The network has a new infection called - texteditor.
C:\Users\User\AppData\Roaming\TextEditor\Daemon\TextEditor
Located in the startup. Opens the search engine created by fraudsters.
It would be nice if the author can add the cure against this infection in his program.
Sorry for my bad English.I used a Google translator))
AdwCleaner v5.025 can`t remove 2 records:
[C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] s3-tool.en.softonic.com
[C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] nkcpopggjcjkiicpenikeogioednjeac
ADW seems to be hanging at deleting shortcuts currently, also files runs a lot longer then before.
hi,
good day
thank you so much, this softwere helped to clean the ad ware successfully.
i was facing the fowling problems:
- DNS and internet dosent works.
-mysearchstar foeces hime page and can not set specific browser home page.
- alto of advertising windows run on brows page.
after cleaned by AdwCleaner everything became good and secure.
warm regards
Bonsoir,
Cette version 4.201 est en anglais.
J'ai viré le moteur de recherche Ixquick et Yahoo
Pour le reste, mêmes résultats et je ne sais pas si je peux supprimer
J'aimerais avoir votre avis et savoir éventuellement d'où pourrait venir ces services.
# AdwCleaner v4.201 - Logfile created 08/04/2015 at 19:09:25
# Updated 08/04/2015 by Xplode
# Database : 2015-04-08.1 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : sophia -
# Running from : C:\Documents and Settings\sophia\Bureau\adwcleaner_4.201.exe
# Option : Scan
***** [ Services ] *****
Service Found : 36596706
Service Found : 68597101
Service Found : 68597102
***** [ Files / Folders ] *****
File Found : C:\WINDOWS\system32\drivers\36596706.sys
File Found : C:\WINDOWS\system32\drivers\68597101.sys
File Found : C:\WINDOWS\system32\drivers\68597102.sys
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Web browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v37.0.1 (x86 fr)
-\\ Comodo Dragon v
Spent hours trying to clean up unwanted browser. Found out abour ADW and cured in a few minutes.
THANK YOU!!
Please, I need your help. After scanning my system with your product, I detected the following (from the report)
# AdwCleaner v3.303 - Report created 08/08/2014 at 10:38:47
# Updated 06/08/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Paulo - PAULO-PC
# Running from : C:\Users\Paulo\Desktop\Clean Up\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Google Chrome v34.0.1847.116
[ File : C:\Users\Paulo\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found [Extension] : eofcbnmajmjmplflapaojjnihcjkigck
*************************
AdwCleaner[R99].txt - [715 octets] - [08/08/2014 10:38:47]
########## EOF - C:\AdwCleaner\AdwCleaner[R99].txt - [775 octets] ##########
After the scan, Under Chrome found an Extension unknown.(see above)
Selected "Clean" - Program ran for a little then a message appeared:
Aut2Exe has stopped working.
A problem caused the program to stop working correctly.
Windows will close the program and notify you if a solution is available.
The faulty chrome Extension was not removed. My system is now unstable and had several dumps (blue screen). Avast, ESET, Malwarebytes and other reported nothing, only AdwCleaner.
Again, my system is now unstable, AdwCleaner is detecting that Chrome Extension but does abort before removing it. Any idea of what the problem is.
Please, contact me at padi5star@gmail.com if you have a solution. I will be away from my computer for 10 days, but I can receive emails.
Thank you.
Here is a log showing what was found on a PC that I had it crash on.
# AdwCleaner v3.303 - Report created 07/08/2014 at 15:00:51
# Updated 06/08/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Robert - MAINPC
# Running from : C:\A.I.R\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
Service Found : CltMngSvc
***** [ Files / Folders ] *****
File Found : C:\Users\Public\Desktop\eBay.lnk
File Found : C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
File Found : C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
File Found : C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Found : C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Folder Found : C:\Program Files (x86)\SearchProtect
Folder Found : C:\ProgramData\374311380
Folder Found : C:\ProgramData\Trymedia
Folder Found : C:\Users\Robert\AppData\Local\SearchProtect
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\Trymedia Systems
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\Trymedia Systems
Key Found : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\Software\SearchProtect
Key Found : HKLM\Software\Trymedia Systems
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Google Chrome v36.0.1985.125
[ File : C:\Users\Guest\AppData\Local\Google\Chrome\User
Help please - I run regularly AdwCleaner (most up to date) and I always find items flagged in Chrome - I click on the clean button and after rebooting I found the following:
# AdwCleaner v3.210 - Report created 19/05/2014 at 13:19:25
# Updated 19/05/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Paulo - PAULO-PC
# Running from : C:\Users\Paulo\Desktop\Clean Up\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Google Chrome v34.0.1847.116
[ File : C:\Users\Paulo\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites0103&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyEtAtC0D0A0ByCyDtB0DzytN0D0Tzu0CyByByDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=938586735&ir=
Deleted [Startup_urls] : hxxp://search.conduit.com/?ctid=CT3306061&SearchSource=48&CUI=UN25144629123183723&UM=2
Deleted [Startup_urls] : hxxp://start.mysearchdial.com/?f=1&a=dsites0103&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyEtAtC0D0A0ByCyDtB0DzytN0D0Tzu0CyByByDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=938586735&ir=
*************************
AdwCleaner[R47].txt - [1467 octets] - [19/05/2014 13:18:36]
AdwCleaner[S21].txt - [1397 octets] - [19/05/2014 13:19:25]
I assume the Chrome items are delete. I run AdwCleaner again, and they seem to be gone. If I run again AwdCleaner a few hours later, the items are back. Where are they coming from? How can I clean them permanently? I do not have ask.com nor aol.com. Please, help.
Contact at pady5star@gmail.com - thanks
########## EOF - C:\AdwCleaner\AdwCleaner[S21].txt - [1458 octets] ##########