Buy Malwarebytes antimalware











This site is hosted at Hostgator.com




Sponsored Adverts

Sponsored Ads

These adverts come direct from Google adsense



Recent Posts

Pages: 1 2 [3] 4 5 6 7 8 ... 10
21
Malware removal and help / just a check
« Last post by rock995 on August 13, 2014, 00:11:04 »
Hi Derek.  Back from my travels and, sure enough, my girlfriend who was using my computer has perhaps picked up
a bit of malware, specifically Win32.2UrFace.bho (which SpyBot S&D says is there but can't seem to eliminate it).

I went to donate to the HH but, on second thought, didn't want to do any financial transactions with something possible lurking in the backgroung.

Anyway to check this computer and see if anything fishy shows up?

I see that the site hasn't been that active since my posting in January.  Hope your health is holding up my friend.

rock
22
Uploads / Re: Files Requested by eddie:
« Last post by Referee06 on July 04, 2014, 03:51:43 »
Second Qoobox submission
24
Malware removal and help / Re: adware/malware popups etc
« Last post by Derek on April 28, 2014, 23:05:59 »
the civic cookie is genuine for this site, I have to have that to comply with EU cookie laws. You will get that every time until you accept it 
What is the suspicious update message
25
Malware removal and help / Re: adware/malware popups etc
« Last post by manicmoms on April 28, 2014, 23:04:32 »
When I visit this page I get a "Civic Cookie" Message....and then I am still getting a suspicious update message that has a lot of pop up messages in it about navigating away from page etc...let me know if you need more detail about them and I will write it down next time they pop up.
26
Malware removal and help / Re: adware/malware popups etc
« Last post by Derek on April 27, 2014, 12:21:52 »
How is it mow and are you still having any problems
27
Malware removal and help / Re: adware/malware popups etc
« Last post by manicmoms on April 26, 2014, 23:18:59 »
had to reboot after the fix and then upon reboot had to locate the log file before pasting it below...but otherwise no other differences in your instructions.

All Processes Killed
[Registry - Safe List]
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3DF5BF98-C5A8-4154-8B63-D07977DBA953}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3DF5BF98-C5A8-4154-8B63-D07977DBA953}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{3DF5BF98-C5A8-4154-8B63-D07977DBA953}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBBEDAC2-B124-494A-9D19-7C0D7741690C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBBEDAC2-B124-494A-9D19-7C0D7741690C}\ deleted successfully.
[Registry - Additional Scans - Safe List]
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{51DEF79C-4941-E5AF-086B-0BC003A792DD}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{51DEF79C-4941-E5AF-086B-0BC003A792DD}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0375699A-9258-90D1-617D-89EB7B787A03}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0375699A-9258-90D1-617D-89EB7B787A03}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{51DEF79C-4941-E5AF-086B-0BC003A792DD}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{51DEF79C-4941-E5AF-086B-0BC003A792DD}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{BBBEDAC2-B124-494A-9D19-7C0D7741690C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBBEDAC2-B124-494A-9D19-7C0D7741690C}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0375699A-9258-90D1-617D-89EB7B787A03}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0375699A-9258-90D1-617D-89EB7B787A03}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{51DEF79C-4941-E5AF-086B-0BC003A792DD}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{51DEF79C-4941-E5AF-086B-0BC003A792DD}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BBBEDAC2-B124-494A-9D19-7C0D7741690C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBBEDAC2-B124-494A-9D19-7C0D7741690C}\ not found.
[Files/Folders - Created Within 90 Days]
C:\Program Files (x86)\MyPC Backup\log folder moved successfully.
C:\Program Files (x86)\MyPC Backup folder moved successfully.
[Files/Folders - Modified Within 90 Days]
C:\Windows\Temp\20F8.tmp deleted successfully.
C:\Windows\Temp\APPX.6nkyon_5bg2mm5l5_fn9ngj3g.tmp deleted successfully.
C:\Windows\Temp\APPX.hpfgykeec9qmkcwc2l_rmldvd.tmp deleted successfully.
C:\Windows\Temp\APPX.myj4n48in70vgy3k19y47fqyg.tmp deleted successfully.
C:\Windows\Temp\APPX.n15xhg8sc6z13k2d5do7nsa7c.tmp deleted successfully.
C:\Windows\Temp\CR_3C4B6.tmp\SETUP_PATCH.PACKED.7Z deleted successfully.
C:\Windows\Temp\CR_3C4B6.tmp folder deleted successfully.
C:\Windows\Temp\DMI167C.tmp deleted successfully.
C:\Windows\Temp\DMI3A41.tmp deleted successfully.
C:\Windows\Temp\DMI3ED8.tmp deleted successfully.
C:\Windows\Temp\DMI70EF.tmp deleted successfully.
C:\Windows\Temp\DMIE1A7.tmp deleted successfully.
C:\Windows\Temp\DMIF4BA.tmp deleted successfully.
C:\Windows\Temp\FireFoxSearchXml.tmp deleted successfully.
C:\Windows\Temp\nsa4D58.tmp\System.dll deleted successfully.
C:\Windows\Temp\nsa4D58.tmp folder deleted successfully.
C:\Windows\Temp\nseE1B6.tmp\System.dll deleted successfully.
C:\Windows\Temp\nseE1B6.tmp folder deleted successfully.
C:\Windows\Temp\nsgAB8.tmp\System.dll deleted successfully.
C:\Windows\Temp\nsgAB8.tmp folder deleted successfully.
C:\Windows\Temp\nsh2395.tmp\System.dll deleted successfully.
C:\Windows\Temp\nsh2395.tmp folder deleted successfully.
C:\Windows\Temp\nsx68FD.tmp\System.dll deleted successfully.
C:\Windows\Temp\nsx68FD.tmp folder deleted successfully.
C:\Windows\Temp\nsx7071.tmp\System.dll deleted successfully.
C:\Windows\Temp\nsx7071.tmp folder deleted successfully.
C:\Windows\Temp\nsxDEF3.tmp\System.dll deleted successfully.
C:\Windows\Temp\nsxDEF3.tmp folder deleted successfully.
C:\Windows\Temp\tmp399A.tmp deleted successfully.
C:\Windows\Temp\tmp399B.tmp deleted successfully.
C:\Windows\Temp\tmp46D8.tmp deleted successfully.
C:\Windows\Temp\tmp46D9.tmp deleted successfully.
C:\Windows\Temp\tmp6700.tmp deleted successfully.
C:\Windows\Temp\tmp6730.tmp deleted successfully.
C:\Windows\Temp\TS_3468.tmp deleted successfully.
C:\Windows\Temp\TS_84F7.tmp deleted successfully.
C:\Windows\Temp\TS_CC91.tmp deleted successfully.
C:\Windows\Temp\TS_D9CB.tmp deleted successfully.
C:\Windows\Temp\UDD2A6C.tmp deleted successfully.
C:\Windows\Temp\UDD2A8E.tmp deleted successfully.
C:\Windows\Temp\avg_a00936\ProgFiles\AVG SafeGuard toolbar\FireFoxSearchXml.tmp deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCall.dll deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla.dll deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla2.dll deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla21.dll deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla31.dll deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla31.exe deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla32.dll deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla33.dll deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla34.dll deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla37.exe deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseData.ini deleted successfully.
C:\Users\Jalee6789\ACF5FE1B377240688B872D2A6EFD0A05.TMP folder deleted successfully.
[Empty Temp Folders]
 
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Jaime
->Temp folder emptied: 2441996 bytes
->Temporary Internet Files folder emptied: 128 bytes
 
User: Jalee6789
->Temp folder emptied: 1180493400 bytes
->Temporary Internet Files folder emptied: 85439226 bytes
->Google Chrome cache emptied: 378642909 bytes
->Flash cache emptied: 15818 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 70814113 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 450991 bytes
RecycleBin emptied: 54120940 bytes
 
Total Files Cleaned = 1,690.00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Jaime
 
User: Jalee6789
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0.00 mb
 
 
[EMPTYJAVA]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Jaime
 
User: Jalee6789
 
User: Public
 
Total Java Files Cleaned = 0.00 mb
 
< End of fix log >
OTS by OldTimer - Version 3.1.47.2 fix logfile created on 04262014_164438

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
28
Malware removal and help / Re: adware/malware popups etc
« Last post by Derek on April 26, 2014, 07:31:53 »
Start OTS. Copy/Paste the information in the Code box below into the pane where it says "Paste fix here" and then click the Run Fix button.


Code: [Select]
[Unregister Dlls]
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {3DF5BF98-C5A8-4154-8B63-D07977DBA953} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {BBBEDAC2-B124-494A-9D19-7C0D7741690C} [HKLM] -> [GetSavin 5.0]
[Registry - Additional Scans - Safe List]
< Ext (PreApproved) - [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
YN -> {51DEF79C-4941-E5AF-086B-0BC003A792DD} [HKLM] -> [Safeurweb]
< Ext (Settings) - [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\
YN -> {0375699A-9258-90D1-617D-89EB7B787A03} [HKLM] -> [REalddeAl]
YN -> {51DEF79C-4941-E5AF-086B-0BC003A792DD} [HKLM] -> [Safeurweb]
YN -> {BBBEDAC2-B124-494A-9D19-7C0D7741690C} [HKLM] -> [GetSavin 5.0]
< Ext (Stats) - [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\
YN -> {0375699A-9258-90D1-617D-89EB7B787A03} [HKLM] -> [REalddeAl]
YN -> {51DEF79C-4941-E5AF-086B-0BC003A792DD} [HKLM] -> [Safeurweb]
YN -> {BBBEDAC2-B124-494A-9D19-7C0D7741690C} [HKLM] -> [GetSavin 5.0]
< Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
YN -> {730C1F02-ABB6-7601-60ED-659A59700742} -> REalddeAl
[Files/Folders - Created Within 90 Days]
NY ->  MyPC Backup -> C:\Program Files (x86)\MyPC Backup
[Files/Folders - Modified Within 90 Days]
NY ->  32 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp
NY ->  32 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp
NY ->  1 C:\Windows\Temp\avg_a00936\ProgFiles\AVG SafeGuard toolbar\*.tmp files -> C:\Windows\Temp\avg_a00936\ProgFiles\AVG SafeGuard toolbar\*.tmp
NY ->  1 C:\Users\Jalee6789\*.tmp files -> C:\Users\Jalee6789\*.tmp
[Empty Temp Folders]
[EmptyFlash]
[EmptyJava]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here .

I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
29
Malware removal and help / Re: adware/malware popups etc
« Last post by manicmoms on April 25, 2014, 23:50:57 »
Sorry....OTS log attached
30
Malware removal and help / Re: adware/malware popups etc
« Last post by Derek on April 25, 2014, 22:26:24 »
that is only part of the OTS log
can you attach the whole log please so I can see what needs fixing
Pages: 1 2 [3] 4 5 6 7 8 ... 10

Donations

You have come to The Spykiller for help because your Antivirus or Antispyware hasn't been able to fix your problem.

Modern Malware has become so involved and difficult to fix that it takes a very long time and a lot of hard work to read all the logs posted here and research and prepare the fixes for you. In many cases each part of the fix takes about 30 minutes to prepare, so a large part of my time is spent helping you

Would you do all this for nothing?

The reason I run this site is to raise funds for Hedgehog Rescue

Please donate if I have helped you or you have found this site useful.

You can donate safely and securely by using the paypal service, just click on one of the buttons below.

To donate in UK £

To donate in US$

To donate in Euro €

Any amount no matter how small is gratefully accepted and needed to ensure we keep the Rescue Centre running

To donate via paypal when the button doesn't appear or the link doesn't work: just go to www.paypal.com or your country's paypal log in page and chose send money and use help@thehedgehog.co.uk as recipient email address and select other service as the option. then follow prompts


Useful Advice and Programs

Stop killing hedgehogs with strimmers
Welcome, Guest. Please login or register.
Did you miss your activation email?
November 23, 2014, 11:47:59

Login with username, password and session length

secunia Software inspector


RoboForm: Learn more...

You have come to The Spykiller for help because your Antivirus or Antispyware hasn't been able to fix your problem.

Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work to read all the logs posted here and research and prepare the fixes for you.
In many cases each part of the fix takes about 30 minutes to prepare, so a large part of my time is spent helping you

Would you do all this for nothing?

I run this site to help raise funds for Hedgehog Rescue

Please donate if I have helped you or you have found this site useful.

You can donate safely and securely by using the PayPal service, just click on one of the buttons below.

To donate in UK £

To donate in US$

To donate in Euro €

Any amount no matter how small is gratefully accepted and needed to ensure we keep the Rescue Centre running