Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Strange things starting up with computer start up


  • Please log in to reply
8 replies to this topic

#1 Twinmum

Twinmum

  • Members
  • 118 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:49 PM

Posted 06 January 2015 - 05:36 AM

Oh dear, just recently got my daughter's computer cleaned of maleware and now mine.

 

So I have picked up a nasty and need help in bannishing it from my computer.

I have three things that open when I start the computer that I can't seem to get rid of. (see inclosed pic) There is also one (possibly two) desktop icons that should not be there. I'm also getting a box pop up in the bottom right of the screen in Japanese.

 

I've run malwarebytes Anti malware and it quarenteened a number if threats, but these things still persist after shutting down and re starting. I've right clicked on the desktop icon that I know shouldn't be there (it's in japanese ) and selected the shred with AVG option, but it tells me it cannot shred it. I've gone to the folder it's in and tried to delete that, but again, it won't let me. I've also tried to uninstal it through the control panel, but when I click the uninstall button, it comes up with a box with three option buttons all in Japanese. I have no idea what they say, so I'm not about to click any of them lol

 

So I'd be very grateful if someone can help me get rid of this.

 

TIA

Norma

 

startup_zps0071d7bf.jpg

 

 



BC AdBot (Login to Remove)

 


m

#2 buddy215

buddy215

  • BC Advisor
  • 12,610 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:49 AM

Posted 06 January 2015 - 06:56 AM

Try using the Revo pro uninstaller. It has a free version but I think using the 30 day Trial pro version is advisable. Use the

Advanced Mode. Of course, you can try the free version first....your option.

Instructions and capabilities: Revo Uninstaller Pro - Uninstaller

Download: Download Revo Uninstaller Freeware - Free and Full Download - Uninstall software, remove programs, solve uninstall problems

 

I don't know if AdwCleaner or Junkware Remover Tool is finding and removing that unknown to me program. Worth a try and 

you likely have other adware needing cleaning up.

 

  • download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

Download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Last but advisable to use to find not only adware but malware, too:

Hold down Control and click on this link to open ESET OnlineScan in a new window. (Eset can take more than an hour to run so plan accordingly)

  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#3 Twinmum

Twinmum
  • Topic Starter

  • Members
  • 118 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:49 PM

Posted 06 January 2015 - 07:02 AM

Thanks buddy215. It's almost 11pm here now, so I will do this in the morning and reply with the results.



#4 Twinmum

Twinmum
  • Topic Starter

  • Members
  • 118 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:49 PM

Posted 06 January 2015 - 09:24 PM

buddy215

    I've run everything you have suggested and all the logs are here. However, nothing got rid of Kingsoft. Before I go on to the logs from all the scans, can I just share something I found this morning, I would appreciate your opinion on it.

I've done some searches on this Kingsoft Internet Security and it 'appears' to be a legitimate program (personally, I don't consider anything that needs to sneak in with another program to be legit!) Anyway, I found a lot of people complaining that they had a Chinese version and could not get rid of it. Some suggested Revo as you did, but unless you can read Chinese, that's not really helpful. Some suggestions were to open the program and select a particular tab and then click the right hand button, but I would like to know what it says before I click lol. Then the other suggestion that popped up was to download the English version which would over write the Chinese version allowing you to then remove it.  This sounds like a sound idea, but I thought I would wait until you have looked over my scan logs and such to see if there is anything else  I can do.

 

Anyway, here are my results for the suggested scans.

 

I ran the Revo uninstaller. Unfortunately, when I tried to uninstall the Kingsoft Internet Security (the icon in Chinese which I mistook for Japanese last night) the following uninstall box comes up in Chinese. I have no idea what anything says, so I'm reluctant to hit any of the buttons. I did remove one program that was installed last night which may or may not have been the host for it.

 

pic

 

I ran AdwCleaner and when it got to the point where it wanted to restart the computer, the following image popped up. I think it's some sort of warning. whatever it is, because I didn't know what it wanted me to do, I just closed it down using the x . However my computer did not shut down after, so I restarted it manually. The logfile didn't open automatically, so I had to go find it myself. This is it....

 

 

 

 

# AdwCleaner v3.004 - Report created 19/09/2013 at 12:11:45

# Updated 15/09/2013 by Xplode

# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

# Username : Norma - NORMA-PC

# Running from : B:\Users\Norma\Downloads\AdwCleaner.exe

# Option : Clean

 

***** [ Services ] *****

 

Service Deleted : WsysSvc

 

***** [ Files / Folders ] *****

 

Folder Deleted : C:\ProgramData\apn

Folder Deleted : C:\ProgramData\AVG Secure Search

Folder Deleted : C:\ProgramData\DealPlyLive

Folder Deleted : C:\ProgramData\eSafe

Folder Deleted : C:\ProgramData\StarApp

Folder Deleted : C:\ProgramData\safE savve

Folder Deleted : C:\ProgramData\Search-NewwTAAbu

Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search-NewwTAAbu

Folder Deleted : C:\Program Files (x86)\AVG Secure Search

Folder Deleted : C:\Program Files (x86)\DealPly

Folder Deleted : C:\Program Files (x86)\DealPlyLive

Folder Deleted : C:\Program Files (x86)\MyPC Backup

Folder Deleted : C:\Program Files (x86)\TornTV.com

Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search

Folder Deleted : C:\Users\Norma\AppData\Local\AVG Secure Search

Folder Deleted : C:\Users\Norma\AppData\Local\DealPlyLive

[!] Folder Deleted : C:\Users\Norma\AppData\Local\DProtect

Folder Deleted : C:\Users\Norma\AppData\Local\Temp\apn

Folder Deleted : C:\Users\Norma\AppData\Local\Temp\DProtect

Folder Deleted : C:\Users\Norma\AppData\Local\Temp\eIntaller

Folder Deleted : C:\Users\Norma\AppData\LocalLow\AVG Secure Search

Folder Deleted : C:\Users\Norma\AppData\LocalLow\Search-NewwTAAbu

Folder Deleted : C:\Users\Norma\AppData\Roaming\DealPly

Folder Deleted : C:\Users\Norma\AppData\Local\Google\Chrome\User Data\Default\Extensions\bccaipeefnadhjggmocpjhemgapddoga

Folder Deleted : C:\Users\Norma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nilhmkgjndmmdfgdnpinmdbcjhblichb

[!] Folder Deleted : C:\Users\Norma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nilhmkgjndmmdfgdnpinmdbcjhblichb

File Deleted : C:\Windows\Tasks\Dealply.job

File Deleted : C:\Windows\System32\Tasks\Dealply

 

***** [ Shortcuts ] *****

 

Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk

Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk

Shortcut Disinfected : C:\Users\Norma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

Shortcut Disinfected : C:\Users\Norma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk

Shortcut Disinfected : C:\Users\Norma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

Shortcut Disinfected : C:\Users\Norma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk

 

***** [ Registry ] *****

 

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bicnnkjibmphdeigoodpjlcklcnaobdj

Key Deleted : HKLM\SOFTWARE\Classes\AppID\PropertySync.EXE

Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE

Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL

Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol

Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi

Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1

Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool

Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1

Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE

Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1

Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]

Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin

Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc

Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0035382.BHO

Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0035382.BHO.1

Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0035382.Sandbox

Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0035382.Sandbox.1

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D25152AF-F40A-80E3-2A00-F23184273875}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311531182}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322532282}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{93CF54F5-CFAA-4440-B588-8ED0DFAD5C21}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D3BC53E7-0437-4C97-90EE-2CD6FF47FB14}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355535582}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366536682}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440344534482}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D25152AF-F40A-80E3-2A00-F23184273875}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311531182}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D25152AF-F40A-80E3-2A00-F23184273875}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311531182}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D25152AF-F40A-80E3-2A00-F23184273875}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311531182}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311531182}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}

Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}

Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}

Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}

Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command

Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command

Key Deleted : HKCU\Software\1ClickDownload

Key Deleted : HKCU\Software\AVG Secure Search

Key Deleted : HKCU\Software\Cr_Installer

Key Deleted : HKCU\Software\dealplylive

Key Deleted : HKCU\Software\InstallCore

Key Deleted : HKCU\Software\InstalledBrowserExtensions

Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider

Key Deleted : HKLM\Software\AVG Secure Search

Key Deleted : HKLM\Software\AVG Security Toolbar

Key Deleted : HKLM\Software\dealplylive

Key Deleted : HKLM\Software\eSafeSecControl

Key Deleted : HKLM\Software\qvo6Software

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSysControl

 

***** [ Browsers ] *****

 

-\\ Internet Explorer v10.0.9200.16686

 

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]

Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]

Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

 

-\\ Mozilla Firefox v23.0.1 (en-US)

 

[ File : C:\Users\Norma\AppData\Roaming\Mozilla\Firefox\Profiles\n90p388q.default-1379555047883\prefs.js ]

 

 

-\\ Google Chrome v

 

[ File : C:\Users\Norma\AppData\Local\Google\Chrome\User Data\Default\preferences ]

 

 

*************************

 

AdwCleaner[R0].txt - [15015 octets] - [19/09/2013 12:06:06]

AdwCleaner[S0].txt - [11419 octets] - [19/09/2013 12:11:45]

 

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11480 octets] ##########

 

 

Ran Junkware removal with the following results, however the Kingsoft program came up with two pop ups while doing the scan so I think it prevented something from being done

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 6.4.1 (12.28.2014:1)

OS: Windows 7 Home Premium x64

Ran by Norma on Wed 07/01/2015 at 10:05:54.98

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

~~~ Services

 

 

 

~~~ Registry Values

 

 

 

~~~ Registry Keys

 

 

 

~~~ Files

 

 

 

~~~ Folders

 

Successfully deleted: [Folder] "C:\Users\Norma\appdata\locallow\ytd"

 

 

 

~~~ FireFox

 

Emptied folder: C:\Users\Norma\AppData\Roaming\mozilla\firefox\profiles\n90p388q.default-1379555047883\minidumps [109 files]

 

 

 

~~~ Event Viewer Logs were cleared

 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Wed 07/01/2015 at 10:14:29.77

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

 

Ran ESET with the following results..

 

 

C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wt5F7D.tmp            a variant of Win32/Toolbar.Widgi.B potentially unwanted application       

B:\Users\Norma\Documents\APNSetup.exe            a variant of Win32/Bundled.Toolbar.Ask.E potentially unsafe application            deleted - quarantined

B:\Users\Norma\Downloads\BitZipperSetup [1].exe a variant of Win32/FileTypeAssistant.A potentially unwanted application            deleted - quarantined

B:\Users\Norma\Downloads\cbsidlm-cbsi134-YTD_Video_Downloader-ORG-10647340.exe            a variant of Win32/CNETInstaller.B potentially unwanted application            deleted - quarantined

B:\Users\Norma\Downloads\cbsidlm-tr1_13-Free_Convert_to_DIVX_AVI_WMV_MP4_MPEG_Converter-ORG-10906593.exe            Win32/DownloadAdmin.G potentially unwanted application            deleted - quarantined

B:\Users\Norma\Downloads\FFSetup3.1.1.0.exe       a variant of Win32/Hao123.A potentially unwanted application            deleted - quarantined

B:\Users\Norma\Downloads\InternationalPrimoPDF.exe            Win32/OpenCandy potentially unsafe application            deleted - quarantined

B:\Users\Norma\Downloads\Shockwave_Installer_Slim.exe            Win32/Bundled.Toolbar.Google.D potentially unsafe application            deleted - quarantined

B:\Users\Norma\Downloads\WinZip175.exe            a variant of Win32/OpenInstall potentially unwanted application            deleted - quarantined

B:\Users\Norma\Downloads\YTDSetup.exe            a variant of Win32/Toolbar.Widgi.B potentially unwanted application            deleted - quarantined

B:\Users\Norma\Downloads\custard\SIMS_2_APARTMENT_LIFE_-_NOCD_NODVD.exe            Win32/AdWare.1ClickDownload.AT application            cleaned by deleting - quarantined

C:\AdwCleaner\Quarantine\C\Program Files (x86)\YTD Toolbar\FF\components\ytdToolbarFF.dll.vir            a variant of Win32/Toolbar.Widgi.G potentially unwanted application            deleted - quarantined

C:\AdwCleaner\Quarantine\C\ProgramData\eSafe\eGdpSvc.exe.vir            Win32/ELEX.S potentially unwanted application            deleted - quarantined

C:\AdwCleaner\Quarantine\C\ProgramData\safE savve\51f20f6859eda.dll.vir            a variant of Win32/Adware.MultiPlug.I application            cleaned by deleting - quarantined

C:\AdwCleaner\Quarantine\C\ProgramData\Search-NewwTAAbu\51f20f886d429.dll.vir   a variant of Win32/Adware.MultiPlug.I application            cleaned by deleting - quarantined

C:\AdwCleaner\Quarantine\C\Users\Norma\AppData\Local\Google\Chrome\User Data\Default\Extensions\bccaipeefnadhjggmocpjhemgapddoga\1\51f20f6859c886.26013333.js.vir            Win32/Adware.MultiPlug.H application            cleaned by deleting - quarantined

C:\AdwCleaner\Quarantine\C\Users\Norma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nilhmkgjndmmdfgdnpinmdbcjhblichb\1\51f20f886d1e58.99923603.js.vir            Win32/Adware.MultiPlug.H application            cleaned by deleting - quarantined

C:\AdwCleaner\Quarantine\C\Users\Norma\AppData\Local\Temp\eIntaller\8CB3953FA3D94cd8A8C5E18DF1FF8F70\eXQ.exe.vir            a variant of Win32/ELEX.D potentially unwanted application            deleted - quarantined

C:\AdwCleaner\Quarantine\C\Users\Norma\AppData\Roaming\Slick Savings\coupons_2.9.xpi.vir            JS/Adware.Spigot.A application            deleted - quarantined

C:\Users\Norma\AppData\Local\Temp\AskPIP_FF_.exe            a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application            deleted - quarantined

C:\Users\Norma\AppData\Local\Temp\J7V8OTQK.exe.part            Win32/DownloadAdmin.G potentially unwanted application            deleted - quarantined

C:\Users\Norma\AppData\Local\Temp\QDeEN3Js.exe.part            Win32/DownloadAdmin.G potentially unwanted application            deleted - quarantined

C:\Users\Norma\AppData\Local\Temp\is1914646434\1438443_stp.EXE            a variant of Win32/FileTypeAssistant.A potentially unwanted application            deleted - quarantined

C:\Users\Norma\AppData\Local\Temp\{9CC67BAA-EF41-4C5D-8503-99B5753E71C3}\BrowserExtensionsSetup.exe            JS/Adware.Spigot.A application            cleaned by deleting - quarantined

C:\Windows\Installer\MSI70B0.tmp   a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application            deleted - quarantined

C:\Windows\Installer\MSIADE0.tmp a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application            deleted - quarantined

C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wt5F7D.tmp            a variant of Win32/Toolbar.Widgi.B potentially unwanted application            deleted - quarantined

E:\Kevin\hold for new computer\music\mp4-tomp3\m4a-to-mp3-converter.exe            a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application            deleted - quarantined



#5 buddy215

buddy215

  • BC Advisor
  • 12,610 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:49 AM

Posted 06 January 2015 - 10:20 PM

I'm glad you can at least identify the program....Kingsoft Internet Security. I didn't have that info until now.

Does it show up in the list of installed programs? You can view that list and uninstalll programs using CCleaner.

Open CCleaner and click on Tools. Choose Uninstall. At the bottom right of that page is a button when clicked will

allow you to copy and paste the list of installled programs into your next post. Please do that.

 

There were some Chinese items mentioned in the scans you ran.

 

I'm not sure what you saw when you used Revo. I don't see any images but if they are as impossible to read as the one

in your first post then they won't help.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#6 Twinmum

Twinmum
  • Topic Starter

  • Members
  • 118 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:49 PM

Posted 06 January 2015 - 10:57 PM

oops, I forgot to add the pics (I was copying logs to a word doc so they were saved when the computer rebooted and forgot to the pics when I posted it here), but yes, they all had Chinese writing, so not very helpful. Sorry, I didn't add the name last night.. was late and I wasn't thinking quite clearly and was worried about getting rid of it.

Do you mean if it's in the list of installed programs when I go to the control panel? If so, yes, in there the name is something in Chinese, the publisher is listed as Kingsoft Internet Security. But when I try to uninstall from there, I get the program dialogue box in Chinese, so I just backed out.

I ran CCleaner and it's there, but the same thing happens when I select it and hit the uninstall button, I get this dialogue box.

 

 

uninstall_zps192fdc79.jpg

 

So this is the list from CCleaner

 

 

3D Canvas    Amabilis Software    21/06/2014    41.6 MB    7.1.1.2
@BIOS    GIGABYTE    14/02/2013        2.28
Adobe AIR    Adobe Systems Incorporated    21/11/2014        15.0.0.356
Adobe Flash Player 10 ActiveX    Adobe Systems Incorporated    7/04/2014        10.0.22.87
Adobe Flash Player 16 NPAPI    Adobe Systems Incorporated    11/12/2014    6.00 MB    16.0.0.235
Adobe Photoshop 6.0    Adobe Systems, Inc.    5/09/2013        6.0
Adobe Reader XI (11.0.10)    Adobe Systems Incorporated    10/12/2014    183 MB    11.0.10
Adobe Shockwave Player 12.1    Adobe Systems, Inc.    15/11/2014        12.1.4.154
Adobe SVG Viewer    Adobe Systems, Inc.    20/02/2013        1.0
ANNO 2070    Ubisoft    31/12/2013        1.0.0.0
Apple Application Support    Apple Inc.    8/08/2014    93.4 MB    3.0.6
Apple Mobile Device Support    Apple Inc.    25/07/2014    21.3 MB    7.1.2.6
Apple Software Update    Apple Inc.    16/02/2013    2.38 MB    2.1.3.127
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver    Atheros Communications Inc.    14/02/2013        2.1.0.7
Autodesk 123D Catch    Autodesk    30/11/2014    137 MB    1.0.654
AutoGreen B12.0206.1    GIGABYTE    14/02/2013    4.77 MB    1.00.0000
AVG 2015    AVG Technologies    14/11/2014        2015.0.5577
Bejeweled® 3    Electronic Arts, Inc.    17/09/2014    243 MB    1.1.13.4753
BigPond Broadband ADSL    BigPond    14/02/2013    365 KB    9.2
Blender    Blender Foundation    3/07/2014        2.71
Bonjour    Apple Inc.    16/02/2013    2.00 MB    3.0.0.10
Camping Manager 2012    astragon    27/03/2013    189 MB    
Canon Easy-WebPrint EX        15/02/2013        
Canon IJ Scan Utility    Canon Inc.    20/05/2014        
Canon MG3200 series MP Drivers    Canon Inc.    26/12/2013        1.01
Canon MG3200 series On-screen Manual    Canon Inc.    26/12/2013        7.5.0
Canon MG5500 series MP Drivers    Canon Inc.    20/05/2014        1.01
Canon MG5500 series On-screen Manual    Canon Inc.    20/05/2014        7.6.1
Canon MP Navigator EX 4.0        5/09/2013        
Canon My Image Garden    Canon Inc.    20/05/2014        2.0.1
Canon My Image Garden Design Files    Canon Inc.    20/05/2014        2.0.0
Canon My Printer    Canon Inc.    20/05/2014        3.1.0
Canon Quick Menu    Canon Inc.    20/05/2014        2.2.1
Canon RAW Image Task for ZoomBrowser EX    Canon Inc.    21/02/2013        3.1.0.22
Canon Utilities CameraWindow    Canon Inc.    21/02/2013        7.0.0.8
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX    Canon Inc.    21/02/2013        6.4.1.15
Canon Utilities Digital Photo Professional    Canon Inc.    25/12/2013        3.13.20.0
Canon Utilities Easy-PhotoPrint EX        15/02/2013        
Canon Utilities EOS Sample Music    Canon Inc.    25/12/2013        1.0.1.1
Canon Utilities EOS Utility    Canon Inc.    25/12/2013        2.13.20.0
Canon Utilities ImageBrowser EX    Canon Inc.    25/12/2013        1.4.0.5
Canon Utilities MyCamera    Canon Inc.    21/02/2013        6.4.0.5
Canon Utilities PhotoStitch    Canon Inc.    25/12/2013        3.1.23.47
Canon Utilities Picture Style Editor    Canon Inc.    25/12/2013        1.13.20.0
Canon Utilities RemoteCapture Task for ZoomBrowser EX    Canon Inc.    21/02/2013        1.7.1.9
Canon Utilities Solution Menu        15/02/2013        
Canon Utilities ZoomBrowser EX    Canon Inc.    21/02/2013        6.0.1.248
CanoScan LiDE 210 Scanner Driver        21/02/2013        
CCleaner    Piriform    7/01/2015        5.00
CD-LabelPrint        15/02/2013        
Circus World        28/02/2013        
Dropbox    Dropbox, Inc.    16/12/2014        3.0.3
Easy Tune 6 B12.0912.1    GIGABYTE    14/02/2013    66.2 MB    1.00.0000
ESET Online Scanner v3        7/01/2015        
Fish Tycoon 1.0    Last Day of Work    2/08/2013        1.0
FreeCAD 0.14 - A free open source CAD system    Juergen Riegel    29/11/2014    195 MB    0.14.3700
Game Dev Tycoon    Greenheart Games    31/08/2013        
Google Earth Plug-in    Google    14/12/2013    83.8 MB    7.1.2.2041
iCloud    Apple Inc.    27/06/2014    156 MB    3.1.0.40
Intel® Management Engine Components    Intel Corporation    14/02/2013        8.1.0.1252
Intel® USB 3.0 eXtensible Host Controller Driver    Intel Corporation    21/05/2012        1.0.5.235
iTunes    Apple Inc.    8/08/2014    220 MB    11.3.1.2
LEGO Digital Designer    LEGO A/S    7/04/2014        
Malwarebytes Anti-Malware version 2.0.4.1028    Malwarebytes Corporation    6/01/2015    57.2 MB    2.0.4.1028
Microsoft .NET Framework 4.5.1    Microsoft Corporation    26/02/2014    38.8 MB    4.5.50938
Microsoft Age of Empires        26/02/2013        
Microsoft Office 2000 Professional    Microsoft Corporation    14/02/2013    170 MB    9.00.2720
Microsoft Publisher 98        15/02/2013        
Microsoft Rise Of Nations    Microsoft    31/07/2013        
Microsoft Silverlight    Microsoft Corporation    14/12/2014    249 MB    5.1.31211.0
Microsoft SQL Server 2005 Compact Edition [ENU]    Microsoft Corporation    14/02/2013    1.69 MB    3.1.0000
Microsoft Visual C++ 2005 Redistributable    Microsoft Corporation    15/02/2013    300 KB    8.0.61001
Microsoft Visual C++ 2005 Redistributable (x64)    Microsoft Corporation    14/02/2013    708 KB    8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729    Microsoft Corporation    14/02/2013    792 KB    9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17    Microsoft Corporation    7/08/2013    242 KB    9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161    Microsoft Corporation    15/02/2013    788 KB    9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022    Microsoft Corporation    29/11/2014    1.41 MB    9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17    Microsoft Corporation    14/02/2013    596 KB    9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148    Microsoft Corporation    14/02/2013    596 KB    9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161    Microsoft Corporation    15/02/2013    600 KB    9.0.30729.6161
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219    Microsoft Corporation    14/02/2013    13.8 MB    10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219    Microsoft Corporation    14/02/2013    11.1 MB    10.0.40219
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005    Microsoft Corporation    11/07/2014    17.1 MB    12.0.21005.1
Microsoft WSE 3.0 Runtime    Microsoft Corp.    14/02/2013    942 KB    3.0.5305.0
Mozilla Firefox 34.0.5 (x86 en-GB)    Mozilla    10/12/2014    80.7 MB    34.0.5
Mozilla Maintenance Service    Mozilla    10/05/2014    341 KB    29.0.1
MSXML 4.0 SP2 (KB954430)    Microsoft Corporation    15/02/2013    1.27 MB    4.20.9870.0
MSXML 4.0 SP2 (KB973688)    Microsoft Corporation    15/02/2013    1.33 MB    4.20.9876.0
MSXML4 Parser    Microsoft Game Studios    31/07/2013    65.0 KB    1.0.0
Myst Masterpiece Edition        12/08/2013        
Myst V End Of Ages        4/09/2013        
Nero BackItUp 10    Nero AG    14/02/2013    109 MB    5.6.11700.17.100
Nero BurnRights 10    Nero AG    14/02/2013    6.14 MB    4.2.10500.1.102
Nero CoverDesigner 10    Nero AG    14/02/2013    77.5 MB    5.2.11400.11.100
Nero DiscSpeed 10    Nero AG    14/02/2013    7.21 MB    6.2.10500.2.100
Nero Express 10    Nero AG    14/02/2013    165 MB    10.2.12400.25.100
Nero InfoTool 10    Nero AG    14/02/2013    8.06 MB    7.2.10400.5.100
Nero Multimedia Suite 10 Essentials    Nero AG    14/02/2013    641 MB    10.5.10000
Nero StartSmart 10    Nero AG    14/02/2013    143 MB    10.2.11300.12.100
Nero Update    Nero AG    14/02/2013    1.43 MB    1.0.0018
Network Play System (Patching)        26/07/2013        
NVIDIA 3D Vision Controller Driver 306.38    NVIDIA Corporation    14/02/2013        306.38
NVIDIA 3D Vision Driver 311.06    NVIDIA Corporation    13/04/2013        311.06
NVIDIA Graphics Driver 311.06    NVIDIA Corporation    13/04/2013        311.06
NVIDIA HD Audio Driver 1.3.18.0    NVIDIA Corporation    14/02/2013        1.3.18.0
NVIDIA PhysX System Software 9.12.0807    NVIDIA Corporation    14/02/2013        9.12.0807
NVIDIA Update 1.11.3    NVIDIA Corporation    13/04/2013        1.11.3
ON_OFF Charge B11.1102.1    GIGABYTE    14/02/2013        1.00.0001
Origin    Electronic Arts, Inc.    12/09/2013        9.3.1.4482
Photo Transfer App    UNKNOWN    19/02/2014        2.1.0
PrimoPDF -- brought to you by Nitro PDF Software    Nitro PDF Software    2/05/2013        5
QuickTime        12/08/2013        
Razer Synapse 2.0    Razer Inc.    17/12/2014    19.1 MB    1.18.18.23036
realMyst    GOG.com    5/09/2013        
Revo Uninstaller Pro 3.1.2    VS Revo Group, Ltd.    7/01/2015    35.5 MB    3.1.2
Riven The sequel to Myst    GOG.com    5/09/2013        
RootsMagic 2.0    RootsMagic, Inc.    26/05/2013    39.7 MB    2.00.0000
Samsung SSD Magician    Samsung Electronics    14/02/2013    45.8 MB    3.2
SimCity 2000 Special Edition    Electronic Arts    10/12/2014    137 MB    2.0.0.1
SketchUp 2014    Trimble Navigation Limited    21/06/2014    192 MB    14.1.1282
Steam    Valve Corporation    31/08/2013    1.77 MB    1.0.0.0
The Sims 2: Ultimate Collection    Electronic Arts    24/07/2014    12.5 GB    1.0.0.0
The Sims™ 3    Electronic Arts    7/04/2014        1.67.2
The Sims™ 3 70s, 80s, & 90s Stuff    Electronic Arts    28/06/2014        17.0.77
The Sims™ 3 Ambitions    Electronic Arts    28/06/2014        4.0.87
The Sims™ 3 Fast Lane Stuff    Electronic Arts    28/06/2014        5.0.44
The Sims™ 3 Generations    Electronic Arts    28/06/2014        8.0.152
The Sims™ 3 High-End Loft Stuff    Electronic Arts    28/06/2014        3.0.38
The Sims™ 3 Into the Future    Electronic Arts    24/10/2013        21.0.150
The Sims™ 3 Island Paradise    Electronic Arts    28/06/2014        19.0.101
The Sims™ 3 Late Night    Electronic Arts    28/06/2014        6.0.81
The Sims™ 3 Master Suite Stuff    Electronic Arts    28/06/2014        11.0.84
The Sims™ 3 Movie Stuff    Electronic Arts    12/09/2013        20.0.53
The Sims™ 3 Outdoor Living Stuff    Electronic Arts    28/06/2014        7.0.55
The Sims™ 3 Pets    Electronic Arts    28/06/2014        10.0.96
The Sims™ 3 Seasons    Electronic Arts    28/06/2014        16.0.136
The Sims™ 3 Showtime    Electronic Arts    28/06/2014        12.0.273
The Sims™ 3 Supernatural    Electronic Arts    28/06/2014        15.0.135
The Sims™ 3 Town Life Stuff    Electronic Arts    28/06/2014        9.0.73
The Sims™ 3 University Life    Electronic Arts    28/06/2014        18.0.126
The Sims™ 3 World Adventures    Electronic Arts    28/06/2014        2.0.86
The Sims™ 4    Electronic Arts Inc.    17/12/2014    9.01 GB    1.3.18.1010
Thunder Master v1.5    Palit Microsystems Ltd.    14/02/2013    4.82 MB    1.5.0.0
TSST OEM Content    Nero AG    14/02/2013    290 KB    10.0.10300.0.0
Ubisoft Game Launcher    UBISOFT    31/12/2013        1.0.0.0
VIA Platform Device Manager    VIA Technologies, Inc.    14/02/2013    2.62 MB    1.39
Visual Studio 2010 x64 Redistributables    AVG Technologies    3/06/2013    12.4 MB    13.0.0.1
Visual Studio 2012 x64 Redistributables    AVG Technologies    8/10/2013    12.9 MB    14.0.0.1
Visual Studio 2012 x86 Redistributables    AVG Technologies CZ, s.r.o.    8/10/2013    10.5 MB    14.0.0.1
Windows Driver Package - Atheros Communications Inc. (arusb_lhx) Net  (09/25/2008 3.1.0.101)    Atheros Communications Inc.    14/02/2013        09/25/2008 3.1.0.101
Windows Driver Package - NETGEAR Inc. (RTL8187) Net  (12/01/2006 6.1258.1201.2006)    NETGEAR Inc.    14/02/2013        12/01/2006 6.1258.1201.2006
Windows Driver Package - Thomson (USB_RNDIS) Net  (02/15/2007 2.0.0.0)    Thomson    14/02/2013        02/15/2007 2.0.0.0
Windows Live Essentials    Microsoft Corporation    30/12/2014        16.4.3528.0331
WinRAR 4.20 (64-bit)    win.rar GmbH    19/09/2013        4.20.0
新毒霸(悟空)    Kingsoft Internet Security    6/01/2015        2015.0.3



#7 buddy215

buddy215

  • BC Advisor
  • 12,610 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:49 AM

Posted 07 January 2015 - 06:46 AM

I think Revo is your best bet for removing the KIS program. The images and text in the instructions should

help you in using Revo.

 

Read the instructions in one or both links below for using Revo.

Completely Uninstall Programs And More With Revo Uninstaller

The Complete Guide To Using Revo Uninstaller - Keep Your PC Clean and Healthy

 

Open CCleaner and click on Tools. Choose Startups. There you will see a list of Windows Startups. Look for

any you don't need to startup especially the KIS one. Click to highlight an item and then on the right side of the

page choose to disable or enable. If KIS is there, after disabling, reboot and use Revo to uninstall.

You can also look in the Task Manager and disable any KIS process before using Revo.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#8 Twinmum

Twinmum
  • Topic Starter

  • Members
  • 118 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:49 PM

Posted 07 January 2015 - 03:54 PM

Success!!  It's gone. Revo was the answer. The problem I had yesterday, was that when I hit the uninstall button, a dialogue box (in Revo) came up saying once the program's uninstaller had finished, to hit the scan button to get the last bits and pieces. The thing was, I had nothing to say that the uninstaller was finished - if it even started because of the chinese dialogue box. I'm not even sure the scan btton was available to be selected. So this morning when I tried, I dismissed the Chinese dialogue box and just hit the scan button. It scanned and found all the things to do with the KIS program. I selected all and removed them. restarted the computer and it's no longer there yay.

 

Thank you so much for your help



#9 buddy215

buddy215

  • BC Advisor
  • 12,610 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:49 AM

Posted 07 January 2015 - 04:19 PM

Good....mission accomplished....happy surfin' ! You're welcome...


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users