Hello, Amanda.
Thank you for the logs. Given the amount of infection on your system, I cannot guarantee that we can completely resolve all the issues completely by this weekend. Let's do what we can before you leave. If you will be away for 2 weeks, I will leave this topic open until you return.
Regarding
UniblueDriverscanner.exe. This was not attached to any of my requests. It appears that this application installs on a system without a user's approval when downloading other software. It is an application designed to check the PC's currently installed drivers against a database and downloads an updated driver if available. However, before downloading the actual driver, the user has to purchase a standing order. We will go ahead and remove this software.
Please back up your system
The following fix requires altering your Windows Registry. Therefore, we need to back it up in case we run into problems.
- Please download ERUNT to your desktop from HERE.
- Right click erunt.zip, choose Extract Allβ¦, and follow the prompts to unzip the program.
- Open the ERUNT folder on your Desktop and double click ERUNT.exe to start the program.
- Click OK for all the prompts to back up your registry to the default location.
Note: if it becomes necessary to restore the registry, open the backup folder and start ERDNT.exe.
Please run the following scan
Run
OTL.exe
- Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
- Then click the Run Fix button at the top.
:processes
killallprocesses
:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=007E00255631B513&affID=121240&tsp=4961
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.deltasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=007E00255631B513&affID=121240&tsp=4961
FF - user.js - File not found
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
[2013/08/01 23:28:59 | 000,000,000 | βD | M] (Wajam) β C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\vixxn2lu.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}
[2013/08/01 23:33:19 | 000,000,000 | βD | M] ("QuickShare Widget") β C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\vixxn2lu.default\extensions\{e5dce098-209c-4f1d-a3ee-52aa625feec2}
[2013/08/01 23:30:11 | 000,000,000 | βD | M] ("Solid Savings") β C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\vixxn2lu.default\extensions\[removed]
[2013/08/01 23:27:44 | 000,006,507 | β- | M] () β C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\vixxn2lu.default\searchplugins\babylon.xml
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKCU..\Run: [NTRedirect] C:\Windows\system32\rundll32.exe "C:\Users\Amanda\AppData\Roaming\BabSolution\Shared\NTRedirect.dll",Run File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O16 - DPF: {FD0EBBED-0C42-4D0F-82DA-44399B5C420A} http://downloads.virginmedia.com/CST/ver1/vistainstaller.cab (Reg Error: Value error.)
O20 - AppInit_DLLs: (c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll ()
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - No CLSID value found.
[2013/08/02 12:35:44 | 000,000,000 | βD | C] β C:\ProgramData\Uniblue
[2013/08/01 23:31:41 | 000,000,000 | βD | C] β C:\Users\Amanda\AppData\Roaming\Uniblue
[2013/08/01 23:31:07 | 000,000,000 | βD | C] β C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2013/08/01 23:31:04 | 000,000,000 | βD | C] β C:\Program Files\Uniblue
[2013/08/01 23:30:02 | 000,000,000 | βD | C] β C:\Program Files\Solid Savings
[2013/08/01 23:28:14 | 000,000,000 | βD | C] β C:\Users\Amanda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
[2013/08/01 23:28:06 | 000,000,000 | βD | C] β C:\ProgramData\BrowserDefender
:Files
ipconfig /flushdns /c
:Commands
[emptytemp]
[resethosts]
[CREATERESTOREPOINT]
- Let the program run unhindered; it will reboot when it is done. If it does not, please reboot your system.
- Post the new log in your next reply.