Solved Why can't we get IE to work?

January 9, 2015 at 10:05:42
Specs: Windows 8, Intel 3.4 (?)/ 6gB
For the last 4-5 days, my bf has not been able to get Internet Explorer to work on his PC. I checked his connection to my router - seems to be fine. We unplugged the router, then plugged it in again. Virus scan shows no problems. When he tries to get on a website, a tab opens and it says it is "waiting for [the website name]". He doesn't have any other browser loaded, so without IE, he can't get on the web at all. Can someone help?

Carolyn


See More: Why cant we get IE to work?

Report •

✔ Best Answer
January 15, 2015 at 13:52:03
Ok Carolyn, here is how you got into this mess.

As you can see from your logs, you had a lot of stuff installed, that you do not know, how it got installed.
A lot of programs, now give you the choice to install toolbars & other during the install. Either uncheck these items during install, or use Custom install. No more click, click during an install, you have to read after each click.

WARNING: CNET Download.com downloads now come bundled with opt-out crapware and toolbars ( Same applies to Softonic & Brothersoft )
http://www.groovypost.com/unplugged...

I use Softpedia & FreewareFiles.com, down the bottom of the page, they make you aware what Ad-supported programs the author of the program has included.
http://www.freewarefiles.com/new_fi...
Sample pages
http://www.softpedia.com/get/CD-DVD...
First and foremost, extra attention needs to be paid during installation as ImgBurn offers to create desktop shortcuts to third-party apps, as well as install a browser toolbar onto the host computer, which are not required to ensure the smooth running of the app.
SS of above.
http://i.imgur.com/jgGYNsP.gif
This is what ImgBurn tries to install.
http://i.imgur.com/ms4DzE9.gif
http://i.imgur.com/vVkd39a.gif
http://i.imgur.com/rqFVaHs.gif
http://i.imgur.com/sm1T7h6.gif
http://i.imgur.com/vhkKLYo.gif

Use Unchecky to help prevent these third party installs. Nothing is perfect, the badies are always ahead of the goodies, so be vigilant.
http://www.softpedia.com/get/System...
http://unchecky.com/
A reliable application that aims to protect your computer against third-party components often offered during software installations.

message edited by Johnw



#1
January 9, 2015 at 10:14:26
"He doesn't have any other browser loaded"

Why not? You'll need it to troubleshoot. If he's unable to download, use another computer, download Firefox (or Google Chrome) onto a USB flash drive, then install to his computer & see if it works.

http://filehippo.com/download_firef...


Report •

#2
January 9, 2015 at 13:05:23
Yep, good idea to temporarily try another browser. If that works then try IE Reset:
Tools > Internet Options > Advanced > Reset button. Your favorites will be retained but you will lose customizations (if any) and add-ons. Add-ons come back quite quickly with usage.

Always pop back and let us know the outcome - thanks


Report •

#3
January 9, 2015 at 18:19:47
OK, I downloaded Google Chrome onto my PC, made a copy of it, and installed it onto his PC. It's not working. I typed "mail.google.com" into the address bar, and all I get is "waiting for mail.google.com" at the bottom of the screen. That's the only thing on the screen.

Carolyn


Report •

Related Solutions

#4
January 9, 2015 at 22:03:29
Make sure there is no proxy set in the browser. Click tools, internet options, Connections tab, at the bottom Lan settings, make sure use a proxy is not selected. It is usually set to "auto detect settings" the top choice or nothing is checked at all. If there is any kind of proxy remove it. Close IE, and then re open it, see if that helps. Chrome will often use the system default settings, (IE's connection setting), so if IE does have a proxy in it, that explains why Chrome also does not work. Did it just stop working one day, or was he having other problems?


To err is human but to really screw things up, you need a computer!

message edited by HopperRox


Report •

#5
January 9, 2015 at 23:31:41
What Antivirus do you use and has it a firewall incorporated?

Always pop back and let us know the outcome - thanks


Report •

#6
January 10, 2015 at 16:11:24
Download Malwarebytes free version and transfer that over also to his machine. Install it (uncheck free trial during install), update it if possible, and run it. If it updates then there is a connection there and it will check for malware that your antivirus is missing to be sure that is not the problem.

You have to be a little bit crazy to keep you from going insane.


Report •

#7
January 11, 2015 at 09:12:03
AT&T Internet Security Suite powered by McAfee.

Carolyn

message edited by cweimer59


Report •

#8
January 11, 2015 at 10:08:58
Lets see what MalwareBytes shows up first. If it finds anything please copy/paste the log on here.

Otherwise temporarily disable McAfee firewall then try just that website only and let us know what happens. Put the firewall back on again afterwards.

Always pop back and let us know the outcome - thanks


Report •

#9
January 11, 2015 at 16:23:32

i can't get MalwareBytes downloaded onto his PC. Yesterday I loaded Chrome on a disc, but I don't remember how I did it. Today's download is on a flashdrive, and I don't really know what I'm doing. Let's get this fixed, then I'll try the original problem. :-)

Carolyn


Report •

#10
January 11, 2015 at 16:36:43
If you have the file on a flash drive then just copy it across to the PC with the problem (anywhere that you will be able to find it afterwards). Go to the file, double click it and MalwareBytes should install. If so it should produce an Icon.

If you find that tricky pop-in the flash drive, go to "Computer", find the flash drive, double click it to open it, then finally double click the downloaded file you see on the flash drive.

Double click the icon that arrives and run the Scan.

Please copypaste the log on here if it finds anything. You can then run the Clean if you wish.

If anything should go wrong, or not work, let us know what happened and at what stage. The reason for saying this is that some viruses will try to prevent you installing MalwareBytes.

EDIT:
I should have asked is the PC with the issues also Win8?

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#11
January 12, 2015 at 07:41:14
My PC is Windows 7; his is Win 8. I put the flash drive in, double-clicked on "Computer', then "Removable Drive E", then "Malwarebytes Anti-Malware". 25 files showed up. I double-clicked on the one that had an icon next to it: mbam.exe, clicked "yes" on the User Control page and nothing happened. I copied the icon to the desktop, double-clicked on it, and got a message about "this program can't load because mbam.dll is missing from your computer." I'm ready to take this PC to the shop.

Carolyn


Report •

#12
January 12, 2015 at 09:01:57
No No, that's not a problem with your computer. Just a bit of finger trouble

Somehow you have the all of the program files on the flash drive (rather than just the one downloaded file).

Have another go.
First delete all the files on the flash drive. On the working PC go to the MalwareBytes website and "Save" the download rather than running it. Find the single file you have downloaded on your computer (mbam-setup) then copy that onto the flash drive.

With the flash drive plugged into the computer with problem, find the flash drive, open it and double click the downloaded file inside it. This should then install MWB but keep the flash drive in place until you are sure it has finish. If for some weird reason it doesn't install then use the more messy first paragraph of my #10 instead.

Unless some virus prevents it running you should be OK this time.

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#13
January 12, 2015 at 17:00:16
Thank you so much, Derek! I got Malwarebytes to load and after I quarantined the threats it found, IE started, though a little slow. I appreciate all the help!

Carolyn


Report •

#14
January 12, 2015 at 17:03:49
"I got Malwarebytes to load and after I quarantined the threats it found, IE started, though a little slow"
You will not be clean yet, Copy & Paste the contents of the log in your next post please cweimer59

Report •

#15
January 13, 2015 at 01:11:24
Yes indeed - run with John or problems could come along again.

Always pop back and let us know the outcome - thanks


Report •

#16
January 13, 2015 at 14:02:25
file:///C:/Users/Carolyn/Desktop/Malware%20scan_1.xml

message edited by cweimer59


Report •

#17
January 13, 2015 at 14:08:55
Thanks cweimer59, but we can't see into your comp.

If you misplace your log, here are ways to find.
http://i.imgur.com/U9IqcVj.gif
http://i.imgur.com/zHMG6J9.gif
http://i.imgur.com/ZZ1trsv.gif
http://i.imgur.com/LL0K3qs.gif
Or,
(Export log to save as txt)
After the restart once you are back at your desktop, open MBAM once more.
Click on the History tab > Application Logs.
Double click on the scan log which shows the Date and time of the scan just performed.
Click 'Export'.
Click 'Text file (*.txt)'
In the Save File dialog box which appears, click on Desktop.
In the File name: box type a name for your scan log.
A message box named 'File Saved' should appear stating "Your file has been successfully exported".
Click Ok
http://i.imgur.com/LNl3Sgw.gif
http://i.imgur.com/xGJgawB.gif


Report •

#18
January 14, 2015 at 10:14:56
There was nothing in the first scan log I did on 1/12. So I restored all the threats from quarantine and ran another scan, There were 2 malicious items and 3773 (that's not a typo) non-malware items detected. I followed directions for saving as .txt file, but there doesn't seem to be anything in it, again.

Malwarebytes Anti-Malware
www.malwarebytes.org

Carolyn


Report •

#19
January 14, 2015 at 12:33:21
Ok Carolyn, lets have a look with these,

Here are the first 2 steps, there will be more steps needed after I see the results of these logs.

Run them in this order.

Step 1: Run AdwCleaner
http://www.softpedia.com/get/Antivi...
http://www.raymond.cc/blog/adwclean...
http://www.bleepingcomputer.com/dow...
Author's site
http://general-changelog-team.fr/en...
Tutorial
http://general-changelog-team.fr/en...
Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Clean.
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please Copy & Paste the contents of that logfile with your next answer.
You can find the logfile at C:\AdwCleaner[S1].txt as well.

Step 2: Run Junkware Removal Tool
http://www.softpedia.com/get/Securi...
http://www.bleepingcomputer.com/dow...
http://thisisudax.blogspot.com.au/2...
Download Junkware Removal Tool onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Warning! Once the scan is complete JRT will shut down your browser with NO warning.
Shut down your protection software now to avoid potential conflicts.
Temporarily disable your antivirus and any antispyware real time protection before performing a scan.
Click this link to see a list of security programs that should be disabled and how to disable them.
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
Run the tool by double-clicking it. If you are using Windows Vista or Windows 7/8, right-click JRT and select Run as Administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved onto your Desktop and will automatically open.
Copy and Paste the contents of the JRT.txt log please.

message edited by Johnw


Report •

#20
January 14, 2015 at 20:16:22
OK John, first I ran the malware scan again to see if the log turned out any better. It didn't, but the items are all quarantined now.
Second, the AdwCleaner wouldn't let me Clean until I ran Scan. The log from that one:

# AdwCleaner v4.107 - Report created 14/01/2015 at 22:51:58
# Updated 07/01/2015 by Xplode
# Database : 2015-01-13.2 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : maddog - KENF1947
# Running from : C:\Users\maddog\Desktop\adwcleaner_4.107 - Copy.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : YahooAUService
Service Deleted : CouponPrinterService

***** [ Files / Folders ] *****

Folder Deleted : C:\SearchDonkey
Folder Deleted : C:\ProgramData\Browser
Folder Deleted : C:\ProgramData\PC Optimizer Pro
Folder Deleted : C:\ProgramData\WinSpeed
Folder Deleted : C:\ProgramData\driver whiz
Folder Deleted : C:\ProgramData\Yahoo! Companion
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
Folder Deleted : C:\Program Files (x86)\Amazon\ABB
Folder Deleted : C:\Program Files (x86)\Easy Speed Check
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Probit Software
Folder Deleted : C:\Program Files (x86)\StormWatch
Folder Deleted : C:\Program Files (x86)\Coupons
Folder Deleted : C:\Program Files (x86)\gmsd_us_63
Folder Deleted : C:\Users\maddog\AppData\Local\globalUpdate
Folder Deleted : C:\Users\maddog\AppData\Local\iac
Folder Deleted : C:\Users\maddog\AppData\Local\visi_coupon
Folder Deleted : C:\Users\maddog\AppData\Local\speed browser
Folder Deleted : C:\Users\maddog\AppData\Local\SmartWeb
Folder Deleted : C:\Users\maddog\AppData\Local\gmsd_us_63
Folder Deleted : C:\Users\maddog\AppData\LocalLow\iac
Folder Deleted : C:\Users\maddog\AppData\LocalLow\mystarttb
Folder Deleted : C:\Users\maddog\AppData\LocalLow\visi_coupon
Folder Deleted : C:\Users\maddog\AppData\LocalLow\SmartWeb
Folder Deleted : C:\Users\maddog\AppData\LocalLow\YahooCouponAddOn
Folder Deleted : C:\Users\maddog\AppData\LocalLow\Yahoo! Companion
Folder Deleted : C:\Users\maddog\AppData\Roaming\AnyProtectEx
Folder Deleted : C:\Users\maddog\AppData\Roaming\Probit Software
Folder Deleted : C:\Users\maddog\AppData\Roaming\Systweak
Folder Deleted : C:\Users\maddog\AppData\Roaming\KeepMySettingsX
File Deleted : C:\WINDOWS\System32\roboot64.exe

***** [ Scheduled Tasks ] *****

Task Deleted : APSnotifierPP1
Task Deleted : APSnotifierPP2
Task Deleted : APSnotifierPP3
Task Deleted : LaunchSignup
Task Deleted : SmartWeb Upgrade Trigger Task

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ToolbarProtector
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ToolbarProtector.1
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [EasySpeedCheck]
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3719959C-1CCD-4FA7-8EBB-7D9DED86FCCB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{37923200-6887-4B44-95D4-CAE8F83ECFEE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607B689F-7600-45E4-B8E5-887F72DAB15C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{900625B6-F89A-40E3-AEE1-3A9A5E8723A7}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{CA021789-C8CD-4676-BC40-90077A19D5CD}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607B689F-7600-45E4-B8E5-887F72DAB15C}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{900625B6-F89A-40E3-AEE1-3A9A5E8723A7}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
Key Deleted : HKCU\Software\AnyProtect
Key Deleted : HKCU\Software\Boxore
Key Deleted : HKCU\Software\Compete
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Microsoft\KanarCore
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\pc optimizer pro
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\Tutorials
Key Deleted : HKCU\Software\Easy Speed Check
Key Deleted : HKCU\Software\GAMESDESKTOP
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\SmartWeb
Key Deleted : HKCU\Software\AppDataLow\Software\TheBestDeals
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\CompeteInc
Key Deleted : HKLM\SOFTWARE\Email Notifier
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\NpApp
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\Tutorials
Key Deleted : HKLM\SOFTWARE\FastPlayer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows5.0.0.9
Key Deleted : [x64] HKLM\SOFTWARE\AVG Secure Search
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~3\WinSpeed\WINSPE~1.DLL
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftwareUpdate.exe
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\home.tb.ask.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ib.adnxs.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nym1.ib.adnxs.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.tb.ask.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\trovi.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.ask.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.trovi.com

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Google Chrome v39.0.2171.95

[C:\Users\maddog\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\maddog\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\maddog\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AFA^xdm068^YYA^us&si=137158XXX30341&ptb=0B0D8B2A-FF46-4508-BAD5-98BC49F8632A&ind=2014100317&n=780cbb5d&psa=&st=sb&searchfor={searchTerms}
[C:\Users\maddog\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystart.com/results.php?gen=ms&pr=vmn&id=mystarttb&v=5_4&ent=ch_5108&q={searchTerms}
[C:\Users\maddog\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3330394&octid=EB_ORIGINAL_CTID&ISID=MC44258A6-D161-4AB0-A7C8-E9F0987979B7&SearchSource=58&CUI=&UM=6&UP=SPB0F9A48F-C681-4D37-B32E-8E58A191B769&q={searchTerms}&SSPV=
[C:\Users\maddog\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3330394&octid=EB_ORIGINAL_CTID&ISID=MC44258A6-D161-4AB0-A7C8-E9F0987979B7&SearchSource=58&CUI=&UM=6&UP=SPB0F9A48F-C681-4D37-B32E-8E58A191B769&q={searchTerms}&SSPV=

*************************

AdwCleaner[R0].txt - [17156 octets] - [14/01/2015 22:50:42]
AdwCleaner[S0].txt - [16244 octets] - [14/01/2015 22:51:58]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16305 octets] ##########

Carolyn


Report •

#21
January 14, 2015 at 20:26:21
Ok Carolyn, stay online, I will have some work for you, once I get the next log.

Report •

#22
January 14, 2015 at 20:41:55
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 8.1 x64
Ran by maddog on Wed 01/14/2015 at 23:37:56.82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~ Services

Successfully stopped: [Service] couponxplorer_5zservice
Successfully deleted: [Service] couponxplorer_5zservice
Successfully stopped: [Service] packagetracer_69service
Successfully deleted: [Service] packagetracer_69service

~~~ Registry Values

~~~ Registry Keys

~~~ Files

Successfully deleted: [File] "C:\WINDOWS\couponprinter.ocx"
Successfully deleted: [File] C:\WINDOWS\prefetch\DRIVERUPDATE.EXE-7973A8B6.pf
Successfully deleted: [File] C:\WINDOWS\prefetch\DRIVERWHIZ.EXE-A5FC22B6.pf
Successfully deleted: [File] C:\WINDOWS\prefetch\SPEEDUPMYPC.TMP-05439281.pf

~~~ Folders

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 01/14/2015 at 23:39:45.53
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Carolyn


Report •

#23
January 14, 2015 at 20:44:50
Run RogueKiller
http://www.softpedia.com/get/Securi...
http://majorgeeks.com/RogueKiller_d...
http://www.geekstogo.com/forum/file...
http://tigzy.geekstogo.com/roguekil...
http://www.sur-la-toile.com/RogueKi...
User Guide
http://www.adlice.com/softwares/rog...
Official tutorial
http://www.adlice.com/softwares/rog...
How to Temporarily Disable your Anti-virus
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
If RogueKiller won't run, open IE & turn off SmartScreen Filter.
http://windows.microsoft.com/en-AU/...
Download & SAVE to your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Quit all programs that you may have started.
Shutdown your antivirus to avoid any conflicts.
Please disconnect any USB or external drives from the computer before you run this scan!
For Vista or Windows 7/8, right-click and select "Run as Administrator to start"

For Windows XP, double-click to start.
Wait until Prescan has finished ...
Then Click on "Scan" button
Wait until the Status box shows "Scan Finished"
Click on "Delete"
Wait until the Status box shows "Deleting Finished"
Click on "Report" and Copy & Paste the content of the Notepad into your next reply.
The log should be found in RKreport[1].txt on your Desktop.
Exit/Close RogueKiller.
When completed make sure to re-enable your antivirus.

Report •

#24
January 14, 2015 at 21:42:17
I tried to download this from the tigzy list, and now I have a whole bunch of unwanted downloads. i'm exhausted. can we pick up tomorrow/

Carolyn


Report •

#25
January 14, 2015 at 21:57:13
" can we pick up tomorrow
Yep, not a problem.

I'm here.
http://www.timeanddate.com/worldclo...

message edited by Johnw


Report •

#26
January 15, 2015 at 08:28:28
John, I am having trouble with RogueKiller. I'm not going to try downloading it any more. Since getting on the PC this morning, I hsve run Malware twice, tried to reinstall Chrome, downloaded and installed Firefox, and had to unplug my router because I lost the connection. IE appears to be working, so I'm going to take a break from this. Thanks for all your help.

Carolyn


Report •

#27
January 15, 2015 at 13:52:03
✔ Best Answer
Ok Carolyn, here is how you got into this mess.

As you can see from your logs, you had a lot of stuff installed, that you do not know, how it got installed.
A lot of programs, now give you the choice to install toolbars & other during the install. Either uncheck these items during install, or use Custom install. No more click, click during an install, you have to read after each click.

WARNING: CNET Download.com downloads now come bundled with opt-out crapware and toolbars ( Same applies to Softonic & Brothersoft )
http://www.groovypost.com/unplugged...

I use Softpedia & FreewareFiles.com, down the bottom of the page, they make you aware what Ad-supported programs the author of the program has included.
http://www.freewarefiles.com/new_fi...
Sample pages
http://www.softpedia.com/get/CD-DVD...
First and foremost, extra attention needs to be paid during installation as ImgBurn offers to create desktop shortcuts to third-party apps, as well as install a browser toolbar onto the host computer, which are not required to ensure the smooth running of the app.
SS of above.
http://i.imgur.com/jgGYNsP.gif
This is what ImgBurn tries to install.
http://i.imgur.com/ms4DzE9.gif
http://i.imgur.com/vVkd39a.gif
http://i.imgur.com/rqFVaHs.gif
http://i.imgur.com/sm1T7h6.gif
http://i.imgur.com/vhkKLYo.gif

Use Unchecky to help prevent these third party installs. Nothing is perfect, the badies are always ahead of the goodies, so be vigilant.
http://www.softpedia.com/get/System...
http://unchecky.com/
A reliable application that aims to protect your computer against third-party components often offered during software installations.

message edited by Johnw


Report •

Ask Question