Computer Hope
Software => Computer viruses and spyware => Topic started by: copas on July 05, 2016, 12:00:07 PM
-
For several years I have been getting my meds via my computer.
Now I can no longer access Caremark.
I just get a message that 'they' are strenghting my digital security.
I think this is Microsoft.
I am running Explorer 9 on a desktop.
Operating system, Vista premium.
Someone wanted my credit card to allow me to upgrade my browser!
What's happening to me??
Can you help?
Ivan Copas
-
Wait for SuperDave to respond, but for now - DO NOT give anyone your credit card number. There is no charge to update browsers and Microsoft would never ask for one anyway. If you're having an issue with IE you can try Firefox or Opera or Chrome, etc. They would be IN ADDITION to IE, you would not be replacing IE. You can have as many browsers on your system as you like and use whichever one(s) you like at any time.
Having said all that, I'm not sure of the depth of the invasiveness into your system (whether it's just a phishing popup from someone trying to get you to bite or if you've actually been hacked to some extent). Again, Dave will help you when he logs on.
-
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.
1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.
If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
Please download AdwCleaner (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner)by Xplode onto your Desktop.
Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon.
(http://i424.photobucket.com/albums/pp322/digistar/AdwCleaner-icon.jpg)
If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run.
When the AdwCleaner program will open, click on the Scan button as shown below.
(http://i424.photobucket.com/albums/pp322/digistar/untitled.png)
AdwCleaner will now start to search for malicious files that may be installed on your computer.
To remove the files that were detected in the previous step, please click on the Clean button.
(http://i424.photobucket.com/albums/pp322/digistar/3.png)
AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer.
Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply.
*********************************************
(http://i424.photobucket.com/albums/pp322/digistar/mbamicontw5.gif) Please download Malwarebytes Anti-Malware from here. (http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe)
Double Click mbam-setup.exe to install the application.
- It should update automatically if the computer is connected to the internet.
- Click on Threat Scan and click on Scan Now.
- The scan may take some time to finish,so please be patient.
- When the scan is complete make sure all the infections have "quarantine" selected in the Action box.
- Click on "Apply actions" You may be asked to Restart your computer to completely remove the infections.
- When disinfection is completed you can click on "Copy to Clipboard".
- Paste the log in you next reply (CTRL+ V)
*************************************************
Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.
•Warning! Once the scan is complete JRT will shut down your browser with NO warning.
•Shut down your protection software now to avoid potential conflicts.
•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this (http://www.bleepingcomputer.com/forums/topic114351.html) link to see a list of security programs that should be disabled and how to disable them.
•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator
•The tool will open and start scanning your system.
•Please be patient as this can take a while to complete depending on your system's specifications.
•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
•Copy and Paste the JRT.txt log into your next message.
-
Hello! I ran adware cleaner.
Resiults: # AdwCleaner v4.105 - Report created 28122014 at 173818
# Updated 08122014 by Xplode
# Database 2014-12-08.2 [Local]
# Operating System Windows Vista (TM) Ultimate Service Pack 2 (32 bits)
# Username copas - COPAS-PC
# Running from Hadwcleaner_4.105.exe
# Option Clean
[ Services ]
[ Files Folders ]
[ Scheduled Tasks ]
[ Shortcuts ]
[ Registry ]
Key Deleted HKCUSoftwarespd
Key Deleted HKCUSoftwareMicrosoftWindowsCurrentVers ionApp ManagementARPCache{597FB4A5-DD86-4316-A410-7E8074CC2CCE}
[ Browsers ]
- Internet Explorer v9.0.8112.16592
- Mozilla Firefox v34.0.5 (x86 en-US)
- Google Chrome v
AdwCleaner[R0].txt - [2803 octets] - [22122014 213003]
AdwCleaner[R1].txt - [1158 octets] - [28122014 173508]
AdwCleaner[S0].txt - [2592 octets] - [22122014 213227]
AdwCleaner[S1].txt - [969 octets] - [28122014 173818]
########## EOF - CAdwCleanerAdwCleaner[S1].txt - [1028 octets] ##########
# AdwCleaner v5.201 - Logfile created 05072016 at 165430
# Updated 30062016 by ToolsLib
# Database 2016-07-04.1 [Server]
# Operating system Windows Vista (TM) Ultimate Service Pack 2 (X86)
# Username copas - COPAS-PC
# Running from CUserscopasAppDataLocalMicrosoftWindows Temporary Internet FilesContent.IE52ETN4F8Iadwcleaner_5.20 1.exe
# Option Scan
# Support httpstoolslib.netforum
[ Services ]
Service Found swdumon
[ Folders ]
Folder Found CProgramDataslimware utilities inc
Folder Found CProgramDatadcc1157c-0575-4f3a-b001-af9a2dcc0614
Folder Found CProgramDataApplication Dataslimware utilities inc
Folder Found CProgramDataApplication Datadcc1157c-0575-4f3a-b001-af9a2dcc0614
Folder Found CProgramDataMicrosoftWindowsStart MenuProgramsdriverupdate
Folder Found CProgramDataMicrosoftWindowsStart MenuProgramsslimcleaner plus
Folder Found CUsersPublicDocumentsDownloaded Installers
Folder Found CUsersPublicDocumentsDownloaded Installers{416964B7-855B-46DE-B39D-08DA443F7CD0}
Folder Found CProgram Filesdriverupdate
Folder Found CProgram Filesslimcleaner plus
Folder Found CProgram Filesslimservice
Folder Found CWindowsInstaller{416964B7-855B-46DE-B39D-08DA443F7CD0}
Folder Found CWindowssystem32configsystemprofileAppD ataLocalLowYahoo! Companion
Folder Found CWindowssystem32configsystemprofileAppD ataLocalLowYahoo!Companion
Folder Found CUserscopasAppDataLocalslimware utilities inc
Folder Found CUserscopasAppDataLocalDownloaded Installers
Folder Found CUserscopasAppDataLocalMapsGalaxyToolta b
Folder Found CUserscopasAppDataLocalDownloaded Installers{416964B7-855B-46DE-B39D-08DA443F7CD0}
Folder Found CUserscopasAppDataLocalVirtualStoreProg ram FilesiWin.com Games
Folder Found CUserscopasAppDataRoamingPDManager
Folder Found CUserscopasAppDataRoamingMozillaFirefox Profiles5fkm5ow0.defaultextensions_edMe [email protected]
[ Files ]
File Found CUsersPublicDesktopslimcleaner plus.lnk
File Found CUsersPublicDesktopdriverupdate.lnk
File Found CWindowssystem32driversswdumon.sys
File Found CUserscopasAppDataRoamingMozillaFirefox Profiles5fkm5ow0.defaultsearchpluginsas k-web-search.xml
[ DLL ]
[ WMI ]
[ Shortcuts ]
[ Scheduled tasks ]
Task Found driverupdate startup
Task Found PC Optimizer Pro Idle
Task Found PC Optimizer Pro Startups
Task Found PC Optimizer Pro Updates
Task Found DriverUpdate Scan
Task Found SlimCleaner Plus (Scheduled Scan - copas)
[ Registry ]
Value Found HKCUSoftwareMicrosoftInternet ExplorerMainFeatureControlFEATURE_BROWS ER_EMULATION [WeatherBug.exe]
Key Found HKLMSOFTWAREClassesApplicationsiLividSe tup-r1168-n-bi.exe
Key Found HKLMSOFTWAREClassesprotector_dll.Protec tor
Key Found HKLMSOFTWAREClassesprotector_dll.Protec tor.1
Key Found HKLMSOFTWAREClassesprotector_dll.Protec torLib
Key Found HKLMSOFTWAREClassesprotector_dll.Protec torLib.1
Key Found HKLMSOFTWAREClassesSample.BrowserHandle r
Key Found HKLMSOFTWAREClassesSample.BrowserHandle r.1
Key Found HKLMSOFTWAREClassesSample.YTBPartnerSam ple
Key Found HKLMSOFTWAREClassesSample.YTBPartnerSam ple.1
Key Found HKLMSOFTWAREClassesuus3url-st
Key Found HKLMSOFTWAREClassesAppID{7375D127-3955-4654-8E7D-1949A7A9C902}
Key Found HKLMSOFTWAREClassesInterface{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
Key Found HKLMSOFTWAREClassesInterface{7F124846-5453-4BB8-A41D-E11481FFC9DF}
Key Found HKLMSOFTWAREClassesInterface{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
Key Found HKLMSOFTWAREClassesTypeLib{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
Key Found HKCUSoftwareSlimWare Utilities Inc
Key Found HKCUSoftwareSparkTrustSparkTrust PC Cleaner Plus
Key Found HKCUSoftwareSparkTrustUNSSparkTrust PC Cleaner Plus
Key Found HKLMSOFTWARESLIMWARE UTILITIES, INC.
Key Found HKLMSOFTWARESlimWare Utilities Inc
Key Found HKLMSOFTWARESparkTrustSparkTrust PC Cleaner Plus
Key Found HKLMSOFTWAREPremier Download Manager
Key Found HKLMSOFTWAREMicrosoftWindowsCurrentVers ionUninstallPremier Download Manager
Key Found HKLMSOFTWAREMicrosoftWindowsCurrentVers ionUninstallDriverUpdate
Key Found HKLMSOFTWAREMicrosoftWindowsCurrentVers ionUninstall{416964B7-855B-46DE-B39D-08DA443F7CD0}
Key Found HKCUSoftwareMicrosoftWindowsCurrentVers ionApp ManagementARPCache{597FB4A5-DD86-4316-A410-7E8074CC2CCE}
Key Found HKCUSoftwareMicrosoftWindowsCurrentVers ionApp ManagementARPCacheDriverUpdate
Key Found HKUS-1-5-21-2893001119-400629070-1170602663-1000SoftwareSlimWare Utilities Inc
Key Found HKUS-1-5-21-2893001119-400629070-1170602663-1000SoftwareSparkTrustSparkTrust PC Cleaner Plus
Key Found HKUS-1-5-21-2893001119-400629070-1170602663-1000SoftwareSparkTrustUNSSparkTrust PC Cleaner Plus
Key Found HKUS-1-5-21-2893001119-400629070-1170602663-1000SoftwareMicrosoftWindowsCurrentVersionApp ManagementARPCache{597FB4A5-DD86-4316-A410-7E8074CC2CCE}
Key Found HKUS-1-5-21-2893001119-400629070-1170602663-1000SoftwareMicrosoftWindowsCurrentVersionApp ManagementARPCacheDriverUpdate
Key Found HKLMSOFTWAREClassesInstallerUpgradeCode s50D2BAFD096C90345A82B25A790BDF69
Key Found HKLMSOFTWAREMicrosoftWindowsCurrentVers ionInstallerUpgradeCodes50D2BAFD096C903 45A82B25A790BDF69
Data Found HKCUSoftwareMicrosoftInternet ExplorerMain [Start Page] - hxxphp.myway.commapsgalaxys16897index.h tmln=782AAD00&p2=^UX^xpu540^S16897^us&ptb=9D248BBA-8F44-469D-9A10-DA8EBF9C7B07&si=CJjf0ca2yc0CFUEfhgoddpgMBw
Data Found HKUS-1-5-21-2893001119-400629070-1170602663-1000SoftwareMicrosoftInternet ExplorerMain [Start Page] - hxxphp.myway.commapsgalaxys16897index.h tmln=782AAD00&p2=^UX^xpu540^S16897^us&ptb=9D248BBA-8F44-469D-9A10-DA8EBF9C7B07&si=CJjf0ca2yc0CFUEfhgoddpgMBw
Key Found HKCUSoftwareMicrosoftInternet ExplorerDOMStoragedriverupdate.net
Key Found HKCUSoftwareMicrosoftInternet ExplorerLowRegistryDOMStorageakamaihd.n et
Key Found HKCUSoftwareMicrosoftInternet ExplorerLowRegistryDOMStorageimgfarm.co m
Key Found HKCUSoftwareMicrosoftInternet ExplorerLowRegistryDOMStoragemyway.com
Key Found HKCUSoftwareMicrosoftInternet ExplorerLowRegistryDOMStoragepckeeper.s oftware
Key Found HKCUSoftwareMicrosoftInternet ExplorerLowRegistryDOMStoragestaticimgf arm.com
Key Found HKLMSOFTWAREMicrosoftShared ToolsMsConfigStartupRegCFO
Key Found HKLMSOFTWAREMicrosoftShared ToolsMSConfigservicesConverterFreeOnlin eUpdt
Key Found HKLMSYSTEMCurrentControlSetServicesEven tLogApplicationpastaleadsServiceCore
[ Web browsers ]
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(browser.search.defaultenginename, Ask Web Search);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(browser.search.defaultenginename.US, Ask Web Search);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(browser.search.selectedEngine, Ask Web Search);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(browser.startup.homepage, hxxphome.tb.ask.comindex.jhtmlptb=24B1D113-BFDE-4EE3-A011-19CE0DD6C799&n=781c29b4&p2=^BYF^xdm026^YYA^us&si=adwords);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.mywebsearch.prevKwdEnabled, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.BUTTON_STRUCTURE, [{b224529188,cmindspark.magnify,pL.0},{b224529189,cmindspark.entersearchterms,pL.0.0[...]
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.search.defaultenginename.prev , Yahoo);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.search.defaultenginename.save dPrev, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.search.defaultenginename.tb, Ask Web Search);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.search.selectedEngine.prev, Yahoo);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.search.selectedEngine.savedPr ev, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.search.selectedEngine.tb, Ask Web Search);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.startup.homepage.savedPrev, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.startup.homepage.tb, hxxphome.tb.ask.comindex.jhtmlptb=24B1D113-BFDE-4EE3-A011-19CE0DD6C799&n=781c29b4&p2=^BYF^xdm026^YYA^us&si=adwor[...]
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.startup.page.savedPrev, 1);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.startup.page.tb, 1);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.browser.version.last, 46.0);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.coId, 453170d8e57c4753bc6dc8b30075600a);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.competitorDNS, {commentrefresh every 1 week (72460601000),refreshPeriod604800000,list[{urlhxxpwww.dnsrsearch.com[...]
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.firstKnownVersion, 7.38.8.46550);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.homepage, hxxphome.tb.ask.comindex.jhtmlptb=24B1D113-BFDE-4EE3-A011-19CE0DD6C799&n=781c29b4&p2=^BYF^xdm026^YYA^us&si=adwords);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.hp.enabled, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.hp.guardType, HPR);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.hp.user.defined, false);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.initialized, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.installType, XPI);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.installation.dlpCountryCode, US);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.installation.installDate, 2015111604);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.installation.partnerId, ^BYF^xdm026^YYA^us);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.installation.partnerSubId, adwords);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.installation.pixelUrl, hxxpfree.myradioaccess.cominstall_pixel s.jhtmlpartner=^BYF^xdm026^YYA^us&sub_id=adwords&coId=453170d8e57c4753bc6dc8b30[...]
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.installation.success, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.installation.toolbarId, 24B1D113-BFDE-4EE3-A011-19CE0DD6C799);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.lastActivePing, 1467727560189);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.lastKnownVersion, 7.38.8.46550);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.lssState, {previousLocales[en-US,en],supportedLocales[de,es,pt,ja,en],defaultLocaleen,supportedLo[...]
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.options.defaultSearch, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.options.homePageEnabled, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.options.keywordEnabled, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.options.tabEnabled, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.partnerPixelFired, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.productDeliveryOption.language, en);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.productDeliveryOption.type, Toolbar);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.successUrl, hxxpfree.myradioaccess.cominstallComple te.jhtml);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.toolbar.ownSearch, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.toolbar.versionChanged, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.toolbarCollapsed, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark._edMembers _.uninstallTasks, {prefBranchesToDelete[extensions.toolbar.mindspark._edMembers_.],filesToDelete[CUserscopasAppData[...]
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark.hp.enabled, true);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark.hp.enabled .guid, [email protected]);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(extensions.toolbar.mindspark.lastInstal led, [email protected]);
[CUserscopasAppDataRoamingMozillaFirefoxProfiles5fkm5ow0.defaultprefs.js] Found user_pref(keyword.URL, hxxpsearch.tb.ask.comsearchGGmain.jhtml st=kwd&ptb=24B1D113-BFDE-4EE3-A011-19CE0DD6C799&n=781c29b4&ind=2015111604&p2=^BYF^xdm026^YYA^us&si=adwords&searchfor=);
[CUserscopasAppDataLocalGoogleChromeUser DataDefaultWeb data] [Search Provider] Found aol.com
[CUserscopasAppDataLocalGoogleChromeUser DataDefaultWeb data] [Search Provider] Found ask.com
CAdwCleanerAdwCleaner[C11].txt - [34836 bytes] - [09012016 155633]
CAdwCleanerAdwCleaner[C5].txt - [11901 bytes] - [29102015 193234]
CAdwCleanerAdwCleaner[C6].txt - [1477 bytes] - [01112015 212529]
CAdwCleanerAdwCleaner[C7].txt - [962 bytes] - [02112015 164006]
CAdwCleanerAdwCleaner[C8].txt - [1214 bytes] - [02112015 181517]
CAdwCleanerAdwCleaner[C9].txt - [1096 bytes] - [06112015 105209]
CAdwCleanerAdwCleaner[R0].txt - [2803 bytes] - [22122014 223003]
CAdwCleanerAdwCleaner[R1].txt - [1158 bytes] - [28122014 183508]
CAdwCleanerAdwCleaner[R2].txt - [15349 bytes] - [29122014 221609]
CAdwCleanerAdwCleaner[R3].txt - [21430 bytes] - [01022015 185619]
CAdwCleanerAdwCleaner[R9].txt - [2074 bytes] - [08112015 144153]
CAdwCleanerAdwCleaner[S0].txt - [2592 bytes] - [22122014 223227]
CAdwCleanerAdwCleaner[S11].txt - [33766 bytes] - [09012016 154847]
CAdwCleanerAdwCleaner[S1].txt - [19687 bytes] - [28122014 183818]
CAdwCleanerAdwCleaner[S2].txt - [14889 bytes] - [29122014 222312]
CAdwCleanerAdwCleaner[S3].txt - [22890 bytes] - [01022015 185940]
CAdwCleanerAdwCleaner[S5].txt - [11127 bytes] - [29102015 192928]
CAdwCleanerAdwCleaner[S6].txt - [1332 bytes] - [01112015 212409]
CAdwCleanerAdwCleaner[S7].txt - [847 bytes] - [02112015 163014]
CAdwCleanerAdwCleaner[S8].txt - [1081 bytes] - [02112015 181310]
CAdwCleanerAdwCleaner[S9].txt - [3016 bytes] - [06112015 105014]
########## EOF - CAdwCleanerAdwCleaner[S1].txt - [20274 bytes] ##########
-
For several years I have been getting my meds via my computer.
Now I can no longer access Caremark.
I just get a message that 'they' are strenghting my digital security.
I think this is Microsoft.
I am running Explorer 9 on a desktop.
Operating system, Vista premium.
Someone wanted my credit card to allow me to upgrade my browser!
What's happening to me??
Can you help?
Ivan Copas
-
Hi, I got lost for awhile (what's new?) but my computer still runs! Perhaps the message I received was legit.
I got a lot of stuff off my machine (a good thing!) It seems much of it was redundant...
Thanks for all the help!
Copas
-
I would like you to run the MBAM and JRT scans and post the logs.