"Ads by Provider" malware is not getting removed with Adaware. It removes temprorily but the malware comes back after a while. Kindly provide a fix. Thanks for providing the great software for free!

Re: Ads by Provider not getting removed

Hello,

Can you provide us the logfile showing the deletion ? (From C:\AdwCleaner\)

Regards,

Re: Ads by Provider not getting removed

Hi,

I couldnt find how to attach file here. There are more than 20 log files in that folder. Will add the content of latest 2:

# AdwCleaner v5.112 - Logfile created 17/04/2016 at 22:57:08
# Updated 17/04/2016 by Xplode
# Database : 2016-04-17.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (X64)
# Username : skaranth - IND-LWSRIHARI
# Running from : C:\Users\skaranth\Downloads\adwcleaner_5.112.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****

***** [ Folders ] *****

***** [ Files ] *****

***** [ DLLs ] *****

***** [ Shortcuts ] *****

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\A-ZApps

***** [ Web browsers ] *****

*************************

:: "Tracing" keys deleted :: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [9566 bytes] - [25/02/2016 22:49:58]
C:\AdwCleaner\AdwCleaner[C2].txt - [6027 bytes] - [28/02/2016 18:51:13]
C:\AdwCleaner\AdwCleaner[C3].txt - [7708 bytes] - [02/03/2016 09:58:08]
C:\AdwCleaner\AdwCleaner[C4].txt - [3227 bytes] - [14/04/2016 20:12:39]
C:\AdwCleaner\AdwCleaner[C5].txt - [3532 bytes] - [15/04/2016 22:53:23]
C:\AdwCleaner\AdwCleaner[C6].txt - [2168 bytes] - [17/04/2016 18:39:20]
C:\AdwCleaner\AdwCleaner[C7].txt - [1200 bytes] - [17/04/2016 22:57:08]
C:\AdwCleaner\AdwCleaner[R1].txt - [15714 bytes] - [24/07/2015 10:06:41]
C:\AdwCleaner\AdwCleaner[R2].txt - [1556 bytes] - [24/07/2015 10:23:23]
C:\AdwCleaner\AdwCleaner[R3].txt - [2218 bytes] - [29/08/2015 22:15:22]
C:\AdwCleaner\AdwCleaner[R4].txt - [2079 bytes] - [29/08/2015 22:27:36]
C:\AdwCleaner\AdwCleaner[S1].txt - [22911 bytes] - [24/07/2015 10:08:52]
C:\AdwCleaner\AdwCleaner[S2].txt - [7097 bytes] - [24/07/2015 10:25:18]
C:\AdwCleaner\AdwCleaner[S3].txt - [5434 bytes] - [29/08/2015 22:18:28]
C:\AdwCleaner\AdwCleaner[S4].txt - [7886 bytes] - [29/08/2015 22:31:56]
C:\AdwCleaner\AdwCleaner[S5].txt - [5616 bytes] - [28/02/2016 18:49:38]
C:\AdwCleaner\AdwCleaner[S6].txt - [7674 bytes] - [02/03/2016 09:56:25]
C:\AdwCleaner\AdwCleaner[S7].txt - [4260 bytes] - [04/03/2016 21:48:44]
C:\AdwCleaner\AdwCleaner[S8].txt - [2143 bytes] - [17/04/2016 22:47:34]

########## EOF - C:\AdwCleaner\AdwCleaner[C7].txt - [2151 bytes] ##########  

 

==========================================

# AdwCleaner v5.112 - Logfile created 17/04/2016 at 22:47:34
# Updated 17/04/2016 by Xplode
# Database : 2016-04-17.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (X64)
# Username : skaranth - IND-LWSRIHARI
# Running from : C:\Users\skaranth\Downloads\adwcleaner_5.112.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****

***** [ Folders ] *****

***** [ Files ] *****

***** [ DLL ] *****

***** [ Shortcuts ] *****

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

Key Found : HKCU\Software\A-ZApps
Key Found : HKU\S-1-5-21-4118153955-3530020610-1020751612-1806\Software\A-ZApps

***** [ Web browsers ] *****

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [9566 bytes] - [25/02/2016 22:49:58]
C:\AdwCleaner\AdwCleaner[C2].txt - [6027 bytes] - [28/02/2016 18:51:13]
C:\AdwCleaner\AdwCleaner[C3].txt - [7708 bytes] - [02/03/2016 09:58:08]
C:\AdwCleaner\AdwCleaner[C4].txt - [3227 bytes] - [14/04/2016 20:12:39]
C:\AdwCleaner\AdwCleaner[C5].txt - [3532 bytes] - [15/04/2016 22:53:23]
C:\AdwCleaner\AdwCleaner[C6].txt - [2168 bytes] - [17/04/2016 18:39:20]
C:\AdwCleaner\AdwCleaner[R1].txt - [15714 bytes] - [24/07/2015 10:06:41]
C:\AdwCleaner\AdwCleaner[R2].txt - [1556 bytes] - [24/07/2015 10:23:23]
C:\AdwCleaner\AdwCleaner[R3].txt - [2218 bytes] - [29/08/2015 22:15:22]
C:\AdwCleaner\AdwCleaner[R4].txt - [2079 bytes] - [29/08/2015 22:27:36]
C:\AdwCleaner\AdwCleaner[S1].txt - [22911 bytes] - [24/07/2015 10:08:52]
C:\AdwCleaner\AdwCleaner[S2].txt - [7097 bytes] - [24/07/2015 10:25:18]
C:\AdwCleaner\AdwCleaner[S3].txt - [5434 bytes] - [29/08/2015 22:18:28]
C:\AdwCleaner\AdwCleaner[S4].txt - [7886 bytes] - [29/08/2015 22:31:56]
C:\AdwCleaner\AdwCleaner[S5].txt - [5616 bytes] - [28/02/2016 18:49:38]
C:\AdwCleaner\AdwCleaner[S6].txt - [7674 bytes] - [02/03/2016 09:56:25]
C:\AdwCleaner\AdwCleaner[S7].txt - [4260 bytes] - [04/03/2016 21:48:44]
C:\AdwCleaner\AdwCleaner[S8].txt - [1991 bytes] - [17/04/2016 22:47:34]

########## EOF - C:\AdwCleaner\AdwCleaner[S8].txt - [2064 bytes] ##########  

 

# AdwCleaner v5.036 - Logfile created 28/02/2016 at 18:49:38
# Updated 22/02/2016 by Xplode
# Database : 2016-02-28.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : skaranth - IND-LWSRIHARI
# Running from : C:\Users\skaranth\Downloads\adwcleaner_5.036.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****

Service Found : PrivoxyService

***** [ Folders ] *****

Folder Found : C:\Program Files (x86)\Megasoft Security
Folder Found : C:\Users\skaranth\AppData\Roaming\Interstat
Folder Found : C:\Users\skaranth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Interstat

***** [ Files ] *****

***** [ DLL ] *****

***** [ Shortcuts ] *****

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

Key Found : HKCU\Software\Interstat
Key Found : HKLM\SOFTWARE\SecureWebChannel Key Found : HKU\S-1-5-21-4118153955-3530020610-1020751612-1806\Software\Interstat
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Interstat]
Value Found : HKU\S-1-5-21-4118153955-3530020610-1020751612-1806\Software\Microsoft\Windows\CurrentVersion\Run [Interstat]

***** [ Web browsers ] *****

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [5157 bytes] - [25/02/2016 22:49:58]
C:\AdwCleaner\AdwCleaner[R1].txt - [15714 bytes] - [24/07/2015 10:06:41]
C:\AdwCleaner\AdwCleaner[R2].txt - [1556 bytes] - [24/07/2015 10:23:23]
C:\AdwCleaner\AdwCleaner[R3].txt - [2218 bytes] - [29/08/2015 22:15:22]
C:\AdwCleaner\AdwCleaner[R4].txt - [2079 bytes] - [29/08/2015 22:27:36]
C:\AdwCleaner\AdwCleaner[S1].txt - [18145 bytes] - [24/07/2015 10:08:52]
C:\AdwCleaner\AdwCleaner[S2].txt - [2995 bytes] - [24/07/2015 10:25:18]
C:\AdwCleaner\AdwCleaner[S3].txt - [3699 bytes] - [29/08/2015 22:18:28]
C:\AdwCleaner\AdwCleaner[S4].txt - [3525 bytes] - [29/08/2015 22:31:56]
C:\AdwCleaner\AdwCleaner[S5].txt - [1904 bytes] - [28/02/2016 18:49:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [1977 bytes] ##########

# AdwCleaner v5.110 - Logfile created 14/04/2016 at 20:09:36
# Updated 10/04/2016 by Xplode
# Database : 2016-04-10.3 [Local]
# Operating system : Windows 7 Professional Service Pack 1 (X64)
# Username : skaranth - IND-LWSRIHARI
# Running from : C:\Users\skaranth\Downloads\adwcleaner_5.110.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****

***** [ Folders ] *****

Folder Found : C:\Users\skaranth\AppData\Roaming\Mozilla\Firefox\Profiles\s6bm1ugc.default\extensions\firefox@helper2

***** [ Files ] *****

File Found : C:\Users\skaranth\AppData\Roaming\Mozilla\Firefox\Profiles\s6bm1ugc.default\searchplugins\search.xml

***** [ DLL ] *****

***** [ Shortcuts ] *****

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxps://search.protectedio.com/?u=6608a94aeb8c2d1ef9454800648a56b7&c=p1&src=hp&inst=1460567360 
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] - hxxps://search.protectedio.com/?u=6608a94aeb8c2d1ef9454800648a56b7&c=p1&src=hp&inst=1460567360 
Data Found : HKU\S-1-5-21-4118153955-3530020610-1020751612-1806\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxps://search.protectedio.com/?u=6608a94aeb8c2d1ef9454800648a56b7&c=p1&src=hp&inst=1460567360
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
Data Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
Key Found : HKU\S-1-5-21-4118153955-3530020610-1020751612-1806\Software\Microsoft\Internet Explorer\SearchScopes\{20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
Data Found : HKU\S-1-5-21-4118153955-3530020610-1020751612-1806\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}

***** [ Web browsers ] *****

[C:\Users\skaranth\AppData\Roaming\Mozilla\Firefox\Profiles\s6bm1ugc.default\prefs.js] [Preference] Found : user_pref("browser.startup.homepage", "hxxps://search.protectedio.com/?u=6608a94aeb8c2d1ef9454800648a56b7&c=p1&src=hp&inst=1460567360");

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [9566 bytes] - [25/02/2016 22:49:58]
C:\AdwCleaner\AdwCleaner[C2].txt - [6027 bytes] - [28/02/2016 18:51:13]
C:\AdwCleaner\AdwCleaner[C3].txt - [7708 bytes] - [02/03/2016 09:58:08]
C:\AdwCleaner\AdwCleaner[R1].txt - [15714 bytes] - [24/07/2015 10:06:41]
C:\AdwCleaner\AdwCleaner[R2].txt - [1556 bytes] - [24/07/2015 10:23:23]
C:\AdwCleaner\AdwCleaner[R3].txt - [2218 bytes] - [29/08/2015 22:15:22]
C:\AdwCleaner\AdwCleaner[R4].txt - [2079 bytes] - [29/08/2015 22:27:36]
C:\AdwCleaner\AdwCleaner[S1].txt - [22911 bytes] - [24/07/2015 10:08:52]
C:\AdwCleaner\AdwCleaner[S2].txt - [7097 bytes] - [24/07/2015 10:25:18]
C:\AdwCleaner\AdwCleaner[S3].txt - [5434 bytes] - [29/08/2015 22:18:28]
C:\AdwCleaner\AdwCleaner[S4].txt - [7886 bytes] - [29/08/2015 22:31:56]
C:\AdwCleaner\AdwCleaner[S5].txt - [5318 bytes] - [28/02/2016 18:49:38]
C:\AdwCleaner\AdwCleaner[S6].txt - [3839 bytes] - [02/03/2016 09:56:25]
C:\AdwCleaner\AdwCleaner[S7].txt - [2260 bytes] - [04/03/2016 21:48:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [5537 bytes] ##########  
# AdwCleaner v5.111 - Logfile created 15/04/2016 at 22:53:23
# Updated 14/04/2016 by Xplode
# Database : 2016-04-15.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (X64)
# Username : skaranth - IND-LWSRIHARI
# Running from : C:\Users\skaranth\Downloads\adwcleaner_5.111.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : PrivoxyService

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Megasoft Security
[-] Folder Deleted : C:\Users\skaranth\AppData\Roaming\Mozilla\Firefox\Profiles\s6bm1ugc.default\extensions\firefox@helper2

***** [ Files ] *****

[-] File Deleted : C:\Users\skaranth\AppData\Roaming\Mozilla\Firefox\Profiles\s6bm1ugc.default\searchplugins\search.xml

***** [ DLLs ] *****

***** [ Shortcuts ] *****

***** [ Scheduled tasks ] *****

[-] Task Deleted : Megasoft Security Uninstaller

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\SecureWeb
[-] Key Deleted : HKLM\SOFTWARE\SecureWebChannel
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
[-] Data Restored : HKU\S-1-5-21-4118153955-3530020610-1020751612-1806\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Data Restored : HKU\S-1-5-21-4118153955-3530020610-1020751612-1806\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]

***** [ Web browsers ] *****

[-] [C:\Users\skaranth\AppData\Roaming\Mozilla\Firefox\Profiles\s6bm1ugc.default\prefs.js] Deleted : user_pref("browser.startup.homepage", "hxxps://search.protectedio.com/?u=6608a94aeb8c2d1ef9454800648a56b7&c=p1&src=hp&inst=1460736806");

*************************

:: "Tracing" keys deleted :: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [9566 bytes] - [25/02/2016 22:49:58]
C:\AdwCleaner\AdwCleaner[C2].txt - [6027 bytes] - [28/02/2016 18:51:13]
C:\AdwCleaner\AdwCleaner[C3].txt - [7708 bytes] - [02/03/2016 09:58:08]
C:\AdwCleaner\AdwCleaner[C4].txt - [3227 bytes] - [14/04/2016 20:12:39]
C:\AdwCleaner\AdwCleaner[C5].txt - [2575 bytes] - [15/04/2016 22:53:23]
C:\AdwCleaner\AdwCleaner[R1].txt - [15714 bytes] - [24/07/2015 10:06:41]
C:\AdwCleaner\AdwCleaner[R2].txt - [1556 bytes] - [24/07/2015 10:23:23]
C:\AdwCleaner\AdwCleaner[R3].txt - [2218 bytes] - [29/08/2015 22:15:22]
C:\AdwCleaner\AdwCleaner[R4].txt - [2079 bytes] - [29/08/2015 22:27:36]
C:\AdwCleaner\AdwCleaner[S1].txt - [22911 bytes] - [24/07/2015 10:08:52]
C:\AdwCleaner\AdwCleaner[S2].txt - [7097 bytes] - [24/07/2015 10:25:18]
C:\AdwCleaner\AdwCleaner[S3].txt - [5434 bytes] - [29/08/2015 22:18:28]
C:\AdwCleaner\AdwCleaner[S4].txt - [7886 bytes] - [29/08/2015 22:31:56]
C:\AdwCleaner\AdwCleaner[S5].txt - [5616 bytes] - [28/02/2016 18:49:38]
C:\AdwCleaner\AdwCleaner[S6].txt - [7674 bytes] - [02/03/2016 09:56:25]
C:\AdwCleaner\AdwCleaner[S7].txt - [2260 bytes] - [04/03/2016 21:48:44]

########## EOF - C:\AdwCleaner\AdwCleaner[C5].txt - [3453 bytes] ##########  

 

Re: Ads by Provider not getting removed

Hello,

Thanks for the reports. Does the ads pop-up are occuring with only one web-browser ?

Can you generate a ZHPDiag logreport to get more informations on your system ?

  • Download ZHPDiag from Nicolas on his website
  • Then run it with administrator's rights (with right click)
  • Then upload the log file on up2share (you will find it on your desktop, just drop the file on the upload zone)
  • Then post the link in your reply

Best regards,