hi Ron, Thanks for your prompt response. I cant really copy all the week scans since March 2013 I bought the PRO for all the computers to October. That is too much additional works. But below are 4 samples logs with the latest malicious screenshot. I hope that could help. ----------- Malwarebytes Anti-Malware 1.60.1.1000www.malwarebytes.org Database version: v2012.04.04.01 Windows 7 x64 NTFSInternet Explorer 8.0.7600.16385user :: USER-HP [administrator] 4/3/2012 7:10:36 PMmbam-log-2012-04-03 (19-10-36).txt Scan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 191628Time elapsed: 4 minute(s), 29 second(s) Memory Processes Detected: 0(No malicious items detected) Memory Modules Detected: 0(No malicious items detected) Registry Keys Detected: 0(No malicious items detected) Registry Values Detected: 0(No malicious items detected) Registry Data Items Detected: 0(No malicious items detected) Folders Detected: 0(No malicious items detected) Files Detected: 0(No malicious items detected) (end)Malwarebytes Anti-Malware 1.60.1.1000www.malwarebytes.org Database version: v2012.04.04.01 Windows 7 Service Pack 1 x64 NTFSInternet Explorer 9.0.8112.16421user :: USER-HP [administrator] 4/8/2012 1:33:14 PMmbam-log-2012-04-08 (13-33-14).txt Scan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 192342Time elapsed: 4 minute(s), 9 second(s) Memory Processes Detected: 0(No malicious items detected) Memory Modules Detected: 0(No malicious items detected) Registry Keys Detected: 0(No malicious items detected) Registry Values Detected: 0(No malicious items detected) Registry Data Items Detected: 0(No malicious items detected) Folders Detected: 0(No malicious items detected) Files Detected: 1C:\Users\user\Downloads\SoftonicDownloader_for_mozilla-firefox.exe (PUP.ToolbarDownloader) -> No action taken. (end)Malwarebytes Anti-Malware 1.60.1.1000www.malwarebytes.org Database version: v2012.04.04.01 Windows 7 Service Pack 1 x64 NTFSInternet Explorer 9.0.8112.16421user :: USER-HP [administrator] 4/9/2012 7:36:32 PMmbam-log-2012-04-09 (19-36-32).txt Scan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 193873Time elapsed: 3 minute(s), 59 second(s) Memory Processes Detected: 0(No malicious items detected) Memory Modules Detected: 0(No malicious items detected) Registry Keys Detected: 0(No malicious items detected) Registry Values Detected: 0(No malicious items detected) Registry Data Items Detected: 0(No malicious items detected) Folders Detected: 0(No malicious items detected) Files Detected: 1C:\Users\user\Downloads\SoftonicDownloader_for_mozilla-firefox.exe (PUP.ToolbarDownloader) -> No action taken. (end) Malwarebytes Anti-Malware 1.61.0.1400www.malwarebytes.org Database version: v2012.05.31.04 Windows 7 Service Pack 1 x64 NTFSInternet Explorer 9.0.8112.16421user :: USER-HP [administrator] 5/31/2012 1:03:30 PMmbam-log-2012-05-31 (13-03-30).txt Scan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 242251Time elapsed: 3 minute(s), 44 second(s) Memory Processes Detected: 0(No malicious items detected) Memory Modules Detected: 0(No malicious items detected) Registry Keys Detected: 0(No malicious items detected) Registry Values Detected: 0(No malicious items detected) Registry Data Items Detected: 0(No malicious items detected) Folders Detected: 0(No malicious items detected) Files Detected: 0(No malicious items detected) (end)Malwarebytes Anti-Malware (PRO) 1.75.0.1300www.malwarebytes.org Database version: v2013.10.05.07 Windows 7 Service Pack 1 x64 NTFSInternet Explorer 10.0.9200.16686user :: USER-HP [administrator] Protection: Enabled 10/5/2013 10:58:04 PMmbam-log-2013-10-05 (22-58-04).txt Scan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 257758Time elapsed: 19 minute(s), 45 second(s) Memory Processes Detected: 0(No malicious items detected) Memory Modules Detected: 0(No malicious items detected) Registry Keys Detected: 8HKCR\CLSID\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Quarantined and deleted successfully.HKCR\CLSID\{69A72A8A-84ED-4a75-8CE7-263DBEF3E5D3} (PUP.Optional.AmazonTB.A) -> Quarantined and deleted successfully.HKCR\TypeLib\{33D0AD98-3347-4A54-8929-5163EBEB9F72} (PUP.Optional.AmazonTB.A) -> Quarantined and deleted successfully.HKCR\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C} (PUP.Optional.AmazonTB.A) -> Quarantined and deleted successfully.HKCR\AlxTB2.ToolBarProxy.1 (PUP.Optional.AmazonTB.A) -> Quarantined and deleted successfully.HKCR\AlxTB2.ToolBarProxy (PUP.Optional.AmazonTB.A) -> Quarantined and deleted successfully.HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Quarantined and deleted successfully.HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Quarantined and deleted successfully. Registry Values Detected: 2HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Data: -> Quarantined and deleted successfully.HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Data: -> Quarantined and deleted successfully. Registry Data Items Detected: 0(No malicious items detected) Folders Detected: 0(No malicious items detected) Files Detected: 1C:\Program Files (x86)\Alexa Toolbar\AlexaToolbar.10.0.dll (PUP.Optional.AmazonTB.A) -> Quarantined and deleted successfully. (end) 2013/10/05 17:28:03 -0400 USER-HP user MESSAGE Executing scheduled update: Daily2013/10/05 17:28:09 -0400 USER-HP user MESSAGE Starting protection2013/10/05 17:28:09 -0400 USER-HP user MESSAGE Protection started successfully2013/10/05 17:28:09 -0400 USER-HP user MESSAGE Starting IP protection2013/10/05 17:28:13 -0400 USER-HP user MESSAGE IP Protection started successfully2013/10/05 17:28:43 -0400 USER-HP user MESSAGE Starting database refresh2013/10/05 17:28:43 -0400 USER-HP user MESSAGE Stopping IP protection2013/10/05 17:28:43 -0400 USER-HP user MESSAGE IP Protection stopped successfully2013/10/05 17:28:43 -0400 USER-HP user MESSAGE Scheduled update executed successfully: database updated from version v2013.10.04.06 to version v2013.10.05.062013/10/05 17:28:46 -0400 USER-HP user MESSAGE Database refreshed successfully2013/10/05 17:28:46 -0400 USER-HP user MESSAGE Starting IP protection2013/10/05 17:28:50 -0400 USER-HP user MESSAGE IP Protection started successfully2013/10/05 21:42:05 -0400 USER-HP (null) MESSAGE Executing scheduled update: Daily2013/10/05 21:42:29 -0400 USER-HP (null) MESSAGE Starting protection2013/10/05 21:42:29 -0400 USER-HP (null) MESSAGE Protection started successfully2013/10/05 21:42:29 -0400 USER-HP (null) MESSAGE Starting IP protection2013/10/05 21:42:32 -0400 USER-HP (null) MESSAGE IP Protection started successfully2013/10/05 21:42:32 -0400 USER-HP (null) MESSAGE Starting database refresh2013/10/05 21:42:32 -0400 USER-HP (null) MESSAGE Stopping IP protection2013/10/05 21:42:32 -0400 USER-HP (null) MESSAGE Database already up-to-date2013/10/05 21:42:33 -0400 USER-HP (null) MESSAGE IP Protection stopped successfully2013/10/05 21:42:35 -0400 USER-HP (null) MESSAGE Database refreshed successfully2013/10/05 21:42:35 -0400 USER-HP (null) MESSAGE Starting IP protection2013/10/05 21:42:38 -0400 USER-HP (null) MESSAGE IP Protection started successfully