jmm157

Members
  • Content count

    50
  • Joined

  • Last visited

About jmm157

  • Rank
    Regular Member
  1. Prior to your last post, I rebooted my switch and connection is good. Will again let you know if it fails. Thanks.
  2. Just like before. It worked for a while and the pages stopped loading. Both Firefox and IE.
  3. Hopefully this was the main issue. That seems to take care of the problem at this point, but it also worked for a bit yesterday after doing what you requested; then it stopped. What I find odd though is that IE was not working and now it is. My Outlook email account was giving errors at the same time since yesterday. I contacted my ISP and they said the line was working good and email was ok. I disabled my network card and rebooted then the connection still didn't work after that. Outlook now works OK as well. Hopefully this is all I need to do. I will keep you posted if things go awry again.
  4. All are correct.
  5. Maybe minor improvement. I did get a couple of pages to load, but not all will load. Attached you will see a couple of screen shots of the pages that did not load. screens.pdf
  6. I use Firefox and have tried with IE, but neither will load pages. Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by Mike at 2015-03-28 09:38:20 Run:3 Running from C:\Users\Mike\Desktop\FRST Loaded Profiles: Mike (Available profiles: Mike & ANOTHER) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\RunOnce: [b Register C:\Program Files (x86)\DivX\DivX Transcode Engine\plugins\mc_demux_mp2_ds.ax] => "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Transcode Engine\plugins\mc_demux_mp2_ds.ax",DllRegisterServer HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\...\Run: [ROC_ROC_APR2013_AV] => C:\Users\Mike\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT --mid ddbae792321c47d1ba9ed15426e99490-dea33aeff6aaebca622fc55477b442c3c67ca2ee --CMPID ROC_APR2013_AV --CMPI (the data entry has 11 more characters). HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\...\Run: [AVG-Secure-Search-Update_0913a] => C:\Users\Mike\AppData\Roaming\AVG 0913a Campaign\AVG-Secure-Search-Update-0913a.exe /PROMPT --mid ddbae792321c47d1ba9ed15426e99490-dea33aeff6aaebca622fc55477b442c3c67ca2ee --CMPID 0913a HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\...\Run: [AVG-Secure-Search-Update_1113a] => C:\Users\Mike\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=ddbae792321c47d1ba9ed15426e99490-dea33aeff6aaebca622fc55477b442c3c67ca2ee /CMPID=1113a CMD: ipconfig /flushdns EmptyTemp: ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\B Register C:\Program Files (x86)\DivX\DivX Transcode Engine\plugins\mc_demux_mp2_ds.ax => value deleted successfully. HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ROC_ROC_APR2013_AV => value deleted successfully. HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_0913a => value deleted successfully. HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_1113a => value deleted successfully. ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= EmptyTemp: => Removed 39.9 GB temporary data. The system needed a reboot. ==== End of Fixlog 09:42:43 ====
  7. Attachments included. Addition.txt FRST.txt
  8. The Internet access lasted a couple of hours, but now seems to be as it was before.
  9. Could you tell me what causes the host file to grow so large?
  10. It seems to be at this point. I have gotten to six webpages without an issue.
  11. I am now able to use the internet.
  12. Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by Mike at 2015-03-27 16:57:50 Run:2 Running from C:\Users\Mike\Desktop\FRST Loaded Profiles: Mike (Available profiles: Mike & ANOTHER) Boot Mode: Normal ============================================== Content of fixlist: ***************** Hosts: ***************** C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. ==== End of Fixlog 16:57:50 ====
  13. Requested tasks completed. First, can you tell me what I need to do with the hosts file? Fixlog file: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by Mike at 2015-03-26 22:10:12 Run:1 Running from C:\Users\Mike\Desktop\FRST Loaded Profiles: Mike (Available profiles: Mike & ANOTHER) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\...\Run: [uTorrent] => "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\...\Run: [] => [X] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction URLSearchHook: HKU\S-1-5-21-1754454339-2153682011-3722641661-1000 - SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch64.dll No File URLSearchHook: HKU\S-1-5-21-1754454339-2153682011-3722641661-1000 - SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll No File SearchScopes: HKU\.DEFAULT -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = R2 PGMTrusted; C:\Program Files (x86)\Pogo Games\PGMTrusted.exe [520360 2013-03-25] (iWin Inc.) AlternateDataStreams: C:\Windows: AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 AlternateDataStreams: C:\Users\Mike\Documents\card1.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\card2.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\Cert.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\Mustacheless.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\Scan0001.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\Scan0002.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\Scan0003.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\Scan0004.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\Scan0005.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\Scan0006.jpg:Roxio EMC Stream AlternateDataStreams: C:\Users\Mike\Documents\scan1.jpg:Roxio EMC Stream C:\Users\Mike\AppData\Local\Temp\Xzg.exe ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value deleted successfully. HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} => Value not found. "HKCR\CLSID\{BC86E1AB-EDA5-4059-938F-CE307B0C6F0A}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{BC86E1AB-EDA5-4059-938F-CE307B0C6F0A}" => Key deleted successfully. HKU\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} => Value not found. "HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}" => Key deleted successfully. HKCR\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key not found. PGMTrusted => Service not found. "C:\Windows" => ":" ADS not found. C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully. C:\Users\Mike\Documents\card1.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\card2.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\Cert.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\Mustacheless.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\Scan0001.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\Scan0002.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\Scan0003.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\Scan0004.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\Scan0005.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\Scan0006.jpg => ":Roxio EMC Stream" ADS removed successfully. C:\Users\Mike\Documents\scan1.jpg => ":Roxio EMC Stream" ADS removed successfully. "C:\Users\Mike\AppData\Local\Temp\Xzg.exe" => File/Directory not found. ==== End of Fixlog 22:10:12 ==== AdwCleaner log file: # AdwCleaner v3.023 - Report created 20/04/2014 at 08:54:31 # Updated 01/04/2014 by Xplode # Operating System : Windows 7 Professional Service Pack 1 (64 bits) # Username : Mike - MIKE-PC-LR # Running from : C:\Users\Mike\Desktop\Downloads\adwcleaner.exe # Option : Clean ***** [ Services ] ***** Service Deleted : BCUService ***** [ Files / Folders ] ***** Folder Deleted : C:\Save Folder Deleted : C:\ProgramData\AGI Folder Deleted : C:\ProgramData\Conduit Folder Deleted : C:\ProgramData\DeviceVM Folder Deleted : C:\ProgramData\ParetoLogic Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ParetoLogic Folder Deleted : C:\Program Files (x86)\AGI Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files (x86)\DeviceVM Folder Deleted : C:\Program Files (x86)\ParetoLogic Folder Deleted : C:\Program Files (x86)\DivX_Browser_Bar Folder Deleted : C:\Program Files (x86)\Common Files\ParetoLogic Folder Deleted : C:\Users\Mike\AppData\Local\PackageAware Folder Deleted : C:\Users\Mike\AppData\LocalLow\AGI Folder Deleted : C:\Users\Mike\AppData\LocalLow\boost_interprocess Folder Deleted : C:\Users\Mike\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Mike\AppData\LocalLow\DivX_Browser_Bar Folder Deleted : C:\Users\Mike\AppData\Roaming\DeviceVM Folder Deleted : C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\lays53kr.default\Smartbar Folder Deleted : C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\lays53kr.default\CT3288691 Folder Deleted : C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\lays53kr.default\Extensions\{77E8143B-6759-416E-B521-82CFED75150B} Folder Deleted : C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda File Deleted : C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\lays53kr.default\user.js ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DownloadManager] Key Deleted : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook Key Deleted : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook.1 Key Deleted : HKLM\SOFTWARE\Classes\agihelper.AGUtils Key Deleted : HKLM\SOFTWARE\Classes\driverscanner Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [bCU] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3220468 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3288691 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_comicrack_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_comicrack_RASMANCS Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0BC6E3FA-78EF-4886-842C-5A1258C4455A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{77E8143B-6759-416E-B521-82CFED75150B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD937C23-9304-4E9E-9FD3-0E00B88E2C2E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{77AA6435-2488-4A94-9FE5-49519DD2ED9B} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BC6E3FA-78EF-4886-842C-5A1258C4455A} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77E8143B-6759-416E-B521-82CFED75150B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0BC6E3FA-78EF-4886-842C-5A1258C4455A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{77E8143B-6759-416E-B521-82CFED75150B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0BC6E3FA-78EF-4886-842C-5A1258C4455A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{77E8143B-6759-416E-B521-82CFED75150B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DD937C23-9304-4E9E-9FD3-0E00B88E2C2E} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{87A0B80B-5BA7-4CB0-9553-105D68777D60} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7B6147A6-FE7F-4D06-A668-1F39C82A6A14} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C05E1E9-CC59-4878-8B4D-8863A889E14E} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{77E8143B-6759-416E-B521-82CFED75150B}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{77E8143B-6759-416E-B521-82CFED75150B}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0BC6E3FA-78EF-4886-842C-5A1258C4455A}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{77E8143B-6759-416E-B521-82CFED75150B}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{77E8143B-6759-416E-B521-82CFED75150B}] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKCU\Software\AGI Key Deleted : HKCU\Software\APN PIP Key Deleted : HKCU\Software\AVG SafeGuard toolbar Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\DeviceVM Key Deleted : HKCU\Software\ParetoLogic Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AppDataLow\Software\DivX_Browser_Bar Key Deleted : HKLM\Software\AGI Key Deleted : HKLM\Software\AVG SafeGuard toolbar Key Deleted : HKLM\Software\AVG Secure Search Key Deleted : HKLM\Software\AVG Security Toolbar Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DeviceVM Key Deleted : HKLM\Software\ParetoLogic Key Deleted : HKLM\Software\PIP Key Deleted : HKLM\Software\Uniblue Key Deleted : HKLM\Software\DivX_Browser_Bar Key Deleted : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Mozilla Firefox v28.0 (en-US) [ File : C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\lays53kr.default\prefs.js ] Line Deleted : user_pref("CT3220468.BT_Stats.enc", "eyJsYXN0X2xvZyI6MTM2NTM5ODU5NiwidXVpZCI6NDAxNDA1MTU2MzMzMzY1LCJzZXFfaWQiOjEzLCJzc2IiOjEzNDk3MDEyODZ9"); Line Deleted : user_pref("CT3220468.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3220468.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3220468.FirstTime", "true"); Line Deleted : user_pref("CT3220468.FirstTimeFF3", "true"); Line Deleted : user_pref("CT3220468.PG_ENABLE", "dHJ1ZQ=="); Line Deleted : user_pref("CT3220468.PG_ENABLE.enc", "ZEhKMVpRPT0="); Line Deleted : user_pref("CT3220468.SF_JUST_INSTALLED.enc", "RkFMU0U="); Line Deleted : user_pref("CT3220468.SF_STATUS.enc", "RU5BQkxFRA=="); Line Deleted : user_pref("CT3220468.SF_USER_ID.enc", "Y2lkXzg0MjAxMzE2NTgxMjkzMzQ0MDE="); Line Deleted : user_pref("CT3220468.UserID", "UN48904327915112615"); Line Deleted : user_pref("CT3220468.addressBarTakeOverEnabledInHidden", "true"); Line Deleted : user_pref("CT3220468.autoDisableScopes", -1); Line Deleted : user_pref("CT3220468.cb_experience_000.enc", "Mw=="); Line Deleted : user_pref("CT3220468.cb_firstuse0100.enc", "MQ=="); Line Deleted : user_pref("CT3220468.cb_user_id_000.enc", "Q0I5NTMxNDc5MDQxNzNfMTM2NDc0MTI1MTgzMV9GaXJlZm94"); Line Deleted : user_pref("CT3220468.cbcountry_001", "US"); Line Deleted : user_pref("CT3220468.cbfirsttime.enc", "TW9uIE9jdCAwOCAyMDEyIDA4OjAxOjE3IEdNVC0wNTAwIChDZW50cmFsIERheWxpZ2h0IFRpbWUp"); Line Deleted : user_pref("CT3220468.countryCode", "US"); Line Deleted : user_pref("CT3220468.defaultSearch", "FALSE"); Line Deleted : user_pref("CT3220468.enableAlerts", "always"); Line Deleted : user_pref("CT3220468.enableFix404ByUser", "FALSE"); Line Deleted : user_pref("CT3220468.enableSearchFromAddressBar", "FALSE"); Line Deleted : user_pref("CT3220468.firstTimeDialogOpened", "true"); Line Deleted : user_pref("CT3220468.fixPageNotFoundError", "true"); Line Deleted : user_pref("CT3220468.fixPageNotFoundErrorByUser", "true"); Line Deleted : user_pref("CT3220468.fixPageNotFoundErrorInHidden", "true"); Line Deleted : user_pref("CT3220468.fixUrls", true); Line Deleted : user_pref("CT3220468.fullUserID", "UN48904327915112615.UP.20130706151606"); Line Deleted : user_pref("CT3220468.homepageuserchanged", true); Line Deleted : user_pref("CT3220468.hxxp___toolbar_utorrent_com.APP_WIN_FEATURES.enc", "cmVzaXphYmxlPTAsc2F2ZXJlc2l6ZWRzaXplPTAsdGl0bGViYXI9MCxjbG9zZW9uZXh0ZXJuYWxjbGljaz0xLHNhdmVsb2NhdGlvbj0wLG9wZW5wb3NpdGlvbj1vZmZ[...] Line Deleted : user_pref("CT3220468.installId", "fft77CE.tmp.exe"); Line Deleted : user_pref("CT3220468.installType", "XPE"); Line Deleted : user_pref("CT3220468.isCheckedStartAsHidden", true); Line Deleted : user_pref("CT3220468.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3220468.isFirstTimeToolbarLoading", "false"); Line Deleted : user_pref("CT3220468.isNewTabEnabled", false); Line Deleted : user_pref("CT3220468.isPerformedSmartBarTransition", "true"); Line Deleted : user_pref("CT3220468.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); Line Deleted : user_pref("CT3220468.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3220468.lastVersion", "10.20.0.513"); Line Deleted : user_pref("CT3220468.mam_gk_appStateReportTime.enc", "MTM2NTQ3MjY5MzA4NQ=="); Line Deleted : user_pref("CT3220468.mam_gk_appState_CouponBuddy.enc", "b24="); Line Deleted : user_pref("CT3220468.mam_gk_appState_Find-a-Pro.enc", "b24="); Line Deleted : user_pref("CT3220468.mam_gk_appState_PriceGong.enc", "b24="); Line Deleted : user_pref("CT3220468.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9wcmljZWdvbmcuY29uZHVpdGFwcHMuY29tL01BTS92MS9odG1sX2NvbXAuaHRtbCIsIm9wdGlvbnNEaWFsb2ciOnsiZGlzcGxheU5h[...] Line Deleted : user_pref("CT3220468.mam_gk_appsDefaultEnabled.enc", "bnVsbA=="); Line Deleted : user_pref("CT3220468.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IkNvdXBvbkJ1ZGR5IiwiY3JpdGVyaWFzIjpbeyJjcml0ZXJpYUlkIjoiZTk3Yjc3NWQtMjNlMS00YjA5LWIzNDItZDExZjEyOTJhMjA2IiwiZG9tYWlucyI[...] Line Deleted : user_pref("CT3220468.mam_gk_currentVersion.enc", "MS40LjQuNg=="); Line Deleted : user_pref("CT3220468.mam_gk_first_time.enc", "MQ=="); Line Deleted : user_pref("CT3220468.mam_gk_installer_preapproved.enc", "dHJ1ZQ=="); Line Deleted : user_pref("CT3220468.mam_gk_lastLoginTime.enc", "MTM2NTQ3MjY4MzY5NQ=="); Line Deleted : user_pref("CT3220468.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50IFBvbGljeSJ9LCJnYWRnZXREZXNjcmlwdGlvblByaW1hcnkiOnsiVGV4dCI6IlZhbHVlIEFwcHMgZW5yaWNoZXMgeW91ciB3ZWIg[...] Line Deleted : user_pref("CT3220468.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ=="); Line Deleted : user_pref("CT3220468.mam_gk_settings1.4.4.6.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMjE1Xy0xIiwiaXNUZXN0IjpmYWxzZSwiaXNXZWxjb21lRXhwZXJpZW5jZUVuYWJsZWRCeURlZmF1b[...] Line Deleted : user_pref("CT3220468.mam_gk_showCloseButton.enc", "dHJ1ZQ=="); Line Deleted : user_pref("CT3220468.mam_gk_showWelcomeGadget.enc", "ZmFsc2U="); Line Deleted : user_pref("CT3220468.mam_gk_userId.enc", "MDU5YWUxYmYtM2RjMy00NmEwLTkyN2ItYmNhZDZiOGQ0M2Ri"); Line Deleted : user_pref("CT3220468.migrateAppsAndComponents", true); Line Deleted : user_pref("CT3220468.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.pogo.com%2Fgames%2Ftripeaks%3FpageSection%3Dcp_home_game_list_card%23game\",\"EB_MAIN_FR[...] Line Deleted : user_pref("CT3220468.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3220468.openThankYouPage", "true"); Line Deleted : user_pref("CT3220468.openUninstallPage", "FALSE"); Line Deleted : user_pref("CT3220468.search.searchAppId", "129813684258939747"); Line Deleted : user_pref("CT3220468.search.searchCount", "0"); Line Deleted : user_pref("CT3220468.searchInNewTabEnabled", "false"); Line Deleted : user_pref("CT3220468.searchInNewTabEnabledByUser", "false"); Line Deleted : user_pref("CT3220468.searchInNewTabEnabledInHidden", "true"); Line Deleted : user_pref("CT3220468.searchSuggestEnabledByUser", "false"); Line Deleted : user_pref("CT3220468.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3220468.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3220468.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}"); Line Deleted : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3220468\"}"); Line Deleted : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://uTorrentControlv2.OurToolbar.com//xpi\"}"); Line Deleted : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentControl_v2 \"}"); Line Deleted : user_pref("CT3220468.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3220468.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}"); Line Deleted : user_pref("CT3220468.serviceLayer_services_Configuration_lastUpdate", "1386733796758"); Line Deleted : user_pref("CT3220468.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1365286994007"); Line Deleted : user_pref("CT3220468.serviceLayer_services_appsMetadata_lastUpdate", "1365398220357"); Line Deleted : user_pref("CT3220468.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1364422992896"); Line Deleted : user_pref("CT3220468.serviceLayer_services_location_lastUpdate", "1372937198645"); Line Deleted : user_pref("CT3220468.serviceLayer_services_login_10.10.27.6_lastUpdate", "1353495405595"); Line Deleted : user_pref("CT3220468.serviceLayer_services_login_10.14.370.524_lastUpdate", "1364364358313"); Line Deleted : user_pref("CT3220468.serviceLayer_services_login_10.14.65.43_lastUpdate", "1363241162334"); Line Deleted : user_pref("CT3220468.serviceLayer_services_login_10.15.0.562_lastUpdate", "1369278357978"); Line Deleted : user_pref("CT3220468.serviceLayer_services_login_10.16.2.509_lastUpdate", "1372937331809"); Line Deleted : user_pref("CT3220468.serviceLayer_services_login_10.16.4.519_lastUpdate", "1375070704855"); Line Deleted : user_pref("CT3220468.serviceLayer_services_login_10.16.70.505_lastUpdate", "1379301628065"); Line Deleted : user_pref("CT3220468.serviceLayer_services_login_10.20.0.513_lastUpdate", "1386733796460"); Line Deleted : user_pref("CT3220468.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1364422992873"); Line Deleted : user_pref("CT3220468.serviceLayer_services_searchAPI_lastUpdate", "1386733796305"); Line Deleted : user_pref("CT3220468.serviceLayer_services_serviceMap_lastUpdate", "1386733796254"); Line Deleted : user_pref("CT3220468.serviceLayer_services_toolbarContextMenu_lastUpdate", "1364422992842"); Line Deleted : user_pref("CT3220468.serviceLayer_services_toolbarSettings_lastUpdate", "1386740996950"); Line Deleted : user_pref("CT3220468.serviceLayer_services_translation_lastUpdate", "1386733796710"); Line Deleted : user_pref("CT3220468.settingsINI", true); Line Deleted : user_pref("CT3220468.shouldFirstTimeDialog", "false"); Line Deleted : user_pref("CT3220468.showToolbarPermission", "false"); Line Deleted : user_pref("CT3220468.smartbar.CTID", "CT3220468"); Line Deleted : user_pref("CT3220468.smartbar.Uninstall", "0"); Line Deleted : user_pref("CT3220468.smartbar.isHidden", true); Line Deleted : user_pref("CT3220468.smartbar.toolbarName", "uTorrentControl_v2 "); Line Deleted : user_pref("CT3220468.toolbarBornServerTime", "8-10-2012"); Line Deleted : user_pref("CT3220468.toolbarCurrentServerTime", "11-12-2013"); Line Deleted : user_pref("CT3220468.toolbarLoginClientTime", "Thu Mar 14 2013 17:34:48 GMT-0500 (Central Daylight Time)"); Line Deleted : user_pref("CT3220468.upgradeFromClearSBVersion", true); Line Deleted : user_pref("CT3220468.url_history0001.enc", "aHR0cHM6Ly9ibHUxNjkubWFpbC5saXZlLmNvbS9tYWlsLyM6OjpjbGlja2hhbmRsZXI6OjoxMzY1NDcwNTEwNDc3LCwsaHR0cDovL3hoYW1zdGVyLmNvbS9yYW5raW5ncy93ZWVrbHktdG9wLXZpZGVvcy5o[...] Line Deleted : user_pref("CT3220468_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1386733806289,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]"); Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_converterVersion", "%BE%B4%B7%B4%B7%B4%B7%B6"); Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_converterVersion.enc", "OC4xLjEuMTA="); Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_playerVersion", "%B7%B7%B4%B6%B4%B6%B4%B9%BC%BA"); Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_playerVersion.enc", "MTEuMC4wLjM2NA=="); Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_streamerVersion", "%B7%B4%B7%B4%B7%B4%B8%BB"); Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_streamerVersion.enc", "MS4xLjEuMjU="); Line Deleted : user_pref("CT3288691.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3288691.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3288691.FF19Solved", "true"); Line Deleted : user_pref("CT3288691.FirstTime", "true"); Line Deleted : user_pref("CT3288691.FirstTimeFF3", "true"); Line Deleted : user_pref("CT3288691.RestartDialogFirstTime", "false"); Line Deleted : user_pref("CT3288691.RestartDialogShouldDisplay", "false"); Line Deleted : user_pref("CT3288691.UserID", "UN29238774651820727"); Line Deleted : user_pref("CT3288691.addressBarTakeOverEnabledInHidden", "true"); Line Deleted : user_pref("CT3288691.countryCode", "US"); Line Deleted : user_pref("CT3288691.defaultSearch", "false"); Line Deleted : user_pref("CT3288691.enableAlerts", "true"); Line Deleted : user_pref("CT3288691.enableSearchFromAddressBar", "true"); Line Deleted : user_pref("CT3288691.firstTimeDialogOpened", "true"); Line Deleted : user_pref("CT3288691.fixPageNotFoundError", "false"); Line Deleted : user_pref("CT3288691.fixPageNotFoundErrorByUser", "false"); Line Deleted : user_pref("CT3288691.fixPageNotFoundErrorInHidden", "true"); Line Deleted : user_pref("CT3288691.fullUserID", "UN29238774651820727.IN.20131108175914"); Line Deleted : user_pref("CT3288691.installDate", "08/11/2013 17:59:15"); Line Deleted : user_pref("CT3288691.installId", "stub.exe"); Line Deleted : user_pref("CT3288691.installSessionId", "{122D7695-2869-4F27-88DE-F9D7C850D76B}"); Line Deleted : user_pref("CT3288691.installSp", "false"); Line Deleted : user_pref("CT3288691.installType", "conduitnsisintegration"); Line Deleted : user_pref("CT3288691.installUsage", "2013-11-09T02:59:23.4613663+03:00"); Line Deleted : user_pref("CT3288691.installUsageEarly", "2013-11-09T02:59:22.7113519+03:00"); Line Deleted : user_pref("CT3288691.installerVersion", "1.8.0.14"); Line Deleted : user_pref("CT3288691.isCheckedStartAsHidden", true); Line Deleted : user_pref("CT3288691.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3288691.isFirstTimeToolbarLoading", "false"); Line Deleted : user_pref("CT3288691.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); Line Deleted : user_pref("CT3288691.keyword", "true"); Line Deleted : user_pref("CT3288691.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?gd=&ctid=CT3288691&octid=CT3288691&ISID=ISID_ID&SearchSource=15&CUI=UN29238774651820727&Lay=1[...] Line Deleted : user_pref("CT3288691.lastVersion", "10.29.0.520"); Line Deleted : user_pref("CT3288691.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.bobandtom.com%2Fcommon%2Fpage.php%3Fpt%3DR.I.P.%2BTim%2BWilson%26id%3D994%26is_corp%3D0\[...] Line Deleted : user_pref("CT3288691.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3288691.openThankYouPage", "false"); Line Deleted : user_pref("CT3288691.openUninstallPage", "true"); Line Deleted : user_pref("CT3288691.originalSearchAddressUrl", ""); Line Deleted : user_pref("CT3288691.performedDomainChangesMigration", "true"); Line Deleted : user_pref("CT3288691.revertSettingsEnabled", "false"); Line Deleted : user_pref("CT3288691.search.searchAppId", "10000002"); Line Deleted : user_pref("CT3288691.search.searchCount", "0"); Line Deleted : user_pref("CT3288691.searchInNewTabEnabledByUser", "false"); Line Deleted : user_pref("CT3288691.searchInNewTabEnabledInHidden", "true"); Line Deleted : user_pref("CT3288691.searchRevert", "false"); Line Deleted : user_pref("CT3288691.searchSuggestEnabledByUser", "true"); Line Deleted : user_pref("CT3288691.searchUserMode", "2"); Line Deleted : user_pref("CT3288691.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3288691.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3288691.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}"); Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3288691\"}"); Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DivXBrowserBar.OurToolbar.com//xpi\"}"); Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DivX Browser Bar \"}"); Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}"); Line Deleted : user_pref("CT3288691.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}"); Line Deleted : user_pref("CT3288691.serviceLayer_services_Configuration_lastUpdate", "1397942871338"); Line Deleted : user_pref("CT3288691.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1383955194727"); Line Deleted : user_pref("CT3288691.serviceLayer_services_appsMetadata_lastUpdate", "1383955196165"); Line Deleted : user_pref("CT3288691.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1383955192284"); Line Deleted : user_pref("CT3288691.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1383955190413"); Line Deleted : user_pref("CT3288691.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1383955191149"); Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.21.1.507_lastUpdate", "1384412023407"); Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.21.1.7_lastUpdate", "1384228840732"); Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.22.3.518_lastUpdate", "1384931808585"); Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.22.5.510_lastUpdate", "1386733796557"); Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.23.0.822_lastUpdate", "1396503299019"); Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.29.0.520_lastUpdate", "1397971678170"); Line Deleted : user_pref("CT3288691.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1383955192631"); Line Deleted : user_pref("CT3288691.serviceLayer_services_searchAPI_lastUpdate", "1397942871791"); Line Deleted : user_pref("CT3288691.serviceLayer_services_serviceMap_lastUpdate", "1397942871103"); Line Deleted : user_pref("CT3288691.serviceLayer_services_toolbarContextMenu_lastUpdate", "1383955191849"); Line Deleted : user_pref("CT3288691.serviceLayer_services_toolbarSettings_lastUpdate", "1397971672999"); Line Deleted : user_pref("CT3288691.serviceLayer_services_translation_lastUpdate", "1397962135964"); Line Deleted : user_pref("CT3288691.settingsINI", true); Line Deleted : user_pref("CT3288691.shouldFirstTimeDialog", "false"); Line Deleted : user_pref("CT3288691.showToolbarPermission", "false"); Line Deleted : user_pref("CT3288691.smartbar.CTID", "CT3288691"); Line Deleted : user_pref("CT3288691.smartbar.Uninstall", "0"); Line Deleted : user_pref("CT3288691.smartbar.toolbarName", "DivX Browser Bar "); Line Deleted : user_pref("CT3288691.startPage", "false"); Line Deleted : user_pref("CT3288691.toolbarBornServerTime", "9-11-2013"); Line Deleted : user_pref("CT3288691.toolbarCurrentServerTime", "20-4-2014"); Line Deleted : user_pref("CT3288691.toolbarInstallDate", "08-11-2013 17:59:14"); Line Deleted : user_pref("CT3288691.toolbarLoginClientTime", "Fri Nov 08 2013 17:59:58 GMT-0600 (Central Standard Time)"); Line Deleted : user_pref("CT3288691.versionFromInstaller", "10.21.1.7"); Line Deleted : user_pref("CT3288691.xpeMode", "0"); Line Deleted : user_pref("CT3288691_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1397856488080,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]"); Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", ""); Line Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 2); Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3288691"); Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN29238774651820727&UM=2&q="); Line Deleted : user_pref("smartbar.machineId", "TOZZNJDKJHALHAYSBEV7KCROF/VSOPJGVHG6ZOTTQNAPX0ODBKHI4DMB5AVX/HUDV94WVYO6QOHO8EF6MDON3A"); Line Deleted : user_pref("smartbar.searchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN29238774651820727&UM=2&q="); Line Deleted : user_pref("valueApps.CT3288691.mam_gk_currentVersion", "312E31332E302E3137"); Line Deleted : user_pref("valueApps.CT3288691.mam_gk_currentVersion.storedInFile", false); Line Deleted : user_pref("valueApps.CT3288691.mam_gk_globalKeysMigratedToLocalStorage", "31"); Line Deleted : user_pref("valueApps.CT3288691.mam_gk_globalKeysMigratedToLocalStorage.storedInFile", false); Line Deleted : user_pref("valueApps.CT3288691.mam_gk_migrated_from_ls", "31"); Line Deleted : user_pref("valueApps.CT3288691.mam_gk_migrated_from_ls.storedInFile", false); Line Deleted : user_pref("valueApps.CT3288691.mam_gk_userBornDate", "4E2F41"); Line Deleted : user_pref("valueApps.CT3288691.mam_gk_userBornDate.storedInFile", false); ************************* AdwCleaner[R0].txt - [29428 octets] - [20/04/2014 08:46:20] AdwCleaner[s0].txt - [29298 octets] - [20/04/2014 08:54:31] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [29359 octets] ########## JRT log: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.6 (03.22.2015:1) OS: Windows 7 Professional x64 Ran by Mike on Thu 03/26/2015 at 22:22:34.29 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateWhilokii_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateWhilokii_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateWhilokii_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateWhilokii_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E862C728-AF17-40E3-BCDF-584932ABFDEE} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Mike\AppData\Roaming\getrighttogo" Successfully deleted: [Folder] "C:\Users\Mike\appdata\local\cre" Successfully deleted: [Folder] "C:\Users\Mike\appdata\local\downloadmanager" Successfully deleted: [Empty Folder] C:\Users\Mike\appdata\local\{5337168D-21D1-468D-9116-42566BA49C47} Successfully deleted: [Empty Folder] C:\Users\Mike\appdata\local\{77E810EE-6A26-45FA-AF47-D668C959146B} ~~~ FireFox Successfully deleted the following from C:\Users\Mike\AppData\Roaming\mozilla\firefox\profiles\lays53kr.default\prefs.js user_pref("WebVideoDownloaderHistory.HistoryArray_0.url", "hxxp://o-o.preferred.ccitexas-ord1.v18.lscache5.c.youtube.com/videoplayback?burst=40&itag=34&fexp=914073%2C919319%2C user_pref("WebVideoDownloaderHistory.HistoryArray_15.url", "hxxp://game3.pogo.com/v/F5Spug/applet/sounds/premspin/blnc.au"); user_pref("WebVideoDownloaderHistory.HistoryArray_16.url", "hxxp://game3.pogo.com/v/F5Spug/applet/sounds/premspin/prizeaward.au"); user_pref("WebVideoDownloaderHistory.HistoryArray_17.url", "hxxp://game3.pogo.com/v/F5Spug/applet/sounds/premspin/Positiveding.au"); user_pref("WebVideoDownloaderHistory.HistoryArray_20.url", "hxxp://o-o---preferred---ccitexas-ord1---v9---lscache2.c.youtube.com/videoplayback?algorithm=throttle-factor&burst= user_pref("WebVideoDownloaderHistory.HistoryArray_5.url", "hxxp://game3.pogo.com/v/F2-ALQ/applet/sounds/premspin/Positiveding.au"); user_pref("WebVideoDownloaderHistory.HistoryArray_6.url", "hxxp://game3.pogo.com/v/F2-ALQ/applet/sounds/premspin/blnc.au"); user_pref("WebVideoDownloaderHistory.HistoryArray_7.url", "hxxp://game3.pogo.com/v/F2-ALQ/applet/sounds/premspin/prizeaward.au"); user_pref("valueApps.storage.mam_gk_userId", "61366439623432362D303437342D346364372D613932382D356433383066333534373730"); Emptied folder: C:\Users\Mike\AppData\Roaming\mozilla\firefox\profiles\lays53kr.default\minidumps [47 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Thu 03/26/2015 at 22:25:51.78 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  14. I have performed the requested tasks. Because of the disclaimer, I want to mention that the HiJack This scan did include this line: 04 - HKCU..Run [uTorrent] "C:\Program Files(x86) uTorrent\uTorrent.exe"/MINIMIZED. This program has been uninstalled for 2-3 years and do not know why it shows up here; perhaps just the remnant in the registry. Malwarebytes log: Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 3/26/2015 Scan Time: 4:37:13 PM Logfile: MBAM_3-26-15.txt Administrator: Yes Version: 2.01.4.1018 Malware Database: v2015.03.26.07 Rootkit Database: v2015.03.26.01 License: Premium Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Enabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Mike Scan Type: Threat Scan Result: Completed Objects Scanned: 467685 Time Elapsed: 38 min, 19 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end) FRST and Additional logs are large and will attach. Rogue Killer log: RogueKiller V10.5.7.0 (x64) [Mar 22 2015] by Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Website : http://www.adlice.com/softwares/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : Mike [Administrator] Started from : C:\Users\Mike\Desktop\RogueKillerX64.exe Mode : Scan -- Date : 03/26/2015 17:44:25 ¤¤¤ Processes : 0 ¤¤¤ ¤¤¤ Registry : 12 ¤¤¤ [suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run | ROC_ROC_APR2013_AV : C:\Users\Mike\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT --mid ddbae792321c47d1ba9ed15426e99490-dea33aeff6aaebca622fc55477b442c3c67ca2ee --CMPID ROC_APR2013_AV --CMPIDEXTRA 2013 -> Found [suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run | AVG-Secure-Search-Update_0913a : C:\Users\Mike\AppData\Roaming\AVG 0913a Campaign\AVG-Secure-Search-Update-0913a.exe /PROMPT --mid ddbae792321c47d1ba9ed15426e99490-dea33aeff6aaebca622fc55477b442c3c67ca2ee --CMPID 0913a -> Found [suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run | AVG-Secure-Search-Update_1113a : C:\Users\Mike\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=ddbae792321c47d1ba9ed15426e99490-dea33aeff6aaebca622fc55477b442c3c67ca2ee /CMPID=1113a -> Found [suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run | ROC_ROC_APR2013_AV : C:\Users\Mike\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT --mid ddbae792321c47d1ba9ed15426e99490-dea33aeff6aaebca622fc55477b442c3c67ca2ee --CMPID ROC_APR2013_AV --CMPIDEXTRA 2013 -> Found [suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run | AVG-Secure-Search-Update_0913a : C:\Users\Mike\AppData\Roaming\AVG 0913a Campaign\AVG-Secure-Search-Update-0913a.exe /PROMPT --mid ddbae792321c47d1ba9ed15426e99490-dea33aeff6aaebca622fc55477b442c3c67ca2ee --CMPID 0913a -> Found [suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Run | AVG-Secure-Search-Update_1113a : C:\Users\Mike\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=ddbae792321c47d1ba9ed15426e99490-dea33aeff6aaebca622fc55477b442c3c67ca2ee /CMPID=1113a -> Found [PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Found [PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1754454339-2153682011-3722641661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Found [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Found [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Found [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Found [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Found ¤¤¤ Tasks : 4 ¤¤¤ [suspicious.Path] 0814avUpdateInfo.job -- C:\ProgramData\Avg_Update_0814av\0814av_AVG-Secure-Search-Update.exe ( /SETINFO /CMPID=0814av /INFORETRY=3) -> Found [suspicious.Path] ROC_REG_JAN_DELETE.job -- C:\ProgramData\AVG January 2013 Campaign\ROC.exe (/DELETE_FROM_SYSTEM=1) -> Found [suspicious.Path] \\0814avUpdateInfo -- C:\ProgramData\Avg_Update_0814av\0814av_AVG-Secure-Search-Update.exe (/SETINFO /CMPID=0814av /INFORETRY=3) -> Found [suspicious.Path] \\ROC_REG_JAN_DELETE -- C:\ProgramData\AVG January 2013 Campaign\ROC.exe (/DELETE_FROM_SYSTEM=1) -> Found ¤¤¤ Files : 0 ¤¤¤ ¤¤¤ Hosts File : 0 [Too big!] ¤¤¤ ¤¤¤ Antirootkit : 1 (Driver: Loaded) ¤¤¤ [Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\cdrom @ \Device\CdRom0 (\SystemRoot\System32\drivers\volmgrx.sys) ¤¤¤ Web browsers : 1 ¤¤¤ [PUM.HomePage][FIREFX:Config] lays53kr.default : user_pref("browser.startup.homepage", "http://my.ebay.com/ws/eBayISAPI.dll?MyEbay&gbh=1&CurrentPage=MyeBaySummary&ssPageName=STRK:ME:LNLK:MESUMX");-> Found ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: WDC WD1001FALS-00J7B0 ATA Device +++++ --- User --- [MBR] eccf1e8dcb5e3920b6dea69b052fa7d1 [bSP] ce2aa0a90325b0e7c3aa954f5afc1bce : Windows Vista/7/8 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953767 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive1: HP Photosmart 6510 USB Device +++++ Error reading User MBR! ([15] The device is not ready. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] The request is not supported. ) Addition.txt FRST.txt
  15. For the last few days I have had trouble getting some web pages to load. Some will load very slowly and some not at all. A few days ago I ran Malwarebytes and I got a clean report. Yesterday I ran Hijack This and it showed "For some reason your system denied write access to the Hosts file." Overnight Malwarebytes ran again and it showed three instances of Conduit which I quarantined and deleted. After this, I again tried to refresh some of the pages and they still would not load. It look probably five or six times to get this page to load on my PC, but could never get this post to send. I am sending from my phone. I am running Windows 7 with 8GB memory. I use Firefox and also tried IE with the same results. Does anyone have a clue what I can do to get my internet connection going again? Thanks.