Computer Hope

Software => Computer viruses and spyware => Topic started by: 007will on August 19, 2014, 02:17:41 PM

Title: My mums computer is infected
Post by: 007will on August 19, 2014, 02:17:41 PM
I think my mums laptop is infected. Possibly malware etc. You guys have helped me before.

Here are her logs. Can you help?

# AdwCleaner v3.307 - Report created 19/08/2014 at 20:33:56
# Updated 17/08/2014 by Xplode
# Operating System : Windows 8.1  (64 bits)
# Username : jenny_000 - MYPC
# Running from : C:\Users\jenny_000\Desktop\adwcleaner_3.307.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : BackupStack

Service Deleted : servervo
Service Deleted : webinstr
Service Deleted : {54ad4f6c-f1ec-4341-a888-284784343715}w64
Service Deleted : {55685567-4840-4a91-962b-49a412e9485a}w64
Service Deleted : {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\374311380
Folder Deleted : C:\ProgramData\DSearchLink
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\Systweak
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\cosstminn
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freesofttoday
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong2
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Speedup
Folder Deleted : C:\Program Files (x86)\AnyProtectEx
Folder Deleted : C:\Program Files (x86)\ASP
Folder Deleted : C:\Program Files (x86)\Bench
Folder Deleted : C:\Program Files (x86)\Browse Safe
Folder Deleted : C:\Program Files (x86)\Driver Pro
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\HomeTab
Folder Deleted : C:\Program Files (x86)\MyPC Backup
Folder Deleted : C:\Program Files (x86)\PriceGong2
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Program Files (x86)\System Speedup
Folder Deleted : C:\Program Files (x86)\cosstminn
Folder Deleted : C:\Program Files (x86)\fst_gb_94
Folder Deleted : C:\Program Files (x86)\Browsers Apps
Folder Deleted : C:\Program Files (x86)\Free Video Grabber  6.6
Folder Deleted : C:\Program Files (x86)\HQualityPro-1.6
Folder Deleted : C:\Program Files (x86)\SmartSaver+ 3
Folder Deleted : C:\Program Files (x86)\videos MediaPlay-Air
Folder Deleted : C:\Program Files (x86)\ver3BlockAndSurf
Folder Deleted : C:\Program Files\HomeTab
Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Guest\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\jenny_000\AppData\Local\BenchUpdater
Folder Deleted : C:\Users\jenny_000\AppData\Local\Browse Safe
Folder Deleted : C:\Users\jenny_000\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\jenny_000\AppData\Local\globalUpdate
Folder Deleted : C:\Users\jenny_000\AppData\Local\LPT
Folder Deleted : C:\Users\jenny_000\AppData\Local\Smartbar
Folder Deleted : C:\Users\jenny_000\AppData\Local\torch
Folder Deleted : C:\Users\jenny_000\AppData\Local\WeatherAlerts
Folder Deleted : C:\Users\jenny_000\AppData\Local\fst_gb_94
Folder Deleted : C:\Users\jenny_000\AppData\LocalLow\HomeTab
Folder Deleted : C:\Users\jenny_000\AppData\LocalLow\PriceGong2
Folder Deleted : C:\Users\jenny_000\AppData\LocalLow\SimplyTech
Folder Deleted : C:\Users\jenny_000\AppData\LocalLow\Smartbar
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\1H1Q
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\Driver Pro
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\istartsurf
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\Nosibay
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\SimplyTech
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\Speedial
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\System Speedup
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\Systweak
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\VOPackage
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browse Safe
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Deleted : C:\Users\jenny_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
Folder Deleted : C:\Users\jenny_000\Documents\Optimizer Pro
Folder Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
Folder Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Folder Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Folder Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnpoeccdlikfebbglldlokpnghpmdnfa
File Deleted : C:\END
File Deleted : C:\Users\Public\Desktop\Advanced System Protector.lnk
File Deleted : C:\Users\Public\Desktop\eBay.lnk
File Deleted : C:\Users\Public\Desktop\System Speedup.lnk
File Deleted : C:\Windows\System32\drivers\webinstr.sys
File Deleted : C:\Windows\System32\GroupPolicy\Machine\Registry.pol
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Windows\System32\sasnative64.exe
File Deleted : C:\Windows\System32\drivers\{54ad4f6c-f1ec-4341-a888-284784343715}w64.sys
File Deleted : C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}w64.sys
File Deleted : C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64.sys
File Deleted : C:\Users\jenny_000\AppData\Roaming\aps.scan.quick.results
File Deleted : C:\Users\jenny_000\AppData\Roaming\aps.scan.results
File Deleted : C:\Users\jenny_000\AppData\Roaming\aps.uninstall.scan.results
File Deleted : C:\Users\jenny_000\AppData\Roaming\Bubble Dock.boostrap.log
File Deleted : C:\Users\jenny_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
File Deleted : C:\Users\jenny_000\Desktop\AnyProtect.lnk
File Deleted : C:\Users\jenny_000\Desktop\Continue Live Installation.lnk
File Deleted : C:\Users\jenny_000\Desktop\Driver Pro.lnk
File Deleted : C:\Users\jenny_000\Desktop\MyPC Backup.lnk
File Deleted : C:\Users\jenny_000\Desktop\Sync Folder.lnk
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.betterdeals00.betterdeals.co_0.localstorage
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.betterdeals00.betterdeals.co_0.localstorage-journal
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage-journal
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage-journal
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage
File Deleted : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage-journal

***** [ Scheduled Tasks ] *****

Task Deleted : Advanced System Protector_startup
Task Deleted : APSnotifierPP1
Task Deleted : APSnotifierPP2
Task Deleted : APSnotifierPP3
Task Deleted : bench-sys
Task Deleted : BlockAndSurf Update
Task Deleted : BlockAndSurf_wd
Task Deleted : Driver Support-RTMRules
Task Deleted : Driver Support-RTMScan
Task Deleted : Driver Support-RTMUpdater
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : LaunchSignup
Task Deleted : Speedial
Task Deleted : System Speedup_DEFAULT
Task Deleted : System Speedup_UPDATES
Task Deleted : 04ad598b-58cd-4f03-b98e-b3c5f4644c88
Task Deleted : 168cbf18-2f0d-45ee-b6f5-0f0dadeaed1b
Task Deleted : 1f9b8f90-1af6-4b0b-a30f-1030355130f6
Task Deleted : 2e285cdc-9a8c-487e-b175-1ea421193c1c
Task Deleted : 3ec41624-2dfc-41f0-9870-dea8ccf47080
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-1
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-10
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-11
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-2
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-3
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-4
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-5
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-5_user
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-6
Task Deleted : 7224874c-abb1-4c05-9a66-3cf7ce5de459-7
Task Deleted : 8eb9f0b5-33fb-4900-9e48-a51e8b285af3-1
Task Deleted : 8eb9f0b5-33fb-4900-9e48-a51e8b285af3-11
Task Deleted : 8eb9f0b5-33fb-4900-9e48-a51e8b285af3-2
Task Deleted : 8eb9f0b5-33fb-4900-9e48-a51e8b285af3-3
Task Deleted : 8eb9f0b5-33fb-4900-9e48-a51e8b285af3-4
Task Deleted : 8eb9f0b5-33fb-4900-9e48-a51e8b285af3-5
Task Deleted : 8eb9f0b5-33fb-4900-9e48-a51e8b285af3-5_user
Task Deleted : 8eb9f0b5-33fb-4900-9e48-a51e8b285af3-6
Task Deleted : 8eb9f0b5-33fb-4900-9e48-a51e8b285af3-7
Task Deleted : a2c088cc-0df7-4ac2-98c9-2abf739bf307-1
Task Deleted : a2c088cc-0df7-4ac2-98c9-2abf739bf307-11
Task Deleted : a2c088cc-0df7-4ac2-98c9-2abf739bf307-2
Task Deleted : a2c088cc-0df7-4ac2-98c9-2abf739bf307-4
Task Deleted : a2c088cc-0df7-4ac2-98c9-2abf739bf307-5
Task Deleted : a2c088cc-0df7-4ac2-98c9-2abf739bf307-5_user
Task Deleted : a2c088cc-0df7-4ac2-98c9-2abf739bf307-6
Task Deleted : a2c088cc-0df7-4ac2-98c9-2abf739bf307-7
Task Deleted : b65d9fac-61af-4338-9f83-bbaa387016c2-1
Task Deleted : b65d9fac-61af-4338-9f83-bbaa387016c2-11
Task Deleted : b65d9fac-61af-4338-9f83-bbaa387016c2-2
Task Deleted : b65d9fac-61af-4338-9f83-bbaa387016c2-3
Task Deleted : b65d9fac-61af-4338-9f83-bbaa387016c2-4
Task Deleted : b65d9fac-61af-4338-9f83-bbaa387016c2-5
Task Deleted : b65d9fac-61af-4338-9f83-bbaa387016c2-5_user
Task Deleted : b65d9fac-61af-4338-9f83-bbaa387016c2-6
Task Deleted : b65d9fac-61af-4338-9f83-bbaa387016c2-7
Task Deleted : dd746b4b-eb86-4e8b-95f3-443c16169913
Task Deleted : df0d5087-c9b5-478e-bab3-688d503ae477-1
Task Deleted : df0d5087-c9b5-478e-bab3-688d503ae477-11
Task Deleted : df0d5087-c9b5-478e-bab3-688d503ae477-2
Task Deleted : df0d5087-c9b5-478e-bab3-688d503ae477-3
Task Deleted : df0d5087-c9b5-478e-bab3-688d503ae477-4
Task Deleted : df0d5087-c9b5-478e-bab3-688d503ae477-5
Task Deleted : df0d5087-c9b5-478e-bab3-688d503ae477-5_user
Task Deleted : df0d5087-c9b5-478e-bab3-688d503ae477-6
Task Deleted : df0d5087-c9b5-478e-bab3-688d503ae477-7
Task Deleted : e8ac9b4c-8cba-419d-95e3-446685b620a0
Task Deleted : bench-S-1-5-21-1532286876-4214409793-2116150237-1001

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\jenny_000\Desktop\Search.lnk

***** [ Registry ] *****

Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{8A9386B4-E958-4C4C-ADF4-8F26DB3E4829}]
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{750DEC7E-197B-E198-7E0F-B0BDD1C1B41E}]
Key Deleted : HKCU\Software\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
Key Deleted : HKCU\Software\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Driver Pro]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\HomeTab.DLL
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.bho
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.Band
Key Deleted : HKLM\SOFTWARE\Classes\wtb.Band.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.NotificationSource
Key Deleted : HKLM\SOFTWARE\Classes\wtb.NotificationSource.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl
Key Deleted : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo
Key Deleted : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo.1
Key Deleted : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.bench.nmhost
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updatewebget_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updatewebget_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilwebget_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilwebget_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\webget_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\webget_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [AnyProtect Scanner]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Bench Communicator Watcher]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Bench Settings Cleaner]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BlockAndSurf]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BService]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Wd]
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [fst_gb_94]
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0052924.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0052924.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0052924.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0052924.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061754.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061754.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061754.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061754.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061787.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061787.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061787.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061787.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061799.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061799.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061799.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061799.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061806.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061806.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061806.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061806.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2B47855E-B429-4DF6-8293-E1DBF2381A07}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8E56A02B-46FE-4490-B169-F16E5231533B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511291124}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171154}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171187}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171199}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611181106}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522292224}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172254}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172287}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172299}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622182206}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4D189E2B-C945-586D-0219-F26D11EDD9A9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555295524}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175554}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175599}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655185506}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566296624}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176654}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176687}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176699}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666186606}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544294424}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644174454}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644174487}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644174499}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644184406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E56A02B-46FE-4490-B169-F16E5231533B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511291124}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171154}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171187}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611181106}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D189E2B-C945-586D-0219-F26D11EDD9A9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1631550F-191D-4826-B069-D9439253D926}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E56A02B-46FE-4490-B169-F16E5231533B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511291124}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611171154}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611171187}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611171199}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611181106}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E56A02B-46FE-4490-B169-F16E5231533B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{2B47855E-B429-4DF6-8293-E1DBF2381A07}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{8E56A02B-46FE-4490-B169-F16E5231533B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511291124}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171154}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171187}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171199}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611181106}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522292224}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172254}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172287}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172299}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622182206}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4D189E2B-C945-586D-0219-F26D11EDD9A9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555295524}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175554}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175587}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175599}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655185506}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566296624}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176654}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176687}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176699}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666186606}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E56A02B-46FE-4490-B169-F16E5231533B}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511291124}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171154}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171187}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171199}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611181106}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D189E2B-C945-586D-0219-F26D11EDD9A9}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Deleted : HKCU\Software\AnyProtect
Key Deleted : HKCU\Software\Driver Pro
Key Deleted : HKCU\Software\FreeSoftToday
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\HomeTab
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Nosibay
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\Proxy
Key Deleted : HKCU\Software\simplytech
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\smartbarbackup
Key Deleted : HKCU\Software\smartbarlog
Key Deleted : HKCU\Software\Speedial
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\System Speedup
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\Tutorials
Key Deleted : HKCU\Software\TutoTag
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\webget
Key Deleted : HKCU\Software\AppDataLow\Software\blockAndSurf
Key Deleted : HKCU\Software\AppDataLow\Software\Browsers Apps
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong2
Key Deleted : HKCU\Software\AppDataLow\Software\Re_Markable
Key Deleted : HKCU\Software\AppDataLow\Software\simplytech
Key Deleted : HKCU\Software\AppDataLow\Software\Free Video Grabber  6.6
Key Deleted : HKCU\Software\AppDataLow\Software\HQualityPro-1.6
Key Deleted : HKCU\Software\AppDataLow\Software\SmartSaver+ 3
Key Deleted : HKCU\Software\AppDataLow\Software\videos MediaPlay-Air
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\Bench
Key Deleted : HKLM\SOFTWARE\Browsers Apps
Key Deleted : HKLM\SOFTWARE\FreeSoftToday
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstallCore
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\Proxy
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKLM\SOFTWARE\System Speedup
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\Tutorials
Key Deleted : HKLM\SOFTWARE\Free Video Grabber  6.6
Key Deleted : HKLM\SOFTWARE\HQualityPro-1.6
Key Deleted : HKLM\SOFTWARE\SmartSaver+ 3
Key Deleted : HKLM\SOFTWARE\videos MediaPlay-Air
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browsers Apps
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PriceGong2
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\System Speedup_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\fst_gb_94_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Free Video Grabber  6.6
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HQualityPro-1.6
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartSaver+ 3
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\videos MediaPlay-Air
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\982D51C7-90CE-4197-7EF1-C31168B3CAE0
Key Deleted : [x64] HKLM\SOFTWARE\Browsers Apps
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\videos MediaPlay-Air
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17239

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl []
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl []
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v36.0.1985.125

[ File : C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Extension] : bakijjialdiiboeaknfpmflphhmljfkd
Deleted [Extension] : bkomkajifikmkfnjgphkjcfeepbnojok
Deleted [Extension] : lnpoeccdlikfebbglldlokpnghpmdnfa
Deleted [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma

*************************

AdwCleaner[R0].txt - [47614 octets] - [19/08/2014 20:26:49]
AdwCleaner[R1].txt - [47675 octets] - [19/08/2014 20:32:24]
AdwCleaner[S0].txt - [41850 octets] - [19/08/2014 20:33:56]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [41911 octets] ##########

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 19/08/2014
Scan Time: 20:39:55
Logfile: Log1.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.03.04.09
Rootkit Database: v2014.02.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: jenny_000

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 239787
Time Elapsed: 12 min, 19 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 2
PUP.Optional.SmartSaver.A, HKLM\SOFTWARE\SmartSaver+ 3-nv, Quarantined, [f55415ea7bff95a177be048a738f966a],
PUP.Optional.SmartSaver.A, HKLM\SOFTWARE\WOW6432NODE\SmartSaver+ 3-nv, Quarantined, [10398d72ff7b9e9876bf721c0002a65a],

Registry Values: 0
(No malicious items detected)

Registry Data: 2
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-1532286876-4214409793-2116150237-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), http://search.certified-toolbar.com?si=77302&st=bs&tid=18145&ver=5.7&ts=1408273292886&tguid=77302-18145-1408273292886-3A2512842838484CBC6C226941374F9E&q=%s, Good: (http://www.google.com), Bad: (http://search.certified-toolbar.com?si=77302&st=bs&tid=18145&ver=5.7&ts=1408273292886&tguid=77302-18145-1408273292886-3A2512842838484CBC6C226941374F9E&q=%s),Replaced,[dd6c0cf3ee8c95a1d233af8136cea15f]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-1532286876-4214409793-2116150237-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI, http://search.certified-toolbar.com?si=77302&st=bs&tid=18145&ver=6.7&ts=1408230000000.000000&tguid=77302-18145-1408273292886-3A2512842838484CBC6C226941374F9E&q=%s, Good: (http://www.google.com), Bad: (http://search.certified-toolbar.com?si=77302&st=bs&tid=18145&ver=6.7&ts=1408230000000.000000&tguid=77302-18145-1408273292886-3A2512842838484CBC6C226941374F9E&q=%s),Replaced,[1e2b24dbfc7e3df98283eb4562a2cc34]

Folders: 1
PUP.Optional.PriceGong.A, C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok, Quarantined, [e069639c7ffb072fa2797219bb47ab55],

Files: 3
PUP.Optional.OptimumInstaller.A, C:\Users\jenny_000\Downloads\Java_Updater_Setup.exe, Quarantined, [61e83fc07dfd60d6b5fcb9d6867bb54b],
PUP.Optional.BubbleDock.A, C:\Users\Public\BDD95AF9D6BC4DCF9B47AA9E8574E5A8\Install_BubbleDock.exe, Quarantined, [88c15fa06f0bfd39334e304c9d64619f],
PUP.Optional.SmartBar.A, C:\Windows\Installer\371d126f.msi, Quarantined, [60e9e11eceac979fcef0354067991de3],

Physical Sectors: 0
(No malicious items detected)


(end)

Results of screen317's Security Check version 0.99.87 
   x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````[/u]
 Windows Firewall Enabled! 
Windows Defender   
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````[/u]
  Adobe Flash Player    11.9.900.170 Flash Player out of Date! 
 Adobe Reader XI 
 Google Chrome 36.0.1985.125 
````````Process Check: objlist.exe by Laurent````````[/u] 
 Windows Defender MSMpEng.exe
`````````````````System Health check`````````````````[/u]
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````[/u]
Title: Re: My mums computer is infected
Post by: SuperDave on August 19, 2014, 04:11:14 PM
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this  (http://www.bleepingcomputer.com/forums/topic114351.html) link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
**********************************************
Update your Adobe Reader. get.adobe.com/reader (http://get.adobe.com/reader/).

Be sure to uncheck the Free McAfee Security Scan so it isn't installed.

***********************************************
Malwarebytes' Anti-Rootkit

Please download Malwarebytes' Anti-Rootkit (http://www.malwarebytes.org/products/mbar/) and save it to your desktop.
Title: Re: My mums computer is infected
Post by: 007will on August 20, 2014, 10:56:18 AM
Hi thanks for your help. I ran both programs but it only produced a log for the first. When i ran the second it said no malware found.

Here's the log from the first one.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by jenny_000 on 20/08/2014 at 13:23:12.51
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611171162}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C9A5694B-EE87-498D-8214-B99EBDF02C2B}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8b617b00-279e-42ff-beac-1f7a8f41ca13}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{8b617b00-279e-42ff-beac-1f7a8f41ca13}



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20/08/2014 at 13:31:05.89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Title: Re: My mums computer is infected
Post by: SuperDave on August 20, 2014, 04:55:18 PM
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
 ESET OnlineScan (http://eset.com/onlinescan)

•Click the (http://i424.photobucket.com/albums/pp322/digistar/esetOnline.png) button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Check (http://i424.photobucket.com/albums/pp322/digistar/esetAcceptTerms.png)
•Click the (http://i424.photobucket.com/albums/pp322/digistar/esetStart.png) button.
•Accept any security warnings from your browser.
•Check (http://i424.photobucket.com/albums/pp322/digistar/esetScanArchives.png)
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push (http://i424.photobucket.com/albums/pp322/digistar/esetListThreats.png)
•Push (http://i424.photobucket.com/albums/pp322/digistar/esetExport.png), and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the (http://i424.photobucket.com/albums/pp322/digistar/esetBack.png) button.
•Push (http://i424.photobucket.com/albums/pp322/digistar/esetFinish.png)
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Title: Re: My mums computer is infected
Post by: 007will on August 21, 2014, 02:54:04 PM
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\df0d5087-c9b5-478e-bab3-688d503ae477-11.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\df0d5087-c9b5-478e-bab3-688d503ae477-2.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\df0d5087-c9b5-478e-bab3-688d503ae477-3.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\df0d5087-c9b5-478e-bab3-688d503ae477-4.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\df0d5087-c9b5-478e-bab3-688d503ae477-5.exe.vir   a variant of Win32/Toolbar.CrossRider.AH potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\df0d5087-c9b5-478e-bab3-688d503ae477-6.exe.vir   a variant of Win32/Toolbar.CrossRider.AE potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\df0d5087-c9b5-478e-bab3-688d503ae477-64.exe.vir   a variant of Win64/Toolbar.Crossrider.I potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\df0d5087-c9b5-478e-bab3-688d503ae477-7.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\videos MediaPlay-Air-bg.exe.vir   a variant of Win32/Toolbar.CrossRider.AL potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\videos MediaPlay-Air-bho.dll.vir   a variant of Win32/Toolbar.CrossRider.AF potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\videos MediaPlay-Air-bho64.dll.vir   a variant of Win64/Toolbar.Crossrider.F potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\videos MediaPlay-Air-codedownloader.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   
C:\AdwCleaner\Quarantine\C\ProgramData\DSearchLink\DSearchLink.exe.vir   Win32/Toolbar.Babylon.Y potentially unwanted application   
C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir   Win32/ELEX.AV potentially unwanted application   
C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir   a variant of Win32/ELEX.AM potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\fst_gb_94\upfst_gb_94.exe.vir   a variant of Win32/Adware.EoRezo.AJ application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\fst_gb_94\Download\majfst_gentlegb.exe.vir   Win32/AdWare.EoRezo.AW application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.14_0\options\pg_options.js.vir   Win32/PriceGong.B potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.14_0\plugins\npPriceGong_CH.dll.vir   a variant of Win32/PriceGong.A potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\LPT\sppsm.dll.vir   a variant of MSIL/Toolbar.Linkury.G potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\LPT\spusm.dll.vir   a variant of MSIL/Toolbar.Linkury.G potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\LPT\srbu.dll.vir   a variant of MSIL/Toolbar.Linkury.F potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\LPT\srptc.dll.vir   a variant of MSIL/Toolbar.Linkury.G potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll.vir   a variant of MSIL/Toolbar.Linkury.E potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll.vir   a variant of MSIL/Toolbar.Linkury.E potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll.vir   a variant of MSIL/Toolbar.Linkury.D potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir   a variant of MSIL/Toolbar.Linkury.D potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\spbl.dll.vir   a variant of MSIL/Toolbar.Linkury.G potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\sppsm.dll.vir   a variant of MSIL/Toolbar.Linkury.G potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\spusm.dll.vir   a variant of MSIL/Toolbar.Linkury.G potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\srbu.dll.vir   a variant of MSIL/Toolbar.Linkury.F potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir   Win32/Toolbar.Linkury.D potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\[email protected]\components\SmartbarFireFoxRemotePlugin_26.dll.vir   a variant of Win32/Toolbar.Linkury.D potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\[email protected]\components\SmartbarFireFoxRemotePlugin_27.dll.vir   a variant of Win32/Toolbar.Linkury.D potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\[email protected]\components\SmartbarFireFoxRemotePlugin_28.dll.vir   a variant of Win32/Toolbar.Linkury.D potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\[email protected]\components\SmartbarFireFoxRemotePlugin_29.dll.vir   a variant of Win32/Toolbar.Linkury.D potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\[email protected]\components\SmartbarFireFoxRemotePlugin_30.dll.vir   a variant of Win32/Toolbar.Linkury.D potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\Smartbar\Application\[email protected]\components\SmartbarFireFoxRemotePlugin_31.dll.vir   a variant of Win32/Toolbar.Linkury.D potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\torch\User Data\Default\Extensions\ekpibplnnkfdcafdpoekhoffegcajene\1.26.14_0\extensionData\plugins\91.js.vir   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\torch\User Data\Default\Extensions\ffhfoagmjcnkolneahbpagjcjjaeofbg\1.26.17_0\extensionData\plugins\91.js.vir   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\torch\User Data\Default\Extensions\hgheonmabinoadcfoneehgpdflbdcjpk\1.26.62_0\extensionData\plugins\91.js.vir   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\torch\User Data\Default\Extensions\iklgpchfbohgmghgfagediakopecfmbm\1.26.67_0\extensionData\plugins\91.js.vir   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Local\torch\User Data\Default\Extensions\pgdilnhhbhcfnpmmekljhmacnmamkdio\1.26.12_0\extensionData\plugins\91.js.vir   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Roaming\1H1Q\Open Office Packages\uninstaller.exe.vir   Win32/InstallCore.PC potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Roaming\Speedial\UpdateProc\UpdateTask.exe.vir   a variant of Win32/DealPly.S potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Roaming\Systweak\ssd\SSDPTstub.exe.vir   Win32/Systweak.G potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Roaming\VOPackage\runasu.exe.vir   a variant of Win32/VOPackage.R potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Roaming\VOPackage\Uninstall.exe.vir   Win32/VOPackage.S potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Roaming\VOPackage\VOPackage.exe.vir   Win32/VOPackage.U potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Users\jenny_000\AppData\Roaming\VOPackage\VOsrv.exe.vir   a variant of Win32/VOPackage.S potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Windows\System32\sasnative64.exe.vir   Win64/AdvancedSystemProtector.A potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Windows\System32\drivers\webinstr.sys.vir   Win64/Adware.AddLyrics.A application   
C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekpibplnnkfdcafdpoekhoffegcajene\1.26.14_0\extensionData\plugins\91.js   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffhfoagmjcnkolneahbpagjcjjaeofbg\1.26.17_0\extensionData\plugins\91.js   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgheonmabinoadcfoneehgpdflbdcjpk\1.26.62_0\extensionData\plugins\91.js   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\iklgpchfbohgmghgfagediakopecfmbm\1.26.67_0\extensionData\plugins\91.js   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\Users\jenny_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnanplinmmnjhobaliikmelmmjpoogkb\1.26.21_0\extensionData\plugins\91.js   JS/Toolbar.Crossrider.B potentially unwanted application   
C:\Users\jenny_000\AppData\Local\Microsoft\Windows\INetCache\IE\VT0ZO0N2\Setup[1].exe   a variant of Win32/InstallCore.PK potentially unwanted application   
C:\Users\jenny_000\AppData\Local\onlysearch\onlysearch\1.3.8.11\onlysearch.exe   a variant of Win32/Toolbar.Montiera.L potentially unwanted application   
C:\Users\jenny_000\AppData\Local\Temp\ICReinstall_nsr47CB.tmp   a variant of Win32/InstallCore.PK potentially unwanted application   
C:\Users\jenny_000\AppData\Local\Temp\nsr47CB.tmp   a variant of Win32/InstallCore.PK potentially unwanted application   
C:\Users\jenny_000\Downloads\ChromeSetup (1).exe   a variant of Win32/SoftPulse.H potentially unwanted application   
C:\Users\jenny_000\Downloads\ChromeSetup.exe   a variant of Win32/SoftPulse.H potentially unwanted application   
C:\Users\jenny_000\Downloads\Open OfficeSetup.exe   a variant of Win32/InstallCore.JO potentially unwanted application   
C:\Users\jenny_000\Downloads\Player (1).exe   a variant of Win32/SoftPulse.H potentially unwanted application   
C:\Users\jenny_000\Downloads\Player (2).exe   a variant of Win32/SoftPulse.H potentially unwanted application   
C:\Users\jenny_000\Downloads\Player (3).exe   a variant of Win32/SoftPulse.H potentially unwanted application   
C:\Users\jenny_000\Downloads\Player.exe   a variant of Win32/SoftPulse.H potentially unwanted application   
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\AdvancedSystemProtector.exe.vir   MSIL/AdvancedSystemProtector.E potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\AspManager.exe.vir   a variant of MSIL/AdvancedSystemProtector.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\Communication.dll.vir   Win32/Systweak.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\filetypehelper.exe.vir   a variant of MSIL/AdvancedSystemProtector.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\scandll.dll.vir   a variant of MSIL/AdvancedSystemProtector.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ASP\SSDPTstub.exe.vir   Win32/Systweak.G potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\168cbf18-2f0d-45ee-b6f5-0f0dadeaed1b.exe.vir   a variant of Win32/Toolbar.CrossRider.AG potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\568a07d5-0c1b-4e9a-862b-b7eb79dacdfd.dll.vir   a variant of Win32/Toolbar.CrossRider.AI potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\b65d9fac-61af-4338-9f83-bbaa387016c2-11.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\b65d9fac-61af-4338-9f83-bbaa387016c2-2.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\b65d9fac-61af-4338-9f83-bbaa387016c2-3.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\b65d9fac-61af-4338-9f83-bbaa387016c2-4.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\b65d9fac-61af-4338-9f83-bbaa387016c2-5.exe.vir   a variant of Win32/Toolbar.CrossRider.AH potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\b65d9fac-61af-4338-9f83-bbaa387016c2-6.exe.vir   a variant of Win32/Toolbar.CrossRider.AE potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\b65d9fac-61af-4338-9f83-bbaa387016c2-64.exe.vir   a variant of Win64/Toolbar.Crossrider.I potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\b65d9fac-61af-4338-9f83-bbaa387016c2-7.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\Browsers Apps-bg.exe.vir   a variant of Win32/Toolbar.CrossRider.AL potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\Browsers Apps-bho.dll.vir   a variant of Win32/Toolbar.CrossRider.AF potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\Browsers Apps-bho64.dll.vir   a variant of Win64/Toolbar.Crossrider.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsers Apps\Browsers Apps-codedownloader.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\04ad598b-58cd-4f03-b98e-b3c5f4644c88.exe.vir   a variant of Win32/Toolbar.CrossRider.AG potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\a2c088cc-0df7-4ac2-98c9-2abf739bf307-11.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\a2c088cc-0df7-4ac2-98c9-2abf739bf307-2.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\a2c088cc-0df7-4ac2-98c9-2abf739bf307-4.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\a2c088cc-0df7-4ac2-98c9-2abf739bf307-5.exe.vir   a variant of Win32/Toolbar.CrossRider.AH potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\a2c088cc-0df7-4ac2-98c9-2abf739bf307-6.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\a2c088cc-0df7-4ac2-98c9-2abf739bf307-64.exe.vir   a variant of Win64/Toolbar.Crossrider.I potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\a2c088cc-0df7-4ac2-98c9-2abf739bf307-7.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\ca638c4c-fc20-44a3-858e-f2bd67334b5b.dll.vir   a variant of Win32/Toolbar.CrossRider.AI potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\Free Video Grabber  6.6-bg.exe.vir   a variant of Win32/Toolbar.CrossRider.AL potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\Free Video Grabber  6.6-bho.dll.vir   a variant of Win32/Toolbar.CrossRider.AF potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\Free Video Grabber  6.6-bho64.dll.vir   a variant of Win64/Toolbar.Crossrider.I potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Free Video Grabber  6.6\Free Video Grabber  6.6-codedownloader.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_gb_94\freeSoftToday_widget.exe.vir   a variant of Win32/AdWare.EoRezo.AU application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_gb_94\fst_gb_94.exe.vir   a variant of Win32/AdWare.EoRezo.AU application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\7224874c-abb1-4c05-9a66-3cf7ce5de459-10.exe.vir   a variant of Win32/Toolbar.CrossRider.AG potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\7224874c-abb1-4c05-9a66-3cf7ce5de459-2.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\7224874c-abb1-4c05-9a66-3cf7ce5de459-3.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\7224874c-abb1-4c05-9a66-3cf7ce5de459-4.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\7224874c-abb1-4c05-9a66-3cf7ce5de459-5.exe.vir   a variant of Win32/Toolbar.CrossRider.AH potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\HQualityPro-1.6-bg.exe.vir   a variant of Win32/Toolbar.CrossRider.AL potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\HQualityPro-1.6-bho.dll.vir   a variant of Win32/Toolbar.CrossRider.AF potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\HQualityPro-1.6-bho64.dll.vir   a variant of Win64/Toolbar.Crossrider.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\HQualityPro-1.6-codedownloader.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\HQualityPro-1.6-nova.dll.vir   a variant of Win32/Toolbar.CrossRider.AI potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\HQualityPro-1.6-nova.exe.vir   a variant of Win32/Toolbar.CrossRider.AE potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQualityPro-1.6\HQualityPro-1.6-novainstaller.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\PriceGong2\2.6.14\PriceGong2IE.dll.vir   a variant of Win32/PriceGong.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\PriceGong2\2.6.14\FF\plugins\npPriceGong_FF.dll.vir   a variant of Win32/PriceGong.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\8eb9f0b5-33fb-4900-9e48-a51e8b285af3-11.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\8eb9f0b5-33fb-4900-9e48-a51e8b285af3-2.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\8eb9f0b5-33fb-4900-9e48-a51e8b285af3-3.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\8eb9f0b5-33fb-4900-9e48-a51e8b285af3-4.exe.vir   a variant of Win32/Toolbar.CrossRider.AK potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\8eb9f0b5-33fb-4900-9e48-a51e8b285af3-5.exe.vir   a variant of Win32/Toolbar.CrossRider.AH potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\8eb9f0b5-33fb-4900-9e48-a51e8b285af3-6.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\8eb9f0b5-33fb-4900-9e48-a51e8b285af3-64.exe.vir   a variant of Win64/Toolbar.Crossrider.I potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\8eb9f0b5-33fb-4900-9e48-a51e8b285af3-7.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\a9e5bdca-3ae6-4271-a6c0-8c46c1c5ec0f.dll.vir   a variant of Win32/Toolbar.CrossRider.AI potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\SmartSaver+ 3-bg.exe.vir   a variant of Win32/Toolbar.CrossRider.AL potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\SmartSaver+ 3-bho.dll.vir   a variant of Win32/Toolbar.CrossRider.AF potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\SmartSaver+ 3-bho64.dll.vir   a variant of Win64/Toolbar.Crossrider.I potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SmartSaver+ 3\SmartSaver+ 3-codedownloader.exe.vir   a variant of Win32/Toolbar.CrossRider.AJ potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir   Win32/Thinknice.E potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface64.dll.vir   Win64/Thinknice.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\HpUI.exe.vir   Win32/Thinknice.E potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader32.exe.vir   Win32/Thinknice.E potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader64.exe.vir   Win64/Thinknice.E potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir   Win32/ELEX.AV potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect32.dll.vir   Win32/Thinknice.E potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect64.dll.vir   Win64/Thinknice.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe.vir   Win32/ELEX.AV potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir   Win32/Thinknice.B potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\uninstall.exe.vir   Win32/Thinknice.E potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\WindowsSupportDll32.dll.vir   Win32/Thinknice.E potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\WindowsSupportDll64.dll.vir   Win64/Thinknice.D potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\System Speedup\systweakasp.exe.vir   Win32/Systweak.E potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver3BlockAndSurf\177.dll.vir   a variant of Win32/AdWare.AddLyrics.BL application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver3BlockAndSurf\d8BlockAndSurfMl177.exe.vir   a variant of Win32/AdWare.AddLyrics.BK application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver3BlockAndSurf\Uninstall.exe.vir   a variant of Win32/AdWare.AddLyrics.BJ application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver3BlockAndSurf\x64\TandemRunner.exe.vir   Win64/Adware.AddLyrics.A application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver3BlockAndSurf\x64\webinstr.sys.vir   Win64/Adware.AddLyrics.A application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver3BlockAndSurf\x86\TandemRunner.exe.vir   a variant of Win32/AdWare.AddLyrics.BJ application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver3BlockAndSurf\x86\webinstr.sys.vir   Win32/AdWare.AddLyrics.BJ application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\videos MediaPlay-Air\2007eb72-4365-455c-ba65-e6a2f81b5201.dll.vir   a variant of Win32/Toolbar.CrossRider.AI potentially unwanted application   deleted - quarantined
Operating memory   a variant of Win32/Toolbar.Montiera.L potentially unwanted application   contained infected files
Title: Re: My mums computer is infected
Post by: SuperDave on August 21, 2014, 07:18:14 PM
Most of that stuff was already quarantined. How's your computer running now? Any other issues?
Title: Re: My mums computer is infected
Post by: 007will on August 22, 2014, 05:23:46 AM
Well Internet Explorer doesn't seem to work? Don't know if a separate issue...
Title: Re: My mums computer is infected
Post by: SuperDave on August 22, 2014, 12:50:09 PM
Well Internet Explorer doesn't seem to work? Don't know if a separate issue...
What happens when you try to open it?
Title: Re: My mums computer is infected
Post by: 007will on August 23, 2014, 05:11:02 AM
It does nothing. No message or anything just does open at all. I have been trying to use google chrome to do this but that is very slow and may at times become unresponsive.
Title: Re: My mums computer is infected
Post by: SuperDave on August 23, 2014, 04:56:19 PM
Please try the SFC command as instructed in this link. (http://www.eightforums.com/tutorials/3047-sfc-scannow-command-run-windows-8-a.html)