Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help Removing Pro PC Cleaner


  • Please log in to reply
12 replies to this topic

#1 gt56

gt56

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:25 PM

Posted 19 March 2015 - 07:25 PM

My computer scanned and found malware and viruses which were removed. Just noticed Pro PC Cleaner in my list of programs but when I choose to uninstall, this message pops up 'There is a problem with this Windows Installer package. A DLL required for this install to complete cound not be run.  Contact your support personnel or package vendor.'  Do I need to reinstall this malware to remove it? Please offer any suggestions.



BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,082 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:25 PM

Posted 19 March 2015 - 07:38 PM

Hello gt56

I moved this from Win 7 to the Am I Infected forum.

What is your browser?

First look in Control Panel/Uninstall, if there uninstall. Restart the machine.

Now run these...


51a46ae42d560-malwarebytes_anti_malware.Malwarebytes Anti-Malware
  • Download MalwareBytes Anti-Malware to your desktop.
  • Double-click mbam-setup-2.0.exe to start the installation of Malwarebytes Anti-Malware.
  • Follow the instructions on your screen to complete the installation. You can find the complete installation procedure here.
  • Click the Scan Now button, a threat scan will start automatically.
  • MalwareBytes Anti-Malware will now check for the latest updates. Click Update Now if new updates are available.
  • Your computer is now being scanned, please do not use your computer during the scan.
  • If no threats were found, click View detailed log.
  • Click Export and save the log as a .txt file on your Desktop or another location.

  • If the scan detected any threats, click Apply Actions.
  • To complete any actions taken you will be prompted to restart your computer...click on Yes.
  • After reboot, start Malwarebytes Anti-Malware again and click the History Tab at the top and select Application Logs.
  • Check the box next to Scan Log. Choose the most current scan and click View.
  • Click Export and save the log as a .txt file on your Desktop or another location.
  • [/list]

  • Providing the MalwareBytes' Anti-Malware log file
  • Attach the log file you just saved to your next reply for further review.

  • >>>
    zcMPezJ.pngAdwCleaner
  • Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool. Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
  • lv0mVRW.pngJunkware Removal Tool
  • Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 gt56

gt56
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:25 PM

Posted 20 March 2015 - 09:22 PM

  • Mozilla Firefox is my current browser.
  • In the Control Panel is the program Pro PC Cleaner, but when I choose Uninstall I get a screen “There is a problem with this Windows Installer package. A DLL required for this install to complete cound not be run.  Contact your support personnel or package vendor.”
  • Ran MalwareBytes Anti-Malware’s full scan - ‘Detected Objects: 0’
  • Ran Adware Cleaner - Showed weather extension and Yahoo search; allowed it to removed Yahoo search
  • Ran Junk Removal Tool - Removed sites I had visited

Originally I was infected with the Binkiland Search. I followed instructions on your site (http://www.bleepingcomputer.com/forums/t/568951/binkiland/). It was not until all was successfully removed, that I noticed the Pro PC Cleaner icon in the Control Panel.
All results are included. Was not sure how to attach to this reply.

 

 

Scan Date: 3/20/2015
Scan Time: 7:31:46 PM
Logfile: MalwareBytes_Log.txt
Administrator: Yes

Version: 2.01.4.1018
Malware Database: v2015.03.21.01
Rootkit Database: v2015.02.25.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Tribs

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 309373
Time Elapsed: 3 min, 37 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

 

 

# AdwCleaner v4.112 - Logfile created 20/03/2015 at 19:41:20
# Updated 09/03/2015 by Xplode
# Database : 2015-03-15.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x86)
# Username : Tribs - TRIBS-PC
# Running from : C:\Users\Tribs\Downloads\AdwCleaner.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17689


-\\ Mozilla Firefox v36.0.1 (x86 en-US)

[8tuwqk2e.default\prefs.js] - Line Deleted : user_pref("startpage.ntsearch_url", "hxxp://search.yahoo.com/search?ei=utf-8&fr=spigot-nt-ff&type=0&ilc=12&p={searchTerms}");

*************************

AdwCleaner[R0].txt - [154042 bytes] - [18/03/2015 17:07:30]
AdwCleaner[R1].txt - [1047 bytes] - [19/03/2015 18:37:37]
AdwCleaner[R2].txt - [1244 bytes] - [20/03/2015 19:39:09]
AdwCleaner[S0].txt - [8766 bytes] - [18/03/2015 17:11:35]
AdwCleaner[S1].txt - [1125 bytes] - [19/03/2015 18:39:06]
AdwCleaner[S2].txt - [1092 bytes] - [20/03/2015 19:41:20]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1151  bytes] ##########

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.5 (03.17.2015:1)
OS: Windows 7 Professional x86
Ran by Tribs on Fri 03/20/2015 at 19:49:38.32
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted the following from C:\Users\Tribs\AppData\Roaming\mozilla\firefox\profiles\pzfe59co.default\prefs.js

user_pref("extensions.trusted-ads.TrustAd", "{\"r\":[{\"t\":\"FQDN\",\"r\":\"trustedads.adtrustmedia.com\",\"c\":[{\"i\":\"1\",\"s\":[\"mmgads.com\",\"www.ad2ad.ir\",\"www.pro
user_pref("extensions.wecarereminder.merchHash", "{\"AFFILIATES\":{\"1-Sale-A-Day\":{\"name\":\"1 Sale A Day\",\"autordr\":1,\"n\":\"3\",\"td\":1.5},\"1and1Internet\":{\"name\



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 03/20/2015 at 19:53:15.42
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 



#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,082 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:25 PM

Posted 20 March 2015 - 10:23 PM

Have you also run ESET ?
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 gt56

gt56
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:25 PM

Posted 21 March 2015 - 11:28 AM

Yes. Once when I got rid of Binkiland and again after this letter. 

The last time shows 'Infected files: 0'



#6 gt56

gt56
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:25 PM

Posted 21 March 2015 - 01:01 PM

Wait.

I did a search for Pro PC Cleaner on my C drive and found it sitting in AdwCleaner quarantine files, from the first scan I ran when trying to remove Binkiland. I am sure I need to remove any file that has the word Binkiland, Pro PC Cleaner and Rainmaker, but am unsure of the rest. Both the Quarantine Text and first Log found in AdwCleaner are included.

 

QUARANTINE TEXT:

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro PC Cleaner\Pro PC Cleaner.lnk->C:\AdwCleaner\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro PC Cleaner\Pro PC Cleaner.lnk.vir
C:\Program Files\Pro PC Cleaner\bo.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\bo.dll.vir
C:\Program Files\Pro PC Cleaner\ComponentFactory.Krypton.Toolkit.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\ComponentFactory.Krypton.Toolkit.dll.vir
C:\Program Files\Pro PC Cleaner\Helper.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Helper.dll.vir
C:\Program Files\Pro PC Cleaner\InstAct.exe->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\InstAct.exe.vir
C:\Program Files\Pro PC Cleaner\InstAct.exe.config->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\InstAct.exe.config.vir
C:\Program Files\Pro PC Cleaner\Interop.Shell32.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Interop.Shell32.dll.vir
C:\Program Files\Pro PC Cleaner\Logging.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Logging.dll.vir
C:\Program Files\Pro PC Cleaner\Microsoft.Deployment.WindowsInstaller.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Microsoft.Deployment.WindowsInstaller.dll.vir
C:\Program Files\Pro PC Cleaner\Microsoft.Deployment.WindowsInstaller.xml->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Microsoft.Deployment.WindowsInstaller.xml.vir
C:\Program Files\Pro PC Cleaner\Microsoft.Win32.TaskScheduler.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Microsoft.Win32.TaskScheduler.dll.vir
C:\Program Files\Pro PC Cleaner\Microsoft.Win32.TaskScheduler.xml->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Microsoft.Win32.TaskScheduler.xml.vir
C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\ProPCCleaner.exe.vir
C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe.config->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\ProPCCleaner.exe.config.vir
C:\Program Files\Pro PC Cleaner\Setup.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Setup.dll.vir
C:\Program Files\Pro PC Cleaner\Splash.exe->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Splash.exe.vir
C:\Program Files\Pro PC Cleaner\Splash.exe.config->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Splash.exe.config.vir
C:\Program Files\Pro PC Cleaner\Uninst000.CA.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Uninst000.CA.dll.vir
C:\Program Files\Pro PC Cleaner\Uninst000.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\Uninst000.dll.vir
C:\Program Files\Pro PC Cleaner\updater.exe->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\updater.exe.vir
C:\Program Files\Pro PC Cleaner\updater.ini->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\updater.ini.vir
C:\Program Files\Pro PC Cleaner\tr-TR\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\tr-TR\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\tr-TR\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\tr-TR\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\th-TH\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\th-TH\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\th-TH\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\th-TH\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\sv\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\sv\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\sv\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\sv\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\sr-Latn-RS\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\sr-Latn-RS\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\sr-Latn-RS\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\sr-Latn-RS\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\sr-Cyrl-RS\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\sr-Cyrl-RS\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\sr-Cyrl-RS\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\sr-Cyrl-RS\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\se-FI\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\se-FI\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\se-FI\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\se-FI\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\no\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\no\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\no\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\no\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\nl\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\nl\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\nl\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\nl\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\ja\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\ja\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\ja\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\ja\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\it\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\it\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\it\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\it\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\hr-HR\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\hr-HR\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\hr-HR\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\hr-HR\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\he\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\he\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\he\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\he\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\fr\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\fr\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\fr\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\fr\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\fil-PH\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\fil-PH\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\fil-PH\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\fil-PH\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\es\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\es\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\es\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\es\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\de\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\de\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\de\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\de\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\da\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\da\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\da\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\da\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\bs-Latn-BA\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\bs-Latn-BA\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\bs-Latn-BA\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\bs-Latn-BA\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\bs-Cyrl-BA\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\bs-Cyrl-BA\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\bs-Cyrl-BA\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\bs-Cyrl-BA\Splash.resources.dll.vir
C:\Program Files\Pro PC Cleaner\ar\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\ar\ProPCCleaner.resources.dll.vir
C:\Program Files\Pro PC Cleaner\ar\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Program Files\Pro PC Cleaner\ar\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Local\Temp\Spigot\SearchProtectionStub.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Local\Temp\Spigot\SearchProtectionStub.exe.vir
C:\Users\Tribs\AppData\Local\Rainmaker_Software_Group_\ProPCCleaner.exe_Url_eu3leohf2lkst0pmyizeddn2uwebg12q\2.5.6.0\user.config->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Local\Rainmaker_Software_Group_\ProPCCleaner.exe_Url_eu3leohf2lkst0pmyizeddn2uwebg12q\2.5.6.0\user.config.vir
C:\Users\Tribs\AppData\Roaming\Search Protection\SP.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Search Protection\SP.exe.vir
C:\Users\Tribs\AppData\Roaming\Search Protection\Uninstall.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Search Protection\Uninstall.exe.vir
C:\Users\Tribs\AppData\Roaming\BrowserExtensions\BEHelper.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\BrowserExtensions\BEHelper.exe.vir
C:\Users\Tribs\AppData\Roaming\BrowserExtensions\Button.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\BrowserExtensions\Button.exe.vir
C:\Users\Tribs\AppData\Roaming\BrowserExtensions\Button64.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\BrowserExtensions\Button64.exe.vir
C:\Users\Tribs\AppData\Roaming\BrowserExtensions\ButtonWrap.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\BrowserExtensions\ButtonWrap.dll.vir
C:\Users\Tribs\AppData\Roaming\BrowserExtensions\ButtonWrap64.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\BrowserExtensions\ButtonWrap64.dll.vir
C:\Users\Tribs\AppData\Roaming\BrowserExtensions\Coupons.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\BrowserExtensions\Coupons.dll.vir
C:\Users\Tribs\AppData\Roaming\BrowserExtensions\Coupons64.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\BrowserExtensions\Coupons64.dll.vir
C:\Users\Tribs\AppData\Roaming\BrowserExtensions\Uninstall.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\BrowserExtensions\Uninstall.exe.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bo.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bo.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ComponentFactory.Krypton.Toolkit.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ComponentFactory.Krypton.Toolkit.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Helper.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Helper.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\InstAct.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\InstAct.exe.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\InstAct.exe.config->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\InstAct.exe.config.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Interop.Shell32.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Interop.Shell32.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Logging.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Logging.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Microsoft.Deployment.WindowsInstaller.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Microsoft.Deployment.WindowsInstaller.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Microsoft.Deployment.WindowsInstaller.xml->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Microsoft.Deployment.WindowsInstaller.xml.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Microsoft.Win32.TaskScheduler.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Microsoft.Win32.TaskScheduler.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Microsoft.Win32.TaskScheduler.xml->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Microsoft.Win32.TaskScheduler.xml.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ProPCCleaner.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ProPCCleaner.exe.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ProPCCleaner.exe.config->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ProPCCleaner.exe.config.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ProPCCleaner.msi->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ProPCCleaner.msi.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Setup.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Setup.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Splash.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Splash.exe.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Splash.exe.config->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Splash.exe.config.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Uninst000.CA.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Uninst000.CA.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Uninst000.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\Uninst000.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\updater.exe->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\updater.exe.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\tr-TR\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\tr-TR\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\tr-TR\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\tr-TR\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\th-TH\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\th-TH\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\th-TH\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\th-TH\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sv\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sv\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sv\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sv\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sr-Latn-RS\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sr-Latn-RS\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sr-Latn-RS\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sr-Latn-RS\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sr-Cyrl-RS\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sr-Cyrl-RS\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sr-Cyrl-RS\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\sr-Cyrl-RS\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\se-FI\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\se-FI\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\se-FI\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\se-FI\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\no\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\no\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\no\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\no\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\nl\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\nl\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\nl\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\nl\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ja\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ja\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ja\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ja\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\it\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\it\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\it\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\it\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\hr-HR\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\hr-HR\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\hr-HR\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\hr-HR\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\he\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\he\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\he\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\he\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\fr\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\fr\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\fr\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\fr\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\fil-PH\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\fil-PH\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\fil-PH\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\fil-PH\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\es\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\es\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\es\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\es\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\de\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\de\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\de\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\de\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\da\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\da\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\da\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\da\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bs-Latn-BA\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bs-Latn-BA\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bs-Latn-BA\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bs-Latn-BA\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bs-Cyrl-BA\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bs-Cyrl-BA\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bs-Cyrl-BA\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\bs-Cyrl-BA\Splash.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ar\ProPCCleaner.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ar\ProPCCleaner.resources.dll.vir
C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ar\Splash.resources.dll->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?\Pro PC Cleaner 2.5.6\install\A5A8ADA\ar\Splash.resources.dll.vir
C:\Users\Tribs\Documents\ProPCCleaner\log.txt->C:\AdwCleaner\Quarantine\C\Users\Tribs\Documents\ProPCCleaner\log.txt.vir
C:\Users\Tribs\Documents\ProPCCleaner\logerror.txt->C:\AdwCleaner\Quarantine\C\Users\Tribs\Documents\ProPCCleaner\logerror.txt.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome.manifest->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome.manifest.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\icon.png->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\icon.png.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\install.rdf->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\install.rdf.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\config.json->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\config.json.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\main.js->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\main.js.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\prefs.txt->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\prefs.txt.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\savingsslider.js->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\savingsslider.js.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\savingsslider.xul->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\savingsslider.xul.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\spigot.js->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}\chrome\content\spigot.js.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome.manifest->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome.manifest.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\icon.png->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\icon.png.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\install.rdf->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\install.rdf.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\config.json->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\config.json.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\ebay.png->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\ebay.png.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\ebay.xul->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\ebay.xul.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\main.js->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\main.js.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\prefs.txt->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\prefs.txt.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\saebay.js->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\saebay.js.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\spigot.js->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}\chrome\content\spigot.js.vir
C:\Users\Public\Desktop\Pro PC Cleaner.lnk->C:\AdwCleaner\Quarantine\C\Users\Public\Desktop\Pro PC Cleaner.lnk.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\bprotector_extensions.sqlite->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\bprotector_extensions.sqlite.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\invalidprefs.js->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\invalidprefs.js.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\user.js->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\user.js.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\searchplugins\yahoo_ff.xml->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\searchplugins\yahoo_ff.xml.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\searchplugins\yahoo_ff.xml->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\searchplugins\yahoo_ff.xml.vir
C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\searchplugins\Binkiland.xml->C:\AdwCleaner\Quarantine\C\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\searchplugins\Binkiland.xml.vir
 

 

LOG:

- - - - - - - - - - - - - - - - - - - -

# AdwCleaner v4.112 - Logfile created 18/03/2015 at 17:07:30
# Updated 09/03/2015 by Xplode
# Database : 2015-03-15.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x86)
# Username : Tribs - TRIBS-PC
# Running from : C:\Users\Tribs\Desktop\to remove Binki\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\Users\Public\Desktop\Pro PC Cleaner.lnk
File Found : C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\searchplugins\Binkiland.xml
File Found : C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\searchplugins\yahoo_ff.xml
File Found : C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\bprotector_extensions.sqlite
File Found : C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\invalidprefs.js
File Found : C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\searchplugins\yahoo_ff.xml
File Found : C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\pzfe59co.default\user.js
Folder Found : C:\Program Files\Pro PC Cleaner
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro PC Cleaner
Folder Found : C:\Users\Tribs\AppData\Local\Rainmaker_Software_Group_
Folder Found : C:\Users\Tribs\AppData\Local\Temp\Spigot
Folder Found : C:\Users\Tribs\AppData\Roaming\BrowserExtensions
Folder Found : C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{50f2ae8a-4cfc-49de-96f2-2660f6dbbcb4}
Folder Found : C:\Users\Tribs\AppData\Roaming\Mozilla\Firefox\Profiles\8tuwqk2e.default\Extensions\{b91e85f8-33ac-4284-a97c-c736f1108e36}
Folder Found : C:\Users\Tribs\AppData\Roaming\Rainmaker Software Group LLC.?
Folder Found : C:\Users\Tribs\AppData\Roaming\Search Protection
Folder Found : C:\Users\Tribs\Documents\ProPCCleaner

***** [ Scheduled tasks ] *****

Task Found : ProPCCleaner_Start
Task Found : ProPCCleaner_Popup

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\AppDataLow\Software\Browser Extensions
Key Found : HKCU\Software\AppDataLow\Software\Search Protection
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\binkiland.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8E57906E-054F-4CF7-8DA3-BD2712F5AFD6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection
Key Found : HKCU\Software\ProPCCleanerConfig
Key Found : HKCU\Software\ProPCCleanerLanguage
Key Found : HKLM\SOFTWARE\Classes\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Extensions]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Search Protection]

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17689

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages] - about:blank
about:blank (repeated 12098 times)

hxxp://binkiland.com/?f=1&a=bnk_frg01_15_12&cd=2XzuyEtN2Y1L1QzutCtD0B0FyEzz0ByByB0ByEtBtAyCyB0FtN0D0Tzu0StCtCyBtCtN1L2XzutAtFzztFtAtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0C0C0BtBzzzzzztG0AtByDyEtGtA0C0EtDtGtByEyByDtGyB0AyCyDyD0B0F0EtDyC0C0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0CzyyBzz0FtDtBtG0EtDyB0FtGyE0CyDyEtG0B0E0ByDtG0D0B0BtB0AyCzztByDtByByE2Q&cr=1160085816&ir=
hxxp://go.microsoft.com/fwlink/?LinkId=69157

-\\ Mozilla Firefox v36.0.1 (x86 en-US)

[8tuwqk2e.default] - Line Found : user_pref("browser.search.hiddenOneOffs", "Binkiland,eBay,Twitter,Yahoo,Yahoo!");
[8tuwqk2e.default] - Line Found : user_pref("browser.startup.homepage", "hxxps://search.yahoo.com/?type=994519&fr=spigot-yhp-ff|hxxp://binkiland.com/?f=1&a=bnk_frg01_15_12&cd=2XzuyEtN2Y1L1QzutCtD0B0FyEzz0ByByB0ByEtBtAyCyB0FtN0D0Tzu0St[...]
[8tuwqk2e.default] - Line Found : user_pref("startpage.ntsearch_url", "hxxps://search.yahoo.com/search?fr=spigot-nt-ff&ei=utf-8&ilc=12&type=994519&p={searchTerms}");
[pzfe59co.default] - Line Found : user_pref("de.soerenrinne.googlebuttons.userlist", "Mail,Web Search,Maps,Calendar,Wave,Dashboard,Translate,Google Shortcuts Settings,LIFE photo archive,");
[pzfe59co.default] - Line Found : user_pref("extensions.aniweather.timeShifted", 125046);
[pzfe59co.default] - Line Found : user_pref("extensions.delta.admin", false);
[pzfe59co.default] - Line Found : user_pref("extensions.delta.aflt", "babsst");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.autoRvrt", "false");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.dfltLng", "en");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.excTlbr", false);
[pzfe59co.default] - Line Found : user_pref("extensions.delta.ffxUnstlRst", true);
[pzfe59co.default] - Line Found : user_pref("extensions.delta.id", "4aa346e000000000000010bf48b77b42");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.instlDay", "15861");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.instlRef", "sst");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.newTab", false);
[pzfe59co.default] - Line Found : user_pref("extensions.delta.prdct", "delta");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.prtnrId", "delta");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.rvrt", "false");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.smplGrp", "none");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.tlbrId", "base");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.tlbrSrchUrl", "");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.vrsn", "1.8.21.5");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.vrsnTs", "1.8.21.55:16:33");
[pzfe59co.default] - Line Found : user_pref("extensions.delta.vrsni", "1.8.21.5");
[pzfe59co.default] - Line Found : user_pref("extensions.delta_i.babExt", "");
[pzfe59co.default] - Line Found : user_pref("extensions.delta_i.babTrack", "affID=122471&tt=gc_");
[pzfe59co.default] - Line Found : user_pref("extensions.delta_i.srcExt", "ss");
[pzfe59co.default] - Line Found : user_pref("extensions.trusted-ads.ExLst", "{\"u\":{\"v\":\"1.70\",\"d\":\"032414\"},\"h\":{\"pogo.com\":{\"p\":[{\"e\":\"/.*/\",\"r\":[\"/connect\\\\.facebook\\\\.net\\\\/en_US\\\\/all\\\\.js$/i\"]}]}[...]
[pzfe59co.default] - Line Found : user_pref("extensions.trusted-ads.list_api", "{\"r\":[\"hxxp://24x7homesecurity.com/\",\"hxxp://a1supplements.com/\",\"hxxp://aactionair.net/\",\"hxxp://abcnews.go.com/\",\"hxxp://adp.com/\",\"hxxp://[...]
[pzfe59co.default] - Line Found : user_pref("extensions.trusted-ads.serpInject", "{\"u\":{\"v\":\"2.74\",\"d\":\"081314\"},\"l\":\"hxxp://search.adtrustmedia.com/search_safecontent.php\",\"e\":[{\"u\":\"hxxp://ads.adtrustmedia.com/con[...]
[pzfe59co.default] - Line Found : user_pref("extensions.trusted-ads.serp_mywebsearch", "\"%2F*!%20serp-mywebsearch%20-%20v0.1.10%20-%202014-04-07%2018%3A21%3A58%20*%2F%0D%0Avar%20u%20%3D%20%7B%7D%3B%0A%0Avar%20Util%20%3D%20%7B%0A%09de[...]
[pzfe59co.default] - Line Found : user_pref("searchreset.backup.browser.newtab.url", "hxxp://start.sweetpacks.com/?barid={54B50E1E-CE39-11E2-B348-10BF48B77B42}&src=97&crg=3.5000006.10045&st=23");
[pzfe59co.default] - Line Found : user_pref("{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=toolbar|babsrc=tb_ss|invocationType=tb50-ie-aolsoftonic-tbsbox-en-us|invocationType=tb50-ff-aolsoftonic[...]
[pzfe59co.default] - Line Found : user_pref("{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"home.mywebsearch.com\":\"searc[...]
[pzfe59co.default] - Line Found : user_pref("{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}.ScriptData_product_name", "Updater By SweetPacks");
[pzfe59co.default] - Line Found : user_pref("browser.startup.homepage", "hxxps://search.yahoo.com/?type=994519&fr=spigot-yhp-ff|hxxp://binkiland.com/?f=1&a=bnk_frg01_15_12&cd=2XzuyEtN2Y1L1QzutCtD0B0FyEzz0ByByB0ByEtBtAyCyB0FtN0D0Tzu0St[...]
*************************

AdwCleaner[R0].txt - [153900 bytes] - [18/03/2015 17:07:30]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [153961 bytes] ##########
 



#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,082 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:25 PM

Posted 21 March 2015 - 07:19 PM

Now remove what ADW found.

A file in Quarantine can no longer harm the PC.


Double click on AdwCleaner.exe to run the tool again. Vista/Windows 7/8 users right-click and select Run As Administrator
  • The tool will start to update the database, please wait a bit.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
  • This time click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 gt56

gt56
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:25 PM

Posted 22 March 2015 - 01:30 AM

Happy to report the malware is gone, but Pro PC Cleaner still shows in Programs in the Control Panel. 

Any way to remove that too?

 

 

# AdwCleaner v4.112 - Logfile created 22/03/2015 at 00:23:15
# Updated 09/03/2015 by Xplode
# Database : 2015-03-21.2 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x86)
# Username : Tribs - TRIBS-PC
# Running from : C:\Users\Tribs\Downloads\AdwCleaner.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17689


-\\ Mozilla Firefox v36.0.1 (x86 en-US)

[pzfe59co.default\prefs.js] - Line Deleted : user_pref("extensions.aniweather.timeShifted", 1069856);

*************************

AdwCleaner[R0].txt - [845 bytes] - [21/03/2015 21:44:15]
AdwCleaner[R1].txt - [903 bytes] - [22/03/2015 00:22:02]
AdwCleaner[S0].txt - [842 bytes] - [22/03/2015 00:23:15]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [900  bytes] ########



#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,082 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:25 PM

Posted 23 March 2015 - 09:25 AM

If you cannot remove it in Control Panel using Uninstall try.... Malwarebytes' File Assassin.


Open MBAM and click on the More Tools tab.

1.Start FileASSASSIN and select a file by dragging it onto the text area or select it using the (...) button.
2.Select a removal method from the list.
3.Click Execute and the removal process will commence.
Warning: Please use caution with FileASSASSIN as deleting critical system files may cause system errors.
In other words be sure to click on the correct file to remove.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 gt56

gt56
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:25 PM

Posted 23 March 2015 - 06:42 PM

Unable to drag a program listed in the Control Panels list of Programs in Add and Remove to File Assassin.

Is there a way to manually remove it from the registry?  I do still see remnants fo it and Rainmaker. 


Edited by gt56, 23 March 2015 - 06:43 PM.


#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,082 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:25 PM

Posted 24 March 2015 - 04:00 PM

Try using REVO

You have unwanted programs on your computer system that should be removed.
I recommend using the following program to do this because it is good at removing any stray remnants that uninstallers often leave behind.

1. Please download REVO UNINSTALLER
and save it on your computer.

2. Install Revo Uninstaller on your computer system.

3. Once the program is installed start the program and insure the uninstaller tab is active. (See image below)

revo-main-menu.png

Icons from all your installed programs will appear alphabetically in the main window.

4. Right click the program you wish to uninstall by selecting the program's icon in the main window.
A menu will appear such as that shown below.

revo-uninstall.png

5. Next, choose Uninstall from this menu.

A confirmation from the program you wish to uninstall will appear on your screen, such as the one shown in the image below.

6. Please choose YES that you wish to uninstall the program.

revo-confirm.png

By default, Revo Uninstaller will be set to Moderate uninstall Mode.
Please change it to Advanced by clicking the radio button near Advanced as shown below and then click the NEXT button.

revo-advanced1.png

7. Next, you will see this screen where a system restore back up is made.

uninstall-1.png

The program's built in uninstaller will appear on screen, confirm removal and the uninstall procedure will begin.

confirm.png

The program you uninstalled will confirm it has been uninstalled and may ask for user feedback as shown below. It is really your choice if you wish to take the time to answer their survey, however it is not important if you do or not and you can skip it by clicking NO

uninstall-complete.png

If you are told to reboot to complete the uninstall, choose NO! We still have other things we need to remove from your computer using Revo Uninstaller's other features.

8. Once the program has been successfully uninstalled, click the NEXT button.

next-button.png

Revo Uninstaller will scan your computer for leftover information, files and registry entries.

leftover-info.png

If any registry entries are found, Revo Uninstaller will list those in BOLD text as shown below.

leftover-registry.png

It is safe to remove those entries as they are often only associated with the program you have just removed from your computer system.

9. Look for the Select All button and click it.
All the BOLD entries should now be checked off like shown in the image below.

select-all.png

Look for the DELETE button and click it.
When asked to confirm the deletion, click YES

confirm-delete-registry.png

When finished click the Next button.

Revo may confirm the uninstall is complete and offer a FINISH button. This means the program has been successfully uninstalled and no further action is needed.

If however, any leftover files and folders are found those will be presented. If you want to get rid of them click Select All then Delete.
This will remove those and send them to your RECYCLE BIN. The image below shows Revo Uninstaller asking for your confirmation, before sending them to the recycle bin, simply choose the Yes Button and away they go to the trash. You can then either retrieve them or clean your recycle bin permanently removing them from your computer system.

revo5.png

You can use Revo Uninstaller to remove other unwanted programs from your computer by performing the above procedures for each one.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#12 gt56

gt56
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:25 PM

Posted 24 March 2015 - 06:26 PM

Wow!  I am impressed.  Thanks so much for sticking with me on this and helping me get rid of this garbage.  Thank you.  You are the best.  :bowdown:



#13 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,082 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:25 PM

Posted 24 March 2015 - 07:00 PM

You're very welcome!!

Empty your temp folders using TFC (Temporary File Cleaner)
  • Please download TFC by Old Timer and save it to your desktop.
    alternate download link
  • Save any unsaved work. (TFC will close ALL open programs including your browser!)
  • Double-click on TFC.exe to run it. (If you are using Vista or above, right-click on the file and choose "Run As Administrator".)
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway allowing Windows to load normally (not into Safe Mode) to ensure a complete clean.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users