Les Parson
New Member
Although 13 Trojan Viruses were detected were detected by ESISSOFT,I was horrified the dreaded 'Inksdata.com' browser re-direct remains. I will be most appreciative of any advice to ultimately destroy this insidious creature.
Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
:OTL
IE - HKLM\..\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^AFA^xdm120^S04375^us&si=7967&ptb=BB79C436-C4DF-4AF0-9A19-CC11EFB26A9E&ind=2013020209&n=77fc4031&psa=&st=sb&searchfor={searchTerms}
IE - HKU\S-1-5-21-2586906720-2871239593-3476299853-1000\..\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^AFA^xdm120^S04375^us&si=7967&ptb=BB79C436-C4DF-4AF0-9A19-CC11EFB26A9E&ind=2013020209&n=77fc4031&psa=&st=sb&searchfor={searchTerms}
FF - HKLM\Software\MozillaPlugins\@CouponXplorer_5z.com/Plugin: C:\Program Files\CouponXplorer_5z\bar\1.bin\NP5zStub.dll (MindSpark)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\5zffxtbr@CouponXplorer_5z.com: C:\Program Files\CouponXplorer_5z\bar\1.bin [2013/06/15 07:38:08 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\games@acandy.com: C:\Users\Parson\AppData\Local\ArcadeCandy\games@acandy.com [2012/08/24 21:45:06 | 000,000,000 | ---D | M]
[2013/06/03 14:11:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Parson\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
CHR - default_search_provider: Bing (Enabled)
CHR - default_search_provider: search_url = http://start.sweetpacks.com?src=6&q={searchTerms}&barid={A4FBD5DF-CC81-11E2-9726-001BB9700D63}&crg=3.5000006.10042&st=23
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\Parson\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
O2 - BHO: (Toolbar BHO) - {0297a026-3011-46d3-ad62-bb9a7612aea7} - C:\PROGRA~1\COUPON~2\bar\1.bin\5zbar.dll File not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1505\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (Search Results Toolbar) - {348bd83c-b2cd-4319-a605-c96bb458dd80} - C:\Program Files\toolbar2\searchresultsDx.dll (Ask.com)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Search Assistant BHO) - {7d69ed06-0171-4379-9528-08df51092727} - C:\Program Files\CouponXplorer_5z\bar\1.bin\5zSrcAs.dll (MindSpark)
O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Parson\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (ArcadeCandy Games) - {AB6BD08C-DB6B-4F02-8A22-4BD343E990FF} - C:\Users\Parson\AppData\Local\ArcadeCandy\candyEX.dll (ArcadeCandy LLC)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.355.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Search Results Toolbar) - {348bd83c-b2cd-4319-a605-c96bb458dd80} - C:\Program Files\toolbar2\searchresultsDx.dll (Ask.com)
O3 - HKLM\..\Toolbar: (CouponXplorer) - {65c72339-fb1d-4155-84e1-9afacee02d6f} - C:\Program Files\CouponXplorer_5z\bar\1.bin\5zbar.dll File not found
O4 - HKLM..\Run: [CouponXplorer Search Scope Monitor] C:\Program Files\CouponXplorer_5z\bar\1.bin\5zSrchMn.exe (MindSpark)
O4 - HKLM..\Run: [CouponXplorer_5z Browser Plugin Loader] C:\Program Files\CouponXplorer_5z\bar\1.bin\5zbrmon.exe (VER_COMPANY_NAME)
O4 - Startup: C:\Users\Parson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk = C:\Program Files\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
[2013/06/03 14:14:40 | 000,000,000 | ---D | C] -- C:\Users\Parson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
[2013/06/03 14:14:36 | 000,000,000 | ---D | C] -- C:\Program Files\MyPC Backup
[2013/05/21 17:13:45 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/06/03 14:14:41 | 000,000,894 | ---- | M] () -- C:\Users\Parson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
[2013/06/03 14:14:41 | 000,000,884 | ---- | M] () -- C:\Users\Parson\Desktop\MyPC Backup.lnk
:commands
[emptytemp]
[reboot]
Members who viewed this thread in the last 5 minutes