C:\Users\KristiAnne\AppData\Roaming\TornTV.com;fs iedefaults; {9030D464-4C02-4ABF-8ECC-5164760863C6};c C:\Windows\tasks\30c9d699-fc2e-4545-a144-7dcce2b5832c-7.job;f C:\Windows\tasks\IDLI.job;f C:\Users\KristiAnne\AppData\Roaming\IDLI.exe;f C:\Users\KristiAnne\AppData\Roaming\Mozilla\Firefox\Profiles\f9las1fh.default\extensions\fftoolbar2014@etech.com;fs C:\Users\KristiAnne\AppData\Roaming\Mozilla\Firefox\Profiles\f9las1fh.default\searchplugins\omiga-plus.xml;fs {318A227B-5E9F-45bd-8999-7F8F10CA4CF5};c {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F};c [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run];r "TornTv Downloader"=-;r C:\Users\KristiAnne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnk;f [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe];r [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe];r C:\Program Files (x86)\XTab;fs C:\ProgramData\WindowsMangerProtect;fs C:\Program Files (x86)\0ca45c95134d;fs C:\Program Files (x86)\f552dd4c52e3;fs C:\Program Files (x86)\mbot_nl_113;fs [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mbot_nl_113];r64 b786bdb3c67d;s C:\Windows\system32\drivers\b786bdb3c67d.sys;f F06DEFF2-5B9C-490D-910F-35D3A91196222;s C:\Program Files (x86)\Settings Manager\smdmf;fs trntv;s emptyalltemp; standardsearch; torpigcheck; emptyfolders;delete