Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
I can't delete Adware, it keeps coming back!
Message
<blockquote data-quote="Nojuzz" data-source="post: 628170" data-attributes="member: 61834"><p># AdwCleaner v6.046 - Logfile created 03/05/2017 at 21:16:07</p><p># Updated on 24/04/2017 by Malwarebytes</p><p># Database : 2017-05-03.1 [Local]</p><p># Operating System : Windows 10 Home (X64)</p><p># Username : Vartotojas - ASUS</p><p># Running from : C:\Users\Vartotojas\Downloads\adwcleaner_6.046.exe</p><p># Mode: Scan</p><p># Support : <a href="https://www.malwarebytes.com/support" target="_blank">Customer Support & Help Center</a></p><p></p><p></p><p></p><p>***** [ Services ] *****</p><p></p><p>No malicious services found.</p><p></p><p></p><p>***** [ Folders ] *****</p><p></p><p>No malicious folders found.</p><p></p><p></p><p>***** [ Files ] *****</p><p></p><p>No malicious files found.</p><p></p><p></p><p>***** [ DLL ] *****</p><p></p><p>No malicious DLLs found.</p><p></p><p></p><p>***** [ WMI ] *****</p><p></p><p>No malicious keys found.</p><p></p><p></p><p>***** [ Shortcuts ] *****</p><p></p><p>No infected shortcut found.</p><p></p><p></p><p>***** [ Scheduled Tasks ] *****</p><p></p><p>No malicious task found.</p><p></p><p></p><p>***** [ Registry ] *****</p><p></p><p>Key Found: HKLM\SOFTWARE\ScreenShot</p><p>Key Found: [x64] HKLM\SOFTWARE\InterSect Alliance</p><p>Value Found: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]</p><p></p><p></p><p>***** [ Web browsers ] *****</p><p></p><p>No malicious Firefox based browser items found.</p><p>Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Web data] - 9initialpage123</p><p>Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Web data] - 36initialpage123</p><p>Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Web data] - 23initialpage123</p><p>Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Web data] - 91initialpage123</p><p>Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - hxxp://<a href="http://www.initialpage123.com/?z=d66f96f2e895f8ef60ea96dg5z8t8ccg9ceqdz0e3b&from=amz&uid=WDCXWD5000LPVX-80V0TT0_" target="_blank">www.initialpage123.com/?z=d66f96f2e895f8ef60ea96dg5z8t8ccg9ceqdz0e3b&from=amz&uid=WDCXWD5000LPVX-80V0TT0_</a></p><p>Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - hxxp://<a href="http://www.initialpage123.com/?z=d66f96f2e895f8ef60ea96dg5z8t8ccg9ceqdz0e3b&from=amz&uid=WDCXWD5000LPVX-80V0TT0" target="_blank">www.initialpage123.com/?z=d66f96f2e895f8ef60ea96dg5z8t8ccg9ceqdz0e3b&from=amz&uid=WDCXWD5000LPVX-80V0TT0</a></p><p></p><p></p><p></p><p></p><p>*************************</p><p></p><p>C:\AdwCleaner\AdwCleaner[C0].txt - [3565 Bytes] - [03/05/2017 20:14:57]</p><p>C:\AdwCleaner\AdwCleaner[S0].txt - [3328 Bytes] - [03/05/2017 20:13:17]</p><p>C:\AdwCleaner\AdwCleaner[S1].txt - [2139 Bytes] - [03/05/2017 21:16:07]</p><p></p><p>########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2212 Bytes] ##########</p><p></p><p></p><p></p><p></p><p># AdwCleaner v6.046 - Logfile created 11/05/2017 at 20:46:54</p><p># Updated on 24/04/2017 by Malwarebytes</p><p># Database : 2017-05-10.1 [Server]</p><p># Operating System : Windows 10 Home (X64)</p><p># Username : Vartotojas - ASUS</p><p># Running from : C:\Users\Vartotojas\Desktop\adwcleaner_6.046.exe</p><p># Mode: Scan</p><p># Support : <a href="https://www.malwarebytes.com/support" target="_blank">Customer Support & Help Center</a></p><p></p><p></p><p></p><p>***** [ Services ] *****</p><p></p><p>Service Found: WinSAPSvc</p><p>Service Found: VNASRE</p><p></p><p></p><p>***** [ Folders ] *****</p><p></p><p>Folder Found: C:\Users\Vartotojas\AppData\Local\VNASRE</p><p>Folder Found: C:\Users\Vartotojas\AppData\Roaming\WinSAPSvc</p><p>Folder Found: C:\ProgramData\BIT</p><p></p><p></p><p>***** [ Files ] *****</p><p></p><p>No malicious files found.</p><p></p><p></p><p>***** [ DLL ] *****</p><p></p><p>No malicious DLLs found.</p><p></p><p></p><p>***** [ WMI ] *****</p><p></p><p>No malicious keys found.</p><p></p><p></p><p>***** [ Shortcuts ] *****</p><p></p><p>No infected shortcut found.</p><p></p><p></p><p>***** [ Scheduled Tasks ] *****</p><p></p><p>Task Found: Milimili</p><p></p><p></p><p>***** [ Registry ] *****</p><p></p><p>Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SNAREA</p><p>Key Found: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SNAREA</p><p>Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\VNASRE</p><p>Key Found: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\VNASRE</p><p>Key Found: HKLM\SOFTWARE\ScreenShot</p><p>Key Found: [x64] HKLM\SOFTWARE\InterSect Alliance</p><p>Value Found: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]</p><p>Value Found: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [BIT]</p><p></p><p></p><p></p><p>I've pasted some files from adwcleaner scans with results, I hope it helps a bit</p></blockquote><p></p>
[QUOTE="Nojuzz, post: 628170, member: 61834"] # AdwCleaner v6.046 - Logfile created 03/05/2017 at 21:16:07 # Updated on 24/04/2017 by Malwarebytes # Database : 2017-05-03.1 [Local] # Operating System : Windows 10 Home (X64) # Username : Vartotojas - ASUS # Running from : C:\Users\Vartotojas\Downloads\adwcleaner_6.046.exe # Mode: Scan # Support : [URL="https://www.malwarebytes.com/support"]Customer Support & Help Center[/URL] ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious keys found. ***** [ Shortcuts ] ***** No infected shortcut found. ***** [ Scheduled Tasks ] ***** No malicious task found. ***** [ Registry ] ***** Key Found: HKLM\SOFTWARE\ScreenShot Key Found: [x64] HKLM\SOFTWARE\InterSect Alliance Value Found: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc] ***** [ Web browsers ] ***** No malicious Firefox based browser items found. Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Web data] - 9initialpage123 Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Web data] - 36initialpage123 Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Web data] - 23initialpage123 Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Web data] - 91initialpage123 Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - hxxp://[URL="http://www.initialpage123.com/?z=d66f96f2e895f8ef60ea96dg5z8t8ccg9ceqdz0e3b&from=amz&uid=WDCXWD5000LPVX-80V0TT0_"]www.initialpage123.com/?z=d66f96f2e895f8ef60ea96dg5z8t8ccg9ceqdz0e3b&from=amz&uid=WDCXWD5000LPVX-80V0TT0_[/URL] Chrome pref Found: [C:\Users\Vartotojas\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - hxxp://[URL="http://www.initialpage123.com/?z=d66f96f2e895f8ef60ea96dg5z8t8ccg9ceqdz0e3b&from=amz&uid=WDCXWD5000LPVX-80V0TT0"]www.initialpage123.com/?z=d66f96f2e895f8ef60ea96dg5z8t8ccg9ceqdz0e3b&from=amz&uid=WDCXWD5000LPVX-80V0TT0[/URL] ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [3565 Bytes] - [03/05/2017 20:14:57] C:\AdwCleaner\AdwCleaner[S0].txt - [3328 Bytes] - [03/05/2017 20:13:17] C:\AdwCleaner\AdwCleaner[S1].txt - [2139 Bytes] - [03/05/2017 21:16:07] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2212 Bytes] ########## # AdwCleaner v6.046 - Logfile created 11/05/2017 at 20:46:54 # Updated on 24/04/2017 by Malwarebytes # Database : 2017-05-10.1 [Server] # Operating System : Windows 10 Home (X64) # Username : Vartotojas - ASUS # Running from : C:\Users\Vartotojas\Desktop\adwcleaner_6.046.exe # Mode: Scan # Support : [URL="https://www.malwarebytes.com/support"]Customer Support & Help Center[/URL] ***** [ Services ] ***** Service Found: WinSAPSvc Service Found: VNASRE ***** [ Folders ] ***** Folder Found: C:\Users\Vartotojas\AppData\Local\VNASRE Folder Found: C:\Users\Vartotojas\AppData\Roaming\WinSAPSvc Folder Found: C:\ProgramData\BIT ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious keys found. ***** [ Shortcuts ] ***** No infected shortcut found. ***** [ Scheduled Tasks ] ***** Task Found: Milimili ***** [ Registry ] ***** Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SNAREA Key Found: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SNAREA Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\VNASRE Key Found: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\VNASRE Key Found: HKLM\SOFTWARE\ScreenShot Key Found: [x64] HKLM\SOFTWARE\InterSect Alliance Value Found: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc] Value Found: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [BIT] I've pasted some files from adwcleaner scans with results, I hope it helps a bit [/QUOTE]
Insert quotes…
Verification
Post reply
Top