Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
MoneyPak Removal (No Safe Mode or Internet Connection)
Message
<blockquote data-quote="RJude" data-source="post: 125968" data-attributes="member: 9341"><p>I got two reports, one from before deleting and one for after the reboot. I can't remember which is which, so I will post both. Sorry about that. Other scans are in process.</p><p></p><p># AdwCleaner v2.303 - Logfile created 06/26/2013 at 01:07:46</p><p># Updated 08/06/2013 by Xplode</p><p># Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)</p><p># User : Caitlin - CAITLIN-PC</p><p># Boot Mode : Normal</p><p># Running from : C:\Users\Caitlin\Desktop\AdwCleaner.exe</p><p># Option [Search]</p><p></p><p></p><p>***** [Services] *****</p><p></p><p></p><p>***** [Files / Folders] *****</p><p></p><p>File Found : C:\END</p><p>File Found : C:\Windows\system32\roboot.exe</p><p>Folder Found : C:\Program Files\1ClickDownload</p><p>Folder Found : C:\Program Files\Babylon</p><p>Folder Found : C:\Program Files\Conduit</p><p>Folder Found : C:\Program Files\Free Offers from Freeze.com</p><p>Folder Found : C:\ProgramData\WeCareReminder</p><p>Folder Found : C:\Users\Caitlin\AppData\Local\Conduit</p><p>Folder Found : C:\Users\Caitlin\AppData\LocalLow\Conduit</p><p>Folder Found : C:\Users\Caitlin\AppData\LocalLow\PriceGong</p><p>Folder Found : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}</p><p>Folder Found : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\OneClickDownload@OneClickDownload.com</p><p>Folder Found : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\wecarereminder@bryan</p><p>Folder Found : C:\Users\Caitlin\AppData\Roaming\OpenCandy</p><p></p><p>***** [Registry] *****</p><p></p><p>Key Found : HKCU\Software\1ClickDownload</p><p>Key Found : HKCU\Software\AppDataLow\Software\Conduit</p><p>Key Found : HKCU\Software\AppDataLow\Software\PriceGong</p><p>Key Found : HKCU\Software\AppDataLow\Software\SmartBar</p><p>Key Found : HKCU\Software\Headlight</p><p>Key Found : HKCU\Software\InstallCore</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}</p><p>Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}</p><p>Key Found : HKCU\Software\wecarereminder</p><p>Key Found : HKCU\Software\YahooPartnerToolbar</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL</p><p>Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}</p><p>Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}</p><p>Key Found : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder</p><p>Key Found : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1</p><p>Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}</p><p>Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}</p><p>Key Found : HKLM\SOFTWARE\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3}</p><p>Key Found : HKLM\SOFTWARE\Classes\Prod.cap</p><p>Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3007394</p><p>Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3072253</p><p>Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3228856</p><p>Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE}</p><p>Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}</p><p>Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api</p><p>Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1</p><p>Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers</p><p>Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1</p><p>Key Found : HKLM\Software\Conduit</p><p>Key Found : HKLM\Software\Freeze.com</p><p>Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb</p><p>Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc</p><p>Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco</p><p>Key Found : HKLM\Software\Iminent</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}</p><p>Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966</p><p>Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload</p><p>Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]</p><p></p><p>***** [Internet Browsers] *****</p><p></p><p>-\\ Internet Explorer v9.0.8112.16447</p><p></p><p>[OK] Registry is clean.</p><p></p><p>-\\ Mozilla Firefox v [Unable to get version]</p><p></p><p>File : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\prefs.js</p><p></p><p>Found : user_pref("CT3072253.autoDisableScopes", -1);</p><p></p><p>-\\ Google Chrome v [Unable to get version]</p><p></p><p>File : C:\Users\Caitlin\AppData\Local\Google\Chrome\User Data\Default\Preferences</p><p></p><p>[OK] File is clean.</p><p></p><p>*************************</p><p></p><p>AdwCleaner[R1].txt - [7332 octets] - [26/06/2013 01:07:46]</p><p></p><p>########## EOF - C:\AdwCleaner[R1].txt - [7392 octets] ##########</p><p></p><p></p><p># AdwCleaner v2.303 - Logfile created 06/26/2013 at 01:09:54</p><p># Updated 08/06/2013 by Xplode</p><p># Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)</p><p># User : Caitlin - CAITLIN-PC</p><p># Boot Mode : Normal</p><p># Running from : C:\Users\Caitlin\Desktop\AdwCleaner.exe</p><p># Option [Delete]</p><p></p><p></p><p>***** [Services] *****</p><p></p><p></p><p>***** [Files / Folders] *****</p><p></p><p>File Deleted : C:\END</p><p>File Deleted : C:\Windows\system32\roboot.exe</p><p>Folder Deleted : C:\Program Files\1ClickDownload</p><p>Folder Deleted : C:\Program Files\Babylon</p><p>Folder Deleted : C:\Program Files\Conduit</p><p>Folder Deleted : C:\Program Files\Free Offers from Freeze.com</p><p>Folder Deleted : C:\ProgramData\WeCareReminder</p><p>Folder Deleted : C:\Users\Caitlin\AppData\Local\Conduit</p><p>Folder Deleted : C:\Users\Caitlin\AppData\LocalLow\Conduit</p><p>Folder Deleted : C:\Users\Caitlin\AppData\LocalLow\PriceGong</p><p>Folder Deleted : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}</p><p>Folder Deleted : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\OneClickDownload@OneClickDownload.com</p><p>Folder Deleted : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\wecarereminder@bryan</p><p>Folder Deleted : C:\Users\Caitlin\AppData\Roaming\OpenCandy</p><p></p><p>***** [Registry] *****</p><p></p><p>Key Deleted : HKCU\Software\1ClickDownload</p><p>Key Deleted : HKCU\Software\AppDataLow\Software\Conduit</p><p>Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong</p><p>Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar</p><p>Key Deleted : HKCU\Software\Headlight</p><p>Key Deleted : HKCU\Software\InstallCore</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}</p><p>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}</p><p>Key Deleted : HKCU\Software\wecarereminder</p><p>Key Deleted : HKCU\Software\YahooPartnerToolbar</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL</p><p>Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder</p><p>Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1</p><p>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap</p><p>Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3007394</p><p>Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3072253</p><p>Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3228856</p><p>Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}</p><p>Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api</p><p>Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1</p><p>Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers</p><p>Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1</p><p>Key Deleted : HKLM\Software\Conduit</p><p>Key Deleted : HKLM\Software\Freeze.com</p><p>Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb</p><p>Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc</p><p>Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco</p><p>Key Deleted : HKLM\Software\Iminent</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}</p><p>Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966</p><p>Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload</p><p>Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]</p><p></p><p>***** [Internet Browsers] *****</p><p></p><p>-\\ Internet Explorer v9.0.8112.16447</p><p></p><p>[OK] Registry is clean.</p><p></p><p>-\\ Mozilla Firefox v [Unable to get version]</p><p></p><p>File : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\prefs.js</p><p></p><p>Deleted : user_pref("CT3072253.autoDisableScopes", -1);</p><p></p><p>-\\ Google Chrome v [Unable to get version]</p><p></p><p>File : C:\Users\Caitlin\AppData\Local\Google\Chrome\User Data\Default\Preferences</p><p></p><p>[OK] File is clean.</p><p></p><p>*************************</p><p></p><p>AdwCleaner[R1].txt - [7461 octets] - [26/06/2013 01:07:46]</p><p>AdwCleaner[R2].txt - [7521 octets] - [26/06/2013 01:09:22]</p><p>AdwCleaner[S1].txt - [7618 octets] - [26/06/2013 01:09:54]</p><p></p><p>########## EOF - C:\AdwCleaner[S1].txt - [7678 octets] ##########</p></blockquote><p></p>
[QUOTE="RJude, post: 125968, member: 9341"] I got two reports, one from before deleting and one for after the reboot. I can't remember which is which, so I will post both. Sorry about that. Other scans are in process. # AdwCleaner v2.303 - Logfile created 06/26/2013 at 01:07:46 # Updated 08/06/2013 by Xplode # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # User : Caitlin - CAITLIN-PC # Boot Mode : Normal # Running from : C:\Users\Caitlin\Desktop\AdwCleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** File Found : C:\END File Found : C:\Windows\system32\roboot.exe Folder Found : C:\Program Files\1ClickDownload Folder Found : C:\Program Files\Babylon Folder Found : C:\Program Files\Conduit Folder Found : C:\Program Files\Free Offers from Freeze.com Folder Found : C:\ProgramData\WeCareReminder Folder Found : C:\Users\Caitlin\AppData\Local\Conduit Folder Found : C:\Users\Caitlin\AppData\LocalLow\Conduit Folder Found : C:\Users\Caitlin\AppData\LocalLow\PriceGong Folder Found : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03} Folder Found : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\OneClickDownload@OneClickDownload.com Folder Found : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\wecarereminder@bryan Folder Found : C:\Users\Caitlin\AppData\Roaming\OpenCandy ***** [Registry] ***** Key Found : HKCU\Software\1ClickDownload Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\Headlight Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKCU\Software\wecarereminder Key Found : HKCU\Software\YahooPartnerToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36} Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Found : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Found : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Found : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Found : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder Key Found : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1 Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Found : HKLM\SOFTWARE\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3} Key Found : HKLM\SOFTWARE\Classes\Prod.cap Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3007394 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3072253 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3228856 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Key Found : HKLM\Software\Conduit Key Found : HKLM\Software\Freeze.com Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco Key Found : HKLM\Software\Iminent Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16447 [OK] Registry is clean. -\\ Mozilla Firefox v [Unable to get version] File : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\prefs.js Found : user_pref("CT3072253.autoDisableScopes", -1); -\\ Google Chrome v [Unable to get version] File : C:\Users\Caitlin\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [7332 octets] - [26/06/2013 01:07:46] ########## EOF - C:\AdwCleaner[R1].txt - [7392 octets] ########## # AdwCleaner v2.303 - Logfile created 06/26/2013 at 01:09:54 # Updated 08/06/2013 by Xplode # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # User : Caitlin - CAITLIN-PC # Boot Mode : Normal # Running from : C:\Users\Caitlin\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\END File Deleted : C:\Windows\system32\roboot.exe Folder Deleted : C:\Program Files\1ClickDownload Folder Deleted : C:\Program Files\Babylon Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\Free Offers from Freeze.com Folder Deleted : C:\ProgramData\WeCareReminder Folder Deleted : C:\Users\Caitlin\AppData\Local\Conduit Folder Deleted : C:\Users\Caitlin\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Caitlin\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03} Folder Deleted : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\OneClickDownload@OneClickDownload.com Folder Deleted : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\extensions\wecarereminder@bryan Folder Deleted : C:\Users\Caitlin\AppData\Roaming\OpenCandy ***** [Registry] ***** Key Deleted : HKCU\Software\1ClickDownload Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\Headlight Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKCU\Software\wecarereminder Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3} Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3007394 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3072253 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3228856 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco Key Deleted : HKLM\Software\Iminent Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16447 [OK] Registry is clean. -\\ Mozilla Firefox v [Unable to get version] File : C:\Users\Caitlin\AppData\Roaming\Mozilla\Firefox\Profiles\zh23lfrc.default\prefs.js Deleted : user_pref("CT3072253.autoDisableScopes", -1); -\\ Google Chrome v [Unable to get version] File : C:\Users\Caitlin\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [7461 octets] - [26/06/2013 01:07:46] AdwCleaner[R2].txt - [7521 octets] - [26/06/2013 01:09:22] AdwCleaner[S1].txt - [7618 octets] - [26/06/2013 01:09:54] ########## EOF - C:\AdwCleaner[S1].txt - [7678 octets] ########## [/QUOTE]
Insert quotes…
Verification
Post reply
Top