This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

my browser is unresponsive and i keep getting ads coming up and progra

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI



getting unwanted ads ,my keyboard is playing up and browser is slow, think i may have a virus.

 hoping you can help me please.

 phil c

:welcome:

 

Download aswMBR.exe ( 511KB ) to your desktop.
 
Double click the aswMBR.exe to run it
 
Click the "Scan" button to start scan
[external image: aswMBR1.png]
 
On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: aswMBR2.png]
 
 
 
==================================================================
 
Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Please make sure All Users is checked
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
  • 

    sorry ken had to attach files it wont let me cut and paste, a pop up toll number keeps coming up at the mo . i have touting down and restarting macine.

     even my mouse wont left click and open anything either . i have to right click and then open or select all. its a little frustrating but im with you

     regards phil compton

    You have a bit going on, lets do this

     

    Download MiniToolBox and save it to your desktop,  right click on it and select RUN AS ADMINISTRATOR
     
    Checkmark the following boxes:
    • Flush DNS 
    • Reset IE Proxy Settings 
    • Reset FF Proxy Settings
    •  
      Click Go and post the result (Result.txt) that pops up. A copy of result.txt will be saved in the same directory the tool is run.
       
       
       
      ===========================================================
       
       
      -AdwCleaner-by Xplode
       
      Click on this link to download : ADWCleaner
      Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
      Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
       
       
      Do not click on any links in the top Advertisment.
       
      • Close all open programs and internet browsers.
      • Double click on AdwCleaner.exe to run the tool.
      • Click on Scan.
      • After the scan is complete click on "Clean"
      • Confirm each time with Ok.
      • Your computer will be rebooted automatically. A text file will open after the restart.
      • Please post the content of that logfile with your next reply.
      • You can find the logfile at C:\AdwCleaner[S1].txt as well.
      •  
         
        ===============================================================================
         
         
        [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
        • Shut down your protection software now to avoid potential conflicts.
        • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
        • The tool will open and start scanning your system.
        • Please be patient as this can take a while to complete depending on your system's specifications.
        • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
        • Post the contents of JRT.txt into your next message.
        •  
           
           
          ===============================================================================
           
          Download Malwarebytes' Anti-Malware  to your desktop. 
           
          • Windows XP : Double click on the icon to run it.
          • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
          •  
            [external image: MBAMDashboard_zpsddef9b5f.gif]
             
            • On the Dashboard click on Update Now
            • Go to the Setting Tab
            • Under Setting go to Detection and Protection
            • Under PUP and PUM make sure both are set to show Treat Detections as Malware
            • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
            • Then on the Dashboard click on Scan
            • Make sure to select THREAT SCAN
            • Then click on Scan
            • When the scan is finished and the log pops up…select Copy to Clipboard
            • Please paste the log back into this thread for review
            • Exit Malwarebytes
            • # AdwCleaner v4.112 - Logfile created 20/03/2015 at 14:47:11
              # Updated 09/03/2015 by Xplode
              # Database : 2015-03-15.1 [Server]
              # Operating system : Windows 7 Professional Service Pack 1 (x64)
              # Username : P Compton - PCOMPTON-PC
              # Running from : C:\Users\P Compton\Desktop\AdwCleaner.exe
              # Option : Cleaning

              ***** [ Services ] *****

              [#] Service Deleted : NewPlayer

              ***** [ Files / Folders ] *****

              Folder Deleted : C:\ProgramData\374311380
              Folder Deleted : C:\ProgramData\apn
              Folder Deleted : C:\ProgramData\Babylon
              Folder Deleted : C:\ProgramData\CostMin
              Folder Deleted : C:\ProgramData\Tarma Installer
              Folder Deleted : C:\ProgramData\deal2dealit
              Folder Deleted : C:\ProgramData\WorldWideCoupon
              Folder Deleted : C:\ProgramData\BestDiscountApp
              Folder Deleted : C:\ProgramData\DownLoaditkeep
              Folder Deleted : C:\ProgramData\easytosshoop
              Folder Deleted : C:\ProgramData\ProoShopPer
              Folder Deleted : C:\ProgramData\realdeal
              Folder Deleted : C:\ProgramData\SaaVERProa
              Folder Deleted : C:\ProgramData\sAvinuggtoYiou
              Folder Deleted : C:\ProgramData\SofutCouP
              Folder Deleted : C:\ProgramData\surfukeeppit
              Folder Deleted : C:\Program Files (x86)\AnyProtectEx
              Folder Deleted : C:\Program Files (x86)\Bench
              Folder Deleted : C:\Program Files (x86)\OApps
              Folder Deleted : C:\Program Files (x86)\predm
              Folder Deleted : C:\Program Files (x86)\VideoConverter
              Folder Deleted : C:\Program Files (x86)\easytosshoop
              Folder Deleted : C:\Program Files (x86)\ProoShopPer
              Folder Deleted : C:\Program Files (x86)\SaaVERProa
              Folder Deleted : C:\Program Files (x86)\SofutCouP
              Folder Deleted : C:\Program Files (x86)\surfukeeppit
              Folder Deleted : C:\Program Files (x86)\Deaal4maE
              Folder Deleted : C:\Program Files (x86)\dowwnLoaedittkeep
              Folder Deleted : C:\Program Files (x86)\greatsAving
              Folder Deleted : C:\Program Files (x86)\Last Tab Keeper
              Folder Deleted : C:\Program Files (x86)\SaverAdddon
              Folder Deleted : C:\Program Files (x86)\savoinnsHOp
              Folder Deleted : C:\Program Files (x86)\topddeal
              Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
              Folder Deleted : C:\Users\Administrator\AppData\Local\torch
              Folder Deleted : C:\Users\Guest\AppData\Local\Chromatic Browser
              Folder Deleted : C:\Users\Guest\AppData\Local\torch
              Folder Deleted : C:\Users\P Compton\AppData\Local\Chromatic Browser
              Folder Deleted : C:\Users\P Compton\AppData\Local\torch
              Folder Deleted : C:\Users\P Compton\AppData\LocalLow\Delta
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Activeris
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\BabSolution
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Babylon
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\DSite
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\Extensions\[removed]
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\Extensions\[removed]
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\Extensions\[removed]
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\Extensions\[removed]
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\Extensions\[removed]
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\Extensions\[removed]
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\Extensions\[removed]
              Folder Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\Extensions\[removed]
              Folder Deleted : C:\Users\P Compton\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe
              Folder Deleted : C:\Users\P Compton\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd
              Folder Deleted : C:\Users\P Compton\AppData\Local\Google\Chrome\User Data\Default\Extensions\olnkgiapbjhdboldbhkagdodklkphaip
              Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\egndfaiblljbaeeedacolmfljipeklnm
              Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\egndfaiblljbaeeedacolmfljipeklnm
              Folder Deleted : C:\Users\P Compton\AppData\Local\Google\Chrome\User Data\Default\Extensions\egndfaiblljbaeeedacolmfljipeklnm
              Folder Deleted : C:\Users\P Compton\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe
              Folder Deleted : C:\Users\P Compton\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd
              Folder Deleted : C:\Users\P Compton\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\olnkgiapbjhdboldbhkagdodklkphaip
              Folder Deleted : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egndfaiblljbaeeedacolmfljipeklnm
              Folder Deleted : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egndfaiblljbaeeedacolmfljipeklnm
              Folder Deleted : C:\Users\P Compton\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egndfaiblljbaeeedacolmfljipeklnm
              Folder Deleted : C:\Users\P Compton\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe
              Folder Deleted : C:\Users\P Compton\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd
              Folder Deleted : C:\Users\P Compton\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\olnkgiapbjhdboldbhkagdodklkphaip
              Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egndfaiblljbaeeedacolmfljipeklnm
              Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egndfaiblljbaeeedacolmfljipeklnm
              Folder Deleted : C:\Users\P Compton\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egndfaiblljbaeeedacolmfljipeklnm
              File Deleted : C:\END
              File Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\bprotector_extensions.sqlite
              File Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\bprotector_prefs.js
              File Deleted : C:\Users\P Compton\AppData\Roaming\Mozilla\Firefox\Profiles\ek3dpg6f.default\searchplugins\Web Search.xml

              ***** [ Scheduled tasks ] *****

              Task Deleted : BitGuard
              Task Deleted : DSite
              Task Deleted : NewPlayer Update
              Task Deleted : NewPlayer_wd

              ***** [ Shortcuts ] *****


              ***** [ Registry ] *****

              Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
              Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
              Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
              Key Deleted : HKLM\SOFTWARE\Classes\S
              Key Deleted : HKLM\SOFTWARE\Classes\P340be700_4693_442b_8dca_4d120fcb0070_.P340be700_4693_442b_8dca_4d120fcb0070_
              Key Deleted : HKLM\SOFTWARE\Classes\P340be700_4693_442b_8dca_4d120fcb0070_.P340be700_4693_442b_8dca_4d120fcb0070_.9
              Key Deleted : HKLM\SOFTWARE\Classes\P4db0ebd4_7aa4_4423_b5cd_7d859859d96c_.P4db0ebd4_7aa4_4423_b5cd_7d859859d96c_
              Key Deleted : HKLM\SOFTWARE\Classes\P4db0ebd4_7aa4_4423_b5cd_7d859859d96c_.P4db0ebd4_7aa4_4423_b5cd_7d859859d96c_.9
              Key Deleted : HKLM\SOFTWARE\Classes\P5b449cbd_4ba8_48ae_ba29_83bb55155ab8_.P5b449cbd_4ba8_48ae_ba29_83bb55155ab8_
              Key Deleted : HKLM\SOFTWARE\Classes\P5b449cbd_4ba8_48ae_ba29_83bb55155ab8_.P5b449cbd_4ba8_48ae_ba29_83bb55155ab8_.9
              Key Deleted : HKLM\SOFTWARE\Classes\Pac9cb131_79b8_4dd0_aaa8_e0189a4eb6b1_.Pac9cb131_79b8_4dd0_aaa8_e0189a4eb6b1_
              Key Deleted : HKLM\SOFTWARE\Classes\Pac9cb131_79b8_4dd0_aaa8_e0189a4eb6b1_.Pac9cb131_79b8_4dd0_aaa8_e0189a4eb6b1_.9
              Key Deleted : HKCU\Software\5e08fd8e234b940
              Key Deleted : HKLM\SOFTWARE\5e08fd8e234b940
              Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EC77D09-02CB-4E1F-E3C4-FB141B2610B3}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{340be700-4693-442b-8dca-4d120fcb0070}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4db0ebd4-7aa4-4423-b5cd-7d859859d96c}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5b449cbd-4ba8-48ae-ba29-83bb55155ab8}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ac9cb131-79b8-4dd0-aaa8-e0189a4eb6b1}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{41F978F3-431A-4464-A789-5C0692D562FB}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{340be700-4693-442b-8dca-4d120fcb0070}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4db0ebd4-7aa4-4423-b5cd-7d859859d96c}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5b449cbd-4ba8-48ae-ba29-83bb55155ab8}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ac9cb131-79b8-4dd0-aaa8-e0189a4eb6b1}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{340be700-4693-442b-8dca-4d120fcb0070}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4db0ebd4-7aa4-4423-b5cd-7d859859d96c}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5b449cbd-4ba8-48ae-ba29-83bb55155ab8}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ac9cb131-79b8-4dd0-aaa8-e0189a4eb6b1}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{340be700-4693-442b-8dca-4d120fcb0070}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4db0ebd4-7aa4-4423-b5cd-7d859859d96c}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5b449cbd-4ba8-48ae-ba29-83bb55155ab8}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ac9cb131-79b8-4dd0-aaa8-e0189a4eb6b1}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{340be700-4693-442b-8dca-4d120fcb0070}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4db0ebd4-7aa4-4423-b5cd-7d859859d96c}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5b449cbd-4ba8-48ae-ba29-83bb55155ab8}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ac9cb131-79b8-4dd0-aaa8-e0189a4eb6b1}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}
              Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
              Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
              Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{340be700-4693-442b-8dca-4d120fcb0070}
              Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4db0ebd4-7aa4-4423-b5cd-7d859859d96c}
              Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5b449cbd-4ba8-48ae-ba29-83bb55155ab8}
              Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{ac9cb131-79b8-4dd0-aaa8-e0189a4eb6b1}
              Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
              Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{340be700-4693-442b-8dca-4d120fcb0070}
              Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4db0ebd4-7aa4-4423-b5cd-7d859859d96c}
              Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5b449cbd-4ba8-48ae-ba29-83bb55155ab8}
              Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ac9cb131-79b8-4dd0-aaa8-e0189a4eb6b1}
              Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
              Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}
              Key Deleted : HKCU\Software\AnyProtect
              Key Deleted : HKCU\Software\DataMngr
              [#] Key Deleted : HKCU\Software\DataMngr_Toolbar
              Key Deleted : HKCU\Software\dsiteproducts
              Key Deleted : HKCU\Software\filescout
              Key Deleted : HKCU\Software\InstallCore
              Key Deleted : HKCU\Software\TutoTag
              Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
              Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
              Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
              Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
              Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
              Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
              Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
              Key Deleted : HKLM\SOFTWARE\AdvertisingSupport
              Key Deleted : HKLM\SOFTWARE\Babylon
              Key Deleted : HKLM\SOFTWARE\Coupon Server
              Key Deleted : HKLM\SOFTWARE\DataMngr
              Key Deleted : HKLM\SOFTWARE\FreeSoftToday
              Key Deleted : HKLM\SOFTWARE\InstallIQ
              Key Deleted : HKLM\SOFTWARE\Tutorials
              Key Deleted : HKLM\SOFTWARE\Taronja
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DSite
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5F003B-C71B-72E3-42B4-DE51AB079EB2}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7540FDBD-7FDC-30AE-3778-815CB87DBE46}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{532970A2-464B-73CB-BBC4-F209EAD3EEBE}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D831E399-50FE-84AE-F5F7-0A63AC282464}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Activeris AntiMalware_is1
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{594FD08C-0622-F9B8-CB02-7C1355D33CB8}
              Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
              Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
              Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
              Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

              ***** [ Web browsers ] *****

              -\\ Internet Explorer v11.0.9600.17689

              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
              Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]

              -\\ Mozilla Firefox v20.0.1 (en-US)

              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.EEU_1xp.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"sumo[…]
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.IsNTiX.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"sumor[…]
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.Ljeq5xNqA15n.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\[…]
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.Lt_u.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"sumorob[…]
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.aQl.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"sumorobo[…]
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.admin", false);
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.aflt", "babsst");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.bbDpng", "24");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.cntry", "GB");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.dfltLng", "en");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.excTlbr", false);
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.hdrMd5", "6DBCE7E4A38EBFC8849A8418815C6EBC");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.id", "56a1f8e1000000000000902b3459aa40");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.instlDay", "15866");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.instlRef", "sst");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.lastVrsnTs", "1.8.21.511:22:55");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.newTab", false);
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.prdct", "delta");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.rvrt", "false");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.sg", "azb");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.smplGrp", "azb");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.tlbrId", "base");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.vrsn", "1.8.21.5");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.21.511:22:55");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta.vrsni", "1.8.21.5");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta_i.babExt", "");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=119982");
              [ek3dpg6f.default\prefs.js] - Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");

              -\\ Google Chrome v


              -\\ Comodo Dragon v


              -\\ Chrome Canary v


              *************************

              AdwCleaner[R0].txt - [22999 bytes] - [20/03/2015 14:44:44]
              AdwCleaner[S0].txt - [20936 bytes] - [20/03/2015 14:47:11]

              ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [20996 bytes] ##########
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
              Junkware Removal Tool (JRT) by Thisisu
              Version: 6.4.5 (03.17.2015:1)
              OS: Windows 7 Professional x64
              Ran by [removed] on 20/03/2015 at 14:55:59.17
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




              ~~~ Services



              ~~~ Registry Values



              ~~~ Registry Keys



              ~~~ Files



              ~~~ Folders

              Failed to delete: [Folder] "C:\ProgramData\flexnet"



              ~~~ FireFox

              Successfully deleted: [Folder] C:\Users\P Compton\AppData\Roaming\mozilla\firefox\profiles\ek3dpg6f.default\extensions\staged



              ~~~ Event Viewer Logs were cleared





              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
              Scan was completed on 20/03/2015 at 14:57:33.45
              End of JRT log
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

              Malwarebytes Anti-Malware
              www.malwarebytes.org

              Scan Date: 20/03/2015
              Scan Time: 15:04:42
              Logfile: mwb text file.txt
              Administrator: Yes

              Version: 2.01.4.1018
              Malware Database: v2015.03.20.04
              Rootkit Database: v2015.02.25.01
              License: Trial
              Malware Protection: Enabled
              Malicious Website Protection: Enabled
              Self-protection: Disabled

              OS: Windows 7 Service Pack 1
              CPU: x64
              File System: NTFS
              User: P Compton

              Scan Type: Threat Scan
              Result: Completed
              Objects Scanned: 382722
              Time Elapsed: 3 min, 51 sec

              Memory: Enabled
              Startup: Enabled
              Filesystem: Enabled
              Archives: Enabled
              Rootkits: Disabled
              Heuristics: Enabled
              PUP: Enabled
              PUM: Enabled

              Processes: 0
              (No malicious items detected)

              Modules: 0
              (No malicious items detected)

              Registry Keys: 5
              PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, , [f6ce56f18cfe5fd7cace70848d76ce32],
              PUP.Optional.PlusHD.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-9.1, , [2a9a83c4b9d1999d988f0fe6739055ab],
              PUP.Optional.PlusHD.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-9.52, , [d9eb0b3c54360036190efafb19ea03fd],
              PUP.Optional.GenericAddon.A, HKU\S-1-5-21-378118014-4011371717-2125457541-1000\SOFTWARE\APPDATALOW\SOFTWARE\GenericAddon, , [1aaa88bf2763fd39755e478938cb7d83],
              PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-378118014-4011371717-2125457541-1000\SOFTWARE\SMARTBAR, , [626236112367e155afd72315d530c53b],

              Registry Values: 3
              PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_gb_13, , [d2f2b790276393a3881fd816ba49b34d],
              PUP.Optional.Tuto4PC.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|t4pc_en_3, , [f3d10c3bb2d88ea89b67f4e3c43f54ac],
              PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-378118014-4011371717-2125457541-1000\SOFTWARE\SMARTBAR|publisher, ShoppingHelper, , [626236112367e155afd72315d530c53b]

              Registry Data: 0
              (No malicious items detected)

              Folders: 0
              (No malicious items detected)

              Files: 30
              PUP.Optional.FileScout.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$R6QQHLY.exe, , [9c283e09ddad64d2c6431e168b76718f],
              PUP.Optional.OutBrowse, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RJCATX8.exe, , [b113b1962664f2447d267db56a98d12f],
              PUP.Optional.Wajam.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$R76PJFU.exe, , [3e86a89faedca5919dd72225b14f817f],
              PUP.Optional.MyPCBackup.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RPQ5PJS.exe, , [358f89bea1e90432e597cb26ca37e61a],
              PUP.Optional.Babylon.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RQ0RRYD.exe, , [685ca5a25733a78fd24a1919ea170ff1],
              Trojan.SProtector, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RW9LLEA.exe, , [8e36e265ee9cec4a79c9215b768b0bf5],
              PUP.Optional.BundleInstaller.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$R0ZH9Y2.txt, , [ecd82e19048645f1f2a79cd5a859bc44],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RO05AKZ\CrxUpdater_d.exe, , [3d87ec5b0189b482ca0289070203b44c],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RDE8KVL\CrxUpdater_d.exe, , [1fa584c36822e25409c3fc9472933fc1],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$R4DBQY3\CrxUpdater_d.exe, , [b11313343852e254c606abe5cb3a916f],
              Backdoor.Bot, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RJQK43N\android.exe, , [f9cbdc6b8ffbd462caa5f3a6fc05cb35],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RXGZ6GL\CrxUpdater_d.exe, , [2e96e0677f0b9d993894bbd520e58779],
              Backdoor.Bot, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RFT2REV\android.exe, , [01c3fc4b2b5f58de5f10abee7b86d22e],
              Backdoor.Bot, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RQMB0RS\android.exe, , [af152e19068457df353a36635aa7936d],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$R04W0UO\CrxUpdater_d.exe, , [51737acdb4d64beb35975838986d36ca],
              PUP.Optional.BundleInstaller.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$R75353W\parent.txt, , [07bd6ed94c3e36006237c4ad639ece32],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RQ84KP3\CrxUpdater_d.exe, , [388ccc7b2862b48253798907778e02fe],
              Backdoor.Bot, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RDZJ2Q3\android.exe, , [dee669de7f0b1d19a7c8b6e3ec15e917],
              PUP.Optional.Tuto4PC.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RIH5SZA.tmp\package_tuto4pc_installer_multilang.exe, , [f1d312353753a690e2aeca3252af7e82],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RQDQBGR\CrxUpdater_d.exe, , [21a3e2658109e94dae1e8a06d53023dd],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RH4V4S0\CrxUpdater_d.exe, , [ccf866e1e3a7979f3c90e8a86a9bd32d],
              Trojan.Agent, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RI8V5FN.tmp\WffRQzXVWPdCPh.exe, , [259f81c6404ab185edfc5bafa65c4bb5],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RI9D3VP\CrxUpdater_d.exe, , [566e96b1c5c5e155ffcd325ec5404db3],
              PUP.Optional.Babylon.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RA4X418\DeltaTB.exe, , [3a8a9aad69210f273ae2ae84c53c0ff1],
              PUP.Optional.Wajam.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RA4X418\wajam_download.exe, , [e3e1ff480e7cd0661262e463f70907f9],
              Backdoor.Bot, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RK4MNCJ\android.exe, , [4a7a81c6018941f596d962370ff2ab55],
              Backdoor.Bot, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RL2GXBW\android.exe, , [14b077d005857cbae986fd9c926ff30d],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RL36KVM\CrxUpdater_d.exe, , [ae16093ef892201626a6d4bcab5afc04],
              PUP.Optional.CRX.A, C:\$Recycle.Bin\S-1-5-21-378118014-4011371717-2125457541-1000\$RL4MR94\CrxUpdater_d.exe, , [ab193c0bccbe40f6ab21127ea2639c64],
              Adware.DomaIQ, C:\Users\P Compton\Downloads\FlashPlayer_V.102887895b.exe, , [7c48ad9adeacb87eede00b085caa9e62],

              Physical Sectors: 0
              (No malicious items detected)


              (end)




























              ~~~ Registry Values



              ~~~ Registry Keys



              ~~~ Files



              ~~~ Folders

              Failed to delete: [Folder] "C:\ProgramData\flexnet"



              ~~~ FireFox

              Successfully deleted: [Folder] C:\Users\P Compton\AppData\Roaming\mozilla\firefox\profiles\ek3dpg6f.default\extensions\staged



              ~~~ Event Viewer Logs were cleared





              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
              Scan was completed on 20/03/2015 at 14:57:33.45
              End of JRT log
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
              hi ken , you should have everything youve asked for now ? thank you so much your help is appreciated. my machine is a lot more responsive now , regards phil compton

              Phil,

               

              Make sure everything that was picked up with Malwarebytes was removed

               

               

              open up FRST, be sure to checkmark Additions , run a new scan and post both the FRST log and Additions

              Malwarebytes Anti-Malware
              www.malwarebytes.org

              Scan Date: 20/03/2015
              Scan Time: 15:40:38
              Logfile: mwb text.txt
              Administrator: Yes

              Version: 2.01.4.1018
              Malware Database: v2015.03.20.04
              Rootkit Database: v2015.02.25.01
              License: Trial
              Malware Protection: Enabled
              Malicious Website Protection: Enabled
              Self-protection: Disabled

              OS: Windows 7 Service Pack 1
              CPU: x64
              File System: NTFS
              User: P Compton

              Scan Type: Threat Scan
              Result: Completed
              Objects Scanned: 382819
              Time Elapsed: 3 min, 51 sec

              Memory: Enabled
              Startup: Enabled
              Filesystem: Enabled
              Archives: Enabled
              Rootkits: Disabled
              Heuristics: Enabled
              PUP: Enabled
              PUM: Enabled

              Processes: 0
              (No malicious items detected)

              Modules: 0
              (No malicious items detected)

              Registry Keys: 0
              (No malicious items detected)

              Registry Values: 0
              (No malicious items detected)

              Registry Data: 0
              (No malicious items detected)

              Folders: 0
              (No malicious items detected)

              Files: 0
              (No malicious items detected)

              Physical Sectors: 0
              (No malicious items detected)


              (end)
              Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
              Ran by [removed] (administrator) on PCOMPTON-PC on 20-03-2015 15:46:06
              Running from C:\Users\[removed]\Desktop
              [removed]

              Ask AI

              AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

              Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI