Help with Removing edeals

I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
C:\Windows\SysWOW64\frozentwextRec\frozentwextRec.exe a variant of Win32/Adware.Pirrit.S application
C:\Windows\SysWOW64\keyboardhotstartapi\keyboardhotstartapi.exe Win32/Adware.Pirrit.S application
C:\AdwCleaner\Quarantine\C\ProgramData\Browser\prompt.exe.vir a variant of MSIL/Adware.PullUpdate.H application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Users\Bowden\AppData\Local\torch\User Data\Default\Extensions\enppohegiimggcofjojflcljafomfbpc\5.10\sZk.js.vir Win32/Adware.MultiPlug.H application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\windows\System32\roboot64.exe.vir a variant of Win64/Systweak.A potentially unwanted application deleted - quarantined
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSS.exe a variant of Win32/Systweak.L potentially unwanted application deleted - quarantined
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll a variant of Win32/Systweak.N potentially unwanted application deleted - quarantined
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe a variant of Win32/Systweak.L potentially unwanted application deleted - quarantined
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe a variant of Win32/Systweak potentially unwanted application deleted - quarantined
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe a variant of Win32/Systweak.L potentially unwanted application deleted - quarantined
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe a variant of Win32/Systweak.L potentially unwanted application deleted - quarantined
C:\Users\Bowden\AppData\Local\appsambaRecovery\defaultremote_86.exe a variant of Win32/Adware.Pirrit.R application cleaned by deleting - quarantined
C:\Windows\wauctla.exe a variant of MSIL/Adware.Pirrit.A application cleaned by deleting (after the next restart) - quarantined
C:\Windows\Installer\17d240e.msi a variant of Win32/Systweak.L potentially unwanted application deleted - quarantined
C:\Windows\System32\frozentwextRec\frozentwextRec.exe a variant of Win32/Adware.Pirrit.S application cleaned by deleting (after the next restart) - quarantined
C:\Windows\System32\keyboardhotstartapi\keyboardhotstartapi.exe Win32/Adware.Pirrit.S application cleaned by deleting (after the next restart) - quarantined
 

My Computer My Computer

Computer type
PC/Desktop
OS
windows 7 Home Premium 64bit
hope that helps

I must say thank you for your help
Also but LAN setting keep changing to proxy - could edeals have something to do with that too
Ben
 

My Computer My Computer

Computer type
PC/Desktop
OS
windows 7 Home Premium 64bit
Can you tell me what this application AppData\Local\appsambaRecovery is?

There is no information about it :confused:

Edit, Is this a server?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Can you tell me what this application AppData\Local\appsambaRecovery is?

There is no information about it :confused:


i havent got a clue sorry?
 

My Computer My Computer

Computer type
PC/Desktop
OS
windows 7 Home Premium 64bit
Oh dear ... edeals should have been quarantined and deleted by eset ...

C:\Users\Bowden\AppData\Local\appsambaRecovery\defaultremote_86.exe a variant of Win32/Adware.Pirrit.R application cleaned by deleting - quarantined

Did you reboot your computer after running eset? If not, please do so. Let me know if proxy keeps coming back.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
yep all rebooted and no edeals ............. yet!!!
 

My Computer My Computer

Computer type
PC/Desktop
OS
windows 7 Home Premium 64bit
Back
Top