[RESOLVED] Got a positive on Malwarebytes - Broni can you review and guide
LOGS:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2014.02.23.04
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Dave :: DAVE-PC [administrator]
2/23/2014 10:31:08 AM
mbam-log-2014-02-23 (10-31-08).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 418401
Time elapsed: 2 hour(s), 10 minute(s), 15 second(s)
Memory Processes Detected: 1
C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher32.exe (PUP.Optional.Savingsbull) -> 648 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 8
HKLM\SYSTEM\CurrentControlSet\Services\Level Quality Watcher (PUP.Optional.Savingsbull) -> Quarantined and deleted successfully.
HKCR\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3} (PUP.Optional.ScorpionSaver) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3} (PUP.Optional.ScorpionSaver) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{10AD2C61-0898-4348-8600-14A342F22AC3} (PUP.Optional.ScorpionSaver) -> Quarantined and deleted successfully.
HKCU\Software\SavingsBull (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
HKCU\Software\AppDataLow\Software\Savings Bull (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
HKCU\Software\AppDataLow\Software\SavingsBull (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Savings Bull (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 4
C:\Program Files\Level Quality Watcher\v1.01 (PUP.Optional.Adpeak) -> Delete on reboot.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0 (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
Files Detected: 106
C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher32.exe (PUP.Optional.Savingsbull) -> Delete on reboot.
C:\Program Files\SavingsBull\IEOptimizer.dll (PUP.Optional.ScorpionSaver) -> Quarantined and deleted successfully.
C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe (PUP.Optional.Savingsbull) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MVD2O93C\spstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\background.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\bootstrap.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\icon128.png (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\icon16.png (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\icon32.png (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\icon48.png (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\icon64.png (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\icon8.png (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\manifest.json (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb\5.0_0\marcopolo.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\bootstrap.js.old (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\CustomActionInstall (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\CustomActionUninstall (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_addonkit_page-mod.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_addonkit_private-browsing.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_addonkit_request.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_addonkit_windows.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_addon_runner.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_api-utils.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_base64.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_byte-streams.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_collection.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_content.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_cortex.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_cuddlefish.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_deprecate.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_environment.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_errors.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_events.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_file.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_functional.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_globals.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_heritage.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_hidden-frame.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_light-traits.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_list.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_loader.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_match-pattern.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_memory.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_namespace.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_observer-service.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_plain-text-console.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_preferences-service.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_promise.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_querystring.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_runtime.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_sandbox.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_self.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_system.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_text-streams.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_timer.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_traceback.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_traits.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_unload.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_url.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_uuid.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_window-utils.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_xhr.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_xpcom.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_base_xul-app.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_bootstrap.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_content_content-proxy.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_content_content-worker.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_content_loader.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_content_symbiont.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_content_worker.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_dom_events.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_events_assembler.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_event_core.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_event_target.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_harness-options.json (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_icon.png (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_icon64.png (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_install.rdf (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_l10n_core.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_l10n_html.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_l10n_loader.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_l10n_locale.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_l10n_prefs.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_locales.json (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_main.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_main.js.old (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_prefs.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_privatebrowsing_utils.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_system_events.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_tabs_events.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_tabs_observer.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_tabs_tab.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_tabs_utils.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_traits_core.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_utils_data.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_utils_object.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_utils_registry.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_utils_thumbnail.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_windows_dom.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_windows_loader.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_windows_observer.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_windows_tabs.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\ff_window_utils.js (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\Microsoft.Deployment.WindowsInstaller.dll (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\Microsoft.Deployment.WindowsInstaller.xml (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
C:\Program Files\SavingsBull\SendJson.dll (PUP.Optional.SavingsBull.A) -> Quarantined and deleted successfully.
(end)
RAN ADWCLEANER - LOG:
# AdwCleaner v3.019 - Report created 23/02/2014 at 13:04:20
# Updated 17/02/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Dave - DAVE-PC
# Running from : D:\downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Level Quality Watcher
Folder Deleted : C:\Program Files\Softonic-Eng7
Folder Deleted : C:\Users\Dave\AppData\Local\PackageAware
Folder Deleted : C:\Users\Dave\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Dave\AppData\LocalLow\Softonic-Eng7
Folder Deleted : C:\Users\Dave\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\Dave\AppData\Roaming\DSite
File Deleted : C:\Users\Public\Desktop\eBay.lnk
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Deleted : C:\Windows\System32\Tasks\DSite
***** [ Shortcuts ] *****
***** [ Registry ] *****
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3EC5CCD5-DCF1-4F20-A3F2-7E3BBFF44D7B}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3EC5CCD5-DCF1-4F20-A3F2-7E3BBFF44D7B}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKCU\Software\5e578dd9b73ced17
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2405280
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0974BA1E-64EC-11DE-B2A5-E43756D89593}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0974BA1E-64EC-11DE-B2A5-E43756D89593}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{990F43D0-0616-46A9-AF65-9508B620C243}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{0974BA1E-64EC-11DE-B2A5-E43756D89593}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Key Deleted : HKCU\Software\dsiteproducts
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\bearsharemediabartb
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Softonic-Eng7
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Softonic-Eng7
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic-Eng7 Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic-Eng7 Toolbar
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C19AC53289098045B06B0DD1D37CBAB
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23D9E9D21B4E77E41B9F50DD22F24E20
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23EEA1F105A7F45449974D9B95E7AC89
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\26982796A8AFD1246B95E00265A95BF9
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42D92D0D75AFEF74297E03876C8D9D33
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50FFE845C555A6E4BADB7CB7A145BFEB
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\715A3348920B6534690067594BB69F60
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B7B13B037A7C2A42AC3E3EAF14D7107
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D05B2942E9CC80499F397F6114DFB35
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8591B8948E1C4A04F90505B3CDEE8555
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8D841C5FEC311624CB88D49DB3884FA7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD746BF3B3B3FD8409B86604BA85982A
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F355F0DB7A2E3A14B8E7A568FBA25937
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16533
-\\ Google Chrome v33.0.1750.117
[ File : C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : homepage
*************************
AdwCleaner[R0].txt - [7049 octets] - [23/02/2014 13:02:16]
AdwCleaner[S0].txt - [7175 octets] - [23/02/2014 13:04:20]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7235 octets] ##########
RAN HITMAN - LOG:
Code:
HitmanPro 3.7.9.212
www.hitmanpro.com
Computer name . . . . : DAVE-PC
Windows . . . . . . . : 6.0.2.6002.X86/2
User name . . . . . . : Dave-PC\Dave
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2014-02-23 13:32:07
Scan mode . . . . . . : Normal
Scan duration . . . . : 20m 55s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 0
Traces . . . . . . . : 4
Objects scanned . . . : 1,994,211
Files scanned . . . . : 19,876
Remnants scanned . . : 285,825 files / 1,688,510 keys
Cookies _____________________________________________________________________
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cookies:hammacher.112.2o7.net
C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\910JFILY.txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\DGSEA2N0.txt
RAN ASWMBR - LOG:
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-02-24 10:03:17
-----------------------------
10:03:17.901 OS Version: Windows 6.0.6002 Service Pack 2
10:03:17.901 Number of processors: 2 586 0x6801
10:03:17.903 ComputerName: DAVE-PC UserName: Dave
10:03:19.190 Initialize success
10:03:23.616 AVAST engine defs: 14022301
10:04:00.176 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
10:04:00.180 Disk 0 Vendor: ST9120822AS 3.BHE Size: 114473MB BusType: 3
10:04:00.184 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-6
10:04:00.187 Disk 1 Vendor: ST9120822AS 3.BHE Size: 114473MB BusType: 3
10:04:00.468 Disk 0 MBR read successfully
10:04:00.472 Disk 0 MBR scan
10:04:00.478 Disk 0 Windows VISTA default MBR code
10:04:00.483 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 105850 MB offset 63
10:04:00.518 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 7528 MB offset 216781110
10:04:00.549 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 1092 MB offset 232200192
10:04:00.591 Disk 0 scanning sectors +234436608
10:04:00.839 Disk 0 scanning C:\Windows\system32\drivers
10:04:20.938 Service scanning
10:04:56.618 Modules scanning
10:05:05.419 Disk 0 trace - called modules:
10:05:05.451 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
10:05:05.459 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x859b6780]
10:05:05.468 3 CLASSPNP.SYS[88bab8b3] -> nt!IofCallDriver -> [0x857a8920]
10:05:05.476 5 acpi.sys[884106bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x84e1ab98]
10:05:06.097 AVAST engine scan C:\Windows
10:05:08.689 AVAST engine scan C:\Windows\system32
10:09:41.177 AVAST engine scan C:\Windows\system32\drivers
10:10:12.386 AVAST engine scan C:\Users\Dave
10:17:09.434 AVAST engine scan C:\ProgramData
10:19:58.278 Scan finished successfully
10:24:39.338 Disk 0 MBR has been saved successfully to "C:\Users\Dave\Desktop\MBR.dat"
10:24:39.347 The log file has been saved successfully to "C:\Users\Dave\Desktop\aswMBR.txt"
Need to know what else I need to do - see private email for more info on system issues.
I'm running Windows Vista on a HP dv9500 lap top. Thanks!