Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
police-central-e-crime-unit-virus lock removal help
Message
<blockquote data-quote="PaulosDeKathos" data-source="post: 120314" data-attributes="member: 8106"><p>[code]</p><p>HitmanPro 3.7.3.194</p><p>www.hitmanpro.com</p><p></p><p> Computer name . . . . : RUTH-PC</p><p> Windows . . . . . . . : 6.0.2.6002.X86/3</p><p> User name . . . . . . : Ruth-PC\Ruth</p><p> UAC . . . . . . . . . : Enabled</p><p> License . . . . . . . : Trial (27 days left)</p><p></p><p> Scan date . . . . . . : 2013-05-12 20:17:59</p><p> Scan mode . . . . . . : Normal</p><p> Scan duration . . . . : 26m 30s</p><p> Disk access mode . . : Direct disk access (SRB)</p><p> Cloud . . . . . . . . : Internet</p><p> Reboot . . . . . . . : No</p><p></p><p> Threats . . . . . . . : 115</p><p> Traces . . . . . . . : 307</p><p></p><p> Objects scanned . . . : 3,643,506</p><p> Files scanned . . . . : 309,336</p><p> Remnants scanned . . : 1,593,765 files / 1,740,405 keys</p><p></p><p>Malware _____________________________________________________________________</p><p></p><p> C:\Users\Ruth\AppData\Local\Temp\Temp1_Android-Emulator.zip\Android-Emulator\Run_Emulator(with Boot Animation).exe -> Quarantined</p><p> Size . . . . . . . : 393,728 bytes</p><p> Age . . . . . . . : 1352.6 days (2009-08-29 05:56:36)</p><p> Entropy . . . . . : 5.5</p><p> SHA-256 . . . . . : F7B0124EDC9D575779A19743AD64385FFF4DAFB1F43DCB0B9B4A8DDFD428A0B5</p><p> Needs elevation . : Yes</p><p> Product . . . . . : Android Emulator</p><p> Publisher . . . . : Google</p><p> Version . . . . . : 1,1,0,0</p><p> > Ikarus . . . . . . : Trojan-Dropper.Win32.BAT!IK</p><p> Fuzzy . . . . . . : 100.0</p><p></p><p> C:\Users\Ruth\AppData\Local\Temp\Temp1_PatformBomber(2).zip\PatformBomber\PatformBomber\Google Rank Checker\Googlerankchecker.exe -> Quarantined</p><p> Size . . . . . . . : 2,676,579 bytes</p><p> Age . . . . . . . : 1017.4 days (2010-07-30 11:19:22)</p><p> Entropy . . . . . : 8.0</p><p> SHA-256 . . . . . : 320C4543ECEB1B98683B0CC40A69FBF4B9B6E0CD1E13CF9AA65A0FF29E2F2803</p><p> Product . . . . . : compiledBot</p><p> Publisher . . . . : Microsoft</p><p> Description . . . : compiledBot</p><p> Version . . . . . : 1.0.0.0</p><p> Copyright . . . . : Copyright @ Microsoft 2010</p><p> > Ikarus . . . . . . : Trojan-PWS.Win32.Dybalom!IK</p><p> Fuzzy . . . . . . : 108.0</p><p></p><p> C:\Users\Ruth\AppData\Roaming\Traffic Travis v4\TTUpdater.exe -> Quarantined</p><p> Size . . . . . . . : 2,020,864 bytes</p><p> Age . . . . . . . : 42.2 days (2013-03-31 14:35:05)</p><p> Entropy . . . . . : 6.7</p><p> SHA-256 . . . . . : E3281F4307B26134F20D1B2A57DA471F24C126AE070DA4AFA8DD1132EF5A6F78</p><p> Product</p><p> Publisher</p><p> Description</p><p> Version . . . . . : 1.0.1.12</p><p> Copyright</p><p> > Ikarus . . . . . . : Trojan-Downloader.Banload!IK</p><p> Fuzzy . . . . . . : 103.0</p><p></p><p> C:\Users\Ruth\Downloads\Android-Emulator\Android-Emulator\Run_Emulator(with Boot Animation).exe -> Quarantined</p><p> Size . . . . . . . : 393,728 bytes</p><p> Age . . . . . . . : 1352.6 days (2009-08-29 05:56:36)</p><p> Entropy . . . . . : 5.5</p><p> SHA-256 . . . . . : F7B0124EDC9D575779A19743AD64385FFF4DAFB1F43DCB0B9B4A8DDFD428A0B5</p><p> Needs elevation . : Yes</p><p> Product . . . . . : Android Emulator</p><p> Publisher . . . . : Google</p><p> Version . . . . . : 1,1,0,0</p><p> > Ikarus . . . . . . : Trojan-Dropper.Win32.BAT!IK</p><p> Fuzzy . . . . . . : 100.0</p><p></p><p> C:\Users\Ruth\Downloads\PatformBomber(2)\PatformBomber\PatformBomber\Google Rank Checker\Googlerankchecker.exe -> Quarantined</p><p> Size . . . . . . . : 2,676,579 bytes</p><p> Age . . . . . . . : 1017.4 days (2010-07-30 11:19:22)</p><p> Entropy . . . . . : 8.0</p><p> SHA-256 . . . . . : 320C4543ECEB1B98683B0CC40A69FBF4B9B6E0CD1E13CF9AA65A0FF29E2F2803</p><p> Product . . . . . : compiledBot</p><p> Publisher . . . . : Microsoft</p><p> Description . . . : compiledBot</p><p> Version . . . . . : 1.0.0.0</p><p> Copyright . . . . : Copyright @ Microsoft 2010</p><p> > Ikarus . . . . . . : Trojan-PWS.Win32.Dybalom!IK</p><p> Fuzzy . . . . . . : 108.0</p><p></p><p> C:\Users\Ruth\Downloads\PatformBomber(2)\PatformBomber\PatformBomber\LinkFinder\LinkFinder.exe -> Quarantined</p><p> Size . . . . . . . : 2,665,539 bytes</p><p> Age . . . . . . . : 1031.9 days (2010-07-15 22:09:06)</p><p> Entropy . . . . . : 8.0</p><p> SHA-256 . . . . . : C3B5CC4BC626152F302BBADE447E329529E68E11933969117510E67774246F8D</p><p> Product . . . . . : compiledBot</p><p> Publisher . . . . : Microsoft</p><p> Description . . . : compiledBot</p><p> Version . . . . . : 1.0.0.0</p><p> Copyright . . . . : Copyright @ Microsoft 2010</p><p> > Ikarus . . . . . . : Trojan-PWS.Win32.Dybalom!IK</p><p> Fuzzy . . . . . . : 108.0</p><p></p><p> C:\Windows\system32\vFrameworkPro1.0.64.ocx -> Quarantined</p><p> Size . . . . . . . : 529,408 bytes</p><p> Age . . . . . . . : 79.1 days (2013-02-22 17:10:12)</p><p> Entropy . . . . . : 6.0</p><p> SHA-256 . . . . . : 12FEF03C973BE31F945ABA47A6A69D3805B29B4D6A36954BF85970DA5EC60EAC</p><p> Product . . . . . : vb5_vFrameworkPro</p><p> Publisher . . . . : None</p><p> Version . . . . . : 1.00.0094</p><p> > Ikarus . . . . . . : Backdoor.Win32.VB!IK</p><p> Fuzzy . . . . . . : 102.0</p><p></p><p> C:\Windows\system32\vFrameworkPro1.0.70.ocx -> Quarantined</p><p> Size . . . . . . . : 542,208 bytes</p><p> Age . . . . . . . : 80.4 days (2013-02-21 11:04:26)</p><p> Entropy . . . . . : 6.0</p><p> SHA-256 . . . . . : B388BE9EC74C0EF6BE1FAFFA89DDD1BFCCF163C849C94FF4A6B9E6885BCDDB88</p><p> Product . . . . . : vb5_vFrameworkPro</p><p> Publisher . . . . : None</p><p> Version . . . . . : 1.00.0099</p><p> > Ikarus . . . . . . : Backdoor.Win32.VB!IK</p><p> Fuzzy . . . . . . : 102.0</p><p></p><p></p><p>Malware remnants ____________________________________________________________</p><p></p><p> HKLM\SOFTWARE\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Classes\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\FocusInteractive\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Fun Web Products\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDLl32Policy\f3ScrCtr.dll\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows Media\WMSDK\sources\f3PopularScreensavers (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin\ (Adware.MyWebSearch) -> Deleted</p><p> HKLM\SYSTEM\ControlSet033\Services\MyWebSearchService\ (Adware.MyWebSearch)</p><p> HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Deleted</p><p> HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}\ (Adware.MyWebSearch) -> Deleted</p><p> HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted</p><p> HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted</p><p></p><p>Potential Unwanted Programs _________________________________________________</p><p></p><p> C:\ProgramData\BrowserProtect\ (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\ (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\bl (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll (Claro)</p><p> Size . . . . . . . : 2,212,304 bytes</p><p> Age . . . . . . . : 96.2 days (2013-02-05 14:54:21)</p><p> Entropy . . . . . : 6.7</p><p> SHA-256 . . . . . : 7F780DC5AC6C5D71E7C2421D7908CBDA4DA78A83D8D5EDE7C620BD2F6374F5B0</p><p> Fuzzy . . . . . . : 12.0</p><p></p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe (Claro)</p><p> Size . . . . . . . : 2,550,224 bytes</p><p> Age . . . . . . . : 96.2 days (2013-02-05 14:54:21)</p><p> Entropy . . . . . : 6.7</p><p> SHA-256 . . . . . : 04E0EDE2520AEB6AACB70870992263EB34D70BB54C3A5AA5FDCED308D654932D</p><p> RSA Key Size . . . : 2048</p><p> Authenticode . . . : Valid</p><p> Fuzzy . . . . . . : -1.0</p><p></p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.settings (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\ (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\chrome.manifest (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\ (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-18.0.dll (Claro)</p><p> Size . . . . . . . : 565,200 bytes</p><p> Age . . . . . . . : 96.2 days (2013-02-05 14:54:21)</p><p> Entropy . . . . . : 6.6</p><p> SHA-256 . . . . . : 04CB82A004B3B66C4B331E9EEC2E14F68EB22AF9AE96A051B0B684D1341191F1</p><p> RSA Key Size . . . : 2048</p><p> Authenticode . . . : Valid</p><p> Fuzzy . . . . . . : -1.0</p><p></p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-19.0.dll (Claro)</p><p> Size . . . . . . . : 574,416 bytes</p><p> Age . . . . . . . : 73.5 days (2013-02-28 08:59:07)</p><p> Entropy . . . . . : 6.5</p><p> SHA-256 . . . . . : 54478CEAD55BB8DA42435C1A033DC06EC8FA2BF69D4D12EAF501BB17426C402C</p><p> RSA Key Size . . . : 2048</p><p> Authenticode . . . : Valid</p><p> Fuzzy . . . . . . : -1.0</p><p></p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-20.0.dll (Claro)</p><p> Size . . . . . . . : 574,416 bytes</p><p> Age . . . . . . . : 27.0 days (2013-04-15 19:48:47)</p><p> Entropy . . . . . : 6.6</p><p> SHA-256 . . . . . : AB087B1BAF7791D21302C8881118806B37F20FDCED64D58F7AB18EEFD0051173</p><p> RSA Key Size . . . : 2048</p><p> Authenticode . . . : Valid</p><p> Fuzzy . . . . . . : -1.0</p><p></p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-3.6.xpt (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\content\ (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\content\BrowserProtect.js (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\content\overlay.xul (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\install.rdf (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\ (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\00 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\01 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\02 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\03 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\10 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\11 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\12 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\13 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\20 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\21 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\22 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\23 (Claro)</p><p> C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe (Claro)</p><p> Size . . . . . . . : 2,550,224 bytes</p><p> Age . . . . . . . : 96.2 days (2013-02-05 14:54:23)</p><p> Entropy . . . . . : 6.7</p><p> SHA-256 . . . . . : 04E0EDE2520AEB6AACB70870992263EB34D70BB54C3A5AA5FDCED308D654932D</p><p> RSA Key Size . . . : 2048</p><p> Authenticode . . . : Valid</p><p> Fuzzy . . . . . . : -1.0</p><p></p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences (Claro)</p><p> C:\Users\Ruth\Local Settings\Temp\AskSearch\ (AskBar)</p><p> HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}\ (Claro)</p><p> HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods)</p><p> HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}\ (Claro)</p><p> HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}\ (Claro)</p><p> HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}\ (Claro)</p><p> HKLM\SOFTWARE\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}\ (Claro)</p><p> HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}\ (Claro)</p><p> HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}\ (Claro)</p><p> HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon)</p><p> HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\ (Babylon)</p><p> HKLM\SOFTWARE\DataMngr\ (SearchQU)</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}\ (Babylon)</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079a25-328f-4bd4-be04-00955acaa0a7}\ (SearchQU)</p><p> HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}\ (AskBar)</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar\ (Babylon)</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar\ (SearchQU)</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam\ (Claro)</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}\ (Claro)</p><p> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ (AskBar)</p><p> HKLM\SYSTEM\ControlSet001\Services\Eventlog\Application\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet021\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet022\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet023\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet024\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet025\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet026\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet027\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet028\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet029\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet030\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet031\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet032\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet033\Services\BrowserProtect\ (Claro)</p><p> HKLM\SYSTEM\ControlSet033\Services\Eventlog\Application\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\ControlSet033\Services\WajamUpdater\ (Claro)</p><p> HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater\ (Claro)</p><p> HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\DataMngr\ (SearchQU)</p><p> HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\DataMngr_Toolbar\ (SearchQU)</p><p> HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro)</p><p> HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}\ (AskBar)</p><p></p><p>Cookies _____________________________________________________________________</p><p></p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:2o7.net</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:adinterax.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:adultfriendfinder.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:analytics.cj.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:bs.serving-sys.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:cj.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:in.getclicky.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:uk.cj.com</p><p> C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\4L6UYW9S.txt</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\6SOY9SYG.txt</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\7MYHYRL1.txt</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\B3OUWQM6.txt</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\CK1TY6C9.txt</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\F0CFGCDD.txt</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\GC913OV3.txt</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\K4TX9BWV.txt</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\NVM67TXK.txt</p><p> C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\Y7JVNCG7.txt</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:112.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:122.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:192com.112.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:247realmedia.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad-emea.doubleclick.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad.360yield.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad.doubleclick.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad.uk.doubleclick.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad.yieldmanager.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:adinterax.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.audience2media.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.creative-serving.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.p161.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.pubmatic.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.undertone.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:adtech.de</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:adtechus.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:advertising.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:adviva.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:amazonservices.122.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ar.atwola.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:at.atwola.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:atdmt.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:atwola.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:bs.serving-sys.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:burstnet.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:care2.112.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:casalemedia.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:clickbank.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:collective-media.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:dmtracker.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:doubleclick.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:fastclick.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:fr.sitestat.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:googleads.g.doubleclick.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:h.atdmt.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:hearstmagazines.112.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:img-cdn.mediaplex.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:invitemedia.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:kontera.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ladbrokesaccount.solution.weborama.fr</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:linksynergy.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:media6degrees.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:mediaplex.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:mm.chitika.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:movitex.122.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:newlook.112.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:nhlbi.122.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:paypal.112.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:pubads.g.doubleclick.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:questionmarket.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:revsci.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ru4.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:serving-sys.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:smartadserver.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:specificclick.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ssl.clickbank.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:stat.dealtime.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:statcounter.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:stats.paypal.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:statse.webtrendslive.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:tacoda.at.atwola.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:thecooperativebank.112.2o7.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:track.adform.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:tradedoubler.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:tribalfusion.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:uk.at.atwola.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:weborama.fr</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ww251.smartadserver.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:www.googleadservices.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:www4.smartadserver.com</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:yadro.ru</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:yieldmanager.net</p><p> C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:zedo.com</p><p></p><p></p><p>[/code]</p></blockquote><p></p>
[QUOTE="PaulosDeKathos, post: 120314, member: 8106"] [code] HitmanPro 3.7.3.194 www.hitmanpro.com Computer name . . . . : RUTH-PC Windows . . . . . . . : 6.0.2.6002.X86/3 User name . . . . . . : Ruth-PC\Ruth UAC . . . . . . . . . : Enabled License . . . . . . . : Trial (27 days left) Scan date . . . . . . : 2013-05-12 20:17:59 Scan mode . . . . . . : Normal Scan duration . . . . : 26m 30s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 115 Traces . . . . . . . : 307 Objects scanned . . . : 3,643,506 Files scanned . . . . : 309,336 Remnants scanned . . : 1,593,765 files / 1,740,405 keys Malware _____________________________________________________________________ C:\Users\Ruth\AppData\Local\Temp\Temp1_Android-Emulator.zip\Android-Emulator\Run_Emulator(with Boot Animation).exe -> Quarantined Size . . . . . . . : 393,728 bytes Age . . . . . . . : 1352.6 days (2009-08-29 05:56:36) Entropy . . . . . : 5.5 SHA-256 . . . . . : F7B0124EDC9D575779A19743AD64385FFF4DAFB1F43DCB0B9B4A8DDFD428A0B5 Needs elevation . : Yes Product . . . . . : Android Emulator Publisher . . . . : Google Version . . . . . : 1,1,0,0 > Ikarus . . . . . . : Trojan-Dropper.Win32.BAT!IK Fuzzy . . . . . . : 100.0 C:\Users\Ruth\AppData\Local\Temp\Temp1_PatformBomber(2).zip\PatformBomber\PatformBomber\Google Rank Checker\Googlerankchecker.exe -> Quarantined Size . . . . . . . : 2,676,579 bytes Age . . . . . . . : 1017.4 days (2010-07-30 11:19:22) Entropy . . . . . : 8.0 SHA-256 . . . . . : 320C4543ECEB1B98683B0CC40A69FBF4B9B6E0CD1E13CF9AA65A0FF29E2F2803 Product . . . . . : compiledBot Publisher . . . . : Microsoft Description . . . : compiledBot Version . . . . . : 1.0.0.0 Copyright . . . . : Copyright @ Microsoft 2010 > Ikarus . . . . . . : Trojan-PWS.Win32.Dybalom!IK Fuzzy . . . . . . : 108.0 C:\Users\Ruth\AppData\Roaming\Traffic Travis v4\TTUpdater.exe -> Quarantined Size . . . . . . . : 2,020,864 bytes Age . . . . . . . : 42.2 days (2013-03-31 14:35:05) Entropy . . . . . : 6.7 SHA-256 . . . . . : E3281F4307B26134F20D1B2A57DA471F24C126AE070DA4AFA8DD1132EF5A6F78 Product Publisher Description Version . . . . . : 1.0.1.12 Copyright > Ikarus . . . . . . : Trojan-Downloader.Banload!IK Fuzzy . . . . . . : 103.0 C:\Users\Ruth\Downloads\Android-Emulator\Android-Emulator\Run_Emulator(with Boot Animation).exe -> Quarantined Size . . . . . . . : 393,728 bytes Age . . . . . . . : 1352.6 days (2009-08-29 05:56:36) Entropy . . . . . : 5.5 SHA-256 . . . . . : F7B0124EDC9D575779A19743AD64385FFF4DAFB1F43DCB0B9B4A8DDFD428A0B5 Needs elevation . : Yes Product . . . . . : Android Emulator Publisher . . . . : Google Version . . . . . : 1,1,0,0 > Ikarus . . . . . . : Trojan-Dropper.Win32.BAT!IK Fuzzy . . . . . . : 100.0 C:\Users\Ruth\Downloads\PatformBomber(2)\PatformBomber\PatformBomber\Google Rank Checker\Googlerankchecker.exe -> Quarantined Size . . . . . . . : 2,676,579 bytes Age . . . . . . . : 1017.4 days (2010-07-30 11:19:22) Entropy . . . . . : 8.0 SHA-256 . . . . . : 320C4543ECEB1B98683B0CC40A69FBF4B9B6E0CD1E13CF9AA65A0FF29E2F2803 Product . . . . . : compiledBot Publisher . . . . : Microsoft Description . . . : compiledBot Version . . . . . : 1.0.0.0 Copyright . . . . : Copyright @ Microsoft 2010 > Ikarus . . . . . . : Trojan-PWS.Win32.Dybalom!IK Fuzzy . . . . . . : 108.0 C:\Users\Ruth\Downloads\PatformBomber(2)\PatformBomber\PatformBomber\LinkFinder\LinkFinder.exe -> Quarantined Size . . . . . . . : 2,665,539 bytes Age . . . . . . . : 1031.9 days (2010-07-15 22:09:06) Entropy . . . . . : 8.0 SHA-256 . . . . . : C3B5CC4BC626152F302BBADE447E329529E68E11933969117510E67774246F8D Product . . . . . : compiledBot Publisher . . . . : Microsoft Description . . . : compiledBot Version . . . . . : 1.0.0.0 Copyright . . . . : Copyright @ Microsoft 2010 > Ikarus . . . . . . : Trojan-PWS.Win32.Dybalom!IK Fuzzy . . . . . . : 108.0 C:\Windows\system32\vFrameworkPro1.0.64.ocx -> Quarantined Size . . . . . . . : 529,408 bytes Age . . . . . . . : 79.1 days (2013-02-22 17:10:12) Entropy . . . . . : 6.0 SHA-256 . . . . . : 12FEF03C973BE31F945ABA47A6A69D3805B29B4D6A36954BF85970DA5EC60EAC Product . . . . . : vb5_vFrameworkPro Publisher . . . . : None Version . . . . . : 1.00.0094 > Ikarus . . . . . . : Backdoor.Win32.VB!IK Fuzzy . . . . . . : 102.0 C:\Windows\system32\vFrameworkPro1.0.70.ocx -> Quarantined Size . . . . . . . : 542,208 bytes Age . . . . . . . : 80.4 days (2013-02-21 11:04:26) Entropy . . . . . : 6.0 SHA-256 . . . . . : B388BE9EC74C0EF6BE1FAFFA89DDD1BFCCF163C849C94FF4A6B9E6885BCDDB88 Product . . . . . : vb5_vFrameworkPro Publisher . . . . : None Version . . . . . : 1.00.0099 > Ikarus . . . . . . : Backdoor.Win32.VB!IK Fuzzy . . . . . . : 102.0 Malware remnants ____________________________________________________________ HKLM\SOFTWARE\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Classes\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\FocusInteractive\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Fun Web Products\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDLl32Policy\f3ScrCtr.dll\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows Media\WMSDK\sources\f3PopularScreensavers (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall\ (Adware.MyWebSearch) -> Deleted HKLM\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin\ (Adware.MyWebSearch) -> Deleted HKLM\SYSTEM\ControlSet033\Services\MyWebSearchService\ (Adware.MyWebSearch) HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Deleted HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}\ (Adware.MyWebSearch) -> Deleted HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ (Adware.MyWebSearch) -> Deleted Potential Unwanted Programs _________________________________________________ C:\ProgramData\BrowserProtect\ (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\ (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\bl (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll (Claro) Size . . . . . . . : 2,212,304 bytes Age . . . . . . . : 96.2 days (2013-02-05 14:54:21) Entropy . . . . . : 6.7 SHA-256 . . . . . : 7F780DC5AC6C5D71E7C2421D7908CBDA4DA78A83D8D5EDE7C620BD2F6374F5B0 Fuzzy . . . . . . : 12.0 C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe (Claro) Size . . . . . . . : 2,550,224 bytes Age . . . . . . . : 96.2 days (2013-02-05 14:54:21) Entropy . . . . . : 6.7 SHA-256 . . . . . : 04E0EDE2520AEB6AACB70870992263EB34D70BB54C3A5AA5FDCED308D654932D RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : -1.0 C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.settings (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\ (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\chrome.manifest (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\ (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-18.0.dll (Claro) Size . . . . . . . : 565,200 bytes Age . . . . . . . : 96.2 days (2013-02-05 14:54:21) Entropy . . . . . : 6.6 SHA-256 . . . . . : 04CB82A004B3B66C4B331E9EEC2E14F68EB22AF9AE96A051B0B684D1341191F1 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : -1.0 C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-19.0.dll (Claro) Size . . . . . . . : 574,416 bytes Age . . . . . . . : 73.5 days (2013-02-28 08:59:07) Entropy . . . . . : 6.5 SHA-256 . . . . . : 54478CEAD55BB8DA42435C1A033DC06EC8FA2BF69D4D12EAF501BB17426C402C RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : -1.0 C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-20.0.dll (Claro) Size . . . . . . . : 574,416 bytes Age . . . . . . . : 27.0 days (2013-04-15 19:48:47) Entropy . . . . . : 6.6 SHA-256 . . . . . : AB087B1BAF7791D21302C8881118806B37F20FDCED64D58F7AB18EEFD0051173 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : -1.0 C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-3.6.xpt (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\content\ (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\content\BrowserProtect.js (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\content\overlay.xul (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\install.rdf (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\ (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\00 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\01 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\02 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\03 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\10 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\11 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\12 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\13 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\20 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\21 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\22 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\23 (Claro) C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe (Claro) Size . . . . . . . : 2,550,224 bytes Age . . . . . . . : 96.2 days (2013-02-05 14:54:23) Entropy . . . . . : 6.7 SHA-256 . . . . . : 04E0EDE2520AEB6AACB70870992263EB34D70BB54C3A5AA5FDCED308D654932D RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : -1.0 C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences (Claro) C:\Users\Ruth\Local Settings\Temp\AskSearch\ (AskBar) HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}\ (Claro) HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon) HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods) HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\ (Babylon) HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}\ (Claro) HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\ (Babylon) HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}\ (Claro) HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}\ (Claro) HKLM\SOFTWARE\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}\ (Claro) HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}\ (Claro) HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ (Babylon) HKLM\SOFTWARE\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}\ (Babylon) HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}\ (Claro) HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\ (Babylon) HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\ (Babylon) HKLM\SOFTWARE\DataMngr\ (SearchQU) HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}\ (Babylon) HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079a25-328f-4bd4-be04-00955acaa0a7}\ (SearchQU) HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar\ (Babylon) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar\ (SearchQU) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam\ (Claro) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}\ (Claro) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ (AskBar) HKLM\SYSTEM\ControlSet001\Services\Eventlog\Application\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet021\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet022\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet023\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet024\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet025\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet026\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet027\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet028\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet029\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet030\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet031\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet032\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet033\Services\BrowserProtect\ (Claro) HKLM\SYSTEM\ControlSet033\Services\Eventlog\Application\WajamUpdater\ (Claro) HKLM\SYSTEM\ControlSet033\Services\WajamUpdater\ (Claro) HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater\ (Claro) HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\DataMngr\ (SearchQU) HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\DataMngr_Toolbar\ (SearchQU) HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro) HKU\S-1-5-21-3021958837-3772347930-3219022640-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}\ (AskBar) Cookies _____________________________________________________________________ C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:2o7.net C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:adinterax.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:adultfriendfinder.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:analytics.cj.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:bs.serving-sys.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:cj.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:in.getclicky.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:uk.cj.com C:\Users\Ruth\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\4L6UYW9S.txt C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\6SOY9SYG.txt C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\7MYHYRL1.txt C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\B3OUWQM6.txt C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\CK1TY6C9.txt C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\F0CFGCDD.txt C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\GC913OV3.txt C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\K4TX9BWV.txt C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\NVM67TXK.txt C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Cookies\Y7JVNCG7.txt C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:112.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:122.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:192com.112.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:247realmedia.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad-emea.doubleclick.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad.360yield.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad.doubleclick.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad.uk.doubleclick.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ad.yieldmanager.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:adinterax.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.audience2media.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.creative-serving.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.p161.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.pubmatic.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ads.undertone.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:adtech.de C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:adtechus.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:advertising.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:adviva.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:amazonservices.122.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ar.atwola.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:at.atwola.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:atdmt.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:atwola.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:bs.serving-sys.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:burstnet.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:care2.112.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:casalemedia.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:clickbank.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:collective-media.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:dmtracker.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:doubleclick.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:fastclick.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:fr.sitestat.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:googleads.g.doubleclick.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:h.atdmt.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:hearstmagazines.112.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:img-cdn.mediaplex.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:invitemedia.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:kontera.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ladbrokesaccount.solution.weborama.fr C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:linksynergy.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:media6degrees.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:mediaplex.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:mm.chitika.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:movitex.122.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:newlook.112.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:nhlbi.122.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:paypal.112.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:pubads.g.doubleclick.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:questionmarket.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:revsci.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ru4.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:serving-sys.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:smartadserver.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:specificclick.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ssl.clickbank.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:stat.dealtime.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:statcounter.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:stats.paypal.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:statse.webtrendslive.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:tacoda.at.atwola.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:thecooperativebank.112.2o7.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:track.adform.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:tradedoubler.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:tribalfusion.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:uk.at.atwola.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:weborama.fr C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:ww251.smartadserver.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:www.googleadservices.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:www4.smartadserver.com C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:yadro.ru C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:yieldmanager.net C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\bvgpgmth.default\cookies.sqlite:zedo.com [/code] [/QUOTE]
Insert quotes…
Verification
Post reply
Top