Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

On and off issues loading websites and downloading


  • Please log in to reply
8 replies to this topic

#1 cantib

cantib

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:05 AM

Posted 01 August 2017 - 11:06 AM

Hi, I'm helping a friend with their computer. It is running Windows Vista Home Premium. She's concerned that there may be malware installed on the computer. She sometimes has trouble loading websites including facebook and outlook.com.She also has trouble downloading things like browser addons and attachments. I used malwarebytes, AdwCleaner, and Junkware Removal Tool but they don't seem to have fixed the problem. I will post the logs.

 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 7/31/17
Scan Time: 11:37 AM
Log File: malwarebytes results.txt
Administrator: Yes

-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.0
Update Package Version: 1.0.2475
License: Free

-System Information-
OS: Windows Vista Service Pack 2
CPU: x64
File System: NTFS
User: Mary-PC\Mary

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 447583
Threats Detected: 104
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 11 min, 55 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 20
PUP.Optional.ArcadeGiant, HKU\S-1-5-21-3439958544-1267488918-2103452222-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{4FD3B33A-372C-439E-BB87-017365EC693C}, No Action By User, [6271], [167660],1.0.2475
PUP.Optional.ArcadeGiant, HKU\S-1-5-21-3439958544-1267488918-2103452222-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{4FD3B33A-372C-439E-BB87-017365EC693C}, No Action By User, [6271], [167660],1.0.2475
PUP.Optional.PhraseFinder, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pfnfd_1_10_0_9, No Action By User, [6454], [241669],1.0.2475
PUP.Optional.Perion, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WNLT, No Action By User, [1463], [183619],1.0.2475
PUP.Optional.SupraSavings, HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\SOFTWARE\APPDATALOW\SOFTWARE\suprasavings, No Action By User, [9282], [243689],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, No Action By User, [12047], [185843],1.0.2475
PUP.Optional.BoosterPop, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\boosterpop, No Action By User, [1797], [235947],1.0.2475
PUP.Optional.InstallCore, HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\SOFTWARE\InstallCore, No Action By User, [2], [239563],1.0.2475
PUP.Optional.Squeaky, HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\SOFTWARE\Squeaky, No Action By User, [8729], [243478],1.0.2475
PUP.Optional.SupraSavings, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\suprasavings, No Action By User, [9282], [243693],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\CLASSES\Extension.ExtensionHelperObject, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\CLASSES\Extension.ExtensionHelperObject.1, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Extension.ExtensionHelperObject, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Extension.ExtensionHelperObject.1, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Extension.ExtensionHelperObject, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Extension.ExtensionHelperObject.1, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.WebAssistant, HKU\S-1-5-21-3439958544-1267488918-2103452222-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{336D0C35-8A85-403A-B9D2-65C292C39087}, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.WebAssistant, HKU\S-1-5-21-3439958544-1267488918-2103452222-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{336D0C35-8A85-403A-B9D2-65C292C39087}, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.BoosterPop, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{99A3F269-025D-476A-82E7-0B67918B6FF7}, No Action By User, [1797], [352444],1.0.2475

Registry Value: 4
PUP.Optional.WebAssistant, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd|PATH, No Action By User, [12047], [185843],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.WebAssistant, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}, No Action By User, [12047], [244759],1.0.2475
PUP.Optional.BoosterPop, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{99A3F269-025D-476A-82E7-0B67918B6FF7}|PATH, No Action By User, [1797], [352444],1.0.2475

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 31
PUP.Optional.RegCurePro, C:\PROGRAMDATA\ParetoLogic\RegCure Pro, No Action By User, [1475], [334940],1.0.2475
PUP.Optional.RegCurePro, C:\USERS\MARY\APPDATA\ROAMING\ParetoLogic\RegCure Pro, No Action By User, [1475], [334940],1.0.2475
PUP.Optional.SupraSavings, C:\PROGRAM FILES\suprasavings, No Action By User, [9282], [179895],1.0.2475
PUP.Optional.MBot, C:\PROGRAM FILES (X86)\mbot_ca_121, No Action By User, [11311], [178114],1.0.2475
PUP.Optional.ArcadeGiant, C:\USERS\MARY\APPDATA\LOCAL\ArcadeGiant, No Action By User, [6271], [175502],1.0.2475
PUP.Optional.MBot, C:\USERS\MARY\APPDATA\LOCAL\mbot_ca_121, No Action By User, [11311], [178113],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0\libraries, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0\resources, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid\libraries, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid\resources, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\USERS\MARY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\DLNEMBNFBCPJNEPMFJMNGJENHHAJPDFD, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.MBot, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MYBESTOFFERSTODAY, No Action By User, [11311], [178115],1.0.2475
PUP.Optional.ArcadeGiant, C:\USERS\MARY\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\ARCADEGIANT, No Action By User, [6271], [235561],1.0.2475
PUP.Optional.Perion, C:\Windows\SysWOW64\WNLT\Installation, No Action By User, [1463], [183619],1.0.2475
PUP.Optional.Perion, C:\WINDOWS\SYSWOW64\WNLT, No Action By User, [1463], [183619],1.0.2475
PUP.Optional.Perion, C:\WINDOWS\SYSTEM32\ARFC, No Action By User, [1463], [183617],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\content\libraries, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\content\resources, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\defaults\preferences, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\locale\en-US, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\content, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\locale, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\skin, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\defaults, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\libraries, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\resources, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\PROGRAM FILES\WEB ASSISTANT, No Action By User, [12047], [244758],1.0.2475

File: 49
PUP.Optional.RegCurePro, C:\ProgramData\ParetoLogic\RegCure Pro\License_Time.rdat, No Action By User, [1475], [334940],1.0.2475
PUP.Optional.RegCurePro, C:\ProgramData\ParetoLogic\RegCure Pro\RB.rdat, No Action By User, [1475], [334940],1.0.2475
PUP.Optional.RegCurePro, C:\ProgramData\ParetoLogic\RegCure Pro\tfn.xml, No Action By User, [1475], [334940],1.0.2475
PUP.Optional.RegCurePro, C:\Users\Mary\AppData\Roaming\ParetoLogic\RegCure Pro\Client.txt, No Action By User, [1475], [334940],1.0.2475
PUP.Optional.RegCurePro, C:\Users\Mary\AppData\Roaming\ParetoLogic\RegCure Pro\Server.txt, No Action By User, [1475], [334940],1.0.2475
PUP.Optional.SupraSavings, C:\Program Files\suprasavings\uninstaller.exe, No Action By User, [9282], [179895],1.0.2475
PUP.Optional.MBot, C:\Program Files (x86)\mbot_ca_121\unins000.dat, No Action By User, [11311], [178114],1.0.2475
PUP.Optional.MBot, C:\Program Files (x86)\mbot_ca_121\unins000.exe, No Action By User, [11311], [178114],1.0.2475
PUP.Optional.ArcadeGiant, C:\Users\Mary\AppData\Local\ArcadeGiant\agiantconfig, No Action By User, [6271], [175502],1.0.2475
PUP.Optional.ArcadeGiant, C:\Users\Mary\AppData\Local\ArcadeGiant\agnt.config, No Action By User, [6271], [175502],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0\libraries\ContentScript.js, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0\libraries\DataExchangeScript.js, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0\resources\localscript.js, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0\background.html, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0\main.js, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0\manifest.json, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.568_0\npbrowserext.dll, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid\libraries\ContentScript.js, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid\libraries\DataExchangeScript.js, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid\resources\localscript.js, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid\background.html, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid\main.js, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid\manifest.json, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.Incredibar, C:\Users\Mary\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\tempid\npbrowserext.dll, No Action By User, [6382], [177770],1.0.2475
PUP.Optional.ASK, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS\ASKSEARCH.JS, No Action By User, [502], [182871],1.0.2475
PUP.Optional.PerionTB, C:\USERS\MARY\DOWNLOADS\INCREDIMAIL_INSTALL(2).EXE, No Action By User, [8008], [123999],1.0.2475
PUP.Optional.SpeedyPC, C:\USERS\MARY\DOWNLOADS\SPEEDYPC PRO INSTALLER.EXE, No Action By User, [849], [396732],1.0.2475
PUP.Optional.PerionTB, C:\USERS\MARY\DOWNLOADS\INCREDIMAIL_INSTALL(1).EXE, No Action By User, [8008], [123999],1.0.2475
PUP.Optional.InstallCore, C:\USERS\MARY\DOWNLOADS\INCREDIMAILSETUP.EXE, No Action By User, [2], [363724],1.0.2475
PUP.Optional.ArcadeGiant, C:\USERS\MARY\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\ARCADEGIANT\PLAY ARCADEGIANT GAMES.URL, No Action By User, [6271], [235561],1.0.2475
PUP.Optional.ArcadeGiant, C:\Users\Mary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ArcadeGiant\Uninstall.lnk, No Action By User, [6271], [235561],1.0.2475
PUP.Optional.Perion, C:\WINDOWS\SYSWOW64\WNLT\INSTALLATION\UNINSTALLER.EXE, No Action By User, [1463], [183619],1.0.2475
PUP.Optional.Perion, C:\WINDOWS\SYSTEM32\ARFC\WRTC.EXE, No Action By User, [1463], [183617],1.0.2475
PUP.Optional.BoosterPop, C:\WINDOWS\SYSTEM32\TASKS\BOOSTERPOP, No Action By User, [1797], [235946],1.0.2475
PUP.Optional.WebAssistant, C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX\CHROME.MANIFEST, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\content\libraries\DataExchangeScript.js, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\content\resources\localscript.js, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\content\main.js, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\content\main.xul, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\locale\en-US\overlay.dtd, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\chrome\skin\overlay.css, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\defaults\preferences\defaults.js, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\Firefox\install.rdf, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\libraries\DataExchangeScript.js, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\resources\localscript.js, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\DGChrome.exe, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\source.crx, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\unins000.dat, No Action By User, [12047], [244758],1.0.2475
PUP.Optional.WebAssistant, C:\Program Files\Web Assistant\unins000.exe, No Action By User, [12047], [244758],1.0.2475

Physical Sector: 0
(No malicious items detected)


(end)



BC AdBot (Login to Remove)

 


#2 cantib

cantib
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:05 AM

Posted 01 August 2017 - 11:08 AM

# AdwCleaner 7.0.1.0 - Logfile created on Tue Aug 01 05:54:45 2017
# Updated on 2017/05/08 by Malwarebytes
# Running on Windows Vista ™ Home Premium (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

Deleted: YahooAUService
Deleted: WtuSystemSupport
Deleted: Update service
Deleted: vToolbarUpdater18.1.9
Deleted: vToolbarUpdater40.3.8


***** [ Folders ] *****

Deleted: C:\Program Files (x86)\Portable Booster
Deleted: C:\ProgramData\Yahoo! Companion
Deleted: C:\ProgramData\Application Data\Yahoo! Companion
Deleted: C:\Windows\System32\config\systemprofile\AppData\LocalLow\Yahoo! Companion
Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Yahoo! Companion
Deleted: C:\Users\All Users\Yahoo! Companion
Deleted: C:\Users\Mary\AppData\LocalLow\Yahoo! Companion
Deleted: C:\ProgramData\AGI
Deleted: C:\ProgramData\Application Data\AGI
Deleted: C:\Windows\System32\config\systemprofile\AppData\LocalLow\AGI
Deleted: C:\Program Files (x86)\AGI
Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AGI
Deleted: C:\Users\All Users\AGI
Deleted: C:\Users\Mary\AppData\LocalLow\AGI
Deleted: C:\Users\Mary\AppData\Roaming\AGI
Deleted: C:\Program Files (x86)\AskBarDis
Deleted: C:\ProgramData\AVG Secure Search
Deleted: C:\ProgramData\Application Data\AVG Secure Search
Deleted: C:\Program Files\Common Files\AVG Secure Search
Deleted: C:\Windows\System32\config\systemprofile\AppData\LocalLow\AVG Secure Search
Deleted: C:\Program Files (x86)\Common Files\AVG Secure Search
Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AVG Secure Search
Deleted: C:\Users\All Users\AVG Secure Search
Deleted: C:\Users\Guest\AppData\Local\AVG Secure Search
Deleted: C:\Users\Guest\AppData\LocalLow\AVG Secure Search
Deleted: C:\Users\Mary1\AppData\Local\AVG Secure Search
Deleted: C:\Users\Mary1\AppData\LocalLow\AVG Secure Search
Deleted: C:\ProgramData\AVG Security Toolbar
Deleted: C:\ProgramData\Application Data\AVG Security Toolbar
Deleted: C:\Users\All Users\AVG Security Toolbar
Deleted: C:\Users\Guest\AppData\Local\AVG Security Toolbar
Deleted: C:\Users\Guest\AppData\LocalLow\AVG Security Toolbar
Deleted: C:\Users\Mary\AppData\Roaming\DriverCure
Deleted: C:\Windows\System32\config\systemprofile\AppData\Roaming\Yahoo!\Companion
Deleted: C:\Windows\System32\config\systemprofile\AppData\LocalLow\Yahoo!\Companion
Deleted: C:\Program Files (x86)\Yahoo!\Companion
Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Yahoo!\Companion
Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Yahoo!\Companion
Deleted: C:\Users\Mary\AppData\LocalLow\Yahoo!\Companion
Deleted: C:\Users\Mary\AppData\Roaming\Yahoo!\Companion
Deleted: C:\ProgramData\avg web tuneup
Deleted: C:\ProgramData\Application Data\avg web tuneup
Deleted: C:\Program Files (x86)\avg web tuneup
Deleted: C:\Users\All Users\avg web tuneup
Deleted: C:\Users\Guest\AppData\Local\avg web tuneup
Deleted: C:\Users\Mary\AppData\Local\avg web tuneup
Deleted: C:\Program Files (x86)\Downloaded Installers
Deleted: C:\ProgramData\Ask
Deleted: C:\ProgramData\Application Data\Ask
Deleted: C:\Users\All Users\Ask
Deleted: C:\ProgramData\PARETOLOGIC
Deleted: C:\ProgramData\Application Data\PARETOLOGIC
Deleted: C:\Users\All Users\PARETOLOGIC
Deleted: C:\Users\Mary\AppData\Roaming\PARETOLOGIC
Deleted: C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
Deleted: C:\ProgramData\Avg_Update_0116av
Deleted: C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7


***** [ Files ] *****

Deleted: C:\Program Files (x86)\Yahoo!\Common\unyt.exe


***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted: AI_Updater
Deleted: ieerror
Deleted: IEError
Deleted: ai_updater
Deleted: 0116avUpdateInfo
Deleted: 0316tbUpdateInfo
Deleted: 0116avUpdateInfo
Deleted: 0316tbUpdateInfo


***** [ Registry ] *****

Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\akamaihd.net
Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls|Tabs [http:\\isearch.avg.com\tab?cid={C5ED888C-E4A4-429B-A740-1A395C68BF78}&mid=b7f8d384f62f8833999f2d31b0663873-5b9b86b797967cbaf8f158defd9f82c657ab2ed2&lang=en&ds=AVG&pr=fr&d=2011-10-12 14:37:02&v=9.0.0.22&sap=nt]
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{7665906D-7AF8-4082-8A3A-3E18BC7EE871}C:\users\mary\appdata\local\popcorn time\node-webkit\popcorn time.exe
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{3E09CBA8-7AD7-413C-B419-5795B2E33071}C:\users\mary\appdata\local\popcorn time\node-webkit\popcorn time.exe
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{C3322DF3-99BF-468C-94B6-FBE668D788B4}C:\users\mary\appdata\local\popcorn time\node-webkit\popcorn time.exe
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{ECC373BE-428A-4ED1-A388-4B852D8EC384}C:\users\mary\appdata\local\popcorn time\node-webkit\popcorn time.exe
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{2A4ADEA6-8C3A-45AA-A54A-FAC2D7EB7121}C:\users\mary\appdata\local\popcorn time\nw.exe
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{9DC14CFD-DF1A-4DD5-8991-95EEA6CAAD4C}C:\users\mary\appdata\local\popcorn time\nw.exe
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{5B6352B8-E37D-4C91-B2F6-5BFA3A010738}C:\users\mary\appdata\local\popcorn time\nw.exe
Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{42BFF168-C2E7-4E0D-9FA0-7B61355B401E}C:\users\mary\appdata\local\popcorn time\nw.exe
Deleted: [Key] - HKLM\SOFTWARE\ImInstaller
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\ImInstaller
Deleted: [Key] - HKCU\Software\ImInstaller
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yahoo! Companion
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yahoo! Companion
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Deleted: [Key] - HKLM\SOFTWARE\WNLT
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WNLT
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WNLT
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Deleted: [Key] - HKLM\SOFTWARE\AGI
Deleted: [Key] - HKU\.DEFAULT\Software\AGI
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\AGI
Deleted: [Key] - HKU\S-1-5-18\Software\AGI
Deleted: [Key] - HKCU\Software\AGI
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\APN PIP
Deleted: [Key] - HKCU\Software\APN PIP
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ask Toolbar_is1
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ask Toolbar_is1
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ask Toolbar_is1
Deleted: [Key] - HKU\.DEFAULT\Software\AppDataLow\AskBarDis
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\AppDataLow\AskBarDis
Deleted: [Key] - HKU\S-1-5-18\Software\AppDataLow\AskBarDis
Deleted: [Key] - HKCU\Software\AppDataLow\AskBarDis
Deleted: [Key] - HKU\.DEFAULT\Software\AVG Secure Search
Deleted: [Key] - HKU\S-1-5-18\Software\AVG Secure Search
Deleted: [Key] - HKU\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar
Deleted: [Key] - HKU\S-1-5-18\Software\AppDataLow\Software\AVG Security Toolbar
Deleted: [Key] - HKLM\SOFTWARE\ParetoLogic
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\ParetoLogic
Deleted: [Key] - HKCU\Software\ParetoLogic
Deleted: [Key] - HKLM\SOFTWARE\PIP
Deleted: [Key] - HKLM\SOFTWARE\Web Assistant
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\YahooPartnerToolbar
Deleted: [Key] - HKCU\Software\YahooPartnerToolbar
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\PCCleaners
Deleted: [Key] - HKCU\Software\PCCleaners
Deleted: [Key] - HKLM\SOFTWARE\Yahoo\Companion
Deleted: [Key] - HKU\.DEFAULT\Software\Yahoo\Companion
Deleted: [Key] - HKU\.DEFAULT\Software\AppDataLow\Software\Yahoo\Companion
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\Yahoo\Companion
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\AppDataLow\Software\Yahoo\Companion
Deleted: [Key] - HKU\S-1-5-18\Software\Yahoo\Companion
Deleted: [Key] - HKU\S-1-5-18\Software\AppDataLow\Software\Yahoo\Companion
Deleted: [Key] - HKCU\Software\Yahoo\Companion
Deleted: [Key] - HKCU\Software\AppDataLow\Software\Yahoo\Companion
Deleted: [Key] - HKU\.DEFAULT\Software\Yahoo\YFriendsBar
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\Yahoo\YFriendsBar
Deleted: [Key] - HKU\S-1-5-18\Software\Yahoo\YFriendsBar
Deleted: [Key] - HKCU\Software\Yahoo\YFriendsBar
Deleted: [Key] - HKLM\SOFTWARE\AVG Tuneup
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted: [Key] - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Deleted: [Key] - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Deleted: [Key] - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Deleted: [Key] - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
Deleted: [Key] - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
Deleted: [Value] - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks|{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0EEDB912-C5FA-486F-8334-57288578C627}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Deleted: [Key] - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Deleted: [Key] - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{41829420-151B-4920-B8A5-16BE4601B42A}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41829420-151B-4920-B8A5-16BE4601B42A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{571715D7-3395-4DF0-B43C-784836209E60}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{62970E2F-A895-4848-B46C-FBD071192995}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{87A0B80B-5BA7-4CB0-9553-105D68777D60}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B0DE3308-5D5A-470D-81B9-634FC078393B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{B3B723CD-7242-4775-B10E-74DB7F4CB5A1}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{D2E5FA06-DCC7-46F9-BEFF-BFD06F69B9B2}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{0C1284BA-4F3A-41C6-94B5-77446F5948A9}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{0548C79F-7B8C-455D-B228-97D35371BB62}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{4A1E52AC-64F2-49E9-BFD7-0806D9494DBB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{78DB07DF-483E-4829-AB44-ED7952083584}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{8A1AB044-787D-4309-8410-709768E484AB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{A2C55651-A23E-43CA-B63D-C10B99EFF7E0}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{AD34BE7D-2603-43DD-8D1F-E4431D42C44E}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{B82D18E0-1649-48DE-92D7-AA89BBB5F0AD}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{D2EA97F6-6235-4B2D-B5AA-A4472B9CE557}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{1147DC83-6208-4dca-8E88-DD45BAAB3043}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{11CB4723-D5A1-4a55-8D1D-5C2679D54CF5}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{37B8167C-B9A4-4316-94B2-67B64BB2BA7C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{3A06AA27-D94B-48C2-BB55-9FD0FF2120E3}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{46140CE4-76FE-440E-AE88-4C2272BC05C7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{6E40017D-FB6A-4804-BDE4-3BB09F1719C1}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{9F9C4C5C-2BA8-4E00-A697-9F710BB1026B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{B7A0E898-93E5-43f4-B99A-6C70B303699C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{C60CCE95-6AF9-4E74-B66B-3212D19F1D2F}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{D40A62D1-8FC0-4F03-90C4-0DE03BE73A41}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{DDCED22E-D018-471D-9A5C-A4EA2F21133D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{E1A2D448-6334-45ec-8800-6D7F71DC87FC}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{F9A10D86-182A-4946-869B-70C3D109D14D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{F9A10D86-182A-4946-869B-70C3D109D14D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{FBE30D66-39A2-4b72-8B43-6D4C335A6F34}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{07CDAAD9-1226-4C6D-B774-C00E7B323484}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{35860EFB-1589-4F32-A618-99E847A502B2}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{39DCCEAF-C749-4390-9953-527CF916935C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{41D7CEE0-D91F-498C-BC88-4A6BEE46C2BC}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{9EDCCD11-960D-49AE-B523-C6B5AB7E1345}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{EB2BA65E-41F6-4F64-92A6-216CDFFDF577}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{FFFFE1D1-E40D-49a1-9622-BC59BD1879C3}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{11D5E9EA-3117-4389-8E58-742F0975C980}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{2723E96B-905F-4C64-8999-D868A08E6370}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{2FCB4E7E-E5C7-4D07-BB2C-78DF2DA867AD}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{3D592FCB-FEFD-43A6-9A4F-BDE2D4607D07}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{67E5E37C-E6B8-4782-877D-E9437C4CD982}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{686D40BC-FA43-4317-8474-E634E6B487F2}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{A310B105-FB7D-4497-A7E8-E046462B012F}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{DF522774-8CA0-4B15-A93A-5F61AB95DA1C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{63EDCDD3-8AFC-4358-A90F-F7FB8F5C64FF}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{BD5843ED-13C4-4EFF-ACE9-56CEE22BC087}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{528B5866-2BA6-42CE-8F74-39FB23B49767}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{F5CC67F7-F6BA-44E3-98EC-EA17D17E6479}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{6EB4349D-4333-442F-ACA4-4C72AF28B6ED}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{7DB8B625-DBF0-4491-B544-5A06F7B17BB4}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{8E74A0AE-F0ED-47ED-A940-A8E99687646B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{9DE77B51-89F6-468E-9402-16050382E950}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Deleted: [Key] - HKLM\SOFTWARE\MozillaPlugins\@avg.com\AVG SiteSafety plugin,version=11.0.0.1,application\x-avg-sitesafety-plugin
Deleted: [Key] - HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\YCAPlugin.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\YPUBC.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\yt.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\YTabBar.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\YTBM.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\YTMsgr.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\YTNavAssist.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\YTSingleInstance.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\PROTOCOLS\handler\viprotocol
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\Conduit
Deleted: [Key] - HKCU\Software\Conduit
Deleted: [Key] - HKLM\SOFTWARE\AdGazelle
Deleted: [Key] - HKU\.DEFAULT\Software\Auslogics
Deleted: [Key] - HKU\S-1-5-18\Software\Auslogics
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\PRODUCTSETUP
Deleted: [Key] - HKCU\Software\PRODUCTSETUP
Deleted: [Key] - HKLM\SOFTWARE\suprasavings
Deleted: [Key] - HKU\S-1-5-21-3439958544-1267488918-2103452222-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\suprasavings
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\suprasavings


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [30073 B] - [2017/8/1 5:24:29]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########
 


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows ™ Vista Home Premium x64
Ran by Mary (Administrator) on 01/08/2017 at  2:04:16.47
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 75

Successfully deleted: C:\ProgramData\pc drivers headquarters (Folder)
Successfully deleted: C:\ProgramData\pc1data (Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{0FE21CA2-0BE3-4A15-9F91-9E4FE73D21ED} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{174E5FEC-A50B-41EE-8B46-062C8BBA8D48} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{24EBF9B7-587E-43C3-B251-23B298B9522E} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{3031DE1D-FFB4-4B26-9AA3-9C0C62633CA6} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{430172E9-D290-4EDD-8D46-1DBD6D4337F4} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{519BF34D-86F0-4646-952C-AA3FC573C66F} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{6087256E-F92D-46CC-B862-1FB2B5FD3E2D} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{64C2981A-38A2-4365-94DC-07E303B7CDAE} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{6CA199AD-A570-422B-8A6A-8C612322EB0E} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{6D278807-4850-42C4-BC0D-EFD3E0555CE2} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{711B2C0B-1EF0-4582-BAEF-6D1B1346D6AD} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{725E7A7A-1F14-491B-A08C-F5E21F94574A} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{79129709-2312-418D-AFEF-E09AF155D31B} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{7C938A82-2563-4D7F-9788-39BA6C95F1CF} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{80B55B82-1339-479B-9C3B-4B56371FD77D} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{81899A8F-9C9E-409D-B895-BCAD1569DC63} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{923E5009-E780-4171-B739-0C3C5A47D483} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{93B611BB-2154-4B18-8812-B13FB93FE352} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{9C950DAE-C51F-40D5-8393-D32DB99F3385} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{9E38E156-C36D-410B-9D3F-2CE1D4349972} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{ADD38583-EEEC-40CA-AA3F-450336E5537F} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{BCF5AFF3-7FF4-47D4-B494-BE2032D7B826} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{DA96C1F7-9F34-4171-B888-B87A02BBF3D7} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{E1BF74B6-B01B-49D8-BE70-8EBF47A38382} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{E3F6199D-24F3-4E2D-AE22-2D47B985375A} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{EA047BE4-24D0-498F-BA62-E22ED717ED6F} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{EA133556-6AF5-4EB8-9599-47669D607847} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{EBB2513B-9632-48B3-A7DD-F7C3646E84F2} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{F954006F-8A16-48BB-B202-61F9AF6F2369} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\{FD6E8B2B-82E3-43F2-9C0D-747C2E0DEA71} (Empty Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\packageaware (Folder)
Successfully deleted: C:\Users\Mary\AppData\Roaming\fixcleaner (Folder)
Successfully deleted: C:\Program Files (x86)\fixcleaner (Folder)
Successfully deleted: C:\Program Files (x86)\pc drivers headquarters (Folder)
Successfully deleted: C:\Program Files\003 (Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\02495R7V (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2U9M35IT (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4N6APSHX (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4XU70X2Q (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PFMSJTR (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RVIDXKC (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BVW9HK5T (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CJZT5OWN (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H97H51JT (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J5BU6EBM (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J7AXPS1W (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M3JAV1ZZ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S4NOH455 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TILT40XE (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WNBY6QAT (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZUBITA5F (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\02495R7V (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2U9M35IT (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4N6APSHX (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4XU70X2Q (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PFMSJTR (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RVIDXKC (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BVW9HK5T (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CJZT5OWN (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H97H51JT (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J5BU6EBM (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J7AXPS1W (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M3JAV1ZZ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S4NOH455 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TILT40XE (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WNBY6QAT (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZUBITA5F (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\SysWOW64\REN2755.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\REN2756.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\REN2766.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\RENDE2E.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\RENDE2F.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\RENDE30.tmp (File)



Registry: 7

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{87394793-8317-426A-A380-443282519A7D} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01/08/2017 at  2:10:06.90
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 



#3 buddy215

buddy215

  • Moderator
  • 13,124 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:05 AM

Posted 01 August 2017 - 11:30 AM

Use CCleaner to remove Temporary files, program caches, cookies, logs, etc. Use the Default settings. No need to use the

Registry Cleaning Tool...risky. Pay close attention while installing and UNcheck offers of toolbars....especially Google.

After install, open CCleaner and run by clicking on the Run Cleaner button in the bottom right corner.

CCleaner - PC Optimization and Cleaning - Free Download

 

 

Rerun MBAM and allow it to remove/ quarantine what it finds. Then rerun both AdwCleaner and JRT and allow them to remove/ delete what they find.

 

Download and run the FREE online scanner from Free Virus Scan | Online Virus Scan from ESET | ESET

  • Place a checkmark in YES, I accept the Terms of Use, then click Start. Wait for ESET Online Scanner to load its components.
  • Select Enable detection of potentially unwanted applications.
  • Click Advanced Settings, then place a checkmark in the following:
    • Remove found threats
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Click Start to begin scanning.
  • ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.
  • When the scan is done, click List threats (only available if ESET Online Scanner found something).
  • Click Export, then save the file to your desktop.
  • Click Back, then Finish to exit ESET Online Scanner.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#4 cantib

cantib
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:05 AM

Posted 01 August 2017 - 03:59 PM

Hi buddy215, thanks for your help! Here are the new logs

 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 8/1/17
Scan Time: 12:43 PM
Log File: mwb.txt
Administrator: Yes

-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.160
Update Package Version: 1.0.2484
License: Free

-System Information-
OS: Windows Vista Service Pack 2
CPU: x64
File System: NTFS
User: Mary-PC\Mary

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 446692
Threats Detected: 0
(No malicious items detected)
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 16 min, 33 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)


(end)

 

 

 

 

# AdwCleaner 7.0.1.0 - Logfile created on Tue Aug 01 17:06:06 2017
# Updated on 2017/05/08 by Malwarebytes
# Running on Windows Vista ™ Home Premium (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted: AI_Updater
Deleted: ieerror
Deleted: IEError
Deleted: ai_updater


***** [ Registry ] *****

Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{1147DC83-6208-4dca-8E88-DD45BAAB3043}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{11CB4723-D5A1-4a55-8D1D-5C2679D54CF5}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{3A06AA27-D94B-48C2-BB55-9FD0FF2120E3}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{46140CE4-76FE-440E-AE88-4C2272BC05C7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{6E40017D-FB6A-4804-BDE4-3BB09F1719C1}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{9F9C4C5C-2BA8-4E00-A697-9F710BB1026B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{C60CCE95-6AF9-4E74-B66B-3212D19F1D2F}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{D40A62D1-8FC0-4F03-90C4-0DE03BE73A41}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{DDCED22E-D018-471D-9A5C-A4EA2F21133D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{E1A2D448-6334-45ec-8800-6D7F71DC87FC}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{FBE30D66-39A2-4b72-8B43-6D4C335A6F34}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{07CDAAD9-1226-4C6D-B774-C00E7B323484}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{35860EFB-1589-4F32-A618-99E847A502B2}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{39DCCEAF-C749-4390-9953-527CF916935C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{41D7CEE0-D91F-498C-BC88-4A6BEE46C2BC}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{9EDCCD11-960D-49AE-B523-C6B5AB7E1345}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{EB2BA65E-41F6-4F64-92A6-216CDFFDF577}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{FFFFE1D1-E40D-49a1-9622-BC59BD1879C3}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{F5CC67F7-F6BA-44E3-98EC-EA17D17E6479}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{6EB4349D-4333-442F-ACA4-4C72AF28B6ED}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{7DB8B625-DBF0-4491-B544-5A06F7B17BB4}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{8E74A0AE-F0ED-47ED-A940-A8E99687646B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{9DE77B51-89F6-468E-9402-16050382E950}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [26452 B] - [2017/8/1 5:54:45]
C:/AdwCleaner/AdwCleaner[S0].txt - [30073 B] - [2017/8/1 5:24:29]
C:/AdwCleaner/AdwCleaner[S1].txt - [5030 B] - [2017/8/1 17:4:47]


########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt ##########
 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows ™ Vista Home Premium x64
Ran by Mary (Administrator) on 01/08/2017 at 13:11:59.73
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 8

Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BGYM4L5J (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCERQRBD (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TZ3Z0RW6 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Mary\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TZIMGSCT (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BGYM4L5J (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCERQRBD (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TZ3Z0RW6 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TZIMGSCT (Temporary Internet Files Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01/08/2017 at 13:17:47.40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

 

 

 

 

this is the eset log

 

C:\AdwCleaner\Quarantine\aMeAjSWfch\bar\bin\askBar.dll    a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application    cleaned by deleting
C:\AdwCleaner\Quarantine\aMeAjSWfch\bar\bin\askPopStp.dll    a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application    cleaned by deleting
C:\Users\Mary\Desktop\ccsetup532.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
C:\Users\Mary\Documents\ApnStub.exe    a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application    cleaned by deleting
C:\Users\Mary\Downloads\cbsidlm-cbsi213-IncrediMail-SEO-10972300.exe    a variant of Win32/CNETInstaller.B potentially unwanted application    cleaned by deleting
C:\Users\Mary\Downloads\ccsetup327.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
C:\Users\Mary\Downloads\IncrediMailSetup(1).exe    a variant of Win32/ClientConnect.A potentially unwanted application    deleted
 



#5 buddy215

buddy215

  • Moderator
  • 13,124 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:05 AM

Posted 01 August 2017 - 04:49 PM

Tell me if there is still a problem and what it is.

  • download Security Check by glax24 and save the file to the Desktop
  • Run the tool by accepting all the Security prompts
  • when complete the tool will produce a log file C:\SecurityCheck\SecurityCheck.txt and also copy the contents to the Clipboard
  • Simply Paste the log to your reply

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#6 cantib

cantib
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:05 AM

Posted 02 August 2017 - 12:35 AM

The problem is that the computer sometimes has trouble loading websites and downloading. I can't tell yet if the problem is fixed because it comes and goes so I'll have to wait and see. Thank you for helping me get ride of all adware

 

here is the Security Check log

 

SecurityCheck by glax24 & Severnyj v.1.4.0.52 [25.07.17].
WebSite: www.safezone.cc
DateLog: 01.08.2017 18:25:06
Path starting: C:\Users\Mary\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: Mary
VersionXML: 4.53is-28.07.2017
___________________________________________________________________________

Windows Vista(6.0.6002) Service Pack 2 (x64) HomePremium Lang: English(0409)
Installation date OS: 27.06.2009 15:49:05
LicenseStatus: Windows™ Vista, HomePremium edition The machine is permanently activated.
Boot Mode: Normal
Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
SystemDrive: C: FS: [NTFS] Capacity: [455.8 Gb] Used: [109.9 Gb] Free: [345.9 Gb]
------------------------------- [ Windows ] -------------------------------
Extended support has ended 11.04.2017, Your operating system may be vulnerable to new types of threats
Internet Explorer 9.0.8112.16421 Warning! Download Update
Online installation. Last version available when Windows update is enabled throught the Internet.
Automatically download and schedule installation
Date install updates: 2014-11-30 18:41:03
Windows Update (wuauserv) - The service is running
Security Center (wscsvc) - The service is running
Remote Registry (RemoteRegistry) - The service has stopped
Terminal Services (TermService) - The service is running
Windows Remote Management (WS-Management) (WinRM) - The service has stopped
SSDP Discovery (SSDPSRV) - The service is running
Account guest is enabled. Not require a password.
---------------------------- [ Antivirus_WMI ] ----------------------------
Avast Antivirus (enabled and up to date)
--------------------------- [ FirewallWindows ] ---------------------------
Windows Firewall (MpsSvc) - The service is running
--------------------------- [ AntiSpyware_WMI ] ---------------------------
Windows Defender (disabled)
Avast Antivirus (enabled and up to date)
-------------------------- [ SecurityUtilities ] --------------------------
Malwarebytes version 3.1.2.1733 v.3.1.2.1733
--------------------------- [ OtherUtilities ] ----------------------------
TeamViewer 10 (TeamViewer) - The service is running
--------------------------- [ AppleProduction ] ---------------------------
Bonjour v.3.1.0.1
iTunes v.12.1.3.6 Warning! Download Update
^Please use Apple Software Update tool.^
Bonjour Service (Bonjour Service) - The service is running
--------------------------- [ RunningProcess ] ----------------------------
C:\Program Files (x86)\Mozilla Firefox\firefox.exe v.52.2.1.6387
------------------ [ AntivirusFirewallProcessServices ] -------------------
Avast Antivirus (avast! Antivirus) - The service is running
C:\Program Files\AVAST Software\Avast\AvastSvc.exe v.17.5.3585.0
aswbIDSAgent (aswbIDSAgent) - The service is running
C:\Program Files\AVAST Software\Avast\avastui.exe v.17.5.3585.192
Malwarebytes Service (MBAMService) - The service has stopped
Windows Defender (WinDefend) - The service has stopped
----------------------------- [ End of Log ] ------------------------------



#7 buddy215

buddy215

  • Moderator
  • 13,124 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:05 AM

Posted 02 August 2017 - 04:27 AM

A suggestion....using Vista is risky. Linux operating systems are free. You can test run a LIVE Linux to see if your hardware and you are compatible without installing.

It will only use the RAM.

If you are interested in trying a Linux distro, Bleeping Computer has a Linux Forum that you can check for more info and assistance from some

very friendly members.

 

I see Firefox is the default browser. If problems with loading sites or downloading comes back, I would suggest backing up your bookmarks

and then do a complete uninstall including your Firefox profile. Run the uninstaller and then do searches for Mozilla and Firefox. Delete all.

Reboot and Reinstall Firefox.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#8 cantib

cantib
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:05 AM

Posted 04 August 2017 - 07:20 PM

Thanks a lot buddy215 the issue seems to be fixed since i followed your instructions :)



#9 buddy215

buddy215

  • Moderator
  • 13,124 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:05 AM

Posted 04 August 2017 - 08:27 PM

Good...you're welcome....happy surfin'


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users