Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Malware won't budge, mysearch.com homepage, flashing pointer


  • This topic is locked This topic is locked
18 replies to this topic

#1 handerson5790

handerson5790

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:07:32 PM

Posted 28 March 2016 - 07:16 AM

Hi, 

 

Yesterday I tried to open a video file and somehow installed a bundle of malware on my computer. In the past 24 hours, I have gotten rid of TTwifi 1.0.0.1, Primary colors, GameCenter, and a gagillion other things that I can't remember the name of right now. I got rid of the most debilitating items in Safe Mode by just uninstalling them, running a full scan using McAfee, and running 2 (updated) Malwarebytes scans. I am now able to start my computer normally, but the Malware keep coming back. McAfee found and deleted 4 more trojans, and Malwarebytes finds like 15-85 pups every time I run it. I have been quarantining all of the results every time it runs. 

 

My homepage when I open Chrome is now mysearch.com, and I can't find a way to uninstall it. Also, my pointer is now blinking continually. 

 

I've obviously got something stubborn. Please help me get rid of it! I am using Windows 7. 

 

Thanks in advance! 



BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • BC Advisor
  • 12,900 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:32 PM

Posted 28 March 2016 - 07:55 AM

Welcome to BC...

 

Please post the last MBAM scan results. You can find that by clicking on the History button.....not the update history....scan results.

 

Use CCleaner to remove Temporary files, program caches, cookies, logs, etc. Use the Default settings. No need to use the

Registry Cleaning Tool...risky. Pay close attention while installing and UNcheck offers of toolbars....especially Google.

After install, open CCleaner and run by clicking on the Run Cleaner button in the bottom right corner.

CCleaner - PC Optimization and Cleaning - Free Download

 

Download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  • download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#3 handerson5790

handerson5790
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:07:32 PM

Posted 28 March 2016 - 08:07 AM

Thank you. Should I post the log files here or in another forum? I'm kind of confused about what is allowed to be posted where. 



#4 buddy215

buddy215

  • BC Advisor
  • 12,900 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:32 PM

Posted 28 March 2016 - 08:19 AM

Post the results in this topic...


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#5 buddy215

buddy215

  • BC Advisor
  • 12,900 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:32 PM

Posted 28 March 2016 - 08:29 AM

More info for posting MBAM scan log...

  • Click on the History tab >> Application Logs.
  • Double click on the scan log which shows the Date and time of the scan that showed the infections.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#6 handerson5790

handerson5790
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:07:32 PM

Posted 28 March 2016 - 04:58 PM

# AdwCleaner v5.106 - Logfile created 28/03/2016 at 09:18:59
# Updated 27/03/2016 by Xplode
# Database : 2016-03-28.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Hayley - HAYLEY-VAIO
# Running from : C:\Users\Hayley\Downloads\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
Service Found : cherimoya
Service Found : MPCProtectService
Service Found : nebynugyzbt
 
***** [ Folders ] *****
 
Folder Found : C:\Program Files (x86)\MPC Cleaner
Folder Found : C:\Program Files (x86)\FA70F400-1459123002-11DF-8101-5442497890B6
Folder Found : C:\Program Files (x86)\Primary Color
Folder Found : C:\ProgramData\FlashBeat
Folder Found : C:\ProgramData\Partner
Folder Found : C:\ProgramData\CloudPrinter
Folder Found : C:\ProgramData\WindowsMsg
Folder Found : C:\ProgramData\47f0877f-0653-0
Folder Found : C:\ProgramData\47f0877f-1ae7-1
Folder Found : C:\ProgramData\47f0877f-4445-1
Folder Found : C:\ProgramData\ed51621d-1b67-1
Folder Found : C:\ProgramData\ed51621d-3ac3-1
Folder Found : C:\ProgramData\ed51621d-6315-0
Folder Found : C:\ProgramData\Service1291
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
Folder Found : C:\Users\Hayley\AppData\Local\DeskBar
Folder Found : C:\Users\Hayley\AppData\Local\PackageAware
Folder Found : C:\Users\Hayley\AppData\Local\PriceFountain
Folder Found : C:\Users\Hayley\AppData\Local\TheBrowser
Folder Found : C:\Users\Hayley\AppData\Local\Temp\MPC
Folder Found : C:\Users\Hayley\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Users\Hayley\AppData\LocalLow\oovootoolbar
Folder Found : C:\Users\Hayley\AppData\Roaming\Yahoo!\Companion
Folder Found : C:\Users\Hayley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TheBrowser
Folder Found : C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\oovootoolbar
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\PackageAware
 
***** [ Files ] *****
 
File Found : C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bmnlcjabgnpnenekpadlanbbkooimhnj
File Found : C:\Windows\SysNative\roboot64.exe
 
***** [ DLL ] *****
 
 
***** [ Shortcuts ] *****
 
Shortcut Infected : C:\Users\boinc_master\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( %SNP% )
 
***** [ Scheduled tasks ] *****
 
Task Found : snp
Task Found : snf
Task Found : IBUpd
Task Found : SystemHealer Monitor
Task Found : SystemHealer Run Delay
Task Found : System HealerStartUp
Task Found : System HealerPeriod
Task Found : System Healer Task
Task Found : IBUpd2
Task Found : DNS Monitoring
Task Found : osTip
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SEARCHSCOPES\IELNKSRCH
Key Found : HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
Key Found : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
Key Found : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKCU\Software\Classes\CLSID\{17EF1FFB-0545-4C9A-BE64-78FF53338475}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{79F768ED-0B12-42EF-8257-36751A0ECF3A}]
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\DAILYPCCLEAN
Key Found : HKCU\Software\Microsoft\Tinstalls
Key Found : HKCU\Software\Yahoo\Companion
Key Found : HKCU\Software\Yahoo\YFriendsBar
Key Found : HKCU\Software\Zugo
Key Found : HKCU\Software\osTip
Key Found : HKCU\Software\AppDataLow\Software\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\SecureWebChannel
Key Found : HKLM\SOFTWARE\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Conduit
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\DAILYPCCLEAN
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Microsoft\Tinstalls
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Yahoo\Companion
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Yahoo\YFriendsBar
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Zugo
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\osTip
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\AppDataLow\Software\Yahoo\Companion
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Conduit
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\DAILYPCCLEAN
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Tinstalls
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Yahoo\Companion
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Yahoo\YFriendsBar
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Zugo
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\osTip
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AppDataLow\Software\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\4E30E037E0535E84D9E3349209D354D4
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\4E30E037E0535E84D9E3349209D354D4
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4E30E037E0535E84D9E3349209D354D4
Key Found : [x64] HKLM\SOFTWARE\Classes\Installer\Products\4E30E037E0535E84D9E3349209D354D4
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ielnksrch
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
Key Found : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
 
***** [ Web browsers ] *****
 
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.aflt", "axl");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.autoRvrt", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.cntry", "US");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.cv", "cv5");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dfltLng", "");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dfltSrch", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dfltlng", "en");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dfltsrch", "false");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.dnsErr", true);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.envrmnt", "production");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.excTlbr", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.hdrMd5", "3372B2A4E32032646C9262D50ECF3137");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.hmpg", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.hrdid", "5442497890B6D485");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.id", "5442497890B6D485");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.instlDay", "15557");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.instlRef", "axl");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.instlday", "15557");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.instlref", "axl");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.isdcmntcmplt", true);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.keywordurl", "");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2219:20:27");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.newTab", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.newtab", "false");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.pnu_base", "{\"newVrsn\":\"259\",\"lastVrsn\":\"259\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.prdct", "funmoods");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.prtnrId", "funmoods");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.prtnrid", "funmoods");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.savedVrsnTs", "1");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.sg", "none");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.similarsitesstorage-pid2", "da79d91d0047f945");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.smplGrp", "none");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.smplgrp", "none");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.srch", "");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.srchPrvdr", "Search");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.srchprvdr", "Search");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.tlbrId", "base");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136&q[...]
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.tlbrid", "base");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136&q[...]
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.vrsn", "1.5.23.22");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2219:20:27");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.vrsni", "1.5.23.22");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.vrsnts", "1.5.23.2219:20:27");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods.xpestat\\xpereportdata", "1-8-2012");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods_i.newTab", false);
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods_i.smplGrp", "none");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2219:20:27");
[C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Found : user_pref("browser.startup.homepage", "hxxp://www-mysearch.com/?site=shyosffdefault&prd=set_ff&s=G3Szamotn11427AD,cc136634-49f9-4006-ae59-4ea5d1238cf5,");
[C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : feed.sonic-search.com
 
*************************
 
C:\AdwCleaner\AdwCleaner[S1].txt - [20343 bytes] - [28/03/2016 09:18:59]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [20417 bytes] ##########
 
# AdwCleaner v5.106 - Logfile created 28/03/2016 at 09:24:31
# Updated 27/03/2016 by Xplode
# Database : 2016-03-28.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Hayley - HAYLEY-VAIO
# Running from : C:\Users\Hayley\Downloads\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
[-] Service Deleted : cherimoya
[-] Service Deleted : MPCProtectService
[-] Service Deleted : nebynugyzbt
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\Program Files (x86)\MPC Cleaner
[-] Folder Deleted : C:\Program Files (x86)\FA70F400-1459123002-11DF-8101-5442497890B6
[-] Folder Deleted : C:\Program Files (x86)\Primary Color
[-] Folder Deleted : C:\ProgramData\FlashBeat
[-] Folder Deleted : C:\ProgramData\Partner
[-] Folder Deleted : C:\ProgramData\CloudPrinter
[-] Folder Deleted : C:\ProgramData\WindowsMsg
[-] Folder Deleted : C:\ProgramData\47f0877f-0653-0
[-] Folder Deleted : C:\ProgramData\47f0877f-1ae7-1
[-] Folder Deleted : C:\ProgramData\47f0877f-4445-1
[-] Folder Deleted : C:\ProgramData\ed51621d-1b67-1
[-] Folder Deleted : C:\ProgramData\ed51621d-3ac3-1
[-] Folder Deleted : C:\ProgramData\ed51621d-6315-0
[-] Folder Deleted : C:\ProgramData\Service1291
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\DeskBar
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\PackageAware
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\PriceFountain
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\TheBrowser
[-] Folder Deleted : C:\Users\Hayley\AppData\Local\Temp\MPC
[-] Folder Deleted : C:\Users\Hayley\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
[-] Folder Deleted : C:\Users\Hayley\AppData\LocalLow\oovootoolbar
[-] Folder Deleted : C:\Users\Hayley\AppData\Roaming\Yahoo!\Companion
[-] Folder Deleted : C:\Users\Hayley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TheBrowser
[-] Folder Deleted : C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\oovootoolbar
[-] Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\PackageAware
 
***** [ Files ] *****
 
[-] File Deleted : C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bmnlcjabgnpnenekpadlanbbkooimhnj
[-] File Deleted : C:\Windows\SysNative\roboot64.exe
 
***** [ DLLs ] *****
 
 
***** [ Shortcuts ] *****
 
[-] Shortcut Disinfected : C:\Users\boinc_master\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
 
***** [ Scheduled tasks ] *****
 
[-] Task Deleted : snp
[-] Task Deleted : snf
[-] Task Deleted : IBUpd
[-] Task Deleted : SystemHealer Monitor
[-] Task Deleted : SystemHealer Run Delay
[-] Task Deleted : System HealerStartUp
[-] Task Deleted : System HealerPeriod
[-] Task Deleted : System Healer Task
[-] Task Deleted : IBUpd2
[-] Task Deleted : DNS Monitoring
[-] Task Deleted : osTip
 
***** [ Registry ] *****
 
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SEARCHSCOPES\IELNKSRCH
[-] Key Deleted : HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
[-] Key Deleted : HKCU\Software\Classes\CLSID\{17EF1FFB-0545-4C9A-BE64-78FF53338475}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{79F768ED-0B12-42EF-8257-36751A0ECF3A}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\DAILYPCCLEAN
[-] Key Deleted : HKCU\Software\Microsoft\Tinstalls
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\Zugo
[-] Key Deleted : HKCU\Software\osTip
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\SecureWebChannel
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Conduit
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\DAILYPCCLEAN
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Tinstalls
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Yahoo\Companion
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Zugo
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\osTip
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\4E30E037E0535E84D9E3349209D354D4
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\4E30E037E0535E84D9E3349209D354D4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4E30E037E0535E84D9E3349209D354D4
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{DDE8C2AA-5A3E-42B9-A535-39A73B24529D}
[-] Key Deleted : HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.aflt", "axl");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.autoRvrt", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.cntry", "US");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.cv", "cv5");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dfltLng", "");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dfltSrch", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dfltlng", "en");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dfltsrch", "false");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.dnsErr", true);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.envrmnt", "production");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.excTlbr", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.hdrMd5", "3372B2A4E32032646C9262D50ECF3137");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.hmpg", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.hrdid", "5442497890B6D485");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.id", "5442497890B6D485");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.instlDay", "15557");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.instlRef", "axl");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.instlday", "15557");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.instlref", "axl");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.isdcmntcmplt", true);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.keywordurl", "");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2219:20:27");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.newTab", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.newtab", "false");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.pnu_base", "{\"newVrsn\":\"259\",\"lastVrsn\":\"259\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.prdct", "funmoods");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.prtnrId", "funmoods");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.prtnrid", "funmoods");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.savedVrsnTs", "1");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.sg", "none");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.similarsitesstorage-pid2", "da79d91d0047f945");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.smplGrp", "none");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.smplgrp", "none");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.srch", "");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.srchPrvdr", "Search");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.srchprvdr", "Search");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.tlbrId", "base");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136&q[...]
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.tlbrid", "base");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuyDyEyEtByEzyyBzzzytD0ByC0DyEzzyDtN0D0Tzu0CtBtCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=942843136&q[...]
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.vrsn", "1.5.23.22");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2219:20:27");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.vrsni", "1.5.23.22");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.vrsnts", "1.5.23.2219:20:27");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods.xpestat\\xpereportdata", "1-8-2012");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods_i.newTab", false);
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2219:20:27");
[-] [C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxp://www-mysearch.com/?site=shyosffdefault&prd=set_ff&s=G3Szamotn11427AD,cc136634-49f9-4006-ae59-4ea5d1238cf5,");
[-] [C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : feed.sonic-search.com
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C1].txt - [19435 bytes] - [28/03/2016 09:24:31]
C:\AdwCleaner\AdwCleaner[S1].txt - [20537 bytes] - [28/03/2016 09:18:59]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [19583 bytes] ##########
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 7 Home Premium x64 
Ran by Hayley (Administrator) on Mon 03/28/2016 at  9:52:14.41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 33 
 
Failed to delete: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ERZGJ40 (Temporary Internet Files Folder) 
Successfully deleted: C:\ProgramData\28341ff220e0446c9fff27c4493d622e (Folder) 
Successfully deleted: C:\Users\Hayley\Appdata\LocalLow\company (Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\searchplugins\bing-zugo.xml (File) 
Successfully deleted: C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\user.js (File) 
Successfully deleted: C:\Users\Hayley\AppData\Roaming\nico mak computing (Folder) 
Successfully deleted: C:\Program Files (x86)\GUTFE19.tmp (File) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ERZGJ40 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4MV35QRW (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86N2NB1O (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AIZF3ECN (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EX46214F (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NZ1JNMB1 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q6X9DVQO (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YBOT4SBM (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZC2TND0Z (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\system32\Drivers\{552ca813-de15-4dfe-937d-e33fb2b3d476}Gw64.sys (File) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4MV35QRW (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86N2NB1O (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AIZF3ECN (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EX46214F (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NZ1JNMB1 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q6X9DVQO (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YBOT4SBM (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZC2TND0Z (Temporary Internet Files Folder) 
 
 
 
Registry: 4 
 
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\{552ca813-de15-4dfe-937d-e33fb2b3d476}Gw64 (Registry Key) 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0a28f54-b08f-4049-a9bf-8d33bd1e9222} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0a28f54-b08f-4049-a9bf-8d33bd1e9222} (Registry Key)
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 03/28/2016 at  9:56:31.67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 7 Home Premium x64 
Ran by Hayley (Administrator) on Mon 03/28/2016 at 17:42:54.57
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 10 
 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ERZGJ40 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86GW8JD7 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OLV1LLJ3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PNG9ANNJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Hayley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TU378WHB (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ERZGJ40 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86GW8JD7 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OLV1LLJ3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PNG9ANNJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TU378WHB (Temporary Internet Files Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 03/28/2016 at 17:47:37.30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 


#7 handerson5790

handerson5790
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:07:32 PM

Posted 28 March 2016 - 05:00 PM

I tried to do Esets twice. Both times it took 2.5 hours to get to 90%, found 36 infected files, and then the computer froze and I lost the logs. 



#8 buddy215

buddy215

  • BC Advisor
  • 12,900 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:32 PM

Posted 28 March 2016 - 07:03 PM

As you can see....a ton of crapola was found and removed.

 

It is likely that most of what Eset was identifying was in the Quarantine folder of AdwCleaner. Run AdwCleaner

one more time as it often finds more on the second scan. Be sure to click on Clean when the scan finishes. Then

after reboot if it asks you to, open AdwCleaner and click on Uninstall.

 

After doing the above, close all other programs, browsers, etc.  Disable all real time security program

you have running such as antivirus programs. Then attempt to run the Eset scan.

If still unsuccessful, scan using Emsisoft.

 

You didn't post the results of the MBAM scan that you ran before starting this topic. Please do that per instructions in my post #5.

 

  • Download the Emsisoft Emergency Kit and execute it. From there, click on the Extract button to extract the program in the EEK folder
  • Once the extraction is complete, Emsisoft Emergency Kit will open, and suggest you to run an online update before using the program. Click on Yes to launch it.
  • After the update, click on Malware Scan under 2. Scan and accept to let Emsisoft Emergency Kit detect PUPs (click on Yes).
  • Once the scan is complete, make sure that every item in the list is checked, and click on Quarantine selected
  • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
  • After the restart, click on the Start Emsisoft Emergency Kit icon again on your desktop to open it
  • This time, click on Logs
  • From there, go under the Quarantine Log tab, and click on the Export button
  • Save the log on your desktop, then open it, and copy/paste its content in your next reply

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#9 handerson5790

handerson5790
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:07:32 PM

Posted 28 March 2016 - 09:05 PM

From Eset: 

 

C:\Users\All Users\xedmal\Jobtokix.dll a variant of Win64/Toolbar.Linkury.L potentially unwanted application
C:\Users\All Users\xedmal\xedmal.exe a variant of Win32/Toolbar.Linkury.AT potentially unwanted application
C:\Program Files\Kezkeojze\Loblijky.dll a variant of Win32/Toolbar.Perion.AB potentially unwanted application cleaned by deleting
C:\Program Files\Kezkeojze\Oryrnic.dll a variant of Win32/Toolbar.Perion.AC potentially unwanted application cleaned by deleting
C:\Program Files\Kezkeojze\Ovyffu.dll a variant of Win32/Toolbar.Perion.AC potentially unwanted application cleaned by deleting
C:\ProgramData\xedmal\Jobtokix.dll a variant of Win64/Toolbar.Linkury.L potentially unwanted application cleaned by deleting
C:\ProgramData\xedmal\xedmal.exe a variant of Win32/Toolbar.Linkury.AT potentially unwanted application cleaned by deleting (after the next restart)
C:\Users\Hayley\AppData\Local\Temp\5d964b0f.a a variant of Win32/IStartSurf.B potentially unwanted application cleaned by deleting
C:\Users\Hayley\AppData\Local\Temp\6D93.tmp.exe a variant of Win32/InstallCore.ACY.gen potentially unwanted application cleaned by deleting
C:\Users\Hayley\AppData\Local\Temp\B8E3.tmp.exe a variant of Win32/InstallCore.ACY.gen potentially unwanted application cleaned by deleting
C:\Users\Hayley\AppData\Local\Temp\EB68.tmp.exe a variant of Win32/InstallCore.ACY.gen potentially unwanted application cleaned by deleting
C:\Users\Hayley\AppData\Local\Temp\nshFCA.tmp a variant of Win32/Adware.ConvertAd.AHH application cleaned by deleting
C:\Users\Hayley\AppData\Local\Temp\nsn2A4C.tmp a variant of Win32/Adware.ConvertAd.ADW application cleaned by deleting
C:\Users\Hayley\AppData\Local\Temp\00019975\casrss.exe a variant of Win32/TrojanDownloader.Agent.BWM trojan cleaned by deleting
C:\Users\Hayley\AppData\Local\Temp\is-9RB94.tmp\components3 Win32/AdWare.Linkular.AH application cleaned by deleting
C:\Users\Hayley\AppData\Local\Temp\is-FQQ30.tmp\cibtdm.exe a variant of Win32/Adware.RVplatform.C application cleaned by deleting
C:\Users\Hayley\AppData\Local\Temp\is-RMR4Q.tmp\print.exe a variant of Win32/TrojanDownloader.Agent.BWM trojan cleaned by deleting
C:\Users\Hayley\AppData\Roaming\comter\esttive.dll a variant of Win64/Adware.Hicosmea.I application cleaned by deleting (after the next restart)
C:\Users\Hayley\AppData\Roaming\comter\fulocdea.dll a variant of Win32/Adware.Hicosmea.J application cleaned by deleting
C:\Users\Hayley\AppData\Roaming\Mozilla\Firefox\Profiles\yfezczhx.default\extensions\{e57c0f3f-0ca0-4e28-9c26-1286d8f1f266}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting
C:\Users\Hayley\AppData\Roaming\Puhziml\Puhziml.exe a variant of Win32/Adware.PennyBee.AH application cleaned by deleting (after the next restart)
C:\Users\Hayley\Downloads\essetup.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application deleted
C:\Windows\Temp\bobca\Ipiasg.din a variant of Win32/Adware.PennyBee.AH application cleaned by deleting
 


#10 handerson5790

handerson5790
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:07:32 PM

Posted 28 March 2016 - 09:08 PM

This was the original MBAM log. After that, the subsequent scans did not leave a log that I can find either in the program or navigating into the program folders. 

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 3/27/2016
Scan Time: 8:56:34 PM
Logfile: 
Administrator: Yes
 
Version: 2.00.3.1025
Malware Database: v2015.01.29.11
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Hayley
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 389257
Time Elapsed: 29 min, 38 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 2
PUP.Optional.Softonic.A, HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, Quarantined, [37f804f9038602348ca38cf960a3ce32], 
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TutoTag, Quarantined, [b7788a73a7e21e18f9c6ef0f05ffc040], 
 
Registry Values: 3
PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_us_021010280, Quarantined, [58d77687c5c40f275621bcc9996a12ee], 
PUP.Optional.Recover.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|rec_en_236, Quarantined, [78b744b968213df96e234838679c7b85], 
PUM.LowRiskFileTypes, HKU\S-1-5-21-800099794-227068069-1844908692-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS|LowRiskFileTypes, .avi;.bat;.com;.cmd;.exe;.htm;.html;.lnk;.mpg;.mpeg;.mov;.mp3;.msi;.m3u;.rar;.reg;.txt;.vbs;.wav;.zip;, Quarantined, [7db2ae4fd6b357df2b89b7d93cc78e72]
 
Registry Data: 0
(No malicious items detected)
 
Folders: 2
PUP.Optional.PriceFountain.A, C:\Users\Hayley\AppData\Local\PriceFountain, Quarantined, [270898659cedf2447a35ed7d8c771be5], 
PUP.Optional.PriceFountain.A, C:\Users\Hayley\AppData\Local\PriceFountain\logs, Quarantined, [270898659cedf2447a35ed7d8c771be5], 
 
Files: 4
Adware.Bundle, C:\Users\Hayley\AppData\Local\Temp\_ir_sf_temp_0\waits.exe, Quarantined, [4be48a73b6d3c37378b3d17013ee56aa], 
PUP.Optional.AZLyrics.A, C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage, Quarantined, [4ee10bf25b2e44f29346bdc840c32cd4], 
PUP.Optional.AZLyrics.A, C:\Users\Hayley\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal, Quarantined, [bf70847995f470c6fcddfe870ef5a759], 
PUP.Optional.PriceFountain.A, C:\Users\Hayley\AppData\Local\PriceFountain\logs\installation.log, Quarantined, [270898659cedf2447a35ed7d8c771be5], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)


#11 handerson5790

handerson5790
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:07:32 PM

Posted 28 March 2016 - 09:11 PM

I'm having a  kind of major issue with Albireo adware right now, which is why I keep posting everything piecemeal. The pop-ups keep screwing up the window and redirecting me. 

 

The www-mysearch.com homepage is resolved though. 

 

Thank you so much for your help! 



#12 buddy215

buddy215

  • BC Advisor
  • 12,900 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:32 PM

Posted 29 March 2016 - 05:25 AM

Eset found remnants of 2 trojans that were likely responsible for much of the adware being downloaded to your computer.

 

Reset Google Chrome

You can reset your browser settings in Chrome any time. You might need to do this if apps or extensions you installed changed your settings without your knowledge. Your saved bookmarks and passwords won't be cleared or changed.

  1. Open Chrome.
  2. In the top right, click the Chrome menu
  3. Click Settings.
  4. At the bottom, click Show advanced settings.
  5. Under the section "Reset settings,” click Reset settings.
  6. In the box that appears, click Reset.

 

Run CCleaner to clean up the computer. Then.....

 

Post the three lists mentioned below using CCleaner.

Open CCleaner and click on Tools. Choose Startups. On that page you will see a list of Windows Startups and at the top tabs for each browser and Scheduled Tasks.

At the bottom right of that page you will see a button when clicked will allow you to Copy and Paste the list of Windows Startups and Scheduled Tasks into your next

post. Please do that.

 

Open CCleaner and click on Tools. Choose Uninstall. On that page you will see a list of programs installed on your computer and at the bottom right of that page you

will see a button when clicked will allow you to Copy and Paste that list in your next post. Please do that.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#13 handerson5790

handerson5790
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:07:32 PM

Posted 29 March 2016 - 08:20 PM

Hi! 

 

First off, let me say that my computer is running SO MUCH BETTER TODAY! The last thing I did yesterday was the Eset scan. Today, no pop-ups, faster startup, no rapidly blinking pointer. I'm sure there could still be something lurking, but it is really running a million times better. 

 

I reset Chrome and ran CClean. 

 

Here are the CClean lists you asked for: 

 

Startup Windows: 

Yes HKCU:Run ApplePhotoStreams Apple Inc. C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
Yes HKCU:Run BingSvc © 2015 Microsoft Corporation C:\Users\Hayley\AppData\Local\Microsoft\BingSvc\BingSvc.exe
Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
Yes HKCU:Run conhost C:\Users\Hayley\AppData\Roaming\Microsoft\conhost.exe
Yes HKCU:Run Dropbox Update Dropbox, Inc. "C:\Users\Hayley\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
Yes HKCU:Run Google Update Google Inc. "C:\Users\Hayley\AppData\Local\Google\Update\GoogleUpdate.exe" /c
Yes HKCU:Run iCloudServices Apple Inc. C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
Yes HKCU:Run MobileDocuments C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
Yes HKCU:Run NETGEARGenie NETGEAR "C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe" -mini -redirect
Yes HKLM:Run Adobe ARM Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
Yes HKLM:Run Adobe Reader Speed Launcher Adobe Systems Incorporated "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Yes HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
Yes HKLM:Run ConnectionCenter Citrix Systems, Inc. "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
Yes HKLM:Run GrooveMonitor Microsoft Corporation "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
Yes HKLM:Run HotKeysCmds Intel Corporation C:\Windows\system32\hkcmd.exe
Yes HKLM:Run HP Software Update Hewlett-Packard C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
Yes HKLM:Run IAStorIcon Intel Corporation C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
Yes HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
Yes HKLM:Run IntelWireless Intel® Corporation "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
Yes HKLM:Run ISBMgr.exe Sony Corporation "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
Yes HKLM:Run iTunesHelper Apple Inc. "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
Yes HKLM:Run McAfeeUpdaterUI McAfee, Inc. "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
Yes HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
Yes HKLM:Run PMBVolumeWatcher Sony Corporation C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
Yes HKLM:Run pnusbclitray pnusbclitray.exe
Yes HKLM:Run Redirector Citrix Systems, Inc. "C:\Program Files (x86)\Citrix\ICA Client\redirector.exe" /startup
Yes HKLM:Run RtHDVBg Realtek Semiconductor C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 
Yes HKLM:Run RtHDVCpl Realtek Semiconductor C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
Yes HKLM:Run SecureW2 Tray SecureW2 B.V. C:\Program Files (x86)\SecureW2\sw2_tray.exe
Yes HKLM:Run ShStatEXE McAfee, Inc. "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
Yes HKLM:Run SmartWiHelper Sony Electronics Corporation "C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup
Yes HKLM:Run SunJavaUpdateSched Sun Microsystems, Inc. "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
Yes HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
Yes Startup Common Bluetooth.lnk Broadcom Corporation. C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Yes Startup Common Device Detector 3.lnk OLYMPUS IMAGING CORP. C:\Program Files (x86)\Olympus\DeviceDetector\DevDtct2.exe
Yes Startup Common HP Digital Imaging Monitor.lnk Hewlett-Packard Co. C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
Yes Startup User Dropbox.lnk Dropbox, Inc. C:\Users\Hayley\AppData\Roaming\Dropbox\bin\Dropbox.exe
Yes Startup User OneNote 2007 Screen Clipper and Launcher.lnk Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
 

Startup Scheduled Tasks: 

Yes Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Yes Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes Task DropboxUpdateTaskUserS-1-5-21-800099794-227068069-1844908692-1005Core Dropbox, Inc. C:\Users\Hayley\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
Yes Task DropboxUpdateTaskUserS-1-5-21-800099794-227068069-1844908692-1005UA Dropbox, Inc. C:\Users\Hayley\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
Yes Task G2MUpdateTask-S-1-5-21-800099794-227068069-1844908692-1005 Citrix Online, a division of Citrix Systems, Inc. C:\Users\Hayley\AppData\Local\Citrix\GoToMeeting\4670\g2mupdate.exe
Yes Task G2MUploadTask-S-1-5-21-800099794-227068069-1844908692-1005 Citrix Online, a division of Citrix Systems, Inc. C:\Users\Hayley\AppData\Local\Citrix\GoToMeeting\4670\g2mupload.exe
Yes Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
Yes Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Yes Task GoogleUpdateTaskUserS-1-5-21-800099794-227068069-1844908692-1005Core Google Inc. C:\Users\Hayley\AppData\Local\Google\Update\GoogleUpdate.exe /c
Yes Task GoogleUpdateTaskUserS-1-5-21-800099794-227068069-1844908692-1005UA Google Inc. C:\Users\Hayley\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Yes Task Mimnyds C:\PROGRA~1\KEZKEO~1\Uguykh.bat
Yes Task SecureW2 Task SecureW2 B.V. C:\Program Files (x86)\SecureW2\sw2_tray.exe
Yes Task thpm2104063961126221479 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\thpm2104063961126221479.tmp
Yes Task thpm5885264203745478740 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\thpm5885264203745478740.tmp
Yes Task VAIO Care "%ProgramFiles%\Sony\VAIO Care\VCsystray.exe"
Yes Task VAIO Care Support "%ProgramFiles%\Sony\VAIO Care\VCSpt.exe"
Yes Task win2066888880 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\win2066888880.exe
Yes Task win4036e0 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\win4036e0.dat
Yes Task win765813708 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\win765813708.exe
Yes Task {146A0EDE-3C00-47E4-BF19-3CE9B18DB42D} Microsoft Corporation C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\Saildubdom\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\Saildubdom\uninstall.dat" -a uninstallme D6CDD76C-BC79-48B0-9B2A-4D8657743145 DeviceId=06820469-219e-69a3-5ead-1ad38b0e8e1c BarcodeId=51130006 ChannelId=6 DistributerName=APSFInsTerra
 
Uninstall: 
Adobe AIR Adobe Systems Inc. 7/29/2010 1.5.3.9130
Adobe Flash Player 21 ActiveX Adobe Systems Incorporated 3/24/2016 4.45 MB 21.0.0.197
Adobe Flash Player 21 NPAPI Adobe Systems Incorporated 3/24/2016 5.06 MB 21.0.0.197
Adobe Reader 9.5.1 Adobe Systems Incorporated 8/5/2012 103 MB 9.5.1
Apple Application Support Apple Inc. 9/1/2014 93.4 MB 3.0.6
Apple Mobile Device Support Apple Inc. 9/1/2014 22.7 MB 7.1.2.6
Apple Software Update Apple Inc. 2/3/2012 2.38 MB 2.1.3.127
Application Manager for VAIO 9/15/2010
ArcSoft Magic-i Visual Effects 2 ArcSoft 9/15/2010 38.0 MB 2.0.1.115
ArcSoft WebCam Companion 3 ArcSoft 1/19/2011 3.0.21.390
Audacity 2.1.0 Audacity Team 5/18/2015 49.8 MB 2.1.0
Bonjour Apple Inc. 2/3/2012 2.04 MB 3.0.0.10
CCleaner Piriform 3/28/2016 5.16
Citrix Online Launcher Citrix 2/18/2014 286 KB 1.0.168
Citrix Receiver Citrix Systems, Inc. 2/26/2016 57.7 MB 14.4.0.8014
comter 7/29/2010
Corel WinDVD Corel Inc. 7/29/2010 181 MB 10.0.5.297
Dropbox Dropbox, Inc. 3/19/2016 3.16.1
ESET Online Scanner v3 3/28/2016
Evernote Evernote Corp. 7/29/2010 80.9 MB 3.5.4.2224
Google Chrome Google Inc. 10/6/2014 49.0.2623.108
Google Talk Plugin Google 12/16/2015 15.1 MB 5.41.3.0
GoToMeeting 7.14.1.4670 CitrixOnline 3/23/2016 7.14.1.4670
HP Update Hewlett-Packard 10/29/2010 3.72 MB 4.000.011.006
iCloud Apple Inc. 11/7/2013 156 MB 3.0.2.163
Intel® Control Center Intel Corporation 7/29/2010 1.2.1.1007
Intel® Graphics Media Accelerator Driver Intel Corporation 7/29/2010 8.15.10.2119
Intel® Management Engine Components Intel Corporation 7/29/2010 6.0.0.1179
Intel® PROSet/Wireless WiFi Software Intel Corporation 7/29/2010 132 MB 13.02.1000
Intel® Rapid Storage Technology Intel Corporation 7/29/2010 9.6.0.1014
Intel® Turbo Boost Technology Driver Intel Corporation 7/29/2010 01.02.00.1002
Intel® Wireless Display Intel Corporation 7/29/2010 86.3 MB 1.2.15.0
iSEEK AnswerWorks English Runtime Vantage Linguistics 3/24/2013 4.77 MB 010.000.0101
iTunes Apple Inc. 9/1/2014 219 MB 11.3.1.2
Java™ 6 Update 20 (64-bit) Sun Microsystems, Inc. 7/29/2010 90.5 MB 6.0.200
Java™ 6 Update 35 Oracle 9/1/2012 95.7 MB 6.0.350
Linksys Connect Linksys LLC 10/26/2014 1.5.13291.0
Malwarebytes Anti-Malware version 2.0.4.1028 Malwarebytes Corporation 3/28/2016 57.2 MB 2.0.4.1028
McAfee Agent McAfee, Inc. 10/29/2010 16.8 MB 4.0.0.1180
McAfee VirusScan Enterprise McAfee, Inc. 10/29/2010 75.3 MB 8.7.0
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 11/28/2010 38.8 MB 4.0.30319
Microsoft Office Enterprise 2007 Microsoft Corporation 5/23/2013 12.0.6612.1000
Microsoft Office File Validation Add-In Microsoft Corporation 5/15/2014 10.9 MB 14.0.5130.5003
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs Microsoft Corporation 3/16/2012 132 KB 12.0.4518.1014
Microsoft Silverlight Microsoft Corporation 1/14/2016 398 MB 5.1.41212.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 7/29/2010 1.72 MB 3.1.0000
Microsoft SQL Server Compact 3.5 SP2 ENU Microsoft Corporation 10/20/2011 3.39 MB 3.5.8080.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 5/23/2013 298 KB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 7/29/2010 788 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 7/29/2010 788 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 5/23/2013 788 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 7/29/2010 596 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 7/29/2010 596 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 5/23/2013 600 KB 9.0.30729.6161
MSXML 4.0 SP3 Parser Microsoft Corporation 7/29/2010 1.47 MB 4.30.2100.0
MSXML 4.0 SP3 Parser (KB2721691) Microsoft Corporation 7/23/2012 1.53 MB 4.30.2114.0
MSXML 4.0 SP3 Parser (KB2758694) Microsoft Corporation 1/10/2013 1.54 MB 4.30.2117.0
MSXML 4.0 SP3 Parser (KB973685) Microsoft Corporation 11/2/2010 1.53 MB 4.30.2107.0
NETGEAR Genie NETGEAR Inc. 10/6/2013 2.2.28.24.exe 
Olympus Digital Wave Player 12/28/2011
PlayReady PC Runtime amd64 Microsoft Corporation 7/29/2010 2.05 MB 1.3.0
QuickTime Apple Inc. 11/7/2013 74.6 MB 7.74.80.86
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 7/29/2010 6.0.1.6098
SecureW2 Enterprise Client 3.5.9 6/26/2014
SmartWi Connection Utility Sony Corporation 7/29/2010 4.11.4.20100722.2739
Synaptics Pointing Device Driver Synaptics Incorporated 7/29/2010 15.0.9.0
Unity Web Player Unity Technologies ApS 6/28/2014 12.0 MB 4.5.1f3
VAIO Help and Support Sony Corporation 7/29/2010 12.00.0622
vWorkspace Connector for Windows Dell, Inc. 7/8/2015 39.5 MB 8.5.307.1955
WIDCOMM Bluetooth Software Broadcom Corporation 7/29/2010 183 MB 6.3.0.5600
Windows Automatic Update Service (WAUS) University of Pennsylvania 6/26/2014 1.48 MB 1.1.0
Windows Driver Package - OLYMPUS IMAGING CORP. (VNUSB) VNUSB  (09/29/2009 2.0.0.0) OLYMPUS IMAGING CORP. 1/2/2012 09/29/2009 2.0.0.0
Windows Live Essentials Microsoft Corporation 5/4/2014 15.4.3502.0922
Windows Live Sync Microsoft Corporation 7/29/2010 2.78 MB 14.0.8117.416
 

 



#14 buddy215

buddy215

  • BC Advisor
  • 12,900 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:32 PM

Posted 29 March 2016 - 09:17 PM

Need to submit conhost.exe  to VirusTotal - Free Online Virus and Malware Scan

It's in your Windows Startups and I'm not sure it should be there. Post the link to the scan results and be sure to have it scanned and not

accept any previous scan results.

Yes HKCU:Run conhost C:\Users\Hayley\AppData\Roaming\Microsoft\conhost.exe

 

Disable these Windows Startups: Use CCleaner by clicking on each item and then choose Disable on the right.

Yes HKCU:Run ApplePhotoStreams Apple Inc. C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
Yes HKCU:Run BingSvc © 2015 Microsoft Corporation C:\Users\Hayley\AppData\Local\Microsoft\BingSvc\BingSvc.exe
Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
Yes HKCU:Run Dropbox Update Dropbox, Inc. "C:\Users\Hayley\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
Yes HKCU:Run Google Update Google Inc. "C:\Users\Hayley\AppData\Local\Google\Update\GoogleUpdate.exe" /c
Yes HKCU:Run iCloudServices Apple Inc. C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
Yes HKLM:Run Adobe ARM Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
Yes HKLM:Run Adobe Reader Speed Launcher Adobe Systems Incorporated "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Yes HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
Yes HKLM:Run ConnectionCenter Citrix Systems, Inc. "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
Yes HKLM:Run HP Software Update Hewlett-Packard C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
Yes HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
Yes McAfeeUpdaterUI McAfee, Inc. "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
Do not disable McAfee Startups if it is up to date and is active.
Yes HKLM:Run ShStatEXE McAfee, Inc. "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
Yes HKLM:Run SunJavaUpdateSched Sun Microsystems, Inc. "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
Yes Startup User Dropbox.lnk Dropbox, Inc. C:\Users\Hayley\AppData\Roaming\Dropbox\bin\Dropbox.exe
Yes Startup User OneNote 2007 Screen Clipper and Launcher.lnk Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
 
Disable these Scheduled Tasks: Use CCleaner by clicking on each item and choosing Disable on the right.
Yes Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Yes Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes Task DropboxUpdateTaskUserS-1-5-21-800099794-227068069-1844908692-1005Core Dropbox, Inc. C:\Users\Hayley\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
Yes Task DropboxUpdateTaskUserS-1-5-21-800099794-227068069-1844908692-1005UA Dropbox, Inc. C:\Users\Hayley\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
Yes Task G2MUpdateTask-S-1-5-21-800099794-227068069-1844908692-1005 Citrix Online, a division of Citrix Systems, Inc. C:\Users\Hayley\AppData\Local\Citrix\GoToMeeting\4670\g2mupdate.exe
Yes Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
Yes Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Yes Task GoogleUpdateTaskUserS-1-5-21-800099794-227068069-1844908692-1005Core Google Inc. C:\Users\Hayley\AppData\Local\Google\Update\GoogleUpdate.exe /c
Yes Task GoogleUpdateTaskUserS-1-5-21-800099794-227068069-1844908692-1005UA Google Inc. C:\Users\Hayley\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Do you know what this is...Yes Task Mimnyds C:\PROGRA~1\KEZKEO~1\Uguykh.bat....if not, Disable for now.
Yes Task thpm2104063961126221479 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\thpm2104063961126221479.tmp
Yes Task thpm5885264203745478740 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\thpm5885264203745478740.tmp
Yes Task VAIO Care Support "%ProgramFiles%\Sony\VAIO Care\VCSpt.exe"
Yes Task win2066888880 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\win2066888880.exe
Yes Task win4036e0 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\win4036e0.dat
Yes Task win765813708 \\.\globalroot\Device\HarddiskVolume3\Users\Hayley\AppData\Local\Temp\win765813708.exe
Yes Task {146A0EDE-3C00-47E4-BF19-3CE9B18DB42D} Microsoft Corporation C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\Saildubdom\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\Saildubdom\uninstall.dat" -a uninstallme D6CDD76C-BC79-48B0-9B2A-4D8657743145 DeviceId=06820469-219e-69a3-5ead-1ad38b0e8e1c BarcodeId=51130006 ChannelId=6 DistributerName=APSFInsTerra
 
Uninstall these programs:
Adobe AIR Adobe Systems Inc. 7/29/2010 1.5.3.9130
Adobe Reader 9.5.1 Adobe Systems Incorporated 8/5/2012 103 MB 9.5.1 (OR UPDATE)
Bonjour Apple Inc. 2/3/2012 2.04 MB 3.0.0.10
ESET Online Scanner v3 3/28/2016
Java™ 6 Update 20 (64-bit) Sun Microsystems, Inc. 7/29/2010 90.5 MB 6.0.200
Java™ 6 Update 35 Oracle 9/1/2012 95.7 MB 6.0.350
McAfee Agent McAfee, Inc. 10/29/2010 16.8 MB 4.0.0.1180 (OR UPDATE)
McAfee VirusScan Enterprise McAfee, Inc. 10/29/2010 75.3 MB 8.7.0 (OR UPDATE)
Unity Web Player Unity Technologies ApS 6/28/2014 12.0 MB 4.5.1f3
Windows Live Essentials Microsoft Corporation 5/4/2014 15.4.3502.0922
Windows Live Sync Microsoft Corporation 7/29/2010 2.78 MB 14.0.8117.416
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#15 handerson5790

handerson5790
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:07:32 PM

Posted 30 March 2016 - 09:24 AM

Hi! 

 

I was unable to scan the conhost.exe file because I couldn't find it. I went to C:\Users\Hayley\AppData\Roaming\Microsoft, searched "conhost" and "conhost,exe", and there were no matching results. It does still appear in CCleaner though. 

 

I disabled all of the startup windows you listed, uninstalled all of the programs you listed, and updated adobe reader. The exception to that was McAfee. I would like to replace it and think I should have something else running before I get rid of it. Sophos was recommended to me--is this a good alternative or would you recommend something else? Once I have something else running, I'll give McAfee the ax. 

 

I was not able to disable any of the startup scheduled tasks. For each one I selected, I got an error that says "Failed to enable/disable startup item: Transaction support within the specified resource manager is not started or was shut down due to an error." 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users