I clicked on a springfiles virus searching for "modensa cot instructions". Doh!

My first clean has the following log. I have cleaned several times since and it says I am clean. But I am still getting lots of redirects and occasional Chrome freezing whilst I am asked to call the Microsoft certified technician.

Thanks in advance.

# AdwCleaner v5.036 - Logfile created 27/02/2016 at 23:10:23
# Updated 22/02/2016 by Xplode
# Database : 2016-02-27.1 [Server]
# Operating system : Windows 10 Home  (x64)
# Username : Robert - SKULLCANDY
# Running from : C:\Users\Robert\Downloads\adwcleaner_5.036.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\dply_en_015020251
[!] Folder Not Deleted : C:\Program Files (x86)\dply_en_015020251
[-] Folder Deleted : C:\ProgramData\AVG Security Toolbar
[-] Folder Deleted : C:\ProgramData\Avg_Update_0915av
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DESKTOPPLAY
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
[-] Folder Deleted : C:\Users\Robert\AppData\Local\dply_en_015020251
[!] Folder Not Deleted : C:\Users\Robert\AppData\Local\dply_en_015020251
[-] Folder Deleted : C:\Users\Robert\AppData\Roaming\SpringFiles

***** [ Files ] *****

***** [ DLLs ] *****

***** [ Shortcuts ] *****

[-] Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk [-] Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk [-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [-] Shortcut Disinfected : C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk [-] Shortcut Disinfected : C:\Users\Robert\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKCU\Software\DriverRestore
[-] Key Deleted : HKCU\Software\eSupport.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}

***** [ Web browsers ] *****

*************************

:: "Tracing" keys removed :: Winsock settings cleared :: Chrome policies deleted

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [2775 bytes] - [27/02/2016 23:10:23] C:\AdwCleaner\AdwCleaner[S1].txt - [3261 bytes] - [27/02/2016 23:05:37]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2921 bytes] ##########

 

Re: Springiles / esurf.biz adware

Hello, We will have a deeper look on what may cause those redirections, can you please follow thoses instructions :

  • Download ZHPDiag from Nicolas on his website
  • Then run it with administrator's rights (with right click)
  • Then upload the log file on up2share (you will find it on your desktop, just drop the file on the upload zone)
  • Then post the link in your reply

With that log, we will be able to target the malwares.

Chapi


Protect Your PC from Malware

Get Malwarebytes for powerful protection against adware and threats.

Get Malwarebytes Now