Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trying to get rid of SavePass Smartbar


  • Please log in to reply
11 replies to this topic

#1 DeathReanimated

DeathReanimated

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 07 June 2014 - 12:15 AM

Hello!

 

Honestly I was dumb. I downloaded something I shouldn't have and then suddenly this program was on my computer. I use a Windows 7, 64-bit system and I've gone through a few google fix-its for how to remove this program. I've used Malwarebytes Anti-Malware and adwcleaner. Both of which removed some stuff but not this program. I wish I could just right click and uninstall it from my programs but every time I try nothing happens.

 

Any help would be much appreciated!

 

-Jo



BC AdBot (Login to Remove)

 


#2 Sirawit

Sirawit

    Bleepin' Brony


  • Malware Response Team
  • 4,158 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Thailand
  • Local time:09:00 PM

Posted 07 June 2014 - 01:57 AM

Hi DeathReanimated and welcome to BleepingComputer! :)

 

So, which tool you already run?

 

Also please run this:

Download MiniToolBox, Save it to your desktop and run it.
Close any Firefox browsers you may have open
Checkmark the following boxes:
• Flush DNS
• Report IE Proxy Settings
• Reset IE Proxy Settings
• Report FF Proxy Settings
• Reset FF Proxy Settings
• List last 10 Event Viewer log
• List Installed Programs
• List Users, Partitions and Memory size.
Click Go and copy / paste the result (Result.txt).

 

Thank you.


If I don't reply back to you in 2 days, feel free to send me a PM.

 

“You’re lying… just like you were lying to me before. You have to hate me. I’ve been the worst daughter in the world… you should hate me.”

“But I don’t, Nyx. Because, Nyx, I’m your mother, and a mother will always love her daughter, no matter what.” -Past sins by Pen stroke.


#3 DeathReanimated

DeathReanimated
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 07 June 2014 - 02:37 AM

HEY!!! :D

 

I've run Malwarebytes Anti-Malware, Adwcleaner_3.212 and SUPERAntiSpyware Free Edition.

 

MiniToolBox by Farbar  Version: 23-01-2014
Ran by owner (administrator) on 07-06-2014 at 02:35:20
Running from "C:\Users\owner\Downloads"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
ProxyServer:
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
 
========================= FF Proxy Settings: ============================== 
 
 
"Reset FF Proxy Settings": Firefox Proxy settings were reset.
 
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (06/06/2014 10:31:45 PM) (Source: Application Error) (User: )
Description: Faulting application name: VcmINSMgr.exe, version: 3.8.0.6090, time stamp: 0x4c0f3438
Faulting module name: CddbMusicIDSony.dll, version: 2.6.206.203, time stamp: 0x4bc521ff
Exception code: 0xc0000005
Fault offset: 0x0000de2a
Faulting process id: 0x6c8
Faulting application start time: 0xVcmINSMgr.exe0
Faulting application path: VcmINSMgr.exe1
Faulting module path: VcmINSMgr.exe2
Report Id: VcmINSMgr.exe3
 
Error: (06/06/2014 10:30:13 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {fcda8c36-1dee-4e38-8f77-bf34f15dd5c6}
 
Error: (06/06/2014 10:16:16 PM) (Source: Application Error) (User: )
Description: Faulting application name: VcmINSMgr.exe, version: 3.8.0.6090, time stamp: 0x4c0f3438
Faulting module name: CddbMusicIDSony.dll, version: 2.6.206.203, time stamp: 0x4bc521ff
Exception code: 0xc0000005
Fault offset: 0x0000de2a
Faulting process id: 0xd8c
Faulting application start time: 0xVcmINSMgr.exe0
Faulting application path: VcmINSMgr.exe1
Faulting module path: VcmINSMgr.exe2
Report Id: VcmINSMgr.exe3
 
Error: (06/06/2014 10:11:13 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {233208c9-b74c-4462-9550-654ccb714406}
 
 
System errors:
=============
Error: (06/06/2014 10:35:00 PM) (Source: Service Control Manager) (User: )
Description: The Windows Modules Installer service failed to start due to the following error: 
%%1053
 
Error: (06/06/2014 10:35:00 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Modules Installer service to connect.
 
Error: (06/06/2014 10:35:00 PM) (Source: DCOM) (User: )
Description: 1053TrustedInstaller{752073A1-23F2-4396-85F0-8FDB879ED0ED}
 
Error: (06/06/2014 10:33:29 PM) (Source: Service Control Manager) (User: )
Description: The Intel® System Behavior Tracker Collector Service service hung on starting.
 
Error: (06/06/2014 10:31:46 PM) (Source: Service Control Manager) (User: )
Description: The VAIO Content Metadata Intelligent Network Service Manager service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/06/2014 10:30:02 PM) (Source: Service Control Manager) (User: )
Description: The McAfee Home Network service hung on starting.
 
Error: (06/06/2014 10:28:01 PM) (Source: Service Control Manager) (User: )
Description: The Energy Server Service service hung on starting.
 
Error: (06/06/2014 10:20:24 PM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
 
Error: (06/06/2014 10:19:47 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
 
Error: (06/06/2014 10:19:14 PM) (Source: Service Control Manager) (User: )
Description: The vToolbarUpdater18.1.5 service failed to start due to the following error: 
%%2
 
 
Microsoft Office Sessions:
=========================
Error: (06/06/2014 10:31:45 PM) (Source: Application Error)(User: )
Description: VcmINSMgr.exe3.8.0.60904c0f3438CddbMusicIDSony.dll2.6.206.2034bc521ffc00000050000de2a6c801cf81ff42188d12C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exeC:\Program Files\Sony\VCM Intelligent Network Service Manager\cddb\CddbMusicIDSony.dll3f954f4f-edf4-11e3-9ba0-c44619b4b870
 
Error: (06/06/2014 10:30:13 PM) (Source: VSS)(User: )
Description: 0x80070005, Access is denied.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {fcda8c36-1dee-4e38-8f77-bf34f15dd5c6}
 
Error: (06/06/2014 10:16:16 PM) (Source: Application Error)(User: )
Description: VcmINSMgr.exe3.8.0.60904c0f3438CddbMusicIDSony.dll2.6.206.2034bc521ffc00000050000de2ad8c01cf81fc4a66fc56C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exeC:\Program Files\Sony\VCM Intelligent Network Service Manager\cddb\CddbMusicIDSony.dll15cad5af-edf2-11e3-a59c-c44619b4b870
 
Error: (06/06/2014 10:11:13 PM) (Source: VSS)(User: )
Description: 0x80070005, Access is denied.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {233208c9-b74c-4462-9550-654ccb714406}
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-03-02 19:17:50.198
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\cryptnet.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-03-02 19:17:49.927
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\cryptnet.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-03-02 19:17:49.569
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\cryptnet.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-03-02 19:17:49.135
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\cryptnet.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-03-02 19:17:48.625
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\cryptnet.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-03-02 19:17:48.153
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\cryptnet.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-03-02 19:17:47.583
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\cryptnet.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-03-02 19:17:47.313
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\cryptnet.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-03-02 19:17:47.066
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\gpapi.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-03-02 19:17:46.819
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\gpapi.dll because the set of per-page image hashes could not be found on the system.
 
 
=========================== Installed Programs ============================
 
Adobe AIR (Version: 13.0.0.111)
Adobe Community Help (Version: 3.0.0)
Adobe Community Help (Version: 3.0.0.400)
Adobe Digital Editions 3.0 (Version: 3.0)
Adobe Flash Player 13 ActiveX (Version: 13.0.0.214)
Adobe Flash Player 13 Plugin (Version: 13.0.0.214)
Adobe Photoshop 7.0 (Version: 7.0)
Adobe Reader XI (11.0.07) (Version: 11.0.07)
AIM 7
Alps Pointing-device for VAIO
Apple Application Support (Version: 3.0)
Apple Mobile Device Support (Version: 7.1.0.32)
Apple Software Update (Version: 2.1.3.127)
Application Manager for VAIO
ArcSoft WebCam Companion 3 (Version: 3.0.21.390)
Audacity 1.2.6
Best Buy pc app (Version: 3.0.0.0)
Bonjour (Version: 3.0.0.10)
CDisplay 1.8
Cisco Connect (Version: 1.4.11299.0)
Corel WinDVD (Version: 10.0.6.166)
D3DX10 (Version: 15.4.2368.0902)
Free YouTube Download version 3.2.12.827 (Version: 3.2.12.827)
Free YouTube to MP3 Converter version 3.12.32.327 (Version: 3.12.32.327)
Google Book Downloader (Version: 0.6.9)
Google Chrome (Version: 35.0.1916.114)
Google Drive (Version: 1.15.6556.8063)
Google Update Helper (Version: 1.3.24.7)
Intel PROSet Wireless
Intel WiMAX Tutorial (Version: 1.5.3.1)
Intel® Control Center (Version: 1.2.1.1007)
Intel® PROSet/Wireless WiFi Software (Version: 13.02.1000)
Intel® Rapid Storage Technology (Version: 9.6.0.1014)
Intel® Turbo Boost Technology Driver (Version: 01.01.01.1007)
Intel® PROSet/Wireless WiMAX Software (Version: 2.03.0005)
iTunes (Version: 11.1.4.62)
Java 7 Update 55 (64-bit) (Version: 7.0.550)
JavaFX 2.1.1 (Version: 2.1.1)
JPG to PDF Converter 1.1 (Version: 1.1)
Junk Mail filter update (Version: 15.4.3502.0922)
K-Lite Codec Pack 7.1.0 (Full) (Version: 7.1.0)
LAME v3.98.3 for Audacity
Malwarebytes Anti-Malware version 2.0.2.1012 (Version: 2.0.2.1012)
McAfee All Access – Total Protection (Version: 12.8.958)
McAfee Online Backup (Version: 1.16.4.0)
McAfee SafeKey(uninstall only) (Version: 2.1.6)
Media Gallery (Version: 1.3.0)
Media Gallery (Version: 1.3.0.06230)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office Click-to-Run 2010 (Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - English (Version: 14.0.4763.1000)
Microsoft Silverlight (Version: 5.1.30214.0)
Microsoft SkyDrive (Version: 17.0.2003.1112)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft SQL Server Compact 3.5 SP2 ENU (Version: 3.5.8080.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft_VC80_ATL_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053)
Microsoft_VC90_ATL_x86 (Version: 1.00.0000)
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000)
Mozilla Firefox 29.0 (x86 en-US) (Version: 29.0)
Mozilla Maintenance Service (Version: 29.0)
MPC-HC 1.7.0 (Version: 1.7.0.7858)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
MyFreeCodec
NVIDIA 3D Vision Driver 327.02 (Version: 327.02)
NVIDIA Control Panel 327.02 (Version: 327.02)
NVIDIA Graphics Driver 327.02 (Version: 327.02)
NVIDIA HD Audio Driver 1.3.26.4 (Version: 1.3.26.4)
NVIDIA Install Application (Version: 2.1002.133.889)
NVIDIA PhysX (Version: 9.10.0514)
NVIDIA PhysX System Software 9.10.0514 (Version: 9.10.0514)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.2702)
NVIDIA Update 1.14.17 (Version: 1.14.17)
NVIDIA Update Components (Version: 1.14.17)
Oasis2Service (Version: 1.0.4)
OOBE (Version: 3.10.0630)
PlayReady PC Runtime amd64 (Version: 1.3.0)
PMB (Version: 5.3.00.06040)
PMB VAIO Edition plug-in (Click to Disc) (Version: 3.3.00)
PMB VAIO Edition plug-in (VAIO Movie Story) (Version: 2.3.00)
PrimoPDF -- brought to you by Nitro PDF Software (Version: 5)
PVSonyDll (Version: 1.00.0001)
QuickTime 7 (Version: 7.75.80.95)
Realtek High Definition Audio Driver (Version: 6.0.1.6098)
Remote Keyboard (Version: 1.1.1.07060)
Remote Play with PlayStation 3 (Version: 1.1.0.15071)
Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.0.4.1)
SAMSUNG USB Driver for Mobile Phones (Version: 1.3.2250.0)
SavePass Smartbar (Version: 10.212.76.15578)
Secunia PSI (2.0.0.4003) (Version: 2.0.0.4003)
Shared C Run-time for x64 (Version: 10.0.0)
Skype™ 6.14 (Version: 6.14.104)
Spotify (Version: 0.9.7.16.g4b197456)
SUPERAntiSpyware (Version: 5.7.1026)
Uninstall 1.0.0.1
VAIO - Media Gallery (Version: 1.3.0.06230)
VAIO - PMB VAIO Edition Guide (Version: 1.3.00.06040)
VAIO - PMB VAIO Edition plug-in (Click to Disc) (Version: 3.3.00.06180)
VAIO - PMB VAIO Edition plug-in (VAIO Image Optimizer) (Version: 1.3.00.06110)
VAIO - PMB VAIO Edition plug-in (VAIO Movie Story) (Version: 2.3.00.06180)
VAIO - Remote Keyboard (Version: 1.1.0.07060)
VAIO - Remote Play with PlayStation®3 (Version: 1.1.0.15071)
VAIO - Xperia Link (Version: 1.1.2.08070)
VAIO Care (Version: 8.4.0.14281)
VAIO Care Recovery (Version: 1.1.1.13230)
VAIO Control Center (Version: 4.3.0.05310)
VAIO Data Restore Tool (Version: 1.4.0.05240)
VAIO DVD Menu Data (Version: 2.2.00.05120)
VAIO Gate (Version: 2.4.2.02200)
VAIO Gate Default (Version: 2.2.0.07020)
VAIO Hardware Diagnostics (Version: 4.0.0.06230)
VAIO Health Report (Version: 1.0)
VAIO Help and Support (Version: 12.00.0622)
VAIO Manual (Version: 1.1.0.05280)
VAIO Media plus (Version: 2.1.0)
VAIO Media plus (Version: 2.1.0.18210)
VAIO Media plus Opening Movie (Version: 2.1.0.14080)
VAIO Messenger (Version: 2.0.550.0)
VAIO Movie Story Template Data (Version: 2.3.00.06040)
VAIO Sample Contents (Version: 1.2.0.16080)
VAIO Smart Network (Version: 3.3.0.06080)
VAIO Survey (Version: 6.00.1028)
VAIO Transfer Support (Version: 1.2.0.06230)
VAIO Update (Version: 7.0.0.14270)
VAIO Wireless Wizard (Version: 3.0.0.06230)
VGClientX64 (Version: 1.0.0)
VGClientX86 (Version: 1.0.0)
VLC media player 2.1.3 (Version: 2.1.3)
VU5x64 (Version: 1.1.0)
VU5x86 (Version: 1.0.0)
VU5x86 (Version: 1.1.0)
WIDCOMM Bluetooth Software (Version: 6.3.0.5600)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live Sync (Version: 14.0.8117.416)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
WinRAR archiver
XperiaLinkx86 (Version: 1.0.0)
 
========================= Memory info: ===================================
 
Percentage of memory in use: 72%
Total physical RAM: 6124.93 MB
Available physical RAM: 1674.67 MB
Total Pagefile: 12248.04 MB
Available Pagefile: 7303.34 MB
Total Virtual: 4095.88 MB
Available Virtual: 3960.5 MB
 
========================= Partitions: =====================================
 
1 Drive c: () (Fixed) (Total:586.03 GB) (Free:397.93 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\OWNER-VAIO
 
Administrator            Guest                    owner                    
UpdatusUser              
 
 
**** End of log ****


#4 Sirawit

Sirawit

    Bleepin' Brony


  • Malware Response Team
  • 4,158 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Thailand
  • Local time:09:00 PM

Posted 07 June 2014 - 04:06 AM

Click "start" on the taskbar and then click on the "Control Panel" icon.
Please doubleclick the "Add or Remove Programs" icon
A list of programs installed will be "populated" this may take a bit of time.
If they exist, uninstall the following by clicking on the following entries and selecting "remove":

Best Buy pc app (Version: 3.0.0.0)

SavePass Smartbar (Version: 10.212.76.15578)
Uninstall 1.0.0.1

Additional instructions can be found here if needed.

 

In case above entries cannot be normally removed, please try alternate method below.

Note: Revo Uninstaller is more thorough in deleting programs on your computer than using the Add/Remove option in Windows. Since it is a more powerful tool, please be sure to follow the instructions carefully.

Note: If the program you want to uninstall is not listed by Revo, let me know and we will try an altenate method of removal.

  • Please download and install Revo Uninstaller Free
    note: there is no need to click anything on that page, the download will start automatically
  • Double click Revo Uninstaller to run it
  • From the list of programs double click on the listed program(s), or anything similar, to remove it:

    Best Buy pc app (Version: 3.0.0.0)

    SavePass Smartbar (Version: 10.212.76.15578)
    Uninstall 1.0.0.1
  • When prompted if you want to uninstall click Yes
  • Be sure the Moderate option is selected then click Next
  • The program will run, If prompted again click Yes
  • When the built-in uninstaller is finished click on Next
  • Once the program has searched for leftovers click Next
  • Check the items in bold only on the list then click Delete
    note: you may have to expand some folders by clicking the "+" mark
  • When prompted click on Yes and then on Next
  • Put a check on any folders that are found and select Delete
  • When prompted select Yes then Next
  • Once done click Finish

Other updates jobs

 

:step1: Your Silverlight installation is outdated, please follow instructions here to get latest version: 

http://www.microsoft.com/getsilverlight/Get-Started/Install/Default.aspx

 

:step2: Important Note: Your version of Firefox is out of date.


Older versions have vulnerabilities that malicious sites can use to exploit and infect your system.

Please follow these steps to update Firefox:

Thank you.


If I don't reply back to you in 2 days, feel free to send me a PM.

 

“You’re lying… just like you were lying to me before. You have to hate me. I’ve been the worst daughter in the world… you should hate me.”

“But I don’t, Nyx. Because, Nyx, I’m your mother, and a mother will always love her daughter, no matter what.” -Past sins by Pen stroke.


#5 DeathReanimated

DeathReanimated
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 07 June 2014 - 04:42 AM

After going to the Control Panel only 'Uninstall 1.0.0.1' was visible under 'Add or Remove Programs' and I was able to uninstall it successfully.
 
After downloading Revo Uninstaller I was only able to find 'SavePass Smartbar' and successfully removed it as well.
 
So the only thing left is 'Best Buy pc app.'
 
I clicked on the link to update my Microsoft Silverlight and downloaded it. But I got a window saying that 'this version of Silverlight was already installed.'
 
Also, I'd been meaning to uninstall Firefox so I did it now via the Control Panel method.


#6 Sirawit

Sirawit

    Bleepin' Brony


  • Malware Response Team
  • 4,158 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Thailand
  • Local time:09:00 PM

Posted 07 June 2014 - 04:47 AM

There's some problem in Silverlight installer (I believed) that if you want to install newer minor version of Silverlight 5 you will need to uninstall old one in control panel first.

 

You had updated firefox or uninstalled it?

 

And great that that toolbar now gone, now let's double check.

 

:step2: Please download AdwCleaner by Xplode and save to your Desktop.

  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • This time click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

:step1: thisisujrt.gif  Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Thank you.


If I don't reply back to you in 2 days, feel free to send me a PM.

 

“You’re lying… just like you were lying to me before. You have to hate me. I’ve been the worst daughter in the world… you should hate me.”

“But I don’t, Nyx. Because, Nyx, I’m your mother, and a mother will always love her daughter, no matter what.” -Past sins by Pen stroke.


#7 DeathReanimated

DeathReanimated
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 07 June 2014 - 09:15 PM

I uninstalled Silverlight and then downloaded the latest version.

 

I uninstalled Firefox.

 

AdwCleaner Results:

 

# AdwCleaner v3.212 - Report created 07/06/2014 at 20:24:20
# Updated 05/06/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : owner - OWNER-VAIO
# Running from : C:\Users\owner\Downloads\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17041
 
 
-\\ Google Chrome v35.0.1916.114
 
[ File : C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
 
*************************
 
AdwCleaner[R0].txt - [13056 octets] - [06/06/2014 20:44:38]
AdwCleaner[R1].txt - [1219 octets] - [06/06/2014 22:11:02]
AdwCleaner[R2].txt - [1154 octets] - [07/06/2014 20:17:40]
AdwCleaner[S0].txt - [12974 octets] - [06/06/2014 20:46:27]
AdwCleaner[S1].txt - [1284 octets] - [06/06/2014 22:17:49]
AdwCleaner[S2].txt - [1080 octets] - [07/06/2014 20:24:20]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1140 octets] ##########
 
 
Junkware Removal Tool Results:
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by owner on Sat 06/07/2014 at 20:45:46.97
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 06/07/2014 at 21:03:06.41
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


#8 Sirawit

Sirawit

    Bleepin' Brony


  • Malware Response Team
  • 4,158 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Thailand
  • Local time:09:00 PM

Posted 08 June 2014 - 09:48 AM

Did Smartbar comes back again?

 

I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.png
      icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.

Thank you.


If I don't reply back to you in 2 days, feel free to send me a PM.

 

“You’re lying… just like you were lying to me before. You have to hate me. I’ve been the worst daughter in the world… you should hate me.”

“But I don’t, Nyx. Because, Nyx, I’m your mother, and a mother will always love her daughter, no matter what.” -Past sins by Pen stroke.


#9 DeathReanimated

DeathReanimated
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 08 June 2014 - 07:14 PM

I don't see the Smartbar when I look at my installed programs. So no, I don't think so.

 

The ESETScan just finished. I still have it opened and wanted to ask if I should check the 'Delete quarantined files' before I close the program?

 

Also, here are the results:

 

C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\DVDVideoSoftTB.exe.vir a variant of Win32/Toolbar.Conduit.B potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir Win32/Toolbar.Conduit.Y potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\CT3309656\plugins\TBVerifier.dll.vir Win32/Toolbar.Conduit.AC potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\LocalLow\KeyBar_2.1\hk64tbKeyB.dll.vir Win64/Toolbar.Conduit.A potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\LocalLow\KeyBar_2.1\hktbKeyB.dll.vir Win32/Toolbar.Conduit.W potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\LocalLow\KeyBar_2.1\ldrtbKeyB.dll.vir a variant of Win32/Toolbar.Conduit.P potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\LocalLow\KeyBar_2.1\tbKeyB.dll.vir a variant of Win32/Toolbar.Conduit.X potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\staged\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_22.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\staged\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_23.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\staged\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_24.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\staged\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_25.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\staged\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_26.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\staged\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_27.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_22.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_23.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_24.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_25.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_26.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\y52meitu.default-1396300589268\Extensions\{5c6e136f-22d3-3460-e360-1a3af98a0e49}\components\SmartbarFireFoxRemotePlugin_27.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application deleted - quarantined
C:\Program Files (x86)\Common Files\DVDVideoSoft\AskTB\ApnIC.dll a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application deleted - quarantined
C:\Program Files (x86)\Common Files\DVDVideoSoft\AskTB\ApnToolbarInstaller.exe a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application deleted - quarantined
C:\Program Files (x86)\Common Files\DVDVideoSoft\AskTB\DVDVideoSoftToolbar.exe a variant of Win32/Toolbar.Visicom.A potentially unwanted application deleted - quarantined
C:\Users\owner\AppData\Local\CRE\ihogoofdaifgdkdilopkeahfcnifkajn.crx a variant of Win32/Toolbar.Conduit.AH potentially unwanted application deleted - quarantined
C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2HCKY11R\SavePass[1].exe a variant of Win32/Toolbar.Linkury.E potentially unwanted application deleted - quarantined
C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2HCKY11R\Setup_product_493[1].exe Win32/OutBrowse.R potentially unwanted application deleted - quarantined
C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MIHEWQ7B\spstub[1].exe a variant of Win32/Conduit.SearchProtect.N potentially unwanted application deleted - quarantined
C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R2V77980\DesktopWeatherAlertsSetup[1].exe a variant of MSIL/Adware.StrongVault.A application cleaned by deleting - quarantined
C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZLSRCYBD\SearchProtectGeneric2[1].exe Win32/OutBrowse.Q potentially unwanted application deleted - quarantined
C:\Users\owner\AppData\Local\Spotify\Browser\f_000086 a variant of Win32/BundleInstaller.D potentially unwanted application deleted - quarantined
C:\Users\owner\AppData\Local\Temp\0_Offer_2.exe a variant of Win32/Toolbar.Linkury.E potentially unwanted application deleted - quarantined


#10 Sirawit

Sirawit

    Bleepin' Brony


  • Malware Response Team
  • 4,158 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Thailand
  • Local time:09:00 PM

Posted 09 June 2014 - 09:28 AM

Yes, please do so.

 

Please check in your browsers, did toolbars appears somewhere else?

 

In your google chrome, please go to settings > Extensions and check for unwanted extensions, you can remove something by click on bin button next to it.

 

Thank you.


If I don't reply back to you in 2 days, feel free to send me a PM.

 

“You’re lying… just like you were lying to me before. You have to hate me. I’ve been the worst daughter in the world… you should hate me.”

“But I don’t, Nyx. Because, Nyx, I’m your mother, and a mother will always love her daughter, no matter what.” -Past sins by Pen stroke.


#11 DeathReanimated

DeathReanimated
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 09 June 2014 - 11:56 AM

I checked my browsers and didn't see the Smartbar anywhere. Does that mean its gone???



#12 Sirawit

Sirawit

    Bleepin' Brony


  • Malware Response Team
  • 4,158 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Thailand
  • Local time:09:00 PM

Posted 10 June 2014 - 10:32 AM

All clean! Congratulations!  :clapping:

 

 

Now we need to remove our removal tools.

 

bwebb7v.jpgDownload Delfix from here and save it to your desktop.

  • Ensure Remove disinfection tools is checked.
  • Also place a checkmark next to:
    • Create registry backup
    • Purge system restore
    delfix.jpg
  • Click the Run button.

When the tool is finished, a log will open in notepad. Please copy and paste the log in your next reply.

 

Some tips to keep your computer safe.

 

Exercise common sense

Having security programs installed is very helpful to you, but none of them have the gift of human thought. The best way to make sure you don't get infected is to look before you leap. Be careful of what websites you visit - if a site looks suspicious, trust your instincts and get out of there. Be careful of what attachments you open in emails and files you download from websites - check them over carefully and look at the file extensions to make sure that you know what you're getting. Using peer-to-peer file sharing programs or downloading cracks and keygens is something else to avoid - the files you will be downloading are infected in the vast majority of cases, and the benefits simply aren't worth the risk to your computer.

Keep up on Windows updates

Along with keeping all of the security programs that you choose to use updated, it is also important to keep up on system updates from Microsoft, as these patch critical security vulnerabilities and help to keep you safe. Typically the windows update icon will appear in your taskbar when new updates are available, whenever you see it you should open the menu up and install the updates that are available. Although it may be an annoyance, that little bit of extra time it takes to stay updated is very well worth it instead of getting infected from an exploit and having to clean your PC again.

Slow computer?

If your computer begins to slow down again in the future for no particular reason, your first step should not be to come back to the malware forum. As your computer ages and is used, its parts wear, files and programs accumulate, and its performance speed can decrease. To restore your computer's performance to its best possible level, follow the steps in this guide written by tech expert Artellos.

 

Thank you, and enjoy your clean computer!  :)


If I don't reply back to you in 2 days, feel free to send me a PM.

 

“You’re lying… just like you were lying to me before. You have to hate me. I’ve been the worst daughter in the world… you should hate me.”

“But I don’t, Nyx. Because, Nyx, I’m your mother, and a mother will always love her daughter, no matter what.” -Past sins by Pen stroke.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users