0 Members and 1 Guest are viewing this topic.
:OTLIE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuyDyEtDyE0AyC0DzytAyEzy0E0D0ByB0BtN0D0Tzu0StBtBtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=63096674IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuyDyEtDyE0AyC0DzytAyEzy0E0D0ByB0BtN0D0Tzu0StBtBtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=63096674IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuyDyEtDyE0AyC0DzytAyEzy0E0D0ByB0BtN0D0Tzu0StBtBtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=63096674IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuyDyEtDyE0AyC0DzytAyEzy0E0D0ByB0BtN0D0Tzu0StBtBtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=63096674IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKU\S-1-5-21-493578736-2699321852-2876254052-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://mystart.incredibar.com/mb167?a=6OyHeoKjqa&i=26IE - HKU\S-1-5-21-493578736-2699321852-2876254052-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuyDyEtDyE0AyC0DzytAyEzy0E0D0ByB0BtN0D0Tzu0StBtBtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=63096674IE - HKU\S-1-5-21-493578736-2699321852-2876254052-1000\..\SearchScopes,Backup.Old.DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}IE - HKU\S-1-5-21-493578736-2699321852-2876254052-1000\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}IE - HKU\S-1-5-21-493578736-2699321852-2876254052-1000\..\SearchScopes\{2C3EDA03-637F-2333-42C5-4986C6D8E1EB}: "URL" = http://mystart.incredibar.com/mb167/?search={searchTerms}&loc=IB_DS&a=6OyHeoKjqa&i=26IE - HKU\S-1-5-21-493578736-2699321852-2876254052-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuyDyEtDyE0AyC0DzytAyEzy0E0D0ByB0BtN0D0Tzu0StBtBtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=63096674FF - prefs.js..keyword.URL: "http://mystart.incredibar.com/mb167/?loc=IB_DS&a=6OyHeoKjqa&&i=26&search="[2012/07/07 12:08:53 | 000,002,203 | ---- | M] () -- C:\Users\wandrey\AppData\Roaming\Mozilla\Firefox\Profiles\k9rm65cf.default\searchplugins\MyStart Search.xml[2012/08/10 22:08:24 | 000,002,335 | ---- | M] () -- C:\Users\wandrey\AppData\Roaming\Mozilla\Firefox\Profiles\k9rm65cf.default\searchplugins\Search.xml[2012/08/10 22:06:08 | 000,384,844 | ---- | C] () -- C:\Users\wandrey\AppData\Local\funmoods-speeddial.crx:Filesipconfig /flushdns /c:Commands[purity][resethosts][emptytemp][CREATERESTOREPOINT][Reboot]
Hi StrongManBR,Could you also run and attach the logs for Malwarebytes, aswMBR.exe? You can find these programs here: http://forum.avast.com/index.php?topic=53253.0 and also a guide on how to proceed. There is a possibility there is more to it than Incredibar on your system.OTL can be like a sledgehammer to kill a gnat; and worse still, it can damage your system, if run in the wrong hands. A malware specialist will be along soon to look at your logs.
:OTLFF - prefs.js..browser.search.defaultenginename: "v9"FF - prefs.js..browser.search.order.1: "v9"FF - prefs.js..browser.search.selectedEngine: "v9"[2012/08/11 00:40:49 | 000,000,402 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\v9.xml:Filesipconfig /flushdns /c:Commands[purity][resethosts][emptytemp][CREATERESTOREPOINT][Reboot]
Could you confirm it is just Firefox Also there should be a user.js file on the root c driveCould you copy that Change the extension to .txt and attach that Warning This fix is only relevant for this system and no other, using on another computer may cause problems Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot Run OTLUnder the Custom Scans/Fixes box at the bottom, paste in the followingQuote:OTLFF - prefs.js..browser.search.defaultenginename: "v9"FF - prefs.js..browser.search.order.1: "v9"FF - prefs.js..browser.search.selectedEngine: "v9"[2012/08/11 00:40:49 | 000,000,402 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\v9.xml:Filesipconfig /flushdns /c:Commands[purity][resethosts][emptytemp][CREATERESTOREPOINT][Reboot]Then click the Run Fix button at the topLet the program run unhindered, reboot the PC when it is doneOpen OTL again and click the Quick Scan button. Post the log it produces in your next reply.
Delete that user.js it is full of incredibar then retry firefox
:OTLIE - HKU\S-1-5-21-493578736-2699321852-2876254052-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=ism&from=ism&uid=12078201000006890A84_CorsairForceGT&ts=1344656448IE - HKU\S-1-5-21-493578736-2699321852-2876254052-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.v9.com/web/?q={searchTerms}