Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Dllhost.exe 100% disk usage
Message
<blockquote data-quote="basketball2323" data-source="post: 475442" data-attributes="member: 49049"><p>Zoek.exe v5.0.0.1 Updated 31-December-2015</p><p>Tool run by Cam on 01/02/2016 at 1:00:29.32.</p><p>Microsoft Windows 8 Pro 6.2.9200 x64</p><p>Running in: Normal Mode Internet Access Detected</p><p>Launched: C:\Users\Cam\Downloads\zoek.exe [Scan all users] [Script inserted] </p><p></p><p>==== System Restore Info ======================</p><p></p><p>01/02/2016 01:08:27 Zoek.exe System Restore Point Created Successfully.</p><p></p><p>==== Empty Folders Check ======================</p><p></p><p>C:\PROGRA~2\AGEIA Technologies deleted successfully</p><p>C:\PROGRA~2\DivX deleted successfully</p><p>C:\PROGRA~3\Avg deleted successfully</p><p>C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully</p><p>C:\Users\Cam\AppData\Roaming\sparta111 deleted successfully</p><p>C:\Users\Cam\AppData\Roaming\uTorrent deleted successfully</p><p>C:\Users\Cam\AppData\Local\Skype deleted successfully</p><p>C:\Users\Cam\AppData\Local\Sparta deleted successfully</p><p>C:\Users\Cam\AppData\Local\WarThunder deleted successfully</p><p>C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully</p><p>C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p>HKEY_USERS\S-1-5-21-626473118-3010605479-898090307-1001\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} deleted successfully</p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully</p><p></p><p>==== Deleting Services ======================</p><p></p><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater14.2.0 deleted successfully</p><p></p><p>==== Batch Command(s) Run By Tool======================</p><p></p><p></p><p>Windows IP Configuration</p><p></p><p>Successfully flushed the DNS Resolver Cache.</p><p></p><p>==== Deleting Files \ Folders ======================</p><p></p><p>C:\PROGRA~2\AGEIA Technologies not found</p><p>C:\PROGRA~2\DivX not found</p><p>C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not found</p><p>C:\PROGRA~2\Flyordie Plugin deleted</p><p>C:\windows\SysNative\Tasks\Bidaily Synchronize Task[973b] deleted</p><p>C:\Windows\tasks\Bidaily Synchronize Task[973b].job deleted</p><p>C:\PROGRA~3\{7c12c1dc-c294-1c6e-7c12-2c1dcc290773} deleted</p><p>C:\PROGRA~3\5767796595995162811 deleted</p><p>C:\PROGRA~3\DivX deleted</p><p>C:\PROGRA~2\SearchProtect deleted</p><p>C:\PROGRA~2\File Scout deleted</p><p>C:\PROGRA~2\COMMON~1\AVG Secure Search deleted</p><p>C:\prefs.js deleted</p><p>C:\Users\Cam\AppData\Roaming\RHEng deleted</p><p>C:\Users\Cam\AppData\Roaming\Systweak deleted</p><p>C:\Users\Cam\AppData\Roaming\OpenCandy deleted</p><p>C:\PROGRA~3\AVG Security Toolbar deleted</p><p>C:\PROGRA~3\IBUpdaterService deleted</p><p>C:\PROGRA~3\AVG SafeGuard toolbar deleted</p><p>C:\PROGRA~3\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} deleted</p><p>C:\PROGRA~3\Package Cache deleted</p><p>C:\Users\Cam\AppData\Local\SearchProtect deleted</p><p>C:\Users\Cam\AppData\Local\Unity deleted</p><p>C:\Users\Cam\AppData\Local\AVG Secure Search deleted</p><p>C:\Users\Cam\AppData\Local\Systweak deleted</p><p>C:\Users\Cam\AppData\Local\AVG SafeGuard toolbar deleted</p><p>C:\Users\Cam\AppData\Local\adawarebp deleted</p><p>C:\Users\Cam\AppData\Local\AVG Nation toolbar deleted</p><p>C:\Users\Cam\AppData\Local\CrashRpt deleted</p><p>C:\Users\Cam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta deleted</p><p>C:\Windows\SysNative\roboot64.exe deleted</p><p>C:\Users\Cam\AppData\LocalLow\AVG SafeGuard toolbar deleted</p><p>C:\Users\Cam\AppData\LocalLow\Unity deleted</p><p>C:\END deleted</p><p>C:\Windows\SysNative\config\systemprofile\Searches deleted</p><p>C:\Windows\Syswow64\SearchProtect deleted</p><p></p><p>==== Firefox Extensions Registry ======================</p><p></p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]</p><p>"avg@toolbar"="C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\14.2.0.1" []</p><p></p><p>==== Chromium Look ======================</p><p></p><p>Google Chrome Version: 46.0.2490.86</p><p></p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions</p><p>lfffjahnfbocnaooecgijfnbpcfekoik - C:\ProgramData\adawaretb\shortcuts\chrome\adawaretb.crx[]</p><p>lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[08/01/2016 10:47]</p><p>ndibdjnfmopecpmkdieinmbadjfpblof - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\14.2.0.1\avg.crx[]</p><p></p><p>Ask Toolbar - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko</p><p>Comodo Drag&Drop Service - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aneodkojaglhnkkdbbdnmmmgimlcaogo</p><p>Comodo Web Inspector - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn</p><p>PrivDog - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja</p><p>Comodo Media Downloader - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\dihmnpngfonlhjmgkflpnibiaaliendo</p><p>Absolute Radio Live Scores - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kgmkadilkeimcolingoooifhoknpkifi</p><p>AVG SafeGuard toolbar - Cam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof</p><p></p><p>==== Chromium Startpages ======================</p><p></p><p>C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Preferences</p><p>"homepage": "<a href="http://websearch.searchtotal.info/?pid=24388&r=2015/06/01&hid=5087950222676336109&lg=EN&cc=AU&unqvl=88" target="_blank">Search</a>",</p><p></p><p></p><p>==== Chromium Fix ======================</p><p></p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_admtpmp123.adk2x.com_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_admtpmp123.adk2x.com_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.donation-tools.org_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.donation-tools.org_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.tunefind.com_0.localstorage" target="_blank">www.tunefind.com_0.localstorage</a> deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.tunefind.com_0.localstorage-journal" target="_blank">www.tunefind.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_career-services.careerone.com.au_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_career-services.careerone.com.au_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_roysautoservices.com_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_roysautoservices.com_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully</p><p>C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko deleted successfully</p><p>C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage deleted successfully</p><p>C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage-journal deleted successfully</p><p>C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kgmkadilkeimcolingoooifhoknpkifi deleted successfully</p><p></p><p>==== Set IE to Default ======================</p><p></p><p>Old Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130986366714421902&GUID=BF406046-4567-454B-8EA1-7975E2173FAC" target="_blank">MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos</a>"</p><p>"Search Page"="<a href="http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}" target="_blank">http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}</a>"</p><p>"Default_Page_URL"="<a href="http://www.google.com/" target="_blank">Google</a>"</p><p>"Default_Search_URL"="<a href="http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}" target="_blank">http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]</p><p>"Default_Search_URL"="<a href="http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}" target="_blank">http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}</a>"</p><p>"Default_Page_URL"="<a href="http://www.google.com/" target="_blank">Google</a>"</p><p>"Search Page"="<a href="http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}" target="_blank">http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]</p><p>"Default_Search_URL"="<a href="http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}" target="_blank">http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}</a>"</p><p>"Default_Page_URL"="<a href="http://www.google.com/" target="_blank">Google</a>"</p><p>"Search Page"="<a href="http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}" target="_blank">http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}</a>"</p><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]</p><p>"Tabs"="res://ieframe.dll/tabswelcome.htm"</p><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]</p><p>"Tabs"="res://ieframe.dll/tabswelcome.htm"</p><p></p><p>New Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Search Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a>"</p><p>"Default_Search_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a>"</p><p>"Default_Page_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos</a>"</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130986366714421902&GUID=BF406046-4567-454B-8EA1-7975E2173FAC" target="_blank">MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]</p><p>"Default_Search_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a>"</p><p>"Search Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a>"</p><p>"Default_Page_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]</p><p>"Default_Search_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a>"</p><p>"Search Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">Bing</a>"</p><p>"Default_Page_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos</a>"</p><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]</p><p>"Tabs"="about:newtab"</p><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]</p><p>"Tabs"="about:newtab"</p><p></p><p>==== All HKLM and HKCU SearchScopes ======================</p><p></p><p>HKLM\SearchScopes "DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}"</p><p>HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - <a href="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" target="_blank">{searchTerms} - Bing</a></p><p>HKLM\Wow6432Node\SearchScopes "DefaultScope"="{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}"</p><p>HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - <a href="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" target="_blank">{searchTerms} - Bing</a></p><p>HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"</p><p>HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - <a href="http://www.google.com/search?q={searchTerms}" target="_blank">{searchTerms} - Google Search</a></p><p>HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - <a href="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR" target="_blank">{searchTerms} - Bing</a></p><p></p><p>==== Deleting Registry Keys ======================</p><p></p><p>HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lfffjahnfbocnaooecgijfnbpcfekoik deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06B99631-BFA2-3B7A-F58B-D067C2BA59B7} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar deleted successfully</p><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\omiga-plus uninstall deleted successfully</p><p></p><p>==== Empty IE Cache ======================</p></blockquote><p></p>
[QUOTE="basketball2323, post: 475442, member: 49049"] Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Cam on 01/02/2016 at 1:00:29.32. Microsoft Windows 8 Pro 6.2.9200 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Cam\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 01/02/2016 01:08:27 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\AGEIA Technologies deleted successfully C:\PROGRA~2\DivX deleted successfully C:\PROGRA~3\Avg deleted successfully C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully C:\Users\Cam\AppData\Roaming\sparta111 deleted successfully C:\Users\Cam\AppData\Roaming\uTorrent deleted successfully C:\Users\Cam\AppData\Local\Skype deleted successfully C:\Users\Cam\AppData\Local\Sparta deleted successfully C:\Users\Cam\AppData\Local\WarThunder deleted successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-626473118-3010605479-898090307-1001\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater14.2.0 deleted successfully ==== Batch Command(s) Run By Tool====================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ==== Deleting Files \ Folders ====================== C:\PROGRA~2\AGEIA Technologies not found C:\PROGRA~2\DivX not found C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not found C:\PROGRA~2\Flyordie Plugin deleted C:\windows\SysNative\Tasks\Bidaily Synchronize Task[973b] deleted C:\Windows\tasks\Bidaily Synchronize Task[973b].job deleted C:\PROGRA~3\{7c12c1dc-c294-1c6e-7c12-2c1dcc290773} deleted C:\PROGRA~3\5767796595995162811 deleted C:\PROGRA~3\DivX deleted C:\PROGRA~2\SearchProtect deleted C:\PROGRA~2\File Scout deleted C:\PROGRA~2\COMMON~1\AVG Secure Search deleted C:\prefs.js deleted C:\Users\Cam\AppData\Roaming\RHEng deleted C:\Users\Cam\AppData\Roaming\Systweak deleted C:\Users\Cam\AppData\Roaming\OpenCandy deleted C:\PROGRA~3\AVG Security Toolbar deleted C:\PROGRA~3\IBUpdaterService deleted C:\PROGRA~3\AVG SafeGuard toolbar deleted C:\PROGRA~3\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} deleted C:\PROGRA~3\Package Cache deleted C:\Users\Cam\AppData\Local\SearchProtect deleted C:\Users\Cam\AppData\Local\Unity deleted C:\Users\Cam\AppData\Local\AVG Secure Search deleted C:\Users\Cam\AppData\Local\Systweak deleted C:\Users\Cam\AppData\Local\AVG SafeGuard toolbar deleted C:\Users\Cam\AppData\Local\adawarebp deleted C:\Users\Cam\AppData\Local\AVG Nation toolbar deleted C:\Users\Cam\AppData\Local\CrashRpt deleted C:\Users\Cam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta deleted C:\Windows\SysNative\roboot64.exe deleted C:\Users\Cam\AppData\LocalLow\AVG SafeGuard toolbar deleted C:\Users\Cam\AppData\LocalLow\Unity deleted C:\END deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Windows\Syswow64\SearchProtect deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "avg@toolbar"="C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\14.2.0.1" [] ==== Chromium Look ====================== Google Chrome Version: 46.0.2490.86 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions lfffjahnfbocnaooecgijfnbpcfekoik - C:\ProgramData\adawaretb\shortcuts\chrome\adawaretb.crx[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[08/01/2016 10:47] ndibdjnfmopecpmkdieinmbadjfpblof - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\14.2.0.1\avg.crx[] Ask Toolbar - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko Comodo Drag&Drop Service - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aneodkojaglhnkkdbbdnmmmgimlcaogo Comodo Web Inspector - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn PrivDog - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja Comodo Media Downloader - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\dihmnpngfonlhjmgkflpnibiaaliendo Absolute Radio Live Scores - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kgmkadilkeimcolingoooifhoknpkifi AVG SafeGuard toolbar - Cam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof ==== Chromium Startpages ====================== C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Preferences "homepage": "[URL="http://websearch.searchtotal.info/?pid=24388&r=2015/06/01&hid=5087950222676336109&lg=EN&cc=AU&unqvl=88"]Search[/URL]", ==== Chromium Fix ====================== C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_admtpmp123.adk2x.com_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_admtpmp123.adk2x.com_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.donation-tools.org_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.donation-tools.org_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[URL="http://www.tunefind.com_0.localstorage"]www.tunefind.com_0.localstorage[/URL] deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[URL="http://www.tunefind.com_0.localstorage-journal"]www.tunefind.com_0.localstorage-journal[/URL] deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_career-services.careerone.com.au_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_career-services.careerone.com.au_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_roysautoservices.com_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_roysautoservices.com_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko deleted successfully C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage deleted successfully C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage-journal deleted successfully C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kgmkadilkeimcolingoooifhoknpkifi deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="[URL="http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130986366714421902&GUID=BF406046-4567-454B-8EA1-7975E2173FAC"]MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos[/URL]" "Search Page"="[URL]http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}[/URL]" "Default_Page_URL"="[URL="http://www.google.com/"]Google[/URL]" "Default_Search_URL"="[URL]http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}[/URL]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="[URL]http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}[/URL]" "Default_Page_URL"="[URL="http://www.google.com/"]Google[/URL]" "Search Page"="[URL]http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}[/URL]" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="[URL]http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}[/URL]" "Default_Page_URL"="[URL="http://www.google.com/"]Google[/URL]" "Search Page"="[URL]http://isearch.omiga-plus.com/web/?type=dspp&ts=1420951040&from=cor&uid=HitachiXHDS721010DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}[/URL]" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="res://ieframe.dll/tabswelcome.htm" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs] "Tabs"="res://ieframe.dll/tabswelcome.htm" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="[URL="http://go.microsoft.com/fwlink/?LinkId=54896"]Bing[/URL]" "Default_Search_URL"="[URL="http://go.microsoft.com/fwlink/?LinkId=54896"]Bing[/URL]" "Default_Page_URL"="[URL="http://go.microsoft.com/fwlink/?LinkId=69157"]MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos[/URL]" "Start Page"="[URL="http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130986366714421902&GUID=BF406046-4567-454B-8EA1-7975E2173FAC"]MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos[/URL]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="[URL="http://go.microsoft.com/fwlink/?LinkId=54896"]Bing[/URL]" "Search Page"="[URL="http://go.microsoft.com/fwlink/?LinkId=54896"]Bing[/URL]" "Default_Page_URL"="[URL="http://go.microsoft.com/fwlink/?LinkId=69157"]MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos[/URL]" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="[URL="http://go.microsoft.com/fwlink/?LinkId=54896"]Bing[/URL]" "Search Page"="[URL="http://go.microsoft.com/fwlink/?LinkId=54896"]Bing[/URL]" "Default_Page_URL"="[URL="http://go.microsoft.com/fwlink/?LinkId=69157"]MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos[/URL]" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="about:newtab" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs] "Tabs"="about:newtab" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - [URL="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC"]{searchTerms} - Bing[/URL] HKLM\Wow6432Node\SearchScopes "DefaultScope"="{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - [URL="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC"]{searchTerms} - Bing[/URL] HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - [URL="http://www.google.com/search?q={searchTerms}"]{searchTerms} - Google Search[/URL] HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - [URL="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR"]{searchTerms} - Bing[/URL] ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lfffjahnfbocnaooecgijfnbpcfekoik deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06B99631-BFA2-3B7A-F58B-D067C2BA59B7} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\omiga-plus uninstall deleted successfully ==== Empty IE Cache ====================== [/QUOTE]
Insert quotes…
Verification
Post reply
Top