Quads
Malware Removalists
In New Zealand
Posts: 9,387
|
Post by Quads on Jan 14, 2014 22:15:14 GMT -8
I have to create a script.
Quads
|
|
Quads
Malware Removalists
In New Zealand
Posts: 9,387
|
Post by Quads on Jan 14, 2014 22:38:37 GMT -8
You may want to read carefully all of this message first before starting the steps.
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Download the script attached, needs to be the same file name as well (fixlist.txt), have it on the Desktop, so that fixlist.txt is next to FRST.exe,
DO NOT DRAG AND DROP to download the script, it won't work for FRST (Right click on the attachment link (not the normal left click) and from the menu choose Save As or Save Link as.)
The script tells FRST what to do.
Start FRST.exe that is on the desktop When the tool opens click Yes to disclaimer. (if it still does)
Press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) please post it to your reply (attach or paste)
Quads
|
|
mai
New Helpee
Posts: 22
|
Post by mai on Jan 14, 2014 22:44:49 GMT -8
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 15-01-2014 Ran by Mai at 2014-01-15 16:14:10 Run:1 Running from C:\Users\Mai\Desktop Boot Mode: Normal
==============================================
Content of fixlist: ***************** start (Vertro Inc.) C:\Users\Mai\AppData\LocalLow\alotservice\alotservice.exe (BitTorrent Inc.) C:\Users\Mai\AppData\Roaming\uTorrent\uTorrent.exe (Updater) C:\ProgramData\Updater\updater.exe (WatchDog) C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe (WatchDog) C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe (WatchDog) C:\ProgramData\RHelpers\IeHelper\IeHelper.exe HKCU\...\Run: [BackgroundContainer] - C:\Users\Mai\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll [319264 2013-10-14] (Conduit Ltd.) <===== ATTENTION HKCU\...\Run: [uTorrent] - C:\Users\Mai\AppData\Roaming\uTorrent\uTorrent.exe [900440 2013-11-16] (BitTorrent Inc.) HKCU\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-19] (Updater) MountPoints2: {2b61fee7-175f-11e1-bbad-e89a8fb40062} - E:\DPFMate.exe MountPoints2: {475f8f60-fb93-11e0-bcb3-e89a8fb40062} - E:\WIN\setup.exe AppInit_DLLs: C:\Program Files\BrowseToSave\sprotector.dll [1050112 2013-01-24] () C:\Users\Mai\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll C:\ProgramData\Updater\updater.exe C:\Program Files\BrowseToSave\sprotector.dll URLSearchHook: HKLM - SearchFlyBar5 Toolbar - {f9bd834b-77af-423e-ad5b-15e0786fe2bb} - C:\Program Files\SearchFlyBar5\prxtbSear.dll No File C:\Program Files\SearchFlyBar5 SearchScopes: HKLM - {087a7792-10bb-455d-bd55-427d589addf5} URL = search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YNxdm004YYau&ptnrS=YNxdm004YYau&si=COW4gLvq-64CFYokpAodgny1vg&ptb=9FE26766-E708-4FE7-A6EA-AC215CDEEC96&ind=2012032221&n=77ed2cdd&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD24} URL = dts.search-results.com/sr?src=ieb&appid=126&systemid=4&sr=0&q={searchTerms} BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: ALOT Appbar Helper - {85F5CF95-EC8F-49fc-BB3F-38C79455CBA2} - C:\Program Files\alotappbar\bin\BHO\ALOTHelperBHO.dll No File BHO: DataMngr - {978C7B0C-1709-4f9e-AE1C-95DC75079894} - C:\PROGRA~1\LPHANT~1\MediaBar\Datamngr\BROWSE~1.DLL No File BHO: Wincore MediaBar - {9a95b751-bf3e-4ea8-a938-2d4d84cd4964} - C:\PROGRA~1\LPHANT~1\MediaBar\Datamngr\ToolBar\lpdtxmltbpi.dll No File BHO: ArcadeFrontier Addon - {A0A838EC-FAAC-4F46-B3BA-D998593DB00E} - C:\Program Files\ArcadeFrontier\arcfront.dll No File BHO: DealPly - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files\DealPly\DealPlyIE.dll No File BHO: NetAssistant - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC) BHO: SearchFlyBar5 Toolbar - {f9bd834b-77af-423e-ad5b-15e0786fe2bb} - C:\Program Files\SearchFlyBar5\prxtbSear.dll No File Toolbar: HKLM - ALOT Appbar - {A531D99C-5A22-449b-83DA-872725C6D0ED} - C:\Program Files\alotappbar\bin\ALOTHelper.dll No File Toolbar: HKLM - Wincore MediaBar - {9a95b751-bf3e-4ea8-a938-2d4d84cd4964} - C:\PROGRA~1\LPHANT~1\MediaBar\Datamngr\ToolBar\lpdtxmltbpi.dll No File Toolbar: HKLM - SearchFlyBar5 Toolbar - {f9bd834b-77af-423e-ad5b-15e0786fe2bb} - C:\Program Files\SearchFlyBar5\prxtbSear.dll No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - No File Toolbar: HKCU - SearchFlyBar5 Toolbar - {F9BD834B-77AF-423E-AD5B-15E0786FE2BB} - C:\Program Files\SearchFlyBar5\prxtbSear.dll No File CHR HomePage: hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP5CF069C2-056B-43FA-8A8D-B3517A423DB4&SSPV= CHR HKLM\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Users\Mai\AppData\Roaming\BabylonToolbar\CR\BabylonChrome1.crx [2013-02-07] CHR HKLM\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files\DealPly\DealPly.crx [2013-02-07] CHR HKLM\...\Chrome\Extension: [hgkpceemnpedhhkieoijjljphmfklold] - C:\Program Files\ArcadeFrontier\arcfront.crx [2013-02-07] CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Mai\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-02-07] CHR HKLM\...\Chrome\Extension: [ndkhncnongaclekkbelchmeafffimifj] - C:\Users\Mai\AppData\Local\Giant Savings\Chrome\Giant Savings.crx [2013-12-10] CHR HKCU\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files\DealPly\DealPly.crx [2013-12-10] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION R2 AlotService; C:\Users\Mai\AppData\LocalLow\alotservice\alotservice.exe [255880 2012-06-19] (Vertro Inc.) C:\Users\Mai\AppData\LocalLow\alotservice\alotservice.exe R2 InternetUpdater; C:\ProgramData\InternetUpdater\InternetUpdaterService.exe [40448 2013-12-06] () 2014-01-09 22:48 - 2014-01-15 00:45 - 00076839 _____ C:\alotserviceruntime.log 2014-01-08 21:15 - 2014-01-08 21:15 - 00000000 ____D C:\Users\Mai\AppData\Roaming\SparkTrust 2014-01-08 21:15 - 2014-01-08 21:15 - 00000000 ____D C:\Users\Mai\AppData\Roaming\DriverCure 2014-01-08 21:14 - 2014-01-08 21:14 - 00000000 ____D C:\ProgramData\SparkTrust 2014-01-08 21:14 - 2014-01-08 21:14 - 00000000 ____D C:\Program Files\SparkTrust 2014-01-08 21:14 - 2014-01-08 21:14 - 00000000 ____D C:\Program Files\Common Files\SparkTrust 2013-12-21 23:09 - 2014-01-10 00:14 - 00000000 ____D C:\ProgramData\RHelpers 2014-01-15 13:21 - 2013-10-01 09:48 - 00000260 _____ C:\windows\Tasks\ArcadeFrontier.job 2013-12-29 19:08 - 2012-10-16 17:08 - 00000000 ____D C:\Users\Mai\AppData\Local\Conduit C:\Users\Mai\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll C:\Users\Mai\AppData\Local\Temp\_isCAAD.exe Task: {B6864478-9480-45AA-8E4E-3C2FB38C2DE5} - System32\Tasks\DealPlyUpdate => C:\Program Files\DealPly\DealPlyUpdate.exe <==== ATTENTION Task: {B6BF1BB6-2310-46EC-B2C0-E78029439AC5} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\Mai\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun end *****************
[2008] C:\Users\Mai\AppData\LocalLow\alotservice\alotservice.exe => Process closed successfully. [3208] C:\Users\Mai\AppData\Roaming\uTorrent\uTorrent.exe => Process closed successfully. [3216] C:\ProgramData\Updater\updater.exe => Process closed successfully. [3444] C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe => Process closed successfully. [3572] C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe => Process closed successfully. [4108] C:\ProgramData\RHelpers\IeHelper\IeHelper.exe => Process closed successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\BackgroundContainer => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Updater => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b61fee7-175f-11e1-bbad-e89a8fb40062} => Key deleted successfully. HKCR\CLSID\{2b61fee7-175f-11e1-bbad-e89a8fb40062} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{475f8f60-fb93-11e0-bcb3-e89a8fb40062} => Key deleted successfully. HKCR\CLSID\{475f8f60-fb93-11e0-bcb3-e89a8fb40062} => Key not found. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. C:\Users\Mai\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll => Moved successfully. C:\ProgramData\Updater\updater.exe => Moved successfully. "C:\Program Files\BrowseToSave\sprotector.dll" => File/Directory not found. HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\{f9bd834b-77af-423e-ad5b-15e0786fe2bb} => Value deleted successfully. HKCR\CLSID\{f9bd834b-77af-423e-ad5b-15e0786fe2bb} => Key deleted successfully. "C:\Program Files\SearchFlyBar5" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{087a7792-10bb-455d-bd55-427d589addf5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{087a7792-10bb-455d-bd55-427d589addf5} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD24} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD24} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key deleted successfully. HKCR\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85F5CF95-EC8F-49fc-BB3F-38C79455CBA2} => Key deleted successfully. HKCR\CLSID\{85F5CF95-EC8F-49fc-BB3F-38C79455CBA2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{978C7B0C-1709-4f9e-AE1C-95DC75079894} => Key deleted successfully. HKCR\CLSID\{978C7B0C-1709-4f9e-AE1C-95DC75079894} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9a95b751-bf3e-4ea8-a938-2d4d84cd4964} => Key deleted successfully. HKCR\CLSID\{9a95b751-bf3e-4ea8-a938-2d4d84cd4964} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A0A838EC-FAAC-4F46-B3BA-D998593DB00E} => Key deleted successfully. HKCR\CLSID\{A0A838EC-FAAC-4F46-B3BA-D998593DB00E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} => Key deleted successfully. HKCR\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1} => Key deleted successfully. HKCR\CLSID\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f9bd834b-77af-423e-ad5b-15e0786fe2bb} => Key deleted successfully. HKCR\CLSID\{f9bd834b-77af-423e-ad5b-15e0786fe2bb} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{A531D99C-5A22-449b-83DA-872725C6D0ED} => Value deleted successfully. HKCR\CLSID\{A531D99C-5A22-449b-83DA-872725C6D0ED} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{9a95b751-bf3e-4ea8-a938-2d4d84cd4964} => Value deleted successfully. HKCR\CLSID\{9a95b751-bf3e-4ea8-a938-2d4d84cd4964} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{f9bd834b-77af-423e-ad5b-15e0786fe2bb} => Value deleted successfully. HKCR\CLSID\{f9bd834b-77af-423e-ad5b-15e0786fe2bb} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} => Value deleted successfully. HKCR\CLSID\{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{F9BD834B-77AF-423E-AD5B-15E0786FE2BB} => Value deleted successfully. HKCR\CLSID\{F9BD834B-77AF-423E-AD5B-15E0786FE2BB} => Key not found. CHR HomePage: hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP5CF069C2-056B-43FA-8A8D-B3517A423DB4&SSPV= ==> The Chrome "Settings" can be used to fix the entry. HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb => Key deleted successfully. "C:\Users\Mai\AppData\Roaming\BabylonToolbar\CR\BabylonChrome1.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje => Key deleted successfully. "C:\Program Files\DealPly\DealPly.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\hgkpceemnpedhhkieoijjljphmfklold => Key deleted successfully. "C:\Program Files\ArcadeFrontier\arcfront.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof => Key deleted successfully. "C:\Users\Mai\AppData\Local\Torch\Plugins\TorchPlugin.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\ndkhncnongaclekkbelchmeafffimifj => Key deleted successfully. "C:\Users\Mai\AppData\Local\Giant Savings\Chrome\Giant Savings.crx" => File/Directory not found. HKCU\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje => Key deleted successfully. "C:\Program Files\DealPly\DealPly.crx" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. AlotService => Service deleted successfully. C:\Users\Mai\AppData\LocalLow\alotservice\alotservice.exe => Moved successfully. InternetUpdater => Service deleted successfully. C:\alotserviceruntime.log => Moved successfully. C:\Users\Mai\AppData\Roaming\SparkTrust => Moved successfully. C:\Users\Mai\AppData\Roaming\DriverCure => Moved successfully. C:\ProgramData\SparkTrust => Moved successfully. C:\Program Files\SparkTrust => Moved successfully. C:\Program Files\Common Files\SparkTrust => Moved successfully. C:\ProgramData\RHelpers => Moved successfully. C:\windows\Tasks\ArcadeFrontier.job => Moved successfully. C:\Users\Mai\AppData\Local\Conduit => Moved successfully. "C:\Users\Mai\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll" => File/Directory not found. C:\Users\Mai\AppData\Local\Temp\_isCAAD.exe => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B6864478-9480-45AA-8E4E-3C2FB38C2DE5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B6864478-9480-45AA-8E4E-3C2FB38C2DE5} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B6BF1BB6-2310-46EC-B2C0-E78029439AC5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B6BF1BB6-2310-46EC-B2C0-E78029439AC5} => Key deleted successfully. C:\Windows\System32\Tasks\BackgroundContainer Startup Task => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BackgroundContainer Startup Task => Key deleted successfully.
The system needs a manual reboot.
==== End of Fixlog ====
|
|
mai
New Helpee
Posts: 22
|
Post by mai on Jan 14, 2014 22:46:44 GMT -8
I am now having multiple Norton messages popping up saying Norton blocked an attack by: Web Attack: Fake Application Download
This time it is not closing down the browser though.
Mai
|
|
Quads
Malware Removalists
In New Zealand
Posts: 9,387
|
Post by Quads on Jan 14, 2014 22:47:41 GMT -8
Did you restart the system??
Quads
|
|
mai
New Helpee
Posts: 22
|
Post by mai on Jan 14, 2014 22:59:08 GMT -8
Ok, now I have rebooted. Been online for several minutes now without a hitch.
Anything else I need to do?
Thanks so much! Mai
|
|
Quads
Malware Removalists
In New Zealand
Posts: 9,387
|
Post by Quads on Jan 14, 2014 23:01:42 GMT -8
Read carefully
Download Adwcleaner www.bleepingcomputer.com/download/adwcleaner/ on to your desktopThe Blue Download now on the site
button and run a scan You may have to right click adwcleaner.exe and choose "Run as Administrator" from the menu. ( Scan Button). It will create a log after. Or there is a Report button. ONE SCAN ONLY
Attach or paste the log back here Quads
|
|
mai
New Helpee
Posts: 22
|
Post by mai on Jan 14, 2014 23:12:05 GMT -8
Ok, here's the results:
# AdwCleaner v3.017 - Report created 15/01/2014 at 16:40:30 # Updated 12/01/2014 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (32 bits) # Username : Mai - MAI-PC # Running from : C:\Users\Mai\Desktop\AdwCleaner.exe # Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\END File Found : C:\Users\Mai\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage File Found : C:\Users\Mai\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal Folder Found C:\Program Files\BrowseToSave Folder Found C:\Program Files\Freeze.com Folder Found C:\Program Files\Yontoo Layers Runtime Folder Found C:\ProgramData\Babylon Folder Found C:\ProgramData\Browse2SiAAvae Folder Found C:\ProgramData\Computer Updater Folder Found C:\ProgramData\Conduit Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly Folder Found C:\ProgramData\SoftSafe Folder Found C:\ProgramData\Tarma Installer Folder Found C:\Searchprotect Folder Found C:\Users\Mai\AppData\Local\PackageAware Folder Found C:\Users\Mai\AppData\Local\torch Folder Found C:\Users\Mai\AppData\LocalLow\alotappbar Folder Found C:\Users\Mai\AppData\LocalLow\alotservice Folder Found C:\Users\Mai\AppData\LocalLow\BabylonToolbar Folder Found C:\Users\Mai\AppData\LocalLow\Browse2SiAAvae Folder Found C:\Users\Mai\AppData\LocalLow\Conduit Folder Found C:\Users\Mai\AppData\LocalLow\PriceGong Folder Found C:\Users\Mai\AppData\LocalLow\SearchFlyBar5 Folder Found C:\Users\Mai\AppData\Roaming\Babylon Folder Found C:\windows\system32\Searchprotect
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\5968cd1b23aec45 Key Found : HKCU\Software\alotservice Key Found : HKCU\Software\AppDataLow\Software\alotAppbar Key Found : HKCU\Software\AppDataLow\Software\BackgroundContainer Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Found : HKCU\Software\AppDataLow\Software\Crossrider Key Found : HKCU\Software\AppDataLow\Software\DynConIE Key Found : HKCU\Software\AppDataLow\Software\Giant Savings Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Software\SearchFlyBar5 Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\AppDataLow\SProtector Key Found : HKCU\Software\AppDataLow\Toolbar Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\DataMngr Key Found : HKCU\Software\DataMngr_Toolbar Key Found : HKCU\Software\DealPly Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\installedbrowserextensions Key Found : HKCU\Software\Microsoft\Babylon Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\NetAssistant 3.8.3 Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch Key Found : HKCU\Software\PrivitizeVPNInstallDates Key Found : HKCU\Software\StartSearch Key Found : HKCU\Software\torch Key Found : HKLM\SOFTWARE\5968cd1b23aec45 Key Found : HKLM\Software\Babylon Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Key Found : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9} Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF} Key Found : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll Key Found : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll Key Found : HKLM\SOFTWARE\Classes\BrowserConnection.Loader Key Found : HKLM\SOFTWARE\Classes\BrowserConnection.Loader.1 Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{59DDD5D7-088F-4C96-9B03-40E5740591DD} Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKLM\SOFTWARE\Classes\DnsBHO.BHO Key Found : HKLM\SOFTWARE\Classes\DnsBHO.BHO.1 Key Found : HKLM\Software\Classes\Installer\Features\6207E55EA2FE71A4AA7ABD89AEF31D1B Key Found : HKLM\Software\Classes\Installer\Products\6207E55EA2FE71A4AA7ABD89AEF31D1B Key Found : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Key Found : HKLM\SOFTWARE\Classes\Prod.cap Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3196716 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3295941 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{1E8FC16F-4C51-49C4-BC9B-4FC24BDDCEE7} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Found : HKLM\Software\Conduit Key Found : HKLM\Software\DataMngr Key Found : HKLM\Software\DealPly Key Found : HKLM\Software\Freeze.com Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{343263AB-D732-4066-A274-4A487A07F108} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61AA0EC2-1E0E-48C5-9DF6-3866FCB6FF5A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF7EB849-2EB7-41B8-8863-B2D733B0BFFF} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C42103E4-7D10-4CC9-B2B4-C546BCCF8706} Key Found : HKLM\SOFTWARE\Microsoft\Tracing\alotservice_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\alotservice_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Key Found : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasapi32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasmancs Key Found : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasapi32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasmancs Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\torch.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{59DDD5D7-088F-4C96-9B03-40E5740591DD} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4 Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6 Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852 Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0 Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96 Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59 Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6207E55EA2FE71A4AA7ABD89AEF31D1B Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C792A75A-2A1F-4991-9B85-291745478A79} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E55E7026-EF2A-4A17-AAA7-DB98EA3FD1B1} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\alotAppbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wincore MediaBar Key Found : HKLM\Software\SearchFlyBar5 Key Found : HKLM\Software\SP Global Key Found : HKLM\Software\SProtector Key Found : HKLM\Software\Tarma Installer Key Found : HKLM\Software\torch
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\Mai\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found : homepage Found : homepage Found : homepage
*************************
AdwCleaner[R0].txt - [10760 octets] - [15/01/2014 16:40:30]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [10821 octets] ##########
|
|
Quads
Malware Removalists
In New Zealand
Posts: 9,387
|
Post by Quads on Jan 14, 2014 23:30:55 GMT -8
a) Click the Scan Button and wait for the scan to finish, (If Adwcleaner has been left open at the finish of the scan this is already done). b) Make sure in your case all the items under each TAB are ticked / checked then. c) Click the Clean Button and Adwcleaner will process all the items ticked / checked and then may ask for the system to be restarted.d) It should create a new log afterwards (with S0 in the name). Here is a Screenshot exampleIt will create a new log afterwards with [S0] in its name Quads
|
|
mai
New Helpee
Posts: 22
|
Post by mai on Jan 14, 2014 23:47:11 GMT -8
# AdwCleaner v3.017 - Report created 15/01/2014 at 17:09:51 # Updated 12/01/2014 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (32 bits) # Username : Mai - MAI-PC # Running from : C:\Users\Mai\Desktop\AdwCleaner.exe # Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Searchprotect Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\Computer Updater Folder Deleted : C:\ProgramData\Conduit Folder Deleted : C:\ProgramData\SoftSafe Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\ProgramData\Browse2SiAAvae Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly Folder Deleted : C:\Program Files\BrowseToSave Folder Deleted : C:\Program Files\Freeze.com Folder Deleted : C:\Program Files\Yontoo Layers Runtime Folder Deleted : C:\windows\system32\Searchprotect Folder Deleted : C:\Users\Mai\AppData\Local\PackageAware Folder Deleted : C:\Users\Mai\AppData\Local\torch Folder Deleted : C:\Users\Mai\AppData\LocalLow\alotappbar Folder Deleted : C:\Users\Mai\AppData\LocalLow\alotservice Folder Deleted : C:\Users\Mai\AppData\LocalLow\BabylonToolbar Folder Deleted : C:\Users\Mai\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Mai\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Mai\AppData\LocalLow\Browse2SiAAvae Folder Deleted : C:\Users\Mai\AppData\LocalLow\SearchFlyBar5 Folder Deleted : C:\Users\Mai\AppData\Roaming\Babylon File Deleted : C:\END File Deleted : C:\Users\Mai\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage File Deleted : C:\Users\Mai\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll Key Deleted : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll Key Deleted : HKLM\SOFTWARE\Classes\BrowserConnection.Loader Key Deleted : HKLM\SOFTWARE\Classes\BrowserConnection.Loader.1 Key Deleted : HKLM\SOFTWARE\Classes\DnsBHO.BHO Key Deleted : HKLM\SOFTWARE\Classes\DnsBHO.BHO.1 Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\alotservice_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\alotservice_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\torch.exe Key Deleted : HKCU\Software\5968cd1b23aec45 Key Deleted : HKLM\SOFTWARE\5968cd1b23aec45 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3196716 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3295941 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{59DDD5D7-088F-4C96-9B03-40E5740591DD} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1E8FC16F-4C51-49C4-BC9B-4FC24BDDCEE7} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{59DDD5D7-088F-4C96-9B03-40E5740591DD} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{343263AB-D732-4066-A274-4A487A07F108} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C42103E4-7D10-4CC9-B2B4-C546BCCF8706} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61AA0EC2-1E0E-48C5-9DF6-3866FCB6FF5A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF7EB849-2EB7-41B8-8863-B2D733B0BFFF} Key Deleted : HKCU\Software\alotservice Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\DataMngr [#] Key Deleted : HKCU\Software\DataMngr_Toolbar Key Deleted : HKCU\Software\DealPly Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\installedbrowserextensions Key Deleted : HKCU\Software\Microsoft\Babylon Key Deleted : HKCU\Software\PrivitizeVPNInstallDates Key Deleted : HKCU\Software\StartSearch Key Deleted : HKCU\Software\torch Key Deleted : HKCU\Software\AppDataLow\SProtector Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\alotAppbar Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKCU\Software\AppDataLow\Software\DynConIE Key Deleted : HKCU\Software\AppDataLow\Software\Giant Savings Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AppDataLow\Software\SearchFlyBar5 Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\DealPly Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\Software\SP Global Key Deleted : HKLM\Software\SProtector Key Deleted : HKLM\Software\Tarma Installer Key Deleted : HKLM\Software\torch Key Deleted : HKLM\Software\SearchFlyBar5 Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\NetAssistant 3.8.3 Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C792A75A-2A1F-4991-9B85-291745478A79} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E55E7026-EF2A-4A17-AAA7-DB98EA3FD1B1} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\alotAppbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wincore MediaBar Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4 Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6 Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852 Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0 Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96 Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59 Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6207E55EA2FE71A4AA7ABD89AEF31D1B Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\Software\Classes\Installer\Features\6207E55EA2FE71A4AA7ABD89AEF31D1B Key Deleted : HKLM\Software\Classes\Installer\Products\6207E55EA2FE71A4AA7ABD89AEF31D1B
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\Mai\AppData\Local\Google\Chrome\User Data\Default\preferences ] Results as follows.
Mai
Deleted : homepage
*************************
AdwCleaner[R0].txt - [10902 octets] - [15/01/2014 16:40:30] AdwCleaner[S0].txt - [11116 octets] - [15/01/2014 17:09:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11177 octets] ##########
|
|