GeekPolice Tech TutorialsLog in

 

Multiple signs of adware in my logs... Please help - Computer hogged

Share

descriptionSolvedRe: Multiple signs of adware in my logs... Please help - Computer hogged

more_horiz
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.

•Check
•Click the button.
•Accept any security warnings from your browser.


  • Leave the check mark next to Remove found threats.

•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

descriptionSolvedRe: Multiple signs of adware in my logs... Please help - Computer hogged

more_horiz
# AdwCleaner v6.045 - Logfile created 15/04/2017 at 16:48:36
# Updated on 28/03/2017 by Malwarebytes
# Database : 2017-04-14.1 [Local]
# Operating System : Windows 7 Ultimate Service Pack 1 (X64)
# Username : darthmaul - darthmaul-PC
# Running from : C:\Users\darthmaul\Desktop\adwcleaner_6.045.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****

[-] Service deleted: scan


***** [ Folders ] *****

[-] Folder deleted: C:\Windows\Installer\{EC6BB2F4-E451-4267-98BB-D87E26523554}
[-] Folder deleted: C:\Users\darthmaul\AppData\LocalLow\Speedbit
[-] Folder deleted: C:\Users\darthmaul\AppData\Roaming\Speedbit
[-] Folder deleted: C:\ProgramData\Speedbit
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Speedbit
[-] Folder deleted: C:\Program Files (x86)\DAP
[-] Folder deleted: C:\Users\darthmaul\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb


***** [ Files ] *****

[-] File deleted: C:\Users\darthmaul\AppData\Roaming\Mozilla\Firefox\Profiles\8pjwl3nz.default\invalidprefs.js
[-] File deleted: C:\Users\darthmaul\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ffdcfjdljhbehggjdkdioajnknjcpbjb_0.localstorage
[-] File deleted: C:\Users\darthmaul\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ffdcfjdljhbehggjdkdioajnknjcpbjb_0.localstorage-journal


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****



***** [ Scheduled Tasks ] *****



***** [ Registry ] *****

[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EC6BB2F4-E451-4267-98BB-D87E26523554}
[#] Key deleted on reboot: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EC6BB2F4-E451-4267-98BB-D87E26523554}_is1
[-] Key deleted: HKLM\SOFTWARE\Classes\AniGIFCtrl.AniGIF
[-] Key deleted: HKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg
[-] Key deleted: HKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg.1
[-] Key deleted: HKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2
[-] Key deleted: HKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\AniGIFCtrl.AniGIF
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2.1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{65416821-217D-44BD-9C61-F53398FB1B46}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{4ABDD67C-44E3-42E0-816D-D7F0E54761DF}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{34F4FEAF-4921-4B5D-8BE5-CA384BFFC2CE}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{39A37965-0A96-43A3-870E-821FE5C84B0B}
[-] Key deleted: HKU\S-1-5-21-2694251990-3721660609-63749276-1000\Software\SlimWare Utilities Inc
[-] Key deleted: HKU\S-1-5-21-2694251990-3721660609-63749276-1000\Software\SpeedBit
[-] Key deleted: HKU\S-1-5-21-2694251990-3721660609-63749276-1000\Software\Speedbit Technology
[-] Key deleted: HKU\S-1-5-21-2694251990-3721660609-63749276-1000\Software\sparktrust
[-] Key deleted: HKU\S-1-5-21-2694251990-3721660609-63749276-1000\Software\ELLS LLC
[#] Key deleted on reboot: HKCU\Software\SlimWare Utilities Inc
[#] Key deleted on reboot: HKCU\Software\SpeedBit
[#] Key deleted on reboot: HKCU\Software\Speedbit Technology
[#] Key deleted on reboot: HKCU\Software\sparktrust
[#] Key deleted on reboot: HKCU\Software\ELLS LLC
[-] Key deleted: HKLM\SOFTWARE\SLIMWARE UTILITIES, INC.
[-] Key deleted: HKLM\SOFTWARE\SlimWare Utilities Inc
[-] Key deleted: HKLM\SOFTWARE\SpeedBit
[-] Key deleted: HKLM\SOFTWARE\Speedbit Technology
[-] Key deleted: HKLM\SOFTWARE\sparktrust
[#] Key deleted on reboot: [x64] HKCU\Software\SlimWare Utilities Inc
[#] Key deleted on reboot: [x64] HKCU\Software\SpeedBit
[#] Key deleted on reboot: [x64] HKCU\Software\Speedbit Technology
[#] Key deleted on reboot: [x64] HKCU\Software\sparktrust
[#] Key deleted on reboot: [x64] HKCU\Software\ELLS LLC
[-] Key deleted: [x64] HKLM\SOFTWARE\SLIMWARE UTILITIES, INC.
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\50D2BAFD096C90345A82B25A790BDF69
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\87BC562E4C903254282D9225FA1226A0
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\50D2BAFD096C90345A82B25A790BDF69
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\87BC562E4C903254282D9225FA1226A0
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\50D2BAFD096C90345A82B25A790BDF69
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\87BC562E4C903254282D9225FA1226A0
[-] Value deleted: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [daplinkchecker@speedbit.com]
[#] Value deleted on reboot: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [daplinkchecker@speedbit.com]
[#] Value deleted on reboot: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [daplinkchecker@speedbit.com]
[-] Key deleted: HKLM\SOFTWARE\Google\Chrome\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb


***** [ Web browsers ] *****

[-] [C:\Users\darthmaul\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\darthmaul\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\darthmaul\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: ffdcfjdljhbehggjdkdioajnknjcpbjb


*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [6222 Bytes] - [15/04/2017 16:48:36]
C:\AdwCleaner\AdwCleaner[S0].txt - [27533 Bytes] - [14/04/2017 18:33:14]
C:\AdwCleaner\AdwCleaner[S1].txt - [6043 Bytes] - [15/04/2017 16:45:35]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [6442 Bytes] ##########


eset:

C:\Users\darthmaul\AppData\Local\Mozilla\Firefox\Profiles\8pjwl3nz.default\cache2\entries\585BD73A2953643BD5CABFDB4382D06140040981 Win32/Bundled.Toolbar.Google.D potentially unsafe application cleaned by deleting
C:\Users\darthmaul\AppData\Local\Mozilla\Firefox\Profiles\8pjwl3nz.default\cache2\entries\B5957252E73698FB4CEA6EB6C6EFA23A5074855A Win32/Deceptor.SmartPCFixer.A application cleaned by deleting
C:\Users\darthmaul\AppData\Local\Mozilla\Firefox\Profiles\8pjwl3nz.default\cache2\entries\B7A88A2E79AF0169EC6C225D01E4189A8852B8D1 multiple threats,Win32/Deceptor.BoostMyPC.A application,Win32/PCBooster.A potentially unwanted application cleaned by deleting
C:\Users\darthmaul\AppData\Local\Mozilla\Firefox\Profiles\8pjwl3nz.default\cache2\entries\EB7BB78381F9AC0F02776902B37502C1710B0ABE JS/Mindspark.D potentially unwanted application,JS/Mindspark.B potentially unwanted application deleted


Also, these programs i highlighted in this pic bother me:
Can I just uninstall them then? Should i have done that first before the tools up there??? Anyway, let me know what to do next. I will wait for your answerrr.

descriptionSolvedRe: Multiple signs of adware in my logs... Please help - Computer hogged

more_horiz
Yes, uninstall them and run the ESET scan.

descriptionSolvedRe: Multiple signs of adware in my logs... Please help - Computer hogged

more_horiz
uninstalled and eset scan clean - no log. Smile...

descriptionSolvedRe: Multiple signs of adware in my logs... Please help - Computer hogged

more_horiz
Good. Please give me an update on your computer.

descriptionSolvedRe: Multiple signs of adware in my logs... Please help - Computer hogged

more_horiz
thank you so much, sorry i took so long to get back, but my computer is fine now... anything else we should do?

descriptionSolvedRe: Multiple signs of adware in my logs... Please help - Computer hogged

more_horiz
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
***************************************
This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:


  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create Registry backup
  • Purge System Restore Points
  • Re-set system settings

Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.
********************************************
I suggest using WOT - Web of Trust . WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

descriptionSolvedRe: Multiple signs of adware in my logs... Please help - Computer hogged

more_horiz
ok this is all done now, thanks for all the help dave

descriptionSolvedRe: Multiple signs of adware in my logs... Please help - Computer hogged

more_horiz
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
Permissions in this forum:
You cannot reply to topics in this forum