Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

adsdelivery1 (amongst others) pop ups all over my browser


  • This topic is locked This topic is locked
2 replies to this topic

#1 patrick17112

patrick17112

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:00 PM

Posted 26 May 2014 - 03:20 PM

Hi, My name is Patrick and I have a problem with pop ups. Pretty much every time I open my internet browser, click on a link, sometimes just do nothing, I am bombarded by pop ups. New windows, things at the sides, top, bottom, in the actual text - there is no escape. I have tried malwarebytes, adw cleaner, and a couple of other malware programs with no luck. I've read some of what others with similar problems have been instructed to do but I have had no change, and I didn't want to do too much because I do not really have a clue what I am doing. Any help is really is much appreciated. DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 9.0.8112.16545 Run by Patrick at 20:53:10 on 2014-05-26 Microsoft® Windows Vista Home Premium 6.0.6002.2.1252.44.1033.18.3000.1390 [GMT 1:00] . AV: Norton Internet Security *Enabled/Updated* {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} SP: Norton Internet Security *Enabled/Updated* {631E4324-D31C-783F-EC5C-35AD42B18466} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton Internet Security *Enabled* {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\Dwm.exe C:\Windows\System32\spoolsv.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Apoint2K\Apoint.exe C:\Windows\system32\agrsmsvc.exe C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe C:\Program Files\Norton Internet Security\Engine\21.3.0.12\NIS.exe C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe C:\Program Files\Norton Internet Security\Engine\21.3.0.12\NIS.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe C:\Windows\system32\igfxsrvc.exe C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe C:\Windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe C:\Windows\system32\SearchIndexer.exe C:\Users\Patrick\AppData\Local\Temp\RtkBtMnt.exe C:\Program Files\Apoint2K\ApMsgFwd.exe C:\Program Files\Launch Manager\LManager.exe C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe C:\Program Files\Apoint2K\HidFind.exe C:\Program Files\Apoint2K\Apntex.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Windows\System32\igfxtray.exe C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\system32\igfxext.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Skype\Phone\Skype.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\MSR\Privoxy\privoxy.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe C:\Windows\system32\igfxext.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=20.4.0.40 uSearch Bar = hxxp://www.google.com/ie uSearch Page = hxxp://www.google.com uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vp32&d=0609&m=aspire_5738 mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vp32&d=0609&m=aspire_5738 mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vp32&d=0609&m=aspire_5738 uProxyServer = hxxp=127.0.0.1:8118;https=127.0.0.1:8118 uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton internet security\engine\21.3.0.12\coieplg.dll BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\norton internet security\engine\21.3.0.12\ips\ipsbho.dll BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: TmBpIeBHO Class: {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton internet security\engine\21.3.0.12\coieplg.dll uRun: [ProductReg] "c:\program files\acer\wr_popup\ProductReg.exe" uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [ArcadeDeluxeAgent] "c:\program files\acer arcade deluxe\acer arcade deluxe\ArcadeDeluxeAgent.exe" mRun: [CLMLServer] "c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\CLMLSvc.exe" mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe mRun: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe mRun: [Apoint] c:\program files\apoint2k\Apoint.exe mRun: [LManager] c:\program files\launch manager\LManager.exe mRun: [BackupManagerTray] "c:\program files\newtech infosystems\acer backup manager\BackupManagerTray.exe" -k mRun: [Acer ePower Management] c:\program files\acer\acer powersmart manager\ePowerTrayLauncher.exe mRun: [EgisTecLiveUpdate] "c:\program files\egistec egis software update\EgisUpdate.exe" mRun: [mwlDaemon] c:\program files\egistec\mywinlocker 3\x86\mwlDaemon.exe mRun: [PlayMovie] "c:\program files\acer arcade deluxe\playmovie\PMVService.exe" mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {49783ED4-258D-4f9f-BE11-137C18D3E543} - c:\poker\titan poker\casino.exe IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - ftp://download2.citrix.com/FILES/en/products/client/ica/current/ica32t.exe DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} - hxxp://www.parallelgraphics.com/l2/bin/cortona3d.cab TCP: NameServer = 192.168.0.1 TCP: Interfaces\{73B5DE15-514B-4DEC-A976-B7BE1415183E} : DHCPNameServer = 192.168.0.1 TCP: Interfaces\{C50B5E64-FEB9-43A5-8D7F-A5168348F856} : DHCPNameServer = 192.168.0.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - Notify: igfxcui - igfxdev.dll AppInit_DLLs= c:\progra~1\google\google~1\GOEC62~1.DLL LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\35.0.1916.114\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome . ================= FIREFOX =================== . FF - ProfilePath - c:\users\patrick\appdata\roaming\mozilla\firefox\profiles\21eur3xr.default\ FF - prefs.js: keyword.URL - hxxp://searchou.com/?q={searchTerms}&id=4e262e5f0000000000000017c499a30a FF - prefs.js: network.proxy.ssl_port - 8118 FF - plugin: c:\progra~1\mcafee\msc\npMcSnFFPl.dll FF - plugin: c:\program files\common files\parallelgraphics\cortona\npCortona.dll FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll FF - plugin: c:\program files\mcafee\siteadvisor\NPMcFFPlg32.dll FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\patrick\appdata\local\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll FF - plugin: c:\users\patrick\appdata\roaming\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_224.dll . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1503000.00c\symds.sys [2014-5-20 367704] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1503000.00c\symefa.sys [2014-5-20 936152] R1 BHDrvx86;BHDrvx86;c:\program files\norton internet security\nortondata\21.2.0.38\definitions\bashdefs\20140510.001\BHDrvx86.sys [2014-5-10 1101616] R1 ccSet_NIS;NIS Settings Manager;c:\windows\system32\drivers\nis\1503000.00c\ccsetx86.sys [2014-5-20 127064] R1 IDSVix86;IDSVix86;c:\program files\norton internet security\nortondata\21.2.0.38\definitions\ipsdefs\20140523.001\IDSvix86.sys [2014-5-24 395992] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1503000.00c\ironx86.sys [2014-5-20 206936] R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nis\1503000.00c\symtdiv.sys [2014-5-20 384728] R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2009-2-18 75048] R2 ePowerSvc;Acer ePower Service;c:\program files\acer\acer powersmart manager\ePowerSvc.exe [2009-6-23 703008] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504] R2 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\drivers\mwlPSDFilter.sys [2008-10-9 19504] R2 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\drivers\mwlPSDNserv.sys [2008-10-9 16432] R2 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\drivers\mwlPSDVDisk.sys [2008-10-9 59952] R2 MWLService;MyWinLocker Service;c:\program files\egistec\mywinlocker 3\x86\MWLService.exe [2008-10-27 306736] R2 NIS;Norton Internet Security;c:\program files\norton internet security\engine\21.3.0.12\nis.exe [2014-5-20 276376] R2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\newtech infosystems\acer backup manager\IScheduleSvc.exe [2009-4-11 61184] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-9-23 144632] R2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2013-10-9 3275136] R2 SystemUpdatekb70007;SystemUpdatekb70007;c:\windows\microsoft\systemupdatekb70007\WindowsUpdater.exe [2014-5-22 18944] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-6-23 112128] R3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60x.sys [2008-9-4 223232] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-1-21 179712] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-9-12 30192] S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-9-23 50424] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-9-11 770168] . =============== Created Last 30 ================ . 2014-05-24 11:44:01 -------- d-----w- c:\users\patrick\appdata\roaming\Activeris 2014-05-24 11:35:08 12872 ----a-w- c:\windows\system32\bootdelete.exe 2014-05-24 11:27:22 -------- d-----w- c:\programdata\HitmanPro 2014-05-24 08:18:13 -------- d-----w- c:\program files\MSR 2014-05-23 18:30:55 536576 ----a-w- c:\windows\system32\sqlite3.dll 2014-05-23 18:27:29 -------- d-----w- C:\AdwCleaner 2014-05-23 14:08:51 -------- d-----w- c:\programdata\Malwarebytes 2014-05-23 11:50:20 -------- d-----w- C:\NPE 2014-05-23 11:48:45 -------- d-----w- c:\users\patrick\appdata\local\NPE 2014-05-22 11:52:32 -------- d-----w- c:\windows\Microsoft 2014-05-20 14:18:17 936152 ----a-r- c:\windows\system32\drivers\nis\1503000.00c\symefa.sys 2014-05-20 14:18:17 664280 ----a-r- c:\windows\system32\drivers\nis\1503000.00c\srtsp.sys 2014-05-20 14:18:17 447704 ----a-r- c:\windows\system32\drivers\nis\1503000.00c\symnets.sys 2014-05-20 14:18:17 384728 ----a-r- c:\windows\system32\drivers\nis\1503000.00c\symtdiv.sys 2014-05-20 14:18:17 367704 ----a-r- c:\windows\system32\drivers\nis\1503000.00c\symds.sys 2014-05-20 14:18:17 32344 ----a-r- c:\windows\system32\drivers\nis\1503000.00c\srtspx.sys 2014-05-20 14:18:17 21520 ----a-r- c:\windows\system32\drivers\nis\1503000.00c\symelam.sys 2014-05-20 14:18:17 206936 ----a-r- c:\windows\system32\drivers\nis\1503000.00c\ironx86.sys 2014-05-20 14:18:17 127064 ----a-r- c:\windows\system32\drivers\nis\1503000.00c\ccsetx86.sys 2014-05-20 14:18:03 30068 ----a-w- c:\windows\system32\drivers\nis\1503000.00c\symvtcer.dat 2014-05-20 14:18:03 -------- d-----w- c:\windows\system32\drivers\nis\1503000.00C 2014-05-15 08:22:17 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2014-05-07 12:59:29 -------- d-----w- c:\users\patrick\appdata\local\PokerStars 2014-05-07 12:59:03 -------- d-----w- c:\program files\PokerStars . ==================== Find3M ==================== . 2014-05-14 17:06:19 70832 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2014-05-14 17:06:19 692400 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-03-26 12:39:25 142936 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2014-03-07 23:12:00 1806848 ----a-w- c:\windows\system32\jscript9.dll 2014-03-07 23:02:19 1427968 ----a-w- c:\windows\system32\inetcpl.cpl 2014-03-07 23:02:07 1129472 ----a-w- c:\windows\system32\wininet.dll 2014-03-07 22:57:17 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2014-03-07 22:56:03 421376 ----a-w- c:\windows\system32\vbscript.dll . ============= FINISH: 20:53:57.32 ===============

BC AdBot (Login to Remove)

 


m

#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,271 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:00 PM

Posted 30 May 2014 - 08:27 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Before you run these tools remove the Word Wrap from NotePad.
You will find this function under the Formal menu.
This will break each line of text and I will be able to read your logs.

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===


Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
p.s.
If the SecurityCheck program fails to run for any reason, run it as an Administrator.
===

Download the correct version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

===

Please paste the logs in your next reply DO NOT ATTACH THEM unless specified.

Wait for further instructions.

#3 nasdaq

nasdaq

  • Malware Response Team
  • 38,271 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:00 PM

Posted 05 June 2014 - 08:52 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users