flashh4 Posted October 20, 2013 Report Share Posted October 20, 2013 Wyo, that's what i wanted to see !! Ok let's continue with the cleaning !! Link to post Share on other sites
flashh4 Posted October 20, 2013 Report Share Posted October 20, 2013 Wyo, We need to Run an OTL fix !! * Double-click OTL.exe to start the program. * Copy and Paste the following code into the . Do not include the word Code:OTLPRC - [2013/10/19 09:59:13 | 000,143,488 | ---- | M] () -- c:\Program Files\Optimizer Pro\OptProCrash.exeDRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS -- (SYMNDISV)DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS -- (SYMFW)DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Owner\AppData\Local\Temp\mbr.sys -- (mbr)DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)IE - HKLM\..\SearchScopes,DefaultScope = {E54CD624-092C-4045-9602-40E45A36643A}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =IE - HKU\.DEFAULT\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\.DEFAULT\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...101881&l=dis&q={SEARCHTERMS}IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-18\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\S-1-5-18\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...101881&l=dis&q={SEARCHTERMS}IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-19\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\S-1-5-19\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...101881&l=dis&q={SEARCHTERMS}IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-20\..\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=yspIE - HKU\S-1-5-20\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...101881&l=dis&q={SEARCHTERMS}IE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes,DefaultScope = {E54CD624-092C-4045-9602-40E45A36643AIE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRCIE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{CE3A3FD1-0A27-07DC-3FED-9D0FBEBC1CD0}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=Z131&form=ZGAIDF&install_date=20110826&iesrc={referrer:source}IE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}IE - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\SearchScopes\{E54CD624-092C-4045-9602-40E45A36643A}: "URL" = http://search.condui...ultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3291325&CUI=UN56563854018622839&UM=2[2010/10/05 20:41:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions[2013/10/19 10:02:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions[2013/10/19 10:02:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged[2012/02/02 20:15:29 | 000,020,591 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi[2013/10/19 11:33:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensionsFile not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{1930E38A-DEEF-4CF4-9BFB-9C4EA3689A9D}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{5911488E-9D1E-40EC-8CBB-06B231CC153F}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{635ABD67-4FE9-1B23-4F01-E679FA7484C1}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}File not found (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RDNDK0Q9.DEFAULT\EXTENSIONS\[email protected] - BHO: (KeyBar 1.12 Toolbar) - {0134af61-7a0c-4649-aeca-90d776060cb3} - C:\Program Files\KeyBar_1.12\prxtbKeyB.dll (Conduit Ltd.)O2 - BHO: (Fast Free Converter 4.1) - {C3E50543-BC36-4C80-8070-38A97E02DEB2} - C:\PROGRA~1\FASTFR~1\FASTFR~1\FASTFR~1.DLL File not foundO3 - HKLM\..\Toolbar: (KeyBar 1.12 Toolbar) - {0134af61-7a0c-4649-aeca-90d776060cb3} - C:\Program Files\KeyBar_1.12\prxtbKeyB.dll (Conduit Ltd.)O3 - HKLM\..\Toolbar: (no name) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - No CLSID value found.O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.O3 - HKU\S-1-5-21-496666239-834425297-2685965361-1000\..\Toolbar\WebBrowser: (no name) - {1930E38A-DEEF-4CF4-9BFB-9C4EA3689A9D} - No CLSID value found.O4 - HKLM..\Run: [] File not foundO4 - HKU\S-1-5-21-496666239-834425297-2685965361-1000..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe (PC Utilities Pro)O13 - gopher Prefix: missingO20 - AppInit_DLLs: (c:\progra~1\optimi~1\optpro~1.dll) - c:\Program Files\Optimizer Pro\OptProCrash.dll ()[2013/10/19 10:04:47 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Optimizer Pro[2013/10/19 10:04:45 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Optimizer Pro[2013/10/19 10:02:29 | 000,000,000 | ---D | C] -- C:\Program Files\KeyBar_1.12[2013/10/19 09:59:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2[2013/10/19 09:59:08 | 000,000,000 | ---D | C] -- C:\Program Files\Optimizer Pro[2013/10/19 10:04:45 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Optimizer Pro:FilesC:\Users\Owner\Documents\Optimizer ProC:\Program Files\KeyBar_1.12 :Commands[emptyjava][emptyflash][EMPTYTEMP][RESETHOSTS][CREATERESTOREPOINT][Reboot]# Then click the Run Fix button at the top.# Click # Please post the contents of the fix log file back here if you are prompted to open the file. It can also be found at C:\_OTL\Moved Files as MMDDYYY_HHMMSS.log where MMDDYYY is date format and HHMMSS is time format.Remember to enable your real time protection. Post that report for me !! ThanksChuck Link to post Share on other sites
wyodlr Posted October 20, 2013 Author Report Share Posted October 20, 2013 All processes killed========== OTL ==========No active process named OptProCrash.exe was found!Service SYMNDISV stopped successfully!Service SYMNDISV deleted successfully!File C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS not found.Service SYMFW stopped successfully!Service SYMFW deleted successfully!File C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS not found.Service NwlnkFwd stopped successfully!Service NwlnkFwd deleted successfully!File system32\DRIVERS\nwlnkfwd.sys not found.Service NwlnkFlt stopped successfully!Service NwlnkFlt deleted successfully!File system32\DRIVERS\nwlnkflt.sys not found.Error: No service named mbr was found to stop!Service\Driver key mbr not found.File C:\Users\Owner\AppData\Local\Temp\mbr.sys not found.Service IpInIp stopped successfully!Service IpInIp deleted successfully!File system32\DRIVERS\ipinip.sys not found.Service blbdrive stopped successfully!Service blbdrive deleted successfully!File C:\Windows\system32\drivers\blbdrive.sys not found.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.Registry key HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}\ not found.Registry key HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CE3A3FD1-0A27-07DC-3FED-9D0FBEBC1CD0}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE3A3FD1-0A27-07DC-3FED-9D0FBEBC1CD0}\ not found.Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ not found.Registry key HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E54CD624-092C-4045-9602-40E45A36643A}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E54CD624-092C-4045-9602-40E45A36643A}\ not found.C:\Users\Owner\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Extensions folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\META-INF folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\chrome\skin folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\chrome\content\locale folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\chrome\content folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}\chrome folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0} folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\components folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome\PublisherImages folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f} folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Plugins folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\modules folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\META-INF folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\lib folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\defaults\preferences folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\defaults folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\components folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\sl folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\lib\jquery.jscrollpane folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\lib\jquery.alerts\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\lib\jquery.alerts folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\lib folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\core folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\WEATHER\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\WEATHER\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\WEATHER folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\TWITTER\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\TWITTER\img folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\TWITTER folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\view\style\rsx folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\view\style folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\view\script folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\view folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\resources folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\Css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH\buildSettings folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\SEARCH folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER\js\resources folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER\css\custom-theme folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\RADIO_PLAYER folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG\css\custom-theme folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG\agreement folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\PRICE_GONG folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\Optimizer\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\Optimizer folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\images\light folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\images\dark folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\NOTIFICATION folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS\js\resources folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS\img folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\MULTI_RSS folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\HIGHLIGHTER\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\HIGHLIGHTER\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\HIGHLIGHTER folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\EMAIL_NOTIFIER\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\EMAIL_NOTIFIER\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\EMAIL_NOTIFIER folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\APPLICATION_BUTTON\resources folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\APPLICATION_BUTTON\Js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa\APPLICATION_BUTTON folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\wa folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\menu\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\menu\img folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\menu\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\menu folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gf\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gf\img folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gf\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gf folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\gadgetFrame folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\dlg\ftd\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\dlg\ftd folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui\dlg folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ui folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\spsd\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\spsd folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\spbd\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\spbd folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\sp folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options\js\resources folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\options folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\msd folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\api folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ac\res folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ac\img folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ac\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\ac folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\aboutBox\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\aboutBox\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al\aboutBox folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb\al folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\tb folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall\dialog\js folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall\dialog\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall\dialog\css folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall\dialog folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic\uninstall folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content\logic folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325\content folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome\CT3291325 folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}\Chrome folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{0134af61-7a0c-4649-aeca-90d776060cb3} folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\components folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome\PublisherImages folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome\images folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f}\chrome folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\{0ebff9e5-d293-b5c2-c96f-168c8d808f2f} folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged folder moved successfully.C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions folder moved successfully.Folder C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\staged\ not found.File C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi not found.C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.C:\Program Files\Mozilla Firefox\extensions folder moved successfully.Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0134af61-7a0c-4649-aeca-90d776060cb3}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0134af61-7a0c-4649-aeca-90d776060cb3}\ deleted successfully.C:\Program Files\KeyBar_1.12\prxtbKeyB.dll moved successfully.Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C3E50543-BC36-4C80-8070-38A97E02DEB2}\ not found.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3E50543-BC36-4C80-8070-38A97E02DEB2}\ not found.Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0134af61-7a0c-4649-aeca-90d776060cb3} deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0134af61-7a0c-4649-aeca-90d776060cb3}\ not found.File C:\Program Files\KeyBar_1.12\prxtbKeyB.dll not found.Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8660E5B3-6C41-44DE-8503-98D99BBECD41} deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\ not found.Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.Registry value HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1930E38A-DEEF-4CF4-9BFB-9C4EA3689A9D} deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1930E38A-DEEF-4CF4-9BFB-9C4EA3689A9D}\ not found.Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.Registry value HKEY_USERS\S-1-5-21-496666239-834425297-2685965361-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro not found.File C:\Program Files\Optimizer Pro\OptProLauncher.exe not found.Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~1\optimi~1\optpro~1.dll deleted successfully.File c:\Program Files\Optimizer Pro\OptProCrash.dll not found.C:\Users\Owner\Documents\Optimizer Pro folder moved successfully.C:\Users\Owner\AppData\Roaming\Optimizer Pro\Undo folder moved successfully.C:\Users\Owner\AppData\Roaming\Optimizer Pro\Log folder moved successfully.C:\Users\Owner\AppData\Roaming\Optimizer Pro\Backup folder moved successfully.C:\Users\Owner\AppData\Roaming\Optimizer Pro folder moved successfully.C:\Program Files\KeyBar_1.12 folder moved successfully.Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\ not found.C:\Program Files\Optimizer Pro folder moved successfully.Folder C:\Users\Owner\AppData\Roaming\Optimizer Pro\ not found.========== FILES ==========File\Folder C:\Users\Owner\Documents\Optimizer Pro not found.File\Folder C:\Program Files\KeyBar_1.12 not found.========== COMMANDS ========== [EMPTYJAVA] User: All Users User: Default User: Default User User: Owner->Java cache emptied: 14421 bytes User: Public Total Java Files Cleaned = 0.00 mb [EMPTYFLASH] User: All Users User: Default->Flash cache emptied: 56502 bytes User: Default User->Flash cache emptied: 0 bytes User: Owner->Flash cache emptied: 37665 bytes User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 33170 bytes->Flash cache emptied: 0 bytes User: Default User->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytes->Flash cache emptied: 0 bytes User: Owner->Temp folder emptied: 8912192 bytes->Temporary Internet Files folder emptied: 1185313 bytes->Java cache emptied: 0 bytes->FireFox cache emptied: 130224386 bytes->Google Chrome cache emptied: 325699781 bytes->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes%systemroot% .tmp files removed: 0 bytes%systemroot%\System32 .tmp files removed: 0 bytes%systemroot%\System32\drivers .tmp files removed: 0 bytesWindows Temp folder emptied: 2096542 bytesRecycleBin emptied: 61417027 bytes Total Files Cleaned = 505.00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully.HOSTS file reset successfullyRestore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 10202013_070615 Link to post Share on other sites
flashh4 Posted October 20, 2013 Report Share Posted October 20, 2013 Morning Wyo, almost done with the cleaning !! Are you using Norton as an antivirus ?? ================ Clean up with OTL Right-click OTL.exe and select " Run as administrator " to run it. This will remove all the tools we used to clean your pc. Close all other programs apart from OTL as this step will require a reboot On the OTL main screen, press the CleanUp! button Say Yes to the prompt and then allow the program to reboot your computer.You can now delete any tools we used if they remain on your Desktop. ====================== ESET online scannner >>> http://www.eset.com/onlinescan/Note: You can use either Internet Explorer or Mozilla FireFox for this scan. 1. Firstly please Disable any Antivirus you have active , as shown in This topic. 2. Note: Don't forget to re-enable it after the scan. 3. Next please click on the following link to open a new window to ESET online scannnerhttp://www.eset.com/us/online-scanner/features 4. Then click on:Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox. 5. Select the option YES, I accept the Terms of Use then click on: 6. When prompted allow the Add-On/Active X to install. 7. Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked. 8. Now click on Advanced Settings and select the following: * Scan for potentially unwanted applications * Scan for potentially unsafe applications * Enable Anti-Stealth Technology 9. Now click on: 10. The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection. 11. When completed the Online Scan will begin automatically. 12. Do not touch either the mouse or keyboard during the scan otherwise it may stall. 13. When completed select Uninstall application on close if you so wish, make sure you copy the logfile first! 14. Now click on: 15. Use notepad to open the log file located at C:\Program Files\ESET\EsetOnlineScanner\log.txt. or may be ESETSmartInstaller@High as CAB hook log: 16. Copy and paste that log as a reply to this topic. If it finds anything !!!!! ThanksChuck Let me know how it's running & if any problems exist ?? Link to post Share on other sites
wyodlr Posted October 20, 2013 Author Report Share Posted October 20, 2013 I run Norton 360. I'll finish this up in a couple hours when I get home Link to post Share on other sites
flashh4 Posted October 20, 2013 Report Share Posted October 20, 2013 Ok, i will leave Norton alone it use to be a big resource hog, slowing down computers ! Most users i get say they want to remove it cause they are tired of paying ! I want to run 1 more program, this is a very powerful tool and do not touch your mouse while in use !!! Vista and Windows 7 users:1. These tools MUST be run from the executable. (.exe) every time you run them2. With Admin Rights (Right click, choose "Run as Administrator")Download ComboFix from this location:Link 1 http://download.bleepingcomputer.com/sUBs/ComboFix.exeLink 2http://www.infospyware.net/antimalware/combofix* IMPORTANT !!! Save ComboFix.exe to your Desktop * Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. * See this Link >>> http://www.bleepingcomputer.com/forums/topic114351.html <<< for programs that need to be disabled and instruction on how to disable them. * Remember to re-enable them when we're done. * Double click on ComboFix.exe & follow the prompts. * As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. * Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:Click on Yes, to continue scanning for malware.When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply. Notes: 1.Do not mouse-click Combofix's window while it is running. That may cause it to stall2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine. Give it at least 20-30 minutes to finish if needed. Please do not attach the scan results from Combofix. Use copy/paste. Post that log next !! ThanksChuck How's it running ? Should be a lot, lot better after all that junk we removed !! Link to post Share on other sites
wyodlr Posted October 20, 2013 Author Report Share Posted October 20, 2013 C:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\genfix.exe.vir Win32/Toolbar.Zugo.D applicationC:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\Reactivate.exe.vir a variant of Win32/Toolbar.Zugo applicationC:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\search_protect.exe.vir Win32/Toolbar.Zugo.D applicationC:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\Toolbar32.dll.vir a variant of Win32/Toolbar.Zugo applicationC:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\ToolbarBroker.exe.vir a variant of Win32/Toolbar.Zugo applicationC:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe.vir a variant of Win32/Toolbar.Zugo applicationC:\AdwCleaner\Quarantine\C\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\Extensions\[email protected]\content\overlay.js.vir Win32/Adware.Yontoo applicationC:\Program Files\Mozilla Firefox\nsprotector.js Win32/Conduit.SearchProtect.A applicationC:\Program Files\Uninstall Information\ib_uninst_342\uninstall.exe a variant of Win32/InstallBrain.H applicationC:\Program Files\Uninstall Information\ib_uninst_343\uninstall.exe a variant of Win32/InstallBrain.H applicationC:\Program Files\Uninstall Information\ib_uninst_383\uninstall.exe a variant of Win32/InstallBrain.H applicationC:\Program Files\Uninstall Information\ib_uninst_514\uninstall.exe a variant of Win32/InstallBrain.H applicationC:\Program Files\Uninstall Information\ib_uninst_569\uninstall.exe a variant of Win32/InstallBrain.H applicationC:\Users\Owner\AppData\Local\Temp\YontooLayers\background.html JS/Adware.Yontoo.B applicationC:\Users\Owner\Downloads\ARO2013_tbt.exe a variant of Win32/Bundled.Toolbar.Ask.D applicationC:\Users\Owner\Downloads\cbsidlm-tr1_6-Photo_Story_3_for_Windows-10339154.exe Win32/DownloadAdmin.G applicationC:\Users\Owner\Downloads\h2testw_1_4_mediaget.exe a variant of Win32/MediaGet applicationC:\Users\Owner\Downloads\setup.exe a variant of Win32/AirAdInstaller.A applicationC:\Users\Owner\Downloads\vlcmediaplayer-setup.exe multiple threatsC:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2F5ORKB1\genfix-e[1] Win32/Toolbar.Zugo.D applicationC:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2F5ORKB1\genfix2-a[1] Win32/Toolbar.Zugo.D applicationC:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2F5ORKB1\updater-startnow-200-2.5-g[1].exe a variant of Win32/Toolbar.Zugo applicationC:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6G7ZBYCJ\search-update-d[1] Win32/Toolbar.Zugo.D applicationC:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RRJYAK5X\search-update-d[1] Win32/Toolbar.Zugo.D applicationC:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UHIBYNU1\genfix-e[1] Win32/Toolbar.Zugo.D application Link to post Share on other sites
flashh4 Posted October 20, 2013 Report Share Posted October 20, 2013 Wyo, what is that ?? When posting please give me the whole header (log) !! ThanksChuck Link to post Share on other sites
wyodlr Posted October 20, 2013 Author Report Share Posted October 20, 2013 ComboFix 13-10-19.02 - Owner 10/20/2013 12:57:50.1.2 - x86Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3061.1215 [GMT -6:00]Running from: c:\users\Owner\Downloads\ComboFix.exeAV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..C:\datac:\data\default\us_sres.dataC:\ENDc:\programdata\ntuser.datc:\users\Owner\AppData\Roaming\SearchProtectc:\windows\desktopc:\windows\desktop\ROAD TRIPS.lnkc:\windows\system32\Cachec:\windows\system32\Cache\06f72eaedf1770ec.fbc:\windows\system32\Cache\1cf59a059cb2885c.fbc:\windows\system32\Cache\1f46af2525172b4f.fbc:\windows\system32\Cache\26c630d098e22dd5.fbc:\windows\system32\Cache\272512937d9e61a4.fbc:\windows\system32\Cache\287204568329e189.fbc:\windows\system32\Cache\28bc8f716fd76a47.fbc:\windows\system32\Cache\2c53092c95605355.fbc:\windows\system32\Cache\31a0997e9a5b5eb3.fbc:\windows\system32\Cache\32c84fe32bb74d60.fbc:\windows\system32\Cache\3917078cb68ec657.fbc:\windows\system32\Cache\590ba23ce359fd0c.fbc:\windows\system32\Cache\610289e025a3ee9a.fbc:\windows\system32\Cache\651c5d3cdbfb8bd1.fbc:\windows\system32\Cache\6c59ac5e7e7a3ad0.fbc:\windows\system32\Cache\6d03dad1035885d3.fbc:\windows\system32\Cache\7377d9d9140c90a3.fbc:\windows\system32\Cache\74857a87930bf46d.fbc:\windows\system32\Cache\95f567698be8a182.fbc:\windows\system32\Cache\9623a552aa2b10dc.fbc:\windows\system32\Cache\a42664768109be55.fbc:\windows\system32\Cache\a8556537add6dfc5.fbc:\windows\system32\Cache\ad10a52aff5e038d.fbc:\windows\system32\Cache\aef0e377a73d0d0e.fbc:\windows\system32\Cache\c1fa887b03019701.fbc:\windows\system32\Cache\c4d28dca2e7648be.fbc:\windows\system32\Cache\d201ef9910cd39de.fbc:\windows\system32\Cache\d2e94710a5708128.fbc:\windows\system32\Cache\d79b9dfe81484ec4.fbc:\windows\system32\Cache\f998975c9cc711ee.fbc:\windows\wininit.ini..((((((((((((((((((((((((( Files Created from 2013-09-20 to 2013-10-20 )))))))))))))))))))))))))))))))..2013-10-20 19:09 . 2013-10-20 19:09 -------- d-----w- c:\users\Default\AppData\Local\temp2013-10-20 17:05 . 2013-10-20 17:05 -------- d-----w- c:\program files\ESET2013-10-20 13:19 . 2013-10-20 13:19 23830 ----a-w- c:\windows\cscmondump.bin2013-10-19 17:10 . 2013-10-20 01:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware2013-10-19 17:10 . 2013-04-04 20:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys2013-10-19 16:02 . 2013-10-20 02:49 -------- d-----w- c:\programdata\Conduit2013-10-19 16:02 . 2013-10-19 16:02 -------- d-----w- c:\users\Owner\AppData\Local\Conduit2013-10-19 16:00 . 2013-10-19 16:01 -------- d-----w- c:\users\Owner\AppData\Local\CRE2013-10-19 16:00 . 2013-10-19 16:02 -------- d-----w- c:\program files\Conduit2013-10-19 16:00 . 2013-10-20 00:37 -------- d-----w- c:\program files\SearchProtect2013-10-19 15:57 . 2013-10-20 00:27 -------- d-----w- c:\programdata\ZalmanInstaller_523312013-10-19 15:56 . 2013-10-20 00:27 -------- d-----w- c:\program files\Browsersafeguard2013-10-19 15:49 . 2013-10-20 13:28 -------- d-----w- c:\users\Owner\AppData\Local\FileTypeAssistant2013-10-19 14:26 . 2013-10-19 14:26 -------- d-----w- c:\windows\ERUNT2013-10-19 13:40 . 2013-10-19 14:17 -------- d-----w- C:\AdwCleaner2013-10-17 17:40 . 2013-10-17 17:40 -------- d-----w- C:\N360_BACKUP2013-10-09 06:24 . 2013-08-27 01:28 1069056 ----a-w- c:\windows\system32\DWrite.dll2013-10-09 06:24 . 2013-08-27 01:28 798208 ----a-w- c:\windows\system32\FntCache.dll2013-10-09 06:24 . 2013-08-27 02:47 219648 ----a-w- c:\windows\system32\d3d10_1core.dll2013-10-09 06:24 . 2013-08-27 02:47 189952 ----a-w- c:\windows\system32\d3d10core.dll2013-10-09 06:24 . 2013-08-27 02:47 1029120 ----a-w- c:\windows\system32\d3d10.dll2013-10-09 06:24 . 2013-08-27 01:52 1172480 ----a-w- c:\windows\system32\d3d10warp.dll2013-10-09 06:24 . 2013-08-27 01:50 486400 ----a-w- c:\windows\system32\d3d10level9.dll2013-10-09 06:24 . 2013-08-27 01:32 683008 ----a-w- c:\windows\system32\d2d1.dll2013-10-09 06:24 . 2013-08-27 02:47 160768 ----a-w- c:\windows\system32\d3d10_1.dll2013-09-29 05:57 . 2013-10-19 02:46 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\FileTypeAssistant2013-09-29 00:34 . 2013-10-19 02:46 -------- d-----w- c:\program files\File Type Assistant2013-09-26 18:00 . 2013-09-26 18:00 208760 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2013-10-09 04:56 . 2012-04-04 14:39 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe2013-10-09 04:56 . 2011-06-29 12:10 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl2013-09-11 05:18 . 2013-09-11 05:18 97008 ----a-w- c:\windows\system32\drivers\RapportKELL.sys2013-09-09 15:24 . 2013-09-09 15:24 1700352 ----a-w- c:\windows\system32\gdiplus.dll2013-08-02 04:09 . 2013-08-27 20:18 1548288 ----a-w- c:\windows\system32\WMVDECOD.DLL2013-01-20 02:50 . 2013-01-20 02:50 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll..((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240].[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-12-13 98304]"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-12-13 106496]"Persistence"="c:\windows\system32\igfxpers.exe" [2006-12-13 81920]"MFPMonitor"="c:\windows\twain_32\DELL\MFP1125\Monitor\Stsmon.exe" [2007-08-08 2002944]"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576].c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE -b -l [2000-1-21 65588].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"EnableUIADesktopToggle"= 0 (0x0).[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]@="Service".[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvcLocalServiceAndNoImpersonation REG_MULTI_SZ FontCachebthsvcs REG_MULTI_SZ BthServWindowsMobile REG_MULTI_SZ wcescomm rapimgrLocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr.[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]2013-10-19 13:26 1185744 ----a-w- c:\program files\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe.Contents of the 'Scheduled Tasks' folder.2013-10-20 c:\windows\Tasks\Adobe Flash Player Updater.job- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 04:56].2013-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-22 01:52].2013-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-22 01:52]..------- Supplementary Scan -------.TCP: DhcpNameServer = 192.168.0.1FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\rdndk0q9.default\FF - prefs.js: browser.search.selectedEngine - KeyBar 1.12 Customized Web SearchFF - ExtSQL: !HIDDEN! 2011-01-05 10:50; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtensionFF - ExtSQL: !HIDDEN! 2012-05-04 20:31; [email protected]; c:\users\Owner\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected]FF - user.js: extensions.autoDisableScopes - 0FF - user.js: extensions.shownSelectionUI - true.- - - - ORPHANS REMOVED - - - -.URLSearchHooks-{0134af61-7a0c-4649-aeca-90d776060cb3} - (no file)WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)SafeBoot-WudfPfSafeBoot-WudfRd...**************************************************************************.catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2013-10-20 13:10Windows 6.0.6002 Service Pack 2 NTFS.scanning hidden processes ... .scanning hidden autostart entries ... .scanning hidden files ... .scan completed successfullyhidden files: 0.**************************************************************************.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]"ImagePath"="\"c:\program files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\20.4.0.40\diMaster.dll\" /prefetch:1".--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]@Denied: (A) (Users)@Denied: (A) (Everyone)@Allowed: (B 1 2 3 4 5) (S-1-5-20)"BlindDial"=dword:00000000.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]@Denied: (A) (Users)@Denied: (A) (Everyone)@Allowed: (B 1 2 3 4 5) (S-1-5-20)"BlindDial"=dword:00000000.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]@Denied: (A) (Users)@Denied: (A) (Everyone)@Allowed: (B 1 2 3 4 5) (S-1-5-20)"BlindDial"=dword:00000000.Completion time: 2013-10-20 13:15:05ComboFix-quarantined-files.txt 2013-10-20 19:14.Pre-Run: 26,655,383,552 bytes freePost-Run: 26,515,025,920 bytes free.- - End Of File - - 49044F13D18CF1C141EF2A821D20FA135C616939100B85E558DA92B899A0FC36 Link to post Share on other sites
wyodlr Posted October 20, 2013 Author Report Share Posted October 20, 2013 the one you questioned was the eset log Link to post Share on other sites
flashh4 Posted October 20, 2013 Report Share Posted October 20, 2013 Ok, thought it might be but i can't make assumptions when it comes to a fix for the log posted !! It could make a door stop out of the computer !!BRB with a fix !! Link to post Share on other sites
flashh4 Posted October 20, 2013 Report Share Posted October 20, 2013 Wyo, click to open ESET !! *Open the main program window by clicking the ESET icon !!*Make sure that the BOX Remove found threats is checked.*Now click on:*Do not touch either the mouse or keyboard during the removal process otherwise it may stall. NEXT Time for some housekeeping [*] Click START then RUN [*] Now type Combofix /Uninstall in the runbox and click OK( please note the space between Combofix and the /, it is needed.)The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.Once you have typed this in, press Enter on your keyboard. A Open File security warning will appear asking if you are sure you want to run ComboFix.Please click on the Run button to start the program.ComboFix will now uninstall itself from your computer and remove any backups and quarantined files.When it has finished you will be greeted by a dialog box stating that ComboFix has been uninstalled.You can now delete the ComboFix.exe program from your computer.ComboFix has now been uninstalled from your Windows Vista or Windows 7 computer. Let me know how this goes ??Also how's it running ??Any other problems ?? ThanksChuck Link to post Share on other sites
wyodlr Posted October 20, 2013 Author Report Share Posted October 20, 2013 Got it done .So far it looks good. I'll let you know in a couple daysThanksDavid Link to post Share on other sites
flashh4 Posted October 20, 2013 Report Share Posted October 20, 2013 Wyo ................ I know you may have some of these installed, this is just my standard all clean speech !Congratulation you are clean !!!Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop. Here are some tips to reduce the potential for spyware infection in the future: 1. Make your Internet Explorer more secure - This can be done by following these simple instructions: * From within Internet Explorer click on the Tools menu and then click on Options. * Click once on the Security tab * Click once on the Internet icon so it becomes highlighted. * Click once on the Custom Level button. * Change the Download signed ActiveX controls to Prompt * Change the Download unsigned ActiveX controls to Disable * Change the Initialize and script ActiveX controls not marked as safe to Disable * Change the Installation of desktop items to Prompt * Change the Launching programs and files in an IFRAME to Prompt * Change the Navigate sub-frames across different domains to Prompt * When all these settings have been made, click on the OK button. * If it prompts you as to whether or not you want to save the settings, press the Yes button. * Next press the Apply button and then the OK to exit the Internet Properties page. 2. Enable Protected Mode in Internet Explorer . This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps: * Open Internet Explorer * Click on Tools > Internet Options * Press Security tab * Select Internet zone then place check next to Enable Protected Mode if not already done * Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply * Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.NOTE: Fire Fox is a great browser also >>> http://www.mozilla.org/en-US/firefox/fx/I use & like FireFox !!3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection. 4. Firewall Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:Online Armor Free Online Armor FreeAgnitum Outpost Firewall Free Agnitum Outpost Firewall5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open. 6. Consider a custom hosts file such as MVPS HOSTS This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002 Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file. 7. WOT (Web of Trust) WOT As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.8.Finally, I strongly recommend that you read TonyKlein's good advice A must is a great Antivirus, i recommend you using AVAST its free >>> http://www.avast.com/free-antivirus-downloadYou are behind on some updates, please visit the Secunia Software Inspector >>>http://secunia.com/vulnerability_scanning/online/ Update any vulnerable software you have. Many malware now use zero day exploits in outdated versions of browsers and third party programs like Flash Player,Java Runtime , Winzip, Acrobat Reader etc to allow them to install silently without your knowledge or detection by your antivirus protection.To insure better safety, these are a must have:Rule #1 ........ Good AntivirusRule #2 ........ Good FirewallRule #3 ........ Good Router is Great ! (optional but best)Happy surfing and Stay CleanChuck I will leave this open for 5 days then close it, if after that you need it re-opened contact me by PM here or another ! Hope i have helped you & if you see an ad for BT acknowledge it, it's good PR for BT !! Link to post Share on other sites
flashh4 Posted October 26, 2013 Report Share Posted October 26, 2013 Since this is resolved i will lock this topic ! If this needs re-opened please PM me or another Mod !! Chuck Link to post Share on other sites
Recommended Posts