OK Firefox has been compromised, we will clear that first and then see what’s left
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:Commands
[CREATERESTOREPOINT]
:OTL
DRV - File not found [File_System | On_Demand | Stopped] -- -- (yeibbiie)
[2014/03/12 04:57:53 | 000,000,000 | ---D | M] (SaveSense) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\5d808ga4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}
[2014/02/15 10:49:42 | 000,000,000 | ---D | M] (YoTuberAdsRemov) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\5d808ga4.default\extensions\a_zjld@oo-aagur.edu
[2014/02/07 00:45:02 | 000,000,000 | ---D | M] (webseavvE) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\5d808ga4.default\extensions\evxmsolyao@ao-ye.com
[2014/02/07 00:45:02 | 000,000,000 | ---D | M] (YoutubeAdblocker) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\5d808ga4.default\extensions\iiemyo@eaye.edu
O4 - HKU\S-1-5-21-861567501-1123561945-839522115-500..\Run: [LiveSupport] "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log File not found
[2014/03/12 04:57:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\SearchProtect
[2014/03/12 04:35:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DOSBox
[2014/03/08 20:32:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Search Protection
[2014/03/08 20:31:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\YTD Video Downloader
[2014/03/08 20:30:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\YTD Video Downloader
[2014/02/13 14:39:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\YoTuberAdsRemov
[2014/02/13 14:39:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\fmcgnbjgipbbpdfgnhallmcmlmngnfah
[2014/03/12 03:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Search Protection
[2014/02/02 03:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Smadav
[2014/02/07 01:03:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\systweak
[2014/02/13 14:39:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\16a2801affcc246b
[2014/02/13 14:39:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fmcgnbjgipbbpdfgnhallmcmlmngnfah
[2014/02/05 05:52:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\greaatosaaver
[2014/02/13 14:39:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YoTuberAdsRemov
[2014/03/08 20:31:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YTD Video Downloader
:Files
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fmcgnbjgipbbpdfgnhallmcmlmngnfah
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpdcfdklflbadebnimcanpkminhcbnii
:Commands
[resethosts]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.
FINALLY
Run a fresh OTL scan selecting all users