Solved IE 11 errors with Windows 10

February 25, 2017 at 12:26:04
Specs: Windows 10
When I try to use IE 11, I get these issues:Box #1 - Internet Explorer has stopped working. Windows is checking for a solution to the problem.
Hit Cancel; and, Cancel again
Box #2 - Internet Explorer has stopped working. A problem caused the program to stop working
correctly. Windows will close the program and notify you if a solution is available.
Hit Close
At bottom - Bing.Com is not responding
Hit 'x'


Pull Page says 'X' in red circle - We were unable to return you to bing.com
Internet Explorer has stopped trying to restore this website. It appears that the website continues to have a problem.
What you can do:
1. Do to your home page - Does go to a home page
Type anything in and goes to 'Box #1' message; then 'Box #2'; then, at bottom - A problem
with this webpage caused Internet Explorer to close and reopen the program; then at
bottom - Yahoo.com is not responding
Now same options come up except 'Try to return to yahoo.com'
2. Try to return to bing.com
3. More information
When a website causes a failure or crash, Internet Explorer attempts to restore the site.
It stops after two tries to avoid an andless loop.

Started again - this time 'thinking' with www.yahoo.com at 'address line'; not bing.com


See More: IE 11 errors with Windows 10

Report •

✔ Best Answer
February 26, 2017 at 06:40:25
You seem to be doing all sorts of things which makes it a bit confusing. For the time being just run these three programs in the order given so that we can check for malware:

AdwCleaner:
https://toolslib.net/downloads/view...
(blue "Download Now" button on right).
Download and "Save" the file somewhere. Go to the saved file then double click it to run the program. Use the "Scan" button, followed by the "Clean" button.

Junkware Removal Tool (JRT)
https://www.malwarebytes.org/junkwa...
(blue Download button).
Download and "Save" the file somewhere. Go to the saved file then double click it to run JRT. It might appear to have stopped at times or flash the screen but sit tight until it has finished.

MalwareBytes:
https://www.malwarebytes.org/
(use the "Free Download" button rather than the "Buy Now" button).
After the install go to "Settings > Protection". Under Scan Options move the "Scan for rootkits" slider over to On and Run the Threat Scan. Quarantine anything it finds.

If they find anything copy/paste the appropriate logs on here and let us know if there is any improvement. If you lose the ADW log you can find it as a text file in the ADWCleaner folder directly off the system drive root (usually C).

Always pop back and let us know the outcome - thanks



#1
February 25, 2017 at 14:47:52
IE Reset is also an option worth considering:
IE > Tools > Internet Options > Advanced tab > Reset button.

You will lose your add-ons but they soon come back with usage. Other things like Favorites will not stay in situ.

Always pop back and let us know the outcome - thanks


Report •

#2
February 25, 2017 at 15:58:15
Resetting should fix it.
You should be using Edge in Windows 10 instead.
You can use other browsers like Firefox as well.

You have to be a little bit crazy to keep you from going insane.


Report •

#3
February 25, 2017 at 17:26:25
Maybe I'm not stating my problem correctly. I have done what you suggested but it doesn't help. What's happening is whenever I enter something in Cortana when it opens it goes to Internet Explorer with a 'bing.com' homepage. I've tried to make it Microsoft Edge with a homepage for that. I've tried a Yahoo.Com homepage; but, I think I found Cortana doesn't work with Yahoo.Com...anyway, that didn't work either. I think I just want to get rid of Internet Explorer but can't figure out how to do that. At any rate, I don't seem to be able to make Cortana work with Edge...not sure what's up. I'm sure when I first got this computer it worked. But, somewhere along the line it did get upgraded to Windows 10 and maybe that's when this started. Just can't remember. I'd like to use Cortana cause it seems to have lots of things it can do.
Thanks for any ideas you may have.


Jeanine


Report •

Related Solutions

#4
February 25, 2017 at 17:32:41
I did just post a new description. I think I wasn't explaining it correctly. Any help, as before, is really, really appreciates.

Thanks


Report •

#5
February 25, 2017 at 18:25:35
You should still try resetting IE as first step - let us know if you have tried it.

IE should be left in place as it is part of the system and cannot be ripped out without causing troubles. You just don't use it. If you have a shortcut to it that can be deleted it you wish but the program stays there.

Always pop back and let us know the outcome - thanks


Report •

#6
February 25, 2017 at 19:07:42
thanks. Yes, I have reset about 6 times. Maybe I'm doing it wrong...but, I hit 'reset' and reboot the computer. I had changed the homepage a few times, back and forth. Would that have anything to do with anything. I think it's at Bing now.

Thanks much


Report •

#7
February 25, 2017 at 21:43:14
New info - with details…again…
Internet Explorer always comes when using Cortena…with errors
Update…still
Box #1 - Internet Explorer has stopped working. Windows is checking for a solution to the problem.
Hit Cancel; and, Cancel again
Box #2 - Internet Explorer has stopped working. A problem caused the program to stop working
correctly. Windows will close the program and notify you if a solution is available.
Hit Close
At bottom - Bing.Com is not responding
Hit 'x'
Pull Page says 'X' in red circle - We were unable to return you to bing.com
Internet Explorer has stopped trying to restore this website. It appears that the website continues to have a problem.
What you can do:
At address line at top:
res://ieframe.dll/acr_error.htm#bing.com,https://www.bing.com/search?q=new+york+city+walking+tours&form=WNSGPH&qs=HS&cvid=cc4f430d611344548aeee9e32592498b&pq=new+york+city+walking+tours&nclid=166981673B0CE623D275372F712FB8C4&ts=1488086666684&nclidts=1488086666&tsms=684&elv=AY3%21uAY7tbNNZGZ2yiGNjfMA0SyhOd0Q7toVe6VwEyakiS2urL9oz62X3JEF08Htg84TPyXrVqfLN0dqlyImW6SaeY1cwh59xumqY89tEN7e&cc=US&setlang=en-US
1. Go to your home page - at address line above says 'about:home'; then at first tab info it says
'Microsoft Edge Web Browser' and wants me to try it now. But I already have it and do use it.
I clicked on one of the icons and got the Boxes #1 and #2 again.
Now at the top https area it says //www.microsoft.com/en-us/
2. I closed the 'boxes' and now the 2nd option says 'try to return to microsoft.com. Trying that
just goes to the 'boxes' again. Now at the top tab it says, again, 'website restore error'.

Now, I will go to that settings and 'reset'. I will give you the details of what I'm doing…

Hit windows, corner icon; to settings icon; to network and internet; at top left in search box under home I type 'control panel' ; hit internet options.
Now, under home page this is what's there 'http://www.microsoft.com/en-us/windows/microsoft-edge'
Now, I click on 'Advanced'
At the top under Accelerated graphics I have checked the box 'use software rendering instead of
GPU rendering' I must have seen that in other instructions cause it was not check when I first
found it.
At the bottom under 'reset Internet Explorer settings I click on 'Reset…'. A 'reset IE settings' box comes up and I just do not check the box 'delete personal settings' . Then I hit 'reset' again. A box comes up that says resetting IE settings with 3 lines under it and I hit close. I close those windows only and restart the computer.

message edited by Jeanine48


Report •

#8
February 25, 2017 at 23:48:36
tried to enter to clean up windows logs...now computer is running slowly...this came up when I entered that to cortana.

https://www.bing.com/search?q=clear+windows+log&form=WNSGPH&qs=SW&cvid=54f7e9ab8b97491081a78379060f836d&pq=clear+windows+log&nclid=166981673B0CE623D275372F712FB8C4&ts=1488095183112&nclidts=1488095183&tsms=112&elv=AY3%21uAY7tbNNZGZ2yiGNjfMA0SyhOd0Q7toVe6VwEyakC3OwoOp4%218PZytuqVKv7p61%21l259KqgEQG*l2rfa3oK32QXVfdq5kxWF16tafq4S&cc=US&setlang=en-US


Report •

#9
February 26, 2017 at 06:40:25
✔ Best Answer
You seem to be doing all sorts of things which makes it a bit confusing. For the time being just run these three programs in the order given so that we can check for malware:

AdwCleaner:
https://toolslib.net/downloads/view...
(blue "Download Now" button on right).
Download and "Save" the file somewhere. Go to the saved file then double click it to run the program. Use the "Scan" button, followed by the "Clean" button.

Junkware Removal Tool (JRT)
https://www.malwarebytes.org/junkwa...
(blue Download button).
Download and "Save" the file somewhere. Go to the saved file then double click it to run JRT. It might appear to have stopped at times or flash the screen but sit tight until it has finished.

MalwareBytes:
https://www.malwarebytes.org/
(use the "Free Download" button rather than the "Buy Now" button).
After the install go to "Settings > Protection". Under Scan Options move the "Scan for rootkits" slider over to On and Run the Threat Scan. Quarantine anything it finds.

If they find anything copy/paste the appropriate logs on here and let us know if there is any improvement. If you lose the ADW log you can find it as a text file in the ADWCleaner folder directly off the system drive root (usually C).

Always pop back and let us know the outcome - thanks


Report •

#10
February 26, 2017 at 14:14:43
Did the first one. When I started the second one it asked for a restore point; which I didn't know what to put, so I got out. When I went to the third one to check it out, since you told me to do them in order, I did download it but under "settings" I couldn't find Protection. I found Application Updates, Notifications, Windows Context Menus, Display Language, Event Log Data, Proxy Server, User Access, Windows Action Center and Usage and Threat Statistics.
Thanks again for your help with this. I must say I do tend to just keep trying stuff, as you can tell.
When it was running slow last night I found a YouTube that talked about delete the Windows Logs. I went into that and had almost 12,000 things in the first folder alone. I didn't do anything cause it was getting late and I didn't want to do something really bad.

Report •

#11
February 26, 2017 at 14:27:38
So sorry, I couldn't this to just 'copy/paste' the link to the log. It's very long.

# AdwCleaner v6.043 - Logfile created 26/02/2017 at 13:50:50
# Updated on 27/01/2017 by Malwarebytes
# Database : 2017-02-24.1 [Server]
# Operating System : Windows 10 Home (X64)
# Username : WeBJa - DESKTOP-C3LJ1S9
# Running from : C:\Users\WeBJa\Desktop\adwcleaner_6.043.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support

***** [ Services ] *****

***** [ Folders ] *****

[-] Folder deleted: C:\ProgramData\1cf2ec47-6ac2-4f36-a089-701170ee50d1
[-] Folder deleted: C:\ProgramData\1f7c829e-a5d0-4e12-89d2-a409536761fe
[-] Folder deleted: C:\ProgramData\219d5106-5a99-41fd-b942-db6b503b0178
[#] Folder deleted on reboot: C:\ProgramData\219d5106-5a99-41fd-b942-db6b503b0178
[-] Folder deleted: C:\ProgramData\3b65a5f7-3bcf-4ff2-b6db-881e68fd073e
[-] Folder deleted: C:\ProgramData\8d3e31ef-71a4-443a-bff7-13357c608ff2
[-] Folder deleted: C:\Users\WeBJa\AppData\Local\TNT2
[-] Folder deleted: C:\Users\WeBJa\AppData\Local\YSearchUtil
[-] Folder deleted: C:\Users\WeBJa\AppData\Local\Programs\BeFrugal.com
[-] Folder deleted: C:\Users\WeBJa\AppData\Roaming\myturbopc.com
[-] Folder deleted: C:\ProgramData\myturbopc.com
[#] Folder deleted on reboot: C:\ProgramData\Application Data\myturbopc.com
[-] Folder deleted: C:\Program Files (x86)\TNT2
[-] Folder deleted: C:\Program Files (x86)\Yahoo!\yset
[-] Folder deleted: C:\WINDOWS\SysWoW64\config\systemprofile\AppData\Local\YSearchUtil


***** [ Files ] *****

[-] File deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk
[-] File deleted: C:\Users\WeBJa\AppData\Roaming\Mozilla\Firefox\Profiles\vj26q17t.default\extensions\jid1-16aeif9OQIRKxA@jetpack.xpi


***** [ DLL ] *****

***** [ WMI ] *****

***** [ Shortcuts ] *****

***** [ Scheduled Tasks ] *****

[-] Task deleted: BeFrugal.com Toolbar


***** [ Registry ] *****

[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\Classes\TypeLib\{ABB8A8A5-FF98-40F6-B573-5841B063EA37}
[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\Classes\TypeLib\{2A05A54D-0614-4EA3-B955-8814E45DCD83}
[-] Key deleted: HKCU\Software\Classes\CLSID\{554EBE31-AEC1-4E34-BCE3-606467760D88}
[-] Key deleted: HKCU\Software\Classes\CLSID\{0FEB2313-F89B-4AC6-8153-84025604A06A}
[-] Key deleted: HKCU\Software\Classes\CLSID\{F8534A9F-4F29-4FDC-9CD9-023ACF0EF9B9}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{0FEB2313-F89B-4AC6-8153-84025604A06A}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{99415057-7C50-439D-AA20-02D83C071B61}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{3BEACC4A-B617-4519-BB20-E5970414CBE4}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{0FEB2313-F89B-4AC6-8153-84025604A06A}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{02F878DF-E2BE-4B85-8CB4-A0D2D4E2ED7F}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{2AF343DD-3102-4F9D-AC95-DCA4C95382C7}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{3137BC14-D8D7-4B67-8FFA-2E0B2E9D541B}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{4CA2AC92-971B-47B1-ACB6-357B552155AC}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{52C5395B-1FCD-47FA-A834-FD830701C2D5}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{5D3DCC39-9233-4330-94E9-DA92BE49CA1A}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{615FACDF-DADB-440D-AC91-8AAB0AE9E3AD}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{762D463B-C45A-456D-A80D-8689C297C91E}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{7A6BE473-7960-44D0-BD54-D23DA76353DF}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{803F550E-BAAE-42BB-8917-64BA0006AB17}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{8D5BC51D-C9D3-43B9-B728-B30677B7C7E8}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{991C9D8D-A789-4DB9-BDFC-5F33398B04BF}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{A5ACC874-D943-483F-A2D1-14598D51F872}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{B0474212-0D9D-4361-90B3-B89D1A44275D}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{BFDE183A-C6FE-41D2-80F9-586C29210AC2}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{D83C83BF-3EDD-4410-ADAB-5295116DD8C7}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{DD260902-9420-4055-A956-9152EB4F3E6A}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{EB1F9F3C-5526-4DAE-BD4B-3EAA7715DA9F}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{F1912128-469A-4138-AA26-9699C15BB13E}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{F68DC16C-9C2B-455B-8853-7E4D34BAA3F4}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{FBA8498F-B3A0-4942-A2BF-E0CB7BC7E000}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{655847A1-FA36-46ED-923B-A5CD523696EA}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{EBBC143E-44AC-4B9C-BCCE-9A0E42921F2A}
[#] Key deleted on reboot: HKCU\Software\Classes\TypeLib\{ABB8A8A5-FF98-40F6-B573-5841B063EA37}
[#] Key deleted on reboot: HKCU\Software\Classes\TypeLib\{2A05A54D-0614-4EA3-B955-8814E45DCD83}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3BEACC4A-B617-4519-BB20-E5970414CBE4}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DEDAF650-12B8-48F5-A843-BBA100716106}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3BEACC4A-B617-4519-BB20-E5970414CBE4}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DEDAF650-12B8-48F5-A843-BBA100716106}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3BEACC4A-B617-4519-BB20-E5970414CBE4}
[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\BEFRUGAL
[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\CoinisRS
[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\MyTurboPC.com
[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\Palikan
[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\PRODUCTSETUP
[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\TNT2
[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\yahooprovidedsearch
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\BEFRUGAL
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\TNT2
[#] Key deleted on reboot: HKCU\Software\BEFRUGAL
[#] Key deleted on reboot: HKCU\Software\CoinisRS
[#] Key deleted on reboot: HKCU\Software\MyTurboPC.com
[#] Key deleted on reboot: HKCU\Software\Palikan
[#] Key deleted on reboot: HKCU\Software\PRODUCTSETUP
[#] Key deleted on reboot: HKCU\Software\TNT2
[#] Key deleted on reboot: HKCU\Software\yahooprovidedsearch
[-] Key deleted: HKLM\SOFTWARE\MyTurboPC.com
[-] Key deleted: HKLM\SOFTWARE\Solvusoft
[-] Key deleted: HKLM\SOFTWARE\SearchWebKnow
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! SearchSet
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\BEFRUGAL
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\TNT2
[#] Key deleted on reboot: [x64] HKCU\Software\BEFRUGAL
[#] Key deleted on reboot: [x64] HKCU\Software\CoinisRS
[#] Key deleted on reboot: [x64] HKCU\Software\MyTurboPC.com
[#] Key deleted on reboot: [x64] HKCU\Software\Palikan
[#] Key deleted on reboot: [x64] HKCU\Software\PRODUCTSETUP
[#] Key deleted on reboot: [x64] HKCU\Software\TNT2
[#] Key deleted on reboot: [x64] HKCU\Software\yahooprovidedsearch
[-] Data restored: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Value deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[-] Key deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\Microsoft\Internet Explorer\SearchScopes\{1b31c9d2-7135-442b-bb93-7c002172adc6}
[#] Value deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1b31c9d2-7135-442b-bb93-7c002172adc6}
[#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1b31c9d2-7135-442b-bb93-7c002172adc6}
[-] Value deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1b31c9d2-7135-442b-bb93-7c002172adc6}
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{25F68CC8-E760-4556-A000-F62EB44ACAAB}
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\eshield.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ask.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dotomi.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\sjc-usadmm.dotomi.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\staticimgfarm.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ttdetect.staticimgfarm.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.ask.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ask.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dotomi.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\sjc-usadmm.dotomi.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\staticimgfarm.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ttdetect.staticimgfarm.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.ask.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\eshield.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ask.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dotomi.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\sjc-usadmm.dotomi.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\staticimgfarm.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ttdetect.staticimgfarm.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.ask.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ask.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dotomi.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\sjc-usadmm.dotomi.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\staticimgfarm.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ttdetect.staticimgfarm.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.ask.com
[-] Value deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\Microsoft\Windows\CurrentVersion\Run [BFHP]
[-] Value deleted: HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [BFHP]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BFHP]
[#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BFHP]
[-] Key deleted: HKCU\Software\MozillaPlugins\@tnt2npapi.com/Plugin
[#] Key deleted on reboot: HKCU\SOFTWARE\MOZILLAPLUGINS\@tnt2npapi.com/Plugin
[-] Key deleted: HKLM\SOFTWARE\Google\Chrome\Extensions\dkmjljdbbgogihjcapfhgkonfmccbffp
[-] Key deleted: HKCU\Software\Google\Chrome\Extensions\kofkpgiaknijknhajbhnghkodiccblkg
[-] Key deleted: HKLM\SOFTWARE\Google\Chrome\Extensions\kofkpgiaknijknhajbhnghkodiccblkg
[#] Key deleted on reboot: [x64] HKCU\Software\Google\Chrome\Extensions\kofkpgiaknijknhajbhnghkodiccblkg
[-] Key deleted: [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\kofkpgiaknijknhajbhnghkodiccblkg


***** [ Web browsers ] *****

[-] [C:\Users\WeBJa\AppData\Local\Chromium\User Data\Default] [startup_urls] Deleted: hxxp://www.palikan.com/?f=7&a=plk_coinisrs_15_50&cd=2XzuyEtN2Y1L1Qzu0EyE0Fzzzy0CzzzyyEzzyDyD0F0DtBtCtN0D0Tzu0StCyEtAyCtN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyDtD0DyEzyyB0DtAtGtAyDyCzytG0CyBtCzytGyD0ByCyBtGzzyD0AyCtD0FtByB0BzzyEtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0Czy0CtA0FtDtBtGtByE0AtDtGyEtDzytAtGzytByC0EtG0EtCtB0Bzy0F0FyEyC0EyC0F2QtN0A0LzuyE&cr=2011620619&ir=&uref=chmm
[-] [C:\Users\WeBJa\AppData\Local\Chromium\User Data\Default] [startup_urls] Deleted: hxxps://us.search.yahoo.com/yhs/search?p=www.yahoo.com&hspart=iry&hsimp=yhs-fullyhosted_003&type=plk_coinisrs_15_50_ag1949¶m1=1¶m2=cd%3D2XzuyEtN2Y1L1Qzu0EyE0Fzzzy0CzzzyyEzzyDyD0F0DtBtCtN0D0Tzu0StCyEtAyCtN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyDtD0DyEzyyB0DtAtGtAyDyCzytG0CyBtCzytGyD0ByCyBtGzzyD0AyCtD0FtByB0BzzyEtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0Czy0CtA0FtDtBtGtByE0AtDtGyEtDzytAtGzytByC0EtG0EtCtB0Bzy0F0FyEyC0EyC0F2QtN0A0LzuyE%26cr%3D2011620619%26a%3Dplk_coinisrs_15_50%26uref%3Dchmm%26f%3D7%26cat%3Dweb%26sid%3Da936b1cfb04fbecac4a340e0cb6f8406%26sesid%3D2700938a79d7dd5cb504828249aeb11f%26abid%3D139%26abg%3D1949%26ip%3D75.141.232.106%26b%3Dchmm%26bv%3D46.0.2472.0%26os%3DWindows%2B10%26os_ver%3D10.0%26pa%3Dpalikan
[-] [C:\Users\WeBJa\AppData\Local\Chromium\User Data\Default] [extension] Deleted: dkmjljdbbgogihjcapfhgkonfmccbffp
[-] [C:\Users\WeBJa\AppData\Local\Chromium\User Data\Default] [extension] Deleted: kofkpgiaknijknhajbhnghkodiccblkg
[-] [C:\Users\WeBJa\AppData\Local\Chromium\User Data\Default] [homepage] Deleted: hxxp://www.palikan.com/?f=1&a=plk_coinisrs_15_50&cd=2XzuyEtN2Y1L1Qzu0EyE0Fzzzy0CzzzyyEzzyDyD0F0DtBtCtN0D0Tzu0StCyEtAyCtN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyDtD0DyEzyyB0DtAtGtAyDyCzytG0CyBtCzytGyD0ByCyBtGzzyD0AyCtD0FtByB0BzzyEtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0Czy0CtA0FtDtBtGtByE0AtDtGyEtDzytAtGzytByC0EtG0EtCtB0Bzy0F0FyEyC0EyC0F2QtN0A0LzuyE&cr=2011620619&ir=&uref=chmm
[-] [C:\Users\WeBJa\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: dkmjljdbbgogihjcapfhgkonfmccbffp
[-] [C:\Users\WeBJa\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: kofkpgiaknijknhajbhnghkodiccblkg


*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [18383 Bytes] - [26/02/2017 13:50:50]
C:\AdwCleaner\AdwCleaner[S0].txt - [16898 Bytes] - [26/02/2017 13:48:24]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [18531 Bytes] ##########


Report •

#12
February 26, 2017 at 14:45:22
Derek...you did it. That first one took care of Cortana. IE11 seems to be good. You're great. If there is somewhere I can go to give you stars let me know. I'm a happy camper.

Thanks much,

Jeanine


Report •

#13
February 26, 2017 at 15:16:19
ADWCleaner found a lot and I doubt your computer is anywhere near clean. That might be why JRT played up.

Try to run MalwareBytes. Settings is at bottom left, Protection 2nd tab along the top next to Application, rootkits is down the bottom under Scan Options (move slider to On). If you can't fathom it out the run the Clean anyway. Let me have the log if it finds anything.

If that runs then give JRT another whirl too.

The only marking around here is selecting a "Best Answer" but that's probably a bit premature.

Always pop back and let us know the outcome - thanks


Report •

#14
February 26, 2017 at 15:45:42
I ran this before I got your recent email. What you just emailed me is running now.


Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 2/26/17
Scan Time: 3:15 PM
Logfile: Threats thru Malwarebytes Premium Trial 3.0.6.txt
Administrator: Yes

-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.50
Update Package Version: 1.0.1366
License: Trial

-System Information-
OS: Windows 10
CPU: x64
File System: NTFS
User: DESKTOP-C3LJ1S9\WeBJa

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 436008
Time Elapsed: 4 min, 25 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 14
PUP.Optional.Yontoo, HKLM\SOFTWARE\CLASSES\APPID\{4031DB0C-B05E-43BD-AC1B-E1F4D5DA0516}, No Action By User, [71], [169896],1.0.1366
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{4031DB0C-B05E-43BD-AC1B-E1F4D5DA0516}, No Action By User, [71], [169896],1.0.1366
PUP.Optional.Yontoo, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{4031db0c-b05e-43bd-ac1b-e1f4d5da0516}, No Action By User, [71], [169896],1.0.1366
PUP.Optional.Yontoo, HKLM\SOFTWARE\CLASSES\APPID\{AB25D3C2-9787-4788-99A1-32A4C1208C11}, No Action By User, [71], [169897],1.0.1366
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{AB25D3C2-9787-4788-99A1-32A4C1208C11}, No Action By User, [71], [169897],1.0.1366
PUP.Optional.Yontoo, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{ab25d3c2-9787-4788-99a1-32a4c1208c11}, No Action By User, [71], [169897],1.0.1366
PUP.Optional.FindWide, HKLM\SOFTWARE\CLASSES\INTERFACE\{0FEB2313-F89B-4AC6-8153-84025604A06A}, No Action By User, [10497], [169193],1.0.1366
PUP.Optional.FindWide, HKU\S-1-5-21-4201248277-1795005648-1735687875-1001_Classes\INTERFACE\{0FEB2313-F89B-4AC6-8153-84025604A06A}, No Action By User, [10497], [169193],1.0.1366
PUP.Optional.FindWide, HKLM\SOFTWARE\CLASSES\CLSID\{0FEB2313-F89B-4AC6-8153-84025604A06A}, No Action By User, [10497], [169193],1.0.1366
PUP.Optional.TidyNetwork, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72A6AB0F-2FA8-4C73-9FCB-1E62A608F001}, No Action By User, [702], [168908],1.0.1366
PUP.Optional.Yontoo, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Mgr SearchWebKnow, No Action By User, [71], [181856],1.0.1366
PUP.Optional.Yontoo, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Service Mgr SearchWebKnow, No Action By User, [71], [255242],1.0.1366
PUP.Optional.TNT, HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72A6AB0F-2FA8-4C73-9FCB-1E62A608F001}, No Action By User, [17700], [244084],1.0.1366
PUP.Optional.TidyNetwork, HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\DRAGDROP\{70BC1CDB-0744-4172-BDA0-B5A487D00C3A}, No Action By User, [702], [244064],1.0.1366

Registry Value: 4
PUP.Optional.Yontoo, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Service Mgr SearchWebKnow|IMAGEPATH, No Action By User, [71], [255242],1.0.1366
PUP.Optional.TNT, HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72A6AB0F-2FA8-4C73-9FCB-1E62A608F001}|APPNAME, No Action By User, [17700], [244084],1.0.1366
PUP.Optional.NotChromeRun, HKU\S-1-5-21-4201248277-1795005648-1735687875-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GOOGLECHROMEAUTOLAUNCH_B359FA29F7970D510D6C3E4303CFE001, No Action By User, [17335], [241243],1.0.1366
PUP.Optional.TNT2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{3C7ACBD7-5301-43CF-84C5-EC44F3D3CB73}, No Action By User, [1892], [257587],1.0.1366

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 4
PUP.Optional.Yontoo, C:\Program Files (x86)\Common Files\219d5106-5a99-41fd-b942-db6b503b0178\updater, No Action By User, [71], [181856],1.0.1366
PUP.Optional.Yontoo, C:\PROGRAM FILES (X86)\COMMON FILES\219D5106-5A99-41FD-B942-DB6B503B0178, No Action By User, [71], [181856],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\USERS\WEBJA\APPDATA\LOCAL\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}, No Action By User, [117], [302717],1.0.1366

File: 19
PUP.Optional.Yontoo, C:\PROGRAMDATA\NTUSER.POL, No Action By User, [71], [-1],0.0.0
PUP.Optional.Yontoo, C:\WINDOWS\SYSTEM32\GROUPPOLICY\MACHINE\REGISTRY.POL, No Action By User, [71], [-1],0.0.0
PUP.Optional.Yontoo, C:\Program Files (x86)\Common Files\219d5106-5a99-41fd-b942-db6b503b0178\updater.exe, No Action By User, [71], [181856],1.0.1366
PUP.Optional.WinYahoo, C:\USERS\WEBJA\APPDATA\LOCAL\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HOWTOREMOVE\HOWTOREMOVE.HTML, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\chromium-min.jpg, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\control panel-min-min.JPG, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\down.png, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\ff menu.JPG, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\ff search engine-min.png, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\hp-min ff.png, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\hp-min ie.png, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\search engine.gif, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\setup pages.gif, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\sp-min.png, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\start-min.jpg, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\HowToRemove\up.png, No Action By User, [117], [302717],1.0.1366
PUP.Optional.WinYahoo, C:\Users\WeBJa\AppData\Local\{49F57FA9-6D5D-1311-00C5-36F924ADCA61}\core, No Action By User, [117], [302717],1.0.1366
PUP.Optional.Yontoo.ChrPRST, C:\USERS\WEBJA\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_searchwebknow-a.akamaihd.net_0.localstorage-journal, No Action By User, [65], [256452],1.0.1366
PUP.Optional.Palikan, C:\USERS\WEBJA\APPDATA\LOCALLOW\MICROSOFT\INTERNET EXPLORER\SERVICES\PALIKAN.ICO, No Action By User, [2043], [255721],1.0.1366

Physical Sector: 0
(No malicious items detected)


(end)


Report •

#15
February 26, 2017 at 15:47:22
Couldn't figure out to actually run the program after I did the settings so I went back to 'dashboard' and said run. It's only 2 minutes in now. We'll see if I get anything since I had just done it and got 15, I think.

Jeanine


Report •

#16
February 26, 2017 at 16:11:18

File System: 4

Successfully deleted: C:\Users\WeBJa\AppData\Local\befrugal (Folder)
Successfully deleted: C:\Users\WeBJa\AppData\Roaming\Mozilla\Firefox\Profiles\components\yahoo-search.xml (File)
Successfully deleted: C:\WINDOWS\system32\Tasks\PCDEventLauncherTask (Task)
Successfully deleted: C:\WINDOWS\system32\Tasks\PCDoctorBackgroundMonitorTask (Task)

Registry: 4

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{ADCE716D-5705-4D63-8CBB-FA742E832A60} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{25F68CC8-E760-4556-A000-F62EB44ACAAB} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet

Explorer\Toolbar\\{ADCE716D-5705-4D63-8CBB-FA742E832A60} (Registry Value)

Here's the JRT below


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 02/26/2017 at 16:08:57.36
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Report •

#17
February 26, 2017 at 16:23:58
OK then maybe it's a better result than I assumed. By the way, beware of things like PC Doctor - even if they are not scams they can often cause more problems than they fix.

We can leave it at that but if you want to ensure your computer is properly clean then let us know and I'll contact another helper who specialises in that sort of thing. If available he would probably take you through a number of additional programs.

Always pop back and let us know the outcome - thanks


Report •

#18
February 26, 2017 at 17:07:39
Thanks again for your assistance.

Report •

Ask Question