crashing and excess memory usage


Recommended Posts

Wyo, We need to Run an OTL fix !!

    * Double-click OTL.exe to start the program.
    * Copy and Paste the following code into the customFix.png. Do not include the word Code

:OTLPRC - [2013/10/19 09:59:13 | 000,143,488 | ---- | M] () -- c:\Program Files\Optimizer Pro\OptProCrash.exeDRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS -- (SYMNDISV)DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS -- (SYMFW)DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Owner\AppData\Local\Temp\mbr.sys -- (mbr)DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)IE - HKLM\..\SearchScopes,DefaultScope = {E54CD624-092C-4045-9602-40E45A36643A}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =IE - HKU\.DEFAULT\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\.DEFAULT\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...101881&l=dis&q={SEARCHTERMS}IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-18\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\S-1-5-18\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...101881&l=dis&q={SEARCHTERMS}IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-19\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\S-1-5-19\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...101881&l=dis&q={SEARCHTERMS}IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-20\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\S-1-5-20\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...101881&l=dis&q={SEARCHTERMS}IE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes,DefaultScope = {E54CD624-092C-4045-9602-40E45A36643AIE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRCIE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{CE3A3FD1-0A27-07DC-3FED-9D0FBEBC1CD0}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=Z131&form=ZGAIDF&install_date=20110826&iesrc={referrer:source}IE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}IE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{E54CD624-092C-4045-9602-40E45A36643A}: "URL" = http://search.condui...ultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3291325&CUI=UN56563854018622839&UM=2[2010/10/05 20:41:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions[2013/10/19 10:02:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions[2013/10/19 10:02:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged[2012/02/02 20:15:29 | 000,020,591 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi[2013/10/19 11:33:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensionsFile not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{1930E38A-DEEF-4CF4-9BFB-9C4EA3689A9D}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{5911488E-9D1E-40EC-8CBB-06B231CC153F}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{635ABD67-4FE9-1B23-4F01-E679FA7484C1}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\[email protected] - BHO: (KeyBar 1.12 Toolbar) - {0134af61-7a0c-4649-aeca-90d776060cb3} - C:\Program Files\KeyBar_1.12\prxtbKeyB.dll (Conduit Ltd.)O2 - BHO: (Fast Free Converter 4.1) - {C3E50543-BC36-4C80-8070-38A97E02DEB2} - C:\PROGRA~1\FASTFR~1\FASTFR~1\FASTFR~1.DLL File not foundO3 - HKLM\..\Toolbar: (KeyBar 1.12 Toolbar) - {0134af61-7a0c-4649-aeca-90d776060cb3} - C:\Program Files\KeyBar_1.12\prxtbKeyB.dll (Conduit Ltd.)O3 - HKLM\..\Toolbar: (no name) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - No CLSID value found.O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.O3 - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\Toolbar\WebBrowser: (no name) - {1930E38A-DEEF-4CF4-9BFB-9C4EA3689A9D} - No CLSID value found.O4 - HKLM..\Run: []  File not foundO4 - HKU\S-1-5-21-496666239-834425297-2685965361-1000..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe (PC Utilities Pro)O13 - gopher Prefix: missingO20 - AppInit_DLLs: (c:\progra~1\optimi~1\optpro~1.dll) - c:\Program Files\Optimizer Pro\OptProCrash.dll ()[2013/10/19 10:04:47 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Optimizer Pro[2013/10/19 10:04:45 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Optimizer Pro[2013/10/19 10:02:29 | 000,000,000 | ---D | C] -- C:\Program Files\KeyBar_1.12[2013/10/19 09:59:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2[2013/10/19 09:59:08 | 000,000,000 | ---D | C] -- C:\Program Files\Optimizer Pro[2013/10/19 10:04:45 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Optimizer Pro:FilesC:\Users\Owner\Documents\Optimizer ProC:\Program Files\KeyBar_1.12 :Commands[emptyjava][emptyflash][EMPTYTEMP][RESETHOSTS][CREATERESTOREPOINT][Reboot]

# Then click the Run Fix button at the top.
# Click btnOK.png
# Please post the contents of the fix log file back here if you are prompted to open the file. It can also be found at C:\_OTL\Moved Files as MMDDYYY_HHMMSS.log where MMDDYYY is date format and HHMMSS is time format.
Remember to enable your real time protection.
 

 

Post that report for me !!

 

Thanks

Chuck
 

Link to post
Share on other sites
All processes killed

========== OTL ==========

No active process named OptProCrash.exe was found!

Service SYMNDISV stopped successfully!

Service SYMNDISV deleted successfully!

File C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS not found.

Service SYMFW stopped successfully!

Service SYMFW deleted successfully!

File C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS not found.

Service NwlnkFwd stopped successfully!

Service NwlnkFwd deleted successfully!

File system32\DRIVERS\nwlnkfwd.sys not found.

Service NwlnkFlt stopped successfully!

Service NwlnkFlt deleted successfully!

File system32\DRIVERS\nwlnkflt.sys not found.

Error: No service named mbr was found to stop!

Service\Driver key mbr not found.

File C:\Users\Owner\AppData\Local\Temp\mbr.sys not found.

Service IpInIp stopped successfully!

Service IpInIp deleted successfully!

File system32\DRIVERS\ipinip.sys not found.

Service blbdrive stopped successfully!

Service blbdrive deleted successfully!

File C:\Windows\system32\drivers\blbdrive.sys not found.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.

HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.

Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.

HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.

Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.

HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.

Registry key HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.

HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.

Registry key HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.

HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.

Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CE3A3FD1-0A27-07DC-3FED-9D0FBEBC1CD0}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE3A3FD1-0A27-07DC-3FED-9D0FBEBC1CD0}\ not found.

Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ not found.

Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E54CD624-092C-4045-9602-40E45A36643A}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E54CD624-092C-4045-9602-40E45A36643A}\ not found.

C:\Users\Owner\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Extensions folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\META-INF folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\chrome\skin folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\chrome\content\locale folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\chrome\content folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\chrome folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0} folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\components folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome\PublisherImages folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f} folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Plugins folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\modules folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\META-INF folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\lib folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\defaults\preferences folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\defaults folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\components folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\sl folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\lib\jquery.jscrollpane folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\lib\jquery.alerts\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\lib\jquery.alerts folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\lib folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\core folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\WEATHER\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\WEATHER\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\WEATHER folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\TWITTER\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\TWITTER\img folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\TWITTER folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\view\style\rsx folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\view\style folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\view\script folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\view folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\resources folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\Css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\buildSettings folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER\js\resources folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER\css\custom-theme folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG\css\custom-theme folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG\agreement folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\Optimizer\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\Optimizer folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\images\light folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\images\dark folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS\js\resources folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS\img folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\HIGHLIGHTER\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\HIGHLIGHTER\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\HIGHLIGHTER folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\EMAIL_NOTIFIER\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\EMAIL_NOTIFIER\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\EMAIL_NOTIFIER folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\APPLICATION_BUTTON\resources folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\APPLICATION_BUTTON\Js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\APPLICATION_BUTTON folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\menu\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\menu\img folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\menu\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\menu folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gf\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gf\img folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gf\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gf folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gadgetFrame folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\dlg\ftd\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\dlg\ftd folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\dlg folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\spsd\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\spsd folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\spbd\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\spbd folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options\js\resources folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\msd folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\api folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ac\res folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ac\img folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ac\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ac folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\aboutBox\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\aboutBox\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\aboutBox folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall\dialog\js folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall\dialog\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall\dialog\css folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall\dialog folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325 folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3} folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\components folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome\PublisherImages folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome\images folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f} folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged folder moved successfully.

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions folder moved successfully.

Folder C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\ not found.

File C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi not found.

C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.

C:\Program Files\Mozilla Firefox\extensions folder moved successfully.

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0134af61-7a0c-4649-aeca-90d776060cb3}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0134af61-7a0c-4649-aeca-90d776060cb3}\ deleted successfully.

C:\Program Files\KeyBar_1.12\prxtbKeyB.dll moved successfully.

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C3E50543-BC36-4C80-8070-38A97E02DEB2}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3E50543-BC36-4C80-8070-38A97E02DEB2}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0134af61-7a0c-4649-aeca-90d776060cb3} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0134af61-7a0c-4649-aeca-90d776060cb3}\ not found.

File C:\Program Files\KeyBar_1.12\prxtbKeyB.dll not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8660E5B3-6C41-44DE-8503-98D99BBECD41} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.

Registry value HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1930E38A-DEEF-4CF4-9BFB-9C4EA3689A9D} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1930E38A-DEEF-4CF4-9BFB-9C4EA3689A9D}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.

Registry value HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro not found.

File C:\Program Files\Optimizer Pro\OptProLauncher.exe not found.


Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~1\optimi~1\optpro~1.dll deleted successfully.

File c:\Program Files\Optimizer Pro\OptProCrash.dll not found.

C:\Users\Owner\Documents\Optimizer Pro folder moved successfully.

C:\Users\Owner\AppData\Roaming\Optimizer Pro\Undo folder moved successfully.

C:\Users\Owner\AppData\Roaming\Optimizer Pro\Log folder moved successfully.

C:\Users\Owner\AppData\Roaming\Optimizer Pro\Backup folder moved successfully.

C:\Users\Owner\AppData\Roaming\Optimizer Pro folder moved successfully.

C:\Program Files\KeyBar_1.12 folder moved successfully.

Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\ not found.

C:\Program Files\Optimizer Pro folder moved successfully.

Folder C:\Users\Owner\AppData\Roaming\Optimizer Pro\ not found.

========== FILES ==========

File\Folder C:\Users\Owner\Documents\Optimizer Pro not found.

File\Folder C:\Program Files\KeyBar_1.12 not found.

========== COMMANDS ==========

 

[EMPTYJAVA]

 

User: All Users

 

User: Default

 

User: Default User

 

User: Owner

->Java cache emptied: 14421 bytes

 

User: Public

 

Total Java Files Cleaned = 0.00 mb

 

 

[EMPTYFLASH]

 

User: All Users

 

User: Default

->Flash cache emptied: 56502 bytes

 

User: Default User

->Flash cache emptied: 0 bytes

 

User: Owner

->Flash cache emptied: 37665 bytes

 

User: Public

 

Total Flash Files Cleaned = 0.00 mb

 

 

[EMPTYTEMP]

 

User: All Users

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

->Flash cache emptied: 0 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

 

User: Owner

->Temp folder emptied: 8912192 bytes

->Temporary Internet Files folder emptied: 1185313 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 130224386 bytes

->Google Chrome cache emptied: 325699781 bytes

->Flash cache emptied: 0 bytes

 

User: Public

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 2096542 bytes

RecycleBin emptied: 61417027 bytes

 

Total Files Cleaned = 505.00 mb

 

C:\Windows\System32\drivers\etc\Hosts moved successfully.

HOSTS file reset successfully

Restore point Set: OTL Restore Point

 

OTL by OldTimer - Version 3.2.69.0 log created on 10202013_070615
Link to post
Share on other sites

Morning Wyo, almost done with the cleaning !!

 

Are you using Norton as an antivirus ??

 

================

 

 

Clean up with OTL


    Right-click OTL.exe and select " Run as administrator " to run it.
    This will remove all the tools we used to clean your pc.
    Close all other programs apart from OTL as this step will require a reboot
    On the OTL main screen, press the CleanUp! button
    Say Yes to the prompt and then allow the program to reboot your computer.


You can now delete any tools we used if they remain on your Desktop.

 

 

 

======================

 

 

ESET online scannner >>> http://www.eset.com/onlinescan/


Note: You can use either Internet Explorer or Mozilla FireFox for this scan.


   1. Firstly please Disable any Antivirus you have active , as shown in This topic.
   2. Note: Don't forget to re-enable it after the scan.
   3. Next please click on the following link to open a new window to ESET online scannnerhttp://www.eset.com/us/online-scanner/features
    4. Then click on:ESETONLINESCAN.gif

Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.


 5. Select the option YES, I accept the Terms of Use then click on:EOLS2.gif
 
 6. When prompted allow the Add-On/Active X to install.
  7. Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  8. Now click on Advanced Settings and select the following:

      * Scan for potentially unwanted applications
      *  Scan for potentially unsafe applications
      *  Enable Anti-Stealth Technology
    
  9. Now click on:EOLS3.gif

    10. The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
    11. When completed the Online Scan will begin automatically.
    12. Do not touch either the mouse or keyboard during the scan otherwise it may stall.
    13. When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!

    14. Now click on: EOLS4.gif

    15. Use notepad to open the log file located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
           or may be ESETSmartInstaller@High as CAB hook log:

    16. Copy and paste that log as a reply to this topic. If it finds anything !!!!!

 

 

 

Thanks

Chuck

 

Let me know how it's running & if any problems exist ??

 

Link to post
Share on other sites

Ok, i will leave Norton alone it use to be a big resource hog, slowing down computers ! Most users i get say they want to remove it cause they are tired of paying !

 

I want to run 1 more program, this is a very powerful tool and do not touch your mouse while in use !!!

 

Vista and Windows 7 users:

1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Download ComboFix from this location:

Link 1
 http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Link 2
http://www.infospyware.net/antimalware/combofix


* IMPORTANT !!! Save ComboFix.exe to your Desktop



  * Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.

    *  See this Link >>> http://www.bleepingcomputer.com/forums/topic114351.html <<<  for programs that need to be disabled and instruction on how to disable them.
   
    *  Remember to re-enable them when we're done.

    *  Double click on ComboFix.exe & follow the prompts.

    *  As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    *  Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.



**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RC1.png


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC2-1.png


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.

 Notes:   

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of  ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
4.  CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.   

Give it at least 20-30 minutes to finish if needed.

 Please do not attach the scan results from Combofix. Use copy/paste.   

 

 

Post that log next !!

 

Thanks

Chuck

 

How's it running ? Should be a lot, lot better after all that junk we removed !!
 

Link to post
Share on other sites
C:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\genfix.exe.vir Win32/Toolbar.Zugo.D application

C:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\Reactivate.exe.vir a variant of Win32/Toolbar.Zugo application

C:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\search_protect.exe.vir Win32/Toolbar.Zugo.D application

C:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\Toolbar32.dll.vir a variant of Win32/Toolbar.Zugo application

C:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\ToolbarBroker.exe.vir a variant of Win32/Toolbar.Zugo application

C:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe.vir a variant of Win32/Toolbar.Zugo application

C:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\Extensions\[email protected]\content\overlay.js.vir Win32/Adware.Yontoo application

C:\Program Files\Mozilla Firefox\nsprotector.js Win32/Conduit.SearchProtect.A application

C:\Program Files\Uninstall Information\ib_uninst_342\uninstall.exe a variant of Win32/InstallBrain.H application

C:\Program Files\Uninstall Information\ib_uninst_343\uninstall.exe a variant of Win32/InstallBrain.H application

C:\Program Files\Uninstall Information\ib_uninst_383\uninstall.exe a variant of Win32/InstallBrain.H application

C:\Program Files\Uninstall Information\ib_uninst_514\uninstall.exe a variant of Win32/InstallBrain.H application

C:\Program Files\Uninstall Information\ib_uninst_569\uninstall.exe a variant of Win32/InstallBrain.H application

C:\Users\Owner\AppData\Local\Temp\YontooLayers\background.html JS/Adware.Yontoo.B application

C:\Users\Owner\Downloads\ARO2013_tbt.exe a variant of Win32/Bundled.Toolbar.Ask.D application

C:\Users\Owner\Downloads\cbsidlm-tr1_6-Photo_Story_3_for_Windows-10339154.exe Win32/DownloadAdmin.G application

C:\Users\Owner\Downloads\h2testw_1_4_mediaget.exe a variant of Win32/MediaGet application

C:\Users\Owner\Downloads\setup.exe a variant of Win32/AirAdInstaller.A application

C:\Users\Owner\Downloads\vlcmediaplayer-setup.exe multiple threats

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2F5ORKB1\genfix-e[1] Win32/Toolbar.Zugo.D application

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2F5ORKB1\genfix2-a[1] Win32/Toolbar.Zugo.D application

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2F5ORKB1\updater-startnow-200-2.5-g[1].exe a variant of Win32/Toolbar.Zugo application

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6G7ZBYCJ\search-update-d[1] Win32/Toolbar.Zugo.D application

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RRJYAK5X\search-update-d[1] Win32/Toolbar.Zugo.D application

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UHIBYNU1\genfix-e[1] Win32/Toolbar.Zugo.D application
Link to post
Share on other sites
ComboFix 13-10-19.02 - Owner 10/20/2013  12:57:50.1.2 - x86

Microsoft® Windows Vistaâ„¢ Business   6.0.6002.2.1252.1.1033.18.3061.1215 [GMT -6:00]

Running from: c:\users\Owner\Downloads\ComboFix.exe

AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\data

c:\data\default\us_sres.data

C:\END

c:\programdata\ntuser.dat

c:\users\Owner\AppData\Roaming\SearchProtect

c:\windows\desktop

c:\windows\desktop\ROAD TRIPS.lnk

c:\windows\system32\Cache

c:\windows\system32\Cache\06f72eaedf1770ec.fb

c:\windows\system32\Cache\1cf59a059cb2885c.fb

c:\windows\system32\Cache\1f46af2525172b4f.fb

c:\windows\system32\Cache\26c630d098e22dd5.fb

c:\windows\system32\Cache\272512937d9e61a4.fb

c:\windows\system32\Cache\287204568329e189.fb

c:\windows\system32\Cache\28bc8f716fd76a47.fb

c:\windows\system32\Cache\2c53092c95605355.fb

c:\windows\system32\Cache\31a0997e9a5b5eb3.fb

c:\windows\system32\Cache\32c84fe32bb74d60.fb

c:\windows\system32\Cache\3917078cb68ec657.fb

c:\windows\system32\Cache\590ba23ce359fd0c.fb

c:\windows\system32\Cache\610289e025a3ee9a.fb

c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb

c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb

c:\windows\system32\Cache\6d03dad1035885d3.fb

c:\windows\system32\Cache\7377d9d9140c90a3.fb

c:\windows\system32\Cache\74857a87930bf46d.fb

c:\windows\system32\Cache\95f567698be8a182.fb

c:\windows\system32\Cache\9623a552aa2b10dc.fb

c:\windows\system32\Cache\a42664768109be55.fb

c:\windows\system32\Cache\a8556537add6dfc5.fb

c:\windows\system32\Cache\ad10a52aff5e038d.fb

c:\windows\system32\Cache\aef0e377a73d0d0e.fb

c:\windows\system32\Cache\c1fa887b03019701.fb

c:\windows\system32\Cache\c4d28dca2e7648be.fb

c:\windows\system32\Cache\d201ef9910cd39de.fb

c:\windows\system32\Cache\d2e94710a5708128.fb

c:\windows\system32\Cache\d79b9dfe81484ec4.fb

c:\windows\system32\Cache\f998975c9cc711ee.fb

c:\windows\wininit.ini

.

.

(((((((((((((((((((((((((   Files Created from 2013-09-20 to 2013-10-20  )))))))))))))))))))))))))))))))

.

.

2013-10-20 19:09 . 2013-10-20 19:09 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-10-20 17:05 . 2013-10-20 17:05 -------- d-----w- c:\program files\ESET

2013-10-20 13:19 . 2013-10-20 13:19 23830 ----a-w- c:\windows\cscmondump.bin

2013-10-19 17:10 . 2013-10-20 01:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2013-10-19 17:10 . 2013-04-04 20:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-10-19 16:02 . 2013-10-20 02:49 -------- d-----w- c:\programdata\Conduit

2013-10-19 16:02 . 2013-10-19 16:02 -------- d-----w- c:\users\Owner\AppData\Local\Conduit

2013-10-19 16:00 . 2013-10-19 16:01 -------- d-----w- c:\users\Owner\AppData\Local\CRE

2013-10-19 16:00 . 2013-10-19 16:02 -------- d-----w- c:\program files\Conduit

2013-10-19 16:00 . 2013-10-20 00:37 -------- d-----w- c:\program files\SearchProtect

2013-10-19 15:57 . 2013-10-20 00:27 -------- d-----w- c:\programdata\ZalmanInstaller_52331

2013-10-19 15:56 . 2013-10-20 00:27 -------- d-----w- c:\program files\Browsersafeguard

2013-10-19 15:49 . 2013-10-20 13:28 -------- d-----w- c:\users\Owner\AppData\Local\FileTypeAssistant

2013-10-19 14:26 . 2013-10-19 14:26 -------- d-----w- c:\windows\ERUNT

2013-10-19 13:40 . 2013-10-19 14:17 -------- d-----w- C:\AdwCleaner

2013-10-17 17:40 . 2013-10-17 17:40 -------- d-----w- C:\N360_BACKUP

2013-10-09 06:24 . 2013-08-27 01:28 1069056 ----a-w- c:\windows\system32\DWrite.dll

2013-10-09 06:24 . 2013-08-27 01:28 798208 ----a-w- c:\windows\system32\FntCache.dll

2013-10-09 06:24 . 2013-08-27 02:47 219648 ----a-w- c:\windows\system32\d3d10_1core.dll

2013-10-09 06:24 . 2013-08-27 02:47 189952 ----a-w- c:\windows\system32\d3d10core.dll

2013-10-09 06:24 . 2013-08-27 02:47 1029120 ----a-w- c:\windows\system32\d3d10.dll

2013-10-09 06:24 . 2013-08-27 01:52 1172480 ----a-w- c:\windows\system32\d3d10warp.dll

2013-10-09 06:24 . 2013-08-27 01:50 486400 ----a-w- c:\windows\system32\d3d10level9.dll

2013-10-09 06:24 . 2013-08-27 01:32 683008 ----a-w- c:\windows\system32\d2d1.dll

2013-10-09 06:24 . 2013-08-27 02:47 160768 ----a-w- c:\windows\system32\d3d10_1.dll

2013-09-29 05:57 . 2013-10-19 02:46 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\FileTypeAssistant

2013-09-29 00:34 . 2013-10-19 02:46 -------- d-----w- c:\program files\File Type Assistant

2013-09-26 18:00 . 2013-09-26 18:00 208760 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll

.

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-10-09 04:56 . 2012-04-04 14:39 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2013-10-09 04:56 . 2011-06-29 12:10 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-09-11 05:18 . 2013-09-11 05:18 97008 ----a-w- c:\windows\system32\drivers\RapportKELL.sys

2013-09-09 15:24 . 2013-09-09 15:24 1700352 ----a-w- c:\windows\system32\gdiplus.dll

2013-08-02 04:09 . 2013-08-27 20:18 1548288 ----a-w- c:\windows\system32\WMVDECOD.DLL

2013-01-20 02:50 . 2013-01-20 02:50 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-12-13 98304]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-12-13 106496]

"Persistence"="c:\windows\system32\igfxpers.exe" [2006-12-13 81920]

"MFPMonitor"="c:\windows\twain_32\DELL\MFP1125\Monitor\Stsmon.exe" [2007-08-08 2002944]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE -b -l [2000-1-21 65588]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

@="Service"

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ   PLA DPS BFE mpssvc

LocalServiceAndNoImpersonation REG_MULTI_SZ   FontCache

bthsvcs REG_MULTI_SZ   BthServ

WindowsMobile REG_MULTI_SZ   wcescomm rapimgr

LocalServiceRestricted REG_MULTI_SZ   WcesComm RapiMgr

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-10-19 13:26 1185744 ----a-w- c:\program files\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe

.

Contents of the 'Scheduled Tasks' folder

.

2013-10-20 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 04:56]

.

2013-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-22 01:52]

.

2013-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-22 01:52]

.

.

------- Supplementary Scan -------

.



TCP: DhcpNameServer = 192.168.0.1

FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\


FF - prefs.js: browser.search.selectedEngine - KeyBar 1.12 Customized Web Search



FF - ExtSQL: !HIDDEN! 2011-01-05 10:50; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - ExtSQL: !HIDDEN! 2012-05-04 20:31; [email protected]; c:\users\Owner\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected]

FF - user.js: extensions.autoDisableScopes - 0

FF - user.js: extensions.shownSelectionUI - true

.

- - - - ORPHANS REMOVED - - - -

.

URLSearchHooks-{0134af61-7a0c-4649-aeca-90d776060cb3} - (no file)

WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

SafeBoot-WudfPf

SafeBoot-WudfRd

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2013-10-20 13:10

Windows 6.0.6002 Service Pack 2 NTFS

.

scanning hidden processes ...  

.

scanning hidden autostart entries ... 

.

scanning hidden files ...  

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]

"ImagePath"="\"c:\program files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\20.4.0.40\diMaster.dll\" /prefetch:1"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

Completion time: 2013-10-20  13:15:05

ComboFix-quarantined-files.txt  2013-10-20 19:14

.

Pre-Run: 26,655,383,552 bytes free

Post-Run: 26,515,025,920 bytes free

.

- - End Of File - - 49044F13D18CF1C141EF2A821D20FA13

5C616939100B85E558DA92B899A0FC36
Link to post
Share on other sites

Ok, thought it might be but i can't make assumptions when it comes to a fix for the log posted !! It could make a door stop out of the computer !!

BRB with a fix !!

Link to post
Share on other sites

Wyo, click to open ESET !!

 

*Open the main program window by clicking the ESET icon  !!

*Make sure that the BOX Remove found threats is  checked.

*Now click on:EOLS3.gif

*Do not touch either the mouse or keyboard during the removal process otherwise it may stall.
 

 

 

 

 

NEXT

 

 

 

 

Time for some housekeeping
[*] Click START then RUN [*] Now type Combofix /Uninstall in the runbox and click OK( please note the space between Combofix and the /, it is needed.)

CF-Uninstall.png


The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.

Once you have typed this in, press Enter on your keyboard. A Open File security warning will appear asking if you are sure you want to run ComboFix.
Please click on the Run button to start the program.

ComboFix will now uninstall itself from your computer and remove any backups and quarantined files.
When it has finished you will be greeted by a dialog box stating that ComboFix has been uninstalled.
You can now delete the ComboFix.exe program from your computer.
ComboFix has now been uninstalled from your Windows Vista or Windows 7 computer.

 

 

 

Let me know how this goes ??

Also how's it running ??

Any other problems ??

 

 

Thanks

Chuck
 

Link to post
Share on other sites

Wyo ................

 

I know you may have some of these installed, this is just my standard all clean speech !

Congratulation you are clean !!!

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:


 1. Make your Internet Explorer more secure - This can be done by following these simple instructions:

  * From within Internet Explorer click on the Tools menu and then click on Options.
   * Click once on the  Security tab
   * Click once on the  Internet icon so it becomes highlighted.
   * Click once on the  Custom Level button.
   * Change the  Download signed ActiveX controls to Prompt
   * Change the  Download unsigned ActiveX controls to Disable
   * Change the  Initialize and script ActiveX controls not marked as safe to Disable
  *  Change the  Installation of desktop items to Prompt
   * Change the  Launching programs and files in an IFRAME to Prompt
   * Change the  Navigate sub-frames across different domains to Prompt
   * When all these settings have been made, click on the  OK button.
   * If it prompts you as to whether or not you want to save the settings, press the  Yes button.
  *  Next press the  Apply button and then the  OK to exit the Internet Properties page.


 2. Enable Protected Mode in Internet Explorer . This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:

  *  Open  Internet Explorer
  *  Click on  Tools > Internet Options
  *  Press  Security tab
   * Select Internet zone then place check next to Enable Protected Mode if not already done
  *  Do the same for  Local Intranet, Trusted Sites and  Restricted Sites and then press  Apply
  *  Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.


NOTE: Fire Fox is a great browser also >>> http://www.mozilla.org/en-US/firefox/fx/
I use & like FireFox !!

3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

 4. Firewall Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:

Online Armor Free
Online Armor Free

Agnitum Outpost Firewall Free Agnitum Outpost Firewall

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update Windows update
 regularly to download and install any critical updates and service packs.  Windows Vista/7 users can open the  Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

 6. Consider a custom hosts file such as MVPS HOSTS
 This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002

Note: Be sure to follow the instructions to disable the  DNS Client service  before installing a custom hosts file.

 7. WOT (Web of Trust)
WOT As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read TonyKlein's good advice
 


A must is a great Antivirus, i recommend you using AVAST its free >>> http://www.avast.com/free-antivirus-download

You are behind on some updates, please visit the Secunia Software Inspector >>>http://secunia.com/vulnerability_scanning/online/   
Update any vulnerable software you have. Many malware now use zero day exploits in outdated versions of browsers and third party programs like Flash Player,Java Runtime , Winzip, Acrobat Reader etc to allow them to install silently without your knowledge or detection by your antivirus protection.

To insure better safety, these are a must have:
Rule #1 ........ Good Antivirus
Rule #2 ........ Good Firewall
Rule #3 ........ Good Router is Great ! (optional but best)


Happy surfing and Stay Clean
Chuck
 

 

I will leave this open for 5 days then close it, if after that you need it re-opened contact me by PM here or another !

 

Hope i have helped you & if you see an ad for BT acknowledge it, it's good PR for BT !!

Link to post
Share on other sites
Guest
This topic is now closed to further replies.