Qtcore4.dll and/or DaemonProcess.exe not found

compused

Posts: 121   +0
My partner's laptop (HP with Vista and Windowsw 98) had 135 viruses found by Malwarebytes which began "Pup .... and most were registry type viruses. We have removed these viruses but when he called up Internet Explorer, he keeps on getting one or the other of the above messages. When he tries to go on the Internet to find out what Qtcore.dll or DaemonProcess.exe is for, it tries to download something and crashes the Internet.


[FONT=Calibri]Malwarebytes Anti-Malware 1.75.0.1300[/FONT]

[FONT=Calibri]www.malwarebytes.org[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Database version: v2013.11.14.06[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Windows Vista Service Pack 2 x86 NTFS[/FONT]

[FONT=Calibri]Internet Explorer 8.0.6001.19475[/FONT]

[FONT=Calibri]User :: USER-PC [administrator][/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]14/11/2013 16:12:50[/FONT]

[FONT=Calibri]mbam-log-2013-11-14 (16-12-50).txt[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Scan type: Full scan (C:\|D:\|)[/FONT]

[FONT=Calibri]Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM[/FONT]

[FONT=Calibri]Scan options disabled: P2P[/FONT]

[FONT=Calibri]Objects scanned: 412298[/FONT]

[FONT=Calibri]Time elapsed: 2 hour(s), 6 minute(s), 39 second(s)[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Memory Processes Detected: 0[/FONT]

[FONT=Calibri](No malicious items detected)[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Memory Modules Detected: 0[/FONT]

[FONT=Calibri](No malicious items detected)[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Registry Keys Detected: 34[/FONT]

[FONT=Calibri]HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCR\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899} (PUP.Optional.WebCake.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517} (PUP.WebCake) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517} (PUP.WebCake) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{58124A0B-DC32-4180-9BFF-E0E21AE34026} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{58124A0B-DC32-4180-9BFF-E0E21AE34026} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00078E95-3A4A-4137-8DE7-2824908D1C17} (PUP.Optional.SearchGolTB.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{204DF522-9A96-4A72-ABB0-60F7A216D6D2} (Adware.Whilokii) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C} (PUP.Optional.SearchGolTB.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA} (PUP.Optional.WebCake.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF190686-9E72-403C-B99D-682ABDB63C5B} (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063412-BEA4-4D76-8ED3-183BE6220D17} (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\Software\DataMngr (PUP.Optional.DataMngr.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\Software\BabSolution\Redir (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKLM\SOFTWARE\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exe (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Registry Values Detected: 4[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{977AE9CC-AF83-45E8-9E03-E2798216E2D5} (PUP.Optional.Iminent.A) -> Data: Ìéz—ƒ¯èEž[/FONT]


[FONT=Times New Roman]ây‚âÕ -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} (PUP.Optional.Iminent.A) -> Data: -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Data: 2O1R1G2Z1F1G1M -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs|bProtectTabs (PUP.Optional.BrowserProtect.A) -> Data: [/FONT][FONT=Calibri]http://www.searchgol.com/?babsrc=NT_ss&mntrId=FEFD001F3A62C4B2&affID=125035&tsp=5032[/FONT][FONT=Calibri] -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Registry Data Items Detected: 1[/FONT]

[FONT=Calibri]HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit) -> Bad: ([/FONT][FONT=Calibri]http://search.conduit.com?SearchSource=10&ctid=CT3042917&CUI=UN26262602822142568[/FONT][FONT=Calibri]) Good: ([/FONT][FONT=Calibri]http://www.google.com[/FONT][FONT=Calibri]) -> Quarantined and repaired successfully.[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Folders Detected: 9[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\ct3268494 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\ProgramData\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\ProgramData\BonanzaDealsLive\Update (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\ProgramData\BonanzaDealsLive\Update\Log (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\BonanzaDealsLive\CrashReports (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Program Files\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Program Files\BonanzaDealsLive\CrashReports (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri]Files Detected: 87[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\00VTF54M\conduitinstaller[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\00VTF54M\vbmz17[1].exe (MSIL.Solimba) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Conduit\CT3042917\Produtools_MapsAutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\GetCC.dll (MSIL.Solimba) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\ICReinstall_SoftwareUpdateSetup.exe (PUP.Optional.Installcore) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\5E17.tmp (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\SetupToparcadehits.exe (Adware.GameVance) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\SoftwareUpdateSetup.exe (PUP.Optional.Installcore) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\mconduitinstaller.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\conduitchecker.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\VisualBeeWebext.exe (PUP.Optional.CrossRider) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\ToolbarHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\vbmz17.exe (MSIL.Solimba) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\is1852162411\DeltaTB.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\is1852162411\Toparcadehits.exe (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\is1852162411\wajam_download.exe (PUP.Optional.Wajam) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\is1852162411\WebConnect.exe (PUP.Optional.WebConnect.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\is1852162411\2123592_stp\SearchGol.exe (PUP.Optional.PCFixSpeed.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\is1852162411\2123760_stp\bd.exe (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\614AADF3-BAB0-7891-B292-49184D5C14FC\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\614AADF3-BAB0-7891-B292-49184D5C14FC\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\614AADF3-BAB0-7891-B292-49184D5C14FC\Latest\ccp.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\614AADF3-BAB0-7891-B292-49184D5C14FC\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\614AADF3-BAB0-7891-B292-49184D5C14FC\Latest\MntrDLLInstall.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\614AADF3-BAB0-7891-B292-49184D5C14FC\Latest\MySgolTB.exe (PUP.Optional.SearchGolTB.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\614AADF3-BAB0-7891-B292-49184D5C14FC\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busB663\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busB6FF\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busB7CA\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busB98E\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busBCAA\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busBEAC\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busC6B8\BUSolution.dll (PUP.Optional.BabSolution.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busCFED\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus4B80\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus4BC2\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus7925\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus892D\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus8D03\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus9BE4\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus9FA8\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busA5B0\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busAB3D\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busB125\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busB173\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\53202F4B-BAB0-7891-856F-056B81602124\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\53202F4B-BAB0-7891-856F-056B81602124\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\53202F4B-BAB0-7891-856F-056B81602124\Latest\BUSolution.dll (PUP.Optional.BabSolution.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\53202F4B-BAB0-7891-856F-056B81602124\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\53202F4B-BAB0-7891-856F-056B81602124\Latest\MntrDLLInstall.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\53202F4B-BAB0-7891-856F-056B81602124\Latest\MyDeltaTB.exe (PUP.Optional.Delta) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\53202F4B-BAB0-7891-856F-056B81602124\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busD7D7\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busDDD0\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busE4C2\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\busFCE4\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\CE3A2886-BAB0-7891-A209-8F25995DB9BC\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\CE3A2886-BAB0-7891-A209-8F25995DB9BC\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\CE3A2886-BAB0-7891-A209-8F25995DB9BC\Latest\ccp.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\CE3A2886-BAB0-7891-A209-8F25995DB9BC\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\CE3A2886-BAB0-7891-A209-8F25995DB9BC\Latest\MntrDLLInstall.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\CE3A2886-BAB0-7891-A209-8F25995DB9BC\Latest\MyDeltaTB.exe (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\CE3A2886-BAB0-7891-A209-8F25995DB9BC\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\ct3268494\ctbe.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\ct3268494\ieLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\ct3268494\statisticsStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\ct3268494\stub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\2C4FB765-BAB0-7891-A2D1-2A342990935B\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\2C4FB765-BAB0-7891-A2D1-2A342990935B\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\4A1427B7-BAB0-7891-AF77-F1194D3B848C\BExternal.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\4A1427B7-BAB0-7891-AF77-F1194D3B848C\Setup.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\4A1427B7-BAB0-7891-AF77-F1194D3B848C\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\4A1427B7-BAB0-7891-AF77-F1194D3B848C\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus118D\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus139F\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus26E3\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus3B7C\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus489A\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\bus497D\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\WINDOWS\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V5CG081E\wajam_update[1].exe (PUP.Optional.Wajam.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Roaming\Babylon\SUDump.dmp (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\SetupToparcadehits.exe (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage (PUP.Optional.BrowserDefender.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\ct3268494\chromeid.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\Users\User\AppData\Local\Temp\ct3268494\setup.ini.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri]C:\ProgramData\BonanzaDealsLive\Update\Log\BonanzaDealsLive.log (PUP.Optional.BonanzaDeals.A) -> Quarantined and deleted successfully.[/FONT]

[FONT=Calibri] [/FONT]

[FONT=Calibri](end)[/FONT]

[FONT=Calibri] [/FONT]
 
Further to the above, I have noted that in my Startup Menu I have HPMonitor.exe, hpwjd.exe and hpwmsd.exe, yet my partner's Startup Menu is empty. Could all these PUP viruses have deleted them or would he have to delete them himself?
 
Hello, I'm having a similar issue with QtCore4.dll, and found your post while searching for an answer.

To answer your second question first, the HP stuff (I'm assuming its printer software) will probably be located in the "All User" profile rather than your individual profiles. Its located at C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

From what I can find, the daemonprocess.exe and qtcore4.dll seem to be something to do with a thing called mobogenie so I would either look in the "Uninstall a program" part of control panel, and uninstall it from there, or if it isn't there, just delete the mobogenie folder from C:\Program Files (might be C:\Program Files(x86) on a 64 bit OS, look in both if your have a 64-Bit Vista)

As for the crashing browser, try going to the start menu, then right click internet explorer, and see if there's an option for start without addons. that may get it working enough for you to surf and find answers to your browser problems, the obvious one being to download chrome or firefox and install them as a backup browser. If you dont get an option for start without addons, try just typing in the search box [FONT=Open Sans]iexplore -extoff [/FONT]and press enter. That should run IE without any addons. Its kinda like safe mode for internet explorer.

Malwarebytes is a good scanning program, and it has found a fair few of the most common internet toolbar hacks going around just now, I certainly recognise Delta, Wajam, Babylon, and conduit engine. No scanner catches everything though, so I would run a couple of other scans too, one with your anti virus, and one with TrendMicro Housecall

Each will probably take a couple of hours, depending on how much data you have, and how big a hard drive you have.

Hope that helps, and I wish you luck in sorting your PC. :)

Lesley
 
I've just had the same problem and after reading the blogs, I thought of how I could fix it - easy.
start
run

type in msconfig
click on Start up tab
Uncheck box labelled Daemon rest reads Programfile/Mogogenie/etc
Restart your computer and all the rest is history. No problems
 
I too had this DaemonProcess.exe error stating that I was missing QTCore4.dll - the above post regarding 'mobogenie' solved it. I searched for 'mobogenie' on the start menu and deleted the files directly as they did not appear on the uninstall programme list on the control panel.

Thanks for the help!
 
I've just had the same problem and after reading the blogs, I thought of how I could fix it - easy.
start
run

type in msconfig
click on Start up tab
Uncheck box labelled Daemon rest reads Programfile/Mogogenie/etc
Restart your computer and all the rest is history. No problems
it worked.thank you so much.;):):D
 
Back