This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

taplika

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Instructions on how to backup your Favourites/Bookmarks and other data can be found below.
  • [external image: xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png]Backup Internet Explorer Favourites
  • [external image: xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg]Backup Firefox Bookmarks
  • [external image: U5NwUGc.png]Backup Chrome Bookmarks
  • You will need to uninstall/delete the below items Google Chrome included.

    Bundled software uninstaller
    Freecorder
    Google Chrome
    Search Protect

    Please download and install Revo Uninstaller Free
    • Double click Revo Uninstaller to run it.
    • From the list of programs double click on Bundled software uninstaller
    • When prompted if you want to uninstall click Yes.
    • Be sure the Moderate option is selected then click Next.
    • The program will run, If prompted again click Yes
    • when the built-in uninstaller is finished click on Next.
    • Once the program has searched for leftovers click Next.
    • Check/tick the bolded items only on the list then click Delete
    • when prompted click on Yes and then on next.
    • put a check on any folders that are found and select delete
    • when prompted select yes then on next
    • Once done click Finish.
    ~~~
    Now please allow Revo Uninstaller to delete these next
    Freecorder
    Google Chrome
    Search Protect



    You may download Google Chrome again from here
    http://www.google.com/chrome/


    Proceed with the reset once done.
    • [external image: xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png]Internet Explorer: How to reset Internet Explorer settings
    • [external image: xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg]Firefox: Reset Firefox
    Once done please proceed.

    ~~~~~
    It's best we move Farbar's to desktop.

    Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
    Go to an open spot on your desktop, right click and select PASTE
    You should now have Farbar Recovery Scan Tool on your desktop.

    Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
    Paste this into the open notepad. save it to the Desktop as fixlist.txt
    NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
    It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


    [external image: FRSTfix.JPG]


    start
    CloseProcesses:
    HKLM-x32\…\Run: [ShopAtHomeWatcher] => C:\Users\Brown\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe
    HKLM-x32\…\Run: [ShopAtHomeUpdater] => C:\Users\Brown\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeUpdater.exe
    AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [245008 2015-01-05] (Client Connect LTD)
    AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [215312 2015-01-05] (Client Connect LTD)
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    CHR HKU\S-1-5-21-768166425-3198317094-3698988174-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10042&barid={2C3F9D84-AD65-11E2-A837-001F16C25050}
    SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
    SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://start.sweetpacks.com/?src=6&q={searchTerms}&st=12&crg=3.5000006.10042&barid={2C3F9D84-AD65-11E2-A837-001F16C25050}
    SearchScopes: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3311767&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP7AA232D7-C519-4AC8-8849-DCF6BC01C6D6&q={searchTerms}&SSPV=
    SearchScopes: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3311767&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP7AA232D7-C519-4AC8-8849-DCF6BC01C6D6&q={searchTerms}&SSPV=
    SearchScopes: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> {2904AF59-AE9B-4F66-85B0-39007F12160D} URL = http://search.conduit.com/Results.aspx?ctid=CT3311767&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP7AA232D7-C519-4AC8-8849-DCF6BC01C6D6&q={searchTerms}&SSPV=
    SearchScopes: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> {5A6D5E5B-BB2D-41A4-A0E7-239C8C87430B} URL = http://isearch.shopathome.com?user_id={20FEDC2F-5220-447D-8C5B-54CFA180EDB9}&q={searchTerms}
    BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
    BHO-x32: DownloadTerms -> {2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3} -> C:\Users\Brown\AppData\Local\DownloadTerms\temp.dat No File
    BHO-x32: No Name -> {5F815AD7-A955-4943-91C4-7A96C2932399} -> No File
    BHO-x32: Funmoods Helper Object -> {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} -> C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll No File
    Toolbar: HKLM-x32 - Funmoods Toolbar - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll No File
    Toolbar: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> No Name - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No File
    Toolbar: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
    Toolbar: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
    Toolbar: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    FF HKLM\…\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox
    FF HKLM-x32\…\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox
    CHR HomePage: Default -> hxxp://Taplika.com/?f=1&a=tpl_tight2_15_05&cd=2XzuyEtN2Y1L1QzutD0CyCtDyByCtAyEtDyByD0E0EtA0AtCtN0D0Tzu0StCtCtBtBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyEtAtDtD0DzztCtGzzyB0EyDtGyCtC0DtBtGtDyD0C0AtGtAyC0Bzy0D0DyByBtC0FtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzztByE0FyD0DyDtGtAyB0AtDtGyE0B0ByBtGzyyEzy0CtGzzyDtA0B0FtBtAtA0E0D0BtA2Q&cr=663910008&ir=
    CHR StartupUrls: Default -> "hxxp://Taplika.com/?f=7&a=tpl_tight2_15_05&cd=2XzuyEtN2Y1L1QzutD0CyCtDyByCtAyEtDyByD0E0EtA0AtCtN0D0Tzu0StCtCtBtBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyEtAtDtD0DzztCtGzzyB0EyDtGyCtC0DtBtGtDyD0C0AtGtAyC0Bzy0D0DyByBtC0FtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzztByE0FyD0DyDtGtAyB0AtDtGyE0B0ByBtGzyyEzy0CtGzzyDtA0B0FtBtAtA0E0D0BtA2Q&cr=663910008&ir=", "hxxp://xfinity.comcast.net/?cid=insDate04192013", "hxxp://search.conduit.com/?ctid=CT3295465&SearchSource=48&CUI=UN27162955361373228&UM=2", "hxxp://www1.delta-search.com/?affID=119351&tt=gc_&babsrc=HP_ss&mntrId=80AF0C607634075E", "hxxp://search.conduit.com/?ctid=CT3311767&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP7AA232D7-C519-4AC8-8849-DCF6BC01C6D6&SSPV=", "hxxp://www.bing.com/?pc=U217", "hxxp://g.msn.com/1ewenusDefaultPack/U217_DefaultPack_DHP2", "hxxp://www.msn.com/?pc=U146&ocid=U146DHP"
    CHR DefaultSearchKeyword: Default -> taplika.com
    CHR DefaultSearchURL: Default -> http://Taplika.com/results.php?f=4&q={searchTerms}&a=tpl_tight2_15_05&cd=2XzuyEtN2Y1L1QzutD0CyCtDyByCtAyEtDyByD0E0EtA0AtCtN0D0Tzu0StCtCtBtBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyEtAtDtD0DzztCtGzzyB0EyDtGyCtC0DtBtGtDyD0C0AtGtAyC0Bzy0D0DyByBtC0FtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzztByE0FyD0DyDtGtAyB0AtDtGyE0B0ByBtGzyyEzy0CtGzzyDtA0B0FtBtAtA0E0D0BtA2Q&cr=663910008&ir=
    CHR Extension: (SweetPacks Chrome Extension) - C:\Users\Brown\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2013-06-22]
    2015-02-03 03:49 - 2015-02-03 19:20 - 00000000 ____D () C:\Users\Brown\AppData\Local\avaxvavya
    2015-01-27 03:01 - 2015-01-28 04:44 - 00000000 ____D () C:\Users\Brown\AppData\Roaming\WSE_Taplika
    2015-01-27 03:00 - 2015-01-28 05:17 - 00000000 ____D () C:\Program Files (x86)\WSE_Taplika
    2015-02-06 02:20 - 2013-06-05 05:11 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
    2012-07-30 12:05 - 2012-07-30 12:04 - 0384844 _____ () C:\Users\Brown\AppData\Local\funmoods-speeddial.crx
    2012-07-30 12:05 - 2012-07-30 12:04 - 0031465 _____ () C:\Users\Brown\AppData\Local\funmoods.crx
    ZeroAccess:
    C:\$Recycle.Bin\S-1-5-21-768166425-3198317094-3698988174-1000\$190345a210c51ff06c03913230c7653a
    C:\ProgramData\uninstaller.exe
    C:\Users\Brown\AppData\Local\Temp\hp_eject.exe
    C:\Users\Brown\AppData\Local\Temp\MSETUP4.EXE
    C:\Users\Brown\AppData\Local\Temp\SPSetup.exe
    C:\Users\Charles\AppData\Local\Temp\cltmng.exe
    C:\Users\Charles\AppData\Local\Temp\contentDATs.exe
    C:\Users\Charles\AppData\Local\Temp\FlashPlayerUpdate.exe
    C:\Users\Charles\AppData\Local\Temp\msvcp100.dll
    C:\Users\Charles\AppData\Local\Temp\msvcr100.dll
    C:\Users\Charles\AppData\Local\Temp\SearchWithGoogleUpdate.exe
    C:\Users\Charles\AppData\Local\Temp\SecondStepInstaller.exe
    C:\Users\Charles\AppData\Local\Temp\SPSetup.exe
    C:\Users\Charles\AppData\Local\Temp\wlsetup-cvr.exe
    Bundled software uninstaller (HKLM-x32\…\bi_uninstaller) (Version: - ) <==== ATTENTION
    Freecorder 8 Applications (8.0.0.87) (HKLM-x32\…\Freecorder 8 Applications) (Version: 8.0.0.87 - Applian Technologies) <==== ATTENTION
    Freecorder extension (HKLM-x32\…\Freecorder extension) (Version: 7.0.0.13 - Applian Technologies Inc.) <==== ATTENTION
    Freecorder extension x64 (HKLM-x32\…\Freecorder extension x64) (Version: 7.0.0.13 - Applian Technologies Inc.) <==== ATTENTION
    Search Protect (HKLM-x32\…\SearchProtect) (Version: 2.19.30.69 - Client Connect LTD) <==== ATTENTION
    Task: {A084FF16-1072-434E-B497-F9B43C1080E7} - System32\Tasks\{3D7CC2FE-1F86-4894-93AC-55AD3C43DFAA} => pcalua.exe -a "C:\Users\Brown\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W1XLZDUT\FreecorderSetup[1].exe" -d C:\Users\Brown\Desktop
    Task: {A87C06DB-7823-4F0C-8ECB-4EB7864AD20C} - System32\Tasks\Test TimeTrigger => C:\Users\Brown\AppData\Local\Temp\Runner.exe <==== ATTENTION
    Task: {AC699059-2EBB-4CF3-B957-985D7CA6D760} - System32\Tasks\{102008AB-2414-4BCE-A8F3-B98DC801C303} => pcalua.exe -a "C:\Users\Brown\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N3M9YF9R\tts50c[1].exe" -d C:\Users\Brown\Desktop
    AlternateDataStreams: C:\Windows:nlsPreferences
    EmptyTemp:
    Hosts:
    End


    Open FRST/FRST64 and press the Fix button just once and wait.
    If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
    When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.



    ~~~~~~~~~~~~~

    [external image: BY4dvz9.png]AdwCleaner
    • Please download AdwCleaner and save the file to your Desktop.
    • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
    • Follow the prompts.
    • Click Scan.
    • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
    • Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
    • Follow the prompts and allow your computer to reboot.
    • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
    – File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.


    please post
    Fixlog.txt
    AdwCleaner.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI