Easy Life, ib.adnxs.com


New member

It started with the ib.adnxs.com adware, and now I have Easylife. I have generally been seeing out of place/more frequent advertisements while browsing.


ok: look in your add/remove programs panel and uninstall the following one by one if present: After all are uninstalled reboot your machine.

EasyLife Search 1.74
Privitize VPN

We will get two downloads to use: Adwcleaner and Malwarebytes.

Please download Adwcleaner by Xplode to your desktop.
Right click on AdwCleaner.exe, select "run as admin"
Click on Search button
A logfile will automatically open after the scan has finished
Copy and paste the contents in your next reply.
You can also find the logfile in your root drive C:\AdwCleaner[R1].txt


Please download the free version of Malwarebytes to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.

Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded, select Perform FULL SCAN, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.

Be sure that everything is checked, and click *Remove Selected.*

*A restart of your computer may be required to remove some items. If prompted please restart your computer to complete the fix.*

When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Post the log in your reply.
Hi shelf life,

I uninstalled all of the programs you instructed me to except for Privitize VPN, which wasn't there. I also ran Adwcleaner and Malwarebytes as instructed. However, after restarting my computer as part of the removal of objects in Malwarebytes, I still have easylife as the default page for a new tab in Firefox.

Here are my log files:


# AdwCleaner v2.301 - Logfile created 05/26/2013 at 23:23:34
# Updated 16/05/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Frank - FRANK-PC
# Boot Mode : Normal
# Running from : C:\Users\Frank\Desktop\AdwCleaner.exe
# Option [Search]

***** [Services] *****

***** [Files / Folders] *****

File Found : C:\Program Files (x86)\Uninstall.exe
File Found : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ypokwgqk.default\searchplugins\EasyLife.xml
Folder Found : C:\Program Files (x86)\EasyLife
Folder Found : C:\Program Files (x86)\MagniPic
Folder Found : C:\ProgramData\clsoft ltd
Folder Found : C:\ProgramData\InstallMate
Folder Found : C:\ProgramData\MagnniPyic
Folder Found : C:\ProgramData\Partner
Folder Found : C:\ProgramData\SearchNewTab
Folder Found : C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\lefcababcdpfgghfpacinhlgkdmalmoe
Folder Found : C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkaofgnnopkaaanbinpcbgcbngkjgog
Folder Found : C:\Users\Frank\AppData\LocalLow\MagnniPyic
Folder Found : C:\Users\Frank\AppData\LocalLow\SearchNewTab
Folder Found : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ypokwgqk.default\extensions\h2pfay7d1@ieu-oqtqpa.net
Folder Found : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ypokwgqk.default\extensions\vxjvfaaioquo@nvxh-jt.com

***** [Registry] *****

Key Found : HKCU\Software\AppDataLow\SProtector
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02EA14EF-1CFF-EE65-B998-72960446F6C0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EDDC773B-DD09-D7DB-EB3E-098E0519D5FC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02EA14EF-1CFF-EE65-B998-72960446F6C0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EDDC773B-DD09-D7DB-EB3E-098E0519D5FC}
Key Found : HKCU\Software\PrivitizeVPNInstallDates
Key Found : HKCU\Software\StartSearch
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{01BD49D7-C76B-4310-8BEB-14D7E5F322C6}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\Software\SP Global
Key Found : HKLM\Software\SProtector
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{01BD49D7-C76B-4310-8BEB-14D7E5F322C6}
Key Found : HKU\S-1-5-21-2903208021-1474375682-2186726498-1001\Software\Microsoft\Internet Explorer\SearchScopes\{01BD49D7-C76B-4310-8BEB-14D7E5F322C6}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.easylifeapp.com/?pid=388&src=ie1&r=2013/05/19&hid=2732658822&lg=EN&cc=US
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.easylifeapp.com/?pid=388&src=ie1&r=2013/05/19&hid=2732658822&lg=EN&cc=US

-\\ Mozilla Firefox v21.0 (en-US)

File : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ypokwgqk.default\prefs.js

Found : user_pref("aol_toolbar.default.homepage.check", false);
Found : user_pref("aol_toolbar.default.search.check", false);
Found : user_pref("browser.search.defaultenginename", "EasyLife");
Found : user_pref("browser.search.defaultenginename,S", "EasyLife");
Found : user_pref("browser.search.defaulturl", "hxxp://search.easylifeapp.com/?pid=388&src=ff2&r=2013/05/19&[...]
Found : user_pref("browser.search.order.1", "EasyLife");
Found : user_pref("browser.search.order.1,S", "EasyLife");
Found : user_pref("browser.search.selectedEngine,S", "EasyLife");
Found : user_pref("browser.startup.homepage", "hxxp://search.easylifeapp.com/?pid=388&src=ff1&r=2013/05/19&h[...]
Found : user_pref("extensions.517edfa47fe51.scode", "(function(){try{if('aol.com,mail.google.com,premiumrepo[...]
Found : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Found : user_pref("extensions.privitize.srchPrvdr", "Search The Web (privitize)");
Found : user_pref("keyword.URL", "hxxp://search.easylifeapp.com/?pid=388&src=ff2&r=2013/05/19&hid=2732658822[...]
Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "EasyLife");
Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "EasyLife");
Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://search.easylifeapp.com/?pid=3[...]
Found : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://search.easylifeapp.com/?pid=388&src=ff2&r=[...]
Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
Found : user_pref("sweetim.toolbar.searchguard.enable", "");

-\\ Google Chrome v27.0.1453.94

File : C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.


AdwCleaner[R1].txt - [5093 octets] - [26/05/2013 23:23:34]

########## EOF - C:\AdwCleaner[R1].txt - [5153 octets] ##########


Malwarebytes Anti-Malware

Database version: v2013.05.27.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Frank :: FRANK-PC [administrator]

5/26/2013 11:29:19 PM
mbam-log-2013-05-26 (23-29-19).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 485538
Time elapsed: 26 minute(s), 46 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 5
C:\ProgramData\MagnniPyic\517edfa47ff57.dll (PUP.Adware.MultiPlug) -> Quarantined and deleted successfully.
C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E7437Z3E\517edfa499bf6[1].exe (PUP.Adware.MultiPlug) -> Quarantined and deleted successfully.
C:\Users\Frank\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E7437Z3E\51984e96ac915[1].exe (PUP.Adware.MultiPlug) -> Quarantined and deleted successfully.
C:\Users\Frank\AppData\Local\Temp\k9VXzsgD.exe.part (PUP.FakeFlash.Domaiq) -> Quarantined and deleted successfully.
C:\Users\Frank\AppData\Local\Temp\NGexDp1w.exe.part (PUP.FakeFlash.Domaiq) -> Quarantined and deleted successfully.

ok. One more step. Run Adwcleaner once more by clicking the search button. After the log appears you can just close it then click the delete button. Adwcleaner will then reboot your machine to delete the items. After restart a new log will be displayed which you can post in your reply.
easylife seems to be gone now. Could this be it?

Adwcleaner log:

# AdwCleaner v2.301 - Logfile created 05/27/2013 at 12:26:03
# Updated 16/05/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Frank - FRANK-PC
# Boot Mode : Normal
# Running from : C:\Users\Frank\Desktop\AdwCleaner.exe
# Option [Delete]

***** [Services] *****

***** [Files / Folders] *****

File Deleted : C:\Program Files (x86)\Uninstall.exe
File Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ypokwgqk.default\searchplugins\EasyLife.xml
Folder Deleted : C:\Program Files (x86)\EasyLife
Folder Deleted : C:\Program Files (x86)\MagniPic
Folder Deleted : C:\ProgramData\clsoft ltd
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\MagnniPyic
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\ProgramData\SearchNewTab
Folder Deleted : C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\lefcababcdpfgghfpacinhlgkdmalmoe
Folder Deleted : C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkaofgnnopkaaanbinpcbgcbngkjgog
Folder Deleted : C:\Users\Frank\AppData\LocalLow\MagnniPyic
Folder Deleted : C:\Users\Frank\AppData\LocalLow\SearchNewTab
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ypokwgqk.default\extensions\h2pfay7d1@ieu-oqtqpa.net
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ypokwgqk.default\extensions\vxjvfaaioquo@nvxh-jt.com

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\SProtector
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02EA14EF-1CFF-EE65-B998-72960446F6C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EDDC773B-DD09-D7DB-EB3E-098E0519D5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02EA14EF-1CFF-EE65-B998-72960446F6C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EDDC773B-DD09-D7DB-EB3E-098E0519D5FC}
Key Deleted : HKCU\Software\PrivitizeVPNInstallDates
Key Deleted : HKCU\Software\StartSearch
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{01BD49D7-C76B-4310-8BEB-14D7E5F322C6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\Software\SP Global
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{01BD49D7-C76B-4310-8BEB-14D7E5F322C6}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.easylifeapp.com/?pid=388&src=ie1&r=2013/05/19&hid=2732658822&lg=EN&cc=US --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.easylifeapp.com/?pid=388&src=ie1&r=2013/05/19&hid=2732658822&lg=EN&cc=US --> hxxp://www.google.com

-\\ Mozilla Firefox v21.0 (en-US)

File : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ypokwgqk.default\prefs.js

C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ypokwgqk.default\user.js ... Deleted !

Deleted : user_pref("aol_toolbar.default.homepage.check", false);
Deleted : user_pref("aol_toolbar.default.search.check", false);
Deleted : user_pref("browser.search.defaultenginename", "EasyLife");
Deleted : user_pref("browser.search.defaultenginename,S", "EasyLife");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.easylifeapp.com/?pid=388&src=ff2&r=2013/05/19&[...]
Deleted : user_pref("browser.search.order.1", "EasyLife");
Deleted : user_pref("browser.search.order.1,S", "EasyLife");
Deleted : user_pref("browser.search.selectedEngine,S", "EasyLife");
Deleted : user_pref("browser.startup.homepage", "hxxp://search.easylifeapp.com/?pid=388&src=ff1&r=2013/05/19&h[...]
Deleted : user_pref("extensions.517edfa47fe51.scode", "(function(){try{if('aol.com,mail.google.com,premiumrepo[...]
Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Deleted : user_pref("extensions.privitize.srchPrvdr", "Search The Web (privitize)");
Deleted : user_pref("keyword.URL", "hxxp://search.easylifeapp.com/?pid=388&src=ff2&r=2013/05/19&hid=2732658822[...]
Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "EasyLife");
Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "EasyLife");
Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://search.easylifeapp.com/?pid=3[...]
Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://search.easylifeapp.com/?pid=388&src=ff2&r=[...]
Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
Deleted : user_pref("sweetim.toolbar.searchguard.enable", "");

-\\ Google Chrome v27.0.1453.94

File : C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.


AdwCleaner[R1].txt - [5220 octets] - [26/05/2013 23:23:34]
AdwCleaner[R2].txt - [5280 octets] - [27/05/2013 12:25:34]
AdwCleaner[S1].txt - [5330 octets] - [27/05/2013 12:26:03]

########## EOF - C:\AdwCleaner[S1].txt - [5390 octets] ##########
That should take care of it. Using explorer take a look in C:\ProgramData and delete the entire Premium folder if found.

ok Good. You can delete the Adwcleaner icon from your desktop as well as its logs. Keep Malwarebytes and note that in the free version both updates and a scan must be done manually. Always check for updates before a scan.

So if all is good now on your end, some tips to help you avoid malware:

No software can think for you. Help yourself. In no special order:

1) It is essential to keep your operating system (Windows) browser (IE, FireFox, Chrome, Opera) and other software up to date to "patch" vulnerabilities that could be exploited. Visit Windows Update frequently or use the Windows auto-update feature. Staying updated is also essential for other web based applications like Java, Adobe Flash/Reader, iTunes etc. More and more third party applications are being targeted. Use the auto-update features available in most software. Not sure if you are using the latest version of software? Check their version status and get the updates here.

2) Know what you are installing to your computer. Alot of software can come bundled with unwanted add-ons, like adware, toolbars and malware. More and more legitimate software are installing useless toolbars if not unchecked first. Do not install any files from ads, popups or random links. Do not fall for fake warnings about virus and trojans being found on your computer and you are then prompted to install software to remedy this.

3) Install and keep updated: one antivirus and two or three anti-malware applications. If not updated they will soon be worthless. If either of these frequently find malware then its time to *review your computer habits*.

4) Refrain from clicking on links or attachments via E-Mail, IM, IRC, Chat Rooms, Blogs or Social Networking Sites, no matter how tempting or legitimate the message may seem. See also E-mail phishing tricks.

5) Do not click on ads/pop ups or offers from websites requesting that you need to install software to your computer--*for any reason*. Use the Alt+F4 keys to close the window.

6) Don't click on offers to "scan" your computer. Install ActiveX Objects with care. Do you trust the website to install components?

7) Consider the use of limited (non-privileged) accounts for everyday use, rather than administrator accounts. Limited accounts can help prevent *malware from installing and lessen its potential impact.* This is exactly what user account control (UAC) in Windows Vista, Windows 7 and Windows 8 attempts to address.

8) Install and understand the *limitations* of a software firewall.

9) Your browser risks: The why and how to secure your browser for safer surfing. For added protection disable Java in your browser.

10) Warez, cracks, keygens etc are very popular for carrying malware payloads. If you look for these you will encounter malware. If you download/install files via p2p networks you will encounter malware. Do you really trust the source of the file?
More info/tips with pictures, link below.

Happy Safe Surfing.
