Hello all,
So my cousins laptop is displaying weird windows while he is on twitch.tv and other sites. Here are the logs..
# AdwCleaner v3.308 - Report created 30/08/2014 at 22:17:59
# Updated 20/08/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Owner-1 - COMPUTER
# Running from : C:\Users\Owner-1\Desktop\adwcleaner_3.308.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : APNMCP
[#] Service Deleted : Update ClearThink
[#] Service Deleted : Util ClearThink
Service Deleted : {c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\2308189059
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\Program Files\AskPartnerNetwork
Folder Deleted : C:\Program Files\GamesBar
Folder Deleted : C:\Program Files\Level Quality Watcher
Folder Deleted : C:\Program Files\SavingsBull
Folder Deleted : C:\Program Files\SavingsbullFilter
Folder Deleted : C:\Program Files\wse_astromenda
[!] Folder Deleted : C:\Program Files\ClearThink
Folder Deleted : C:\Windows\Installer\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
Folder Deleted : C:\Users\Owner-1\AppData\Local\AskPartnerNetwork
Folder Deleted : C:\Users\Owner-1\AppData\Local\VNT
Folder Deleted : C:\Users\Owner-1\AppData\Local\Temp\ClearThink
Folder Deleted : C:\Users\Owner-1\AppData\Roaming\Astromenda
Folder Deleted : C:\Users\Owner-1\AppData\Roaming\Search Protection
Folder Deleted : C:\Users\Owner-1\AppData\Roaming\wse_astromenda
Folder Deleted : C:\Users\Owner-1\Documents\Optimizer Pro
File Deleted : C:\END
File Deleted : C:\Windows\system32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw.sys
File Deleted : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage
File Deleted : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage-journal
File Deleted : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Scheduled Tasks ] *****
Task Deleted : LaunchSignup
Task Deleted : Optimizer Pro Schedule
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pljcgbedjplidkdjahbaalanadmjfgop
Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BRS]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SearchProtection]
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ClearThink_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ClearThink_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updateClearThink_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updateClearThink_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilClearThink_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilClearThink_RASMANCS
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update ClearThink
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util ClearThink
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7e6d4e3e-fc66-4036-9799-ce5c625c4c56}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8972B0D-B0FB-4158-A567-365283693AD6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{06e035f9-c6b3-4ae7-a839-ba68791f5499}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e6d4e3e-fc66-4036-9799-ce5c625c4c56}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7e6d4e3e-fc66-4036-9799-ce5c625c4c56}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\Astromenda
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\WSE_Astromenda
Key Deleted : HKCU\Software\ClearThink
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\Search Protection
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\AskPartnerNetwork
Key Deleted : HKLM\SOFTWARE\GoforFiles
Key Deleted : HKLM\SOFTWARE\InstallCore
Key Deleted : HKLM\SOFTWARE\LevelQualityWatcher
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\SavingsBullFilter
Key Deleted : HKLM\SOFTWARE\ClearThink
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ac225167-00fc-452d-94c5-bb93600e7d9a}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Astromenda
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows5.0.0.7
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ClearThink
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C19AC53289098045B06B0DD1D37CBAB
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23D9E9D21B4E77E41B9F50DD22F24E20
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23EEA1F105A7F45449974D9B95E7AC89
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\26982796A8AFD1246B95E00265A95BF9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42D92D0D75AFEF74297E03876C8D9D33
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50FFE845C555A6E4BADB7CB7A145BFEB
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\715A3348920B6534690067594BB69F60
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B7B13B037A7C2A42AC3E3EAF14D7107
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D05B2942E9CC80499F397F6114DFB35
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8591B8948E1C4A04F90505B3CDEE8555
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8D841C5FEC311624CB88D49DB3884FA7
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD04033484A18CA4CAB3EE59D39D756E
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD746BF3B3B3FD8409B86604BA85982A
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F355F0DB7A2E3A14B8E7A568FBA25937
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1708EDD6AB4EB164A86999D0AF0ABE1D
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\1708EDD6AB4EB164A86999D0AF0ABE1D
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\1708EDD6AB4EB164A86999D0AF0ABE1D
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17239
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Google Chrome v36.0.1985.143
[ File : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Search Provider] : hxxp://www.search.ask.com/web?tpid=ORJ-V7C&o=APN11411&l=dis&pf=V7&p2=%5EBBJ%5EOSJ000%5EYY%5EUS&gct=&itbv=12.12.2.83&doi=2014-07-02&apn_uid=4AC8DD0D-F4AC-4D0C-9550-0D47EBE6D4DA&apn_ptnrs=BBJ&apn_dtid=%5EOSJ000%5EYY%5EUS&apn_dbr=cr_35.0.1916.153&psv=&pt=tb&trgb=CR&q={searchTerms}
Deleted [Search Provider] : hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_suma_14_50_ch&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDyD0FyD0Azzzz0F0DyEyBtN0D0Tzu0SzyyDyEtN1L2XzutAtFtDtFtCtDtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDtDzytA0Azz0EtBtGtB0AtC0EtGtByE0CyEtGyCyE0AyDtGyC0Azzzz0E0EzztDyDyByD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StB0F0CtB0CzytCtDtGtA0ByEtAtGyEzzyD0EtGzztAzzyBtGyC0BtDtCyB0FyE0Ezz0CzzyB2Q&cr=1316248977&ir=
Deleted [Startup_urls] : hxxp://astromenda.com/?f=7&a=ast_suma_14_50_ch&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDyD0FyD0Azzzz0F0DyEyBtN0D0Tzu0SzyyDyEtN1L2XzutAtFtDtFtCtDtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDtDzytA0Azz0EtBtGtB0AtC0EtGtByE0CyEtGyCyE0AyDtGyC0Azzzz0E0EzztDyDyByD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StB0F0CtB0CzytCtDtGtA0ByEtAtGyEzzyD0EtGzztAzzyBtGyC0BtDtCyB0FyE0Ezz0CzzyB2Q&cr=1316248977&ir=
Deleted [Startup_urls] : hxxp://www.search.ask.com/?tpid=ORJ-V7C&o=APN11411&pf=V7&trgb=CR&p2=%5EBBJ%5EOSJ000%5EYY%5EUS&gct=hp&apn_ptnrs=BBJ&apn_dtid=%5EOSJ000%5EYY%5EUS&apn_dbr=cr_35.0.1916.153&apn_uid=4AC8DD0D-F4AC-4D0C-9550-0D47EBE6D4DA&itbv=12.12.2.83&doi=2014-07-02&psv=&pt=tb
Deleted [Homepage] : hxxp://astromenda.com/?f=1&a=ast_suma_14_50_ch&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDyD0FyD0Azzzz0F0DyEyBtN0D0Tzu0SzyyDyEtN1L2XzutAtFtDtFtCtDtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDtDzytA0Azz0EtBtGtB0AtC0EtGtByE0CyEtGyCyE0AyDtGyC0Azzzz0E0EzztDyDyByD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StB0F0CtB0CzytCtDtGtA0ByEtAtGyEzzyD0EtGzztAzzyBtGyC0BtDtCyB0FyE0Ezz0CzzyB2Q&cr=1316248977&ir=
Deleted [Extension] : pljcgbedjplidkdjahbaalanadmjfgop
*************************
AdwCleaner[R0].txt - [12147 octets] - [30/08/2014 22:15:56]
AdwCleaner[S0].txt - [11507 octets] - [30/08/2014 22:17:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11568 octets] ##########
And
Results of screen317's Security Check version 0.99.87
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Windows Firewall Disabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 60
Java version out of Date!
Adobe Flash Player 14.0.0.145
Adobe Reader XI
Google Chrome 36.0.1985.125
Google Chrome 36.0.1985.143
Google Chrome plugins...
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Malwarebytes Anti-Malware mbamscheduler.exe
iolo System Mechanic iologovernor.exe
iolo Common Lib ioloServiceManager.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
And
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 8/30/2014
Scan Time: 10:30:56 PM
Logfile: fdsf.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.31.01
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Owner-1
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 281000
Time Elapsed: 8 min, 55 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 3
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{10AD2C61-0898-4348-8600-14A342F22AC3}, Quarantined, [1409933a0873b77f4f823b3e927047b9],
PUP.Optional.ClearThink.A, HKLM\SOFTWARE\ClearThink, Quarantined, [e03d8d40a3d8e6502f0b2334c53fbb45],
PUP.Optional.ClearThink.A, HKU\S-1-5-21-1484660218-3856736019-134160805-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ClearThink, Quarantined, [4fcebb12611a6dc9003be5727c88e020],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 3
PUP.Optional.Amonetize, C:\Users\Owner-1\Downloads\alien vs predator arcade game pc__3039_i984502094_il2406994.exe, Quarantined, [c6577c51fe7dc76fce659b02837e30d0],
PUP.Optional.Astromenda.A, C:\Windows\System32\Tasks\WSE_Astromenda, Quarantined, [32ebfdd0eb90bc7a6bda46a746bc19e7],
PUP.Optional.Astromenda.A, C:\Windows\Tasks\WSE_Astromenda.job, Quarantined, [5dc0686581fa8da9b096668715ed0df3],
Physical Sectors: 0
(No malicious items detected)
(end)
and
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 8/30/2014
Scan Time: 10:28:54 PM
Logfile: ss.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.31.01
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Owner-1
Scan Type: Threat Scan
Result: Cancelled
Objects Scanned: 0
(No malicious items detected)
Time Elapsed: 0 min, 23 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
So my cousins laptop is displaying weird windows while he is on twitch.tv and other sites. Here are the logs..
# AdwCleaner v3.308 - Report created 30/08/2014 at 22:17:59
# Updated 20/08/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Owner-1 - COMPUTER
# Running from : C:\Users\Owner-1\Desktop\adwcleaner_3.308.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : APNMCP
[#] Service Deleted : Update ClearThink
[#] Service Deleted : Util ClearThink
Service Deleted : {c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\2308189059
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\Program Files\AskPartnerNetwork
Folder Deleted : C:\Program Files\GamesBar
Folder Deleted : C:\Program Files\Level Quality Watcher
Folder Deleted : C:\Program Files\SavingsBull
Folder Deleted : C:\Program Files\SavingsbullFilter
Folder Deleted : C:\Program Files\wse_astromenda
[!] Folder Deleted : C:\Program Files\ClearThink
Folder Deleted : C:\Windows\Installer\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
Folder Deleted : C:\Users\Owner-1\AppData\Local\AskPartnerNetwork
Folder Deleted : C:\Users\Owner-1\AppData\Local\VNT
Folder Deleted : C:\Users\Owner-1\AppData\Local\Temp\ClearThink
Folder Deleted : C:\Users\Owner-1\AppData\Roaming\Astromenda
Folder Deleted : C:\Users\Owner-1\AppData\Roaming\Search Protection
Folder Deleted : C:\Users\Owner-1\AppData\Roaming\wse_astromenda
Folder Deleted : C:\Users\Owner-1\Documents\Optimizer Pro
File Deleted : C:\END
File Deleted : C:\Windows\system32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw.sys
File Deleted : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage
File Deleted : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage-journal
File Deleted : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Scheduled Tasks ] *****
Task Deleted : LaunchSignup
Task Deleted : Optimizer Pro Schedule
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pljcgbedjplidkdjahbaalanadmjfgop
Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BRS]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SearchProtection]
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ClearThink_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ClearThink_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updateClearThink_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updateClearThink_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilClearThink_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilClearThink_RASMANCS
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update ClearThink
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util ClearThink
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7e6d4e3e-fc66-4036-9799-ce5c625c4c56}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8972B0D-B0FB-4158-A567-365283693AD6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{06e035f9-c6b3-4ae7-a839-ba68791f5499}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e6d4e3e-fc66-4036-9799-ce5c625c4c56}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7e6d4e3e-fc66-4036-9799-ce5c625c4c56}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\Astromenda
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\WSE_Astromenda
Key Deleted : HKCU\Software\ClearThink
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\Search Protection
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\AskPartnerNetwork
Key Deleted : HKLM\SOFTWARE\GoforFiles
Key Deleted : HKLM\SOFTWARE\InstallCore
Key Deleted : HKLM\SOFTWARE\LevelQualityWatcher
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\SavingsBullFilter
Key Deleted : HKLM\SOFTWARE\ClearThink
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ac225167-00fc-452d-94c5-bb93600e7d9a}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Astromenda
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows5.0.0.7
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ClearThink
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C19AC53289098045B06B0DD1D37CBAB
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23D9E9D21B4E77E41B9F50DD22F24E20
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23EEA1F105A7F45449974D9B95E7AC89
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\26982796A8AFD1246B95E00265A95BF9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42D92D0D75AFEF74297E03876C8D9D33
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50FFE845C555A6E4BADB7CB7A145BFEB
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\715A3348920B6534690067594BB69F60
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B7B13B037A7C2A42AC3E3EAF14D7107
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D05B2942E9CC80499F397F6114DFB35
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8591B8948E1C4A04F90505B3CDEE8555
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8D841C5FEC311624CB88D49DB3884FA7
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD04033484A18CA4CAB3EE59D39D756E
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD746BF3B3B3FD8409B86604BA85982A
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F355F0DB7A2E3A14B8E7A568FBA25937
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1708EDD6AB4EB164A86999D0AF0ABE1D
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\1708EDD6AB4EB164A86999D0AF0ABE1D
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\1708EDD6AB4EB164A86999D0AF0ABE1D
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17239
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Google Chrome v36.0.1985.143
[ File : C:\Users\Owner-1\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Search Provider] : hxxp://www.search.ask.com/web?tpid=ORJ-V7C&o=APN11411&l=dis&pf=V7&p2=%5EBBJ%5EOSJ000%5EYY%5EUS&gct=&itbv=12.12.2.83&doi=2014-07-02&apn_uid=4AC8DD0D-F4AC-4D0C-9550-0D47EBE6D4DA&apn_ptnrs=BBJ&apn_dtid=%5EOSJ000%5EYY%5EUS&apn_dbr=cr_35.0.1916.153&psv=&pt=tb&trgb=CR&q={searchTerms}
Deleted [Search Provider] : hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_suma_14_50_ch&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDyD0FyD0Azzzz0F0DyEyBtN0D0Tzu0SzyyDyEtN1L2XzutAtFtDtFtCtDtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDtDzytA0Azz0EtBtGtB0AtC0EtGtByE0CyEtGyCyE0AyDtGyC0Azzzz0E0EzztDyDyByD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StB0F0CtB0CzytCtDtGtA0ByEtAtGyEzzyD0EtGzztAzzyBtGyC0BtDtCyB0FyE0Ezz0CzzyB2Q&cr=1316248977&ir=
Deleted [Startup_urls] : hxxp://astromenda.com/?f=7&a=ast_suma_14_50_ch&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDyD0FyD0Azzzz0F0DyEyBtN0D0Tzu0SzyyDyEtN1L2XzutAtFtDtFtCtDtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDtDzytA0Azz0EtBtGtB0AtC0EtGtByE0CyEtGyCyE0AyDtGyC0Azzzz0E0EzztDyDyByD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StB0F0CtB0CzytCtDtGtA0ByEtAtGyEzzyD0EtGzztAzzyBtGyC0BtDtCyB0FyE0Ezz0CzzyB2Q&cr=1316248977&ir=
Deleted [Startup_urls] : hxxp://www.search.ask.com/?tpid=ORJ-V7C&o=APN11411&pf=V7&trgb=CR&p2=%5EBBJ%5EOSJ000%5EYY%5EUS&gct=hp&apn_ptnrs=BBJ&apn_dtid=%5EOSJ000%5EYY%5EUS&apn_dbr=cr_35.0.1916.153&apn_uid=4AC8DD0D-F4AC-4D0C-9550-0D47EBE6D4DA&itbv=12.12.2.83&doi=2014-07-02&psv=&pt=tb
Deleted [Homepage] : hxxp://astromenda.com/?f=1&a=ast_suma_14_50_ch&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDyD0FyD0Azzzz0F0DyEyBtN0D0Tzu0SzyyDyEtN1L2XzutAtFtDtFtCtDtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDtDzytA0Azz0EtBtGtB0AtC0EtGtByE0CyEtGyCyE0AyDtGyC0Azzzz0E0EzztDyDyByD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StB0F0CtB0CzytCtDtGtA0ByEtAtGyEzzyD0EtGzztAzzyBtGyC0BtDtCyB0FyE0Ezz0CzzyB2Q&cr=1316248977&ir=
Deleted [Extension] : pljcgbedjplidkdjahbaalanadmjfgop
*************************
AdwCleaner[R0].txt - [12147 octets] - [30/08/2014 22:15:56]
AdwCleaner[S0].txt - [11507 octets] - [30/08/2014 22:17:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11568 octets] ##########
And
Results of screen317's Security Check version 0.99.87
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Windows Firewall Disabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 60
Java version out of Date!
Adobe Flash Player 14.0.0.145
Adobe Reader XI
Google Chrome 36.0.1985.125
Google Chrome 36.0.1985.143
Google Chrome plugins...
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Malwarebytes Anti-Malware mbamscheduler.exe
iolo System Mechanic iologovernor.exe
iolo Common Lib ioloServiceManager.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
And
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 8/30/2014
Scan Time: 10:30:56 PM
Logfile: fdsf.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.31.01
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Owner-1
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 281000
Time Elapsed: 8 min, 55 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 3
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{10AD2C61-0898-4348-8600-14A342F22AC3}, Quarantined, [1409933a0873b77f4f823b3e927047b9],
PUP.Optional.ClearThink.A, HKLM\SOFTWARE\ClearThink, Quarantined, [e03d8d40a3d8e6502f0b2334c53fbb45],
PUP.Optional.ClearThink.A, HKU\S-1-5-21-1484660218-3856736019-134160805-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ClearThink, Quarantined, [4fcebb12611a6dc9003be5727c88e020],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 3
PUP.Optional.Amonetize, C:\Users\Owner-1\Downloads\alien vs predator arcade game pc__3039_i984502094_il2406994.exe, Quarantined, [c6577c51fe7dc76fce659b02837e30d0],
PUP.Optional.Astromenda.A, C:\Windows\System32\Tasks\WSE_Astromenda, Quarantined, [32ebfdd0eb90bc7a6bda46a746bc19e7],
PUP.Optional.Astromenda.A, C:\Windows\Tasks\WSE_Astromenda.job, Quarantined, [5dc0686581fa8da9b096668715ed0df3],
Physical Sectors: 0
(No malicious items detected)
(end)
and
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 8/30/2014
Scan Time: 10:28:54 PM
Logfile: ss.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.31.01
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Owner-1
Scan Type: Threat Scan
Result: Cancelled
Objects Scanned: 0
(No malicious items detected)
Time Elapsed: 0 min, 23 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)