(01-07-2015, 02:32 AM)145ah Wrote: [ -> ]hi, GuiltySpark I have try reset IE11 but every time restart my computer mysearchdial.com come back any way I will first try remove most of the programs we have told me with Revo Uninstaller and then I will do scans you mentioned
what about UVK - Ultra Virus Killer do think should use that as well
I am not good with computer sorry if ask you go by step by step
UVK contains some of those programs so you could do, but I would still like you to run the Emsisoft scan.
145ah can you please run Emsisoft Emergency Kit as requested by GuiltySpark
Please
Download Emsisoft Emergency Kit to your desktop.
· Please double click
EmsisoftEmergencyKit.exe this will install
Emsisoft Emergency Kit
· Next choose
Extract it will put program in
C:\EEK
· Navigate to
C:\EEK then click "
Start Emergency Kit Scanner .exe"
· Click
Yes to
User Account Control (UAC)
· Click
Yes to
Update Signature Definitions
· Now click "
Smart Scan "and select
Yes" to "
Detect Potently Unwanted Programs (PuPs) "
· Click
Delete Selected then click
View Report and save as
EEK.log.
· Click
Finish and post
EEK.log on next post.
hi, GuiltySpark I will keep the following programs Advanced SystemCare 8, Auslogics DiskDefrag, Defraggler, IObit Malware Fighter, nurago web meter, Qmee, Smart Defrag 3, SmartSHOW 2.0,SmartSHOW 2.0 because I use them
did the Emsisoft Emergency Scan but for got to put View Report and save as EEK.log, SORRY GuiltySpark I will do one more tomorrow
(01-10-2015, 03:06 AM)145ah Wrote: [ -> ]hi, GuiltySpark I will keep the following programs Advanced SystemCare 8, Auslogics DiskDefrag, Defraggler, IObit Malware Fighter, nurago web meter, Qmee, Smart Defrag 3, SmartSHOW 2.0,SmartSHOW 2.0 because I use them
That's entirely up to you but I don't understand why you have 3 Defrag programs??? Windows handles defrag just fine and is automated.
hi, GuiltySpark thank you for your help so far, below is the Emergency Scan still can't get rid of mysearchdial.com
Emsisoft Emergency Kit - Version 9.0
Last update: 10/01/2015 23:42:59
User account: ant-PC\ant
Scan settings:
Scan type: Smart Scan
Objects: Rootkits, Memory, Traces, C:\Windows\, C:\Program Files\, C:\Program Files (x86)\
Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off
Scan start: 10/01/2015 23:43:21
Key: HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\BROWSERCOMPANION detected: Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\FILETYPEASSISTANT detected: Application.InstallAd (A)
Scanned 267034
Found 2
Scan end: 11/01/2015 00:57:54
Scan time: 1:14:33
Ok we need to remove those traces;
Hold
Winkey+R to bring up a Run box.
Type "
Regedit" (minus quotes).
Navigate to
HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\BROWSERCOMPANION detected: Application.InstallAd (A)
Delete the entire
BrowserCompanion folder.
Navigate to
HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\FILETYPEASSISTANT detected: Application.InstallAd (A)
Delete the entire
FileTypeAssistant folder.
Download
SAS and select
System Tools ---
Uninstall Unwanted Programs;
[
attachment=88]
[
attachment=89]
If nothing is displayed, select the settings exactly as you see here;
[
attachment=90]
[
attachment=91]
Run a Full Scan.
To Reset IE fully follow this post :
https://malwaretips.com/blogs/start-mysearchdial-removal/#browser
Then Update and Run a Full Scan with MBAM (malwarebytes).
hi, GuiltySpark sorry I am bit confused how do you
Navigate to HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\BROWSERCOMPANION detected: Application.InstallAd (A)
Navigate to HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\FILETYPEASSISTANT detected: Application.InstallAd (A)
I did this Hold Winkey+R and Type "Regedit and then paste and copy under edit and find and but couldn't the them
sorry about please can you tell me what doing wrong, thank you
Please try this
Step 1
- Fix with FRST
Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
- Open Notepad.exe. Do not use any other text editor software;
- Copy and Paste the contents inside the code-box to your Notepad --
Code: [Select]
Code:
Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
HKLM-x32\...\Run: [] => [X]
HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\BROWSERCOMPANION
HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\FILETYPEASSISTANT
CMD: ipconfig /flushdns
End
- Click on File > Save as...
- Inside the File Name box type fixlist.txt
- From the Save as type drop down list, choose All Files
- Save the file to your Desktop;
- Re-run FRST.exe and click Fix;
- Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.
- After the completion, a log will be produced;
- Attach the log in your next reply.
thank you very much Britec for your help I try what you told me but mysearchdial.com is back below is the FRST.exe log
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-01-2015 02
Ran by ant at 2015-01-13 23:18:11 Run:1
Running from C:\Users\ant\Desktop
Loaded Profile: ant (Available profiles: ant & all)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
HKLM-x32\...\Run: [] => [X]
HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\BROWSERCOMPANION
HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\FILETYPEASSISTANT
CMD: ipconfig /flushdns
End
*****************
Restore point was successfully created.
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\BROWSERCOMPANION => Error: No automatic fix found for this entry.
HKEY_USERS\S-1-5-21-2908333697-2003391469-1437793153-1004\SOFTWARE\FILETYPEASSISTANT => Error: No automatic fix found for this entry.
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
EmptyTemp: => Removed 929.1 MB temporary data.
The system needed a reboot.
==== End of Fixlog 23:19:51 ====