:OTL
SRV - (CltMngSvc) -- C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (Conduit)
PRC - C:\Users\SJB\AppData\Roaming\SearchProtect\bin\cltmng.exe (Conduit)
PRC - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (Conduit)
FF - prefs.js..browser.search.defaultthis.engineName: "entrusted Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3281675&CUI=UN50561302613957146&UM=2&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3281675&SearchSource=2&CUI=UN50561302613957146&UM=2&q="
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q=
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{520CAB51-2253-D723-50E9-2E61F8B8EBD9}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^UX^xdm005^YY^ca&si=CP6U2_3k8LUCFag7MgodpAoAPA&ptb=F6D2E23D-E0D1-4439-93D8-3E98AE408BD2&ind=2013030918&n=77fc6a06&psa=&st=sb&searchfor={searchTerms}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2035478722-3542266299-2287163729-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=70048
[2012/11/16 12:33:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\SJB\AppData\Roaming\Mozilla\Extensions
[2013/04/18 11:18:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\SJB\AppData\Roaming\Mozilla\Firefox\Profiles\mzjq8361.default\extensions
[2013/01/29 08:37:52 | 000,000,000 | ---D | M] (Advanced SystemCare Surfing Protection) -- C:\Users\SJB\AppData\Roaming\Mozilla\Firefox\Profiles\mzjq8361.default\extensions\ascsurfingprotection@iobit.com
[2013/03/30 11:28:16 | 000,609,882 | ---- | M] () (No name found) -- C:\Users\SJB\AppData\Roaming\Mozilla\Firefox\Profiles\mzjq8361.default\extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}.xpi
[2013/02/15 17:19:21 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\SJB\AppData\Roaming\Mozilla\Firefox\Profiles\mzjq8361.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/04/11 16:58:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
O2 - BHO: (no name) - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - No CLSID value found.
O2 - BHO: (no name) - {71c1d63a-c944-428a-a5bd-ba513190e5d2} - No CLSID value found.
O2 - BHO: (Advanced SystemCare Browser Protection) - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Advanced SystemCare 6\BrowerProtect\ASCPlugin_Protection.dll (IObit)
O3 - HKLM\..\Toolbar: (no name) - {364ea597-e728-4ce4-bb4a-ed846ef47970} - No CLSID value found.
O3 - HKU\S-1-5-21-2035478722-3542266299-2287163729-1001\..\Toolbar\WebBrowser: (no name) - {364EA597-E728-4CE4-BB4A-ED846EF47970} - No CLSID value found.
O3 - HKU\S-1-5-21-2035478722-3542266299-2287163729-1001\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe (Conduit)
O4 - HKU\S-1-5-21-2035478722-3542266299-2287163729-1001..\Run: [SearchProtect] C:\Users\SJB\AppData\Roaming\SearchProtect\bin\cltmng.exe (Conduit)
[2013/04/13 13:08:39 | 000,000,000 | ---D | C] -- C:\Users\SJB\AppData\Roaming\SearchProtect
[2013/04/13 10:45:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SearchProtect
[2013/04/13 16:06:09 | 000,012,800 | ---- | M] () -- C:\Users\SJB\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/29 15:06:36 | 000,012,800 | ---- | C] () -- C:\Users\SJB\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/28 17:11:47 | 000,000,000 | ---D | M] -- C:\Users\SJB\AppData\Roaming\PC Cleaners
[2013/04/19 18:47:14 | 000,000,000 | ---D | M] -- C:\Users\SJB\AppData\Roaming\SearchProtect
:Files
C:\Users\SJB\AppData\Roaming\SearchProtect
C:\Users\SJB\AppData\Roaming\PC Cleaners
C:\Program Files (x86)\SearchProtect
:commands
[emptytemp]
[reboot]