Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

AOL Computer Checkup


  • Please log in to reply
24 replies to this topic

#1 SusanJD

SusanJD

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:44 AM

Posted 04 January 2015 - 04:03 PM

Being new to the site, I may have posted this in the wrong place; if so, please would someone move it? Thank you.

 

Does anyone know anything about AOL Computer Checkup?

 



BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,516 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:44 AM

Posted 04 January 2015 - 04:19 PM

Welcome to BC !

 

It says it removes temporary files, cookies and cleans the registry. That tells me it is worthless and possibly

very risky to use. BC does not recommend the use of the many registry cleaners. I would bet it comes with adware, too.

 

If you are having a problem, someone here can definitely help you with it.

 

A very good program to use to delete temporary files, cookies, clean logs, cache files and has other useful tools

is CCleaner. Just pay close attention while installing and UNcheck any offers of toolbars...especially Google's.

Use the default settings. After install click on the button in bottom right corner to run the cleaner. Explore the

tools on the left such as find out what is in your Windows startups, browser startups and Tasks.

CCleaner - PC Optimization and Cleaning - Free Download


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 SusanJD

SusanJD
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:44 AM

Posted 04 January 2015 - 04:25 PM

Thank you, that is very helpful.



#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 52,090 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:44 AM

Posted 04 January 2015 - 07:08 PM

AOL Computer Checkup is software which claims to be a comprehensive optimization suite with registry cleaning capability that purports to improve performance, make repairs and enhance the speed of a computer. The optimization and performance improvement claims made by such software vendors are borderline scams. There is no statistical evidence to back such claims. Advertisements to do so are a marketing ploy intended to goad users into using an unnecessary and potential dangerous product. I would not trust any results such programs detect as problematic or needing repair nor recommend using the options to fix them.

AOL Checkup is offered as a 30-day free trial...then you have to pay $4.99 a month. Although the software also offers backup & recovery features for deleted files and a File Encryption tool, there are free alternatives which can do the same. As already noted by buddy215...

 

Bleeping Computer DOES NOT recommend the use of registry cleaners/optimizers for several reasons.

Why you should not use Registry Cleaners and Optimization Tools


Be sure to read Microsoft's support policy for the use of registry cleaning utilities in that topic...Microsoft does not support the use of registry cleaners.


.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#5 buddy215

buddy215

  • Moderator
  • 13,516 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:44 AM

Posted 04 January 2015 - 07:25 PM

If you are looking for an online storage program then I suggest you consider online email accounts. I use a few

and back up what is important to at least two email providers such as Gmail, Outlook and Yahoo. All free and tons

of storage space.

 

You are welcome....


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#6 SusanJD

SusanJD
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:44 AM

Posted 05 January 2015 - 03:52 AM

Thank you.

We are happy with our email system.

We had received an email from AOL (UK) Limited inviting us to try the 90 day free trial; we accepted the free trial but then remembered that a while ago a relative recommended bleepingcomputer.com so decided to ask here for advice.



#7 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 52,090 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:44 AM

Posted 05 January 2015 - 06:54 AM

You can cancel free trials at any time which in this case I would recommend you do.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#8 buddy215

buddy215

  • Moderator
  • 13,516 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:44 AM

Posted 05 January 2015 - 07:48 AM

If you gave them CC info I suggest you cancel as soon as possible. Online free trials requiring CC info are notorious for

being difficult to cancel and some will still charge you.

 

Suggest you run a scan using AdwCleaner. Here are the directions to use.

  • download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#9 SusanJD

SusanJD
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:44 AM

Posted 05 January 2015 - 09:03 AM

Thank you. I have clicked on report but none of it means a thing to me - what do I do now, please?

 

Shall I click on the clean button or send a copy of it to you in a message?


Edited by SusanJD, 05 January 2015 - 09:12 AM.


#10 buddy215

buddy215

  • Moderator
  • 13,516 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:44 AM

Posted 05 January 2015 - 09:29 AM

Click on the clean button which will remove all the adware. A reboot is required to complete the removal.

 

  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#11 SusanJD

SusanJD
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:44 AM

Posted 05 January 2015 - 09:43 AM

Thank you. All done, and this has appeared:

 

# AdwCleaner v4.106 - Report created 05/01/2015 at 14:37:36
# Updated 21/12/2014 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Windows Vista ™ Home Premium Service Pack 2 (32 bits)
# Username : joy - JOY-PC
# Running from : C:\Users\joy\Downloads\adwcleaner_4.106 (1).exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\~0
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\DriverCure
Folder Deleted : C:\ProgramData\IBUpdaterService
Folder Deleted : C:\ProgramData\ParetoLogic
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\UpdateCommon
Folder Deleted : C:\ProgramData\PC Drivers HeadQuarters
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\xVidly
Folder Deleted : C:\Users\joy\AppData\Local\Babylon
Folder Deleted : C:\Users\joy\AppData\Local\Conduit
Folder Deleted : C:\Users\joy\AppData\Local\PackageAware
Folder Deleted : C:\Users\joy\AppData\Local\PerformerSoft
Folder Deleted : C:\Users\joy\AppData\Local\SearchProtect
Folder Deleted : C:\Users\joy\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\joy\AppData\LocalLow\Delta
Folder Deleted : C:\Users\joy\AppData\LocalLow\HPAppData
Folder Deleted : C:\Users\joy\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\joy\AppData\Roaming\7go
Folder Deleted : C:\Users\joy\AppData\Roaming\BabSolution
Folder Deleted : C:\Users\joy\AppData\Roaming\Babylon
Folder Deleted : C:\Users\joy\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\joy\AppData\Roaming\HPAppData
Folder Deleted : C:\Users\joy\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\joy\AppData\Roaming\ParetoLogic
Folder Deleted : C:\Users\joy\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\joy\AppData\Roaming\SpeedAnalysis2
Folder Deleted : C:\Users\joy\Documents\drivergenius
File Deleted : C:\END
File Deleted : C:\Windows\system32\roboot.exe
File Deleted : C:\Users\joy\AppData\Roaming\speedanalysis.ico
File Deleted : C:\Users\joy\AppData\Roaming\Mozilla\Firefox\Profiles\3k9n49r8.default\invalidprefs.js
File Deleted : C:\Users\joy\AppData\Roaming\Mozilla\Firefox\Profiles\3k9n49r8.default\searchplugins\Babylon.xml
File Deleted : C:\Users\joy\AppData\Roaming\Mozilla\Firefox\Profiles\3k9n49r8.default\searchplugins\BrowserProtect.xml
File Deleted : C:\Users\joy\AppData\Roaming\Mozilla\Firefox\Profiles\3k9n49r8.default\searchplugins\Conduit.xml
 
***** [ Scheduled Tasks ] *****
 
Task Deleted : PC Performer
Task Deleted : PC Performer_DEFAULT
Task Deleted : PC Performer_UPDATES
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dgjkhjdcljddbedokogakmmdjgnbeanf
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\gjajpkikblccgefaibcafkfbanllpefi
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\PropertySync.EXE
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 2.BackgroundHostObject
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 2.BackgroundHostObject.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Key Deleted : HKLM\SOFTWARE\5a53da8fb66fba40
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{19975B78-1907-4DD6-A437-4C48120F46A4}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{562B9317-C08A-444A-9482-62080DD851AE}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EB93AADE-9884-47F0-AA9D-0920E1D1203F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BB30FEA7-5866-406A-B47D-FB69E1AF8FD7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DBB6CE-3148-4FEC-B481-103CB3290427}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DBB6CE-3148-4FEC-B481-103CB3290427}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E6547E-325B-403C-A3BB-AD29ED37A92F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B0DE3308-5D5A-470D-81B9-634FC078393B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{F4E6547E-325B-403C-A3BB-AD29ED37A92F}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{F4E6547E-325B-403C-A3BB-AD29ED37A92F}]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Deleted : HKCU\Software\BABSOLUTION
Key Deleted : HKCU\Software\BabylonToolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DataMngr
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\filescout
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\PerformerSoft
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\Toolbar
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\Driver-Soft
Key Deleted : HKLM\SOFTWARE\Freeze.com
Key Deleted : HKLM\SOFTWARE\InstallIQ
Key Deleted : HKLM\SOFTWARE\ParetoLogic
Key Deleted : HKLM\SOFTWARE\PerformerSoft
Key Deleted : HKLM\SOFTWARE\Tarma Installer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{471D8B37-C5B3-4457-9FA1-B3C693334F4F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows5.0.0.0
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ask Toolbar_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PC Performer_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Speed Analysis 2
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{471D8B37-C5B3-4457-9FA1-B3C693334F4F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Coupon Printer for Windows5.0.0.0
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v7.0.6002.18005
 
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs]
 
-\\ Mozilla Firefox v29.0.1 (en-US)
 
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.FF19Solved", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.UserID", "UN25399893841375885");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.addressUrlXPETakeover", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.autoDisableScopes", -1);
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.browser.search.defaultthis.engineName", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.defaultSearchXPETakeover", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.installDate", "4/5/2013 12:54:18");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.installSessionId", "-1");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.installSp", "TRUE");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.installerVersion", "1.4.1.3");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.keyword", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.searchRevert", "FALSE");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.searchUserMode", "2");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.smartbar.homepage", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.startPageXPETakeover", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3293887.versionFromInstaller", "10.15.2.23");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3295548.FF19Solved", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3295548.UserID", "UN31044786502092430");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3295548.autoDisableScopes", 10);
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3295548.browser.search.defaultthis.engineName", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3295548.defaultSearchXPETakeover", "true");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3295548.installDate", "4/5/2013 13:31:19");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("CT3295548.installerVersion", "1.3.7.3");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("extensions.7go@7go.com.mzID", "93");
[3k9n49r8.default\prefs.js] - Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
 
-\\ Google Chrome v39.0.2171.95
 
 
-\\ Opera v26.0.1656.60
 
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : aaipilfmheplbcghignccoiiebekkdhe
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : elchiiiejkobdbblfejjkbphbddgmljf
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : ffhfoagmjcnkolneahbpagjcjjaeofbg
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : hjghiofiijcepdnocbgefbdlbckjfheg
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : iklgpchfbohgmghgfagediakopecfmbm
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : kfgaibfbmkjgmimhbbaikfnpkkjkpoan
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : lmnbobhffedhdhfpcjkjphcfpeeiocdn
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : kjpifmjicccpbkfjdkehimhgklfkbanh
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : hoidflomjnnnbiemmkjdjkkialmhbago
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : ekpibplnnkfdcafdpoekhoffegcajene
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : ipljmghelflfikejmgkmlmpjmehfjodc
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : ejddjnilmdncjilbfjgameihlklfpohp
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : eagomcfjiefffhpaejnlpjccikpipdoe
[C:\Users\joy\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : aonedlchkbicmhepimiahfalheedjgbh
 
*************************
 
AdwCleaner[R0].txt - [14814 octets] - [05/01/2015 13:50:52]
AdwCleaner[R1].txt - [14879 octets] - [05/01/2015 14:33:38]
AdwCleaner[S0].txt - [15159 octets] - [05/01/2015 14:37:36]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15220 octets] ##########


#12 buddy215

buddy215

  • Moderator
  • 13,516 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:44 AM

Posted 05 January 2015 - 10:00 AM

That is a huge collection of adware. Strongly suggest you continue to clean the computer of other adware and malware.

The programs below are the most frequently recommended for use here at BC.

 

Download Malwarebytes' Anti-Malware from Here

Double-click mbam-setup-2.X.X.XXXX.exe to install the application (X's are the current version number).

  • Make sure a checkmark is placed next to Launch Malwarebytes' Anti-Malware, then click Finish.
  • Once MBAM opens, when it says Your databases are out of date, click the Fix Now button.
  • Click the Settings tab at the top, and then in the left column, select Detections and Protections, and if not already checked place a checkmark in the selection box for Scan for rootkits.
  • Click the Scan tab at the top of the program window, select Threat Scan and click the Scan Now button.
  • If you receive a message that updates are available, click the Update Now button (the update will be downloaded, installed, and the scan will start).
  • The scan may take some time to finish,so please be patient.
  • If potential threats are detected, ensure that Quarantine is selected as the Action for all the listed items, and click the Apply Actions button.
  • While still on the Scan tab, click the link for View detailed log, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
  • The log is automatically saved by MBAM and can also be viewed by clicking the History tab and then selecting Application Logs.

POST THE MBAM LOG FOR REVIEW.

 

Use CCleaner to remove Temporary files, program caches, cookies, logs, etc. Use the Default settings. No need to use the

Registry Cleaning Tool...risky. Pay close attention while installing and UNcheck offers of toolbars....especially Google.

After install, open CCleaner and run by clicking on the Run Cleaner button in the bottom right corner.

CCleaner - PC Optimization and Cleaning - Free Download

 

Download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Hold down Control and click on this link to open ESET OnlineScan in a new window. (Eset can take more than an hour to run so plan accordingly)

  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#13 SusanJD

SusanJD
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:44 AM

Posted 05 January 2015 - 11:30 AM

THE MBAM LOG FOR REVIEW.

 

Malwarebytes Anti-Malware

www.malwarebytes.org
 
Scan Date: 05/01/2015
Scan Time: 15:40:45
Logfile: MBAM LOG.txt
Administrator: Yes
 
Version: 2.00.4.1028
Malware Database: v2015.01.05.06
Rootkit Database: v2014.12.30.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: joy
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 324829
Time Elapsed: 31 min, 29 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 2
PUP.Optional.WiseConvert.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\cgiaikfpllchefojlnehlmpekeogihnm, Quarantined, [2dd4e287502cbb7bfa7bde976e951fe1], 
PUP.Optional.WiseConvert.A, HKU\S-1-5-21-3853519489-807770662-3182495173-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\cgiaikfpllchefojlnehlmpekeogihnm, Quarantined, [de23fd6c7b013ff7a9cd95e046bd6c94], 
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 21
Adware.DomaIQ, C:\Users\joy\Downloads\FlashPlayer_V.106022376c.exe, Quarantined, [8e73096080fc38fe2cc62b80fc0942be], 
Adware.DomaIQ, C:\Users\joy\Downloads\FlashPlayer_V.106023067c.exe, Quarantined, [788913567309e452c52de6c5d62fed13], 
PUP.Optional.DomaIQ, C:\Users\joy\Downloads\FlashPlayer_V.106055481c.exe, Quarantined, [c0411059e19b63d3b0cb768a53b29967], 
PUP.FakeFlash.Domaiq, C:\Users\joy\Downloads\FlashPlayer_V.160848617c.exe, Quarantined, [7a874821f983cb6b228634d3d72aa957], 
PUP.FakeFlash.Domaiq, C:\Users\joy\Downloads\FlashPlayer_V.160909051c.exe, Quarantined, [f9082d3c79036fc7159353b4ac55837d], 
PUP.FakeFlash.Domaiq, C:\Users\joy\Downloads\FlashPlayer_V.160909928c.exe, Quarantined, [4db4cb9e82fac670a503cb3ce31e7c84], 
Adware.Agent, C:\Users\joy\Downloads\FlvPlayerSetup.exe, Quarantined, [709171f86d0f32049e03395bf010728e], 
PUP.Optional.Domalq, C:\Users\joy\Downloads\Player Setup.exe, Quarantined, [cb36f178b0cc1e189b6dde7b8382bd43], 
PUP.Optional.OptimumInstaller.A, C:\Users\joy\Downloads\SoftwareUpdate (1).exe, Quarantined, [bf42d9906a128fa763b9fb73738ece32], 
PUP.Optional.OptimumInstaller.A, C:\Users\joy\Downloads\SoftwareUpdate.exe, Quarantined, [3cc5ea7f64185adc0517aec0f50c57a9], 
PUP.Optional.OutBrowse, C:\Users\joy\Downloads\setup (12).exe, Quarantined, [e21f79f084f8b08619367c79887c718f], 
PUP.Optional.SquareNet, C:\Users\joy\Downloads\setup (14).exe, Quarantined, [24dd40295428d85e447fd6f2cc3545bb], 
PUP.Optional.SquareNet, C:\Users\joy\Downloads\setup (15).exe, Quarantined, [13ee2e3bd7a5dc5a972c5f698a77c43c], 
PUP.Optional.SquareNet, C:\Users\joy\Downloads\setup (16).exe, Quarantined, [c63b93d6eb91191de8db23a524ddef11], 
PUP.Optional.DomaIQ, C:\Users\joy\Downloads\Setup (17).exe, Quarantined, [33ce6efbc4b8d066303d7dd9b44c32ce], 
PUP.Optional.DomaIQ, C:\Users\joy\Downloads\Setup (18).exe, Quarantined, [768b9ecbb4c894a2bf17fff304fd8c74], 
PUP.Optional.IBryte.A, C:\Users\joy\Downloads\Setup (2).exe, Quarantined, [6b96acbd611bd75fa847c85fdd246d93], 
PUP.Optional.IBryte.A, C:\Users\joy\Downloads\Setup (3).exe, Quarantined, [e021b8b17ffdd85e7d7213144eb31be5], 
PUP.Optional.BundleInstaller.A, C:\Users\joy\Downloads\Setup (4).exe, Quarantined, [dd24fd6c7a0255e1d39da57f22de8c74], 
PUP.Optional.BundleInstaller.A, C:\Users\joy\Downloads\Setup (5).exe, Quarantined, [34cdcd9cc2ba191dc2ae27fdb14f6f91], 
PUP.Optional.DomaIQ, C:\Users\joy\Downloads\Setup (6).exe, Quarantined, [18e91c4dc2ba3bfb69d7a2a47d8445bb], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)


#14 SusanJD

SusanJD
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:44 AM

Posted 05 January 2015 - 12:04 PM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows Vista ™ Home Premium x86
Ran by joy on 05/01/2015 at 16:49:10.75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
Successfully deleted [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\bProtectTabs
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\Windows\System32\Tasks\Driver Booster SkipUAC (joy)
Successfully deleted: [File] "C:\Windows\couponprinter.ocx"
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\Users\joy\AppData\Roaming\fixcleaner"
Successfully deleted: [Folder] "C:\Users\joy\AppData\Roaming\getrighttogo"
Successfully deleted: [Folder] "C:\Users\joy\Local Settings\Application Data\cre"
Successfully deleted: [Folder] "C:\Program Files\coupons"
Successfully deleted: [Folder] "C:\Program Files\fixcleaner"
Successfully deleted: [Empty Folder] C:\Users\joy\appdata\local\{2E50B1C9-EF40-47EA-B10C-416FB373189D}
Successfully deleted: [Empty Folder] C:\Users\joy\appdata\local\{46AEE62F-3437-4824-A3FA-8F9A68BA7101}
Successfully deleted: [Empty Folder] C:\Users\joy\appdata\local\{6494A0F9-22CD-44CC-A20F-C0C692A33A1F}
Successfully deleted: [Empty Folder] C:\Users\joy\appdata\local\{9F28665E-0AEA-4E6D-A416-6D8471926CE4}
Successfully deleted: [Empty Folder] C:\Users\joy\appdata\local\{CB4796C3-6C85-41E9-B6AE-6B58544912A0}
 
 
 
~~~ FireFox
 
Emptied folder: C:\Users\joy\AppData\Roaming\mozilla\firefox\profiles\3k9n49r8.default\minidumps [5 files]
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05/01/2015 at 16:54:12.24
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#15 buddy215

buddy215

  • Moderator
  • 13,516 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:44 AM

Posted 05 January 2015 - 12:13 PM

The Eset scan will take more than an hour...possibly a few hours...depending on computer resources and volume of

programs and data stored. It is definitely worth the time. Allowing it full use of the computer will decrease the scan time.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users