:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://start.funmoods.com/?f=1&a=iron2& ... 1476950442 IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{5C59EA7A-B509-BC51-5274-39737BD12B4A}: "URL" =
http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
IE - HKCU\..\URLSearchHook: {AEEC3B59-CA98-4EBA-A140-57B94E283583} - No CLSID value found
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {814C76CB-2623-43F4-AAD0-58A0E5190A20}
IE - HKCU\..\SearchScopes,DefaultScope = {814C76CB-2623-43F4-AAD0-58A0E5190A20}
IE - HKCU\..\SearchScopes\{5C59EA7A-B509-BC51-5274-39737BD12B4A}: "URL" =
http://r.orange.fr/r?ref=O_OI_hook_open ... nge?rdata={searchTerms}
IE - HKCU\..\SearchScopes\{814C76CB-2623-43F4-AAD0-58A0E5190A20}: "URL" =
http://r.orange.fr/r?ref=O_OI_hook_open ... nge?rdata={searchTerms}
IE - HKCU\..\SearchScopes\{D6AA20EA-B90A-4DF3-8D3E-ED3FF55FBD1B}: "URL" =
http://websearch.ask.com/redirect?clien ... src=crm&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=6FBF62ED-2912-4126-8645-57B9332C49CC&apn_sauid=86F1B8E0-8A05
FF - prefs.js..backup.old.browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..extensions.enabledAddons:
ffxtlbr@babylon.com:1.5.0
FF - prefs.js..extensions.enabledAddons:
ffxtlbr@funmoods.com:1.5.1
[2012/08/30 11:05:35 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\h3hrpsm2.default\extensions\ffxtlbr@babylon.com
[2012/08/29 12:56:04 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\h3hrpsm2.default\extensions\ffxtlbr@funmoods.com
[2012/08/25 11:43:55 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\h3hrpsm2.default\extensions\toolbar@ask.com
[2012/08/25 11:43:55 | 000,002,299 | ---- | M] () -- C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\h3hrpsm2.default\searchplugins\askcom.xml
CHR - default_search_provider: Web Search ()
CHR - default_search_provider: search_url =
http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0FtDyB0B0C0BtC0F0F0DtA0E0AyCtDzytN0D0Tzu0CtByEtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1476950442
CHR - homepage:
http://start.funmoods.com/?f=1&a=iron2& ... 1476950442 O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM\..\Run: [] File not found
O4 - Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Socialbox.lnk = File not found
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:0B9176C0
:Commands
[emptytemp]