Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Delta


  • This topic is locked This topic is locked
41 replies to this topic

#1 khemsley

khemsley

  • Members
  • 59 posts
  • OFFLINE
  •  
  • Local time:03:11 AM

Posted 15 August 2013 - 11:46 AM

Can you please help me remove Delta Search?

Thank you



BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:11 AM

Posted 15 August 2013 - 12:11 PM

Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

-- Note: The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on each one and uncheck any items you want to keep (except you cannot uncheck Chrome and Firefox preferences lines).

 

 

 

 

Please download Junkware Removal Tool thisisujrt.gif and save it to your Desktop.

  • Close all open programs and shut down any protection/security software now to avoid potential conflicts.
  • Double-click on JRT.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log file named JRT.txt will automatically open and be saved to your Desktop.
  • Copy and paste the contents of JRT.txt in your next reply.

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 khemsley

khemsley
  • Topic Starter

  • Members
  • 59 posts
  • OFFLINE
  •  
  • Local time:03:11 AM

Posted 15 August 2013 - 12:18 PM

How do I shut down protection? I have AVG



#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:11 AM

Posted 15 August 2013 - 12:27 PM

How to temporarily disable AVG
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#5 khemsley

khemsley
  • Topic Starter

  • Members
  • 59 posts
  • OFFLINE
  •  
  • Local time:03:11 AM

Posted 15 August 2013 - 12:32 PM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.4.6 (08.15.2013:1)
OS: Windows 7 Professional x86
Ran by Teacher on Thu 08/15/2013 at 10:28:44.79
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ntredirect
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\aol toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\aol toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\UpdateTask_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\UpdateTask_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{933C8EA4-2B78-4924-8DA1-E13D2CA82527}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EF64538-8B54-4573-B48F-4D34B0238AB2}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA}
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\Windows\System32\Tasks\epupdater
Successfully deleted: [File] "C:\Users\Teacher.teacher-10-PC\appdata\local\google\chrome\user data\default\bprotector web data"
Successfully deleted: [File] "C:\Users\Teacher.teacher-10-PC\appdata\local\google\chrome\user data\default\bprotectorpreferences"
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\ProgramData\aol toolbar"
Successfully deleted: [Folder] "C:\Users\Teacher.teacher-10-PC\AppData\Roaming\babsolution"
Successfully deleted: [Folder] "C:\Users\Teacher.teacher-10-PC\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\Teacher.teacher-10-PC\AppData\Roaming\delta"
Successfully deleted: [Folder] "C:\Users\Teacher.teacher-10-PC\AppData\Roaming\dsite"
Successfully deleted: [Folder] "C:\Users\Teacher.teacher-10-PC\appdata\local\aol toolbar"
Successfully deleted: [Folder] "C:\Users\Teacher.teacher-10-PC\appdata\local\toparcadehits"
Successfully deleted: [Folder] "C:\Program Files\aol toolbar"
Successfully deleted: [Folder] "C:\Users\Teacher.teacher-10-PC\AppData\Roaming\microsoft\windows\start menu\programs\toparcadehits"
Successfully deleted: [Empty Folder] C:\Users\Teacher.teacher-10-PC\appdata\local\{cec7308f-e63a-690e-4028-1e88f311d30b}
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 08/15/2013 at 10:30:39.14
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#6 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:11 AM

Posted 15 August 2013 - 12:40 PM

Can you post the results from AdwCleaner.txt?
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#7 khemsley

khemsley
  • Topic Starter

  • Members
  • 59 posts
  • OFFLINE
  •  
  • Local time:03:11 AM

Posted 15 August 2013 - 12:45 PM

I might have done this twice.  And this would be the second one.  If you need the other one and can tell me how to find it I can try.  Sorry.

 

# AdwCleaner v2.306 - Logfile created 08/15/2013 at 10:03:07
# Updated 19/07/2013 by Xplode
# Operating system : Windows 7 Professional Service Pack 1 (32 bits)
# User : Teacher - TEACHER-10-PC
# Boot Mode : Normal
# Running from : C:\Users\Teacher.teacher-10-PC\Downloads\adwcleaner (2).exe
# Option [Delete]
 
 
***** [Services] *****
 
 
***** [Files / Folders] *****
 
Deleted on reboot : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\ProgramData\BrowserDefender
 
***** [Registry] *****
 
 
***** [Internet Browsers] *****
 
-\\ Internet Explorer v9.0.8112.16447
 
[OK] Registry is clean.
 
-\\ Google Chrome v28.0.1500.95
 
*************************
 
AdwCleaner[R1].txt - [14899 octets] - [15/08/2013 08:21:23]
AdwCleaner[S1].txt - [14896 octets] - [15/08/2013 08:25:31]
AdwCleaner[S2].txt - [819 octets] - [15/08/2013 10:03:07]
 
########## EOF - C:\AdwCleaner[S2].txt - [878 octets] ##########


#8 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:11 AM

Posted 15 August 2013 - 12:53 PM


Please download Malwarebytes Anti-Malware mbamicontw5.gif and save it to your desktop.
  • Important!! When you save the mbam-setup file, rename it to something random (such as 123abc.exe) before beginning the download.
  • Double-click on the renamed file to install, then follow these instructions for doing a Quick Scan in normal mode.
  • Don't forget to check for database definition updates through the program's interface (preferable method) before scanning.
  • If you cannot update Malwarebytes or use the Internet to download any files to the infected computer, manually update the database by following the instructions in FAQ Section A.4. Issues.
Malwarebytes may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • After the scan, make sure that everything is checked and then click the Remove Selected button to remove all the listed malware.
  • When done, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab .
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows the database version and your operating system.
  • Exit Malwarebytes when done.
If Malwarebytes encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally will prevent Malwarebytes from removing all the malware.

Note: A 14-day trial of Malwarebytes Anti-Malware PRO is available as an option when first installing the free version so all users can test the real-time protection component for a period of two weeks. When the limited time period expires those features will be deactivated and locked. Enabling the Protection Module feature again requires registration and purchase of a license key. If you continue to use the free version, there is no requirement to buy a license...you can just use it as a stand-alone scanner. Users who have previously completed the trial will not be prompted to start the trial upon upgrade or reinstallation.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#9 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:11 AM

Posted 15 August 2013 - 12:57 PM

Then check for and remove any Delta Search add-ons from your browser:
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#10 khemsley

khemsley
  • Topic Starter

  • Members
  • 59 posts
  • OFFLINE
  •  
  • Local time:03:11 AM

Posted 15 August 2013 - 01:16 PM

Oh, jeeze! I don't think I renamed it. I must have missed the prompt.  What should I do now?

BTW: Thank you! I appreciate you.



#11 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:11 AM

Posted 15 August 2013 - 01:34 PM

Renaming is used for serious malware infections that try to keep it from running. If you didn't rename, don't worry as it should run ok.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#12 khemsley

khemsley
  • Topic Starter

  • Members
  • 59 posts
  • OFFLINE
  •  
  • Local time:03:11 AM

Posted 15 August 2013 - 01:57 PM

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
 
Database version: v2013.08.15.05
 
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Teacher :: TEACHER-10-PC [administrator]
 
Protection: Enabled
 
8/15/2013 11:42:45 AM
mbam-log-2013-08-15 (11-42-45).txt
 
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 279035
Time elapsed: 11 minute(s), 37 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 12
C:\Users\Teacher.teacher-10-PC\AppData\Local\Temp\SetupToparcadehits.exe (Adware.GameVance) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\AppData\Local\Temp\is357113909\DeltaTB.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\AppData\Local\Temp\is357113909\Toparcadehits.exe (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\AppData\Local\Temp\7DAC389B-BAB0-7891-8CED-717A0464E461\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\AppData\Local\Temp\7DAC389B-BAB0-7891-8CED-717A0464E461\Latest\BUSolution.dll (PUP.Optional.BabSolution.A) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\AppData\Local\Temp\7DAC389B-BAB0-7891-8CED-717A0464E461\Latest\ccp.exe (PUP.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\AppData\Local\Temp\7DAC389B-BAB0-7891-8CED-717A0464E461\Latest\MyDeltaTB.exe (PUP.Delta.A) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\AppData\Local\Temp\7DAC389B-BAB0-7891-8CED-717A0464E461\Latest\NTRedirect.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\AppData\Local\Temp\7DAC389B-BAB0-7891-8CED-717A0464E461\Latest\Setup.exe (PUP.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\Downloads\Setup.exe (PUP.Optional.IBryte.A) -> Quarantined and deleted successfully.
C:\Users\Teacher.teacher-10-PC\Local Settings\Temporary Internet Files\Content.IE5\VQ7YYWIP\pack[1].7z (PUP.Optional.BrowserDefender.A) -> Quarantined and deleted successfully.
C:\Windows\Tasks\TopArcadeHits.job (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully.
 
(end)


#13 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:11 AM

Posted 15 August 2013 - 02:16 PM

How is your computer running now?
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#14 khemsley

khemsley
  • Topic Starter

  • Members
  • 59 posts
  • OFFLINE
  •  
  • Local time:03:11 AM

Posted 15 August 2013 - 02:57 PM

Thank you so much.  Everything appears to be running smoothly.

I appreciate your efficiency too :cherry:



#15 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:11 AM

Posted 15 August 2013 - 06:13 PM

You're welcome.

:thumbup2: Tips to protect yourself against malware and reduce the potential for re-infection
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users