Solved Possible Malware Detected

No able to run the ESET scan. When I click on start a bar appears at the bottom of the page stating that an add on for the site failed to run. Any thoughts?
 
Farbar Service Scanner Version: 21-07-2014
Ran by Larry Roman (administrator) on 03-09-2014 at 11:37:06
Running from "C:\Users\Larry Roman\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.

Windows Firewall:
=============
Firewall Disabled Policy:
==================

System Restore:
============
System Restore Disabled Policy:
========================

Action Center:
============
Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.

Windows Update:
============
Windows Autoupdate Disabled Policy:
============================

Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Disabled. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.

Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1

Other Services:
==============
Checking ServiceDll of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist.
File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed

**** End of log ****
 
C:\AdwCleaner\Quarantine\C\Windows\System32\roboot64.exe.vir a variant of Win64/Systweak.A potentially unwanted application deleted - quarantined
C:\Program Files (x86)\RocketTab\Client.exe a variant of MSIL/Adware.iBryte.F application cleaned by deleting - quarantined
C:\Program Files (x86)\Vuze\spg.zip a variant of Win32/Toolbar.Widgi.G potentially unwanted application deleted (after the next restart) - quarantined
C:\Program Files (x86)\Vuze\.install4j\i4j_extf_20_5p83tu.exe Win32/Somoto.F potentially unwanted application deleted - quarantined
C:\Program Files (x86)\Vuze\.install4j\i4j_extf_27_5p83tu.dll a variant of Win32/Bunndle potentially unsafe application deleted - quarantined
C:\Program Files (x86)\Vuze\.install4j\i4j_extf_32_5p83tu.dll a variant of Win32/Bunndle potentially unsafe application deleted - quarantined
C:\Users\Larry Roman\AppData\Local\Temp\rt-installer.exe a variant of MSIL/Adware.iBryte.G application cleaned by deleting - quarantined
C:\Users\Larry Roman\Desktop\avc-free.exe.h2ojnin.partial Win32/OpenCandy potentially unsafe application deleted - quarantined
C:\Users\Larry Roman\Documents\Vuze Downloads Old\AVS Audio Converter 7.0.3.485 Incl. Patch - MPT\AC7MPT[deepstatus@h33t.com].rar a variant of Win32/HackTool.Patcher.T potentially unsafe application deleted - quarantined
C:\Users\Larry Roman\Documents\Vuze Downloads Old\Corel VideoStudio Pro X3 v13.6.2.36 + Keygen by AGAiN [RH]\CVSP.X3.v13.6.2.36_[RH].rar a variant of Win32/Keygen.AF potentially unsafe application deleted - quarantined
C:\Users\Larry Roman\Documents\Vuze Downloads Old\Updated Corel VideoStudio Pro X3 with KeyGEN for Windows 7\VideoStudio Pro X3.rar a variant of Win32/Keygen.AF potentially unsafe application deleted - quarantined
C:\Windows\Installer\31ad684f.msi probably a variant of Win32/Systweak potentially unwanted application deleted - quarantined
C:\Windows\Installer\53a159f.msi a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application deleted - quarantined
 
redtarget.gif
Update your Java version here: https://www.techspot.com/downloads/6463-java-se.html
Alternate download: http://www.java.com/en/download/manual.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

Note 3: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

redtarget.gif
FSS log shows couple of registry issues.
Download Windows Repair (All in One) from this site

Install the program then run it.

NOTE 1. In Windows Vista, 7 and 8 right click on the program, click "Run As Administrator".
NOTE 2. Disable your antivirus program before running Windows Repair.


Go to Step 3 and click on Check button next to 1. See If Check Disk Is Needed.
If the tool that the Check Disk is needed click on Do It button next to 2. Check Disk.
In that case make sure you restart computer.

p22004342.gif



Once the above is done go to Step 4 and allow it to run System File Check by clicking on Do It button:

p22004343.gif



Go to Step 5 and under "System Restore" click on Create button:

p22004346.gif



Go to Start Repairs tab and click Start button.

Leave all checkmarks as they're.
NOTE for Windows 8 users. Reset Registry Permissions is NOT checked by design.

Click on Start button.

p22004347.gif


Post Windows Repair log which is located in the following folder:
64-bit systems - C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Logs
32-bit systems - C:\Program Files\Tweaking.com\Windows Repair (All in One)\Logs

Post fresh FSS log as well.
 
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\Larry Roman\Desktop>CD /D C:\
C:\>chkdsk C:
The type of the file system is NTFS.
The volume is in use by another process. Chkdsk
might report errors when no corruption is present.
Volume label is HP.
WARNING! F parameter not specified.
Running CHKDSK in read-only mode.
CHKDSK is verifying files (stage 1 of 3)...
9 percent complete. (478541 of 531712 file records processed)
531712 file records processed.
File verification completed.
10569 large file records processed.
0 bad file records processed.
0 EA records processed.
59 reparse records processed.
CHKDSK is verifying indexes (stage 2 of 3)...
11 percent complete. (572287 of 649864 index entries processed)
Index entry CHKDSK.EXE-645779F7.pf in index $I30 of file 300777 is incorrect.
Index entry CHKDSK~1.PF in index $I30 of file 300777 is incorrect.
11 percent complete. (590580 of 649864 index entries processed)
649864 index entries processed.
Index verification completed.
Errors found. CHKDSK cannot continue in read-only mode.
C:\>
 
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\Larry Roman\Desktop>CD /D C:\
C:\>chkdsk C:
The type of the file system is NTFS.
The volume is in use by another process. Chkdsk
might report errors when no corruption is present.
Volume label is HP.
WARNING! F parameter not specified.
Running CHKDSK in read-only mode.
CHKDSK is verifying files (stage 1 of 3)...
0 percent complete. (0 of 531712 file records processed)
0 percent complete. (6145 of 531712 file records processed)
0 percent complete. (26001 of 531712 file records processed)
1 percent complete. (53172 of 531712 file records processed)
1 percent complete. (69597 of 531712 file records processed)
1 percent complete. (88091 of 531712 file records processed)
2 percent complete. (106343 of 531712 file records processed)
2 percent complete. (141051 of 531712 file records processed)
3 percent complete. (159514 of 531712 file records processed)
3 percent complete. (196959 of 531712 file records processed)
4 percent complete. (212685 of 531712 file records processed)
4 percent complete. (226049 of 531712 file records processed)
4 percent complete. (233217 of 531712 file records processed)
4 percent complete. (247158 of 531712 file records processed)
5 percent complete. (265856 of 531712 file records processed)
5 percent complete. (309120 of 531712 file records processed)
6 percent complete. (319028 of 531712 file records processed)
6 percent complete. (355291 of 531712 file records processed)
7 percent complete. (372199 of 531712 file records processed)
7 percent complete. (407341 of 531712 file records processed)
8 percent complete. (425370 of 531712 file records processed)
9 percent complete. (478541 of 531712 file records processed)
531712 file records processed.
File verification completed.
10569 large file records processed.
0 bad file records processed.
0 EA records processed.
59 reparse records processed.
CHKDSK is verifying indexes (stage 2 of 3)...
10 percent complete. (91094 of 649864 index entries processed)
10 percent complete. (185714 of 649864 index entries processed)
10 percent complete. (272649 of 649864 index entries processed)
11 percent complete. (369505 of 649864 index entries processed)
11 percent complete. (506606 of 649864 index entries processed)
11 percent complete. (531724 of 649864 index entries processed)
11 percent complete. (532231 of 649864 index entries processed)
11 percent complete. (532440 of 649864 index entries processed)
11 percent complete. (532715 of 649864 index entries processed)
11 percent complete. (533386 of 649864 index entries processed)
11 percent complete. (533907 of 649864 index entries processed)
11 percent complete. (534483 of 649864 index entries processed)
11 percent complete. (534957 of 649864 index entries processed)
11 percent complete. (535225 of 649864 index entries processed)
11 percent complete. (535391 of 649864 index entries processed)
11 percent complete. (535684 of 649864 index entries processed)
11 percent complete. (536014 of 649864 index entries processed)
11 percent complete. (536398 of 649864 index entries processed)
11 percent complete. (536969 of 649864 index entries processed)
11 percent complete. (537245 of 649864 index entries processed)
11 percent complete. (537614 of 649864 index entries processed)
11 percent complete. (538361 of 649864 index entries processed)
11 percent complete. (538642 of 649864 index entries processed)
11 percent complete. (539184 of 649864 index entries processed)
11 percent complete. (539586 of 649864 index entries processed)
11 percent complete. (540148 of 649864 index entries processed)
11 percent complete. (540584 of 649864 index entries processed)
11 percent complete. (541106 of 649864 index entries processed)
11 percent complete. (541729 of 649864 index entries processed)
11 percent complete. (542259 of 649864 index entries processed)
11 percent complete. (542756 of 649864 index entries processed)
11 percent complete. (543073 of 649864 index entries processed)
11 percent complete. (543439 of 649864 index entries processed)
11 percent complete. (543626 of 649864 index entries processed)
11 percent complete. (543798 of 649864 index entries processed)
11 percent complete. (544406 of 649864 index entries processed)
11 percent complete. (544639 of 649864 index entries processed)
11 percent complete. (544906 of 649864 index entries processed)
11 percent complete. (545135 of 649864 index entries processed)
11 percent complete. (545415 of 649864 index entries processed)
11 percent complete. (545840 of 649864 index entries processed)
11 percent complete. (546364 of 649864 index entries processed)
11 percent complete. (547194 of 649864 index entries processed)
11 percent complete. (547458 of 649864 index entries processed)
11 percent complete. (548509 of 649864 index entries processed)
11 percent complete. (552171 of 649864 index entries processed)
11 percent complete. (552805 of 649864 index entries processed)
11 percent complete. (553389 of 649864 index entries processed)
11 percent complete. (553887 of 649864 index entries processed)
11 percent complete. (554406 of 649864 index entries processed)
11 percent complete. (555093 of 649864 index entries processed)
11 percent complete. (555441 of 649864 index entries processed)
11 percent complete. (556135 of 649864 index entries processed)
11 percent complete. (556860 of 649864 index entries processed)
11 percent complete. (557268 of 649864 index entries processed)
11 percent complete. (557873 of 649864 index entries processed)
11 percent complete. (558414 of 649864 index entries processed)
11 percent complete. (558641 of 649864 index entries processed)
11 percent complete. (559419 of 649864 index entries processed)
11 percent complete. (560298 of 649864 index entries processed)
11 percent complete. (561146 of 649864 index entries processed)
11 percent complete. (561952 of 649864 index entries processed)
11 percent complete. (562357 of 649864 index entries processed)
11 percent complete. (562856 of 649864 index entries processed)
11 percent complete. (563662 of 649864 index entries processed)
11 percent complete. (564447 of 649864 index entries processed)
11 percent complete. (564853 of 649864 index entries processed)
11 percent complete. (565318 of 649864 index entries processed)
11 percent complete. (565608 of 649864 index entries processed)
11 percent complete. (566271 of 649864 index entries processed)
11 percent complete. (567755 of 649864 index entries processed)
11 percent complete. (569074 of 649864 index entries processed)
11 percent complete. (570150 of 649864 index entries processed)
11 percent complete. (570672 of 649864 index entries processed)
11 percent complete. (570918 of 649864 index entries processed)
11 percent complete. (571269 of 649864 index entries processed)
11 percent complete. (571372 of 649864 index entries processed)
11 percent complete. (571468 of 649864 index entries processed)
11 percent complete. (571946 of 649864 index entries processed)
11 percent complete. (572287 of 649864 index entries processed)
Index entry CHKDSK.EXE-645779F7.pf in index $I30 of file 300777 is incorrect.
Index entry CHKDSK~1.PF in index $I30 of file 300777 is incorrect.
11 percent complete. (572748 of 649864 index entries processed)
11 percent complete. (573021 of 649864 index entries processed)
11 percent complete. (573242 of 649864 index entries processed)
11 percent complete. (573704 of 649864 index entries processed)
11 percent complete. (574537 of 649864 index entries processed)
11 percent complete. (574899 of 649864 index entries processed)
11 percent complete. (575318 of 649864 index entries processed)
11 percent complete. (577400 of 649864 index entries processed)
11 percent complete. (578297 of 649864 index entries processed)
11 percent complete. (578910 of 649864 index entries processed)
11 percent complete. (579612 of 649864 index entries processed)
11 percent complete. (580026 of 649864 index entries processed)
11 percent complete. (580463 of 649864 index entries processed)
11 percent complete. (581245 of 649864 index entries processed)
11 percent complete. (582010 of 649864 index entries processed)
11 percent complete. (583631 of 649864 index entries processed)
11 percent complete. (584294 of 649864 index entries processed)
11 percent complete. (585132 of 649864 index entries processed)
11 percent complete. (585885 of 649864 index entries processed)
11 percent complete. (586286 of 649864 index entries processed)
11 percent complete. (586694 of 649864 index entries processed)
11 percent complete. (587241 of 649864 index entries processed)
11 percent complete. (587614 of 649864 index entries processed)
11 percent complete. (588288 of 649864 index entries processed)
11 percent complete. (588830 of 649864 index entries processed)
11 percent complete. (589638 of 649864 index entries processed)
11 percent complete. (590580 of 649864 index entries processed)
649864 index entries processed.
Index verification completed.
Errors found. CHKDSK cannot continue in read-only mode.
C:\>
 
Farbar Service Scanner Version: 21-07-2014
Ran by Larry Roman (administrator) on 07-09-2014 at 16:38:50
Running from "C:\Users\Larry Roman\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.

Windows Firewall:
=============
Firewall Disabled Policy:
==================

System Restore:
============
System Restore Disabled Policy:
========================

Action Center:
============
Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.

Windows Update:
============
Windows Autoupdate Disabled Policy:
============================

Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.

Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1

Other Services:
==============
Checking ServiceDll of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist.
File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed

**** End of log ****
 
We have to fix it manually.

Following steps involve registry editing. Please create new restore point before proceeding!!!
How to: http://www.smartestcomputing.us.com/topic/63983-how-to-create-new-restore-point-all-windows/

Download win-7-8-action-center-notification-icon-missing.reg from here: http://www.bleepstatic.com/fhost/uploads/1/win-7-8-action-center-notification-icon-missing.reg
Double-click on downloaded file and confirm the prompt.

Download RemoteAccess.reg
Double-click on downloaded file and confirm the prompt.

Restart computer.
Post new FSS log.
 
Farbar Service Scanner Version: 21-07-2014
Ran by Larry Roman (administrator) on 08-09-2014 at 08:27:45
Running from "C:\Users\Larry Roman\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.

Windows Firewall:
=============
Firewall Disabled Policy:
==================

System Restore:
============
System Restore Disabled Policy:
========================

Action Center:
============

Windows Update:
============
Windows Autoupdate Disabled Policy:
============================

Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.

Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1

Other Services:
==============

File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed

**** End of log ****
 
System performance is noticeably better then before the last set of requested steps. System was slow on the reboot and performance in general was sluggish. Now things appear to be normal again.
 
Excellent!

Update your Java version here: https://www.techspot.com/downloads/6463-java-se.html
Alternate download: http://www.java.com/en/download/manual.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

Note 3: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

=================================

Your computer is clean

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download
51a5ce45263de-delfix.png
DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.

3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

4. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

11. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

12. Please, let me know, how your computer is doing.
 
Performed the tasks above. Computer is running great! Stable and performance is back to normal. Thank you very much for your time!
 
Follow up concern/question: Not sure if this is related to my virus issue.

Every time I reboot I get the following message:

windows cannot find c:\program files(x86)\rocket tab\client.exe. Make sure you typed in the name correctly, and then try again.

I went to add/remove programs and found rocket tab and uninstalled it and still receive the message. How can I eliminate this from occurring?
 
Re-run Autoruns, scroll down to "Task Scheduler" section.
UN-check:

+ "\RocketTab"

Restart computer, re-run Autoruns, scroll down to "Task Scheduler" section.
Right click on

+ "\RocketTab"

Click "Delete".
 
Back