:OTL
MOD - C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll ()
MOD - C:\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll ()
IE - HKU\S-1-5-21-3360812674-231123269-959133015-1000\..\SearchScopes\{5B1E54A2-A4E1-4D74-B618-A2BB75F00F5E}: "URL" =
http://search.conduit.com/ResultsExt.as ... 31910&UM=2
IE - HKU\S-1-5-21-3360812674-231123269-959133015-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.offerbox.com
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ips\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coieplg.dll (Symantec Corporation)
O4 - HKU\.DEFAULT..\Run: [SearchProtect] \SearchProtect\bin\cltmng.exe File not found
O4 - HKU\S-1-5-18..\Run: [SearchProtect] \SearchProtect\bin\cltmng.exe File not found
O36 - AppCertDlls: x64 - (C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll) - C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll ()
O36 - AppCertDlls: x86 - (C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll) - C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll ()
MsConfig:64bit - StartUpFolder: C:^Users^claude^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^lollipop.lnk - - File not found
[2013/08/13 12:25:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Wincert
[2013/08/13 12:25:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Movies Toolbar
[2013/08/13 12:25:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Datamngr
[2013/08/13 12:24:56 | 000,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\iLivid
[2013/08/13 11:30:39 | 000,000,000 | ---D | C] -- C:\ProgramData\BrowserDefender
[5 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
:reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2D795BEC-4BE7-41B2-8961-9F9C2D918C2C}"=-
"{8DCACC3A-D2C8-4641-9753-D290B88C3F66}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbardlaGC]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Tuto_4pc_is1]
:commands
[emptytemp]