Jump to content

pop adware


Recommended Posts

hey guys i have problems with adware called tradeadexchange


only way to remove this adware by reseting router settings


but the problem its keep coming back


malwarebytes dose not detect it


i tried every thing i removed all the programs and resetup them


and i did  full scan twice


any help?

Link to post
Share on other sites

Hello and welcome to Malwarebytes,

Please be aware the following P2P/Piracy Warning is a standard opening reply made here at Malwarebytes, we make no accusations but do make you aware of Forum Protocol....

If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

Anyone other than the original starter of this thread please DO NOT follow the instructions and advice posted as replies here, my help and advice is NOT related to your system and will probably cause more harm than good...

Please open Malwarebytes Anti-Malware.

  • On the Settings tab > Detection and Protection sub tab, Detection Options, tick the box "Scan for rootkits". <---- Very Important
  • Under Non-Malware Protection sub tab Change PUP and PUM entries to Treat detections as Malware
  • Click on the Scan tab, then click on Scan Now >> . If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • With some infections, you may or may not see this message box.

            'Could not load DDA driver'
  • Click 'Yes' to this message, to allow the driver to load after a restart.
  • Allow the computer to restart. Continue with the rest of these instructions.
  • When the scan is complete, click Apply Actions.
  • Wait for the prompt to restart the computer to appear, then click on Yes.
  • After the restart once you are back at your desktop, open MBAM once more.

To get the log from Malwarebytes do the following:

  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have three options:

      Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
      Text file (*.txt)        - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
      XML file (*.xml)      - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
  • Please use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply…

If Malwarebytes is not installed follow these instructions first:

Download Malwarebytes Anti-Malware to your desktop.

  • Double-click mbam-setup and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
  • Launch Malwarebytes Anti-Malware
  • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish. Follow the instructions above....


Download AdwCleaner by Xplode onto your Desktop.

  • Double click on Adwcleaner.exe to run the tool.
  • Click on the Scan in the Actions box
  • Please wait fot the scan to finish..
  • When "Waiting for action.Please uncheck elements you want to keep" shows in top line..
  • Click on the Cleaning box.
  • Next click OK on the "Closing Programs" pop up box.
  • Click OK on the Information box & again OK to allow the necessary reboot
  • After restart the AdwCleaner(C*)-Notepad log will appear, please copy/paste it in your next reply. Where * is the number relative to list of scans completed...


Download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
    (Windows 8/10 users will be prompted about Windows SmartScreen protection - click More information and Run.)
  • Make sure Addition.txt is checkmarked under "Optional scans"
  • Press Scan button to run the tool....
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The tool will also make a log named (Addition.txt) Please attach those logs to your reply.

Let me see those logs in your next reply...

Thank you,


Link to post
Share on other sites

Additional scan result of Farbar Recovery Scan Tool (x64) Version:24-02-2016

Ran by amr (2016-02-25 20:57:30)

Running from C:\Users\amr\Downloads

Windows 7 Home Basic Service Pack 1 (X64) (2016-02-20 12:42:39)

Boot Mode: Normal




==================== Accounts: =============================


Administrator (S-1-5-21-2477750965-3279092746-2328752535-500 - Administrator - Disabled)

amr (S-1-5-21-2477750965-3279092746-2328752535-1000 - Administrator - Enabled) => C:\Users\amr

Guest (S-1-5-21-2477750965-3279092746-2328752535-501 - Limited - Enabled)


==================== Security Center ========================


(If an entry is included in the fixlist, it will be removed.)


AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


==================== Installed Programs ======================


(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)


Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)

Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)

Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version:  - Cheat Engine)

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)

Google Update Helper (x32 Version: - Google Inc.) Hidden

IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: - IObit)

Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)

Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)

Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: - AVG Technologies)

Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: - AVG Technologies CZ, s.r.o.)

WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version:  - )


==================== Custom CLSID (Whitelisted): ==========================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)



==================== Scheduled Tasks (Whitelisted) =============


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


Task: {220FBCB7-E9B3-4FDB-AE12-9B34BFBD06A6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-24] (Google Inc.)

Task: {52A67081-B019-48F3-AF8F-A73B15C19CDF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-24] (Google Inc.)

Task: {C01895CF-CF64-42CD-8B99-993DC2A88407} - System32\Tasks\ASC Task (One-Time) => C:\Program Files (x86)\IObit\Advanced SystemCare\PromoteASCAfterInstall.exe

Task: {C37F30F6-1732-40DA-B7C3-CF543C58BE0B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-20] (Adobe Systems Incorporated)


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe


==================== Shortcuts =============================


(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============


2016-02-24 22:23 - 2016-02-18 06:14 - 01630360 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libglesv2.dll

2016-02-24 22:23 - 2016-02-18 06:14 - 00085656 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libegl.dll

2016-02-24 23:49 - 2015-12-23 16:27 - 00355616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl

2016-02-24 23:49 - 2015-12-23 16:27 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl

2016-02-24 23:49 - 2015-12-23 16:27 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl


==================== Alternate Data Streams (Whitelisted) =========


(If an entry is included in the fixlist, only the ADS will be removed.)



==================== Safe Mode (Whitelisted) ===================


(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)



==================== EXE Association (Whitelisted) ===============


(If an entry is included in the fixlist, the registry item will be restored to default or removed.)



==================== Internet Explorer trusted/restricted ===============


(If an entry is included in the fixlist, it will be removed from the registry.)



==================== Hosts content: ===============================


(If needed Hosts: directive could be included in the fixlist to reset Hosts.)


2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts



==================== Other Areas ============================


(Currently there is no automatic fix for this section.)


HKU\S-1-5-21-2477750965-3279092746-2328752535-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\amr\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

DNS Servers: -

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Windows Firewall is enabled.


==================== MSCONFIG/TASK MANAGER disabled items ==


(Currently there is no automatic fix for this section.)



==================== FirewallRules (Whitelisted) ===============


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


FirewallRules: [{72C09185-5170-427F-BEDD-320930AF3135}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Restore Points =========================


25-02-2016 19:49:59 Windows Modules Installer

25-02-2016 20:48:51 JRT Pre-Junkware Removal


==================== Faulty Device Manager Devices =============


Name: Teredo Tunneling Pseudo-Interface

Description: Microsoft Teredo Tunneling Adapter

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Manufacturer: Microsoft

Service: tunnel

Problem: : This device cannot start. (Code10)

Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.

On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.



==================== Event log errors: =========================


Application errors:


Error: (02/25/2016 07:44:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )

Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.



AddLegacyDriverFiles: Unable to back up image of binary AVGIDSDriver.


System Error:

The system cannot find the file specified.



Error: (02/25/2016 02:30:34 AM) (Source: MsiInstaller) (EventID: 11706) (User: amr-PC)

Description: Product: AdAwareInstaller -- Error 1706. No valid source could be found for product AdAwareInstaller.  The Windows Installer cannot continue.


Error: (02/25/2016 02:28:43 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: AdAwareTray.exe, version: 11.10.767.8917, time stamp: 0x56aa28a8

Faulting module name: HtmlFramework.dll_unloaded, version:, time stamp: 0x56a9e3f7

Exception code: 0xc0000005

Fault offset: 0x000007fef702eb43

Faulting process id: 0x3f0

Faulting application start time: 0xAdAwareTray.exe0

Faulting application path: AdAwareTray.exe1

Faulting module path: AdAwareTray.exe2

Report Id: AdAwareTray.exe3


Error: (02/25/2016 12:46:36 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: Explorer.EXE, version: 6.1.7601.19135, time stamp: 0x56a1bbe2

Faulting module name: WINHTTP.DLL, version: 6.1.7601.17514, time stamp: 0x4ce7ca23

Exception code: 0xc0000005

Fault offset: 0x0000000000001376

Faulting process id: 0x6f4

Faulting application start time: 0xExplorer.EXE0

Faulting application path: Explorer.EXE1

Faulting module path: Explorer.EXE2

Report Id: Explorer.EXE3


Error: (02/25/2016 12:44:29 AM) (Source: MsiInstaller) (EventID: 11706) (User: amr-PC)

Description: Product: AdAwareInstaller -- Error 1706. No valid source could be found for product AdAwareInstaller.  The Windows Installer cannot continue.


Error: (02/24/2016 11:57:46 PM) (Source: MsiInstaller) (EventID: 11706) (User: amr-PC)

Description: Product: AdAwareInstaller -- Error 1706. No valid source could be found for product AdAwareInstaller.  The Windows Installer cannot continue.


Error: (02/23/2016 09:40:10 PM) (Source: Application Hang) (EventID: 1002) (User: )

Description: The program sro_client.exe version stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.


Process ID: 664


Start Time: 01d16e71eaa6714f


Termination Time: 230


Application Path: D:\QueenSro\sro_client.exe


Report Id: 3ee2cfa7-da65-11e5-83df-6c626db106cc


Error: (02/21/2016 03:39:25 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: mscorsvw.exe, version: 4.0.30319.34209, time stamp: 0x5348947f

Faulting module name: unknown, version:, time stamp: 0x00000000

Exception code: 0xc0000005

Fault offset: 0x74977374

Faulting process id: 0xfc8

Faulting application start time: 0xmscorsvw.exe0

Faulting application path: mscorsvw.exe1

Faulting module path: mscorsvw.exe2

Report Id: mscorsvw.exe3


Error: (02/20/2016 07:02:26 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: mscorsvw.exe, version: 4.0.30319.1, time stamp: 0x4ba1da21

Faulting module name: unknown, version:, time stamp: 0x00000000

Exception code: 0xc0000005

Fault offset: 0x75076cc4

Faulting process id: 0x334

Faulting application start time: 0xmscorsvw.exe0

Faulting application path: mscorsvw.exe1

Faulting module path: mscorsvw.exe2

Report Id: mscorsvw.exe3


Error: (02/20/2016 06:50:17 PM) (Source: SideBySide) (EventID: 33) (User: )

Description: Activation context generation failed for "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".

Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.

Please use sxstrace.exe for detailed diagnosis.



System errors:


Error: (02/25/2016 02:35:16 AM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load: 




Error: (02/25/2016 02:12:33 AM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load: 




Error: (02/23/2016 02:24:45 AM) (Source: volsnap) (EventID: 36) (User: )

Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.


Error: (02/22/2016 01:24:38 PM) (Source: volsnap) (EventID: 36) (User: )

Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.


Error: (02/21/2016 05:05:04 PM) (Source: volsnap) (EventID: 36) (User: )

Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.


Error: (02/21/2016 02:59:30 PM) (Source: EventLog) (EventID: 6008) (User: )

Description: The previous system shutdown at 02:58:02 م on ‏21/‏02/‏2016 was unexpected.


Error: (02/21/2016 03:54:24 AM) (Source: volsnap) (EventID: 36) (User: )

Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.


Error: (02/21/2016 03:45:07 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)

Description: Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Internet Explorer 8 Compatibility View List for Windows 7 for x64-based Systems (KB2598845).


Error: (02/21/2016 03:44:07 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The Windows Modules Installer service terminated with the following error: 



Error: (02/21/2016 03:39:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: )

Description: The Microsoft .NET Framework NGEN v4.0.30319_X86 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.



==================== Memory info =========================== 


Processor: Intel® Core i3 CPU 540 @ 3.07GHz

Percentage of memory in use: 33%

Total physical RAM: 6007.11 MB

Available physical RAM: 3966.36 MB

Total Virtual: 12012.43 MB

Available Virtual: 10187.07 MB


==================== Drives ================================


Drive c: () (Fixed) (Total:48.49 GB) (Free:16.04 GB) NTFS

Drive d: () (Fixed) (Total:249.26 GB) (Free:144.24 GB) NTFS

Drive f: (System Reserved) (Fixed) (Total:0.34 GB) (Free:0.08 GB) NTFS ==>[system with boot components (obtained from drive)]


==================== MBR & Partition Table ==================



Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 7185AC3F)

Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=48.5 GB) - (Type=07 NTFS)

Partition 3: (Not Active) - (Size=249.3 GB) - (Type=07 NTFS)


==================== End of Addition.txt ============================

Link to post
Share on other sites

If logs are exceeding character limits you can attach them to your reply direct, do not use any outside file transfer programs.... Also did you run Malwarebytes as requested, can I see that log...


To attach files or images etc.. Select "More Reply Options" tab under the reply box, a new reply window will open. Select "Browse" to locate the file you want, double click direct on that file to upload, then select "Attach This File" to do just that. Repeat if required...

Link to post
Share on other sites

AdwCleaner log only shows entries as "Found" why has the "Cleaning" action not been used?




I gave you the instructions to install Malwarebytes in my opening reply, why has that not been done?


Download Malwarebytes Anti-Malware to your desktop.

  • Double-click mbam-setup and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
  • Launch Malwarebytes Anti-Malware
  • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes Select > Settings > Detection and Protection > Enable Scan for rootkit and Under Non Malware Protection set both PUP and PUM to Treat detections as malware.
  • Now select > Scan > Threat scan > Scan now
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

To get the log from Malwarebytes do the following:

  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have three options:

      Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
      Text file (*.txt)        - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
      XML file (*.xml)      - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
  • Please use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply…


Post those logs, also give an update on any remaining issues or concerns...


Thank you,



Link to post
Share on other sites

Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.
NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

Run FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply.




Download and Save McAfee Stinger to your Desktop from here:


Read the Terms and Conditions, the download tab is at the bottom of the page.
Close all browsers before starting. Disable your antivirus program and anti-malware, if any.
To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs read here:


On Windows 7, 8, 10 & Vista systems, Right Click on Stinger stinger.jpg and select Run as Administrator.
On XP, double-click to start it.
Click on “I Accept” tab at McAfee end user licence agreement.


In the new Window select “Advanced” then “Settings”


The settings window will open, make sure the settings are exactly as shown in the following image, then select “Save” <<------Very Important


In the new window Click the “Customize my Scan” under the “Scan” button.


In the new Window select C:\ drive and any other listed Hard Drive, then select “Scan”


When the scan completes select the “View log” to do that, select “Notepad” if offered in list of choices.

If the log opens in your browser, copy and save to  a file....

I will need a copy of that log.


Post those logs in your reply...


Thank you,




Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.