Not sure if I should "clean" these

Ran AdwCleaner for first time with the following results. Concerned I'll remove something I should not. Would appreciate some advice on how to proceed. Thanks is advance for your help!

# AdwCleaner v5.201 - Logfile created 04/08/2016 at 07:28:02
# Updated 30/06/2016 by ToolsLib
# Database : 2016-08-04.1 [Server]
# Operating system : Windows 10 Home  (X64)
# Username : Ron - LENOVO-PC
# Runnin...

Re: Adwcleaner cannot remove bsdriver.sys and cherimoya.sys

Hello,

Great !

If you have any issues in the future, please come back and we'll try to help.

Best regards,

Re: Adwcleaner cannot remove bsdriver.sys and cherimoya.sys

on AdwCleaner by ****

okay, Mbam removed 80 items. Adwcleaner still founds bsdriver service after that, but was able to remove it. the last scan with adwcleaner says "all clear" !

Mbam log :

Malwarebytes Anti-Malware
www.malwarebytes.org


Protection, 03/08/2016 17:19, SYSTEM, PERICLES, Protection, Malware Protection, Starting, 
Protection, 03/08/2016 17:19, SYSTEM, PERICLES, Protection, Malware Protection, Start...

Re: Adwcleaner cannot remove bsdriver.sys and cherimoya.sys

Hello,

Hm... We'll try with MBAM to remove Shopperz:

  • Download MalwareBytes Anti Malware here.
  • Launch MalwareByte's Anti Malware from your desktop
  • Click on the tab Settings -> Detection & Protection -> PUP/PUM and check "Treat these detections like malware".
  • Tab Exam choose Threats, click on Scan now, and click on Launch the exam.
  • If something is detected, choose to Quarantine everything. ...

Re: AdwCleaner v5.201 - Rapport créé le 31/07/2016 à 22:41:09

# DelFix v1.013 - Rapport créé le 02/08/2016 à 18:32:00
# Mis à jour le 17/04/2016 par Xplode
# Nom d'utilisateur : client - MARIETTE
# Système d'exploitation : Windows 10 Home  (64 bits)

~ Activation de l'UAC ... OK

~ Suppression des outils de désinfection ...

Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
Supprimé : C:\Users\client\Desktop\ZHPDiag.lnk
Supprimé : C:\Us...

Re: Adwcleaner cannot remove bsdriver.sys and cherimoya.sys

on AdwCleaner by ****

first, thank you for your advices. Here is the fixlog.txt :

Résultats de correction de Farbar Recovery Scan Tool (x64) Version: 27-07-2016
Exécuté par Charles-Etienne (2016-08-02 21:55:36) Run:1
Exécuté depuis C:\Users\Charles-Etienne\Downloads
Profils chargés: Charles-Etienne (Profils disponibles: Charles-Etienne)
Mode d'amorçage: Normal
==============================================

fixlis...

Re: Adwcleaner cannot remove bsdriver.sys and cherimoya.sys

Hello,

Ok. I think that AdwCleaner has cleaned most of the elements I found in the FRST log since it has been created before, but we'll see what it gives:

  • Download the file fixlist.txt and save it as "fixlist.txt" to the Desktop or where FRST is located.

NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script wa...

ad hijacker not removed by any program - its hiding somewhere

on Désinfection by ****

Ugg... I have this stupid ad hijacker that i cannot find to remove and it is driving me crazy!   When browsing in Chrome  and you click on anything it opens a new tab wanting to you download some software to update files on your computer, or directs you to a buy a russian bride website, or tells you have a virus that must be removed in 60 seconds... if you get that one it locks up your computer...

Re: Adwcleaner cannot remove bsdriver.sys and cherimoya.sys

on AdwCleaner by ****

Thanks for your answer, here are the links :

FRST.txt  : https://up2sha.re/file?f=KLAbqoDluZ5b

Addition.txt : https://up2sha.re/file?f=UKwSMByQaFg2

Regards,

Re: AdwCleaner v5.201 - Rapport créé le 31/07/2016 à 22:41:09

Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015
Fichier d'export Registre :
Run by client at 02/08/2016 08:02:21
High Elevated Privileges : OK
Windows 8 Home Premium Edition, 64-bit Service Pack 1 (10586)

Corbeille vidée (00mn 07s)
Dossier Prefetcher vidé

========== Processus mémoire ==========
SUPPRIMÉ: Memory Process: C:\Users\client\AppData\Roaming\inst.exe

=====...