Quantcast
Channel: Tech Support Guy - Virus & Other Malware Removal
Viewing all 4746 articles
Browse latest View live

Browser can't fix and server

$
0
0
Where was it moved to? My browser can't find server. I do have internet. Help!

loaned laptop now poluted jt log

$
0
0
Please download whichever of the following you need for the system in question (if you do not know if it is 32 or 64 bit then download both; only one will run on the system).

Please download Farbar Recovery Scan Tool 32bit and save it to your Desktop.

Please download Farbar Recovery Scan Tool 64bit and save it to your Desktop.

  • Right click the FRST file on your desktop and select "Run as Administrator..." (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • If an update is available, the program will inform you and download the update. Allow it do this please.
  • Press the Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

long lags and hangs

$
0
0
Let's take a look at what is happening on the system.

Please download what you need to run on your system. (If you don't know if it is 32 or 64 bit, then download both file; only one will run on the system.)


Please download Farbar Recovery Scan Tool 32bit and save it to your Desktop.

Please download Farbar Recovery Scan Tool 64bit and save it to your Desktop.

  • Right click the FRST file on your desktop and select "Run as Administrator..." (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • If an update is available, the program will inform you and download the update. Allow it do this please.
  • Press the Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

Not Sure What's Going On -- But It's Not Good!

$
0
0
Great, will be waiting. Same symptoms plus one pop-up that's blinking at me. No others, tho.

Jane

Get rid of Pro PC Cleaner!

$
0
0
Please help me remove this filthy thing from my PC. Safe mode uninstall unsuccessful.

Thanks for any help

Windows 7 computer immediately shuts off at random intervals

$
0
0
My computer sometimes crashes without any indication, and I would like to know why. I am currently using a refurbished Dell Studio laptop, and the computer rarely, but annoyingly, crashes without shutting down, displaying a blue screen, or having the "Windows has recovered from an unexpected shutdown" popup. Malwarebytes and Microsoft Security Essentials have returned no results upon scanning. I do not believe this is an overheating problem, as the computer has never felt hot while using it, and I don't believe this is an issue with the power supply either, since the battery still works.

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz, Intel64 Family 6 Model 37 Stepping 2
Processor Count: 4
RAM: 3892 Mb
Graphics Card: Intel(R) Graphics Media Accelerator HD, 1722 Mb
Hard Drives: C: Total - 462936 MB, Free - 338480 MB; D: Total - 14000 MB, Free - 6328 MB;
Motherboard: Dell Inc.,
Antivirus: Microsoft Security Essentials, Updated and Enabled

Cryptowall 3.0 infection

$
0
0
Hi there,



My computer has recently been infected with the new Cryptowall 3.0 virus. So most of my pictures,Videos,Documents etc are encrypted, so i cant see them or do anything basically. It has also caused a huge slowdown of my normally fast working computer.


Is there anything that can be done without paying the ransom?


Any help will be much appreciated

Nathan




Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 8.1, 64 bit
Processor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz, Intel64 Family 6 Model 58 Stepping 9
Processor Count: 8
RAM: 16312 Mb
Graphics Card: NVIDIA GeForce GTX 660, -2048 Mb
Hard Drives: C: Total - 1907376 MB, Free - 1408313 MB;
Motherboard: ASUSTeK COMPUTER INC., P8B75-M LX
Antivirus: COMODO Antivirus

Redirected Google Link

$
0
0
My question is whether the software redirecting my browser is in my computer or in the link. Here's what happened.

I did a Google search about the French terrorism incident and clicked on the highlighted UPI link below (I copied the link but forgot to save it):


The link took me to a page with a url about discount furniture but this was what opened:




When I used the back space key I was taken to the UPI page. When I looked at my History the discount furniture link does not appear. It's like it never happened. Within the past few days I had a browser hijacker which greatly slowed down my computer. I used AdwCleaner and F-Secure and everything is now back to normal. They found some problems and removed them. Now I'm wondering if I still have something in my computer.

I should mention I had this same type of incident before the browser highjacking. Always when I clicked on a Google link (that time it was a legal site that provides text of court findings) and was redirected to one of two sites: discount furniture or Land's End fashion wear. The site never actually opened, instead I got the Windows Security Essential page which appeared phoney to me.

When I Googled Windows Security Essential 888-259-9242 the link that came up was to a site called ourmentalspa.blogspot.com and a page that is apparently in Chinese. Not good!

I will be running another scan and I'm not too worried about getting rid of whatever I downloaded (if I did download Malware). I'm wondering, however, if anyone has come across this malware before.

scanned many times but there are threats.

$
0
0
i am now attaching malwarebytes anti-malware report:
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 1/16/2015
Scan Time: 9:00:55 PM
Logfile: mbm report.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.16.09
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: arun

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 395937
Time Elapsed: 42 min, 30 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

annoying adware found on pc

$
0
0
After failing to uninstall a program called andyroid the adware from it is still here present, i especially noticed this on hijackthis


Sys Info
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Professional, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM) i7 CPU 950 @ 3.07GHz, Intel64 Family 6 Model 26 Stepping 5
Processor Count: 8
RAM: 6142 Mb
Graphics Card: NVIDIA GeForce GTX 480, 1536 Mb
Hard Drives: C: Total - 953766 MB, Free - 786612 MB;
Motherboard: Gigabyte Technology Co., Ltd., X58A-UD3R
Antivirus: None

Popups

$
0
0
Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Download AdwCleaner from here. Save the file to the desktop.


NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.
  • XP users: Double click the AdwCleaner icon to start the program.
  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:
  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending. Please uncheck elements you don't want to remove.
  • Click the Clean button.
  • Everything checked will be deleted.
  • When the program has finished cleaning a report appears.Once done it will ask to reboot, allow this
  • On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[S0].txt

Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup-2.0..exe to install the application. (The revision number may vary.)
  • Select the language and click OK.
  • Accept the agreement
  • Make sure a checkmark is placed next to Enable the Free Trial and Launch
  • Malwarebytes' Anti-Malware, then click on finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Scan Now".
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click on Quanrantee All,.
  • When disinfection is completed, a dialog will open and you may be prompted to Restart.(See Extra Note)
  • Upon restart, launch Malwarebytes Antimalware and select History.
  • Double click on the last scan done, then on Copy to Clipboard.
  • Right click on your next reply and select Paste.
  • Submit your reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Make sure that under Optional Scans, there is a checkmark on Addition.txt and Shortcut.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The tool will also produce another two logs (Addition.txt and Shortcut.txt). Please attach these to your reply.

Edge of Blue and White Window appears on upper right of desktop

$
0
0
Move the Taskbar to the bottom, then attempt to drag that window from its top.

To move the taskbar to its default position along the bottom edge of the screen:
  1. Click a blank portion of the taskbar.
  2. Hold down the primary mouse button, and then drag the mouse pointer to the bottom.

surfvox removal for windows8

$
0
0
Hi,

I tried following the instructions for removal of surfbox from the other threads but when I open combofix, it displays the attached error message although it I clearly says it supports windows 8.
whenever i try going to a site to remove surfbox it seems to auto close my browser. Please help me.
My windows version is 8.1.

thank you so much!

warmest regards,
Jake

Attached Images
File Type: jpg clip.jpg (32.0 KB)

Require Help Removing Multiple Trojans

$
0
0
Re-opening per request. You will want to update the logs but I see most of your "infections" are just items in ADWCleaner's quarantine, backups of those files, some downloads in the Downloads folder, and a "Free MP3 Converter" tool.

Incessant Pop-Ups/Malware

$
0
0
Lol...I understand. System seems to be doing very well now...if there is more cleanup to be done please let me know...

Please, help me remove "genius box clien/exc"from my computer

$
0
0
Hello, please help me remove this black screen and the message by it, about "genius box, client.exe." that cannot be found. Every time I open the computer this pops up. Also, I need to tell you that my level of understanding the sophisticated computer language is zero. In fact, I don't understand any kind of computer language. I need help from somebody with huge patience. Thank you.

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Professional, Service Pack 1, 32 bit
Processor: Intel(R) Core(TM) i7 CPU L 640 @ 2.13GHz, x64 Family 6 Model 37 Stepping 5
Processor Count: 4
RAM: 2995 Mb
Graphics Card: Intel(R) HD Graphics, 1273 Mb
Hard Drives: C: Total - 305142 MB, Free - 80447 MB;
Motherboard: LENOVO, 2985EYU
Antivirus: Early Detection Center 4.0 Antivirus, Updated and Enabled

Virus, malware help needed!!

$
0
0
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 8, 64 bit
Processor: AMD A8-4500M APU with Radeon(tm) HD Graphics, AMD64 Family 21 Model 16 Stepping 1
Processor Count: 4
RAM: 3554 Mb
Graphics Card: AMD Radeon HD 7640G, 512 Mb
Hard Drives: C: Total - 584260 MB, Free - 528924 MB; D: Total - 25429 MB, Free - 3064 MB;
Motherboard: Hewlett-Packard, 184B
Antivirus: Sophos Anti-Virus, Updated and Enabled

I have a serious virus on my computer and it is effecting everything I do. Anything from very slow speed to pop ups from simply clicking my mouse on a page. I get extra tabs popping up, ads galore, I can't navigate through a single site without coming across a serious ad or extra tab opening up, disabling me from using the internet effectively in any way. What can I do to get rid of this all together? I have gone to two different people in IT for help, neither were virus and malware removal specialists. Their help seemed to have cleaned my computer, but the virus came back within a week both times. First IT guy made me delete unneeded files and other guy used a virus scan disk to remove files and clean up the computer.....obviously neither worked. Is this as simple as cleaning my hard disk or is there more to it?

Thanks,
Ian

ckfgiex.exe problem, dds already ran and report posted

$
0
0
Ok, just finished running anti-mal program and I think that got it, thanks!

Hijackthis log

$
0
0
This is an update, today I removed the programs that were installed on the desktop including the Vosteran, and optimizer. I've run spybot and removed infections, installed avg antivirus and adaware and run them as well also installed zone alarm firewall. It seems to have fixed the majority of the issue with the Vosteran download but I really don't like having all these services in my hijack profile, I remember on my computer I had a few years ago my hijack this file was only like 10 lines and I never had issues for years it was real easy to maintain. So I'd appreciate help in just keeping essentials and knowing what I can get rid of. Also should I go into the windows registry and remove anything, I'm thinking I have only superficially removed the virus.

Thank you.



Logfile
of Trend Micro HijackThis v2.0.5
saved at 4:14:36 PM, on 1/17/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)

SysInfo

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 8.1, 64 bit
Processor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz, Intel64 Family 6 Model 69 Stepping 1
Processor Count: 4
RAM: 8122 Mb
Graphics Card: Intel(R) HD Graphics Family, -2016 Mb
Hard Drives: C: Total - 930059 MB, Free - 848472 MB; D: Total - 22764 MB, Free - 2557 MB;
Motherboard: Hewlett-Packard, 22B6
Antivirus: McAfee Anti-Virus and Anti-Spyware, Updated and Enabled


FIREFOX: 35.0 (x86 en-US)
Boot mode: Normal

Running processes:
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
C:\Program Files (x86)\Solution Real\bin\SolutionReal.expext.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Users\Chris\Downloads\HijackThis.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT14/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT14/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/HPNOT14/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Solution Real 1.0.0.6 - {1bb456da-878f-44a5-b013-4bfe0ae02fce} - C:\Program Files (x86)\Solution Real\SolutionRealbho.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: Adobe Acrobat Create PDF Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe
O4 - HKLM\..\Run: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\RunOnce: [Application Restart #2] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --appletID=HomePanel_BL --appletVersion=1.0 --mode=LBS --helperBridgeName={D89FFDAF-02E8-413E-B806-C8E5C1E9D1DE} --lbsWorkflowID={085D3B56-4971-46B1-A05B-146775621DF7} --aamHelperPipeName="{D89FFDAF-02E8-413E-B806-C8E5C1E9D1DE}" --accPipeName="{E90F056C-26A6-4127-9772-B17660DE0704}" --acccUpdated="true" --mode="update" --registerService="true" --selfDelete="C:\Users\Chris\AppData\Local\Temp\CreativeCloudSet-Up.exe" --shouldLaunchACC="false" --workflowId="{085D3B56-4971-46B1-A05B-146775621DF7}" /RestartByRestartManager:75DE7593-A26F-42fc-9B5F-8E2DC214AD6C
O4 - HKCU\..\RunOnce: [Application Restart #3] C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe /RestartByRestartManager:4BF2C9BE-0212-44b6-A071-0D01B9C3377C /RestartByRestartManager:EDA2F3EF-0807-48b4-AAB3-28400B00F2A3 /RestartByRestartManager:A558F158-5C58-4fa1-B312-ABFDEEF8CE98 /RestartByRestartManager:9DB7FCF0-213B-4afb-A62E-BC124CA58ECA
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O4 - Global Startup: ISCTSystray.lnk = C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Clip bookmark - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: Clip image - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: New note - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll
O20 - AppInit_DLLs: C:/PROGRA~3/{1BC9F~1/171~1.0/rado.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AdobeUpdateService - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ElevationManager\AdobeUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: McAfee Home Network (HomeNetSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @oem26.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee AP Service (McAPExe) - McAfee, Inc. - C:\Program Files\McAfee\MSC\McAPExe.exe
O23 - Service: McAfee Activation Service (McAWFwk) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee Platform Services (mcpltsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Anti-Malware Core (mfecore) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Solution Real - Unknown owner - C:\Program Files (x86)\Solution Real\updateSolutionReal.exe
O23 - Service: Util Solution Real - Unknown owner - C:\Program Files (x86)\Solution Real\bin\utilSolutionReal.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 17160 bytes

websearch adware removal

$
0
0
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 8.1, 64 bit
Processor: AMD A6-5200 APU with Radeon(TM) HD Graphics, AMD64 Family 22 Model 0 Stepping 1
Processor Count: 4
RAM: 5570 Mb
Graphics Card: AMD Radeon HD 8400, 512 Mb
Hard Drives: C: Total - 702797 MB, Free - 604997 MB;
Motherboard: AMD, Larne
Antivirus: Windows Defender, Disabled

Hi, i just looked over the forums to see how to rid myself of the websearch.thesearchinfo and "youtubeadblocker" adware. After finding this thread http://forums.techguy.org/windows-7/...anisoales.html I used AdwCleaner and Malwarebytes, and now I quarantined them. My question is, should I go forward and delete the quarantined files? Some of these seem like they are part of my comp's system and I want to know for sure if it's a good idea to just delete all of them.

Malwarebyte's scan log:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 1/17/2015
Scan Time: 10:59:21 PM
Logfile: malreport.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.18.02
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: [CLASSIFIED]
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 332055
Time Elapsed: 15 min, 59 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 9
Trojan.Agent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{AD11D ADE-C597-45D9-D8C5-1D2EB0B89613}, Quarantined, [5c7e29cf9eeb8baba9ccea1734ce2fd1],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\TYPELIB\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\INTERFACE\{0F19EF48-CB8C-416A-B84C-C33B02970632}, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\INTERFACE\{382F6195-1B46-40D5-B9FD-0493263E6132}, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\INTERFACE\{DFF50D27-9859-4F50-9BE1-A4CBFA102B9D}, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0F19EF48-CB8C-416A-B84C-C33B02970632}, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{382F6195-1B46-40D5-B9FD-0493263E6132}, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DFF50D27-9859-4F50-9BE1-A4CBFA102B9D}, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}, Quarantined, [a13909ef30592a0cd97d390233d060a0],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 1
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker, Quarantined, [a13909ef30592a0cd97d390233d060a0],

Files: 11
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\youtubeadblocker\rl4eIrXkoukOJ6.dll, Quarantined, [03d738c08aff290d5123226954b137c9],
Trojan.Agent, C:\Program Files (x86)\youtubeadblocker\rl4eIrXkoukOJ6.exe, Quarantined, [cc0e23d588010f27fb7a36cbe61c7d83],
Trojan.Agent, C:\Program Files (x86)\SingleFile Core\SingleFile Core.exe, Quarantined, [5c7e29cf9eeb8baba9ccea1734ce2fd1],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\uniusalles\rpat8ohdWgoATJ.dll, Quarantined, [5684e1170980e94de68ea3e846bff808],
Trojan.Agent, C:\Program Files (x86)\uniusalles\rpat8ohdWgoATJ.exe, Quarantined, [30aa797fc9c0ab8b1b5aff021ee417e9],
PUP.Optional.MultiPlug.A, C:\Users\[CLASSIFIED]\AppData\Local\Temp\Dd8e9\temp\hpds_setup.exe, Quarantined, [b1293fb9375211257f1bba648e74e61a],
PUP.Optional.Bundler, C:\Users\[CLASSIFIED]\AppData\Local\Temp\Dd8e9\temp\RMZ3.ZIP.exe, Quarantined, [9a40c830cdbc20160bd8e8a4a2638779],
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker\rl4eIrXkoukOJ6.dat, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker\rl4eIrXkoukOJ6.exe, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker\rl4eIrXkoukOJ6.tlb, Quarantined, [a13909ef30592a0cd97d390233d060a0],
PUP.Optional.Multiplug, C:\Program Files (x86)\youtubeadblocker\rl4eIrXkoukOJ6.x64.dll, Quarantined, [a13909ef30592a0cd97d390233d060a0],

Physical Sectors: 0
(No malicious items detected)


(end)

AdwCleaner scanlog:
# AdwCleaner v4.108 - Report created 17/01/2015 at 22:52:51
# Updated 17/01/2015 by Xplode
# Database : 2015-01-13.2 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : [CLASSIFIED] - JC-PC
# Running from : C:\Users\[CLASSIFIED]\AppData\Local\Microsoft\Windows\INetCache\IE\UR4IM2BA\adwcleaner_4.108.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\CLASSIFIED]\Favorites\StumbleUpon
Folder Deleted : C:\ProgramData\16193058868039961894
Folder Deleted : C:\Users\CLASSIFIED]\AppData\Roaming\SendSpace
File Deleted : C:\WINDOWS\System32\roboot64.exe

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****

Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Start Now Technology.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\P5922d6f5_a2da_49a9_9b86_404fb7fb7189_.P5922d6f5_a2da _49a9_9b86_404fb7fb7189_
Key Deleted : HKLM\SOFTWARE\Classes\P5922d6f5_a2da_49a9_9b86_404fb7fb7189_.P5922d6f5_a2da _49a9_9b86_404fb7fb7189_.9
Key Deleted : HKLM\SOFTWARE\Classes\Pb33f0a2e_6827_4b0e_b335_f7e43a356336_.Pb33f0a2e_6827 _4b0e_b335_f7e43a356336_
Key Deleted : HKLM\SOFTWARE\Classes\Pb33f0a2e_6827_4b0e_b335_f7e43a356336_.Pb33f0a2e_6827 _4b0e_b335_f7e43a356336_.9
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5922d6f5-a2da-49a9-9b86-404fb7fb7189}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{b33f0a2e-6827-4b0e-b335-f7e43a356336}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5922d6f5-a2da-49a9-9b86-404fb7fb7189}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b33f0a2e-6827-4b0e-b335-f7e43a356336}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5922d6f5-a2da-49a9-9b86-404fb7fb7189}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{b33f0a2e-6827-4b0e-b335-f7e43a356336}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5922d6f5-a2da-49a9-9b86-404fb7fb7189}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{b33f0a2e-6827-4b0e-b335-f7e43a356336}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5922d6f5-a2da-49a9-9b86-404fb7fb7189}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{b33f0a2e-6827-4b0e-b335-f7e43a356336}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5922d6f5-a2da-49a9-9b86-404fb7fb7189}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{b33f0a2e-6827-4b0e-b335-f7e43a356336}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5922d6f5-a2da-49a9-9b86-404fb7fb7189}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b33f0a2e-6827-4b0e-b335-f7e43a356336}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKCU\Software\Pokki
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\websearch.thesearchpage.info

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17416

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Secondary Start Pages]

*************************

AdwCleaner[R0].txt - [4680 octets] - [17/01/2015 22:47:57]
AdwCleaner[S0].txt - [4235 octets] - [17/01/2015 22:52:51]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4295 octets] ##########
Viewing all 4746 articles
Browse latest View live




Latest Images