This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

infected I think

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I haven't seen a computer this infected in a long time.


Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

**

Google is under attack of sorts and we will need to uninstall.

Make sure you export your passwords and bookmarks first so you still know how to login to sites.

Instructions on how to backup your Favourites/Bookmarks and other data can be found below.
[external image: U5NwUGc.png]Backup Chrome Bookmarks

Please download and install Revo Uninstaller 1.95.
Then please run Revo Uninstaller and select Google Chrome
Please click Uninstall icon to uninstall the selected program.
Please choose Advanced.
Then click Next and follow the prompts.
Please click Select All and Delete to delete all registry items, folders and files listed by Revo.
If asked to restart the computer, please do so.


To download Google Chrome again use the link below after running the script I create.
https://support.google.com/chrome/answer/95346?hl=en

**
Also, using Revo Uninstaller, delete the following if found

337 GAMES
AdBlocker Manger
BBQLeads
Consumer Input
ConvertAd
NewSaveer
Remote Desktop Access (VuuPC)
Search Protect
Team Liquid Streams
WinCheck
Word Proser


VuuPC\Connectivity.exe. Win32/VuuPc.C potentially unwanted application
Please delete the above too.

***
Running from C:\Users\[removed]\Desktop\4m phone

The below FRST script will need to be saved to the same directory to run correctly.

Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CloseProcesses:
C:\Users\Dell User\AppData\Local\Temp\is-ETN9N.tmp\PreCheck.exe
C:\ProgramData\Optimizer\program\newver_93_1.7.3.0.exe
C:\Program Files\WinZipper\winzipersvc.exe
HKLM\…\Run: [WinCheck] => C:\Users\Dell User\AppData\Local\wincheck\wincheck.exe [527872 2014-12-07] ()
C:\Users\Dell User\AppData\Local\wincheck\wincheck.exe
HKLM\…\RunOnce: [SafetySearch-repairJob] => wscript.exe "C:\Users\Dell User\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob"
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
C:\Users\Dell User\AppData\Local\SafetySearch
HKU\S-1-5-21-21511121-2051934517-72339275-1000\…\Run: [BBQLeadsApplication] => C:\Program Files\bbqleads\BBQLeadsApplication.exe [378880 2014-11-27]
C:\Program Files\bbqleads\BBQLeadsApplication.exe
AppInit_DLLs: c:\progra~1\suppor~1\suppor~1.dll => c:\progra~1\suppor~1\suppor~1.dll File Not Found
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-21511121-2051934517-72339275-1000] => http=127.0.0.1:8800;https=127.0.0.1:8800
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.v9.com/web/?type=ds&ts=1417981126&from=air&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T&i=psd&t=34d2ebfbc&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istart123.com/?type=hp&ts=1423443943&from=wpm0202&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.v9.com/web/?type=ds&ts=1417981126&from=air&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T&i=psd&t=34d2ebfbc&q={searchTerms}
HKU\S-1-5-21-21511121-2051934517-72339275-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istart123.com/web/?type=ds&ts=1423443943&from=wpm0202&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T&q={searchTerms}
HKU\S-1-5-21-21511121-2051934517-72339275-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istart123.com/?type=hp&ts=1423443943&from=wpm0202&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T
HKU\S-1-5-21-21511121-2051934517-72339275-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istart123.com/web/?type=ds&ts=1423443943&from=wpm0202&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?type=ds&ts=1417981126&from=air&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T&i=psd&t=34d2ebfbc&q={searchTerms}
SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?type=ds&ts=1417981126&from=air&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T&i=psd&t=34d2ebfbc&q={searchTerms}
SearchScopes: HKU\S-1-5-21-21511121-2051934517-72339275-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3323128&octid=EB_ORIGINAL_CTID&ISID=MF25E00D0-9D30-456B-8729-49C3CAD6C96E&SearchSource=58&CUI=&UM=6&UP=SPA1387C18-2FA0-4EF8-81D7-8539BAED3A7D&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-21511121-2051934517-72339275-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3323128&octid=EB_ORIGINAL_CTID&ISID=MF25E00D0-9D30-456B-8729-49C3CAD6C96E&SearchSource=58&CUI=&UM=6&UP=SPA1387C18-2FA0-4EF8-81D7-8539BAED3A7D&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-21511121-2051934517-72339275-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1423443943&from=wpm0202&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T&q={searchTerms}
BHO: FunDeaulsu -> {18d06f94-1198-4e55-82ed-958b1dff3e1a} -> C:\Program Files\FunDeaulsu\ykGJrpFKGrdCxU.dll No File
BHO: SafetySearch BHO -> {1EDE0D83-B129-4ABC-923B-725D5B0C0DAC} -> C:\Program Files\SafetySearch\FrameworkBHO.dll ()
BHO: EExstraSavings -> {242a66e4-b553-4f91-95fd-4e60c05e9025} -> C:\Program Files\EExstraSavings\hIoyAq21HNePAh.dll No File
BHO: NewSaaveurr -> {4d0a350f-fbce-4b22-b312-d992c75a2b7f} -> C:\Program Files\NewSaaveurr\0X6XqeAeZHjcyV.dll No File
BHO: Fun2SaaVe -> {6417ae8c-ce68-4b40-9b78-f09d4ed7b980} -> C:\Program Files\Fun2SaaVe\AUq4laIscPBXgf.dll No File
BHO: DiGiCoupoN -> {795aadc1-a9b8-4336-8535-2f886ef682f2} -> C:\Program Files\DiGiCoupoN\7RrWcOM0kZN9CF.dll No File
Hosts: 54.235.90.58 fjnoekdlmmjagmmlchagfonjgbioomoo
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istart123.com/?type=sc&ts=1423443943&from=wpm0202&uid=TOSHIBAXMK6026GAX_X5CJ0523TXXX5CJ0523T
CHR dev: Chrome dev build detected! <======= ATTENTION
R2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [425648 2015-01-27] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION
2015-02-11 11:12 - 2015-02-12 10:58 - 00000000 ____D () C:\Users\Dell User\AppData\Local\avaxvyyvyf
2015-02-09 03:07 - 2015-02-11 17:44 - 00000000 ____D () C:\Program Files\SaveLoits
2015-02-09 03:07 - 2015-02-09 05:24 - 00000000 ____D () C:\Program Files\ShhoupDroup
2015-02-04 21:02 - 2015-02-11 17:48 - 00000000 ____D () C:\Users\Dell User\AppData\Local\avaxvavya
2015-02-11 17:47 - 2014-12-07 13:36 - 00000000 ____D () C:\ProgramData\PriceLess
2015-02-11 12:31 - 2014-12-07 14:03 - 00000000 ____D () C:\Program Files\ShopSave Toolbar
2015-02-11 11:12 - 2014-12-07 12:05 - 00000000 ____D () C:\Program Files\SearchProtect
2015-02-08 19:17 - 2014-12-07 13:37 - 00000000 ____D () C:\ProgramData\bbqleads
2015-02-08 18:56 - 2014-12-07 14:06 - 00000000 ____D () C:\ProgramData\Optimizer
2015-02-08 18:56 - 2014-12-07 13:37 - 00000000 ____D () C:\Program Files\bbqleads
2015-02-08 18:56 - 2014-12-07 12:40 - 00000000 ____D () C:\ProgramData\CfwKfVvuEQ
337 GAMES (HKU\S-1-5-21-21511121-2051934517-72339275-1000\…\337Games) (Version: 1.1.1.0 - ) <==== ATTENTION
AdBlocker Manger (HKLM\…\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - AdBlocker Manger) <==== ATTENTION
BBQLeads (HKLM\…\bbqleads) (Version: 2.1.0.0 - BBQLeads) <==== ATTENTION!
Consumer Input (remove only) (HKLM\…\Consumer Input Installer) (Version: - Compete Inc.) <==== ATTENTION
ConvertAd (HKLM\…\ConvertAd) (Version: 1.0.0.0 - ConvertAd) <==== ATTENTION!
NewSaveer (HKLM\…\{6A08B379-76FB-B4CF-0C70-CAFCD3635A77}) (Version: - "") <==== ATTENTION
Remote Desktop Access (VuuPC) (HKLM\…\VOPackage) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
Search Protect (HKLM\…\SearchProtect) (Version: 2.20.11.17 - Client Connect LTD) <==== ATTENTION
Supporter 1.80 (HKLM\…\{5F189DF5-2D05-472B-9091-84D9848AE48B}{40030ae4}) (Version: - PriceLess) <==== ATTENTION
Team Liquid Streams (HKLM\…\{F6A71DC7-28F4-C6C7-8FA9-8A56C80FC96A}) (Version: - "") <==== ATTENTION
WinCheck (HKLM\…\wincheck) (Version: 1.0.0.0 - WinCheck) <==== ATTENTION!
WinZipper (HKLM\…\WinZipper) (Version: 1.5.86 - Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION
Word Proser 1.10.0.1 (HKLM\…\WordProser_1.10.0.1) (Version: 1.10.0.1 - Word Proser) <==== ATTENTION
Task: {366D260C-7A69-4C57-BDD3-22C100263C2C} - System32\Tasks\bench-sys => C:\Program Files\Bench\Updater\updater.exe [2014-10-14] () <==== ATTENTION
Task: {6CFD3D71-DF5E-4D0C-B7EE-9BC4D62E81A8} - System32\Tasks\CIMT_daily_S-1-5-21-21511121-2051934517-72339275-1000 => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe [2015-01-19] () <==== ATTENTION
Task: {6D70869B-22CB-494E-A496-1C684C6FF5B3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: {76265A30-7802-42EB-BC2E-EAFC299A9A6E} - System32\Tasks\ConsumerInputUpdateTaskMachineUA => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [2014-12-07] (ConsumerInput) <==== ATTENTION
Task: {7D796867-C2E5-43C0-BB19-07DD90ADF2AC} - System32\Tasks\APSnotifierPP3 => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {AFCC833A-6462-4CCF-A8D8-30B36EFF244E} - System32\Tasks\APSnotifierPP1 => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {D027CF24-2860-4B5D-8FD2-A07E121D280F} - System32\Tasks\avaxvyyvyf => C:\Users\Dell User\AppData\Local\avaxvyyvyf\avaxvyyvyf.exe [2015-02-02] ()
Task: {D559F1B0-66ED-47C0-8F27-6A0CCE84B6E2} - System32\Tasks\CIMT_S-1-5-21-21511121-2051934517-72339275-1000 => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe [2015-01-19] () <==== ATTENTION
Task: {EBAD5170-6496-4511-B79B-81B8EAB8FD14} - System32\Tasks\ConsumerInputUpdateTaskMachineCore => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [2014-12-07] (ConsumerInput) <==== ATTENTION
Task: {F51FF107-0370-435B-98B5-2B431C352CC0} - System32\Tasks\APSnotifierPP2 => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-S-1-5-21-21511121-2051934517-72339275-1000.job => C:\Program Files\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-sys.job => C:\Program Files\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_daily_S-1-5-21-21511121-2051934517-72339275-1000.job => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_S-1-5-21-21511121-2051934517-72339275-1000.job => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
EmptyTemp:
Hosts:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~`

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click Scan.
  • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
  • Follow the prompts and allow your computer to reboot.
  • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
– File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


[external image: thisisujrt.gif]
Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
~~~
please post
Fixlog.txt
C:\AdwCleaner.txt
JRT.txt
I'm not sure what I did bit it seems a little better….let's me online can I send you the frst again?? And let me know if it's gone??

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI