Jump to content

CouponDropDown in Shockwave Flash PLUG-IN


Guest GregoryPOL

Recommended Posts

Guest GregoryPOL

Hello,

I didn't post DDS logs, because I know the exact source of my problem with CouponDropDown. It resides in the Shockwave Flash Plug-in. I'm using Mozilla Firefox and it's the only browser where this adware pops up. When I disable the plug in, the adware is gone and everything works fine. Since it's a Flash plug-in I need it to be functional and it must be turned ON all the time so I don't know what to do next. The only thing that came to my mind was updating the Flash Plug-in but this didn't change anything. The CDD was also present is some other spots, but I've removed them all (except for the one mentioned) with Add/Remove Programs in Control Panel and browser's Add-ons manager.

If the DDS logs are necessary I will post them. I didn't want to make the conversation too complicated since my experience with PCs is not that deep as far as the PC maintanance, system details, malware removal etc. I'm still hoping that a simple solution is possible here and the info I've provided will be enough.

Please help, this thing is very annoying ...

Link to post
Share on other sites

Guest GregoryPOL

I've just noticed that turning off the Flash plug in does not remove CDD from my browser anymore. So here are my DDS logs :

C:\WINDOWS\System32\svchost.exe -k NetworkService

C:\WINDOWS\System32\svchost.exe -k LocalService

.

============== Pseudo HJT Report ===============

.

uStart Page = about:blank

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll

BHO: Freecorder extension: {B15BBE59-42F5-4206-B3F0-BE98F5DC4B93} - c:\program files\freecorder extension\ScriptHost.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [AVG_UI] "d:\program files\avg\avgui.exe" /TRAYONLY

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\edimax~1.lnk - c:\program files\edimax\11n usb wireless lan utility\RtWLan.exe

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

mPolicies-Explorer: NoDriveTypeAutoRun = dword:145

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

LSP: %SYSTEMROOT%\system32\nvappfilter.dll

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

TCP: NameServer = 192.168.1.1 192.168.1.1

TCP: Interfaces\{00533975-3016-4FC1-942E-D7934257EE64} : NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1

TCP: Interfaces\{1C324A99-A32B-4AE6-9ECF-AD70CE5E3CDF} : DHCPNameServer = 192.168.1.1 192.168.1.1

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\27.0.1453.94\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\documents and settings\mercury\application data\mozilla\firefox\profiles\dtcyf5j9.default\

FF - prefs.js: browser.startup.homepage - about:home

FF - plugin: c:\documents and settings\mercury\application data\mozilla\firefox\profiles\dtcyf5j9.default\extensions\addon@freecorder.com\plugins\npFreeCoder.dll

FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll

FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll

FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll

FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_202.dll

.

============= SERVICES / DRIVERS ===============

.

R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-10-15 55776]

R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-9-21 177376]

R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-11-16 94048]

R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-9-14 35552]

R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-10-22 179936]

R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-9-21 19936]

R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-10-2 159712]

R2 AVGIDSAgent;AVGIDSAgent;d:\program files\avg\avgidsagent.exe [2012-11-16 5814904]

R2 avgwd;AVG WatchDog;d:\program files\avg\avgwdsvc.exe [2012-10-22 196664]

R2 DragonUpdater;COMODO Dragon Update Service;c:\program files\comodo\dragon\dragon_updater.exe [2013-5-29 2094216]

R2 MBAMScheduler;MBAMScheduler;d:\program files\anti malware\malwarebytes' anti-malware\mbamscheduler.exe [2013-6-1 418376]

R2 MBAMService;MBAMService;d:\program files\anti malware\malwarebytes' anti-malware\mbamservice.exe [2013-6-1 701512]

R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\enigma~1\spyhun~1\SH4SER~1.EXE [2010-5-18 327064]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-6-1 22856]

R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [2012-12-21 594048]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2012-12-21 1691480]

.

=============== Created Last 30 ================

.

2013-06-01 08:07:48 733224 ----a-w- c:\documents and settings\mercury\local settings\application data\qs.dll

2013-06-01 08:07:48 63160 ----a-w- c:\documents and settings\mercury\local settings\application data\dpqs.exe

2013-06-01 08:07:48 2051696 ----a-w- c:\documents and settings\mercury\local settings\application data\qs64.dll

2013-06-01 07:23:59 110080 ----a-r- c:\documents and settings\mercury\application data\microsoft\installer\{4fc9da9d-f608-454e-8191-d7effdcc5726}\IconF7A21AF7.exe

2013-06-01 07:23:59 110080 ----a-r- c:\documents and settings\mercury\application data\microsoft\installer\{4fc9da9d-f608-454e-8191-d7effdcc5726}\IconD7F16134.exe

2013-06-01 07:23:56 -------- d-----w- C:\sh4ldr

2013-06-01 07:23:41 -------- d-----w- c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP

2013-06-01 07:12:33 -------- d-----w- c:\documents and settings\mercury\application data\uTorrent

2013-06-01 02:12:49 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-06-01 02:00:17 -------- d-----w- c:\program files\Enigma Software Group

2013-06-01 01:59:59 -------- d-----w- c:\windows\E89498D814304A2BA76A4A71326981E9.TMP

2013-06-01 01:59:55 -------- d-----w- c:\program files\common files\Wise Installation Wizard

.

==================== Find3M ====================

.

2013-06-01 13:04:14 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-06-01 13:04:14 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2013-05-30 08:44:17 47368 ----a-w- c:\windows\system32\certsentry.dll

2013-04-04 03:35:08 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll

2013-03-05 11:50:47 861088 ----a-w- c:\windows\system32\npDeployJava1.dll

2013-03-05 11:50:47 782240 ----a-w- c:\windows\system32\deployJava1.dll

.

============= FINISH: 5:12:28,64 ===============

RP100: 2013-04-20 02:20:58 - System Checkpoint

RP101: 2013-04-21 17:22:04 - System Checkpoint

RP102: 2013-04-22 17:58:00 - System Checkpoint

RP103: 2013-04-24 18:52:54 - System Checkpoint

RP104: 2013-04-25 17:20:38 - Installed Java 7 Update 21

RP105: 2013-05-01 12:35:38 - System Checkpoint

RP106: 2013-05-05 19:23:42 - System Checkpoint

RP107: 2013-05-07 16:01:08 - System Checkpoint

RP108: 2013-05-11 23:10:53 - System Checkpoint

RP109: 2013-05-18 16:09:39 - System Checkpoint

RP110: 2013-05-22 23:45:57 - System Checkpoint

RP111: 2013-05-23 09:08:02 - Usunięto AVG 2013

RP112: 2013-05-24 17:57:29 - System Checkpoint

RP113: 2013-05-29 11:53:29 - System Checkpoint

RP114: 2013-06-01 04:00:15 - Installed SpyHunter

RP115: 2013-06-01 04:17:00 - Removed SpyHunter

RP116: 2013-06-01 09:23:54 - Installed SpyHunter

RP117: 2013-06-01 13:49:41 - Removed Microsoft Silverlight

RP118: 2013-06-01 14:06:30 - Removed SweetPacks bundle uninstaller

RP119: 2013-06-01 14:49:53 - Removed Microsoft Silverlight

.

==== Installed Programs ======================

.

7-Zip 9.20

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Applian FLV and Media Player 3.1.1.12

µTorrent

Auslogics Registry Cleaner

AVG 2013

CCleaner

Comodo Dragon

Edimax Wireless LAN Driver and Utility

FEAR

FEAR Extraction Point

Freecorder 7 Applications (7.0.0.48)

Freecorder extension

Freecorder extension for Chrome

Freecorder extension for Firefox

Full Tilt Poker.Eu

Google Chrome

Google Update Helper

High Definition Audio Driver Package - KB888111

Hotfix for Windows XP (KB915865)

Java 7 Update 21

Java Auto Updater

Malwarebytes Anti-Malware version 1.75.0.1300

Microsoft .NET Framework 2.0

Microsoft Internationalized Domain Names Mitigation APIs

Microsoft National Language Support Downlevel APIs

Microsoft Silverlight

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Microsoft_VC80_CRT_x86

Microsoft_VC90_CRT_x86

Mozilla Firefox 21.0 (x86 pl)

Mozilla Maintenance Service

NVIDIA Control Panel 306.81

NVIDIA Drivers

NVIDIA ForceWare Network Access Manager

NVIDIA Graphics Driver 306.81

NVIDIA Install Application

NVIDIA nView 136.28

NVIDIA Update 1.10.8

NVIDIA Update Components

PokerStars.eu

Realtek High Definition Audio Driver

SpyHunter

Total Commander (Remove or Repair)

WebFldrs XP

Winamp

Winamp Detector Plug-in

Windows Media Format Runtime

Windows XP Service Pack 2

.

==== Event Viewer Messages From Past Week ========

.

2013-06-01 13:49:42, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.

2013-06-01 13:45:27, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.

2013-06-01 10:48:45, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

2013-06-01 10:48:39, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

2013-06-01 05:50:52, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.

.

==== End Of File ===========================

Link to post
Share on other sites

Hello GregoryPOL and :welcome:! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.

Step 1

Please uninstall the following applications:

µTorrent

Freecorder extension

Freecorder extension for Chrome

Freecorder extension for Firefox

Step 2

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Step 3

  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

Step 4

Please download AdwCleaner from here and save it on your Desktop.

  1. Right-click on adwcleaner.exe and select Run As Administrator to launch the application.
  2. Now click on the Search tab.
  3. Please post the contents of the log-file created in your next post.

Note: The log can also be located at C:\ >> AdwCleaner[XX].txt >> XX <-- Denotes the number of times the application has been ran, so in this should be something like R1.

Step 5

  • Download on the desktop RogueKiller
  • Quit all programs
  • Start RogueKiller.exe
  • Wait until Prescan has finished ...
  • Click on Scan. Click on Report and copy/paste the content of the notepad in your next reply.

In your next reply, post the following log files:

  • Junkware Removal Tool log
  • Malwarebytes' Anti-Malware log
  • AdwCleaner log
  • RogueKiller log

Link to post
Share on other sites

Guest GregoryPOL

Looks like all the CouponDropDown garbage is gone ... :) Here are the logs, RogueKiller found 3 Registry files, but I didn't delete them since it wasn't mentioned in the instructions. I think it was the Freecorder extension that was responsible, but I still need to reboot to be 100 % sure if it's all gone.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 4.9.4 (05.06.2013:1)

OS: Microsoft Windows XP x86

Ran by Mercury on 2013-06-02 at 12:27:46,46

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services

~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\Mercury\Application Data\goforfiles"

Successfully deleted: [Folder] "C:\Program Files\goforfiles"

~~~ FireFox

Successfully deleted: [Folder] C:\Documents and Settings\Mercury\Application Data\mozilla\firefox\profiles\dtcyf5j9.default\extensions\addon@freecorder.com

Successfully deleted the following from C:\Documents and Settings\Mercury\Application Data\mozilla\firefox\profiles\dtcyf5j9.default\prefs.js

user_pref("extensions.freecorder@freecorder.com.menuitems", "[{\"name\":\"Freecorder Menu Header\",\"img\":\"hxxp://freecorder.com/fc7/ui/buttons/menu_header.png\",\"width\":2

Emptied folder: C:\Documents and Settings\Mercury\Application Data\mozilla\firefox\profiles\dtcyf5j9.default\minidumps [4 files]

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on 2013-06-02 at 12:30:20,10

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Malwarebytes Anti-Malware 1.75.0.1300

www.malwarebytes.org

Database version: v2013.06.01.01

Windows XP Service Pack 2 x86 NTFS

Internet Explorer 7.0.5730.13

Mercury :: MERCURY-FSYLY0J [administrator]

2013-06-02 12:33:23

mbam-log-2013-06-02 (12-33-23).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 217134

Time elapsed: 2 minute(s), 40 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

# AdwCleaner v2.301 - Logfile created 06/02/2013 at 12:38:32

# Updated 16/05/2013 by Xplode

# Operating system : Microsoft Windows XP Service Pack 2 (32 bits)

# User : Mercury - MERCURY-FSYLY0J

# Boot Mode : Normal

# Running from : D:\Program Files\AdwCleaner\AdwCleaner.exe

# Option [search]

***** [services] *****

***** [Files / Folders] *****

***** [Registry] *****

***** [internet Browsers] *****

-\\ Internet Explorer v7.0.5730.13

[OK] Registry is clean.

-\\ Mozilla Firefox v21.0 (pl)

File : C:\Documents and Settings\Mercury\Application Data\Mozilla\Firefox\Profiles\dtcyf5j9.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v27.0.1453.94

File : C:\Documents and Settings\Mercury\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [3845 octets] - [02/06/2013 04:49:07]

AdwCleaner[R2].txt - [3905 octets] - [02/06/2013 04:49:52]

AdwCleaner[R3].txt - [1179 octets] - [02/06/2013 04:55:12]

AdwCleaner[R4].txt - [1051 octets] - [02/06/2013 12:38:32]

AdwCleaner[s1].txt - [4163 octets] - [02/06/2013 04:50:36]

########## EOF - C:\AdwCleaner[R4].txt - [1171 octets] ##########

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com

Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/

Website : http://tigzy.geekstogo.com/roguekiller.php

Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 2) 32 bits version

Started in : Normal mode

User : Mercury [Admin rights]

Mode : Scan -- Date : 06/02/2013 12:41:39

| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 5 ¤¤¤

[DNS] HKLM\[...]\ControlSet001\Services\Tcpip\Interfaces\{00533975-3016-4FC1-942E-D7934257EE64} : NameServer (8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1) -> FOUND

[DNS] HKLM\[...]\ControlSet002\Services\Tcpip\Interfaces\{00533975-3016-4FC1-942E-D7934257EE64} : NameServer (195.150.77.18) -> FOUND

[HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND

[HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND

[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

--> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD5000AZRX-00A8LB0 +++++

--- User ---

[MBR] ad060a40419b8fa8008feb1c3a99d439

[bSP] 566a7a06bea82a911537cb1b21f4572c : Windows XP MBR Code

Partition table:

0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 76928 Mo

1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 157549455 | Size: 200004 Mo

2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 567158760 | Size: 200004 Mo

User = LL1 ... OK!

User = LL2 ... OK!

+++++ PhysicalDrive1: WDC WD4000AAKS-00A7B0 +++++

--- User ---

[MBR] f93f5f6af01549ed317632b4a17eb695

[bSP] e24cb1d96bb0435339ae2e20363bf06b : Windows XP MBR Code

Partition table:

0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 381551 Mo

User = LL1 ... OK!

User = LL2 ... OK!

Finished : << RKreport[1]_S_06022013_02d1241.txt >>

RKreport[1]_S_06022013_02d1241.txt

Link to post
Share on other sites

Glad I could help! :)

Step 1

  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

Step 2

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Uninstall
  • Confirm with Yes

Step 3

Some malware prevention tips:

users.telenet.be/bluepatchy/miekiemoes/prevention.html

Safe surfing! :)

Link to post
Share on other sites

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.