Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
need help removing stubborn java update pop up + ads throughout text
Message
<blockquote data-quote="LvonB" data-source="post: 282977" data-attributes="member: 29480"><p>I don't have a clue how to use the:</p><p>aswMBR version 1.0.1.2161 Copyright(c) 2014 AVAST Software</p><p>Run date: 2014-10-23 19:26:51</p><p>-----------------------------</p><p>19:26:51.811 OS Version: Windows 6.1.7601 Service Pack 1</p><p>19:26:51.811 Number of processors: 2 586 0x1706</p><p>19:26:51.815 ComputerName: STLR-PC UserName: stlr</p><p>19:26:52.113 Initialze error C0000022 - driver not loaded</p><p>19:27:08.464 AVAST engine download error: 0</p><p>19:27:38.024 Scan error: Incorrect function.</p><p>19:27:42.450 Disk 0 statistics 0/0/0 @ -1,#J MB/s</p><p>19:27:42.451 Scan stopped</p><p>19:27:45.748 Scan error: Incorrect function.</p><p>19:28:03.725 The log file has been saved successfully to "C:\Users\stlr\Desktop\aswMBR.txt"</p><p></p><p></p><p></p><p></p><p># AdwCleaner v4.001 - Report created 22/10/2014 at 23:31:39</p><p># Updated 20/10/2014 by Xplode</p><p># Database :</p><p># Operating System : Windows 7 Professional Service Pack 1 (32 bits)</p><p># Username : stlr - STLR-PC</p><p># Running from : C:\Users\stlr\Downloads\AdwCleaner.exe</p><p># Option : Scan</p><p></p><p>***** [ Services ] *****</p><p></p><p></p><p>***** [ Files / Folders ] *****</p><p></p><p>File Found : C:\Users\stlr\AppData\Roaming\Mozilla\Firefox\Profiles\16x6kc6q.default\searchplugins\astromenda.xml</p><p>File Found : C:\Users\stlr\AppData\Roaming\Mozilla\Firefox\Profiles\16x6kc6q.default\user.js</p><p>Folder Found : C:\Program Files\file scout</p><p>Folder Found : C:\Program Files\MapsGalaxy_39EI</p><p>Folder Found : C:\Program Files\VideoPerformer</p><p>Folder Found : C:\ProgramData\2308189059</p><p>Folder Found : C:\ProgramData\Browser Manager</p><p>Folder Found : C:\ProgramData\Tarma Installer</p><p>Folder Found : C:\Users\stlr\AppData\Local\Gameo</p><p>Folder Found : C:\Users\stlr\AppData\Local\PutLockerDownloader</p><p>Folder Found : C:\Users\stlr\AppData\Local\Temp\AirInstaller</p><p>Folder Found : C:\Users\stlr\AppData\Local\torch</p><p>Folder Found : C:\Users\stlr\AppData\LocalLow\MapsGalaxy_39EI</p><p>Folder Found : C:\Users\stlr\AppData\Roaming\Funmoods</p><p>Folder Found : C:\Users\stlr\AppData\Roaming\Gameo</p><p>Folder Found : C:\Users\stlr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1clickmoviedownloader.com</p><p>Folder Found : C:\Users\stlr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoPerformer</p><p>Folder Found : C:\Users\stlr\AppData\Roaming\PerformerSoft</p><p>Folder Found : C:\Users\stlr\AppData\Roaming\WebExtend</p><p></p><p>***** [ Scheduled Tasks ] *****</p><p></p><p>Task Found : Funmoods</p><p>Task Found : LaunchSignup</p><p></p><p>***** [ Shortcuts ] *****</p><p></p><p></p><p>***** [ Registry ] *****</p><p></p><p>Key Found : HKCU\Software\1ClickDownload</p><p>Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}</p><p>Key Found : HKCU\Software\AppDataLow\Software\MapsGalaxy_39EI</p><p>Key Found : HKCU\Software\AppDataLow\Software\SmartBar</p><p>Key Found : HKCU\Software\ClickConnect</p><p>Key Found : HKCU\Software\Conduit</p><p>Key Found : HKCU\Software\filescout</p><p>Key Found : HKCU\Software\Funmoods</p><p>Key Found : HKCU\Software\ilivid</p><p>Key Found : HKCU\Software\InstallCore</p><p>Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}</p><p>Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}</p><p>Key Found : HKCU\Software\systweak</p><p>Key Found : HKCU\Software\torch</p><p>Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}</p><p>Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}</p><p>Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{8F0B76E1-4E46-427B-B55B-B90593468AC6}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}</p><p>Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho</p><p>Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1</p><p>Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3279411</p><p>Key Found : HKLM\SOFTWARE\Conduit</p><p>Key Found : HKLM\SOFTWARE\InstallCore</p><p>Key Found : HKLM\SOFTWARE\MapsGalaxy_39EI</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}</p><p>Key Found : HKLM\SOFTWARE\Tarma Installer</p><p>Key Found : HKLM\SOFTWARE\torch</p><p>Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe]</p><p>Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe]</p><p>Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe]</p><p>Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe]</p><p></p><p>***** [ Browsers ] *****</p><p></p><p>-\\ Internet Explorer v11.0.9600.17344</p><p></p><p></p><p>-\\ Mozilla Firefox v32.0.3 (x86 en-US)</p><p></p><p>[16x6kc6q.default] - Line Found : user_pref("CT3279411_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1361928092224,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");</p><p>[16x6kc6q.default] - Line Found : user_pref("Smartbar.ConduitHomepagesList", "");</p><p>[16x6kc6q.default] - Line Found : user_pref("Smartbar.ConduitSearchEngineList", "");</p><p>[16x6kc6q.default] - Line Found : user_pref("Smartbar.ConduitSearchUrlList", "");</p><p>[16x6kc6q.default] - Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://dts.search-results.com/sr?src=ffb&gct=ds&appid=400&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=2354520593834836&o=APN10645&q=");</p><p>[16x6kc6q.default] - Line Found : user_pref("Smartbar.keywordURLSelectedCTID", "CT3279411");</p><p>[16x6kc6q.default] - Line Found : user_pref("browser.search.defaultenginename", "Astromenda");</p><p>[16x6kc6q.default] - Line Found : user_pref("browser.search.defaultthis.engineName", "appbario12 Customized Web Search");</p><p>[16x6kc6q.default] - Line Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=3&q={searchTerms}&CUI=UN14353232782267721");</p><p>[16x6kc6q.default] - Line Found : user_pref("browser.search.order.1", "Search Results");</p><p>[16x6kc6q.default] - Line Found : user_pref("browser.search.selectedEngine", "Astromenda");</p><p>[16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.hmpgUrl", "hxxp://astromenda.com/?f=1&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyE[...]</p><p>[16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.newTabUrl", "hxxp://astromenda.com/?f=2&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1CzutC[...]</p><p>[16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.prtnrId", "WSE_Astromenda");</p><p>[16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.srchPrvdr", "Astromenda");</p><p>[16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.tlbrSrchUrl", "hxxp://astromenda.com/?f=3&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1Czu[...]</p><p>[16x6kc6q.default] - Line Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=2&CUI=UN14353232782267721&UM=UM_ID&q=");</p><p>[16x6kc6q.default] - Line Found : user_pref("smartBar.searchInNewTabOwner", "CT3279411");</p><p></p><p>*************************</p><p></p><p>AdwCleaner[R0].txt - [8306 octets] - [22/10/2014 23:31:39]</p><p></p><p>########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [8366 octets] ##########</p><p></p><p> AdwCleaner v4.001 - Report created 22/10/2014 at 23:48:42</p><p># Updated 20/10/2014 by Xplode</p><p># Database : 2014-10-21.1</p><p># Operating System : Windows 7 Professional Service Pack 1 (32 bits)</p><p># Username : stlr - STLR-PC</p><p># Running from : C:\Users\stlr\Downloads\AdwCleaner(1).exe</p><p># Option : Scan</p><p></p><p>***** [ Services ] *****</p><p></p><p></p><p>***** [ Files / Folders ] *****</p><p></p><p>Folder Found : C:\Program Files\Enigma Software Group</p><p>Folder Found : C:\ProgramData\Browser Manager</p><p></p><p>***** [ Scheduled Tasks ] *****</p><p></p><p></p><p>***** [ Shortcuts ] *****</p><p></p><p></p><p>***** [ Registry ] *****</p><p></p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{8F0B76E1-4E46-427B-B55B-B90593468AC6}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}</p><p>Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho</p><p>Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1</p><p>Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3279411</p><p>Key Found : HKLM\SOFTWARE\EnigmaSoftwareGroup</p><p>Key Found : HKLM\SOFTWARE\TermTutor</p><p>Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [<a href="mailto:termtutor@termtutor.com">termtutor@termtutor.com</a>]</p><p>Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe]</p><p>Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe]</p><p>Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe]</p><p>Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe]</p><p></p><p>***** [ Browsers ] *****</p><p></p><p>-\\ Internet Explorer v11.0.9600.17344</p><p></p><p></p><p>-\\ Mozilla Firefox v32.0.3 (x86 en-US)</p><p></p><p></p><p>*************************</p><p></p><p>AdwCleaner[R0].txt - [8446 octets] - [22/10/2014 23:31:39]</p><p>AdwCleaner[R1].txt - [2301 octets] - [22/10/2014 23:48:42]</p><p>AdwCleaner[S0].txt - [8688 octets] - [22/10/2014 23:36:13]</p><p></p><p>########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [2421 octets] ##########</p><p></p><p># AdwCleaner v4.001 - Report created 22/10/2014 at 23:36:13</p><p># DB v</p><p># Updated 20/10/2014 by Xplode</p><p># Operating System : Windows 7 Professional Service Pack 1 (32 bits)</p><p># Username : stlr - STLR-PC</p><p># Running from : C:\Users\stlr\Downloads\AdwCleaner.exe</p><p># Option : Clean</p><p></p><p>***** [ Services ] *****</p><p></p><p></p><p>***** [ Files / Folders ] *****</p><p></p><p>Folder Deleted : C:\Users\stlr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1clickmoviedownloader.com</p><p>Folder Deleted : C:\ProgramData\2308189059</p><p>Folder Deleted : C:\Users\stlr\AppData\Local\Temp\AirInstaller</p><p>[!] Folder Deleted : C:\ProgramData\Browser Manager</p><p>Folder Deleted : C:\Program Files\file scout</p><p>Folder Deleted : C:\Users\stlr\AppData\Roaming\Funmoods</p><p>Folder Deleted : C:\Users\stlr\AppData\Local\Gameo</p><p>Folder Deleted : C:\Users\stlr\AppData\Roaming\Gameo</p><p>Folder Deleted : C:\Program Files\MapsGalaxy_39EI</p><p>Folder Deleted : C:\Users\stlr\AppData\LocalLow\MapsGalaxy_39EI</p><p>Folder Deleted : C:\Users\stlr\AppData\Roaming\PerformerSoft</p><p>Folder Deleted : C:\Users\stlr\AppData\Local\PutLockerDownloader</p><p>Folder Deleted : C:\ProgramData\Tarma Installer</p><p>Folder Deleted : C:\Users\stlr\AppData\Local\torch</p><p>Folder Deleted : C:\Program Files\VideoPerformer</p><p>Folder Deleted : C:\Users\stlr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoPerformer</p><p>Folder Deleted : C:\Users\stlr\AppData\Roaming\WebExtend</p><p>File Deleted : C:\Users\stlr\AppData\Roaming\Mozilla\Firefox\Profiles\16x6kc6q.default\searchplugins\astromenda.xml</p><p>File Deleted : C:\Users\stlr\AppData\Roaming\Mozilla\Firefox\Profiles\16x6kc6q.default\user.js</p><p></p><p>***** [ Scheduled Tasks ] *****</p><p></p><p>Task Deleted : Funmoods</p><p>Task Deleted : LaunchSignup</p><p></p><p>***** [ Shortcuts ] *****</p><p></p><p></p><p>***** [ Registry ] *****</p><p></p><p>Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho</p><p>Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS</p><p>Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3279411</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8F0B76E1-4E46-427B-B55B-B90593468AC6}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}</p><p>Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}</p><p>Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}</p><p>Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe]</p><p>Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe]</p><p>Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe]</p><p>Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe]</p><p>Key Deleted : HKCU\Software\1ClickDownload</p><p>Key Deleted : HKCU\Software\ClickConnect</p><p>Key Deleted : HKCU\Software\Conduit</p><p>Key Deleted : HKCU\Software\filescout</p><p>Key Deleted : HKCU\Software\Funmoods</p><p>Key Deleted : HKCU\Software\ilivid</p><p>Key Deleted : HKCU\Software\InstallCore</p><p>Key Deleted : HKCU\Software\systweak</p><p>Key Deleted : HKCU\Software\torch</p><p>Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}</p><p>Key Deleted : HKCU\Software\AppDataLow\Software\MapsGalaxy_39EI</p><p>Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar</p><p>Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}</p><p>Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}</p><p>Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}</p><p>Key Deleted : HKLM\SOFTWARE\Conduit</p><p>Key Deleted : HKLM\SOFTWARE\InstallCore</p><p>Key Deleted : HKLM\SOFTWARE\MapsGalaxy_39EI</p><p>Key Deleted : HKLM\SOFTWARE\Tarma Installer</p><p>Key Deleted : HKLM\SOFTWARE\torch</p><p></p><p>***** [ Browsers ] *****</p><p></p><p>-\\ Internet Explorer v11.0.9600.17344</p><p></p><p></p><p>-\\ Mozilla Firefox v32.0.3 (x86 en-US)</p><p></p><p>[16x6kc6q.default] - Line Deleted : user_pref("CT3279411_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1361928092224,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("Smartbar.ConduitHomepagesList", "");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("Smartbar.ConduitSearchEngineList", "");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("Smartbar.ConduitSearchUrlList", "");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://dts.search-results.com/sr?src=ffb&gct=ds&appid=400&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=2354520593834836&o=APN10645&q=");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3279411");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("browser.search.defaultenginename", "Astromenda");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("browser.search.defaultthis.engineName", "appbario12 Customized Web Search");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=3&q={searchTerms}&CUI=UN14353232782267721");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("browser.search.order.1", "Search Results");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("browser.search.selectedEngine", "Astromenda");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.hmpgUrl", "hxxp://astromenda.com/?f=1&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyE[...]</p><p>[16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.newTabUrl", "hxxp://astromenda.com/?f=2&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1CzutC[...]</p><p>[16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.prtnrId", "WSE_Astromenda");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.srchPrvdr", "Astromenda");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.tlbrSrchUrl", "hxxp://astromenda.com/?f=3&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1Czu[...]</p><p>[16x6kc6q.default] - Line Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=2&CUI=UN14353232782267721&UM=UM_ID&q=");</p><p>[16x6kc6q.default] - Line Deleted : user_pref("smartBar.searchInNewTabOwner", "CT3279411");</p><p></p><p>*************************</p><p></p><p>AdwCleaner[R0].txt - [8446 octets] - [22/10/2014 23:31:39]</p><p>AdwCleaner[S0].txt - [8548 octets] - [22/10/2014 23:36:13]</p><p></p><p>########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8608 octets] ##########</p><p></p><p></p><p> AdwCleaner v4.001 - Report created 22/10/2014 at 23:51:07</p><p># DB v2014-10-21.1</p><p># Updated 20/10/2014 by Xplode</p><p># Operating System : Windows 7 Professional Service Pack 1 (32 bits)</p><p># Username : stlr - STLR-PC</p><p># Running from : C:\Users\stlr\Downloads\AdwCleaner(1).exe</p><p># Option : Clean</p><p></p><p>***** [ Services ] *****</p><p></p><p></p><p>***** [ Files / Folders ] *****</p><p></p><p>[#] Folder Deleted : C:\ProgramData\Browser Manager</p><p>Folder Deleted : C:\Program Files\Enigma Software Group</p><p></p><p>***** [ Scheduled Tasks ] *****</p><p></p><p></p><p>***** [ Shortcuts ] *****</p><p></p><p></p><p>***** [ Registry ] *****</p><p></p><p>Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [<a href="mailto:termtutor@termtutor.com">termtutor@termtutor.com</a>]</p><p>Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho</p><p>Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1</p><p>Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3279411</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8F0B76E1-4E46-427B-B55B-B90593468AC6}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}</p><p>Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe]</p><p>Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe]</p><p>Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe]</p><p>Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe]</p><p>Key Deleted : HKLM\SOFTWARE\EnigmaSoftwareGroup</p><p>Key Deleted : HKLM\SOFTWARE\TermTutor</p><p></p><p>***** [ Browsers ] *****</p><p></p><p>-\\ Internet Explorer v11.0.9600.17344</p><p></p><p></p><p>-\\ Mozilla Firefox v32.0.3 (x86 en-US)</p><p></p><p></p><p>*************************</p><p></p><p>AdwCleaner[R0].txt - [8446 octets] - [22/10/2014 23:31:39]</p><p>AdwCleaner[R1].txt - [2501 octets] - [22/10/2014 23:48:42]</p><p>AdwCleaner[S0].txt - [8688 octets] - [22/10/2014 23:36:13]</p><p>AdwCleaner[S1].txt - [2453 octets] - [22/10/2014 23:51:07]</p><p></p><p>########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2513 octets] ##########</p><p></p><p></p><p>Malwarebytes Anti-Malware</p><p><a href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a></p><p></p><p>Scan Date: 23/10/14</p><p>Scan Time: 00:11:22</p><p>Logfile: malwarebytes scan.txt</p><p>Administrator: Yes</p><p></p><p>Version: 2.00.3.1025</p><p>Malware Database: v2014.10.23.01</p><p>Rootkit Database: v2014.10.22.01</p><p>License: Trial</p><p>Malware Protection: Enabled</p><p>Malicious Website Protection: Enabled</p><p>Self-protection: Disabled</p><p></p><p>OS: Windows 7 Service Pack 1</p><p>CPU: x86</p><p>File System: NTFS</p><p>User: stlr</p><p></p><p>Scan Type: Threat Scan</p><p>Result: Completed</p><p>Objects Scanned: 294115</p><p>Time Elapsed: 17 min, 14 sec</p><p></p><p>Memory: Enabled</p><p>Startup: Enabled</p><p>Filesystem: Enabled</p><p>Archives: Enabled</p><p>Rootkits: Disabled</p><p>Heuristics: Enabled</p><p>PUP: Enabled</p><p>PUM: Enabled</p><p></p><p>Processes: 0</p><p>(No malicious items detected)</p><p></p><p>Modules: 0</p><p>(No malicious items detected)</p><p></p><p>Registry Keys: 1</p><p>PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD, Quarantined, [dc4119ff027a5bdbc36830f48281718f],</p><p></p><p>Registry Values: 2</p><p>PUP.Optional.Somoto, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|network_smb_saisoftwarecracks, "C:\Users\stlr\AppData\Local\Temp\\BI_RunOnce.exe" /initurl <a href="http://sub.hereon.info/init/N4xKZste6/:uid:?" target="_blank">http://sub.hereon.info/init/N4xKZste6/:uid:?</a> /affid "-" /id "0" /name " " /uniqid N4xKZste6 /uuid 80DA284F-517A-DD11-8023-CD3D98022083 /biosserial 98022083H /biosversion TOSHIB - 20080603 /csname TECRA S10, Quarantined, [9786df39cfad87af2c4e14fcf213956b]</p><p>PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD|ImagePath, system32\drivers\ttnfd.sys, Quarantined, [dc4119ff027a5bdbc36830f48281718f]</p><p></p><p>Registry Data: 0</p><p>(No malicious items detected)</p><p></p><p>Folders: 4</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi\defaults, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi\defaults\preferences, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p></p><p>Files: 15</p><p>PUP.Optional.Somoto, C:\Users\stlr\AppData\Local\Temp\BI_RunOnce.exe, Quarantined, [9786df39cfad87af2c4e14fcf213956b],</p><p>PUP.Optional.PCPerformer.A, C:\Users\stlr\AppData\Local\Temp\ibtmpc810551\component_358.decrpt, Quarantined, [21fc9c7c483455e141c1db45c33e56aa],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ibtmpc810551\component_514, Quarantined, [27f66dab1c6093a3307c5ce259a7bd43],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\ctbe.exe, Quarantined, [66b748d01a628bab43d3ee319967d52b],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\ieLogic.exe, Quarantined, [39e42eea710bf34399a773bfa55cb749],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\statisticsStub.exe, Quarantined, [48d51008f3891620269e28f45ea33dc3],</p><p>PUP.Optional.SweetPacks.A, C:\Users\stlr\AppData\Local\Temp\BundleSweetIMSetup.exe, Quarantined, [4fce869293e964d2f6de929c778c619f],</p><p>PUP.Optional.Babylon.A, C:\Users\stlr\AppData\Local\Temp\MybabylonTB.exe, Quarantined, [8697bd5bbbc166d0706636f860a3e719],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\chromeid.txt, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\conduit.xml, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\CT3279411.xpi, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\setup.ini.txt, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\version.txt, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi\install.rdf, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p>PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi\defaults\preferences\defaults.js, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46],</p><p></p><p>Physical Sectors: 0</p><p>(No malicious items detected)</p><p></p><p></p><p>(end)</p></blockquote><p></p>
[QUOTE="LvonB, post: 282977, member: 29480"] I don't have a clue how to use the: aswMBR version 1.0.1.2161 Copyright(c) 2014 AVAST Software Run date: 2014-10-23 19:26:51 ----------------------------- 19:26:51.811 OS Version: Windows 6.1.7601 Service Pack 1 19:26:51.811 Number of processors: 2 586 0x1706 19:26:51.815 ComputerName: STLR-PC UserName: stlr 19:26:52.113 Initialze error C0000022 - driver not loaded 19:27:08.464 AVAST engine download error: 0 19:27:38.024 Scan error: Incorrect function. 19:27:42.450 Disk 0 statistics 0/0/0 @ -1,#J MB/s 19:27:42.451 Scan stopped 19:27:45.748 Scan error: Incorrect function. 19:28:03.725 The log file has been saved successfully to "C:\Users\stlr\Desktop\aswMBR.txt" # AdwCleaner v4.001 - Report created 22/10/2014 at 23:31:39 # Updated 20/10/2014 by Xplode # Database : # Operating System : Windows 7 Professional Service Pack 1 (32 bits) # Username : stlr - STLR-PC # Running from : C:\Users\stlr\Downloads\AdwCleaner.exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** File Found : C:\Users\stlr\AppData\Roaming\Mozilla\Firefox\Profiles\16x6kc6q.default\searchplugins\astromenda.xml File Found : C:\Users\stlr\AppData\Roaming\Mozilla\Firefox\Profiles\16x6kc6q.default\user.js Folder Found : C:\Program Files\file scout Folder Found : C:\Program Files\MapsGalaxy_39EI Folder Found : C:\Program Files\VideoPerformer Folder Found : C:\ProgramData\2308189059 Folder Found : C:\ProgramData\Browser Manager Folder Found : C:\ProgramData\Tarma Installer Folder Found : C:\Users\stlr\AppData\Local\Gameo Folder Found : C:\Users\stlr\AppData\Local\PutLockerDownloader Folder Found : C:\Users\stlr\AppData\Local\Temp\AirInstaller Folder Found : C:\Users\stlr\AppData\Local\torch Folder Found : C:\Users\stlr\AppData\LocalLow\MapsGalaxy_39EI Folder Found : C:\Users\stlr\AppData\Roaming\Funmoods Folder Found : C:\Users\stlr\AppData\Roaming\Gameo Folder Found : C:\Users\stlr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1clickmoviedownloader.com Folder Found : C:\Users\stlr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoPerformer Folder Found : C:\Users\stlr\AppData\Roaming\PerformerSoft Folder Found : C:\Users\stlr\AppData\Roaming\WebExtend ***** [ Scheduled Tasks ] ***** Task Found : Funmoods Task Found : LaunchSignup ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\1ClickDownload Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Found : HKCU\Software\AppDataLow\Software\MapsGalaxy_39EI Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\ClickConnect Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\filescout Key Found : HKCU\Software\Funmoods Key Found : HKCU\Software\ilivid Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKCU\Software\systweak Key Found : HKCU\Software\torch Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{8F0B76E1-4E46-427B-B55B-B90593468AC6} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3279411 Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\InstallCore Key Found : HKLM\SOFTWARE\MapsGalaxy_39EI Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Key Found : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6} Key Found : HKLM\SOFTWARE\Tarma Installer Key Found : HKLM\SOFTWARE\torch Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17344 -\\ Mozilla Firefox v32.0.3 (x86 en-US) [16x6kc6q.default] - Line Found : user_pref("CT3279411_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1361928092224,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]"); [16x6kc6q.default] - Line Found : user_pref("Smartbar.ConduitHomepagesList", ""); [16x6kc6q.default] - Line Found : user_pref("Smartbar.ConduitSearchEngineList", ""); [16x6kc6q.default] - Line Found : user_pref("Smartbar.ConduitSearchUrlList", ""); [16x6kc6q.default] - Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://dts.search-results.com/sr?src=ffb&gct=ds&appid=400&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=2354520593834836&o=APN10645&q="); [16x6kc6q.default] - Line Found : user_pref("Smartbar.keywordURLSelectedCTID", "CT3279411"); [16x6kc6q.default] - Line Found : user_pref("browser.search.defaultenginename", "Astromenda"); [16x6kc6q.default] - Line Found : user_pref("browser.search.defaultthis.engineName", "appbario12 Customized Web Search"); [16x6kc6q.default] - Line Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=3&q={searchTerms}&CUI=UN14353232782267721"); [16x6kc6q.default] - Line Found : user_pref("browser.search.order.1", "Search Results"); [16x6kc6q.default] - Line Found : user_pref("browser.search.selectedEngine", "Astromenda"); [16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.hmpgUrl", "hxxp://astromenda.com/?f=1&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyE[...] [16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.newTabUrl", "hxxp://astromenda.com/?f=2&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1CzutC[...] [16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.prtnrId", "WSE_Astromenda"); [16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.srchPrvdr", "Astromenda"); [16x6kc6q.default] - Line Found : user_pref("extensions.astrmndasr.tlbrSrchUrl", "hxxp://astromenda.com/?f=3&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1Czu[...] [16x6kc6q.default] - Line Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=2&CUI=UN14353232782267721&UM=UM_ID&q="); [16x6kc6q.default] - Line Found : user_pref("smartBar.searchInNewTabOwner", "CT3279411"); ************************* AdwCleaner[R0].txt - [8306 octets] - [22/10/2014 23:31:39] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [8366 octets] ########## AdwCleaner v4.001 - Report created 22/10/2014 at 23:48:42 # Updated 20/10/2014 by Xplode # Database : 2014-10-21.1 # Operating System : Windows 7 Professional Service Pack 1 (32 bits) # Username : stlr - STLR-PC # Running from : C:\Users\stlr\Downloads\AdwCleaner(1).exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Found : C:\Program Files\Enigma Software Group Folder Found : C:\ProgramData\Browser Manager ***** [ Scheduled Tasks ] ***** ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{8F0B76E1-4E46-427B-B55B-B90593468AC6} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3279411 Key Found : HKLM\SOFTWARE\EnigmaSoftwareGroup Key Found : HKLM\SOFTWARE\TermTutor Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[email]termtutor@termtutor.com[/email]] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17344 -\\ Mozilla Firefox v32.0.3 (x86 en-US) ************************* AdwCleaner[R0].txt - [8446 octets] - [22/10/2014 23:31:39] AdwCleaner[R1].txt - [2301 octets] - [22/10/2014 23:48:42] AdwCleaner[S0].txt - [8688 octets] - [22/10/2014 23:36:13] ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [2421 octets] ########## # AdwCleaner v4.001 - Report created 22/10/2014 at 23:36:13 # DB v # Updated 20/10/2014 by Xplode # Operating System : Windows 7 Professional Service Pack 1 (32 bits) # Username : stlr - STLR-PC # Running from : C:\Users\stlr\Downloads\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Users\stlr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1clickmoviedownloader.com Folder Deleted : C:\ProgramData\2308189059 Folder Deleted : C:\Users\stlr\AppData\Local\Temp\AirInstaller [!] Folder Deleted : C:\ProgramData\Browser Manager Folder Deleted : C:\Program Files\file scout Folder Deleted : C:\Users\stlr\AppData\Roaming\Funmoods Folder Deleted : C:\Users\stlr\AppData\Local\Gameo Folder Deleted : C:\Users\stlr\AppData\Roaming\Gameo Folder Deleted : C:\Program Files\MapsGalaxy_39EI Folder Deleted : C:\Users\stlr\AppData\LocalLow\MapsGalaxy_39EI Folder Deleted : C:\Users\stlr\AppData\Roaming\PerformerSoft Folder Deleted : C:\Users\stlr\AppData\Local\PutLockerDownloader Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\Users\stlr\AppData\Local\torch Folder Deleted : C:\Program Files\VideoPerformer Folder Deleted : C:\Users\stlr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoPerformer Folder Deleted : C:\Users\stlr\AppData\Roaming\WebExtend File Deleted : C:\Users\stlr\AppData\Roaming\Mozilla\Firefox\Profiles\16x6kc6q.default\searchplugins\astromenda.xml File Deleted : C:\Users\stlr\AppData\Roaming\Mozilla\Firefox\Profiles\16x6kc6q.default\user.js ***** [ Scheduled Tasks ] ***** Task Deleted : Funmoods Task Deleted : LaunchSignup ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3279411 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8F0B76E1-4E46-427B-B55B-B90593468AC6} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] Key Deleted : HKCU\Software\1ClickDownload Key Deleted : HKCU\Software\ClickConnect Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\filescout Key Deleted : HKCU\Software\Funmoods Key Deleted : HKCU\Software\ilivid Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\systweak Key Deleted : HKCU\Software\torch Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Deleted : HKCU\Software\AppDataLow\Software\MapsGalaxy_39EI Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\InstallCore Key Deleted : HKLM\SOFTWARE\MapsGalaxy_39EI Key Deleted : HKLM\SOFTWARE\Tarma Installer Key Deleted : HKLM\SOFTWARE\torch ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17344 -\\ Mozilla Firefox v32.0.3 (x86 en-US) [16x6kc6q.default] - Line Deleted : user_pref("CT3279411_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1361928092224,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]"); [16x6kc6q.default] - Line Deleted : user_pref("Smartbar.ConduitHomepagesList", ""); [16x6kc6q.default] - Line Deleted : user_pref("Smartbar.ConduitSearchEngineList", ""); [16x6kc6q.default] - Line Deleted : user_pref("Smartbar.ConduitSearchUrlList", ""); [16x6kc6q.default] - Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://dts.search-results.com/sr?src=ffb&gct=ds&appid=400&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=2354520593834836&o=APN10645&q="); [16x6kc6q.default] - Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3279411"); [16x6kc6q.default] - Line Deleted : user_pref("browser.search.defaultenginename", "Astromenda"); [16x6kc6q.default] - Line Deleted : user_pref("browser.search.defaultthis.engineName", "appbario12 Customized Web Search"); [16x6kc6q.default] - Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=3&q={searchTerms}&CUI=UN14353232782267721"); [16x6kc6q.default] - Line Deleted : user_pref("browser.search.order.1", "Search Results"); [16x6kc6q.default] - Line Deleted : user_pref("browser.search.selectedEngine", "Astromenda"); [16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.hmpgUrl", "hxxp://astromenda.com/?f=1&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyE[...] [16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.newTabUrl", "hxxp://astromenda.com/?f=2&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1CzutC[...] [16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.prtnrId", "WSE_Astromenda"); [16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.srchPrvdr", "Astromenda"); [16x6kc6q.default] - Line Deleted : user_pref("extensions.astrmndasr.tlbrSrchUrl", "hxxp://astromenda.com/?f=3&a=ast_clickconnect_14_38_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0DyCtBzztDyD0CyC0EyB0CtN0D0Tzu0SzyzytDtN1L2XzutAtFtBtFtCtFyDtN1L1Czu[...] [16x6kc6q.default] - Line Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=2&CUI=UN14353232782267721&UM=UM_ID&q="); [16x6kc6q.default] - Line Deleted : user_pref("smartBar.searchInNewTabOwner", "CT3279411"); ************************* AdwCleaner[R0].txt - [8446 octets] - [22/10/2014 23:31:39] AdwCleaner[S0].txt - [8548 octets] - [22/10/2014 23:36:13] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8608 octets] ########## AdwCleaner v4.001 - Report created 22/10/2014 at 23:51:07 # DB v2014-10-21.1 # Updated 20/10/2014 by Xplode # Operating System : Windows 7 Professional Service Pack 1 (32 bits) # Username : stlr - STLR-PC # Running from : C:\Users\stlr\Downloads\AdwCleaner(1).exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** [#] Folder Deleted : C:\ProgramData\Browser Manager Folder Deleted : C:\Program Files\Enigma Software Group ***** [ Scheduled Tasks ] ***** ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[email]termtutor@termtutor.com[/email]] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3279411 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8F0B76E1-4E46-427B-B55B-B90593468AC6} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] Key Deleted : HKLM\SOFTWARE\EnigmaSoftwareGroup Key Deleted : HKLM\SOFTWARE\TermTutor ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17344 -\\ Mozilla Firefox v32.0.3 (x86 en-US) ************************* AdwCleaner[R0].txt - [8446 octets] - [22/10/2014 23:31:39] AdwCleaner[R1].txt - [2501 octets] - [22/10/2014 23:48:42] AdwCleaner[S0].txt - [8688 octets] - [22/10/2014 23:36:13] AdwCleaner[S1].txt - [2453 octets] - [22/10/2014 23:51:07] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2513 octets] ########## Malwarebytes Anti-Malware [url="http://www.malwarebytes.org"]www.malwarebytes.org[/url] Scan Date: 23/10/14 Scan Time: 00:11:22 Logfile: malwarebytes scan.txt Administrator: Yes Version: 2.00.3.1025 Malware Database: v2014.10.23.01 Rootkit Database: v2014.10.22.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x86 File System: NTFS User: stlr Scan Type: Threat Scan Result: Completed Objects Scanned: 294115 Time Elapsed: 17 min, 14 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 1 PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD, Quarantined, [dc4119ff027a5bdbc36830f48281718f], Registry Values: 2 PUP.Optional.Somoto, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|network_smb_saisoftwarecracks, "C:\Users\stlr\AppData\Local\Temp\\BI_RunOnce.exe" /initurl [url]http://sub.hereon.info/init/N4xKZste6/:uid:?[/url] /affid "-" /id "0" /name " " /uniqid N4xKZste6 /uuid 80DA284F-517A-DD11-8023-CD3D98022083 /biosserial 98022083H /biosversion TOSHIB - 20080603 /csname TECRA S10, Quarantined, [9786df39cfad87af2c4e14fcf213956b] PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD|ImagePath, system32\drivers\ttnfd.sys, Quarantined, [dc4119ff027a5bdbc36830f48281718f] Registry Data: 0 (No malicious items detected) Folders: 4 PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi\defaults, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi\defaults\preferences, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], Files: 15 PUP.Optional.Somoto, C:\Users\stlr\AppData\Local\Temp\BI_RunOnce.exe, Quarantined, [9786df39cfad87af2c4e14fcf213956b], PUP.Optional.PCPerformer.A, C:\Users\stlr\AppData\Local\Temp\ibtmpc810551\component_358.decrpt, Quarantined, [21fc9c7c483455e141c1db45c33e56aa], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ibtmpc810551\component_514, Quarantined, [27f66dab1c6093a3307c5ce259a7bd43], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\ctbe.exe, Quarantined, [66b748d01a628bab43d3ee319967d52b], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\ieLogic.exe, Quarantined, [39e42eea710bf34399a773bfa55cb749], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\statisticsStub.exe, Quarantined, [48d51008f3891620269e28f45ea33dc3], PUP.Optional.SweetPacks.A, C:\Users\stlr\AppData\Local\Temp\BundleSweetIMSetup.exe, Quarantined, [4fce869293e964d2f6de929c778c619f], PUP.Optional.Babylon.A, C:\Users\stlr\AppData\Local\Temp\MybabylonTB.exe, Quarantined, [8697bd5bbbc166d0706636f860a3e719], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\chromeid.txt, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\conduit.xml, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\CT3279411.xpi, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\setup.ini.txt, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\version.txt, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi\install.rdf, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], PUP.Optional.Conduit.A, C:\Users\stlr\AppData\Local\Temp\ct3279411\xpi\defaults\preferences\defaults.js, Quarantined, [0e0f5dbbf587a88eeab4c828f40eba46], Physical Sectors: 0 (No malicious items detected) (end) [/QUOTE]
Insert quotes…
Verification
Post reply
Top