InterviewSolution
| 1. |
Solve : Proxy Server connection? |
|
Answer» Hello. I'm hoping to get some help with this problem I'm having with my DELL Inspiron 1520. I have searched for an answer but nothing so far. (I was going to wipe the computer clean and start over but I cannot find my disks for this thing.) Did you try making a new user account yet and see if the problem is also observed with other new logon account with same system?No I haven't. I did run McAfee again and it came up with Adware-RocketTab and Adware-BProtect. My computer wouldn't delete it. What do I do now? Thank you for your help. Now that I have a virus do I need to post a different post? Thanks. Quote I did run McAfee again and it came up with Adware-RocketTab and Adware-BProtect. My computer wouldn't delete it. What do I do now?While unchecking proxy server in LAN settings, checkmark Automatically detect settings, Ok and Apply. Download Adwcleaner by Xplode from here. CLICK on Adwcleaner and hit the Scan button and will begin to search for PUP and malicious files. Once finished click the Clean button. Copy and paste the log on your next reply. Do you see the problem with other browsers? Have you tried Firefox? Maybe a reset of IE browser would also help but see if after running Adwcleaner would make a difference. Hi Jason. I've run AdwCleaner and here are the results: # AdwCleaner v4.107 - Report created 16/01/2015 at 22:38:04 # UPDATED 07/01/2015 by Xplode # Database : 2015-01-13.2 [Live] # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : sheila - SHEILA-PC # Running from : C:\Users\sheila\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DO50OMS2\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** Service Deleted : MyFunCards_5mService Service Deleted : {e8294a7e-8442-4f3a-8722-cb5c3f67ed67}Gw64 ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\Interenet Optimizer Folder Deleted : C:\ProgramData\couponpeak Folder Deleted : C:\ProgramData\websaver Folder Deleted : C:\ProgramData\77d964edf1532fec Folder Deleted : C:\Program Files (x86)\MyFunCards_5m Folder Deleted : C:\Program Files (x86)\Optimizer Pro Folder Deleted : C:\Program Files (x86)\Search Extensions Folder Deleted : C:\Program Files (x86)\couponpeak Folder Deleted : C:\Users\sheila\AppData\LocalLow\MyFunCards_5m Folder Deleted : C:\Users\sheila\Documents\Optimizer Pro Folder Deleted : C:\Users\sheila\AppData\Roaming\Mozilla\Firefox\Profiles\bmhk3sr0.default\Extensions\[email protected] Folder Deleted : C:\Users\sheila\AppData\Roaming\Mozilla\Firefox\Profiles\bmhk3sr0.default\Extensions\[email protected] Folder Deleted : C:\Users\sheila\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhngcoclgbcfihebeepcnkikpcadgfjg File Deleted : C:\Windows\System32\drivers\{e8294a7e-8442-4f3a-8722-cb5c3f67ed67}Gw64.sys File Deleted : C:\Users\sheila\AppData\LocalLow\SkwConfig.bin File Deleted : C:\Users\sheila\AppData\Roaming\Mozilla\Firefox\Profiles\bmhk3sr0.default\searchplugins\SweetIm.xml File Deleted : C:\Users\sheila\AppData\Roaming\Mozilla\Firefox\Profiles\bmhk3sr0.default\searchplugins\trovi-search.xml File Deleted : C:\Users\sheila\AppData\Roaming\Mozilla\Firefox\Profiles\bmhk3sr0.default\user.js File Deleted : C:\Users\sheila\AppData\Roaming\Mozilla\Firefox\Profiles\bmhk3sr0.default\searchplugins\Vosteran.xml ***** [ Scheduled TASKS ] ***** Task Deleted : LaunchSignup Task Deleted : RocketTab Update Task Task Deleted : RocketTab ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com Key Deleted : HKLM\SOFTWARE\Classes\. Key Deleted : HKLM\SOFTWARE\Classes\..9 Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C4B22C87-45EF-4F43-89F2-40DB2078864E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DA71FD14-5F7B-46AE-B8B1-44074A38F331} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{20a3a5aa-22e2-4f13-a6e6-9d071c0eb8e2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C4B22C87-45EF-4F43-89F2-40DB2078864E} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DA71FD14-5F7B-46AE-B8B1-44074A38F331} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C4B22C87-45EF-4F43-89F2-40DB2078864E} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA71FD14-5F7B-46AE-B8B1-44074A38F331} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{20a3a5aa-22e2-4f13-a6e6-9d071c0eb8e2} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C4B22C87-45EF-4F43-89F2-40DB2078864E} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DA71FD14-5F7B-46AE-B8B1-44074A38F331} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{20a3a5aa-22e2-4f13-a6e6-9d071c0eb8e2} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{20a3a5aa-22e2-4f13-a6e6-9d071c0eb8e2} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{20a3a5aa-22e2-4f13-a6e6-9d071c0eb8e2} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6} Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{acbd5593-e5ee-4c15-b48f-1823ce819dec} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{acbd5593-e5ee-4c15-b48f-1823ce819dec} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\MyFunCards_5m Key Deleted : HKCU\Software\Optimizer Pro Key Deleted : HKCU\Software\RocketTabInstalled Key Deleted : HKCU\Software\Search Extensions Key Deleted : HKCU\Software\SweetIM Key Deleted : HKCU\Software\Vosteran Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Deleted : HKCU\Software\AppDataLow\Software\MyFunCards_5m Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} Key Deleted : HKLM\SOFTWARE\MyFunCards_5m Key Deleted : HKLM\SOFTWARE\PIP Key Deleted : HKLM\SOFTWARE\RocketTab Key Deleted : HKLM\SOFTWARE\SweetIM Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RocketTab Key Deleted : [x64] HKLM\SOFTWARE\SweetIM ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17496 -\\ Mozilla Firefox v29.0.1 (en-US) [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=MD9E525F3-0D5E-4ECB-9C97-0C4CEF975CED&SearchSource=55&CUI=&UM=6&UP=SP2FCCDE3A-614A-4F73-B4B3[...] [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("extensions.i9079U5jL9Y5nGa7.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...] [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.hmpgUrl", "hxxp://Vosteran.com/?f=1&a=vst_ggbc_14_47_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtByD0F0D0CtDyBzztC0CyB0A0AtN0D0Tzu0StCtDyDtAtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDyD1[...] [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.newTabUrl", "hxxp://Vosteran.com/?f=2&a=vst_ggbc_14_47_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtByD0F0D0CtDyBzztC0CyB0A0AtN0D0Tzu0StCtDyDtAtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDy[...] [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.prtnrId", "WSE_Vosteran"); [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.srchPrvdr", "Vosteran"); [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.tlbrSrchUrl", "hxxp://Vosteran.com/?f=3&a=vst_ggbc_14_47_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtByD0F0D0CtDyBzztC0CyB0A0AtN0D0Tzu0StCtDyDtAtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzyt[...] [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("sweetim.toolbar.previous.browser.search .defaultenginename", ""); [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("sweetim.toolbar.previous.browser.search .selectedEngine", ""); [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("sweetim.toolbar.previous.browser.startu p.homepage", ""); [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", ""); [bmhk3sr0.default\prefs.js] - Line Deleted : user_pref("sweetim.toolbar.urls.homepage", "hxxp://www.better-search.net/?src=10&st=12&i=998&did=10874&ppd=,,,,,,,,,www.smilebox.com&barid=1605756192124466368"); -\\ Google Chrome v38.0.2125.111 [C:\Users\sheila\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms} [C:\Users\sheila\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms} [C:\Users\sheila\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=MD9E525F3-0D5E-4ECB-9C97-0C4CEF975CED&SearchSource=58&CUI=&UM=6&UP=SP2FCCDE3A-614A-4F73-B4B3-FF8B77EE0CEE&q={searchTerms}&SSPV= [C:\Users\sheila\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=MD9E525F3-0D5E-4ECB-9C97-0C4CEF975CED&SearchSource=58&CUI=&UM=6&UP=SP2FCCDE3A-614A-4F73-B4B3-FF8B77EE0CEE&q={searchTerms}&SSPV= ************************* AdwCleaner[R0].txt - [1098 octets] - [16/03/2014 13:16:06] AdwCleaner[R1].txt - [11328 octets] - [16/01/2015 22:32:13] AdwCleaner[S0].txt - [1164 octets] - [16/03/2014 13:18:24] AdwCleaner[S1].txt - [10621 octets] - [16/01/2015 22:38:04] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [10682 octets] ########## I haven't used any other internet browser lately to know if there are any problems. I can start to use them to find out though. Ok, let us know how it went after trying out a different browser including IE since Adwcleaner scan removed some unwanted.So far so good. Thank you for your help. |
|