|
Post by isolde on Mar 29, 2015 17:22:33 GMT -8
I'm confused.
I sent the response from the scan. Should I try again?
|
|
|
Post by isolde on Mar 29, 2015 17:30:22 GMT -8
|
|
Quads
Malware Removalists
In New Zealand
Posts: 9,387
|
Post by Quads on Mar 29, 2015 17:43:43 GMT -8
That is one log (FRST.txt) where is the other log??? (addition.txt)
Quads
|
|
|
Post by isolde on Mar 29, 2015 17:47:57 GMT -8
|
|
Quads
Malware Removalists
In New Zealand
Posts: 9,387
|
Post by Quads on Mar 29, 2015 19:35:48 GMT -8
Press the + R Keys on your keyboard at the same time. Type notepad and click OK. Copy the entire content of the codebox below and paste into the notepad (Including start and end) start () C:\Users\yita19\AppData\Local\DIRECTV Player\NDSPCShowServer.exe HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-187704923-4088787427-3436568899-1001\...\Run: [Octoshape Streaming Services] => C:\Users\yita19\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800 2011-03-24] (Octoshape ApS) SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-187704923-4088787427-3436568899-1001 -> {5C3C5038-8518-4F7B-8F9A-458593050A3D} URL = BHO-x32: Roaming Rate -> {8d0ea870-e492-4825-a734-a0ed7d65882a} -> C:\Program Files (x86)\Roaming Rate\Extensions\8d0ea870-e492-4825-a734-a0ed7d65882a.dll No File FF user.js: detected! => C:\Users\yita19\AppData\Roaming\Mozilla\Firefox\Profiles\zul0k6ar.default\user.js [2015-03-25] FF Plugin ProgramFiles/Appdata: C:\Users\yita19\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2015-03-28] (Octoshape ApS) FF Extension: Roaming Rate - C:\Users\yita19\AppData\Roaming\Mozilla\Firefox\Profiles\zul0k6ar.default\Extensions\{9762cc89-12a9-463c-a4e2-e5b338096153}.xpi [2015-03-25] CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=M71950D28-EFC6-4775-9721-2D6B54B5951E&SearchSource=55&CUI=&UM=5&UP=SP0CDDBF41-1563-4E61-B255-EA3A81745BC5&SSPV= CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=M71950D28-EFC6-4775-9721-2D6B54B5951E&SearchSource=55&CUI=&UM=5&UP=SP0CDDBF41-1563-4E61-B255-EA3A81745BC5&SSPV=", "hxxp://www.inbox.com/homepage.aspx?tbid=82773&iwk=284&lng=en" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} S2 0212981409964643mcinstcleanup; C:\Windows\TEMP\021298~1.EXE -cleanup -nolog [X] S3 iscFlash; \??\C:\Users\yita19\AppData\Local\Temp\7zSF2FF.tmp\iscflashx64.sys [X] C:\Users\yita19\AppData\Local\Temp\7zSF2FF.tmp R3 PCDSRVC{3B54B31B-D06B6431-06020200}_0; \??\c:\program files\dell\supportassist\pcdsrvc_x64.pkms [X] 2015-03-28 11:28 - 2015-03-28 11:28 - 00000000 ____D () C:\Users\yita19\AppData\Roaming\Octoshape 2015-03-28 11:28 - 2015-03-28 11:28 - 00000000 ____D () C:\Users\yita19\AppData\Local\Octoshape 2015-03-25 14:07 - 2015-03-25 14:07 - 00000000 ____D () C:\Users\yita19\Documents\ProPCCleaner 2015-03-25 08:48 - 2015-03-25 08:48 - 00000000 ____D () C:\Users\yita19\AppData\Local\Rainmaker_Software_Group_ 2015-03-10 06:49 - 2015-03-10 06:49 - 00000126 _____ () C:\Users\yita19\jobq.dat Task: {450F357C-0308-4916-B366-13D33D806606} - \ProPCCleaner_Start No Task File <==== ATTENTION Task: {6F6B9674-3F2B-47C7-B056-03D36C776B11} - \DriverAssist.Scanning No Task File <==== ATTENTION Task: {A7546D6D-9C5D-4FD2-89FF-BCA53AF3027D} - \ProPCCleaner_Popup No Task File <==== ATTENTION Task: {C67D00E3-20AC-4405-BAA3-CADD133F7A08} - \DriverAssist.Autostart No Task File <==== ATTENTION Reboot: end Click File, Save As and type fixlist (.txt may be seen on the end depending on the system setup) as the File Name. Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!
Right-click on icon and select Run as Administrator to start FRST. (XP users click run after receipt of Windows Security Warning - Open File). Press the button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop, called Fixlog.txt. To paste or attach back here Quads
|
|
|
Post by isolde on Mar 30, 2015 6:00:02 GMT -8
ix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by yita19 at 2015-03-30 06:42:50 Run:1 Running from C:\Users\yita19\Desktop Loaded Profiles: yita19 (Available profiles: yita19) Boot Mode: Normal ==============================================
Content of fixlist: ***************** start () C:\Users\yita19\AppData\Local\DIRECTV Player\NDSPCShowServer.exe HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-187704923-4088787427-3436568899-1001\...\Run: [Octoshape Streaming Services] => C:\Users\yita19\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800 2011-03-24] (Octoshape ApS) SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-187704923-4088787427-3436568899-1001 -> {5C3C5038-8518-4F7B-8F9A-458593050A3D} URL = BHO-x32: Roaming Rate -> {8d0ea870-e492-4825-a734-a0ed7d65882a} -> C:\Program Files (x86)\Roaming Rate\Extensions\8d0ea870-e492-4825-a734-a0ed7d65882a.dll No File FF user.js: detected! => C:\Users\yita19\AppData\Roaming\Mozilla\Firefox\Profiles\zul0k6ar.default\user.js [2015-03-25] FF Plugin ProgramFiles/Appdata: C:\Users\yita19\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2015-03-28] (Octoshape ApS) FF Extension: Roaming Rate - C:\Users\yita19\AppData\Roaming\Mozilla\Firefox\Profiles\zul0k6ar.default\Extensions\{9762cc89-12a9-463c-a4e2-e5b338096153}.xpi [2015-03-25] CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=M71950D28-EFC6-4775-9721-2D6B54B5951E&SearchSource=55&CUI=&UM=5&UP=SP0CDDBF41-1563-4E61-B255-EA3A81745BC5&SSPV= CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=M71950D28-EFC6-4775-9721-2D6B54B5951E&SearchSource=55&CUI=&UM=5&UP=SP0CDDBF41-1563-4E61-B255-EA3A81745BC5&SSPV=", "hxxp://www.inbox.com/homepage.aspx?tbid=82773&iwk=284&lng=en" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} S2 0212981409964643mcinstcleanup; C:\Windows\TEMP\021298~1.EXE -cleanup -nolog [X] S3 iscFlash; \??\C:\Users\yita19\AppData\Local\Temp\7zSF2FF.tmp\iscflashx64.sys [X] C:\Users\yita19\AppData\Local\Temp\7zSF2FF.tmp R3 PCDSRVC{3B54B31B-D06B6431-06020200}_0; \??\c:\program files\dell\supportassist\pcdsrvc_x64.pkms [X] 2015-03-28 11:28 - 2015-03-28 11:28 - 00000000 ____D () C:\Users\yita19\AppData\Roaming\Octoshape 2015-03-28 11:28 - 2015-03-28 11:28 - 00000000 ____D () C:\Users\yita19\AppData\Local\Octoshape 2015-03-25 14:07 - 2015-03-25 14:07 - 00000000 ____D () C:\Users\yita19\Documents\ProPCCleaner 2015-03-25 08:48 - 2015-03-25 08:48 - 00000000 ____D () C:\Users\yita19\AppData\Local\Rainmaker_Software_Group_ 2015-03-10 06:49 - 2015-03-10 06:49 - 00000126 _____ () C:\Users\yita19\jobq.dat Task: {450F357C-0308-4916-B366-13D33D806606} - \ProPCCleaner_Start No Task File <==== ATTENTION Task: {6F6B9674-3F2B-47C7-B056-03D36C776B11} - \DriverAssist.Scanning No Task File <==== ATTENTION Task: {A7546D6D-9C5D-4FD2-89FF-BCA53AF3027D} - \ProPCCleaner_Popup No Task File <==== ATTENTION Task: {C67D00E3-20AC-4405-BAA3-CADD133F7A08} - \DriverAssist.Autostart No Task File <==== ATTENTION Reboot: end *****************
[10880] C:\Users\yita19\AppData\Local\DIRECTV Player\NDSPCShowServer.exe => Process closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-187704923-4088787427-3436568899-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Octoshape Streaming Services => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKU\S-1-5-21-187704923-4088787427-3436568899-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5C3C5038-8518-4F7B-8F9A-458593050A3D}" => Key deleted successfully. HKCR\CLSID\{5C3C5038-8518-4F7B-8F9A-458593050A3D} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8d0ea870-e492-4825-a734-a0ed7d65882a}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{8d0ea870-e492-4825-a734-a0ed7d65882a}" => Key deleted successfully. C:\Users\yita19\AppData\Roaming\Mozilla\Firefox\Profiles\zul0k6ar.default\user.js => Moved successfully. C:\Users\yita19\AppData\Roaming\mozilla\plugins\npoctoshape.dll => Moved successfully. C:\Users\yita19\AppData\Roaming\Mozilla\Firefox\Profiles\zul0k6ar.default\Extensions\{9762cc89-12a9-463c-a4e2-e5b338096153}.xpi => Moved successfully. Chrome HomePage deleted successfully. Chrome StartupUrls deleted successfully. Chrome DefaultSuggestURL deleted successfully. 0212981409964643mcinstcleanup => Service deleted successfully. iscFlash => Service deleted successfully. "C:\Users\yita19\AppData\Local\Temp\7zSF2FF.tmp" => File/Directory not found. PCDSRVC{3B54B31B-D06B6431-06020200}_0 => Unable to stop service PCDSRVC{3B54B31B-D06B6431-06020200}_0 => Service deleted successfully.
"C:\Users\yita19\AppData\Roaming\Octoshape" directory move:
Could not move "C:\Users\yita19\AppData\Roaming\Octoshape" directory. => Scheduled to move on reboot.
C:\Users\yita19\AppData\Local\Octoshape => Moved successfully. C:\Users\yita19\Documents\ProPCCleaner => Moved successfully. C:\Users\yita19\AppData\Local\Rainmaker_Software_Group_ => Moved successfully. C:\Users\yita19\jobq.dat => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{450F357C-0308-4916-B366-13D33D806606}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{450F357C-0308-4916-B366-13D33D806606}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Start" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F6B9674-3F2B-47C7-B056-03D36C776B11}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F6B9674-3F2B-47C7-B056-03D36C776B11}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DriverAssist.Scanning => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A7546D6D-9C5D-4FD2-89FF-BCA53AF3027D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7546D6D-9C5D-4FD2-89FF-BCA53AF3027D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Popup" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C67D00E3-20AC-4405-BAA3-CADD133F7A08}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C67D00E3-20AC-4405-BAA3-CADD133F7A08}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DriverAssist.Autostart => Key not found.
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-03-30 06:46:24)<=
C:\Users\yita19\AppData\Roaming\Octoshape => Is moved successfully.
==== End of Fixlog 06:46:24 ====
|
|
Quads
Malware Removalists
In New Zealand
Posts: 9,387
|
Post by Quads on Mar 30, 2015 9:34:29 GMT -8
Read carefully
Download Adwcleaner www.bleepingcomputer.com/download/adwcleaner/ on to your desktop The Blue Download Now @bleeping Computer button and run a scan ( Scan Button). It will create a log after. Or there is a Report button, ONE SCAN ONLY
Attach or paste the log back here Quads
|
|
|
Post by isolde on Mar 30, 2015 12:09:01 GMT -8
# AdwCleaner v4.200 - Logfile created 30/03/2015 at 13:08:00 # Updated 29/03/2015 by Xplode # Database : 2015-03-29.1 [Server] # Operating system : Windows 8.1 (x64) # Username : yita19 - YITA # Running from : C:\Users\yita19\Desktop\AdwCleaner.exe # Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nortonsafe.search.ask.com_0.localstorage File Found : C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nortonsafe.search.ask.com_0.localstorage-journal Folder Found : C:\Users\yita19\AppData\Roaming\Mozilla\Firefox\Profiles\zul0k6ar.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD} Key Found : [x64] HKLM\SOFTWARE\WebBar
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v
-\\ Google Chrome v41.0.2272.101
[C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms} [C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms} [C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=M71950D28-EFC6-4775-9721-2D6B54B5951E&SearchSource=58&CUI=&UM=5&UP=SP0CDDBF41-1563-4E61-B255-EA3A81745BC5&q={searchTerms}&SSPV= [C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN10506&l=dis&prt=360&chn=retail&geo=US&ver=21&locale=en_US&gct=sb&qsrc=2869
*************************
AdwCleaner[R0].txt - [2758 bytes] - [30/03/2015 13:08:00]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2817 bytes] ##########
|
|
Quads
Malware Removalists
In New Zealand
Posts: 9,387
|
Post by Quads on Mar 30, 2015 13:04:50 GMT -8
a) Click the Scan Button and wait for the scan to finish,. (already done if Adwcleaner is left pending) b) Make sure all of the items under each TAB are to be ticked. c) Click the Clean Button and Adwcleaner will process all the items ticked / checked and then may ask for the system to be restarted.[/span] d) It should create a new log afterwards (with S0 in the name). Here is a Screenshot example Quads
|
|
|
Post by isolde on Mar 30, 2015 14:18:07 GMT -8
# AdwCleaner v4.200 - Logfile created 30/03/2015 at 15:08:50 # Updated 29/03/2015 by Xplode # Database : 2015-03-29.1 [Server] # Operating system : Windows 8.1 (x64) # Username : yita19 - YITA # Running from : C:\Users\yita19\Desktop\AdwCleaner.exe # Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\yita19\AppData\Roaming\Mozilla\Firefox\Profiles\zul0k6ar.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} File Deleted : C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nortonsafe.search.ask.com_0.localstorage File Deleted : C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nortonsafe.search.ask.com_0.localstorage-journal
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD} Key Deleted : [x64] HKLM\SOFTWARE\WebBar
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v
-\\ Google Chrome v41.0.2272.101
[C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms} [C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms} [C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=M71950D28-EFC6-4775-9721-2D6B54B5951E&SearchSource=58&CUI=&UM=5&UP=SP0CDDBF41-1563-4E61-B255-EA3A81745BC5&q={searchTerms}&SSPV= [C:\Users\yita19\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN10506&l=dis&prt=360&chn=retail&geo=US&ver=21&locale=en_US&gct=sb&qsrc=2869
*************************
AdwCleaner[R0].txt - [2936 bytes] - [30/03/2015 13:08:00] AdwCleaner[R1].txt - [2995 bytes] - [30/03/2015 15:07:49] AdwCleaner[S0].txt - [2916 bytes] - [30/03/2015 15:08:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2975 bytes] ##########
|
|