CloseProcesses: CreateRestorePoint: (Coupons.com Inc.) C:\Program Files (x86)\Coupons\CouponPrinterService.exe C:\Program Files (x86)\Coupons HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [] => [X] SearchScopes: HKU\S-1-5-21-2265975064-750569843-396226551-1000 -> URL hxxp://search.conduit.com/Results.aspx?ctid=CT3323128&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP24669AC7-576C-4678-B3F0-03F1FEE1369D&q={searchTerms}&SSPV= URLSearchHook: HKU\S-1-5-21-2265975064-750569843-396226551-1000 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File FF SearchEngineOrder.2: FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2014-10-01] (Coupons, Inc.) R2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [179184 2014-10-15] (Coupons.com Inc.) S2 0033971393984459mcinstcleanup; C:\windows\TEMP\003397~1.EXE -cleanup -nolog [X] S2 OutfoxTvService; C:\Program Files\OutfoxTV\OutfoxTvService.exe [X] C:\Program Files\OutfoxTV U3 McMPFSvc; no ImagePath U3 McNaiAnn; no ImagePath U3 mcpltsvc; no ImagePath U3 McProxy; no ImagePath U3 mfecore; no ImagePath U3 MSK80Service; no ImagePath AlternateDataStreams: C:\ProgramData\Temp:373E1720 EmptyTemp: CMD: bitsadmin /reset /allusers cmd: netsh advfirewall reset cmd: netsh advfirewall set allprofiles state on Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartupApproved" /F Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartupApproved" /F Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F