Awardhotspot and blocking

I woke up to an infected computer this morning. I had the Awardhotspot addons in chrome. I removed them and installed malwarebytes. That is when I started getting pop-up saying that access to was being blocked. I noticed the the first step in a lot of these situations is to run Rogue Killer, so I tried that but it hangs on various parts of the scan. Is this normal?

Thanks in advance.


DDS (Ver_2012-11-20.01) - NTFS_AMD64 

Internet Explorer: 10.0.9200.16750  BrowserJavaVersion: 10.51.2

Run by Zephram at 0:34:33 on 2014-01-17

Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.16301.12761 [GMT 9:00]


AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}

SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}


Hello PyroDwarf! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
Step 1

Please uninstall this application: Coupon Printer for Windows .

Step 2

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 3

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan button. Wait until is finished.
  • Click on Clean.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner\AdwCleaner[s0].txt as well.
Step 4
  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

In your next reply, post the following log files:

  • Junkware Removal Tool log
  • AdwCleaner log
  • Malwarebytes' Anti-Malware log
Thank you!




Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows 7 Professional x64
Ran by Zephram on Fri 01/17/2014 at  1:27:07.83
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1038941090-660640611-790380482-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?
    Value Name          Type                             Value Data                     
    BackgroundContainer    REG_SZ    "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Zephram\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\pricegong
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\caphyon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3220468
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Zephram\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\Zephram\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\Zephram\appdata\local\torch"
Successfully deleted: [Folder] "C:\Users\Zephram\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Zephram\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Users\Zephram\appdata\locallow\utorrentcontrol_v2"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Zephram\AppData\Roaming\mozilla\firefox\profiles\h88vqbsn.default\extensions\staged
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
~~~ Event Viewer Logs were cleared
Scan was completed on Fri 01/17/2014 at  1:33:22.33
End of JRT log
# AdwCleaner v3.017 - Report created 17/01/2014 at 01:45:11
# Updated 12/01/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Zephram - PYRODWARF
# Running from : F:\Downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\SoftWarehouse
Folder Deleted : C:\ProgramData\greatsAverr
Folder Deleted : C:\Program Files (x86)\greatsAverr
Folder Deleted : C:\Users\Zephram\AppData\Local\genienext
Folder Deleted : C:\Users\Zephram\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Zephram\Documents\Mobogenie
File Deleted : C:\Windows\System32\Tasks\BackgroundContainer Startup Task
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\conduit.com
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4FB8563-ABF4-4578-8E6B-F15D21BB9BAA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AAD61A4F-ED84-4A1F-AB27-E75777C62A75}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\uTorrentControl_v2
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16750
-\\ Mozilla Firefox v23.0.1 (en-US)
[ File : C:\Users\Zephram\AppData\Roaming\Mozilla\Firefox\Profiles\h88vqbsn.default\prefs.js ]
-\\ Google Chrome v32.0.1700.76
[ File : C:\Users\Zephram\AppData\Local\Google\Chrome\User Data\Default\preferences ]
AdwCleaner[R0].txt - [3775 octets] - [17/01/2014 01:44:43]
AdwCleaner[s0].txt - [3191 octets] - [17/01/2014 01:45:11]
########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [3251 octets] ##########
Malwarebytes Anti-Malware (Trial)
Database version: v2014.01.16.04
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16750
Zephram :: PYRODWARF [administrator]
Protection: Disabled
1/17/2014 1:39:07 AM
mbam-log-2014-01-17 (01-39-07).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 228238
Time elapsed: 1 minute(s), 46 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|BackgroundContainer (PUP.Optional.Conduit) -> Data: "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Zephram\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 6
C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\hk64tbuTo2.dll (PUP.Optional.Conduit) -> Quarantined and deleted successfully.
C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\hktbuTo2.dll (PUP.Optional.Conduit) -> Quarantined and deleted successfully.
C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\ldrtbuTo2.dll (PUP.Optional.Conduit) -> Quarantined and deleted successfully.
C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\prxtbuTo2.dll (PUP.Optional.Conduit) -> Quarantined and deleted successfully.
C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\tbuTo2.dll (PUP.Optional.Conduit) -> Quarantined and deleted successfully.
C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\uTorrentControl_v2ToolbarHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
Please scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.

    ESET OnlineScan

  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer.

      Save it to your Desktop.

    • Double click on the esetsmartinstaller_enu.png to download the ESET Smart Installer. icon on your Desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under Scan Settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\ldrtbuTo0.dll a variant of Win32/Toolbar.Conduit.P application cleaned by deleting - quarantined

C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\ldrtbuTor.dll a variant of Win32/Toolbar.Conduit.P application cleaned by deleting - quarantined

C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\prxtbuTor.dll Win32/Toolbar.Conduit.O application cleaned by deleting - quarantined

C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\tbuTo0.dll a variant of Win32/Toolbar.Conduit.B application cleaned by deleting - quarantined

C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$R8LNGCM\tbuTor.dll a variant of Win32/Toolbar.Conduit.B application cleaned by deleting - quarantined

C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$RMFPEGR\nengine.dll Win32/NextLive.A application cleaned by deleting - quarantined

C:\$Recycle.Bin\S-1-5-21-1038941090-660640611-790380482-1000\$RNSI863\OldVersion\Mobogenie\nengine.dll Win32/NextLive.A application cleaned by deleting - quarantined

C:\AdwCleaner\Quarantine\C\Program Files (x86)\greatsAverr\gsqN6HJOL.x64.dll.vir a variant of Win64/Adware.MultiPlug.A application cleaned by deleting - quarantined

C:\AdwCleaner\Quarantine\C\Users\Zephram\AppData\Local\genienext\nengine.dll.vir Win32/NextLive.A application cleaned by deleting - quarantined

C:\Program Files (x86)\GS Supporter\Assistant.dll a variant of Win32/SProtector.D application cleaned by deleting (after the next restart) - quarantined

C:\Program Files (x86)\GS Supporter\AssistantSvc.dll a variant of Win32/SProtector.D application cleaned by deleting (after the next restart) - quarantined

C:\Users\Zephram\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2V1EFQ7F\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}[1].cpi a variant of Win32/PriceGong.A application deleted - quarantined

C:\Users\Zephram\AppData\Local\Temp\tbedrs.dll a variant of Win32/Toolbar.Conduit.B application cleaned by deleting - quarantined

F:\Downloads\cbsidlm-cbsi145-Revo_Uninstaller-ORG-10687648.exe a variant of Win32/CNETInstaller.B application cleaned by deleting - quarantined

F:\Downloads\PFConfig 1.0.296+working serial\PFCSetup.exe a variant of Win32/Bundled.Toolbar.Ask application cleaned by deleting - quarantined

F:\Video\Black Swan {2010} DVDRIP. Jaybob\Jaybob's_Movies_Toolbar_Internet Explorer.exe a variant of Win32/Toolbar.Conduit.B application cleaned by deleting - quarantined
Download TFC to your desktop

  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
Please let me know how are things now.
Glad I could help! :)

Step 1

  • Download OTL to your desktop and run it.
  • Click on CleanUp button.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.
Step 2
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Uninstall
  • Confirm with Yes
Step 3

Please uninstall ESET Online Scanner .

Step 4

Some malware preventions:


Safe surfing! :)

