This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Legit copy of windows now displays as unverified. [Solved]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

STEP 1
[external image: sSxh9jE.png] Junkware Removal Tool (JRT)

  • Please download Junkware Removal Tool and save the file to your Desktop.
  • Temporarily disable your Anti-Virus software. For instructions, please refer to the following link.
  • Right-click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the program.
  • Follow the prompts and allow the scan to run uninterrupted. 
  • Upon completion, a log (JRT.txt) will open on your Desktop.
  • Re-enable your Anti-Virus software.
  • Copy the contents of JRT.txt and paste in your next reply.
     

STEP 2
[external image: eL8MiAP.png] AdwCleaner

  • Please download AdwCleaner and save the file to your Desktop.
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts. 
  • Click [external image: A49sxPr.png] Scan. 
  • Upon completion, click [external image: 6cyn5v5.png] Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate. 
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png] Clean. 
  • Follow the prompts and allow your computer to reboot. 
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.

– File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[S1].txt.
 
======================================================
STEP 3

[external image: Ky7CZ60.png] Obtain Malwarebytes Anti-Malware (MBAM) Log

  • Open Malwarebytes Anti-Malware (MBAM).
  • Check for any new definitions and run a scan.
  • Click the History tab.
  • Click Application Logs.
  • Click the Type box to sort by log type so that Protection/Scan Log is at the top.
  • Click the first Protection/Scan Log in the list.
  • Click Export followed by Text file (*.txt).
  • Click Desktop in the sidebar on the left.
  • Give the file a name and click Save.
  • Click OK.
  • Attach the file (found on your Desktop) in your next reply. 
  •  

STEP 4

[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • JRT.txt
  • AdwCleaner[C1].txt
  • MBAM

After running these tools, please let me know if you are still experiencing TerraClick in Chrome - and how the system seems to be performing now.

Ok, so heres the logs.

JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on Thu 04/21/2016 at 14:35:38.36
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 29 
 
Successfully deleted: C:\ProgramData\28341ff220e0446c9fff27c4493d622e (Folder) 
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal (File) 
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage (File) 
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal (File) 
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage (File) 
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.lyricsmode.com_0.localstorage-journal (File) 
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.lyricsmode.com_0.localstorage (File) 
Successfully deleted: C:\Users\Owner\Appdata\LocalLow\company (Folder) 
Successfully deleted: C:\Program Files (x86)\startpoint (Folder) 
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PXNBR0O (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CN66PO8X (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JO1VV7RS (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SOXJ67OP (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PXNBR0O (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CN66PO8X (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JO1VV7RS (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SOXJ67OP (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\SysWOW64\RENB9FB.tmp (File) 
Successfully deleted: C:\Windows\SysWOW64\sho2702.tmp (File) 
Successfully deleted: C:\Windows\SysWOW64\shoCF2B.tmp (File) 
Successfully deleted: C:\Windows\SysWOW64\shoEF5D.tmp (File) 
 
 
 
Registry: 1 
 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 04/21/2016 at 14:39:31.82
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
adwcleaner
# AdwCleaner v5.112 - Logfile created 21/04/2016 at 14:46:47
# Updated 17/04/2016 by Xplode
# Database : 2016-04-19.5 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Owner - OWNER-VAIO
# Running from : C:\Users\Owner\Desktop\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
Folder Found : C:\Users\Owner\WebConnect
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\PackageAware
 
***** [ Files ] *****
 
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d16fk4ms6rqz1v.cloudfront.net_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d2m2wsoho8qq12.cloudfront.net_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d2m2wsoho8qq12.cloudfront.net_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.strtpoint.com_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.strtpoint.com_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_serviceama-a.akamaihd.net_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_serviceama-a.akamaihd.net_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_uk.ask.com_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_uk.ask.com_0.localstorage-journal
 
***** [ DLL ] *****
 
 
***** [ Shortcuts ] *****
 
Shortcut Infected : C:\Users\Public\Desktop\Google Chrome.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\Desktop\Internet Explorer (64-bit).lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\I-Learn_ Student Dashboard.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\kamkam94 _ Quizlet.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Found : HKCU\Software\Microsoft\Tinstalls
Key Found : HKCU\Software\SrpnFiles
Key Found : HKLM\SOFTWARE\SrpnFiles
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ac225167-00fc-452d-94c5-bb93600e7d9a}
Key Found : HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\Software\Microsoft\Tinstalls
Key Found : HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\Software\SrpnFiles
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{B2B2E4A1-9B67-41D3-ABD5-5994E6A51961}]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{B7F2BFE1-81D6-4555-9D9F-9904913F8635}]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{879AC841-3BFA-462D-AC63-273580238EBB}]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{52B67663-FEA8-4050-85DB-9452D511695E}]
 
***** [ Web browsers ] *****
 
 
*************************
 
C:\AdwCleaner\AdwCleaner[S1].txt - [6040 bytes] - [21/04/2016 14:46:47]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [6113 bytes] ##########
 
Mbam
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 4/21/2016
Scan Time: 2:57 PM
Logfile: mbamlog.txt
Administrator: Yes
 
Version: 2.2.1.1043
Malware Database: v2016.04.21.06
Rootkit Database: v2016.04.17.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Owner
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 391999
Time Elapsed: 36 min, 55 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 12
PUP.Optional.HijackHosts.Gen, C:\Windows\System32\bhvo\shsu\ygo.dat, Quarantined, [6b0f4f626138360079697ced53b28d73], 
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (107.178.247.130 connect.facebook.net), Replaced,[502a723fb6e342f48236303fa65f5ba5]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (.facebook.net
107.178.255.88 www.go), Replaced,[bebcf3be6b2e1422d7e127487590f60a]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (107.178.248.130 static.doubleclick.net), Removal Failed,[6a10e3ce8316dc5aa811650ad3328a76]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (.facebook.net
107.178.255.88 www.goog), Replaced,[7901862bd2c772c42594afc064a145bb]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (107.178.255.88 www.google-analytics.com), Removal Failed,[d4a6664b4e4b9e9894267ff0a06558a8]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (nalytics.com
107.178.255.88 www.s), Removal Failed,[0278ac055b3edc5abefc6d023fc635cb]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (gle-analytics.com
107.178.255), Removal Failed,[fc7e149d4f4ac472dddd27480df8db25]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (.google-analytics.com
107.178.255.88 w), Replaced,[7703664ba6f3e0560ab02946ec19728e]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (nalytics.com
107.178.255.88 www.statcounte), Replaced,[3f3b159c960347ef5862501f669ff50b]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (tics.com
107.178.255.88 www.statco), Replaced,[bebcfcb5c2d769cd6951313e20e503fd]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (er.com
107.178.255.88 ssl.google-analy), Removal Failed,[aad08c250198072f4e6c393661a4847c]
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
Everything is going good, but I'm still getting spam tabs opening up, not the same one as last time now.  This time its a different service.  I'll edit in the name later.

The domain for the tab was trusted surf.

Adware seems to be the main issue remaining. Let's do the following:
 
——————————————————
 
Please download Shortcut Cleaner from the following location:
 
http://www.bleepingc…ortcut-cleaner/
 
Run the program, which has a filename of sc-cleaner.exe. 
When it is run, it will scan the computer for shortcuts and look for hijacked properties and clean them if they are found. 
It will then create a log on your desktop called sc-cleaner.txt and automatically display it. 
Please copy and paste the log in your reply.
 
——————————————————
 
To reset the Hosts file back to the default, follow these steps:
  1. Open Notepad. To do this, swipe in from the right edge of the screen, tap Search, type Notepad, and then tap the Notepad icon. Or, if you are using a mouse, point to the upper-right corner of the screen, move the mouse pointer down, click Search, type Notepad, and then click Notepad.
  2. Copy the following text, and then paste the text into the file:
    # Copyright © 1993-2006 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # [removed] rhino.acme.com # source server
    # [removed] x.acme.com # x client host
    # localhost name resolution is handle within DNS itself.
    # 127.0.0.1 localhost
    # ::1 localhost
  3. On the File menu, tap or click Save as, type "hosts" in the File name box (as displayed in the following image), and then save the file to the desktop.
    [external image: 2893064.png]
  4. Close Notepad.
  5. Open the %WinDir%\System32\Drivers\Etc folder. by clicking on Start
    1. Type %WinDir%\System32\Drivers\Etc in the Search box, then click OK.
  6. Select the Hosts file, and rename the file as "Hosts.old".
  7. Copy or move the Hosts file that you created in step 3 to the %WinDir%\System32\Drivers\Etc folder. If you are prompted to enter an administrator password, click Continue.
——————————————————

Then, please run AdwCleaner again and when the scan has finished, click on the Clean button, which will cause AdwCleaner to reboot your computer and remove the files and registry entries associated with the various adware that you are removing. On reboot, AdwCleaner will display a log showing the files, folders, and registry entries that were removed.

Please copy and paste the log in your reply.

 

——————————————————

 

Please let me know if you are still experiencing the open tabs, redirects, etc., and how the machine seems to be behaving now. 

Welp, I don't see any issues!  The ad tabs are gone!

 

Here are the logs:

 

sc-cleaner:

Shortcut Cleaner 1.4.0 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2016 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
 http://www.bleepingcomputer.com/download/shortcut-cleaner/
 
Windows Version: Windows 7 Home Premium Service Pack 1
Program started at: 04/21/2016 09:42:53 PM.
 
Scanning for registry hijacks:
 
 * No issues found in the Registry.
 
Searching for Hijacked Shortcuts:
 
Searching C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\
 
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
 
Searching C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
 
Searching C:\Users\Public\Desktop\
 
Searching C:\Users\Owner\Desktop\
 
Searching C:\Users\Public\Desktop\
 
 
0 bad shortcuts found.
 
Program finished at: 04/21/2016 09:43:01 PM
Execution time: 0 hours(s), 0 minute(s), and 8 seconds(s)
 
Adwclean:
# AdwCleaner v5.112 - Logfile created 21/04/2016 at 21:50:11
# Updated 17/04/2016 by Xplode
# Database : 2016-04-19.5 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Owner - OWNER-VAIO
# Running from : C:\Users\Owner\Desktop\AdwCleaner.exe
# Option : Clean
# Support : http://toolslib.net/forum
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\Users\Owner\WebConnect
[-] Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\PackageAware
 
***** [ Files ] *****
 
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d16fk4ms6rqz1v.cloudfront.net_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d2m2wsoho8qq12.cloudfront.net_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d2m2wsoho8qq12.cloudfront.net_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.strtpoint.com_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.strtpoint.com_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_serviceama-a.akamaihd.net_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_serviceama-a.akamaihd.net_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_uk.ask.com_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_uk.ask.com_0.localstorage-journal
 
***** [ DLLs ] *****
 
 
***** [ Shortcuts ] *****
 
[-] Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
[-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[-] Shortcut Disinfected : C:\Users\Owner\Desktop\Internet Explorer (64-bit).lnk
[-] Shortcut Disinfected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[-] Shortcut Disinfected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\I-Learn_ Student Dashboard.lnk
[-] Shortcut Disinfected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\kamkam94 _ Quizlet.lnk
[-] Shortcut Disinfected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
[-] Shortcut Disinfected : C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[-] Shortcut Disinfected : C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Shortcut Disinfected : C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
[-] Key Deleted : HKCU\Software\Microsoft\Tinstalls
[-] Key Deleted : HKCU\Software\SrpnFiles
[-] Key Deleted : HKLM\SOFTWARE\SrpnFiles
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ac225167-00fc-452d-94c5-bb93600e7d9a}
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{B2B2E4A1-9B67-41D3-ABD5-5994E6A51961}]
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{B7F2BFE1-81D6-4555-9D9F-9904913F8635}]
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{879AC841-3BFA-462D-AC63-273580238EBB}]
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{52B67663-FEA8-4050-85DB-9452D511695E}]
 
***** [ Web browsers ] *****
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C1].txt - [5141 bytes] - [21/04/2016 21:50:11]
C:\AdwCleaner\AdwCleaner[S1].txt - [6196 bytes] - [21/04/2016 14:46:47]
C:\AdwCleaner\AdwCleaner[S2].txt - [6269 bytes] - [21/04/2016 21:48:30]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [5360 bytes] ##########
 
Thank you so much for working with me!  You are amazing and I can't thank you enough.  Thank you again!

You deserve a cookie!

Thank you for the kind words, but we aren't quite done yet. I'm very glad things are looking good at the moment. Let's take a moment to get a couple more scans to be sure the tools we've used so far haven't missed anything. Different tools look in different areas and this is a double check that nothing has sneaked past us  :yeah:

 

[external image: 5aQQfhu.png]  F-Secure Online Scan
  • Please download F-Secure Online Scan and save the file to your Desktop.
  • Temporarily disable your Anti-Virus software. For instructions, please refer to the following link.
  • Right-click F-SecureOnlineScanner-HC.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the program.
  • Click Start.
  • Click Accept.
  • The scan will commence. Please allow the scan to complete. 
  • Upon completion, you will be presented with a number of steps. In Step 3: Clean the files, do not alter any settings.
  • Click Next.
  • Click Full Report.
  • Copy the contents of the log and paste in your next reply.
  • Re-enable your Anti-Virus software.
 
 
 
 
[external image: SJXWuki.png]  BitDefender Quick Scan 
  • Please go to BitDefender Quick Scan and click Scan Now.
  • If your browser interrupts the installation, allow the installation to commence. 
  • Follow any prompts from your browser. 
  • Click I agree.
  • Allow the scan to complete.
     
  • Upon completion, please inform me of the results.
  • Note: If the scan installed a browser extension/add-on, please proceed with the following steps
  • For [external image: U5NwUGc.png]  Chrome Users: In the URL bar, type chrome://extensions and click the [external image: BruhcZq.png]  icon next to BitDefender. 
  • For [external image: Qlf57ne.png]  Firefox Users: In the URL bar, type users about:addons and click the Remove button next to BitDefender.
 

 

 

The F-Secure link is coming back as a 404.  I'm doing the bit defender now.

 

edit: i came back clean.


All Clean!
 
Congratulations, your computer appears clean! :)
I see no signs of malware/adware on your computer. The steps below will remove the tools we have used and reset any settings changed. I've also provided a list of resources and tools you may find useful.
 
DelFix
  • Please download DelFix and save the file to your Desktop.
  • Double-click DelFix.exe to run the program.
  • Place a checkmark next to the following items:
               Remove disinfection tools
  • Create registry backup
  • Purge system restore
  • Reset system settings
  • Click the Run button.
 
– DelFix will remove the specialised tools we used to clean your computer. Any leftover logs, files, folders or tools remaining on your computer which were not removed can be deleted manually (right-click the file + delete). DelFix will also create a new System Restore Point, and delete all but the most recent.
 
— Malwarebytes Anti-Malware will still be present on your computer. I recommend keeping this program, updating and scanning with it once a week to maintain security on your computer. If you do not wish to keep this program installed, you can uninstall it by pressing the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time, typing appwiz.cpl, clicking OK and searching forMalwarebytes.
 
=============================================
 
The following programs are known to have frequent security updates. I recommend you update these now and routinely check them for any new updates. Outdated software contain vulnerabilities that must be patched. Please download and install the latest version of the program(s) below.
  • Adobe AIR
  • Adobe Flash Player (uncheck the "Optional Offer")
  • Adobe Reader (uncheck the "Optional Offer")
  • Adobe Shockwave Player
  • Java (watch out for "Optional Offers" or bundled software)
  • Java SE Development Kit
  • Follow these instructions to check for and download the latest Windows Updates.
 
=============================================
 
Disable Java in Your Browser
Due to frequent exploits involving Java vulnerabilities we recommend you disable Java in your browser.
For information on Java exploits vulnerabilities, please read the following article (point #7).
  • Click the [external image: 29Fou9c.jpg] Windows Start Button  and type Java Control Panel (or javacpl) in the search bar.
  • Press the Windows Key [external image: pdKOQKY.png]+ s on your keyboard at the same time. Type Java Control Panel (or javacpl) in the search bar.
  • Click on the Java Control Panel. Once opened, click the Security tab.
  • Deselect the check box for Enable Java content in the browser. This will disable the Java plug-in in the browser.
  • Click Apply.
  • Click OK in the Java Plug-in confirmation window.
  • Restart your browser(s) for changes to take effect.
  • More information can be found here and here.
 
=============================================
 
Below a list of resources you may find useful. The articles document information on computer security, common attack vectors and how you can stay safe on the Internet.
  • Answers to common security questions - Best Practices by quietman7
  • How Malware Spreads - How did I get infected? by quietman7
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams
  • How to Prevent Malware by miekiemoes
  • Slow Computer/browser? It May Not Be Malware by quietman7
 
The following programs come highly recommended in the security community.
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • Sandboxie isolates programs of your choice, preventing files from being written to your HDD unless approved by you.
  • Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • Unchecky automatically removes checkmarks for bunlded software in program installers; helping you avoid adware and PUPs.
  • Web of Trust WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.
 
Need a second opinion on a file or website? Scan the file/URL before clicking by using one of the following free online scanner services.
  • VirusTotal (File & URL)
  • Jotti's Malware Scan (File)
  • Dr.Web Online Check (URL)
  • Trend Micro Site Safety Center (URL)
  • Norton Safe Web (URL)
 
– Please feel free to ask if you have any questions or concerns on computer security or the programs above.
 
======================================================
 
Please confirm you have no outstanding issues, and feel happy with the state of your computer. Since you've indicated all seems well now, I will close this topic. 
 
Thank you for using What the Tech.
 
Safe Surfing,   :thumbup:
 

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI