2014-08-08, 18:07
Inadvertently downloaded wajam with something else, I thought that spybot had got rid of it but noticed on the start screen under Apps I have wajam with lots of search apps for things such as Ikea, Home Depot, Walmart etc. Nothing showing up in Control Panel, and the option to uninstall is not available.

Spybot gives me congratulations with no immediate threats found.
Have backed up registry

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-08-2014
Ran by Mike Chidley (administrator) on MIKE on 08-08-2014 14:08:05
Running from C:\Users\Mike Chidley\Desktop
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal

2014-08-08, 22:33
Hi and welcome

The script below will reboot your computer, please don't be alarmed.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)

FF SearchEngineOrder.1: Secure Search
S2 Wajam Internet Enhancer Service; C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe [X]
C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe [X]
2014-08-05 15:02 - 2014-08-05 15:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam
C:\Users\Mike Chidley\AppData\Local\Temp\0001011407319115mcinst.exe

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

Shut down your protection software now to avoid potential conflicts. Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator". The tool will open and start scanning your system. Please be patient as this can take a while to complete depending on your system's specifications. On completion, a log (JRT.txt) is saved to your desktop and will automatically open. Post the contents of JRT.txt into your next message.

Please post:

2014-08-09, 00:09
Hi Juliette, and thank you for your assistance

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-08-2014
Ran by Mike Chidley at 2014-08-08 20:46:43 Run:1
Running from C:\Users\Mike Chidley\Desktop
Boot Mode: Normal

Content of fixlist:
FF SearchEngineOrder.1: Secure Search
S2 Wajam Internet Enhancer Service; C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe [X]
C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe [X]
2014-08-05 15:02 - 2014-08-05 15:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam
C:\Users\Mike Chidley\AppData\Local\Temp\0001011407319115mcinst.exe

Firefox SearchEngineOrder.1 deleted successfully.
Wajam Internet Enhancer Service => Service deleted successfully.
"C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe [X]" => File/Directory not found.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam => Moved successfully.
C:\ProgramData\uninstall3390515.exe => Moved successfully.
C:\Users\Mike Chidley\AppData\Local\Temp\0001011407319115mcinst.exe => Moved successfully.

The system needed a reboot.

==== End of Fixlog ====

# AdwCleaner v3.304 - Report created 08/08/2014 at 21:04:01
# Updated 08/08/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Mike Chidley - MIKE
# Running from : C:\Users\Mike Chidley\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\Users\MIKECH~1\AppData\Local\Temp\Iminent
File Deleted : C:\Users\Mike Chidley\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage

***** [ Scheduled Tasks ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\Iminent
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{84FF7BD6-B47F-46F8-9130-01B2696B36CB}]
Key Deleted : HKLM\Software\Iminent
Key Deleted : [x64] HKLM\SOFTWARE\Iminent
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DatamngrCoordinator.exe

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17126

-\\ Mozilla Firefox v31.0 (x86 en-US)

[ File : C:\Users\Mike Chidley\AppData\Roaming\Mozilla\Firefox\Profiles\1qvile6h.default\prefs.js ]

Line Deleted : user_pref("iminent.BirthDate", "1407247316");

-\\ Google Chrome v36.0.1985.125

[ File : C:\Users\Mike Chidley\AppData\Local\Google\Chrome\User Data\Default\preferences ]


AdwCleaner[R0].txt - [2025 octets] - [08/08/2014 20:59:18]
AdwCleaner[S0].txt - [1966 octets] - [08/08/2014 21:04:01]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2026 octets] ##########

Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Mike Chidley on 08/08/2014 at 21:42:05.43

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ FireFox

Emptied folder: C:\Users\Mike Chidley\AppData\Roaming\mozilla\firefox\profiles\1qvile6h.default\minidumps [10 files]

~~~ Event Viewer Logs were cleared

Scan was completed on 08/08/2014 at 21:48:01.64
End of JRT log

2014-08-09, 00:23
Are you seeing an improvement?

Below are a couple of scans to check for remnants. If one doesn't work or is incompatible move to the next

Please Run TFC by OldTimer to clear temporary files:

What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.

Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.

Please post
Malwarebytes' Anti-Malware
ESET log

2014-08-09, 00:28
Sorry I should have mentioned I am on Windows 8.1, should I continue?

2014-08-09, 00:33
I did see you are Windows 8.1
What we know is there are some tools and scanners that will work, just not sure which they are.
Thats why I posted, if 1 wont work continue to the other. :)

By the way, have you seen improvement?

2014-08-09, 00:45
Yes, the apps are no longer on the start screen, will run now.

2014-08-09, 00:54

2014-08-09, 03:20
Ran TFC no log
Ran ESET No threats found.

I think we are there?

2014-08-09, 03:58
I think we are there?
We're there!, don't that feel good!

2014-08-09, 04:25
All done, thank you Juliette you and your team are just great and very much appreciated.
Please close the thread as fixed.

2014-08-09, 13:28
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.