Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Computer is slow on start up and I cannot uninstall PC Fix Speed program


  • Please log in to reply
11 replies to this topic

#1 StrobeStop

StrobeStop

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:12:58 AM

Posted 24 August 2013 - 11:32 PM

Hello.  I am on a computer that is using Windows 7 Ultimate.  When I start up the computer it is very slow.  I tried to uninstall some unused programs from the computer and there is a program that I tried to uninstall that keeps reinstalling automatically called PC Fix Speed.    

So far I have tried to restore the computer from a save point and it has not worked.  I am currently running a malwarebytes scan.  

 

I am trying to fix this computer for my landlord so that he can use it as a HTPC in our living room.  Thanks for your help.



BC AdBot (Login to Remove)

 


#2 Condobloke

Condobloke

    Outback Aussie @ 54.2101 N, 0.2906 W


  • Members
  • 5,949 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:58 PM

Posted 25 August 2013 - 12:11 AM

 
 

Hello StrobeStop,

Lets see if these will kick it to the curb.....

 

 

 

 

1.  Please download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Double-click on the Rkill desktop icon to run the tool.
    If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    If not, delete the file, then download and use the one provided in Link 2.
    Do not reboot until instructed.
    If the tool does not run from any of the links provided, please advise me of this..

2..

Please download AdwCleaner by Xplode and save to your Desktop.

    Double click on AdwCleaner.exe to run the tool. Vista/Windows 7/8 users right-click and select Run As Administrator

.

    Click on the Scan button.

    AdwCleaner will begin...be patient as the scan may take some time to complete.

    After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.

    The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.

    Copy and paste the contents of that logfile in your next reply.

    A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

 

and Then::

3.

Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

 

Note: If Malwarebytes encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally will prevent Malwarebytes from removing all the malware.

 

If you have any problems running MalwareBytes.....go to your program list to MalwareBytes >>Tools>>malwarebytes anti malware Chameleon......follow the Instructions there.

 

 

 

 


Condobloke ...Outback Australian  

 

fed up with Windows antics...??....LINUX IS THE ANSWER....I USE LINUX MINT 18.3  EXCLUSIVELY.

“A man travels the world in search of what he needs and returns home to find it."

It has been said that time heals all wounds. I don't agree. The wounds remain. Time - the mind, protecting its sanity - covers them with some scar tissue and the pain lessens, but it is never gone. Rose Kennedy


#3 StrobeStop

StrobeStop
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:12:58 AM

Posted 25 August 2013 - 04:40 PM

# AdwCleaner v3.001 - Report created 25/08/2013 at 14:20:14
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Paul - HP-PC
# Running from : C:\Users\Paul\Desktop\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
File Found : C:\END
File Found : C:\Users\Paul\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage
File Found : C:\Users\Paul\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal
File Found : C:\Users\Paul\AppData\Roaming\BabMaint.exe
File Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\bProtector_extensions.rdf
File Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\addon@defaulttab.com.xpi
File Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\searchplugins\Babylon.xml
File Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\searchplugins\search.xml
File Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\searchplugins\Web Search.xml
File Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\user.js
File Found : C:\Windows\System32\Tasks\DSite
File Found : C:\Windows\System32\Tasks\EPUpdater
File Found : C:\Windows\Tasks\DSite.job
Folder Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\{01e86e69-a2f8-48a0-b068-83869bdba3d0}
Folder Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\{07cbf788-1359-421b-a4e3-5a8d041b90a3}
Folder Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\{739df940-c5ee-4bab-9d7e-270894ae687a}
Folder Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\{9ed31f84-c8b3-4926-b950-dff74047ff79}
Folder Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\ffxtlbr@delta.com
Folder Found : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\plugin@getwebcake.com
Folder Found C:\Program Files\Conduit
Folder Found C:\Program Files\Free Offers from Freeze.com
Folder Found C:\Program Files\internethelper3.1
Folder Found C:\Program Files\LyricsContainer
Folder Found C:\Program Files\MapsGalaxy_39EI
Folder Found C:\Program Files\MyPC Backup
Folder Found C:\Program Files\MyPC Backup 
Folder Found C:\Program Files\OApps
Folder Found C:\Program Files\Playbryte
Folder Found C:\Program Files\Red Sky
Folder Found C:\Program Files\SearchProtect
Folder Found C:\ProgramData\Babylon
Folder Found C:\ProgramData\blekko toolbars
Folder Found C:\ProgramData\PC Optimizer Pro
Folder Found C:\ProgramData\SpeedMaxPc
Folder Found C:\ProgramData\WeCareReminder
Folder Found C:\Users\Paul\AppData\Local\Conduit
Folder Found C:\Users\Paul\AppData\Local\cre
Folder Found C:\Users\Paul\AppData\Local\DownTango
Folder Found C:\Users\Paul\AppData\Local\SwvUpdater
Folder Found C:\Users\Paul\AppData\Local\Temp\CT3286042
Folder Found C:\Users\Paul\AppData\Local\Temp\Smartbar
Folder Found C:\Users\Paul\AppData\Local\visualbeeexe
Folder Found C:\Users\Paul\AppData\LocalLow\adawaretb
Folder Found C:\Users\Paul\AppData\LocalLow\AVG Security Toolbar
Folder Found C:\Users\Paul\AppData\LocalLow\BabylonToolbar
Folder Found C:\Users\Paul\AppData\LocalLow\Conduit
Folder Found C:\Users\Paul\AppData\LocalLow\delta
Folder Found C:\Users\Paul\AppData\LocalLow\internethelper3.1
Folder Found C:\Users\Paul\AppData\LocalLow\MapsGalaxy_39EI
Folder Found C:\Users\Paul\AppData\LocalLow\PriceGong
Folder Found C:\Users\Paul\AppData\LocalLow\Toolbar4
Folder Found C:\Users\Paul\AppData\Roaming\Betcat
Folder Found C:\Users\Paul\AppData\Roaming\DriverCure
Folder Found C:\Users\Paul\AppData\Roaming\DSite
Folder Found C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\adawaretb
Folder Found C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\CT3286042
Folder Found C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\CT3287808
Folder Found C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\CT3289663
Folder Found C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\CT3289847
Folder Found C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Smartbar
Folder Found C:\Users\Paul\AppData\Roaming\PerformerSoft
Folder Found C:\Users\Paul\AppData\Roaming\SearchProtect
Folder Found C:\Users\Paul\AppData\Roaming\SpeedMaxPc
Folder Found C:\Users\Paul\AppData\Roaming\Systweak
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\5fede8ce53ebd43
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\MapsGalaxy_39EI
Key Found : HKCU\Software\BabSolution
Key Found : HKCU\Software\BabylonToolbar
Key Found : HKCU\Software\Cr_Installer
Key Found : HKCU\Software\delta LTD
Key Found : HKCU\Software\dsiteproducts
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Found : HKCU\Software\pc optimizer pro
Key Found : HKCU\Software\wecarereminder
Key Found : HKCU\Software\YahooPartnerToolbar
Key Found : HKLM\SOFTWARE\5fede8ce53ebd43
Key Found : HKLM\Software\Babylon
Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Found : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Found : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Found : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Found : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\speedupmypc
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Found : HKLM\Software\Freeze.com
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\bcjagnifjocnddgeknajocbkkhlgibem
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh
Key Found : HKLM\Software\Iminent
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\App24x7Help_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\App24x7Help_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\DSite
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\EPUpdater
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\DSite
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\EPUpdater
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Key Found : HKLM\Software\Tarma Installer
Key Found : HKLM\Software\Uniblue\DriverScanner
Value Found : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Value Found : HKCU\Software\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v10.0.9200.16660
 
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www2.delta-search.com/?affID=121846&babsrc=HP_ss&mntrId=480E001BFC68D107
 
-\\ Mozilla Firefox v20.0.1 (en-US)
 
[ File : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\prefs.js ]
 
Line Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Found : user_pref("extensions.BabylonToolbar.admin", false);
Line Found : user_pref("extensions.BabylonToolbar.aflt", "orgnl");
Line Found : user_pref("extensions.BabylonToolbar.bbDpng", 5);
Line Found : user_pref("extensions.BabylonToolbar.cntry", "US");
Line Found : user_pref("extensions.BabylonToolbar.dfltSrch", false);
Line Found : user_pref("extensions.BabylonToolbar.excTlbr", false);
Line Found : user_pref("extensions.BabylonToolbar.hdrMd5", "45B45E1E2ECF3E3F905CF1820AB961F6");
Line Found : user_pref("extensions.BabylonToolbar.hmpg", false);
Line Found : user_pref("extensions.BabylonToolbar.lastActv", "19");
Line Found : user_pref("extensions.BabylonToolbar.lastDP", 5);
Line Found : user_pref("extensions.BabylonToolbar.lastVrsnTs", "");
Line Found : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "12.0");
Line Found : user_pref("extensions.BabylonToolbar.newTab", true);
Line Found : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP");
Line Found : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);
Line Found : user_pref("extensions.BabylonToolbar.propectorlck", 77515525);
Line Found : user_pref("extensions.BabylonToolbar.prtkDS", 1);
Line Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 1);
Line Found : user_pref("extensions.BabylonToolbar.smplGrp", "free");
Line Found : user_pref("extensions.crossrider.bic", "136c2394292d7f52a9100c3cef17b6bb");
Line Found : user_pref("extensions.crossriderapp2258.2258.InstallationThankYouPage", true);
Line Found : user_pref("extensions.crossriderapp2258.2258.InstallationTime", 1334691556);
Line Found : user_pref("extensions.crossriderapp2258.2258.InstallationUserSettings.searchUserConifrmation", false);
Line Found : user_pref("extensions.crossriderapp2258.2258.InstallationUserSettings.setHomepage", false);
Line Found : user_pref("extensions.crossriderapp2258.2258.InstallationUserSettings.setNewTab", false);
Line Found : user_pref("extensions.crossriderapp2258.2258.InstallationUserSettings.setSearch", false);
Line Found : user_pref("extensions.crossriderapp2258.2258.active", true);
Line Found : user_pref("extensions.crossriderapp2258.2258.addressbar", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.affid", "0");
Line Found : user_pref("extensions.crossriderapp2258.2258.backgroundjs", "\n\n_GPL_PID = 21;\nfunction parse_url(str,component){var key=['source','scheme','authority','userInfo','user','pass','host','port','relati[...]
Line Found : user_pref("extensions.crossriderapp2258.2258.backgroundver", 8);
Line Found : user_pref("extensions.crossriderapp2258.2258.can_run_bg_code", true);
Line Found : user_pref("extensions.crossriderapp2258.2258.certdomaininstaller", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.changeprevious", false);
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie.InstallationTime.value", "1334691556");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_aoi.value", "1334691556");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_crr.value", "1335058875");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_geo.expiration", "Tue Apr 24 2012 14:33:50 GMT-0700 (Pacific Daylight Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_geo.value", "%7B%22geoplugin_city%22%3A%22Sunnyvale%22%2C%22geoplugin_region%22%3A%22CA%22%2C%22geoplugin_areaCode%22%3A408%2C%22geoplugin_dmaC[...]
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_hotfix20111102645.value", "%221%22");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_installer_params.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_installer_params.value", "%7B%22source_id%22%3A%224caa425a93dbdb1f6d0AQ3204%22%2C%22sub_id%22%3A%22default%22%2C%22uzid%22%3A%2227782%26subid%3[...]
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_parent_zoneid.value", "%2227782%22");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_zoneid.value", "%2230787%22");
Line Found : user_pref("extensions.crossriderapp2258.2258.description", "I Want This!");
Line Found : user_pref("extensions.crossriderapp2258.2258.domain", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.emailsig", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.enablesearch", false);
Line Found : user_pref("extensions.crossriderapp2258.2258.exposesites", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.fbremoteurl", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.group", 0);
Line Found : user_pref("extensions.crossriderapp2258.2258.homepage", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.iframe", false);
Line Found : user_pref("extensions.crossriderapp2258.2258.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Found : user_pref("extensions.crossriderapp2258.2258.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%22CD552FD62487471EA146A5B84F2EFD23IE%22%2C%22installer_verifier%22%3A%223e3a825c242066a1[...]
Line Found : user_pref("extensions.crossriderapp2258.2258.js", "\n\nvar _GPL_PID = 21;\n\n(function($) {   \n\n  $.geoplugin = function(options) {\n    var baseCurrency = \"USD\";\n    var address = null;\n    var[...]
Line Found : user_pref("extensions.crossriderapp2258.2258.manifesturl", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.name", "I Want This");
Line Found : user_pref("extensions.crossriderapp2258.2258.newtab", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.opensearch", "");
Line Found : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_13.code", "(function(B){b.selectedText=function(f,a){function c(){if(window.getSelection)return window.getSelection();if(document.getSelecti[...]
Line Found : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_13.name", "CrossriderAppUtils");
Line Found : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_13.ver", 1);
Line Found : user_pref("extensions.delta.admin", false);
Line Found : user_pref("extensions.delta.aflt", "babsst");
Line Found : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Found : user_pref("extensions.delta.autoRvrt", "false");
Line Found : user_pref("extensions.delta.bbDpng", "23");
Line Found : user_pref("extensions.delta.cntry", "US");
Line Found : user_pref("extensions.delta.dfltLng", "en");
Line Found : user_pref("extensions.delta.excTlbr", false);
Line Found : user_pref("extensions.delta.ffxUnstlRst", true);
Line Found : user_pref("extensions.delta.hdrMd5", "91D8EBE011C9CE1312CD84E7303183A3");
Line Found : user_pref("extensions.delta.id", "480ea2a2000000000000001bfc68d107");
Line Found : user_pref("extensions.delta.instlDay", "15826");
Line Found : user_pref("extensions.delta.instlRef", "sst");
Line Found : user_pref("extensions.delta.lastVrsnTs", "1.8.16.1617:28:18");
Line Found : user_pref("extensions.delta.newTab", false);
Line Found : user_pref("extensions.delta.prdct", "delta");
Line Found : user_pref("extensions.delta.prtnrId", "delta");
Line Found : user_pref("extensions.delta.rvrt", "false");
Line Found : user_pref("extensions.delta.sg", "azb");
Line Found : user_pref("extensions.delta.smplGrp", "azb");
Line Found : user_pref("extensions.delta.tlbrId", "base");
Line Found : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Found : user_pref("extensions.delta.vrsn", "1.8.16.16");
Line Found : user_pref("extensions.delta.vrsnTs", "1.8.16.1617:28:18");
Line Found : user_pref("extensions.delta.vrsni", "1.8.16.16");
Line Found : user_pref("extensions.enabledAddons", "%7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0,ffxtlbr%40delta.com:1.5.0,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1");
Line Found : user_pref("extensions.funmoods.SimilarSitesStorage-pid2", "a005f81465588ef6");
Line Found : user_pref("extensions.funmoods.admin", false);
Line Found : user_pref("extensions.funmoods.aflt", "adknlg");
Line Found : user_pref("extensions.funmoods.cntry", "US");
Line Found : user_pref("extensions.funmoods.dfltLng", "");
Line Found : user_pref("extensions.funmoods.dfltSrch", true);
Line Found : user_pref("extensions.funmoods.excTlbr", false);
Line Found : user_pref("extensions.funmoods.hdrMd5", "7C3F20BACE7563B6430683AF06971409");
Line Found : user_pref("extensions.funmoods.hmpg", true);
Line Found : user_pref("extensions.funmoods.id", "480ea2a2000000000000001bfc68d107");
Line Found : user_pref("extensions.funmoods.instlDay", "15451");
Line Found : user_pref("extensions.funmoods.instlRef", "");
Line Found : user_pref("extensions.funmoods.lastVrsnTs", "1.5.11.1622:09:19");
Line Found : user_pref("extensions.funmoods.newTab", true);
Line Found : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=adknlg");
Line Found : user_pref("extensions.funmoods.noFFXTlbr", false);
Line Found : user_pref("extensions.funmoods.prdct", "funmoods");
Line Found : user_pref("extensions.funmoods.prtnrId", "funmoods");
Line Found : user_pref("extensions.funmoods.sg", "none");
Line Found : user_pref("extensions.funmoods.smplGrp", "none");
Line Found : user_pref("extensions.funmoods.srchPrvdr", "Search");
Line Found : user_pref("extensions.funmoods.tlbrId", "base");
Line Found : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=adknlg&q=");
Line Found : user_pref("extensions.funmoods.vrsn", "1.5.11.16");
Line Found : user_pref("extensions.funmoods.vrsnTs", "1.5.11.1622:09:19");
Line Found : user_pref("extensions.funmoods.vrsni", "1.5.11.16");
Line Found : user_pref("extensions.funmoods_i.aflt", "adknlg");
Line Found : user_pref("extensions.funmoods_i.dfltLng", "");
Line Found : user_pref("extensions.funmoods_i.dfltSrch", true);
Line Found : user_pref("extensions.funmoods_i.dnsErr", true);
Line Found : user_pref("extensions.funmoods_i.excTlbr", false);
Line Found : user_pref("extensions.funmoods_i.hmpg", true);
Line Found : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=adknlg");
Line Found : user_pref("extensions.funmoods_i.id", "480ea2a2000000000000001bfc68d107");
Line Found : user_pref("extensions.funmoods_i.instlDay", "15451");
Line Found : user_pref("extensions.funmoods_i.instlRef", "");
Line Found : user_pref("extensions.funmoods_i.newTab", true);
Line Found : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=adknlg");
Line Found : user_pref("extensions.funmoods_i.prdct", "funmoods");
Line Found : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
Line Found : user_pref("extensions.funmoods_i.smplGrp", "none");
Line Found : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
Line Found : user_pref("extensions.funmoods_i.tlbrId", "base");
Line Found : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=adknlg&q=");
Line Found : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
Line Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1622:09:19");
Line Found : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
Line Found : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"c:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\W[...]
Line Found : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Found : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=311903A1-787E-454B-9565-F40E5AFE85E8&n=77ed7af1&ind=2012052209&id=UXxdm011YYus&ptnrS=U[...]
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=311903A1-787E-454B-9565-F40E5AFE85E8&n=77ed7af1&ptnrS=UXxdm011YYus&si=maps4pc");
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.hp.enabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.hp.lastGuardTime", -1074855524);
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.hp.numGuards", 1);
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.initialized", true);
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.installDate", "2012052209");
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerId", "UXxdm011YYus");
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerSubId", "maps4pc");
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.success", true);
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.toolbarId", "311903A1-787E-454B-9565-F40E5AFE85E8");
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.lastActivePing", "1338936766174");
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.defaultSearch", true);
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.homePageEnabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.keywordEnabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.tabEnabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.searchHistory", "yahoo mail");
Line Found : user_pref("extensions.toolbar.mindspark._39Members_.weather.location", "95101");
Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "mapsgalaxy@mindspark.com");
Line Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "mapsgalaxy@mindspark.com");
 
-\\ Google Chrome v
 
[ File : C:\Users\Paul\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
 
*************************
 
AdwCleaner[R0].txt - [28504 octets] - [25/08/2013 14:20:14]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [28565 octets] ##########
 

-------------------------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
 
Database version: v2013.08.25.01
 
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16660
Paul :: HP-PC [administrator]
 
8/25/2013 2:23:11 PM
mbam-log-2013-08-25 (14-23-11).txt
 
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 211312
Time elapsed: 14 minute(s), 59 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
(end)
 

 

 



#4 Condobloke

Condobloke

    Outback Aussie @ 54.2101 N, 0.2906 W


  • Members
  • 5,949 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:58 PM

Posted 25 August 2013 - 08:35 PM

 
 
 
 
 
 
 
 
 
 
 
 
 
 

My apologies for not providing this link ::

http://www.bleepingcomputer.com/download/adwcleaner/

 

Did you run RKill ??

 

Please run AdwCleaner again and this time click on "CLEAN"

 

Next.... run ESET...........http://www.eset.com/us/online-scanner-popup/

then you will be prompted to click on

  esetsmartinstaller_enu.exe/.....Do so...

       .

        Check "YES, I accept the Terms of Use."

        Click the Start button.

        Accept any security warnings from your browser.

        Under scan settings, check "Scan Archives" and "Remove found threats"

        Click Advanced settings and select the following:

        Scan potentially unwanted applications

        Scan for potentially unsafe applications

        Enable Anti-Stealth technology

        ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.

        When the scan completes, click List Threats

        Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

        Click the Back button.

        Click the Finish button.

 

        NOTE:Sometimes if ESET finds no infections it will not create a log.


Edited by Condobloke, 25 August 2013 - 10:35 PM.

Condobloke ...Outback Australian  

 

fed up with Windows antics...??....LINUX IS THE ANSWER....I USE LINUX MINT 18.3  EXCLUSIVELY.

“A man travels the world in search of what he needs and returns home to find it."

It has been said that time heals all wounds. I don't agree. The wounds remain. Time - the mind, protecting its sanity - covers them with some scar tissue and the pain lessens, but it is never gone. Rose Kennedy


#5 penwright

penwright

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:58 AM

Posted 25 August 2013 - 09:25 PM

I wanted to take the time to thank you for helping me clean up my computer with Adwcleaner. It worked perfectly. But, first, I have to tell you what happened at install and scan.

 

After the scan was finished, I received a message from my antivirus that it wasn't a trusted application and the recommendation to have them erase it. I agreed. Then I tried downloading and installing Adwcleaner again, to no avail. No matter what web site I went to, I could not, successfullly, download it.

 

How I finally resolved this situation was to go into my antivirus and restore Adwcleaner back to it's original folder, which was, originally, on my desktop.

 

I opened it and ran a scan again. I finally got rid of all those pesky BO's, malware and other intrusive files, that my step son put on my computer, especially, Babylon.

 

After scanning and deleting all those files, Adwcleaner restarted my computer, then showed me what it got rid of.

 

Now, between, AVG's trial antivirus and Adwcleaner, my computer is running like it's new again.

 

I, personally, am a very happy, surfing camper again.

 

The really great part about all of this is, it is our 24th. Anniversary. What a great gift!!!



#6 Condobloke

Condobloke

    Outback Aussie @ 54.2101 N, 0.2906 W


  • Members
  • 5,949 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:58 PM

Posted 25 August 2013 - 09:52 PM

@ penwright....good to know !
 
 
StrobeStop...In addition to the above....
 
How is your PC running now......
 
Just to be Sure....
 
 
Download MiniToolBox, .....Save it to your desktop and run it.
Checkmark the following boxes:
List last 10 Event Viewer log
List Installed Programs
Click Go and copy / paste the result (Result.txt).
 
and...
 
Download Security Check from here or here and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Let us know how things are now !!

Edited by boopme, 25 August 2013 - 10:36 PM.

Condobloke ...Outback Australian  

 

fed up with Windows antics...??....LINUX IS THE ANSWER....I USE LINUX MINT 18.3  EXCLUSIVELY.

“A man travels the world in search of what he needs and returns home to find it."

It has been said that time heals all wounds. I don't agree. The wounds remain. Time - the mind, protecting its sanity - covers them with some scar tissue and the pain lessens, but it is never gone. Rose Kennedy


#7 StrobeStop

StrobeStop
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:12:58 AM

Posted 26 August 2013 - 10:22 PM

Hello.  I ran rkill first, before I ran any other tools.  My computer is running a lot faster.  However, the PC Fix Speed icon is still in the system tray and there is a desktop shortcut as well.  Thanks.

 

Okay here is the adwcleaner report after "CLEAN":

 

# AdwCleaner v3.001 - Report created 26/08/2013 at 17:55:10
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Paul - HP-PC
# Running from : C:\Users\Paul\Downloads\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\blekko toolbars
Folder Deleted : C:\ProgramData\PC Optimizer Pro
Folder Deleted : C:\ProgramData\SpeedMaxPc
Folder Deleted : C:\ProgramData\WeCareReminder
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Free Offers from Freeze.com
Folder Deleted : C:\Program Files\internethelper3.1
Folder Deleted : C:\Program Files\LyricsContainer
Folder Deleted : C:\Program Files\MapsGalaxy_39EI
Folder Deleted : C:\Program Files\MyPC Backup 
Folder Deleted : C:\Program Files\OApps
Folder Deleted : C:\Program Files\Playbryte
Folder Deleted : C:\Program Files\Red Sky
Folder Deleted : C:\Program Files\SearchProtect
Folder Deleted : C:\Users\Paul\AppData\Local\Conduit
Folder Deleted : C:\Users\Paul\AppData\Local\cre
Folder Deleted : C:\Users\Paul\AppData\Local\DownTango
Folder Deleted : C:\Users\Paul\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Paul\AppData\Local\visualbeeexe
Folder Deleted : C:\Users\Paul\AppData\Local\Temp\Smartbar
Folder Deleted : C:\Users\Paul\AppData\Local\Temp\CT3286042
Folder Deleted : C:\Users\Paul\AppData\LocalLow\adawaretb
Folder Deleted : C:\Users\Paul\AppData\LocalLow\AVG Security Toolbar
Folder Deleted : C:\Users\Paul\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\Paul\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Paul\AppData\LocalLow\delta
Folder Deleted : C:\Users\Paul\AppData\LocalLow\internethelper3.1
Folder Deleted : C:\Users\Paul\AppData\LocalLow\MapsGalaxy_39EI
Folder Deleted : C:\Users\Paul\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Paul\AppData\LocalLow\Toolbar4
Folder Deleted : C:\Users\Paul\AppData\Roaming\Betcat
Folder Deleted : C:\Users\Paul\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\Paul\AppData\Roaming\DSite
Folder Deleted : C:\Users\Paul\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\Paul\AppData\Roaming\SearchProtect
Folder Deleted : C:\Users\Paul\AppData\Roaming\SpeedMaxPc
Folder Deleted : C:\Users\Paul\AppData\Roaming\Systweak
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\adawaretb
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Smartbar
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\CT3287808
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\CT3289663
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\CT3289847
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\CT3286042
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\ffxtlbr@delta.com
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\plugin@getwebcake.com
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\{01e86e69-a2f8-48a0-b068-83869bdba3d0}
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\{07cbf788-1359-421b-a4e3-5a8d041b90a3}
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\{739df940-c5ee-4bab-9d7e-270894ae687a}
Folder Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\{9ed31f84-c8b3-4926-b950-dff74047ff79}
File Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\Extensions\addon@defaulttab.com.xpi
File Deleted : C:\END
File Deleted : C:\Users\Paul\AppData\Roaming\BabMaint.exe
File Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\searchplugins\Babylon.xml
File Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\searchplugins\search.xml
File Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\searchplugins\Web Search.xml
File Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\bProtector_extensions.rdf
File Deleted : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\user.js
File Deleted : C:\Users\Paul\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage
File Deleted : C:\Users\Paul\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal
File Deleted : C:\Windows\Tasks\DSite.job
File Deleted : C:\Windows\System32\Tasks\DSite
File Deleted : C:\Windows\System32\Tasks\EPUpdater
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bcjagnifjocnddgeknajocbkkhlgibem
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{182995D8-3544-4963-BCBE-0936290BFE67}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{182995D8-3544-4963-BCBE-0936290BFE67}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77F8C261-B422-4BE7-9706-445C838CD920}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{77F8C261-B422-4BE7-9706-445C838CD920}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\App24x7Help_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\App24x7Help_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Key Deleted : HKCU\Software\5fede8ce53ebd43
Key Deleted : HKLM\SOFTWARE\5fede8ce53ebd43
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\BabylonToolbar
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\delta LTD
Key Deleted : HKCU\Software\dsiteproducts
Key Deleted : HKCU\Software\pc optimizer pro
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\MapsGalaxy_39EI
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\Software\Uniblue\DriverScanner
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v10.0.9200.16660
 
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
 
-\\ Mozilla Firefox v20.0.1 (en-US)
 
[ File : C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\hbpese7h.default\prefs.js ]
 
Line Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Deleted : user_pref("extensions.BabylonToolbar.admin", false);
Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "orgnl");
Line Deleted : user_pref("extensions.BabylonToolbar.bbDpng", 5);
Line Deleted : user_pref("extensions.BabylonToolbar.cntry", "US");
Line Deleted : user_pref("extensions.BabylonToolbar.dfltSrch", false);
Line Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar.hdrMd5", "45B45E1E2ECF3E3F905CF1820AB961F6");
Line Deleted : user_pref("extensions.BabylonToolbar.hmpg", false);
Line Deleted : user_pref("extensions.BabylonToolbar.lastActv", "19");
Line Deleted : user_pref("extensions.BabylonToolbar.lastDP", 5);
Line Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "");
Line Deleted : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "12.0");
Line Deleted : user_pref("extensions.BabylonToolbar.newTab", true);
Line Deleted : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP");
Line Deleted : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar.propectorlck", 77515525);
Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 1);
Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 1);
Line Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "free");
Line Deleted : user_pref("extensions.crossrider.bic", "136c2394292d7f52a9100c3cef17b6bb");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.InstallationThankYouPage", true);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.InstallationTime", 1334691556);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.InstallationUserSettings.searchUserConifrmation", false);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.InstallationUserSettings.setHomepage", false);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.InstallationUserSettings.setNewTab", false);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.InstallationUserSettings.setSearch", false);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.active", true);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.addressbar", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.affid", "0");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.backgroundjs", "\n\n_GPL_PID = 21;\nfunction parse_url(str,component){var key=['source','scheme','authority','userInfo','user','pass','host','port','relati[...]
Line Deleted : user_pref("extensions.crossriderapp2258.2258.backgroundver", 8);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.can_run_bg_code", true);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.certdomaininstaller", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.changeprevious", false);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.InstallationTime.value", "1334691556");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_aoi.value", "1334691556");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_crr.value", "1335058875");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_geo.expiration", "Tue Apr 24 2012 14:33:50 GMT-0700 (Pacific Daylight Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_geo.value", "%7B%22geoplugin_city%22%3A%22Sunnyvale%22%2C%22geoplugin_region%22%3A%22CA%22%2C%22geoplugin_areaCode%22%3A408%2C%22geoplugin_dmaC[...]
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_hotfix20111102645.value", "%221%22");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_installer_params.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_installer_params.value", "%7B%22source_id%22%3A%224caa425a93dbdb1f6d0AQ3204%22%2C%22sub_id%22%3A%22default%22%2C%22uzid%22%3A%2227782%26subid%3[...]
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_parent_zoneid.value", "%2227782%22");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_zoneid.value", "%2230787%22");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.description", "I Want This!");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.domain", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.emailsig", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.enablesearch", false);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.exposesites", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.fbremoteurl", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.group", 0);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.homepage", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.iframe", false);
Line Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT-0800 (Pacific Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%22CD552FD62487471EA146A5B84F2EFD23IE%22%2C%22installer_verifier%22%3A%223e3a825c242066a1[...]
Line Deleted : user_pref("extensions.crossriderapp2258.2258.js", "\n\nvar _GPL_PID = 21;\n\n(function($) {   \n\n  $.geoplugin = function(options) {\n    var baseCurrency = \"USD\";\n    var address = null;\n    var[...]
Line Deleted : user_pref("extensions.crossriderapp2258.2258.manifesturl", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.name", "I Want This");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.newtab", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.opensearch", "");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_13.code", "(function(B){b.selectedText=function(f,a){function c(){if(window.getSelection)return window.getSelection();if(document.getSelecti[...]
Line Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_13.name", "CrossriderAppUtils");
Line Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_13.ver", 1);
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.bbDpng", "23");
Line Deleted : user_pref("extensions.delta.cntry", "US");
Line Deleted : user_pref("extensions.delta.dfltLng", "en");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.hdrMd5", "91D8EBE011C9CE1312CD84E7303183A3");
Line Deleted : user_pref("extensions.delta.id", "480ea2a2000000000000001bfc68d107");
Line Deleted : user_pref("extensions.delta.instlDay", "15826");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.lastVrsnTs", "1.8.16.1617:28:18");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.sg", "azb");
Line Deleted : user_pref("extensions.delta.smplGrp", "azb");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.16.16");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.16.1617:28:18");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.16.16");
Line Deleted : user_pref("extensions.enabledAddons", "%7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0,ffxtlbr%40delta.com:1.5.0,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1");
Line Deleted : user_pref("extensions.funmoods.SimilarSitesStorage-pid2", "a005f81465588ef6");
Line Deleted : user_pref("extensions.funmoods.admin", false);
Line Deleted : user_pref("extensions.funmoods.aflt", "adknlg");
Line Deleted : user_pref("extensions.funmoods.cntry", "US");
Line Deleted : user_pref("extensions.funmoods.dfltLng", "");
Line Deleted : user_pref("extensions.funmoods.dfltSrch", true);
Line Deleted : user_pref("extensions.funmoods.excTlbr", false);
Line Deleted : user_pref("extensions.funmoods.hdrMd5", "7C3F20BACE7563B6430683AF06971409");
Line Deleted : user_pref("extensions.funmoods.hmpg", true);
Line Deleted : user_pref("extensions.funmoods.id", "480ea2a2000000000000001bfc68d107");
Line Deleted : user_pref("extensions.funmoods.instlDay", "15451");
Line Deleted : user_pref("extensions.funmoods.instlRef", "");
Line Deleted : user_pref("extensions.funmoods.lastVrsnTs", "1.5.11.1622:09:19");
Line Deleted : user_pref("extensions.funmoods.newTab", true);
Line Deleted : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=adknlg");
Line Deleted : user_pref("extensions.funmoods.noFFXTlbr", false);
Line Deleted : user_pref("extensions.funmoods.prdct", "funmoods");
Line Deleted : user_pref("extensions.funmoods.prtnrId", "funmoods");
Line Deleted : user_pref("extensions.funmoods.sg", "none");
Line Deleted : user_pref("extensions.funmoods.smplGrp", "none");
Line Deleted : user_pref("extensions.funmoods.srchPrvdr", "Search");
Line Deleted : user_pref("extensions.funmoods.tlbrId", "base");
Line Deleted : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=adknlg&q=");
Line Deleted : user_pref("extensions.funmoods.vrsn", "1.5.11.16");
Line Deleted : user_pref("extensions.funmoods.vrsnTs", "1.5.11.1622:09:19");
Line Deleted : user_pref("extensions.funmoods.vrsni", "1.5.11.16");
Line Deleted : user_pref("extensions.funmoods_i.aflt", "adknlg");
Line Deleted : user_pref("extensions.funmoods_i.dfltLng", "");
Line Deleted : user_pref("extensions.funmoods_i.dfltSrch", true);
Line Deleted : user_pref("extensions.funmoods_i.dnsErr", true);
Line Deleted : user_pref("extensions.funmoods_i.excTlbr", false);
Line Deleted : user_pref("extensions.funmoods_i.hmpg", true);
Line Deleted : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=adknlg");
Line Deleted : user_pref("extensions.funmoods_i.id", "480ea2a2000000000000001bfc68d107");
Line Deleted : user_pref("extensions.funmoods_i.instlDay", "15451");
Line Deleted : user_pref("extensions.funmoods_i.instlRef", "");
Line Deleted : user_pref("extensions.funmoods_i.newTab", true);
Line Deleted : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=adknlg");
Line Deleted : user_pref("extensions.funmoods_i.prdct", "funmoods");
Line Deleted : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
Line Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
Line Deleted : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
Line Deleted : user_pref("extensions.funmoods_i.tlbrId", "base");
Line Deleted : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=adknlg&q=");
Line Deleted : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16");
Line Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1622:09:19");
Line Deleted : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16");
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"c:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\W[...]
Line Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=311903A1-787E-454B-9565-F40E5AFE85E8&n=77ed7af1&ind=2012052209&id=UXxdm011YYus&ptnrS=U[...]
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=311903A1-787E-454B-9565-F40E5AFE85E8&n=77ed7af1&ptnrS=UXxdm011YYus&si=maps4pc");
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.hp.lastGuardTime", -1074855524);
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.hp.numGuards", 1);
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.initialized", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.installation.installDate", "2012052209");
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerId", "UXxdm011YYus");
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerSubId", "maps4pc");
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.installation.success", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.installation.toolbarId", "311903A1-787E-454B-9565-F40E5AFE85E8");
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.lastActivePing", "1338936766174");
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.options.defaultSearch", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.options.homePageEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.options.keywordEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.options.tabEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.searchHistory", "yahoo mail");
Line Deleted : user_pref("extensions.toolbar.mindspark._39Members_.weather.location", "95101");
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "mapsgalaxy@mindspark.com");
Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "mapsgalaxy@mindspark.com");
 
-\\ Google Chrome v
 
[ File : C:\Users\Paul\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted : urls_to_restore_on_startup
 
*************************
 
AdwCleaner[R0].txt - [28646 octets] - [25/08/2013 14:20:14]
AdwCleaner[R1].txt - [28709 octets] - [26/08/2013 17:52:06]
AdwCleaner[S0].txt - [29335 octets] - [26/08/2013 17:55:10]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [29396 octets] ##########
 
-----------------------
 
Here is the ESET scan log:
 
C:\AdwCleaner\Quarantine\C\Users\Paul\AppData\LocalLow\MapsGalaxy_39EI\Installr\Cache\0102D57C.exe.vir a variant of Win32/Toolbar.MyWebSearch.O application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Users\Paul\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe.vir Win32/DownWare.E application cleaned by deleting - quarantined
C:\Program Files\FLVPlayer\FLVPlayer.exe a variant of Win32/InstallCore.A application cleaned by deleting - quarantined
C:\Users\Paul\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M5K7YPCF\PCFixSpeedSetup_253[1] multiple threats cleaned by deleting - quarantined
C:\Users\Paul\AppData\Local\Temp\352ED16A-BAB0-7891-AA41-3442818F6147\BabMaint.exe a variant of Win32/Toolbar.Babylon.I application cleaned by deleting - quarantined
C:\Users\Paul\AppData\Local\Temp\is-FBEBE.tmp\setup.exe a variant of Win32/Adware.MediaFinder.F application cleaned by deleting - quarantined
C:\Users\Paul\AppData\Local\Temp\is357113909\PCFixSpeedSetup.exe multiple threats cleaned by deleting - quarantined
C:\Users\Paul\AppData\Local\Temp\is357113909\uninstaller.exe a variant of Win32/InstallCore.AZ application cleaned by deleting - quarantined
C:\Users\Paul\AppData\Roaming\Video Player Packages\uninstaller.exe a variant of Win32/InstallCore.AZ application cleaned by deleting - quarantined
C:\Users\Paul\Downloads\dolphin.exe a variant of Win32/InstallIQ.A application cleaned by deleting - quarantined
C:\Users\Paul\Downloads\FLVPlayerSetup.exe a variant of Win32/InstallCore.R application cleaned by deleting - quarantined
C:\Users\Paul\Downloads\The_Texas_Chainsaw_Massacre_2003_720p_BRRip_x264-HDLiTE.exe multiple threats cleaned by deleting - quarantined
 

----------------------

 

Here is the MiniToolbox results:

 

MiniToolBox by Farbar  Version: 13-07-2013

Ran by Paul (administrator) on 26-08-2013 at 19:49:24
Running from "C:\Users\Paul\Desktop"
Microsoft Windows 7 Ultimate  Service Pack 1 (X86)
Boot Mode: Normal
***************************************************************************
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (08/24/2013 06:11:09 PM) (Source: System Restore) (User: )
Description: An unspecified error occurred during System Restore: (Restore Operation). Additional information: 0xc0000121.
 
Error: (08/24/2013 05:28:47 PM) (Source: Application Hang) (User: )
Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 638
 
Start Time: 01cea1268964b9c0
 
Termination Time: 32
 
Application Path: C:\Windows\Explorer.EXE
 
Report Id: 49c2c241-0d1d-11e3-bf92-001bfc68d107
 
Error: (08/24/2013 04:38:27 PM) (Source: CltMngSvc) (User: )
Description: CltMngSvcServiceInstall: Fail to Start serviceSearch Protect by Conduit Updater (Error: 1056)
 
Error: (08/24/2013 04:37:11 PM) (Source: CltMngSvc) (User: )
Description: CltMngSvcServiceInstall: Fail to Start serviceSearch Protect by Conduit Updater (Error: 1056)
 
Error: (08/24/2013 02:51:33 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (08/15/2013 08:25:07 PM) (Source: Microsoft Security Client Setup) (User: HP-PC)
Description: HRESULT:0x8004FF0A
Description:Upgrade installation canceled. To upgrade later, run the Security Essentials Upgrade Wizard again. Error code:0x8004FF0A.
 
Error: (08/15/2013 08:23:48 PM) (Source: Microsoft Security Client Setup) (User: HP-PC)
Description: HRESULT:0x8004FF0A
Description:Upgrade installation canceled. To upgrade later, run the Security Essentials Upgrade Wizard again. Error code:0x8004FF0A.
 
Error: (08/15/2013 08:18:20 PM) (Source: Application Error) (User: )
Description: Faulting application name: DefaultTabSearch.exe, version: 0.0.0.0, time stamp: 0x51a70ae7
Faulting module name: DefaultTabSearch.exe, version: 0.0.0.0, time stamp: 0x51a70ae7
Exception code: 0xc0000005
Fault offset: 0x00002db0
Faulting process id: 0xad0
Faulting application start time: 0xDefaultTabSearch.exe0
Faulting application path: DefaultTabSearch.exe1
Faulting module path: DefaultTabSearch.exe2
Report Id: DefaultTabSearch.exe3
 
Error: (08/15/2013 08:09:52 PM) (Source: ESENT) (User: )
Description: Windows (2908) Windows: An attempt to write to the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log" at offset 0 (0x0000000000000000) for 1048576 (0x00100000) bytes failed after Windows0 seconds with system error 1450 (0x000005aa): "Insufficient system resources exist to complete the requested service. ".  The write operation will fail with error -1011 (0xfffffc0d).  If this error persists then the file may be damaged and may need to be restored from a previous backup.
 
Error: (08/15/2013 06:58:10 PM) (Source: Application Hang) (User: )
Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: dd8
 
Start Time: 01ce99c1e2908130
 
Termination Time: 327
 
Application Path: C:\Windows\Explorer.EXE
 
Report Id: 41a3a911-0617-11e3-af7e-001bfc68d107
 
 
System errors:
=============
Error: (08/25/2013 02:13:30 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Windows 7 (KB2834140).
 
Error: (08/25/2013 02:13:30 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80242016: Cumulative Security Update for Internet Explorer 9 for Windows 7 (KB2862772).
 
Error: (08/24/2013 10:38:58 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Microsoft .NET Framework 4 on XP, Server 2003, Vista, Windows 7, Server 2008 x86 (KB2835393).
 
Error: (08/24/2013 10:38:58 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Windows 7 (KB2849470).
 
Error: (08/24/2013 10:37:12 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Windows 7 (KB2862966).
 
Error: (08/24/2013 10:36:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Windows 7 (KB2859537).
 
Error: (08/24/2013 10:32:35 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Microsoft .NET Framework 4 on XP, Server 2003, Vista, Windows 7, Server 2008 x86 (KB2840628).
 
Error: (08/24/2013 10:32:35 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Windows 7 (KB2868623).
 
Error: (08/24/2013 10:31:36 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Windows 7 (KB2803821).
 
Error: (08/24/2013 10:31:36 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 SP1 x86 (KB2844286).
 
 
Microsoft Office Sessions:
=========================
Error: (08/24/2013 06:11:09 PM) (Source: System Restore)(User: )
Description: Restore Operation0xc0000121
 
Error: (08/24/2013 05:28:47 PM) (Source: Application Hang)(User: )
Description: Explorer.EXE6.1.7601.1756763801cea1268964b9c032C:\Windows\Explorer.EXE49c2c241-0d1d-11e3-bf92-001bfc68d107
 
Error: (08/24/2013 04:38:27 PM) (Source: CltMngSvc)(User: )
Description: CltMngSvcServiceInstall: Fail to Start serviceSearch Protect by Conduit Updater (Error: 1056)
 
Error: (08/24/2013 04:37:11 PM) (Source: CltMngSvc)(User: )
Description: CltMngSvcServiceInstall: Fail to Start serviceSearch Protect by Conduit Updater (Error: 1056)
 
Error: (08/24/2013 02:51:33 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Speed Analysis 2\BackgroundHost64.exe
 
Error: (08/15/2013 08:25:07 PM) (Source: Microsoft Security Client Setup)(User: HP-PC)
Description: HRESULT:0x8004FF0A
Description:Upgrade installation canceled. To upgrade later, run the Security Essentials Upgrade Wizard again. Error code:0x8004FF0A.
 
Error: (08/15/2013 08:23:48 PM) (Source: Microsoft Security Client Setup)(User: HP-PC)
Description: HRESULT:0x8004FF0A
Description:Upgrade installation canceled. To upgrade later, run the Security Essentials Upgrade Wizard again. Error code:0x8004FF0A.
 
Error: (08/15/2013 08:18:20 PM) (Source: Application Error)(User: )
Description: DefaultTabSearch.exe0.0.0.051a70ae7DefaultTabSearch.exe0.0.0.051a70ae7c000000500002db0ad001ce9a2f376e21e0C:\Program Files\DefaultTab\DefaultTabSearch.exeC:\Program Files\DefaultTab\DefaultTabSearch.exe7fbe75d0-0622-11e3-b519-001bfc68d107
 
Error: (08/15/2013 08:09:52 PM) (Source: ESENT)(User: )
Description: Windows2908Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log0 (0x0000000000000000)1048576 (0x00100000)-1011 (0xfffffc0d)1450 (0x000005aa)Insufficient system resources exist to complete the requested service. 0
 
Error: (08/15/2013 06:58:10 PM) (Source: Application Hang)(User: )
Description: Explorer.EXE6.1.7601.17567dd801ce99c1e2908130327C:\Windows\Explorer.EXE41a3a911-0617-11e3-af7e-001bfc68d107
 
 
CodeIntegrity Errors:
===================================
  Date: 2012-12-28 13:38:34.775
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-12-28 13:38:34.456
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-12-28 13:38:34.110
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-12-28 13:38:33.791
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-12-28 13:38:33.455
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-12-28 13:38:32.984
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-12-28 13:38:32.635
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-12-28 13:38:32.288
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-12-28 13:38:31.934
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-12-28 13:38:31.610
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
 
=========================== Installed Programs ============================
 
µTorrent (Version: 3.2.3.28705)
µTorrent (Version: 3.3.1.30017)
7-Zip 9.20
Adobe AIR (Version: 3.2.0.2070)
Adobe Flash Player 11 ActiveX (Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (Version: 11.8.800.94)
Adobe Reader XI (11.0.03) (Version: 11.0.03)
AMD AVIVO Codecs (Version: 11.6.0.10914)
AMD Catalyst Install Manager (Version: 3.0.842.0)
AMD MCE Encoder (Version: 11.6.0.10914)
Apple Application Support (Version: 2.3)
Apple Mobile Device Support (Version: 5.1.1.4)
Apple Software Update (Version: 2.1.3.127)
Bonjour (Version: 3.0.0.10)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center InstallProxy (Version: 2011.0908.1355.23115)
CDBurnerXP (Version: 4.3.8.2631)
Google Chrome (Version: 29.0.1547.57)
Google Earth (Version: 7.1.1.1888)
Google Talk Plugin (Version: 4.4.2.14502)
Google Update Helper (Version: 1.3.21.153)
iCloud (Version: 1.1.0.40)
iTunes (Version: 10.6.1.7)
Java 7 Update 7 (Version: 7.0.70)
Java Auto Updater (Version: 2.1.9.0)
K-Lite Codec Pack 6.6.6 (Full) (Version: 6.6.6)
Living 3D Dolphin (Version: 1.0.2)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
McAfee Security Scan Plus (Version: 3.0.318.3)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Security Client (Version: 4.3.0215.0)
Microsoft Security Essentials (Version: 4.3.215.0)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
MobileMe Control Panel (Version: 3.1.8.0)
Mozilla Firefox 20.0.1 (x86 en-US) (Version: 20.0.1)
Mozilla Maintenance Service (Version: 20.0.1)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
NVIDIA Drivers
OpenOffice.org 3.2 (Version: 3.2.9502)
PC Fix Speed 1.2.0.24 (Version: 1.2.0.24)
Picasa 3 (Version: 3.9)
QuickTime (Version: 7.73.80.64)
Safari (Version: 5.34.55.3)
Soft Data Fax Modem with SmartCP (Version: 7.74.00)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Video Player
Video Player Packages
 
**** End of log ****
 

------------------------------

 

Here are the results from security check:

 

 Results of screen317's Security Check version 0.99.73  
 Windows 7 Service Pack 1 x86 (UAC is enabled)  
 Internet Explorer 10  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Microsoft Security Essentials   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:````````` 
 Malwarebytes Anti-Malware version 1.75.0.1300  
 Java 7 Update 7  
 Java version out of Date! 
 Adobe Flash Player  11.8.800.94  
 Adobe Reader XI  
 Mozilla Firefox 20.0.1 Firefox out of Date!  
 Google Chrome 27.0.1453.93  
 Google Chrome 29.0.1547.57  
 Google Chrome Extensions...  
````````Process Check: objlist.exe by Laurent````````  
 Microsoft Security Essentials MSMpEng.exe 
 Microsoft Security Essentials msseces.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 1% 
````````````````````End of Log`````````````````````` 


#8 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:06:58 PM

Posted 26 August 2013 - 10:38 PM

If the program is still seen, try Revo Uninstaller -

 

¦ Please download and install Revo Uninstaller Free
¦ Double click Revo Uninstaller to run it.
¦ From the list of programs double click on The Program to remove
¦ When prompted if you want to uninstall click Yes.
¦ For most programs - Be sure the Moderate option is selected then click Next.
¦ The program will run, If prompted again click Yes
¦ when the built-in uninstaller is finished click on Next.
¦ Once the program has searched for leftovers click Next.
¦ NOTE - Check/tick the bolded items only on the list then click Delete
¦ when prompted click on Yes and then on next.
¦ put a check on any folders that are found and select delete
¦ when prompted select yes then on next
¦ Once done click Finish.

 

Try this option for very hard to remove programs only -

 

Thanks -



#9 StrobeStop

StrobeStop
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:12:58 AM

Posted 27 August 2013 - 07:44 PM

Thank you so much!!!  Our computer is now running great.  



#10 Condobloke

Condobloke

    Outback Aussie @ 54.2101 N, 0.2906 W


  • Members
  • 5,949 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:58 PM

Posted 27 August 2013 - 09:50 PM

You Java is out of date....please visit ::

 

http://www.java.com/inc/BrowserRedirect1.jsp

(Java Version7 Update25)

 

( be sure to remove any remaining old versions via add/remove )

 

 

and also ...Firefox ::

 

http://filehippo.com/download_firefox/15733/

 

 

Regards,


Condobloke ...Outback Australian  

 

fed up with Windows antics...??....LINUX IS THE ANSWER....I USE LINUX MINT 18.3  EXCLUSIVELY.

“A man travels the world in search of what he needs and returns home to find it."

It has been said that time heals all wounds. I don't agree. The wounds remain. Time - the mind, protecting its sanity - covers them with some scar tissue and the pain lessens, but it is never gone. Rose Kennedy


#11 StrobeStop

StrobeStop
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:12:58 AM

Posted 28 August 2013 - 07:28 PM

Okay. I upgraded both.  Thanks.  Everything is fixed now thanks to you guys!!



#12 Condobloke

Condobloke

    Outback Aussie @ 54.2101 N, 0.2906 W


  • Members
  • 5,949 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:58 PM

Posted 28 August 2013 - 09:20 PM

Always a Pleasure !!  :bananas:


Condobloke ...Outback Australian  

 

fed up with Windows antics...??....LINUX IS THE ANSWER....I USE LINUX MINT 18.3  EXCLUSIVELY.

“A man travels the world in search of what he needs and returns home to find it."

It has been said that time heals all wounds. I don't agree. The wounds remain. Time - the mind, protecting its sanity - covers them with some scar tissue and the pain lessens, but it is never gone. Rose Kennedy





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users