MalwareRemoval.com provides free support for people with infected computers.

Unread postby lmtis » July 4th, 2013, 10:36 am

When browsing I am constantly having add pages, tabs, and hover things popping up. Help please! My OS is Vista and I use Firefox for browsing.

Re: Browser infected?

Unread postby melboy » July 4th, 2013, 5:34 pm

Hi and welcome to the MR forums. :)

I'm melboy and I am going to try to help you with your problem. Please take note of the following:

  1. I will be working on your Malware issues this may or may not solve other issues you have with your machine.
  2. The fixes are specific to your problem and should only be used for this issue on this machine.
  3. If you don't know or understand something, please don't hesitate to ask.
  4. Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc...)
  5. Please DO NOT run any other tools or scans whilst I am helping you.
  6. It is important that you reply to this thread. Do not start a new topic.
  7. DO NOT attach logs unless requested to. Please copy/paste all requested logs into your replies.
  8. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  9. Absence of symptoms does not mean that everything is clear.

NOTE: Please take time to read the Malware Removal Forum Guidelines and Rules where the conditions for receiving help at this forum are explained.

IMPORTANT: Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.

No Reply Within 3 Days Will Result In Your Topic Being Closed!! If you need more time, please inform me.


Uninstall Programs

  • Go to start > control panel > programs and features.
  • Right click on each instance of:
    Adobe Reader 8.1.2
    ASPCA Reminder by We-Care.com v4.1.22.1
    Internet Explorer Toolbar 4.8 by SweetPacks
    Java(TM) 6 Update 6
    SweetPacks Updater Service
    Updater By SweetPacks
  • Click Uninstall & then follow the prompts to remove them.


Download AdwCleaner from HERE & save it to your desktop.

  • Right click AdwCleaner.exe & chosse "Run as Administrator" to run it.
  • Click Search.
  • A logfile will automatically open after the scan has finished.
  • Close the adwCleaner window, click ok to the prompt.
  • Post the contents of that logfile with your next reply.
  • You can also find the logfile at C:\AdwCleaner[R1].txt.
Re: Browser infected?

Unread postby lmtis » July 5th, 2013, 10:03 am

Thank you Melboy, I can already see improvement. I keep getting a message saying that Adobe Flash Player 11.7 r700 has stopped working. Also, when I open a new tab in Firefox, it opens to:


Scan data:

# AdwCleaner v2.304 - Logfile created 07/05/2013 at 09:57:33
# Updated 03/07/2013 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : Pete - PETE-PC
# Boot Mode : Normal
# Running from : C:\Users\Pete\Desktop\adwcleaner.exe
# Option [Search]

***** [Services] *****

***** [Files / Folders] *****

File Found : C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\b32qold8.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Found : C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\b32qold8.default\searchplugins\SweetIm.xml
Folder Found : C:\Program Files\SweetIM
Folder Found : C:\Program Files\Trymedia
Folder Found : C:\Users\Pete\AppData\Local\Smartbar
Folder Found : C:\Users\Pete\AppData\Local\Temp\Smartbar
Folder Found : C:\Users\Pete\AppData\LocalLow\Smartbar
Folder Found : C:\Users\Pete\AppData\Roaming\OpenCandy

***** [Registry] *****

Key Found : HKCU\Software\IM
Key Found : HKCU\Software\ImInstaller
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\SmartBar
Key Found : HKCU\Software\SmartbarBackup
Key Found : HKCU\Software\SmartbarLog
Key Found : HKCU\Software\wecarereminder
Key Found : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5EB0259D-AB79-4AE6-A6E6-24FFE21C3DA4}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Found : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute
Key Found : HKLM\SOFTWARE\Classes\IESmartBar.BHO
Key Found : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel
Key Found : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar
Key Found : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject
Key Found : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState
Key Found : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm
Key Found : HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Key Found : HKLM\SOFTWARE\Software
Key Found : HKU\S-1-5-21-397148462-3030776477-163826579-1000\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}
Key Found : HKU\S-1-5-21-397148462-3030776477-163826579-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.19437

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.sweetpacks.com/?src=10&st= ... 045&barid={03E63A50-E42C-11E2-AD1E-001E3363C0D4}
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.sweetpacks.com/?src=10&st= ... 045&barid={03E63A50-E42C-11E2-AD1E-001E3363C0D4}

-\\ Mozilla Firefox v22.0 (en-US)

File : C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\b32qold8.default\prefs.js

Found : user_pref("browser.newtab.url", "hxxp://start.sweetpacks.com/?barid={03E63A50-E42C-11E2-AD1E-001E336[...]
Found : user_pref("extensions.dynconff.JS.SFMNAppData", "%5B%7B%22d%22%3A%22start.sweetpacks.com%22%2C%22t%2[...]
Found : user_pref("extensions.dynconff.cache.app.noproblemppc.com.content", "<package expire=\"3600\" es=\"9[...]
Found : user_pref("extensions.dynconff.cache.login.yahoo.com.content", "<package expire=\"3600\" es=\"914\" [...]
Found : user_pref("extensions.dynconff.cache.my.yahoo.com.content", "<package expire=\"3600\" es=\"914\" pcd[...]
Found : user_pref("extensions.dynconff.cache.plugin.we-care.com.content", "<package expire=\"3600\" es=\"914[...]
Found : user_pref("extensions.dynconff.cache.start.sweetpacks.com.content", "<package expire=\"3600\" es=\"9[...]
Found : user_pref("extensions.dynconff.cache.start.sweetpacks.com.expires", "1373034837396");
Found : user_pref("extensions.dynconff.cache.tracking.si.com.content", "<package expire=\"3600\" es=\"914\" [...]
Found : user_pref("extensions.dynconff.cache.us-mg5.mail.yahoo.com.content", "<package expire=\"3600\" es=\"[...]
Found : user_pref("extensions.dynconff.cache.www.malwareremoval.com.content", "<package expire=\"3600\" es=\[...]
Found : user_pref("extensions.helperbar.SmartbarDisabled", false);
Found : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Found : user_pref("extensions.wecarereminder.merchHash", "{\"AFFILIATES\":{\"1-Sale-A-Day\":{\"name\":\"1 Sa[...]
Found : user_pref("keyword.URL", "hxxp://start.sweetpacks.com?src=6&barid={03E63A50-E42C-11E2-AD1E-001E3363C[...]
Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://www.msn.com/");
Found : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Found : user_pref("sweetim.toolbar.urls.homepage", "hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.[...]


AdwCleaner[R1].txt - [8565 octets] - [05/07/2013 09:57:33]

########## EOF - C:\AdwCleaner[R1].txt - [8625 octets] ##########
Re: Browser infected?

Unread postby melboy » July 5th, 2013, 12:52 pm


Let me know how things are running after deleting with AdwCleaner and let me know if there are any outstanding issues.


  • Right click AdwCleaner.exe & choose "Run as Administrator" to run it.
  • Click Delete.
  • Click OK to the prompt.
  • The tool will run & your computer will be rebooted automatically. A logfile will open after the restart.
  • Post the contents of the logfile with your next reply.
  • You can also find the logfile at C:\AdwCleaner[s1].txt.
Re: Browser infected?

Unread postby lmtis » July 6th, 2013, 8:35 am

It is definitely doing better, but I still have a couple of problems. I periodically get a warning dialog box that says

"Warning: Unresponsive plugin"

"Shockwave Flash may be busy, or it may have stopped responding. You can stop the plugin now, or you can continue to see if the plugin will complete."

Also, whenever I open a new tab in Firefox it opens to a sweetpacks page:


which usually has a malware type warning dialog on it. I cannot find where to set the page that a new tab opens to.

Thanks for your help,
Re: Browser infected?

Unread postby melboy » July 6th, 2013, 8:55 am

Hi :)

Have you re-run AdwCleaner as above to delete the items found?
Re: Browser infected?

Unread postby lmtis » July 6th, 2013, 9:27 am

Sorry, I didn't read closely enough! I did not go back and delete. I have now, and the new tabs are now blank. I will let you know how it goes with the "Flash" warning.

Re: Browser infected?

Unread postby melboy » July 6th, 2013, 10:32 am

Post the AdwCleaner log for me to see.

For the flash problem there's information here that may help. I don't think that issue is malware related in any way.
Re: Browser infected?

Unread postby lmtis » July 6th, 2013, 11:26 am

Would you recommend that I update Flash now? I didn't want to make any changes without your direction before you tell me that you are finished helping me.

Thank you again for your help.

# AdwCleaner v2.304 - Logfile created 07/06/2013 at 09:13:05
# Updated 03/07/2013 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : Pete - PETE-PC
# Boot Mode : Normal
# Running from : C:\Users\Pete\Desktop\adwcleaner.exe
# Option [Delete]

***** [Services] *****

***** [Files / Folders] *****

File Deleted : C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\b32qold8.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Deleted : C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\b32qold8.default\searchplugins\SweetIm.xml
Folder Deleted : C:\Program Files\SweetIM
Folder Deleted : C:\Program Files\Trymedia
Folder Deleted : C:\Users\Pete\AppData\Local\Smartbar
Folder Deleted : C:\Users\Pete\AppData\Local\Temp\Smartbar
Folder Deleted : C:\Users\Pete\AppData\LocalLow\Smartbar
Folder Deleted : C:\Users\Pete\AppData\Roaming\OpenCandy

***** [Registry] *****

Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\SmartbarBackup
Key Deleted : HKCU\Software\SmartbarLog
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5EB0259D-AB79-4AE6-A6E6-24FFE21C3DA4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BHO
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Key Deleted : HKLM\SOFTWARE\Software
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.19437

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.sweetpacks.com/?src=10&st= ... 045&barid={03E63A50-E42C-11E2-AD1E-001E3363C0D4} --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.sweetpacks.com/?src=10&st= ... 045&barid={03E63A50-E42C-11E2-AD1E-001E3363C0D4} --> hxxp://www.google.com

-\\ Mozilla Firefox v22.0 (en-US)

File : C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\b32qold8.default\prefs.js

Deleted : user_pref("browser.newtab.url", "hxxp://start.sweetpacks.com/?barid={03E63A50-E42C-11E2-AD1E-001E336[...]
Deleted : user_pref("extensions.dynconff.JS.SFMNAppData", "%5B%7B%22d%22%3A%22start.sweetpacks.com%22%2C%22t%2[...]
Deleted : user_pref("extensions.dynconff.cache.app.noproblemppc.com.content", "<package expire=\"3600\" es=\"9[...]
Deleted : user_pref("extensions.dynconff.cache.login.yahoo.com.content", "<package expire=\"3600\" es=\"914\" [...]
Deleted : user_pref("extensions.dynconff.cache.my.yahoo.com.content", "<package expire=\"3600\" es=\"914\" pcd[...]
Deleted : user_pref("extensions.dynconff.cache.plugin.we-care.com.content", "<package expire=\"3600\" es=\"914[...]
Deleted : user_pref("extensions.dynconff.cache.start.sweetpacks.com.content", "<package expire=\"3600\" es=\"9[...]
Deleted : user_pref("extensions.dynconff.cache.start.sweetpacks.com.expires", "1373034837396");
Deleted : user_pref("extensions.dynconff.cache.tracking.si.com.content", "<package expire=\"3600\" es=\"914\" [...]
Deleted : user_pref("extensions.dynconff.cache.us-mg5.mail.yahoo.com.content", "<package expire=\"3600\" es=\"[...]
Deleted : user_pref("extensions.dynconff.cache.www.malwareremoval.com.content", "<package expire=\"3600\" es=\[...]
Deleted : user_pref("extensions.helperbar.SmartbarDisabled", false);
Deleted : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Deleted : user_pref("extensions.wecarereminder.merchHash", "{\"AFFILIATES\":{\"1-Sale-A-Day\":{\"name\":\"1 Sa[...]
Deleted : user_pref("keyword.URL", "hxxp://start.sweetpacks.com?src=6&barid={03E63A50-E42C-11E2-AD1E-001E3363C[...]
Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://www.msn.com/");
Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Deleted : user_pref("sweetim.toolbar.urls.homepage", "hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.[...]


AdwCleaner[R1].txt - [8694 octets] - [05/07/2013 09:57:33]
AdwCleaner[R2].txt - [8754 octets] - [06/07/2013 09:12:31]
AdwCleaner[S1].txt - [8623 octets] - [06/07/2013 09:13:05]

########## EOF - C:\AdwCleaner[S1].txt - [8683 octets] ##########
Re: Browser infected?

Unread postby melboy » July 6th, 2013, 6:04 pm


lmtis wrote:Would you recommend that I update Flash now?

Yes, update Flash.


Uncheck any unnecessary extras that may be offered (Mcafee Security Scan, Google Toolbar etc), before downloading.

Let me know how things are running.
Re: Browser infected?

Unread postby melboy » July 8th, 2013, 6:48 pm

melboy wrote:Let me know how things are running.

Hi lmtis

It has been two days since my last post.

  • Do you still need help?
  • Do you need more time?
  • Are you having problems following my instructions?
  • In accordance with Malware Removal policy, topics can be closed after 3 days without a response. If you do not reply within the next 24 hours, this topic will be closed.
Re: Browser infected?

Unread postby lmtis » July 9th, 2013, 7:43 pm

Hi melboy,

I am still trying to evaluate the performance. I inherited this laptop and am trying to see what I need to do to make it right. We re basically using it as a kitchen PC that is basically used for nothing other than the internet. I am still getting periods where it freezes for as long as a minute. I appreciate what you have done for me, and I know that there is a time pressure, but I would really like either a little more time to evaluate before closing, or if you can think of any way to find the reason for the lockups that would be great.

Re: Browser infected?

Unread postby melboy » July 10th, 2013, 1:15 pm

Hi Jim

We'll continue to see if there's anything amiss.


Download OTL by Old Timer and save it to your Desktop.

  • Double click on OTL.exe to run it.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened
    • Extras.txt <-- Will be minimized
  • Please post the contents of these 2 Notepad files in your next reply.
Re: Browser infected?

Unread postby Wingman » July 13th, 2013, 9:33 am

Due to a lack of response, this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
