Monday 2 June 2014

Remove “Ads by Supra Savings” virus (Easy Removal Guide)

http://malwaretips.com/blogs/ads-by-supra-savings-virus/

adwcleaner
http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner

# AdwCleaner v3.211 - Report created 02/06/2014 at 20:45:44
# Updated 26/05/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : abc - 0R00FW
# Running from : C:\Users\abc\Downloads\adwcleaner_3.211.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : SECUREASSIST
Service Deleted : vxlsnyaiet64

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\baidu
Folder Deleted : C:\Program Files (x86)\baidu
Folder Deleted : C:\Program Files\003
Folder Deleted : C:\Program Files\SupraSavings
Folder Deleted : C:\Users\abc\AppData\Local\baidu
Folder Deleted : C:\Users\abc\AppData\Local\Temp\apn
Folder Deleted : C:\Users\abc\AppData\Local\Temp\baidu
Folder Deleted : C:\Users\abc\AppData\LocalLow\baidu
Folder Deleted : C:\Users\abc\AppData\Roaming\baidu
File Deleted : C:\windows\SysWOW64\SecureAssist.dll
File Deleted : C:\windows\SysWOW64\SecureAssist.ini
File Deleted : C:\windows\SysWOW64\SecureAssistOff.ini
File Deleted : C:\windows\System32\SecureAssist.ini
File Deleted : C:\windows\System32\SecureAssist64.dll
File Deleted : C:\windows\System32\SecureAssistOff.ini

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\pricegong_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\pricegong_rasmancs
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{76A60138-58B3-4E27-85FB-8FEF344A8998}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9863E762-BACC-46E4-8CAA-2A6ADA06B65B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{03EF41A4-BA24-4E49-A2C0-E1D047299287}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{130CCD34-0382-48E5-B307-0E7E72166828}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{26D25DD5-F17A-4D93-9A94-997E2124EEB4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{30279F40-D76B-443C-A34D-F43B35B35CE1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{796D0AA0-DC0E-44C9-A398-C874F04D55A4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CE2102F0-DF63-452E-9CA7-0F75FF4DDD4B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{DADFCC6F-66D2-4E1D-A01B-7064CAD2F583}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{EBE666C3-F26C-4CF6-8ABA-3D5F5D2625E1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\powerpack
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\Rr Savings
Key Deleted : HKLM\Software\suprasavings
Key Deleted : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Key Deleted : [x64] HKLM\SOFTWARE\Rr Savings
Key Deleted : [x64] HKLM\SOFTWARE\suprasavings

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17041


-\\ Google Chrome v35.0.1916.114

[ File : C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=M1F01C0DA-8335-46F8-827B-83EE70A0DF4A&SearchSource=58&CUI=&UM=5&UP=SPD2932542-581C-440E-B115-6614573D8EBD&q={searchTerms}&SSPV=
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [3796 octets] - [02/06/2014 20:45:03]
AdwCleaner[S0].txt - [3849 octets] - [02/06/2014 20:45:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3909 octets] ##########

No comments:

Post a Comment