2014-05-17, 22:10

This is the first time I have tried to fix malware myself. I read the instructions and hope I have provided everything required.
Please note the scan I have just performed seems to indicate there are no problems. BUT it is also a different display to the first scan. Does this mean Spybot has removed the Malware?

I was on an unsecured network, as usual. A pop up window came onto the webpage I was viewing. It was in French but obviously without a cancel, only a submit button. I pressed this (stupid) and went to another screen without an exit possibility.

Steps taken and the results:

1. Ran Skybot Search and Destroy 2.2. The results appear to have been saved but I searched my computer (all drives) and cannot find them. I did take and image which is attached named "Spybot 2014-05-15.JPG

2. Downloaded and ran ERUNT. Successful

3. Downloaded and ran DDS - successful. Surely this would be better attached?
4. Downloaded and ran aswMBR Log - NOT successful

My computer crashed and rebooted. I never start in safe mode nor do I try and find out what caused the crash. Inevitably I am not online after a crash anyway.

5. Reran Spybot - successful

The results show there is no longer a problem. I am wary though. I don't believe malware will just remove itself. Or did Spybot remove the Malware.

Search results from Spybot - Search & Destroy

5/17/2014 8:27:26 PM
Scan took 01:15:54.
15 items found.

DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (User): Ann) (Browser: Cookie, nothing done)

7-Zip: [SBI $12C3A52C] Folder history (Registry Value, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry Change, nothing done)

MS DirectInput: [SBI $9A063C91] Most recent application (Registry Change, nothing done)

MS DirectInput: [SBI $7B184199] Most recent application ID (Registry Change, nothing done)

Windows Explorer: [SBI $D20DA0AD] Recent file global history (Registry Key, nothing done)

Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-3847289671-3493599336-2917903439-1001\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-3847289671-3493599336-2917903439-1001\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry Value, nothing done)
HKEY_USERS\S-1-5-21-3847289671-3493599336-2917903439-1001\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

Cookie: [SBI $49804B54] Browser: Cookie (12) (Browser: Cookie, nothing done)

Cache: [SBI $49804B54] Browser: Cache (354) (Browser: Cache, nothing done)

History: [SBI $49804B54] Browser: History (55) (Browser: History, nothing done)

2014-05-18, 02:04

I am going to ask you not to run any other programs on your own or it could interfere with the analysis, also do not install or uninstall any programs until we are done.

Looks like you have some PUP (Potentially Unwanted Programs ) on your system, lets do this

-AdwCleaner-by Xplode

Click on this link to download : ADWCleaner (http://www.bleepingcomputer.com/download/adwcleaner/)
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.

Do not click on any links in the top Advertisment.

Double click on AdwCleaner.exe to run the tool.
Vista/Windows 7/8 users right-click and select Run As Administrator (http://windows.microsoft.com/en-US/windows7/How-do-I-run-an-application-once-with-a-full-administrator-access-token).
Click on the Scan button.
AdwCleaner will begin...be patient as the scan may take some time to complete.
After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
Copy and paste the contents of that logfile in your next reply.
A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

2014-05-18, 11:53
There is nothing in the report that I recognize as something I want to keep.

This is the report from AdwCleaner

# AdwCleaner v3.208 - Report created 18/05/2014 at 10:38:26
# Updated 11/05/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Ann - ANN-PC
# Running from : C:\Users\Ann\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\save net
Folder Found : C:\Program Files\SNT
Folder Found : C:\Program Files\SW-Booster
Folder Found : C:\Program Files\YoutubeAdblocker
Folder Found : C:\ProgramData\save net
Folder Found : C:\ProgramData\SNT
Folder Found : C:\ProgramData\SuperbApp
Folder Found : C:\ProgramData\Tarma Installer
Folder Found : C:\ProgramData\YoutubeAdblocker
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbifcgdmblggjcefpnipldpgcbegfjfb
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclbdehngbefbfmephopjgigkfkgbadi
Folder Found : C:\Users\Administrator\AppData\Local\torch
Folder Found : C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil
Folder Found : C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil
Folder Found : C:\Users\Ann\AppData\Local\torch
Folder Found : C:\Users\Ann\AppData\LocalLow\Conduit
Folder Found : C:\Users\Ann\AppData\LocalLow\Funmoods
Folder Found : C:\Users\Ann\AppData\Roaming\Funmoods
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbifcgdmblggjcefpnipldpgcbegfjfb
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclbdehngbefbfmephopjgigkfkgbadi
Folder Found : C:\Users\Guest\AppData\Local\torch
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbifcgdmblggjcefpnipldpgcbegfjfb
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclbdehngbefbfmephopjgigkfkgbadi
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Found : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbifcgdmblggjcefpnipldpgcbegfjfb
Folder Found : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclbdehngbefbfmephopjgigkfkgbadi
Folder Found : C:\Users\UpdatusUser\AppData\Local\torch
Folder Found : C:\Windows\system32\SearchProtect

***** [ Shortcuts ] *****

***** [ Registry ] *****

Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~1\sw-boo~1\assist~1.dll
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Google\Chrome\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil
Key Found : HKCU\Software\Google\Chrome\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil
Key Found : HKCU\Software\IM
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\RegisteredApplicationsEx
Key Found : HKCU\Software\Softonic
Key Found : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\Software\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Found : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Found : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\esrv.funmoodsESrvc
Key Found : HKLM\SOFTWARE\Classes\esrv.funmoodsESrvc.1
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3000930
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Key Found : HKLM\Software\InstallCore
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Found : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SweetPacks Communicator
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_picasa_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_picasa_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\sweetpacksupdatemanager_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{c67abfdb}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileParade bundle uninstaller
Key Found : HKLM\Software\Tarma Installer

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521

Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://websearch.amaizingsearches.info/?pid=2145&r=2014/04/14&hid=8826810464153519484&lg=EN&cc=NL&unqvl=51

-\\ Google Chrome v34.0.1847.116

[ File : C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Search Provider] : hxxp://websearch.amaizingsearches.info/?l=1&q={searchTerms}&pid=2145&r=2014/04/14&hid=8826810464153519484&lg=EN&cc=NL&unqvl=51
Found [Extension] : jgaanchmbkbjjjclkdlcjhhipijhndil


AdwCleaner[R0].txt - [7336 octets] - [18/05/2014 10:38:26]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [7396 octets] ##########

2014-05-18, 13:12
Good Morning,

Lots of garbage needs to go, run these in order please and post the log for each one, they may not fit all in one reply so use as many replies as you need

Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next reply.
You can find the logfile at C:\AdwCleaner[S1].txt as well.

http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

http://i.imgur.com/GUZVCQN.jpg Please download Malwarebytes Anti-Malware (http://www.malwarebytes.org/mbam-download.php) to your desktop.

Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
Once installed, Malwarebytes will ask if you want to Launch Now. Please select to do so and then Malwarebytes will open and update on its own. Please allow this to complete.
If an update is found, it will download and install the latest version.
Let's be sure to run a Hyper Scan. Press the Scan tab and then select Hyper Scan.
Press Scan Now then Skip Update (since we just updated it)


When the scan is complete, click View Detailed Log, then Export to save the log to your Desktop (name the log MBAM Scan).
Copy and Paste all of the information in that file to your next reply.

2014-05-19, 10:39
I have copied all the logs below

Unfortunately I could not run Malwarebytes Hyper Scan. This is only available in the premium version. I did run the normal scan.

Why I missed it:
First I copied the copy of your reply to Word so I could follow the instructions. Then closed the browser.
The Word document did not contain the screen shot.
Second I downloaded the free version of Malwarebytes and ran the scan. No, I didn't read the instructions properly. As soon as I realized my mistake I cancelled the scan.
Third I tried to obtain a 14 day trial. I uninstalled Malwarebytes and specifically loaded the 14 day trial version. Even so the freeware version installed. I tried several scenarios but none worked.

AdwCleaner Log

# AdwCleaner v3.208 - Report created 18/05/2014 at 14:36:58
# Updated 11/05/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Ann - ANN-PC
# Running from : C:\Users\Ann\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\SNT
Folder Deleted : C:\ProgramData\SuperbApp
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\save net
Folder Deleted : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\SNT
Folder Deleted : C:\Program Files\SW-Booster
Folder Deleted : C:\Program Files\save net
Folder Deleted : C:\Program Files\YoutubeAdblocker
Folder Deleted : C:\Windows\system32\SearchProtect
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Ann\AppData\Local\torch
Folder Deleted : C:\Users\Ann\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Ann\AppData\LocalLow\Funmoods
Folder Deleted : C:\Users\Ann\AppData\Roaming\Funmoods
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbifcgdmblggjcefpnipldpgcbegfjfb
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbifcgdmblggjcefpnipldpgcbegfjfb
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbifcgdmblggjcefpnipldpgcbegfjfb
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbifcgdmblggjcefpnipldpgcbegfjfb
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclbdehngbefbfmephopjgigkfkgbadi
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclbdehngbefbfmephopjgigkfkgbadi
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclbdehngbefbfmephopjgigkfkgbadi
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclbdehngbefbfmephopjgigkfkgbadi
Folder Deleted : C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil
[!] Folder Deleted : C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Key Deleted : HKCU\Software\Google\Chrome\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jgaanchmbkbjjjclkdlcjhhipijhndil
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\esrv.funmoodsESrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.funmoodsESrvc.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SweetPacks Communicator
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\sweetpacksupdatemanager_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{c67abfdb}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3000930
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_picasa_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_picasa_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\InstallCore
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileParade bundle uninstaller
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~1\sw-boo~1\assist~1.dll

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v34.0.1847.116

[ File : C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://websearch.amaizingsearches.info/?l=1&q={searchTerms}&pid=2145&r=2014/04/14&hid=8826810464153519484&lg=EN&cc=NL&unqvl=51
Deleted [Extension] : jgaanchmbkbjjjclkdlcjhhipijhndil


AdwCleaner[R0].txt - [7476 octets] - [18/05/2014 10:38:26]
AdwCleaner[R1].txt - [7534 octets] - [18/05/2014 14:33:14]
AdwCleaner[S0].txt - [7274 octets] - [18/05/2014 14:36:58]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7334 octets] ##########

Junk Removal Tool Log

Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x86
Ran by Ann on Sun 05/18/2014 at 14:45:15.74

~~~ Services

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B6D204D8-1AB1-82F8-CBB8-798B937AB885}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B6D204D8-1AB1-82F8-CBB8-798B937AB885}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6D204D8-1AB1-82F8-CBB8-798B937AB885}

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\Users\Ann\Local Settings\Application Data\cre"

~~~ Event Viewer Logs were cleared

Scan was completed on Sun 05/18/2014 at 14:56:07.08
End of JRT log

Malwarebytes Log

Malwarebytes Anti-Malware

Scan Date: 5/19/2014
Scan Time: 9:18:43 AM
Logfile: MBAM.txt
Administrator: Yes

Malware Database: v2014.05.19.02
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Ann

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 288271
Time Elapsed: 27 min, 52 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 5
PUP.Optional.MultiPlug.A, C:\ProgramData\SSaVeRRExtteensIon\RKO.dll, , [92ac83d07dfe4beb9561430631d0669a],
BadJoke.KillFiles, C:\$Recycle.Bin\S-1-5-21-3847289671-3493599336-2917903439-1001\$RT4GXIQ.zip, , [9ca2262d1f5c77bf903c991acc35619f],
BadJoke.KillFiles, C:\$Recycle.Bin\S-1-5-21-3847289671-3493599336-2917903439-1001\$RPGSTSU.zip, , [a896db787803ec4ab01cbcf78b7657a9],
PUP.Optional.Superfish.A, C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [b58985ce7dfe6ccab4bd86fe1de5837d],
PUP.Optional.Superfish.A, C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, , [f44af55ed6a53cfa87ea2c58c63c1de3],

Physical Sectors: 0
(No malicious items detected)


2014-05-19, 12:22
Good Morning,

When your not used to running these type of programs it can be a bit confusing, but your doing fine.

Open up Malwarebytes and run the Threat scan again

When the scan has completed, you will now be presented with a screen showing you the malware infections that Malwarebytes’ Anti-Malware has detected. To remove the malicious programs that Malwarebytes Anti-malware has found, click on the “Quarantine All” button, and then click on the “Apply Now” button.

Then post the log please

2014-05-19, 16:43
I reran Malwarebytes.

As I am not sure which log you are referring to I have attached a copy of the screen after I quarantined the malware.


I then reran the scan and have copied the report below.

Malwarebytes Anti-Malware

Scan Date: 5/19/2014
Scan Time: 3:35:11 PM
Logfile: MBAM3.txt
Administrator: Yes

Malware Database: v2014.05.19.04
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Ann

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 288187
Time Elapsed: 42 min, 29 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


2014-05-19, 17:14

Lets check for leftovers

OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the "Scan All Users" checkbox.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

2014-05-21, 12:24
OTL logfile created on: 5/21/2014 10:59:47 AM - Run 1
OTL by OldTimer - Version Folder = C:\Users\Ann\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.75 Gb Total Physical Memory | 0.91 Gb Available Physical Memory | 51.97% Memory free
3.50 Gb Paging File | 2.26 Gb Available in Paging File | 64.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 57.59 Gb Total Space | 8.20 Gb Free Space | 14.24% Space Free | Partition Type: NTFS
Drive D: | 163.98 Gb Total Space | 51.10 Gb Free Space | 31.16% Space Free | Partition Type: NTFS
Drive E: | 11.11 Gb Total Space | 10.99 Gb Free Space | 98.95% Space Free | Partition Type: NTFS

Computer Name: ANN-PC | User Name: Ann | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

2014-05-21, 12:26
2014-05-21, 13:48
Just a few more things to remove. After the fix let me know how you feel your system is behaving now

Open OTL.exe

Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

[2012/12/17 19:35:54 | 000,000,000 | ---D | M] (Serif WebPlus Community Toolbar) -- C:\Users\Ann\AppData\Roaming\Mozilla\Firefox\extensions\{07364a98-eb02-4736-bc54-ebe437fccb87}
CHR - default_search_provider: WebSearch (Enabled)
CHR - default_search_provider: search_url = http://websearch.amaizingsearches.info/?l=1&q={searchTerms}&pid=2145&r=2014/04/14&hid=8826810464153519484&lg=EN&cc=NL&unqvl=51
CHR - Extension: DownSaave = C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\omdbkioijpmnnheejmlbkddibejbioik\5.2\
O3 - HKU\S-1-5-21-3847289671-3493599336-2917903439-1001\..\Toolbar\WebBrowser: (no name) - {07364A98-EB02-4736-BC54-EBE437FCCB87} - No CLSID value found.
[2014/04/21 18:26:30 | 000,000,000 | ---D | C] -- C:\ProgramData\SSaVeRRExtteensIon



ipconfig /flushdns /c

[start explorer]

Then click the Run Fix button at the top. <--Not run Scan
Let the program run unhindered, reboot when it is done
Then post the results of the log it produces

2014-05-21, 14:41
Thanks very much for helping me. I really appreciate this.http://forums.spybot.info/images/smilies/animated/crowned.gif

I am sure the computer will run better and I am definitely sure it is clean for the moment.

2014-05-21, 14:46
Open Chrome
Click the Chrome menu http://i24.photobucket.com/albums/c30/ken545/Clipboard01_zps2e55f676.jpgon the browser toolbar.
Click on Settings
Then Manage Search Engines
Highlite WebSearch and select Delete

2014-05-21, 16:34

2014-05-21, 16:50
How is your system behaving now ?

2014-05-21, 16:58
It is running perfectly.

2014-05-21, 17:03
Wonderful , glad we could help

Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups, any programs that where not removed you can just drag to the trash.

Malwarebytes is the free version and yours to keep and will not be removed

How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/index.php?showtopic=57817)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)

Safe Surfn