Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Can't stop popup windows


  • This topic is locked This topic is locked
16 replies to this topic

#1 JSLayton

JSLayton

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:53 PM

Posted 29 August 2014 - 09:44 AM

DDS (Ver_2012-11-20.01) - NTFS_AMD64

 

Internet Explorer: 11.0.9600.17239

 

Run by Owner at 9:33:56 on 2014-08-29

 

.

 

============== Running Processes ===============

 

.

 

C:\windows\system32\lsm.exe

 

C:\windows\system32\svchost.exe -k DcomLaunch

 

C:\windows\system32\svchost.exe -k RPCSS

 

c:\Program Files\Microsoft Security Client\MsMpEng.exe

 

C:\windows\system32\atiesrxx.exe

 

C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted

 

C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted

 

C:\windows\system32\svchost.exe -k LocalService

 

C:\windows\system32\svchost.exe -k netsvcs

 

C:\windows\system32\svchost.exe -k GPSvcGroup

 

C:\windows\system32\atieclxx.exe

 

C:\windows\system32\svchost.exe -k NetworkService

 

C:\windows\System32\spoolsv.exe

 

C:\windows\system32\svchost.exe -k LocalServiceNoNetwork

 

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

 

C:\Program Files\Bonjour\mDNSResponder.exe

 

C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

 

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe

 

C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe

 

C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe

 

C:\windows\system32\svchost.exe -k imgsvc

 

C:\windows\system32\TODDSrv.exe

 

C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

 

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

 

C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

 

C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe

 

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

 

C:\windows\system32\taskhost.exe

 

C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

 

C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe

 

C:\windows\system32\Dwm.exe

 

C:\windows\Explorer.EXE

 

C:\windows\system32\taskeng.exe

 

C:\Program Files\Elantech\ETDCtrl.exe

 

C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe

 

C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe

 

C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe

 

C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe

 

C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe

 

C:\Program Files\Microsoft Security Client\msseces.exe

 

C:\Program Files (x86)\Skype\Phone\Skype.exe

 

C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe

 

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe

 

C:\Program Files\Elantech\ETDCtrlHelper.exe

 

C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe

 

C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

 

C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

 

C:\Program Files (x86)\iTunes\iTunesHelper.exe

 

C:\windows\system32\wbem\wmiprvse.exe

 

C:\windows\system32\SearchIndexer.exe

 

C:\Program Files\iPod\bin\iPodService.exe

 

C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

 

C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe

 

C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe

 

C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe

 

C:\windows\system32\wbem\wmiprvse.exe

 

C:\windows\system32\sppsvc.exe

 

C:\Program Files\Windows Media Player\wmpnetwk.exe

 

C:\windows\System32\cscript.exe

 

.

 

============== Pseudo HJT Report ===============

 

.

 

uStart Page = hxxp://www.google.com

 

mStart Page = hxxp://www.google.com

 

mSearch Page = hxxp://www.google.com

 

mDefault_Page_URL = hxxp://www.google.com

 

mDefault_Search_URL = hxxp://www.google.com

 

uProxyOverride = <local>

 

uSearchAssistant = hxxp://www.google.com

 

dURLSearchHooks: YTNavAssistPlugin Class: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll

 

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

 

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} -

 

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

 

BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

 

TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

 

TB: PasswordBox Toolbar: {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} -

 

TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

 

uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

 

uRun: [GoogleChromeAutoLaunch_721577D41E77D440C916E2687EBA0267] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window

 

uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe

 

uRun: [KSS] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe" /autorun

 

mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

 

mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60

 

mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" UNATTENDED

 

mRun: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"

 

mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

 

mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe"  -osboot

 

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

 

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

 

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

 

uPolicies-Explorer: NoDrives = dword:0

 

mPolicies-Explorer: NoDrives = dword:0

 

mPolicies-Explorer: HideSCAHealth = dword:1

 

mPolicies-System: ConsentPromptBehaviorAdmin = dword:0

 

mPolicies-System: ConsentPromptBehaviorUser = dword:0

 

mPolicies-System: EnableLUA = dword:0

 

mPolicies-System: EnableUIADesktopToggle = dword:0

 

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

 

DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -

 

TCP: NameServer = 8.8.8.8 8.8.4.4 24.159.64.23

 

TCP: Interfaces\{12E2DCA4-8BCF-4527-97FE-298725427E2F} : DHCPNameServer = 8.8.8.8 8.8.4.4 24.159.64.23

 

TCP: Interfaces\{12E2DCA4-8BCF-4527-97FE-298725427E2F}\2375942554537343 : DHCPNameServer = 192.168.1.254

 

TCP: Interfaces\{12E2DCA4-8BCF-4527-97FE-298725427E2F}\2656C6B696E6E2162356 : DHCPNameServer = 192.168.2.1

 

TCP: Interfaces\{12E2DCA4-8BCF-4527-97FE-298725427E2F}\84F4D454D273343403 : DHCPNameServer = 75.75.75.75 75.75.76.76

 

TCP: Interfaces\{12E2DCA4-8BCF-4527-97FE-298725427E2F}\8596F6D234F6D6D6F646F6275623 : DHCPNameServer = 216.10.80.65

 

TCP: Interfaces\{12E2DCA4-8BCF-4527-97FE-298725427E2F}\8596F6D234F6D6D6F646F6275653 : DHCPNameServer = 216.10.84.161

 

TCP: Interfaces\{12E2DCA4-8BCF-4527-97FE-298725427E2F}\C696E6B6379737 : DHCPNameServer = 192.168.0.1 192.168.1.254

 

TCP: Interfaces\{12E2DCA4-8BCF-4527-97FE-298725427E2F}\E4544574541425 : DHCPNameServer = 10.0.0.1

 

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

 

Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} -

 

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

 

SSODL: WebCheck - <orphaned>

 

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

 

x64-mStart Page = hxxp://www.google.com

 

x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

 

x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

 

x64-BHO: TmBpIeBHO Class: {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -

 

x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

 

x64-Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t

 

x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe

 

x64-Run: [TPwrMain] C:\Program Files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE

 

x64-Run: [TCrdMain] C:\Program Files (x86)\TOSHIBA\FlashCards\TCrdMain.exe

 

x64-Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe

 

x64-Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe

 

x64-Run: [TosNC] C:\Program Files (x86)\Toshiba\BulletinBoard\TosNcCore.exe

 

x64-Run: [TosReelTimeMonitor] C:\Program Files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe

 

x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey

 

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

 

x64-Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} -

 

x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>

 

x64-SSODL: WebCheck - <orphaned>

 

.

 

============= SERVICES / DRIVERS ===============

 

.

 

R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86

 

R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64

 

R? GamesAppIntegrationService;GamesAppIntegrationService

 

R? GamesAppService;GamesAppService

 

R? IEEtwCollectorService;Internet Explorer ETW Collector Service

 

R? NisDrv;Microsoft Network Inspection System

 

R? NisSrv;Microsoft Network Inspection

 

R? PasswordBox;PasswordBox

 

R? RdpVideoMiniport;Remote Desktop Video Miniport Driver

 

R? RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service

 

R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader

 

R? RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver

 

R? SkypeUpdate;Skype Updater

 

R? TsUsbFlt;TsUsbFlt

 

R? TsUsbGD;Remote Desktop Generic USB Device

 

R? USBAAPL64;Apple Mobile USB Driver

 

R? WatAdminSvc;Windows Activation Technologies Service

 

R? wlcrasvc;Windows Live Mesh remote connections service

 

R? X5XSEx_Pr143;X5XSEx_Pr143

 

S? AMD External Events Utility;AMD External Events Utility

 

S? amd_sata;amd_sata

 

S? amd_xata;amd_xata

 

S? avgtp;avgtp

 

S? cvhsvc;Client Virtualization Handler

 

S? ETD;ELAN PS/2 Port Input Device

 

S? FwLnk;FwLnk Driver

 

S? KSS;Kaspersky Security Scan Service

 

S? L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller

 

S? MpFilter;Microsoft Malware Protection Driver

 

S? PCCUJobMgr;Common Client Job Manager Service

 

S? PGEffect;Pangu effect driver

 

S? RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter

 

S? Sftfs;Sftfs

 

S? sftlist;Application Virtualization Client

 

S? Sftplay;Sftplay

 

S? Sftredir;Sftredir

 

S? Sftvol;Sftvol

 

S? sftvsa;Application Virtualization Service Agent

 

S? TMachInfo;TMachInfo

 

S? TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service

 

.

 

=============== Created Last 30 ================

 

.

 

2014-08-29 14:21:55 -------- d-sh--w- C:\AI_RecycleBin

 

2014-08-29 13:53:41 -------- d-----w- C:\Program Files (x86)\VS Revo Group

 

2014-08-28 22:48:10 -------- d-sh--w- C:\$RECYCLE.BIN

 

2014-08-28 19:40:55 1169712 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CEE71352-4BCC-4565-B176-55E64FE33C4B}\gapaengine.dll

 

2014-08-28 19:40:15 11319192 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F9D1CC9C-6B25-4EDB-985A-02FDCB7F7F19}\mpengine.dll

 

2014-08-28 14:38:29 -------- d-----w- C:\ProgramData\HitmanPro

 

2014-08-28 13:45:08 11319192 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

 

2014-08-27 20:50:36 -------- d-----w- C:\NPE

 

2014-08-27 20:47:45 -------- d-----w- C:\Users\Owner\AppData\Local\NPE

 

2014-08-27 18:45:38 3163648 ----a-w- C:\windows\System32\win32k.sys

 

2014-08-27 18:45:37 404480 ----a-w- C:\windows\System32\gdi32.dll

 

2014-08-27 18:45:37 311808 ----a-w- C:\windows\SysWow64\gdi32.dll

 

2014-08-27 18:40:16 -------- d-----w- C:\windows\ERUNT

 

2014-08-25 19:04:07 -------- d-----w- C:\windows\Microsoft Antimalware

 

2014-08-24 22:58:07 2620928 ----a-w- C:\windows\System32\wucltux.dll

 

2014-08-24 22:57:36 97792 ----a-w- C:\windows\System32\wudriver.dll

 

2014-08-24 22:57:36 92672 ----a-w- C:\windows\SysWow64\wudriver.dll

 

2014-08-24 22:57:21 36864 ----a-w- C:\windows\System32\wuapp.exe

 

2014-08-24 22:57:21 33792 ----a-w- C:\windows\SysWow64\wuapp.exe

 

2014-08-24 22:57:21 198600 ----a-w- C:\windows\System32\wuwebv.dll

 

2014-08-24 22:57:21 179656 ----a-w- C:\windows\SysWow64\wuwebv.dll

 

2014-08-23 04:13:03 98816 ----a-w- C:\windows\sed.exe

 

2014-08-23 04:13:03 256000 ----a-w- C:\windows\PEV.exe

 

2014-08-23 04:13:03 208896 ----a-w- C:\windows\MBR.exe

 

2014-08-15 08:04:09 99480 ----a-w- C:\windows\SysWow64\infocardapi.dll

 

2014-08-15 08:04:08 171160 ----a-w- C:\windows\System32\infocardapi.dll

 

2014-08-15 08:04:08 1389208 ----a-w- C:\windows\System32\icardagt.exe

 

2014-08-15 08:04:07 619672 ----a-w- C:\windows\SysWow64\icardagt.exe

 

2014-08-15 08:04:01 8856 ----a-w- C:\windows\SysWow64\icardres.dll

 

2014-08-15 08:04:01 8856 ----a-w- C:\windows\System32\icardres.dll

 

2014-08-15 08:03:05 35480 ----a-w- C:\windows\SysWow64\TsWpfWrp.exe

 

2014-08-15 08:03:05 35480 ----a-w- C:\windows\System32\TsWpfWrp.exe

 

2014-08-14 19:59:45 7168 ----a-w- C:\windows\SysWow64\KBDYAK.DLL

 

2014-08-14 19:59:45 6656 ----a-w- C:\windows\SysWow64\KBDBASH.DLL

 

2014-08-14 19:59:44 7168 ----a-w- C:\windows\System32\KBDYAK.DLL

 

2014-08-14 19:59:43 7168 ----a-w- C:\windows\System32\KBDBASH.DLL

 

2014-08-14 19:59:29 2048 ----a-w- C:\windows\SysWow64\tzres.dll

 

2014-08-14 19:59:29 2048 ----a-w- C:\windows\System32\tzres.dll

 

2014-08-14 19:57:59 293056 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll

 

2014-08-14 19:57:58 977408 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll

 

2014-08-14 19:57:57 940032 ----a-w- C:\windows\System32\MsSpellCheckingFacility.exe

 

2014-08-14 19:57:54 10747904 ----a-w- C:\Program Files\Internet Explorer\F12Resources.dll

 

2014-08-14 19:57:26 1216000 ----a-w- C:\windows\System32\rpcrt4.dll

 

2014-08-14 19:57:25 664064 ----a-w- C:\windows\SysWow64\rpcrt4.dll

 

2014-08-14 19:57:23 529920 ----a-w- C:\windows\System32\aepdu.dll

 

2014-08-14 19:57:21 424448 ----a-w- C:\windows\System32\aeinv.dll

 

2014-08-07 13:51:04 -------- d-----w- C:\ProgramData\UpdateServer

 

2014-08-06 15:38:21 536576 ----a-w- C:\windows\SysWow64\sqlite3.dll

 

2014-08-02 02:16:22 338992 ----a-w- C:\windows\System32\WiredTools64.dll

 

2014-08-02 02:16:04 296080 ----a-w- C:\windows\SysWow64\WiredTools.dll

 

.

 

==================== Find3M  ====================

 

.

 

2014-08-28 19:02:12 122584 ----a-w- C:\windows\System32\drivers\MBAMSwissArmy.sys

 

2014-07-25 14:02:12 2724864 ----a-w- C:\windows\System32\mshtml.tlb

 

2014-07-25 14:01:41 4096 ----a-w- C:\windows\System32\ieetwcollectorres.dll

 

2014-07-25 13:30:30 66048 ----a-w- C:\windows\System32\iesetup.dll

 

2014-07-25 13:28:35 48640 ----a-w- C:\windows\System32\ieetwproxystub.dll

 

2014-07-25 13:28:27 548352 ----a-w- C:\windows\System32\vbscript.dll

 

2014-07-25 13:25:45 83968 ----a-w- C:\windows\System32\MshtmlDac.dll

 

2014-07-25 13:04:40 2724864 ----a-w- C:\windows\SysWow64\mshtml.tlb

 

2014-07-25 13:00:51 139264 ----a-w- C:\windows\System32\ieUnatt.exe

 

2014-07-25 13:00:25 111616 ----a-w- C:\windows\System32\ieetwcollector.exe

 

2014-07-25 12:59:28 758272 ----a-w- C:\windows\System32\jscript9diag.dll

 

2014-07-25 12:34:49 61952 ----a-w- C:\windows\SysWow64\iesetup.dll

 

2014-07-25 12:34:03 455168 ----a-w- C:\windows\SysWow64\vbscript.dll

 

2014-07-25 12:33:08 51200 ----a-w- C:\windows\SysWow64\ieetwproxystub.dll

 

2014-07-25 12:30:32 61952 ----a-w- C:\windows\SysWow64\MshtmlDac.dll

 

2014-07-25 12:28:15 5824512 ----a-w- C:\windows\System32\jscript9.dll

 

2014-07-25 12:28:05 72704 ----a-w- C:\windows\System32\JavaScriptCollectionAgent.dll

 

2014-07-25 12:10:15 112128 ----a-w- C:\windows\SysWow64\ieUnatt.exe

 

2014-07-25 12:08:47 597504 ----a-w- C:\windows\SysWow64\jscript9diag.dll

 

2014-07-25 12:06:47 4204032 ----a-w- C:\windows\SysWow64\jscript9.dll

 

2014-07-25 11:43:16 60416 ----a-w- C:\windows\SysWow64\JavaScriptCollectionAgent.dll

 

2014-07-25 11:39:29 2087936 ----a-w- C:\windows\System32\inetcpl.cpl

 

2014-07-25 11:39:25 1249280 ----a-w- C:\windows\System32\mshtmlmedia.dll

 

2014-07-25 11:07:49 2001920 ----a-w- C:\windows\SysWow64\inetcpl.cpl

 

2014-07-25 11:07:10 1068032 ----a-w- C:\windows\SysWow64\mshtmlmedia.dll

 

2014-07-25 10:52:06 2266624 ----a-w- C:\windows\System32\wininet.dll

 

2014-07-25 10:05:23 1792512 ----a-w- C:\windows\SysWow64\wininet.dll

 

2014-06-26 17:34:58 464160 ----a-w- C:\windows\System32\Sendori64.dll

 

2014-06-18 02:18:30 692736 ----a-w- C:\windows\System32\osk.exe

 

2014-06-18 01:51:32 646144 ----a-w- C:\windows\SysWow64\osk.exe

 

2014-06-16 02:10:19 985536 ----a-w- C:\windows\System32\drivers\dxgkrnl.sys

 

2014-06-06 10:10:34 624128 ----a-w- C:\windows\System32\qedit.dll

 

2014-06-06 09:44:17 509440 ----a-w- C:\windows\SysWow64\qedit.dll

 

2014-06-05 14:45:15 1460736 ----a-w- C:\windows\System32\lsasrv.dll

 

2014-06-05 14:26:58 22016 ----a-w- C:\windows\SysWow64\secur32.dll

 

2014-06-05 14:25:49 96768 ----a-w- C:\windows\SysWow64\sspicli.dll

 

2014-06-03 10:02:37 112064 ----a-w- C:\windows\System32\consent.exe

 

2014-06-03 10:02:21 504320 ----a-w- C:\windows\System32\msihnd.dll

 

2014-06-03 10:02:21 3241984 ----a-w- C:\windows\System32\msi.dll

 

2014-06-03 10:02:12 1941504 ----a-w- C:\windows\System32\authui.dll

 

2014-06-03 09:29:50 337408 ----a-w- C:\windows\SysWow64\msihnd.dll

 

2014-06-03 09:29:50 2363392 ----a-w- C:\windows\SysWow64\msi.dll

 

2014-06-03 09:29:40 1805824 ----a-w- C:\windows\SysWow64\authui.dll

 

.

 

============= FINISH:  9:42:21.34 ===============

 



BC AdBot (Login to Remove)

 


m

#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:53 PM

Posted 01 September 2014 - 07:56 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download Malwarebytes' Anti-Malware from Here

Double-click mbam-setup-2.X.X.XXXX.exe to install the application (X's are the current version number).
  • Make sure a checkmark is placed next to Launch Malwarebytes' Anti-Malware, then click Finish.
  • Once MBAM opens, when it says Your databases are out of date, click the Fix Now button.
  • Click the Settings tab at the top, and then in the left column, select Detections and Protections, and if not already checked place a checkmark in the selection box for Scan for rootkits.
  • Click the Scan tab at the top of the program window, select Threat Scan and click the Scan Now button.
  • If you receive a message that updates are available, click the Update Now button (the update will be downloaded, installed, and the scan will start).
  • The scan may take some time to finish,so please be patient.
  • If potential threats are detected, ensure that Quarantine is selected as the Action for all the listed items, and click the Apply Actions button.
  • While still on the Scan tab, click the link for View detailed log, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
  • The log is automatically saved by MBAM and can also be viewed by clicking the History tab and then selecting Application Logs.
POST THE LOG FOR MY REVIEW.

Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.

===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
===

Please paste the logs in your next reply DO NOT ATTACH THEM unless specified.
To attach a file select the "More Reply Option" and follow the instructions.

How is the computer running?
Wait for further instructions.

P.S.
Please use Notepad to save your logs.
Make sure that you do not have additional blank lines as you have on your first log.

#3 JSLayton

JSLayton
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:53 PM

Posted 02 September 2014 - 09:36 AM

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 9/2/2014
Scan Time: 8:43:35 AM
Logfile: MBAM-2014-09-02.txt
Administrator: Yes
 
Version: 2.00.2.1012
Malware Database: v2014.09.02.06
Rootkit Database: v2014.08.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Owner
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 365939
Time Elapsed: 25 min, 11 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 1
PUP.Optional.DomaIQ, C:\$RECYCLE.BIN\S-1-5-21-3778843924-91701314-3341541671-1001\$R1RCJYG.exe, Quarantined, [e7b2a623037867cff62360f204fc53ad], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
 
-------------------------------------------------------------------------------------------------------------------------------------------------------------------
 
 
# AdwCleaner v3.308 - Report created 02/09/2014 at 09:18:00
# Updated 20/08/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Owner - OWNER-PC
# Running from : C:\Users\Owner\Downloads\adwcleaner_3.308.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Scheduled Tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17239
 
 
-\\ Google Chrome v27.0.1453.110
 
[ File : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [913 octets] - [02/09/2014 09:18:00]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2238 octets] ##########
 

--------------------------------------------------------------------------------------------------------------------------------------------------------------------

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02
Ran by Owner (administrator) on OWNER-PC on 02-09-2014 09:25:27
Running from C:\Users\Owner\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(TOSHIBA Corporation) C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(TOSHIBA Corporation) C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588456 2010-11-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [590256 2011-05-17] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [972672 2011-04-27] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710560 2011-06-09] (TOSHIBA Corporation)
HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [596912 2011-06-28] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38824 2011-06-28] (TOSHIBA Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
HKLM-x32\...\Run: [NortonOnlineBackupReminder] => C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe [3218864 2011-06-22] (Toshiba)
HKLM-x32\...\Run: [ToshibaAppPlace] => C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe [552960 2010-09-23] (Toshiba)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295072 2012-12-27] (RealNetworks, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-3778843924-91701314-3341541671-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-3778843924-91701314-3341541671-1001\...\Run: [GoogleChromeAutoLaunch_721577D41E77D440C916E2687EBA0267] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [825808 2013-05-29] (Google Inc.)
HKU\S-1-5-21-3778843924-91701314-3341541671-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-3778843924-91701314-3341541671-1001\...\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202328 2012-12-07] (Kaspersky Lab ZAO)
HKU\S-1-5-21-3778843924-91701314-3341541671-1001\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {A76DF8AB-BD5D-406D-9BC1-33BE1E00F125} URL = 
SearchScopes: HKCU - {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = https://www.google.com/search?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: TmBpIeBHO Class -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe64.dll No File
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll No File
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} -  No File
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} 
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe64.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe32.dll No File
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4 24.159.64.23
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @ei.DictionaryBoss.com/Plugin -> C:\Program Files (x86)\DictionaryBossEI\Installr\1.bin\NPv4EISB.dll No File
FF Plugin-x32: @exent.com/npExentCtl,version=7.0.0.0 -> C:\Program Files (x86)\Free Ride Games\npExentCtl.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.0.282 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.6.14 -> c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.0.282 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: www.exent.com/GameTreatWidget -> C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll No File
FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 -> C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File
FF Extension: Playtopus  - C:\Users\Owner\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\links@playtopus.com [2013-06-26]
FF Extension: WordOv - C:\Program Files (x86)\Mozilla Firefox\extensions\exjzanej@rsligfihubxtiyrwg.org [2013-10-29]
FF HKLM-x32\...\Firefox\Extensions: [{38783831-6098-4faa-A9C9-1EE1E343F4D2}] - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\firefoxextension
FF HKLM-x32\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012-12-27]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKCU\...\Firefox\Extensions: [lspeaker@lyricsspeaker.net] - C:\Program Files (x86)\LyricsSpeaker\128.xpi
FF HKCU\...\Firefox\Extensions: [ConsumerInput@Compete] - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12171.xpi
 
Chrome: 
=======
CHR HomePage: Default -> 
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [adkpedkkojgaiolglalapeenhoapdlag] - C:\Program Files (x86)\OApps\chrome-sl.crx []
CHR HKLM-x32\...\Chrome\Extension: [aigpiepdfjlnahejechnegkblnkidiom] - C:\Program Files (x86)\LyricsSpeaker\128.crx []
CHR HKLM-x32\...\Chrome\Extension: [ghepdeopemnlhlemlamkihdphpgghghn] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta2669\ch\VideoPlayerV3beta2669.crx []
CHR HKLM-x32\...\Chrome\Extension: [hdkimeogkokcdglcefaalgmgadjibhej] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1679\ch\MediaViewV1alpha1679.crx []
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2012-11-29]
CHR HKLM-x32\...\Chrome\Extension: [jejhmoeapkjibkipedchefnpjadoelkb] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha141\ch\WebexpEnhancedV1alpha141.crx [2012-11-29]
CHR HKLM-x32\...\Chrome\Extension: [jmidajlhibbpeiagegofgeaeohjpfgog] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha51\ch\MediaViewerV1alpha51.crx [2012-11-29]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S4 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
R2 KSS; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202328 2012-12-07] (Kaspersky Lab ZAO)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S4 PasswordBox; C:\Program Files (x86)\PasswordBox\pbbtnService.exe [67584 2014-05-14] (PasswordBox, Inc.) [File not signed]
R2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [126392 2011-07-19] (Symantec Corporation)
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [50976 2014-03-02] (AVG Technologies)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation                           )
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S2 X5XSEx_Pr143; \??\C:\Program Files (x86)\Free Ride Games\X5XSEx_Pr143.Sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-02 09:25 - 2014-09-02 09:26 - 00020145 _____ () C:\Users\Owner\Downloads\FRST.txt
2014-09-02 09:24 - 2014-09-02 09:25 - 00000000 ____D () C:\FRST
2014-09-02 09:24 - 2014-09-02 09:24 - 02104832 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2014-09-02 09:14 - 2014-09-02 09:14 - 00001182 _____ () C:\Users\Owner\Desktop\MBAM-2014-09-02.txt
2014-08-29 16:56 - 2014-08-29 16:56 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Oracle
2014-08-29 16:40 - 2014-08-29 16:40 - 00000000 ____D () C:\windows\Sun
2014-08-29 16:35 - 2014-08-29 16:35 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-29 14:14 - 2014-09-02 09:07 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-08-29 14:14 - 2014-08-29 14:14 - 00699568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-08-29 14:14 - 2014-08-29 14:14 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-29 14:14 - 2014-08-29 14:14 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-08-29 14:10 - 2014-08-29 14:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-29 14:10 - 2014-08-29 14:09 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-08-29 14:10 - 2014-08-29 14:09 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-08-29 14:10 - 2014-08-29 14:09 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-08-29 14:10 - 2014-08-29 14:09 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-29 09:33 - 2014-09-02 09:11 - 00003228 _____ () C:\windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3778843924-91701314-3341541671-1001
2014-08-29 09:32 - 2014-09-02 09:11 - 00003362 _____ () C:\windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3778843924-91701314-3341541671-1001
2014-08-29 09:21 - 2014-08-29 09:21 - 00000000 __SHD () C:\AI_RecycleBin
2014-08-29 08:53 - 2014-08-29 08:53 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-29 08:52 - 2014-08-29 08:52 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Owner\Downloads\revosetup.exe
2014-08-29 08:40 - 2014-08-29 08:40 - 00688992 ____R (Swearware) C:\Users\Owner\Downloads\dds.exe
2014-08-29 08:35 - 2014-08-29 08:35 - 00000000 ____D () C:\Users\Owner\Downloads\backups
2014-08-29 08:29 - 2014-08-29 08:29 - 00388608 _____ (Trend Micro Inc.) C:\Users\Owner\Downloads\HijackThis.exe
2014-08-28 17:48 - 2014-08-28 17:48 - 00024765 _____ () C:\ComboFix.txt
2014-08-28 10:08 - 2014-09-02 08:31 - 00003340 _____ () C:\windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3778843924-91701314-3341541671-1001
2014-08-28 10:08 - 2014-09-02 08:31 - 00003206 _____ () C:\windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3778843924-91701314-3341541671-1001
2014-08-28 10:04 - 2014-08-28 10:04 - 00015892 _____ () C:\windows\system32\.crusader
2014-08-28 09:38 - 2014-08-28 10:05 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-08-28 09:37 - 2014-08-28 09:38 - 11193392 _____ (SurfRight B.V.) C:\Users\Owner\Downloads\HitmanPro_x64.exe
2014-08-27 15:50 - 2014-08-27 15:51 - 00000000 ____D () C:\NPE
2014-08-27 15:47 - 2014-08-27 16:10 - 00000000 ____D () C:\Users\Owner\AppData\Local\NPE
2014-08-27 15:47 - 2014-08-27 15:47 - 03077584 ____N (Symantec Corporation) C:\Users\Owner\Downloads\NPE.exe
2014-08-27 14:11 - 2014-08-27 14:11 - 01364531 _____ () C:\Users\Owner\Downloads\adwcleaner_3.308.exe
2014-08-27 13:45 - 2014-08-22 21:07 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2014-08-27 13:45 - 2014-08-22 20:45 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2014-08-27 13:45 - 2014-08-22 19:59 - 03163648 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-08-27 13:40 - 2014-08-27 13:40 - 00000000 ____D () C:\windows\ERUNT
2014-08-27 13:39 - 2014-08-27 13:39 - 01016261 _____ (Thisisu) C:\Users\Owner\Downloads\JRT.exe
2014-08-25 14:04 - 2014-08-25 14:04 - 00000000 ____D () C:\windows\Microsoft Antimalware
2014-08-24 17:58 - 2014-05-14 11:23 - 02477536 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2014-08-24 17:58 - 2014-05-14 11:23 - 00058336 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2014-08-24 17:58 - 2014-05-14 11:23 - 00044512 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2014-08-24 17:58 - 2014-05-14 11:21 - 02620928 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2014-08-24 17:57 - 2014-05-14 11:23 - 00700384 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2014-08-24 17:57 - 2014-05-14 11:23 - 00581600 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2014-08-24 17:57 - 2014-05-14 11:23 - 00038880 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2014-08-24 17:57 - 2014-05-14 11:23 - 00036320 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2014-08-24 17:57 - 2014-05-14 11:20 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2014-08-24 17:57 - 2014-05-14 11:17 - 00092672 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2014-08-24 17:57 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2014-08-24 17:57 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2014-08-24 17:57 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2014-08-24 17:57 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2014-08-22 23:13 - 2011-06-26 01:45 - 00256000 _____ () C:\windows\PEV.exe
2014-08-22 23:13 - 2010-11-07 12:20 - 00208896 _____ () C:\windows\MBR.exe
2014-08-22 23:13 - 2009-04-19 23:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-08-22 23:13 - 2000-08-30 19:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-08-22 23:13 - 2000-08-30 19:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-08-22 23:13 - 2000-08-30 19:00 - 00098816 _____ () C:\windows\sed.exe
2014-08-22 23:13 - 2000-08-30 19:00 - 00080412 _____ () C:\windows\grep.exe
2014-08-22 23:13 - 2000-08-30 19:00 - 00068096 _____ () C:\windows\zip.exe
2014-08-22 16:35 - 2014-08-22 16:35 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Owner\Downloads\tdsskiller (1).exe
2014-08-22 16:34 - 2014-08-28 17:12 - 05574834 ____R (Swearware) C:\Users\Owner\Downloads\ComboFix.exe
2014-08-15 03:04 - 2014-06-30 17:24 - 00008856 _____ (Microsoft Corporation) C:\windows\system32\icardres.dll
2014-08-15 03:04 - 2014-06-30 17:14 - 00008856 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardres.dll
2014-08-15 03:04 - 2014-03-09 16:48 - 01389208 _____ (Microsoft Corporation) C:\windows\system32\icardagt.exe
2014-08-15 03:04 - 2014-03-09 16:48 - 00171160 _____ (Microsoft Corporation) C:\windows\system32\infocardapi.dll
2014-08-15 03:04 - 2014-03-09 16:47 - 00619672 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardagt.exe
2014-08-15 03:04 - 2014-03-09 16:47 - 00099480 _____ (Microsoft Corporation) C:\windows\SysWOW64\infocardapi.dll
2014-08-15 03:03 - 2014-06-06 01:16 - 00035480 _____ (Microsoft Corporation) C:\windows\SysWOW64\TsWpfWrp.exe
2014-08-15 03:03 - 2014-06-06 01:12 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
2014-08-14 14:59 - 2014-07-15 22:23 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2014-08-14 14:59 - 2014-07-15 21:46 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2014-08-14 14:59 - 2014-07-08 21:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
2014-08-14 14:59 - 2014-07-08 21:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
2014-08-14 14:59 - 2014-07-08 21:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
2014-08-14 14:59 - 2014-07-08 21:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
2014-08-14 14:59 - 2014-07-08 21:03 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
2014-08-14 14:59 - 2014-07-08 20:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDYAK.DLL
2014-08-14 14:59 - 2014-07-08 20:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDTAT.DLL
2014-08-14 14:59 - 2014-07-08 20:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU1.DLL
2014-08-14 14:59 - 2014-07-08 20:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU.DLL
2014-08-14 14:59 - 2014-07-08 20:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDBASH.DLL
2014-08-14 14:59 - 2014-07-08 17:38 - 00419992 _____ () C:\windows\system32\locale.nls
2014-08-14 14:59 - 2014-07-08 17:30 - 00419992 _____ () C:\windows\SysWOW64\locale.nls
2014-08-14 14:58 - 2014-07-31 18:41 - 00348856 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-08-14 14:58 - 2014-07-31 18:16 - 00307384 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-08-14 14:58 - 2014-07-25 09:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-08-14 14:58 - 2014-07-25 09:01 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-08-14 14:58 - 2014-07-25 08:51 - 17524224 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-08-14 14:58 - 2014-07-25 08:30 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-08-14 14:58 - 2014-07-25 08:28 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-08-14 14:58 - 2014-07-25 08:28 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-08-14 14:58 - 2014-07-25 08:25 - 02774528 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-08-14 14:58 - 2014-07-25 08:25 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-08-14 14:58 - 2014-07-25 08:11 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-08-14 14:58 - 2014-07-25 08:10 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-08-14 14:58 - 2014-07-25 08:04 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-08-14 14:58 - 2014-07-25 08:03 - 00598016 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-08-14 14:58 - 2014-07-25 08:00 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-08-14 14:58 - 2014-07-25 08:00 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-08-14 14:58 - 2014-07-25 07:59 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-08-14 14:58 - 2014-07-25 07:40 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-08-14 14:58 - 2014-07-25 07:34 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-08-14 14:58 - 2014-07-25 07:34 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-08-14 14:58 - 2014-07-25 07:33 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-08-14 14:58 - 2014-07-25 07:30 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-08-14 14:58 - 2014-07-25 07:28 - 05824512 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-08-14 14:58 - 2014-07-25 07:28 - 00072704 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 14:58 - 2014-07-25 07:21 - 02184704 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-08-14 14:58 - 2014-07-25 07:19 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-08-14 14:58 - 2014-07-25 07:18 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-08-14 14:58 - 2014-07-25 07:17 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-08-14 14:58 - 2014-07-25 07:17 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-08-14 14:58 - 2014-07-25 07:12 - 00438784 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-08-14 14:58 - 2014-07-25 07:10 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-08-14 14:58 - 2014-07-25 07:10 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-08-14 14:58 - 2014-07-25 07:08 - 00597504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-08-14 14:58 - 2014-07-25 07:06 - 04204032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-08-14 14:58 - 2014-07-25 06:52 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-08-14 14:58 - 2014-07-25 06:47 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-08-14 14:58 - 2014-07-25 06:43 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-14 14:58 - 2014-07-25 06:42 - 00692736 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-08-14 14:58 - 2014-07-25 06:39 - 02087936 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-08-14 14:58 - 2014-07-25 06:39 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-08-14 14:58 - 2014-07-25 06:36 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-08-14 14:58 - 2014-07-25 06:34 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-08-14 14:58 - 2014-07-25 06:29 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-08-14 14:58 - 2014-07-25 06:23 - 13547008 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-08-14 14:58 - 2014-07-25 06:13 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-08-14 14:58 - 2014-07-25 06:07 - 02001920 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-08-14 14:58 - 2014-07-25 06:07 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-08-14 14:58 - 2014-07-25 06:03 - 11772928 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-08-14 14:58 - 2014-07-25 05:52 - 02266624 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-08-14 14:58 - 2014-07-25 05:26 - 01431040 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-08-14 14:58 - 2014-07-25 05:17 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-08-14 14:58 - 2014-07-25 05:09 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-08-14 14:58 - 2014-07-25 05:05 - 01792512 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-08-14 14:58 - 2014-07-25 05:00 - 01169920 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-08-14 14:58 - 2014-06-15 21:10 - 00985536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2014-08-14 14:58 - 2014-06-03 05:02 - 03241984 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2014-08-14 14:58 - 2014-06-03 05:02 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2014-08-14 14:58 - 2014-06-03 05:02 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2014-08-14 14:58 - 2014-06-03 05:02 - 00112064 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2014-08-14 14:58 - 2014-06-03 04:29 - 02363392 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2014-08-14 14:58 - 2014-06-03 04:29 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2014-08-14 14:58 - 2014-06-03 04:29 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2014-08-14 14:57 - 2014-08-06 21:06 - 00529920 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-08-14 14:57 - 2014-08-06 21:01 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-08-14 14:57 - 2014-07-25 09:52 - 23645696 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-08-14 14:57 - 2014-07-25 07:47 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-08-14 14:57 - 2014-07-13 21:02 - 01216000 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2014-08-14 14:57 - 2014-07-13 20:40 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2014-08-14 14:57 - 2014-06-24 21:05 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-08-14 14:57 - 2014-06-24 20:41 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-08-07 09:06 - 2014-08-07 09:06 - 00000000 ____D () C:\Users\Owner\Downloads\tdsskiller
2014-08-07 09:02 - 2014-08-07 09:02 - 04161313 _____ () C:\Users\Owner\Downloads\tdsskiller.zip
2014-08-07 08:51 - 2014-08-07 10:35 - 00000000 ____D () C:\ProgramData\UpdateServer
2014-08-06 10:38 - 2014-04-05 08:21 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-02 09:26 - 2014-09-02 09:25 - 00020145 _____ () C:\Users\Owner\Downloads\FRST.txt
2014-09-02 09:25 - 2014-09-02 09:24 - 00000000 ____D () C:\FRST
2014-09-02 09:24 - 2014-09-02 09:24 - 02104832 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2014-09-02 09:19 - 2014-05-24 19:23 - 00000000 ____D () C:\AdwCleaner
2014-09-02 09:19 - 2009-07-13 23:45 - 00024608 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-02 09:19 - 2009-07-13 23:45 - 00024608 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-02 09:16 - 2011-09-17 10:47 - 02012329 _____ () C:\windows\WindowsUpdate.log
2014-09-02 09:14 - 2014-09-02 09:14 - 00001182 _____ () C:\Users\Owner\Desktop\MBAM-2014-09-02.txt
2014-09-02 09:12 - 2014-05-24 21:06 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-02 09:11 - 2014-08-29 09:33 - 00003228 _____ () C:\windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3778843924-91701314-3341541671-1001
2014-09-02 09:11 - 2014-08-29 09:32 - 00003362 _____ () C:\windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3778843924-91701314-3341541671-1001
2014-09-02 09:10 - 2010-11-20 22:47 - 01281422 _____ () C:\windows\PFRO.log
2014-09-02 09:10 - 2009-07-14 00:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-09-02 09:10 - 2009-07-13 23:51 - 00089399 _____ () C:\windows\setupact.log
2014-09-02 09:07 - 2014-08-29 14:14 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-09-02 08:31 - 2014-08-28 10:08 - 00003340 _____ () C:\windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3778843924-91701314-3341541671-1001
2014-09-02 08:31 - 2014-08-28 10:08 - 00003206 _____ () C:\windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3778843924-91701314-3341541671-1001
2014-08-29 16:56 - 2014-08-29 16:56 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Oracle
2014-08-29 16:40 - 2014-08-29 16:40 - 00000000 ____D () C:\windows\Sun
2014-08-29 16:35 - 2014-08-29 16:35 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-29 14:14 - 2014-08-29 14:14 - 00699568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-08-29 14:14 - 2014-08-29 14:14 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-29 14:14 - 2014-08-29 14:14 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-08-29 14:10 - 2014-08-29 14:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-29 14:09 - 2014-08-29 14:10 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-08-29 14:09 - 2014-08-29 14:10 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-08-29 14:09 - 2014-08-29 14:10 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-08-29 14:09 - 2014-08-29 14:10 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-29 14:09 - 2011-07-21 20:49 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-29 09:31 - 2009-07-14 00:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2014-08-29 09:23 - 2013-05-18 22:08 - 00000000 ____D () C:\Users\Owner\AppData\Local\Strongvault Online Backup
2014-08-29 09:21 - 2014-08-29 09:21 - 00000000 __SHD () C:\AI_RecycleBin
2014-08-29 09:14 - 2009-07-13 23:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-08-29 08:53 - 2014-08-29 08:53 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-29 08:52 - 2014-08-29 08:52 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Owner\Downloads\revosetup.exe
2014-08-29 08:40 - 2014-08-29 08:40 - 00688992 ____R (Swearware) C:\Users\Owner\Downloads\dds.exe
2014-08-29 08:35 - 2014-08-29 08:35 - 00000000 ____D () C:\Users\Owner\Downloads\backups
2014-08-29 08:29 - 2014-08-29 08:29 - 00388608 _____ (Trend Micro Inc.) C:\Users\Owner\Downloads\HijackThis.exe
2014-08-28 19:01 - 2009-07-13 22:20 - 00000000 ____D () C:\windows\rescache
2014-08-28 17:48 - 2014-08-28 17:48 - 00024765 _____ () C:\ComboFix.txt
2014-08-28 17:48 - 2014-05-24 20:08 - 00000000 ____D () C:\Qoobox
2014-08-28 17:41 - 2009-07-13 21:34 - 00000215 _____ () C:\windows\system.ini
2014-08-28 17:13 - 2014-06-22 22:49 - 00000258 __RSH () C:\Users\Owner\ntuser.pol
2014-08-28 17:13 - 2014-06-21 22:33 - 00912228 _____ () C:\windows\SysWOW64\helper.dat
2014-08-28 17:13 - 2011-11-11 16:29 - 00000000 ____D () C:\Users\Owner
2014-08-28 17:12 - 2014-08-22 16:34 - 05574834 ____R (Swearware) C:\Users\Owner\Downloads\ComboFix.exe
2014-08-28 14:25 - 2009-07-13 22:20 - 00000000 ____D () C:\windows\IME
2014-08-28 10:05 - 2014-08-28 09:38 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-08-28 10:04 - 2014-08-28 10:04 - 00015892 _____ () C:\windows\system32\.crusader
2014-08-28 09:38 - 2014-08-28 09:37 - 11193392 _____ (SurfRight B.V.) C:\Users\Owner\Downloads\HitmanPro_x64.exe
2014-08-28 03:19 - 2009-07-13 23:45 - 00267672 _____ () C:\windows\system32\FNTCACHE.DAT
2014-08-27 16:10 - 2014-08-27 15:47 - 00000000 ____D () C:\Users\Owner\AppData\Local\NPE
2014-08-27 16:06 - 2014-06-21 20:38 - 00000000 ____D () C:\Program Files\pcmax
2014-08-27 15:51 - 2014-08-27 15:50 - 00000000 ____D () C:\NPE
2014-08-27 15:47 - 2014-08-27 15:47 - 03077584 ____N (Symantec Corporation) C:\Users\Owner\Downloads\NPE.exe
2014-08-27 15:47 - 2011-09-17 11:46 - 00000000 ____D () C:\ProgramData\Norton
2014-08-27 15:45 - 2014-06-21 22:10 - 00000000 ____D () C:\Program Files (x86)\ISTsearch
2014-08-27 14:11 - 2014-08-27 14:11 - 01364531 _____ () C:\Users\Owner\Downloads\adwcleaner_3.308.exe
2014-08-27 13:40 - 2014-08-27 13:40 - 00000000 ____D () C:\windows\ERUNT
2014-08-27 13:39 - 2014-08-27 13:39 - 01016261 _____ (Thisisu) C:\Users\Owner\Downloads\JRT.exe
2014-08-27 13:38 - 2009-07-14 00:13 - 00783226 _____ () C:\windows\system32\PerfStringBackup.INI
2014-08-25 14:04 - 2014-08-25 14:04 - 00000000 ____D () C:\windows\Microsoft Antimalware
2014-08-22 21:07 - 2014-08-27 13:45 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2014-08-22 20:45 - 2014-08-27 13:45 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2014-08-22 19:59 - 2014-08-27 13:45 - 03163648 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-08-22 16:35 - 2014-08-22 16:35 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Owner\Downloads\tdsskiller (1).exe
2014-08-22 16:30 - 2014-05-24 20:04 - 00000000 ____D () C:\windows\erdnt
2014-08-22 09:02 - 2011-12-28 20:11 - 00000000 ____D () C:\Users\Owner\AppData\Local\CrashDumps
2014-08-15 20:29 - 2009-07-14 00:32 - 00000000 ____D () C:\windows\Offline Web Pages
2014-08-15 08:29 - 2013-06-06 12:59 - 00000000 ____D () C:\Program Files (x86)\PasswordBox
2014-08-15 03:56 - 2009-07-13 22:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-08-15 03:23 - 2014-05-25 05:47 - 00000000 ____D () C:\windows\system32\MRT
2014-08-15 03:16 - 2012-03-15 16:23 - 99218768 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-08-15 03:01 - 2014-05-26 00:46 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-08-13 15:50 - 2011-07-21 21:00 - 00000000 ____D () C:\windows\en
2014-08-12 08:24 - 2012-05-26 22:05 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Skype
2014-08-07 12:28 - 2014-06-21 21:47 - 00000000 ____D () C:\ProgramData\MediaDev
2014-08-07 12:28 - 2009-07-13 23:45 - 00000000 ____D () C:\windows\Setup
2014-08-07 10:35 - 2014-08-07 08:51 - 00000000 ____D () C:\ProgramData\UpdateServer
2014-08-07 10:35 - 2014-06-21 22:12 - 00000000 ____D () C:\Users\Owner\AppData\Local\3539
2014-08-07 10:35 - 2014-06-21 21:42 - 00000000 ____D () C:\ProgramData\UpdateTask
2014-08-07 09:06 - 2014-08-07 09:06 - 00000000 ____D () C:\Users\Owner\Downloads\tdsskiller
2014-08-07 09:02 - 2014-08-07 09:02 - 04161313 _____ () C:\Users\Owner\Downloads\tdsskiller.zip
2014-08-07 08:33 - 2014-06-21 22:34 - 00008783 _____ () C:\windows\SysWOW64\main.dat
2014-08-07 08:33 - 2014-06-21 22:34 - 00000205 _____ () C:\windows\SysWOW64\user.dat
2014-08-07 08:33 - 2013-06-06 17:32 - 00000000 ____D () C:\Program Files (x86)\SoundFrost
2014-08-07 08:33 - 2011-12-27 16:37 - 00000000 ____D () C:\ProgramData\Origin
2014-08-07 08:26 - 2011-12-27 16:37 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-08-06 21:06 - 2014-08-14 14:57 - 00529920 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-08-06 21:01 - 2014-08-14 14:57 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-08-06 10:47 - 2012-05-20 11:42 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-08-06 10:47 - 2012-05-20 11:42 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-08-06 10:47 - 2009-07-13 22:20 - 00000000 ____D () C:\windows\TAPI
2014-08-06 03:06 - 2010-11-21 02:17 - 00000000 ____D () C:\Program Files\Windows Journal
2014-08-06 03:05 - 2012-05-20 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-08-05 15:45 - 2014-02-25 20:58 - 00883045 _____ () C:\Users\Owner\AppData\Local\viewer.txt
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-08-07 04:25
 
==================== End Of Log ============================
 
Attached File  Addition.txt   41.81KB   1 downloads


#4 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:53 PM

Posted 02 September 2014 - 01:26 PM

Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below.
 
start

SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: TmBpIeBHO Class -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe64.dll No File
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll No File
Toolbar: HKCU - No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} -  No File
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe64.dll No File
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe32.dll No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @ei.DictionaryBoss.com/Plugin -> C:\Program Files (x86)\DictionaryBossEI\Installr\1.bin\NPv4EISB.dll No File
FF Plugin-x32: @exent.com/npExentCtl,version=7.0.0.0 -> C:\Program Files (x86)\Free Ride Games\npExentCtl.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin-x32: www.exent.com/GameTreatWidget -> C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll No File
FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 -> C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File
FF Extension: WordOv - C:\Program Files (x86)\Mozilla Firefox\extensions\exjzanej@rsligfihubxtiyrwg.org [2013-10-29]
FF HKCU\...\Firefox\Extensions: [lspeaker@lyricsspeaker.net] - C:\Program Files (x86)\LyricsSpeaker\128.xpi
FF HKCU\...\Firefox\Extensions: [ConsumerInput@Compete] - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12171.xpi
CHR HKLM-x32\...\Chrome\Extension: [adkpedkkojgaiolglalapeenhoapdlag] - C:\Program Files (x86)\OApps\chrome-sl.crx []
CHR HKLM-x32\...\Chrome\Extension: [aigpiepdfjlnahejechnegkblnkidiom] - C:\Program Files (x86)\LyricsSpeaker\128.crx []
CHR HKLM-x32\...\Chrome\Extension: [ghepdeopemnlhlemlamkihdphpgghghn] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta2669\ch\VideoPlayerV3beta2669.crx []
CHR HKLM-x32\...\Chrome\Extension: [hdkimeogkokcdglcefaalgmgadjibhej] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1679\ch\MediaViewV1alpha1679.crx []
CHR HKLM-x32\...\Chrome\Extension: [jejhmoeapkjibkipedchefnpjadoelkb] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha141\ch\WebexpEnhancedV1alpha141.crx [2012-11-29]
CHR HKLM-x32\...\Chrome\Extension: [jmidajlhibbpeiagegofgeaeohjpfgog] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha51\ch\MediaViewerV1alpha51.crx [2012-11-29]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S2 X5XSEx_Pr143; \??\C:\Program Files (x86)\Free Ride Games\X5XSEx_Pr143.Sys [X]
Task: {D6815912-C472-4E4B-9878-DF3C84C026EB} - System32\Tasks\pcreg => C:\Program Files\pcmax\service.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:2342AE46
AlternateDataStreams: C:\ProgramData\TEMP:373E1720

End
Save the files as fixlist.txt into the same folder as FRST

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
p.s.
If the SecurityCheck program fails to run for any reason, run it as an Administrator.

If the site is busy or not available use this mirror site:
http://www.bleepingcomputer.com/download/securitycheck/
===

How is the computer running now?

#5 JSLayton

JSLayton
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:53 PM

Posted 02 September 2014 - 02:42 PM

The computer still seems to be running slow, but the popups appear to be gone.  
 
_________________________________________________________________________________________________
 
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-08-2014 02
Ran by Owner at 2014-09-02 14:25:36 Run:1
Running from C:\Users\Owner\Downloads
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
start
 
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: TmBpIeBHO Class -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe64.dll No File
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll No File
Toolbar: HKCU - No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} -  No File
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe64.dll No File
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe32.dll No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @ei.DictionaryBoss.com/Plugin -> C:\Program Files (x86)\DictionaryBossEI\Installr\1.bin\NPv4EISB.dll No File
FF Plugin-x32: @exent.com/npExentCtl,version=7.0.0.0 -> C:\Program Files (x86)\Free Ride Games\npExentCtl.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF Plugin-x32: www.exent.com/GameTreatWidget -> C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll No File
FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 -> C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File
FF Extension: WordOv - C:\Program Files (x86)\Mozilla Firefox\extensions\exjzanej@rsligfihubxtiyrwg.org [2013-10-29]
FF HKCU\...\Firefox\Extensions: [lspeaker@lyricsspeaker.net] - C:\Program Files (x86)\LyricsSpeaker\128.xpi
FF HKCU\...\Firefox\Extensions: [ConsumerInput@Compete] - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12171.xpi
CHR HKLM-x32\...\Chrome\Extension: [adkpedkkojgaiolglalapeenhoapdlag] - C:\Program Files (x86)\OApps\chrome-sl.crx []
CHR HKLM-x32\...\Chrome\Extension: [aigpiepdfjlnahejechnegkblnkidiom] - C:\Program Files (x86)\LyricsSpeaker\128.crx []
CHR HKLM-x32\...\Chrome\Extension: [ghepdeopemnlhlemlamkihdphpgghghn] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta2669\ch\VideoPlayerV3beta2669.crx []
CHR HKLM-x32\...\Chrome\Extension: [hdkimeogkokcdglcefaalgmgadjibhej] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1679\ch\MediaViewV1alpha1679.crx []
CHR HKLM-x32\...\Chrome\Extension: [jejhmoeapkjibkipedchefnpjadoelkb] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha141\ch\WebexpEnhancedV1alpha141.crx [2012-11-29]
CHR HKLM-x32\...\Chrome\Extension: [jmidajlhibbpeiagegofgeaeohjpfgog] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha51\ch\MediaViewerV1alpha51.crx [2012-11-29]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S2 X5XSEx_Pr143; \??\C:\Program Files (x86)\Free Ride Games\X5XSEx_Pr143.Sys [X]
Task: {D6815912-C472-4E4B-9878-DF3C84C026EB} - System32\Tasks\pcreg => C:\Program Files\pcmax\service.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:2342AE46
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
 
End
*****************
 
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC}" => Key deleted successfully.
"HKCR\CLSID\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{3049C3E9-B461-4BC5-8870-4C09146192CA}" => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} => value deleted successfully.
"HKCR\CLSID\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE}" => Key not found.
"HKCR\PROTOCOLS\Handler\tmbp" => Key deleted successfully.
"HKCR\CLSID\{1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF}" => Key deleted successfully.
"HKCR\Wow6432Node\PROTOCOLS\Handler\tmbp" => Key not found.
"HKCR\Wow6432Node\CLSID\{1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF}" => Key deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@ei.DictionaryBoss.com/Plugin" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\www.exent.com/GameTreatWidget" => Key deleted successfully.
"HKCU\Software\MozillaPlugins\@lightspark.github.com/Lightspark;version=1" => Key deleted successfully.
C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll not found.
C:\Program Files (x86)\Mozilla Firefox\extensions\exjzanej@rsligfihubxtiyrwg.org => Moved successfully.
HKCU\Software\Mozilla\Firefox\Extensions\\lspeaker@lyricsspeaker.net => value deleted successfully.
HKCU\Software\Mozilla\Firefox\Extensions\\ConsumerInput@Compete => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\adkpedkkojgaiolglalapeenhoapdlag" => Key deleted successfully.
"C:\Program Files (x86)\OApps\chrome-sl.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\aigpiepdfjlnahejechnegkblnkidiom" => Key deleted successfully.
"C:\Program Files (x86)\LyricsSpeaker\128.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ghepdeopemnlhlemlamkihdphpgghghn" => Key deleted successfully.
"C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta2669\ch\VideoPlayerV3beta2669.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hdkimeogkokcdglcefaalgmgadjibhej" => Key deleted successfully.
"C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1679\ch\MediaViewV1alpha1679.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jejhmoeapkjibkipedchefnpjadoelkb" => Key deleted successfully.
"C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha141\ch\WebexpEnhancedV1alpha141.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jmidajlhibbpeiagegofgeaeohjpfgog" => Key deleted successfully.
"C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha51\ch\MediaViewerV1alpha51.crx" => File/Directory not found.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
gupdate => Service deleted successfully.
gupdatem => Service deleted successfully.
catchme => Service deleted successfully.
X5XSEx_Pr143 => Service deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D6815912-C472-4E4B-9878-DF3C84C026EB}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D6815912-C472-4E4B-9878-DF3C84C026EB}" => Key deleted successfully.
C:\Windows\System32\Tasks\pcreg => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pcreg" => Key deleted successfully.
C:\ProgramData\TEMP => ":2342AE46" ADS removed successfully.
C:\ProgramData\TEMP => ":373E1720" ADS removed successfully.
 
==== End of Fixlog ====
 
 
------------------------------------------------------------------------------------------------------------------------------------------------------------------
 
 

 Results of screen317's Security Check version 0.99.87  
 Windows 7 Service Pack 1 x64 (UAC is disabled!)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Microsoft Security Essentials   
  (On Access scanning disabled!) 
 Error obtaining update status for antivirus!  
`````````Anti-malware/Other Utilities Check:````````` 
 I SPY™ Fun House  
 Java 7 Update 67  
 Google Chrome 26.0.1410.64  
 Google Chrome 27.0.1453.110  
 Google Chrome 27.0.1453.94  
 Google Chrome Plugins...  
````````Process Check: objlist.exe by Laurent````````  
 Norton ccSvcHst.exe 
 Microsoft Security Essentials MSMpEng.exe 
 Microsoft Security Essentials msseces.exe 
 Kaspersky Lab Kaspersky Security Scan 2.0 kss.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 0% 
````````````````````End of Log`````````````````````` 
 


#6 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:53 PM

Posted 03 September 2014 - 07:50 AM

This may take awhile. Do it when you know you will not be using the computer.

Please scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer.
      Save it to your Desktop.
    • Double click on the esetsmartinstaller_enu.png to download the ESET Smart Installer. icon on your Desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.


#7 JSLayton

JSLayton
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:53 PM

Posted 05 September 2014 - 09:28 AM

It ran for 24 hours yesterday and seemed stuck at 49% while checking the Q:\ drive which is a Microsoft Office Click to Run Installer.  I clicked stop and started over, thinking the sleep settings on the computer caused it to lock up.  I restarted the scan with all power saving options off (screen saver will not come on and computer will not sleep) and it's now stuck at the same place.  Should I allow it to finish or should I click stop?  It's found 298 Infected Files



#8 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:53 PM

Posted 06 September 2014 - 07:17 AM

Stop it if not already done.

Are you running Microsoft office from the Q drive or is this only the installation software?

Any problems with Microsoft Office?

You can also check the integrity of the drive.

Refer to this article.
http://technet.microsoft.com/en-us/library/cc730714(v=ws.10).aspx

Start with this command using the Start run box.

chkdsk q: /f

#9 JSLayton

JSLayton
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:53 PM

Posted 08 September 2014 - 09:11 AM

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Download_Energy\hk64tbDow0.dll.vir a variant of Win64/Toolbar.Conduit.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Download_Energy\hktbDow0.dll.vir a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Download_Energy\ldrtbDow0.dll.vir a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Download_Energy\ldrtbDown.dll.vir a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Download_Energy\prxtbDow0.dll.vir Win32/Toolbar.Conduit.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Download_Energy\prxtbDown.dll.vir Win32/Toolbar.Conduit.O potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Download_Energy\tbDow0.dll.vir a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Download_Energy\tbDown.dll.vir a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Driver Pro\DPSmartScan.exe.vir Win32/Adware.SpeedingUpMyPC.C application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\File Type Helper\FileTypeHelper.exe.vir MSIL/FileTypeHelper.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\File Type Helper\FileTypeHelper_assoc.exe.vir MSIL/FileTypeHelper.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\FlvPlayer\FLVPlayerApp.exe.vir Win32/InstallCore.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\360-59601.crx.vir JS/Toolbar.Crossrider.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\59601.crx.vir JS/Toolbar.Crossrider.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\59601.xpi.vir JS/Toolbar.Crossrider.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\eb055e1f-3b5f-4dd1-9757-8490b8cffcec-11.exe.vir a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\eb055e1f-3b5f-4dd1-9757-8490b8cffcec-2.exe.vir a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\eb055e1f-3b5f-4dd1-9757-8490b8cffcec-3.exe.vir a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\eb055e1f-3b5f-4dd1-9757-8490b8cffcec-4.exe.vir a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\eb055e1f-3b5f-4dd1-9757-8490b8cffcec-5.exe.vir a variant of Win32/Toolbar.CrossRider.AH potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\eb055e1f-3b5f-4dd1-9757-8490b8cffcec.crx.vir JS/Toolbar.Crossrider.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\Fraveen 1.4-bg.exe.vir a variant of Win32/Toolbar.CrossRider.AL potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\Fraveen 1.4-codedownloader.exe.vir a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\Fraveen 1.4-nova.dll.vir a variant of Win32/Toolbar.CrossRider.AI potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\Fraveen 1.4-nova.exe.vir a variant of Win32/Toolbar.CrossRider.AE potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\Fraveen 1.4-novainstaller.exe.vir a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\f_in_box.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.AxImp.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Booster.UI.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Business.Connect.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Business.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Entity.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.exe.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Mediator.ActivePlayers.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Mediator.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Messengers.exe.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Services.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.WinCore.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.WinCore.WLM.WinEvents.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.WinCore.WLM15.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.WinCore.Yahoo.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Windows.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Workflow.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Microsoft.DirectX.AudioVideoPlayback.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Microsoft.Expression.Interactions.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx64.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx86.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\System.Data.SQLite.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\System.Windows.Interactivity.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\WPFLocalizeExtension.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\jfilemanager\LTV.exe.vir MSIL/Tuguu.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\jfilemanager\update.xml.vir Win32/DomaIQ.BC potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\LyricsSpeaker\128.dll.vir a variant of Win32/AdWare.AddLyrics.S application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha348\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha51\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaViewV1\MediaViewV1alpha1679\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\Installer.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\InstallerLibrary.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\InstallFirefoxExtension.dll.vir MSIL/Adware.Proxomoto.B application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\NewVersionUploader.exe.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\WindowsUpdater.exe.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\backup\InstallerLibrary.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3DTACTL.DLL.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL.vir a variant of Win32/Toolbar.MyWebSearch.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL.vir Win32/Toolbar.MyWebSearch.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL.vir Win32/Toolbar.MyWebSearch.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL.vir Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3WPHOOK.DLL.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL.vir Win32/Toolbar.MyWebSearch.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3HTML.DLL.vir Win32/Toolbar.MyWebSearch.F potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL.vir Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3IEOVR.DLL.vir Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL.vir Win32/Toolbar.MyWebSearch.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL.vir a variant of Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL.vir Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKNLCR.DLL.vir a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE.vir Win32/Toolbar.MyWebSearch.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE.vir a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3TPINST.DLL.vir Win32/Toolbar.MyWebSearch.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir Win32/Toolbar.MyWebSearch.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptimizerPro.exe.vir Win32/SpeedingUpMyPC.O application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrash.dll.vir a variant of Win32/SProtector.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProLauncher.exe.vir a variant of Win32/AdWare.SpeedingUpMyPC.D application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe.vir a variant of Win32/Adware.SpeedingUpMyPC.C application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir a variant of Win32/SpeedingUpMyPC application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RebateInformer\RebateI.dll.vir a variant of Win32/Toolbar.Inbox.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RebateInformer\RebateInf.exe.vir a variant of Win32/Toolbar.Inbox.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\rlcm.crx.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\rlls.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\rlvknlg.exe.vir a variant of Win32/Adware.RK.AE application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\components\rlxg.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\firefox\rlnx.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-bg.exe.vir a variant of Win32/Toolbar.CrossRider.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-bho.dll.vir a variant of Win32/Toolbar.CrossRider.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-buttonutil.dll.vir probably a variant of Win32/Toolbar.CrossRider.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-buttonutil.exe.vir a variant of Win32/Toolbar.CrossRider.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-buttonutil64.dll.vir a variant of Win64/Toolbar.Crossrider.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-buttonutil64.exe.vir probably a variant of Win64/Toolbar.Crossrider.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-codedownloader.exe.vir a variant of Win32/Toolbar.CrossRider.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-helper.exe.vir a variant of Win32/Toolbar.CrossRider.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Uninstall.exe.vir a variant of Win32/Packed.VMDetector.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\supporter\Supporter_x64.dll.vir a variant of Win64/SProtector.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Uninstaller\Uninstall.exe.vir a variant of MSIL/DomaIQ.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta2669\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\w3i\UninstallHelper\UninstallHelper.exe.vir probably a variant of Win32/InstallIQ.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha141\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe.vir Win32/AdWare.Yontoo.F application
C:\AdwCleaner\Quarantine\C\ProgramData\BBestSaVeFuorYou\hV_j.dll.vir a variant of Win32/AdWare.MultiPlug.BN application
C:\AdwCleaner\Quarantine\C\ProgramData\BBestSaVeFuorYou\hV_j.exe.vir a variant of Win32/AdWare.MultiPlug.AG application
C:\AdwCleaner\Quarantine\C\ProgramData\BBestSaVeFuorYou\hV_j.x64.dll.vir a variant of Win64/Adware.MultiPlug.D application
C:\AdwCleaner\Quarantine\C\ProgramData\FinedBoestDeal\_bt9h.dll.vir a variant of Win32/AdWare.MultiPlug.BN application
C:\AdwCleaner\Quarantine\C\ProgramData\FinedBoestDeal\_bt9h.exe.vir a variant of Win32/AdWare.MultiPlug.AG application
C:\AdwCleaner\Quarantine\C\ProgramData\FinedBoestDeal\_bt9h.x64.dll.vir a variant of Win64/Adware.MultiPlug.D application
C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application
C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application
C:\AdwCleaner\Quarantine\C\ProgramData\VisualBee\VisualBeeSoftware.exe.vir a variant of Win32/Toolbar.Babylon.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\CommonLauncher.exe.vir a variant of Win32/SoundFrost.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\ContentAgent.exe.vir a variant of Win32/SoundFrost.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\ContentFinder.exe.vir Win32/SoundFrost.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Conduit\CT1269415\Download_EnergyAutoUpdateHelper.exe.vir Win32/Toolbar.Conduit.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\DownloadTerms\temp.dat.vir a variant of Win32/AdWare.Toolbar.AmyBar.A application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll.vir Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.26.9.505_0\APISupport\APISupport.dll.vir a variant of Win32/Conduit.SearchProtect.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.26.9.505_0\nativeMessaging\TBMessagingHost.exe.vir a variant of Win32/Toolbar.Conduit.AH potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.31.0.526_0\APISupport\APISupport.dll.vir Win32/Conduit.SearchProtect potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.31.0.526_0\nativeMessaging\TBMessagingHost.exe.vir a variant of Win32/Toolbar.Conduit.AH potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.31.0.526_0\plugins\ChromeApiPlugin.dll.vir a variant of Win32/Conduit.SearchProtect.N potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.11_0\BabMaint.x.vir a variant of Win32/Toolbar.Babylon.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.11_0\BabylonChromeToolBar.dll.vir Win32/Toolbar.Babylon.Q potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.11_0\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.332.1_0\plugins\rlcm.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\BrowserHelper.exe.vir a variant of MSIL/Toolbar.Linkury.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Interop.SHDocVw.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\MACTrackBarLib.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\NDde.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Newtonsoft.Json.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\QuickShare.exe.vir a variant of Win32/Toolbar.Linkury.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sgml.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sidb.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\siem.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sipb.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sismlp.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll.vir a variant of Win32/Toolbar.Linkury.F potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.XmlSerializers.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.Translations.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll.vir a variant of MSIL/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir a variant of MSIL/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\spbe.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\spbl.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sppsm.dll.vir a variant of MSIL/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\spsm.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\spusm.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srau.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srbhu.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srbs.dll.vir a variant of MSIL/Toolbar.Linkury.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srgu.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srns.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srpdm.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srprl.dll.vir a variant of MSIL/Toolbar.Linkury.F potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srpu.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srsbs.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srsbsau.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srsl.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sruhs.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srus.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srut.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\ar\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\es\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\fr\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\he\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_20.dll.vir Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_21.dll.vir Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_22.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_23.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_24.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_25.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\it\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\pt\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\ru\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\tr\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.DMP.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.NotepadPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.ScreenCapturePlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WordPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\spup.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Solid Savings\gpedit.exe.vir Win32/AdWare.SmartApps.B application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Solid Savings\SoftwareDetector.exe.vir Win32/AdWare.SmartApps.B application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\strongvault\StrongVaultApp.exe.vir MSIL/Adware.StrongVault.A application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\SwvUpdater\Updater.exe.vir a variant of Win32/Amonetize.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\Helper.dll.vir a variant of Win32/Toolbar.SearchSuite.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\Uninstall.exe.vir a variant of Win32/TorchMedia potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\Update\Download\TorchSetup.exe.vir a variant of Win32/TorchMedia potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.22.5.510_0\nativeMessaging\TBMessagingHost.exe.vir a variant of Win32/Toolbar.Conduit.AH potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.22.5.510_0\plugins\ConduitChromeApiPlugin.dll.vir a variant of Win32/Toolbar.Conduit.AH potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.22.5.510_0\TBHostSupport\TBHostSupport.dll.vir a variant of Win32/Toolbar.Conduit.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.332.1_0\plugins\rlcm.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\VisualBeeExe\conduitinstaller.exe.vir Win32/Toolbar.Conduit potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\VisualBeeExe\MyBabylonTB.exe.vir a variant of Win32/Toolbar.Babylon.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\LocalLow\Download_Energy\ldrtbDown.dll.vir a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\LocalLow\Download_Energy\tbDown.dll.vir a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\LocalLow\FunWebProducts\Installr\Cache\056A4E79.exe.vir a variant of Win32/Toolbar.MyWebSearch.O potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\CR\BabylonChrome1.crx.vir a variant of Win32/Toolbar.Babylon.Q potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\CR\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\FF\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\IE\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\Shared\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Complitly\Complitly.dll.vir a variant of Win32/Complitly.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Complitly\KeepMeUpdated.exe.vir a variant of Win32/PredictAd.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Complitly\64\Complitly64.dll.vir a variant of Win64/Complitly.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Complitly\64\KeepMeUpdated.exe.vir a variant of Win32/PredictAd.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll.vir a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart.exe.vir a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart64.exe.vir Win64/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap.dll.vir a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap64.dll.vir Win64/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe.vir Win32/Toolbar.DefaultTab.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe.vir a variant of Win32/Toolbar.DefaultTab.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\serv\ClickAndMark_2040-5250.exe.vir multiple threats
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\serv\Okiitan.exe.vir Win32/BrowseFox.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\serv\setup_istsearch.exe.vir probably a variant of Win32/SquareNet.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\VOPackage\Uninstall.exe.vir Win32/VOPackage.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Yontoo\YontooDesktop.exe.vir a variant of MSIL/WebCake.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\windows\Microsoft\SystemUpdatekb70007\Installer.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\windows\Microsoft\SystemUpdatekb70007\InstallerLibrary.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\windows\SysWOW64\f3PSSavr.scr.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Downloads\Software\7zip_installer_d162802.exe a variant of Win32/InstallIQ.A potentially unwanted application
C:\Downloads\Software\DictionaryBoss.exe Win32/AdInstaller potentially unwanted application
C:\Downloads\Software\intunemp3.exe a variant of Win32/InstallIQ.A potentially unwanted application
C:\Downloads\Software\SoftonicDownloader_for_limewire-music.exe Win32/SoftonicDownloader.E potentially unwanted application
C:\Program Files (x86)\ISTsearch\ISTsearch_Uninstall.exe probably a variant of Win32/SquareNet.C potentially unwanted application
C:\Program Files (x86)\Windows Live\Messenger\msimg32.dll Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Program Files (x86)\Windows Live\Messenger\riched20.dll Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Qoobox\Quarantine\C\Program Files (x86)\DictionaryBossEI\Installr\1.bin\NPv4EISb.dll.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Qoobox\Quarantine\C\Program Files (x86)\DictionaryBossEI\Installr\1.bin\v4EIPlug.dll.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Qoobox\Quarantine\C\Program Files (x86)\DictionaryBossEI\Installr\1.bin\v4EZSETP.dll.vir Win32/Toolbar.MyWebSearch.Q potentially unwanted application
C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\CommonLauncher.exe.vir a variant of Win32/SoundFrost.A potentially unwanted application
C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\ContentAgent.exe.vir a variant of Win32/SoundFrost.A potentially unwanted application
C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\ContentFinder.exe.vir a variant of Win32/SoundFrost.A potentially unwanted application
C:\Users\Owner\AppData\Roaming\launher\Setup.exe NSIS/TrojanDownloader.Agent.NMB trojan
C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\Windows\Installer\1b283ad.msi a variant of Win32/Toolbar.Babylon.Q potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\hk64tbDow0.dll a variant of Win64/Toolbar.Conduit.B potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\hktbDow0.dll a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\ldrtbDow0.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\ldrtbDown.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\tbDow0.dll a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\tbDow1.dll a variant of Win32/Toolbar.Conduit.Y potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\tbDown.dll a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\hk64tbDow0.dll a variant of Win64/Toolbar.Conduit.B potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\hktbDow0.dll a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\ldrtbDow0.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\ldrtbDown.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\tbDow0.dll a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\tbDow1.dll a variant of Win32/Toolbar.Conduit.Y potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\tbDown.dll a variant of Win32/Toolbar.Conduit.B potentially unwanted application
 


#10 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:53 PM

Posted 08 September 2014 - 12:49 PM

What is this?
Did you execute my previous instructions?

#11 JSLayton

JSLayton
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:53 PM

Posted 08 September 2014 - 01:25 PM

This is the ESET log

#12 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:53 PM

Posted 09 September 2014 - 07:27 AM

Did you do anything suggested in my post No 8.?

How is the computer running?

#13 JSLayton

JSLayton
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:53 PM

Posted 09 September 2014 - 08:06 AM

I tried to run the instructions from post 8 but because it is what I would call a "psuedo-drive" then it won't allow chkdsk to run.  It's not actually a seperate partition.  It's Microsoft Click-To-Run 2010



#14 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:53 PM

Posted 09 September 2014 - 08:58 AM

If you want to continue with ESET refer to this page.
http://kb.eset.com/esetkb/index?page=content&id=SOLN405

Last item.

18 - Can I select the destination of the scan?

Yes, the new version of ESET Online Scanner provides an option to select the destination of the scan. This option can be found under Additional Settings.

Can your run ESET on C:\ only?

#15 JSLayton

JSLayton
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:53 PM

Posted 10 September 2014 - 11:34 AM

Here is the ESETScan with the Q:\ drive excluded

 

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\Fraveen 1.4-nova.dll.vir a variant of Win32/Toolbar.CrossRider.AI potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\Fraveen 1.4-nova.exe.vir a variant of Win32/Toolbar.CrossRider.AE potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Fraveen 1.4\Fraveen 1.4-novainstaller.exe.vir a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\f_in_box.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.AxImp.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Booster.UI.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Business.Connect.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Business.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Entity.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.exe.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Mediator.ActivePlayers.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Mediator.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Messengers.exe.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Services.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.WinCore.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.WinCore.WLM.WinEvents.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.WinCore.WLM15.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.WinCore.Yahoo.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Windows.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Iminent.Workflow.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Microsoft.DirectX.AudioVideoPlayback.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Microsoft.Expression.Interactions.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx64.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx86.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\System.Data.SQLite.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\System.Windows.Interactivity.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\WPFLocalizeExtension.dll.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\jfilemanager\LTV.exe.vir MSIL/Tuguu.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\jfilemanager\update.xml.vir Win32/DomaIQ.BC potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\LyricsSpeaker\128.dll.vir a variant of Win32/AdWare.AddLyrics.S application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha348\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha51\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaViewV1\MediaViewV1alpha1679\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\Installer.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\InstallerLibrary.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\InstallFirefoxExtension.dll.vir MSIL/Adware.Proxomoto.B application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\NewVersionUploader.exe.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\WindowsUpdater.exe.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MSR\backup\System Update kb70007\backup\InstallerLibrary.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3DTACTL.DLL.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL.vir a variant of Win32/Toolbar.MyWebSearch.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL.vir Win32/Toolbar.MyWebSearch.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL.vir Win32/Toolbar.MyWebSearch.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL.vir Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\F3WPHOOK.DLL.vir Win32/FunWeb potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL.vir Win32/Toolbar.MyWebSearch.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3HTML.DLL.vir Win32/Toolbar.MyWebSearch.F potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL.vir Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3IEOVR.DLL.vir Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL.vir Win32/Toolbar.MyWebSearch.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL.vir a variant of Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL.vir Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKNLCR.DLL.vir a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE.vir Win32/Toolbar.MyWebSearch.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE.vir a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\M3TPINST.DLL.vir Win32/Toolbar.MyWebSearch.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir Win32/Toolbar.MyWebSearch.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptimizerPro.exe.vir Win32/SpeedingUpMyPC.O application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrash.dll.vir a variant of Win32/SProtector.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProLauncher.exe.vir a variant of Win32/AdWare.SpeedingUpMyPC.D application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe.vir a variant of Win32/Adware.SpeedingUpMyPC.C application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir a variant of Win32/SpeedingUpMyPC application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RebateInformer\RebateI.dll.vir a variant of Win32/Toolbar.Inbox.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RebateInformer\RebateInf.exe.vir a variant of Win32/Toolbar.Inbox.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\rlcm.crx.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\rlls.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\rlvknlg.exe.vir a variant of Win32/Adware.RK.AE application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\components\rlxg.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\RelevantKnowledge\firefox\rlnx.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-bg.exe.vir a variant of Win32/Toolbar.CrossRider.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-bho.dll.vir a variant of Win32/Toolbar.CrossRider.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-buttonutil.dll.vir probably a variant of Win32/Toolbar.CrossRider.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-buttonutil.exe.vir a variant of Win32/Toolbar.CrossRider.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-buttonutil64.dll.vir a variant of Win64/Toolbar.Crossrider.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-buttonutil64.exe.vir probably a variant of Win64/Toolbar.Crossrider.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-codedownloader.exe.vir a variant of Win32/Toolbar.CrossRider.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Solid Savings-helper.exe.vir a variant of Win32/Toolbar.CrossRider.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Solid Savings\Uninstall.exe.vir a variant of Win32/Packed.VMDetector.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\supporter\Supporter_x64.dll.vir a variant of Win64/SProtector.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Uninstaller\Uninstall.exe.vir a variant of MSIL/DomaIQ.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta2669\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\w3i\UninstallHelper\UninstallHelper.exe.vir probably a variant of Win32/InstallIQ.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha141\uninstall.exe.vir a variant of Win32/Amonetize.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe.vir Win32/AdWare.Yontoo.F application
C:\AdwCleaner\Quarantine\C\ProgramData\BBestSaVeFuorYou\hV_j.dll.vir a variant of Win32/AdWare.MultiPlug.BN application
C:\AdwCleaner\Quarantine\C\ProgramData\BBestSaVeFuorYou\hV_j.exe.vir a variant of Win32/AdWare.MultiPlug.AG application
C:\AdwCleaner\Quarantine\C\ProgramData\BBestSaVeFuorYou\hV_j.x64.dll.vir a variant of Win64/Adware.MultiPlug.D application
C:\AdwCleaner\Quarantine\C\ProgramData\FinedBoestDeal\_bt9h.dll.vir a variant of Win32/AdWare.MultiPlug.BN application
C:\AdwCleaner\Quarantine\C\ProgramData\FinedBoestDeal\_bt9h.exe.vir a variant of Win32/AdWare.MultiPlug.AG application
C:\AdwCleaner\Quarantine\C\ProgramData\FinedBoestDeal\_bt9h.x64.dll.vir a variant of Win64/Adware.MultiPlug.D application
C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application
C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application
C:\AdwCleaner\Quarantine\C\ProgramData\VisualBee\VisualBeeSoftware.exe.vir a variant of Win32/Toolbar.Babylon.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\CommonLauncher.exe.vir a variant of Win32/SoundFrost.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\ContentAgent.exe.vir a variant of Win32/SoundFrost.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\ContentFinder.exe.vir Win32/SoundFrost.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Conduit\CT1269415\Download_EnergyAutoUpdateHelper.exe.vir Win32/Toolbar.Conduit.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\DownloadTerms\temp.dat.vir a variant of Win32/AdWare.Toolbar.AmyBar.A application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll.vir Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.26.9.505_0\APISupport\APISupport.dll.vir a variant of Win32/Conduit.SearchProtect.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.26.9.505_0\nativeMessaging\TBMessagingHost.exe.vir a variant of Win32/Toolbar.Conduit.AH potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.31.0.526_0\APISupport\APISupport.dll.vir Win32/Conduit.SearchProtect potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.31.0.526_0\nativeMessaging\TBMessagingHost.exe.vir a variant of Win32/Toolbar.Conduit.AH potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.31.0.526_0\plugins\ChromeApiPlugin.dll.vir a variant of Win32/Conduit.SearchProtect.N potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.11_0\BabMaint.x.vir a variant of Win32/Toolbar.Babylon.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.11_0\BabylonChromeToolBar.dll.vir Win32/Toolbar.Babylon.Q potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.11_0\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.332.1_0\plugins\rlcm.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\BrowserHelper.exe.vir a variant of MSIL/Toolbar.Linkury.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Interop.SHDocVw.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\MACTrackBarLib.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\NDde.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Newtonsoft.Json.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\QuickShare.exe.vir a variant of Win32/Toolbar.Linkury.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sgml.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sidb.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\siem.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sipb.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sismlp.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll.vir a variant of Win32/Toolbar.Linkury.F potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.XmlSerializers.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\Smartbar.Resources.Translations.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll.vir a variant of MSIL/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir a variant of MSIL/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\spbe.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\spbl.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sppsm.dll.vir a variant of MSIL/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\spsm.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\spusm.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srau.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srbhu.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srbs.dll.vir a variant of MSIL/Toolbar.Linkury.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srgu.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srns.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srpdm.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srprl.dll.vir a variant of MSIL/Toolbar.Linkury.F potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srpu.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srsbs.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srsbsau.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srsl.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\sruhs.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srus.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\srut.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\ar\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\es\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\fr\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\he\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_20.dll.vir Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_21.dll.vir Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_22.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_23.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_24.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_25.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\it\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\pt\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\ru\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Application\tr\Smartbar.Resources.LanguageSettings.resources.dll.vir a variant of MSIL/Toolbar.Linkury.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.DMP.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.NotepadPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.ScreenCapturePlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WordPlugin.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Smartbar\Common\ServicesPlugins\spup.dll.vir a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Solid Savings\gpedit.exe.vir Win32/AdWare.SmartApps.B application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\Solid Savings\SoftwareDetector.exe.vir Win32/AdWare.SmartApps.B application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\strongvault\StrongVaultApp.exe.vir MSIL/Adware.StrongVault.A application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\SwvUpdater\Updater.exe.vir a variant of Win32/Amonetize.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\Helper.dll.vir a variant of Win32/Toolbar.SearchSuite.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\Uninstall.exe.vir a variant of Win32/TorchMedia potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\Update\Download\TorchSetup.exe.vir a variant of Win32/TorchMedia potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.22.5.510_0\nativeMessaging\TBMessagingHost.exe.vir a variant of Win32/Toolbar.Conduit.AH potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.22.5.510_0\plugins\ConduitChromeApiPlugin.dll.vir a variant of Win32/Toolbar.Conduit.AH potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\10.22.5.510_0\TBHostSupport\TBHostSupport.dll.vir a variant of Win32/Toolbar.Conduit.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\torch\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.332.1_0\plugins\rlcm.dll.vir a variant of Win32/Adware.RK.AM application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\VisualBeeExe\conduitinstaller.exe.vir Win32/Toolbar.Conduit potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Local\VisualBeeExe\MyBabylonTB.exe.vir a variant of Win32/Toolbar.Babylon.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\LocalLow\Download_Energy\ldrtbDown.dll.vir a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\LocalLow\Download_Energy\tbDown.dll.vir a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\LocalLow\FunWebProducts\Installr\Cache\056A4E79.exe.vir a variant of Win32/Toolbar.MyWebSearch.O potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\CR\BabylonChrome1.crx.vir a variant of Win32/Toolbar.Babylon.Q potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\CR\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\FF\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\IE\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\BabylonToolbar\Shared\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Complitly\Complitly.dll.vir a variant of Win32/Complitly.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Complitly\KeepMeUpdated.exe.vir a variant of Win32/PredictAd.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Complitly\64\Complitly64.dll.vir a variant of Win64/Complitly.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Complitly\64\KeepMeUpdated.exe.vir a variant of Win32/PredictAd.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll.vir a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart.exe.vir a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart64.exe.vir Win64/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap.dll.vir a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap64.dll.vir Win64/Toolbar.DefaultTab.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe.vir Win32/Toolbar.DefaultTab.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe.vir a variant of Win32/Toolbar.DefaultTab.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\serv\ClickAndMark_2040-5250.exe.vir multiple threats
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\serv\Okiitan.exe.vir Win32/BrowseFox.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\serv\setup_istsearch.exe.vir probably a variant of Win32/SquareNet.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\VOPackage\Uninstall.exe.vir Win32/VOPackage.J potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Yontoo\YontooDesktop.exe.vir a variant of MSIL/WebCake.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\windows\Microsoft\SystemUpdatekb70007\Installer.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\windows\Microsoft\SystemUpdatekb70007\InstallerLibrary.dll.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe.vir MSIL/Adware.Proxomoto.A application
C:\AdwCleaner\Quarantine\C\windows\SysWOW64\f3PSSavr.scr.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Downloads\Software\7zip_installer_d162802.exe a variant of Win32/InstallIQ.A potentially unwanted application
C:\Downloads\Software\DictionaryBoss.exe Win32/AdInstaller potentially unwanted application
C:\Downloads\Software\intunemp3.exe a variant of Win32/InstallIQ.A potentially unwanted application
C:\Downloads\Software\SoftonicDownloader_for_limewire-music.exe Win32/SoftonicDownloader.E potentially unwanted application
C:\Program Files (x86)\ISTsearch\ISTsearch_Uninstall.exe probably a variant of Win32/SquareNet.C potentially unwanted application
C:\Program Files (x86)\Windows Live\Messenger\msimg32.dll Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Program Files (x86)\Windows Live\Messenger\riched20.dll Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Qoobox\Quarantine\C\Program Files (x86)\DictionaryBossEI\Installr\1.bin\NPv4EISb.dll.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Qoobox\Quarantine\C\Program Files (x86)\DictionaryBossEI\Installr\1.bin\v4EIPlug.dll.vir Win32/Toolbar.MyWebSearch potentially unwanted application
C:\Qoobox\Quarantine\C\Program Files (x86)\DictionaryBossEI\Installr\1.bin\v4EZSETP.dll.vir Win32/Toolbar.MyWebSearch.Q potentially unwanted application
C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\CommonLauncher.exe.vir a variant of Win32/SoundFrost.A potentially unwanted application
C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\ContentAgent.exe.vir a variant of Win32/SoundFrost.A potentially unwanted application
C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\ContentFinder.exe.vir a variant of Win32/SoundFrost.A potentially unwanted application
C:\Users\Owner\AppData\Roaming\launher\Setup.exe NSIS/TrojanDownloader.Agent.NMB trojan
C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll a variant of Win32/Toolbar.Linkury.G potentially unwanted application
C:\Windows\Installer\1b283ad.msi a variant of Win32/Toolbar.Babylon.Q potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\hk64tbDow0.dll a variant of Win64/Toolbar.Conduit.B potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\hktbDow0.dll a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\ldrtbDow0.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\ldrtbDown.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\tbDow0.dll a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\tbDow1.dll a variant of Win32/Toolbar.Conduit.Y potentially unwanted application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Download_Energy\tbDown.dll a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\hk64tbDow0.dll a variant of Win64/Toolbar.Conduit.B potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\hktbDow0.dll a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\ldrtbDow0.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\ldrtbDown.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\tbDow0.dll a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\tbDow1.dll a variant of Win32/Toolbar.Conduit.Y potentially unwanted application
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Download_Energy\tbDown.dll a variant of Win32/Toolbar.Conduit.B potentially unwanted application
 





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users