taplika
1 min read
Instructions on how to backup your Favourites/Bookmarks and other data can be found below.
- [external image: xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png]Backup Internet Explorer Favourites
- [external image: xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg]Backup Firefox Bookmarks
- [external image: U5NwUGc.png]Backup Chrome Bookmarks
- You will need to uninstall/delete the below items Google Chrome included.
Bundled software uninstaller
Freecorder
Google Chrome
Search Protect
Please download and install Revo Uninstaller Free- Double click Revo Uninstaller to run it.
- From the list of programs double click on Bundled software uninstaller
- When prompted if you want to uninstall click Yes.
- Be sure the Moderate option is selected then click Next.
- The program will run, If prompted again click Yes
- when the built-in uninstaller is finished click on Next.
- Once the program has searched for leftovers click Next.
- Check/tick the bolded items only on the list then click Delete
- when prompted click on Yes and then on next.
- put a check on any folders that are found and select delete
- when prompted select yes then on next
- Once done click Finish.
Now please allow Revo Uninstaller to delete these next
Freecorder
Google Chrome
Search Protect
You may download Google Chrome again from here
http://www.google.com/chrome/
Proceed with the reset once done.- [external image: xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png]Internet Explorer: How to reset Internet Explorer settings
- [external image: xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg]Firefox: Reset Firefox
~~~~~
It's best we move Farbar's to desktop.
Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.
Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)
[external image: FRSTfix.JPG]start
CloseProcesses:
HKLM-x32\…\Run: [ShopAtHomeWatcher] => C:\Users\Brown\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe
HKLM-x32\…\Run: [ShopAtHomeUpdater] => C:\Users\Brown\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeUpdater.exe
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [245008 2015-01-05] (Client Connect LTD)
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [215312 2015-01-05] (Client Connect LTD)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-768166425-3198317094-3698988174-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10042&barid={2C3F9D84-AD65-11E2-A837-001F16C25050}
SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://start.sweetpacks.com/?src=6&q={searchTerms}&st=12&crg=3.5000006.10042&barid={2C3F9D84-AD65-11E2-A837-001F16C25050}
SearchScopes: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3311767&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP7AA232D7-C519-4AC8-8849-DCF6BC01C6D6&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3311767&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP7AA232D7-C519-4AC8-8849-DCF6BC01C6D6&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> {2904AF59-AE9B-4F66-85B0-39007F12160D} URL = http://search.conduit.com/Results.aspx?ctid=CT3311767&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP7AA232D7-C519-4AC8-8849-DCF6BC01C6D6&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> {5A6D5E5B-BB2D-41A4-A0E7-239C8C87430B} URL = http://isearch.shopathome.com?user_id={20FEDC2F-5220-447D-8C5B-54CFA180EDB9}&q={searchTerms}
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: DownloadTerms -> {2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3} -> C:\Users\Brown\AppData\Local\DownloadTerms\temp.dat No File
BHO-x32: No Name -> {5F815AD7-A955-4943-91C4-7A96C2932399} -> No File
BHO-x32: Funmoods Helper Object -> {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} -> C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll No File
Toolbar: HKLM-x32 - Funmoods Toolbar - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll No File
Toolbar: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> No Name - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No File
Toolbar: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
Toolbar: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
Toolbar: HKU\S-1-5-21-768166425-3198317094-3698988174-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
FF HKLM\…\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox
FF HKLM-x32\…\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox
CHR HomePage: Default -> hxxp://Taplika.com/?f=1&a=tpl_tight2_15_05&cd=2XzuyEtN2Y1L1QzutD0CyCtDyByCtAyEtDyByD0E0EtA0AtCtN0D0Tzu0StCtCtBtBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyEtAtDtD0DzztCtGzzyB0EyDtGyCtC0DtBtGtDyD0C0AtGtAyC0Bzy0D0DyByBtC0FtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzztByE0FyD0DyDtGtAyB0AtDtGyE0B0ByBtGzyyEzy0CtGzzyDtA0B0FtBtAtA0E0D0BtA2Q&cr=663910008&ir=
CHR StartupUrls: Default -> "hxxp://Taplika.com/?f=7&a=tpl_tight2_15_05&cd=2XzuyEtN2Y1L1QzutD0CyCtDyByCtAyEtDyByD0E0EtA0AtCtN0D0Tzu0StCtCtBtBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyEtAtDtD0DzztCtGzzyB0EyDtGyCtC0DtBtGtDyD0C0AtGtAyC0Bzy0D0DyByBtC0FtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzztByE0FyD0DyDtGtAyB0AtDtGyE0B0ByBtGzyyEzy0CtGzzyDtA0B0FtBtAtA0E0D0BtA2Q&cr=663910008&ir=", "hxxp://xfinity.comcast.net/?cid=insDate04192013", "hxxp://search.conduit.com/?ctid=CT3295465&SearchSource=48&CUI=UN27162955361373228&UM=2", "hxxp://www1.delta-search.com/?affID=119351&tt=gc_&babsrc=HP_ss&mntrId=80AF0C607634075E", "hxxp://search.conduit.com/?ctid=CT3311767&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP7AA232D7-C519-4AC8-8849-DCF6BC01C6D6&SSPV=", "hxxp://www.bing.com/?pc=U217", "hxxp://g.msn.com/1ewenusDefaultPack/U217_DefaultPack_DHP2", "hxxp://www.msn.com/?pc=U146&ocid=U146DHP"
CHR DefaultSearchKeyword: Default -> taplika.com
CHR DefaultSearchURL: Default -> http://Taplika.com/results.php?f=4&q={searchTerms}&a=tpl_tight2_15_05&cd=2XzuyEtN2Y1L1QzutD0CyCtDyByCtAyEtDyByD0E0EtA0AtCtN0D0Tzu0StCtCtBtBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyEtAtDtD0DzztCtGzzyB0EyDtGyCtC0DtBtGtDyD0C0AtGtAyC0Bzy0D0DyByBtC0FtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BzztByE0FyD0DyDtGtAyB0AtDtGyE0B0ByBtGzyyEzy0CtGzzyDtA0B0FtBtAtA0E0D0BtA2Q&cr=663910008&ir=
CHR Extension: (SweetPacks Chrome Extension) - C:\Users\Brown\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2013-06-22]
2015-02-03 03:49 - 2015-02-03 19:20 - 00000000 ____D () C:\Users\Brown\AppData\Local\avaxvavya
2015-01-27 03:01 - 2015-01-28 04:44 - 00000000 ____D () C:\Users\Brown\AppData\Roaming\WSE_Taplika
2015-01-27 03:00 - 2015-01-28 05:17 - 00000000 ____D () C:\Program Files (x86)\WSE_Taplika
2015-02-06 02:20 - 2013-06-05 05:11 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2012-07-30 12:05 - 2012-07-30 12:04 - 0384844 _____ () C:\Users\Brown\AppData\Local\funmoods-speeddial.crx
2012-07-30 12:05 - 2012-07-30 12:04 - 0031465 _____ () C:\Users\Brown\AppData\Local\funmoods.crx
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-768166425-3198317094-3698988174-1000\$190345a210c51ff06c03913230c7653a
C:\ProgramData\uninstaller.exe
C:\Users\Brown\AppData\Local\Temp\hp_eject.exe
C:\Users\Brown\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Brown\AppData\Local\Temp\SPSetup.exe
C:\Users\Charles\AppData\Local\Temp\cltmng.exe
C:\Users\Charles\AppData\Local\Temp\contentDATs.exe
C:\Users\Charles\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Charles\AppData\Local\Temp\msvcp100.dll
C:\Users\Charles\AppData\Local\Temp\msvcr100.dll
C:\Users\Charles\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Charles\AppData\Local\Temp\SecondStepInstaller.exe
C:\Users\Charles\AppData\Local\Temp\SPSetup.exe
C:\Users\Charles\AppData\Local\Temp\wlsetup-cvr.exe
Bundled software uninstaller (HKLM-x32\…\bi_uninstaller) (Version: - ) <==== ATTENTION
Freecorder 8 Applications (8.0.0.87) (HKLM-x32\…\Freecorder 8 Applications) (Version: 8.0.0.87 - Applian Technologies) <==== ATTENTION
Freecorder extension (HKLM-x32\…\Freecorder extension) (Version: 7.0.0.13 - Applian Technologies Inc.) <==== ATTENTION
Freecorder extension x64 (HKLM-x32\…\Freecorder extension x64) (Version: 7.0.0.13 - Applian Technologies Inc.) <==== ATTENTION
Search Protect (HKLM-x32\…\SearchProtect) (Version: 2.19.30.69 - Client Connect LTD) <==== ATTENTION
Task: {A084FF16-1072-434E-B497-F9B43C1080E7} - System32\Tasks\{3D7CC2FE-1F86-4894-93AC-55AD3C43DFAA} => pcalua.exe -a "C:\Users\Brown\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W1XLZDUT\FreecorderSetup[1].exe" -d C:\Users\Brown\Desktop
Task: {A87C06DB-7823-4F0C-8ECB-4EB7864AD20C} - System32\Tasks\Test TimeTrigger => C:\Users\Brown\AppData\Local\Temp\Runner.exe <==== ATTENTION
Task: {AC699059-2EBB-4CF3-B957-985D7CA6D760} - System32\Tasks\{102008AB-2414-4BCE-A8F3-B98DC801C303} => pcalua.exe -a "C:\Users\Brown\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N3M9YF9R\tts50c[1].exe" -d C:\Users\Brown\Desktop
AlternateDataStreams: C:\Windows:nlsPreferences
EmptyTemp:
Hosts:
End
Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
~~~~~~~~~~~~~
[external image: BY4dvz9.png]AdwCleaner- Please download AdwCleaner and save the file to your Desktop.
- Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Follow the prompts.
- Click Scan.
- Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
- Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
- Follow the prompts and allow your computer to reboot.
- After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
please post
Fixlog.txt
AdwCleaner.txt
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI