Welcome Guest, to the Spybot Forums! It's 2025, and we just upgraded our forum software.
Today is Safer Internet Day, and with our new forum, you can finally use passkeys to login. That was about time!
Of course, you could ask if a forum is still useful, with so many social media networks out there where you might already have an account, and met a lot of users. You can now use your login from some of those networks to log in here. And by posting here, your question and data is stored on our servers and not automatically shared with a whole social media network.
We'll also start using the forum for small bits of information, announcements and more again.
Hi and welcome
When you ran the Farbar Recovery Scan Tool, did it also produce an Addition.txt?
If so, could you please copy and paste it into your next reply.
~~~~~~~~~~~~~~~~~~~~~
AdwCleaner![]()
-- File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.
- Please download AdwCleaner and save the file to your Desktop.
- Right-Click AdwCleaner.exe and select
Run as administrator to run the programme.![]()
- Follow the prompts.
- Click Scan.
- Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
- Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
- Follow the prompts and allow your computer to reboot.
- After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
~~~~~~~~~~~~~~~
Please download Malwarebytes Anti-Malware and save it to your desktop.
To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 1)
- Double-click on the setup file (mbam-setup.exe), then click on Run to install.
- Malwarebytes will automatically open to it's Dashboard. If you have never run this version, you should see a red note at the top indicating "A scan has never been run on your system"
- Click on Update Now to download the current database definitions, then click the Scan Now >> button.
- If you have run this version before, you should see a green note at the top indicating "Your system is fully protected".
- You will be prompted to update Malwarebytes...click on the Update Now button.
- The THREAT SCAN will automatically begin.
- When the scan has completed, the results will be displayed. Click on Quarantine All, then click on Apply Actions.
- To complete any actions taken you will be prompted to restart your computer...click on Yes. Failure to reboot normally will prevent Malwarebytes from removing all the malware.
- After rebooting the computer, copy and paste the mbam.log in your next reply.
To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)
- Open Malwarebytes Anti-Malware.
- Click the History Tab at the top and select Application Logs.
- Select (check) the box next to Scan Log. Choose the most current scan.
- Click the View button.
- Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
- Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
- Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
- Open Malwarebytes Anti-Malware.
- Click the Scan Tab at the top.
- Click the View detailed log link on the right.
- Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
- Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
- Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
-- XP: C:\Documents and Settings\<Username>\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
-- Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
~~
please post
Addition.txt
AdwCleaner.txt
Malwarebytes Anti-Malware Log
Good news for your browser.My web browser appears to be back to normal, can I trust this?
Will run the Farbar recovery again and post the additional txt.
start
CreateRestorePoint:
CloseProcesses:
SearchScopes: HKLM -> {718AA698-BD70-46E4-A23F-546A65BD347D} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/710-29550-11896-25/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {718AA698-BD70-46E4-A23F-546A65BD347D} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/710-29550-11896-25/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3115212846-1808065930-1501414302-1001 -> {718AA698-BD70-46E4-A23F-546A65BD347D} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-3115212846-1808065930-1501414302-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/710-29550-11896-25/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
Toolbar: HKU\S-1-5-21-3115212846-1808065930-1501414302-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-04-05]
C:\Users\clair_000\AppData\Local\Temp\Quarantine.exe
C:\Users\clair_000\AppData\Local\Temp\sqlite3.dll
EmptyTemp:
End