Still quite a bit of stuff to remove. Still, we're getting there. 
NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
Next ....
Run a new scan and search for me with FRST on the next account (if there are any left that we haven't yet scanned) and post me the new logs please.
- Click Start
- Type notepad.exe in the search programs and files box and click Enter.
- A blank Notepad page should open.
- Copy/Paste the contents of the code box below into Notepad. (don't include Code: Select all)
HKU\S-1-5-21-4229975068-1931466670-3666739151-1001\...\MountPoints2: {4eef8173-e036-11e1-8a92-c89cdcb53833} - E:\LaunchU3.exe -a
HKU\S-1-5-21-4229975068-1931466670-3666739151-1002\...\MountPoints2: {4eef8173-e036-11e1-8a92-c89cdcb53833} - F:\LaunchU3.exe -a
HKU\S-1-5-21-4229975068-1931466670-3666739151-1003\...\MountPoints2: F - F:\LaunchU3.exe -a
HKU\S-1-5-21-4229975068-1931466670-3666739151-1003\...\MountPoints2: {4eef8173-e036-11e1-8a92-c89cdcb53833} - E:\LaunchU3.exe -a
HKU\S-1-5-21-4229975068-1931466670-3666739151-1004\...\MountPoints2: {4eef8173-e036-11e1-8a92-c89cdcb53833} - F:\LaunchU3.exe -a
URLSearchHook: HKU\S-1-5-21-4229975068-1931466670-3666739151-1004 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
URLSearchHook: HKU\S-1-5-21-4229975068-1931466670-3666739151-1005 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
URLSearchHook: HKU\S-1-5-21-4229975068-1931466670-3666739151-1006 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
SearchScopes: HKU\S-1-5-21-4229975068-1931466670-3666739151-1002 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1Qzu0Czzzy0C0D0C0ByDtAzztAtAyDtAyB0EtN0D0Tzu0CtCzzyEtN1L2XzutBtFtCtFtDtFtAtDtC&cr=996414931
SearchScopes: HKU\S-1-5-21-4229975068-1931466670-3666739151-1002 -> Backup.Old.DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
SearchScopes: HKU\S-1-5-21-4229975068-1931466670-3666739151-1002 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1Qzu0Czzzy0C0D0C0ByDtAzztAtAyDtAyB0EtN0D0Tzu0CtCzzyEtN1L2XzutBtFtCtFtDtFtAtDtC&cr=996414931
SearchScopes: HKU\S-1-5-21-4229975068-1931466670-3666739151-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-4229975068-1931466670-3666739151-1004 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-4229975068-1931466670-3666739151-1005 -> {72DE6055-3568-696D-18F3-25733E4372F6} URL =
SearchScopes: HKU\S-1-5-21-4229975068-1931466670-3666739151-1006 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
Toolbar: HKU\S-1-5-21-4229975068-1931466670-3666739151-1006 -> No Name - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - No File
CHR StartupUrls: Default -> "hxxp://Vosteran.com/?f=7&a=vst_cmi_14_47_ch&cd=2XzuyEtN2Y1L1Qzu0Czzzy0C0D0C0ByDtAzztAtAyDtAyB0EtN0D0Tzu0StCtDyDyBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1OtN1L1G1B1V1N2Y1L1Qzu2StAzz0B0A0DtB0E0AtG0ByByByDtGyE0FyByBtG0FtB0C0FtGtAyDyDyEtBtB0DtDtD0EtAzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0Azy0FyB0EyD0FtGyCzztAtAtGyEtDyDyEtGzztB0FtDtG0AyC0B0AtDzy0EtCyB0E0DyE2Q&cr=960361997&ir="
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION" /v "ALOTWidgets.exe" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_CLIPCHILDREN_OPTIMIZATION" /v "ALOTWidgets.exe" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1002\Software\AppDataLow\Software\alotappbar" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\AppDataLow\Software\alotappbar" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1004\Software\AppDataLow\Software\alotappbar" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1005\Software\AppDataLow\Software\alotappbar" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1006\Software\AppDataLow\Software\alotappbar" /f
Reg: Reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders" /v "C:\Users\Daddy\AppData\Roaming\BabylonToolbar\Shared\" /f
Reg: Reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders" /v "C:\Users\Daddy\AppData\Roaming\BabylonToolbar\CR\" /f
Reg: Reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders" /v "C:\Users\Daddy\AppData\Roaming\BabylonToolbar\IE\" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1002\Software\AppDataLow\Software\BlockAndSurf" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\AppDataLow\Software\BlockAndSurf" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1004\Software\AppDataLow\Software\BlockAndSurf" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1005\Software\AppDataLow\Software\BlockAndSurf" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1006\Software\AppDataLow\Software\BlockAndSurf" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1002\Software\DealCabby" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted" /v "C:\Users\Mommy\Downloads\EasyDriverPro.exe" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E540A74-25E-4C6A-91C5-AEFB8C9E7258}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E197BA28-6497-4D92-8BC-7BA8888B5B5}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1002\Software\AppDataLow\Software\Savepass 3.0" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\AppDataLow\Software\Savepass 3.0" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16985C8-3D0C-4A34-8939-8C89E46B4622}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{291C2B3E-BC10-47B9-82F7-476F237FD90}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2AEC82FB-F75E-4086-B041-7F34AAD0E3F6}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4772716C-A71E-48BB-859C-873545C762F0}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{645608CD-FC18-474E-924F-68573FD6DCB3}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E0133CF-F549-4DC4-B7CE-947660F01EBA}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C87B9BB-842C-4424-8096-B832D41FD6CC}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E540A74-25E-4C6A-91C5-AEFB8C9E7258}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4E5D7E7-37ED-4592-9BDE-E1AEB758C25E}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C19BF089-7D4D-420C-B470-C482F42960BD}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D3A14A00-B866-4D44-9D68-28F0F527B2E6}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0E45F32-C550-41DC-A81B-B0915D64E8E3}" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1004\Software\AppDataLow\Software\Savepass 3.0" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1006\Software\AppDataLow\Software\Savepass 3.0" /f
Reg: Reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING" /v "snipsmart.BOAS.exe" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\AppDataLow\Software\snipsmart" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\snipsmart" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1382c0bf_0" /v "" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\apisnipsmartinfo-a.akamaihd.net" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\snipsmart" /f
Reg: Reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.webp\OpenWithProgids" /v "VosteranHTML.XAQEHVRZTKJGE27YQRA7GQFX4I" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Microsoft\Direct3D\MostRecentApplication" /v "Name" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice" /v "Progid" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice" /v "Progid" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice" /v "Progid" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice" /v "Progid" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Classes\.xht" /v "" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001\Software\Classes\http\DefaultIcon" /v "" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001_Classes\.html" /v "" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001_Classes\ftp\DefaultIcon" /v "" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1001_Classes\https\DefaultIcon" /v "" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1002\Software\AppDataLow\Software\zoomify" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1003\Software\AppDataLow\Software\zoomify" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1004\Software\AppDataLow\Software\zoomify" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1005\Software\AppDataLow\Software\zoomify" /f
Reg: Reg.exe delete "HKEY_USERS\S-1-5-21-4229975068-1931466670-3666739151-1006\Software\AppDataLow\Software\zoomify" /f
Hosts:
EmptyTemp:
- Save it to the same folder/directory that FRST.exe is in, naming it as fixlist.txt
NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
- Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
- Press the Fix button once and wait.
- FRST will process fixlist.txt
- When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
- Please post me the log
Next ....
Run a new scan and search for me with FRST on the next account (if there are any left that we haven't yet scanned) and post me the new logs please.