I clicked on a springfiles virus searching for "modensa cot instructions". Doh!

My first clean has the following log. I have cleaned several times since and it says I am clean. But I am still getting lots of redirects and occasional Chrome freezing whilst I am asked to call the Microsoft certified technician.

Thanks in advance.

# AdwCleaner v5.036 - Logfile created 27/02/2016 at 23:10:23
# Updated 22/02/2016 by Xplode
# Database : 2016-02-27.1 [Server]
# Operating system : Windows 10 Home  (x64)
# Username : Robert - SKULLCANDY
# Running from : C:\Users\Robert\Downloads\adwcleaner_5.036.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\dply_en_015020251
[!] Folder Not Deleted : C:\Program Files (x86)\dply_en_015020251
[-] Folder Deleted : C:\ProgramData\AVG Security Toolbar
[-] Folder Deleted : C:\ProgramData\Avg_Update_0915av
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DESKTOPPLAY
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
[-] Folder Deleted : C:\Users\Robert\AppData\Local\dply_en_015020251
[!] Folder Not Deleted : C:\Users\Robert\AppData\Local\dply_en_015020251
[-] Folder Deleted : C:\Users\Robert\AppData\Roaming\SpringFiles

***** [ Files ] *****

***** [ DLLs ] *****

***** [ Shortcuts ] *****

[-] Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk [-] Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk [-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [-] Shortcut Disinfected : C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk [-] Shortcut Disinfected : C:\Users\Robert\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKCU\Software\DriverRestore
[-] Key Deleted : HKCU\Software\eSupport.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}

***** [ Web browsers ] *****

*************************

:: "Tracing" keys removed :: Winsock settings cleared :: Chrome policies deleted

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [2775 bytes] - [27/02/2016 23:10:23] C:\AdwCleaner\AdwCleaner[S1].txt - [3261 bytes] - [27/02/2016 23:05:37]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2921 bytes] ##########

 

Re: Springiles / esurf.biz adware

Hello, We will have a deeper look on what may cause those redirections, can you please follow thoses instructions :

  • Download ZHPDiag from Nicolas on his website
  • Then run it with administrator's rights (with right click)
  • Then upload the log file on up2share (you will find it on your desktop, just drop the file on the upload zone)
  • Then post the link in your reply

With that log, we will be able to target the malwares.

Chapi