2014-03-08, 20:30
Hi there. Have done numerous scans with spybot and got down to 8 entries but on last scan went up to 9; including delta.toolbar; started off with 806. DDS and aswMBR logs follow/are attached:

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16518
Run by TOSHIBA at 17:59:19 on 2014-03-08
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.2811.1381 [GMT 0:00]
AV: avast! Internet Security *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: avast! Internet Security *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Internet Security *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
Other thread: http://forums.spybot.info/showthread.php?70277-win32-downloader-%28possibly%29

2014-03-08, 23:18

Lets do this
C:\Users\TOSHIBA\Downloads\PDFReaderSetup.exe <-- Delete this file

-AdwCleaner-by Xplode

Click on this link to download : ADWCleaner (http://www.bleepingcomputer.com/download/adwcleaner/)
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.

Do not click on any links in the top Advertisment.

Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next reply.
You can find the logfile at C:\AdwCleaner[S1].txt as well.


http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

2014-03-10, 18:22
Hi there. Thanks for your help thus far. Here are the logs for adwcleaner and jrt. My apologies, but the virus protection on this machine is avast and I don't know how to switch it off, so jrt may not have run clearly. If I need to run it again then just say so. Please advise. I also notice that IE says there is a problem and I have to close it. Should I just uninstall and re-install it?:

2014-03-10, 20:15

Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the "Scan All Users" checkbox.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

2014-03-10, 21:11
I have run maleware bytes but forgot to save the file before it rebooted. Sorry about that, but there were 16 entries of pup files that I removed; I think they were in the download directory. Anyway here are the two logs for otl:

[2014/03/06 17:51:27 | 005,785,993 | ---- | C] () -- C:\Users\TOSHIBA\Desktop\05 Snip Snip Snip.m4a
[2014/03/06 17:51:27 | 004,256,581 | ---- | C] () -- C:\Users\TOSHIBA\Desktop\11 Stitch That.m4a
[2014/03/06 17:51:27 | 003,009,580 | ---- | C] () -- C:\Users\TOSHIBA\Desktop\08 Pop Star Kidnap.m4a
[2014/02/26 11:21:42 | 000,765,700 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/02/22 20:05:13 | 000,033,864 | ---- | C] () -- C:\Windows\Launcher.exe
[2013/06/15 11:29:51 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2013/06/15 11:28:10 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe

2014-03-10, 21:12
OTL Extras logfile created on: 3/10/2014 6:52:40 PM - Run 1
OTL by OldTimer - Version Folder = C:\Users\TOSHIBA\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.75 Gb Total Physical Memory | 1.51 Gb Available Physical Memory | 55.19% Memory free
5.49 Gb Paging File | 3.64 Gb Available in Paging File | 66.31% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.41 Gb Total Space | 26.88 Gb Free Space | 17.99% Space Free | Partition Type: NTFS
Drive D: | 148.28 Gb Total Space | 141.11 Gb Free Space | 95.16% Space Free | Partition Type: NTFS

Computer Name: TOSHIBA-TOSH | User Name: TOSHIBA | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

2014-03-10, 23:13
Ok, looking over your OTL log now. Open up Malwarebytes and go to the LOGS Tab, the last entry should be for the one you just ran, check the time and date, open it and copy and paste the log into this forum for me to see please

2014-03-10, 22:12
Malwarebytes Anti-Malware (Trial)

Database version: v2014.03.10.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16518
TOSHIBA :: TOSHIBA-TOSH [administrator]

Protection: Enabled

10/03/2014 18:31:56
mbam-log-2014-03-10 (18-31-56).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 215128
Time elapsed: 5 minute(s), 54 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\SOFTWARE\diamondata (PUP.Optional.Diamondata.A) -> Quarantined and deleted successfully.

Registry Values Detected: 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings|AutoConfigURL (PUP.Optional.HomeTab.A) -> Data: http://cdn1.browsersecurity.net/safe/cloud.js?si=77302&tid=18145 -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 3
C:\Users\TOSHIBA\AppData\Local\Temp\CT3282137 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\AppData\Local\Temp\ct3302239 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\AppData\Local\Temp\ct3302239\plugins (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

Files Detected: 13
C:\Users\TOSHIBA\Downloads\AbiWord_Setup (1).exe (PUP.Bundle.Installer.OI) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\AbiWord_Setup.exe (PUP.Bundle.Installer.OI) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\FLV_Runner_B.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\iTunes.exe (PUP.Optional.Smart) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\iTunes64.exe (PUP.Optional.Smart) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\OpenOffice.org (1).exe (PUP.Optional.Firseria) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\OpenOffice.org (2).exe (PUP.Optional.Firseria) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\OpenOffice.org.exe (PUP.Optional.Firseria) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\rcpsetup_latest (1).exe (PUP.Optional.RegCleanerPro) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\rcpsetup_latest.exe (PUP.Optional.RegCleanerPro) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\Skype_Setup (1).exe (PUP.Optional.IBryte) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\Downloads\Skype_Setup.exe (PUP.Optional.IBryte) -> Quarantined and deleted successfully.
C:\Users\TOSHIBA\AppData\Roaming\Bubble Dock.boostrap.log (PUP.Optional.Bubbledock.A) -> Quarantined and deleted successfully.


2014/03/10 18:29:39 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Executing scheduled update: Daily
2014/03/10 18:29:44 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Starting protection
2014/03/10 18:29:44 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Protection started successfully
2014/03/10 18:29:44 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Starting IP protection
2014/03/10 18:30:17 GMT TOSHIBA-TOSH TOSHIBA MESSAGE IP Protection started successfully
2014/03/10 18:30:29 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Scheduled update executed successfully: database updated from version v2013.04.04.07 to version v2014.03.10.07
2014/03/10 18:30:29 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Starting database refresh
2014/03/10 18:30:30 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Stopping IP protection
2014/03/10 18:30:31 GMT TOSHIBA-TOSH TOSHIBA MESSAGE IP Protection stopped successfully
2014/03/10 18:30:36 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Database refreshed successfully
2014/03/10 18:30:36 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Starting IP protection
2014/03/10 18:30:44 GMT TOSHIBA-TOSH TOSHIBA MESSAGE IP Protection started successfully
2014/03/10 18:41:58 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Starting protection
2014/03/10 18:41:58 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Protection started successfully
2014/03/10 18:41:58 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Starting IP protection
2014/03/10 18:42:06 GMT TOSHIBA-TOSH TOSHIBA MESSAGE IP Protection started successfully
2014/03/10 20:02:16 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Starting protection
2014/03/10 20:02:16 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Protection started successfully
2014/03/10 20:02:16 GMT TOSHIBA-TOSH TOSHIBA MESSAGE Starting IP protection
2014/03/10 20:02:25 GMT TOSHIBA-TOSH TOSHIBA MESSAGE IP Protection started successfully

2014-03-10, 23:13

Thanks for the Malwarebytes log :)

Your OTL log really doesn't look that bad, just a few things to fix

Open OTL.exe

Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

IE:64bit: - HKLM\..\SearchScopes\{BD0001FF-AF5E-481D-9919-FA256C3C0F0A}: "URL" = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=solimmsd&cd=2XzuyEtN2Y1L1QzuyBtDtC0AtDyEtBzyyB0Fzy0DtAzyyD0FtN0D0Tzu0CyCyCtBtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1F1I1L1H1H1B1Q&cr=1244745655&ir=
CHR - default_search_provider: search_url = http://search.certified-toolbar.com?si=77302&st=bs&tid=18145&ver=5.7&ts=1393099447640&tguid=77302-18145-1393099447640-8B267C944A6FFBEE2E40AFB7D4838859&q={searchTerms}



ipconfig /flushdns /c

[start explorer]

Then click the Run Fix button at the top. <--Not run Scan
Let the program run unhindered, reboot when it is done
Then post the results of the log it produces

Then run a new scan with OTL and post the new log please

2014-03-10, 23:59
Hi there again. I hope the fact that I just did a scan; without scan all users, LOP check and purity check boxes ticked, but minimal output. Here's the log:

OTL logfile created on: 3/10/2014 9:39:45 PM - Run 2
OTL by OldTimer - Version Folder = C:\Users\TOSHIBA\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.75 Gb Total Physical Memory | 1.61 Gb Available Physical Memory | 58.56% Memory free
5.49 Gb Paging File | 3.71 Gb Available in Paging File | 67.54% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.41 Gb Total Space | 27.21 Gb Free Space | 18.21% Space Free | Partition Type: NTFS
Drive D: | 148.28 Gb Total Space | 141.11 Gb Free Space | 95.16% Space Free | Partition Type: NTFS

Computer Name: TOSHIBA-TOSH | User Name: TOSHIBA | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

< End of report >

2014-03-11, 00:01
2014-03-11, 00:18
Open Chrome
Click the Chrome menu http://i24.photobucket.com/albums/c30/ken545/Clipboard01_zps2e55f676.jpgon the browser toolbar.
Click on Settings
Then Manage Search Engines
Highlite search.certified-toolbar and select Delete

How are things running now, do you still see Delta ?

2014-03-11, 00:55
Hi there. I have done what you requested with chrome and everything seems ok; even IE is working now. To be honest I never did see the delta search engine; rather, chrome just showed the most commonly viewed sites. Thanks again for all your help :)

2014-03-11, 01:17

Glad all is well and we could help

Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups, any programs that where not removed you can just drag to the trash.

Malwarebytes is the free version and yours to keep and will not be removed

How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/index.php?showtopic=57817)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)

Safe Surfn

2014-03-12, 13:24
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.