Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: Im back: Kids are good for something!!!

  1. #1
    Junior Member
    Join Date
    Jun 2013
    Posts
    11

    Default Im back: Kids are good for something!!!

    Sorry

    Went out of town, and longer than expected. I have removed the following:
    wajam, search protect by conduit, conduit, xvidly, xvidly1 toolbar, get lyrics, viewpoint media player, free download manager 3.9.2
    and any other toolbar that might be listed.


    I still cant get a dds log. Nothing else has been done since last log. below is an adwcleaner log. i still have the xvidly icon on desktop.My CPU usage is alot better. But should I be worried that I cant get a DDS log?

    http://forums.spybot.info/showthread...Need-some-help


    http://forums.spybot.info/showthread...m-among-others



    # AdwCleaner v2.304 - Logfile created 07/07/2013 at 23:58:02
    # Updated 03/07/2013 by Xplode
    # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
    # User : David & Amber Watts - WATTS-DESKTOP
    # Boot Mode : Normal
    # Running from : C:\Users\David & Amber Watts\Downloads\AdwCleaner.exe
    # Option [Delete]


    ***** [Services] *****


    ***** [Files / Folders] *****

    File Deleted : C:\END
    File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
    File Deleted : C:\Windows\Tasks\Get Lyrics Update.job
    Folder Deleted : C:\Program Files\Conduit
    Folder Deleted : C:\Program Files\getlyrics
    Folder Deleted : C:\ProgramData\Ask
    Folder Deleted : C:\ProgramData\Viewpoint
    Folder Deleted : C:\Users\David & Amber Watts\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
    Folder Deleted : C:\Users\David & Amber Watts\AppData\Local\Smartbar
    Folder Deleted : C:\Users\David & Amber Watts\AppData\Local\Wajam
    Folder Deleted : C:\Users\David & Amber Watts\AppData\LocalLow\Conduit
    Folder Deleted : C:\Users\David & Amber Watts\AppData\LocalLow\PriceGong
    Folder Deleted : C:\Users\David & Amber Watts\AppData\LocalLow\Smartbar
    Folder Deleted : C:\Users\DAVID&~1\AppData\Local\Temp\Smartbar

    ***** [Registry] *****

    Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
    Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
    Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
    Key Deleted : HKCU\Software\Google\Chrome\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AF5B5C22-498A-4239-9A51-82BDD99C6A44}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF5B5C22-498A-4239-9A51-82BDD99C6A44}
    Key Deleted : HKCU\Software\SmartbarBackup
    Key Deleted : HKCU\Software\SmartbarLog
    Key Deleted : HKCU\Software\YahooPartnerToolbar
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5EB0259D-AB79-4AE6-A6E6-24FFE21C3DA4}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF5B5C22-498A-4239-9A51-82BDD99C6A44}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
    Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute
    Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BHO
    Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel
    Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar
    Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject
    Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState
    Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3300236
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF5B5C22-498A-4239-9A51-82BDD99C6A44}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{03F998B2-0E00-11D3-A498-00104B6EB52E}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Viewpoint Manager
    Key Deleted : HKLM\Software\Viewpoint
    Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v9.0.8112.16490

    [OK] Registry is clean.

    *************************

    AdwCleaner[R1].txt - [8052 octets] - [07/07/2013 23:57:10]
    AdwCleaner[S1].txt - [8151 octets] - [07/07/2013 23:58:02]

    ########## EOF - C:\AdwCleaner[S1].txt - [8211 octets] ##########

  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Hello ylwhmr,

    Please send a private message (PM) to the person who responded to your original topic and ask if it can be re-opened.

    http://forums.spybot.info/showthread...m-among-others

    Best regards.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #3
    Junior Member
    Join Date
    Jun 2013
    Posts
    11

    Default Thanks

    Will do

  4. #4
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Hi ylwhmr

    Your back. May as well stay in this thread. We will get another download to use. Its similar to Adwcleaner. We will see if it can dig up anything.

    Please download JRT.exe Removal Tool to your desktop.

    Shutdown your antivirus to avoid any conflicts.
    Double click the icon or Right click for Vista/W7,8 and select Run as administrator
    The tool will open and start scanning.
    Please be patient as this can take a while to complete.
    On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    Post the contents of JRT.txt into your next message
    How Can I Reduce My Risk?

  5. #5
    Junior Member
    Join Date
    Jun 2013
    Posts
    11

    Default

    Okay. So I have been trying different ways to get to get a log. However it is not working for me. Kind of like the DDS log.
    It scans. Appears to be working then disappears. Any thoughts??

  6. #6
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    You can try running a DDS log in safe mode. To reach safe mode you would tap the f8 key during a computer restart. From the list chose the Safe Mode option. Log into your normal account and once at the safe mode desktop try running DDS and then JRT. Save the logs so you can find them. Then reboot computer normally. See how that goes.
    How Can I Reduce My Risk?

  7. #7
    Junior Member
    Join Date
    Jun 2013
    Posts
    11

    Default

    okay. I tried in safe mode. Still did the say thing. Did some researching. There are a couple files created since yesterday o my desktop. They are dat files. I don't how to open them to post them. Any ideas.

    I haven't done anything except log onto internet so I donw they must be related to the DDS scan or the JRT scan.

  8. #8
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Try right clicking on one of the .dat files and chose "rename" and change the extension to a .txt
    see if it opens up then in notepad.
    How Can I Reduce My Risk?

  9. #9
    Junior Member
    Join Date
    Jun 2013
    Posts
    11

    Default

    it came as signs and symbols.
    This is frustrating. I have tried since you last post.
    I have tried in safe mode. I have looked by dates.
    I am not having any luck. I don't have a virus scan.
    the file name is something like

    ntuser.dat.log2

    I have tried running dds, erunt which says it saved a backup point. and the jrt. but there are no logs that i can find related to any of these. the dds and jrt run then just disappear.
    Ug. '

    At 3:58 Erunt created a restore point

    What next

  10. #10
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Ok no problem. Run Roguekiller.exe then try getting a DDS log. If that dosnt work we will forget about the DDS log and move on.

    Quit all programs that you may have started.
    Please disconnect any USB or external drives from the computer before you run this scan!
    For Vista or Windows 7, right-click and select "Run as Administrator to start"
    For Windows XP, double-click to start. A prescan will take place
    Wait until the Prescan has finished
    Then Click on "Scan" button
    Wait until the Status box shows "Scan Finished"
    click on "delete"
    Wait until the Status box shows "Deleting Finished"
    Click on "Report" and copy/paste the content of the Notepad into your next reply.
    The log should be found in RKreport[1].txt on your Desktop
    File>Quit to exit Rougekiller

    Try running DDS again.
    How Can I Reduce My Risk?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •