google redirecting/hijacking

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ezzaray, Dec 10, 2014.

  1. ezzaray

    ezzaray Private E-2

    Hi I have gone through the steps that we outlined for google redirecting thread. Clearing the cache for all the browser, clearing the DNS, rebooting the modem. I also ran TDSSkiller. I have now ran roguekiller and have a print screen that I will attach. I am a new user but have made sure I have read all the information before I posted anything. Also I ran roguekiller and it froze at 80%. So I booted the computer in safe mode with networking and it did a full scan. I hope that is ok. Please let me know if I have not fulfilled my end of the process, or if I'm not attaching things properly. Thank you sooo much for you help and patience.
     

    Attached Files:

  2. ezzaray

    ezzaray Private E-2

    I worked out how to get a report from Roguekiller and I have attached it hope that is ok?
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You ran the procedure in the below link:

    Fixing Google Redirection/hijacking and other redirection problems

    See the last step which boldly stated the below
    Thus you need to run the READ & RUN ME FIRST if you are still having problems. ;)
     
  4. ezzaray

    ezzaray Private E-2

    thankyou. I thought I would do the whole process again to make sure I had done them properly. I'm hoping all I have to post is the TDSSKiller that found no threats, and the MBR report. Thankyou for you patience.:-o
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes as stated! Basically when you went off to the the Google Hijacker fix, it returns you back to the READ & RUN ME to continue with the rest of the READ & RUN ME at the point after doing the Google Hijacker procedure which you clearly do not need anymore. ;)
     
  7. ezzaray

    ezzaray Private E-2

    Ok I have done that. What is next?
    :)
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you've done that then please attach the requested logs. (Apart from RogueKiller as you've already done that one)
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ... as our guide states -
     
  10. ezzaray

    ezzaray Private E-2

    oh thankyou, I thought I had to hear back after every attachment. I'm on to it. Cheers
     
  11. ezzaray

    ezzaray Private E-2

    I have done the malwarebytes scan and attached log. cheers
     

    Attached Files:

  12. ezzaray

    ezzaray Private E-2

    Also restarted computer for the next step I'm going to do. :)
     
  13. ezzaray

    ezzaray Private E-2

    I've done a Hitman Pro scan, and only a scan. It says that the file is too big to upload. What should I do?:-o
     
  14. ezzaray

    ezzaray Private E-2

    I have also encountered a popup window that not sure what to do I have attached a print screen. Cheers
     

    Attached Files:

  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Send the HitmanPro log to a Compressed (Zipped) archive and attach it with all of the remaining requested logs.

    You must Agree to the TrendMicro License twice for the program to be installed and ran.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not the log from the scan. This is an active protection log! We need the log from the scan.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes as stated in the READ & RUN ME FIRST instructions for Using MGtools. ;)
     
  18. ezzaray

    ezzaray Private E-2

    Thankyou. When I did the scan, I came back to the computer with this screen I have attached. It didn't ask me to quarantine the items it just automatically quarantined them. There was no export log, like the example you have. How do I get that log now?
     

    Attached Files:

  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *If you have closed that window, follow the below steps.

    Now right click the Malwarebytes' shortcut icon and choose "Run as administrator"
    • Click on the History tab
    • On the left side options -choose "Application Logs"
    • In the middle pane - put a checkmark in the box next to the latest Scan Log and click the View button
    • At the bottom left corner, click on the Export button and select "Text file(*.txt)"
    • Save the log to your desktop and attach it to your next reply.
     
  20. ezzaray

    ezzaray Private E-2

    Thankyou sooo much!!!!!!! I have now hopefully done the required steps with all the information I will be attaching right now. Let me know if there is more required of me. It wont let me re attach rogue killer report as I have already attached it previously. Thankyou very much.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Working on a fix now! You appear to be what we call "A Junkware Collector" You need to be more careful/selective on what you are allowing to be downloaded on your PC. There is so much junk that it would take too long to make a complete fix so we may have to run things in stages and hope that some of the steps seriously cut down on the junk.
     
    Last edited: Dec 13, 2014
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please rmove MGtools.exe from the below location as it is not a document and it is not where we asked you to save. Thus when we get to final cleanup instructions, they would not work. You don't need this file anymore so just delete it.

    C:\Users\john\Documents\MGtools.exe



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?typ...id=HGSTXHTS541075A9E680_JA120011G5N2RPG5N2RPX
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com...7DC1A8FF78650EC8FE6526671F623403&st=chrome&q=
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com...7DC1A8FF78650EC8FE6526671F623403&st=chrome&q=
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com...7DC1A8FF78650EC8FE6526671F623403&st=chrome&q=
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?typ...id=HGSTXHTS541075A9E680_JA120011G5N2RPG5N2RPX
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com...7DC1A8FF78650EC8FE6526671F623403&st=chrome&q=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com...7DC1A8FF78650EC8FE6526671F623403&st=chrome&q=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com...7DC1A8FF78650EC8FE6526671F623403&st=chrome&q=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com...7DC1A8FF78650EC8FE6526671F623403&st=chrome&q=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com...7DC1A8FF78650EC8FE6526671F623403&st=chrome&q=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.certified-toolbar.com...6981774-7DC1A8FF78650EC8FE6526671F623403&q=%s
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.certified-toolbar.com...6981774-7DC1A8FF78650EC8FE6526671F623403&q=%s
    O2 - BHO: Rad Rater 1.0.0.5 - {316cdecf-3a39-4fac-b224-29059a0fe5a7} - C:\Program Files (x86)\Rad Rater\RadRaterBHO.dll (file missing)
    O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (file missing)
    O2 - BHO: WordProser - {3EBB5099-9732-48AE-B032-58B702D86EEC} - C:\Program Files (x86)\WordProser_1.10.0.2\IE\WordProserClientIE.dll (file missing)
    O2 - BHO: Search App by Ask BHO - {4F524A2D-5350-4500-76A7-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll" (file missing)
    O2 - BHO: HomeTab - {56e32636-e2b8-4b04-9a97-60581dd90f51} - C:\Program Files (x86)\HomeTab\IE\HomeTab.dll
    O2 - BHO: BlockAndSurf - {7AAEFC9B-5EFA-08C7-A58D-371D4FFAF457} - C:\Program Files (x86)\ver5BlockAndSurf\184.dll (file missing)
    O3 - Toolbar: Search App by Ask - {4F524A2D-5350-4500-76A7-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll" (file missing)
    O3 - Toolbar: HomeTab - {56e32636-e2b8-4b04-9a97-60581dd90f51} - C:\Program Files (x86)\HomeTab\IE\HomeTab.dll
    O4 - HKLM\..\Run: [ConvertAd] C:\Users\john\AppData\Local\ConvertAd\ConvertAd.exe
    O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1418343120


    After clicking Fix, exit HJT.


    Now uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    AnyProtect
    BlockAndSurf
    ConvertAd
    HomeTab 7.2
    Remote Desktop Access (VuuPC)
    Search App by Ask
    webssearches uninstall
    WindowsMangerProtect20.0.0.1270
    Word Proser 1.10.0.2



    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    
    :Services
    gupdate
    gupdatem
    servervo
    SupraSavingsService64
    Update Rad Rater
    WindowsMangerProtect
    
     
    :Files
    C:\Users\john\AppData\Roaming\sp_data.sys
    C:\Users\john\Desktop\AnyProtect.lnk
    C:\Users\john\Desktop\MGtools - Shortcut.lnk
    C:\Program Files (x86)\3197DA9B-E2A5-4EA4-BC1D-62E7F33E1011
    C:\ProgramData\44fa52db-e405-4860-9675-591a035762d0
    C:\ProgramData\APN
    C:\ProgramData\AskPartnerNetwork
    C:\ProgramData\IePluginServices
    C:\ProgramData\WindowsMangerProtect
    C:\Program Files\WordProser_1.10.0.2
    C:\Program Files (x86)\AnyProtectEx
    C:\Program Files (x86)\AskPartnerNetwork
    C:\Program Files (x86)\HomeTab
    C:\Program Files (x86)\mbot_au_101
    C:\Program Files (x86)\MyPC Backup
    C:\Program Files (x86)\predm
    C:\Program Files (x86)\Rad Rater
    C:\Program Files (x86)\SupTab
    C:\Program Files (x86)\ver5BlockAndSurf
    C:\Users\john\AppData\Roaming\SimplyTech
    C:\Windows\System32\Tasks\Browser Updater
    C:\Windows\System32\Tasks\SystemSockets
    C:\Windows\System32\Tasks\ProtectedSearch
    C:\Users\john\AppData\Roaming\smileyswelove
    C:\Users\john\AppData\LocalLow\HomeTab
    C:\Users\john\AppData\Roaming\VOPackage
    C:\Users\john\AppData\Local\ConvertAd
    C:\Program Files (x86)\Optimizer Pro
    C:\ProgramData\Systweak
    C:\Users\john\AppData\Local\AskPartnerNetwork
    C:\Users\john\AppData\Roaming\webssearches
    C:\Windows\system32\drivers\wpnfd_1_10_0_2.sys
    C:\Windows\system32\drivers\{3fb64001-af43-4182-bfc8-11e1fee2385f}Gw64.sys
    C:\Windows\System32\Drivers\{578b4215-f29d-44b8-9b3f-ddf8690c8780}Gw64.sys
    C:\Windows\system32\drivers\{62b23f4d-1a77-4dc0-a311-9d8c70e16633}Gw64.sys
    C:\Windows\system32\drivers\{6a0c272b-67e5-4617-9812-522d12a42d7a}Gw64.sys
    C:\Windows\system32\drivers\{6ae56b3b-b4e1-47bb-8719-04f47e9feb4d}Gw64.sys
    C:\Windows\system32\drivers\{978113af-a056-42ab-90c7-cedc7e260032}Gw64.sys
    C:\Windows\system32\drivers\{bb4259be-1910-4ae0-ab31-9666aeec23b3}Gw64.sys
    C:\Windows\system32\drivers\{ce0cf332-28d5-4271-a744-1eb0f7704cf4}Gw64.sys
    C:\Windows\Temp\*.*
    C:\Users\john\AppData\Local\Temp\*.*
    
    
    
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "Adobe Speed Launcher"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "mbot_au_101"=-
    "ConvertAd"==
    
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "mbot_au_101"=-
    "ConvertAd"=-
    
    [HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\Microsoft\Windows\CurrentVersion\runonce]
    "Adobe Speed Launcher"=-
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SupraSavingsService64
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util Rad Rater
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}]
    [-HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EBB5099-9732-48AE-B032-58B702D86EEC}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EBB5099-9732-48AE-B032-58B702D86EEC}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3EBB5099-9732-48AE-B032-58B702D86EEC}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{03A19B15-6866-4B99-97A7-57F359C40931}]
    [-HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EBB5099-9732-48AE-B032-58B702D86EEC}]
    [-HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EBB5099-9732-48AE-B032-58B702D86EEC}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EBB5099-9732-48AE-B032-58B702D86EEC}]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MaintainerSvc3.37.8493095]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IePluginServices]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WindowsMangerProtect]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\servervo]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{3f068af7-4402-4c2d-86c8-012e5b369fd2}Gw64]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{3fb64001-af43-4182-bfc8-11e1fee2385f}Gw64]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{578b4215-f29d-44b8-9b3f-ddf8690c8780}Gw64]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{62b23f4d-1a77-4dc0-a311-9d8c70e16633}Gw64]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{6a0c272b-67e5-4617-9812-522d12a42d7a}Gw64]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{6ae56b3b-b4e1-47bb-8719-04f47e9feb4d}Gw64]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{bb4259be-1910-4ae0-ab31-9666aeec23b3}Gw64]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{ce0cf332-28d5-4271-a744-1eb0f7704cf4}Gw64]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\APNMCP]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\AskPartnerNetwork]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{BD125908-5F10-409F-9C01-F2207CA18887}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\wtb.Band.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\wtb.Band]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\wtb.NotificationSource.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\wtb.NotificationSource]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\wtb.SourceSinkImpl.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\wtb.SourceSinkImpl]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\wtb.ToolbarInfo.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\wtb.ToolbarInfo]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cfd485f0-96bd-47cd-bb6d-cd7dda95f102}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\Default_Page_URL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\Default_Search_URL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\Search Page]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\Start Page]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProtectedSearch]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SystemSockets]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\06B42F08F6F40FA4F83EA94EF9F03F63]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\06FCEE940712E4B4C8A7362CD8D249A1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\085CE460BADC1D14EA94D8A62E517577]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A5AC497E6BBC8D45BE8AD6619DA8217]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0B2690283E07C9B4085B3B794202E7F7]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12D3738E79C70C74E9D808E162BD6691]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\158D6D9E3FE81fa428925F22ACB3A965]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15E6C514FEFC09f45BAFAAE1D7546ED4]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\189F6D048E923EA48B11D15B30CDAC81]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DB42320A8525634AA089F0BEC86473B]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0968491626AD249A2A6CBAC4DE352D]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22468B0D6050b2e46B9C4B67A8F59577]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2251BF05A2F606d43BB064BD63CBD87E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22A78C977EC431247B2ECECC374DFE13]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2CAC1D959B4188B4F8E8C251A25DA9DB]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3255D95681398614190EDF0A4F3F77DB]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\33990057697C62f47BB9FFD59CB4AEEB]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3CDF313E9B28c944FBC7579CF4949414]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41BF64DDE5C2457478691CB0675759BA]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42F5B13BF4BAD8D409578286A354E360]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4374E71C5355C4B4AACC93BBBF40E99F]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4410C9B6FF0094C418865CD2B243B258]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45B0A4620F799834C82DE0BD4E90E40B]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4859A93046C917F408248F3C16F75E77]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A3D29BA507550f4F87F6F33D42B24D6]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4E28C30B25E21BF4C9418857AEB2AF7C]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50390A9E27AD04A4698BF297EF564973]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D5D3B13CCBA08C479F107E50BD81C8A]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\661134B612233374391C95E8AC373BA3]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71E54748EDD3dc1468548785DC856EDA]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\734F787B99D52824EAB6CA1A89F801F7]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\73A172B6C18A3594A9FA363311A187A3]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\754590DD06DE8d249B526503432F99D4]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A0CF0C6A9F9B8642A392A1896DCCCF2]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE43E6BAE0DC0B43883C669D8DCE8B1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7EC46CC5C43127A45A99762BF7A9C9E5]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFDE7BEC9977ac46B41B0A2BF7D88CD]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8011A895DAAC4CC45AF1397E3CE9CA16]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8036C72171EF4ba46856BF57969F6A36]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\81EE804DA9066C64A859E01A38075C59]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\879DDA62492E58A40898AD146BBB572E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88761D7BAC02ccc428CD5EF352BB933C]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89BB7852687BDC34B9A81E01C7FF9173]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89EA4F1B8FBCDEF47AE328E455E28AA0]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CB53AD495D2C5443B95C9EE29E47902]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CBC85D72B148084ABE8C2F072F781F4]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC5A38A64D6098468BC8395BA0EFF03]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8DF9A1AC557F56c49B56F6B83E293C15]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F85A4D374D5bf245B8722C062C2D00E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9516FC331A505934FA76C22DCFFEC47E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97ECFF59EE08D4F47BB1464DEC37DA87]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A08449608E3Ca1f4ABF236256A256754]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A431C8F3F57D7844B89242F5F7A5F62C]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A66E2D84F93A9E94FBA6AB3524D85958]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8CB937199A57E748B6AC433DA453EE2]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A97C590397DCC454AA8923563BAB10E4]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA27FE018F87f5e4F97F31C09E7C5370]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC049320EE27170499EC0B6124142ED7]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B08932C78B697C244BE7BA3E6FF09B62]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B448F401EF39C8346BF7BE9B8D1C7060]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4E78E12704AFCE408C7FBE501F1AA0A]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5211271DD585A740AA28576B137D09D]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B58469E2C54833741B90BAD9CE5A1159]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B6DA77032731EEE40B463A325128D613]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCC2BCA248E19F74F9AEDE4D1EFEFBC9]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6A54B56C58C82a4688AFB93F42EA17B]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C70C6F53DEE245249956FC291D801A71]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C7C0052DD04CBC84C81C0AC586485E50]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C879DCC3D00BE8E4282F02F1735E78DF]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C9FBD8E8A2691564FA012512BCC3748C]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB3AEBFFA9E907145906294AB669B1F2]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE142BFA81B72674892EB318BD603CB0]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE90A73A5D5A01a43A2EDCCF04BA9487]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CFA51B44D54927c4E9B7BC1D3FD1E49F]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D05B2B3F5629f9d41A7E57FB534168CA]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D14A7F65792054F418578C78367D13F7]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D158B0E5D051EA046B8E08BF6B004842]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D45A81F48EF19334EABB33FF8871C4F5]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D538E650623CB2C43AD5FBF587227D55]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D8D06C15BF8AFCD449EFF90B935AEF7C]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB1AE396B3BBfe940922C55C6EEF740A]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDF89DEE0C7E9A5448382117C4436818]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFE9F0BD163D827438CB6AD6B100EC48]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E55AA93871A0fde4490A708053AC6501]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E954A03F45EC92B419A55A0D4815C0A3]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E97C12D46BF588241856422D760336B4]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EA1332016439DD54C840C7D45CFB2705]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EFBB6B0872B0DBB4D912A0F52986399D]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F0390A76D28822743A68D7F1AB22E6D0]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F739A19A8327dc64C9A8B641A9E89646]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\AskPartnerNetwork]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fjbbjfdilbioabojmcplalojlmdngbjl]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cfd485f0-96bd-47cd-bb6d-cd7dda95f102}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\Default_Page_URL (Webssearches)
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage\ (VOPackage)
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\webssearches uninstall]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MYBESTOFFERSTODAY]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\supTab]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\supWPM]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\systweak]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\webssearchesSoftware]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\{6791A2F3-FC80-475C-A002-C014AF797E9C}]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\APNMCP]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\Registry Helper Service]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\APNMCP]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Registry Helper Service]
    [-HKEY_USERS\.DEFAULT\Software\AppDataLow\Software\Simplytech]
    [-HKEY_USERS\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKEY_USERS\.DEFAULT\Software\AskPartnerNetwork]
    [-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_USERS\S-1-5-18\Software\AppDataLow\Software\Simplytech]
    [-HKEY_USERS\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKEY_USERS\S-1-5-18\Software\AskPartnerNetwork]
    [-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\AppDataLow\Software\Simplytech]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\AskPartnerNetwork]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\Microsoft\Internet Explorer\MAIN\Default_Page_URL (Webssearches)
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\Optimizer Pro]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\Popajar]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\SimplyTech]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\SmileysWeLove]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\systweak]
    [-HKEY_USERS\S-1-5-21-2925710435-3151974224-1744885798-1001\Software\TutoTag]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5865539A-DF34-41D5-871A-9D2EA0E9895B}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
    "Tabs"="res://ieframe.dll/tabswelcome.htm"
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  23. ezzaray

    ezzaray Private E-2

    It only happened when I stupidly clicked on a $500 voucher for KMART. Well I may possibly have downloaded other things, could you give me some preventative processes when your finished trying to fix up my mess. Also would a restore be better? or reinstall windows 8? Thankyou very much.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No and no to both!

    Just follow my instructions and we will get thru this. As you can see the fix is quite long. So let's complete this first stage and hope that it it fixes most of the issues.
     
  25. ezzaray

    ezzaray Private E-2

    I have done the hijackthis scan, and the results I got were all different to the ones I'm to select to fix. I have attached the log.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask for a HijackThis log. Please just follow the instructions given. If you don't find all the items mentioned just select what does exist and continue. Things may have changed after you posted your very first set of logs.
     
  27. ezzaray

    ezzaray Private E-2

    All went well. Thankyou ihave attached the 3 logs. I'm still getting lots of popups and malware bytes keeps blocking popups.
    Cheers Erin
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay round two.

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java 7 Update 51
    Rad Rater

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab

    After clicking Fix, exit HJT.

    Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\john\AppData\Local\nsu3B6.tmp
    C:\Users\john\Documents\rougekiller2.png
    C:\Users\john\Documents\tdsskiller1.png
    C:\Users\john\Documents\tdsskiller2.png
    C:\Users\john\Documents\tdsskiller_recent.png
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\system32\tasks\Browser Updater
    C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore
    C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA
    C:\Windows\system32\tasks\ProtectedSearch
    C:\Windows\system32\tasks\SystemSockets
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "ConvertAd\""=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please run a new scan with Hitman Pro and save a new log to attach.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the Hitman Prolog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    If still having problems, which browser are you running when you have the problem?
     
  29. ezzaray

    ezzaray Private E-2

    I'm going well but just wanted to clarify that I only do a scan for hitmanpro? Not a fix or removal of malicious software?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Correct!
     
  31. ezzaray

    ezzaray Private E-2

    going well. Rad Rater said that it was already uninstalled do you want to delete it from the program list, I click yes and continued. I have attached the 3 logs. I'm hoping there is more of a process as I'm still getting lots of popups, but I can at least search something on the internet. I've tried both internet explorer and google chrome and having similar issues. Cheers Erin
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Popups to what and when do you get them?

    There is a little more to do but I want to understand what you are calling popups.
     
  33. ezzaray

    ezzaray Private E-2

    I have done some print screens to show you whats going on. Rad Ratter and PC Cleaner and other Ads keep appearing. Also malware bytes keeps blocking jsl.infostatsvc.com and app.tvlsvc.com. What do you make of this?
     

    Attached Files:

    • eg1.jpg
      eg1.jpg
      File size:
      81.5 KB
      Views:
      4
    • eg2.jpg
      eg2.jpg
      File size:
      87.7 KB
      Views:
      3
    • eg3.jpg
      eg3.jpg
      File size:
      102.6 KB
      Views:
      3
    • eg4.jpg
      eg4.jpg
      File size:
      102.1 KB
      Views:
      3
    • eg5.jpg
      eg5.jpg
      File size:
      98.1 KB
      Views:
      2
  34. ezzaray

    ezzaray Private E-2

    Just one more attachment.
    Cheers Erin
     

    Attached Files:

    • eg6.jpg
      eg6.jpg
      File size:
      104.4 KB
      Views:
      1
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's run two more tools.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)

    Attach the two logs from above and then we will continue with your cleanup.
     
  36. ezzaray

    ezzaray Private E-2

    Do I just do a scan with Adwcleaner, not a fix?
     
  37. ezzaray

    ezzaray Private E-2

    here are the logs.
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now you can rerun AdwCleaner and this time have it fix all that it reports.

    Then immediately reboot. After reboot, run a new scan with OTL and attach the new log. Also check if you are still having problems.
     
  39. ezzaray

    ezzaray Private E-2

    On the OTL scan do I have to do the following

    Check the "Scan All Users" checkbox.
    Check the "Standard Output".
    Change the setting of "Drivers" and "Services" to "All"
    Copy the text in the code box below and paste it into the text-field.
    Code:

    activex
    netsvcs
    drives

    Or do I just click run scan?
     
  40. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Run it again exactly as you were instructed in Post#35.
     
  41. ezzaray

    ezzaray Private E-2

    I'm still having the same issue. I have done a fix with adwcleaner and now am doing another scan with OLT. I will attach the report when it finishes.
     
  42. ezzaray

    ezzaray Private E-2

    here is the OTL log. Cheers Erin
     
  43. ezzaray

    ezzaray Private E-2

    ooooops here it is :-o
     

    Attached Files:

    • OTL.Txt
      File size:
      275.3 KB
      Views:
      1
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  45. ezzaray

    ezzaray Private E-2

    I went into the addons for explorer and chrome and noticed they had some add ons, one was Rad Ratter so I disable them all and it is working like a dream!!!!!!!!!!!!!!!!! You have been soooo incredable patient and sooooo helpful I am forever in your dept. You do an amazing job!!!!! Thankyou Thankyou Thankyou!!!!!!!;););););););):):):):):):):):)
     
  46. ezzaray

    ezzaray Private E-2

    I just got your last post. That was spot on, I just happened to do the short version. Hee Hee Hee. Once again thank you sooo very much. Erin
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent news! You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds