Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspicious of infection after running Eset/malwarebytes


  • Please log in to reply
10 replies to this topic

#1 steelkobra03

steelkobra03

  • Members
  • 101 posts
  • OFFLINE
  •  
  • Local time:11:39 AM

Posted 01 April 2014 - 11:11 PM

I just currently removed a few infected files from my computer but i'm still suspicious due to slow responding apps after a restart. I have a gaming pc setup and I know it's not supposed to run any where near this slow. I would genuinely appreciate the help please! Thank you!



BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,591 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:39 AM

Posted 02 April 2014 - 08:28 AM

Please post the complete results of your Malwarebytes scan for review.

To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 1)
  • Open Malwarebytes Anti-Malware.
  • Click the History Tab at the top and select Application Logs.
  • Select (check) the box next to Scan Log. Choose the most current scan.
  • Click the View button.
  • Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)
  • Open Malwarebytes Anti-Malware.
  • Click the Scan Tab at the top.
  • Click the View detailed log link on the right.
  • Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
To retrieve the Malwarebytes Anti-Malware 1.75 scan log information, launch MBAM.
  • Click the Logs Tab at the top.
  • The log will be named by the date of scan in the following format: mbam-log-yyyy-mm-dd
    -- If you have previously used MBAM, there may be several logs showing in the list.
  • Click on the log name to highlight it.
  • Go to the bottom and click on Open.
  • The log will automatically open in Notepad as a text file.
  • Go to Edit and choose Select all.
  • Go back to Edit and choose Copy or right-click on the highlighted text and choose Copy from there.
  • Come back to this thread, click Add Reply, then right-click and choose Paste.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
-- XP: C:\Documents and Settings\<Username>\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
-- Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 steelkobra03

steelkobra03
  • Topic Starter

  • Members
  • 101 posts
  • OFFLINE
  •  
  • Local time:11:39 AM

Posted 02 April 2014 - 01:10 PM

Malwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.org
 
Database version: v2014.04.01.10
 
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Qp33zy :: QP33ZY [administrator]
 
Protection: Enabled
 
4/1/2014 8:23:26 PM
mbam-log-2014-04-01 (20-23-26).txt
 
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 440195
Time elapsed: 1 hour(s), 26 minute(s), 19 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 1
C:\Program Files (x86)\ASUS\AASP\1.00.78\PowNap.dll (Trojan.Boaxxe) -> Delete on reboot.
 
Registry Keys Detected: 2
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
HKCU\Software\Conduit\ValueApps (PUP.Optional.ValueApps.A) -> Quarantined and deleted successfully.
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 1
C:\Users\Qp33zy\AppData\Local\Temp\CT3288691 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
 
Files Detected: 1
C:\Program Files (x86)\ASUS\AASP\1.00.78\PowNap.dll (Trojan.Boaxxe) -> Delete on reboot.
 
(end)
 


#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,591 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:39 AM

Posted 02 April 2014 - 01:40 PM


Your Malwarebytes Anti-Malware log indicates some files will be deleted on reboot. If Malwarebytes encounters a file that is difficult to remove, you need to restart the computer so the malware can be fully removed. Failure to reboot normally will prevent Malwarebytes from removing all the malware. If you have not rebooted, make sure you do this. When done, continue as follows:
  • Rescan again (THREAT SCAN) in normal mode.
  • Don't forgot to check for database definition updates through the program's interface (preferable method) before scanning.
  • Make sure that everything detected is checked and then click the Remove Selected button.
  • Then click the Logs tab and copy/paste the contents of the new report in your next reply. If you did reboot, then rescan again anyway and post a new log.
BTW, in case you are not aware....Malwarebytes Anti-Malware has been updated to v2.00.0.1000. You can download and install the most current version from here (alternate download link).
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#5 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,591 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:39 AM

Posted 02 April 2014 - 01:40 PM

After doing the above...continue as follows:

Please download and use the following tools (in the order listed) which will search for and remove many potentially unwanted programs (PUPs), adware, toolbars, browser hijackers, extensions, add-ons and other junkware as well as related registry entries (values, keys) and remnants.

RKill created by Grinler (aka Lawrence Abrams), the site owner of BleepingComputer.
AdwCleaner created by Xplode.
Junkware Removal Tool created by thisisu.

1. Double-click on RKill to launch the tool. A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully. A log file will be created and saved to the root directory, C:\RKill.log. Copy and paste the contents of RKill.log in your next reply.

Important: Do not reboot your computer until you complete the next step.

2. Double-click on AdwCleaner.exe to run the tool.
Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
-- Note: The contents of the AdwCleaner log file may be confusing. Unless you see a program name that you recognize and know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on each one and uncheck any items you want to keep (except you cannot uncheck Chrome and Firefox preferences lines).


Close all open programs and shut down any protection/security software to avoid potential conflicts.

3. Double-click on JRT.exe to run the tool.
Vista/Windows 7/8 users right-click and select Run As Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log file named JRT.txt will automatically open and be saved to your Desktop.
  • Copy and paste the contents of JRT.txt in your next reply.

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#6 steelkobra03

steelkobra03
  • Topic Starter

  • Members
  • 101 posts
  • OFFLINE
  •  
  • Local time:11:39 AM

Posted 02 April 2014 - 03:55 PM

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 4/2/2014
Scan Time: 2:39:52 PM
Logfile: 
Administrator: Yes
 
Version: 2.00.0.1000
Malware Database: v2014.04.02.07
Rootkit Database: v2014.03.27.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
 
OS: Windows Vista Service Pack 2
CPU: x64
File System: NTFS
User: Qp33zy
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 313043
Time Elapsed: 18 min, 59 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 2
PUP.Optional.Conduit.A, HKU\S-1-5-21-3566799651-3591339517-3716990925-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\FF, Quarantined, [e8a70b1a90eb49eded1b6a1d40c32dd3], 
PUP.Optional.ValueApps.A, HKU\S-1-5-21-3566799651-3591339517-3716990925-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\ValueApps, Quarantined, [67282302b7c475c1f3c2d19aef13e51b], 
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 2
PUP.Optional.ValueApps.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\valueApps, Delete-on-Reboot, [d7b8af76dba034024765c692010104fc], 
PUP.Optional.ValueApps.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\valueApps\CT3288691, Quarantined, [d7b8af76dba034024765c692010104fc], 
 
Files: 18
PUP.Optional.Conduit.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\searchplugins\conduit.xml, Quarantined, [3c53d74e0d6ef93ddb298ed2946ee11f], 
PUP.Optional.CrossRider.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "135ea9c9e2fc06b841d1d5e5a6c2f3e2");), Replaced,[eba41a0baad1c37369070a31887ca759]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.admin", false);), Replaced,[76197baa1d5e2115e49c94a759ab54ac]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.aflt", "babsst");), Replaced,[602f44e10378dc5af0902c0f9f658080]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");), Replaced,[d0bfa5802457fd39dca4b487d331619f]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.dfltLng", "en");), Replaced,[dfb0d550cdaece68e69a152663a1dc24]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.excTlbr", false);), Replaced,[c8c70f16f4876acc81ff0833857f629e]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.id", "4cd9ffb5000000000000002354917d6e");), Replaced,[bdd29095057688aebec23b0024e0946c]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.instlDay", "15650");), Replaced,[5f3035f0a4d7a98deb95e3584db73fc1]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.instlRef", "sst");), Replaced,[d8b779ac91ea5dd9a3ddba8101038e72]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");), Replaced,[870835f0fb80ea4ccbb5be7db84c4bb5]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.prtnrId", "babylon");), Replaced,[7a15b86def8cf83e740cd566788ca858]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.tlbrId", "tb9");), Replaced,[840b79acee8d2e0868183dfeda2a1ae6]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "http://search.babylon.com/?babsrc=TB_def&mntrId=4cd9ffb5000000000000002354917d6e&q=");), Replaced,[e0af121382f9b185631dad8e669ed12f]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.vrsn", "1.8.3.8");), Replaced,[2e6174b14437b185285846f5f3117a86]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.vrsni", "1.8.3.8");), Replaced,[a5eaf33292e9f442740c9f9c4eb611ef]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), Replaced,[2b640f16d8a356e0146c69d291734db3]
PUP.Optional.Babylon.A, C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.3.818:06:56");), Replaced,[a8e768bd6714f541f789de5de91b8878]
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)Rkill 2.6.5 by Lawrence Abrams (Grinler)
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 04/02/2014 02:47:45 PM in x64 mode.
Windows Version: Windows Vista ™ Ultimate Service Pack 2
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * No malware processes found to kill.
 
Checking Registry for malware related settings:
 
 * No issues found in the Registry.
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * Windows Firewall Disabled
 
   [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
   "EnableFirewall" = dword:00000000
 
Checking Windows Service Integrity: 
 
 * No issues found.
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * HOSTS file entries found: 
 
  127.0.0.1       localhost
 
Program finished at: 04/02/2014 02:50:42 PM
Execution time: 0 hours(s), 2 minute(s), and 56 seconds(s)
 
 
# AdwCleaner v3.023 - Report created 02/04/2014 at 15:06:02
# Updated 01/04/2014 by Xplode
# Operating System : Windows ™ Vista Ultimate Service Pack 2 (64 bits)
# Username : Qp33zy - QP33ZY
# Running from : C:\Users\Qp33zy\Favorites\Downloads\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
[!] Folder Deleted : C:\ProgramData\Babylon
[!] Folder Deleted : C:\ProgramData\Conduit
[!] Folder Deleted : C:\Program Files (x86)\Conduit
[!] Folder Deleted : C:\Program Files (x86)\DivX_Browser_Bar
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Local\Conduit
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Local\PackageAware
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Local\SwvUpdater
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Local\Zoom_Downloader
[!] Folder Deleted : C:\Users\Qp33zy\AppData\LocalLow\boost_interprocess
[!] Folder Deleted : C:\Users\Qp33zy\AppData\LocalLow\Conduit
[!] Folder Deleted : C:\Users\Qp33zy\AppData\LocalLow\DivX_Browser_Bar
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Roaming\Search Protection
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\Smartbar
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\CT3288691
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\Extensions\{77E8143B-6759-416E-B521-82CFED75150B}
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\Extensions\{77e8143b-6759-416e-b521-82cfed75150b}
[!] Folder Deleted : C:\Users\Qp33zy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
File Deleted : C:\END
File Deleted : C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\searchplugins\web-search.xml
File Deleted : C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\user.js
File Deleted : C:\Windows\System32\Tasks\AmiUpdXp
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf
Key Deleted : HKCU\Software\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Key Deleted : HKLM\SOFTWARE\Classes\driverscanner
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DD937C23-9304-4E9E-9FD3-0E00B88E2C2E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{369385E4-88F0-4400-8A22-BC8B65BE5EEA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C3BDFF8-B966-4200-B01A-AE512ABE1861}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4B5C-9287-DA72D38F4FE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4B5C-9287-DA72D38F4FE6}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{77E8143B-6759-416E-B521-82CFED75150B}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{77E8143B-6759-416E-B521-82CFED75150B}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{77E8143B-6759-416E-B521-82CFED75150B}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{77E8143B-6759-416E-B521-82CFED75150B}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\DivX_Browser_Bar
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKLM\Software\DivX_Browser_Bar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DivX_Browser_Bar Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\alotAppbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BabylonToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyFreeCodec
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DivX_Browser_Bar Toolbar
Key Deleted : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v9.0.8112.16540
 
 
-\\ Mozilla Firefox v28.0 (en-US)
 
[ File : C:\Users\Qp33zy\AppData\Roaming\Mozilla\Firefox\Profiles\xitb790a.default\prefs.js ]
 
Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_converterVersion.enc", "MTAuMS4xLjY3");
Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_lastTimeUpdateChecked.enc", 556416188);
Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_playerVersion.enc", "MTEuMy4xLjg=");
Line Deleted : user_pref("CT3288691.CONDUIT_UPDATE_streamerVersion.enc", "MTAuMS4xLjY3");
Line Deleted : user_pref("CT3288691.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.FF19Solved", "true");
Line Deleted : user_pref("CT3288691.FirstTime", "true");
Line Deleted : user_pref("CT3288691.FirstTimeFF3", "true");
Line Deleted : user_pref("CT3288691.UserID", "UN22476895942796120");
Line Deleted : user_pref("CT3288691.addressBarTakeOverEnabledInHidden", "true");
Line Deleted : user_pref("CT3288691.addressUrlXPETakeover", "true");
Line Deleted : user_pref("CT3288691.autoDisableScopes", -1);
Line Deleted : user_pref("CT3288691.countryCode", "US");
Line Deleted : user_pref("CT3288691.defaultSearch", "false");
Line Deleted : user_pref("CT3288691.embeddedsData", "[{\"appId\":\"10000002\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"instantAlert\":[...]
Line Deleted : user_pref("CT3288691.enableAlerts", "true");
Line Deleted : user_pref("CT3288691.enableFix404ByUser", "TRUE");
Line Deleted : user_pref("CT3288691.enableSearchFromAddressBar", "true");
Line Deleted : user_pref("CT3288691.firstTimeDialogOpened", "true");
Line Deleted : user_pref("CT3288691.fixPageNotFoundError", "true");
Line Deleted : user_pref("CT3288691.fixPageNotFoundErrorByUser", "true");
Line Deleted : user_pref("CT3288691.fixPageNotFoundErrorInHidden", "true");
Line Deleted : user_pref("CT3288691.fixUrls", true);
Line Deleted : user_pref("CT3288691.fullUserID", "UN22476895942796120.UP.20130625013958");
Line Deleted : user_pref("CT3288691.homepageuserchanged", true);
Line Deleted : user_pref("CT3288691.installDate", "23/5/2013 18:30:23");
Line Deleted : user_pref("CT3288691.installId", "stub.exe");
Line Deleted : user_pref("CT3288691.installSessionId", "{A5F0348C-F865-4D9B-BEAC-1E41495C5557}");
Line Deleted : user_pref("CT3288691.installSp", "true");
Line Deleted : user_pref("CT3288691.installType", "conduitnsisintegration");
Line Deleted : user_pref("CT3288691.installUsage", "2013-05-24T02:36:56.4944359+03:00");
Line Deleted : user_pref("CT3288691.installUsageEarly", "2013-05-24T02:36:55.5428176+03:00");
Line Deleted : user_pref("CT3288691.installerVersion", "1.4.2.3");
Line Deleted : user_pref("CT3288691.isCheckedStartAsHidden", true);
Line Deleted : user_pref("CT3288691.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.isFirstTimeToolbarLoading", "false");
Line Deleted : user_pref("CT3288691.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT3288691.keyword", "true");
Line Deleted : user_pref("CT3288691.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?gd=&ctid=CT3288691&octid=CT3288691&ISID=ISID_ID&SearchSource=15&CUI=UN22476895942796120&SSPV=[...]
Line Deleted : user_pref("CT3288691.lastVersion", "10.23.0.822");
Line Deleted : user_pref("CT3288691.mam_gk_installer_preapproved.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3288691.migrateAppsAndComponents", true);
Line Deleted : user_pref("CT3288691.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxps%3A%2F%2Fwww.facebook.com%2F%3Fstype%3Dlo%26jlou%3DAffWfjbw2GAJXobLJZj6_3lRS1bbCsSWLAwZIB8dMdoQp49M8[...]
Line Deleted : user_pref("CT3288691.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.openThankYouPage", "false");
Line Deleted : user_pref("CT3288691.openUninstallPage", "true");
Line Deleted : user_pref("CT3288691.originalSearchAddressUrl", "hxxp://websearch.shopathome.com?user_id={03b1d81c-65e1-4227-b0cb-c373794e11b2}&q=");
Line Deleted : user_pref("CT3288691.revertSettingsEnabled", "false");
Line Deleted : user_pref("CT3288691.search.searchAppId", "10000002");
Line Deleted : user_pref("CT3288691.search.searchCount", "0");
Line Deleted : user_pref("CT3288691.searchInNewTabEnabledByUser", "false");
Line Deleted : user_pref("CT3288691.searchInNewTabEnabledInHidden", "true");
Line Deleted : user_pref("CT3288691.searchRevert", "false");
Line Deleted : user_pref("CT3288691.searchSuggestEnabledByUser", "true");
Line Deleted : user_pref("CT3288691.searchUserMode", "2");
Line Deleted : user_pref("CT3288691.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3288691\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DivXBrowserBar.OurToolbar.com//xpi\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DivX Browser Bar \"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_services_Configuration_lastUpdate", "1396420784111");
Line Deleted : user_pref("CT3288691.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1396228778993");
Line Deleted : user_pref("CT3288691.serviceLayer_services_appsMetadata_lastUpdate", "1396420782173");
Line Deleted : user_pref("CT3288691.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1395985943623");
Line Deleted : user_pref("CT3288691.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1369352213611");
Line Deleted : user_pref("CT3288691.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1369352214701");
Line Deleted : user_pref("CT3288691.serviceLayer_services_location_lastUpdate", "1372057342046");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.16.2.10_lastUpdate", "1369387128975");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.16.2.510_lastUpdate", "1372136004320");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.16.4.519_lastUpdate", "1374538362895");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.16.7.524_lastUpdate", "1374448492035");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.16.70.505_lastUpdate", "1377152922453");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.19.2.505_lastUpdate", "1378681618869");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.20.0.513_lastUpdate", "1380210544513");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.20.1.508_lastUpdate", "1382289142732");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.21.1.507_lastUpdate", "1384652133997");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.22.3.518_lastUpdate", "1385249595185");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.22.5.510_lastUpdate", "1386769279327");
Line Deleted : user_pref("CT3288691.serviceLayer_services_login_10.23.0.822_lastUpdate", "1396420782744");
Line Deleted : user_pref("CT3288691.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1395985943724");
Line Deleted : user_pref("CT3288691.serviceLayer_services_searchAPI_lastUpdate", "1396420783957");
Line Deleted : user_pref("CT3288691.serviceLayer_services_serviceMap_lastUpdate", "1396420782734");
Line Deleted : user_pref("CT3288691.serviceLayer_services_toolbarContextMenu_lastUpdate", "1396420783091");
Line Deleted : user_pref("CT3288691.serviceLayer_services_toolbarSettings_lastUpdate", "1396420782145");
Line Deleted : user_pref("CT3288691.serviceLayer_services_translation_lastUpdate", "1396420782721");
Line Deleted : user_pref("CT3288691.settingsINI", true);
Line Deleted : user_pref("CT3288691.shouldFirstTimeDialog", "false");
Line Deleted : user_pref("CT3288691.showToolbarPermission", "false");
Line Deleted : user_pref("CT3288691.smartbar.CTID", "CT3288691");
Line Deleted : user_pref("CT3288691.smartbar.Uninstall", "0");
Line Deleted : user_pref("CT3288691.smartbar.toolbarName", "DivX Browser Bar ");
Line Deleted : user_pref("CT3288691.startPage", "false");
Line Deleted : user_pref("CT3288691.toolbarBornServerTime", "24-5-2013");
Line Deleted : user_pref("CT3288691.toolbarCurrentServerTime", "2-4-2014");
Line Deleted : user_pref("CT3288691.toolbarLoginClientTime", "Thu May 23 2013 20:07:26 GMT-0500 (Central Standard Time)");
Line Deleted : user_pref("CT3288691.versionFromInstaller", "10.16.2.10");
Line Deleted : user_pref("CT3288691_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1396420778448,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("CT3289847.FF19Solved", "true");
Line Deleted : user_pref("CT3289847.UserID", "UN93644122038492037");
Line Deleted : user_pref("CT3289847.browser.search.defaultthis.engineName", "true");
Line Deleted : user_pref("CT3289847.installDate", "13/3/2013 4:52:46");
Line Deleted : user_pref("CT3289847.installerVersion", "1.3.6.5");
Line Deleted : user_pref("CT3289847.keyword", "true");
Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://websearch.shopathome.com?user_id={03b1d81c-65e1-4227-b0cb-c373794e11b2}&q=");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "WhiteSmoke New Customized Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.aol.com/search/search?q={searchTerms}&s_it=outbrowseaol-ff&s_qt=sb&tb_uuid=2013031381353146&tb_oid=13-03-2013&tb_mrud=13-03-2013");
Line Deleted : user_pref("extensions.enabledItems", "{20a82645-c095-46ed-80e3-08825760534b}:1.2.1,{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21,{B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1,{CAFEEFAC-0016-0000-0022-A[...]
Line Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 2);
Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3288691");
Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN93644122038492037&UM=2&q=,hxxp://search.conduit.com/ResultsExt.aspx?cti[...]
Line Deleted : user_pref("smartbar.machineId", "7GORGMQ4TIUJI3NJMSJWGZSTBSPIUO0MEC2T/CET6I2ZCFY34ZTSVDS2CRCHYJRR2ZHKEZYFZCP5NB0KLSNH8Q");
Line Deleted : user_pref("smartbar.originalSearchAddressUrl", "");
Line Deleted : user_pref("smartbar.originalSearchEngine", "Bing");
Line Deleted : user_pref("valueApps.CT3288691.mam_gk_currentVersion", "312E31332E302E3137");
Line Deleted : user_pref("valueApps.CT3288691.mam_gk_currentVersion.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3288691.mam_gk_globalKeysMigratedToLocalStorage", "31");
Line Deleted : user_pref("valueApps.CT3288691.mam_gk_globalKeysMigratedToLocalStorage.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3288691.mam_gk_migrated_from_ls", "31");
Line Deleted : user_pref("valueApps.CT3288691.mam_gk_migrated_from_ls.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3288691.mam_gk_userBornDate", "4E2F41");
Line Deleted : user_pref("valueApps.CT3288691.mam_gk_userBornDate.storedInFile", false);
 
-\\ Google Chrome v33.0.1750.154
 
[ File : C:\Users\Qp33zy\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [18242 octets] - [02/04/2014 14:53:07]
AdwCleaner[S0].txt - [18384 octets] - [02/04/2014 15:06:02]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [18445 octets] ##########
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows ™ Vista Ultimate x64
Ran by Qp33zy on Wed 04/02/2014 at 15:27:46.52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{53202115-D1FA-48FA-9F4F-B6BB8F5E2EDE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CC5A2F16-4C73-44D1-BE97-7AEF87B1A77F}
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\Users\Qp33zy\appdata\local\cre"
 
 
 
~~~ FireFox
 
Emptied folder: C:\Users\Qp33zy\AppData\Roaming\mozilla\firefox\profiles\xitb790a.default\minidumps [184 files]
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 04/02/2014 at 15:45:25.15
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


#7 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,591 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:39 AM

Posted 02 April 2014 - 04:33 PM

Your log(s) show that most of the detections were Potentially Unwanted Programs (PUPs). In most cases they are related to junk software, toolbars, add-ons/plug-ins, and browser extensions bundled with other free third-party software.

These bundled packages, installers and downloaders can often be the source of various issues and problems to include Adware, pop-up ads, browser hijacking which may change your home page and search engine, and user profile corruption.

A PUP is a very broad threat category which can encompass any number of different programs to include those which are benign as well as problematic. Thus, this type of detection does not always necessarily mean the file is malicious or a bad program. PUPs in and of themselves are not always bad...many are generally known, non-malicious but unwanted software. PUPs are considered unwanted because they can cause undesirable system performance or other problems and are sometimes installed without the user's consent since they are often included when downloading legitimate programs. PUPs may also be defined somewhat differently by various security vendors and may or may not be detected/removed based on that definition. That fact adds to confusion and a lot of complaints from end users asking why a detection was not made on a particular file (program) they are having issues with.

How is your computer running now?
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#8 steelkobra03

steelkobra03
  • Topic Starter

  • Members
  • 101 posts
  • OFFLINE
  •  
  • Local time:11:39 AM

Posted 02 April 2014 - 05:06 PM

My computer seems revived back to the way it's supposed to run. It's very responsive now. Blazing fast again, very quick and swift like it should be! Thank you sir! Is there anything else that I need to complete or that you suggest to protect or prevent from future added pups?  I'm trying to install Hosts Anti PUP/adware but it just says "awaiting action."



#9 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,591 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:39 AM

Posted 02 April 2014 - 06:07 PM

You're welcome.

You may want to read these topics.
Best Practices for Safe Computing - Prevention of Malware Infection
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs)
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#10 steelkobra03

steelkobra03
  • Topic Starter

  • Members
  • 101 posts
  • OFFLINE
  •  
  • Local time:11:39 AM

Posted 02 April 2014 - 06:19 PM

Ok. Thank you again sir I really appreciate you for taking out this time to assist me. How do I go by of donating to this site? 



#11 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,591 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:39 AM

Posted 02 April 2014 - 06:27 PM

As far as donations...We appreciate your generous offer but since our advertisements are able to offset the cost of the site, Bleeping Computer is no longer accepting donations. The site is by no means a profit making venture, but it is at this point self sustaining so the donation link was removed by the site owner. If you would like, please make a donation to the Wounded Warrior Project, or your local Fire or Police department instead.

Thanks just the same and I'm glad we were able to assist you.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users