- Jul 2, 2015
- 2
Hello.
I have 64-bit win7 ultimate OS.
I'm getting "Exploit Fake Flash Player [Type 1747]" pop-up every time I go to youtube website.
Symptoms started from last 5-6 days.
It blocked all the Google services.
My AVG Anti-virus pops up every time I use ay Google services.
So, I formatted my C drive and re-install the win7.
Now I'm getting AVG pop-up only when I try to use youtube website.
It's showing the error: Exploit Fake Flash Player [Type 1747]
I also followed all the instructions given in this link:
http://malwaretips.com/blogs/remove-fake-flash-player-update/
Still I'm getting this pop-up or whatever it is called:-
AdwCleaner scan log is:-
# AdwCleaner v4.207 - Logfile created 02/07/2015 at 12:21:44
# Updated 21/06/2015 by Xplode
# Database : 2015-07-02.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : KinG - KING-PC
# Running from : C:\Users\KinG\Downloads\adwcleaner_4.207.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKCU\Software\Avg Secure Update
Key Deleted : HKU\.DEFAULT\Software\Avg Secure Update
***** [ Web browsers ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v38.0.5 (x86 en-US)
*************************
AdwCleaner[R0].txt - [753 bytes] - [01/07/2015 18:33:58]
AdwCleaner[R1].txt - [811 bytes] - [01/07/2015 18:57:10]
AdwCleaner[R2].txt - [1997 bytes] - [02/07/2015 12:21:00]
AdwCleaner[S0].txt - [874 bytes] - [01/07/2015 18:57:54]
AdwCleaner[S1].txt - [1895 bytes] - [02/07/2015 12:21:44]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1954 bytes] ##########
And My JRT Scan log is:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.2.6 (07.02.2015:1)
OS: Windows 7 Ultimate x64
Ran by KinG on 02-07-2015 at 11:18:42.60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully deleted: [Service] vToolbarUpdater18.4.0
~~~ Tasks
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2863353252-3341005711-1125978481-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
~~~ Files
~~~ Folders
Failed to delete: [Folder] C:\Program Files (x86)\avg web tuneup
Successfully deleted: [Folder] C:\ProgramData\avg security toolbar
Successfully deleted: [Folder] C:\ProgramData\avg web tuneup
Successfully deleted: [Folder] C:\Users\KinG\appdata\local\avg web tuneup
Successfully deleted: [Folder] C:\Users\KinG\appdata\locallow\avg web tuneup
Successfully deleted: [Folder] C:\Users\KinG\AppData\Roaming\tuneup software
~~~ FireFox
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02-07-2015 at 11:24:26.60
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
There are not many softwares installed on my pc as I formatted my C drive.
So please tell me..how to remove this virus?
Thank you.
I have 64-bit win7 ultimate OS.
I'm getting "Exploit Fake Flash Player [Type 1747]" pop-up every time I go to youtube website.
Symptoms started from last 5-6 days.
It blocked all the Google services.
My AVG Anti-virus pops up every time I use ay Google services.
So, I formatted my C drive and re-install the win7.
Now I'm getting AVG pop-up only when I try to use youtube website.
It's showing the error: Exploit Fake Flash Player [Type 1747]
I also followed all the instructions given in this link:
http://malwaretips.com/blogs/remove-fake-flash-player-update/
Still I'm getting this pop-up or whatever it is called:-
AdwCleaner scan log is:-
# AdwCleaner v4.207 - Logfile created 02/07/2015 at 12:21:44
# Updated 21/06/2015 by Xplode
# Database : 2015-07-02.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : KinG - KING-PC
# Running from : C:\Users\KinG\Downloads\adwcleaner_4.207.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKCU\Software\Avg Secure Update
Key Deleted : HKU\.DEFAULT\Software\Avg Secure Update
***** [ Web browsers ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v38.0.5 (x86 en-US)
*************************
AdwCleaner[R0].txt - [753 bytes] - [01/07/2015 18:33:58]
AdwCleaner[R1].txt - [811 bytes] - [01/07/2015 18:57:10]
AdwCleaner[R2].txt - [1997 bytes] - [02/07/2015 12:21:00]
AdwCleaner[S0].txt - [874 bytes] - [01/07/2015 18:57:54]
AdwCleaner[S1].txt - [1895 bytes] - [02/07/2015 12:21:44]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1954 bytes] ##########
And My JRT Scan log is:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.2.6 (07.02.2015:1)
OS: Windows 7 Ultimate x64
Ran by KinG on 02-07-2015 at 11:18:42.60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully deleted: [Service] vToolbarUpdater18.4.0
~~~ Tasks
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2863353252-3341005711-1125978481-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
~~~ Files
~~~ Folders
Failed to delete: [Folder] C:\Program Files (x86)\avg web tuneup
Successfully deleted: [Folder] C:\ProgramData\avg security toolbar
Successfully deleted: [Folder] C:\ProgramData\avg web tuneup
Successfully deleted: [Folder] C:\Users\KinG\appdata\local\avg web tuneup
Successfully deleted: [Folder] C:\Users\KinG\appdata\locallow\avg web tuneup
Successfully deleted: [Folder] C:\Users\KinG\AppData\Roaming\tuneup software
~~~ FireFox
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02-07-2015 at 11:24:26.60
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
There are not many softwares installed on my pc as I formatted my C drive.
So please tell me..how to remove this virus?
Thank you.