Hi,
Start > Run, copy - paste the content below
notepad C:\Program Files\PATCH.BAT
Enter
Notepad will be open with contents. Save that notepad to your desktop ( file > save us ) and attach it here.
------------------------------------------
Re-run
OTL.exe.
- Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
:OTL
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=fmtoby&chnl=fmtoby&cd=2XzuyEtN2Y1L1QzutDtDtCyBtAtCtAtCyBtCtB0AyB0AzytDtN0D0Tzu0CtBtDtDtN1L2XzutBtFtCtFtDtFtAtDtC&cr=1245145440
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.clampton.com/
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes,Backup.Old.DefaultScope = {0CFF4DA9-D584-47E8-AFDA-43D049082B70}
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes\{0CFF4DA9-D584-47E8-AFDA-43D049082B70}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=fmtoby&chnl=fmtoby&cd=2XzuyEtN2Y1L1QzutDtDtCyBtAtCtAtCyBtCtB0AyB0AzytDtN0D0Tzu0CtBtDtDtN1L2XzutBtFtCtFtDtFtAtDtC&cr=1245145440
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}: "URL" = http://search.alot.com/web?q={searchTerms}&pr=prov&client_id=D079994001CC0F1D1EFEB21A&install_time=2011-05-10T14:23:26Z&src_id=12251&camp_id=2556&tb_version=2.5.18000.3
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes\{73F57A96-B175-4A4D-97FC-C92FB76C86CE}: "URL" = http://websearch.ask.com/custom/java/redirect?client=ie&tb=ORJ&o=100000028&src=crm&q={searchTerms}&locale=&apn_ptnrs=U4&apn_dtid=OSJ000
CHR - homepage: http://www.delta-search.com/?affID=120519&tt=190313_wctrl&babsrc=HP_ss&mntrId=6C6A00173131712A
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\WebBrowser: (no name) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - No CLSID value found.
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-CFC3-3CECC9AB2EDA} - No CLSID value found.
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA5F15C4
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:40FEC790
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
:FILES
C:\Install.exe
ipconfig /flushdns /c
ipconfig /release /c
ipconfig /renew /c
:COMMANDS
[CREATERESTOREPOINT]
[emptytemp]
- Then click the Run Fix button at the top.
- Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
-----------------------------------
Please download
Junkware Removal Tool to your desktop.
- Shut down your protection software now to avoid potential conflicts.
- Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
- The tool will open and start scanning your system.
- Please be patient as this can take a while to complete depending on your system's specifications.
- On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
- Post the contents of JRT.txt into your next message.
************************
Re-run OTL, just click on QuickScan and attach fresh OTL.txt logreport.