This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus and Malware [Closed]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi HR2008,

It would be more helpful if you would follow the directions below and post these requested logs. B)

=========================

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

1. Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

2. aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================


3. OTL

Download OTL to your desktop.
  • Make sure all other windows are closed and to let it run uninterrupted.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    dir "%systemdrive%\*" /S /A:L /C
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    BASESERVICES
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
    • You may need two posts to fit them both in.
=========================

In your next post please provide the following:
  • checkup.txt
  • aswMBR.txt
  • attach MBR.zip
  • OTL.txt
  • Extras.txt
Results of screen317's Security Check version 0.99.71
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Trend Micro AntiVirus
Microsoft Security Essentials
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
Malwarebytes Anti-Malware version 1.70.0.1100
Out of date Malwarebytes Anti-Malware installed!
HijackThis 2.0.2
CCleaner
Java™ 6 Update 32
Java 7 Update 21
Java version out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader 8 Adobe Reader out of Date!
Mozilla Firefox (22.0)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Trend Micro Internet Security SfCtlCom.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````





end of checkup
beginning of aswMbR

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-08-07 19:36:21
—————————–
19:36:21.359 OS Version: Windows 5.1.2600 Service Pack 3
19:36:21.359 Number of processors: 2 586 0xF0D
19:36:21.359 ComputerName: DJTYBHF1 UserName:
19:36:22.187 Initialize success
19:52:14.359 AVAST engine defs: 13080701
19:52:39.343 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
19:52:39.359 Disk 0 Vendor: ST980811AS 3.CDE Size: 76319MB BusType: 3
19:52:39.515 Disk 0 MBR read successfully
19:52:39.515 Disk 0 MBR scan
19:52:39.578 Disk 0 Windows XP default MBR code
19:52:39.578 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 78 MB offset 63
19:52:39.625 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 73673 MB offset 160650
19:52:39.671 Disk 0 Partition - 00 0F Extended LBA 2557 MB offset 151059195
19:52:39.703 Disk 0 Partition 3 00 DD MSDOS5.0 2557 MB offset 151059258
19:52:40.046 Disk 0 scanning sectors +156296385
19:52:40.437 Disk 0 scanning C:\WINDOWS\system32\drivers
19:53:12.015 Service scanning
19:53:34.218 Service MpKsl7d11627e c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AF3218BF-9CD4-45FC-99B0-B4EAD5E15871}\MpKsl7d11627e.sys **LOCKED** 32
19:54:01.296 Modules scanning
19:54:17.781 Disk 0 trace - called modules:
19:54:17.828 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
19:54:17.843 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a96bab8]
19:54:17.859 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8a947940]
19:54:18.234 AVAST engine scan C:\WINDOWS
19:54:29.562 AVAST engine scan C:\WINDOWS\system32
19:59:35.562 AVAST engine scan C:\WINDOWS\system32\drivers
20:00:09.562 AVAST engine scan C:\Documents and Settings\TEMP
20:02:28.953 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\TEMP\Desktop\MBR.dat"
20:02:28.968 The log file has been saved successfully to "C:\Documents and Settings\TEMP\Desktop\aswMBR.txt"


end MBR.txt
MBR.dat attached
beginning OTL

was unable to use this as it told me to have it on my desktop and it was already there
i did actually download it and move it to the desktop as told it told me this exactly OTL cannot be run from a temporary folder! Please download it to your desktop or other suitable location. just to clarify my previous statement
Hi HR2008,

You can choose a location on your computer where downloads should be saved by default. This means that whenever you using Save As in the File> Save As or when you choose to Save a download, it will automatically default to the location you have set. You may find that setting the Default Download Location to your Desktop the most convenient.If you want to move the file later, you can. If you want to delete the file, it will be most handy on the Desktop. For the cleaning and scanning programs we use, almost all are directed to be saved to the desktop.

Set Default Download Location in Browsers:

Chrome:
Open Chrome > Customize and control > Options > Under the Hood > Downloads > Change > Select Desktop > OK
(Don't check 'ask where to save each time….')

Firefox:
Open Firefox > Tools > Options > Main/General > Downloads Section > Save Files to > Browse > Navigate to and select Desktop > OK

Internet Explorer
Open IE > Gear icon > View Downloads > Options > Browse to and select Desktop > OK

There may be a slight difference in the path dependent on the browser version. There may also be a box to check to "Ask me the location each time". I do not advise checking that box.

=========================

Reboot

=========================

Now re-try the OTL step from my previous post, and post the logs generated.
i moved it from the temp folder and got it to run but now it freezes when it gets to StartMenu/Programs/Startup folder, i tried it 2 or 3 times to make sure
Hi HR2008,

OK, try this tool instead.

1. Farbar Recovery Scan Tool

Download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply
=========================

In your next post please provide the following:
  • FRST.txt
  • Additions.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-08-2013
Ran by [removed] (administrator) on 09-08-2013 17:22:49
Running from C:\Documents and Settings\[removed]\Desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation ) C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Just Develop It) C:\Program Files\MyPC Backup\BackupStack.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Conduit) C:\Program Files\SearchProtect\bin\CltMngSvc.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
(SingleClick Systems) C:\Program Files\Dell Network Assistant\hnm_svc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
( ) C:\WINDOWS\system32\lxdncoms.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
(Intel® Corporation) C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
(Dell Inc) C:\Program Files\Dell\QuickSet\quickset.exe
(CyberLink Corp.) C:\Program Files\Dell\MediaDirect\PCMService.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RealPlay.exe
(Sony Corporation) C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Conduit) C:\Documents and Settings\TEMP\Application Data\SearchProtect\bin\cltmng.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(DUELINGELECTRONS ) C:\Documents and Settings\TEMP\Desktop\YAEB_5000-might work.exe
(DUELINGELECTRONS ) C:\Documents and Settings\TEMP\Desktop\YAEB_5000-might work.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [851968 2007-06-03] (Synaptics, Inc.)
HKLM\…\Run: [IntelZeroConfig] - C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [823296 2007-07-25] (Intel Corporation)
HKLM\…\Run: [IntelWireless] - C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [974848 2007-07-25] (Intel Corporation)
HKLM\…\Run: [Dell QuickSet] - C:\Program Files\Dell\QuickSet\quickset.exe [1191936 2007-05-14] (Dell Inc)
HKLM\…\Run: [ECenter] - C:\Dell\E-Center\EULALauncher.exe [17920 2007-05-24] ( )
HKLM\…\Run: [PCMService] - C:\Program Files\Dell\MediaDirect\PCMService.exe [189736 2007-11-01] (CyberLink Corp.)
HKLM\…\Run: [RealTray] - C:\Program Files\Real\RealPlayer\RealPlay.exe [26112 2008-01-24] (RealNetworks, Inc.)
HKLM\…\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-10-15] (Adobe Systems Incorporated)
HKLM\…\Run: [Malwarebytes Anti-Malware (reboot)] - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [824232 2012-12-14] (Malwarebytes Corporation)
HKLM\…\Run: [ContentTransferWMDetector.exe] - C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe [423200 2008-07-11] (Sony Corporation)
HKLM\…\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM\…\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [947152 2013-01-27] (Microsoft Corporation)
HKLM\…\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\…\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM\…\Run: [SearchProtectAll] - C:\Program Files\SearchProtect\bin\cltmng.exe [2852640 2013-05-08] (Conduit)
HKCU\…\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation)
HKCU\…\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\…\Run: [SearchProtect] - C:\Documents and Settings\TEMP\Application Data\SearchProtect\bin\cltmng.exe [2852640 2013-05-08] (Conduit) <===== ATTENTION
HKU\GriffinM\…\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [ 2006-09-11] (Macrovision Corporation)
HKU\Guest\…\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [ 2006-09-11] (Macrovision Corporation)
HKU\Guest\…\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [ 2012-04-18] (Apple Inc.)
HKU\Rev. JMWynn\…\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [ 2006-09-11] (Macrovision Corporation)
HKU\Rev. JMWynn\…\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [ 2008-04-13] (Microsoft Corporation)
HKU\Rev. JMWynn\…\Run: [DW6] - "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" [x]
HKU\Rev. JMWynn\…\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2009-06-10] (Google Inc.)
HKU\Rev. JMWynn\…\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [x]
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
BootExecute:

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT3289663&…69-2499AF052F43
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.delta-search.com/?affID=119776&…006001DE04F0273
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a;=AgnUp…4257458&ir;=
URLSearchHook: InternetHelper3.1 Toolbar - {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files\InternetHelper3.1\prxtbInte.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM - {0A57EAB3-3E77-4935-93E1-C5293835CC0E} URL = http://www.seekeen.com/?prt=SEEKEEN124&…s={searchTerms}
SearchScopes: HKLM - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = http://www.ask.com/web?&o;=101881&l;…q={SEARCHTERMS}
SearchScopes: HKLM - {CF739809-1C6C-47C0-85B9-569DBB141420} URL = http://toolbar.ask.com/toolbarv/askRedirec…erms}&crm;=1
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerm…006001DE04F0273
SearchScopes: HKCU - {5CEDA225-9CDE-43F4-A1A2-D76CCEC3EDBF} URL = http://search.conduit.com/ResultsExt.aspx?…331725&UM;=2
BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: InternetHelper3.1 Toolbar - {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files\InternetHelper3.1\prxtbInte.dll (Conduit Ltd.)
BHO: GetSavin 5.0 - {3FA3BA27-0528-4D19-9348-C69282EFD922} - C:\Documents and Settings\TEMP\Local Settings\Application Data\getsavin\ie\getsavin_1374378001.dll ()
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
BHO: Define - {B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} - C:\Documents and Settings\TEMP\Local Settings\Application Data\DefineExt\temp.dat ()
BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
Toolbar: HKLM - InternetHelper3.1 Toolbar - {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files\InternetHelper3.1\prxtbInte.dll (Conduit Ltd.)
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Chessmaster%20Challenge/Images/stg_drm.ocx
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Chessmaster%20Challenge/Images/armhelper.ocx
Handler: ipp - No CLSID Value -
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254

FireFox:
========
FF ProfilePath: C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default
FF user.js: detected! => C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\user.js
FF Homepage: www.google.com
FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663&SearchSource;=2&CUI;=UN51329034426236514&UM;=2&q;=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=13 - C:\Program Files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\searchplugins\delta.xml
FF SearchPlugin: C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\searchplugins\internethelper31-customized-web-search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml
FF Extension: No Name - C:\Documents and Settings\TEMP\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: Babylon - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: Delta Toolbar - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: Funmoods.com - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: GetSavin - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\getsavin@jetpack
FF Extension: Define Ext - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: InternetHelper3.1 - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\{07cbf788-1359-421b-a4e3-5a8d041b90a3}
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: movie2kdownloader - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: Define Ext - C:\Program Files\Mozilla Firefox\extensions\[removed]
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\…\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\
FF HKLM\…\Firefox\Extensions: [{ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}] C:\WINDOWS\system32\5008
FF Extension: Java String Helper - C:\WINDOWS\system32\5008
FF HKCU\…\Firefox\Extensions: [{0F827075-B026-42F3-885D-98981EE7B1AE}] C:\Documents and Settings\All Users\Application Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
FF Extension: BrowserProtect - C:\Documents and Settings\All Users\Application Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension

Chrome:
=======
CHR Extension: (Define Ext) - C:\DOCUME~1\TEMP\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\gjkpcnacdgdlpfejlgflolpaigoicibh\1_0
CHR Extension: (Amazing Coupons) - C:\DOCUME~1\TEMP\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\mjildcbkilmkddbbpbjljljdmmlfeppl\5.0_0
CHR HKLM\…\Chrome\Extension: [blaofbhgbmeikidhlkmjhbkbfohpgekf] - C:\Program Files\Movie2KDownloader.com\Movie2KDownloader10.crx
CHR HKLM\…\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\DOCUME~1\TEMP\LOCALS~1\APPLIC~1\funmoods-speeddial_sf.crx
CHR HKLM\…\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Documents and Settings\TEMP\Application Data\BabSolution\CR\Delta.crx

========================== Services (Whitelisted) =================

R2 BackupStack; C:\Program Files\MyPC Backup\BackupStack.exe [32808 2013-07-01] (Just Develop It)
S4 BrowserProtect; C:\Documents and Settings\All Users\Application Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [2561488 2013-02-21] ()
R2 CltMngSvc; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [97056 2013-05-08] (Conduit)
R2 gupdate1c9e997644d890a; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-10] (Google Inc.)
R2 hnmsvc; C:\Program Files\Dell Network Assistant\hnm_svc.exe [112176 2007-05-25] (SingleClick Systems)
R2 lxdn_device; C:\WINDOWS\system32\lxdncoms.exe [589824 2007-11-28] ( )
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [20456 2013-01-27] (Microsoft Corporation)
R2 NwSapAgent; C:\Windows\System32\ipxsap.dll [66560 2004-08-04] (Microsoft Corporation)
R2 S24EventMonitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [987136 2007-07-25] (Intel Corporation )
R2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [700760 2009-02-18] (Trend Micro Inc.)
R2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-08-13] (SupportSoft, Inc.)
S2 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [333064 2008-02-18] (Trend Micro Inc.)
R2 WLANKEEPER; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [294912 2007-07-25] (Intel® Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [x]
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
S2 RoxLiveShare9; "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]
S3 WinDefend; %ProgramFiles%\Windows Defender\mpsvc.dll [x]

==================== Drivers (Whitelisted) ====================

R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [21393 2008-01-16] (Cisco Systems, Inc.)
R1 APPDRV; C:\Windows\SYSTEM32\DRIVERS\APPDRV.SYS [16128 2005-08-12] (Dell Inc)
R2 ASCTRM; C:\Windows\System32\Drivers\ASCTRM.sys [8552 2008-01-24] (Windows ® 2000 DDK provider)
R3 DXEC02; C:\Windows\System32\drivers\dxec02.sys [103168 2006-11-02] (Knowles Acoustics)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows ® Server 2003 DDK provider)
R3 HSFHWAZL; C:\Windows\System32\DRIVERS\HSFHWAZL.sys [209152 2007-04-23] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [989696 2007-04-23] (Conexant Systems, Inc.)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [32072 2012-06-14] ()
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\mbamswissarmy.sys [40776 2013-08-09] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [195296 2013-01-20] (Microsoft Corporation)
R3 NETw4x32; C:\Windows\System32\DRIVERS\NETw4x32.sys [2211456 2007-08-12] (Intel Corporation)
R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-13] (Microsoft Corporation)
R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2004-08-04] (Microsoft Corporation)
R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2004-08-04] (Microsoft Corporation)
R2 Packet; C:\Windows\System32\DRIVERS\packet.sys [12672 2006-12-18] (SingleClick Systems)
R2 s24trans; C:\Windows\System32\DRIVERS\s24trans.sys [12416 2007-05-29] (Intel Corporation)
S3 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [447024 2008-01-16] (Symantec Corporation)
R3 STHDA; C:\Windows\System32\drivers\sthda.sys [1222840 2007-06-06] (SigmaTel, Inc.)
S2 tmactmon; C:\WINDOWS\system32\drivers\tmactmon.sys [52496 2008-02-18] (Trend Micro Inc.)
R2 tmcomm; C:\WINDOWS\system32\drivers\tmcomm.sys [138384 2008-02-18] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [65936 2008-02-18] (Trend Micro Inc.)
S2 tmxpflt; C:\Windows\System32\DRIVERS\tmxpflt.sys [205328 2008-11-26] (Trend Micro Inc.)
R2 vsapint; C:\Windows\System32\DRIVERS\vsapint.sys [1195384 2008-11-26] (Trend Micro Inc.)
S3 catchme; \??\C:\DOCUME~1\TEMP\LOCALS~1\Temp\catchme.sys [x]
S3 RimUsb; System32\Drivers\RimUsb.sys [x]
S1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [x]
S3 SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\ipsdefs\20080215.001\SymIDSCo.sys [x]
U3 TlntSvr;
S3 wanatw; system32\DRIVERS\wanatw4.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-09 17:17 - 2013-08-09 17:17 - 01230570 _____ (Farbar) C:\Documents and Settings\TEMP\Desktop\FRST.exe
2013-08-09 17:17 - 2013-08-09 17:17 - 01230570 _____ (Farbar) C:\Documents and Settings\TEMP\Desktop\FRST.exe
2013-08-08 16:00 - 2013-08-08 16:00 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(2).exe
2013-08-08 16:00 - 2013-08-08 16:00 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(2).exe
2013-08-08 15:51 - 2013-08-08 15:51 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(1).exe
2013-08-08 15:51 - 2013-08-08 15:51 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(1).exe
2013-08-07 20:03 - 2013-08-07 20:03 - 00000526 _____ C:\Documents and Settings\TEMP\Desktop\MBR.zip
2013-08-07 20:03 - 2013-08-07 20:03 - 00000526 _____ C:\Documents and Settings\TEMP\Desktop\MBR.zip
2013-08-07 20:02 - 2013-08-07 20:02 - 00002207 _____ C:\Documents and Settings\TEMP\Desktop\aswMBR.txt
2013-08-07 20:02 - 2013-08-07 20:02 - 00002207 _____ C:\Documents and Settings\TEMP\Desktop\aswMBR.txt
2013-08-07 20:02 - 2013-08-07 20:02 - 00000512 _____ C:\Documents and Settings\TEMP\Desktop\MBR.dat
2013-08-07 20:02 - 2013-08-07 20:02 - 00000512 _____ C:\Documents and Settings\TEMP\Desktop\MBR.dat
2013-08-07 19:12 - 2013-08-07 20:58 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-07 18:59 - 2013-08-07 18:59 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\OTL.exe
2013-08-07 18:57 - 2013-08-07 19:25 - 04745728 _____ (AVAST Software) C:\Documents and Settings\TEMP\Desktop\aswMBR.exe
2013-08-07 18:57 - 2013-08-07 19:25 - 04745728 _____ (AVAST Software) C:\Documents and Settings\TEMP\Desktop\aswMBR.exe
2013-08-07 18:57 - 2013-08-07 18:57 - 00891098 _____ C:\Documents and Settings\TEMP\Desktop\SecurityCheck.exe
2013-08-07 18:57 - 2013-08-07 18:57 - 00891098 _____ C:\Documents and Settings\TEMP\Desktop\SecurityCheck.exe
2013-08-06 21:04 - 2013-08-06 21:04 - 00011903 _____ C:\Documents and Settings\TEMP\My Documents\hijackthis2013
2013-08-06 21:04 - 2013-08-06 21:04 - 00011903 _____ C:\Documents and Settings\TEMP\My Documents\hijackthis2013
2013-08-03 22:56 - 2013-08-03 22:56 - 00090112 _____ C:\WINDOWS\Minidump\Mini080313-01.dmp
2013-07-27 10:29 - 2013-07-27 10:29 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\InternetHelper3.1
2013-07-26 12:17 - 2013-07-30 22:04 - 00000000 ____D C:\Program Files\MyPC Backup
2013-07-26 12:17 - 2013-07-26 12:17 - 00000000 ____D C:\Documents and Settings\TEMP\Start Menu\Programs\MyPC Backup
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Program Files\InternetHelper3.1
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Program Files\Conduit
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\InternetHelper3.1
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\Conduit
2013-07-26 12:14 - 2013-07-26 12:14 - 00000000 ____D C:\Program Files\SearchProtect
2013-07-26 12:14 - 2013-05-08 01:10 - 00770384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr100.dll
2013-07-26 12:14 - 2013-05-08 01:10 - 00421200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp100.dll
2013-07-26 12:13 - 2013-07-26 12:14 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\SearchProtect
2013-07-26 12:13 - 2013-07-26 12:14 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\SearchProtect
2013-07-26 12:12 - 2013-07-26 12:16 - 00000009 _____ C:\END
2013-07-20 22:47 - 2013-07-20 22:47 - 00000182 _____ C:\drwtsn32.log
2013-07-20 22:44 - 2013-07-20 22:44 - 00000000 ____D C:\Documents and Settings\TEMP\Start Menu\Programs\Define Ext
2013-07-20 22:43 - 2013-07-20 22:44 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\DefineExt
2013-07-20 22:42 - 2013-07-20 22:42 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\getsavin
2013-07-12 19:47 - 2013-07-12 19:47 - 00068112 _____ C:\Documents and Settings\TEMP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2013-07-10 02:33 - 2013-07-10 02:33 - 00259840 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-10 02:17 - 2013-07-10 02:17 - 00021647 _____ C:\WINDOWS\KB2834904.log
2013-07-10 02:17 - 2013-07-10 02:17 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-10 02:16 - 2013-07-10 02:16 - 00021422 _____ C:\WINDOWS\KB2834886.log
2013-07-10 02:16 - 2013-07-10 02:16 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-10 02:15 - 2013-07-10 02:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-10 02:15 - 2013-07-10 02:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-10 02:06 - 2013-07-10 02:17 - 00030913 _____ C:\WINDOWS\FaxSetup.log
2013-07-10 02:06 - 2013-07-10 02:17 - 00014780 _____ C:\WINDOWS\ocgen.log
2013-07-10 02:06 - 2013-07-10 02:17 - 00011795 _____ C:\WINDOWS\tsoc.log
2013-07-10 02:06 - 2013-07-10 02:17 - 00010075 _____ C:\WINDOWS\comsetup.log
2013-07-10 02:06 - 2013-07-10 02:17 - 00006199 _____ C:\WINDOWS\ntdtcsetup.log
2013-07-10 02:06 - 2013-07-10 02:17 - 00004872 _____ C:\WINDOWS\iis6.log
2013-07-10 02:06 - 2013-07-10 02:17 - 00001710 _____ C:\WINDOWS\ocmsn.log
2013-07-10 02:06 - 2013-07-10 02:17 - 00001545 _____ C:\WINDOWS\msgsocm.log
2013-07-10 02:06 - 2013-07-10 02:17 - 00001374 _____ C:\WINDOWS\imsins.log
2013-07-10 02:06 - 2013-07-10 02:16 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-07-10 02:06 - 2013-07-10 02:06 - 00002763 _____ C:\WINDOWS\updspapi.log
2013-07-10 02:06 - 2013-07-10 02:06 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-07-10 02:06 - 2013-07-10 02:06 - 00000000 _____ C:\WINDOWS\setupact.log
2013-07-10 02:04 - 2013-07-10 02:06 - 00023951 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-10 00:48 - 2013-07-10 02:16 - 00039137 _____ C:\WINDOWS\KB2850851.log
2013-07-10 00:48 - 2013-07-10 02:15 - 00038218 _____ C:\WINDOWS\KB2845187.log

==================== One Month Modified Files and Folders =======

2013-08-09 17:20 - 2013-08-09 17:20 - 00000000 ____D C:\FRST
2013-08-09 17:18 - 2012-08-07 20:20 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\Skype
2013-08-09 17:18 - 2012-08-07 20:20 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\Skype
2013-08-09 17:17 - 2013-08-09 17:17 - 01230570 _____ (Farbar) C:\Documents and Settings\TEMP\Desktop\FRST.exe
2013-08-09 17:17 - 2013-08-09 17:17 - 01230570 _____ (Farbar) C:\Documents and Settings\TEMP\Desktop\FRST.exe
2013-08-09 16:50 - 2009-07-04 00:48 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-09 16:37 - 2012-07-06 02:18 - 01917127 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-09 16:31 - 2012-10-10 10:29 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-08-09 15:01 - 2013-03-07 11:22 - 00000384 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-08-09 14:54 - 2012-10-16 23:59 - 01502643 _____ C:\Documents and Settings\TEMP\Desktop\WarReport.swf
2013-08-09 14:54 - 2012-10-16 23:59 - 01502643 _____ C:\Documents and Settings\TEMP\Desktop\WarReport.swf
2013-08-09 14:53 - 2013-07-07 20:01 - 00010454 _____ C:\WINDOWS\setupapi.log
2013-08-09 14:51 - 2013-01-30 16:16 - 00040776 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2013-08-09 14:51 - 2004-08-10 14:09 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-08-09 14:51 - 2004-08-10 14:08 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-09 14:51 - 2004-08-10 13:59 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-08-09 14:51 - 2004-08-10 13:59 - 00000048 _____ C:\WINDOWS\wiaservc.log
2013-08-09 14:50 - 2012-12-12 11:22 - 00032372 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-09 14:50 - 2011-01-26 11:12 - 00000178 ___SH C:\Documents and Settings\TEMP\ntuser.ini
2013-08-09 14:50 - 2011-01-26 11:12 - 00000178 ___SH C:\Documents and Settings\TEMP\ntuser.ini
2013-08-09 11:14 - 2012-12-22 12:14 - 00000412 _____ C:\WINDOWS\Tasks\At1.job
2013-08-09 03:11 - 2012-09-06 23:24 - 00000298 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2435779118-4229668356-2006412331-1006.job
2013-08-08 20:50 - 2009-07-04 00:48 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-08 16:00 - 2013-08-08 16:00 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(2).exe
2013-08-08 16:00 - 2013-08-08 16:00 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(2).exe
2013-08-08 15:51 - 2013-08-08 15:51 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(1).exe
2013-08-08 15:51 - 2013-08-08 15:51 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(1).exe
2013-08-07 22:15 - 2013-03-07 08:50 - 00000000 ___RD C:\Program Files\Skype
2013-08-07 22:15 - 2012-08-07 19:20 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2013-08-07 20:58 - 2013-08-07 19:12 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-07 20:57 - 2012-05-28 15:53 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-07 20:03 - 2013-08-07 20:03 - 00000526 _____ C:\Documents and Settings\TEMP\Desktop\MBR.zip
2013-08-07 20:03 - 2013-08-07 20:03 - 00000526 _____ C:\Documents and Settings\TEMP\Desktop\MBR.zip
2013-08-07 20:02 - 2013-08-07 20:02 - 00002207 _____ C:\Documents and Settings\TEMP\Desktop\aswMBR.txt
2013-08-07 20:02 - 2013-08-07 20:02 - 00002207 _____ C:\Documents and Settings\TEMP\Desktop\aswMBR.txt
2013-08-07 20:02 - 2013-08-07 20:02 - 00000512 _____ C:\Documents and Settings\TEMP\Desktop\MBR.dat
2013-08-07 20:02 - 2013-08-07 20:02 - 00000512 _____ C:\Documents and Settings\TEMP\Desktop\MBR.dat
2013-08-07 19:25 - 2013-08-07 18:57 - 04745728 _____ (AVAST Software) C:\Documents and Settings\TEMP\Desktop\aswMBR.exe
2013-08-07 19:25 - 2013-08-07 18:57 - 04745728 _____ (AVAST Software) C:\Documents and Settings\TEMP\Desktop\aswMBR.exe
2013-08-07 18:59 - 2013-08-07 18:59 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\OTL.exe
2013-08-07 18:57 - 2013-08-07 18:57 - 00891098 _____ C:\Documents and Settings\TEMP\Desktop\SecurityCheck.exe
2013-08-07 18:57 - 2013-08-07 18:57 - 00891098 _____ C:\Documents and Settings\TEMP\Desktop\SecurityCheck.exe
2013-08-06 21:04 - 2013-08-06 21:04 - 00011903 _____ C:\Documents and Settings\TEMP\My Documents\hijackthis2013
2013-08-06 21:04 - 2013-08-06 21:04 - 00011903 _____ C:\Documents and Settings\TEMP\My Documents\hijackthis2013
2013-08-04 22:11 - 2012-10-14 11:43 - 00048128 _____ C:\Documents and Settings\TEMP\My Documents\goals for Vulcain.wps
2013-08-04 22:11 - 2012-10-14 11:43 - 00048128 _____ C:\Documents and Settings\TEMP\My Documents\goals for Vulcain.wps
2013-08-03 22:56 - 2013-08-03 22:56 - 00090112 _____ C:\WINDOWS\Minidump\Mini080313-01.dmp
2013-08-03 22:56 - 2008-02-02 20:15 - 00000000 ____D C:\WINDOWS\Minidump
2013-08-03 22:56 - 2004-08-10 13:51 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-07-30 22:25 - 2012-05-03 09:54 - 00017408 _____ C:\Documents and Settings\TEMP\My Documents\goals for chevelle.wps
2013-07-30 22:25 - 2012-05-03 09:54 - 00017408 _____ C:\Documents and Settings\TEMP\My Documents\goals for chevelle.wps
2013-07-30 22:04 - 2013-07-26 12:17 - 00000000 ____D C:\Program Files\MyPC Backup
2013-07-30 22:04 - 2012-04-17 16:25 - 00068112 _____ C:\Documents and Settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2013-07-27 10:29 - 2013-07-27 10:29 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\InternetHelper3.1
2013-07-27 10:29 - 2012-05-07 09:36 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2013-07-26 12:17 - 2013-07-26 12:17 - 00000000 ____D C:\Documents and Settings\TEMP\Start Menu\Programs\MyPC Backup
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Program Files\InternetHelper3.1
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Program Files\Conduit
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\InternetHelper3.1
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\Conduit
2013-07-26 12:16 - 2013-07-26 12:12 - 00000009 _____ C:\END
2013-07-26 12:14 - 2013-07-26 12:14 - 00000000 ____D C:\Program Files\SearchProtect
2013-07-26 12:14 - 2013-07-26 12:13 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\SearchProtect
2013-07-26 12:14 - 2013-07-26 12:13 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\SearchProtect
2013-07-26 12:12 - 2008-01-16 19:19 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Adobe
2013-07-21 16:24 - 2009-11-19 15:56 - 00000000 ____D C:\Documents and Settings\All Users\lx_Cats
2013-07-20 22:47 - 2013-07-20 22:47 - 00000182 _____ C:\drwtsn32.log
2013-07-20 22:44 - 2013-07-20 22:44 - 00000000 ____D C:\Documents and Settings\TEMP\Start Menu\Programs\Define Ext
2013-07-20 22:44 - 2013-07-20 22:43 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\DefineExt
2013-07-20 22:42 - 2013-07-20 22:42 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\getsavin
2013-07-16 18:57 - 2011-01-26 11:12 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\Adobe
2013-07-12 19:47 - 2013-07-12 19:47 - 00068112 _____ C:\Documents and Settings\TEMP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2013-07-10 02:33 - 2013-07-10 02:33 - 00259840 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-10 02:33 - 2008-01-16 19:18 - 00000000 ____D C:\Program Files\Google
2013-07-10 02:17 - 2013-07-10 02:17 - 00021647 _____ C:\WINDOWS\KB2834904.log
2013-07-10 02:17 - 2013-07-10 02:17 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-10 02:17 - 2013-07-10 02:06 - 00030913 _____ C:\WINDOWS\FaxSetup.log
2013-07-10 02:17 - 2013-07-10 02:06 - 00014780 _____ C:\WINDOWS\ocgen.log
2013-07-10 02:17 - 2013-07-10 02:06 - 00011795 _____ C:\WINDOWS\tsoc.log
2013-07-10 02:17 - 2013-07-10 02:06 - 00010075 _____ C:\WINDOWS\comsetup.log
2013-07-10 02:17 - 2013-07-10 02:06 - 00006199 _____ C:\WINDOWS\ntdtcsetup.log
2013-07-10 02:17 - 2013-07-10 02:06 - 00004872 _____ C:\WINDOWS\iis6.log
2013-07-10 02:17 - 2013-07-10 02:06 - 00001710 _____ C:\WINDOWS\ocmsn.log
2013-07-10 02:17 - 2013-07-10 02:06 - 00001545 _____ C:\WINDOWS\msgsocm.log
2013-07-10 02:17 - 2013-07-10 02:06 - 00001374 _____ C:\WINDOWS\imsins.log
2013-07-10 02:16 - 2013-07-10 02:16 - 00021422 _____ C:\WINDOWS\KB2834886.log
2013-07-10 02:16 - 2013-07-10 02:16 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-10 02:16 - 2013-07-10 02:06 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-07-10 02:16 - 2013-07-10 00:48 - 00039137 _____ C:\WINDOWS\KB2850851.log
2013-07-10 02:15 - 2013-07-10 02:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-10 02:15 - 2013-07-10 02:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-10 02:15 - 2013-07-10 00:48 - 00038218 _____ C:\WINDOWS\KB2845187.log
2013-07-10 02:14 - 2004-08-10 13:57 - 00504786 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-07-10 02:07 - 2008-10-20 17:21 - 75699896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-07-10 02:06 - 2013-07-10 02:06 - 00002763 _____ C:\WINDOWS\updspapi.log
2013-07-10 02:06 - 2013-07-10 02:06 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-07-10 02:06 - 2013-07-10 02:06 - 00000000 _____ C:\WINDOWS\setupact.log
2013-07-10 02:06 - 2013-07-10 02:04 - 00023951 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-10 02:06 - 2012-04-17 10:03 - 00000000 ____D C:\WINDOWS\ie8updates
2013-07-10 02:00 - 2009-08-15 03:07 - 00000000 ____D C:\WINDOWS\system32\XPSViewer

Files to move or delete:
====================
C:\Documents and Settings\TEMP\Application Data\SearchProtect\bin\cltmng.exe
C:\Windows\Tasks\At1.job

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================



Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-08-2013
Ran by [removed] at 2013-08-09 17:24:05
Running from C:\Documents and Settings\[removed]\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Adobe Flash Player 11 ActiveX (Version: 11.4.402.265)
Adobe Flash Player 11 Plugin (Version: 11.7.700.224)
Adobe Reader 8.1.3 (Version: 8.1.3)
Adobe Shockwave Player 11.5 (Version: 11.5.1.601)
America Online (Choose which version to remove)
Apple Application Support (Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
Bonjour (Version: 3.0.0.10)
Broadcom Management Programs (Version: 10.15.03)
Browser Address Error Redirector (Version: 1.00.0000)
BrowserProtect
CCleaner (Version: 4.03)
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
Conexant HDA D330 MDC V.92 Modem
Content Transfer (Version: 1.0.0.07110)
Corel WordPerfect Suite 8
Define Ext (HKCU Version: 8)
Dell Network Assistant (Version: 3.0.0.0)
Dell Support Center (Support Software) (Version: 2.2.09085)
Dell Touchpad (Version: 9.1.18.6)
Delta Chrome Toolbar
Delta toolbar (Version: 1.8.10.0)
Digital Line Detect (Version: 1.21)
ffdshow v1.2.4422 [2012-04-09] (Version: 1.2.4422.0)
FlightGear v2.0.0
GetSavin (Version: 1.1374378017)
Google Chrome Packages
Google Earth (Version: 7.0.3.8542)
Google Update Helper (Version: 1.3.21.153)
Google Updater (Version: 2.4.1601.7122)
HDVidCodec (Version: 2.1 Build 26473)
HiJackThis (Version: 1.0.0)
HijackThis 2.0.2 (Version: 2.0.2)
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software (Version: 11.01.0000)
IntelliSonic Speech Enhancement (Version: 2.1.37)
InternetHelper3.1 Toolbar (Version: 6.14.0.28)
iTunes (Version: 11.0.4.4)
J2SE Runtime Environment 5.0 Update 6 (Version: 1.5.0.60)
Java 7 Update 21 (Version: 7.0.210)
Java Auto Updater (Version: 2.1.9.5)
Java™ 6 Update 32 (Version: 6.0.320)
Malwarebytes Anti-Malware version 1.70.0.1100 (Version: 1.70.0.1100)
mCore (Version: 9.24.0000)
mDrWiFi (Version: 9.24.0000)
MediaDirect (Version: 3.5)
mHlpDell (Version: 9.24.0000)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2833941)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000)
Microsoft Security Client (Version: 4.2.0223.1)
Microsoft Security Essentials (Version: 4.2.223.1)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Works (Version: 08.05.0818)
mIWA (Version: 9.24.0000)
mLogView (Version: 9.24.0000)
mMHouse (Version: 9.24.0000)
MobileMe Control Panel (Version: 3.1.8.0)
Modem Diagnostic Tool (Version: 1.0.20.0)
Monster Trucks Nitro Demo
Mozilla Firefox 23.0 (x86 en-US) (Version: 23.0)
Mozilla Maintenance Service (Version: 23.0)
mPfMgr (Version: 9.24.0000)
mPfWiz (Version: 9.24.0000)
mProSafe (Version: 9.00.0000)
mSCfg (Version: 9.24.0000)
mSSO (Version: 9.24.0000)
MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 6.0 Parser (KB933579) (Version: 6.10.1200.0)
mWlsSafe (Version: 9.00.0000)
mWMI (Version: 9.24.0000)
MyPC Backup (Version: )
mZConfig (Version: 9.24.0000)
NetWaiting (Version: 2.5.44)
OpenAL
OpenOffice.org 3.4.1 (Version: 3.41.9593)
OutlookAddinSetup (Version: 1.0.0)
QuickSet (Version: 8.1.12)
QuickTime (Version: 7.72.80.56)
RealPlayer Basic
Safari (Version: 5.34.57.2)
Search Protect by conduit (Version: 1.5.0.71)
SearchAssist
Skype™ 6.6 (Version: 6.6.106)
Sonic Activation Module (Version: 1.0)
SPBBC 32bit (Version: 4.1.0.15)
Startup Manager 2.4.2 (Version: 2.4.2)
Trend Micro AntiVirus (Version: 16.10)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Windows Internet Explorer 7 (KB976749) (Version: 1)
Update for Windows Internet Explorer 7 (KB980182) (Version: 1)
Update for Windows Internet Explorer 8 (KB2598845) (Version: 1)
WebFldrs XP (Version: 9.50.7523)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7 (Version: 20070813.185237)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3 (Version: 20080414.031525)


==================== Restore Points =========================

13-06-2013 15:27:31 System Checkpoint
13-06-2013 15:35:06 Software Distribution Service 3.0
14-06-2013 15:36:20 Software Distribution Service 3.0
15-06-2013 15:34:56 Software Distribution Service 3.0
16-06-2013 06:06:09 Software Distribution Service 3.0
16-06-2013 15:36:19 Software Distribution Service 3.0
17-06-2013 15:34:59 Software Distribution Service 3.0
18-06-2013 15:34:54 Software Distribution Service 3.0
19-06-2013 15:35:05 Software Distribution Service 3.0
20-06-2013 15:35:01 Software Distribution Service 3.0
21-06-2013 15:35:31 Software Distribution Service 3.0
22-06-2013 01:30:57 Installed iTunes
23-06-2013 00:58:32 Software Distribution Service 3.0
23-06-2013 05:46:07 Software Distribution Service 3.0
24-06-2013 00:58:33 Software Distribution Service 3.0
25-06-2013 00:58:03 Software Distribution Service 3.0
26-06-2013 00:58:10 Software Distribution Service 3.0
27-06-2013 00:58:28 Software Distribution Service 3.0
28-06-2013 00:57:57 Software Distribution Service 3.0
29-06-2013 00:58:32 Software Distribution Service 3.0
30-06-2013 00:58:47 Software Distribution Service 3.0
30-06-2013 05:45:43 Software Distribution Service 3.0
01-07-2013 00:58:22 Software Distribution Service 3.0
02-07-2013 00:58:11 Software Distribution Service 3.0
03-07-2013 00:58:30 Software Distribution Service 3.0
04-07-2013 00:58:34 Software Distribution Service 3.0
05-07-2013 00:58:59 Software Distribution Service 3.0
06-07-2013 00:58:32 Software Distribution Service 3.0
07-07-2013 00:59:13 Software Distribution Service 3.0
07-07-2013 01:04:44 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
07-07-2013 05:46:17 Software Distribution Service 3.0
08-07-2013 00:58:38 Software Distribution Service 3.0
09-07-2013 00:58:47 Software Distribution Service 3.0
10-07-2013 00:58:27 Software Distribution Service 3.0
10-07-2013 07:00:19 Software Distribution Service 3.0
11-07-2013 07:38:24 System Checkpoint
11-07-2013 07:45:50 Software Distribution Service 3.0
12-07-2013 07:45:51 Software Distribution Service 3.0
13-07-2013 07:46:05 Software Distribution Service 3.0
14-07-2013 06:04:48 Software Distribution Service 3.0
14-07-2013 07:46:08 Software Distribution Service 3.0
15-07-2013 07:47:02 Software Distribution Service 3.0
17-07-2013 00:07:03 Software Distribution Service 3.0
18-07-2013 00:03:36 Software Distribution Service 3.0
19-07-2013 00:05:38 Software Distribution Service 3.0
20-07-2013 00:04:52 Software Distribution Service 3.0
21-07-2013 00:04:19 Software Distribution Service 3.0
21-07-2013 06:02:36 Software Distribution Service 3.0
22-07-2013 04:00:04 Software Distribution Service 3.0
23-07-2013 03:59:35 Software Distribution Service 3.0
24-07-2013 03:59:34 Software Distribution Service 3.0
25-07-2013 03:58:46 Software Distribution Service 3.0
26-07-2013 03:59:36 Software Distribution Service 3.0
27-07-2013 04:07:22 Software Distribution Service 3.0
31-07-2013 03:16:21 Software Distribution Service 3.0
04-08-2013 04:09:04 Software Distribution Service 3.0
04-08-2013 05:45:02 Software Distribution Service 3.0
05-08-2013 05:59:47 System Checkpoint
06-08-2013 03:53:19 Software Distribution Service 3.0
07-08-2013 05:02:55 System Checkpoint
07-08-2013 23:03:52 Software Distribution Service 3.0
08-08-2013 21:50:22 System Checkpoint
09-08-2013 20:03:02 Software Distribution Service 3.0
09-08-2013 20:11:32 System Checkpoint

==================== Hosts content: ==========================

2004-08-10 13:51 - 2012-07-06 09:47 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\At1.job => è6ÛöM„n’Oª-ËF&<
s !Ý 9C:\DOCUME~1\TEMP\APPLIC~1\Funmoods\UPDATE~1\UPDATE~1.EXE/CheckSYSTEMCreated by NetScheduleJobAdd.0Ü  Øó˜¥&ýLfÀÂìߝ! ÎPR d0ýzâ¾d{¾ABy< %±éºÐ9—2»Òþvþx3ŠæŠ2ô>ýÝÖ
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: C:\WINDOWS\Tasks\NSSstub.job => C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-2435779118-4229668356-2006412331-1006.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2435779118-4229668356-2006412331-1006.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/09/2013 02:51:31 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Service Manager returned a fatal error (0x80004002). Will stop service

Error: (08/08/2013 04:22:46 PM) (Source: Application Hang) (User: )
Description: Fault bucket -1117197148.

Error: (08/08/2013 04:22:39 PM) (Source: Application Hang) (User: )
Description: Hanging application OTL.exe, version 3.2.69.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (08/08/2013 04:20:29 PM) (Source: Application Hang) (User: )
Description: Fault bucket -1117197148.

Error: (08/08/2013 04:14:48 PM) (Source: Application Hang) (User: )
Description: Hanging application OTL.exe, version 3.2.69.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (08/08/2013 03:56:20 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile, P4 [removed], P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P6 unspecified, P7 unspecified, P8 NIL, P9 mptelemetry0, P10 mptelemetry1.

Error: (08/08/2013 03:54:41 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Service Manager returned a fatal error (0x80004002). Will stop service

Error: (08/08/2013 03:41:19 PM) (Source: Application Error) (User: )
Description: Faulting application yaeb_5000-might work.exe, version 0.0.0.1, faulting module yaeb_5000-might work.exe, version 0.0.0.1, fault address 0x007658ac.
Processing media-specific event for [yaeb_5000-might work.exe!ws!]

Error: (08/08/2013 03:39:48 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Service Manager returned a fatal error (0x80004002). Will stop service

Error: (08/06/2013 08:44:23 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Service Manager returned a fatal error (0x80004002). Will stop service


System errors:
=============
Error: (08/09/2013 02:52:02 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SASKUTIL

Error: (08/09/2013 02:51:52 PM) (Source: Service Control Manager) (User: )
Description: The Trend Micro Unauthorized Change Prevention Service service depends on the tmactmon service which failed to start because of the following error:
%%1075

Error: (08/09/2013 02:51:52 PM) (Source: Service Control Manager) (User: )
Description: The tmactmon service depends on the following nonexistent service: tmevtmgr

Error: (08/09/2013 02:51:52 PM) (Source: Service Control Manager) (User: )
Description: The tmxpflt service depends on the following nonexistent service: tmpreflt

Error: (08/09/2013 02:49:55 PM) (Source: 0) (User: )
Description: 0xC000009Arep.datHarddiskVolume2

Error: (08/08/2013 03:55:18 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SASKUTIL

Error: (08/08/2013 03:55:07 PM) (Source: Service Control Manager) (User: )
Description: The Trend Micro Unauthorized Change Prevention Service service depends on the tmactmon service which failed to start because of the following error:
%%1075

Error: (08/08/2013 03:55:07 PM) (Source: Service Control Manager) (User: )
Description: The tmactmon service depends on the following nonexistent service: tmevtmgr

Error: (08/08/2013 03:55:07 PM) (Source: Service Control Manager) (User: )
Description: The tmxpflt service depends on the following nonexistent service: tmpreflt

Error: (08/08/2013 03:40:45 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SASKUTIL


Microsoft Office Sessions:
=========================
Error: (08/09/2013 02:51:31 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Service Manager returned a fatal error (0x80004002). Will stop service

Error: (08/08/2013 04:22:46 PM) (Source: Application Hang)(User: )
Description: -1117197148

Error: (08/08/2013 04:22:39 PM) (Source: Application Hang)(User: )
Description: OTL.exe3.2.69.0hungapp0.0.0.000000000

Error: (08/08/2013 04:20:29 PM) (Source: Application Hang)(User: )
Description: -1117197148

Error: (08/08/2013 04:14:48 PM) (Source: Application Hang)(User: )
Description: OTL.exe3.2.69.0hungapp0.0.0.000000000

Error: (08/08/2013 03:56:20 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry2152759308unspecifiedscanfile4.2.223.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)unspecifiedunspecifiedNILNILNIL

Error: (08/08/2013 03:54:41 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Service Manager returned a fatal error (0x80004002). Will stop service

Error: (08/08/2013 03:41:19 PM) (Source: Application Error)(User: )
Description: yaeb_5000-might work.exe0.0.0.1yaeb_5000-might work.exe0.0.0.1007658ac

Error: (08/08/2013 03:39:48 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Service Manager returned a fatal error (0x80004002). Will stop service

Error: (08/06/2013 08:44:23 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Service Manager returned a fatal error (0x80004002). Will stop service


==================== Memory info ===========================

Percentage of memory in use: 63%
Total physical RAM: 2038.11 MB
Available physical RAM: 744.38 MB
Total Pagefile: 4941.27 MB
Available Pagefile: 3655.84 MB
Total Virtual: 2047.88 MB
Available Virtual: 1950.42 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:71.95 GB) (Free:16.03 GB) NTFS ==>[Drive with boot components (Windows XP)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 75 GB) (Disk ID: D0F4738C)
Partition 1: (Not Active) - (Size=78 MB) - (Type=DE)
Partition 2: (Active) - (Size=72 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=2 GB) - (Type=OF Extended)

==================== End Of Log ============================
Hi HR2008,

[external image: Posted Image] Uninstall via Add/Remove Programs

Click Start > Control Panel > Add Remove Programs. Locate and select the following that are present on the list and click the Remove button:
  • BrowserProtect
  • Delta Chrome Toolbar
  • Delta toolbar (Version: 1.8.10.0)
  • GetSavin (Version: 1.1374378017)
  • Search Protect by conduit (Version: 1.5.0.71)
  • SearchAssist
=========================

[external image: Posted Image] FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt

(Conduit) C:\Program Files\SearchProtect\bin\CltMngSvc.exe
(Conduit) C:\Documents and Settings\TEMP\Application Data\SearchProtect\bin\cltmng.exe
HKLM\…\Run: [SearchProtectAll] - C:\Program Files\SearchProtect\bin\cltmng.exe [2852640 2013-05-08] (Conduit)
HKCU\…\Run: [SearchProtect] - C:\Documents and Settings\TEMP\Application Data\SearchProtect\bin\cltmng.exe [2852640 2013-05-08] (Conduit) <===== ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT3289663&…69-2499AF052F43
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.delta-search.com/?affID=119776&…006001DE04F0273
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=AgnUp…4257458&ir=
URLSearchHook: InternetHelper3.1 Toolbar - {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files\InternetHelper3.1\prxtbInte.dll (Conduit Ltd.)
SearchScopes: HKLM - {0A57EAB3-3E77-4935-93E1-C5293835CC0E} URL = http://www.seekeen.com/?prt=SEEKEEN124&…s={searchTerms}
SearchScopes: HKLM - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
SearchScopes: HKLM - {CF739809-1C6C-47C0-85B9-569DBB141420} URL = http://toolbar.ask.com/toolbarv/askRedirec…erms}&crm=1
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerm…006001DE04F0273
SearchScopes: HKCU - {5CEDA225-9CDE-43F4-A1A2-D76CCEC3EDBF} URL = http://search.conduit.com/ResultsExt.aspx?…331725&UM=2
BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: InternetHelper3.1 Toolbar - {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files\InternetHelper3.1\prxtbInte.dll (Conduit Ltd.)
BHO: GetSavin 5.0 - {3FA3BA27-0528-4D19-9348-C69282EFD922} - C:\Documents and Settings\TEMP\Local Settings\Application Data\getsavin\ie\getsavin_1374378001.dll ()
BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
Toolbar: HKLM - InternetHelper3.1 Toolbar - {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files\InternetHelper3.1\prxtbInte.dll (Conduit Ltd.)
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663&SearchSource=2&CUI=UN51329034426236514&UM=2&q=
FF SearchPlugin: C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\searchplugins\delta.xml
FF SearchPlugin: C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\searchplugins\internethelper31-customized-web-search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml
FF Extension: No Name - C:\Documents and Settings\TEMP\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: Babylon - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: Delta Toolbar - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: Funmoods.com - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: GetSavin - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\getsavin@jetpack
FF Extension: Define Ext - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed]
FF Extension: InternetHelper3.1 - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\{07cbf788-1359-421b-a4e3-5a8d041b90a3}
FF Extension: Define Ext - C:\Program Files\Mozilla Firefox\extensions\[removed]
CHR HKLM\…\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\DOCUME~1\TEMP\LOCALS~1\APPLIC~1\funmoods-speeddial_sf.crx
CHR HKLM\…\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Documents and Settings\TEMP\Application Data\BabSolution\CR\Delta.crx
S4 BrowserProtect; C:\Documents and Settings\All Users\Application Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [2561488 2013-02-21] ()
R2 CltMngSvc; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [97056 2013-05-08] (Conduit)
2013-07-27 10:29 - 2013-07-27 10:29 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\InternetHelper3.1
2013-07-26 12:17 - 2013-07-30 22:04 - 00000000 ____D C:\Program Files\MyPC Backup
2013-07-26 12:17 - 2013-07-26 12:17 - 00000000 ____D C:\Documents and Settings\TEMP\Start Menu\Programs\MyPC Backup
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Program Files\InternetHelper3.1
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Program Files\Conduit
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\InternetHelper3.1
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\Conduit
2013-07-26 12:14 - 2013-07-26 12:14 - 00000000 ____D C:\Program Files\SearchProtect
2013-07-26 12:13 - 2013-07-26 12:14 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\SearchProtect
2013-07-26 12:13 - 2013-07-26 12:14 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\SearchProtect
2013-07-27 10:29 - 2013-07-27 10:29 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\InternetHelper3.1
2013-07-26 12:17 - 2013-07-26 12:17 - 00000000 ____D C:\Documents and Settings\TEMP\Start Menu\Programs\MyPC Backup
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Program Files\InternetHelper3.1
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Program Files\Conduit
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\InternetHelper3.1
2013-07-26 12:16 - 2013-07-26 12:16 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\Conduit
2013-07-26 12:14 - 2013-07-26 12:14 - 00000000 ____D C:\Program Files\SearchProtect
2013-07-26 12:14 - 2013-07-26 12:13 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\SearchProtect
2013-07-26 12:14 - 2013-07-26 12:13 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\SearchProtect
C:\Documents and Settings\TEMP\Application Data\SearchProtect\bin\cltmng.exe
C:\Windows\Tasks\At1.job

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.

=========================

In your next post please provide the following:
  • Fixlog.txt
  • AdwCleaner[S1].txt
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-08-2013 Ran by [removed] at 2013-08-10 00:48:39 Run:1 Running from C:\Documents and Settings\[removed]\Desktop Boot Mode: Normal ============================================== "C:\Program Files\SearchProtect\bin\CltMngSvc.exe" => File/Directory not found. C:\Documents and Settings\TEMP\Application Data\SearchProtect\bin\cltmng.exe => No running process found HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtectAll => Value not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtect => Value not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{07cbf788-1359-421b-a4e3-5a8d041b90a3} => Value deleted successfully. HKCR\CLSID\{07cbf788-1359-421b-a4e3-5a8d041b90a3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0A57EAB3-3E77-4935-93E1-C5293835CC0E} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0A57EAB3-3E77-4935-93E1-C5293835CC0E} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{CF739809-1C6C-47C0-85B9-569DBB141420} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5CEDA225-9CDE-43F4-A1A2-D76CCEC3EDBF} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{5CEDA225-9CDE-43F4-A1A2-D76CCEC3EDBF} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key deleted successfully. HKCR\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07cbf788-1359-421b-a4e3-5a8d041b90a3} => Key deleted successfully. HKCR\CLSID\{07cbf788-1359-421b-a4e3-5a8d041b90a3} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3FA3BA27-0528-4D19-9348-C69282EFD922} => Key not found. HKCR\CLSID\{3FA3BA27-0528-4D19-9348-C69282EFD922} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Value deleted successfully. HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{07cbf788-1359-421b-a4e3-5a8d041b90a3} => Value deleted successfully. HKCR\CLSID\{07cbf788-1359-421b-a4e3-5a8d041b90a3} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. Firefox Keyword.URL deleted successfully. C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\searchplugins\delta.xml => Moved successfully. C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\searchplugins\internethelper31-customized-web-search.xml => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\babylon.xml => Moved successfully. C:\Documents and Settings\TEMP\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} => Moved successfully. C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed] => Moved successfully. C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed] => Moved successfully. C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed] => Moved successfully. C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed] => Moved successfully. C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\getsavin@jetpack => not found. C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\[removed] => Moved successfully. C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\{07cbf788-1359-421b-a4e3-5a8d041b90a3} => Moved successfully. C:\Program Files\Mozilla Firefox\extensions\[removed] => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj => Key deleted successfully. C:\DOCUME~1\TEMP\LOCALS~1\APPLIC~1\funmoods-speeddial_sf.crx => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde => Key not found. "C:\Documents and Settings\TEMP\Application Data\BabSolution\CR\Delta.crx" => File/Directory not found. BrowserProtect => Service not found. CltMngSvc => Service not found. C:\Documents and Settings\NetworkService\Local Settings\Application Data\InternetHelper3.1 => Moved successfully. C:\Program Files\MyPC Backup => Moved successfully. C:\Documents and Settings\TEMP\Start Menu\Programs\MyPC Backup => Moved successfully. C:\Program Files\InternetHelper3.1 => Moved successfully. C:\Program Files\Conduit => Moved successfully. C:\Documents and Settings\TEMP\Local Settings\Application Data\InternetHelper3.1 => Moved successfully. C:\Documents and Settings\TEMP\Local Settings\Application Data\Conduit => Moved successfully. "C:\Program Files\SearchProtect" => File/Directory not found. "C:\Documents and Settings\TEMP\Application Data\SearchProtect" => File/Directory not found. "C:\Documents and Settings\TEMP\Application Data\SearchProtect" => File/Directory not found. "C:\Documents and Settings\NetworkService\Local Settings\Application Data\InternetHelper3.1" => File/Directory not found. "C:\Documents and Settings\TEMP\Start Menu\Programs\MyPC Backup" => File/Directory not found. "C:\Program Files\InternetHelper3.1" => File/Directory not found. "C:\Program Files\Conduit" => File/Directory not found. "C:\Documents and Settings\TEMP\Local Settings\Application Data\InternetHelper3.1" => File/Directory not found. "C:\Documents and Settings\TEMP\Local Settings\Application Data\Conduit" => File/Directory not found. "C:\Program Files\SearchProtect" => File/Directory not found. "C:\Documents and Settings\TEMP\Application Data\SearchProtect" => File/Directory not found. "C:\Documents and Settings\TEMP\Application Data\SearchProtect" => File/Directory not found. "C:\Documents and Settings\TEMP\Application Data\SearchProtect\bin\cltmng.exe" => File/Directory not found. C:\Windows\Tasks\At1.job => Moved successfully. ==== End of Fixlog ==== Also where do i find the adw.txt thing you mentioned… was i supposed to download something and missed it?
Hi HR2008,

My mistake, I forgot to include the step in my previous instructions.

=========================

[external image: Posted Image] AdwCleaner

Download AdwCleaner to your desktop.

  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

In your next post please provide the following:
  • AdwCleaner[S1].txt
# AdwCleaner v2.306 - Logfile created 08/11/2013 at 02:07:16 # Updated 19/07/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Rev. JMWynn - DJTYBHF1 # Boot Mode : Normal # Running from : C:\Documents and Settings\TEMP\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\bProtector_extensions.rdf File Deleted : C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\extensions\[removed] File Deleted : C:\Documents and Settings\TEMP\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cjpglkicenollcignonpgiafdgfeehoj_0.localstorage File Deleted : C:\END File Deleted : C:\Program Files\Mozilla FireFox\Components\AskSearch.js File Deleted : C:\WINDOWS\system32\roboot.exe Folder Deleted : C:\Documents and Settings\All Users\Application Data\Babylon Folder Deleted : C:\Documents and Settings\All Users\Application Data\BrowserProtect Folder Deleted : C:\Documents and Settings\All Users\Application Data\Tarma Installer Folder Deleted : C:\Documents and Settings\All Users\Application Data\Trymedia Folder Deleted : C:\Documents and Settings\TEMP\Application Data\Babylon Folder Deleted : C:\Documents and Settings\TEMP\Application Data\BabylonToolbar Folder Deleted : C:\Documents and Settings\TEMP\Application Data\delta Folder Deleted : C:\Documents and Settings\TEMP\Application Data\Funmoods Folder Deleted : C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Smartbar Folder Deleted : C:\Documents and Settings\TEMP\Local Settings\Application Data\PackageAware Folder Deleted : C:\Documents and Settings\TEMP\Start Menu\Programs\BrowserProtect Folder Deleted : C:\Documents and Settings\TEMP\Start Menu\Programs\HDvidCodec.com Folder Deleted : C:\Program Files\delta Folder Deleted : C:\Program Files\Free Offers from Freeze.com Folder Deleted : C:\Program Files\Funmoods Folder Deleted : C:\Program Files\HDvidCodec.com Folder Deleted : C:\Program Files\Movie2KDownloader.com ***** [Registry] ***** Key Deleted : HKCU\Software\1ClickDownload Key Deleted : HKCU\Software\96dedfb36fe943 Key Deleted : HKCU\Software\BabylonToolbar Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\DataMngr Key Deleted : HKCU\Software\Delta Key Deleted : HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\InternetHelper3.1 Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\SearchProtect Key Deleted : HKCU\Software\SmartBar Key Deleted : HKCU\Toolbar Key Deleted : HKLM\SOFTWARE\96dedfb36fe943 Key Deleted : HKLM\Software\AskBarDis Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1 Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1 Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6CE83F03-4DFD-4070-A0A7-C46C82E20971} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore.1 Key Deleted : HKLM\SOFTWARE\Classes\delta.deltadskBnd Key Deleted : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1 Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaHlpr Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1 Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289663 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\Delta Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\blaofbhgbmeikidhlkmjhbkbfohpgekf Key Deleted : HKLM\Software\InstallCore Key Deleted : HKLM\Software\InternetHelper3.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E} Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8A606D17-43EF-4D59-ADAC-CAAEC50200AB} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E009257F-2ECC-4A37-A0CE-6916F7E5CBF8} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{D08D9F98-1C78-4704-87E6-368B0023D831} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\InternetHelper3.1 Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RegClean Pro_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6CE83F03-4DFD-4070-A0A7-C46C82E20971} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetHelper3.1 Toolbar Key Deleted : HKLM\Software\OpenCandy Key Deleted : HKLM\Software\systweak Key Deleted : HKLM\Software\Tarma Installer Key Deleted : HKLM\Software\Viewpoint Key Deleted : HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Key Deleted : HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://searchfunmoods.com/?f=2&a=AgnUpd&cd=2XzuyEtN2Y1L1QzutDtDtC0D0EtDyE0FtDtByBtAyB0CyDtBtN0D0Tzu0CyEzyzytN1L2Xzut N1L1Czu&cr=1286196492&ir= –> hxxp://www.google.com -\\ Mozilla Firefox v23.0 (en-US) File : C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\prefs.js C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\user.js … Deleted ! Deleted : user_pref("CT3289663.1000082.isPlayDisplay", "true"); Deleted : user_pref("CT3289663.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi…\",\"description[…] Deleted : user_pref("CT3289663.1000234.TWC_TMP_city", "TEXARKANA"); Deleted : user_pref("CT3289663.1000234.TWC_TMP_country", "US"); Deleted : user_pref("CT3289663.1000234.TWC_country", "UNITED STATES"); Deleted : user_pref("CT3289663.1000234.TWC_locId", "USTX1347"); Deleted : user_pref("CT3289663.1000234.TWC_location", "Texarkana, TX"); Deleted : user_pref("CT3289663.1000234.TWC_region", "US"); Deleted : user_pref("CT3289663.1000234.TWC_temp_dis", "f"); Deleted : user_pref("CT3289663.1000234.TWC_wind_dis", "mph"); Deleted : user_pref("CT3289663.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3289663.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[…] Deleted : user_pref("CT3289663.FirstTime", "true"); Deleted : user_pref("CT3289663.FirstTimeFF3", "true"); Deleted : user_pref("CT3289663.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT328[…] Deleted : user_pref("CT3289663.UserID", "UN51329034426236514"); Deleted : user_pref("CT3289663.addressBarTakeOverEnabledInHidden", "true"); Deleted : user_pref("CT3289663.autoDisableScopes", -1); Deleted : user_pref("CT3289663.browser.search.defaultthis.engineName", true); Deleted : user_pref("CT3289663.countryCode", "US"); Deleted : user_pref("CT3289663.defaultSearch", "true"); Deleted : user_pref("CT3289663.enableAlerts", "true"); Deleted : user_pref("CT3289663.enableSearchFromAddressBar", "true"); Deleted : user_pref("CT3289663.firstTimeDialogOpened", "true"); Deleted : user_pref("CT3289663.fixPageNotFoundError", "true"); Deleted : user_pref("CT3289663.fixPageNotFoundErrorByUser", "true"); Deleted : user_pref("CT3289663.fixPageNotFoundErrorInHidden", "true"); Deleted : user_pref("CT3289663.fixUrls", true); Deleted : user_pref("CT3289663.fullUserID", "UN51329034426236514.IN.20130726121344"); Deleted : user_pref("CT3289663.homepageuserchanged", true); Deleted : user_pref("CT3289663.installId", "stub.exe"); Deleted : user_pref("CT3289663.installType", "conduitnsisintegration"); Deleted : user_pref("CT3289663.installUsage", "2013-08-04T07:03:10.8139254+03:00"); Deleted : user_pref("CT3289663.installUsageEarly", "2013-08-04T07:03:08.360769+03:00"); Deleted : user_pref("CT3289663.installerVersion", "1.5.4.4"); Deleted : user_pref("CT3289663.isCheckedStartAsHidden", true); Deleted : user_pref("CT3289663.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3289663.isFirstTimeToolbarLoading", "false"); Deleted : user_pref("CT3289663.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); Deleted : user_pref("CT3289663.keyword", true); Deleted : user_pref("CT3289663.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit[…] Deleted : user_pref("CT3289663.lastVersion", "10.16.70.5"); Deleted : user_pref("CT3289663.mam_gk_installer_preapproved.enc", "ZmFsc2U="); Deleted : user_pref("CT3289663.migrateAppsAndComponents", true); Deleted : user_pref("CT3289663.missingMachineIdSent", "true"); Deleted : user_pref("CT3289663.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"\",\"[…] Deleted : user_pref("CT3289663.openThankYouPage", "false"); Deleted : user_pref("CT3289663.openUninstallPage", "true"); Deleted : user_pref("CT3289663.originalHomepage", "hxxps://www.google.com/"); Deleted : user_pref("CT3289663.originalSearchAddressUrl", ""); Deleted : user_pref("CT3289663.originalSearchEngine", "Google"); Deleted : user_pref("CT3289663.originalSearchEngineName", "Google"); Deleted : user_pref("CT3289663.revertSettingsEnabled", "false"); Deleted : user_pref("CT3289663.search.searchAppId", "130067724014616498"); Deleted : user_pref("CT3289663.search.searchCount", "0"); Deleted : user_pref("CT3289663.searchFromAddressBarEnabledByUser", "true"); Deleted : user_pref("CT3289663.searchInNewTabEnabledByUser", "true"); Deleted : user_pref("CT3289663.searchInNewTabEnabledInHidden", "true"); Deleted : user_pref("CT3289663.searchSuggestEnabledByUser", "true"); Deleted : user_pref("CT3289663.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3289663.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[…] Deleted : user_pref("CT3289663.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[…] Deleted : user_pref("CT3289663.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[…] Deleted : user_pref("CT3289663.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3289663.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3289663.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[…] Deleted : user_pref("CT3289663.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data[…] Deleted : user_pref("CT3289663.serviceLayer_services_Configuration_lastUpdate", "1376108648519"); Deleted : user_pref("CT3289663.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1375588990928"); Deleted : user_pref("CT3289663.serviceLayer_services_appsMetadata_lastUpdate", "1375588990807"); Deleted : user_pref("CT3289663.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1375588990621"); Deleted : user_pref("CT3289663.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1375588988[…] Deleted : user_pref("CT3289663.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1375588991375")[…] Deleted : user_pref("CT3289663.serviceLayer_services_login_10.16.70.5_lastUpdate", "1376111328545"); Deleted : user_pref("CT3289663.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1375588990736"); Deleted : user_pref("CT3289663.serviceLayer_services_searchAPI_lastUpdate", "1376108648237"); Deleted : user_pref("CT3289663.serviceLayer_services_serviceMap_lastUpdate", "1376108647934"); Deleted : user_pref("CT3289663.serviceLayer_services_toolbarContextMenu_lastUpdate", "1375588990458"); Deleted : user_pref("CT3289663.serviceLayer_services_toolbarSettings_lastUpdate", "1376111328631"); Deleted : user_pref("CT3289663.serviceLayer_services_translation_lastUpdate", "1376108648205"); Deleted : user_pref("CT3289663.settingsINI", true); Deleted : user_pref("CT3289663.shouldFirstTimeDialog", "false"); Deleted : user_pref("CT3289663.showToolbarPermission", "false"); Deleted : user_pref("CT3289663.smartbar.CTID", "CT3289663"); Deleted : user_pref("CT3289663.smartbar.Uninstall", "0"); Deleted : user_pref("CT3289663.smartbar.homepage", true); Deleted : user_pref("CT3289663.smartbar.isHidden", true); Deleted : user_pref("CT3289663.smartbar.toolbarName", "InternetHelper3.1 "); Deleted : user_pref("CT3289663.startPage", "true"); Deleted : user_pref("CT3289663.toolbarBornServerTime", "4-8-2013"); Deleted : user_pref("CT3289663.toolbarCurrentServerTime", "10-8-2013"); Deleted : user_pref("CT3289663.toolbarLoginClientTime", "Sat Aug 03 2013 23:03:11 GMT-0500 (Central Standard T[…] Deleted : user_pref("CT3289663.versionFromInstaller", "10.16.70.5"); Deleted : user_pref("CT3289663.xpeMode", "3"); Deleted : user_pref("CT3289663_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[…] Deleted : user_pref("Smartbar.ConduitHomepagesList", ""); Deleted : user_pref("Smartbar.ConduitSearchEngineList", "InternetHelper3.1 Customized Web Search"); Deleted : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663[…] Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3289663"); Deleted : user_pref("browser.search.defaultenginename", "InternetHelper3.1 Customized Web Search"); Deleted : user_pref("extensions.BabylonToolbar.admin", false); Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst"); Deleted : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); Deleted : user_pref("extensions.BabylonToolbar.autoRvrt", "false"); Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en"); Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false); Deleted : user_pref("extensions.BabylonToolbar.id", "b0067c52000000000000001de04f0273"); Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15590"); Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst"); Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base"); Deleted : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[…] Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.6.9.12"); Deleted : user_pref("extensions.BabylonToolbar.vrsni", "[removed]"); Deleted : user_pref("extensions.BabylonToolbar_i.babExt", ""); Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=114066&tt=040912_ctrl_3612_2"); Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false); Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.9.1223:18:54"); Deleted : user_pref("extensions.crossriderapp3026.3026.InstallationThankYouPage", false); Deleted : user_pref("extensions.crossriderapp3026.3026.InstallationTime", 1374378746); Deleted : user_pref("extensions.crossriderapp3026.3026.active", true); Deleted : user_pref("extensions.crossriderapp3026.3026.addressbar", ""); Deleted : user_pref("extensions.crossriderapp3026.3026.addressbarenhanced", ""); Deleted : user_pref("extensions.crossriderapp3026.3026.backgroundjs", "\n\n// This app has been blocked\n"); Deleted : user_pref("extensions.crossriderapp3026.3026.backgroundver", 22); Deleted : user_pref("extensions.crossriderapp3026.3026.can_run_bg_code", true); Deleted : user_pref("extensions.crossriderapp3026.3026.certdomaininstaller", ""); Deleted : user_pref("extensions.crossriderapp3026.3026.changeprevious", false); Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[…] Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.InstallationTime.value", "1374378746"); Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.load_balancer.expiration", "Fri Feb 01 2030 00:0[…] Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%[…] Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.previous_page.expiration", "Fri Feb 01 2030 00:0[…] Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.previous_page.value", "%22hxxp%3A//forums.whatth[…] Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.session_id.expiration", "Fri Feb 01 2030 00:00:0[…] Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.session_id.value", "%22tCKwZpa9o6%22"); Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 G[…] Deleted : user_pref("extensions.crossriderapp3026.3026.cookie.user_id.value", "%2213fff5b61c15f811f0b0269bd1d5[…] Deleted : user_pref("extensions.crossriderapp3026.3026.description", "Software Assist is an add on designed to[…] Deleted : user_pref("extensions.crossriderapp3026.3026.domain", ""); Deleted : user_pref("extensions.crossriderapp3026.3026.enablesearch", false); Deleted : user_pref("extensions.crossriderapp3026.3026.homepage", ""); Deleted : user_pref("extensions.crossriderapp3026.3026.iframe", false); Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.InstallerIdentifiers.expiratio n", "Fri Feb 0[…] Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.InstallerIdentifiers.value", "%7B%22installe[…] Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[…] Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_appVer.value", "190"); Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_lastVersion.expirati on", "Fri Feb […] Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_lastVersion.value", "0"); Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[…] Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_meta.value", "%7B%7D"); Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_nextCheck.expiration", "Sat Aug 10[…] Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_nextCheck.value", "true"); Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_queue.expiration", "Fri Feb 01 203[…] Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.Resources_queue.value", "%7B%7D"); Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.installer.expiration", "Fri Feb 01 2030 00:0[…] Deleted : user_pref("extensions.crossriderapp3026.3026.internaldb.installer.value", "%7B%22InstallerIdentifier[…] Deleted : user_pref("extensions.crossriderapp3026.3026.js", "\n\n// This app has been blocked\n\n(function() {[…] Deleted : user_pref("extensions.crossriderapp3026.3026.manifesturl", ""); Deleted : user_pref("extensions.crossriderapp3026.3026.name", "Software Assist"); Deleted : user_pref("extensions.crossriderapp3026.3026.newtab", ""); Deleted : user_pref("extensions.crossriderapp3026.3026.opensearch", ""); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_11.code", "$jquery(document).ready(funct[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_11.name", "autocomplete"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_11.ver", 2); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_13.code", "(function(a){a.selectedText=f[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_13.name", "CrossriderAppUtils"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_13.ver", 3); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_14.name", "CrossriderUtils"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_14.ver", 5); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_16.code", "if((typeof isBackground===\"u[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_16.name", "FFAppAPIWrapper"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_16.ver", 9); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_17.code", "if(typeof window!==\"undefine[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_17.name", "jQuery"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_17.ver", 4); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_31.code", "if (!appAPI.monetize || appAP[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_31.name", "dealply"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_31.ver", 5); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_47.code", "(function(){appAPI.ready=func[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_47.name", "resources_background"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_47.ver", 3); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_49.code", "if (!appAPI.monetize || appAP[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_49.name", "similar_web"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_49.ver", 4); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_50.code", "function create_id(string_siz[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_50.name", "similar_web_bg"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_50.ver", 2); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_60.code", "var MonitizationPluginsBase=f[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_60.name", "base_monetization"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_60.ver", 2); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_64.code", "(function(){var h=\"__CR_EMPT[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_64.name", "appApiMessage"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_64.ver", 2); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_65.code", "if (!appAPI.monetize || appAP[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_65.name", "superfish_no_coupons"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_65.ver", 2); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_72.code", "if(appAPI.__should_activate_v[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_72.name", "appApiValidation"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_72.ver", 3); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_78.code", "if(typeof jQuery!==\"undefine[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_78.name", "CrossriderInfo"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_78.ver", 3); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_98.code", "(function(){var b=\"cr_\"+app[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_98.name", "omniCommands"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins.plugin_98.ver", 2); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins_lists.plugins_0", "14,78,16,64,47,72,98,50"); Deleted : user_pref("extensions.crossriderapp3026.3026.plugins_lists.plugins_1", "17,14,78,13,16,64,72,98,60,3[…] Deleted : user_pref("extensions.crossriderapp3026.3026.plugins_lists.plugins_5", "14,78,13,16,64,47,72"); Deleted : user_pref("extensions.crossriderapp3026.3026.pluginsurl", "hxxps://w9u6a2p6.ssl.hwcdn.net/plugin/app[…] Deleted : user_pref("extensions.crossriderapp3026.3026.pluginsversion", 43); Deleted : user_pref("extensions.crossriderapp3026.3026.publisher", "KlassKode"); Deleted : user_pref("extensions.crossriderapp3026.3026.searchstatus", 0); Deleted : user_pref("extensions.crossriderapp3026.3026.setnewtab", false); Deleted : user_pref("extensions.crossriderapp3026.3026.thankyou", ""); Deleted : user_pref("extensions.crossriderapp3026.3026.updateinterval", 360); Deleted : user_pref("extensions.crossriderapp3026.3026.ver", 190); Deleted : user_pref("extensions.crossriderapp3026.apps", "3026"); Deleted : user_pref("extensions.crossriderapp3026.bic", "13fff5b61c15f811f0b0269bd1d56f7d"); Deleted : user_pref("extensions.crossriderapp3026.cid", 3026); Deleted : user_pref("extensions.crossriderapp3026.firstrun", false); Deleted : user_pref("extensions.crossriderapp3026.hadappinstalled", true); Deleted : user_pref("extensions.crossriderapp3026.installationdate", 1374378746); Deleted : user_pref("extensions.crossriderapp3026.lastcheck", 22935060); Deleted : user_pref("extensions.crossriderapp3026.lastcheckitem", 22935212); Deleted : user_pref("extensions.crossriderapp3026.modetype", "production"); Deleted : user_pref("extensions.crossriderapp3026.reportInstall", true); Deleted : user_pref("extensions.crossriderapp3026.statsDailyCounter", 23); Deleted : user_pref("extensions.delta.admin", false); Deleted : user_pref("extensions.delta.aflt", "babsst"); Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Deleted : user_pref("extensions.delta.autoRvrt", "false"); Deleted : user_pref("extensions.delta.dfltLng", "en"); Deleted : user_pref("extensions.delta.excTlbr", false); Deleted : user_pref("extensions.delta.id", "b0067c52000000000000001de04f0273"); Deleted : user_pref("extensions.delta.instlDay", "15781"); Deleted : user_pref("extensions.delta.instlRef", "sst"); Deleted : user_pref("extensions.delta.newTab", false); Deleted : user_pref("extensions.delta.prdct", "delta"); Deleted : user_pref("extensions.delta.prtnrId", "delta"); Deleted : user_pref("extensions.delta.rvrt", "false"); Deleted : user_pref("extensions.delta.smplGrp", "none"); Deleted : user_pref("extensions.delta.tlbrId", "base"); Deleted : user_pref("extensions.delta.tlbrSrchUrl", ""); Deleted : user_pref("extensions.delta.vrsn", "[removed]"); Deleted : user_pref("extensions.delta.vrsnTs", "1.8.10.022:14:50"); Deleted : user_pref("extensions.delta.vrsni", "[removed]"); Deleted : user_pref("extensions.funmoods.aflt", "ironpub12"); Deleted : user_pref("extensions.funmoods.autoRvrt", false); Deleted : user_pref("extensions.funmoods.dfltLng", ""); Deleted : user_pref("extensions.funmoods.dfltSrch", false); Deleted : user_pref("extensions.funmoods.dnsErr", true); Deleted : user_pref("extensions.funmoods.envrmnt", "production"); Deleted : user_pref("extensions.funmoods.excTlbr", false); Deleted : user_pref("extensions.funmoods.hmpg", true); Deleted : user_pref("extensions.funmoods.hmpgUrl", "hxxp://searchfunmoods.com/?f=1&a=ironpub12&ir=ironpub12&cd[…] Deleted : user_pref("extensions.funmoods.id", "001DE04F02737C52"); Deleted : user_pref("extensions.funmoods.instlDay", "15696"); Deleted : user_pref("extensions.funmoods.instlRef", "ironpub12"); Deleted : user_pref("extensions.funmoods.isdcmntcmplt", true); Deleted : user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); Deleted : user_pref("extensions.funmoods.newTabUrl", "hxxp://searchfunmoods.com/?f=2&a=ironpub12&ir=ironpub12&[…] Deleted : user_pref("extensions.funmoods.prdct", "funmoods"); Deleted : user_pref("extensions.funmoods.prtnrId", "funmoods"); Deleted : user_pref("extensions.funmoods.srchPrvdr", "Funmoods"); Deleted : user_pref("extensions.funmoods.tlbrId", "base"); Deleted : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://searchfunmoods.com/?f=3&a=ironpub12&ir=ironpub1[…] Deleted : user_pref("extensions.funmoods.vrsn", "1.5.23.22"); Deleted : user_pref("extensions.funmoods.vrsni", "1.5.23.22"); Deleted : user_pref("extensions.funmoods_i.newTab", false); Deleted : user_pref("extensions.funmoods_i.smplGrp", "none"); Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2211:13:43"); Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3289663"); Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289663&CUI=UN513290344[…] Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT[…] Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3289663"); Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3289663"); Deleted : user_pref("smartbar.machineId", "F8XYJXL+9R82PSEUANR/SCYGKVQKZLWMPCKFTTHOGDYQDXO5GLPM/CQ/5VMG6FRLK/W[…] Deleted : user_pref("smartbar.originalHomepage", "hxxp://search.conduit.com/?ctid=CT3289663&CUI=UN513290344262[…] File : C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\prefs.js [OK] File is clean. File : C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\prefs.js [OK] File is clean. File : C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\prefs.js [OK] File is clean. File : C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\prefs.js [OK] File is clean. -\\ Google Chrome v [Unable to get version] File : C:\Documents and Settings\TEMP\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. File : C:\Documents and Settings\TEMP\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. File : C:\Documents and Settings\TEMP\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. File : C:\Documents and Settings\TEMP\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. File : C:\Documents and Settings\TEMP\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [35254 octets] - [11/08/2013 02:07:16] ########## EOF - C:\AdwCleaner[S1].txt - [35315 octets] ##########
Hi HR2008,

[external image: Posted Image] Re-run Farbar Recovery Scan Tool it should be on your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
=========================

In your next post please provide the following:
  • FRST.txt
  • How is the computer running?
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-08-2013
Ran by [removed] (administrator) on 11-08-2013 14:45:45
Running from C:\Documents and Settings\[removed]\Desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation ) C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
(SingleClick Systems) C:\Program Files\Dell Network Assistant\hnm_svc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
( ) C:\WINDOWS\system32\lxdncoms.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
(Intel® Corporation) C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
(Dell Inc) C:\Program Files\Dell\QuickSet\quickset.exe
(CyberLink Corp.) C:\Program Files\Dell\MediaDirect\PCMService.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RealPlay.exe
(Sony Corporation) C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(DUELINGELECTRONS ) C:\Documents and Settings\TEMP\Desktop\YAEB_5000-might work.exe
(DUELINGELECTRONS ) C:\Documents and Settings\TEMP\Desktop\YAEB_5000-might work.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [851968 2007-06-03] (Synaptics, Inc.)
HKLM\…\Run: [IntelZeroConfig] - C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [823296 2007-07-25] (Intel Corporation)
HKLM\…\Run: [IntelWireless] - C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [974848 2007-07-25] (Intel Corporation)
HKLM\…\Run: [Dell QuickSet] - C:\Program Files\Dell\QuickSet\quickset.exe [1191936 2007-05-14] (Dell Inc)
HKLM\…\Run: [ECenter] - C:\Dell\E-Center\EULALauncher.exe [17920 2007-05-24] ( )
HKLM\…\Run: [PCMService] - C:\Program Files\Dell\MediaDirect\PCMService.exe [189736 2007-11-01] (CyberLink Corp.)
HKLM\…\Run: [RealTray] - C:\Program Files\Real\RealPlayer\RealPlay.exe [26112 2008-01-24] (RealNetworks, Inc.)
HKLM\…\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-10-15] (Adobe Systems Incorporated)
HKLM\…\Run: [Malwarebytes Anti-Malware (reboot)] - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [824232 2012-12-14] (Malwarebytes Corporation)
HKLM\…\Run: [ContentTransferWMDetector.exe] - C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe [423200 2008-07-11] (Sony Corporation)
HKLM\…\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM\…\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [947152 2013-01-27] (Microsoft Corporation)
HKLM\…\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\…\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKCU\…\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation)
HKCU\…\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKU\GriffinM\…\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [ 2006-09-11] (Macrovision Corporation)
HKU\Guest\…\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [ 2006-09-11] (Macrovision Corporation)
HKU\Guest\…\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [ 2012-04-18] (Apple Inc.)
HKU\Rev. JMWynn\…\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [ 2006-09-11] (Macrovision Corporation)
HKU\Rev. JMWynn\…\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [ 2008-04-13] (Microsoft Corporation)
HKU\Rev. JMWynn\…\Run: [DW6] - "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" [x]
HKU\Rev. JMWynn\…\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2009-06-10] (Google Inc.)
HKU\Rev. JMWynn\…\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [x]
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
BootExecute:

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
BHO: Define - {B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} - C:\Documents and Settings\TEMP\Local Settings\Application Data\DefineExt\temp.dat ()
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Chessmaster%20Challenge/Images/stg_drm.ocx
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Chessmaster%20Challenge/Images/armhelper.ocx
Handler: ipp - No CLSID Value -
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254

FireFox:
========
FF ProfilePath: C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=13 - C:\Program Files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8is70qn8.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\…\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\
FF HKLM\…\Firefox\Extensions: [{ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}] C:\WINDOWS\system32\5008
FF Extension: Java String Helper - C:\WINDOWS\system32\5008

Chrome:
=======
CHR Extension: (Define Ext) - C:\DOCUME~1\TEMP\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\gjkpcnacdgdlpfejlgflolpaigoicibh\1_0

========================== Services (Whitelisted) =================

S2 gupdate1c9e997644d890a; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-10] (Google Inc.)
R2 hnmsvc; C:\Program Files\Dell Network Assistant\hnm_svc.exe [112176 2007-05-25] (SingleClick Systems)
R2 lxdn_device; C:\WINDOWS\system32\lxdncoms.exe [589824 2007-11-28] ( )
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [20456 2013-01-27] (Microsoft Corporation)
R2 NwSapAgent; C:\Windows\System32\ipxsap.dll [66560 2004-08-04] (Microsoft Corporation)
R2 S24EventMonitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [987136 2007-07-25] (Intel Corporation )
R2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [700760 2009-02-18] (Trend Micro Inc.)
R2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-08-13] (SupportSoft, Inc.)
S2 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [333064 2008-02-18] (Trend Micro Inc.)
R2 WLANKEEPER; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [294912 2007-07-25] (Intel® Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S2 BackupStack; C:\Program Files\MyPC Backup\BackupStack.exe [x]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [x]
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
S2 RoxLiveShare9; "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]
S3 WinDefend; %ProgramFiles%\Windows Defender\mpsvc.dll [x]

==================== Drivers (Whitelisted) ====================

R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [21393 2008-01-16] (Cisco Systems, Inc.)
R1 APPDRV; C:\Windows\SYSTEM32\DRIVERS\APPDRV.SYS [16128 2005-08-12] (Dell Inc)
R2 ASCTRM; C:\Windows\System32\Drivers\ASCTRM.sys [8552 2008-01-24] (Windows ® 2000 DDK provider)
R3 DXEC02; C:\Windows\System32\drivers\dxec02.sys [103168 2006-11-02] (Knowles Acoustics)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows ® Server 2003 DDK provider)
R3 HSFHWAZL; C:\Windows\System32\DRIVERS\HSFHWAZL.sys [209152 2007-04-23] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [989696 2007-04-23] (Conexant Systems, Inc.)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [32072 2012-06-14] ()
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\mbamswissarmy.sys [40776 2013-08-11] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [195296 2013-01-20] (Microsoft Corporation)
R1 MpKsl8e3b39c5; c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B1A6A1BC-E02E-472B-91EB-D06352609F11}\MpKsl8e3b39c5.sys [29904 2013-08-11] (Microsoft Corporation)
R3 NETw4x32; C:\Windows\System32\DRIVERS\NETw4x32.sys [2211456 2007-08-12] (Intel Corporation)
R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-13] (Microsoft Corporation)
R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2004-08-04] (Microsoft Corporation)
R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2004-08-04] (Microsoft Corporation)
R2 Packet; C:\Windows\System32\DRIVERS\packet.sys [12672 2006-12-18] (SingleClick Systems)
R2 s24trans; C:\Windows\System32\DRIVERS\s24trans.sys [12416 2007-05-29] (Intel Corporation)
S3 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [447024 2008-01-16] (Symantec Corporation)
R3 STHDA; C:\Windows\System32\drivers\sthda.sys [1222840 2007-06-06] (SigmaTel, Inc.)
S2 tmactmon; C:\WINDOWS\system32\drivers\tmactmon.sys [52496 2008-02-18] (Trend Micro Inc.)
R2 tmcomm; C:\WINDOWS\system32\drivers\tmcomm.sys [138384 2008-02-18] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [65936 2008-02-18] (Trend Micro Inc.)
S2 tmxpflt; C:\Windows\System32\DRIVERS\tmxpflt.sys [205328 2008-11-26] (Trend Micro Inc.)
R2 vsapint; C:\Windows\System32\DRIVERS\vsapint.sys [1195384 2008-11-26] (Trend Micro Inc.)
S3 catchme; \??\C:\DOCUME~1\TEMP\LOCALS~1\Temp\catchme.sys [x]
S3 RimUsb; System32\Drivers\RimUsb.sys [x]
S1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [x]
S3 SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\ipsdefs\20080215.001\SymIDSCo.sys [x]
U3 TlntSvr;
S3 wanatw; system32\DRIVERS\wanatw4.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-11 02:10 - 2013-08-11 02:10 - 00259840 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-08-11 02:07 - 2013-08-11 02:08 - 00035385 _____ C:\AdwCleaner[S1].txt
2013-08-11 02:06 - 2013-08-11 02:06 - 00666633 _____ C:\Documents and Settings\TEMP\Desktop\AdwCleaner.exe
2013-08-11 02:06 - 2013-08-11 02:06 - 00666633 _____ C:\Documents and Settings\TEMP\Desktop\AdwCleaner.exe
2013-08-10 00:49 - 2013-08-10 00:49 - 00022016 _____ C:\Documents and Settings\TEMP\Desktop\Untitled Document.wps
2013-08-10 00:49 - 2013-08-10 00:49 - 00022016 _____ C:\Documents and Settings\TEMP\Desktop\Untitled Document.wps
2013-08-10 00:48 - 2013-08-10 00:51 - 00000000 ____D C:\Program Files\MyPC Backup
2013-08-10 00:26 - 2013-08-10 00:26 - 00043808 _____ C:\Documents and Settings\TEMP\My Documents\cc_20130810_002632.reg
2013-08-10 00:26 - 2013-08-10 00:26 - 00043808 _____ C:\Documents and Settings\TEMP\My Documents\cc_20130810_002632.reg
2013-08-09 17:24 - 2013-08-09 17:24 - 00017169 _____ C:\Documents and Settings\TEMP\Desktop\Addition.txt
2013-08-09 17:24 - 2013-08-09 17:24 - 00017169 _____ C:\Documents and Settings\TEMP\Desktop\Addition.txt
2013-08-09 17:20 - 2013-08-09 17:20 - 00000000 ____D C:\FRST
2013-08-09 17:17 - 2013-08-09 17:17 - 01230570 _____ (Farbar) C:\Documents and Settings\TEMP\Desktop\FRST.exe
2013-08-09 17:17 - 2013-08-09 17:17 - 01230570 _____ (Farbar) C:\Documents and Settings\TEMP\Desktop\FRST.exe
2013-08-08 16:00 - 2013-08-08 16:00 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(2).exe
2013-08-08 16:00 - 2013-08-08 16:00 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(2).exe
2013-08-08 15:51 - 2013-08-08 15:51 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(1).exe
2013-08-08 15:51 - 2013-08-08 15:51 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(1).exe
2013-08-07 20:03 - 2013-08-07 20:03 - 00000526 _____ C:\Documents and Settings\TEMP\Desktop\MBR.zip
2013-08-07 20:03 - 2013-08-07 20:03 - 00000526 _____ C:\Documents and Settings\TEMP\Desktop\MBR.zip
2013-08-07 20:02 - 2013-08-07 20:02 - 00002207 _____ C:\Documents and Settings\TEMP\Desktop\aswMBR.txt
2013-08-07 20:02 - 2013-08-07 20:02 - 00002207 _____ C:\Documents and Settings\TEMP\Desktop\aswMBR.txt
2013-08-07 20:02 - 2013-08-07 20:02 - 00000512 _____ C:\Documents and Settings\TEMP\Desktop\MBR.dat
2013-08-07 20:02 - 2013-08-07 20:02 - 00000512 _____ C:\Documents and Settings\TEMP\Desktop\MBR.dat
2013-08-07 19:12 - 2013-08-07 20:58 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-07 18:59 - 2013-08-07 18:59 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\OTL.exe
2013-08-07 18:57 - 2013-08-07 19:25 - 04745728 _____ (AVAST Software) C:\Documents and Settings\TEMP\Desktop\aswMBR.exe
2013-08-07 18:57 - 2013-08-07 19:25 - 04745728 _____ (AVAST Software) C:\Documents and Settings\TEMP\Desktop\aswMBR.exe
2013-08-07 18:57 - 2013-08-07 18:57 - 00891098 _____ C:\Documents and Settings\TEMP\Desktop\SecurityCheck.exe
2013-08-07 18:57 - 2013-08-07 18:57 - 00891098 _____ C:\Documents and Settings\TEMP\Desktop\SecurityCheck.exe
2013-08-06 21:04 - 2013-08-06 21:04 - 00011903 _____ C:\Documents and Settings\TEMP\My Documents\hijackthis2013
2013-08-06 21:04 - 2013-08-06 21:04 - 00011903 _____ C:\Documents and Settings\TEMP\My Documents\hijackthis2013
2013-07-26 12:14 - 2013-05-08 01:10 - 00770384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr100.dll
2013-07-26 12:14 - 2013-05-08 01:10 - 00421200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp100.dll
2013-07-20 22:47 - 2013-07-20 22:47 - 00000182 _____ C:\drwtsn32.log
2013-07-20 22:44 - 2013-07-20 22:44 - 00000000 ____D C:\Documents and Settings\TEMP\Start Menu\Programs\Define Ext
2013-07-20 22:43 - 2013-07-20 22:44 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\DefineExt

==================== One Month Modified Files and Folders =======

2013-08-11 14:31 - 2012-10-10 10:29 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-08-11 14:24 - 2012-07-06 02:18 - 02056162 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-11 14:14 - 2012-08-07 20:20 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\Skype
2013-08-11 14:14 - 2012-08-07 20:20 - 00000000 ____D C:\Documents and Settings\TEMP\Application Data\Skype
2013-08-11 13:50 - 2009-07-04 00:48 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-11 02:32 - 2012-10-16 23:59 - 01502643 _____ C:\Documents and Settings\TEMP\Desktop\WarReport.swf
2013-08-11 02:32 - 2012-10-16 23:59 - 01502643 _____ C:\Documents and Settings\TEMP\Desktop\WarReport.swf
2013-08-11 02:20 - 2013-03-07 11:22 - 00000384 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-08-11 02:11 - 2013-08-11 02:11 - 00068112 _____ C:\Documents and Settings\TEMP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2013-08-11 02:11 - 2013-01-30 16:16 - 00040776 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2013-08-11 02:10 - 2013-08-11 02:10 - 00259840 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-08-11 02:10 - 2004-08-10 14:09 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-08-11 02:10 - 2004-08-10 14:08 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-11 02:10 - 2004-08-10 13:59 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-08-11 02:10 - 2004-08-10 13:59 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-08-11 02:09 - 2012-12-12 11:22 - 00032632 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-11 02:09 - 2011-01-26 11:12 - 00000178 ___SH C:\Documents and Settings\TEMP\ntuser.ini
2013-08-11 02:09 - 2011-01-26 11:12 - 00000178 ___SH C:\Documents and Settings\TEMP\ntuser.ini
2013-08-11 02:08 - 2013-08-11 02:07 - 00035385 _____ C:\AdwCleaner[S1].txt
2013-08-11 02:06 - 2013-08-11 02:06 - 00666633 _____ C:\Documents and Settings\TEMP\Desktop\AdwCleaner.exe
2013-08-11 02:06 - 2013-08-11 02:06 - 00666633 _____ C:\Documents and Settings\TEMP\Desktop\AdwCleaner.exe
2013-08-10 20:50 - 2009-07-04 00:48 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-10 10:29 - 2012-05-07 09:36 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2013-08-10 00:51 - 2013-08-10 00:48 - 00000000 ____D C:\Program Files\MyPC Backup
2013-08-10 00:49 - 2013-08-10 00:49 - 00022016 _____ C:\Documents and Settings\TEMP\Desktop\Untitled Document.wps
2013-08-10 00:49 - 2013-08-10 00:49 - 00022016 _____ C:\Documents and Settings\TEMP\Desktop\Untitled Document.wps
2013-08-10 00:42 - 2008-01-16 19:18 - 00000000 ____D C:\Program Files\Google
2013-08-10 00:26 - 2013-08-10 00:26 - 00043808 _____ C:\Documents and Settings\TEMP\My Documents\cc_20130810_002632.reg
2013-08-10 00:26 - 2013-08-10 00:26 - 00043808 _____ C:\Documents and Settings\TEMP\My Documents\cc_20130810_002632.reg
2013-08-10 00:24 - 2008-02-02 20:15 - 00000000 ____D C:\WINDOWS\Minidump
2013-08-09 17:24 - 2013-08-09 17:24 - 00017169 _____ C:\Documents and Settings\TEMP\Desktop\Addition.txt
2013-08-09 17:24 - 2013-08-09 17:24 - 00017169 _____ C:\Documents and Settings\TEMP\Desktop\Addition.txt
2013-08-09 17:20 - 2013-08-09 17:20 - 00000000 ____D C:\FRST
2013-08-09 17:17 - 2013-08-09 17:17 - 01230570 _____ (Farbar) C:\Documents and Settings\TEMP\Desktop\FRST.exe
2013-08-09 17:17 - 2013-08-09 17:17 - 01230570 _____ (Farbar) C:\Documents and Settings\TEMP\Desktop\FRST.exe
2013-08-09 03:11 - 2012-09-06 23:24 - 00000298 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2435779118-4229668356-2006412331-1006.job
2013-08-08 16:00 - 2013-08-08 16:00 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(2).exe
2013-08-08 16:00 - 2013-08-08 16:00 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(2).exe
2013-08-08 15:51 - 2013-08-08 15:51 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(1).exe
2013-08-08 15:51 - 2013-08-08 15:51 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\TEMP\Desktop\OTL(1).exe
2013-08-07 22:15 - 2013-03-07 08:50 - 00000000 ___RD C:\Program Files\Skype
2013-08-07 22:15 - 2012-08-07 19:20 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2013-08-07 20:58 - 2013-08-07 19:12 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-07 20:57 - 2012-05-28 15:53 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-07 20:03 - 2013-08-07 20:03 - 00000526 _____ C:\Documents and Settings\TEMP\Desktop\MBR.zip
2013-08-07 20:03 - 2013-08-07 20:03 - 00000526 _____ C:\Documents and Settings\TEMP\Desktop\MBR.zip
2013-08-07 20:02 - 2013-08-07 20:02 - 00002207 _____ C:\Documents and Settings\TEMP\Desktop\aswMBR.txt
2013-08-07 20:02 - 2013-08-07 20:02 - 00002207 _____ C:\Documents and Settings\TEMP\Desktop\aswMBR.txt
2013-08-07 20:02 - 2013-08-07 20:02 - 00000512 _____ C:\Documents and Settings\TEMP\Desktop\MBR.dat
2013-08-07 20:02 - 2013-08-07 20:02 - 00000512 _____ C:\Documents and Settings\TEMP\Desktop\MBR.dat
2013-08-07 19:25 - 2013-08-07 18:57 - 04745728 _____ (AVAST Software) C:\Documents and Settings\TEMP\Desktop\aswMBR.exe
2013-08-07 19:25 - 2013-08-07 18:57 - 04745728 _____ (AVAST Software) C:\Documents and Settings\TEMP\Desktop\aswMBR.exe
2013-08-07 18:59 - 2013-08-07 18:59 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\OTL.exe
2013-08-07 18:57 - 2013-08-07 18:57 - 00891098 _____ C:\Documents and Settings\TEMP\Desktop\SecurityCheck.exe
2013-08-07 18:57 - 2013-08-07 18:57 - 00891098 _____ C:\Documents and Settings\TEMP\Desktop\SecurityCheck.exe
2013-08-06 21:04 - 2013-08-06 21:04 - 00011903 _____ C:\Documents and Settings\TEMP\My Documents\hijackthis2013
2013-08-06 21:04 - 2013-08-06 21:04 - 00011903 _____ C:\Documents and Settings\TEMP\My Documents\hijackthis2013
2013-08-04 22:11 - 2012-10-14 11:43 - 00048128 _____ C:\Documents and Settings\TEMP\My Documents\goals for Vulcain.wps
2013-08-04 22:11 - 2012-10-14 11:43 - 00048128 _____ C:\Documents and Settings\TEMP\My Documents\goals for Vulcain.wps
2013-08-03 22:56 - 2004-08-10 13:51 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-07-30 22:25 - 2012-05-03 09:54 - 00017408 _____ C:\Documents and Settings\TEMP\My Documents\goals for chevelle.wps
2013-07-30 22:25 - 2012-05-03 09:54 - 00017408 _____ C:\Documents and Settings\TEMP\My Documents\goals for chevelle.wps
2013-07-30 22:04 - 2012-04-17 16:25 - 00068112 _____ C:\Documents and Settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2013-07-26 12:12 - 2008-01-16 19:19 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Adobe
2013-07-21 16:24 - 2009-11-19 15:56 - 00000000 ____D C:\Documents and Settings\All Users\lx_Cats
2013-07-20 22:47 - 2013-07-20 22:47 - 00000182 _____ C:\drwtsn32.log
2013-07-20 22:44 - 2013-07-20 22:44 - 00000000 ____D C:\Documents and Settings\TEMP\Start Menu\Programs\Define Ext
2013-07-20 22:44 - 2013-07-20 22:43 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\DefineExt
2013-07-16 18:57 - 2011-01-26 11:12 - 00000000 ____D C:\Documents and Settings\TEMP\Local Settings\Application Data\Adobe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================




its running quite a bit better, there is a few things that are bothering me.. i was needing to know what to get to let me run Malwarebytes anti-malware, its says im missing something for it to run.. i will open it now and see if it tells me and that way you can tell me possibly what i need to get it working again

ah.. the ieframe.dll is what its missing to work, would also like to use internet explorer again as kid got on and typed in a random password completely shutting me out of anything it does which wont let me update flash players as well
Hi HR2008,

We will address the Internet Explorer issue when we have finished removing the malware.

=========================

[external image: Posted Image] Uninstall via Programs and Features

  • Please go to Start > Control Panel > Add Remove Programs.
    Locate the following programs: (if present) Locate and select the following that are present on the list and click the Remove button:
    • Malwarebytes Anti-Malware
    =========================

    [external image: Posted Image] Reboot

    =========================

    [external image: Posted Image] Malwarebytes' Anti-Malware

    Please download Malwarebytes' Anti-Malware to your desktop.

    Right click mbam-setup.exe and select "Run as Administrator" and follow the prompts to install the program.
    • At the end, be sure a check-mark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan as shown below.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
    =========================

    [external image: Posted Image] ESET Online Scanner

    *Note:
    • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
    • Please don't go surfing while your resident protection is disabled!
    • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.
    ** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

    = = = = = = = = = = = = = = = = = = = =

    Go here to run ESET Online Scanner

    (Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to install
    • Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
    • Click Start
    • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
    • Click Scan.
    • Wait for the scan to finish.
    • When the scan completes, click List of found threats
    • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
    • Include the contents of this report in your next reply

      Note - when ESET doesn't find any threats, no report will be created.
    • Push the back button.
    • Push Finish
    • Re-enable your Antivirus software.
    =========================

    In your next post please provide the following:
    • MBAM log
    • ESET's log.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI