WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionClicking on Links opens up another tab EmptyClicking on Links opens up another tab

more_horiz
When I click on links, it often opens up another tab with an advertisement like this: http://onlinewebfind.com/ads-clicktrack/click/newjump1.do?affiliate=63795&subid=C1240275&terms=virus,%20spyware%20%26amp;%20malware%20removal&rtw=&ai=xDBb3iFPjxbTSzd6y__oEuqn3TwegpT2_uMojHRCfoAk9UxzgUO1eBRJ8xaTh1YLdqxFZaePvePG9dZUiLMb4vw24uyt5Cmp0qknpuPyTC84zYVYLmknsogezaZPhP6qVAg_eHAY-2TqIJA89ctKLKADhTRuH74YHWtZk5atqcOtlRQH2hxc4hBjH9p27jFAh8HTNC_-fBpw5FjcBbwuyTs5aVtVF7khCbDQsQTjWNhONxEFkKcXhUGiGdA-y1N9QNGQAlnAVEzbCTsJctkMIPIE0YBf7eHBkjA1IoGGAQxTe3jt16b9ccOrg0rE31p46elSGdXfZAw&product=iy

Could you please help? Thanks!

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.  

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
Please download AdwCleaner by Xplode onto your Desktop.

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete or Clean
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

*********************************************
Clicking on Links opens up another tab Mbamicontw5 Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
*************************************************
Please download Junkware Removal Tool to your desktop.

Warning! Once the scan is complete JRT will shut down your browser with NO warning.

Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
*****************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
Adware Cleaner:
# AdwCleaner v3.016 - Report created 02/01/2014 at 11:19:51
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Student - HP-2CE1290FGQ
# Running from : C:\Users\Student\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : Level Quality Watcher

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\NCH Software
Folder Deleted : C:\Program Files (x86)\NCH Software
Folder Deleted : C:\Program Files (x86)\ScorpionSaver
Folder Deleted : C:\Program Files\Level Quality Watcher
Folder Deleted : C:\Program Files\ScorpionSaver Services
Folder Deleted : C:\Users\Student\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\Student\AppData\Local\TBHostSupport
Folder Deleted : C:\Users\Student\AppData\Local\Temp\NativeMessaging
Folder Deleted : C:\Users\Student\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Student\AppData\Roaming\NCH Software
Folder Deleted : C:\Users\Student\AppData\Roaming\Mozilla\Firefox\Profiles\rlhbakip.default\Extensions\ScorpionSaver@jetpack
Folder Deleted : C:\Users\Student\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl
Folder Deleted : C:\Users\Student\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg
File Deleted : C:\Windows\SysWOW64\AdpeakProxy.ini
File Deleted : C:\Windows\SysWOW64\AdpeakProxyOff.ini
File Deleted : C:\Windows\System32\AdpeakProxy.ini
File Deleted : C:\Windows\System32\AdpeakProxy64.dll
File Deleted : C:\Windows\System32\AdpeakProxyOff.ini
File Deleted : C:\Windows\System32\Tasks\NCH Software

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\AdpeakProxy.exe
Key Deleted : HKLM\SOFTWARE\Classes\PCProxy.DataContainer
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9B7B034B-944A-4261-B487-862F642F7615}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE91F9CE-0900-4E2A-B673-F3F6E4FC54D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10AD2C61-0898-4348-8600-14A342F22AC3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKCU\Software\Adpeak, Inc.
Key Deleted : HKCU\Software\FLEXnet
Key Deleted : HKCU\Software\NCH Software
Key Deleted : HKCU\Software\ScorpionSaver
Key Deleted : HKCU\Software\SearchProtectINT
Key Deleted : HKCU\Software\AppDataLow\Software\Scorpion Saver
Key Deleted : HKCU\Software\AppDataLow\Software\ScorpionSaver
Key Deleted : HKLM\Software\Adpeak, Inc.
Key Deleted : HKLM\Software\FLEXnet
Key Deleted : HKLM\Software\NCH Software
Key Deleted : [x64] HKLM\SOFTWARE\Adpeak, Inc.
Key Deleted : [x64] HKLM\SOFTWARE\Scorpion Saver
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6E810AB6-F34E-49A3-A93F-9E503660F718}
Key Deleted : HKLM\Software\Classes\Installer\Features\6BA018E6E43F3A949AF3E90563067F81
Key Deleted : HKLM\Software\Classes\Installer\Products\6BA018E6E43F3A949AF3E90563067F81

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16576


-\\ Mozilla Firefox v12.0 (en-US)

[ File : C:\Users\Student\AppData\Roaming\Mozilla\Firefox\Profiles\rlhbakip.default\prefs.js ]


-\\ Google Chrome v

[ File : C:\Users\Student\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [12459 octets] - [07/11/2013 22:22:55]
AdwCleaner[R1].txt - [12478 octets] - [09/11/2013 16:15:10]
AdwCleaner[R2].txt - [5173 octets] - [02/01/2014 11:15:38]
AdwCleaner[S0].txt - [12290 octets] - [09/11/2013 16:16:32]
AdwCleaner[S1].txt - [4980 octets] - [02/01/2014 11:19:51]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5040 octets] ##########

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
Were you able to run the other two scanners?

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
Superdave wrote:
Were you able to run the other two scanners?


Superdave, I'm currently running both right now. Thanks for your help

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
Junkware Removal:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.9 (01.01.2014:1)
OS: Windows 7 Professional x64
Ran by Student on Thu 01/02/2014 at 14:41:54.71
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{02DD8284-A49F-43E5-9D84-CF19DC9AD21D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{27DE7D30-BCCD-44D1-ADCB-A74A4259EBEF}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3A0EFC4E-F167-4D0E-9C24-FC5519237993}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{65DEE40A-3E93-4CAE-9F98-B8E06DCEE2BF}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F251ECE2-5616-4C6A-BB6E-A16C8F1DBB5A}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{65DEE40A-3E93-4CAE-9F98-B8E06DCEE2BF}



~~~ Files

Successfully deleted: [File] "C:\Windows\syswow64\wscm32.dll"
Successfully deleted: [File] "C:\Windows\syswow64\wscm64.dll"



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Student\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\Student\appdata\locallow\boost_interprocess"
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{08A68C39-1097-426B-AE73-96A73E7746CA}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{2EED790F-074B-4740-9EC9-276E658E5867}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{49BEF8B9-6A78-4AE0-91B1-A7BE9F369011}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{4BCD2400-ADC7-45B3-8526-111A0336A0D3}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{5470640D-13EC-43F7-9128-07FD5B32CF13}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{597F5A53-A844-42F7-B1B4-A648A74193FD}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{81C7C3A6-2E46-4640-9683-6C6D25548A8C}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{83274379-CD91-419C-8447-4064DEB692B3}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{8ACB76D4-CC58-4A02-8DE5-06C887F01279}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{92C3B56A-55AD-48FF-8D59-C89AD8B7B05E}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{97BDBD0E-F036-49EC-9378-139B686AA8FE}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{99323625-3518-4BD2-8AB3-27FC9CB661F0}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{A3723D3F-6C85-432C-A342-F26E2C45817B}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{A9DC5356-7FBC-4698-8080-30D8F1EB8805}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{B3976B86-0234-4EBF-B63D-117C2F8CAE6D}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{B7C76F61-2649-4AE5-83B4-4A0A5C93DE0E}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{B98F4E40-88E9-40D2-9BB4-4D1C7581BF56}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{BB167CA9-4B2D-4736-9202-0CD48CC7F4FB}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{BE9C4823-FF0C-4FE4-BDDD-A62249CE99FE}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{C0C16CA1-8DBB-46CA-BB22-118DDA2CFD39}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{C441088F-5100-456F-B119-DAC80D913428}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{CE48BBFC-11D4-41AE-BC4C-E6A36435294E}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{CFB66D3A-CAE3-4517-A897-23669BDD3403}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{DEFB5251-A48D-4043-8CA9-09A339BC2BF6}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{E2AC5E83-05FC-42DB-B854-2DAAD3DD6A49}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{EAD8FBFD-6752-4947-B58B-8CEE9C94D762}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{F6C77E3E-A765-4882-9346-BA0AB7A27F62}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{F6FAC0CD-0C98-42EB-B264-71E1D7DB4826}
Successfully deleted: [Empty Folder] C:\Users\Student\appdata\local\{FFF03C40-D66C-4E81-BFF4-9533E8A9772B}



~~~ FireFox

Emptied folder: C:\Users\Student\AppData\Roaming\mozilla\firefox\profiles\rlhbakip.default\minidumps [4 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 01/02/2014 at 14:47:53.45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
I tried to run "Security Check", but it said, "unsupported operating system, ABORTED". Why does it say this?

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
but it said, "unsupported operating system, ABORTED". Why does it say this?.

I'm not quite sure but it's been doing that a lot lately.
I now need to see the MBAM log.

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
Superdave wrote:

I now need to see the MBAM log.[/color]


Sorry Superdave, I thought I had posted it already:

MBAM LOG:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.01.02.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16576
Student :: HP-2CE1290FGQ [administrator]

1/2/2014 11:25:00 AM
MBAM-log-2014-01-02 (14-35-22).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 571696
Time elapsed: 2 hour(s), 49 minute(s), 17 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 2
HKLM\SOFTWARE\Wow6432Node\Wow6432Node\Adpeak, Inc. (PUP.Optional.Adpeak) -> No action taken.
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AdpeakProxy (PUP.Optional.ScorpionSaver) -> No action taken.

Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|TBHostSupport (PUP.Optional.Conduit) -> Data: "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Student\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin -> No action taken.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\Users\Student\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg (PUP.Optional.ScorpionSaver) -> No action taken.

Files Detected: 25
C:\AdwCleaner\Quarantine\C\Program Files\ScorpionSaver Services\AdpeakProxy64.dll.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files\ScorpionSaver Services\AdpeakRegisterLSP.exe.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files\ScorpionSaver Services\AdpeakRegisterLSP64.exe.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files\ScorpionSaver Services\Installbat.dll.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files\ScorpionSaver Services\InstallDLL.dll.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files\ScorpionSaver Services\InstallDLL64.dll.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files\ScorpionSaver Services\PCProxyDLL.dll.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir (PUP.Optional.Conduit) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScorpionSaver\CustomActionInstall.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScorpionSaver\CustomActionUninstall.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScorpionSaver\IECore.dll.vir (PUP.Optional.Adpeak) -> No action taken.
C:\AdwCleaner\Quarantine\C\Windows\System32\AdpeakProxy64.dll.vir (PUP.Optional.Adpeak) -> No action taken.
C:\temp\000.exe (PUP.Optional.Adpeak) -> No action taken.
C:\temp\InstallServices64.msi (PUP.Optional.Adpeak) -> No action taken.
C:\temp\ScorpionSaver.msi (Adware.Adpeak) -> No action taken.
C:\temp\t.msi (PUP.Optional.Adpeak) -> No action taken.
C:\Users\Student\Downloads\Chinky P Samples.zip (1).exe (PUP.Optional.InstalleRex) -> No action taken.
C:\Users\Student\Downloads\Chinky P Samples.zip.exe (PUP.Optional.InstalleRex) -> No action taken.
C:\Windows\Installer\4721590.msi (PUP.Optional.Adpeak) -> No action taken.
C:\Windows\Installer\5a837e81.msi (Adware.Adpeak) -> No action taken.
C:\Windows\Installer\a2e5196.msi (PUP.Optional.Adpeak) -> No action taken.
C:\temp\ScorpionSaver.msi (PUP.Optional.Adpeak) -> No action taken.
C:\Users\Student\AppData\Local\Temp\AdpeakProxyr.log (PUP.Optional.AdpeakProxy) -> No action taken.
C:\Windows\Temp\AdpeakProxy.log (PUP.Optional.AdpeakProxy) -> No action taken.
C:\Windows\Temp\AdpeakProxyr.log (PUP.Optional.AdpeakProxy) -> No action taken.

(end)

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
You will need to run MBAM again, make sure every infection has a check mark and click on "Remove Selected"

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the Clicking on Links opens up another tab EsetOnline button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on Clicking on Links opens up another tab EsetSmartInstall to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the Clicking on Links opens up another tab EsetSmartInstallDesktopIcon-1 icon on your desktop.

•Check Clicking on Links opens up another tab EsetAcceptTerms
•Click the Clicking on Links opens up another tab EsetStart button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check Clicking on Links opens up another tab EsetScanArchives
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push Clicking on Links opens up another tab EsetListThreats
•Push Clicking on Links opens up another tab EsetExport, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the Clicking on Links opens up another tab EsetBack button.
•Push Clicking on Links opens up another tab EsetFinish
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.01.02.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16576
Student :: HP-2CE1290FGQ [administrator]

1/4/2014 6:21:50 PM
mbam-log-2014-01-04 (18-21-50).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 573000
Time elapsed: 2 hour(s), 36 minute(s), 53 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
Ok, now the ESET log.

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
C:\AdwCleaner\Quarantine\C\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher32.exe.vir a variant of Win32/AdWare.Adpeak.B application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe.vir a variant of Win64/Adware.Adpeak.B application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Users\Student\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js.old.vir Win32/AdWare.Adpeak.B application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Users\Student\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\bootstrap.js.vir Win32/AdWare.Adpeak.B application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Users\Student\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\manifest.json.vir Win32/AdWare.Adpeak.B application cleaned by deleting - quarantined
C:\Users\Student\AppData\Local\Temp\is1598539481\95264352_Setup.DAT a variant of Win32/Agent.SZW trojan cleaned by deleting - quarantined
C:\Users\Student\AppData\Local\TempImages\UpdateInstaller.exe a variant of Win32/Agent.SZW trojan cleaned by deleting - quarantined
C:\Users\Student\Desktop\Hp Desktop 2012\desktop\Cruise Music\2010\8 28 10 - Music\Microsoft Office 2010 Pro Plus RC0-Windows 7 Compatible\Microsoft.Office.2010.Professional.x86.Build.4734-WinBeta.rar a variant of MSIL/Agent.NCF trojan deleted - quarantined
C:\Users\Student\Desktop\Hp Desktop 2012\desktop\Cruise Music\8 28 10 - Music\Microsoft Office 2010 Pro Plus RC0-Windows 7 Compatible\Microsoft.Office.2010.Professional.x86.Build.4734-WinBeta.rar a variant of MSIL/Agent.NCF trojan deleted - quarantined
C:\Users\Student\Downloads\Adobe-Audition-v1.0_Installer.exe Win32/Adware.Lollipop.D application cleaned by deleting - quarantined
C:\Users\Student\Downloads\FreeWAVToMP3ConverterSetup.exe a variant of Win32/Agent.SZW trojan cleaned by deleting - quarantined
C:\Windows\Installer\MSI2B27.tmp a variant of Win64/Adware.Adpeak.B application cleaned by deleting - quarantined

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
How's your computer running now?

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
Superdave wrote:
How's your computer running now?


It's definitely not doing what it was doing, but there is still this ABP symbol on the top right of my screen and the numbers change sometimes. Do you know what this is?

Clicking on Links opens up another tab Abpsign

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
According to this site it looks like something that's installed on your computer. Go to Control Panel, Programs and Features to see if there's something installed that shouldn't be there.

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
thanks for all your help Superdave!

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.

descriptionClicking on Links opens up another tab EmptyRe: Clicking on Links opens up another tab

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum