Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for Addon control

- - - - -

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Content is republished with permission from Malwarebytes.

What is Addon control?
 
The Malwarebytes research team has determined that Addon control is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.
 
How do I know if my computer is affected by Addon control?
 
You may see these browser extensions/add-ons:
 
warning1.png
 
warning2.png

warning3.png
 
and this entry in your list of installed programs:
 
warning4.png
 
 
How did Addon control get on my computer?
 
Browser hijackers use different methods for distributing themselves. This particular one was bundled with other software.
 
How do I remove Addon control?
 
Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Is there anything else I need to do to get rid of Addon control?
  • If you are using Opera, you may have to remove the Extension manually under Opera > Extensions click the x behind Addon control and click OK in the prompt to confirm.
How would the full version of Malwarebytes Anti-Malware help protect me?
 
We hope our application and this guide have helped you eradicate this hijacker.  
 
As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the Addon control hijacker.  It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late.
 
 

protection1.png


 
Technical details for experts
 
Signs in a HijackThis log:
  
 
O2 - BHO: CrossriderApp0063443 - {11111111-1111-1111-1111-110611341143} - C:\Program Files\Addon control\Addon control-bho.dll
 
Alterations made by the installer:
 
 
File system details  
---------------------------------------------
    Adds the folder C:\Program Files\Addon control
       Adds the file 1293297481.mxaddon"="8/14/2014 6:46 PM, 44330 bytes, A
       Adds the file 36348df0-01de-47c1-9664-9c5204b7f5d2.crx"="10/3/2014 8:29 AM, 258914 bytes, A
       Adds the file Addon control.ico"="9/11/2014 10:23 AM, 15086 bytes, A
       Adds the file Addon control-bg.exe"="10/3/2014 8:29 AM, 657256 bytes, A
       Adds the file Addon control-bho.dll"="10/3/2014 8:29 AM, 584552 bytes, A
       Adds the file Addon control-buttonutil.dll"="10/3/2014 8:29 AM, 382312 bytes, A
       Adds the file Addon control-buttonutil.exe"="10/3/2014 8:29 AM, 277352 bytes, A
       Adds the file Addon control-codedownloader.exe"="10/3/2014 8:29 AM, 1075560 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123.crx"="10/3/2014 8:29 AM, 257713 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123.xpi"="10/3/2014 8:29 AM, 299217 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-11.exe"="10/3/2014 8:29 AM, 1920360 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-2.exe"="10/3/2014 8:29 AM, 901992 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-4.exe"="10/3/2014 8:29 AM, 1479528 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-5.exe"="10/3/2014 8:29 AM, 980840 bytes, A
       Adds the file background.html"="9/11/2014 10:22 AM, 729 bytes, A
       Adds the file Uninstall.exe"="10/3/2014 8:29 AM, 103784 bytes, A
       Adds the file utils.exe"="10/3/2014 8:29 AM, 2563395 bytes, A
    Adds the folder C:\Users\{username}\AppData\LocalLow\Addon control
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]
       Adds the file chrome.manifest"="10/3/2014 8:29 AM, 498 bytes, A
       Adds the file install.rdf"="10/3/2014 8:29 AM, 1207 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\defaults
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\locale
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\iblkcjfaedgaaklafbjbieapaomjfnjk\1.26.15_0
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\iblkcjfaedgaaklafbjbieapaomjfnjk\1.26.15_0\extensionData
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\iblkcjfaedgaaklafbjbieapaomjfnjk\1.26.15_0\icons
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\iblkcjfaedgaaklafbjbieapaomjfnjk\1.26.15_0\js
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\iblkcjfaedgaaklafbjbieapaomjfnjk\1.26.15_0\js\lib\popupResource
       Adds the file newPopup.js"="10/3/2014 8:29 AM, 40 bytes, A
       Adds the file popup.js"="10/3/2014 8:29 AM, 45 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-1"="10/3/2014 8:29 AM, 5786 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-11"="10/3/2014 8:29 AM, 7512 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-2"="10/3/2014 8:29 AM, 5126 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-5"="10/3/2014 8:29 AM, 5462 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-5_user"="10/3/2014 8:29 AM, 5468 bytes, A
    In the existing folder C:\Windows\Tasks
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-1.job"="10/3/2014 8:29 AM, 2756 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-11.job"="10/3/2014 8:29 AM, 4482 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-2.job"="10/3/2014 8:29 AM, 2096 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-5.job"="10/3/2014 8:29 AM, 2432 bytes, A
       Adds the file b9a95d99-27d2-4284-8627-f487b3258123-5_user.job"="10/3/2014 8:29 AM, 2432 bytes, A

Registry details  
------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Addon control\AkVpO8uesSBC7ayL0Y8Ck8IO/T8cMmwHNqdh/Wegkxjpn0DnzavY/+qBr+Gw3xFhztaieZMydmpOLCdsstqrfSPXV+YCPVK+6mUDWyg3b57jmClUYOP41aufNoGIiw/tK9Px2uvdOYHvsaMcJqISOqdA069gUcwg2sS/zM1t8QQ=]
       "D0uo9UTpZtdw4hYJeqqi/Wo65lCZj/XTiYgbkfD5sosEGAoy1FMvA/HyFnogJcMfltsMnOqW8dqGMAx7fHlhL/+F1nYw10XLo/usbu4lJZL8tfQZ3yiidZDvXJbdV4F2ZFVxsNvYKqRhWEmsL3P/J4GALLWxoFrV1ubZtiYkduo="="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Addon control\Firefox]
       "TotalProfiles"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Addon control\Firefox\Profiles]
       "C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Addon control\IE]
       "TotalProfiles"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Addon control\IE\Profiles]
       "S-1-5-21-4016700205-1717049133-1125222536-1001"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Addon control\Installer]
       "BundledAddCh"="REG_DWORD", 1
       "BundledFirefox"="REG_DWORD", 1
       "BundledIe"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Addon control\oUALk3R+LgfgppNW0ywCOnug7/OVfOO+AVS3Vdz7HXd+4hXlf4wKJhvx5ZmOeidL/0URRt7nfDNDzS1w27PlcgAdNrfoiwGhm06rADWyjwOJvnvZ5NO5HBBAKNVfryvTlCq8thV3m6k/eKTjI5kVCaDTg8ShK3+c62oM++VpDS4=]
       "K8+gzBIFZysMi2/Uk5OHT6c1JQxtjSEsiVATKiYJrViq9boT1yIWTtOp1VmiRlXuY2mynY5qJAP+3Y7Plg41viaqB9xjVDbDEILm3XC+ZjvLEwnNbs5nDCa3R476iGRBsOY496+NmTbjw3Jk7yX4PuRZxiRVkegVpz3hf4AzPzo="="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341143}]
       "(Default)"="REG_SZ", "Addon control"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341143}\Implemented Categories]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341143}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341143}\InprocServer32]
       "(Default)"="REG_SZ", "C:\Program Files\Addon control\Addon control-bho.dll"
       "ThreadingModel"="REG_SZ", "Apartment"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341143}\ProgID]
       "(Default)"="REG_SZ", "CrossriderApp0063443.BHO.1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341143}\Programmable]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341143}\TypeLib]
       "(Default)"="REG_SZ", "{44444444-4444-4444-4444-440644344443}"]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341143}\VersionIndependentProgID
       "(Default)"="REG_SZ", "CrossriderApp0063443"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342243}]
       "(Default)"="REG_SZ", "CrossriderApp0063443.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342243}\InprocServer32]
       "(Default)"="REG_SZ", "C:\Program Files\Addon control\Addon control-bho.dll"
       "ThreadingModel"="REG_SZ", "Apartment"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342243}\ProgID]
       "(Default)"="REG_SZ", "CrossriderApp0063443.Sandbox.1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342243}\Programmable]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342243}\TypeLib]
       "(Default)"="REG_SZ", "{44444444-4444-4444-4444-440644344443}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342243}\VersionIndependentProgID]
       "(Default)"="REG_SZ", "CrossriderApp0063443.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.BHO]
       "(Default)"="REG_SZ", "CrossriderApp0063443"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.BHO\CLSID]
       "(Default)"="REG_SZ", "{11111111-1111-1111-1111-110611341143}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.BHO\CurVer]
       "(Default)"="REG_SZ", "CrossriderApp0063443"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.BHO.1]
       "(Default)"="REG_SZ", "CrossriderApp0063443"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.BHO.1\CLSID]
       "(Default)"="REG_SZ", "{11111111-1111-1111-1111-110611341143}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.Sandbox]
       "(Default)"="REG_SZ", "CrossriderApp0063443.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.Sandbox\CLSID]
       "(Default)"="REG_SZ", "{22222222-2222-2222-2222-220622342243}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.Sandbox\CurVer]
       "(Default)"="REG_SZ", "CrossriderApp0063443.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.Sandbox.1]
       "(Default)"="REG_SZ", "CrossriderApp0063443.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0063443.Sandbox.1\CLSID]
       "(Default)"="REG_SZ", "{22222222-2222-2222-2222-220622342243}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655345543}]
       "(Default)"="REG_SZ", "ICrossriderBHO"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655345543}\ProxyStubClsid]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655345543}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655345543}\TypeLib]
       "(Default)"="REG_SZ", "{44444444-4444-4444-4444-440644344443}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666346643}]
       "(Default)"="REG_SZ", "ISandBox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666346643}\ProxyStubClsid]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666346643}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666346643}\TypeLib]
       "(Default)"="REG_SZ", "{44444444-4444-4444-4444-440644344443}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644344443}\1.0]
       "(Default)"="REG_SZ", "CrossriderApp0063443 Type Library"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644344443}\1.0\0\win32]
       "(Default)"="REG_SZ", "C:\Program Files\Addon control\Addon control-bho.dll"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644344443}\1.0\FLAGS]
       "(Default)"="REG_SZ", "0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644344443}\1.0\HELPDIR]
       "(Default)"="REG_SZ", "C:\Program Files\Addon control"
    [HKEY_LOCAL_MACHINE\SOFTWARE\InstalledBrowserExtensions\21836]
       "63443"="REG_SZ", "Addon control"
    [HKEY_LOCAL_MACHINE\SOFTWARE\InstalledBrowserExtensions\21836\Status]
       "Installed"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION]
       "Addon control-bg.exe"="REG_DWORD", 8000
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341143}]
       "(Default)"="REG_SZ", "CrossriderApp0063443"
       "NoExplorer"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID]
       "{11111111-1111-1111-1111-110611341143}"="REG_SZ", "1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Addon control]
       "CrAppId"="REG_SZ", "63443"
       "CrPublisherId"="REG_SZ", "21836"
       "DisplayIcon"="REG_SZ", "C:\Program Files\Addon control\utils.exe"
       "DisplayName"="REG_SZ", "Addon control"
       "DisplayVersion"="REG_SZ", "1.35.3.9"
       "Publisher"="REG_SZ", "iWebar"
       "UninstallString"="REG_SZ", "C:\Program Files\Addon control\Uninstall.exe /fcp=1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures]
       "b9a95d99-27d2-4284-8627-f487b3258123-1.job"="REG_BINARY, ................................
       "b9a95d99-27d2-4284-8627-f487b3258123-1.job.fp"="REG_DWORD", 66928291
       "b9a95d99-27d2-4284-8627-f487b3258123-11.job"="REG_BINARY, ................................
       "b9a95d99-27d2-4284-8627-f487b3258123-11.job.fp"="REG_DWORD", -189499485
       "b9a95d99-27d2-4284-8627-f487b3258123-2.job"="REG_BINARY, ................................
       "b9a95d99-27d2-4284-8627-f487b3258123-2.job.fp"="REG_DWORD", 2042179018
       "b9a95d99-27d2-4284-8627-f487b3258123-5.job"="REG_BINARY, ................................
       "b9a95d99-27d2-4284-8627-f487b3258123-5.job.fp"="REG_DWORD", 1616916681
       "b9a95d99-27d2-4284-8627-f487b3258123-5_user.job"="REG_BINARY, ...............................g
       "b9a95d99-27d2-4284-8627-f487b3258123-5_user.job.fp"="REG_DWORD", -403907150
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Addon control]
       "ActiveAppId"="REG_SZ", "63443"
       "BhoRunningVersion"="REG_SZ", "154"
       "IsBhoEnabled"="REG_DWORD", 1
       "LastSetSearch"="REG_DWORD", 1412317840
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Addon control\background]
       " { Javascript removed, full log availabe on request } "
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Addon control\Debug]
       "DebuggedAppUrl"="REG_SZ", "file://C:\Users\{username}\Documents\debug.js"
       "DebuggedBgUrl"="REG_SZ", "file://C:\Users\{username}\Documents\bg_debug.js"
       "DebuggedNewTabUrl"="REG_SZ", "file://C:\Users\{username}\Documents\new_debug.js"
       "IsDebuggingPlugins"="REG_DWORD", 0
       "IsDebugMode"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Addon control\Installer]
       "AdditionalInfo"="REG_SZ", "{"asw":[67108864, -1073733563, 0],"browser_name":"ie"}"
       "CodeDownloadDomain"="REG_SZ", "http://js.newclientgenservice.com"
       "CodeDownloadFbDomain"="REG_SZ", "http://js.clientdemocloud.com"
       "DefaultBrowser"="REG_SZ", "opera"
       "ErrorsDomain"="REG_SZ", "http://errors.newclientgenservice.com"
       "FullVersion"="REG_SZ", "1.35.3.9"
       "FullVersionForUrl"="REG_SZ", "1_35_09_03"
       "OsName"="REG_SZ", "7"
       "Params"="REG_SZ", "{   "source_id" : "002005",   "sub_id" : "0",   "uzid" : "0"}"
       "SetSearch"="REG_SZ", "false"
       "SrcId"="REG_SZ", "002005"
       "StatsDomain"="REG_SZ", "http://stats.newclientgenservice.com"
       "SubId"="REG_SZ", "0"
       "Time"="REG_SZ", "1412317740"
       "ZData"="REG_SZ", "0"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Addon control\Log]
       "addon control-buttonutil"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Addon control\Manifest]
       "AddressbarURL"="REG_SZ", "NA"
       "BgVersion"="REG_SZ", "1"
       "ChangePrevious"="REG_SZ", "false"
       "Description"="REG_SZ", "Addon control"
       "DisableIe"="REG_SZ", "true"
       "EnableSearchIE"="REG_SZ", "false"
       "HomePageUrl"="REG_SZ", "NA"
       "IsButtonEnabled"="REG_SZ", "false"
       "Manifest"="REG_SZ", "NA"
       "ModeType"="REG_SZ", "production"
       "Name"="REG_SZ", "Addon control"
       "PluginsManifestVersion"="REG_SZ", "10"
       "PublisherId"="REG_SZ", "21836"
       "PublisherName"="REG_SZ", "iWebar"
       "RunInFrame"="REG_SZ", "false"
       "SetNewTab"="REG_SZ", "false"
       "ThanksUrl"="REG_SZ", "NA"
       "UninstallerOfferAction"="REG_SZ", "NA"
       "UninstallerOfferUrl"="REG_SZ", "NA"
       "UpdateInterval"="REG_DWORD", 360
       "Version"="REG_SZ", "16"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Addon control\Update]
       "LastCheck"="REG_DWORD", 1412317763
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider]
       "Bic"="REG_SZ", "0063E56D47F5484E8F606FB74F9E5D7CIE"
       "Verifier"="REG_SZ", "839e3c7779d844252735d5762c54736b"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider\onBeforeNavigate]
       "63443"="REG_SZ", ""
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider\onRequest]
       "63443"="REG_SZ", ""
    [HKEY_CURRENT_USER\Software\InstalledBrowserExtensions\21836]
       "63443"="REG_SZ", "Addon control"
    [HKEY_CURRENT_USER\Software\InstalledBrowserExtensions\21836\Status]
       "Installed"="REG_DWORD", 1
    [HKEY_CURRENT_USER\Software\InstalledBrowserExtensions\iWebar]
       "63443"="REG_SZ", "Addon control"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611341143}]
       "Flags"="REG_DWORD", 1024

 
Malwarebytes Anti-Malware log:
 
 
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/3/2014
Scan Time: 8:35:02 AM
Logfile: mbamAddOnControl.txt
Administrator: Yes

Version: 2.00.3.1024
Malware Database: v2014.10.03.01
Rootkit Database: v2014.09.19.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Malwarebytes

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 266599
Time Elapsed: 3 min, 1 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 37
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611341143}, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644344443}, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655345543}, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666346643}, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063443.BHO.1, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611341143}, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063443.BHO, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110611341143}, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110611341143}, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622342243}, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063443.Sandbox.1, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0063443.Sandbox, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611341143}\INPROCSERVER32, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\Addon control, Quarantined, [da7397791f5d5bdb2202e92470939d63], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE, Quarantined, [321bd739205c16200e5d20fa91729f61], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, Quarantined, [4d00b957700c7cba9bef7cb902019769], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Quarantined, [e469a56b5923e94d3705a5d6ad57c739], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Quarantined, [27260f0181fbd95dd9647b002bd9ba46], 
PUP.Optional.AddonControl.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Addon control, Quarantined, [d9743fd1cab271c5022440cd32d1f30d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [c984fe12e19b53e36305383439cb38c8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, Quarantined, [0b4240d08fed989ef12b0905986bf808], 
PUP.Optional.iWebar.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\iWebar, Quarantined, [c489020e9edeeb4bbde7d26cf60d17e9], 
PUP.Optional.Superfish.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\DOMSTORAGE\superfish.com, Quarantined, [ca83cb45275586b03642215c1be939c7], 
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.AddonControl.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Addon control, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 

Registry Values: 1
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE|path, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [321bd739205c16200e5d20fa91729f61]

Registry Data: 0
(No malicious items detected)

Folders: 22
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Download, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Install, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline\{1C133933-46EA-45C5-A280-B5D3605421B1}, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.AddonControl.A, C:\Users\{username}\AppData\LocalLow\Addon control, Quarantined, [a7a659b7136955e1f1969078b350e31d], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected], Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\defaults, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\defaults\preferences, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\userCode, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\locale, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\locale\en-US, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 

Files: 149
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\Addon control-bho.dll, Quarantined, [b598c050eb9138fef161a51ca25ffd03], 
PUP.Optional.crossRider.A, C:\Users\{username}\Desktop\Addon control.exe, Quarantined, [004df9171666191d38e167d9946ca25e], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\Addon control-bg.exe, Quarantined, [6edf51bf413b51e5be94fdc4fe039a66], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\Addon control-buttonutil.exe, Quarantined, [78d5d838fd7f8babff532f920cf5fa06], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\Addon control-codedownloader.exe, Quarantined, [f5580e020a72d95d4e04d9e81de44fb1], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\b9a95d99-27d2-4284-8627-f487b3258123-11.exe, Quarantined, [b598b06058243501b1a149784bb6b44c], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\b9a95d99-27d2-4284-8627-f487b3258123-2.exe, Quarantined, [73da53bd9ce0bf771b379d240cf56b95], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\b9a95d99-27d2-4284-8627-f487b3258123-4.exe, Quarantined, [202de42c8af279bd2032734ee61b8878], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\b9a95d99-27d2-4284-8627-f487b3258123-5.exe, Quarantined, [53fa9f710d6f290d272bffc2cc356e92], 
PUP.Optional.crossRider.A, C:\Program Files\Addon control\utils.exe, Quarantined, [62eb98786c104beb8c8d70d0ba46b050], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-1, Quarantined, [88c58789304cf93d1650190162a1f30d], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-11, Quarantined, [d776fc14eb91e254eb7ba278788b59a7], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-2, Quarantined, [a2abbc54d2aaa492cb9b8496748f24dc], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-5, Quarantined, [56f7d33deb91f5415a0c4bcf6a99ab55], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-5_user, Quarantined, [ada0d23ed9a3f93d6bfbf624d42f5aa6], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-1.job, Quarantined, [90bd010fb3c94aec4886ef89768ea060], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-11.job, Quarantined, [232af11f324a1f17507efe7ade26d12f], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-2.job, Quarantined, [5af3739dc3b9fd3929a5fb7dc63e9070], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-5.job, Quarantined, [321b957b423a47ef13bbbcbc996b5ea2], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\b9a95d99-27d2-4284-8627-f487b3258123-5_user.job, Quarantined, [1439cf4175077bbb24aa2b4d58ac11ef], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, Quarantined, [3518838d5923d85ea83c87f13ec636ca], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, Quarantined, [282517f9285484b2638222566d97b54b], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, Quarantined, [a9a49b753b41f3434d990276c044649c], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, Quarantined, [3914d739bdbfb77f72755a1e15eff10f], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll, Quarantined, [76d799772f4d9b9bf18ed8228d7503fd], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\GoogleCrashHandler.exe, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\GoogleUpdate.exe, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\GoogleUpdateBroker.exe, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\GoogleUpdateHelper.msi, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\GoogleUpdateOnDemand.exe, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\goopdate.dll, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\goopdateres_en.dll, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\npGoogleUpdate4.dll, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\psmachine.dll, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.7195\psuser.dll, Quarantined, [4d00df31304c58de6f2cf604bc46ad53], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\1293297481.mxaddon, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\36348df0-01de-47c1-9664-9c5204b7f5d2.crx, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\Addon control-buttonutil.dll, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\Addon control.ico, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\b9a95d99-27d2-4284-8627-f487b3258123.crx, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\b9a95d99-27d2-4284-8627-f487b3258123.xpi, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\background.html, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 
PUP.Optional.AddonControl.A, C:\Program Files\Addon control\Uninstall.exe, Quarantined, [e5680c0497e516204a3fd33541c2e51b], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome.manifest, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\install.rdf, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\10bf2cb28a07681e468f14b36d7fd4ef.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\2cfc556b0b26174d5f979172785716ff.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\2f97a3ee4e8b985fbaa9dc00a4f2408d.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\46b52d9294942054240f976cb72634cd.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\54d6408838744fb2a9be30f9ca03acf6.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\a5ebf64d9a3402d0c96df207b71e4df4.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\background.html, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\browser.xul, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\dialog.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\ffCoreFilesIndex.txt, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\options.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\options.xul, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\search_dialog.xul, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\7eb63d5a7049599cb483ad9db747ae5d.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\1521fe02ee883c4fb5dd51f1e5a82cae.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\19994ee6dd8b1cfeaf2e28c493fbaf91.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\1bdfba3bb4b5170f5809021d1743691a.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\20dbe3e745000210e26cede2f2e22b55.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\3533b0667f5df631f2bbf48b4d5e8559.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\443ff944705f633829ba7f0f33dc4073.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\4fdc30c34e0787d73e5fb6dcb818332c.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\7184d55e2ce1c8b119152b1d203e1fa3.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\80bff2fe8fd1dac8fab872c633076c3d.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\80e62618077c4484912eda49ccc5806d.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\8ed91c2b6e0b8b963502064fce60e0b2.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\9dcee496b3e1b1118d975c5ed4197446.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\ac4ac3b9a1eb4dfe6621cde58232773b.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\c78969546e9b70c262a315281f8457bd.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\api\f0d662752eb229bd27cc1ef6ea0fb673.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\8317078de00ae262b78aefa31ca2f34a.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\242b27ae2bf88dfa5b06b3ebca37a9ba.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\281f635da66387ae250bf97944618504.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\352d92820e9f89fcb281f750efdc0028.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\454342418eb969ca60a5b080f7a16def.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\45d266491b534ab7b68e28e03915c47a.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\49cf6d812827382eed3a6a27a0fcc217.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\4ba248dcd5990247aa5814c96f84c4ea.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\537a38eb2c9bc9953f384f498f06738f.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\5fb7f5fe52b7ea4162a3a449645e998a.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\67c76850020ae12cdb493414a315e62a.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\8ea74ebdad485e73cb47e4aada08d663.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\8efdb5207e4faa88af1a1375d43aca05.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\964a3f7063f23906754ccdbbd6cd5abd.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\97ea4535b56e3eed299cf4994a3b868c.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\aa7d65093bc287e11acbdb1342bca5b9.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\c3c42817ccdb873b10be41ce0cc5edb0.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\c9d9295a451ffac61d92e744353f55c0.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\ccf66e1737e8dde3caadfd2ae3b061cf.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\e2be50b95cfa745f0fab125e884a1291.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\chrome\content\core\installer.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\defaults\preferences\prefs.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\manifest.xml, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins.json, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\1.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\102.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\104.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\13.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\14.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\16.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\17.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\177.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\182.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\183.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\207.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\21.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\22.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\246.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\268.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\28.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\4.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\47.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\64.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\72.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\78.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\91.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\93.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\plugins\98.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\userCode\background.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\extensionData\userCode\extension.js, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\locale\en-US\translations.dtd, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\button1.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\button2.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\button3.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\button4.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\button5.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\crossrider_statusbar.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\icon128.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\icon16.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\icon24.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\icon48.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\panelarrow-up.png, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\popup.html, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\skin.css, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 
PUP.Optional.MultiPlug.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\[email protected]\skin\update.css, Quarantined, [ae9f67a90e6e41f52e5f4dbb976c35cb], 

Physical Sectors: 0
(No malicious items detected)


(end)
 
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.