This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

very slow, browsers/tabs popping up and redirecting [Closed]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm going to keep it because I've used it before with no issues, but I let someone else use my computer and they completely screwed up.
I will try to get the newest instructions completed tomorrow with an update. Thank you!
Hi electriccrayon

I'm going to keep it because I've used it before with no issues,
I will try to get the newest instructions completed tomorrow with an update

:thumbup:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-06-2014 02
Ran by [removed] at 2014-06-14 23:03:04 Run:1
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
BHO-x32: best-markit - {A90EF874-D8F4-653A-B396-CDFC7CDFF513} - C:\Program Files (x86)\best-markit\170.dll No File
FF Extension: ScanTack - C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\Extensions\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}.xpi [2014-05-22]
FF HKCU\…\Firefox\Extensions: [{3FC12FD8-623B-B4F1-94D5-E0688217340C}] - C:\Program Files (x86)\best-markit\170.xpi
CHR Extension: (best-markit) - C:\Users\RAC\AppData\Local\Google\Chrome\User Data\Default\Extensions\olimhpiccpogaohkijonbfajaggkegig [2014-05-22]
Task: {3C02EC9B-7147-4938-B3D7-86F98D5201A1} - \Browser Updater\Zapp Browser Updater No Task File <==== ATTENTION
Task: {58D5F89C-5A60-4732-AD7C-19631BFDAF8B} - \BackgroundContainer Startup Task No Task File <==== ATTENTION
FF Extension: Zapp - C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\Extensions\{c22c1a80-3af2-449c-a94e-e15e7686e0ed} [2014-05-22]
*****************

C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
'HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A90EF874-D8F4-653A-B396-CDFC7CDFF513}' => Key deleted successfully.
'HKCR\Wow6432Node\CLSID\{A90EF874-D8F4-653A-B396-CDFC7CDFF513}' => Key deleted successfully.
C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\Extensions\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}.xpi => Moved successfully.
HKCU\Software\Mozilla\Firefox\Extensions\\{3FC12FD8-623B-B4F1-94D5-E0688217340C} => value deleted successfully.
C:\Users\RAC\AppData\Local\Google\Chrome\User Data\Default\Extensions\olimhpiccpogaohkijonbfajaggkegig => Moved successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3C02EC9B-7147-4938-B3D7-86F98D5201A1}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C02EC9B-7147-4938-B3D7-86F98D5201A1}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater\Zapp Browser Updater' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{58D5F89C-5A60-4732-AD7C-19631BFDAF8B}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58D5F89C-5A60-4732-AD7C-19631BFDAF8B}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BackgroundContainer Startup Task' => Key deleted successfully.
C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\Extensions\{c22c1a80-3af2-449c-a94e-e15e7686e0ed} => Moved successfully.


The system needed a reboot.

==== End of Fixlog ====

 

everything seems to be running smooth now. I think it's running better than it was when I first got it from rent a center!

Is there anything else I need to follow up on?

Hi electriccrayon,

It's important that you follow through with the remainder of the steps I will outline. Absence of symptoms doesn't necessarily translate into malware free. We are making progress so please stay with me until I give you the "all clean" sign. :thumbup:

You previously downloaded the next tool. If you still have it on the computer it is not necessary to download it again.

[external image: bullseye_zpse9eaf36e.gif] Security Check

Download Security Check by screen317 from here or here.

  • Save it to your Desktop.
  • Right click SecurityCheck.exe, select "Run as Administrator" and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=========================

[external image: bullseye_zpse9eaf36e.gif] Re- run AdwCleaner

It should be on your desktop

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished…
  • This time, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a log file report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that log file in your next reply.
  • A copy of that log file will also be saved in the C:\AdwCleaner folder.

=========================

[external image: bullseye_zpse9eaf36e.gif] Malwarebytes' Anti-Malware

Download Malwarebytes' Anti-Malware (save it to your desktop).

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Select Scan tab.
    [external image: MBAMDashboard_zpsddef9b5f.gif]
  • Select type of scan to perform:
    [external image: MBAMScanTab_zps2c5e74bd.gif]
    • Threat Scan < — Select this type of scan
    • Custom Scan
    • Hyper Scan
  • Next click the Scan button.
  • When the scan is complete, if no malicious items are found you can close the program.
  • If malicious items are found be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

=========================

[external image: bullseye_zpse9eaf36e.gif] ESET Online Scanner

*Note:

  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.

** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.

=========================

In your next post please provide the following:

  • checkup.txt
  • AdwCleaner[S1].txt
  • MBAM log
  • ESET's log.txt

  Results of screen317's Security Check version 0.99.85  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:`````````
 Malwarebytes Anti-Malware version 1.75.0.1300  
  Adobe Flash Player 13.0.0.214 Flash Player out of Date!  
 Adobe Reader 10.1.9 Adobe Reader out of Date!  
 Mozilla Firefox 29.0.1 Firefox out of Date!  
 Google Chrome 35.0.1916.114  
 Google Chrome 35.0.1916.153  
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast avastui.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````
 

 

 

# AdwCleaner v3.212 - Report created 18/06/2014 at 16:08:38
# Updated 05/06/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : RAC - RAC-PC
# Running from : C:\Users\RAC\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\RAC\AppData\LocalLow\SimplyTech
File Deleted : C:\Windows\System32\Tasks\Browser Updater

***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17126


-\\ Mozilla Firefox v29.0.1 (en-US)

[ File : C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\prefs.js ]


-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\RAC\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [36941 octets] - [13/06/2014 15:10:51]
AdwCleaner[R1].txt - [1126 octets] - [18/06/2014 16:04:15]
AdwCleaner[S0].txt - [36219 octets] - [13/06/2014 15:14:30]
AdwCleaner[S1].txt - [1052 octets] - [18/06/2014 16:08:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1112 octets] ##########
 

 

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 6/18/2014
Scan Time: 4:33:08 PM
Logfile: MBscan.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.06.18.08
Rootkit Database: v2014.06.02.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: RAC

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 283231
Time Elapsed: 22 min, 6 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 3
PUP.Optional.Highlightly, HKLM\SOFTWARE\WOW6432NODE\Highlightly, Quarantined, [faf63f3ae299b581118748a9d42f48b8],
PUP.Optional.BestMarkIt.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\best_markit, Quarantined, [668a6e0b52291e180f7720988b77c43c],
PUP.Optional.BestMarkIt.A, HKU\S-1-5-21-3708736227-2111386937-3921986071-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\best_markit, Quarantined, [a749d7a25d1ea195176fd7e148baff01],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 2
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\toolbarImages, Quarantined, [38b86415413ab383f5444e4546bca15f],

Files: 81
PUP.Optional.Breitschopp, C:\Users\RAC\Downloads\five finger death punch+delug+bittorent+client_1.0(1).exe, Quarantined, [816fd9a03f3c3ef83c747bea32d244bc],
PUP.Optional.Breitschopp, C:\Users\RAC\Downloads\five finger death punch+delug+bittorent+client_1.0.exe, Quarantined, [f000e4953c3f64d23878521336ce53ad],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.129813684258939747.search.selectedEngineId, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.129813684258939747.search.settings, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.AlertService, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.AlertsInfoData, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.appOptions, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.cookiesRepo, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.NotificationSettings, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.NOTIFICATION_ID.alert_login_service, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_setupAPI, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_toolbarContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_toolbarSettings, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_translation, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_serviceMap, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_toolbarContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_toolbarSettings, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_translation, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_appsMetadata, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_appTrackingFirstTime, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_gottenAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_login, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_otherAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.NOTIFICATION_ID.notifications-repository, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_searchAPI, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_searchAPI, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_searchAPI, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_otherAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_serviceMap, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_serviceMap, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_toolbarContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_toolbarSettings, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.13.40.15.serviceLayer_services_translation, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_appsMetadata, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_appTrackingFirstTime, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_gottenAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_login, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_otherAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\serviceLayer_userApps_added, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\serviceLayer_userApps_removed, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\toolbar_initializing_logger.txt, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\uninstallData, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\uninstallUrl, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.NOTIFICATION_ID.notifications-servicemap, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.NOTIFICATION_ID.notifications-service_1647765, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.NOTIFICATION_ID.notifications_serviceMap, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.pg_conf_global, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.savedPositions, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.searchProtectorData, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468.skin, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_appsMetadata, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_appTrackingFirstTime, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_gottenAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_login, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.10.27.6.serviceLayer_services_otherAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_serviceMap, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_toolbarContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_toolbarSettings, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_translation, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.40.128.serviceLayer_services_userApps, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_appsMetadata, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_appTrackingFirstTime, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_gottenAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_location, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_login, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_searchAPI, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_serviceMap, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_setupAPI, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_toolbarContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_toolbarSettings, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_10.14.65.43.serviceLayer_services_translation, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_appsMetadata, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_appTrackingFirstTime, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_gottenAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_location, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_login, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_otherAppsContextMenu, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\CT3220468_RAW.serviceLayer_services_searchAPI, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\toolbarImages\http___storage_conduit_com_53_307_CT3072253_Images_634520779497696087.png, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\toolbarImages\http___storage_conduit_com_Images_ClientResources_mini_browser.gif, Quarantined, [38b86415413ab383f5444e4546bca15f],
PUP.Optional.Conduit.A, C:\Users\RAC\AppData\Roaming\Mozilla\Firefox\Profiles\nlh1noug.default\CT3220468\toolbarImages\http___storage_conduit_com_images_searchengines_search_icon.gif, Quarantined, [38b86415413ab383f5444e4546bca15f],

Physical Sectors: 0
(No malicious items detected)


(end)

 

 

C:\AdwCleaner\Quarantine\C\Program Files (x86)\best-markit\best-markitXX170.exe.vir    a variant of Win32/AdWare.AddLyrics.AN application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\best-markit\Uninstall.exe.vir    a variant of Win32/AdWare.AddLyrics.AM application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir    Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_en_105\freeSoftToday_widget.exe.vir    a variant of Win32/AdWare.EoRezo.AU application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_en_105\fst_en_105.exe.vir    a variant of Win32/AdWare.EoRezo.AU application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\ScanTackBHO.dll.vir    a variant of Win32/BrowseFox.F potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\ScanTackUninstall.exe.vir    Win32/BrowseFox.C potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\updateScanTack.exe.vir    a variant of Win32/BrowseFox.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\ScanTack.BrowserAdapter.exe.vir    a variant of Win32/BrowseFox.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\ScanTack.PurBrowse64.exe.vir    a variant of Win64/BrowseFox.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\ScanTackBAApp.dll.vir    a variant of Win32/BrowseFox.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\utilScanTack.exe.vir    a variant of Win32/BrowseFox.H potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}.dll.vir    a variant of Win32/BrowseFox.K potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\plugins\ScanTack.Bromon.dll.vir    a variant of MSIL/BrowseFox.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\plugins\ScanTack.BroStats.dll.vir    a variant of MSIL/BrowseFox.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\plugins\ScanTack.BrowserAdapterS.dll.vir    probably a variant of MSIL/BrowseFox.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\plugins\ScanTack.CompatibilityChecker.dll.vir    a variant of MSIL/BrowseFox.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\plugins\ScanTack.FFUpdate.dll.vir    a variant of MSIL/BrowseFox.E potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\plugins\ScanTack.IEUpdate.dll.vir    a variant of MSIL/BrowseFox.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\plugins\ScanTack.PurBrowseG.dll.vir    a variant of MSIL/BrowseFox.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\uTorrentControl_v2\ldrtbuTor.dll.vir    a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll.vir    Win32/Toolbar.Conduit.O potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\uTorrentControl_v2\tbuTor.dll.vir    a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\uTorrentControl_v2\uTorrentControl_v2ToolbarHelper.exe.vir    Win32/Toolbar.Conduit.Q potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll.vir    Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\Local\Conduit\BackgroundContainer\TBUpdaterLogic_1.0.0.1.dll.vir    Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\Local\Conduit\BackgroundContainer\TBUpdaterLogic_1.0.0.2.dll.vir    Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\Local\Conduit\CT3220468\uTorrentControl_v2AutoUpdateHelper.exe.vir    a variant of Win32/Conduit.SearchProtect.N potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\Local\fst_en_105\Download\majfstusau.exe.vir    multiple threats
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\hk64tbuTo0.dll.vir    Win64/Toolbar.Conduit.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\hk64tbuTo2.dll.vir    Win64/Toolbar.Conduit.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\hktbuTo0.dll.vir    Win32/Toolbar.Conduit.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\hktbuTo2.dll.vir    Win32/Toolbar.Conduit.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\ldrtbuTo0.dll.vir    a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\ldrtbuTo2.dll.vir    a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\ldrtbuTor.dll.vir    a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\tbuTo0.dll.vir    a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\tbuTo1.dll.vir    Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\tbuTo2.dll.vir    a variant of Win32/Toolbar.Conduit.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\tbuTo3.dll.vir    a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\tbuTor.dll.vir    a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\RAC\AppData\LocalLow\uTorrentControl_v2\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGongIE.dll.vir    a variant of Win32/PriceGong.A potentially unwanted application
 

Hi electriccrayon,

[external image: bullseye_zpse9eaf36e.gif] Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • Adobe Flash Player 13.0.0.214
  • Adobe Reader 10.1.9
=========================

[external image: bullseye_zpse9eaf36e.gif] Adobe Flash Player:

Go to http://get.adobe.com/flashplayer/?no_ab=1
  • Remove the check mark from the box "Install Google Drive"
  • Click the Download button, and follow the onscreen directions to complete the installation.
Please note, depending on your settings, you may have to temporarily disable your antivirus software for the Adobe Reader update.

=========================

[external image: bullseye_zpse9eaf36e.gif] Adobe Reader:

Go to http://get.adobe.com/reader/otherversions/
  • Use the drop down menu's to select your operating system
  • Select your language > Select The current version of Adobe Reader for your language
  • Remove the check mark from the box "Free! McAfee Security Scan Plus"
  • Click the Download button, and follow the onscreen directions to complete the installation.
Please note, depending on your settings, you may have to temporarily disable your antivirus software for the Adobe Reader update.

=========================

[external image: bullseye_zpse9eaf36e.gif] Update Firefox
  • In the upper left corner of your monitor screen you will see an orange Firefox button [external image: Firefox-2_zpsa7259ec1.png]
  • Click the dropdown menu, slide your mouse cursor over to the Help sub menu.
  • Wait for the Help menu to expand, then click on About Firefox
  • A small window will open similar to the one below.
[external image: Firefox-3_zpsc32408ba.png]
  • Click on the Update button as shown in the image above.
  • Allow Mozilla Firefox to update, reboot if instructed to do so.
=========================

In your next post please provide the following:
  • How is the computer running?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI