HI and thanks for the response,ok as requested adwcleaner log
# AdwCleaner v2.306 - Logfile created 08/12/2013 at 14:13:56
# Updated 19/07/2013 by Xplode
# Operating system : Windows Vista (TM) Home Basic Service Pack 1 (32 bits)
# User : Darran - DARRAN-PC
# Boot Mode : Normal
# Running from : C:\Users\Darran\Downloads\adwcleaner(2).exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted : C:\ProgramData\EbookkBBrowSe
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EbookkBBrowSe
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\safeee saavve
Folder Deleted : C:\ProgramData\safeee saavve
Folder Deleted : C:\Users\Darran\AppData\Local\Google\Chrome\User Data\Default\Extensions\blhmgdgajeeceaggicflaihgcbmdfcko
Folder Deleted : C:\Users\Darran\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlbinibidegpidngjlaemekkkepgflnl
Folder Deleted : C:\Users\Darran\AppData\Local\PackageAware
Folder Deleted : C:\Users\Darran\AppData\LocalLow\EbookkBBrowSe
Folder Deleted : C:\Users\Darran\AppData\LocalLow\safeee saavve
Folder Deleted : C:\Users\Darran\AppData\Roaming\Mozilla\Firefox\Profiles\urjd6bnf.default-1360272701897\extensions\eyy-3os@ouoiyuaezh.net
Folder Deleted : C:\Users\Darran\AppData\Roaming\Mozilla\Firefox\Profiles\urjd6bnf.default-1360272701897\extensions\iuuu_4uaa@oiege-q.org
Folder Deleted : C:\Users\Darran\AppData\Roaming\Mozilla\Firefox\Profiles\urjd6bnf.default-1360272701897\jetpack
***** [Registry] *****
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{60FD0270-4F78-9E59-BC3A-A3A1176B1630}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E623350D-C03E-C978-2269-F6B675CDA038}
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60FD0270-4F78-9E59-BC3A-A3A1176B1630}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E623350D-C03E-C978-2269-F6B675CDA038}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60FD0270-4F78-9E59-BC3A-A3A1176B1630}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E623350D-C03E-C978-2269-F6B675CDA038}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{924C3DC2-8E4E-432E-F973-9A2174A39774}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E5B7E1B4-21FC-6765-A3D7-BA0416DC6AF7}
***** [Internet Browsers] *****
-\\ Internet Explorer v7.0.6001.18639
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] =
hxxp://search.fbdownloader.com/?channel=sfuk205 -->
hxxp://www.google.com-\\ Mozilla Firefox v22.0 (en-GB)
File : C:\Users\Darran\AppData\Roaming\Mozilla\Firefox\Profiles\urjd6bnf.default-1360272701897\prefs.js
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.fbdownloader.com/search.php?channel=sfuk205&q=[...]
Deleted : user_pref("extensions.51c354fac7cba.scode", "if(window.self.location.protocol.indexOf('hxxp')>-1 && [...]
Deleted : user_pref("extensions.51c35532f03db.scode", "(function(){try{if(window.opener&&window.self==window.t[...]
Deleted : user_pref("keyword.URL", "hxxp://search.fbdownloader.com/search.php?channel=sfuk205&q=");
-\\ Google Chrome v [Unable to get version]
File : C:\Users\Darran\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[S1].txt - [1945 octets] - [07/02/2013 22:38:13]
AdwCleaner[S2].txt - [4067 octets] - [12/08/2013 14:13:56]
########## EOF - C:\AdwCleaner[S2].txt - [4127 octets] ##########
JRT LOG
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.4.4 (08.12.2013:1)
OS: Windows Vista (TM) Home Basic x86
Ran by Darran on 13/08/2013 at 14:37:35.08
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\scheck
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ssync
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Darran\AppData\Roaming\scheck"
Successfully deleted: [Folder] "C:\Users\Darran\AppData\Roaming\ssync"
Successfully deleted: [Folder] "C:\Users\Darran\appdata\locallow\baidu"
Successfully deleted: [Folder] "C:\Program Files\baidu"
~~~ FireFox
Emptied folder: C:\Users\Darran\AppData\Roaming\mozilla\firefox\profiles\urjd6bnf.default-1360272701897\minidumps [59 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13/08/2013 at 14:41:07.69
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
MBMAM LOG
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.orgDatabase version: v2013.08.13.03
Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 7.0.6001.18000
Darran :: DARRAN-PC [administrator]
14/08/2013 18:04:46
mbam-log-2013-08-14 (18-04-46).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 664400
Time elapsed: 8 hour(s), 4 minute(s), 49 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 9
C:\Users\Darran\AppData\Roaming\Common\LuaRT (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\luasql (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\alien (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\decode (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\Microsoft.VC80.CRT (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\mime (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\socket (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
Files Detected: 55
C:\Users\Darran\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OXRC4965\OptimizerPro[1].exe (PUP.Optional.OptimizePro.A) -> Quarantined and deleted successfully.
C:\Users\Darran\Downloads\Bradcot Awnings Brochure pdf.exe (PUP.Optional.Installex) -> Quarantined and deleted successfully.
C:\Users\Darran\Downloads\user manual FORD MONDEO 2847413 pdf.exe (PUP.Optional.Installex) -> Quarantined and deleted successfully.
C:\Users\Darran\Downloads\setup(1).exe (PUP.Optional.InstallCore) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\alien.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\base.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\debug_ext.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\debug_init.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\getopt.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\io_ext.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\lfs.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\list.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\lpeg.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\ltn12.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\lua5.1.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\lua51.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\luacom.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\math_ext.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\mime.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\modules.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\package_ext.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\set.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\socket.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\std.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\strbuf.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\string_ext.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\table_ext.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\tree.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\wlua.exe (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\luasql\sqlite3.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\alien\core.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\alien\struct.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\decode.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\util.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\decode\array.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\decode\calls.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\decode\number.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\decode\object.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\decode\others.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\decode\strings.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\decode\util.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode\array.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode\calls.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode\number.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode\object.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode\others.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode\output.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode\output_utility.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\json\encode\strings.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\mime\core.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\socket\core.dll (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\socket\http.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
C:\Users\Darran\AppData\Roaming\Common\LuaRT\socket\url.lua (PUP.Optional.LuaRT.A) -> Quarantined and deleted successfully.
(end)
SECURITY CHECK LOG
Results of screen317's
Security Check version 0.99.72
Windows Vista Service Pack 1
x86 (UAC is enabled)
Out
of date service pack!!
Internet Explorer 7
Out of date!
``````````````Antivirus/Firewal
l Check:`````````````` Windows Firewall Enabled!
Windows Firewall Disabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-
malware/Other Utilities
Check:````````` Spybot - Search & Destroy
Malwarebytes Anti-Malware
version 1.75.0.1300
Java(TM) 6 Update 37
Java version out
of Date! Adobe Flash Player
11.7.700.224
Adobe Reader 9
Adobe Reader out of Date!
Mozilla Firefox 22.0
Firefox out of
Date! ````````Process Check:
objlist.exe by Laurent````````
Microsoft Security Essentials
MSMpEng.exe
Microsoft Security Essentials
msseces.exe
`````````````````System
Health check`````````````````
Total Fragmentation on Drive
C: 5 %
Defragment
your hard drive soon! (Do NOT
defrag if SSD!)````````````````````End
of Log``````````````````````
THANKS FOR YOUR TIME:smile2: