2.21 Gigs free

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Deacon

Thread Starter
Joined
Oct 27, 2002
Messages
34
My wife's PC (Vista, 32-bit) has 71.2 gigs but only 2.21 free. There are no pictures. .no movies. .no music. .and no games downloaded on it. What should I do to start freeing up some space? ~ Thanks ~
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,154
Go here, then click the large blue "Download Now @ Author's Site" button to download and save TFC.exe (Temp File Cleaner by OldTimer) to your desktop.

After it's downloaded and saved, close all open windows.

Double-click it to load its main window.

Click the "Start" button.

If there are a large number of temp files or if there are multiple user accounts, the temp file deletion process may appear to freeze and may take a few minutes, so don't interfere with or abort it.

After it's finished, restart the computer.

---------------------------------------------------------

Go here and click the large green "Download" button to download and save HiJackThis 2.0.5 (HijackThis.exe) to your desktop.

After it's been downloaded and saved, close all open windows.

Double-click it and allow its main window to load.

Uncheck "Do not show this window when I start HiJackThis".

Click "Do a system scan and save a log file".

When the scan is finished in 30 - 60 seconds, a log file will appear.

Save that log file.

Return here to your thread, then copy-and-paste the ENTIRE log file here.

Note: Windows Vista users and Windows 7 users may get a "hosts file" or similar message when trying to use HiJackThis.

If you do get that message, do the following before using it:

Go to Control Panel - User Accounts.

Turn off or disable the User Account control(UAC) feature.

Apply the change, then restart the computer.

---------------------------------------------------------
 

Deacon

Thread Starter
Joined
Oct 27, 2002
Messages
34
After running TFC cleaner, I now have 23 gigs free.

Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 1:34:07 PM, on 3/24/2015
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16386)

FIREFOX: 36.0.4 (x86 en-US)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eMode\PCM\PCMService.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\Windows\System32\mobsync.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\wuauclt.exe
C:\Users\Kennedy\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Windows\system32\SysMonitor.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [PCMService] "C:\Acer\Empowering Technology\eMode\PCM\PCMService.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [?????????] ??????????????e
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 8663 bytes
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,154
My wife's PC (Vista, 32-bit) has 71.2 gigs but only 2.21 gigs free. There are no pictures. .no movies. .no music. .and no games downloaded on it. What should I do to start freeing up some space?
After running TFC cleaner, I now have 23 gigs free.
That's over 20 GB of hard drive space reclaimed. (y)

You should put TFC.exe to use at least once a month, and even more often if it becomes necessary.

------------------------------------------------------------------------

Your computer appears to be infested with malware, spyware, etc., so do the following:

Go here, then click the large blue "Download Now @ Bleeping Computer" button to download and save AdwCleaner.exe to your desktop.

Close all open windows first, then double-click AdwCleaner.exe to load its main window.

Click the "Scan" button, then allow the scanning process to finish.
(Note: Several seconds may pass before the scanning process starts, so be patient.)

Click the "Logfile" button.

When the log appears, save it.

Return here to your thread, then copy-and-paste the ENTIRE log here.

------------------------------------------------------------------------
 

Deacon

Thread Starter
Joined
Oct 27, 2002
Messages
34
# AdwCleaner v4.113 - Logfile created 24/03/2015 at 18:14:18
# Updated 22/03/2015 by Xplode
# Database : 2015-03-23.1 [Server]
# Operating system : Windows Vista (TM) Home Basic (x86)
# Username : Kennedy - KENNEDY-PC
# Running from : C:\Users\Kennedy\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : YahooAUService

***** [ Files / Folders ] *****

File Found : C:\Users\Kennedy\AppData\Roaming\Mozilla\Firefox\Profiles\uw4hf29y.default\searchplugins\ask-web-search.xml
Folder Found : C:\ProgramData\Yahoo! Companion
Folder Found : C:\Users\Kennedy\AppData\LocalLow\visi_coupon
Folder Found : C:\Users\Kennedy\AppData\LocalLow\Yahoo! Companion
Folder Found : C:\Users\Kennedy\AppData\LocalLow\YahooCouponAddOn

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yahoo! Companion
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]

***** [ Web browsers ] *****

-\\ Internet Explorer v7.0.6000.16386


-\\ Mozilla Firefox v36.0.4 (x86 en-US)

[uw4hf29y.default] - Line Found : user_pref("browser.search.defaultenginename", "Ask Web Search");
[uw4hf29y.default] - Line Found : user_pref("browser.search.defaultenginename.US", "Ask Web Search");
[uw4hf29y.default] - Line Found : user_pref("browser.search.selectedEngine", "Ask Web Search");
[uw4hf29y.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=525B63D4-69D5-46DA-91E1-378AF60D23EF&n=781acdad&p2=^ASP^xdm069^YYA^us");
[uw4hf29y.default] - Line Found : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.BUTTON_STRUCTURE", "[{\"b\":221353544,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":221353545,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0[...]
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.search.defaultenginename.prev", "Yahoo");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.search.defaultenginename.savedPrev", "true");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.search.defaultenginename.tb", "Ask Web Search");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.search.selectedEngine.prev", "Yahoo");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.search.selectedEngine.savedPrev", "true");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.search.selectedEngine.tb", "Ask Web Search");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.startup.homepage.savedPrev", "true");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.startup.homepage.tb", "hxxp://home.tb.ask.com/index.jhtml?ptb=525B63D4-69D5-46DA-91E1-378AF60D23EF&n=781acdad&p2=^ASP^xdm069^YYA^us");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.startup.page.savedPrev", 1);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.startup.page.tb", 1);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.browser.version.last", "36.0");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"refreshPeriod\":604800000,\"list\":[{\"url\":\"hxxp://www.dnsrsearch.com/[...]
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.firstKnownVersion", "6.85.5.65220");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=525B63D4-69D5-46DA-91E1-378AF60D23EF&n=781acdad&p2=^ASP^xdm069^YYA^us");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.hp.enabled", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.hp.guardType", "HPR");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.hp.user.defined", false);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.initialized", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.installKeysSource", "Cookies");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.installType", "XPI");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.installation.contextKey", "");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.installation.installDate", "2015022509");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.installation.partnerId", "^ASP^xdm069^YYA^us");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.installation.partnerSubId", "");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.installation.pixelUrl", "hxxp://download.crazyforcrafts.com/install_pixels.jhtml?partner=^ASP^xdm069^YYA^us&coId=4f655c4dd90a434895547b4270e464d1&tb[...]
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.installation.success", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.installation.toolbarId", "525B63D4-69D5-46DA-91E1-378AF60D23EF");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.isCompliantUninstallImplementation", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.lastActivePing", "1427198857407");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.lastKnownVersion", "6.85.5.65220");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.options.defaultSearch", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.options.homePageEnabled", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.options.keywordEnabled", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.options.tabEnabled", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.partnerPixelFired", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.searchHistory", "crocheting for dummies||free crocheting patterns||u tube on how to add lace crochet to a baby blanket crocheted");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.successUrl", "hxxp://download.crazyforcrafts.com/installComplete.jhtml");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.toolbar.ownSearch", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.toolbar.versionChanged", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.toolbarCollapsed", false);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark._7nMembers_.weather.location", "26501");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "[email protected]");
[uw4hf29y.default] - Line Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "[email protected]");
[uw4hf29y.default] - Line Found : user_pref("keyword.URL", "hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=525B63D4-69D5-46DA-91E1-378AF60D23EF&n=781acdad&ind=2015022509&p2=^ASP^xdm069^YYA^us&searchfor=");
*************************

AdwCleaner[R0].txt - [9755 bytes] - [24/03/2015 18:14:19]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [9814 bytes] ##########

After saving the log, I thought I'd close AdwCleaner scan page. When I clicked on the 'X' in the upper right corner I got the following message:
"By using only the scan mode, AdwCleaner has not removed detected items.
To perform the deletion of items found, click on [clean] unless you were asked to use only the scan mode.
Are you sure you want to close AdwCleaner?
Yes No"
I clicked "No" and left that page on my PC.
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,154
After saving the log, I thought I'd close AdwCleaner scan page. When I clicked on the 'X' in the upper right corner I got the following message:
"By using only the scan mode, AdwCleaner has not removed detected items.
To perform the deletion of items found, click on [clean] unless you were asked to use only the scan mode.
Are you sure you want to close AdwCleaner?
Yes No"
I clicked "No" and left that page on my PC.
Ignore the warning and click "Yes" to close AdwCleaner.

-------------------------------------------------------------

Close all open windows first, then double-click AdwCleaner to load its main window.

Click the "Scan" button, then allow the scanning process to finish.

Click the "Cleaning" button, then click "OK".

Allow the cleaning process to finish.

When it's finished, click "OK" in each window that appears.

The computer will restart.

When the log appears during restart, save it.

Return here to your thread, then copy-and-paste the ENTIRE log here.

-------------------------------------------------------------
 

Deacon

Thread Starter
Joined
Oct 27, 2002
Messages
34
AdwCleaner starts to scan then stops and says, "Waiting for action. Please uncheck elements you want to keep."
In the "Results" window it says,

Full name. Service name
(Checked box). Yahoo!. . . YahooAUService

I unchecked the box but nothing happens. The scan does not resume. The word "scan" is grayed out. The other three (Cleaning, Logfile, and Uninstall) are active. The only other thing I can do is close the window--then I get the message I mentioned above. When I click "Yes" the window closes and I'm back at my desktop b/c I've closed all of the other windows. I go to "Downloads" and open AdwCleaner.exe and get back to the same page ready to scan again but the same thing happens as described at the beginning of this post.

Almost midnight now so I'll be back in the morning (retired).
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,154
You need to be patient and wait for the scan to completely finish.

Once it does, click "Cleaning" and allow it to delete everything.

Follow the instructions from there.

-----------------------------------------------------------
 

Deacon

Thread Starter
Joined
Oct 27, 2002
Messages
34
Should I remove the check mark from the box in front of "Yahoo". . . "YahooAUService", or leave it there?
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,154
Should I remove the check mark from the box in front of "Yahoo". . . "YahooAUService", or leave it there?
Yes, remove the checkmark.

--------------------------------------------------------
 

Deacon

Thread Starter
Joined
Oct 27, 2002
Messages
34
I would have posted sooner but I've been busy. It's been 2 hours with no change after I unchecked the box.
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,154
I would have posted sooner but I've been busy. It's been 2 hours with no change after I unchecked the box.
I don't know what you're doing wrong or don't understand.

I give these same instructions several times here every day.

---------------------------------------------------------
 

Deacon

Thread Starter
Joined
Oct 27, 2002
Messages
34
On the AdwCleaner scan screen there is a folders tab. I opened it:
C:\Program Data\Yahoo!Companion
C:\Users\(a name)\AppData\LocalLow\visi_coupon
C:\Users\(a name)\AppData\LocalLow\Yahoo!CouponAddOn
C:\Users\(a name)\AppData\LocalLow\Yahoo!Companiion

There is also a 'Registry' tab:
Seven lines look like this:
(checked box) Key HKLM\Software\classes\clsid\ (series of #'s and letters)
One line like this:
(checked box) Key HKLM\Software\Microsoft\Windows\Current Version\Explorer\BrowserHelperObjects\(#'s. )
Two lines like this:
(checked box) Key HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\(#'s and letters)
One line like this:
(checked box) Key HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\(#'s and letters)

And there are seven more lines like these.

Does that help any?

I tried to run AdwCleaner from cnet with the same results. The scan did not resume after I unchecked the box mentioned above.
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,154
Close AdwCleaner, then reload it.

Next, click the "Scan" button and wait for the scan to completely finish.

Next, click the "Cleaning" button and allow it to delete everything.

There's no need to click on and open any of the tabs.

--------------------------------------------------------

Downloading software from CNET and Softonic and certain other sites is a good way to infest your computer with malware, spyware, etc..

--------------------------------------------------------
 

Deacon

Thread Starter
Joined
Oct 27, 2002
Messages
34
I posted the info from the 'folders' tab and the 'registry' tab in post #13 hoping to find something that might be causing AdwCleaner from finishing the scan.

I downloaded AdwCleaner again and started the scan with the same result.
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Top