Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need help


  • Please log in to reply
13 replies to this topic

#1 ace17

ace17

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 01:19 PM

My system is infected. There are constant ads that pop up when I'm browsing the internet. They will come in from the left side and float towards the center of the screen. There's also been a search engine called Groovorio that pops up as a separate tab in my browser. Sometimes when I click one link another tab will open up as well saying that my system may be infected. I've ran malwarebytes and removed some issues but there are still these ads that pop up everywhere. I am using windows 8.


Edited by ace17, 18 November 2014 - 01:38 PM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:22 AM

Posted 18 November 2014 - 04:42 PM

Hello ace,, let's see how it is after these.

Please download MiniToolBox, save it to your desktop and run it.
Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
  • Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
    Note: When using "Reset FF Proxy Settings" option Firefox should be closed.



    Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
  • .
    .
    .
    ADW Cleaner

    Please download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
  • -- Note: The contents of the AdwCleaner log file may be confusing. Unless you see a program name that you recognize and know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on each one and uncheck any items you want to keep (except you cannot uncheck Chrome and Firefox preferences lines).


    .

    thisisujrt.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
  • .
    .
    .
    .
  • Last run ESET.
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 ace17

ace17
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 05:13 PM

MiniToolBox by Farbar  Version: 21-07-2014

Ran by chiecheng1012 (administrator) on 18-11-2014 at 16:11:25
Running from "C:\Users\chiecheng1012\Downloads"
Microsoft Windows 8.1  (X64)
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
 
========================= FF Proxy Settings: ============================== 
 
 
"Reset FF Proxy Settings": Firefox Proxy settings were reset.
 
========================= Hosts content: =================================
 
 
 
========================= IP Configuration: ================================
 
Qualcomm Atheros AR9485 802.11b|g|n WiFi Adapter = Wi-Fi (Connected)
Realtek PCIe FE Family Controller = Ethernet (Media disconnected)
 
 
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
 
reset
set global icmpredirects=enabled
set interface interface="Local Area Connection* 1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 11" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="ethernet_3" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
 
 
popd
# End of IPv4 configuration
 
 
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : CLC
   Primary Dns Suffix  . . . . . . . : 
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : earthlink.net
 
Wireless LAN adapter Local Area Connection* 11:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : 12-68-9D-C3-79-76
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Ethernet adapter Ethernet:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : earthlink.net
   Description . . . . . . . . . . . : Realtek PCIe FE Family Controller
   Physical Address. . . . . . . . . : 84-34-97-76-40-75
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Wi-Fi:
 
   Connection-specific DNS Suffix  . : earthlink.net
   Description . . . . . . . . . . . : Qualcomm Atheros AR9485 802.11b|g|n WiFi Adapter
   Physical Address. . . . . . . . . : 20-68-9D-C3-79-76
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::2c77:abd9:6796:dcc6%3(Preferred) 
   IPv4 Address. . . . . . . . . . . : 192.168.1.102(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Monday, November 17, 2014 2:42:53 PM
   Lease Expires . . . . . . . . . . : Wednesday, November 19, 2014 4:07:56 PM
   Default Gateway . . . . . . . . . : 192.168.1.1
   DHCP Server . . . . . . . . . . . : 192.168.1.1
   DHCPv6 IAID . . . . . . . . . . . : 337668253
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-17-FF-FC-2F-84-34-97-76-40-75
   DNS Servers . . . . . . . . . . . : 207.69.188.186
                                       207.69.188.187
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Tunnel adapter isatap.earthlink.net:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : earthlink.net
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Local Area Connection* 13:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:5ef5:79fd:2cb3:334e:3f57:fe99(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::2cb3:334e:3f57:fe99%7(Preferred) 
   Default Gateway . . . . . . . . . : ::
   DHCPv6 IAID . . . . . . . . . . . : 184549376
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-17-FF-FC-2F-84-34-97-76-40-75
   NetBIOS over Tcpip. . . . . . . . : Disabled
Server:  rns2.earthlink.net
Address:  207.69.188.186
 
Name:    google.com
Addresses:  2607:f8b0:4006:809::1005
 173.194.123.46
 173.194.123.32
 173.194.123.37
 173.194.123.38
 173.194.123.36
 173.194.123.34
 173.194.123.39
 173.194.123.33
 173.194.123.35
 173.194.123.40
 173.194.123.41
 
 
Pinging google.com [173.194.123.46] with 32 bytes of data:
Reply from 173.194.123.46: bytes=32 time=369ms TTL=48
Reply from 173.194.123.46: bytes=32 time=57ms TTL=48
 
Ping statistics for 173.194.123.46:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 57ms, Maximum = 369ms, Average = 213ms
Server:  rns2.earthlink.net
Address:  207.69.188.186
 
Name:    yahoo.com
Addresses:  206.190.36.45
 98.139.183.24
 98.138.253.109
 
 
Pinging yahoo.com [98.138.253.109] with 32 bytes of data:
Reply from 98.138.253.109: bytes=32 time=75ms TTL=47
Reply from 98.138.253.109: bytes=32 time=797ms TTL=47
 
Ping statistics for 98.138.253.109:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 75ms, Maximum = 797ms, Average = 436ms
 
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
  8...12 68 9d c3 79 76 ......Microsoft Wi-Fi Direct Virtual Adapter
  4...84 34 97 76 40 75 ......Realtek PCIe FE Family Controller
  3...20 68 9d c3 79 76 ......Qualcomm Atheros AR9485 802.11b|g|n WiFi Adapter
  1...........................Software Loopback Interface 1
  5...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
  7...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1    192.168.1.102     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         On-link     192.168.1.102    281
    192.168.1.102  255.255.255.255         On-link     192.168.1.102    281
    192.168.1.255  255.255.255.255         On-link     192.168.1.102    281
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link     192.168.1.102    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link     192.168.1.102    281
===========================================================================
Persistent Routes:
  None
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  7    306 ::/0                     On-link
  1    306 ::1/128                  On-link
  7    306 2001::/32                On-link
  7    306 2001:0:5ef5:79fd:2cb3:334e:3f57:fe99/128
                                    On-link
  3    281 fe80::/64                On-link
  7    306 fe80::/64                On-link
  3    281 fe80::2c77:abd9:6796:dcc6/128
                                    On-link
  7    306 fe80::2cb3:334e:3f57:fe99/128
                                    On-link
  1    306 ff00::/8                 On-link
  3    281 ff00::/8                 On-link
  7    306 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================
 
Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [53760] (Microsoft Corporation)
Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [68096] (Microsoft Corporation)
Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [68096] (Microsoft Corporation)
Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [64000] (Microsoft Corporation)
Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [21504] (Microsoft Corporation)
Catalog9 01 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 02 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 03 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 04 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 05 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 06 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 07 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 08 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 09 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 10 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [67584] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [84480] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [30208] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (11/18/2014 01:45:41 PM) (Source: Application Hang) (User: )
Description: The program LiveComm.exe version 17.5.9600.20605 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1984
 
Start Time: 01d00367860af150
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: 798bc8fb-6f5b-11e4-beae-843497764075
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (11/18/2014 01:37:40 PM) (Source: Application Error) (User: )
Description: Faulting application name: rundll32.exe, version: 6.3.9600.16384, time stamp: 0x52158827
Faulting module name: ntdll.dll, version: 6.3.9600.17278, time stamp: 0x53eeb4a3
Exception code: 0xc000000d
Fault offset: 0x000edae2
Faulting process id: 0x6280
Faulting application start time: 0xrundll32.exe0
Faulting application path: rundll32.exe1
Faulting module path: rundll32.exe2
Report Id: rundll32.exe3
Faulting package full name: rundll32.exe4
Faulting package-relative application ID: rundll32.exe5
 
Error: (11/18/2014 01:15:44 PM) (Source: Application Hang) (User: )
Description: The program LiveComm.exe version 17.5.9600.20605 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 773c
 
Start Time: 01d00363551fcc3c
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: 4909281b-6f57-11e4-beae-843497764075
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (11/18/2014 00:53:07 PM) (Source: Application Error) (User: )
Description: Faulting application name: rundll32.exe, version: 6.3.9600.16384, time stamp: 0x52158827
Faulting module name: ntdll.dll, version: 6.3.9600.17278, time stamp: 0x53eeb4a3
Exception code: 0xc000000d
Fault offset: 0x000edae2
Faulting process id: 0x7de0
Faulting application start time: 0xrundll32.exe0
Faulting application path: rundll32.exe1
Faulting module path: rundll32.exe2
Report Id: rundll32.exe3
Faulting package full name: rundll32.exe4
Faulting package-relative application ID: rundll32.exe5
 
Error: (11/18/2014 00:45:51 PM) (Source: Application Hang) (User: )
Description: The program LiveComm.exe version 17.5.9600.20605 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 6094
 
Start Time: 01d0035f243367a3
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: 17d79185-6f53-11e4-beae-843497764075
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (11/18/2014 00:12:13 PM) (Source: Application Hang) (User: )
Description: The program LiveComm.exe version 17.5.9600.20605 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 7820
 
Start Time: 01d0035a651382da
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: 588ecc59-6f4e-11e4-beae-843497764075
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (11/18/2014 00:09:42 PM) (Source: Application Error) (User: )
Description: Faulting application name: rundll32.exe, version: 6.3.9600.16384, time stamp: 0x52158827
Faulting module name: ntdll.dll, version: 6.3.9600.17278, time stamp: 0x53eeb4a3
Exception code: 0xc000000d
Fault offset: 0x000edae2
Faulting process id: 0x1c80
Faulting application start time: 0xrundll32.exe0
Faulting application path: rundll32.exe1
Faulting module path: rundll32.exe2
Report Id: rundll32.exe3
Faulting package full name: rundll32.exe4
Faulting package-relative application ID: rundll32.exe5
 
Error: (11/18/2014 11:45:41 AM) (Source: Application Hang) (User: )
Description: The program LiveComm.exe version 17.5.9600.20605 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 4b08
 
Start Time: 01d00356c27336a4
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: b5f2f1ea-6f4a-11e4-beae-843497764075
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (11/18/2014 11:16:10 AM) (Source: Application Hang) (User: )
Description: The program LiveComm.exe version 17.5.9600.20605 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 23c4
 
Start Time: 01d00352918cbeec
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: 850819d0-6f46-11e4-beae-843497764075
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (11/18/2014 10:45:41 AM) (Source: Application Hang) (User: )
Description: The program LiveComm.exe version 17.5.9600.20605 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: db0
 
Start Time: 01d0034e60aaa2f5
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: 54362d52-6f42-11e4-beae-843497764075
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
 
System errors:
=============
Error: (11/18/2014 01:52:52 PM) (Source: DCOM) (User: CLC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/18/2014 01:52:52 PM) (Source: DCOM) (User: CLC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/18/2014 01:52:47 PM) (Source: DCOM) (User: CLC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/18/2014 01:52:47 PM) (Source: DCOM) (User: CLC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/18/2014 06:40:59 AM) (Source: Service Control Manager) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the scores service.
 
Error: (11/17/2014 11:26:46 PM) (Source: DCOM) (User: CLC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
 
Error: (11/17/2014 02:42:49 PM) (Source: Tcpip) (User: )
Description: The system detected an address conflict for IP address 192.168.1.101 with the system
having network hardware address B0-05-94-C1-F9-41. Network operations on this system may
be disrupted as a result.
 
Error: (11/17/2014 08:11:12 AM) (Source: DCOM) (User: CLC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/17/2014 08:11:12 AM) (Source: DCOM) (User: CLC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/17/2014 00:22:40 AM) (Source: DCOM) (User: CLC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
 
Microsoft Office Sessions:
=========================
 
CodeIntegrity Errors:
===================================
  Date: 2014-11-18 16:11:34.249
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-18 16:10:53.746
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-18 16:10:40.832
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-18 16:10:27.405
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-18 13:51:01.131
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-18 13:48:58.146
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-18 13:47:45.121
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-18 13:47:39.369
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-18 13:46:39.204
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-18 13:46:06.827
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system.
 
 
 
=========================== Installed Programs ============================
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.4.5527 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.5.4.5527 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Star (HKLM\...\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.101 - Google Inc.)
Hewlett-Packard ACLM.NET v1.2.0.0 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{F244D07D-1876-4CDD-914D-214E15A8D327}) (Version: 4.2.5.1 - Hewlett-Packard Company)
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd)
HP CoolSense (HKLM-x32\...\{16B7BDA1-B967-4D2D-8B27-E12727C28350}) (Version: 2.10.3 - Hewlett-Packard Company)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Documentation (HKLM-x32\...\{D044EBE7-94E7-4C49-90FC-9069E3F374E1}) (Version: 1.1.0.0 - Hewlett-Packard)
HP MyRoom (HKLM-x32\...\{9C35EDE5-4B0F-45E7-A438-314BA889948E}) (Version: 9.0.0.0 - Hewlett-Packard Company)
HP Postscript Converter (Version: 3.1.3554 - Hewlett-Packard) Hidden
HP Quick Launch (HKLM-x32\...\{609B11CC-8CED-4116-AD8A-A72168894D39}) (Version: 3.0.4 - Hewlett-Packard Company)
HP Recovery Manager (x32 Version: 7.00 - Hewlett-Packard) Hidden
HP Registration Service (HKLM\...\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}) (Version: 1.0.5976.4186 - Hewlett-Packard)
HP Software Framework (HKLM-x32\...\{835B275B-F29B-464B-BD4B-097FD55FAB0A}) (Version: 4.6.8.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{B8019B54-F9BE-490A-9619-6D06F18F129F}) (Version: 7.0.32.44 - Hewlett-Packard Company)
HP Utility Center (HKLM-x32\...\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.7 - Hewlett-Packard)
HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.5.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6417.0 - IDT)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
magicJack (HKCU\...\magicJack) (Version: 2.0.6073.4413 - magicJack L.P.)
magicJack Recovery Tool 1.0 (HKLM-x32\...\magicJack Recovery Tool_is1) (Version:  - magicJack, L.P.)
Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (Version: 2.2.173.0 - Microsoft Corporation) Hidden
Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 31.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MWSnap 3 (HKLM-x32\...\MWSnap 3) (Version: 3.0.0.74 - Mirek Wojtowicz)
Programmer's Notepad (HKLM-x32\...\{52CF142B-7B0E-41E7-98F5-B834122523E7}_is1) (Version: 2.3.4.2350 - Simon Steele)
Qualcomm Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Qualcomm Atheros)
RealDownloader (x32 Version: 17.0.6 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.6 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.16.31.75 - Client Connect LTD)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.12 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.27614 - TeamViewer)
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version:  - Elaborate Bytes)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
????? (HKLM-x32\...\IQIYI Video) (Version:  - ???)
 
========================= Memory info: ===================================
 
Percentage of memory in use: 67%
Total physical RAM: 3993.28 MB
Available physical RAM: 1278.71 MB
Total Pagefile: 6934.87 MB
Available Pagefile: 3821.83 MB
Total Virtual: 4095.88 MB
Available Virtual: 3984.3 MB
 
========================= Partitions: =====================================
 
1 Drive c: () (Fixed) (Total:439.45 GB) (Free:347.43 GB) NTFS
2 Drive d: (RECOVERY) (Fixed) (Total:25.1 GB) (Free:2.86 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\CLC
 
Administrator            Chie                     chiecheng1012            
CLC168                   Guest                    
 
 
**** End of log ****


#4 ace17

ace17
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 05:31 PM

# AdwCleaner v4.101 - Report created 18/11/2014 at 16:26:20
# Updated 09/11/2014 by Xplode
# Database : 2014-11-16.1 [Live]
# Operating System : Windows 8.1  (64 bits)
# Username : chiecheng1012 - CLC
# Running from : C:\Users\chiecheng1012\Desktop\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
Service Deleted : Scores
[#] Service Deleted : SMUpd
[#] Service Deleted : SMUpdd
[#] Service Deleted : SPBIUpd
[#] Service Deleted : SPBIUpdd
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\baidu
Folder Deleted : C:\ProgramData\ParetoLogic
Folder Deleted : C:\ProgramData\WorldWideWebCoupon
Folder Deleted : C:\ProgramData\PriceeDOwaNlOader
Folder Deleted : C:\ProgramData\SAverPProo
Folder Deleted : C:\ProgramData\20eaea0899bf680e
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
Folder Deleted : C:\Program Files (x86)\Advanced System Protector
Folder Deleted : C:\Program Files (x86)\baidu
Folder Deleted : C:\Program Files (x86)\Bench
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\predm
Folder Deleted : C:\Program Files (x86)\RegClean Pro
Folder Deleted : C:\Program Files (x86)\SearchProtect
Folder Deleted : C:\Program Files (x86)\ShopperPro
Folder Deleted : C:\Program Files (x86)\Systweak Support Dock
Folder Deleted : C:\Program Files (x86)\Web Protect
Folder Deleted : C:\Program Files (x86)\WinZip Registry Optimizer
Folder Deleted : C:\Program Files (x86)\PriceeDOwaNlOader
Folder Deleted : C:\Program Files (x86)\SAverPProo
Folder Deleted : C:\Program Files (x86)\Common Files\baidu
Folder Deleted : C:\Users\chiecheng1012\AppData\Local\globalUpdate
Folder Deleted : C:\Users\chiecheng1012\AppData\Local\CrashRpt
Folder Deleted : C:\Users\chiecheng1012\AppData\LocalLow\baidu
Folder Deleted : C:\Users\chiecheng1012\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\chiecheng1012\AppData\LocalLow\mystarttb
Folder Deleted : C:\Users\chiecheng1012\AppData\Roaming\baidu
Folder Deleted : C:\Users\chiecheng1012\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\chiecheng1012\AppData\Roaming\ParetoLogic
Folder Deleted : C:\Users\chiecheng1012\AppData\Roaming\Systweak
Folder Deleted : C:\Users\Public\Documents\ShopperPro
Folder Deleted : C:\Users\chiecheng1012\AppData\Roaming\Mozilla\Firefox\Profiles\45hgdb2o.default\Extensions\ii@qsiaoi.co.uk
Folder Deleted : C:\Users\chiecheng1012\AppData\Roaming\Mozilla\Firefox\Profiles\45hgdb2o.default\Extensions\juz-0sm@yiasbmpb.com
Folder Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
File Deleted : C:\END
File Deleted : C:\Users\Public\Desktop\eBay.lnk
File Deleted : C:\WINDOWS\score.exe
File Deleted : C:\WINDOWS\System32\roboot64.exe
File Deleted : C:\Users\Chie\Desktop\PepperZip.lnk
File Deleted : C:\Users\Chie\Desktop\FastPlayer.lnk
File Deleted : C:\Users\chiecheng1012\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Funshion.lnk
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage-journal
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage-journal
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage-journal
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Deleted : C:\Users\chiecheng1012\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
 
***** [ Scheduled Tasks ] *****
 
Task Deleted : LaunchSignup
Task Deleted : SPDriver
Task Deleted : YTDownloader
 
***** [ Shortcuts ] *****
 
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\chiecheng1012\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\chiecheng1012\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc
Key Deleted : HKLM\SOFTWARE\Classes\SauverrPrro.SauverrPrro
Key Deleted : HKLM\SOFTWARE\Classes\SauverrPrro.SauverrPrro.4.31
Key Deleted : HKLM\SOFTWARE\Classes\PPriceDownloaudEr.PPriceDownloaudEr
Key Deleted : HKLM\SOFTWARE\Classes\PPriceDownloaudEr.PPriceDownloaudEr.2.4
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289663
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1E1A4EA1-99CE-1701-5323-01D8D5B6A2A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5574D46B-4BD8-A640-D67B-AC45DD938921}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DA624F8F-98BF-4B03-AD11-A12D07119E81}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1E1A4EA1-99CE-1701-5323-01D8D5B6A2A3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E1A4EA1-99CE-1701-5323-01D8D5B6A2A3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1E1A4EA1-99CE-1701-5323-01D8D5B6A2A3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5574D46B-4BD8-A640-D67B-AC45DD938921}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{1E1A4EA1-99CE-1701-5323-01D8D5B6A2A3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5574D46B-4BD8-A640-D67B-AC45DD938921}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Deleted : HKCU\Software\Compete
Key Deleted : HKCU\Software\distromatic
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\ShopperPro
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\CompeteInc
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\ParetoLogic
Key Deleted : HKLM\SOFTWARE\ShopperPro
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\Tutorials
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\WebProtect
Key Deleted : HKLM\SOFTWARE\XTRM Group Ltd.
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2D471A31-4FA7-95BA-1880-D441113ED736}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : [x64] HKLM\SOFTWARE\iWebar-nv
Key Deleted : [x64] HKLM\SOFTWARE\ShopperPro
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17416
 
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
 
-\\ Mozilla Firefox v31.0 (x86 en-US)
 
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "Web Search");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Web Search");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.PIlkJgBZPH.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"sumor[...]
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.SBF_0.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"sumorobo.n[...]
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.DockingPositionDown", false);
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.SmartbarDisabled", false);
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.Visibility", false);
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.backPageCapacity", 3);
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.backPageCounter", 0);
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.backPageDay", 15);
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.backPageLastEvent", "1413247050738");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.backPageMinInterval", 15);
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.barcodeid", "151115");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.countryiso", "us");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.downloadprovider", "ob_316");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[\\\"snap.do\\\",\\\"snapdo.com\\\",\\\".search.yahoo.com\\\\\\/yhs\\\\\\/search?hspart=lkry\\\",\\\"www.only-apart[...]
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.fromautoupdate", "false");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.installationid", "4ddc1640-a711-c428-fefc-16f9558497d9");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.installdate", "15/10/2014");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.iswinxp", "false");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.keepAliveLastevent", "1413419850");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.lastExternalJsUpdate", "1413419919867");
[45hgdb2o.default\prefs.js] - Line Deleted : user_pref("extensions.helperbar.publisher", "shoppinghelper");
 
-\\ Google Chrome v38.0.2125.101
 
 
*************************
 
AdwCleaner[R0].txt - [13481 octets] - [18/11/2014 16:22:26]
AdwCleaner[S0].txt - [13557 octets] - [18/11/2014 16:26:20]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13618 octets] ##########


#5 ace17

ace17
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 05:39 PM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.9 (11.15.2014:2)
OS: Windows 8.1 x64
Ran by chiecheng1012 on Tue 11/18/2014 at 16:34:12.88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCEB8456-DF6E-4D76-86E2-A6C9CF274CFC}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{CCEB8456-DF6E-4D76-86E2-A6C9CF274CFC}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCEB8456-DF6E-4D76-86E2-A6C9CF274CFC}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{CCEB8456-DF6E-4D76-86E2-A6C9CF274CFC}
 
 
 
~~~ Files
 
Successfully deleted: [File] "C:\Users\chiecheng1012\appdata\local\google\chrome\user data\default\local storage\http_static.boostsaves.com_0.localstorage"
Successfully deleted: [File] "C:\Users\chiecheng1012\appdata\local\google\chrome\user data\default\local storage\http_static.boostsaves.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\chiecheng1012\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\chiecheng1012\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\chiecheng1012\appdata\local\google\chrome\user data\default\local storage\https_static.boostsaves.com_0.localstorage"
Successfully deleted: [File] "C:\Users\chiecheng1012\appdata\local\google\chrome\user data\default\local storage\https_static.boostsaves.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\chiecheng1012\funshion.ini"
Successfully deleted: [File] C:\WINDOWS\prefetch\BAIDUSD.EXE-F817479C.pf
Successfully deleted: [File] "C:\WINDOWS\wininit.ini"
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\chiecheng1012\appdata\local\{3B9CF165-051A-4879-AF99-B70422D1274C}
 
 
 
~~~ FireFox
 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@baidu.com/npxbdsetup
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 11/18/2014 at 16:37:54.25
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#6 ace17

ace17
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 08:29 PM

C:\AdwCleaner\Quarantine\C\WINDOWS\System32\roboot64.exe.vir a variant of Win64/Systweak.A potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\195496.exe.exe Win32/Adware.1ClickDownload.AX application cleaned by deleting - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\Astroupdate.exe a variant of Win32/DealPly.U potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\ConsumerInputSetup.exe Win32/Compete.A potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\D114.tmp a variant of Win32/Conduit.SearchProtect.N potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\ICReinstall_nsb3AED.tmp a variant of Win32/InstallCore.PK potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\ICReinstall_nsr717F.tmp a variant of Win32/InstallCore.PK potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\ICReinstall_nsvD488.tmp a variant of Win32/InstallCore.PK potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\nsb3AED.tmp a variant of Win32/InstallCore.PK potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\nsr717F.tmp a variant of Win32/InstallCore.PK potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\nsr8C77.tmp a variant of Win32/InstallCore.PK potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\nsvD488.tmp a variant of Win32/InstallCore.PK potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\optprosetup.exe multiple threats cleaned by deleting - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\PartnerInstaller_adk.exe a variant of Win32/SpeedBit.D potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\post1.exe a variant of Win32/Adware.AddLyrics.CL application cleaned by deleting - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\rt9EqtRyZn.exe a variant of MSIL/Adware.iBryte.J application cleaned by deleting - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\tu17p84.exe a variant of Win32/SBWatchman.D potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\__tmp_34c256dc a variant of Win32/SProtector.I potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\DAE2tmp\speedupmypc.exe Win32/SpeedUpMyPC.A potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\DAF8tmp\fastplayersetup.exe JS/Superfish.A potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\DAF9tmp\cloud_backup_setup.exe Win32/MyPCBackup.A potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\DB2Atmp\setup_ospd_us.exe multiple threats cleaned by deleting - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\Install_6904\shopperpro.exe a variant of Win32/SpeedBit.D potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\Install_6904\ytd.exe a variant of Win32/SBWatchman.D potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\is-86KJ3.tmp\gentlemjospd_ius.exe Win32/AdWare.EoRezo.AW application cleaned by deleting - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\is-CK88H.tmp\SpeedUpMyPC-standalone-setup.exe Win32/SpeedUpMyPC.B potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\is-K7686.tmp\xml_package_groovorio_installer_multilang.exe Win32/AdWare.EoRezo.AW application cleaned by deleting - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\is45637729\122134073_stp\Generic_vo.exe Win32/VOPackage.X potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\is45637729\122219963_stp\Generic_vo.exe Win32/VOPackage.X potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\is45637729\123426233_stp\Generic_vo.exe Win32/VOPackage.X potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll a variant of MSIL/Toolbar.Linkury.I potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\Smartbar.Resources.LanguageSettings.resources.dll a variant of MSIL/Toolbar.Linkury.E potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\spbe.dll a variant of MSIL/Toolbar.Linkury.I potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\spbl.dll a variant of MSIL/Toolbar.Linkury.G potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\sppsm.dll a variant of MSIL/Toolbar.Linkury.G potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\spusm.dll a variant of MSIL/Toolbar.Linkury.G potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\srbs.dll a variant of MSIL/Toolbar.Linkury.C potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\srbu.dll a variant of MSIL/Toolbar.Linkury.F potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\srptc.dll a variant of MSIL/Toolbar.Linkury.G potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\AppData\Local\Temp\MSIB00D.tmp-\srpu.dll a variant of MSIL/Toolbar.Linkury.I potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\Documents\APNSetup.exe a variant of Win32/Bundled.Toolbar.Ask.E potentially unsafe application deleted - quarantined
C:\Users\chiecheng1012\Downloads\setup (1).exe a variant of Win32/AdGazelle.B potentially unwanted application deleted - quarantined
C:\Users\chiecheng1012\Downloads\xiguaplayer.exe a variant of Win32/FlyStudio.Packed.AD potentially unwanted application deleted - quarantined


#7 ace17

ace17
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 08:31 PM

I have completed all of the listed steps but I'm still seeing some pop ups and ads when browsing. Certain words automatically turn into links for example words like "download" and "install" and "windows". I'm also getting random tabs opening without my command.



#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:22 AM

Posted 18 November 2014 - 08:40 PM

What is your browser?

ESET was clean?

Edited by boopme, 18 November 2014 - 08:41 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 ace17

ace17
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 08:44 PM

ESET found and cleaned 43 issues. This is on chrome. When I open internet explorer something pops up saying "A website wants to open web content using this program on your computer" the name is "RealDownloader" and the publisher is "RealNetworks, Inc."



#10 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:22 AM

Posted 18 November 2014 - 08:59 PM

About RealDownloader  is popular tool that helps you store your favorite videos from more than 100 web sites such as YouTube or Vimeo.

Looks like you have some of these installed and if so perhaps it wants to update.

RealDownloader (x32 Version: 17.0.6 - RealNetworks, Inc.) Hidden

RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden

RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden

RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden

RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.6 - RealNetworks)

>>>>>>>

Possibly one of Chromes Plug-ins is causing the redirect/popups... Disable them and see

How To Disable Individual Plug-ins in Google Chrome
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#11 ace17

ace17
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 09:11 PM

i've tried disabling the chrome plugins but i'm still getting redirects to irrelevant websites when i try to click and there are still ads that pop up on the side. For example it just redirected me to naolabo dot com



#12 ace17

ace17
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 09:13 PM

on the side it says "ads by info" and there's an ad that pops up to "call for great tech support"



#13 ace17

ace17
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 18 November 2014 - 09:18 PM

i just tried on firefox and the same issues are happening on firefox as well



#14 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:22 AM

Posted 18 November 2014 - 09:32 PM

Appears then we need a deeper look to find what's protecting it.

Please follow this Preparation Guide, do steps 6,7 and 8 and post in a new topic.
Let me know if all went well.

But instead of DDS as it will not run on Win 8.1 use RSIT ..

Please download RSIT by random/random from the link provided for your operating system and save it to your desktop.This tool needs to run while the computer is connected to the Internet. If you get a warning from your firewall or other security programs regarding RSIT attempting to contact the Internet, please allow the connection.
  • Close all applications and windows so that you have nothing open and are at your Desktop.
  • Double-click on RSIT.exe to start the program.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • Read the disclaimer and click Continue.
  • When the scan is complete, a text file named log.txt will automatically open in Notepad.
  • Another text file named info.txt will open minimized.
  • Save the log files to your desktop and copy/paste the contents of log.txt by highlighting everything and pressing Ctrl+C.
  • After highlighting, right-click, choose Copy and then paste the contents into a new topic in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here.
  • Copies of both log files are automatically saved in the C:\RSIT folder which the tool creates during the scan.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users