Jump to content

Request for Help on infected computer


Recommended Posts

Hello,

 

Malware noobie here, just did a scan on a friends computer and it has a bunch of infected files.  I was going to remove using malware bytes but reading from the forums it seems like this is not a good idea.

 

So with that said, if anyone could help me I would appreciate it greatly.  Here is my log from the scan:

 

Please let me know if I need to attach anything else.  Thanks in advance!

 

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.12.01.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421

01/12/2013 5:00:40 PM
MBAM-log-2013-12-01 (17-19-12).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206395
Time elapsed: 17 minute(s), 36 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 6
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> No action taken.
HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1 (PUP.Optional.OptimizerPro.A) -> No action taken.
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> No action taken.
HKCU\SOFTWARE\OPTIMIZER PRO (PUP.Optional.OptimizerPro.A) -> No action taken.

Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell (Hijack.Shell.Gen) -> Data: C:\Users\Actyl\AppData\Roaming\Microsoft\vqxftg.exe -> No action taken.
HKCU\Software\Optimizer Pro|AdsBuyNowURL (PUP.Optional.OptimizerPro.A) -> Data: http://pcup26b.pcutilitiespro.revenuewire.net/driverpro/register?121000667-CA-006_ECDE9EBF-31C1-A9A6-ECD4-76D291818172 -> No action taken.

Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs (PUP.Optional.OptimizerPro.A) -> Bad: (c:\progra~1\optimi~1\optpro~1.dll) Good: () -> No action taken.

Folders Detected: 3
C:\Program Files\Optimizer Pro (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Users\Actyl\AppData\Roaming\DefaultTab\DefaultTab (PUP.Optional.DefaultTab.A) -> No action taken.

Files Detected: 35
C:\Users\Actyl\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (PUP.Optional.DefaultTab) -> No action taken.
C:\Users\Actyl\Local Settings\Temporary Internet Files\Content.IE5\B030TRSK\DefaultTabSetup_20130514[1].exe (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\Actyl\Local Settings\Temporary Internet Files\Content.IE5\LEIHLJ7Y\OptimizerPro[1].exe (PUP.Optional.OptimizePro.A) -> No action taken.
C:\Users\Actyl\Local Settings\Temporary Internet Files\Content.IE5\LEIHLJ7Y\statisticsstub[1].exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Actyl\Local Settings\Temporary Internet Files\Content.IE5\LRHNI81O\KeyBar_1.8[1].exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Actyl\Local Settings\Temporary Internet Files\Content.IE5\LRHNI81O\OtshotInstaller7[1].exe (PUP.Optional.Otshot.A) -> No action taken.
C:\Users\Actyl\Local Settings\Temporary Internet Files\Content.IE5\LRHNI81O\SPSetup[1].exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Actyl\Local Settings\Temporary Internet Files\Content.IE5\QH4N40G5\checktbexist[1].exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Actyl\Local Settings\Temporary Internet Files\Content.IE5\QH4N40G5\KeyBar_1_8_wpf[1].exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Windows\System32\f3PSSavr.scr (Trojan.Agent) -> No action taken.
C:\Program Files\Optimizer Pro\OptimizerPro.chm (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\CookiesException.txt (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\English.ini (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\file_id.diz (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\HomePage.url (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\OptimizerPro.exe (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\OptProCrash.dll (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\OptProGuard.exe (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\OptProLauncher.exe (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\OptProReminder.exe (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\OptProSchedule.exe (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\OptProSmartScan.exe (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\OptProStart.exe (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\OptProUninstaller.exe (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\scan.gif (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\sqlite3.dll (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\StartupList.txt (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\unins000.dat (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\unins000.exe (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\Program Files\Optimizer Pro\unins000.msg (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro\Optimizer Pro on the Web.lnk (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro\Check updates.lnk (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro\Help.lnk (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro\Optimizer Pro.lnk (PUP.Optional.OptimizerPro.A) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro\Uninstall Optimizer Pro.lnk (PUP.Optional.OptimizerPro.A) -> No action taken.

(end)
 

Link to post
Share on other sites

Welcome to the forum, try this procedure:

Lets clean out any adware/spyware now: (this will require a reboot so save all your work)

Please download AdwCleaner by Xplode and save to your Desktop.

Make sure you click on download buttons that look similar to this, not "sponsored ad links":

bleep-crop.jpg

  • Double click on AdwCleaner.exe to run the tool.

    Vista/Windows 7/8 users right-click and select Run As Administrator

  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you may want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review. (all items found are adware/spyware/foistware)
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted:
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.
Then..................

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a Quick Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Please let me know how computer is running now, MrC

Link to post
Share on other sites

Hello,

 

Here is my log from AdwCleaner.

 

I did also the same procedure for another computer of my friend's.  And when I do scan with Malwarebytes, there are three items the program finds however when I try to delete them the program just locks up.  Any suggestions for this?

 

Thanks much again, I'll make sure to donate for all your help ;)

 

# AdwCleaner v3.014 - Report created 03/12/2013 at 18:27:58
# Updated 01/12/2013 by Xplode
# Operating System : Windows Vista Home Premium Service Pack 2 (32 bits)
# Username : Actyl - ACTYL-PC
# Running from : C:\Users\Actyl\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Searchprotect
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\Tencent
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\otshot
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\FunWebProducts
Folder Deleted : C:\Program Files\MyWebSearch
Folder Deleted : C:\Program Files\optimizer pro
Folder Deleted : C:\Program Files\otshot
Folder Deleted : C:\Program Files\TelevisionFanaticEI
Folder Deleted : C:\Program Files\Tencent
Folder Deleted : C:\Program Files\Common Files\Tencent
Folder Deleted : C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}
Folder Deleted : C:\Users\Actyl\AppData\Local\apn
Folder Deleted : C:\Users\Actyl\AppData\Local\Conduit
Folder Deleted : C:\Users\Actyl\AppData\Local\Tencent
Folder Deleted : C:\Users\Actyl\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Actyl\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Actyl\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Actyl\AppData\LocalLow\TelevisionFanatic
Folder Deleted : C:\Users\Actyl\AppData\LocalLow\TelevisionFanaticEI
Folder Deleted : C:\Users\Actyl\AppData\LocalLow\Tencent
Folder Deleted : C:\Users\Actyl\AppData\Roaming\DefaultTab
Folder Deleted : C:\Users\Actyl\AppData\Roaming\Tencent
Folder Deleted : C:\Users\Actyl\AppData\Roaming\UpdaterEX
Folder Deleted : C:\Users\Actyl\AppData\Roaming\Mozilla\Firefox\Profiles\czcwag7d.default\CT3311668
Folder Deleted : C:\Users\Actyl\AppData\Roaming\Mozilla\Firefox\Profiles\czcwag7d.default\Extensions\toolbar@ask.com
Folder Deleted : C:\Users\Actyl\AppData\Roaming\Mozilla\Firefox\Profiles\czcwag7d.default\Extensions\{9ed31f84-c8b3-4926-b950-dff74047ff79}
Folder Deleted : C:\Users\Actyl\AppData\Local\Google\Chrome\User Data\Default\Extensions\adopjdgphfekoiecgklciallnajkpdgn
[!] Folder Deleted : C:\Users\Actyl\AppData\Local\Google\Chrome\User Data\Default\Extensions\adopjdgphfekoiecgklciallnajkpdgn
File Deleted : C:\END
File Deleted : C:\Windows\system32\f3PSSavr.scr
File Deleted : C:\Users\Actyl\AppData\Roaming\Mozilla\Firefox\Profiles\czcwag7d.default\invalidprefs.js
File Deleted : C:\Users\Actyl\AppData\Roaming\Mozilla\Firefox\Profiles\czcwag7d.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Actyl\AppData\Roaming\Mozilla\Firefox\Profiles\czcwag7d.default\searchplugins\Conduit.xml
File Deleted : C:\Users\Actyl\AppData\Roaming\Mozilla\Firefox\Profiles\czcwag7d.default\user.js
File Deleted : C:\Users\Actyl\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage
File Deleted : C:\Users\Actyl\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage-journal
File Deleted : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Google\Chrome\Extensions\adopjdgphfekoiecgklciallnajkpdgn
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\adopjdgphfekoiecgklciallnajkpdgn
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5CCC4F85-9B8D-4A79-8154-1553D623DED7}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5CCC4F85-9B8D-4A79-8154-1553D623DED7}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduit.com
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchProtectAll
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3311668
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6517DD27-EA6F-4947-9DEA-F9C487BB1020}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6517DD27-EA6F-4947-9DEA-F9C487BB1020}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04D2B915-19FF-41E9-994D-95DC898BEA43}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A5B9C0F5-5616-47CD-A95F-E43B488FACCF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A5B9C0F5-5616-47CD-A95F-E43B488FACCF}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00A6FAF6-072E-44CF-8957-5838F569A31D}]
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\TENCENT
Key Deleted : HKCU\Software\UpdaterEX
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\MyWebSearch
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\TelevisionFanatic
Key Deleted : HKCU\Software\AppDataLow\Software\TelevisionFanaticEI
Key Deleted : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\FocusInteractive
Key Deleted : HKLM\Software\Fun Web Products
Key Deleted : HKLM\Software\MyWebSearch
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\TelevisionFanatic
Key Deleted : HKLM\Software\TENCENT
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Optimizer Pro_is1
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16520


-\\ Mozilla Firefox v25.0.1 (en-US)

[ File : C:\Users\Actyl\AppData\Roaming\Mozilla\Firefox\Profiles\czcwag7d.default\prefs.js ]

Line Deleted : user_pref("CT3311668.FF19Solved", "true");
Line Deleted : user_pref("CT3311668.UserID", "UN12712179783116218");
Line Deleted : user_pref("CT3311668.browser.search.defaultthis.engineName", "true");
Line Deleted : user_pref("CT3311668.fullUserID", "UN12712179783116218.IN.20130911153741");
Line Deleted : user_pref("CT3311668.installDate", "11/09/2013 15:37:50");
Line Deleted : user_pref("CT3311668.installSessionId", "-1");
Line Deleted : user_pref("CT3311668.installSp", "TRUE");
Line Deleted : user_pref("CT3311668.installerVersion", "1.6.1.1");
Line Deleted : user_pref("CT3311668.keyword", "true");
Line Deleted : user_pref("CT3311668.originalHomepage", "about:home");
Line Deleted : user_pref("CT3311668.originalSearchAddressUrl", "");
Line Deleted : user_pref("CT3311668.originalSearchEngine", "");
Line Deleted : user_pref("CT3311668.originalSearchEngineName", "");
Line Deleted : user_pref("CT3311668.searchRevert", "false");
Line Deleted : user_pref("CT3311668.searchUserMode", "2");
Line Deleted : user_pref("CT3311668.smartbar.homepage", "true");
Line Deleted : user_pref("CT3311668.versionFromInstaller", "10.16.9.6");
Line Deleted : user_pref("CT3311668.xpeMode", "0");

Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "KeyBar 1.8 Customized Web Search");

Line Deleted : user_pref("browser.search.order.1", "Ask.com");

Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3311668");


Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3311668");
Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3311668");
Line Deleted : user_pref("smartbar.machineId", "9FTZKA+4XKZSJ2IFFONZ1GYTTXDIPASLMGH3HODWDXKNDVZSMKYPO0ERWLNPIX4KRHRFHK46ZCMC0QO/W5ES1Q");


-\\ Google Chrome v31.0.1650.57

[ File : C:\Users\Actyl\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : icon_url
Deleted : search_url
Deleted : suggest_url
Deleted : keyword
Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [16157 octets] - [03/12/2013 18:26:27]
AdwCleaner[s0].txt - [16050 octets] - [03/12/2013 18:27:58]

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [16111 octets] ##########
 

Link to post
Share on other sites

I did also the same procedure for another computer of my friend's. And when I do scan with Malwarebytes, there are three items the program finds however when I try to delete them the program just locks up. Any suggestions for this?

Just take note of what they are if you could and skip them.

They should show in a FRST scan.

MrC

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.