Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Adwcleaner


  • Please log in to reply
9 replies to this topic

#1 otisman

otisman

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:04:56 AM

Posted 08 February 2014 - 10:57 AM

While reviewing the files on my computer and those needing to be eliminated I found Mobogenie.  I googled it and found it called a virus or close-to-virus.  I removed it and followed instructions to remove the adware with Adwcleaner.  Since then I have not been able to load certain pictures.  Particularly, I cannot get all the pictures to load on Ebay.  Some do but most do not and I get a gray background with a circling dot.  I previously had that problem and solved it with compatibility view settings or by refreshing the page.

 

I did check the multimedia portion of Internet options and all appear to be where they should (checked).  I know I should have left the computer alone since the Mobogenie was not bothering me but I seem to have to learn my lessons the hard way.

 

Anyone have any suggestions?

 

Thanks.



BC AdBot (Login to Remove)

 


#2 dls62

dls62

  • Members
  • 623 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Berkshire, UK
  • Local time:09:56 AM

Posted 08 February 2014 - 11:15 AM

Can you copy and paste the contents of your AdwCleaner[R0].txt and AdwCleaner[R1].txt in your next reply.  These logs can be found in C:\AdwCleaner.



#3 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,086 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:08:56 AM

Posted 08 February 2014 - 11:34 AM

Hi,

 

AdwCleaner should create a restore point, so if you need to you can use that. You should have been able to uninstall Mobogenie, even if you do choose to restore.

 

Out of interest, what browser are you using?

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#4 dc3

dc3

    Bleeping Treehugger


  • Members
  • 30,752 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:12:56 AM

Posted 08 February 2014 - 12:33 PM

 I googled it and found it called a virus or close-to-virus.  I removed it and followed instructions to remove the adware with Adwcleaner.  

 

How did you remove it?


Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 


#5 otisman

otisman
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:04:56 AM

Posted 08 February 2014 - 01:30 PM

Thanks to those who responded

 

dls62 - I have the text document below.

 

xXToffeeXx - I am using Windows 7 Internet Explorer 11.0.96.  I would not even know how to get to the restore point.

 

dc3 - I uninstalled it from the Control Panel.  Perhaps using the word "remove" was not correct.

 

-----------------------------------------------------------------------------------

# AdwCleaner v3.018 - Report created 05/02/2014 at 08:28:02
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Maria - MARIA-HP
# Running from : C:\Users\Maria\Downloads\Applications\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

[x] Not Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\ProgramData\StarApp
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\MyPC Backup
Folder Deleted : C:\Program Files (x86)\SafeSaver
Folder Deleted : C:\Program Files (x86)\xfin_portal
[x] Not Deleted : C:\Users\Maria\AppData\Local\Babylon
Folder Deleted : C:\Users\Maria\AppData\Local\Conduit
Folder Deleted : C:\Users\Maria\AppData\LocalLow\comcasttb
Folder Deleted : C:\Users\Maria\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Maria\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Maria\AppData\LocalLow\xfin_portal
Folder Deleted : C:\Users\Maria\AppData\Roaming\Searchprotect

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_4e24eecb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_e14dcdfa
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_f5d3e0aa
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3292715
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{49BC4DD1-0E69-4611-9164-0009538C5E46}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{08635077-8829-49E2-B338-C968817EB460}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{20A3F109-F7C1-47B4-8098-8E654B264B1D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8C7478AB-3155-463E-936F-55F91F0F10D0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9E1B65EE-A131-42B4-94CA-847505E2F611}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A11A6BD-7880-49BD-92D4-6F09D0BD3250}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{68DE31F7-43FF-4EE2-B88B-10665016970D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1791C1B5-FFD0-4D4B-ABCD-7A7DF6EAA89C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49BC4DD1-0E69-4611-9164-0009538C5E46}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49BC4DD1-0E69-4611-9164-0009538C5E46}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\smartbar
Key Deleted : HKCU\Software\AppDataLow\Software\xfin_portal
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\SP Global
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\xfin_portal

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

-\\ Google Chrome v

[ File : C:\Users\Maria\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [5833 octets] - [05/02/2014 08:26:09]
AdwCleaner[S0].txt - [5706 octets] - [05/02/2014 08:28:02]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5766 octets] ##########



#6 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,086 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:08:56 AM

Posted 08 February 2014 - 01:39 PM

Hi,

 

Reset IE using the directions here and see if that makes a difference.

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#7 otisman

otisman
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:04:56 AM

Posted 08 February 2014 - 03:17 PM

xXToffeeXx  - I tried it but has made no noticeable difference.

 

Thanks.



#8 dls62

dls62

  • Members
  • 623 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Berkshire, UK
  • Local time:09:56 AM

Posted 08 February 2014 - 03:23 PM

Download and run TFC, which will clear all you temporary internet files, etc.  You will need to reboot your system after running the utility.



#9 otisman

otisman
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:04:56 AM

Posted 08 February 2014 - 04:39 PM

Downloaded and ran TFC.  There is no change and the pictures still do not load.

 

Thanks.



#10 otisman

otisman
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:04:56 AM

Posted 09 February 2014 - 08:20 PM

Got it.  I removed Ebay from compatibility view and the pictures downloaded.

 

Thanks to all who responded.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users