Run the herdprotect scan again, this time clicking the items I have listed below and clicking action-remove
Code:
File path: c:\program files (x86)\the wedownload manager\49074.xpi
Publisher:
MD5: c9cb2f0fc00a86c28cdb68e153b6b2ea
SHA-1: 1e46cdd5d7ee0fd04c76b35e461b390a7dc82955
Created: 4/6/2014 12:09:02 PM
Detections: 4
Code:
File path: c:\program files (x86)\the wedownload manager\49074.crx
Publisher:
MD5: cebbc24d84bda169f262e7c97a1fecea
SHA-1: 7d798d77178f4ddddb417f24916e7457d18aee77
Created: 4/6/2014 12:08:58 PM
Detections: 3
Code:
File path: c:\program files (x86)\the wedownload manager\the wedownload manager-bho64.dll
Publisher: weDownload
MD5: cbd0a348e3a35e69d7cc3ab816fdec7f
SHA-1: a486ef6700a7967a3f76ef069421cc7ef1c0793c
Created: 4/6/2014 12:09:13 PM
Detections: 6
Code:
File path: c:\program files (x86)\hosts_anti_adwares_pups\hosts_anti-adware_main.exe
Publisher:
MD5: c1db9bdf885c2f1adc15264fbea2788f
SHA-1: 938a71b4134de7f37b125ac48eac18a8a1db4085
Created: 4/10/2014 7:29:01 PM
Detections: 12
Code:
File path: c:\program files (x86)\hosts_anti_adwares_pups\hosts_anti-adware.exe
Publisher:
MD5: 59538d76ea7d0fe8283d72265833e0e4
SHA-1: 724abd1ecb3a1cd566c57470a485a72f296dc2e4
Created: 4/10/2014 7:28:57 PM
Detections: 12
Code:
File path: c:\program files (x86)\the wedownload manager\utils.exe
Publisher:
MD5: b6943df0c6d09b1e1846d5fec737a1da
SHA-1: d3d31fea9505b979ce71bd97827dc551de8e8421
Created: 4/6/2014 12:08:55 PM
Detections: 5
Code:
File path: c:\program files (x86)\the wedownload manager\ea727281-8281-467f-bafd-cf5fb6f1777a-5.exe
Publisher: weDownload
MD5: f742c59be1a1554a73491540563e352b
SHA-1: 801df77ee439dc2382ba385a200d73326d8eb6ec
Created: 4/6/2014 12:09:18 PM
Detections: 4
Code:
File path: c:\program files (x86)\the wedownload manager\ea727281-8281-467f-bafd-cf5fb6f1777a-4.exe
Publisher: weDownload
MD5: a01ba938c93678f2e2aaae11df9259b8
SHA-1: 69d8a3c4bc8e4847b1ee0a37c272b9302d62a55f
Created: 4/6/2014 12:09:02 PM
Detections: 4
Code:
File path: c:\program files (x86)\the wedownload manager\ea727281-8281-467f-bafd-cf5fb6f1777a-3.exe
Publisher: weDownload
MD5: 20f57566af85c315bed57667fea3c92e
SHA-1: 66bccae5319e8cf7fed0a2c4711b114e2d74e20a
Created: 4/6/2014 12:08:59 PM
Detections: 4
Determination: Adware
Code:
File path: c:\program files (x86)\the wedownload manager\ea727281-8281-467f-bafd-cf5fb6f1777a-2.exe
Publisher: weDownload
MD5: 0239b4ad3709e58629390a4d934613ae
SHA-1: 59a3aaf56e9f62b0c8834639651744f5889ac720
Created: 4/6/2014 12:09:14 PM
Detections: 5
Code:
File path: c:\users\trr-office\appdata\local\google\chrome\user data\default\extensions\ecoccdldklbjglocbgbfpmpehjegkode\1.26.56_0\manifest.json
Publisher:
MD5: 4f86f1ca201c283eba119a668688ecf7
SHA-1: 72b77cfb3acba85829c1f7dd02d174e085bc081b
Created: 4/23/2014 8:14:15 PM
Detections: 1
Determination: Adware
Uninstall any iobit products first (like driverbooster), before removing with herdprotect. If it still shows up in herdprotect.
Code:
File path: c:\program files (x86)\iobit\driver booster\autoupdate.exe
Publisher: IObit
Signer: IObit Information Technology
MD5: 498df557613771ecc3178a626d0c15f2
SHA-1: 2f6a6423590ceb6a053e81e1c67474e82d01a305
Created: 2/19/2014 11:21:56 AM
Detections: 1
Code:
File path: c:\program files (x86)\iobit\driver booster\scheduler.exe
Publisher: IObit
Signer: IObit Information Technology
MD5: 0fea4f4248d0d1a1ab6c18007e982e0b
SHA-1: ca2493f36698e096a6b6b26ab92e742d8f85cd4a
Created: 2/19/2014 11:21:56 AM
Detections: 1
Code:
File path: c:\program files (x86)\iobit\driver booster\maddisasm_.bpl
Publisher:
Signer: IObit Information Technology
MD5: 5c4debd7b96bbfa9b3c590d487558880
SHA-1: 05f6a913004c78a6353a75aea5009ce59f4989f2
Created: 2/19/2014 11:21:55 AM
Detections: 1
Delete this folder:
c:\program files (x86)\the wedownload manager\
Once all this is complete, restart and post a new scan log.