Jump to content

Recommended Posts

Posted

I ran a scan on the free malware bytes anti malware on my W7 PC and it shows one item detected:

 

(Vendor) PUP. Optional.C ...

(Category) File

(Item) C:\Users\PC\App

 

There is also a small green icon or bug like thing.

 

I attempted to remove this item but it wont budge. Am i doing the correct thing in trying to remove it?

  • Replies 8
  • Created
  • Last Reply

Top Posters In This Topic

Top Posters In This Topic

Posted

I noticed another, earlier, thread ref PUP's, and followed the advice to download what i thought was Adw Cleaner from CCNET (?).

 

However, i now have a thing called Reg Clean Pro ( although i clicked the download Ad Cleaner button) on my desktop and i dont know how to get rid of it.

 

AAMOI: the Reg Cleaner Pro claims to have detected over 200 errors.

Posted
followed the advice to download what i thought was Adw Cleaner from CCNET

Never trust these sites.... they can mess up anything.

Always get programs and tools from either the actual vendor or a site like BC.

 

the Reg Cleaner Pro claims to have detected over 200 errors.

It probably will...... just ignore anything it says.

 

There is also a small green icon or bug like thing.

I attempted to remove this item but it wont budge.

Assuming that it is AdwCleaner........... (sounds like it)

 

Double click on AdwCleaner.exe to run the tool.

  • Click on the Uninstall button.
  • Click Yes when asked are you sure you want to uninstall.
  • Both AdwCleaner.exe, its folder and all logs will be removed.

 

Now use this to get a proper copy and run a scan to remove whatever has been added to your system.

 

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer.
  • After the scan has finished...
  • Click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

Member of:

UNITE

Posted

Thanks for replying.

 

I attempted to download AdwCleaner from your prompt above and i immediately run into confusion. Of the two suggestions "Download Now" & "Download Here" neither will go to my desktop.

I have bottom left of this page AdwCleaner(4).exe

When i click it, it takes me to a series of prompts that seem to go nowhere?

Posted

Hi Tom,

 

neither will go to my desktop.

What browser are you using?

By default most browsers will download to the Download Folder..... to change this:

If Firefox:

Click on the Tools tab >> Options >>

Look under the General Tab for the Downloads section and make sure that Desktop is selected in the Save Files To section.

If not, you can select Desktop by using the browse button at the side... then click OK.

 

If IE:

Click on the gear icon in the upper right corner, then click on View downloads.

Click on the Options link (bottom left hand corner)

Click the Browse button and select Desktop

Click on the Select Folder button.

Click OK

 

Then proceed with the download and it should go to the Desktop..

 

I attempted to download AdwCleaner from your prompt above and i immediately run into confusion. Of the two suggestions "Download Now" & "Download Here"

The link in my post is for a direct download.

If you click on the link for AdwCleaner and then wait a couple of seconds you should get this come up if using Firefox:

 

http://img.photobucket.com/albums/v708/starbuck50/adw_zps562b46b4.png

 

All you do then is click on 'Save File'

 

If you are using Internet Explorer, you should see this:

 

http://img.photobucket.com/albums/v708/starbuck50/ie_zps4c623954.png

 

Just click on Save

Member of:

UNITE

Posted

Thank you once again,

 

I successfully opened adw this time and below isthe result:

 

 

 

 

 

# Updated 22/09/2013 by Xplode

# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

# Username : PC - PC-PC

# Running from : C:\Users\PC\Downloads\AdwCleaner (5).exe

# Option : Clean

 

 

***** [ Services ] *****

 

 

 

 

***** [ Files / Folders ] *****

 

 

Folder Deleted : C:\Program Files (x86)\Conduit

Folder Deleted : C:\Program Files (x86)\WiseConvert_2.1

Folder Deleted : C:\Users\PC\AppData\Local\Conduit

Folder Deleted : C:\Users\PC\AppData\LocalLow\Conduit

Folder Deleted : C:\Users\PC\AppData\LocalLow\PriceGong

Folder Deleted : C:\Users\PC\AppData\LocalLow\WiseConvert_2.1

Folder Deleted : C:\Users\PC\AppData\Roaming\Systweak

File Deleted : C:\Windows\System32\roboot64.exe

 

 

***** [ Shortcuts ] *****

 

 

 

 

***** [ Registry ] *****

 

 

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS

Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3208938

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ECCE0073-A837-45A2-95B9-600420505F7E}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E50B7E38-622C-4B2D-9C27-8EA71952741A}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ECCE0073-A837-45A2-95B9-600420505F7E}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ECCE0073-A837-45A2-95B9-600420505F7E}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ECCE0073-A837-45A2-95B9-600420505F7E}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E50B7E38-622C-4B2D-9C27-8EA71952741A}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C955CA05-874E-4639-A32B-09A94C580BB9}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39BD12DC-D854-450F-930C-B116EC353210}

Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{ECCE0073-A837-45A2-95B9-600420505F7E}]

Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{ECCE0073-A837-45A2-95B9-600420505F7E}]

Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{ECCE0073-A837-45A2-95B9-600420505F7E}]

Key Deleted : HKCU\Software\distromatic

Key Deleted : HKCU\Software\WiseConvert_2.1

Key Deleted : HKCU\Software\AppDataLow\Toolbar

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit

Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes

Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong

Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar

Key Deleted : HKCU\Software\AppDataLow\Software\WiseConvert_2.1

Key Deleted : HKLM\Software\Conduit

Key Deleted : HKLM\Software\systweak

Key Deleted : HKLM\Software\WiseConvert_2.1

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WiseConvert_2.1 Toolbar

 

 

***** [ Browsers ] *****

 

 

-\\ Internet Explorer v10.0.9200.16686

 

 

 

 

-\\ Google Chrome v

 

 

[ File : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]

 

 

 

 

*************************

 

 

AdwCleaner[R0].txt - [3594 octets] - [25/09/2013 12:51:39]

AdwCleaner[s0].txt - [3511 octets] - [25/09/2013 12:52:13]

 

 

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [3571 octets] ##########

Posted

Hi Tom,

 

Seems there was some Adware to get rid of.

Normally we run 2 Adware removing programs, they search and find things in a slightly different way.

We should now run the second tool and then check for any orphan entries and other leftovers.

 

Step 1

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

 

Step 2

  • Download OTL to your desktop.
    right click on the link and select 'Save Link/Target As'.
     
    if you have problems, try this download link:
    OTL
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check

.

 

.

http://img.photobucket.com/albums/v708/starbuck50/new/Otllatest.png

 

Now copy the lines in bold below.

 

netsvcs

msconfig

%SYSTEMDRIVE%\*.*

%systemroot%\system32\Spool\prtprocs\w32x86\*.dll

%systemroot%\*. /mp /s

%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles

%systemroot%\system32\drivers\*.sys /lockedfiles

%systemroot%\system32\*.exe /lockedfiles

%systemroot%\System32\config\*.sav

%PROGRAMFILES%\*

%USERPROFILE%\..|smtmp;true;true;true /FP

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU

hklm\software\clients\startmenuinternet|command /rs

hklm\software\clients\startmenuinternet|command /64 /rs

CREATERESTOREPOINT

 

  • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.
     
    http://img.photobucket.com/albums/v708/starbuck50/new%20forum/scan-fix.png
    .
  • Click the Run Scan button.
     
    http://img.photobucket.com/albums/v708/starbuck50/runscan.png
     
  • Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply.

 

 

 

In your next reply, please submit:

JRT.txt

and both reports from OTL

 

 

Thanks.

Member of:

UNITE

  • 2 weeks later...
Posted
Thank you for the info so far. Unfortunately, i'm ill and, at the moment, cant get around to doing what you suggest. Later, i will try. thank you once again.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...