JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows Vista Home Premium x64
Ran by karen hastings on Sun 06/30/2013 at 13:35:29.67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\cr_installer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\freeze.com
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\pc optimizer pro
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\surf canyon
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\zugo
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\pricegong
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT2612669
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BF5CDBD7-EC78-41F8-A1B1-01829572104D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
~~~ Files
Successfully deleted [File] C:\Windows\svchost.exe [Check for TDL4 Rootkit!]
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\fighters"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\ProgramData\wecarereminder"
Successfully deleted: [Folder] "C:\Users\karen hastings\AppData\Roaming\fighters"
Successfully deleted: [Folder] "C:\Users\karen hastings\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\karen hastings\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\free offers from freeze.com"
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{0559D804-F08E-49CF-B8ED-ACFB11B88207}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{0F8FCEC9-4EDB-4C4F-B9F6-2BE507154869}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{1DB04C60-160C-4385-970C-65202C2C9D03}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{300E8C7B-B967-4E7A-9B61-257E3904A3AD}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{34FCEEE6-7F01-4A82-89D1-8AB07C9F9D2D}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{64F83BA5-2BF4-4F3B-B9BE-869F2CE49B6A}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{7DEA55D7-7618-401E-A783-3D93C5DFC0E4}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{88E1CD2A-ADB5-422C-A7BE-DD6385A90CC5}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{8BD36CFD-152A-4415-8998-94A8EA4E2BF7}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{8D4CE712-8F9A-471C-91C2-93D96A6E97AE}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{997C3A25-4DFB-4749-8786-D4680CEFB900}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{9A31E02E-B1AF-4ED9-9087-AC3794BE0BB0}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{9E4CA768-DD53-4F2E-A03F-0E4C43B42DF8}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{B37FCBF4-94AA-41F9-AC50-991848597953}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{BAC8216E-059B-42D5-B05B-7A0C52394B7F}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{C1AD4DB2-91CE-42B3-AB06-E4095430B9F5}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{CB923DAE-70B9-4EC7-8A4B-207F65F133EF}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{EFAD7B83-61C6-45A2-9015-1C99B78721A1}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{F96EB297-D5AF-488E-AEDB-20BEC686C19D}
Successfully deleted: [Empty Folder] C:\Users\karen hastings\appdata\local\{FE88FBBE-E25B-44C9-8323-A25445AB0A88}
Successfully deleted: [Folder] "C:\ProgramData\ask"
~~~ FireFox
Successfully deleted: [File] C:\Users\karen hastings\AppData\Roaming\mozilla\firefox\profiles\f8fx7ukf.default\extensions\[email protected] [Tracur]
Emptied folder: C:\Users\karen hastings\AppData\Roaming\mozilla\firefox\profiles\f8fx7ukf.default\minidumps [208 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 06/30/2013 at 13:40:38.47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AdwcCleaner log
# AdwCleaner v2.303 - Logfile created 06/30/2013 at 13:43:08
# Updated 08/06/2013 by Xplode
# Operating system : Windows Vista Home Premium Service Pack 2 (64 bits)
# User : karen hastings - TOMDELLSTUDIO
# Boot Mode : Normal
# Running from : C:\Users\karen hastings\Desktop\AdwCleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
***** [Registry] *****
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Tarma Installer
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16490
[OK] Registry is clean.
-\\ Mozilla Firefox v21.0 (en-US)
File : C:\Users\karen hastings\AppData\Roaming\Mozilla\Firefox\Profiles\f8fx7ukf.default\prefs.js
Deleted : user_pref("browser.newtabpage.blocked", "{\"bo4iF8X7cw640HqVn22zWg==\":1,\"Bfd7+tG331O7t9j+XXmwMw==\[...]
*************************
AdwCleaner[S1].txt - [2549 octets] - [30/06/2013 13:43:08]
########## EOF - C:\AdwCleaner[S1].txt - [2609 octets] ##########
Malwarebytes log 1
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.06.30.06
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
karen hastings :: TOMDELLSTUDIO [administrator]
Protection: Enabled
6/30/2013 1:50:58 PM
MBAM-log-2013-06-30 (14-05-49).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 216781
Time elapsed: 4 minute(s), 25 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKCR\AH (Rogue.MultipleAV) -> No action taken.
Registry Values Detected: 4
HKCU\SOFTWARE\Mozilla\Firefox\Extensions\{59A40AC9-E67D-4155-B31D-4B7330FCD2D6} (Trojan.Agent) -> Data: -> No action taken.
HKCU\SOFTWARE\Mozilla\Firefox\Extensions|{59A40AC9-E67D-4155-B31D-4B7330FCD2D6} (Trojan.Agent) -> Data: C:\Program Files (x86)\Outerinfo\FF\ -> No action taken.
HKCR\.exe\shell\open\command| (Hijack.ExeFile) -> Data: "C:\Users\karen hastings\AppData\Local\lsu.exe" -a "%1" %* -> No action taken.
HKCR\ah|Content Type (Rogue.MultipleAV) -> Data: application/x-msdownload -> No action taken.
Registry Data Items Detected: 2
HKCR\.exe| (Hijacked.exeFile) -> Bad: (vH4) Good: (exefile) -> No action taken.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Users\karen hastings\AppData\Local\lsu.exe" -a "C:\Program Files (x86)\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> No action taken.
Folders Detected: 3
C:\Program Files (x86)\Outerinfo (Adware.PurityScan) -> No action taken.
C:\Program Files (x86)\Outerinfo\FF (Adware.PurityScan) -> No action taken.
C:\Program Files (x86)\Outerinfo\FF\components (Adware.PurityScan) -> No action taken.
Files Detected: 5
C:\Program Files (x86)\Outerinfo\outerinfo.ico (Adware.PurityScan) -> No action taken.
C:\Program Files (x86)\Outerinfo\Terms.rtf (Adware.PurityScan) -> No action taken.
C:\Program Files (x86)\Outerinfo\FF\chrome.manifest (Adware.PurityScan) -> No action taken.
C:\Program Files (x86)\Outerinfo\FF\install.rdf (Adware.PurityScan) -> No action taken.
C:\Program Files (x86)\Outerinfo\FF\components\OuterinfoAds.xpt (Adware.PurityScan) -> No action taken.
(end)
Malwarebytes log 2
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.06.30.06
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
karen hastings :: TOMDELLSTUDIO [administrator]
Protection: Enabled
6/30/2013 1:50:58 PM
mbam-log-2013-06-30 (13-50-58).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 216781
Time elapsed: 4 minute(s), 25 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKCR\AH (Rogue.MultipleAV) -> Quarantined and deleted successfully.
Registry Values Detected: 4
HKCU\SOFTWARE\Mozilla\Firefox\Extensions\{59A40AC9-E67D-4155-B31D-4B7330FCD2D6} (Trojan.Agent) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Mozilla\Firefox\Extensions|{59A40AC9-E67D-4155-B31D-4B7330FCD2D6} (Trojan.Agent) -> Data: C:\Program Files (x86)\Outerinfo\FF\ -> Quarantined and deleted successfully.
HKCR\.exe\shell\open\command| (Hijack.ExeFile) -> Data: "C:\Users\karen hastings\AppData\Local\lsu.exe" -a "%1" %* -> Quarantined and deleted successfully.
HKCR\ah|Content Type (Rogue.MultipleAV) -> Data: application/x-msdownload -> Quarantined and deleted successfully.
Registry Data Items Detected: 2
HKCR\.exe| (Hijacked.exeFile) -> Bad: (vH4) Good: (exefile) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Users\karen hastings\AppData\Local\lsu.exe" -a "C:\Program Files (x86)\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and repaired successfully.
Folders Detected: 3
C:\Program Files (x86)\Outerinfo (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Outerinfo\FF (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Outerinfo\FF\components (Adware.PurityScan) -> Quarantined and deleted successfully.
Files Detected: 5
C:\Program Files (x86)\Outerinfo\outerinfo.ico (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Outerinfo\Terms.rtf (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Outerinfo\FF\chrome.manifest (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Outerinfo\FF\install.rdf (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Outerinfo\FF\components\OuterinfoAds.xpt (Adware.PurityScan) -> Quarantined and deleted successfully.
(end)