Start
HKLM\...\InprocServer32: [Default-cscui] <==== ATTENTION!
HKCU\...\Run: [GetBooks] - C:\Users\Luci\AppData\Local\GetBooks\GetBooks.exe [509440 2013-05-15] ()
MountPoints2: {13ae7729-e3b9-11df-934e-806e6f6e6963} - E:\InstAll.exe
MountPoints2: {6334e708-69c5-11e0-840b-20cf302aa77b} - F:\Startme.exe
MountPoints2: {fee2718c-80af-11e0-b528-20cf302aa77b} - "G:\WD SmartWare.exe" autoplay=true
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.net?appid=1157
URLSearchHook: (No Name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - No File
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL = http://dts.search-results.com/sr?src=ie ... nrs=AGE&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL = http://dts.search-results.com/sr?src=ie ... nrs=AGE&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL = http://dts.search-results.com/sr?src=ie ... nrs=AGE&q={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL = http://dts.search-results.com/sr?src=ie ... nrs=AGE&q={searchTerms}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL = http://dts.search-results.com/sr?src=ie ... nrs=AGE&q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=111015&tt=060612_6_&babsrc=SP_ss_cr&mntrId=0cbda7cd00000000000072f06d8ce164
SearchScopes: HKCU - {4B8C28A7-A9BC-45F8-990D-21499EED643C} URL = http://www.questscan.com/?prt=QstscanPB&keywords={searchTerms}
SearchScopes: HKCU - {65DCECE6-824B-4CCE-8A79-15A9AB21DEA6} URL = http://search.yahoo.com/search?fr=chr-g ... =198484&p={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL = http://dts.search-results.com/sr?src=ie ... nrs=AGE&q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253
FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.as ... ource=2&q=
FF SearchPlugin: C:\Users\Luci\AppData\Roaming\Mozilla\Firefox\Profiles\g9rjekg0.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\Luci\AppData\Roaming\Mozilla\Firefox\Profiles\g9rjekg0.default\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
FF HKLM-x32\...\Firefox\Extensions: [ClickPotatoLite@ClickPotatoLite.com] C:\Program Files (x86)\ClickPotatoLite\bin\11.0.19.0\firefox\extensions
FF Extension: ClickPotatoLite Component - C:\Program Files (x86)\ClickPotatoLite\bin\11.0.19.0\firefox\extensions
CHR HomePage: hxxp://search.imesh.net?appid=1157
CHR HKLM-x32\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Program Files (x86)\Common Files\Spigot\GC\coupons_2.4.crx
CHR HKLM-x32\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\Luci\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx
CHR HKLM-x32\...\Chrome\Extension: [pfndaklgolladniicklehhancnlgocpp] - C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx
Task: {66A9C07B-93F4-486F-8190-9DDDC9A83927} - System32\Tasks\Norton Security Scan for Luci => C:\Program Files (x86)\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-07-07] (Symantec Corporation)
Task: C:\Windows\Tasks\Norton Security Scan for Luci.job => C:\Program Files (x86)\Norton Security Scan\Engine\2.7.3.34\Nss.exe
C:\Users\Luci\AppData\Local\GetBooks\GetBooks.exe
Hosts:
End