I found some good info earlier and have been using the tools but have come to a halt. The process is considered hidden, it is STOPPED and has been for a while.
I have the adwcleaner info
AdwCleaner v3.007 - Report created 12/10/2013 at 23:00:45
Updated 09/10/2013 by Xplode
Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
Username : Mar - MAR-PLAYTOY
Running from : C:\Documents and Settings\Mar\Desktop\adwcleaner.exe
Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\Documents and Settings\Mar\Application Data\Mozilla\Firefox\Profiles\t80yzm1x.default\searchplugins\WebSearch.xml
File Found : C:\Documents and Settings\Mar\Application Data\Mozilla\Firefox\Profiles\t80yzm1x.default\user.js
Folder Found C:\Documents and Settings\All Users\Application Data\AlawarWrapper
Folder Found C:\Documents and Settings\All Users\Application Data\savEnshare!
Folder Found C:\Documents and Settings\All Users\Application Data\SearchNewTab
Folder Found C:\Documents and Settings\All Users\Application Data\SearchNewTab
Folder Found C:\Documents and Settings\Mar\Application Data\Mozilla\Firefox\Profiles\t80yzm1x.default\jetpack
Folder Found C:\Documents and Settings\Mar\Application Data\yourfiledownloader
***** [ Shortcuts ] *****
***** [ Registry ] *****
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~1\sshelp~1\sprote~1.dll
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~1\websea~1\sprote~1.dll
Key Found : HKCU\Software\Alexa Internet
Key Found : HKCU\Software\AppDataLow\SProtector
Key Found : HKCU\Software\Crossrider
Key Found : HKCU\Software\distromatic
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\YourFileDownloader
Key Found : HKLM\SOFTWARE\Classes\CLSID{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Found : HKLM\SOFTWARE\Classes\CLSID{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Key Found : HKLM\SOFTWARE\Classes\CLSID{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0004493.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0004493.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0004493.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0004493.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\Interface{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Found : HKLM\SOFTWARE\Classes\Interface{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Found : HKLM\SOFTWARE\Classes\Interface{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Found : HKLM\SOFTWARE\Classes\TypeLib{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Found : HKLM\Software\SP Global
Key Found : HKLM\Software\SProtector
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
***** [ Browsers ] *****
-\ Internet Explorer v6.0.2900.5512
-\ Mozilla Firefox v24.0 (en-US)
[ File : C:\Documents and Settings\Mar\Application Data\Mozilla\Firefox\Profiles\t80yzm1x.default\prefs.js ]
Line Found : user_pref(“aol_toolbar.default.homepage.check”, false);
Line Found : user_pref(“aol_toolbar.default.search.check”, false);
Line Found : user_pref(“browser.search.defaultenginename,S”, “WebSearch”);
Line Found : user_pref(“browser.search.defaulturl”, “hxxp://websearch.the-searcheng.info/?pid=1182&r=2013/09/13&hid=7141243511682829539&lg=EN&cc=US&unqvl=35&l=1&q=”);
Line Found : user_pref(“browser.search.order.1,S”, “WebSearch”);
Line Found : user_pref(“browser.search.selectedEngine,S”, “WebSearch”);
Line Found : user_pref(“extensions.BabylonToolbar.prtkDS”, 0);
Line Found : user_pref(“extensions.BabylonToolbar.prtkHmpg”, 0);
Line Found : user_pref(“extensions.crossrider.bic”, “13b5a14025c960840bf2a7eeb1b2359e”);
Line Found : user_pref(“extensions.wrc.SearchRules.ask.com.url”, “^hxxp(s)?\:\/\/(.+\.)?ask\.com\/.*”);
Line Found : user_pref(“sweetim.toolbar.previous.browser.search.defaultenginename”, “”);
Line Found : user_pref(“sweetim.toolbar.previous.browser.search.selectedEngine”, “”);
Line Found : user_pref(“sweetim.toolbar.previous.browser.startup.homepage”, “”);
Line Found : user_pref(“sweetim.toolbar.previous.keyword.URL”, “”);
Line Found : user_pref(“sweetim.toolbar.scripts.1.domain-blacklist”, “”);
Line Found : user_pref(“sweetim.toolbar.searchguard.UserRejectedGuard_DS”, “”);
Line Found : user_pref(“sweetim.toolbar.searchguard.UserRejectedGuard_HP”, “”);
Line Found : user_pref(“sweetim.toolbar.searchguard.enable”, “”);
AdwCleaner[R0].txt - [4847 octets] - [12/10/2013 23:00:45]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4907 octets] ##########
I ran and deleted 21 pups using the Malwarebytes anti-malware
I have the aswMBR info
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-10-12 23:53:30
23:53:30.234 OS Version: Windows 5.1.2600 Service Pack 3
23:53:30.234 Number of processors: 2 586 0x170A
23:53:30.234 ComputerName: MAR-PLAYTOY UserName: Mar
23:53:32.171 Initialize success
23:53:32.531 AVAST engine defs: 13101200
23:53:44.609 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP2T0L0-6
23:53:44.609 Disk 0 Vendor: ST500DM002-1BD142 KC45 Size: 476940MB BusType: 3
23:53:44.609 Disk 1 \Device\Harddisk1\DR1 → \Device\Ide\IdeDeviceP2T1L0-e
23:53:44.609 Disk 1 Vendor: ST500DM002-1BD142 KC45 Size: 476940MB BusType: 3
23:53:44.609 Disk 2 \Device\Harddisk2\DR2 → \Device\Ide\IdeDeviceP3T0L0-1a
23:53:44.609 Disk 2 Vendor: ST3500413AS JC45 Size: 476940MB BusType: 3
23:53:44.703 Disk 0 MBR read successfully
23:53:44.703 Disk 0 MBR scan
23:53:44.703 Disk 0 Windows XP default MBR code
23:53:44.718 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476929 MB offset 63
23:53:44.718 Disk 0 scanning sectors +976752000
23:53:44.812 Disk 0 scanning C:\WINDOWS\system32\drivers
23:54:01.562 Service scanning
23:54:09.187 Service ?etadpug HIDDEN
23:54:09.703 Modules scanning
23:54:26.312 Disk 0 trace - called modules:
23:54:26.343 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
23:54:26.343 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x8b085ab8]
23:54:26.359 3 CLASSPNP.SYS[f74d7fd7] → nt!IofCallDriver → \Device\00000074[0x8b0e6290]
23:54:26.375 5 ACPI.sys[f735e620] → nt!IofCallDriver → \Device\Ide\IdeDeviceP2T0L0-6[0x8b0dad98]
23:54:27.468 AVAST engine scan C:\WINDOWS
23:55:03.796 AVAST engine scan C:\WINDOWS\system32
23:59:48.734 AVAST engine scan C:\WINDOWS\system32\drivers
00:00:48.093 AVAST engine scan C:\Documents and Settings\Mar
00:14:08.906 AVAST engine scan C:\Documents and Settings\All Users
00:28:09.250 Scan finished successfully
00:31:34.156 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\Mar\Desktop\MBR.dat”
00:31:34.156 The log file has been saved successfully to “C:\Documents and Settings\Mar\Desktop\aswMBR finished scan.txt”