Jump to content

PUP.FaceThemes infection found


Recommended Posts

I ran a MB full scan earlier today and found 5 instances of "PUP.FaceThemes." I found a post in the forum that relates to this. It said it was OK to delete these, which I have done. The reply to the post had addition steps to take. The first one was to download and run AdwCleaner and post the log which I did. The log is posted below the dotted line.

I would appreciated any help you can give in interpreting the log results and what actions might be necessary to take.

Thank you.

..........................................................................................................................................................

# AdwCleaner v2.300 - Logfile created 05/13/2013 at 10:47:39

# Updated 28/04/2013 by Xplode

# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)

# User : Phil - PHIL-PC

# Boot Mode : Normal

# Running from : C:\Users\Phil\Desktop\adwcleaner.exe

# Option [search]

***** [services] *****

***** [Files / Folders] *****

File Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk

File Found : C:\user.js

File Found : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\fegxbq1l.default\searchplugins\Search_Results.xml

File Found : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\t7e8lzso.Phil\searchplugins\Askcom.xml

File Found : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\t7e8lzso.Phil\searchplugins\Conduit.xml

Folder Found : C:\Program Files (x86)\Common Files\Speedbit

Folder Found : C:\ProgramData\Speedbit

Folder Found : C:\ProgramData\Tarma Installer

Folder Found : C:\Users\Phil\AppData\Local\SwvUpdater

Folder Found : C:\Users\Phil\AppData\LocalLow\Conduit

Folder Found : C:\Users\Phil\AppData\LocalLow\PriceGong

Folder Found : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ds8gaxvc.default\jetpack

Folder Found : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\fegxbq1l.default\extensions\staged

Folder Found : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\t7e8lzso.Phil\Conduit

Folder Found : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\t7e8lzso.Phil\extensions\staged

Folder Found : C:\Users\Phil\AppData\Roaming\OpenCandy

***** [Registry] *****

Key Found : HKCU\Software\1ClickDownload

Key Found : HKCU\Software\AppDataLow\Software\Crossrider

Key Found : HKCU\Software\AppDataLow\Software\Search Settings

Key Found : HKCU\Software\Conduit

Key Found : HKCU\Software\IM

Key Found : HKCU\Software\ImInstaller

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com

Key Found : HKCU\Software\SpeedBit

Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}

Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}

Key Found : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}

Key Found : HKLM\Software\Conduit

Key Found : HKLM\Software\Iminent

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5EB0259D-AB79-4AE6-A6E6-24FFE21C3DA4}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco

Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{5EB0259D-AB79-4AE6-A6E6-24FFE21C3DA4}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}

Key Found : HKLM\SOFTWARE\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}

Key Found : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}

Key Found : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}

Key Found : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}

Key Found : HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}

Key Found : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}

Key Found : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}

Key Found : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}

Key Found : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}

Key Found : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}

Key Found : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}

Key Found : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}

Key Found : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}

Key Found : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}

Key Found : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}

Key Found : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}

Key Found : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}

Key Found : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}

Key Found : HKLM\SOFTWARE\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}

Key Found : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}

Key Found : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}

Key Found : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}

Key Found : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}

Key Found : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}

Key Found : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}

Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh

Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd

Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\incredibar

Key Found : HKLM\SOFTWARE\Tarma Installer

Key Found : HKLM\SOFTWARE\Web Assistant

***** [internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16537

[OK] Registry is clean.

-\\ Mozilla Firefox v19.0.2 (en-US)

File : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ds8gaxvc.default\prefs.js

Found : user_pref("extensions.daplinkchecker@speedbit.com.install-event-fired", true);

Found : user_pref("extensions.funmoods.aflt", "axl");

Found : user_pref("extensions.funmoods.autoRvrt", false);

Found : user_pref("extensions.funmoods.cntry", "US");

Found : user_pref("extensions.funmoods.cv", "cv5");

Found : user_pref("extensions.funmoods.dfltLng", "");

Found : user_pref("extensions.funmoods.dfltSrch", false);

Found : user_pref("extensions.funmoods.dnsErr", true);

Found : user_pref("extensions.funmoods.envrmnt", "production");

Found : user_pref("extensions.funmoods.excTlbr", false);

Found : user_pref("extensions.funmoods.hdrMd5", "E1F701B980732FFDA37D0662E6A9C6A4");

Found : user_pref("extensions.funmoods.hmpg", false);

Found : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2[...]

Found : user_pref("extensions.funmoods.id", "002215195D92B641");

Found : user_pref("extensions.funmoods.instlDay", "15561");

Found : user_pref("extensions.funmoods.instlRef", "axl");

Found : user_pref("extensions.funmoods.isdcmntcmplt", true);

Found : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2217:40:20");

Found : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");

Found : user_pref("extensions.funmoods.newTab", false);

Found : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEt[...]

Found : user_pref("extensions.funmoods.prdct", "funmoods");

Found : user_pref("extensions.funmoods.prtnrId", "funmoods");

Found : user_pref("extensions.funmoods.sg", "none");

Found : user_pref("extensions.funmoods.smplGrp", "none");

Found : user_pref("extensions.funmoods.srchPrvdr", "Search");

Found : user_pref("extensions.funmoods.tlbrId", "base");

Found : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2Xzuy[...]

Found : user_pref("extensions.funmoods.vrsn", "1.5.23.22");

Found : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2217:40:20");

Found : user_pref("extensions.funmoods.vrsni", "1.5.23.22");

Found : user_pref("extensions.funmoods_i.newTab", false);

Found : user_pref("extensions.funmoods_i.smplGrp", "none");

Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2217:40:20");

Found : user_pref("extensions.incredibar.admin", false);

Found : user_pref("extensions.incredibar.aflt", "orgnl");

Found : user_pref("extensions.incredibar.cntry", "US");

Found : user_pref("extensions.incredibar.dfltLng", "");

Found : user_pref("extensions.incredibar.dfltSrch", false);

Found : user_pref("extensions.incredibar.did", "10658");

Found : user_pref("extensions.incredibar.envrmnt", "production");

Found : user_pref("extensions.incredibar.excTlbr", false);

Found : user_pref("extensions.incredibar.hdrMd5", "4599394C106A180B485A6568B925BCEF");

Found : user_pref("extensions.incredibar.hmpg", false);

Found : user_pref("extensions.incredibar.id", "3e63b641000000000000002215195d92");

Found : user_pref("extensions.incredibar.installerproductid", "26");

Found : user_pref("extensions.incredibar.instlDay", "15586");

Found : user_pref("extensions.incredibar.instlRef", "");

Found : user_pref("extensions.incredibar.isDcmntCmplt", true);

Found : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1418:28:47");

Found : user_pref("extensions.incredibar.mntrvrsn", "1.2.0");

Found : user_pref("extensions.incredibar.newTab", false);

Found : user_pref("extensions.incredibar.noFFXTlbr", false);

Found : user_pref("extensions.incredibar.ppd", "");

Found : user_pref("extensions.incredibar.prdct", "incredibar");

Found : user_pref("extensions.incredibar.productid", "26");

Found : user_pref("extensions.incredibar.prtnrId", "Incredibar");

Found : user_pref("extensions.incredibar.sg", "none");

Found : user_pref("extensions.incredibar.smplGrp", "none");

Found : user_pref("extensions.incredibar.tlbrId", "base");

Found : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyN2vn6Go&loc=IB_T[...]

Found : user_pref("extensions.incredibar.upn2", "6OyN2vn6Go");

Found : user_pref("extensions.incredibar.upn2n", "92262044960820116");

Found : user_pref("extensions.incredibar.vrsn", "1.5.11.14");

Found : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1418:28:47");

Found : user_pref("extensions.incredibar.vrsni", "1.5.11.14");

Found : user_pref("extensions.incredibar_i.aflt", "orgnl");

Found : user_pref("extensions.incredibar_i.dfltLng", "");

Found : user_pref("extensions.incredibar_i.did", "10658");

Found : user_pref("extensions.incredibar_i.excTlbr", false);

Found : user_pref("extensions.incredibar_i.id", "3e63b641000000000000002215195d92");

Found : user_pref("extensions.incredibar_i.installerproductid", "26");

Found : user_pref("extensions.incredibar_i.instlDay", "15586");

Found : user_pref("extensions.incredibar_i.instlRef", "");

Found : user_pref("extensions.incredibar_i.ms_url_id", "");

Found : user_pref("extensions.incredibar_i.newTab", false);

Found : user_pref("extensions.incredibar_i.ppd", "");

Found : user_pref("extensions.incredibar_i.prdct", "incredibar");

Found : user_pref("extensions.incredibar_i.productid", "26");

Found : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");

Found : user_pref("extensions.incredibar_i.smplGrp", "none");

Found : user_pref("extensions.incredibar_i.tlbrId", "base");

Found : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyN2vn6Go&loc=IB[...]

Found : user_pref("extensions.incredibar_i.upn2", "6OyN2vn6Go");

Found : user_pref("extensions.incredibar_i.upn2n", "92262044960820116");

Found : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");

Found : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1418:28:47");

Found : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");

File : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\fegxbq1l.default\prefs.js

Found : user_pref("browser.search.order.1", "Search Results");

Found : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb128?a=6OyN2vn6Go&loc=FF_NT");

File : C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\t7e8lzso.Phil\prefs.js

Found : user_pref("CT2384137.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");

Found : user_pref("CT2384137.CTID", "CT2384137");

Found : user_pref("CT2384137.DialogsAlignMode", "LTR");

Found : user_pref("CT2384137.EMailNotifierPollDate", "Sat Dec 19 2009 14:53:58 GMT-0500 (Eastern Standard Ti[...]

Found : user_pref("CT2384137.FeedLastCount129027572955594721", 100);

Found : user_pref("CT2384137.FeedPollDate129027572956531254", "Sat Dec 19 2009 14:53:42 GMT-0500 (Eastern St[...]

Found : user_pref("CT2384137.FeedPollDate129027572956531255", "Sat Dec 19 2009 14:53:42 GMT-0500 (Eastern St[...]

Found : user_pref("CT2384137.FeedPollDate129027572956531256", "Sat Dec 19 2009 14:53:42 GMT-0500 (Eastern St[...]

Found : user_pref("CT2384137.FeedPollDate129027572956531257", "Sat Dec 19 2009 14:53:42 GMT-0500 (Eastern St[...]

Found : user_pref("CT2384137.FeedPollDate129027572956531258", "Sat Dec 19 2009 14:53:58 GMT-0500 (Eastern St[...]

Found : user_pref("CT2384137.FeedTTL129027572956531254", 40);

Found : user_pref("CT2384137.FeedTTL129027572956531255", 40);

Found : user_pref("CT2384137.FeedTTL129027572956531256", 40);

Found : user_pref("CT2384137.FeedTTL129027572956531257", 40);

Found : user_pref("CT2384137.FeedTTL129027572956531258", 40);

Found : user_pref("CT2384137.FirstTime", true);

Found : user_pref("CT2384137.FirstTimeFF3", true);

Found : user_pref("CT2384137.GroupingServerCheckInterval", 1440);

Found : user_pref("CT2384137.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");

Found : user_pref("CT2384137.Initialize", true);

Found : user_pref("CT2384137.InitializeCommonPrefs", true);

Found : user_pref("CT2384137.InstalledDate", "Sat Dec 19 2009 14:53:42 GMT-0500 (Eastern Standard Time)");

Found : user_pref("CT2384137.InvalidateCache", false);

Found : user_pref("CT2384137.IsGrouping", false);

Found : user_pref("CT2384137.IsMulticommunity", false);

Found : user_pref("CT2384137.IsOpenThankYouPage", true);

Found : user_pref("CT2384137.IsOpenUninstallPage", true);

Found : user_pref("CT2384137.LanguagePackLastCheckTime", "Sat Dec 19 2009 14:53:42 GMT-0500 (Eastern Standar[...]

Found : user_pref("CT2384137.LanguagePackReloadIntervalMM", 1440);

Found : user_pref("CT2384137.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]

Found : user_pref("CT2384137.LastLogin_2.4.0.4", "Sat Dec 19 2009 14:53:59 GMT-0500 (Eastern Standard Time)"[...]

Found : user_pref("CT2384137.LatestVersion", "2.1.0.18");

Found : user_pref("CT2384137.Locale", "en");

Found : user_pref("CT2384137.LoginCache", 4);

Found : user_pref("CT2384137.MCDetectTooltipHeight", "83");

Found : user_pref("CT2384137.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");

Found : user_pref("CT2384137.MCDetectTooltipWidth", "295");

Found : user_pref("CT2384137.RadioIsPodcast", false);

Found : user_pref("CT2384137.RadioLastCheckTime", "Sat Dec 19 2009 14:53:42 GMT-0500 (Eastern Standard Time)[...]

Found : user_pref("CT2384137.RadioLastUpdateIPServer", "4");

Found : user_pref("CT2384137.RadioLastUpdateServer", "128998424480370000");

Found : user_pref("CT2384137.RadioMediaID", "12743586");

Found : user_pref("CT2384137.RadioMediaType", "Media Player");

Found : user_pref("CT2384137.RadioMenuSelectedID", "EBRadioMenu_CT238413712743586");

Found : user_pref("CT2384137.RadioStationName", "Radio%20IO%20-%2080s%20New%20Wave%20");

Found : user_pref("CT2384137.RadioStationURL", "hxxp://eradioportal.com/radioio_80s_New_Wave.asx");

Found : user_pref("CT2384137.SHRINK_TOOLBAR", 1);

Found : user_pref("CT2384137.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]

Found : user_pref("CT2384137.SearchFromAddressBarIsInit", true);

Found : user_pref("CT2384137.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT238[...]

Found : user_pref("CT2384137.SearchInNewTabEnabled", true);

Found : user_pref("CT2384137.SearchInNewTabIntervalMM", 1440);

Found : user_pref("CT2384137.SearchInNewTabLastCheckTime", "Sat Dec 19 2009 14:53:59 GMT-0500 (Eastern Stand[...]

Found : user_pref("CT2384137.SearchInNewTabServiceUrl", "hxxp://hosting.conduit-services.com/newtab/?ctid=EB[...]

Found : user_pref("CT2384137.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]

Found : user_pref("CT2384137.SettingsCheckIntervalMin", 120);

Found : user_pref("CT2384137.SettingsLastCheckTime", "Sat Dec 19 2009 14:53:41 GMT-0500 (Eastern Standard Ti[...]

Found : user_pref("CT2384137.SettingsLastUpdate", "1261254872");

Found : user_pref("CT2384137.ThirdPartyComponentsInterval", 72);

Found : user_pref("CT2384137.ThirdPartyComponentsLastCheck", "Sat Dec 19 2009 14:53:41 GMT-0500 (Eastern Sta[...]

Found : user_pref("CT2384137.ThirdPartyComponentsLastUpdate", "1261254872");

Found : user_pref("CT2384137.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]

Found : user_pref("CT2384137.UserID", "UN37674825774431864");

Found : user_pref("CT2384137.WeatherNetwork", "");

Found : user_pref("CT2384137.WeatherPollDate", "Sat Dec 19 2009 14:53:42 GMT-0500 (Eastern Standard Time)");

Found : user_pref("CT2384137.WeatherUnit", "F");

Found : user_pref("CT2384137.alertChannelId", "778910");

Found : user_pref("CT2384137.clientLogIsEnabled", true);

Found : user_pref("CT2384137.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]

Found : user_pref("CT2384137.myStuffEnabled", true);

Found : user_pref("CT2384137.myStuffPublihserMinWidth", 400);

Found : user_pref("CT2384137.myStuffSearchUrl", "hxxp://search.conduit.com/Results.aspx?q=SEARCH_TERM&ctid=E[...]

Found : user_pref("CT2384137.myStuffServiceIntervalMM", 1440);

Found : user_pref("CT2384137.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]

Found : user_pref("CT2384137.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]

Found : user_pref("CommunityToolbar.ToolbarsList", "CT2384137");

Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 60);

Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sat Dec 19 2009 14:53:42 GMT-0500 (Easte[...]

Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");

Found : user_pref("CommunityToolbar.alert.locale", "en");

Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);

Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sat Dec 19 2009 14:53:41 GMT-0500 (Eastern S[...]

Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1234796400");

Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);

Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");

Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);

Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);

Found : user_pref("CommunityToolbar.alert.userId", "{da1cbaeb-cc9a-48ce-80ab-ce25eb47f8a4}");

Found : user_pref("CommunityToolbar.twitter.user_14372486.LastCheckTime", "Sat Dec 19 2009 14:53:42 GMT-0500[...]

Found : user_pref("CommunityToolbar.twitter.user_20278298.LastCheckTime", "Sat Dec 19 2009 14:53:42 GMT-0500[...]

Found : user_pref("CommunityToolbar.twitter.user_717313.LastCheckTime", "Sat Dec 19 2009 14:53:42 GMT-0500 ([...]

Found : user_pref("CommunityToolbar.twitter.user_816653.LastCheckTime", "Sat Dec 19 2009 14:53:42 GMT-0500 ([...]

Found : user_pref("CommunityToolbar.twitter.user_819800.LastCheckTime", "Sat Dec 19 2009 14:53:42 GMT-0500 ([...]

Found : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?SSPV=FFSB1&ctid=CT2737658&Sea[...]

Found : user_pref("Smartbar.ConduitSearchEngineList", "FreeOnlineRadioPlayerRecorder Customized Web Search")[...]

Found : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?SSPV=FFSB1&cti[...]

Found : user_pref("browser.search.defaultengine", "Ask.com");

Found : user_pref("browser.search.order.1", "Ask.com");

Found : user_pref("extensions.BabylonToolbar.admin", false);

Found : user_pref("extensions.BabylonToolbar.aflt", "babsst");

Found : user_pref("extensions.BabylonToolbar.babExt", "");

Found : user_pref("extensions.BabylonToolbar.babTrack", "affID=101067");

Found : user_pref("extensions.BabylonToolbar.bbDpng", 28);

Found : user_pref("extensions.BabylonToolbar.dfltSrch", false);

Found : user_pref("extensions.BabylonToolbar.hmpg", false);

Found : user_pref("extensions.BabylonToolbar.id", "3e63b641000000000000002215195d92");

Found : user_pref("extensions.BabylonToolbar.instlDay", "15334");

Found : user_pref("extensions.BabylonToolbar.instlRef", "sst");

Found : user_pref("extensions.BabylonToolbar.lastDP", 28);

Found : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.1716:35:47");

Found : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "8.0");

Found : user_pref("extensions.BabylonToolbar.newTab", true);

Found : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_bb");

Found : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);

Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");

Found : user_pref("extensions.BabylonToolbar.propectorlck", 63652552);

Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");

Found : user_pref("extensions.BabylonToolbar.ptch_0717", true);

Found : user_pref("extensions.BabylonToolbar.smplGrp", "none");

Found : user_pref("extensions.BabylonToolbar.srcExt", "ss");

Found : user_pref("extensions.BabylonToolbar.tlbrId", "base");

Found : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");

Found : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.1716:35:47");

Found : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");

Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");

Found : user_pref("extensions.BabylonToolbar_i.babExt", "");

Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=101067");

Found : user_pref("extensions.BabylonToolbar_i.hardId", "3e63b641000000000000002215195d92");

Found : user_pref("extensions.BabylonToolbar_i.id", "3e63b641000000000000002215195d92");

Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15334");

Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");

Found : user_pref("extensions.BabylonToolbar_i.newTab", false);

Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");

Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");

Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");

Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");

Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");

Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");

Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1716:35:47");

Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");

Found : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb128?a=6OyN2vn6Go&loc=FF_NT");

-\\ Google Chrome v [unable to get version]

File : C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [25302 octets] - [13/05/2013 10:47:39]

########## EOF - C:\AdwCleaner[R1].txt - [25363 octets] ##########

Link to post
Share on other sites

Hello prh1217 and :welcome:! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.

Please follow the instructions here and post your log files:

http://forums.malwarebytes.org/index.php?showtopic=9573

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.