WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptioncomputer is being strange!! Emptycomputer is being strange!!

more_horiz
Hello,
I have used your fantastic service before when our home computer started acting up and has been really good for a while until yesterday and i am getting all sorts of redirections away from the actual page that i want.
I tried to scan my computer with Microsoft essentials protection that we have but it failed to scan properly.
Please can you help me sort out this computer.

Kind Regards
Debbie Hornshaw

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
Please download AdwCleaner by Xplode onto your Desktop.

Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon.

computer is being strange!! AdwCleaner-icon

If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run.
When the AdwCleaner program will open, click on the Scan button as shown below.

computer is being strange!! Untitled

AdwCleaner will now start to search for malicious files that may be installed on your computer.
To remove the files that were detected in the previous step, please click on the Clean button.

computer is being strange!! 3

AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer.
Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply.
*********************************************
computer is being strange!! Mbamicontw5 Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.

  • It should update automatically if the computer is connected to the internet.
  • Click on Threat Scan and click on Scan Now.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete make sure all the infections have "quarantine" selected in the Action box.
  • Click on "Apply actions" You may be asked to Restart your computer to completely remove the infections.
  • When disinfection is completed you can click on "Copy to Clipboard".
  • Paste the log in you next reply (CTRL+ V)

*************************************************
Please download Junkware Removal Tool to your desktop.

Warning! Once the scan is complete JRT will shut down your browser with NO warning.

Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
*****************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
# AdwCleaner v5.005 - Logfile created 04/09/2015 at 07:39:15
# Updated 31/08/2015 by Xplode
# Database : 2015-08-31.2 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
# Username : Robert Hornshaw - ROBERT
# Running from : C:\Users\Robert Hornshaw\Downloads\adwcleaner_5.005.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****

[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage-journal
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_download-freemaps.dl.tb.ask.com_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_download-freemaps.dl.tb.ask.com_0.localstorage-journal

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25D62E1A-BD8B-4E6E-B7CC-1E0EE04A4622}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{062D6B05-B83A-46DE-81AD-1750FB7C8DE5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{92B0265C-B929-4D42-BA54-75AA39C99198}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2ADDCC11-40AD-4244-AFC6-90FEEB3BB2E9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A9994E4-A107-4C07-ABE2-832242BF8486}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{71593183-19AB-4FB2-9477-0C396E232CE8}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9664E31F-B2BC-4DE2-87C7-43694E33ECC4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A12635F7-09EA-479C-8FA0-65C98B053C3A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C43DDE8B-9428-4C43-9A64-FC66912FE6A4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DD51B24F-4AD0-43E2-83BB-ED9AF4475A0D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E9934F5D-7A0F-4240-A709-11C91854CE21}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38122A36-83B2-46B8-B39A-EC72A4614A07}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25D62E1A-BD8B-4E6E-B7CC-1E0EE04A4622}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66D59105-FE06-43A4-B292-EB0097E9EB74}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8AADC8B2-562B-407B-88B3-916140226CBC}
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar
[!] Key Not Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar
[!] Key Not Deleted : HKU\S-1-5-18\Software\AppDataLow\Software\AVG Security Toolbar
[-] Key Deleted : HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
[-] Key Deleted : HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

***** [ Web browsers ] *****

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download-freemaps.dl.tb.ask.com_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download-freemaps.dl.tb.ask.com_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download-freemaps.dl.tb.ask.com_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download-freemaps.dl.tb.ask.com_0.localstorage-journal.vir

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
I hope i have posted everything correctly what you require, the computer is still redirecting me to other web pages and the junkware removal page is saying it isnt being found!!

Kind Regards
Debbie Hornshaw

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Yes Debbie, I need to see the other logs; MBAM and Security Check

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
# AdwCleaner v5.005 - Logfile created 04/09/2015 at 07:37:04
# Updated 31/08/2015 by Xplode
# Database : 2015-08-31.2 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
# Username : Robert Hornshaw - ROBERT
# Running from : C:\Users\Robert Hornshaw\Downloads\adwcleaner_5.005.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****

File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage-journal
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_download-freemaps.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_download-freemaps.dl.tb.ask.com_0.localstorage-journal

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\CLSID\{25D62E1A-BD8B-4E6E-B7CC-1E0EE04A4622}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{062D6B05-B83A-46DE-81AD-1750FB7C8DE5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{92B0265C-B929-4D42-BA54-75AA39C99198}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2ADDCC11-40AD-4244-AFC6-90FEEB3BB2E9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4A9994E4-A107-4C07-ABE2-832242BF8486}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{71593183-19AB-4FB2-9477-0C396E232CE8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9664E31F-B2BC-4DE2-87C7-43694E33ECC4}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A12635F7-09EA-479C-8FA0-65C98B053C3A}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C43DDE8B-9428-4C43-9A64-FC66912FE6A4}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DD51B24F-4AD0-43E2-83BB-ED9AF4475A0D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E9934F5D-7A0F-4240-A709-11C91854CE21}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25D62E1A-BD8B-4E6E-B7CC-1E0EE04A4622}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66D59105-FE06-43A4-B292-EB0097E9EB74}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8AADC8B2-562B-407B-88B3-916140226CBC}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar
Key Found : HKU\S-1-5-18\Software\AppDataLow\Software\AVG Security Toolbar
Key Found : HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Found : HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

***** [ Web browsers ] *****


########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [3898 bytes] ##########

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
is that correct??

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
# AdwCleaner v5.005 - Logfile created 04/09/2015 at 07:37:04
# Updated 31/08/2015 by Xplode
# Database : 2015-08-31.2 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
# Username : Robert Hornshaw - ROBERT
# Running from : C:\Users\Robert Hornshaw\Downloads\adwcleaner_5.005.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****

File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage-journal
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_download-freemaps.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_download-freemaps.dl.tb.ask.com_0.localstorage-journal

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\CLSID\{25D62E1A-BD8B-4E6E-B7CC-1E0EE04A4622}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{062D6B05-B83A-46DE-81AD-1750FB7C8DE5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{92B0265C-B929-4D42-BA54-75AA39C99198}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2ADDCC11-40AD-4244-AFC6-90FEEB3BB2E9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4A9994E4-A107-4C07-ABE2-832242BF8486}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{71593183-19AB-4FB2-9477-0C396E232CE8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9664E31F-B2BC-4DE2-87C7-43694E33ECC4}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A12635F7-09EA-479C-8FA0-65C98B053C3A}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C43DDE8B-9428-4C43-9A64-FC66912FE6A4}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DD51B24F-4AD0-43E2-83BB-ED9AF4475A0D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E9934F5D-7A0F-4240-A709-11C91854CE21}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25D62E1A-BD8B-4E6E-B7CC-1E0EE04A4622}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66D59105-FE06-43A4-B292-EB0097E9EB74}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8AADC8B2-562B-407B-88B3-916140226CBC}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar
Key Found : HKU\S-1-5-18\Software\AppDataLow\Software\AVG Security Toolbar
Key Found : HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Found : HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

***** [ Web browsers ] *****


########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [3898 bytes] ##########C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download-freemaps.dl.tb.ask.com_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download-freemaps.dl.tb.ask.com_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download-freemaps.dl.tb.ask.com_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download-freemaps.dl.tb.ask.com_0.localstorage-journal.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage.vir
C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal->C:\AdwCleaner\Quarantine\C\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal.vir

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
The junkware removal link that you sent is giving me a code of 404 not found so i cant do that bit!

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Please run AdwCleaner again and hit the clean or delete button. There is a problem with JRT. I would also like to see the Security Check log.

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
How do i get the security check log? I have posted the log from the adware clean below for you which i have just run again.# AdwCleaner v5.005 - Logfile created 06/09/2015 at 08:36:58
# Updated 31/08/2015 by Xplode
# Database : 2015-09-04.4 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
# Username : Robert Hornshaw - ROBERT
# Running from : C:\Users\Robert Hornshaw\Downloads\adwcleaner_5.005 (2).exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****

[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage-journal
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

[-] [C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : uk.ask.com
[-] [C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : 3d-chess-game-windows-8.en.softonic.com

*************************

:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C4].txt - [1921 bytes] ##########

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
sorry!! I have done the security check and here areMalwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 06/09/2015
Scan Time: 16:22:04
Logfile:
Administrator: Yes

Version: 2.01.6.1022
Malware Database: v2015.09.06.03
Rootkit Database: v2015.08.16.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: Robert Hornshaw

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 429475
Time Elapsed: 41 min, 9 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 2
PUP.Optional.ReMarkable, C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, , [515ab17b523954e21eca77316c98c937],
PUP.Optional.ReMarkable, C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, , [7b30a28a0b8042f46583b2f6dc28d32d],

Physical Sectors: 0
(No malicious items detected)


(end) the results as follows.

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
computer is still redirecting me to various pages!! Sorry to be a pain!

Kind Regards
Debbie

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
How do i get the security check log?

Just click on linke 1 or 2 I have posted in my first reply.
Also, please run MBAM again to see if it comes up clean.


I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the computer is being strange!! EsetOnline button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on computer is being strange!! EsetSmartInstall to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the computer is being strange!! EsetSmartInstallDesktopIcon-1 icon on your desktop.

•Check computer is being strange!! EsetAcceptTerms
•Click the computer is being strange!! EsetStart button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check computer is being strange!! EsetScanArchives
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push computer is being strange!! EsetListThreats
•Push computer is being strange!! EsetExport, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the computer is being strange!! EsetBack button.
•Push computer is being strange!! EsetFinish
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=97b99416ca10cb488f04034e4f46c2b6
# end=init
# utc_time=2015-09-07 07:04:43
# local_time=2015-09-07 08:04:43 (+0000, GMT Daylight Time)
# country="United Kingdom"
# osver=6.0.6002 NT Service Pack 2
Update Init
Update Download
Update Finalize
Updated modules version: 25634
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=97b99416ca10cb488f04034e4f46c2b6
# end=updated
# utc_time=2015-09-07 07:09:55
# local_time=2015-09-07 08:09:55 (+0000, GMT Daylight Time)
# country="United Kingdom"
# osver=6.0.6002 NT Service Pack 2
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=97b99416ca10cb488f04034e4f46c2b6
# engine=25634
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-09-07 11:19:42
# local_time=2015-09-07 12:19:42 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 10117919 64601576 0 0
# scanned=514720
# found=59
# cleaned=0
# scan_time=14987
sh=DF9ED474C61475C18BAA617128959B4E1D4A1139 ft=1 fh=fcebc6768eea5b76 vn="a variant of Win32/Downloader.Delf.A potentially unwanted application" ac=I fn="C:\$RECYCLE.BIN\S-1-5-21-2587230002-3812537154-1661091937-1000\$R0UUUQS.exe"
sh=08EEA8C5839D81CF4FE8C4D7C304F84757C4B99B ft=1 fh=41dc015150d2b8d9 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12auxstb.dll.vir"
sh=8872824DA370A893AF27EDA5914C81B016FDE10D ft=1 fh=7df6b6eaf73c436e vn="a variant of Win64/Toolbar.MyWebSearch.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12auxstb64.dll.vir"
sh=352E15324D870431C6A80AEFA1B3826AF5F8AD7B ft=1 fh=d498158229edd61d vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12bar.dll.vir"
sh=2DB76E64C44398F284BB9607477FFAB286C822A5 ft=1 fh=a15fd42821542f57 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12barsvc.exe.vir"
sh=3E702CCA69804CDADE4A916C4666099B252CEC46 ft=1 fh=3ff9f90724b61074 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12bprtct.dll.vir"
sh=242016E4DB00A6326CB726E517BD8C44C0D9AF4F ft=1 fh=5585cde8f9518639 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12brmon.exe.vir"
sh=BD3BA77A76482B8432E852B6C12718DFD8A805E8 ft=1 fh=d0f2a63db6645c6c vn="a variant of Win64/Toolbar.MyWebSearch.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12brmon64.exe.vir"
sh=43057F202484834CAED5265AF9ADBD5C1C00C47C ft=1 fh=cbe7b8075d97fef6 vn="a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12brstub.dll.vir"
sh=E22F1101BCDB847DDA207076C20847EE7BA14783 ft=1 fh=6dacd07894aac7d3 vn="a variant of Win64/Toolbar.MyWebSearch.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12brstub64.dll.vir"
sh=6F8E675C0259BDB7CEEADA861381E8655E3882FD ft=1 fh=0c2cde178f5cb3ea vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12datact.dll.vir"
sh=D14FF0D978C0818F3219AB303258B61961E24B5B ft=1 fh=95d16e31093cddf4 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12dlghk.dll.vir"
sh=BFF74D4CF269E36527CE43A484298A7797D85DDB ft=1 fh=e0568f6273d6b1f6 vn="a variant of Win64/Toolbar.MyWebSearch.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12dlghk64.dll.vir"
sh=4B8694F7BFF75DDF2A99D67136B9FCAA8BCBF818 ft=1 fh=54e43688a7d5acff vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12feedmg.dll.vir"
sh=03E45FC678FA04E05647FE60BBC68BB08AECE2A2 ft=1 fh=8b53f416e8ada167 vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12highin.exe.vir"
sh=0FAA086438AAC60EC0C682BC7D976219F4DA2391 ft=1 fh=9f4b0c0053402bd0 vn="Win32/Toolbar.MyWebSearch.AM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12hkstub.dll.vir"
sh=8000F7F069170BA3962B6D1DE97641CB8E8795E6 ft=1 fh=41956871b2c6a631 vn="a variant of Win32/Toolbar.MyWebSearch.AT potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12htmlmu.dll.vir"
sh=56E4F2B4EC1A6E8836C2541D66E710DABCA48FB3 ft=1 fh=bc873fb5e0ff5b6a vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12httpct.dll.vir"
sh=7318474377B8A97C09E8B4E76BC84CD967F41425 ft=1 fh=2cc6ec5e6a8fb481 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12idle.dll.vir"
sh=B17E3F03EDE4F7710DD0678C170FEFC0457ACF7D ft=1 fh=03d8ea72626c5942 vn="Win32/Toolbar.MyWebSearch.AG potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12ieovr.dll.vir"
sh=7EA3B8DAD33B1BF24CA0AFE285257D65CB6AA477 ft=1 fh=b9d84b03cd6d0f27 vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12medint.exe.vir"
sh=0BFBBF33F74B6E9187D80CDD84DD49997DE10DBC ft=1 fh=7e5ba4990ad2843d vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12mlbtn.dll.vir"
sh=AD9FAD90CC49091BBEA91AA9829BA7C7DE57A080 ft=1 fh=333fc276c8268012 vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12Plugin.dll.vir"
sh=E591A3DBC8B508F86149B610BDD39DF799C101FA ft=1 fh=e63430e62a50e4d1 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12radio.dll.vir"
sh=08B86C2A2D83758DC2A2737519E99B6409BFCE4A ft=1 fh=aae2e643a8115a99 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12regfft.dll.vir"
sh=EB72B3FD8A5091CEBC62873FBF045E42A07925D1 ft=1 fh=48d010e3b86cf0db vn="a variant of Win32/Toolbar.MyWebSearch.AK potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12reghk.dll.vir"
sh=5A7521CEEC575EF85C8E191C4331DF8888B3A22B ft=1 fh=890daf73d694e35c vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12regiet.dll.vir"
sh=80650AAB853B1ACEBE666EC834BE9AE519116254 ft=1 fh=88f6e6dcc31aacd1 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12script.dll.vir"
sh=1A401BBE5BA7C679A6B56A2F335D8AF67A063C4A ft=1 fh=22f921539bef2c08 vn="a variant of Win32/Toolbar.MyWebSearch.P potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12skin.dll.vir"
sh=213828740B318856D4E2FDD3A6547915388047A7 ft=1 fh=3c1b043f447a01dd vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12skplay.exe.vir"
sh=C2989D1054DEF8375543745EB246AC09139DBB99 ft=1 fh=9502a7177dbba1c1 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12SrcAs.dll.vir"
sh=B98D80A58AC1E84CC296C3D822A489E17A45B042 ft=1 fh=e3a00bd945cd82af vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12SrchMn.exe.vir"
sh=DF8005C51D4EE75E9C3CEE21A96FDCA75EF2E71B ft=1 fh=24159591b5465636 vn="a variant of Win32/Toolbar.MyWebSearch.AK potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12srchmr.dll.vir"
sh=72489280930F183E34FE5AF817F207A5EB65F8D4 ft=1 fh=033eb58713fd33d4 vn="a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12tpinst.dll.vir"
sh=6EC5E158787B12F765B36EA5A16C879A6A0A9E9D ft=1 fh=0cf43fe14bb44f80 vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\APPINTEGRATOR.EXE.vir"
sh=F76EBFB49A14135188A858A9A19ADE33D841FAD9 ft=1 fh=fd6523e46258979f vn="a variant of Win64/Toolbar.MyWebSearch.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\AppIntegrator64.exe.vir"
sh=B072CCA78C74E55E8950EF3C35C7C4F7877739D1 ft=1 fh=51845fb3eae1c0f2 vn="Win32/Toolbar.MyWebSearch.AM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\APPINTEGRATORSTUB.DLL.vir"
sh=385877E899E02E0F9C551D5B3293270C5FEB9D6B ft=1 fh=fc49323ed3498cd9 vn="a variant of Win64/Toolbar.MyWebSearch.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\AppIntegratorStub64.dll.vir"
sh=3C2251BC6DBC556B960D82FC7211B6005A613A8A ft=1 fh=e2babb33b836a3b5 vn="a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\ASSISTMONITOR.DLL.vir"
sh=E9C0F7642BFDCA4F304679F44A2351765D25D7E3 ft=1 fh=df272951a00ae964 vn="a variant of Win64/Toolbar.MyWebSearch.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\ASSISTMONITOR64.DLL.vir"
sh=5B52C97808B05C61C42C660EF788C6E30E9956D1 ft=1 fh=3bd8668ff345b3ba vn="a variant of Win32/Toolbar.MyWebSearch.Z potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\CREXT.DLL.vir"
sh=C0F1C1AD7E3E71F00D10961BF88368998314C8B5 ft=1 fh=1104306037fac477 vn="a variant of Win32/Toolbar.MyWebSearch.AR potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\CrExtP12.exe.vir"
sh=1B7027E34F895FA1E93C6CEDD86EB8415F086E5C ft=1 fh=0f1abfa76a5eafd1 vn="a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\DPNMNGR.DLL.vir"
sh=FA366450E70C686F15807DAD7D890CA19C739EE4 ft=1 fh=c3b0d1b55e33b10b vn="a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\EXEMANAGER.DLL.vir"
sh=ED7CCFFE86134DB07B0BEE73EC86B99C7243897A ft=1 fh=30bb44c368d084a2 vn="a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\FF-NativeMessagingDispatcher.dll.vir"
sh=2C88C56E84FB90C27DA50DF87011A98C77362B19 ft=1 fh=054dd36e0a8ce909 vn="a variant of Win64/Toolbar.MyWebSearch.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\Hpg64.dll.vir"
sh=D99BD974FF5A9502B17CFFB6E721F1B46C5B25E9 ft=1 fh=e75af964f60c8f9c vn="Win32/Toolbar.MyWebSearch.AI potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\NP12Stub.dll.vir"
sh=AFDF3F69BEB1CDE4A5AA1D9EE5BEFD8A5DE808D7 ft=1 fh=6f20f9ce0b4866ad vn="a variant of Win32/Toolbar.MyWebSearch.AU potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8EPMSUP.DLL.vir"
sh=ACBBE4D6CB48DD5CF142D79FDFEECBD7F9E9854E ft=1 fh=c0c375ff197f91b8 vn="a variant of Win32/Toolbar.MyWebSearch.AU potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8EXTEX.DLL.vir"
sh=BB1DF373EBE307C63271B72B7905E86FBF58D2CB ft=1 fh=16b6d8b2476550db vn="a variant of Win32/Toolbar.MyWebSearch.AU potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8EXTPEX.DLL.vir"
sh=0C27996F6F6194AA4EE5DA4031A78B9E304B05E3 ft=1 fh=44a79e41ea9fa8ee vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8HTML.DLL.vir"
sh=88A01244271EF4EE3E78DDCEAF4287D4B053ED9A ft=1 fh=6b89c95ed44a94f1 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8TICKER.DLL.vir"
sh=BC3EDB50A86B8838EB86DA38B2012A16B4ABBDC5 ft=1 fh=a52b1d8d089a2cba vn="Win32/Toolbar.MyWebSearch.AI potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\TPIMANAGERCONSOLE.EXE.vir"
sh=E773874752E4170F8A04CB32ADACE5204A8C28B2 ft=1 fh=5f04f5f98ab14616 vn="a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\UNIFIEDLOGGING.DLL.vir"
sh=AB85089131865A0535CD21A15D60C00AA7C425A2 ft=1 fh=13b78041014ac185 vn="a variant of Win32/Toolbar.MyWebSearch.AU potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\VERIFY.DLL.vir"
sh=BE577FE27B2453B16A2A2D3ADE8A40DA510ED4CC ft=1 fh=f175fa7624bffb79 vn="a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\assists\ie_default_search_provider\ARBITER.DLL.vir"
sh=527A15F6D343F750733C47FA8E2561894CE31D2A ft=1 fh=fc06c72d9fe6c9c7 vn="Win64/Toolbar.MyWebSearch.C potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\assists\ie_default_search_provider\ARBITER64.DLL.vir"
sh=AC297627AB9AB7AD194EC4E3CDE50D2A42F9A4FA ft=1 fh=609aefa527ec4346 vn="Win32/Toolbar.MyWebSearch.AF potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\assists\ie_default_search_provider\ASSIST.EXE.vir"
sh=03E190B747DC937BDE6CC210FBCC4676F0C84B9C ft=1 fh=f58098137308c9c0 vn="a variant of Win32/TorchMedia potentially unwanted application" ac=I fn="C:\Users\Robert Hornshaw\AppData\Local\temp\nst2BCE.tmp\Uninstall.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=97b99416ca10cb488f04034e4f46c2b6
# end=init
# utc_time=2015-09-07 07:27:17
# local_time=2015-09-07 08:27:17 (+0000, GMT Daylight Time)
# country="United Kingdom"
# osver=6.0.6002 NT Service Pack 2
Update Init
Update Download
Update Finalize
Updated modules version: 25646
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=97b99416ca10cb488f04034e4f46c2b6
# end=updated
# utc_time=2015-09-07 07:27:53
# local_time=2015-09-07 08:27:53 (+0000, GMT Daylight Time)
# country="United Kingdom"
# osver=6.0.6002 NT Service Pack 2
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=97b99416ca10cb488f04034e4f46c2b6
# engine=25646
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-09-07 11:07:15
# local_time=2015-09-08 12:07:15 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 10160372 64644029 0 0
# scanned=538731
# found=59
# cleaned=59
# scan_time=13161
sh=DF9ED474C61475C18BAA617128959B4E1D4A1139 ft=1 fh=fcebc6768eea5b76 vn="a variant of Win32/Downloader.Delf.A potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\$RECYCLE.BIN\S-1-5-21-2587230002-3812537154-1661091937-1000\$R0UUUQS.exe"
sh=08EEA8C5839D81CF4FE8C4D7C304F84757C4B99B ft=1 fh=41dc015150d2b8d9 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12auxstb.dll.vir"
sh=8872824DA370A893AF27EDA5914C81B016FDE10D ft=1 fh=7df6b6eaf73c436e vn="a variant of Win64/Toolbar.MyWebSearch.B potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12auxstb64.dll.vir"
sh=352E15324D870431C6A80AEFA1B3826AF5F8AD7B ft=1 fh=d498158229edd61d vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12bar.dll.vir"
sh=2DB76E64C44398F284BB9607477FFAB286C822A5 ft=1 fh=a15fd42821542f57 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12barsvc.exe.vir"
sh=3E702CCA69804CDADE4A916C4666099B252CEC46 ft=1 fh=3ff9f90724b61074 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12bprtct.dll.vir"
sh=242016E4DB00A6326CB726E517BD8C44C0D9AF4F ft=1 fh=5585cde8f9518639 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12brmon.exe.vir"
sh=BD3BA77A76482B8432E852B6C12718DFD8A805E8 ft=1 fh=d0f2a63db6645c6c vn="a variant of Win64/Toolbar.MyWebSearch.B potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12brmon64.exe.vir"
sh=43057F202484834CAED5265AF9ADBD5C1C00C47C ft=1 fh=cbe7b8075d97fef6 vn="a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12brstub.dll.vir"
sh=E22F1101BCDB847DDA207076C20847EE7BA14783 ft=1 fh=6dacd07894aac7d3 vn="a variant of Win64/Toolbar.MyWebSearch.B potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12brstub64.dll.vir"
sh=6F8E675C0259BDB7CEEADA861381E8655E3882FD ft=1 fh=0c2cde178f5cb3ea vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12datact.dll.vir"
sh=D14FF0D978C0818F3219AB303258B61961E24B5B ft=1 fh=95d16e31093cddf4 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12dlghk.dll.vir"
sh=BFF74D4CF269E36527CE43A484298A7797D85DDB ft=1 fh=e0568f6273d6b1f6 vn="a variant of Win64/Toolbar.MyWebSearch.B potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12dlghk64.dll.vir"
sh=4B8694F7BFF75DDF2A99D67136B9FCAA8BCBF818 ft=1 fh=54e43688a7d5acff vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12feedmg.dll.vir"
sh=03E45FC678FA04E05647FE60BBC68BB08AECE2A2 ft=1 fh=8b53f416e8ada167 vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12highin.exe.vir"
sh=0FAA086438AAC60EC0C682BC7D976219F4DA2391 ft=1 fh=9f4b0c0053402bd0 vn="Win32/Toolbar.MyWebSearch.AM potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12hkstub.dll.vir"
sh=8000F7F069170BA3962B6D1DE97641CB8E8795E6 ft=1 fh=41956871b2c6a631 vn="a variant of Win32/Toolbar.MyWebSearch.AT potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12htmlmu.dll.vir"
sh=56E4F2B4EC1A6E8836C2541D66E710DABCA48FB3 ft=1 fh=bc873fb5e0ff5b6a vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12httpct.dll.vir"
sh=7318474377B8A97C09E8B4E76BC84CD967F41425 ft=1 fh=2cc6ec5e6a8fb481 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12idle.dll.vir"
sh=B17E3F03EDE4F7710DD0678C170FEFC0457ACF7D ft=1 fh=03d8ea72626c5942 vn="Win32/Toolbar.MyWebSearch.AG potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12ieovr.dll.vir"
sh=7EA3B8DAD33B1BF24CA0AFE285257D65CB6AA477 ft=1 fh=b9d84b03cd6d0f27 vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12medint.exe.vir"
sh=0BFBBF33F74B6E9187D80CDD84DD49997DE10DBC ft=1 fh=7e5ba4990ad2843d vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12mlbtn.dll.vir"
sh=AD9FAD90CC49091BBEA91AA9829BA7C7DE57A080 ft=1 fh=333fc276c8268012 vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12Plugin.dll.vir"
sh=E591A3DBC8B508F86149B610BDD39DF799C101FA ft=1 fh=e63430e62a50e4d1 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12radio.dll.vir"
sh=08B86C2A2D83758DC2A2737519E99B6409BFCE4A ft=1 fh=aae2e643a8115a99 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12regfft.dll.vir"
sh=EB72B3FD8A5091CEBC62873FBF045E42A07925D1 ft=1 fh=48d010e3b86cf0db vn="a variant of Win32/Toolbar.MyWebSearch.AK potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12reghk.dll.vir"
sh=5A7521CEEC575EF85C8E191C4331DF8888B3A22B ft=1 fh=890daf73d694e35c vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12regiet.dll.vir"
sh=80650AAB853B1ACEBE666EC834BE9AE519116254 ft=1 fh=88f6e6dcc31aacd1 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12script.dll.vir"
sh=1A401BBE5BA7C679A6B56A2F335D8AF67A063C4A ft=1 fh=22f921539bef2c08 vn="a variant of Win32/Toolbar.MyWebSearch.P potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12skin.dll.vir"
sh=213828740B318856D4E2FDD3A6547915388047A7 ft=1 fh=3c1b043f447a01dd vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12skplay.exe.vir"
sh=C2989D1054DEF8375543745EB246AC09139DBB99 ft=1 fh=9502a7177dbba1c1 vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12SrcAs.dll.vir"
sh=B98D80A58AC1E84CC296C3D822A489E17A45B042 ft=1 fh=e3a00bd945cd82af vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12SrchMn.exe.vir"
sh=DF8005C51D4EE75E9C3CEE21A96FDCA75EF2E71B ft=1 fh=24159591b5465636 vn="a variant of Win32/Toolbar.MyWebSearch.AK potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12srchmr.dll.vir"
sh=72489280930F183E34FE5AF817F207A5EB65F8D4 ft=1 fh=033eb58713fd33d4 vn="a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\12tpinst.dll.vir"
sh=6EC5E158787B12F765B36EA5A16C879A6A0A9E9D ft=1 fh=0cf43fe14bb44f80 vn="a variant of Win32/Toolbar.MyWebSearch.AJ potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\APPINTEGRATOR.EXE.vir"
sh=F76EBFB49A14135188A858A9A19ADE33D841FAD9 ft=1 fh=fd6523e46258979f vn="a variant of Win64/Toolbar.MyWebSearch.A potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\AppIntegrator64.exe.vir"
sh=B072CCA78C74E55E8950EF3C35C7C4F7877739D1 ft=1 fh=51845fb3eae1c0f2 vn="Win32/Toolbar.MyWebSearch.AM potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\APPINTEGRATORSTUB.DLL.vir"
sh=385877E899E02E0F9C551D5B3293270C5FEB9D6B ft=1 fh=fc49323ed3498cd9 vn="a variant of Win64/Toolbar.MyWebSearch.A potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\AppIntegratorStub64.dll.vir"
sh=3C2251BC6DBC556B960D82FC7211B6005A613A8A ft=1 fh=e2babb33b836a3b5 vn="a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\ASSISTMONITOR.DLL.vir"
sh=E9C0F7642BFDCA4F304679F44A2351765D25D7E3 ft=1 fh=df272951a00ae964 vn="a variant of Win64/Toolbar.MyWebSearch.A potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\ASSISTMONITOR64.DLL.vir"
sh=5B52C97808B05C61C42C660EF788C6E30E9956D1 ft=1 fh=3bd8668ff345b3ba vn="a variant of Win32/Toolbar.MyWebSearch.Z potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\CREXT.DLL.vir"
sh=C0F1C1AD7E3E71F00D10961BF88368998314C8B5 ft=1 fh=1104306037fac477 vn="a variant of Win32/Toolbar.MyWebSearch.AR potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\CrExtP12.exe.vir"
sh=1B7027E34F895FA1E93C6CEDD86EB8415F086E5C ft=1 fh=0f1abfa76a5eafd1 vn="a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\DPNMNGR.DLL.vir"
sh=FA366450E70C686F15807DAD7D890CA19C739EE4 ft=1 fh=c3b0d1b55e33b10b vn="a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\EXEMANAGER.DLL.vir"
sh=ED7CCFFE86134DB07B0BEE73EC86B99C7243897A ft=1 fh=30bb44c368d084a2 vn="a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\FF-NativeMessagingDispatcher.dll.vir"
sh=2C88C56E84FB90C27DA50DF87011A98C77362B19 ft=1 fh=054dd36e0a8ce909 vn="a variant of Win64/Toolbar.MyWebSearch.A potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\Hpg64.dll.vir"
sh=D99BD974FF5A9502B17CFFB6E721F1B46C5B25E9 ft=1 fh=e75af964f60c8f9c vn="Win32/Toolbar.MyWebSearch.AI potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\NP12Stub.dll.vir"
sh=AFDF3F69BEB1CDE4A5AA1D9EE5BEFD8A5DE808D7 ft=1 fh=6f20f9ce0b4866ad vn="a variant of Win32/Toolbar.MyWebSearch.AU potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8EPMSUP.DLL.vir"
sh=ACBBE4D6CB48DD5CF142D79FDFEECBD7F9E9854E ft=1 fh=c0c375ff197f91b8 vn="a variant of Win32/Toolbar.MyWebSearch.AU potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8EXTEX.DLL.vir"
sh=BB1DF373EBE307C63271B72B7905E86FBF58D2CB ft=1 fh=16b6d8b2476550db vn="a variant of Win32/Toolbar.MyWebSearch.AU potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8EXTPEX.DLL.vir"
sh=0C27996F6F6194AA4EE5DA4031A78B9E304B05E3 ft=1 fh=44a79e41ea9fa8ee vn="a variant of Win32/Toolbar.MyWebSearch.AS potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8HTML.DLL.vir"
sh=88A01244271EF4EE3E78DDCEAF4287D4B053ED9A ft=1 fh=6b89c95ed44a94f1 vn="a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\T8TICKER.DLL.vir"
sh=BC3EDB50A86B8838EB86DA38B2012A16B4ABBDC5 ft=1 fh=a52b1d8d089a2cba vn="Win32/Toolbar.MyWebSearch.AI potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\TPIMANAGERCONSOLE.EXE.vir"
sh=E773874752E4170F8A04CB32ADACE5204A8C28B2 ft=1 fh=5f04f5f98ab14616 vn="a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\UNIFIEDLOGGING.DLL.vir"
sh=AB85089131865A0535CD21A15D60C00AA7C425A2 ft=1 fh=13b78041014ac185 vn="a variant of Win32/Toolbar.MyWebSearch.AU potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\VERIFY.DLL.vir"
sh=BE577FE27B2453B16A2A2D3ADE8A40DA510ED4CC ft=1 fh=f175fa7624bffb79 vn="a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\assists\ie_default_search_provider\ARBITER.DLL.vir"
sh=527A15F6D343F750733C47FA8E2561894CE31D2A ft=1 fh=fc06c72d9fe6c9c7 vn="Win64/Toolbar.MyWebSearch.C potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\assists\ie_default_search_provider\ARBITER64.DLL.vir"
sh=AC297627AB9AB7AD194EC4E3CDE50D2A42F9A4FA ft=1 fh=609aefa527ec4346 vn="Win32/Toolbar.MyWebSearch.AF potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\MyScrapNook_12\bar\1.bin\assists\ie_default_search_provider\ASSIST.EXE.vir"
sh=03E190B747DC937BDE6CC210FBCC4676F0C84B9C ft=1 fh=f58098137308c9c0 vn="a variant of Win32/TorchMedia potentially unwanted application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Robert Hornshaw\AppData\Local\temp\nst2BCE.tmp\Uninstall.exe"

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Above is the log text from the eset scan.

Kind regards
Mrs Deborah Hornshaw

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
How's your computer working now? Any other issues?

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Hi,
Sorry i havent had chance to get back to you. My computer is still playing up by redirecting me to other sites.

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Please run AdwCleaner and MBAM again and only post the logs if they find something.

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
# AdwCleaner v5.005 - Logfile created 30/09/2015 at 09:28:59
# Updated 31/08/2015 by Xplode
# Database : 2015-09-30.1 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
# Username : Robert Hornshaw - ROBERT
# Running from : C:\Users\Robert Hornshaw\Downloads\adwcleaner_5.005 (2).exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****

[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage-journal
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage
[-] File Deleted : C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage-journal

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****


*************************

:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C6].txt - [1948 bytes] ##########

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 30/09/2015
Scan Time: 10:04:59
Logfile: mbam 30.09.15.txt
Administrator: Yes

Version: 2.01.6.1022
Malware Database: v2015.09.30.02
Rootkit Database: v2015.09.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: Robert Hornshaw

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 406144
Time Elapsed: 24 min, 55 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 6
PUP.Optional.PricePeep, C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage, , [9971d75f96f592a4872ea51618ecee12],
PUP.Optional.PricePeep, C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal, , [f01a1422d8b3b581fbba8437a65e758b],
PUP.Optional.ReMarkable, C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, , [ed1d00364447e84e07d0813c83818e72],
PUP.Optional.ReMarkable, C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, , [2edc40f6d7b485b1f4e35b627f850cf4],
PUP.Optional.SelectNGo, C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage, , [f416b87eafdc003637227949778dbc44],
PUP.Optional.SelectNGo, C:\Users\Robert Hornshaw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal, , [4ebcfc3a1d6e02349ebb7b47d92b857b],

Physical Sectors: 0
(No malicious items detected)


(end)

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
I have logged the results from both scan as you require, even after doing both scans these annoying redirecting websites keep popping up in place of what i actually want.

Kind Regards
Debbie

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
What browser are you using? Please run Junkware Removal tool I provided in my first reply. It's working now.

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Robert Hornshaw on 01/10/2015 at 7:18:15.48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{D9B924B9-98DF-4E68-BFFF-F11F3CD601E1}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{192F7A17-FD85-4109-A2EF-A44ECCCCE17A}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D9B924B9-98DF-4E68-BFFF-F11F3CD601E1}



~~~ Files

Successfully deleted: [File] C:\ProgramData\SPL1424.tmp
Successfully deleted: [File] C:\ProgramData\SPL16F9.tmp
Successfully deleted: [File] C:\ProgramData\SPL18F7.tmp
Successfully deleted: [File] C:\ProgramData\SPL1C8D.tmp
Successfully deleted: [File] C:\ProgramData\SPL2044.tmp
Successfully deleted: [File] C:\ProgramData\SPL2159.tmp
Successfully deleted: [File] C:\ProgramData\SPL2794.tmp
Successfully deleted: [File] C:\ProgramData\SPL2BC4.tmp
Successfully deleted: [File] C:\ProgramData\SPL30C1.tmp
Successfully deleted: [File] C:\ProgramData\SPL3246.tmp
Successfully deleted: [File] C:\ProgramData\SPL3DCF.tmp
Successfully deleted: [File] C:\ProgramData\SPL45A7.tmp
Successfully deleted: [File] C:\ProgramData\SPL49EB.tmp
Successfully deleted: [File] C:\ProgramData\SPL4C6A.tmp
Successfully deleted: [File] C:\ProgramData\SPL5319.tmp
Successfully deleted: [File] C:\ProgramData\SPL5560.tmp
Successfully deleted: [File] C:\ProgramData\SPL5567.tmp
Successfully deleted: [File] C:\ProgramData\SPL55B3.tmp
Successfully deleted: [File] C:\ProgramData\SPL5C13.tmp
Successfully deleted: [File] C:\ProgramData\SPL6221.tmp
Successfully deleted: [File] C:\ProgramData\SPL64EB.tmp
Successfully deleted: [File] C:\ProgramData\SPL6650.tmp
Successfully deleted: [File] C:\ProgramData\SPL67F0.tmp
Successfully deleted: [File] C:\ProgramData\SPL690F.tmp
Successfully deleted: [File] C:\ProgramData\SPL6AD5.tmp
Successfully deleted: [File] C:\ProgramData\SPL7281.tmp
Successfully deleted: [File] C:\ProgramData\SPL77E6.tmp
Successfully deleted: [File] C:\ProgramData\SPL7911.tmp
Successfully deleted: [File] C:\ProgramData\SPL7FCB.tmp
Successfully deleted: [File] C:\ProgramData\SPL951D.tmp
Successfully deleted: [File] C:\ProgramData\SPL9BA3.tmp
Successfully deleted: [File] C:\ProgramData\SPLA1DC.tmp
Successfully deleted: [File] C:\ProgramData\SPLA63D.tmp
Successfully deleted: [File] C:\ProgramData\SPLAB92.tmp
Successfully deleted: [File] C:\ProgramData\SPLB4FD.tmp
Successfully deleted: [File] C:\ProgramData\SPLBB06.tmp
Successfully deleted: [File] C:\ProgramData\SPLC283.tmp
Successfully deleted: [File] C:\ProgramData\SPLC61.tmp
Successfully deleted: [File] C:\ProgramData\SPLD097.tmp
Successfully deleted: [File] C:\ProgramData\SPLD0B7.tmp
Successfully deleted: [File] C:\ProgramData\SPLD0DC.tmp
Successfully deleted: [File] C:\ProgramData\SPLD31F.tmp
Successfully deleted: [File] C:\ProgramData\SPLD412.tmp
Successfully deleted: [File] C:\ProgramData\SPLDC7B.tmp
Successfully deleted: [File] C:\ProgramData\SPLEC42.tmp
Successfully deleted: [File] C:\ProgramData\SPLEDF7.tmp
Successfully deleted: [File] C:\ProgramData\SPLF548.tmp
Successfully deleted: [File] C:\ProgramData\SPLFB7F.tmp
Successfully deleted: [File] C:\Users\Robert Hornshaw\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.audienceinsights.net_0.localstorage
Successfully deleted: [File] C:\Users\Robert Hornshaw\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.audienceinsights.net_0.localstorage-journal
Successfully deleted: [File] C:\Users\Robert Hornshaw\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
Successfully deleted: [File] C:\Users\Robert Hornshaw\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal



~~~ Folders



~~~ Chrome


[C:\Users\Robert Hornshaw\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Robert Hornshaw\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Robert Hornshaw\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Robert Hornshaw\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01/10/2015 at 7:21:34.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Robert Hornshaw on 01/10/2015 at 7:18:15.48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{D9B924B9-98DF-4E68-BFFF-F11F3CD601E1}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{192F7A17-FD85-4109-A2EF-A44ECCCCE17A}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D9B924B9-98DF-4E68-BFFF-F11F3CD601E1}



~~~ Files

Successfully deleted: [File] C:\ProgramData\SPL1424.tmp
Successfully deleted: [File] C:\ProgramData\SPL16F9.tmp
Successfully deleted: [File] C:\ProgramData\SPL18F7.tmp
Successfully deleted: [File] C:\ProgramData\SPL1C8D.tmp
Successfully deleted: [File] C:\ProgramData\SPL2044.tmp
Successfully deleted: [File] C:\ProgramData\SPL2159.tmp
Successfully deleted: [File] C:\ProgramData\SPL2794.tmp
Successfully deleted: [File] C:\ProgramData\SPL2BC4.tmp
Successfully deleted: [File] C:\ProgramData\SPL30C1.tmp
Successfully deleted: [File] C:\ProgramData\SPL3246.tmp
Successfully deleted: [File] C:\ProgramData\SPL3DCF.tmp
Successfully deleted: [File] C:\ProgramData\SPL45A7.tmp
Successfully deleted: [File] C:\ProgramData\SPL49EB.tmp
Successfully deleted: [File] C:\ProgramData\SPL4C6A.tmp
Successfully deleted: [File] C:\ProgramData\SPL5319.tmp
Successfully deleted: [File] C:\ProgramData\SPL5560.tmp
Successfully deleted: [File] C:\ProgramData\SPL5567.tmp
Successfully deleted: [File] C:\ProgramData\SPL55B3.tmp
Successfully deleted: [File] C:\ProgramData\SPL5C13.tmp
Successfully deleted: [File] C:\ProgramData\SPL6221.tmp
Successfully deleted: [File] C:\ProgramData\SPL64EB.tmp
Successfully deleted: [File] C:\ProgramData\SPL6650.tmp
Successfully deleted: [File] C:\ProgramData\SPL67F0.tmp
Successfully deleted: [File] C:\ProgramData\SPL690F.tmp
Successfully deleted: [File] C:\ProgramData\SPL6AD5.tmp
Successfully deleted: [File] C:\ProgramData\SPL7281.tmp
Successfully deleted: [File] C:\ProgramData\SPL77E6.tmp
Successfully deleted: [File] C:\ProgramData\SPL7911.tmp
Successfully deleted: [File] C:\ProgramData\SPL7FCB.tmp
Successfully deleted: [File] C:\ProgramData\SPL951D.tmp
Successfully deleted: [File] C:\ProgramData\SPL9BA3.tmp
Successfully deleted: [File] C:\ProgramData\SPLA1DC.tmp
Successfully deleted: [File] C:\ProgramData\SPLA63D.tmp
Successfully deleted: [File] C:\ProgramData\SPLAB92.tmp
Successfully deleted: [File] C:\ProgramData\SPLB4FD.tmp
Successfully deleted: [File] C:\ProgramData\SPLBB06.tmp
Successfully deleted: [File] C:\ProgramData\SPLC283.tmp
Successfully deleted: [File] C:\ProgramData\SPLC61.tmp
Successfully deleted: [File] C:\ProgramData\SPLD097.tmp
Successfully deleted: [File] C:\ProgramData\SPLD0B7.tmp
Successfully deleted: [File] C:\ProgramData\SPLD0DC.tmp
Successfully deleted: [File] C:\ProgramData\SPLD31F.tmp
Successfully deleted: [File] C:\ProgramData\SPLD412.tmp
Successfully deleted: [File] C:\ProgramData\SPLDC7B.tmp
Successfully deleted: [File] C:\ProgramData\SPLEC42.tmp
Successfully deleted: [File] C:\ProgramData\SPLEDF7.tmp
Successfully deleted: [File] C:\ProgramData\SPLF548.tmp
Successfully deleted: [File] C:\ProgramData\SPLFB7F.tmp
Successfully deleted: [File] C:\Users\Robert Hornshaw\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.audienceinsights.net_0.localstorage
Successfully deleted: [File] C:\Users\Robert Hornshaw\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.audienceinsights.net_0.localstorage-journal
Successfully deleted: [File] C:\Users\Robert Hornshaw\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
Successfully deleted: [File] C:\Users\Robert Hornshaw\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal



~~~ Folders



~~~ Chrome


[C:\Users\Robert Hornshaw\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Robert Hornshaw\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Robert Hornshaw\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Robert Hornshaw\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01/10/2015 at 7:21:34.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
we use google chrome and the computer is still redirecting me.

Debbie

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Does it always re-direct you to the same site or is it random sites?

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Just random sites, everytime i click on something either to type or open a page it redirects me to random sites so i have to keep closing the pages to eventually get to what i want to.

Debbie

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Does it re-direct you using IE?

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Hi Sorry i havent been in touch, i have stopped using Google chrome and there doesnt seem to be any pups so far. i am using ie but alot slower! Is there anything i should be doing?

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
Did you try using FireFox as your browser?

descriptioncomputer is being strange!! EmptyRe: computer is being strange!!

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum