New
#201
Open notepad. Inside notepad Paste the text below
start
HKCU\...\Run: [ConduitFloatingPlugin_kdohfoobcodjjkpmogkjifipaocmihom] - C:\Program Files (x86)\Conduit\CT3298584\plugins\TBVerifier.dll [287008 1623-04-06] (Conduit Ltd.)
HKCU\...\Run: [ConduitFloatingPlugin_gpaiibklhaneknloaoccoidbaffjjlnb] - C:\Program Files (x86)\Conduit\CT3286042\plugins\TBVerifier.dll [287008 1623-04-06] (Conduit Ltd.)
BHO-x32: Wajam - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll No File
BHO-x32: Define - {B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} - C:\Users\Mike\AppData\Local\DefineExt\temp.dat No File
S2 WajamUpdater; "C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe" [x]
2013-08-15 20:48 - 2013-08-15 20:48 - 00000000 ____D C:\Users\Mike\AppData\Local\{FC9C10B8-5985-439B-A6F8-E8D3BFA86A0C}
2013-08-15 19:59 - 2013-08-15 21:34 - 00000000 ____D C:\Program Files (x86)\OtShot
2013-08-15 19:51 - 2013-08-15 20:11 - 00000000 ____D C:\Users\Mike\AppData\Local\Conduit
2013-08-15 19:51 - 2013-08-15 20:11 - 00000000 ____D C:\Users\Mike\AppData\Local\Conduit
2013-08-15 19:50 - 2013-08-15 19:59 - 00000000 ____D C:\Users\Mike\AppData\Local\CRE
2013-08-15 19:50 - 2013-08-15 19:59 - 00000000 ____D C:\Program Files (x86)\Conduit
2013-08-15 19:50 - 2013-08-15 19:50 - 00000000 ____D C:\Users\Mike\AppData\Roaming\SearchProtect
2013-08-15 19:38 - 2013-08-15 22:38 - 00000294 _____ C:\Windows\Tasks\Dealply.job
2013-08-15 19:38 - 2013-08-15 20:43 - 00000000 ____D C:\Program Files (x86)\DealPlyLive
2013-08-15 19:38 - 2013-08-15 20:10 - 00000866 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-15 19:38 - 2013-08-15 19:38 - 00003230 _____ C:\Windows\System32\Tasks\Dealply
2013-08-15 19:38 - 2013-08-15 19:38 - 00000000 ____D C:\Users\Mike\AppData\Roaming\Dealply
2013-08-15 19:38 - 2013-08-15 19:38 - 00000000 ____D C:\Users\Mike\AppData\Local\DealPlyLive
2013-08-15 19:38 - 2013-08-15 19:38 - 00000000 ____D C:\ProgramData\DealPlyLive
2013-08-15 19:37 - 2013-08-15 20:07 - 00000000 ____D C:\Users\Mike\AppData\Local\WebPlayer
2013-08-15 19:36 - 2013-08-15 20:00 - 00000009 _____ C:\END
2013-08-14 16:29 - 2013-08-14 19:16 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield
2013-08-14 16:29 - 2013-08-14 16:59 - 00000000 ____D C:\ProgramData\Hotspot Shield
2013-08-14 16:12 - 2013-08-14 16:12 - 00000000 ____D C:\Users\Mike\Documents\rmi
2013-08-11 19:11 - 2013-08-11 18:44 - 00001059 _____ C:\Users\Mike\Documents\win.lnk
2013-08-07 21:52 - 2013-08-15 20:37 - 00000000 ____D C:\Users\Mike\AppData\Local\Unity
2013-08-15 21:18 - 2013-08-15 07:19 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-14 22:51 - 2012-01-18 12:27 - 00000000 ____D C:\Program Files (x86)\PCPitstop
end
Click on File > Save As
File Name : Fixlist.txt
Location: Desktop
Save as type : All Files
Click on the Save button. Close Notepad
Open FRST64.exe click on the FIX button . Upload the Fixlog.txt file
Then run these
AdwCleaner
Click here AdwCleaner
Click on Download Now button
Save to the Desktop
Right-click on AdwCleaner.exe and choose
Click on Clean and confirm the prompt.
Upload the log : The log file is at C:\AdwCleaner[n].txt
Junkware Removal Toolkit
Click here Junkware Removal Tool to download
Drag the JRT.exe from the Downloads folder to your Desktop
Right click JRT.exe and choose
Once done upload the JRT.txt file
Upload these log files
- Fixlog.txt
- AdwCleaner[n].txt
- JRT.txt