:OTL
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.nationzoom.com/web/?type=ds&ts=1388339732&from=tugs&uid=395049983_1052515_7C3A2C28&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.nationzoom.com/web/?type=ds&ts=1388339732&from=tugs&uid=395049983_1052515_7C3A2C28&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}: "URL" =
http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dnldstr&cd=2XzuyEtN2Y1L1QzuyBtDyBtC0B0C0EtD0Azz0DtBtB0CtBzztN0D0Tzu0SyCzzzytN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R&cr=2045456231&ir=
IE - HKU\S-1-5-21-2932182427-2808064505-1375074575-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://start.iminent.com/?appId=E5837EF9-C7F4-45B9-B5F7-5F95D21173CB&ref=toolbox&q={searchTerms}
FF - prefs.js..extensions.enabledAddons: 183e80e2-aadc-4735-b752-524bfc0a2000%408be0bc77-499e-4775-8a8c-aaf7a94d52fc.com:0.95.126
FF - prefs.js..extensions.enabledAddons: firefoxmini%40go.im:8.30.1.1
FF - prefs.js..extensions.enabledAddons: TAZQS3370276%40NSOGW71353942.com:0.95.12
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:31.0
CHR - homepage:
http://start.iminent.com/?appId=E5837EF9-C7F4-45B9-B5F7-5F95D21173CBO3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O18:[b]64bit:[/b] - Protocol\Handler\linkscanner - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O27 - HKLM IFEO\rjatydimofu.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
:Files
C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpfeggemggokijeahnacacopejaabljl
C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pigkdicgnehbfjnaopalgpelkbkcnbfa
ipconfig /flushdns /c
:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]