My Malwarebytes identified a problem withWin32:InstallMate-AD [PUP] virus (Removal Guide). I followed your sites removal steps but still the prefs.js seems to be a problem (no symptoms though).
Again? I did that this morning and sent you a before and after Adwcleaner log....Please download AdwCleaner by Xplode and save to your Desktop.
Double click on AdwCleaner.exe to run the tool.
- Click on the Scan button.
- After the scan has finished click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
- After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
- Post logfile will also be saved in the C:\AdwCleaner folder.
createsrpoint;
emptyfolderscheck;delete
autoclean;
emptyclsid;
emptyalltemp;
ipconfig /flushdns;b
Ok, then no need for adwcleaner.
Please download zoek.zip or zoek.rar by smeenk () from here or here and save it to your Desktop.
Unpack the archive...
- Close any open browsers
- Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.
- Double click on zoek.exe to run the tool .
Please wait while the tool does not start...
- Copy the text present inside the code box below and paste it into the large window in the zoek tool:
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Code:createsrpoint; emptyfolderscheck;delete autoclean; emptyclsid; emptyalltemp; ipconfig /flushdns;b
- Click on
button.
Please wait until a logreport will open (this can be after reboot)
- Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named "zoek-results.log"
I'm still a bit worried --PC should be clean now, what do you think?
PC should be clean now, what do you think?
I don't see anything odd (I never did have any symptoms). All my plugins and add-ons look normal and there are no extra ones. No services. I'd noticed a site listed that I didn't recognize for "The following websites are allowed to store data for offline use" and I deleted that and it stayed deleted. I run noscript, flashblock, Adblock and WOT and have Shockwave Flash set to Ask to Activate.How is the situation inside Firefox?
Thanks. I do t use chrome but I'm using adblock plus in firefox. I'll take a look at unchecky.For future protection I can recommend you:
- Adblock --> https://adblockplus.org/en/chrome
- Unchecky --> http://unchecky.com/
• The following will implement some post-cleanup procedures:
=> Please download DelFix by Xplode to your Desktop.
Run the tool and check the following boxes below;
Remove disinfection tools
Create registry backup
Purge System Restore
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.