IE - HKLM\..\SearchScopes\{63C5EA49-DA73-48DA-83E1-A84E4A4F921C}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms }&SearchSource=4&ctid=CT280193 9
IE - HKU\S-1-5-21-4077891155-3280609002-2602844934-1000\..\URLSearchHook: {9e96c0cd-a901-4032-9236-0e4a264aeee4} - No CLSID value found
IE - HKU\S-1-5-21-4077891155-3280609002-2602844934-1000\..\SearchScopes,DefaultSc ope = {13EEED75-D16E-4FBD-9466-3BE52A77A91F}
IE - HKU\S-1-5-21-4077891155-3280609002-2602844934-1000\..\SearchScopes\{13EEED75-D16E-4FBD-9466-3BE52A77A91F}: "URL" = http://www.fastbrowsersearch.com/results/results.aspx?q={searchTerms}&c =web&s=DSP&v=19&tid={83E259ED-4849-489d-9E34-1441669233EC}
IE - HKU\S-1-5-21-4077891155-3280609002-2602844934-1000\..\SearchScopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}: "URL" = http://fastbrowsersearch.com/results/results.aspx?q={searchTerms}&c =web&s=DSP&v=19&tid={83E259ED-4849-489d-9E34-1441669233EC}
IE - HKU\S-1-5-21-4077891155-3280609002-2602844934-1000\..\SearchScopes\{63C5EA49-DA73-48DA-83E1-A84E4A4F921C}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms }&SearchSource=4&ctid=CT280193 9
FF - prefs.
js..extensions.enabledIt ems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.
js..extensions.enabledIt ems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.
js..extensions.enabledIt ems:
ShopperReports@ShopperReports. com:3.0.497.0
FF - prefs.
js..extensions.enabledIt ems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.
js..extensions.enabledIt ems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.
js..extensions.enabledIt ems: vshare@toolbar:1.0.0
O3 - HKU\.DEFAULT\..\Toolbar\WebBro wser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found.
O3 - HKU\S-1-5-21-4077891155-3280609002-2602844934-1000\..\Toolbar\WebBrowser: (no name) - {9E96C0CD-A901-4032-9236-0E4A264AEEE4} - No CLSID value found.
O4 - HKU\S-1-5-21-4077891155-3280609002-2602844934-1000\..\Run: [Polar Sync] File not found
O4 - HKLM\..\RunOnce: [DeleteDir[CD8] Fast Browser Search] cmd.exe /C RD /S /Q C:\PROGRA~1\FASTBR~1 File not found
O4 - HKLM\..\RunOnce: [DeleteDir[CD8] SGPSA] cmd.exe /C RD /S /Q C:\PROGRA~1\SGPSA File not found
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_07)
O33 - MountPoints2\{3454d7c9-1664-11df-9f2e-00225f20efbd}\Shell\AutoRun\co mmand - "" = srgo.exe
O33 - MountPoints2\{3454d7c9-1664-11df-9f2e-00225f20efbd}\Shell\open\Comma nd - "" = srgo.exe
O33 - MountPoints2\{892cee0c-37c7-11de-b697-00225f20efbd}\Shell - "" = AutoRun
O33 - MountPoints2\{892cee0c-37c7-11de-b697-00225f20efbd}\Shell\AutoRun\co mmand - "" = H:\LaunchU3.exe -a
O33 - MountPoints2\{f3d3c47f-b1b3-11df-a911-002170909f68}\Shell - "" = AutoRun
O33 - MountPoints2\{f3d3c47f-b1b3-11df-a911-002170909f68}\Shell\AutoRun\co mmand - "" = G:\ReadMe.exe
[1 C:\Users\Heïdy\AppData\Local\* .tmp files -> C:\Users\Heïdy\AppData\Local\* .tmp -> ]
[954 C:\Users\HEDY~1\AppData\Local\ Temp\*.tmp files -> C:\Users\HEDY~1\AppData\Local\ Temp\*.tmp -> ]
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:6B9ADB51
:Files
ipconfig /flushdns /c
:Commands
[emptytemp]