OK could you run OTL from safe mode please as I do not want the malware to regenerate
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:OTL
SRV:64bit: - [2013-01-29 14:28:02 | 000,188,760 | ---- | M] () [Auto | Stopped] -- C:\Program Files\IB Updater\ExtensionUpdaterService.exe -- (Web Assistant)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=281&systemid=2&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=281&systemid=2&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^XP^xdm208^LENIN^in&si=197727&ptb=6D7CC341-00C3-4415-B892-9553DAC26150&psa=&ind=2012090709&st=sb&n=77ee1155&searchfor={searchTerms}
IE - HKU\S-1-5-21-3464401708-3411778692-912532096-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=fc06d0bd000000000000000000000000
IE - HKU\S-1-5-21-3464401708-3411778692-912532096-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3464401708-3411778692-912532096-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerms}&affID=119370&babsrc=SP_ss&mntrId=fc06d0bd000000000000000000000000
IE - HKU\S-1-5-21-3464401708-3411778692-912532096-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=281&systemid=2&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3464401708-3411778692-912532096-1000\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^XP^xdm208^LENIN^in&si=197727&ptb=6D7CC341-00C3-4415-B892-9553DAC26150&psa=&ind=2012090709&st=sb&n=77ee1155&searchfor={searchTerms}
IE - HKU\S-1-5-21-3464401708-3411778692-912532096-1000\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = http://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80182&lng=en
IE - HKU\S-1-5-21-3464401708-3411778692-912532096-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb128/?search={searchTerms}&loc=IB_DS&a=6PQK31Bz1e&i=26
FF - prefs.js..browser.search.selectedEngine: "Delta Search"
FF - prefs.js..extensions.enabledAddons: 64ffxtbr@TelevisionFanatic.com:2.26.0.50199
FF - prefs.js..extensions.enabledAddons: ffxtlbr@babylon.com:1.5.0
FF - prefs.js..extensions.enabledAddons: inboxcomtoolbar@inbox.com:1.2.0.34
FF - prefs.js..extensions.enabledAddons: ffxtlbr@incredibar.com:1.5.0
FF - prefs.js..extensions.enabledAddons: plugin@yontoo.com:1.20.00
FF - prefs.js..extensions.enabledAddons: 1cffxtbr@BringMeSports_1c.com:2.50.0.53478
FF - prefs.js..browser.startup.homepage: "http://www.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=fc06d0bd000000000000000000000000"
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX [2013-03-25 19:55:27 | 000,000,000 | ---D | M]
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\PROGRAM FILES\IB UPDATER\FIREFOX [2013-03-25 19:55:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox [2013-03-25 19:55:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\Program Files\IB Updater\Firefox [2013-03-25 19:55:27 | 000,000,000 | ---D | M]
[2012-10-02 21:22:53 | 000,000,000 | ---D | M] (Wincore Mediabar) -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}
[2013-01-21 16:38:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\extensions\64ffxtbr@TelevisionFanatic.com
[2013-03-07 10:54:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\extensions\ffxtlbr@babylon.com
[2012-09-19 01:10:52 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\extensions\ffxtlbr@incredibar.com
[2012-09-19 01:07:56 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\extensions\plugin@yontoo.com
[2012-09-19 01:06:46 | 000,214,127 | ---- | M] () (No name found) -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\extensions\freehdsport@freehdsport.tv.xpi
[2013-03-07 10:54:33 | 000,006,484 | ---- | M] () -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\searchplugins\browsemngr.xml
[2013-03-07 10:55:04 | 000,001,294 | ---- | M] () -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\searchplugins\delta.xml
[2012-09-03 21:02:45 | 000,009,614 | ---- | M] () -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\searchplugins\my-web-search.xml
[2012-09-19 01:09:34 | 000,002,203 | ---- | M] () -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\searchplugins\MyStart Search.xml
[2012-10-02 21:22:28 | 000,002,515 | ---- | M] () -- C:\Users\PRINCETEEJAY\AppData\Roaming\Mozilla\Firefox\Profiles\8waqz9y6.default\searchplugins\Search_Results.xml
[2013-03-07 10:54:33 | 000,006,484 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O2:64bit: - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension64.dll ()
O2:64bit: - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\x64\BrowserConnection.dll (MusicLab, LLC)
O2 - BHO: (no name) - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\Program Files (x86)\SiteRanker\SiteRank.dll (Crawler, LLC)
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension32.dll ()
O2 - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC)
O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKU\S-1-5-21-3464401708-3411778692-912532096-1000..\Run: [b773b] C:\Users\PRINCETEEJAY\AppData\Roaming\a16\b773b.js ()
O4 - HKU\S-1-5-21-3464401708-3411778692-912532096-1000..\Run: [eType] C:\Users\PRINCETEEJAY\AppData\Roaming\eType\eType.exe (DSNR Media Innovations)
O4 - Startup: C:\Users\PRINCETEEJAY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e33.js ()
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\x64\datamngr.dll (MusicLab, LLC)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\x64\IEBHO.dll (MusicLab, LLC)
[2013-05-19 17:47:20 | 000,000,000 | -HSD | C] -- C:\Users\PRINCETEEJAY\AppData\Roaming\a16
[2013-05-19 17:47:20 | 000,000,000 | -HSD | C] -- C:\a0e6
[2013-05-19 17:47:20 | 000,000,000 | -HSD | M] -- C:\Users\PRINCETEEJAY\AppData\Roaming\a16
[2012-09-04 01:23:38 | 000,000,000 | ---D | M] -- C:\Users\PRINCETEEJAY\AppData\Roaming\Babylon
[2013-05-21 20:41:04 | 000,000,000 | ---D | M] -- C:\Users\PRINCETEEJAY\AppData\Roaming\eType
:Files
C:\Users\PRINCETEEJAY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js
:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.