Author Topic: delta toolbar  (Read 3802 times)

0 Members and 1 Guest are viewing this topic.

BCLAMPTON

  • Guest
delta toolbar
« on: March 31, 2013, 01:49:43 AM »
I HAVE TRIED TO REMOVE THIS FROM MY COMPUTER BUT NO LUCK.  cAN ANYBODY HELP PLEASE.
bERYL

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: delta toolbar
« Reply #1 on: March 31, 2013, 03:10:26 AM »
first run AdwCleaner....click delete....attach log here
then run malwarebytes quick scan.....click remove selected....attach log

you find the tools here.   http://forum.avast.com/index.php?topic=53253.0

when done attach OTL diagnostic log and a removal expert will check it tomorrow for any leftovers


BCLAMPTON

  • Guest
Re: delta toolbar
« Reply #2 on: March 31, 2013, 03:33:53 AM »
log attached.  Hope it is correct.

Beryl

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: delta toolbar
« Reply #3 on: March 31, 2013, 11:01:26 AM »
log attached.  Hope it is correct.

Beryl
yes....did that solve your problem?

also attach malwarebytes and OTL log


BCLAMPTON

  • Guest
Re: delta toolbar
« Reply #4 on: March 31, 2013, 11:19:27 AM »
Yes, it has gone.  Thank you.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: delta toolbar
« Reply #5 on: March 31, 2013, 11:41:40 AM »
Yes, it has gone.  Thank you.
when you have attached malwarebytes and OTL log a removal expert will look for any leftover files that need to be removed


BCLAMPTON

  • Guest
Re: delta toolbar
« Reply #6 on: March 31, 2013, 02:24:05 PM »
Can't find anything with otl.free on it.


Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: delta toolbar
« Reply #7 on: March 31, 2013, 02:54:06 PM »
Hi,


Start > Run, copy - paste the content below
Code: [Select]
notepad  C:\Program Files\PATCH.BATEnter

Notepad will be open with contents. Save that notepad to your desktop ( file > save us ) and attach it here.
------------------------------------------

Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]

:OTL
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=fmtoby&chnl=fmtoby&cd=2XzuyEtN2Y1L1QzutDtDtCyBtAtCtAtCyBtCtB0AyB0AzytDtN0D0Tzu0CtBtDtDtN1L2XzutBtFtCtFtDtFtAtDtC&cr=1245145440
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.clampton.com/
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes,Backup.Old.DefaultScope = {0CFF4DA9-D584-47E8-AFDA-43D049082B70}
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes\{0CFF4DA9-D584-47E8-AFDA-43D049082B70}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=fmtoby&chnl=fmtoby&cd=2XzuyEtN2Y1L1QzutDtDtCyBtAtCtAtCyBtCtB0AyB0AzytDtN0D0Tzu0CtBtDtDtN1L2XzutBtFtCtFtDtFtAtDtC&cr=1245145440
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}: "URL" = http://search.alot.com/web?q={searchTerms}&pr=prov&client_id=D079994001CC0F1D1EFEB21A&install_time=2011-05-10T14:23:26Z&src_id=12251&camp_id=2556&tb_version=2.5.18000.3
IE - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\SearchScopes\{73F57A96-B175-4A4D-97FC-C92FB76C86CE}: "URL" = http://websearch.ask.com/custom/java/redirect?client=ie&tb=ORJ&o=100000028&src=crm&q={searchTerms}&locale=&apn_ptnrs=U4&apn_dtid=OSJ000
CHR - homepage: http://www.delta-search.com/?affID=120519&tt=190313_wctrl&babsrc=HP_ss&mntrId=6C6A00173131712A
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\WebBrowser: (no name) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - No CLSID value found.
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKU\S-1-5-21-854245398-1409082233-725345543-1004\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-CFC3-3CECC9AB2EDA} - No CLSID value found.
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA5F15C4
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:40FEC790
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9

:FILES
C:\Install.exe
ipconfig /flushdns /c
ipconfig /release /c
ipconfig /renew /c

:COMMANDS
[CREATERESTOREPOINT]
[emptytemp]

  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
-----------------------------------



  Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


************************


Re-run OTL, just click on QuickScan and attach fresh OTL.txt logreport.