TechSpot

I have trouble removing shopping sidekick plugin

Solved
By Carmen__Tsamg
Feb 5, 2013
Topic Status:
Not open for further replies.
  1. Carmen__Tsamg

    Carmen__Tsamg TS Enthusiast Topic Starter Posts: 103

    ========== Files/Folders - Created Within 30 Days ==========

    [2013/02/06 17:47:51 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2013/02/06 17:46:01 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2013/02/06 11:09:59 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2013/02/06 11:09:59 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2013/02/06 11:09:59 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2013/02/06 11:09:46 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2013/02/06 11:09:21 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
    [2013/02/06 10:35:44 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
    [2013/02/06 10:35:19 | 000,000,000 | ---D | C] -- C:\JRT
    [2013/02/06 10:33:49 | 000,547,275 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Kitty Tsang\Desktop\JRT.exe
    [2013/02/05 16:06:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    [2013/02/02 15:45:47 | 000,000,000 | ---D | C] -- C:\Program Files\FreeFixer
    [2013/02/01 12:19:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    [2013/01/29 21:54:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
    [2013/01/29 21:54:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDFCreator
    [2013/01/29 21:52:50 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\Updater21802
    [2013/01/29 21:21:59 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logon Loader
    [2013/01/29 21:11:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logon Loader
    [2013/01/29 21:11:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Logon Loader
    [2013/01/24 14:44:36 | 000,000,000 | ---D | C] -- C:\found.002
    [2013/01/11 21:11:36 | 000,035,328 | ---- | C] (IncrediMail, Ltd.) -- C:\Windows\SysNative\ImHttpComm.dll
    [2013/01/11 21:11:36 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ARFC
    [2013/01/11 21:10:10 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\PutLockerDownloader
    [2013/01/11 21:09:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PutLockerDownloader
    [2013/01/11 21:09:54 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PutLockerDownloader.com
    [2013/01/11 21:09:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PutLockerDownloader.com
    [2013/01/07 20:40:07 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\Documents\CyberLink
    [2013/01/07 20:39:40 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Roaming\CyberLink
    [2013/01/07 20:18:31 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector 11
    [2013/01/07 20:18:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cyberlink
    [2013/01/07 20:12:29 | 000,000,000 | ---D | C] -- C:\Program Files\CyberLink
    [2013/01/07 19:50:46 | 000,000,000 | ---D | C] -- C:\ProgramData\install_clap
    [1 C:\Users\Kitty Tsang\Desktop\*.tmp files -> C:\Users\Kitty Tsang\Desktop\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2013/02/06 17:56:00 | 000,000,466 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
    [2013/02/06 17:44:05 | 000,000,526 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2013/02/06 17:18:29 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2013/02/06 17:11:21 | 000,000,538 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013/02/06 16:59:03 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2013/02/06 16:59:03 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2013/02/06 16:52:20 | 000,000,534 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2013/02/06 15:58:00 | 000,000,460 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Kitty Tsang.job
    [2013/02/06 11:46:46 | 001,202,004 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2013/02/06 11:46:46 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2013/02/06 11:46:46 | 000,378,104 | ---- | M] () -- C:\Windows\SysNative\prfh0404.dat
    [2013/02/06 11:46:46 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2013/02/06 11:46:46 | 000,099,568 | ---- | M] () -- C:\Windows\SysNative\prfc0404.dat
    [2013/02/06 11:41:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2013/02/06 11:41:46 | 3151,417,344 | -HS- | M] () -- C:\hiberfil.sys
    [2013/02/06 10:33:51 | 000,547,275 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Kitty Tsang\Desktop\JRT.exe
    [2013/02/06 02:12:10 | 000,000,047 | ---- | M] () -- C:\Users\Kitty Tsang\AppData\Roaming\CoreAVC.ini
    [2013/02/05 16:06:57 | 000,002,230 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2013/02/03 16:21:26 | 000,002,192 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\迅雷7.lnk
    [2013/02/02 16:15:18 | 000,001,046 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\PPStream.lnk
    [2013/02/02 15:04:04 | 000,211,560 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
    [2013/01/30 22:15:20 | 000,002,951 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\Microsoft Excel 2010.lnk
    [2013/01/30 22:15:14 | 000,002,937 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\Microsoft PowerPoint 2010.lnk
    [2013/01/30 22:15:00 | 000,001,242 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\Paint.lnk
    [2013/01/29 21:58:31 | 000,000,866 | ---- | M] () -- C:\Windows\SysWow64\InstallUtil.InstallLog
    [2013/01/29 21:41:02 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
    [2013/01/24 10:02:30 | 000,037,720 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
    [2013/01/23 21:07:15 | 000,001,069 | ---- | M] () -- C:\Users\Kitty Tsang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
    [2013/01/11 22:04:40 | 000,000,000 | ---- | M] () -- C:\Users\Kitty Tsang\Documents\貝多芬第九號交響曲:貝多芬快樂頌.flv
    [2013/01/11 02:36:14 | 000,000,000 | ---- | M] () -- C:\Users\Kitty Tsang\Documents\(HQ 192kb).flv
    [2013/01/10 00:16:55 | 000,455,384 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [1 C:\Users\Kitty Tsang\Desktop\*.tmp files -> C:\Users\Kitty Tsang\Desktop\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2013/02/06 11:09:59 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2013/02/06 11:09:59 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2013/02/06 11:09:59 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2013/02/06 11:09:59 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2013/02/06 11:09:59 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2013/02/05 16:06:57 | 000,002,230 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2013/02/02 16:15:18 | 000,001,046 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\PPStream.lnk
    [2013/02/02 15:06:27 | 000,000,538 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013/02/02 15:06:24 | 000,000,534 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2013/01/30 22:15:20 | 000,002,951 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\Microsoft Excel 2010.lnk
    [2013/01/30 22:15:14 | 000,002,937 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\Microsoft PowerPoint 2010.lnk
    [2013/01/30 22:15:00 | 000,001,242 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\Paint.lnk
    [2013/01/30 22:14:37 | 000,002,192 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\迅雷7.lnk
    [2013/01/29 21:54:55 | 000,087,040 | ---- | C] () -- C:\Windows\SysNative\pdfcmnnt.dll
    [2013/01/29 00:41:04 | 000,000,866 | ---- | C] () -- C:\Windows\SysWow64\InstallUtil.InstallLog
    [2013/01/11 22:04:22 | 000,000,000 | ---- | C] () -- C:\Users\Kitty Tsang\Documents\貝多芬第九號交響曲:貝多芬快樂頌.flv
    [2013/01/11 21:11:36 | 001,261,936 | ---- | C] () -- C:\Windows\SysNative\dmwu.exe
    [2013/01/11 02:36:14 | 000,000,000 | ---- | C] () -- C:\Users\Kitty Tsang\Documents\(HQ 192kb).flv
    [2012/12/24 23:31:42 | 002,299,360 | ---- | C] () -- C:\Windows\SysWow64\kindling.dll
    [2012/09/24 22:49:21 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
    [2012/06/14 20:15:44 | 000,000,033 | ---- | C] () -- C:\Users\Kitty Tsang\AppData\Roaming\turing_files.ini
    [2012/04/28 12:03:54 | 000,211,560 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
    [2012/04/01 13:29:46 | 000,000,091 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
    [2012/03/24 20:34:49 | 000,000,047 | ---- | C] () -- C:\Users\Kitty Tsang\AppData\Roaming\CoreAVC.ini
    [2012/03/20 18:01:22 | 000,000,190 | ---- | C] () -- C:\Windows\ODBCINST.INI
    [2012/01/24 00:50:46 | 000,009,506 | ---- | C] () -- C:\Windows\UN070618.INI
    [2011/08/13 01:05:36 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
    [2011/07/28 11:52:17 | 000,000,020 | ---- | C] () -- C:\Windows\SysWow64\pub_store.dat
    [2011/07/17 21:40:36 | 000,018,760 | ---- | C] () -- C:\Windows\SysWow64\QQVistaHelper.dll
    [2011/07/15 10:17:49 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2011/07/15 10:17:49 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
    [2011/07/15 10:17:48 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
    [2011/07/15 10:17:48 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
    [2011/07/15 10:17:48 | 000,073,216 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
    [2011/07/15 05:25:24 | 001,220,378 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2011/04/17 05:21:03 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
    [2011/04/17 05:15:22 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
    [2011/04/17 05:15:20 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
    [2011/04/17 05:15:17 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin

    ========== ZeroAccess Check ==========

    [2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

    ========== LOP Check ==========

    [2012/06/10 18:35:50 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Audacity
    [2012/11/06 16:26:37 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\AVG2013
    [2013/01/24 13:51:36 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Dropbox
    [2012/12/02 13:54:41 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\ExpressFiles
    [2012/11/01 13:55:19 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Kugou7
    [2013/02/06 05:26:10 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\KuGou8
    [2012/08/01 08:24:09 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\OpenOffice.org
    [2012/05/04 15:50:22 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PCDr
    [2012/03/23 18:45:07 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PPLive
    [2013/02/06 16:53:17 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PPStream
    [2012/03/24 00:18:54 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PwrMgr
    [2012/04/07 15:19:54 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\QQMusicUpdate
    [2012/04/12 17:08:43 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\SoftGrid Client
    [2012/11/06 16:17:58 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\TuneUp Software
    [2012/08/27 19:12:19 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Youtube Downloader HD
    [2012/07/23 22:15:26 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Youtube to MP3 Converter

    ========== Purity Check ==========



    ========== Files - Unicode (All) ==========
    [2013/02/05 10:35:12 | 000,000,162 | -H-- | M] ()(C:\Users\Kitty Tsang\Desktop\~$八婚后事件?.docx) -- C:\Users\Kitty Tsang\Desktop\~$八婚后事件录.docx
    [2013/02/05 10:35:12 | 000,000,162 | -H-- | C] ()(C:\Users\Kitty Tsang\Desktop\~$八婚后事件?.docx) -- C:\Users\Kitty Tsang\Desktop\~$八婚后事件录.docx
    [2012/09/16 22:54:47 | 035,273,178 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\永遠?幸????方法、見?????。 歌????@????。_(360p).flv) -- C:\Users\Kitty Tsang\Documents\永遠に幸せになる方法、見つけました。 歌いました@あまとぉ。_(360p).flv
    [2012/09/16 22:51:00 | 035,273,178 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\永遠?幸????方法、見?????。 歌????@????。_(360p).flv) -- C:\Users\Kitty Tsang\Documents\永遠に幸せになる方法、見つけました。 歌いました@あまとぉ。_(360p).flv
    [2012/08/25 20:00:36 | 015,143,289 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\Gumi - Eye Examination (???????)_(360p).flv) -- C:\Users\Kitty Tsang\Documents\Gumi - Eye Examination (シリョクケンサ)_(360p).flv
    [2012/08/25 19:57:29 | 015,143,289 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\Gumi - Eye Examination (???????)_(360p).flv) -- C:\Users\Kitty Tsang\Documents\Gumi - Eye Examination (シリョクケンサ)_(360p).flv
    [2012/08/25 18:29:48 | 026,959,563 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\【clear×96?×???】背??記憶~The Lost Memory~【歌????】_(360p).mp4) -- C:\Users\Kitty Tsang\Documents\【clear×96猫×ぽこた】背徳の記憶~The Lost Memory~【歌ってみた】_(360p).mp4
    [2012/08/25 18:29:24 | 011,921,083 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\【clear】嗚呼、素晴??????生【???】_(360p).flv) -- C:\Users\Kitty Tsang\Documents\【clear】嗚呼、素晴らしきニャン生【リツカ】_(360p).flv
    [2012/08/25 18:26:53 | 011,921,083 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\【clear】嗚呼、素晴??????生【???】_(360p).flv) -- C:\Users\Kitty Tsang\Documents\【clear】嗚呼、素晴らしきニャン生【リツカ】_(360p).flv
    [2012/08/25 18:26:51 | 026,959,563 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\【clear×96?×???】背??記憶~The Lost Memory~【歌????】_(360p).mp4) -- C:\Users\Kitty Tsang\Documents\【clear×96猫×ぽこた】背徳の記憶~The Lost Memory~【歌ってみた】_(360p).mp4
    [2012/08/25 18:08:01 | 016,279,320 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\?????? ver 96? with vip店長 ※??? with 中文字幕 (Chinese Sub)_(360p).flv) -- C:\Users\Kitty Tsang\Documents\マトリョシカ ver 96猫 with vip店長 ※フリー with 中文字幕 (Chinese Sub)_(360p).flv
    [2012/08/25 18:05:20 | 016,279,320 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\?????? ver 96? with vip店長 ※??? with 中文字幕 (Chinese Sub)_(360p).flv) -- C:\Users\Kitty Tsang\Documents\マトリョシカ ver 96猫 with vip店長 ※フリー with 中文字幕 (Chinese Sub)_(360p).flv
    [2012/08/24 22:54:14 | 018,107,222 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\【9人?歌?】合唱『初?????終??時』【?????、????】_(360p).flv) -- C:\Users\Kitty Tsang\Documents\【9人の歌姫】合唱『初めての恋が終わる時』【ありがとう、サヨナラ】_(360p).flv
    [2012/08/24 22:53:48 | 016,577,957 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\合唱 『?????????』Girls Version【初音??曲】_(360p).flv) -- C:\Users\Kitty Tsang\Documents\合唱 『ロミオとシンデレラ』Girls Version【初音ミク曲】_(360p).flv
    [2012/08/24 22:50:38 | 016,577,957 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\合唱 『?????????』Girls Version【初音??曲】_(360p).flv) -- C:\Users\Kitty Tsang\Documents\合唱 『ロミオとシンデレラ』Girls Version【初音ミク曲】_(360p).flv
    [2012/08/24 22:50:23 | 018,107,222 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\【9人?歌?】合唱『初?????終??時』【?????、????】_(360p).flv) -- C:\Users\Kitty Tsang\Documents\【9人の歌姫】合唱『初めての恋が終わる時』【ありがとう、サヨナラ】_(360p).flv
    [2012/08/24 22:40:58 | 027,020,438 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\【手描?PV】夢?【鏡音?????】ChineseSub_(360p).mp4) -- C:\Users\Kitty Tsang\Documents\【手描きPV】夢桜【鏡音リン・レン】ChineseSub_(360p).mp4
    [2012/08/24 22:37:40 | 027,020,438 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\【手描?PV】夢?【鏡音?????】ChineseSub_(360p).mp4) -- C:\Users\Kitty Tsang\Documents\【手描きPV】夢桜【鏡音リン・レン】ChineseSub_(360p).mp4
    [2012/08/24 22:31:07 | 027,927,454 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\「Kagamine Rin?Hatsune Miku」 Amayumero - (Sub. Espanol)_(360p).flv) -- C:\Users\Kitty Tsang\Documents\「Kagamine Rin・Hatsune Miku」 Amayumero - (Sub. Español)_(360p).flv
    [2012/08/24 22:27:30 | 027,927,454 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\「Kagamine Rin?Hatsune Miku」 Amayumero - (Sub. Espanol)_(360p).flv) -- C:\Users\Kitty Tsang\Documents\「Kagamine Rin・Hatsune Miku」 Amayumero - (Sub. Español)_(360p).flv
    [2012/08/14 23:17:38 | 015,250,706 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\【8 Vocaloids】Crazy ∞ nighT (English Sub)【?????】_(360p).flv) -- C:\Users\Kitty Tsang\Documents\【8 Vocaloids】Crazy ∞ nighT (English Sub)【オリジナル】_(360p).flv
    [2012/08/14 23:15:23 | 015,250,706 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\【8 Vocaloids】Crazy ∞ nighT (English Sub)【?????】_(360p).flv) -- C:\Users\Kitty Tsang\Documents\【8 Vocaloids】Crazy ∞ nighT (English Sub)【オリジナル】_(360p).flv
    [2012/08/14 23:01:17 | 017,188,426 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\【GUMI×鏡音??】嗚呼、素晴??????生【?????曲】 中文字幕_(360p).flv) -- C:\Users\Kitty Tsang\Documents\【GUMI×鏡音レン】嗚呼、素晴らしきニャン生【オリジナル曲】 中文字幕_(360p).flv
    [2012/08/14 22:58:50 | 017,188,426 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\【GUMI×鏡音??】嗚呼、素晴??????生【?????曲】 中文字幕_(360p).flv) -- C:\Users\Kitty Tsang\Documents\【GUMI×鏡音レン】嗚呼、素晴らしきニャン生【オリジナル曲】 中文字幕_(360p).flv
    [2012/08/14 22:58:02 | 023,611,462 | ---- | M] ()(C:\Users\Kitty Tsang\Documents\???、幸福安心委員???。歌???? ver96? ※??? 繁體中文字幕_(360p).flv) -- C:\Users\Kitty Tsang\Documents\こちら、幸福安心委員会です。歌ってみた ver96猫 ※フリー 繁體中文字幕_(360p).flv
    [2012/08/14 22:54:52 | 023,611,462 | ---- | C] ()(C:\Users\Kitty Tsang\Documents\???、幸福安心委員???。歌???? ver96? ※??? 繁體中文字幕_(360p).flv) -- C:\Users\Kitty Tsang\Documents\こちら、幸福安心委員会です。歌ってみた ver96猫 ※フリー 繁體中文字幕_(360p).flv
    (C:\ProgramData\Microsoft\Windows\Start Menu\Programs\迅雷?件) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\迅雷软件
    (C:\ProgramData\Microsoft\Windows\Start Menu\Programs\快播?件) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\快播软件
    (C:\ProgramData\Microsoft\Windows\Start Menu\Programs\百度工具?) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\百度工具栏
    (C:\ProgramData\Microsoft\Windows\Start Menu\Programs\???件) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
    < End of report >
     
  2. Carmen__Tsamg

    Carmen__Tsamg TS Enthusiast Topic Starter Posts: 103

    So is it clean?? it looks like the shopping sidekick plugin disspear in the chrome , for now....thanks again for your time!
     
  3. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Let's remove Shopping Sidekick and do some final fixes before cleaning up...

    OTL Fix

    Please run OTL
    • Under the Custom Scans/Fixes box at the bottom, copy and paste in the following:

    • Then click the Run Fix button at the top.
    • Note: The fix for OTL automatically hides your Desktop and Start menu so the fix can be completed. Do not be alerted, as this is normal.
    • Please do not exit the program. It might take a while to fix, but allow it to run. If it asks to reboot the computer, allow it to reboot. If the program freezes, and the computer fails to reboot - let me know.
      Lastly, post the contents of the log. (Located at C:\_OTL\Moved Files)
     
  4. Carmen__Tsamg

    Carmen__Tsamg TS Enthusiast Topic Starter Posts: 103

    All processes killed
    ========== OTL ==========
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_0\crossrider not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_0 not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_1\crossrider not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_1 not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_2\crossrider not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_2 not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_0\crossrider not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_0 not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_1\crossrider not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_1 not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_2\crossrider not found.
    File C:\Users\Kitty Tsang\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.21.24_2 not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
    Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    ========== FILES ==========
    < ipconfig /flushdns /c >
    Windows IP 設定
    成功清除 DNS 解讀器快取。
    C:\Users\Kitty Tsang\Downloads\cmd.bat deleted successfully.
    C:\Users\Kitty Tsang\Downloads\cmd.txt deleted successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Kitty Tsang
    ->Temp folder emptied: 91828196 bytes
    ->Temporary Internet Files folder emptied: 269196172 bytes
    ->Java cache emptied: 57691 bytes
    ->Google Chrome cache emptied: 382857716 bytes
    ->Apple Safari cache emptied: 125932544 bytes
    ->Flash cache emptied: 5623315 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: TEMP
    ->Temp folder emptied: 0 bytes

    User: user
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 560415620 bytes
    ->Java cache emptied: 10412 bytes
    ->Google Chrome cache emptied: 159312870 bytes
    ->Apple Safari cache emptied: 183566336 bytes
    ->Flash cache emptied: 3305648 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 780910 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50390 bytes
    RecycleBin emptied: 238603 bytes

    Total Files Cleaned = 1,701.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 02072013_154338

    Files\Folders moved on Reboot...
    C:\Users\Kitty Tsang\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
    thanks!
     
  5. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Hi there. It all appears to be good, so we will finish up to make sure your computer is protected from malware in the future.

    Clean up System Restore

    Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."

    To manually create a new Restore Point
    • Go to Control Panel and select System and Maintenance
    • Select System
    • On the left select Advanced System Settings and accept the warning if you get one
    • Select System Protection Tab
    • Select Create at the bottom
    • Type in a name I.e. Clean
    • Select Create


    Remove tools, temp files, old Restore Points

    Please run OTL
    • Under the Custom Scans/Fixes box at the bottom, copy and paste in the following:

    • Then click the Run Fix button at the top.
    • Note: The fix for OTL sometimes hides your Desktop and Start menu so the cleanup can be completed. Do not be alerted, as this is normal.
    • It may open a log for you, but I don't need that.

    To remove all of the tools we used and the files and folders they created do the following:
    Double click OTL.exe.
    • Click the CleanUp button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.


    Security Check

    Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
     
  6. Carmen__Tsamg

    Carmen__Tsamg TS Enthusiast Topic Starter Posts: 103

    Results of screen317's Security Check version 0.99.57
    Windows 7 Service Pack 1 x64 (UAC is disabled!)
    Internet Explorer 9
    ``````````````Antivirus/Firewall Check:``````````````
    AVG Anti-Virus Free Edition 2013
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Malwarebytes Anti-Malware 版本 1.70.0.1100
    Duplicate Cleaner 2.0.6
    Eusing Free Registry Cleaner
    Java(TM) 6 Update 37
    Java version out of Date!
    Adobe Flash Player 11.5.502.146
    Google Chrome 24.0.1312.57
    ````````Process Check: objlist.exe by Laurent````````
    AVG avgwdsvc.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C:
    ````````````````````End of Log``````````````````````
    thanks again
    PS. I have a notebook that I suspect it might has virus, do I follow the four step procedures like I did for this one and open a new post?
     
  7. Carmen__Tsamg

    Carmen__Tsamg TS Enthusiast Topic Starter Posts: 103

    Oh, I just updated Java after I read the log...
    Results of screen317's Security Check version 0.99.57
    Windows 7 Service Pack 1 x64 (UAC is disabled!)
    Internet Explorer 9
    ``````````````Antivirus/Firewall Check:``````````````
    AVG Anti-Virus Free Edition 2013
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Malwarebytes Anti-Malware 版本 1.70.0.1100
    Duplicate Cleaner 2.0.6
    Eusing Free Registry Cleaner
    Java(TM) 6 Update 39
    Java version out of Date!
    Adobe Flash Player 11.5.502.146
    Google Chrome 24.0.1312.57
    ````````Process Check: objlist.exe by Laurent````````
    AVG avgwdsvc.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C:
    ````````````````````End of Log``````````````````````
     
  8. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Personal Tips on Preventing Malware

    See this page for more info about malware and prevention.


    Any other questions before I mark this topic solved?
     
  9. Carmen__Tsamg

    Carmen__Tsamg TS Enthusiast Topic Starter Posts: 103

    No, so is my computer clean? thanks so much
     
  10. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Yes. Topic marked solved.
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.