I decided to run hijack this and found two BHO's. It's funny that on my new install that I used a handful of times, I have adware, but on this install that's been going for years, I have nothing. Oh well. So I had "Crossrider" and "Coupon Companion". I removed all traces of both, yet still no go. It looks like this managed to install itself on 12/2... which had to be damn close to the date that I bought the SSD, however, I had internet activity as recent as 12/26. Here's the log of what Coupon Companion did:
1354500268 -
1354500268 - --------------------------- Installer started ---------------------------
1354500268 -
1354500268 - appid: 4493
1354500268 - installername: 4493.exe
1354500268 - installertype: 12417
1354500268 - appname: Coupon Companion
1354500268 - publisher: 215 Apps
1354500268 - publisherid: 390
1354500268 - installerfullversion: 1.24.151.151
1354500268 - platformversion: 1
1354500268 - installerscriptversion: 24
1354500268 - bhoversion: 151
1354500268 - helperversion: 151
1354500268 - bhoguid: 11111111-1111-1111-1111-110011441193
1354500268 - scrambletoken: 8093c230043101303486692df6c812c4
1354500268 - Installing IE extension
1354500268 - Firefox extension is bundled
1354500268 - Chrome extension is bundled
1354500268 - CmdLine:
1354500268 - Function onInit started.
1354500268 - Read the OS: V7
1354500268 - App registry path: Software\AppDataLow\Software\Coupon Companion
1354500268 - srcid: 100086
1354500268 - subid: default
1354500268 - zdata: 100086&subid=&pid=1322
1354500268 - No app ver was found in the registry.
1354500268 - No old platform ver was found in the registry.
1354500268 - Installer platform ver: 1.
1354500268 - Bic was not found in Software\AppDataLow\Software\Crossrider. Need to create one.
1354500268 - Bic: D725F83F0E284D0B86BDCCAF387568B6IE.
1354500268 - Verifier: ba82b082b7a4ade8d69fd70a4253a17b.
1354500268 - 215 App Verifier: 1c33c8f442f50355c31676ef714de463.
1354500268 - Read the full IE version from the registry: 9.0.8112.16421
1354500268 - IE short version: 9
1354500268 - Read the default browser: ff
1354500268 - User is admin.
1354500268 - Switching to silent mode.
1354500268 - Attempting to send ping:
http://stats.crossrider.com/installe...pe=12417&asw=0
1354500268 - Ping result: OK
1354500269 - Sending ping to 215 apps:
http://www.ping-track.com/installer-...ubid=&pid=1322
1354500269 - Section Install started.
1354500269 - Extracting to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\mixer.exe
1354500269 - Extracting to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp
1354500269 - Unmixing C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp
1354500269 - Copying from C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\installer_util.exe
1354500269 - Installing a fresh copy of Coupon Companion.
1354500269 - SoftwareDetected: <{"AnySoftware":false,"Wireshark":false,"VirtualBox":false,"VMWare":false,"InsideVM":false,"InsideVM Ware":false,"InsideVirtualBox":false,"InsideVirtualPc":false}>
1354500269 - Check if IE is open
1354500269 - Check if FF is open
1354500269 - FF is open
1354500269 - Check if CH is open
1354500271 - Deploying IE extension files
1354500271 - Creating folder: C:\Program Files (x86)\Coupon Companion
1354500271 - Copying from C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\installer_util.exe to C:\Program Files (x86)\Coupon Companion\Coupon Companion.exe
1354500271 - Copying from C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\installer_util.exe to C:\Program Files (x86)\Coupon Companion\Coupon Companion-bg.exe
1354500271 - Extracting to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp
1354500271 - Unmixing C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp
1354500271 - Copying from C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp to C:\Program Files (x86)\Coupon Companion\ButtonUtil.dll
1354500271 - Extracting to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp
1354500271 - Unmixing C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp
1354500271 - Copying from C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp to C:\Program Files (x86)\Coupon Companion\Coupon Companion.dll
1354500271 - Extracting to C:\Program Files (x86)\Coupon Companion\Coupon Companion.ico
1354500271 - installer_alternative: 3
1354500271 - Setting uninstallation registry keys.
1354500271 - Auto enabling extension for IE.
1354500271 - Setting BHO elevation policy. Guid: 11111111-1111-1111-1111-110011441193.
1354500271 - Setting BG elevation policy. Guid: 21111111-1111-1111-1111-110011441193.
1354500271 - Registering BHO.
1354500272 - Writing installed app to global registry: Software\InstalledBrowserExtensions\215 Apps
1354500272 - Check if IE is open
1354500272 - Check if FF is open
1354500272 - Check if CH is open
1354500272 - Installing Firefox extension
1354500272 - Extracting to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp
1354500272 - Unmixing C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp
1354500272 - Copying from C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\Coupon Companion.xpi
1354500272 - Function InstallXpi started
1354500272 - Mozilla base is C:\Program Files (x86)\Mozilla Firefox\firefox.exe
1354500272 - controlling user is Windows 7
1354500272 - Profile root is C:\Users
1354500272 - going to open C:\Users\All Users\AppData\Roaming\Mozilla\Firefox\profiles.ini
1354500272 - profiles.ini does not exist for this user
1354500272 - going to open C:\Users\Default\AppData\Roaming\Mozilla\Firefox\profiles.ini
1354500272 - profiles.ini does not exist for this user
1354500272 - going to open C:\Users\Public\AppData\Roaming\Mozilla\Firefox\profiles.ini
1354500272 - profiles.ini does not exist for this user
1354500272 - going to open C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\profiles.ini
1354500272 - successfully opened C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\profiles.ini
1354500272 - Auto enabling extension for FF
1354500272 - Didn't find autoDisableScopes for this file: C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\jugf08vy.default\prefs.js
1354500272 - Creating pref in firefox file: extensions.crossriderapp4493.adsOldValue = -1 in file: C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\jugf08vy.default\prefs.js
1354500272 - path is C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\jugf08vy.default\extensions\crossriderapp4493@crossrider. com
1354500272 - Created folder: C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\jugf08vy.default\extensions\crossriderapp4493@crossrider. com
1354500272 - Extracted the XPI into folder: C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\jugf08vy.default\extensions\crossriderapp4493@crossrider. com
1354500272 - Check if IE is open
1354500272 - Check if FF is open
1354500272 - Check if CH is open
1354500272 - Installing Chrome extension
1354500272 - chromeid: pbkdpahkifcigckmhiafindmaflfifgm
1354500272 - chromeversion: 1.20.40
1354500272 - Creating folder: C:\Users\Windows 7\AppData\Local\Coupon Companion\Chrome
1354500272 - Extracting to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp
1354500272 - Unmixing C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_before.tmp to C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp
1354500272 - Copying from C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\temp_file_after.tmp to C:\Users\Windows 7\AppData\Local\Coupon Companion\Chrome\Coupon Companion.crx
1354500272 - Attempting to run VBS: C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\RemoveFromList.vbs
1354500272 - VBS execution finished successfully: C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\RemoveFromList.vbs
1354500272 - Attempting to run VBS: C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\CleanChromePrefs.vbs
1354500272 - VBS execution finished successfully: C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\CleanChromePrefs.vbs
1354500272 - Function SetChromeInstallerParams Started
1354500272 - Databases file does not exist: C:\Users\Windows 7\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db
1354500272 - Copying Chrome databases file to: C:\Users\Windows 7\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db
1354500272 - The extension cookie db index read from the db:
1354500272 - The extension cookie db index is empty so we need to create it
1354500272 - Attempting to run sql command: INSERT INTO Databases (origin, name, description, estimated_size) VALUES('chrome-extension_pbkdpahkifcigckmhiafindmaflfifgm_0','crossrider_cookies_4493','Crossrider Cookies Store',50 * 1024 * 1024);
1354500272 - Chrome sql command finished successfully: Insert into databases...
1354500272 - The extension cookie db index read from the db: 3
1354500272 - Need to create the extension db folder: C:\Users\Windows 7\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_pbkdpahkifcigckmhiafindmaflfifgm_0
1354500272 - Successfully created the extension db folder: C:\Users\Windows 7\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_pbkdpahkifcigckmhiafindmaflfifgm_0
1354500272 - Attempting to run sql command:
1354500272 - C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\scs.exe "C:\Users\Windows 7\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_pbkdpahkifcigckmhiafindmaflfifgm_0\3" "REPLACE INTO cookies (name,value,expires) values('InstallerParams','{\"value\" : { \"source_id\" : \"100086\", \"sub_id\" : \"default\", \"uzid\" : \"100086&subid=&pid=1322\" } }','2111-09-11 21:16:31');"
1354500272 - Chrome sql command finished successfully
1354500272 - Attempting to run sql command:
1354500272 - C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\scs.exe "C:\Users\Windows 7\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_pbkdpahkifcigckmhiafindmaflfifgm_0\3" "REPLACE INTO cookies (name,value,expires) values('InstallationTime','{\"value\" : 1354500268}','2111-09-11 21:16:31');"
1354500272 - Chrome sql command finished successfully
1354500272 - Attempting to run sql command:
1354500272 - C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\scs.exe "C:\Users\Windows 7\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_pbkdpahkifcigckmhiafindmaflfifgm_0\3" "REPLACE INTO cookies (name,value,expires) values('InstallationThankYouPage','{\"value\" : true}','2111-09-11 21:16:31');"
1354500272 - Chrome sql command finished successfully
1354500272 - Attempting to run sql command:
1354500272 - C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\scs.exe "C:\Users\Windows 7\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_pbkdpahkifcigckmhiafindmaflfifgm_0\3" "REPLACE INTO internaldb (name,value,expires) values('InstallerIdentifiers','{\"value\" : { \"installer_bic\" : \"D725F83F0E284D0B86BDCCAF387568B6IE\", \"installer_verifier\" : \"ba82b082b7a4ade8d69fd70a4253a17b\", \"installer_verifier_for_215app\" : \"1c33c8f442f50355c31676ef714de463\" } }','2111-09-11 21:16:31');"
1354500272 - Chrome sql command finished successfully
1354500272 - Attempting to run sql command:
1354500272 - C:\Users\WINDOW~1\AppData\Local\Temp\nsr6FF3.tmp\scs.exe "C:\Users\Windows 7\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_pbkdpahkifcigckmhiafindmaflfifgm_0\3" "REPLACE INTO internaldb (name,value,expires) values('SoftwareDetected','{\"value\" : { \"AnySoftware\" : false,\"Wireshark\" : false,\"VirtualBox\" : false,\"VMWare\" : false,\"InsideVM\":false,\"InsideVMWare\":false,\"InsideVirtualBox\":false,\"InsideVirtualPc\":false } }','2111-09-11 21:16:31');"
1354500272 - Chrome sql command finished successfully
1354500272 - Function onInstSuccess started.
1354500272 - FinishInstallation started
1354500272 - About to run the helper EXE with command line: /installapp=4493 /executebgcode
1354500274 - Helper EXE finished successfully
1354500274 - Attempting to send ping:
http://stats.crossrider.com/installe...pe=12417&asw=0
1354500274 - Ping result: OK
1354500274 - Attempting to send ping:
http://stats.crossrider.com/apps.gif...268&lifetime=0
1354500274 - Ping result: OK
1354500275 - Sending ping to 215 apps:
http://www.ping-track.com/tbi-ping/D...ubid=&pid=1322
1354500275 - Sending ping to 215 apps:
http://www.ping-track.com/newuser-pi...&os=V7&admin=1
1354500275 - Read thank you page url: NA
1354500275 - thank you page url is NA, not opening any browser.
1354500275 -
1354500275 - --------------------------- Installer ended ---------------------------
1354500275 -