Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

cannot access the internet after running adware removal tool


  • Please log in to reply
37 replies to this topic

#1 uhl77

uhl77

  • Members
  • 14 posts
  • OFFLINE
  •  

Posted 15 January 2015 - 08:40 AM

Hello All,

I am new to this and not very computer savey so hope you can help.

I had a problem with my proxy turning on every 10 minutes so searched around to see if i could fix it. I came across a thread on this site that resembled my problem. The solution was to run some adware removal tool reboot and run something else. I cant recall the name of the adware tool but it was something like adWcleaner.

Anyways i followed the instructions ran the tool and cleaned 2 hotspot shield errors or something. Then i rebooted as directed and now cannot access the internet as i have limited connectivity.

I troubleshot the connection issue and it says network adapter is experiencing problems.

I found many other topics on this site for not having inet connection and tried all the cmd recommendations i could find (netsh interface, winsoc, flush dns etc.) and nothing has worked.

Any assistance would be greatly appreciated.


Edited by hamluis, 15 January 2015 - 10:09 AM.
Moved from Win 7 to Am I Infected - Hamluis.


BC AdBot (Login to Remove)

 


#2 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:12:44 AM

Posted 15 January 2015 - 08:48 AM

Try the portable version of Windows Repair (All In One).
 
Once you've extracted the Tweaking.com - Windows Repair folder, open it and click on PwbGpDx.png to run the program.
 
Go to step 5, backup the registry and create a restore point:
 
 
B0d3a37.png
 
 
Click Next:
 
 
lsXwdmK.png
 
 
Click on Open Repairs.

 

 

BkmLvXn.png
 

 

Select the circled items and deselect the others.
 
Click on box next to the Restart/Shutdown System when Finished.
 
Click on Restart System.
 

Disabling your antivirus is recommended before running the repairs.

 

Click on Start Repairs:
 
 
SMzY5MM.png



#3 uhl77

uhl77
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  

Posted 15 January 2015 - 09:00 AM

Thank you for the answer but i am not able to access the website you recommended as i cannot get on the internet. I am currently using my phone to write this post.

#4 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:12:44 AM

Posted 15 January 2015 - 09:09 AM

You'll need another running computer to download the program. Save it to a USB flash drive or other removable media, and plug it into the faulty computer. Save the download from the removable media onto your faulty computer and run it.


Edited by Phantom010, 15 January 2015 - 09:09 AM.


#5 uhl77

uhl77
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  

Posted 15 January 2015 - 09:36 AM

Hello Phantom,

I downloaded and tried the above solution however i still have the same issue.

#6 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:12:44 AM

Posted 15 January 2015 - 09:40 AM

Was Hotspot Shield uninstalled on that computer? If so, was it right before having problems?



#7 uhl77

uhl77
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  

Posted 15 January 2015 - 09:41 AM

Yes. I believe the adwcleaner removed it.

#8 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:12:44 AM

Posted 15 January 2015 - 09:42 AM

I don't think it removed the program entirely. Hotspot Shield is not adware. Look inside "Programs and Features". Do you see Hotspot Shield in there?



#9 uhl77

uhl77
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  

Posted 15 January 2015 - 09:45 AM

Not there. It said there were 2 problems with hotspot shield and i cleaned both.

#10 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:12:44 AM

Posted 15 January 2015 - 09:48 AM

Can you post the latest log from AdwCleaner, the one where those two entries were deleted?

 

You should find the log (text file) in C:\AdwCleaner.


Edited by Phantom010, 15 January 2015 - 09:48 AM.


#11 uhl77

uhl77
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  

Posted 15 January 2015 - 09:54 AM

# AdwCleaner v4.107 - Report created 15/01/2015 at 14:31:19
# Updated 07/01/2015 by Xplode
# Database : 2015-01-13.2 [Live]
# Operating System : Windows 7 Home Basic Service Pack 1 (64 bits)
# Username : Lawrence Uhl - LAWRENCE
# Running from : C:\Users\Lawrence Uhl\Downloads\adwcleaner_4.107.exe
# Option : Scan

***** [ Services ] *****

Service Found : hshld
Service Found : hsstrayservice
Service Found : hsswd
Service Found : YahooAUService

***** [ Files / Folders ] *****

File Found : C:\Windows\System32\drivers\hssdrv6.sys
File Found : C:\Windows\System32\drivers\taphss6.sys
Folder Found : C:\Program Files (x86)\Common Files\FreeCause
Folder Found : C:\Program Files (x86)\Common Files\Spigot
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\ExpressFiles
Folder Found : C:\Program Files (x86)\hotspot shield
Folder Found : C:\Program Files (x86)\NCH Software
Folder Found : C:\Program Files (x86)\OApps
Folder Found : C:\ProgramData\hotspot shield
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hotspot shield
Folder Found : C:\ProgramData\NCH Software
Folder Found : C:\ProgramData\Tarma Installer
Folder Found : C:\ProgramData\Yahoo! Companion
Folder Found : C:\Users\Lawrence Uhl\AppData\Local\Conduit
Folder Found : C:\Users\Lawrence Uhl\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
Folder Found : C:\Users\Lawrence Uhl\AppData\Local\iac
Folder Found : C:\Users\Lawrence Uhl\AppData\Local\visi_coupon
Folder Found : C:\Users\Lawrence Uhl\AppData\LocalLow\Conduit
Folder Found : C:\Users\Lawrence Uhl\AppData\LocalLow\HPAppData
Folder Found : C:\Users\Lawrence Uhl\AppData\LocalLow\iac
Folder Found : C:\Users\Lawrence Uhl\AppData\LocalLow\Yahoo! Companion
Folder Found : C:\Users\Lawrence Uhl\AppData\Roaming\ExpressFiles
Folder Found : C:\Users\Lawrence Uhl\AppData\Roaming\goforfiles
Folder Found : C:\Users\Lawrence Uhl\AppData\Roaming\NCH Software
Folder Found : C:\Windows\SysWOW64\hotspot shield

***** [ Scheduled Tasks ] *****

Task Found : GoforFilesUpdate

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\anchorfree
Key Found : HKCU\Software\AppDataLow\Software\Compete
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\Freecause
Key Found : HKCU\Software\AppDataLow\Software\Search Settings
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Software\Smartbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\ExpressFiles
Key Found : HKCU\Software\GoforFiles
Key Found : HKCU\Software\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{23088cf8-eaf8-4bb3-a251-9ba61557ac75}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30CEEEA2-3742-40e4-85DD-812BF1CBB83D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30CEEEA2-3742-40e4-85DD-812BF1CBB83D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4C2743F0-A2E2-41A0-9E65-798943109F42}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\ExpressFiles
Key Found : HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\anchorfree
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\ExpressFiles
Key Found : [x64] HKCU\Software\GoforFiles
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{23088cf8-eaf8-4bb3-a251-9ba61557ac75}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{23088CF8-EAF8-4BB3-A251-9BA61557AC75}
Key Found : [x64] HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Found : HKLM\SOFTWARE\Classes\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007}
Key Found : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{30CEEEA2-3742-40e4-85DD-812BF1CBB83D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Found : HKLM\SOFTWARE\Classes\

#12 uhl77

uhl77
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  

Posted 15 January 2015 - 09:56 AM

# AdwCleaner v4.107 - Report created 15/01/2015 at 14:33:56
# Updated 07/01/2015 by Xplode
# Database : 2015-01-13.2 [Live]
# Operating System : Windows 7 Home Basic Service Pack 1 (64 bits)
# Username : Lawrence Uhl - LAWRENCE
# Running from : C:\Users\Lawrence Uhl\Downloads\adwcleaner_4.107.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : hshld
[#] Service Deleted : hsstrayservice
Service Deleted : hsswd
Service Deleted : YahooAUService

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\hotspot shield
Folder Deleted : C:\ProgramData\NCH Software
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\Yahoo! Companion
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hotspot shield
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\ExpressFiles
Folder Deleted : C:\Program Files (x86)\hotspot shield
Folder Deleted : C:\Program Files (x86)\NCH Software
Folder Deleted : C:\Program Files (x86)\OApps
Folder Deleted : C:\Program Files (x86)\Common Files\FreeCause
Folder Deleted : C:\Program Files (x86)\Common Files\Spigot
Folder Deleted : C:\Windows\SysWOW64\hotspot shield
Folder Deleted : C:\Users\Lawrence Uhl\AppData\Local\Conduit
Folder Deleted : C:\Users\Lawrence Uhl\AppData\Local\iac
Folder Deleted : C:\Users\Lawrence Uhl\AppData\Local\visi_coupon
Folder Deleted : C:\Users\Lawrence Uhl\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Lawrence Uhl\AppData\LocalLow\HPAppData
Folder Deleted : C:\Users\Lawrence Uhl\AppData\LocalLow\iac
Folder Deleted : C:\Users\Lawrence Uhl\AppData\LocalLow\Yahoo! Companion
Folder Deleted : C:\Users\Lawrence Uhl\AppData\Roaming\ExpressFiles
Folder Deleted : C:\Users\Lawrence Uhl\AppData\Roaming\goforfiles
Folder Deleted : C:\Users\Lawrence Uhl\AppData\Roaming\NCH Software
Folder Deleted : C:\Users\Lawrence Uhl\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
File Deleted : C:\Windows\System32\drivers\taphss6.sys
File Deleted : C:\Windows\System32\drivers\hssdrv6.sys

***** [ Scheduled Tasks ] *****

Task Deleted : GoforFilesUpdate

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{30CEEEA2-3742-40e4-85DD-812BF1CBB83D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E69D4A59-73DE-4E38-9FB3-740EC4D9060D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4C2743F0-A2E2-41A0-9E65-798943109F42}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30CEEEA2-3742-40e4-85DD-812BF1CBB83D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30CEEEA2-3742-40e4-85DD-812BF1CBB83D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key D

#13 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:12:44 AM

Posted 15 January 2015 - 10:03 AM

1- It's possible, of course, but what made you think Hotspot Shield is the one responsible, among all other items removed by AdwCleaner, for your connection problem?

 

2- Did you at one point install Hotspot Shield on that computer?



#14 uhl77

uhl77
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  

Posted 15 January 2015 - 10:14 AM

I didnt really think it was hotspot shield but it did cross my mind as i was having proxy issues. I installed it a long time ago but never use it.

When adwcleaner said there were 2 problems with hs shield and 1 other (cant remember what it was) i figured as i dont use it that it would be ok to clean.

#15 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:12:44 AM

Posted 15 January 2015 - 10:16 AM

Well, AdwCleaner removed more than 2 entries from Hotspot Shield, as I can see in your log.

 

You must be careful with AdwCleaner and not let it blindly remove everything it finds. The program is good, but removes too many programs IT believes are PUPs. Hotspot Shield is a legitimate program.


Edited by Phantom010, 15 January 2015 - 10:20 AM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users