A family member downloaded some sort of coupon garbage that had an attached toolbar and "Strongvault Online Backup" option. I tried to remove everything that had installed, but ever since that time, when anything is right clicked the Strongvault residue / installer tries to open briefly and then closes. Strongvault is still listed in the right click menu options too.
In general, it seems my computer is running more slowly since this occurred. Any help appreciated. Below are my logs (ran them last week, but havent had a chance to post until now):
AdwCleaner Log
# AdwCleaner v2.304 - Logfile created 07/10/2013 at 21:06:49
# Updated 03/07/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : John R Twist - DELL-8300
# Boot Mode : Normal
# Running from : C:\Documents and Settings\John R Twist\My Documents\Downloads\adwcleaner(1).exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\bProtector_extensions.rdf
File Deleted : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\bprotector_extensions.sqlite
File Deleted : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\BrowserMngr_extensions.sqlite
File Deleted : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\searchplugins\web-search.xml
File Deleted : C:\END
Folder Deleted : C:\Documents and Settings\All Users\Application Data\FreeRIP
Folder Deleted : C:\Documents and Settings\John R Twist\Local Settings\Application Data\Coupon Companion Plugin
Folder Deleted : C:\Documents and Settings\John R Twist\Local Settings\Application Data\PackageAware
Folder Deleted : C:\Documents and Settings\John R Twist\Local Settings\Application Data\Zoom_Downloader
***** [Registry] *****
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\Crossrider
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B00FE392-639D-4688-976E-A1BFF368CB96}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] Registry is clean.
-\\ Mozilla Firefox v15.0.1 (en-US)
File : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\prefs.js
Deleted : user_pref("browser.search.selectedEngine", "Web Search");
Deleted : user_pref("keyword.URL", "hxxp://websearch.shopathome.com?user_id={287ea785-f85d-4ba0-8aae-b39d0b9a6[...]
*************************
AdwCleaner[S1].txt - [12152 octets] - [30/09/2012 09:19:17]
AdwCleaner[S2].txt - [2749 octets] - [10/07/2013 21:06:49]
########## EOF - C:\AdwCleaner[S2].txt - [2809 octets] ##########
mbam log
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.07.15.06
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
John R Twist :: DELL-8300 [administrator]
Protection: Disabled
7/17/2013 8:08:30 PM
mbam-log-2013-07-17 (20-08-30).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 393214
Time elapsed: 1 hour(s), 41 minute(s), 5 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Security Check log
Results of screen317's Security Check version 0.99.68
Windows XP Service Pack 3 x86
Internet Explorer 8 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Symantec AntiVirus Corporate Edition
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
CCleaner
Java(TM) 6 Update 23
Java 7 Update 21
Java(TM) 6 Update 3
Java version out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox 15.0.1 Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Symantec AntiVirus DefWatch.exe
Symantec AntiVirus Rtvscan.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 17% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
In general, it seems my computer is running more slowly since this occurred. Any help appreciated. Below are my logs (ran them last week, but havent had a chance to post until now):
AdwCleaner Log
# AdwCleaner v2.304 - Logfile created 07/10/2013 at 21:06:49
# Updated 03/07/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : John R Twist - DELL-8300
# Boot Mode : Normal
# Running from : C:\Documents and Settings\John R Twist\My Documents\Downloads\adwcleaner(1).exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\bProtector_extensions.rdf
File Deleted : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\bprotector_extensions.sqlite
File Deleted : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\BrowserMngr_extensions.sqlite
File Deleted : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\searchplugins\web-search.xml
File Deleted : C:\END
Folder Deleted : C:\Documents and Settings\All Users\Application Data\FreeRIP
Folder Deleted : C:\Documents and Settings\John R Twist\Local Settings\Application Data\Coupon Companion Plugin
Folder Deleted : C:\Documents and Settings\John R Twist\Local Settings\Application Data\PackageAware
Folder Deleted : C:\Documents and Settings\John R Twist\Local Settings\Application Data\Zoom_Downloader
***** [Registry] *****
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\Crossrider
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B00FE392-639D-4688-976E-A1BFF368CB96}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] Registry is clean.
-\\ Mozilla Firefox v15.0.1 (en-US)
File : C:\Documents and Settings\John R Twist\Application Data\Mozilla\Firefox\Profiles\adirnwn8.default\prefs.js
Deleted : user_pref("browser.search.selectedEngine", "Web Search");
Deleted : user_pref("keyword.URL", "hxxp://websearch.shopathome.com?user_id={287ea785-f85d-4ba0-8aae-b39d0b9a6[...]
*************************
AdwCleaner[S1].txt - [12152 octets] - [30/09/2012 09:19:17]
AdwCleaner[S2].txt - [2749 octets] - [10/07/2013 21:06:49]
########## EOF - C:\AdwCleaner[S2].txt - [2809 octets] ##########
mbam log
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.07.15.06
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
John R Twist :: DELL-8300 [administrator]
Protection: Disabled
7/17/2013 8:08:30 PM
mbam-log-2013-07-17 (20-08-30).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 393214
Time elapsed: 1 hour(s), 41 minute(s), 5 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Security Check log
Results of screen317's Security Check version 0.99.68
Windows XP Service Pack 3 x86
Internet Explorer 8 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Symantec AntiVirus Corporate Edition
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
CCleaner
Java(TM) 6 Update 23
Java 7 Update 21
Java(TM) 6 Update 3
Java version out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox 15.0.1 Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Symantec AntiVirus DefWatch.exe
Symantec AntiVirus Rtvscan.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 17% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````