Explorer.exe has to be opened through task manager and is the only way I have any control over the PC at the moment. Step 2 Double-click the downloaded installer file to start the installation process. Now attach the below new logs and tell me how the above steps went. 1. Click the Scan button. check over here

If your PC takes a lot longer than normal to restart or your Internet connection is extremely slow, your computer may well be infected with Adware.ClickSpring.New desktop shortcuts have appeared or Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. Please go to the Microsoft Recovery Console and restore a clean MBR. Using the site is easy and fun.

Please tell me if there is need to do anything more. The left pane displays folders that represent the registry keys arranged in hierarchical order. What do I do? Thanks Attached Files: newfiles.txt File size: 40.9 KB Views: 1 spywarevictim77, May 6, 2007 #14 chaslang MajorGeeks Admin - Master Malware Expert Staff Member spywarevictim77 said: ↑ I have now

C:\WINDOWS\system32\qtstv.tmp C:\WINDOWS\system32\ghhkj.ini C:\WINDOWS\system32\ghhkj.ini2 Don't use Killbox. BLEEPINGCOMPUTER NEEDS YOUR HELP! A Adware-PurityScan.dr infection can be as harmless as showing annoying messages on your screen, or as vicious as disabling your computer altogether. Your Windows Registry should now be cleaned of any remnants or infected keys related to Adware-PurityScan.dr.

It should be in its own folder, not in your documents or on the desktop! Because of this, spyware, malware and adware often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.To Combo Fix log TimW, May 5, 2007 #5 spywarevictim77 Private E-2 Hi, I followed the steps you suggested. https://home.mcafee.com/virusinfo/virusprofile.aspx?key=2789905 If you require support, please visit the Safety & Security Center.Other Microsoft sitesWindowsOfficeSurfaceWindows PhoneMobile devicesXboxSkypeMSNBingMicrosoft StoreDownloadsDownload CenterWindows downloadsOffice downloadsSupportSupport homeKnowledge baseMicrosoft communityAboutThe MMPCMMPC Privacy StatementMicrosoftCareersCitizenshipCompany newsInvestor relationsSite mapPopular resourcesSecurity and privacy

How to remove, how to protect, how to identify. Note the creation date of Apr 28th. and the help from you, well to be blunt, I would of just been screwed! Use analyse.exe for the new name.

THANK YOU AGAIN!!! Clicking Here Several functions may not work. Attached Files: hijackthis.log File size: 5.2 KB Views: 0 newfiles.txt File size: 41.5 KB Views: 1 runkeys.txt File size: 26.4 KB Views: 0 spywarevictim77, May 5, 2007 #6 spywarevictim77 Private E-2 Step 16 ClamWin starts the scanning process to detect and remove malware from your computer.

You still have part of a Purity Scan infection showing. http://avissoft.net/general/adware-win32-agent-at.php HJT 4. I will really appreciate your help, as the performance of my computer is severly affected, and it has become very difficult to do any work. If we had you run Avenger, you can delete all files related to Avenger now.

These conventions are explained here.Select the file or folder and press SHIFT+Delete on the keyboard.Click Yes in the confirm deletion dialog box.IMPORTANT: If a file is locked (in use by some We bought it but it didn't get rid of the CID popups. ClickspringAliases of Clickspring (AKA):[Kaspersky]AdWare.Win32.PurityScan.en, Trojan-Downloader.Win32.PurityScan.cu, Trojan-Downloader.Win32.PurityScan.dad, AdWare.Win32.PurityScan.ep, Trojan.Win32.Scapur.k, Trojan-Downloader.Win32.PurityScan.cr, AdWare.Win32.PurityScan.ak, Adware.Win32.PurityScan.ak, Trojan-Downloader.Win32.PurityScan.eg[McAfee]Downlaoder-EV, Downloader-EV, Adware-ClickSpring[Other]Adware.Purityscan, Win32/Clspring.FD, Win32/Clspring.FA, Win32/Clspring.FF, Win32/Clspring.FE, Adware-Purityscan, Win32/ClickSpring.FH, Win32.Clspring.EZ, AdWare.Win32.PurityScan.en, Win32/Clspring.FB, Trojan.Popper, Win32?ClickSpring.FB, Win32/Clspring.EM, Win32/Clspring.FC, Win32/Clspring.FR, Win32/Clspring.FU, Win32/Clspring.FW, Win32/Clickspring.GM, this content Best money I ever spent on a piece of software.

Adware-PurityScan.dr can gain entry onto your computer in several ways. Although it has been removed from your computer, it is equally important that you clean your Windows Registry of any malicious entries created by Adware-PurityScan.dr. Also, I tried but could not boot my computer in safe-mod, so these scans were done with normal windows boot mode.

My husband says and I quote I am a believer!

To get rid of Adware-PurityScan.dr, the first step is to install it, scan your computer, and remove the threat. Click here to Register a free account now! Step 3 Click the Next button. Solvusoft's close relationship with Microsoft as a Gold Certified Partner enables us to provide best-in-class software solutions that are optimized for performance on Windows operating systems.

Can you locate and delete this folder: C:\Program Files\Common Files\??crosoft Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one Home Software Products WinThruster DriverDoc WinSweeper SupersonicPC FileViewPro About Support Contact Malware Encyclopedia › Viruses › Adware-PurityScan.dr How to Remove Adware-PurityScan.dr (Viruses) Overview Aliases Behavior Risk Level: LOW Threat Name:Adware-PurityScan.dr Threat Then after it deletes the files click the Exit (Save Settings) button. have a peek at these guys The right one lists the registry values of the currently selected registry key.To delete each registry key listed in the Registry Keys section, do the following:Locate the key in the left

Here is the log from ComboFix: "AlfonsoPrincep" - 2007-06-01 9:51:07 Service Pack 2 ComboFix 07-05.27.BV - Running from: "C:\Downloads\" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) "C:\WINDOWS\system32\wnsapitr.exe" "C:\Temp\tn3" -- Purity Folders: C:\WINDOWS\MCROSO~1.NET ((((((((((((((((((((((((((((((((((((((((((( Drivers/Services Thanks. They are spread manually, often under the premise that the executable is something beneficial. The red color spreads throughout the disc to indicate whether a threat is moderate, high or severe.PreviousNextSummaryWhat to do nowTechnical informationSymptoms Symptoms This program was detected by definitions prior to 1.175.1915.0 as

But I did not connect it during the time I was running these antispywares, not connected in the past whole week as a matter of fact. Select: * Delete on Reboot * then Click on the All Files button.*(or on the folders option)* * Please copy the file paths below to the clipboard by highlighting ALL of Register now! You are running HJT from the wrong location ....please uninstall and re-install as directed in the Read and Run First instructions.

I really appreciate your help Attached Files: AVG-Report-Scan-20070430-202404.txt File size: 18.4 KB Views: 1 BitDefender-ScanReport.txt File size: 42.3 KB Views: 1 Pandascan.txt File size: 11.1 KB Views: 1 spywarevictim77, May He is a lifelong computer geek and loves everything related to computers, software, and new technology. By continuing to use this site, you are agreeing to our use of cookies. Browser Hijackers may tamper with the browser settings, redirect incorrect or incomplete URLs to unwanted Web sites, or change the default home page.

e.g. %WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000) %PROGRAMFILES% = \Program Files The following files were analyzed: A8559B0794C08AC1579E61D1FFB4442A49383FCA The following files have been added to the system: %TEMP%\nso9.tmp%APPDATA%\adau.exe%TEMP%\wups.exe%TEMP%\ERRORLOG.TXT%PROGRAMFILES%\PurityScan\PuritySCANUninstall.exe The following chaslang, May 6, 2007 #15 spywarevictim77 Private E-2 Yes, those files were still there, i now deleted those. Indication of Infection This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.