1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: Frustrated

Discussion in 'Windows Vista' started by newcompute, May 12, 2015.

Thread Status:
Not open for further replies.
Advertisement
  1. newcompute

    newcompute Thread Starter

    Joined:
    May 12, 2015
    Messages:
    10
    Tech Support Guy System Info Utility version 1.0.0.2
    OS Version: Microsoft® Windows Vista™ Home Premium, Service Pack 2, 32 bit
    Processor: Intel(R) Core(TM)2 Duo CPU T5750 @ 2.00GHz, x64 Family 6 Model 15 Stepping 13
    Processor Count: 2
    RAM: 3061 Mb
    Graphics Card: Mobile Intel(R) 965 Express Chipset Family, 448 Mb
    Hard Drives: C: Total - 238472 MB, Free - 154083 MB;
    Motherboard: Dell Inc.,
    Antivirus: Kaspersky Internet Security, Updated and Enabled

    I think I have a malware virus: "Cheapcoup, Webroot, pc-technical-messages.com" keeps popping up and won't go away! Thanks for your help.
     
  2. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,728
    First Name:
    Frank
    Go here, then click the large blue "Download Now @ Bleeping Computer" button to download and save AdwCleaner.exe to your desktop.

    Close all open windows first, then double-click AdwCleaner.exe to load its main window.

    Click the "Scan" button, then allow the scanning process to finish.
    (Note: Several seconds may pass before the scanning process starts, so be patient.)

    Click the "Cleaning" button, then click "OK".

    Allow the cleaning process to finish.

    When it's finished, click "OK" in each window that appears.

    The computer will restart.

    When the log appears during restart, save it.

    Return here to your thread, then copy-and-paste the ENTIRE log here.

    ----------------------------------------------------------------------------------------------
     
  3. newcompute

    newcompute Thread Starter

    Joined:
    May 12, 2015
    Messages:
    10
    Thank you for the advise. I'll try it!
     
  4. newcompute

    newcompute Thread Starter

    Joined:
    May 12, 2015
    Messages:
    10
    # AdwCleaner v4.203 - Logfile created 12/05/2015 at 18:06:21
    # Updated 30/04/2015 by Xplode
    # Database : 2015-05-12.2 [Server]
    # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
    # Username : Annette - ANNETTE-PC
    # Running from : C:\Users\Annette\Desktop\adwcleaner_4.203.exe
    # Option : Cleaning

    ***** [ Services ] *****

    [#] Service Deleted : ReimageRealTimeProtector

    ***** [ Files / Folders ] *****

    Folder Deleted : C:\rei
    Folder Deleted : C:\ProgramData\ParetoLogic
    Folder Deleted : C:\ProgramData\Reimage Protector
    Folder Deleted : C:\ProgramData\shoppilation
    Folder Deleted : C:\ProgramData\12c5c7ee0000469e
    Folder Deleted : C:\ProgramData\6572564627647796712
    Folder Deleted : C:\ProgramData\737d34da000044f4
    Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
    Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reimage repair
    Folder Deleted : C:\Program Files\Conduit
    Folder Deleted : C:\Program Files\Fast Free Converter
    Folder Deleted : C:\Program Files\Reimage
    Folder Deleted : C:\Program Files\DriverRestore
    Folder Deleted : C:\Program Files\niIccenFrEe
    Folder Deleted : C:\Users\Annette\AppData\Local\Gameo
    Folder Deleted : C:\Users\Annette\AppData\Roaming\Gameo
    Folder Deleted : C:\Users\Annette\AppData\Roaming\ParetoLogic
    Folder Deleted : C:\Users\Annette\AppData\Roaming\UpdaterEX
    File Deleted : C:\END
    File Deleted : C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
    File Deleted : C:\Windows\Reimage.ini
    File Deleted : C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
    File Deleted : C:\Users\Annette\AppData\Roaming\Mozilla\Firefox\Profiles\demypywn.default\user.js
    File Deleted : C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.reimageplus.com_0.localstorage
    File Deleted : C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.reimageplus.com_0.localstorage-journal

    ***** [ Scheduled tasks ] *****

    Task Deleted : driverupdate startup
    Task Deleted : gameo_update
    Task Deleted : LaunchApp
    Task Deleted : Printatree
    Task Deleted : Reimage Reminder
    Task Deleted : ReimageUpdater
    Task Deleted : UpdaterEX

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKCU\Software\Google\Chrome\Extensions\dmibjfmphcpfoacbchialfobiohmhged
    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dmibjfmphcpfoacbchialfobiohmhged
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
    Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Reimage.exe
    Key Deleted : HKLM\SOFTWARE\Classes\P401cff32_06dc_425c_988a_3c7698e69b3a_.P401cff32_06dc_425c_988a_3c7698e69b3a_
    Key Deleted : HKLM\SOFTWARE\Classes\P401cff32_06dc_425c_988a_3c7698e69b3a_.P401cff32_06dc_425c_988a_3c7698e69b3a_.9
    Key Deleted : HKLM\SOFTWARE\Classes\Pd425696f_c306_49cd_9dbb_6480c98f92b9_.Pd425696f_c306_49cd_9dbb_6480c98f92b9_
    Key Deleted : HKLM\SOFTWARE\Classes\Pd425696f_c306_49cd_9dbb_6480c98f92b9_.Pd425696f_c306_49cd_9dbb_6480c98f92b9_.9
    Key Deleted : HKLM\SOFTWARE\08691f49-d554-1d36-9ba7-8fc03ac4e3b7
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3008668
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3106575
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{401cff32-06dc-425c-988a-3c7698e69b3a}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{d425696f-c306-49cd-9dbb-6480c98f92b9}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{f7921d9c-168a-40ee-a4a9-42dd202b0bb4}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DB507187-9746-458C-97DA-C458131EEDE7}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EB559340-3A8F-4456-B24D-160098054EF0}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{401cff32-06dc-425c-988a-3c7698e69b3a}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d425696f-c306-49cd-9dbb-6480c98f92b9}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{401cff32-06dc-425c-988a-3c7698e69b3a}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d425696f-c306-49cd-9dbb-6480c98f92b9}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{401cff32-06dc-425c-988a-3c7698e69b3a}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d425696f-c306-49cd-9dbb-6480c98f92b9}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FD79F359-E577-46DB-AA74-D6E6B8B45BA8}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{401cff32-06dc-425c-988a-3c7698e69b3a}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d425696f-c306-49cd-9dbb-6480c98f92b9}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B6}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03f3147c-cea6-4aae-b0ae-8d8abe7a8080}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4a80a60d-bdef-4d70-bccc-d0dad25ff951}
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8CDE19E6-71C2-4B46-89B7-35F6A18C571A}
    Key Deleted : HKCU\Software\CToolbar
    Key Deleted : HKCU\Software\eSupport.com
    Key Deleted : HKCU\Software\InstallCore
    Key Deleted : HKCU\Software\ParetoLogic
    Key Deleted : HKCU\Software\SiteRanker
    Key Deleted : HKCU\Software\UpdaterEX
    Key Deleted : HKCU\Software\Reimage
    Key Deleted : HKCU\Software\DriverRestore
    Key Deleted : HKCU\Software\gameo
    Key Deleted : HKCU\Software\Super Optimizer
    Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
    Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
    Key Deleted : HKCU\Software\AppDataLow\Software\Fun Web Products
    Key Deleted : HKCU\Software\AppDataLow\Software\FunWebProducts
    Key Deleted : HKCU\Software\AppDataLow\Software\MyWebSearch
    Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
    Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
    Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
    Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
    Key Deleted : HKLM\SOFTWARE\Conduit
    Key Deleted : HKLM\SOFTWARE\CToolbar
    Key Deleted : HKLM\SOFTWARE\Driver-Soft
    Key Deleted : HKLM\SOFTWARE\FocusInteractive
    Key Deleted : HKLM\SOFTWARE\ParetoLogic
    Key Deleted : HKLM\SOFTWARE\Reimage
    Key Deleted : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Repair
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{612AD33D-9824-4E87-8396-92374E91C4BB}_is1
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WebConnect
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{37476589-E48E-439E-A706-56189E2ED4C4}_is1
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E

    ***** [ Web browsers ] *****

    -\\ Internet Explorer v9.0.8112.16636

    Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

    -\\ Mozilla Firefox v


    -\\ Google Chrome v42.0.2311.135

    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : hxxp://search.conduit.com/?gd=&ctid=CT3323878&octid=EB_ORIGINAL_CTID&ISID=MBB84B037-B15C-44D1-9F94-EB0DFDBB1C95&SearchSource=55&CUI=&UM=5&UP=SPA22E7F7F-EDC6-409C-AE2F-3EFCA00075D6&SSPV=
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Startup_URLs] : hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP", "hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ggbc_15_16&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDtDtBtByD0FtCtAyC0A0EyEyCtByCzztN0D0Tzu0StCtBtDtDtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StBtAzyyC0CzzzytAtG0AtA0FtAtG0A0Azz0CtG0D0A0FyEtGtByBzyzytAyEyCzyyCzz0AtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtByCyE0D0E0DtDtGyByEtCtDtGyEyEtC0EtG0A0D0D0CtGzztCyD0C0B0E0BzztB0B0DtC2QtN0A0LzutB%26cr%3D732154682%26a%3Dwny_ggbc_15_16%26os%3DWindows Vista (TM) Home Premium
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Default_Search_Provider_Data] : hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ggbc_15_16&param1=1&param2=f%3D4%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDtDtBtByD0FtCtAyC0A0EyEyCtByCzztN0D0Tzu0StCtBtDtDtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0E0CyCtAzzyDyEtG0F0BtB0DtGzz0B0DtDtGyE0CtB0DtGyEyE0Fzz0A0DtD0A0A0C0EtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtDzytByDtAtBzytG0FyB0E0DtGyEtCtDtAtG0A0E0DtAtGyDtCyBtDyBtAyCtC0FyCyD0F2QtN0A0LzutB%26cr%3D1869639471%26a%3Dwny_ggbc_15_16%26os%3DWindows Vista (TM) Home Premium&p={searchTerms}

    *************************

    AdwCleaner[R0].txt - [15851 bytes] - [12/05/2015 18:04:51]
    AdwCleaner[S0].txt - [14689 bytes] - [12/05/2015 18:06:21]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14749 bytes] ##########

    THANKS FOR YOUR HELP!! I think it worked!
     
  5. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,728
    First Name:
    Frank
    Your computer is heavily infested, so we're not done yet.

    ----------------------------------------------------------

    Follow the previous instructions for AdwCleaner so its second log can be compared with its first log.

    After that's done, do the following.

    ----------------------------------------------------------

    Download and save and then install the free version of

    Malwarebytes Anti-Malware 2.1.6.1022

    SUPERAntiSpyware 6.0.1194

    Make sure to uncheck and decline to install any extras, such as toolbars and homepages, they may offer.

    Make sure to uncheck and decline to use the "Pro" or "Trial" version, if it's offered.

    After they're installed, DON'T do anything else with them.

    I'll give you complete instructions for setting them up and using them.

    ----------------------------------------------------------
     
  6. newcompute

    newcompute Thread Starter

    Joined:
    May 12, 2015
    Messages:
    10
    Okay - Here is the 2nd Log:

    # AdwCleaner v4.203 - Logfile created 13/05/2015 at 10:06:28
    # Updated 30/04/2015 by Xplode
    # Database : 2015-05-12.2 [Server]
    # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
    # Username : Annette - ANNETTE-PC
    # Running from : C:\Users\Annette\Desktop\adwcleaner_4.203.exe
    # Option : Cleaning

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****


    ***** [ Scheduled tasks ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****


    ***** [ Web browsers ] *****

    -\\ Internet Explorer v9.0.8112.16636


    -\\ Mozilla Firefox v


    -\\ Google Chrome v42.0.2311.135

    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=Z7xdm298YYus&ptnrS=Z7xdm298YYus&si=classiccards&ptb=10124972-B3C6-48D2-935B-30198022E2C9&psa=&ind=2012032318&st=sb&n=77ed2d3e&searchfor={searchTerms}
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80273&lng=en
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&affID=109935&babsrc=SP_ss&mntrId=90a6b5b0000000000000009096b6eb6f
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://dts.search-results.com/sr?src=ieb&appid=151111&systemid=426&sr=0&q={searchTerms}
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&affID=110819&tt=120812_bandext_3312_6&babsrc=SP_ss&mntrId=b0b25ad600000000000064273762e752
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=ORJ&o=&locale=&apn_uid=C6C5AE56-2F22-43E3-8726-5923F6753B04&apn_ptnrs=TV&apn_sauid=CA60E56F-9577-426E-81FC-36A3B888743D&apn_dtid=OSJ000YYUS&q={searchTerms}
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://asksearch.ask.com/redirect?client=cr&src=kw&tb=BCPA1&o=APN10474&itbv=11.8.1.231&doi=2013-04-20&locale=en_US&apn_uid=3B3FA955-BDE3-46AE-8205-55A70474B5D0&apn_ptnrs=^AKZ&apn_dtid=^YYYYYY^YY^US&apn_dbr=ie_9.0.8112.16476&&q={searchTerms}
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3323878&octid=EB_ORIGINAL_CTID&ISID=MBB84B037-B15C-44D1-9F94-EB0DFDBB1C95&SearchSource=58&CUI=&UM=5&UP=SPA22E7F7F-EDC6-409C-AE2F-3EFCA00075D6&q={searchTerms}&SSPV=
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://feed.snapdo.com/?publisher=Somoto&dpid=SomotoCH&co=US&userid=11697d47-13b7-b563-d686-f5787f956b3c&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBDDI6Pk-fpITtt_7-dx2uywuT-4gdlP7btPtzk_jJ3qV9p99dgH5fALLa9lVdvkFHDBF-SymBDHEnqav-qcZSO7bpzMNK3XAXDZgXV91yndjBhFyiwf2il3ERiGd6r3EhSprST1rnHLXYX3RIJ7Dfuzhbv7gEvevFeR8qyzvbSg,,&q={searchTerms}
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ggbc_15_16&param1=1&param2=f%3D4%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDtDtBtByD0FtCtAyC0A0EyEyCtByCzztN0D0Tzu0StCtBtDtDtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0E0CyCtAzzyDyEtG0F0BtB0DtGzz0B0DtDtGyE0CtB0DtGyEyE0Fzz0A0DtD0A0A0C0EtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtDzytByDtAtBzytG0FyB0E0DtGyEtCtDtAtG0A0E0DtAtGyDtCyBtDyBtAyCtC0FyCyD0F2QtN0A0LzutB%26cr%3D1869639471%26a%3Dwny_ggbc_15_16%26os%3DWindows Vista (TM) Home Premium&p={searchTerms}
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : hxxp://search.conduit.com/?gd=&ctid=CT3323878&octid=EB_ORIGINAL_CTID&ISID=MBB84B037-B15C-44D1-9F94-EB0DFDBB1C95&SearchSource=55&CUI=&UM=5&UP=SPA22E7F7F-EDC6-409C-AE2F-3EFCA00075D6&SSPV=
    [C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Startup_URLs] : hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP", "hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ggbc_15_16&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDtDtBtByD0FtCtAyC0A0EyEyCtByCzztN0D0Tzu0StCtBtDtDtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StBtAzyyC0CzzzytAtG0AtA0FtAtG0A0Azz0CtG0D0A0FyEtGtByBzyzytAyEyCzyyCzz0AtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtByCyE0D0E0DtDtGyByEtCtDtGyEyEtC0EtG0A0D0D0CtGzztCyD0C0B0E0BzztB0B0DtC2QtN0A0LzutB%26cr%3D732154682%26a%3Dwny_ggbc_15_16%26os%3DWindows Vista (TM) Home Premium

    *************************

    AdwCleaner[R0].txt - [15851 bytes] - [12/05/2015 18:04:51]
    AdwCleaner[R1].txt - [5669 bytes] - [13/05/2015 10:04:56]
    AdwCleaner[S0].txt - [14830 bytes] - [12/05/2015 18:06:21]
    AdwCleaner[S1].txt - [5565 bytes] - [13/05/2015 10:06:28]
     
  7. newcompute

    newcompute Thread Starter

    Joined:
    May 12, 2015
    Messages:
    10
    I have installed the malwarebytes program and the superantispyware program. Let me know what I do with them. Thanks for all your time and help!
     
  8. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,728
    First Name:
    Frank
    Follow these instructions carefully, and take your time.

    ---------------------------------------------------------

    Start Malwarebytes Anti-Malware.

    Click "Settings". then click "Detection and Protection".

    Make sure all boxes in "Detection Options" are checked.

    Click "Scan", then select Threat Scan, then click "Start Scan".

    Note: If it wants to update the definition files first, allow it to do so.

    If problems are found during the scan, the number of "Detected Objects" will be listed.

    When the scan is finished, make sure to select and quarantine EVERYTHING in the list.

    If you're prompted to restart the computer to complete the process, do so.

    Start Malwarebytes Anti-Malware again.

    Click "History - Application Logs".

    Double-click on the most recent scan log entry.

    When the next window appears, click on the most recent scan log entry.

    Select "Export - Text File", then name it mbam, then save it on the desktop.

    Return here, then copy-and-paste its ENTIRE contents here.

    ---------------------------------------------------------

    Start SUPERAntiSpyware.

    Click "System Tools".

    Click "Preferences", then uncheck "Run in the background (system tray)", then click "Done".

    Click "Advanced Settings", then uncheck "Follow shortcuts (*.lnk) during scan", then click "OK - Done".

    Click "Click here to check for updates".

    When the definition files have updated, click "OK".

    Click "Scan This Computer", then click Quick Scan.

    If problems are found during the scan, the number of them will be highlighted in red.

    When the scan is finished, click "Continue".

    Make sure that EVERYTHING in the list is selected, then click "Continue".

    When the removal process is complete, click "Continue".

    If you're prompted to restart to finish the removal process, do so.

    Start SUPERAntiSpyware again.

    Click "System Tools", then click "Scan Logs".

    Select the most current scan log, then click on its magnifying glass icon so it can open and be viewed, then save it on the desktop.

    Return here, then copy-and-paste its ENTIRE contents here.

    ---------------------------------------------------------
     
  9. newcompute

    newcompute Thread Starter

    Joined:
    May 12, 2015
    Messages:
    10
    Here is my Malwarebytes report:

    Malwarebytes Anti-Malware
    www.malwarebytes.org


    Protection, 5/13/2015 10:30:03 AM, SYSTEM, ANNETTE-PC, Protection, Malware Protection, Starting,
    Protection, 5/13/2015 10:30:03 AM, SYSTEM, ANNETTE-PC, Protection, Malware Protection, Started,
    Protection, 5/13/2015 10:30:03 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Starting,
    Update, 5/13/2015 10:30:12 AM, SYSTEM, ANNETTE-PC, Manual, Remediation Database, 2015.3.9.1, 2015.5.9.1,
    Update, 5/13/2015 10:30:13 AM, SYSTEM, ANNETTE-PC, Manual, Rootkit Database, 2015.2.25.1, 2015.4.21.1,
    Protection, 5/13/2015 10:30:14 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Started,
    Update, 5/13/2015 10:30:43 AM, SYSTEM, ANNETTE-PC, Manual, Malware Database, 2015.3.9.5, 2015.5.13.4,
    Protection, 5/13/2015 10:30:43 AM, SYSTEM, ANNETTE-PC, Protection, Refresh, Starting,
    Protection, 5/13/2015 10:30:43 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Stopping,
    Protection, 5/13/2015 10:30:43 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Stopped,
    Protection, 5/13/2015 10:30:51 AM, SYSTEM, ANNETTE-PC, Protection, Refresh, Success,
    Protection, 5/13/2015 10:30:51 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Starting,
    Protection, 5/13/2015 10:30:56 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Started,
    Update, 5/13/2015 11:22:21 AM, SYSTEM, ANNETTE-PC, Scheduler, Remediation Database, 2015.5.9.1, 2015.5.13.1,
    Protection, 5/13/2015 11:22:21 AM, SYSTEM, ANNETTE-PC, Protection, Refresh, Starting,
    Protection, 5/13/2015 11:22:21 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Stopping,
    Protection, 5/13/2015 11:22:21 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Stopped,
    Protection, 5/13/2015 11:23:08 AM, SYSTEM, ANNETTE-PC, Protection, Refresh, Success,
    Protection, 5/13/2015 11:23:08 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Starting,
    Protection, 5/13/2015 11:23:17 AM, SYSTEM, ANNETTE-PC, Protection, Malicious Website Protection, Started,

    (end)
     
  10. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,728
    First Name:
    Frank
    That's not the scan log.

    Did it find any threats during the scan, and did you quarantine or remove them all?

    ----------------------------------------------------------
     
  11. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,728
    First Name:
    Frank
    I'm getting ready to shut down for a few hours or possibly for the rest of the day.

    I'll check back here later or tomorrow morning. (y)

    ----------------------------------------------------------
     
  12. newcompute

    newcompute Thread Starter

    Joined:
    May 12, 2015
    Messages:
    10
    Okay. Have a nice afternoon.
    I thought I had quarantined and removed everything. I'll check again.
    Here is Superantispyware report: Is it the right thing?

    1. SUPERAntiSpyware Scan Log
    2. http://www.superantispyware.com

    3. Generated 05/13/2015 at 12:41 PM

    4. Application Version : 6.0.1194
    5. Database Version : 11875

    6. Scan type : Quick Scan
    7. Total Scan Time : 00:07:56

    8. Operating System Information
    9. Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
    10. UAC On - Limited User (Administrator User)

    11. Memory items scanned : 544
    12. Memory threats detected : 0
    13. Registry items scanned : 28716
    14. Registry threats detected : 0
    15. File items scanned : 4504
    16. File threats detected : 51

    17. Adware.Tracking Cookie
    a. .doubleclick.net [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    b. .serving-sys.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    c. oasn04.247realmedia.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    d. www.googleadservices.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    e. .serving-sys.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    f. .atdmt.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    g. .imrworldwide.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    h. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    i. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    j. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    k. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    l. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DEMYPYWN.DEFAULT\COOKIES.SQLITE ]
    m. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\DEGNY826.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\DEGNY826.txt [ Cookie:[email protected]/ ]
    n. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\UIHRMTFW.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\UIHRMTFW.txt [ Cookie:[email protected]/ ]
    o. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\O66FPVTQ.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\O66FPVTQ.txt [ Cookie:[email protected]echus.com/ ]
    p. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\NM03ID8L.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\NM03ID8L.txt [ Cookie:[email protected]/ ]
    q. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\L8WP2JN7.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\L8WP2JN7.txt [ Cookie:[email protected]/ ]
    r. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZDY9HCCZ.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZDY9HCCZ.txt [ Cookie:[email protected]/ ]
    s. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZBJI6R5B.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZBJI6R5B.txt [ Cookie:[email protected]/ ]
    t. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\6197EP2P.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\6197EP2P.txt [ Cookie:[email protected]/cgi-bin ]
    u. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\C5D16G03.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\C5D16G03.txt [ Cookie:[email protected]/ ]
    v. C:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\169UESHE.txtC:\USERS\ANNETTE\AppData\Roaming\Microsoft\Windows\Cookies\Low\169UESHE.txt [ Cookie:[email protected]/ ]
    w. C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\25A8AGHG.txtC:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\25A8AGHG.txt [ /ad.360yield.com ]
    x. C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\UBZDTRT3.txtC:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\UBZDTRT3.txt [ /ru4.com ]
    y. C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\QRHPG0TQ.txtC:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\QRHPG0TQ.txt [ /tracking.instantcheckmate.com ]
    z. C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\M5BK6Y3K.txtC:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\M5BK6Y3K.txt [ /advertising.com ]
    aa. C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\NQK12B0R.txtC:\Users\Annette\AppData\Roaming\Microsoft\Windows\Cookies\Low\NQK12B0R.txt [ /at.atwola.com ]
    bb. .eyeviewads.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    cc. s.alexa-tracking.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    dd. .doubleclick.net [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ee. .imrworldwide.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ff. .track.rqtzz.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    gg. .reimage.revenuewire.net [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    hh. .adaptv.advertising.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ii. .track.rqtzz.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    jj. .doubleclick.net [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    kk. s1.alexa-stats-premium.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ll. s1.alexa-stats-premium.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    mm. .track.jo2alw.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    nn. .enigma.revenuewire.net [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    oo. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    pp. .revsci.net [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    qq. .revsci.net [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    rr. .revsci.net [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ss. .revsci.net [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    tt. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    uu. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    vv. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ww. .casalemedia.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    xx. .adaptv.advertising.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    yy. .adaptv.advertising.com [ C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]

    18. ============
    19. End of Log
    20. ============
     
  13. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,728
    First Name:
    Frank
    As long as you know you selected and quarantined/removed everything in Malwarebytes Anti-Malware and selected and deleted everything in SUPERAntiSpyware, that's fine.

    Let's do one more thing and then we should be done.

    ----------------------------------------------------------

    Go here, then click the large blue "Download Now @ Author's Site" button to download and save TFC.exe (Temp File Cleaner by OldTimer) to your desktop.

    After it's downloaded and saved, close all open windows.

    Double-click it to load its main window.

    Click the "Start" button.

    If there are a large number of temp files or if there are multiple user accounts, the temp file deletion process may appear to freeze and may take a few minutes, so don't interfere with or abort it.

    After it's finished, restart the computer.

    Advise how many files in MB's were found and deleted.

    ----------------------------------------------------------
     
  14. newcompute

    newcompute Thread Starter

    Joined:
    May 12, 2015
    Messages:
    10
    I did the tfc. There were 2,995.00 MB. But I keep getting this "Ad by cheapcoup" popping into everything I bring up.
     
  15. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,728
    First Name:
    Frank
    That's also 3 GB of temp files that you cleaned out and reclaimed hard drive free space. (y)

    We don't know what your computing and browsing habits are, and we don't know what's installed and running in your computer, so that's probably the reason for that particular pop-up.

    I highly recommend you put AdwCleaner and Malwarebytes Anti-Malware and SUPERAntiSpyware and Temp File Cleaner By OldTimer (in that order) to use once a week.

    Let's check some other things.

    -----------------------------------------------------------

    Click Start, then type MSCONFIG in the search or run box, then press the Enter key.

    When the small "System Configuration" window appears, click the "Startup" tab.

    Write down ONLY the names in the "Startup Item" column that have a checkmark next to them.

    If the "Startup Item" column isn't wide enough to see the entire name of any of them, widen the column.

    Submit those names here in a vertical list.

    Make sure to spell them EXACTLY as you see them there.

    -----------------------------------------------------------
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1148134

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice