wudriver.dll
2015-03-25 03:00:57 3088384 ----a-w- c:\windows\system32\wucltux.dll
2015-03-25 03:00:57 173056 ----a-w- c:\windows\system32\wuwebv.dll
2015-03-25 03:00:27 50176 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-03-25 03:00:18 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-03-25 03:00:15 33792 ----a-w- c:\windows\system32\wuapp.exe
2015-03-23 03:06:47 576000 ----a-w- c:\windows\system32\generaltel.dll
2015-03-23 03:06:32 630784 ----a-w- c:\windows\system32\invagent.dll
2015-03-23 03:06:26 331264 ----a-w- c:\windows\system32\devinv.dll
2015-03-23 03:06:22 860160 ----a-w- c:\windows\system32\appraiser.dll
2015-03-23 03:06:21 26112 ----a-w- c:\windows\system32\acmigration.dll
2015-03-23 03:06:21 202752 ----a-w- c:\windows\system32\aepdu.dll
2015-03-23 03:06:21 159744 ----a-w- c:\windows\system32\aepic.dll
2015-03-23 02:59:03 896000 ----a-w- c:\windows\system32\aeinv.dll
2015-03-10 03:08:26 1237504 ----a-w- c:\windows\system32\msxml3.dll
2015-03-10 03:05:39 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-03-05 04:06:01 305152 ----a-w- c:\windows\system32\gdi32.dll
2015-03-04 23:34:52 95408 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2015-03-04 23:34:52 245096 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2015-03-04 04:16:14 249784 ----a-w- c:\windows\system32\clfs.sys
2015-03-04 04:11:12 5120 ----a-w- c:\windows\system32\shimeng.dll
2015-03-04 04:10:54 58880 ----a-w- c:\windows\system32\clfsw32.dll
2015-03-04 04:10:53 295936 ----a-w- c:\windows\system32\apphelp.dll
2015-03-04 04:10:52 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2015-03-04 04:10:52 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2015-03-04 04:10:37 20992 ----a-w- c:\windows\system32\sdbinst.exe
2015-03-04 04:06:41 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2015-03-03 13:16:52 246920 ------w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 18:07:28.52 ===============
and I've attached attach.txt as well. I also recently cleaned out my browsers using Junkware Removal Tool and ADWCleaner. Here are my JRT logs ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.8.0 (05.25.2015:1)
OS: Windows 7 Professional x86
Ran by Matthew on Tue 05/26/2015 at 17:35:39.26
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Failed to stop: [Service] apnmcp
Successfully stopped: [Service] brshelper
Successfully deleted: [Service] brshelper
Successfully stopped: [Service] netfilter
Successfully deleted: [Service] netfilter
Successfully stopped: [Service] smupd
Successfully deleted: [Service] smupd
Successfully stopped: [Service] smupdd
Successfully deleted: [Service] smupdd
Successfully stopped: [Service] spbiupd
Successfully deleted: [Service] spbiupd
Successfully stopped: [Service] spbiupdd
Successfully deleted: [Service] spbiupdd
~~~ Tasks
Successfully deleted: [Task] C:\Windows\System32\tasks\AI_Updater
Successfully deleted: [Task] C:\Windows\System32\tasks\boosterpop
Successfully deleted: [Task] C:\Windows\System32\tasks\HDNINSTSCHD
Successfully deleted: [Task] C:\Windows\System32\tasks\IE_ERR4WDR
Successfully deleted: [Task] C:\Windows\System32\tasks\IEError
Successfully deleted: [Task] C:\Windows\System32\tasks\PCPrivacyDock_Master
Successfully deleted: [Task] C:\Windows\System32\tasks\PCPrivacyDock_Popup
Successfully deleted: [Task] C:\Windows\System32\tasks\PCPrivacyDock_Popup3
Successfully deleted: [Task] C:\Windows\System32\tasks\PCPrivacyDock_Start
Successfully deleted: [Task] C:\Windows\System32\tasks\UPDTEXE4_WDR
~~~ Registry Values
Failed to delete: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hawker
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\pcprivacydock
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\hawker
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AskPartnerNetwork
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\AskPartnerNetwork
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\158D6D9E3FE81FA428925F22ACB3A965
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15E6C514FEFC09F45BAFAAE1D7546ED4
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DB42320A8525634AA089F0BEC86473B
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22468B0D6050B2E46B9C4B67A8F59577
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2251BF05A2F606D43BB064BD63CBD87E
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3CDF313E9B28C944FBC7579CF4949414
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71E54748EDD3DC1468548785DC856EDA
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\754590DD06DE8D249B526503432F99D4
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8036C72171EF4BA46856BF57969F6A36
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CBC85D72B148084ABE8C2F072F781F4
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC5A38A64D6098468BC8395BA0EFF03
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8DF9A1AC557F56C49B56F6B83E293C15
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CFA51B44D54927C4E9B7BC1D3FD1E49F
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D14A7F65792054F418578C78367D13F7
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFE9F0BD163D827438CB6AD6B100EC48
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F739A19A8327DC64C9A8B641A9E89646
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220222622278}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{853130B6-1A29-4D9D-9513-2A461287651E}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660266626678}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Toolbar.CT3072253
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Toolbar.CT3298566
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{80CFE4F4-B31A-4850-8A62-67832B628DBA}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660266626678}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3072253
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3298566
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{853130B6-1A29-4D9D-9513-2A461287651E}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update Shop Time
~~~ Files
Successfully deleted: [File] C:\end
Successfully deleted: [File] C:\Windows\verson_hawker.txt
Successfully deleted: [File] C:\Users\Matthew\appdata\local\nsaE9B7.tmp
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\aghaobcn\encecal.dll [Adware.AdPeak?]
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\cbhicrqr\encecal.dll [Adware.AdPeak?]
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\fuzwseql\encecal.dll [Adware.AdPeak?]
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\newxfolq\encecal.dll [Adware.AdPeak?]
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\szfaqduc\encecal.dll [Adware.AdPeak?]
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\zgzmikpx\encecal.dll [Adware.AdPeak?]
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\zosaxknb\encecal.dll [Adware.AdPeak?]
~~~ Folders
Successfully deleted: [Folder] C:\Program Files\app_setup
Successfully deleted: [Folder] C:\Program Files\askpartnernetwork
Successfully deleted: [Folder] C:\Program Files\conduit
Successfully deleted: [Folder] C:\Program Files\delta
Successfully deleted: [Folder] C:\Program Files\PariccELess
Successfully deleted: [Folder] C:\Program Files\pcp
Successfully deleted: [Folder] C:\Program Files\PorriceLeossa
Successfully deleted: [Folder] C:\Program Files\portable weatherapp
Successfully deleted: [Folder] C:\Program Files\predm
Successfully deleted: [Folder] C:\Program Files\searchprotect
Successfully deleted: [Folder] C:\ProgramData\abc
Successfully deleted: [Folder] C:\ProgramData\apn
Successfully deleted: [Folder] C:\ProgramData\askpartnernetwork
Successfully deleted: [Folder] C:\ProgramData\babylon
Successfully deleted: [Folder] C:\ProgramData\browserdefender
Successfully deleted: [Folder] C:\ProgramData\microsoft\windows\start menu\programs\hawker
Successfully deleted: [Folder] C:\Users\Matthew\appdata\local\installer
Successfully deleted: [Folder] C:\Users\Matthew\appdata\locallow\claro ltd
Successfully deleted: [Folder] C:\Users\Matthew\appdata\locallow\conduit
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\microsoft\windows\start menu\programs\pc performer
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\pc privacy dock
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\performersoft
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\search protection
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\searchprotect
Successfully deleted: [Folder] C:\Users\Matthew\documents\optimizer pro
Successfully deleted: [Folder] C:\Users\Matthew\documents\pcprivacydock
Successfully deleted: [Folder] C:\Users\Matthew\local settings\application data\askpartnernetwork
Successfully deleted: [Folder] C:\Users\Matthew\local settings\application data\conduit
Successfully deleted: [Folder] C:\Users\Matthew\local settings\application data\crashrpt
Successfully deleted: [Folder] C:\Users\Matthew\local settings\application data\cre
Successfully deleted: [Folder] C:\Users\Matthew\local settings\application data\pc_privacy_dock
Successfully deleted: [Folder] C:\Users\Matthew\appdata\local\ospd_us_1071 [Adware.EoRezo]
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\aghaobcn [Adware.AdPeak?]
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\cbhicrqr [Adware.AdPeak?]
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\fuzwseql [Adware.AdPeak?]
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\newxfolq [Adware.AdPeak?]
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\szfaqduc [Adware.AdPeak?]
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\zgzmikpx [Adware.AdPeak?]
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\zosaxknb [Adware.AdPeak?]
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\user.js
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\bprotector_extensions.sqlite
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\bprotector_prefs.js
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\searchplugins\babylon.xml
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\searchplugins\bprotect.xml
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\searchplugins\conduit.xml
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\searchplugins\delta.xml
Successfully deleted: [File] C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\searchplugins\yahoo_ff.xml
Successfully deleted: [Folder] C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\smartbar
Successfully deleted the following from C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\prefs.js
user_pref(CT3072253.ENABALE_HISTORY, {\dataType\:\string\,\data\:\true\});
user_pref(CT3072253.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE, {\dataType\:\string\,\data\:\true\});
user_pref(CT3072253.Facebook_Mode, 2);
user_pref(CT3072253.Facebook_User_Locale, en);
user_pref(CT3072253.FirstTime, true);
user_pref(CT3072253.FirstTimeFF3, true);
user_pref(CT3072253.UserID, UN56340175764143331);
user_pref(CT3072253.addressBarTakeOverEnabledInHidden, true);
user_pref(CT3072253.autoDisableScopes, -1);
user_pref(CT3072253.cb_experience_000, 88);
user_pref(CT3072253.cb_firstuse0100, 1);
user_pref(CT3072253.cbcountry_001, US);
user_pref(CT3072253.cbfirsttime, Sun Aug 12 2012 17:39:08 GMT-0400 (Eastern Daylight Time));
user_pref(CT3072253.defaultSearch, FALSE);
user_pref(CT3072253.embeddedsData, [{\appId\:\129571859753931591\,\apiPermissions\:{\crossDomainAjax\:true,\getMainFrameTitle\:true,\getMainFrameUrl\:true,\get
user_pref(CT3072253.enableAlerts, always);
user_pref(CT3072253.enableSearchFromAddressBar, FALSE);
user_pref(CT3072253.firstTimeDialogOpened, true);
user_pref(CT3072253.fixPageNotFoundError, true);
user_pref(CT3072253.fixPageNotFoundErrorInHidden, true);
user_pref(CT3072253.fixUrls, true);
user_pref(CT3072253.hxxp___facebook_conduitapps_com.APP_WIN_FEATURES, resizable=0,hscroll=0,vscroll=0,titlebar=1,closebutton=1,saveresizedsize=0,openposition=alignment:(B;L
user_pref(CT3072253.hxxp___www_socialgrowthtechnologies_com_couponbuddy_v001.APP_WIN_FEATURES, openposition=offset:50;50,savelocation=0,resizable=no,scrollbars=no,titlebar=
user_pref(CT3072253.installId, fft2CD1.tmp.exe);
user_pref(CT3072253.installType, XPE);
user_pref(CT3072253.isEnableAllDialogs, {\dataType\:\string\,\data\:\true\});
user_pref(CT3072253.isNewTabEnabled, true);
user_pref(CT3072253.isPerformedSmartBarTransition, true);
user_pref(CT3072253.isToolbarShrinked, {\dataType\:\string\,\data\:\false\});
user_pref(CT3072253.isWelcomPage, {\dataType\:\boolean\,\data\:\true\});
user_pref(CT3072253.navigationAliasesJson, {\EB_SEARCH_TERM\:\\,\EB_MAIN_FRAME_URL\:\hxxp%3A%2F%2Fwww.reddit.com%2Fr%2FHistoricalWhatIf%2F\,\EB_MAIN_FRAME_TITLE\:
user_pref(CT3072253.newSettings, {\dataType\:\boolean\,\data\:\true\});
user_pref(CT3072253.openThankYouPage, true);
user_pref(CT3072253.openUninstallPage, FALSE);
user_pref(CT3072253.search.searchAppId, 129571859753931591);
user_pref(CT3072253.search.searchCount, 1);
user_pref(CT3072253.searchInNewTabEnabledInHidden, true);
user_pref(CT3072253.selectToSearchBoxEnabled, {\dataType\:\string\,\data\:\true\});
user_pref(CT3072253.serviceLayer_service_login_isFirstLoginInvoked, {\dataType\:\boolean\,\data\:\true\});
user_pref(CT3072253.serviceLayer_service_login_loginCount, {\dataType\:\number\,\data\:\4\});
user_pref(CT3072253.serviceLayer_service_toolbarGrouping_activeCTID, {\dataType\:\string\,\data\:\CT3072253\});
user_pref(CT3072253.serviceLayer_service_toolbarGrouping_activeDownloadUrl, {\dataType\:\string\,\data\:\hxxp://uTorrentControl2.OurToolbar.com//xpi\});
user_pref(CT3072253.serviceLayer_service_toolbarGrouping_activeToolbarName, {\dataType\:\string\,\data\:\uTorrentControl2\});
user_pref(CT3072253.serviceLayer_service_toolbarGrouping_invoked, {\dataType\:\string\,\data\:\true\});
user_pref(CT3072253.serviceLayer_service_usage_toolbarUsageCount, {\dataType\:\number\,\data\:\2\});
user_pref(CT3072253.serviceLayer_services_appTrackingFirstTime_lastUpdate, 1349896906457);
user_pref(CT3072253.serviceLayer_services_appTracking_lastUpdate, 1344807547583);
user_pref(CT3072253.serviceLayer_services_appsMetadata_lastUpdate, 1350127424176);
user_pref(CT3072253.serviceLayer_services_gottenAppsContextMenu_lastUpdate, 1349037393233);
user_pref(CT3072253.serviceLayer_services_login_10.10.20.14_lastUpdate, 1354985899027);
user_pref(CT3072253.serviceLayer_services_otherAppsContextMenu_lastUpdate, 1349037393412);
user_pref(CT3072253.serviceLayer_services_searchAPI_lastUpdate, 1350155994255);
user_pref(CT3072253.serviceLayer_services_serviceMap_lastUpdate, 1354928324535);
user_pref(CT3072253.serviceLayer_services_toolbarContextMenu_lastUpdate, 1349037393314);
user_pref(CT3072253.serviceLayer_services_toolbarSettings_lastUpdate, 1354985898654);
user_pref(CT3072253.serviceLayer_services_translation_lastUpdate, 1354928324723);
user_pref(CT3072253.settingsINI, true);
user_pref(CT3072253.shouldFirstTimeDialog, false);
user_pref(CT3072253.smartbar.CTID, CT3072253);
user_pref(CT3072253.smartbar.Uninstall, 0);
user_pref(CT3072253.smartbar.toolbarName, uTorrentControl2 );
user_pref(CT3072253.startPage, userChanged);
user_pref(CT3072253.toolbarBornServerTime, 13-8-2012);
user_pref(CT3072253.toolbarCurrentServerTime, 8-12-2012);
user_pref(CT3072253.url_history0001, hxxp://www.politifact.com/truth-o-meter/article/2012/oct/08/suggest-fact-check-us-use-politifactthis/:::clickhandler:::1350008771659,,,
user_pref(CT3298566.1000082.isPlayDisplay, true);
user_pref(CT3298566.1000082.state, {\state\:\stopped\,\text\:\Californi...\,\description\:\California Rock - Rock\,\url\:\hxxp://www.feedlive.net/california.
user_pref(CT3298566.ENABALE_HISTORY, {\dataType\:\string\,\data\:\true\});
user_pref(CT3298566.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE, {\dataType\:\string\,\data\:\true\});
user_pref(CT3298566.FF19Solved, true);
user_pref(CT3298566.FirstTime, true);
user_pref(CT3298566.FirstTimeFF3, true);
user_pref(CT3298566.SearchFromAddressBarUrl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3298566&SearchSource=2&CUI=UN39718417211268134&UM=2&q=);
user_pref(CT3298566.TopHitsConfig.enc, ew0KICAgICJzcHJpdGVVcmwiOiAiaHR0cDovL3N0b3JhZ2UuY29uZHVpdC5jb20vcHMvVG9wSGl0c0dlbmVyaWNBcHAvY29uZmlncy9VUy1VSy1EYW5jZS1Sb2NrLVJhcC9zc
user_pref(CT3298566.UserID, UN39718417211268134);
user_pref(CT3298566.YTbyClickFavorites.enc, W10=);
user_pref(CT3298566.YTbyClickRecent.enc, W10=);
user_pref(CT3298566.addressBarTakeOverEnabledInHidden, true);
user_pref(CT3298566.autoDisableScopes, 14);
user_pref(CT3298566.browser.search.defaultthis.engineName, true);
user_pref(CT3298566.defaultSearch, true);
user_pref(CT3298566.embeddedsData, [{\appId\:\130110228003246321\,\apiPermissions\:{\crossDomainAjax\:true,\getMainFrameTitle\:true,\getMainFrameUrl\:true,\get
user_pref(CT3298566.enableAlerts, true);
user_pref(CT3298566.enableFix404ByUser, TRUE);
user_pref(CT3298566.enableSearchFromAddressBar, true);
user_pref(CT3298566.firstTimeDialogOpened, true);
user_pref(CT3298566.fixPageNotFoundError, true);
user_pref(CT3298566.fixPageNotFoundErrorByUser, true);
user_pref(CT3298566.fixPageNotFoundErrorInHidden, true);
user_pref(CT3298566.fixUrls, true);
user_pref(CT3298566.installDate, 28/5/2013 10:39:40);
user_pref(CT3298566.installId, cid111);
user_pref(CT3298566.installSessionId, {8AC80814-5EA5-41F2-A7C3-8D330E2C214E});
user_pref(CT3298566.installSp, TRUE);
user_pref(CT3298566.installType, conduitnsisintegration);
user_pref(CT3298566.installUsage, 2013-06-06T01:31:20.4418221+03:00);
user_pref(CT3298566.installUsageEarly, 2013-06-06T01:31:17.5245473+03:00);
user_pref(CT3298566.installerVersion, 1.4.2.3);
user_pref(CT3298566.isCheckedStartAsHidden, true);
user_pref(CT3298566.isEnableAllDialogs, {\dataType\:\string\,\data\:\true\});
user_pref(CT3298566.isFirstTimeToolbarLoading, false);
user_pref(CT3298566.isToolbarShrinked, {\dataType\:\string\,\data\:\false\});
user_pref(CT3298566.keyword, true);
user_pref(CT3298566.lastNewTabSettings, {\isEnabled\:false,\newTabUrl\:\hxxp://search.conduit.com/?ctid=CT3298566&octid=CT3298566&SearchSource=15&CUI=UN397184172112681
user_pref(CT3298566.lastVersion, 10.16.300.3);
user_pref(CT3298566.mam_gk_appStateReportTime.enc, MTM3MDQ3MTQ4OTk1Nw==);
user_pref(CT3298566.mam_gk_appState_CouponBuddy.enc, b24=);
user_pref(CT3298566.mam_gk_appState_PriceGong.enc, b24=);
user_pref(CT3298566.mam_gk_appState_WindowShopper.enc, b24=);
user_pref(CT3298566.mam_gk_appsData.enc, eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9wcmljZWdvbmcuY29uZHVpdGFwcHMuY29tL01BTS92MS9odG1sX2NvbXAuaHRtbCIsIm9wdGlvbnN
user_pref(CT3298566.mam_gk_appsDefaultEnabled.enc, dHJ1ZQ==);
user_pref(CT3298566.mam_gk_configuration.enc, eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IlByaWNlR29uZyIsImNyaXRlcmlhcyI6W3siY3JpdGVyaWFJZCI6ImE1NGZiYjczLWU3OWEtNDAwOS04NjUxLTFiYTYxZW
user_pref(CT3298566.mam_gk_currentVersion.enc, MS42LjAuOTk=);
user_pref(CT3298566.mam_gk_eventsCache.enc, eyI2Njc2Mzc0Zi1kODI3LTRkZGMtOTc0NC1hZjk4NTdiOWY0YWMiOnsidG9waWMiOiJzZW5kVXNhZ2UiLCJkYXRhIjp7ImNhdGVnb3J5IjoiV2VsY29tZSIsImFjdGlv
user_pref(CT3298566.mam_gk_first_time.enc, MQ==);
user_pref(CT3298566.mam_gk_gadgetOpen.enc, d2VsY29tZQ==);
user_pref(CT3298566.mam_gk_installer_preapproved.enc, ZmFsc2U=);
user_pref(CT3298566.mam_gk_lastLoginTime.enc, MTM3MDQ3MTQ4NjExMQ==);
user_pref(CT3298566.mam_gk_localization.enc, eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50IFBvbGljeSJ9LCJnYWRnZXREZXNjcmlwdGlvblByaW1hcnkiOnsiVGV4dCI6IlZhbHVlIEFwcHM
user_pref(CT3298566.mam_gk_pgUnloadedOnce.enc, dHJ1ZQ==);
user_pref(CT3298566.mam_gk_settings1.6.0.99.enc, eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMV8wIiwiaXNUZXN0Ijp0cnVlLCJpc1dlbGNvbWVFeHBlcmllbmN
user_pref(CT3298566.mam_gk_showCloseButton.enc, dHJ1ZQ==);
user_pref(CT3298566.mam_gk_showWelcomeGadget.enc, dHJ1ZQ==);
user_pref(CT3298566.mam_gk_userId.enc, MGZjMmMyNTEtODY0MC00OTVlLWIwZTYtZjk2M2E4NWU0Yjhi);
user_pref(CT3298566.migrateAppsAndComponents, true);
user_pref(CT3298566.navigationAliasesJson, {\EB_MAIN_FRAME_URL\:\\,\EB_MAIN_FRAME_TITLE\:\\,\EB_SEARCH_TERM\:\\,\EB_TOOLBAR_SUB_DOMAIN\:\hxxp://MixiDJV30.Our
user_pref(CT3298566.openThankYouPage, false);
user_pref(CT3298566.openUninstallPage, true);
user_pref(CT3298566.originalHomepage, hxxp://www.politifact.com);
user_pref(CT3298566.originalSearchAddressUrl, hxxps://isearch.avg.com/search?cid=%7B68322086-56e8-4ee9-8507-5b41541fc664%7D&mid=23513c543f7747d0ac4a8d6f4cdee406-72980b38dd9
user_pref(CT3298566.originalSearchEngine, Bing);
user_pref(CT3298566.revertSettingsEnabled, false);
user_pref(CT3298566.search.searchAppId, 130110228003246321);
user_pref(CT3298566.search.searchCount, 0);
user_pref(CT3298566.searchFromAddressBarEnabledByUser, true);
user_pref(CT3298566.searchInNewTabEnabledByUser, true);
user_pref(CT3298566.searchInNewTabEnabledInHidden, true);
user_pref(CT3298566.searchProtector.notifyChanges, {\dataType\:\string\,\data\:\false\});
user_pref(CT3298566.searchRevert, false);
user_pref(CT3298566.searchUserMode, 2);
user_pref(CT3298566.selectToSearchBoxEnabled, {\dataType\:\string\,\data\:\true\});
user_pref(CT3298566.serviceLayer_service_login_isFirstLoginInvoked, {\dataType\:\boolean\,\data\:\true\});
user_pref(CT3298566.serviceLayer_service_login_loginCount, {\dataType\:\number\,\data\:\4\});
user_pref(CT3298566.serviceLayer_service_toolbarGrouping_activeCTID, {\dataType\:\string\,\data\:\CT3298566\});
user_pref(CT3298566.serviceLayer_service_toolbarGrouping_activeDownloadUrl, {\dataType\:\string\,\data\:\hxxp://MixiDJV30.OurToolbar.com//xpi\});
user_pref(CT3298566.serviceLayer_service_toolbarGrouping_activeToolbarName, {\dataType\:\string\,\data\:\MixiDJ V30\});
user_pref(CT3298566.serviceLayer_service_toolbarGrouping_invoked, {\dataType\:\string\,\data\:\true\});
user_pref(CT3298566.serviceLayer_services_appTrackingFirstTime_lastUpdate, 1370471481986);
user_pref(CT3298566.serviceLayer_services_appsMetadata_lastUpdate, 1370471481929);
user_pref(CT3298566.serviceLayer_services_gottenAppsContextMenu_lastUpdate, 1370471481837);
user_pref(CT3298566.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate, 1370471480121);
user_pref(CT3298566.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate, 1370471482579);
user_pref(CT3298566.serviceLayer_services_location_lastUpdate, 1370471480550);
user_pref(CT3298566.serviceLayer_services_login_10.16.300.3_lastUpdate, 1370471482278);
user_pref(CT3298566.serviceLayer_services_otherAppsContextMenu_lastUpdate, 1370471481885);
user_pref(CT3298566.serviceLayer_services_searchAPI_lastUpdate, 1370471480129);
user_pref(CT3298566.serviceLayer_services_serviceMap_lastUpdate, 1370471478267);
user_pref(CT3298566.serviceLayer_services_toolbarContextMenu_lastUpdate, 1370471481778);
user_pref(CT3298566.serviceLayer_services_toolbarSettings_lastUpdate, 1370471479349);
user_pref(CT3298566.serviceLayer_services_translation_lastUpdate, 1370471481958);
user_pref(CT3298566.settingsINI, true);
user_pref(CT3298566.shouldFirstTimeDialog, false);
user_pref(CT3298566.showToolbarPermission, false);
user_pref(CT3298566.smartbar.CTID, CT3298566);
user_pref(CT3298566.smartbar.Uninstall, 0);
user_pref(CT3298566.smartbar.homepage, true);
user_pref(CT3298566.smartbar.toolbarName, MixiDJ V30 );
user_pref(CT3298566.startPage, true);
user_pref(CT3298566.toolbarBornServerTime, 6-6-2013);
user_pref(CT3298566.toolbarCurrentServerTime, 6-6-2013);
user_pref(CT3298566.toolbarLoginClientTime, Wed Jun 05 2013 16:31:22 GMT-0600 (Mountain Daylight Time));
user_pref(CT3298566.versionFromInstaller, 10.16.300.3);
user_pref(CT3298566_Firefox.csv, [{\from\:\Abs Layer\,\action\:\loading toolbar\,\time\:1371080184969,\isWithState\:\\,\timeFromStart\:0,\timeFromPrev\:0}
user_pref(Smartbar.ConduitHomepagesList, hxxp://search.conduit.com/?ctid=CT3298566&octid=CT3298566&SearchSource=61&CUI=UN39718417211268134&UM=2&UP=SP6BA6D775-929A-47FA-A5DB
user_pref(Smartbar.ConduitSearchEngineList, MixiDJ V30 Customized Web Search);
user_pref(Smartbar.ConduitSearchUrlList, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3298566&SearchSource=2&CUI=UN39718417211268134&UM=2&q=);
user_pref(Smartbar.SearchFromAddressBarSavedUrl, hxxps://isearch.avg.com/search?cid=%7B68322086-56e8-4ee9-8507-5b41541fc664%7D&mid=23513c543f7747d0ac4a8d6f4cdee406-72980b38
user_pref(Smartbar.keywordURLSelectedCTID, CT3298566);
user_pref(browser.search.defaultthis.engineName, MixiDJ V30 Customized Web Search);
user_pref(browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3298566&CUI=UN39718417211268134&UM=2&SearchSource=3&q={searchTerms});
user_pref(extensions.506a239b818d5.scode, (function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\acebook\)>-1||url.indexOf(\warnalert11.co
user_pref(extensions.BabylonToolbar_i.newTab, true);
user_pref(extensions.BabylonToolbar_i.newTabUrl, hxxp://www.claro-search.com/?affID=114506&tt=3912_2&babsrc=NT_clro&mntrId=6eb04da700000000000068a3c4169287);
user_pref(extensions.GXTKBkXggUm6P5CH.scode, (function(){try{if(window.location.href.indexOf(\rjr5qHsFrTY5qdrEpdn9qjg5qTY\)>-1){return;}}catch(e){}try{var d=[[\
www.virac
user_pref(extensions.QoFSdcLQt2HsQt3X.scode, (function(){try{if(window.location.href.indexOf(\rjr5qHsFrTY5qdrEpdn9qjg5qTY\)>-1){return;}}catch(e){}try{var d=[[\
www.virac
user_pref(extensions.claro.admin, false);
user_pref(extensions.claro.aflt, babsst);
user_pref(extensions.claro.dfltLng, en);
user_pref(extensions.claro.excTlbr, false);
user_pref(extensions.claro.id, 6eb04da700000000000068a3c4169287);
user_pref(extensions.claro.instlDay, 15611);
user_pref(extensions.claro.instlRef, sst);
user_pref(extensions.claro.prdct, claro);
user_pref(extensions.claro.prtnrId, claro);
user_pref(extensions.claro.tlbrId, claro);
user_pref(extensions.claro.vrsn, 1.6.4.1);
user_pref(extensions.claro.vrsni, 1.6.4.1);
user_pref(extensions.claro_i.smplGrp, none);
user_pref(extensions.claro_i.vrsnTs, 1.6.4.19:19:16);
user_pref(extensions.crossriderapp26278.adsOldValue, 10);
user_pref(extensions.delta.admin, false);
user_pref(extensions.delta.aflt, babsst);
user_pref(extensions.delta.appId, {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3});
user_pref(extensions.delta.autoRvrt, false);
user_pref(extensions.delta.dfltLng, en);
user_pref(extensions.delta.excTlbr, false);
user_pref(extensions.delta.ffxUnstlRst, true);
user_pref(extensions.delta.id, 6eb04da700000000000068a3c4169287);
user_pref(extensions.delta.instlDay, 15869);
user_pref(extensions.delta.instlRef, sst);
user_pref(extensions.delta.newTab, false);
user_pref(extensions.delta.prdct, delta);
user_pref(extensions.delta.prtnrId, delta);
user_pref(extensions.delta.rvrt, false);
user_pref(extensions.delta.smplGrp, none);
user_pref(extensions.delta.tlbrId, base);
user_pref(extensions.delta.tlbrSrchUrl, );
user_pref(extensions.delta.vrsn, 1.8.21.5);
user_pref(extensions.delta.vrsnTs, 1.8.21.521:20:09);
user_pref(extensions.delta.vrsni, 1.8.21.5);
user_pref(extensions.delta_i.babExt, );
user_pref(extensions.delta_i.babTrack, affID=121441);
user_pref(extensions.delta_i.srcExt, ss);
user_pref(extentions.y2layers.defaultEnableAppsList, bestvideodownloader,buzzdock,YontooNewOffers);
user_pref(extentions.y2layers.installId, 425c3413-d80b-4bd8-b00f-453b06906a2e);
user_pref(smartbar.addressBarOwnerCTID, CT3298566);
user_pref(smartbar.conduitHomepageList, hxxp://search.conduit.com/?ctid=CT3298566&CUI=UN39718417211268134&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3298566&oct
user_pref(smartbar.conduitSearchAddressUrlList, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3298566&SearchSource=2&CUI=UN39718417211268134&UM=2&q=);
user_pref(smartbar.defaultSearchOwnerCTID, CT3298566);
user_pref(smartbar.homePageOwnerCTID, CT3298566);
user_pref(smartbar.machineId, /C9+HS/UZI29/BYW3IEXF1QOXZFQOIWDS+UPN/AKINQHLFNKGLDGPSZV7OIMWSRNYID0BZGXT8/QZCGWTAUWMW);
user_pref(smartbar.originalHomepage, hxxp://search.conduit.com/?ctid=CT3298566&CUI=UN39718417211268134&UM=2&SearchSource=13);
Emptied folder: C:\Users\Matthew\AppData\Roaming\mozilla\firefox\profiles\ekw1m3zj.default\minidumps [53 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 05/26/2015 at 17:37:31.29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
and my ADW logs # AdwCleaner v4.205 - Logfile created 26/05/2015 at 17:39:40
# Updated 21/05/2015 by Xplode
# Database : 2015-05-25.3 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x86)
# Username : Matthew - MATTHEW
# Running from : C:\Users\Matthew\Downloads\adwcleaner_4.205.exe
# Option : Cleaning
***** [ Services ] *****
[#] Service Deleted : APNMCP
[#] Service Deleted : SPDRIVER_1.42.1.1870
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\2650880150728770864
Folder Deleted : C:\ProgramData\a7cc6c19000017a9
Folder Deleted : C:\ProgramData\{7c0bff9e-a75a-d21f-7c0b-bff9ea75fe7a}
Folder Deleted : C:\Program Files\ConnectPC
Folder Deleted : C:\Program Files\Hawker
Folder Deleted : C:\Program Files\Priceless
Folder Deleted : C:\Users\Matthew\AppData\Local\Temp\apn
Folder Deleted : C:\Users\Matthew\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbnkklencjcmkepldaineciclcheaoef
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja
Folder Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Folder Deleted : C:\ProgramData\bjpchbfkcjcpafkggdmjcgkhilammejk
Folder Deleted : C:\ProgramData\coffdcpgfndebnobjbdimccfjkbjhdhb
File Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gighmmpiobklfepjocnamgkkbiglidom_0.localstorage
File Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kbmfpngjjgdllneeigpgjifpgocmfgmb_0.localstorage
File Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_laankejkbhbdhmipfmgcngdelahlfoji_0.localstorage
File Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mgijmajocgfcbeboacabfgobmjgjcoja_0.localstorage
File Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mgijmajocgfcbeboacabfgobmjgjcoja
File Deleted : C:\Program Files\Common Files\System\SysMenu.dll
File Deleted : C:\Windows\system32\drivers\netfilter.sys
File Deleted : C:\Users\Matthew\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Program Files\Mozilla Firefox\nsprotector.js
File Deleted : C:\Program Files\Mozilla Firefox\browser\nsprotector.js
File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
File Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
File Deleted : C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\bprotector web data
***** [ Scheduled tasks ] *****
Task Deleted : EPUpdater
Task Deleted : gtaUpt
Task Deleted : Inst_Rep
Task Deleted : ShopperPro
Task Deleted : ShopperProJSUpd
Task Deleted : SPDriver
Task Deleted : amiupdaterExd
Task Deleted : amiupdaterExi
Task Deleted : PCPrivacyDock_Start
Task Deleted : PCPrivacyDock_Popup
Task Deleted : PCPrivacyDock_Master
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Google\Chrome\Extensions\fdkednngfjmpnljkolbapdednncafhen
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fdkednngfjmpnljkolbapdednncafhen
Key Deleted : HKCU\Software\Google\Chrome\Extensions\apdfllckaahabafndbhieahigkjlhalf
Key Deleted : HKCU\Software\Google\Chrome\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh
Key Deleted : HKLM\SOFTWARE\Classes\AppID\AddonsFramework.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\PropertySync.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5}
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D}
Key Deleted : HKCU\Software\5d538cd9b068bd46
Key Deleted : HKLM\SOFTWARE\5d538cd9b068bd46
Key Deleted : HKLM\SOFTWARE\7b7d31ed-8fad-3564-87a6-c1c422265cf1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{19975B78-1907-4DD6-A437-4C48120F46A4}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CCC3E766-7BA9-4629-AC1A-7F4B7F362E65}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97C47A30-3CFB-474B-94E3-6019A7EE0610}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F398D871-ED00-42A8-BEAA-0209E9E59FCC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CF50C82-4C4B-43E9-B1B2-15CB1BD0C193}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{16466D47-74A8-4928-B8B2-07CD79ABFC9F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26D5CC0A-7A46-4D86-AF45-2EFA320B0C54}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D13AC8F-037E-40C5-ADA6-231BA74EA2F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{322EDCF5-9E7D-4021-8C67-F3FFE4961A38}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E254398-828F-4D51-A39E-3F6B6D96A12C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{442DAF0C-7EAD-48D9-ABEA-E0036470D6D5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{58EB187D-24F8-4423-BD6C-655CE4C416BD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6BEB066C-A791-4A21-B934-7783533FE888}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7697BC38-D0FA-454B-AC75-968B4CCABFCE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A07612DF-B1DD-484F-A1C3-36CA4CE919D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A76F97B2-2C56-456A-A29E-72741595C2E8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B19D9D96-E59C-4936-B283-8A831CDB3A53}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC8AAABA-3F8B-4866-8B3A-D9368133A478}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E15519AE-99BE-42DD-BE60-FFC3C183F443}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A903AC15-686E-4D67-A355-86FCBE9F60DA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{96BB8E60-6EF9-47E0-9ED8-4AD477ECF427}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{853130B6-1A29-4D9D-9513-2A461287651E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{853130B6-1A29-4D9D-9513-2A461287651E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\AnyProtect
Key Deleted : HKCU\Software\BABSOLUTION
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Hawker
Key Deleted : HKCU\Software\PCPrivacyDockLanguage
Key Deleted : HKCU\Software\sidecom
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Delta
Key Deleted : HKLM\SOFTWARE\SearchProtect
Key Deleted : HKLM\SOFTWARE\Tarma Installer
Key Deleted : HKLM\SOFTWARE\SearchModule
Key Deleted : HKLM\SOFTWARE\Hawker
Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
Key Deleted : HKU\.DEFAULT\Software\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17801
-\\ Mozilla Firefox v38.0.1 (x86 en-US)
[ekw1m3zj.default\prefs.js] - Line Deleted : user_pref("CT3072253.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ekw1m3zj.default\prefs.js] - Line Deleted : user_pref("CT3298566.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ekw1m3zj.default\prefs.js] - Line Deleted : user_pref("CT3298566.embeddedsData", "[{\"appId\":\"130110228003246321\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
[ekw1m3zj.default\prefs.js] - Line Deleted : user_pref("CT3298566.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3298566&octid=CT3298566&SearchSource=15&CUI=UN39718417211268134&SSPV=EB_SSPV&Lay=1&UM=[...]
[ekw1m3zj.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxps://search.yahoo.com/?type=282369&fr=spigot-yhp-ff");
[ekw1m3zj.default\prefs.js] - Line Deleted : user_pref("extensions.506a239b818d5.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"su[...]
[ekw1m3zj.default\prefs.js] - Line Deleted : user_pref("extensions.GXTKBkXggUm6P5CH.scode", "(function(){try{if(window.location.href.indexOf(\"rjr5qHsFrTY5qdrEpdn9qjg5qTY\")>-1){return;}}catch(e){}try{var d=[[\"www.viracure.com\",\"onesystemcare[...]
[ekw1m3zj.default\prefs.js] - Line Deleted : user_pref("extensions.QoFSdcLQt2HsQt3X.scode", "(function(){try{if(window.location.href.indexOf(\"rjr5qHsFrTY5qdrEpdn9qjg5qTY\")>-1){return;}}catch(e){}try{var d=[[\"www.viracure.com\",\"onesystemcare[...]
-\\ Google Chrome v
[C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.claro-search.com/?q={searchTerms}&affID=114506&tt=3912_2&babsrc=SP_clro&mntrId=6eb04da700000000000068a3c4169287
[C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN18762388492178927&ctid=CT3298566&UM=2
[C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&affID=121441&babsrc=SP_ss&mntrId=6EB068A3C4169287
[C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Matthew\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","webRequest","webRequestBlocking"],"explicit_host":["hxxp://*/*","hxxps://*/*"],"manifest_permissions":[],"scriptable_host":["*://*.ask.com/
*************************
AdwCleaner[R0].txt - [16122 bytes] - [26/05/2015 17:38:22]
AdwCleaner[S0].txt - [16486 bytes] - [26/05/2015 17:39:40]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16546 bytes] ##########
Thanks!