R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://start.facemoods.comR1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs =
http://start.facemoods.com O4 - Global Startup: C:\Users\UpdatusUser\Desktop\SpeedFan.lnk . (...) -- C:\Program Files (x86)\SpeedFan\speedfan.exe (.not file.)
O42 - Logiciel: Facemoods Toolbar - (.Pas de propriétaire.) [HKLM] – facemoods
[HKCU\Software\facemoods.com]
[HKLM\Software\facemoods.com]
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.DNSErrUrl", "http://start.facemoods.com/?a=ddrnw&f=5"); =>
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.aflt", "_#ddrnw");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.dfltSrch", true);
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.dfltSrchPrvdr", "Facemoods Search");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.dnsErr", true);
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.firstRun", false);
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.first_time", false);
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.hmpg", true);
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.hmpgUrl", "http://start.facemoods.com/?a=ddrnw");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.id", "_#64c3094600000000000000268336e044");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.instlDay", "_#15320");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.mntz", "");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.newTab", true);
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.newTabUrl", "http://start.facemoods.com/?a=ddrnw&f=2");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.searchProviderAdded", true)
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.sid", "_#d2bc945e38e442a59fa83e05fa90a097");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.tlbrSrchUrl", "http://start.facemoods.com/?a=ddrnw&f=3");
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.uninst", true);
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.update", "_#v1.4.0"
O69 - SBI: prefs.js [Ziiz - bo7suia1.default] user_pref("extensions.facemoods.vrsn", "_#1.4.17.11")
O69 - SBI: SearchScopes [HKCU] {0D7562AE-8EF6-416d-A838-AB665251703A} [DefaultScope] - (Facemoods Search) -
http://start.facemoods.com HKLM\Software\WOW6432Node\Classes\AppID\esrv.EXE]
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}]
[HKLM\Software\WOW6432Node\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}]
[HKLM\Software\WOW6432Node\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}]
[HKLM\Software\WOW6432Node\Classes\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}]
[HKLM\Software\WOW6432Node\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}]
[HKLM\Software\WOW6432Node\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}]
[HKLM\Software\WOW6432Node\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}]
[HKLM\Software\WOW6432Node\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}]
[HKLM\Software\WOW6432Node\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}]
[HKLM\Software\WOW6432Node\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}]
[HKLM\Software\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}]
[HKLM\Software\WOW6432Node\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}]
[HKLM\Software\WOW6432Node\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}]
[HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
[HKLM\Software\WOW6432Node\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}]
[HKLM\Software\WOW6432Node\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}]
[HKLM\Software\WOW6432Node\Google\Chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif]
[HKCU\Software\facemoods.com]
[HKLM\Software\WOW6432Node\facemoods.com]
C:\Users\Ziiz\AppData\LocalLow\facemoods.com
FirewallRaz
EmptyFlash
Emptytemp