Virus Deletion Now Makes Internet Access Impossible

Page 11 of 20 FirstFirst ... 910111213 ... LastLast

  1. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #101

    JACEE: I downloaded the AdwCleaner.exe file from Bleeping Computer and got the following warning I've never seen before: "This program is not commonly downloaded and could harm your computer." So, I'm hesitant.
    This application was written by a very talented anti-malware/adware/spyware associate. It is fine to run as Golden said.
      My Computer


  2. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #102

    I have found that downloading AdwCleaner.exe works better if I use
    Internet Explorer. (I.E.)
      My Computer


  3. Posts : 2,470
    Windows 7 Home Premium
       #103

    Florida Rene,

    If you will, please use the following diagnostic tool. It has a powerful detection mechanism, and may help us get to the cause of your issues:

    Please use the Farbar Recovery Scan Tool.
    Download: Farbar Recovery Scan Tool Download
    Select the version that applies to your system: 64-bit
    Save it to your Desktop.
    Double-click the downloaded file to run it.

    When the tool opens click Yes to the disclaimer.
    At the program's console, press the Scan button.

    When done, the tool makes a log (FRST.txt) in the same directory from which the tool is run (Desktop).
    >> Please provide the FRST.txt in your reply.

    The first time the tool is run, it also makes another log: Addition.txt
    >> Also post the Addition.txt in your reply.


    Also, once again, use the Farbar Service Scanner


    This time, let's get a view of all services and dependencies scoped by the tool...
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
    • Press: Scan
    • When done, FSS creates a log, FSS.txt, on the Desktop.
    Please provide the FSS.txt in your reply.

    Thank you.
      My Computer


  4. Posts : 110
    Windows 7 64
    Thread Starter
       #104

    Jacee said:
    Hi Florida Rene :)



    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator.
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Copy and paste the contents of that logfile in your next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
    Using AdwCleaner v3: Scan & Clean:
    Double click on AdwCleaner.exe to run the tool again.
    Click on the Scan button.
    AdwCleaner will begin to scan your computer like it did before.
    After the scan has finished...

    This time click on the Clean button.
    Press OK when asked to close all programs and follow the onscreen prompts.
    Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
    Copy and paste the contents of that logfile in your next reply.
    A copy of that logfile will also be saved in the C:\AdwCleaner folder
    Sorry for the delay. Short business trip.

    Thank you, Jacee & Golden. Ran AdwCleaner a short while ago. WOW!

    Here's the report from the first pass:

    # AdwCleaner v3.016 - Report created 23/12/2013 at 15:43:45
    # Updated 23/12/2013 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : Rene - ZIVA
    # Running from : C:\Users\Rene\Desktop\AdwCleaner.exe
    # Option : Scan
    ***** [ Services ] *****

    ***** [ Files / Folders ] *****
    File Found : C:\Program Files (x86)\Mozilla Firefox\Components\AskHPRFF.js
    File Found : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\searchplugins\Mysearchdial.xml
    File Found : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\user.js
    File Found : C:\Windows\System32\AdpeakProxy64.dll
    File Found : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
    Folder Found : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\Extensions\{AD9A41D2-9A49-4FA6-A79E-71A0785364C8}
    Folder Found : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\Extensions\ScorpionSaver@jetpack
    Folder Found C:\Program Files (x86)\Ask.com
    Folder Found C:\Program Files (x86)\Conduit
    Folder Found C:\Program Files (x86)\Mobogenie
    Folder Found C:\Program Files (x86)\RadioRage_4j
    Folder Found C:\Program Files (x86)\WinZipBar
    Folder Found C:\Program Files\Level Quality Watcher
    Folder Found C:\Users\Rene\AppData\Local\Conduit
    Folder Found C:\Users\Rene\AppData\Local\Mobogenie
    Folder Found C:\Users\Rene\AppData\LocalLow\Conduit
    Folder Found C:\Users\Rene\AppData\LocalLow\WinZipBar
    Folder Found C:\Users\Rene\AppData\Roaming\DefaultTab
    Folder Found C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}
    ***** [ Shortcuts ] *****

    ***** [ Registry ] *****
    Key Found : HKCU\Software\Adpeak, Inc.
    Key Found : HKCU\Software\APN PIP
    Key Found : HKCU\Software\AppDataLow\AskBarDis
    Key Found : HKCU\Software\AppDataLow\AskToolbarInfo
    Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
    Key Found : HKCU\Software\AppDataLow\Software\Conduit
    Key Found : HKCU\Software\AppDataLow\Software\RadioRage_4j
    Key Found : HKCU\Software\AppDataLow\Software\ScorpionSaver
    Key Found : HKCU\Software\AppDataLow\Software\WinZipBar
    Key Found : HKCU\Software\AppDataLow\Toolbar
    Key Found : HKCU\Software\Ask.com
    Key Found : HKCU\Software\AVG SafeGuard toolbar
    Key Found : HKCU\Software\dsiteproducts
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9638B7D6-11F5-4406-B387-327642A11FFB}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Found : HKCU\Software\YahooPartnerToolbar
    Key Found : [x64] HKCU\Software\Adpeak, Inc.
    Key Found : [x64] HKCU\Software\APN PIP
    Key Found : [x64] HKCU\Software\Ask.com
    Key Found : [x64] HKCU\Software\AVG SafeGuard toolbar
    Key Found : [x64] HKCU\Software\dsiteproducts
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Found : [x64] HKCU\Software\YahooPartnerToolbar
    Key Found : HKLM\Software\AVG Secure Search
    Key Found : HKLM\Software\AVG Security Toolbar
    Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
    Key Found : HKLM\SOFTWARE\Classes\AppID\BHO.DLL
    Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{9280CAA3-237E-468E-A41C-43EADB5FF61A}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{9B7B034B-944A-4261-B487-862F642F7615}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE91F9CE-0900-4E2A-B673-F3F6E4FC54D9}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8}
    Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
    Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
    Key Found : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
    Key Found : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
    Key Found : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{A25AA6E2-1CDE-4D0F-A5D4-4898D7FB3C86}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{A5C9CB1C-1C0A-45A2-81CC-1DD342D0A478}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{A661D4DC-4BD8-48FC-964B-A24AB8157DE6}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
    Key Found : HKLM\SOFTWARE\Classes\PCProxy.DataContainer
    Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3106777
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
    Key Found : HKLM\Software\Conduit
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{44DB423D-A0DB-4664-9477-CCDCEB7CD666}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{53855564-CF81-410C-9C1C-321C7E067816}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{69C10CE3-114B-4DF1-B200-AFAD083224CF}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5C9CB1C-1C0A-45A2-81CC-1DD342D0A478}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A661D4DC-4BD8-48FC-964B-A24AB8157DE6}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5731AB1-8566-4441-AEFB-9AFB2EEA63D9}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF42950A-621F-414D-864E-E7E674F369BB}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askchecker_RASAPI32
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askchecker_RASMANCS
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{434FA5E9-253E-4BD0-ADB6-7CE4CEA114CA}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{581C7D7D-F809-4E03-A631-74C069D5F04A}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{60B34F47-3FDD-46F8-AB6C-AAABEA55C3D6}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{68122F44-3A4A-4EDB-B28F-0C0E07F89BD0}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9280CAA3-237E-468E-A41C-43EADB5FF61A}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9638B7D6-11F5-4406-B387-327642A11FFB}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F706E19B-6C14-4272-BA98-2F16636A898D}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZipBar Toolbar
    Key Found : HKLM\SOFTWARE\MozillaPlugins\@RadioRage_4j.com/Plugin
    Key Found : HKLM\Software\PIP
    Key Found : HKLM\Software\RadioRage_4j
    Key Found : HKLM\Software\WinZipBar
    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A25AA6E2-1CDE-4D0F-A5D4-4898D7FB3C86}
    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A5C9CB1C-1C0A-45A2-81CC-1DD342D0A478}
    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A661D4DC-4BD8-48FC-964B-A24AB8157DE6}
    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
    Key Found : [x64] HKLM\SOFTWARE\Conduit
    Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
    Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
    Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
    Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
    Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Found : [x64] HKLM\SOFTWARE\Scorpion Saver
    Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{78BA36C9-6036-482B-B48D-ECCA6F964B84}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}]
    Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
    Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [4jffxtbr@RadioRage_4j.com]
    ***** [ Browsers ] *****
    -\\ Internet Explorer v11.0.9600.16428
    Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] - hxxp://start.mysearchdial.com/?f=2&a=irmsd1202&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtF tCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1168143589&ir=
    Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtF tCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1168143589&ir=
    -\\ Mozilla Firefox v6.0.2 (en-US)
    [ File : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\prefs.js ]
    Line Found : user_pref("browser.search.defaultenginename", "Mysearchdial");
    Line Found : user_pref("extensions.mysearchdial.aflt", "irmsd1202");
    Line Found : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
    Line Found : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1 CzutCyD1B1P1R");
    Line Found : user_pref("extensions.mysearchdial.cr", "1168143589");
    Line Found : user_pref("extensions.mysearchdial.dfltLng", "");
    Line Found : user_pref("extensions.mysearchdial.dfltSrch", true);
    Line Found : user_pref("extensions.mysearchdial.dnsErr", true);
    Line Found : user_pref("extensions.mysearchdial.excTlbr", false);
    Line Found : user_pref("extensions.mysearchdial.hmpg", true);
    Line Found : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtF tCyEtFtCtAyBzytN1L1CzutC[...]
    Line Found : user_pref("extensions.mysearchdial.id", "6431503B9E223DB9");
    Line Found : user_pref("extensions.mysearchdial.instlDay", "16060");
    Line Found : user_pref("extensions.mysearchdial.instlRef", "");
    Line Found : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=irmsd1202&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtF tCyEtFtCtAyBzytN1L1Czu[...]
    Line Found : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
    Line Found : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
    Line Found : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
    Line Found : user_pref("extensions.mysearchdial.tlbrId", "base");
    Line Found : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=irmsd1202&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtF tCyEtFtCtAyBzytN1L1C[...]
    Line Found : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
    Line Found : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
    Line Found : user_pref("extensions.mysearchdial_i.hmpg", true);
    Line Found : user_pref("extensions.mysearchdial_i.newTab", false);
    Line Found : user_pref("extensions.mysearchdial_i.smplGrp", "none");
    Line Found : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.014:50:35");
    -\\ Google Chrome v31.0.1650.63
    [ File : C:\Users\Rene\AppData\Local\Google\Chrome\User Data\Default\preferences ]
    Found : homepage
    Found : urls_to_restore_on_startup
    *************************
    AdwCleaner[R0].txt - [15485 octets] - [23/12/2013 15:43:45]
    ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [15546 octets] ##########
      My Computer


  5. Posts : 110
    Windows 7 64
    Thread Starter
       #105

    And here's the report from the second pass:

    # AdwCleaner v3.016 - Report created 23/12/2013 at 15:49:35
    # Updated 23/12/2013 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : Rene - ZIVA
    # Running from : C:\Users\Rene\Desktop\AdwCleaner.exe
    # Option : Clean
    ***** [ Services ] *****

    ***** [ Files / Folders ] *****
    Folder Deleted : C:\Program Files (x86)\Ask.com
    Folder Deleted : C:\Program Files (x86)\Conduit
    Folder Deleted : C:\Program Files (x86)\Mobogenie
    Folder Deleted : C:\Program Files (x86)\RadioRage_4j
    Folder Deleted : C:\Program Files (x86)\WinZipBar
    Folder Deleted : C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}
    Folder Deleted : C:\Program Files\Level Quality Watcher
    Folder Deleted : C:\Users\Rene\AppData\Local\Conduit
    Folder Deleted : C:\Users\Rene\AppData\Local\Mobogenie
    Folder Deleted : C:\Users\Rene\AppData\LocalLow\Conduit
    Folder Deleted : C:\Users\Rene\AppData\LocalLow\WinZipBar
    Folder Deleted : C:\Users\Rene\AppData\Roaming\DefaultTab
    Folder Deleted : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\Extensions\{AD9A41D2-9A49-4FA6-A79E-71A0785364C8}
    Folder Deleted : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\Extensions\ScorpionSaver@jetpack
    File Deleted : C:\Windows\System32\AdpeakProxy64.dll
    File Deleted : C:\Program Files (x86)\Mozilla Firefox\Components\AskHPRFF.js
    File Deleted : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\searchplugins\Mysearchdial.xml
    File Deleted : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\user.js
    File Deleted : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
    ***** [ Shortcuts ] *****

    ***** [ Registry ] *****
    Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [4jffxtbr@RadioRage_4j.com]
    Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\BHO.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
    Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
    Key Deleted : HKLM\SOFTWARE\Classes\PCProxy.DataContainer
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askchecker_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askchecker_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
    Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
    Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@RadioRage_4j.com/Plugin
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3106777
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9B7B034B-944A-4261-B487-862F642F7615}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE91F9CE-0900-4E2A-B673-F3F6E4FC54D9}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9280CAA3-237E-468E-A41C-43EADB5FF61A}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A25AA6E2-1CDE-4D0F-A5D4-4898D7FB3C86}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A5C9CB1C-1C0A-45A2-81CC-1DD342D0A478}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A661D4DC-4BD8-48FC-964B-A24AB8157DE6}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9638B7D6-11F5-4406-B387-327642A11FFB}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{434FA5E9-253E-4BD0-ADB6-7CE4CEA114CA}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{581C7D7D-F809-4E03-A631-74C069D5F04A}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{60B34F47-3FDD-46F8-AB6C-AAABEA55C3D6}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{68122F44-3A4A-4EDB-B28F-0C0E07F89BD0}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9638B7D6-11F5-4406-B387-327642A11FFB}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F706E19B-6C14-4272-BA98-2F16636A898D}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9280CAA3-237E-468E-A41C-43EADB5FF61A}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{44DB423D-A0DB-4664-9477-CCDCEB7CD666}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{53855564-CF81-410C-9C1C-321C7E067816}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5C9CB1C-1C0A-45A2-81CC-1DD342D0A478}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A661D4DC-4BD8-48FC-964B-A24AB8157DE6}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5731AB1-8566-4441-AEFB-9AFB2EEA63D9}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF42950A-621F-414D-864E-E7E674F369BB}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{69C10CE3-114B-4DF1-B200-AFAD083224CF}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{78BA36C9-6036-482B-B48D-ECCA6F964B84}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}]
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A25AA6E2-1CDE-4D0F-A5D4-4898D7FB3C86}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A5C9CB1C-1C0A-45A2-81CC-1DD342D0A478}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A661D4DC-4BD8-48FC-964B-A24AB8157DE6}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Deleted : HKCU\Software\Adpeak, Inc.
    Key Deleted : HKCU\Software\APN PIP
    Key Deleted : HKCU\Software\Ask.com
    Key Deleted : HKCU\Software\AVG SafeGuard toolbar
    Key Deleted : HKCU\Software\dsiteproducts
    Key Deleted : HKCU\Software\YahooPartnerToolbar
    Key Deleted : HKCU\Software\AppDataLow\AskBarDis
    Key Deleted : HKCU\Software\AppDataLow\AskToolbarInfo
    Key Deleted : HKCU\Software\AppDataLow\Toolbar
    Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
    Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
    Key Deleted : HKCU\Software\AppDataLow\Software\RadioRage_4j
    Key Deleted : HKCU\Software\AppDataLow\Software\ScorpionSaver
    Key Deleted : HKCU\Software\AppDataLow\Software\WinZipBar
    Key Deleted : HKLM\Software\AVG Secure Search
    Key Deleted : HKLM\Software\AVG Security Toolbar
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\Software\PIP
    Key Deleted : HKLM\Software\RadioRage_4j
    Key Deleted : HKLM\Software\WinZipBar
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZipBar Toolbar
    Key Deleted : [x64] HKLM\SOFTWARE\Conduit
    Key Deleted : [x64] HKLM\SOFTWARE\Scorpion Saver
    Key Deleted : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
    Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
    ***** [ Browsers ] *****
    -\\ Internet Explorer v11.0.9600.16428
    Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
    Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
    -\\ Mozilla Firefox v6.0.2 (en-US)
    [ File : C:\Users\Rene\AppData\Roaming\Mozilla\Firefox\Profiles\l4idliqi.default-1385750867390\prefs.js ]
    Line Deleted : user_pref("browser.search.defaultenginename", "Mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.aflt", "irmsd1202");
    Line Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
    Line Deleted : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1 CzutCyD1B1P1R");
    Line Deleted : user_pref("extensions.mysearchdial.cr", "1168143589");
    Line Deleted : user_pref("extensions.mysearchdial.dfltLng", "");
    Line Deleted : user_pref("extensions.mysearchdial.dfltSrch", true);
    Line Deleted : user_pref("extensions.mysearchdial.dnsErr", true);
    Line Deleted : user_pref("extensions.mysearchdial.excTlbr", false);
    Line Deleted : user_pref("extensions.mysearchdial.hmpg", true);
    Line Deleted : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtF tCyEtFtCtAyBzytN1L1CzutC[...]
    Line Deleted : user_pref("extensions.mysearchdial.id", "6431503B9E223DB9");
    Line Deleted : user_pref("extensions.mysearchdial.instlDay", "16060");
    Line Deleted : user_pref("extensions.mysearchdial.instlRef", "");
    Line Deleted : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=irmsd1202&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtF tCyEtFtCtAyBzytN1L1Czu[...]
    Line Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.tlbrId", "base");
    Line Deleted : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=irmsd1202&cd=2XzuyEtN2Y1L1QzuyCyEtAtCyDtDtA0Bzy0EtBtBtA0D0BzytN0D0Tzu0SyBtBtCtN1L2XzutBtFtBtF tCyEtFtCtAyBzytN1L1C[...]
    Line Deleted : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
    Line Deleted : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
    Line Deleted : user_pref("extensions.mysearchdial_i.hmpg", true);
    Line Deleted : user_pref("extensions.mysearchdial_i.newTab", false);
    Line Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none");
    Line Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.014:50:35");
    -\\ Google Chrome v31.0.1650.63
    [ File : C:\Users\Rene\AppData\Local\Google\Chrome\User Data\Default\preferences ]
    Deleted : homepage
    Deleted : urls_to_restore_on_startup
    *************************
    AdwCleaner[R0].txt - [15727 octets] - [23/12/2013 15:43:45]
    AdwCleaner[R1].txt - [15788 octets] - [23/12/2013 15:48:04]
    AdwCleaner[S0].txt - [14907 octets] - [23/12/2013 15:49:35]
    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14968 octets] ##########
    I'm now going to download new definitions for MalwareBytes and run it in Safe with Networking mode. Then I'll report again.

    MANY, MANY THANKS!
      My Computer


  6. Posts : 110
    Windows 7 64
    Thread Starter
       #106

    Ran Mbam in Safe/Networking mode. Got this report:

    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org
    Database version: v2013.12.23.07
    Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
    Internet Explorer 11.0.9600.16476
    Rene :: ZIVA [administrator]
    12/23/2013 4:08:48 PM
    mbam-log-2013-12-23 (16-08-48).txt
    Scan type: Full scan (C:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 523052
    Time elapsed: 1 hour(s), 6 minute(s), 11 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 1
    C:\AdwCleaner\Quarantine\C\Windows\System32\AdpeakProxy64.dll.vir (PUP.Optional.Adpeak) -> Quarantined and deleted successfully.
    (end)

    I am able to access the internet via IE, FF, and Chrome without any nasty pop-ups. And a search via Agent Ransack indicates no foul files containing *peak*.*

    What else do I need to do to assure that all of this has been removed?
      My Computer


  7. Posts : 10,796
    Microsoft Windows 7 Home Premium 64-bits 7601 Multiprocessor Free Service Pack 1
       #107

    All seems fine. Why all those tricks...
      My Computer


  8. Posts : 110
    Windows 7 64
    Thread Starter
       #108

    Kaktussoft said:
    All seems fine. Why all those tricks...
    Following up on recommendations and instructions from Jacee, because they seem to be doing the job!
      My Computer


  9. Posts : 110
    Windows 7 64
    Thread Starter
       #109

    Florida Rene said:
    Kaktussoft said:
    All seems fine. Why all those tricks...
    Following up on recommendations and instructions from Jacee, because they seem to be doing the job!
    JACEE: Thank you so much for your explicit instructions. As far as I can tell, they worked just fine!

    COTTONBALL & INDIANACARNIE: Apparently, I don't have to run Farbar again because, after the prompt from Jacee, I ran AdwCleaner which got rid of almost everything, except Scorpion Saver and Great Arcade Hits. SuperAntiSpyware (suggested by Indiana) told me they were in my browser. Couldn't find them in IE or FF, but they were listed as enabled extensions in Chrome. I deleted them.

    KAKTUSSOFT: Your suggestion to get MS Fix-It worked perfectly to finally get rid of the lingering Scorpion Saver which I had been unable to uninstall from the Add/Repair listing.

    Then I ran sfc /scannow and got the message below. I've just restarted the sick machine.
    Attached Thumbnails Attached Thumbnails Virus Deletion Now Makes Internet Access Impossible-elevated-scannow.jpg  
      My Computer


  10. Posts : 110
    Windows 7 64
    Thread Starter
       #110

    Well, I thought all was fixed. But after restarting, I again ran SuperAntiSpyware, and the attached is what I got. What do I do now?

    KAKTUS...that's why "all those tricks." Somewhere, as JMScreator said previously, there's a lurking file which apparently keeps restarting all these bugs.

    BTW, on restart, Chrome again says there are no extensions.
    Attached Thumbnails Attached Thumbnails Virus Deletion Now Makes Internet Access Impossible-superantispyware.jpg  
      My Computer


 
Page 11 of 20 FirstFirst ... 910111213 ... LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 08:04.
Find Us