2013-03-30, 04:33
I foolishly installed Privitize VPM an now have a mess. Actually, I don't even know if that was the source of my problem, but it may have been. I completed a removal using SB S&D 2 but I am left with cookies from every tracking site and porn site on the internet that repopulate every time I delete them. (S&D wasn't effective) What can I do to get rid of the source so that it doesn't keep coming back?

I hope you can help. Thanks in advance.

2013-04-04, 20:33
Hello, eve.online. :snwelcome:

My name is fbfbfb. I will gladly assist you with your concerns.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your DDS and aswMBR logs now, and I will post back shortly with instructions.

I am checking over your DDS and aswMBR logs now, and I will post back shortly with instructions.

While working to resolve the issues with your machine, please follow these guidelines:
Please be patient. Logs are lengthy and can take time to analyze.
Read and follow my directions carefully, in the sequence they are posted. If you are unsure about anything, please ask for clarification before continuing.
Use only those tools that you have been directed to use.
Do not install or uninstall any applications or run any other scans without being directed to do so.
Copy and Paste the log files inside your post. Do not send them as attachments unless otherwise instructed.
Stay with me until your machine has been deemed all clear.
Please reply within 3 days to avoid closing this topic.

2013-04-05, 14:41
Hello, eve.online.

Thank you for submitting your DDS log. DDS should have produced a second log named attach.txt and saved it to your desktop. If it is there, please submit this log to me. If you are unable to locate this report, please rerun DDS and submit both reports.

Please run the following scans

1. Rogue Killer

Please download Rogue Killer from HERE (http://tigzy.geekstogo.com/roguekiller.php).
Quit all running programs before continuing.
Double-click roguekiller.exe to run it.
Wait for the Prescan to finish.
Click Scan and wait for the scan to complete.


A report will be created and saved on your desktop.
Exit the program.Copy and paste the RKreport.txt report into your next reply.

2. Security Check

Please download Security Check by screen317 from HERE (http://screen317.spywareinfoforum.org/SecurityCheck.exe) or HERE (http://screen317.changelog.fr/SecurityCheck.exe). Save it to your Desktop. Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. A Notepad document should open automatically called checkup.txt. This may take a few minutes.Please copy and paste the contents of that document into your next reply.

2013-04-05, 20:15
First, Thanks for your help!!

the Security Check report is here:
Results of screen317's Security Check version 0.99.61
Windows 7 x64 (UAC is disabled!)
Out of date service pack!! (http://windows.microsoft.com/en-US/windows7/install-windows-7-service-pack-1)
Internet Explorer 8 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
Spybot - Search & Destroy
Java(TM) 6 Update 17
Java 7 Update 17
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 11.5.502.146 Flash Player out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (19.0.2)
````````Process Check: objlist.exe by Laurent````````
Spybot Teatimer.exe is disabled!
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````

and the RogueKiller report is here
When I ran Rogue Killer it prompted to delete the items it found but I did not do that yet. Please let me know if I should go ahead and delete them.

I have attached the attach zip

Thanks Again

I have attached the attach zip

Thanks Again

2013-04-06, 17:24
Hello, eve.online.

You're welcome, and thank you for your logs.

Please run the following scans

1. Rogue Killer

Please run Rogue Killer again (double click on roguekiller.exe to start).
Note: Please remove any usb or external drives from the computer and quit any running programs before you run this scan. When the scan has completed, click Delete.
Please copy and paste the RKreport.txt located on your desktop into your next reply.

2. ComboFix

Note: Before you begin, please read through these instructions completely, noting all important messages and warnings. Please download ComboFix from HERE (http://www.bleepingcomputer.com/download/combofix/dl/12/) or HERE (http://www.infospyware.net/antimalware/combofix/).Very Important! Save ComboFix.exe to to your Desktop.
Close all browsers.
Disable your AntiVirus and AntiSpyware applications as they can interfere with running ComboFix. To disable any security programs:
Right click on the System Tray icon, or
Refer to this link HERE (http://forums.whatthetech.com/index.php?showtopic=96260&pid=494216#entry494216) for further assistance. Double click on ComboFix.exe and follow the prompts.
When finished, ComboFix will produce a log for you. Please include the C:\ComboFix.txt in your next reply.Warnings:
Do not mouse-click on ComboFix's window while it is running. This may cause it to stall.
Do not re-run ComboFix. If problems occur with the installation or running of ComboFix, please reply back for further instructions.
Do not attempt to surf the internet while ComboFix is scanning.
Note: If there is no internet connection after running ComboFix, reboot your computer to restore the connection.Very Important! Make sure you re-enable your security programs when ComboFix is finished.

2013-04-06, 19:32
Ok here is the Combofix report

And Here is the Rogue Killer report again:
I did get an error message during bootup but I didn't recognize what it was referring to and I can't remember what it said. It was something about a moving on to the next file. I clicked "no" and the error went away.

Let me know what's next. I really appreciate the help!

Let me know what's next. I really appreciate the help!

2013-04-08, 05:19
Hello, eve.online.

Thank you for the logs.

Please run the following scans

1. Junkware Removal Tool

Please download Junkware Removal Tool from HERE (http://www.bleepingcomputer.com/download/junkware-removal-tool/dl/131/) and save it to your desktop.
Shutdown your antivirus to avoid any potential conflicts.
Right-mouse click JRT.exe and select Run as Administrator.
JRTwill begin to backup your registry and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, the log JRT.txt is saved on your desktop and will automatically open.Post the contents of JRT.txt into your next reply.

2. AdwCleaner

Please download AdwCleaner from HERE (http://www.bleepingcomputer.com/download/adwcleaner/dl/125/).
Close all open programs and internet browsers.
Double click on adwcleaner.exe to run the tool.
Click on the Delete button.
A logfile will automatically open after the scan has finished.
You can also find the logfile at C:\AdwCleaner[S1].txt.Copy and paste the adwcleaner.txt report into your next reply.

3. Malwarebytes Anti-Malware

Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html).
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.http://i24.photobucket.com/albums/c30/ken545/MBAMCapture.jpg
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.Post the report please.

4. ESET Online Scanner
Note: Disable any antivirus program and antispyware programs to avoid conflicts.
If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted, then double click on it to install.
Please do not surf the internet while your security programs are disabled.
Let the scan run uninterrupted to avoid a stall.
Remember to enable your security programs when the scan has finished.Run ESET Online Scanner from HERE (http://www.eset.eu/online-scanner).
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box YES, I accept the Terms of Use.
Click on the Start button next to it.
If prompted, allow the Add-On/Active X to install.Under Computer scan settings:
Do not check Remove found threats
Check Scan Archives.
Click Advanced settings and select the following:
Scan potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth technology Click Start. ESET will download updates, install itself, and begin scanning your computer. Please be patient as this scan could take up to a few hours to complete.
Wait for the scan to finish. When the scan completes, click List of found threats.
Click Export and save the file to your desktop using a unique name, such as ESETScan.
Copy and paste the contents of this report in your next reply.
Click the Back button.
Click the Finish button.5. Clean Up Temp Files

Please download TFC (http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer) by OldTimer to your desktop.
Close any open windows.
Double click the TFC icon to run the program.
TFC will close all open programs itself in order to run.
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish.
Once complete, it should automatically reboot your machine.
If your computer does not automatically reboot, manually reboot to ensure a complete clean.
SUMMARY: In your next reply, please post the following:
MBAM log
ESET log
Let me know how your computer is running at this stage.

2013-04-11, 04:48
Hello, eve.online.

Do you still need help?

2013-04-13, 23:57
Sorry it took so long to run the last batch of scans. I had a deadline and couldn't risk a problem. thanks for your patience.

here is the latest batch of scans. the only problem I ran into was the last scan TFC which stalled the two times I tried to run it, the first time I forgot to run it as administrator so when it stalled I aborted and ran it as admin and it stalled again.


eset scan
C:\$RECYCLE.BIN\S-1-5-21-1342298365-2549134341-3604237475-1000\$RNN9NU2.exe Win32/InstalleRex.I.Gen application
C:\Users\me\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljidpgmdpigjjgieiifpdpkhcbabgabb\1\51411f9b31a0d4.61490956.js Win32/Adware.MultiPlug.H application
C:\Users\me\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\74558a21-2600181b a variant of Java/TrojanDownloader.OpenStream.NCM trojan
C:\Users\me\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\74558a21-31f26178 a variant of Java/TrojanDownloader.OpenStream.NCM trojan
C:\Users\me\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\74558a21-3f8f007b a variant of Java/TrojanDownloader.OpenStream.NCM trojan
C:\Users\me\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\74558a21-49778fb3 a variant of Java/TrojanDownloader.OpenStream.NCM trojan
C:\Users\me\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\74558a21-534bcfd7 a variant of Java/TrojanDownloader.OpenStream.NCM trojan
C:\Users\me\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\74558a21-59ae07b3 a variant of Java/TrojanDownloader.OpenStream.NCM trojan
C:\Users\me\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\fc6cc7a-6e9f197b Java/TrojanDownloader.OpenStream.NCM trojan
C:\Users\me\Downloads\cnet2_DoubleCAD-XT-3-1_exe.exe a variant of Win32/InstallCore.D application

Junkware Removal Tool (JRT) by Thisisu
Version: 4.8.3 (04.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by me on Sat 04/13/2013 at 13:43:37.10

~~~ Services

~~~ Registry Values

Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\main\\Start Page

~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_current_user\software\startsearch
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\sprotector
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\sp global
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\sprotector
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{3bd44f0e-0596-4008-aee0-45d47e3a8f0e}

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\clsoft ltd"
Successfully deleted: [Folder] "C:\ProgramData\installmate"
Successfully deleted: [Folder] "C:\Users\me\appdata\local\torch"
Successfully deleted: [Folder] "C:\Users\me\appdata\locallow\adawaretb"

~~~ FireFox

Successfully deleted: [File] "C:\Users\me\AppData\Roaming\mozilla\firefox\profiles\bvhir24s.default\extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi"
Successfully deleted: [Folder] C:\Users\me\AppData\Roaming\mozilla\firefox\profiles\bvhir24s.default\jetpack
Emptied folder: C:\Users\me\AppData\Roaming\mozilla\firefox\profiles\bvhir24s.default\minidumps [9 files]

~~~ Event Viewer Logs were cleared

Scan was completed on Sat 04/13/2013 at 13:58:18.42
End of JRT log

Adw Cleaner

# AdwCleaner v2.200 - Logfile created 04/13/2013 at 14:02:16
# Updated 02/04/2013 by Xplode
# Operating system : Windows 7 Home Premium (64 bits)
# User : me - ME-PC
# Boot Mode : Normal
# Running from : C:\Users\me\Downloads\AdwCleaner.exe
# Option [Delete]

***** [Services] *****

***** [Files / Folders] *****

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7600.16800

[OK] Registry is clean.

-\\ Mozilla Firefox v20.0.1 (en-US)

File : C:\Users\me\AppData\Roaming\Mozilla\Firefox\Profiles\bvhir24s.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v [Unable to get version]

File : C:\Users\me\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

-\\ Opera v12.14.1738.0

File : C:\Users\me\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.


AdwCleaner[R1].txt - [1342 octets] - [13/04/2013 14:00:25]
AdwCleaner[S1].txt - [1279 octets] - [13/04/2013 14:02:16]

########## EOF - C:\AdwCleaner[S1].txt - [1339 octets] ##########

and finally MalwareBytes

Malwarebytes Anti-Malware

Database version: v2013.04.13.04

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
me :: ME-PC [administrator]

4/13/2013 2:08:02 PM
mbam-log-2013-04-13 (14-08-02).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 215610
Time elapsed: 4 minute(s), 10 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\ProgramData\MAgoniPicc\51411f9b31c4a.dll (Adware.MultiPlug) -> Quarantined and deleted successfully.


2013-04-15, 05:01
Hello, eve.online.

Thank you for your logs. If you require more response time while we work to clean your system, please drop me a quick note so that we do not close this thread.

Please continue with the following tasks

1. Show Hidden System Files and Folders

Some of the files and folders we need to delete are hidden and need to be shown before they can be removed. Do the following:
Click Start, then click Control Panel.
Locate and double-click Folder Options.
Click on the View tab.
Under the Advanced Settings section, please do the following:
Under Hidden files and folders, check Show hidden files, folders, or drives.
Uncheck Hide file extensions for known file types.
Uncheck Hide protected operating system files (Recommended) . When the warning message appears, click YES.
Click Apply > OK.2. Empty Recycler Folder
Empty the Recycle Bin on your desktop.
Close all running programs.
Click Start > Computer .
Double click Local Disk (C) > Scroll down to and double click the Recycler folder.
Double click the following Recycle bin to show the contents:
S-1-5-21-1342298365-2549134341-3604237475-1000 Click Edit > Select All.
Click File > Delete.
Exit all windows.3. Hide System Files and Folders

We need to rehide the system files and folders to keep them from being accidentally changed or deleted. Do the following:
Click Start, then click Control Panel.
Locate and double-click Folder Options.
Click on the View tab.
Under the Advanced Settings section, please do the following:
Under Hidden files and folders, uncheck Show hidden files, folders, or drives.
Check Hide file extensions for known file types.
Check Hide protected operating system files (Recommended) . When the warning message appears, click YES.
Click Apply > OK.4. Clear Java Cache
Click Start and select Control Panel.
In Classic View, double-click the Java Icon (coffee cup symbol)
Under Temporary Internet Files, click Settings.
Click the Delete Files button.
There are two options in the window to clear the cache. Leave both of these unchecked:
Applications and Applets
Trace and Log Files Click OK on Delete Temporary Files Window.
Note: This deletes all the Downloaded Applications and Applets from the cache. Click OK to exit the Temporary Files Settings.
Click OK to exit the Java Control Panel.5. Delete Extension(s) in Google Chrome

To completely remove the following extension from your browser, do this:
Open Google Chrome.
Click the Chrome menu on the browser toolbar (symbol of 3 horizontal lines).
Go to Settings.
Click Extensions in the pop-up menu.
From the list of installed Extensions, find the following extension:
ljidpgmdpigjjgieiifpdpkhcbabgabb\1\51411f9b31a0d4.61490956.js Click on the trash can icon to the right of Enable.
Close your browser completely and reopen it. The toolbar extension should no longer appear in your Chrome browser.6. Reset Your Home Page and Default Search Engine

Removing the toolbars may have changed your browser settings (homepage, default search engines). If so, please follow the instructions found HERE (http://eula.mindspark.com/reset-homepage-default-search-settings/).

7. Clean Temp Files with CCleaner

Since you were unable to run TFC, try this cleaner instead.
Download CCleaner from HERE (http://www.piriform.com/ccleaner).
Double click on the file to begin the installation.
Select your language > Click OK > Click Next.
Read the license agreement > click I Agree.
Click Next to use the default install location > Click Install > Finish.
Double click the CCleaner shortcut on the desktop to start the program(only if you do not want them deleted.)
Note: If you use Firefox, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla. Click on the Options icon (left side) > Click Advanced.
Deselect Only delete files in Windows Temp folders older than 48 hours.
Click on the Cleaner icon (left side) > Click Run Cleaner.
Click Exit when finished.

Please run DDS again and send me a fresh log. Are there any other issues we need to address?

2013-04-17, 19:50
Ok, attached is the final reports from DDS. Everything seems OK.

Thanks for all your help.

2013-04-18, 03:29
Hello, eve.online. Thank you for the DDS log. It is clean , and you are reporting that all is well with your computer. Let's wrap up with some final housekeeping.

Please work through the following steps to ensure that unnecessary programs and files have been removed and your system is up-to-date.

Uninstall Combofix.
Press the Win Key + R to open up the Run dialog box.
In the Open field type combofix /uninstall. Please note that there is a space between combofix and /uninstall.
Click OK. The Open File security warning will appear asking if you are sure you want to run ComboFix. Please click the Run button to start the program. This will uninstall Combofix and anything associated with it.
When ComboFix has finished uninstalling, delete the ComboFix.exe program from your computer.Tool Removal

You no longer need the following tools. Please delete these tools and any logs from your machine: DDS, RogueKiller, Security Check, JRT, AdwCleaner, MBAM, ESET, and TFC. You can keep Malwarebytes for future use if you choose.

To uninstall ESET Online Scanner, please do the following:
Click Start and select Control Panel.
Click the Uninstall a Program option found under the Programs category.
Select the ESET Online Scanner.
Click Remove.
A restart may be required to complete uninstallation.Anti-Virus Protection

I do not see an anti-virus program listed in your logs. You are currently running Windows Defender. This is an anti-spyware program, not an anti-virus program, and will not protect your computer against malicious infections. Check to ensure you have an anti-virus program installed and enabled, or you can download Microsoft Security Essentials or any one good free anti-virus program from HERE (http://www.geekstogo.com/forum/topic/38-free-antivirus-and-antispyware-software/).

Update Java (Version 7 Update 17)

To improve your software's performance and stability, please remove any older versions of Java and update to the latest version.
Click Start > Control Panel.
Click on the Java icon (coffee cup symbol) > Update > Update Now .
Follow the prompts to install the latest version of Java.To remove older versions:
Click Start and select Control Panel.
When the Control Panel window opens, click on Uninstall a program found under the Programs category.
If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.
Look through the list of programs for any old versions of Java, and then left-click on it once to highlight it.
Click on the Uninstall button.
When finished, close the Programs and Features screen.Windows 7 Service Pack Update

Security Check indicates that you have an outdated Service Pack. To update to the latest Service Pack for your version of Windows, please visit Microsoft HERE (http://windows.microsoft.com/en-CA/windows/service-packs-download#sptabs=win7).

Internet Explorer 10

Download the latest version of Internet Explorer HERE (http://windows.microsoft.com/en-CA/internet-explorer/downloads/ie-10/worldwide-languages).

Turn On Automatic Updates

You can stay up to date with the latest critical and security updates by using Automatic Updates. To turn on Automatic Updates:
Click Start > click Control Panel > Click Windows Update.
In the left pane, click Change Settings.
Under Important Updates, click the down arrow and select Install updates automatically (recommended).
Under Recommended Updates, check Give me updates the same way I receive Important Updates.
Under Who can install updates, check Allow all users to install updates on this computer.
Click OK to apply the changes.

Note: If Windows prompts you to confirm these changes, allow it. Close the window.Adobe Updates

Adobe Reader 11 (Version 11.0.02)

To improve the funtionaility and security of your software, please update Adobe Reader HERE (http://get.adobe.com/reader/). Updates safeguard your system against malicious attacks through PDF files.

Update Adobe Flash 11 (Version 11.7.700.169)

Please update Adobe Flash HERE (http://get2.adobe.com/flashplayer/). Updating your Flash player ensures that it is working properly and guards against security vulnerabilities.

Recommended Reading

To maintain a clean and healthy system, please take the time to read through the following informative articles:
The Dangers of P2P File Sharing HERE (http://www.esecurityguy.com/p2p_file_sharing)
How to Prevent Malware by Miekiemoes HERE (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html)
So How Did I Get Infected In the First Place? By Tony Klein HERE (http://www.spywareinfoforum.com/index.php?showtopic=60955)
Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams HERE (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/)
Help! My computer is Slow – How to improve system performance after malware removal by Miekiemoes HERE (http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html)
Create Strong Passwords by Microsoft HERE (http://www.microsoft.com/security/online-privacy/passwords-create.aspx)
PC Safety and Security – What do I need to do? by Glaswegian HERE (http://www.techsupportforum.com/forums/f112/pc-safety-and-security-what-do-i-need-525915.html)

Wishing you a very safe browsing experience. :)
~ fbfbfb