Removing easylifeapp?

Obtained the first txt file in the manner I've used for this one. That is, used Manager Att......
 

My Computer

OS
home premium 64bit
Run the Delete

:ar: Close all open programs.

:ar: To run the program, right-click AdwCleaner.exe and select Run as administrator

:ar: Click on Delete and confirm the prompt.

:ar: After it finishes, the computer is restarted.

Upload the log saved at C:\AdwCleaner[S1].txt
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Do not 'save' to word .... it should be saved to notepad. Copy and paste the notepad .txt
C:\AdwCleaner[S1].txt in your next post. You may have to divide it into two posts.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Strange. When I tried with Notepad text, it became all jumbled, so I didn't post it. Anyway ...
Notepad part 1 text:

# AdwCleaner v2.303 - Logfile created 06/12/2013 at 21:15:17
# Updated 08/06/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Wayne - SOLARBLAST1
# Boot Mode : Normal
# Running from : C:\Users\Wayne\Downloads\AdwCleaner.exe
# Option [Search]


***** [Services] *****

Found : CltMngSvc

***** [Files / Folders] *****

File Found : C:\END
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\adawaretb.xml
File Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\bProtector_extensions.rdf
File Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\searchplugins\Babylon.xml
File Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\searchplugins\Conduit.xml
File Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\searchplugins\delta.xml
File Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\searchplugins\EasyLife.xml
File Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\rr5cfg1s.AstroGuy\searchplugins\delta.xml
File Found : C:\Windows\Tasks\AmiUpdXp.job
File Found : C:\Windows\Tasks\DSite.job
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\EasyLife
Folder Found : C:\Program Files (x86)\Mozilla Firefox\Extensions\[email protected]
Folder Found : C:\Program Files (x86)\SearchProtect
Folder Found : C:\Program Files (x86)\Vaudix
Folder Found : C:\Program Files (x86)\Vaudix
Folder Found : C:\Program Files (x86)\Vgrabber_v1.5
Folder Found : C:\Program Files (x86)\WhiteSmoke_New
Folder Found : C:\Program Files (x86)\Wondershare
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\InstallMate
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SaveByClick
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vaudix
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vaudix
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
Folder Found : C:\ProgramData\search protection
Folder Found : C:\ProgramData\SoftSafe
Folder Found : C:\ProgramData\Vaudix
Folder Found : C:\ProgramData\Vaudix
Folder Found : C:\Users\Wayne\AppData\Local\AVG Secure Search
Folder Found : C:\Users\Wayne\AppData\Local\Conduit
Folder Found : C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccngiooofklpnnmmcplileaanildgmai
Folder Found : C:\Users\Wayne\AppData\Local\OpenCandy
Folder Found : C:\Users\Wayne\AppData\Local\SwvUpdater
Folder Found : C:\Users\Wayne\AppData\Local\Wondershare
Folder Found : C:\Users\Wayne\AppData\LocalLow\Conduit
Folder Found : C:\Users\Wayne\AppData\LocalLow\pdfforge
Folder Found : C:\Users\Wayne\AppData\LocalLow\PriceGong
Folder Found : C:\Users\Wayne\AppData\LocalLow\Search Settings
Folder Found : C:\Users\Wayne\AppData\LocalLow\Vgrabber_v1.5
Folder Found : C:\Users\Wayne\AppData\LocalLow\WhiteSmoke_New
Folder Found : C:\Users\Wayne\AppData\Roaming\BabSolution
Folder Found : C:\Users\Wayne\AppData\Roaming\Babylon
Folder Found : C:\Users\Wayne\AppData\Roaming\DSite
Folder Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\ConduitCommon
Folder Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\extensions\{73507124-6acd-43aa-b749-c3bcfefbea97}
Folder Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a}
Folder Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\extensions\[email protected]
Folder Found : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\rr5cfg1s.AstroGuy\extensions\[email protected]
Folder Found : C:\Users\Wayne\AppData\Roaming\OpenCandy
Folder Found : C:\Users\Wayne\AppData\Roaming\pdfforge
Folder Found : C:\Users\Wayne\AppData\Roaming\SearchProtect

***** [Registry] *****

Data Found : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\easylife\sprote~1.dll
Data Found : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\vaudix\sprote~1.dll
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Software\Vgrabber_v1.5
Key Found : HKCU\Software\AppDataLow\Software\WhiteSmoke_New
Key Found : HKCU\Software\AppDataLow\SProtector
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\BabSolution
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\DataMngr_Toolbar
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{73507124-6ACD-43AA-B749-C3BCFEFBEA97}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1BB8B3AE-757D-443F-B3A4-0629E709B0D9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{73507124-6ACD-43AA-B749-C3BCFEFBEA97}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Key Found : HKCU\Software\pdfforge
Key Found : HKCU\Software\Search Settings
Key Found : HKCU\Software\SearchProtect
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\Vgrabber_v1.5
Key Found : HKCU\Software\WhiteSmoke_New
Key Found : HKCU\Software\YahooPartnerToolbar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{01BD49D7-C76B-4310-8BEB-14D7E5F322C6}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Key Found : HKLM\Software\AVG Security Toolbar
Key Found : HKLM\Software\Babylon
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Found : HKLM\SOFTWARE\Classes\AppID\BHO.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2953735
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3289847
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3293216
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\DataMngr
Key Found : HKLM\Software\InfoAtoms
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1BB8B3AE-757D-443F-B3A4-0629E709B0D9}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9817FDB5-8C5F-45F7-8740-6DEBD0AEAAE9}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\Software\pdfforge
Key Found : HKLM\Software\Search Settings
Key Found : HKLM\Software\SearchProtect
Key Found : HKLM\Software\SP Global
Key Found : HKLM\Software\SProtector
Key Found : HKLM\Software\Vgrabber_v1.5
Key Found : HKLM\Software\WhiteSmoke_New
Key Found : HKLM\SOFTWARE\Wow6432Node\5c578cdbb13dec47
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1BB8B3AE-757D-443F-B3A4-0629E709B0D9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{73507124-6ACD-43AA-B749-C3BCFEFBEA97}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9817FDB5-8C5F-45F7-8740-6DEBD0AEAAE9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{34E7668C-8785-4559-8E65-44B42844DDAA}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{63972AD1-DD95-4496-85AF-4AA864F8ABDC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6C5983A2-B4A6-478D-9E0E-D2CF7D3CCD0D}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B4BD8983-D9CA-428F-A71D-F6172DAAF00D}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{01BD49D7-C76B-4310-8BEB-14D7E5F322C6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73507124-6ACD-43AA-B749-C3BCFEFBEA97}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{681002C6-5019-81A2-7871-A43754F71E56}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Vgrabber_v1.5 Toolbar
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WhiteSmoke_New Toolbar
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Key Found : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Software
Key Found : HKU\S-1-5-21-716105666-1754228386-2663804873-1001\Software\Microsoft\Internet Explorer\SearchScopes\{01BD49D7-C76B-4310-8BEB-14D7E5F322C6}
Key Found : HKU\S-1-5-21-716105666-1754228386-2663804873-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKU\S-1-5-21-716105666-1754228386-2663804873-1001\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{73507124-6ACD-43AA-B749-C3BCFEFBEA97}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{739DF940-C5EE-4BAB-9D7E-270894AE687A}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{73507124-6ACD-43AA-B749-C3BCFEFBEA97}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{739DF940-C5EE-4BAB-9D7E-270894AE687A}]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [searchprotect]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{73507124-6ACD-43AA-B749-C3BCFEFBEA97}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{739DF940-C5EE-4BAB-9D7E-270894AE687A}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchSettings]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{73507124-6ACD-43AA-B749-C3BCFEFBEA97}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{739DF940-C5EE-4BAB-9D7E-270894AE687A}]

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16576

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.delta-search.com/?affID=119351&babsrc=HP_ss&mntrId=7AB290E6BA3DE1E8
 

My Computer

OS
home premium 64bit
Part 2 text:
-\\ Mozilla Firefox v21.0 (en-US)

File : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\prefs.js

Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2953735&Search[...]
Found : user_pref("aol_toolbar.default.homepage.check", false);
Found : user_pref("aol_toolbar.default.search.check", false);
Found : user_pref("browser.search.defaultthis.engineName", "Vgrabber v1.5 Customized Web Search");
Found : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Found : user_pref("extensions.delta.admin", false);
Found : user_pref("extensions.delta.aflt", "babsst");
Found : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Found : user_pref("extensions.delta.autoRvrt", "false");
Found : user_pref("extensions.delta.dfltLng", "en");
Found : user_pref("extensions.delta.excTlbr", false);
Found : user_pref("extensions.delta.ffxUnstlRst", true);
Found : user_pref("extensions.delta.id", "7ab2510600000000000090e6ba3de1e8");
Found : user_pref("extensions.delta.instlDay", "15868");
Found : user_pref("extensions.delta.instlRef", "sst");
Found : user_pref("extensions.delta.newTab", false);
Found : user_pref("extensions.delta.prdct", "delta");
Found : user_pref("extensions.delta.prtnrId", "delta");
Found : user_pref("extensions.delta.rvrt", "false");
Found : user_pref("extensions.delta.smplGrp", "none");
Found : user_pref("extensions.delta.tlbrId", "base");
Found : user_pref("extensions.delta.tlbrSrchUrl", "");
Found : user_pref("extensions.delta.vrsn", "1.8.21.5");
Found : user_pref("extensions.delta.vrsnTs", "1.8.21.510:35:35");
Found : user_pref("extensions.delta.vrsni", "1.8.21.5");
Found : user_pref("extensions.delta_i.babExt", "");
Found : user_pref("extensions.delta_i.babTrack", "affID=119351");
Found : user_pref("extensions.delta_i.srcExt", "ss");
Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
Found : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
Found : user_pref("sweetim.toolbar.searchguard.enable", "");

File : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\rr5cfg1s.AstroGuy\prefs.js

Found : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289847&octid=CT3289847[...]
Found : user_pref("smartbar.originalHomepage", "about:home");

-\\ Google Chrome v27.0.1453.110

File : C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Preferences

Found [l.1] : search_url ={"browser":{},"countryid_at_install":21843,"default_search_provider":{"id":"2","name":"Google","prepopulate_id":"1","{google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}","suggest_url":"{google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}"},"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":true,"make_chrome_default":false,"show_welcome_page":true,"skip_first_run_ui":true,"verbose_logging":false},"download":{"directory_upgrade":true,"extensions_to_open":""},"extensions":{"autoupdate":{"last_check":"12932525772657431","next_check":"12932837381775878"},"blacklistupdate":{"lastpingday":"12932463599705714"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"settings":{"hchkdglnjoagfcnikmcebkjlfbcbkhnm":{"ack_external":true},"klibnahbojhkanfgaglnlalfkgpcppfi":{"ack_external":true}}},"homepage":"hxxp://www.delta-search.com/?affID=119351&babsrc=HP_ss&mntrId=7AB290E6BA3DE1E8","homepage_is_newtabpage":false,"ntp":{"alt_logo_end":1255028400,"alt_logo_resource_server":"hxxps://www.google.com/support/chrome/bin/topic/30248/inproduct","alt_logo_start":1255028400,"pref_version":3,"shown_sections":1,"tips_cache":{"current_tip":0,"tips":["The <a href=\"hxxp://chrome.google.com/extensions/\">Chrome extensions gallery</a> has over 5,000 extensions! Explore extensions in different categories, such as blogging, shopping, web development, and more.","Parlez-vous français ? Google Chrome's built-in translation bar helps you read more of the Web. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=173424&ctx=tip\">Learn more</a>","Add extra features and functionality to your browser with extensions. Visit the <a href=\"hxxps://chrome.google.com/extensions\" target=\"_blank\">Chrome extensions gallery</a> or <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?hl=en&answer=154007&ctx=tip\" target=\"_blank\">learn more</a>.\n","Click and hold down the back button to see your browsing history.","Customize Google Chrome with themes! Check out designs at the <a href=\"hxxps://tools.google.com/chrome/intl/en/themes/index.html\" target=\"_blank\">Themes Gallery</a>.","When you use the find bar, yellow markers on the scrollbar help you quickly locate matches on the page. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95635&ctx=tip\">Learn more</a>","Search your bookmarks and browsing history from the address bar. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95440&ctx=tip\">Learn more</a>","Have your tabs arranged your way. Click a tab and drag it to a new position along the top of the browser window. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95622&ctx=tips\">Learn more</a>","Quickly resize a tab by dragging it to a docking position on your monitor or browser window. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95622#resize&ctx=tip\">Learn more</a>","Drag a link to the tab strip at the top of your browser window to open it in a new tab.","Press <strong>Ctrl+T</strong> to open a new tab. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Press <strong>Ctrl+N</strong> to open a new browser window. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","To search a site, start typing the site's web address in the address bar and press <strong>Tab</strong> when prompted. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95655&ctx=tip\">search tricks</a>.","Create address bar keywords for search engines you frequently use. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?hl=en&answer=95653&ctx=tips\">Learn how</a>","Press <strong>Ctrl</strong> and + to enlarge a page; <strong>Ctrl</strong> and - to make the page smaller; and <strong>Ctrl</strong> and <strong>0</strong> to return the page to its normal size. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Press <strong>Ctrl+F</strong> to search the page you're viewing. Learn more about <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95635&ctx=tip\">using the find bar</a>.\n","Press <strong>Ctrl+S</strong> to save your current webpage. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Press <strong>Ctrl+P</strong> to print your current webpage. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Press <strong>Ctrl+J</strong> to see a list of files you've downloaded. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Press <strong>Ctrl+H</strong> to see your browsing history. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Click a tab and drag it out of the tab strip to open it in a new window. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95622&ctx=tips\">Learn more</a>\n","Press <strong>Ctrl+Shift+N</strong> to open a new window in incognito mode. Pages you visit while in incognito mode aren't stored in your browsing history. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95464&ctx=tip\">Learn more</a>","Press <strong>Ctrl+O</strong> to open a file in the browser. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Press <strong>F11</strong> to go full screen. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Click the star next to the address bar to bookmark the page you're viewing. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95739&ctx=tip\">bookmarking tricks</a>.\n","Place shortcuts for your favorite sites on your computer desktop. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95710&ctx=tip\">Learn more</a>","Want to hide thumbnails on the New Tab page? Use the controls at the top of the page. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95451&ctx=tip\">Learn more</a>","Drag the star to the bookmarks bar to create a bookmark for the page? Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95739&ctx=tip\">bookmarking tricks</a>.","Drag a link to the bookmarks bar to create an instant bookmark. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95739&ctx=tip\">bookmarking tricks</a>.","Press <strong>Ctrl+Shift+T</strong> repeatedly to reopen the last 10 tabs you closed. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Don't want to leave traces of your browsing history? Browse in incognito mode. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95464&ctx=tip\">Learn more</a>","Accidentally closed a window full of tabs? Find it again in the <strong>Recently closed</strong> section of the New Tab page.","Add a home button next to the address bar. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95314&ctx=tip\">Learn how</a>","Search directly from the address bar. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95655&ctx=tip\">search tips</a>.\n","Press <strong>F6</strong> to quickly place your cursor in the address bar. Learn more <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\">keyboard shortcuts</a>.","Switching between computers? Keep your Google Chrome settings, bookmarks, and themes in sync across computers. <a href=\"hxxp://www.google.com/support/chrome/bin/answer.py?answer=165138&ctx=tip\">Learn how</a>"],"topic_id":"24013"},"tips_cache_update":"1277059040.093496","tips_server":"hxxps://clients2.google.com/tools/service/npredir?r=chrometips_win&hl=en-US","web_resource_cache_update":"1288216977.106448"},"profile":{"content_settings":{"pref_version":1},"exited_cleanly":true,"id":"not-signed-in","name":"","nickname":""},"session":{"restore_on_startup":4,"urls_to_restore_on_startup":["hxxp://www.delta-search.com/?affID=119351&babsrc=HP_ss&mntrId=7AB290E6BA3DE1E8"]},"tabs":{"use_vertical_tabs":false}}

*************************

AdwCleaner[R1].txt - [27831 octets] - [12/06/2013 21:15:17]

########## EOF - C:\AdwCleaner[R1].txt - [27892 octets] ##########
 

My Computer

OS
home premium 64bit
Run Adwcleaner once more this time click on Delete

After the scan IRST will restart your pc . Allow it to . Once you're back inside Windows it will open up a log . Copy and paste that log in with your reply
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Run Adwcleaner once more this time click on Delete

After the scan IRST will restart your pc . Allow it to . Once you're back inside Windows it will open up a log . Copy and paste that log in with your reply

What is IRST? "Allow it to" what?
 

My Computer

OS
home premium 64bit
Use this icon to attach
Attachment 272369
If you're trying to click on this picture of the paper clip to attach the note pad text file.... it certainly won't work!! :p

Right click on AdwCleaner, choose to run as Administrator, click the DELETE button... when done, reboot your computer. You will find a second AdwCleaner.txt by clicking on your Computer (right hand side menu), then clicking on "Local Disk" C:

Click on Post to open a new window in this topic (as you already know how to do, then click on the paper clip next to the down arrow, once it opens up the window that says 'browse', click on the 2nd notepad text that AdwCleaner saved for you. It will put it's file name in the first 'browse' box. Then, post the attachment that you uploaded.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I'm not using the paperclip icon you show.

I'll stick with copying the txt file into the message.
 

My Computer

OS
home premium 64bit
Re-read my post above. I edited it and hopefully it is more clear for you to understand.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Short one this time. 69 lines.

# AdwCleaner v2.303 - Logfile created 06/13/2013 at 18:15:23
# Updated 08/06/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Wayne - SOLARBLAST1
# Boot Mode : Normal
# Running from : C:\Users\Wayne\Downloads\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search
Deleted on reboot : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\rr5cfg1s.AstroGuy\extensions\[email protected]

***** [Registry] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16576

[OK] Registry is clean.

-\\ Mozilla Firefox v21.0 (en-US)

File : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\3mjlqxij.default\prefs.js

Deleted : user_pref("extensions.50ea4fa976323.scode", "(function(){try{if('aol.com,mail.google.com,premiumrepo[...]

File : C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\rr5cfg1s.AstroGuy\prefs.js

[OK] File is clean.

-\\ Google Chrome v27.0.1453.110

File : C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [27916 octets] - [12/06/2013 21:15:17]
AdwCleaner[S1].txt - [19528 octets] - [13/06/2013 08:09:47]
AdwCleaner[S2].txt - [1355 octets] - [13/06/2013 18:15:23]

########## EOF - C:\AdwCleaner[S2].txt - [1415 octets] ##########
 

My Computer

OS
home premium 64bit
Too short ... let us see the entire .txt log.

If you need help to do this, do you have neighbor or someone living in your house that can do this?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Too short ... let us see the entire .txt log.

If you need help to do this, do you have neighbor or someone living in your house that can do this?

That's it. There is no more. Note the EOF in the last line.

Is this the end of any further use of AdwCleaner?

So what has been accomplished? Is easylifeapp now gone? Although I did not expect AcwCleaner to clean out anything but easylife, it removed a Criteo ad that appears on a Google page the first time Google is used after a boot. That's certainly a plus, since it eventually disappears, as I repeatedly use Google.
 

My Computer

OS
home premium 64bit
This (easylifeapp) mess is called Google redirect virus. Here's one YouTube DIY that looks good. <http://www.youtube.com/watch?NR=1&feature=fvwp&v=FjBXMHO4NIk>/ This one starts with a nice intro <http://www.youtube.com/watch?NR=1&feature=fvwp&v=FjBXMHO4NIk> of how redirect works, but the removal windows are pretty fuzzy. Google easylifeapp removal for more. I think the virus can prevent security updates getting to the right place.

As far as I can tell, I'm out of the woods now.
 

My Computer

OS
home premium 64bit
Back
Top