Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

how to uninstall omiga-plus


  • Please log in to reply
17 replies to this topic

#1 Terrano2001

Terrano2001

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 08 February 2015 - 07:22 PM

I have run Malwarebytes anti-malware also sas and avast antivirus all free versions. I am at a loss what to do next. I am a novice regarding computers 

 

hope you can help

 

regards Arthur



BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:58 PM

Posted 08 February 2015 - 07:35 PM

First, run a scan using Shortcut Cleaner. Shortcut Cleaner Download

When run, Shortcut Cleaner will scan various locations on your computer for Windows shortcuts.  When a shortcut is detected it will check properties for a possible hijacking. If one is detected, it will automatically clean the shortcut so that it no longer opens the offending program or  web site. When the Shortcut Cleaner has finished scanning your hard drive it will create a log file on your desktop called sc-cleaner.txt and then display it.  This log file will contains a list of all the shortcuts that were detected and cleaned. Please post the results of the scan.

 

Use CCleaner to remove Temporary files, program caches, cookies, logs, etc. Use the Default settings. No need to use the

Registry Cleaning Tool...risky. Pay close attention while installing and UNcheck offers of toolbars....especially Google.

After install, open CCleaner and run by clicking on the Run Cleaner button in the bottom right corner.

CCleaner - PC Optimization and Cleaning - Free Download

 

  • download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

Download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Hold down Control and click on this link to open ESET OnlineScan in a new window. (Eset can take more than an hour to run so plan accordingly)

  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 Terrano2001

Terrano2001
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 09 February 2015 - 12:20 PM

Shortcut Cleaner 1.3.4 by Lawrence Abrams (Grinler)
Copyright 2008-2015 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
 
Windows Version: Windows 7 Home Premium Service Pack 1
Program started at: 02/09/2015 05:07:31 PM.
 
Scanning for registry hijacks:
 
 * No issues found in the Registry.
 
Searching for Hijacked Shortcuts:
 
Searching C:\Users\x3990-i3\AppData\Roaming\Microsoft\Windows\Start Menu\
 
  * Shortcut Cleaned: C:\Users\x3990-i3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1423344848&from=tugs&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5V56386263862
 
  * Shortcut Cleaned: C:\Users\x3990-i3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1423344848&from=tugs&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5V56386263862
 
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
 
Searching C:\Users\x3990-i3\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
 
  * Shortcut Cleaned: C:\Users\x3990-i3\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1423344848&from=tugs&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5V56386263862
 
Searching C:\Users\Public\Desktop\
 
Searching C:\Users\x3990-i3\Desktop
 
 
3 bad shortcuts found.
 
Program finished at: 02/09/2015 05:07:35 PM
Execution time: 0 hours(s), 0 minute(s), and 3 seconds(s)
 
here are the results of the scan thanks for your help


#4 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:58 PM

Posted 09 February 2015 - 12:28 PM

Important that you run all the scans...


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#5 Terrano2001

Terrano2001
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 09 February 2015 - 02:22 PM

I have posted the adware scan but I cannot see it now. It seems to have removed the trouble some programs I have run adware again I will post this scan# AdwCleaner v4.110 - Logfile created 09/02/2015 at 19:12:03

# Updated 05/02/2015 by Xplode
# Database : 2015-02-09.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : x3990-i3 - X3990-I3-PC
# Running from : C:\Users\x3990-i3\Documents\AdwCleaner.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17496
 
 
-\\ Mozilla Firefox v
 
 
-\\ Google Chrome v
 
 
-\\ Opera v27.0.1689.66
 
 
*************************
 
AdwCleaner[R0].txt - [6766 bytes] - [09/02/2015 17:28:24]
AdwCleaner[R1].txt - [1183 bytes] - [09/02/2015 19:09:47]
AdwCleaner[S0].txt - [7102 bytes] - [09/02/2015 17:55:31]
AdwCleaner[S1].txt - [845 bytes] - [09/02/2015 19:12:03]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [903  bytes] ##########
 
I will now run JRT


#6 Terrano2001

Terrano2001
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 10 February 2015 - 05:18 AM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by x3990-i3 on 09/02/2015 at 19:23:03.67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Event Viewer Logs were cleared
 
all scan completed looking forward to diagnosis thanks for all your help
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09/02/2015 at 19:30:48.52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#7 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:58 PM

Posted 10 February 2015 - 07:11 AM

I don't see the results of the Eset Online Scan. If you ran it and nothing was found then you are good to go.

If you haven't run the scan, then you should.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#8 Terrano2001

Terrano2001
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 10 February 2015 - 11:56 AM

  sorry I thought I had posted 

C:\AdwCleaner\Quarantine\C\Program Files (x86)\ShopperPro\manifest.json.vir JS/ShopperPro.A potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ShopperPro\FireFox\content\overlay.js.vir JS/ShopperPro.A potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ShopperPro\JSDriver\jsdrv.exe.vir a variant of Win32/ShopperPro.B potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchCH.dll.vir Win32/ELEX.BM potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchFF.dll.vir Win32/ELEX.BM potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowserAction.dll.vir a variant of Win32/ELEX.BM potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\CmdShell.exe.vir Win32/ELEX.BM potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\HPNotify.exe.vir Win32/ELEX.BM potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\IeWatchDog.dll.vir Win32/ELEX.BM potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\x3990-i3\AppData\Roaming\Opera Software\Opera Stable\Extensions\hniiadklfgdhjcmmkpggffjngihaaoip\1.26.42_0\extensionData\plugins\91.js.vir JS/Toolbar.Crossrider.B potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\x3990-i3\AppData\Roaming\Opera Software\Opera Stable\Extensions\kfgaibfbmkjgmimhbbaikfnpkkjkpoan\1.26.243_0\extensionData\plugins\91.js.vir JS/Toolbar.Crossrider.B potentially unwanted application deleted - quarantined
C:\OEM\Preload\Autorun\APP\Nero 10 Essentials Acer Edition\ISSetupPrerequisites\{BF80A1C0-C3FF-4B1C-ABEF-22CD4F97A0AB}\Toolbar.exe a variant of Win32/Bundled.Toolbar.Ask.A potentially unsafe application deleted - quarantined
C:\Users\x3990-i3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E8M1LMGF\setup[1].exe_a Win32/Packed.ScrambleWrapper.O potentially unwanted application deleted - quarantined
C:\Users\x3990-i3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E8M1LMGF\StormWatchSetup[1].exe Win32/Verti.K potentially unwanted application deleted - quarantined
C:\Users\x3990-i3\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TPBJD34A\iweb[1].exe_a Win32/Packed.ScrambleWrapper.O potentially unwanted application deleted - quarantined
C:\Users\x3990-i3\AppData\Roaming\Opera Software\Opera Stable\Extensions\hdhmofnopkgkpgnpggloijpbnaonhplc\1.26.13_0\extensionData\plugins\91.js JS/Toolbar.Crossrider.B potentially unwanted application deleted - quarantined
C:\Users\x3990-i3\Downloads\ccsetup502 (1).exe Win32/Bundled.Toolbar.Google.D potentially unsafe application deleted - quarantined
C:\Users\x3990-i3\Downloads\ccsetup502.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application deleted - quarantined
C:\Windows\FixCamera.exe a variant of Win32/KillProc.A potentially unwanted application deleted - quarantined
C:\Windows\Installer\MSI840E.tmp-\spbe.dll a variant of MSIL/Toolbar.Linkury.I potentially unwanted application deleted - quarantined


#9 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:58 PM

Posted 10 February 2015 - 12:30 PM

Open CCleaner. Click on Tools and choose Startups. On that page you will see a list of Windows Startups and at the top you will see buttons for

each browser and Scheduled Tasks. At the bottom right of that page you will see a button when clicked will allow you to copy and paste the list of Windows Startups

into your next post. Then click on the Tasks button and Copy and Paste that list of Tasks into your next post.

 

Download Security Check from here or here and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#10 Terrano2001

Terrano2001
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 10 February 2015 - 02:24 PM

Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
No HKCU:Run Google Update "C:\Users\x3990-i3\AppData\Local\Google\Update\GoogleUpdate.exe" /c
Yes HKCU:Run iCloudServices Apple Inc. C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
Yes HKCU:Run SUPERAntiSpyware SUPERAntiSpyware C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
No HKCU:Run TomTomHOME.exe TomTom "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
Yes HKCU:Run WinPatrol Ruiware LLC C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe -expressboot
No HKLM:Run Adobe ARM Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
No HKLM:Run ArcadeMovieService CyberLink Corp. "C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe"
Yes HKLM:Run AvastUI.exe AVAST Software "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
No HKLM:Run FixCamera C:\Windows\FixCamera.exe
Yes HKLM:Run HostManager AOL Inc. C:\Program Files (x86)\Common Files\AOL\1331050844\ee\AOLSoftware.exe
No HKLM:Run iTunesHelper "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
Yes HKLM:Run Malwarebytes Anti-Exploit Malwarebytes Corporation C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
Yes HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
Yes HKLM:Run QuickTime Task Apple Inc. C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime
No HKLM:Run RtHDVCpl Realtek Semiconductor C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
No HKLM:Run snp325 C:\Windows\vsnp325.exe
No HKLM:Run tsnp325 C:\Windows\tsnp325.exe
Yes HKLM:Run ZALFree Zemana Ltd. "C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe" /MINIMIZED
No Startup Common Bluetooth.lnk Broadcom Corporation. C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe 
Yes Startup Common Secunia PSI Tray.lnk Secunia C:\Program Files (x86)\Secunia\PSI\psi_tray.exe


#11 Terrano2001

Terrano2001
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 10 February 2015 - 02:33 PM

 Results of screen317's Security Check version 0.99.96  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Secunia PSI (3.0.0.9016)   
  Java 64-bit 8 Update 31  
 Adobe Reader XI  
````````Process Check: objlist.exe by Laurent````````  
 WinPatrol winpatrol.exe 
 Malwarebytes Anti-Exploit mbae-svc.exe   
 Malwarebytes Anti-Exploit mbae64.exe   
 Malwarebytes Anti-Exploit mbae.exe   
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast avastui.exe  
 AVAST Software Avast ng vbox\AvastVBoxSVC.exe 
 AVAST Software Avast ng ngservice.exe 
 Ruiware WinPatrol WinPatrol.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 2% 
````````````````````End of Log`````````````````````` 


#12 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:58 PM

Posted 10 February 2015 - 03:35 PM

Please post the lists of Scheduled Tasks. (CCleaner > Tools > Startups > Click on Scheduled Tasks Tab > Click button at bottom right > Copy and Paste)

 

Disable these Windows Startups. Click on each item in CCleaner's list to highlight and then choose Disable on the right of the page.

Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
Yes HKCU:Run iCloudServices Apple Inc. C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
Yes HKCU:Run SUPERAntiSpyware SUPERAntiSpyware C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Yes HKLM:Run HostManager AOL Inc. C:\Program Files (x86)\Common Files\AOL\1331050844\ee\AOLSoftware.exe
Yes HKLM:Run QuickTime Task Apple Inc. C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime

Edited by buddy215, 10 February 2015 - 03:36 PM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#13 Terrano2001

Terrano2001
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 10 February 2015 - 04:24 PM

Yes Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Yes Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Yes Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes Task CreateChoiceProcessTask Microsoft Corporation C:\Windows\System32\browserchoice.exe /launch
Yes Task EgisUpdate Egis Technology Inc. "C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d
Yes Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
Yes Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Yes Task Launch HTC Sync Loader C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe -startup
Yes Task Opera scheduled Autoupdate 1417523201 Opera Software C:\Program Files (x86)\Opera\launcher.exe --scheduledautoupdate
Yes Task PMMUpdate Egis Technology Inc. "C:\Program Files\EgisTec IPS\PMMUpdate.exe"
Yes Task QINTW C:\Users\x3990-i3\AppData\Roaming\QINTW.exe /infocmdline=lLYb/tOZ1Xuzkuk/sg5Otvmy3bRGs7lLdPnBMFPAaqhTsZGdQMdyc5luXbhLbRvg45HS3OUcXwpLjOWMc+LdSX/h03CieFOys5AmOna83dKyWY35AWANNsmxQGRMtLOXnPUzmvDQy74rvaGk2Kl/XBxGTmfROcOQMJClEaCTDwIp8AL5kd9dlk6Qmi8ht0vl0VozI8E1bK/LcCok4QcG/oxHfMvru7Dc4M24/5B0EEID5C29ZEenx4gQ1DGS0RpvFio1PACtBZq/PyOjQ5CmcEaVVH7O+G3VdULtXZRLbTM2Aof2u3Z7srBGNUJy6m0nUbfsvw9+qJKMAQyFFrjkC1jeXv7+abzMI+oiAw6D+ir1lS8nbqSDyEqIUoS4pjCpLjF2h1izpjIcyQp96u5LpASnyHMYyKJ1weekrXu/baWeX9wxnF0TnmbzTI0IWqU/B2vnw1XDGjzKC2fr2j25UTEdKQUcF+cXILK0uZ4R6ArW7JxoeN8LMcsjBeXgh6ms
Yes Task SHSG C:\Users\x3990-i3\AppData\Roaming\SHSG.exe /infocmdline=BhkBpsjXwhjvyMSzMeybCG1KETHw4/mb+R8CBc9OGJ+CxHLKA94FoGdSkEYn2EGGjI1IlNFfHMYF6zjBdBLW1bdMfUzXEl1Xoyk9HE6Q+wroQ/tqPvAUtFPffiHT/14FOkIEl2xoNBnGdbo9TSuNBXeqarm9sGrGiGbd+F4PZ49mkydsMOQQ3lPKFE+uLPv8elKQmfVHgMETOU2z4vNaBGHlYaP+0X3V2BZqfZIouPilVEivWsy1O2CjjJEOO1g7JP6Fs77A8OOEqNzOrodkVLnqB3vqhNndnh4zu1DGLd2zATOKLvB5YQQ2ukLzdFTRTjoi2wVZlH0u+71sxRPauXmRQj97rPKhsf9ivYziylPWzOpeBv53Wa/p3lGjgE2VdZOdtRJmrc7Yvzw3CP550J/F6+zle2iGKWA0buj5FLeTEhP2D3oKXb/syWf4GIlz3mH/WDpyBoWCiFhNCVOV8FROmhQaM/QxLuTJF7Tcx8AQqhMboGH88CPMDJS7waXc
Yes Task {35F3015D-8CB5-476E-BB69-0B287F7B5270} C:\Program Files (x86)\Klick\Klick Viewer\Klick.exe
Yes Task {4766984D-D800-4E47-A93A-1F60361C5772} Google C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe
Yes Task {640DA100-E0C0-420E-9B2D-427B6FFEF342} C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
Yes Task {93B991FB-3154-428C-8B9F-240139217046} SEIKO EPSON CORPORATION C:\Program Files (x86)\EPSON Software\Easy Photo Print\EPQuicker.exe
Yes Task {C03A1FF9-5DB4-47A4-9D85-AFEB62B99562} C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
Yes Task {C6AAE0F9-3B04-4A5C-BB09-34F3D0A28B13} C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
Yes Task {F285273B-9898-4705-A664-CCCB411633F3} C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe


#14 Terrano2001

Terrano2001
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 10 February 2015 - 04:41 PM

I have run ccleaner

 

also Malwarebytes antimalware  this Found nothing

 

Avast antivirus free version full scan this came up with file not able to scan they where all aol desk top9.7a browser cache error archives is password 

I was unable to copy these file

 

ran SAS found nothing

 

I seem to have remnant of firefox and chrome which I use anymore 



#15 Terrano2001

Terrano2001
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:58 AM

Posted 10 February 2015 - 04:43 PM

In have disabled window startup as instruct






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users