Here are the AdwCleaner files (it stopped responding during the first clean so rescanned). ~Lynne
# AdwCleaner v3.003 - Report created 09/09/2013 at 06:08:41
# Updated 07/09/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : Lynne - LYNNEHENDEE
# Running from : C:\Users\Lynne\Downloads\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\END
File Found : C:\Users\Lynne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk
File Found : C:\Users\Lynne\AppData\Roaming\Mozilla\Firefox\Profiles\r4q34n7i.default\user.js
File Found : C:\Users\Lynne\Desktop\iLivid.lnk
Folder Found : C:\Users\Lynne\AppData\Local\Google\Chrome\User Data\Default\Extensions\halffneccaebicfdfajnbfgpglahfgoe
Folder Found C:\Program Files (x86)\Giant Savings Extension
Folder Found C:\ProgramData\Ask
Folder Found C:\Users\Lynne\AppData\Local\DownloadTerms
Folder Found C:\Users\Lynne\AppData\Local\Giant Savings Extension
Folder Found C:\Users\Lynne\AppData\Local\Ilivid
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\Giant Savings Extension
Key Found : HKCU\Software\Cr_Installer
Key Found : HKCU\Software\ilivid
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\Cr_Installer
Key Found : [x64] HKCU\Software\ilivid
Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : [x64] HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\halffneccaebicfdfajnbfgpglahfgoe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Giant Savings Extension
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v20.0.1 (en-US)
[ File : C:\Users\Lynne\AppData\Roaming\Mozilla\Firefox\Profiles\r4q34n7i.default\prefs.js ]
-\\ Google Chrome v29.0.1547.66
[ File : C:\Users\Lynne\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found : icon_url
Found : search_url
Found : suggest_url
Found : keyword
Found : search_url
Found : suggest_url
[ File : C:\Users\Mackinaw\AppData\Local\Google\Chrome\User Data\Default\preferences ]
# AdwCleaner v3.003 - Report created 09/09/2013 at 06:15:00
# Updated 07/09/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : Lynne - LYNNEHENDEE
# Running from : C:\Users\Lynne\Downloads\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\END
File Found : C:\Users\Lynne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk
File Found : C:\Users\Lynne\AppData\Roaming\Mozilla\Firefox\Profiles\r4q34n7i.default\user.js
File Found : C:\Users\Lynne\Desktop\iLivid.lnk
Folder Found : C:\Users\Lynne\AppData\Local\Google\Chrome\User Data\Default\Extensions\halffneccaebicfdfajnbfgpglahfgoe
Folder Found C:\Users\Lynne\AppData\Local\Ilivid
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\Giant Savings Extension
Key Found : HKCU\Software\Cr_Installer
Key Found : HKCU\Software\ilivid
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\Cr_Installer
Key Found : [x64] HKCU\Software\ilivid
Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : [x64] HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\halffneccaebicfdfajnbfgpglahfgoe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Giant Savings Extension
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v20.0.1 (en-US)
[ File : C:\Users\Lynne\AppData\Roaming\Mozilla\Firefox\Profiles\r4q34n7i.default\prefs.js ]
-\\ Google Chrome v29.0.1547.66
[ File : C:\Users\Lynne\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found : icon_url
Found : search_url
Found : suggest_url
Found : keyword
Found : search_url
Found : suggest_url
[ File : C:\Users\Mackinaw\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [3176 octets] - [09/09/2013 06:08:41]
AdwCleaner[R1].txt - [2854 octets] - [09/09/2013 06:15:00]
AdwCleaner[S0].txt - [547 octets] - [09/09/2013 06:10:48]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [2973 octets] ##########
# AdwCleaner v3.003 - Report created 09/09/2013 at 06:10:48
# Updated 07/09/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : Lynne - LYNNEHENDEE
# Running from : C:\Users\Lynne\Downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\Program Files (x86)\Giant Savings Extension
Folder Deleted : C:\Users\Lynne\AppData\Local\DownloadTerms
Folder Deleted : C:\Users\Lynne\AppData\Local\Giant Savings Extension
# AdwCleaner v3.003 - Report created 09/09/2013 at 06:15:40
# Updated 07/09/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : Lynne - LYNNEHENDEE
# Running from : C:\Users\Lynne\Downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Lynne\AppData\Local\Ilivid
Folder Deleted : C:\Users\Lynne\AppData\Local\Google\Chrome\User Data\Default\Extensions\halffneccaebicfdfajnbfgpglahfgoe
File Deleted : C:\END
File Deleted : C:\Users\Lynne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk
File Deleted : C:\Users\Lynne\Desktop\iLivid.lnk
File Deleted : C:\Users\Lynne\AppData\Roaming\Mozilla\Firefox\Profiles\r4q34n7i.default\user.js
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\halffneccaebicfdfajnbfgpglahfgoe
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\Giant Savings Extension
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Giant Savings Extension
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v20.0.1 (en-US)
[ File : C:\Users\Lynne\AppData\Roaming\Mozilla\Firefox\Profiles\r4q34n7i.default\prefs.js ]
-\\ Google Chrome v29.0.1547.66
[ File : C:\Users\Lynne\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : icon_url
Deleted : search_url
Deleted : suggest_url
Deleted : keyword
[ File : C:\Users\Mackinaw\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [3176 octets] - [09/09/2013 06:08:41]
AdwCleaner[R1].txt - [3077 octets] - [09/09/2013 06:15:00]
AdwCleaner[S0].txt - [547 octets] - [09/09/2013 06:10:48]
AdwCleaner[S1].txt - [2704 octets] - [09/09/2013 06:15:40]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2764 octets] ##########
Fiery said:
Hi,
Don't worry about the system log, we can do without that one.
Please download
AdwCleaner by Xplode onto your desktop.
- Close all open programs and internet browsers.
- Double click on AdwCleaner.exe to run the tool(For Vista or Windows 7, right-click and select Run as Administrator to start)
- Click delete
- Please post the content of that logfile with your next reply.
- You can find the logfile at C:\AdwCleaner[S1].txt
Next, Download Farbar Recovery Scan Tool from the below link:
<ul><li>For 64 bit systems download <a title="External link" href="http://download.bleepingcomputer.com/farbar/FRST64.exe" rel="nofollow external"><
>Farbar Recovery Scan Tool x64</></a> and save it to a USB/flash drive.</li>
<li>Plug the flashdrive into the infected PC and double click on it.</li>
<li>When the tool opens click <>Yes</> to disclaimer.</li>
<li>Press <>Scan</> button.</li>
<li><>FRST</> will let you know when the scan is complete and has written the <>FRST.txt</> to file, close the message.
<li>Please copy and paste FRST.txt in your next reply</li></li>
</ol>
</ul>