SD,
Below please find a copy of the JRT scan. I will forward the other two when completed. The JRT scan was run in Safe Mode and I will try and run the other scans via regular boot.
Thanks.
SwineSlayer
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Howard on Tue 05/21/2013 at 9:21:20.27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully stopped: [Service] browserprotect
Successfully deleted: [Service] browserprotect
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\mixidj
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\totalrecipesearch_14ei
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\search settings
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\windows\currentversion\ext\bprotectsettings
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\applications\ilividsetup.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctl
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctl.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctlsecondary
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctlsecondary.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0021804.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\CrossriderApp0021804.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT3298573
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{05AF0AD6-7102-4BCF-8730-CAB7AEAB6E17}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] "hkey_current_user\software\pip"
Successfully deleted: [Registry Key] "hkey_local_machine\software\pip"
~~~ Files
Successfully deleted: [File] "C:\end"
Successfully deleted: [File] C:\eula.1028.txt
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\eula.1033.txt
Successfully deleted: [File] C:\eula.1036.txt
Successfully deleted: [File] C:\eula.1040.txt
Successfully deleted: [File] C:\eula.1041.txt
Successfully deleted: [File] C:\eula.1042.txt
Successfully deleted: [File] C:\eula.2052.txt
Successfully deleted: [File] C:\install.res.1028.dll
Successfully deleted: [File] C:\install.res.1031.dll
Successfully deleted: [File] C:\install.res.1033.dll
Successfully deleted: [File] C:\install.res.1036.dll
Successfully deleted: [File] C:\install.res.1040.dll
Successfully deleted: [File] C:\install.res.1041.dll
Successfully deleted: [File] C:\install.res.1042.dll
Successfully deleted: [File] C:\install.res.2052.dll
Successfully deleted: [File] C:\install.res.3082.dll
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\browserprotect"
Successfully deleted: [Folder] "C:\ProgramData\pc optimizer pro"
Successfully deleted: [Folder] "C:\ProgramData\strongvault online backup"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\ProgramData\viewpoint"
Successfully deleted: [Folder] "C:\ProgramData\wincert"
Successfully deleted: [Folder] "C:\Users\Howard\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\Howard\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\Howard\appdata\local\babylon"
Successfully deleted: [Folder] "C:\Users\Howard\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\Howard\appdata\local\coupon companion plugin"
Successfully deleted: [Folder] "C:\Users\Howard\appdata\local\ilivid"
Successfully deleted: [Folder] "C:\Users\Howard\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Program Files\browserprotect"
Successfully deleted: [Folder] "C:\Program Files\conduit"
Successfully deleted: [Folder] "C:\Program Files\driver-soft"
Successfully deleted: [Folder] "C:\Program Files\mixidj"
Successfully deleted: [Folder] "C:\Program Files\search results toolbar"
Successfully deleted: [Folder] "C:\Program Files\viewpoint"
Successfully deleted: [Folder] "C:\Program Files\Common Files\spigot"
Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"
Successfully deleted: [Folder] "C:\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{037E1F0E-08AF-4A75-8146-1B54365400D6}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{0852317F-0665-406D-9B99-CF48B10C4F00}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{12551B0B-2AF5-4148-B648-1858D4CB8B33}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{24CC1CE8-501F-4EBE-B051-38D04D68D27C}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{29AEF431-AE97-4829-8BA5-BCB6BA0FF4E5}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{36F08147-8B63-47CF-AAA2-4BB37FBFF583}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{475DC22D-ED46-4999-A25F-1A4631B7319A}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{60754F16-E1A7-4B6A-A893-2B7FB02B2FA0}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{8735DDC8-8D45-47BD-AD12-71CE474000D9}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{ABB5C42C-796C-43D5-A41A-038F1A72E20E}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{AE9BD801-AB39-4479-8647-DFEB9FFD56CC}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{C62453F3-3654-4960-838A-FC61F5E832A4}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{F1557824-C339-45A2-8CE5-8E565134D31A}
Successfully deleted: [Empty Folder] C:\Users\Howard\appdata\local\{F9842B64-E2F3-4D74-986C-76EF874E19E1}
Successfully deleted: [Folder] "C:\ProgramData\ask"
~~~ FireFox
Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\search_results.xml"
Successfully deleted: [File] C:\Users\Howard\AppData\Roaming\mozilla\firefox\profiles\bqm8qhci.default-1362589089732\user.js
Successfully deleted: [File] C:\Users\Howard\AppData\Roaming\mozilla\firefox\profiles\bqm8qhci.default-1362589089732\bprotector_extensions.sqlite
Successfully deleted: [File] "C:\Users\Howard\AppData\Roaming\mozilla\firefox\profiles\bqm8qhci.default-1362589089732\extensions\
[email protected]"
Successfully deleted: [File] C:\Users\Howard\AppData\Roaming\mozilla\firefox\profiles\bqm8qhci.default-1362589089732\extensions\
[email protected]Successfully deleted: [Folder] C:\Users\Howard\AppData\Roaming\mozilla\firefox\profiles\bqm8qhci.default-1362589089732\jetpack
Successfully deleted: [Folder] C:\Users\Howard\AppData\Roaming\mozilla\firefox\profiles\bqm8qhci.default-1362589089732\extensions\staged
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}
Successfully deleted the following from C:\Users\Howard\AppData\Roaming\mozilla\firefox\profiles\bqm8qhci.default-1362589089732\prefs.js
user_pref("CT3298573_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1369067411169,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}
user_pref("browser.search.defaultthis.engineName", "MixiDJ V37 Customized Web Search");
user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3298573&CUI=UN30100869021999146&UM=2&SearchSource=3&q={searchTerms}");
user_pref("extensions.brandthunder.websearchplus", false);
user_pref("extensions.browserprotect.searchProvide
rExceptions", "hxxp://en.wikipedia.org/wiki/Special:Search;hxxp://search.yahoo.com/search;hxxp://www.answers.com/main/ntquery
user_pref("extensions.browserprotect.urlBarExcepti
ons", "hxxp://www.google.com;hxxp://search.yahoo.com;hxxp://search.live.com;hxxp://en.wikipedia.org;chrome://*;chrome://brows
user_pref("{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=toolbar|babsrc=tb_ss|invocationType=tb50-ie-aolsoftonic-tbsbox-en-us|invocatio
user_pref("{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"
www.search-results.com\":\"q\",\"home.
user_pref("{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}.ScriptData_product_name", "Updater By SweetPacks");
Emptied folder: C:\Users\Howard\AppData\Roaming\mozilla\firefox\profiles\bqm8qhci.default-1362589089732\minidumps [12 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 05/21/2013 at 9:23:10.55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~