Quantcast
Channel: Security Cleanup forum - dslreports.com
Viewing all articles
Browse latest Browse all 98

Infected, need Clean-up Help Plz.

$
0
0
I work out of town weeks at a time, just got in and the wife and kids have done a number on the desktop. Thanks in advance. MBAM: Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Database version: v2014.04.09.06 Windows 7 Service Pack 1 x64 NTFS (Safe Mode) Internet Explorer 11.0.9600.16521 Jason i4 :: JASONMC-PC [administrator] Protection: Disabled 4/10/2014 10:03:45 AM mbam-log-2014-04-10 (10-03-45).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 374428 Time elapsed: 6 minute(s), 46 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 23 HKLM\SYSTEM\CurrentControlSet\Services\ConvertFilesforFreeUpdt (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. HKCR\CLSID\{59A062A1-5ECA-4a1a-BC44-B2A9283A8ACB} (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. HKCR\TypeLib\{22B58425-A384-436c-A334-BB9255664D10} (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. HKCR\Interface\{951F4658-6461-46AD-AB13-F73E7FCBE6DB} (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. HKCR\ConvertFilesforFree.1 (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. HKCR\ConvertFilesforFree (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59A062A1-5ECA-4A1A-BC44-B2A9283A8ACB} (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. HKCR\CLSID\{83F2328D-0D6A-42B4-B0C4-02A929EDD4BE} (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. HKCR\TypeLib\{EA3802D2-C00A-4478-9319-34075A31C28F} (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. HKCR\Interface\{483F56D2-1D67-44A5-A4C5-67DBB724F7A0} (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83F2328D-0D6A-42B4-B0C4-02A929EDD4BE} (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{83F2328D-0D6A-42B4-B0C4-02A929EDD4BE} (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Convert Files for Free (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Highlightly (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\cmclajginlihohopoeofghddnhpplhom (PUP.Optional.HighLightly.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Quarantined and deleted successfully. HKLM\SOFTWARE\V9Software\v9hp (PUP.Optional.V9.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\ZUpdater\ConvertFilesforFreeUpdt.exe (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\HLNFD (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\HLSVC (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Highlightly (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. Registry Values Detected: 5 HKLM\SOFTWARE\Mozilla\Firefox\Extensions|extension@Convert_Files_for_Free.com (PUP.Optional.FreeFileConverter.A) -> Data: C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com -> Quarantined and deleted successfully. HKLM\SOFTWARE\Mozilla\Firefox\Extensions|quick_start@gmail.com (PUP.Optional.QuickStart.A) -> Data: C:\Users\Jason i4\AppData\Roaming\Mozilla\Firefox\Profiles\bk8egblr.default\extensions\quick_start@gmail.com -> Quarantined and deleted successfully. HKLM\SOFTWARE\Mozilla\Firefox\Extensions|gethighlightly@gethighlightly.com (PUP.Optional.Highlightly.A) -> Data: C:\Program Files (x86)\Mozilla Firefox\extensions\gethighlightly@gethighlightly.com -> Quarantined and deleted successfully. HKLM\SYSTEM\CurrentControlSet\Services\hlnfd|DisplayName (PUP.Optional.Highlightly) -> Data: hlnfd -> Quarantined and deleted successfully. HKLM\SYSTEM\CurrentControlSet\Services\hlsvc|DisplayName (PUP.Optional.Highlightly) -> Data: Highlightly Client Service -> Quarantined and deleted successfully. Registry Data Items Detected: 3 HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (Hijack.StartPage) -> Bad: (http://www.v9.com/?type=hp&ts=1397138451&from=irs&uid=WDCXWD6400AAKS-75A7B2_WD-WMASY764972749727&i=psd&t=340c268c0) Good: (http://www.google.com) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Bad: (http://www.v9.com/?type=hp&ts=1397138451&from=irs&uid=WDCXWD6400AAKS-75A7B2_WD-WMASY764972749727&i=psd&t=340c268c0) Good: (http://www.google.com) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope (PUP.Optional.Qone8) -> Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}) Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}) -> Quarantined and repaired successfully. Folders Detected: 40 C:\Program Files (x86)\Convert Files for Free (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com\content (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com\defaults (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com\defaults\preferences (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0 (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1 (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files\Highlightly (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files\Highlightly\IE (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\3rd Party Licenses (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\Chrome (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\FireFox (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\IE (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\Service (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0 (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\img (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\img\weather (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\js (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\en (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\es (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\es_419 (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr-BE (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr-CA (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr-CH (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr-LU (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\it (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\it-CH (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\pl (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\pt_BR (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\ru (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\ru-MO (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\tr (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\vi (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\zh_CN (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\zh_TW (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. Files Detected: 85 C:\Program Files (x86)\Convert Files for Free\ConvertFilesforFreeUpdt.exe (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\ConvertFilesforFree.dll (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\IE\HighlightlyClientIE.dll (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Temp\4ytergbe.05b.exe (PUP.Optional.SkyTech.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Temp\c3a3k3ql.z3c.exe (PUP.Optional.HighLightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Temp\dsi0xfdp.vcu.exe (PUP.Optional.FastFreeConverter.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Temp\fullpackage_temp1397138432\alilog.dll (PUP.Optional.SkyTech.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Temp\fullpackage_temp1397138432\package1.zip (PUP.Optional.SkyTech.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\install.ico (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\ConvertFilesforFree_x64.dll (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\uninstall.exe (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com\chrome.manifest (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com\install.rdf (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com\content\browserOverlay.js (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com\content\browserOverlay.xul (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Convert Files for Free\extension@Convert_Files_for_Free.com\defaults\preferences\defaults.js (PUP.Optional.FreeFileConverter.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\v9.xml (PUP.Optional.V9.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\Service\hlsvc.exe (PUP.Optional.Highlightly) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\background.html (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\background.js (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\icon-128.png (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\icon-16.png (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\icon-48.png (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\manifest.json (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\options.css (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\options.html (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\options.js (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\vitruvian.bootstrap.js (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_0\vitruvian.plugin-api.js (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\background.html (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\background.js (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\icon-128.png (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\icon-16.png (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\icon-48.png (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\manifest.json (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\options.css (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\options.html (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\options.js (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\vitruvian.bootstrap.js (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmclajginlihohopoeofghddnhpplhom\1.9.0.2_1\vitruvian.plugin-api.js (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files\Highlightly\IE\HighlightlyClientIE.dll (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\terms-of-service.rtf (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\Uninstall.exe (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\3rd Party Licenses\buildcrx-license.txt (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\3rd Party Licenses\Info-ZIP-license.txt (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\3rd Party Licenses\nsJSON-license.txt (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\3rd Party Licenses\SimpleSC-license.txt (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\3rd Party Licenses\UAC-license.txt (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\Chrome\cmclajginlihohopoeofghddnhpplhom.crx (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Highlightly\FireFox\gethighlightly@gethighlightly.com.xpi (PUP.Optional.Highlightly.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\index.html (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\manifest.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\style.css (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\img\default_logo.png (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\img\icon128.png (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\img\icon16.png (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\img\icon48.png (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\img\loading.gif (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\img\search.png (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\img\weather\0.png (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\js\background.js (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\js\ga.js (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\js\jquery-base.js (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\js\jquery.autocomplete.js (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\js\js.js (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\js\xagainit.js (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\en\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\es\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\es_419\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr-BE\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr-CA\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr-CH\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\fr-LU\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\it\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\it-CH\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\pl\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\pt_BR\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\ru\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\ru-MO\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\tr\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\vi\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\zh_CN\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma\3.2.0_0\_locales\zh_TW\messages.json (PUP.Optional.QuickStart.A) -> Quarantined and deleted successfully. (end) AdwCleaner: # AdwCleaner v3.023 - Report created 10/04/2014 at 13:22:31 # Updated 01/04/2014 by Xplode # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits) # Username : Jason i4 - JASONMC-PC # Running from : C:\Users\Jason i4\Desktop\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Program Files (x86)\File Type Helper Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\gethighlightly@gethighlightly.com Folder Deleted : C:\Users\Jason i4\AppData\Roaming\Mozilla\Firefox\Profiles\bk8egblr.default\Extensions\quick_start@gmail.com Folder Deleted : C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc [!] Folder Deleted : C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc File Deleted : C:\END ***** [ Shortcuts ] ***** Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox 4.0 Beta 10.lnk Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Shortcut Disinfected : C:\Users\Jason i4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Shortcut Disinfected : C:\Users\Jason i4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Shortcut Disinfected : C:\Users\Jason i4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Shortcut Disinfected : C:\Users\Jason i4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Shortcut Disinfected : C:\Users\Jason i4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk Shortcut Disinfected : C:\Users\Jason i4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk Shortcut Disinfected : C:\Users\Jason i4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ***** [ Registry ] ***** Key Deleted : HKCU\Software\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_securable_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_securable_RASMANCS Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\SAFARI.EXE\shell\open\command Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKLM\Software\V9Software ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16521 Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] -\\ Mozilla Firefox v28.0 (en-US) [ File : C:\Users\Jason Mc\AppData\Roaming\Mozilla\Firefox\Profiles\gjj40hsg.default\prefs.js ] [ File : C:\Users\Jason i4\AppData\Roaming\Mozilla\Firefox\Profiles\bk8egblr.default\prefs.js ] Line Deleted : user_pref("extensions.fvd_single.surfcanyon.ramp.start_time", "1395779534985"); [ File : C:\Users\Averi\AppData\Roaming\Mozilla\Firefox\Profiles\u8vpcrs6.default\prefs.js ] -\\ Google Chrome v33.0.1750.154 [ File : C:\Users\Jason Mc\AppData\Local\Google\Chrome\User Data\Default\preferences ] [ File : C:\Users\Jason i4\AppData\Local\Google\Chrome\User Data\Default\preferences ] Deleted : homepage Deleted : search_url [ File : C:\Users\Averi\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [8548 octets] - [10/04/2014 13:19:37] AdwCleaner[S0].txt - [5194 octets] - [10/04/2014 13:22:31] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5254 octets] ##########

Viewing all articles
Browse latest Browse all 98

Latest Images

Trending Articles



Latest Images