HOMEPAGE browser Anda berubah menjadi Sweet-Page.com? Itu “virus” berupa “browser hijacker”. Hapus dengan Adware Cleaner (AdwCleaner).
Menurut Malware Tips, laman yang berbagi soal cara menghapus Sweet-Page dan malware lainnya:
“Sweet-Page.com is a browser hijacker, which is promoted via other free downloads, and once installed it will change your browser homepage to sweet-page.com.”
Intinya, “virus” malware Sweet-Page.com itu harus dihapus, dibasmi, dibunuh! Caranya:
- Download AdwCleaner di link ini: ADWCLEANER DOWNLOAD LINK (This link will automatically download AdwCleaner on your computer) atau donload disini (4shared)
- Sebelum install program AdwCleaner, tutup semua program dan browser internet yang sedang dibuka.
- Doble klik ikon AdwCleaner hasil download tadi (proses intall).
- Setelah install selesai, program AdwCleaner akan terbuka.
- Klik tombol Scan
- Selesai scanning, klik tomblol Clean. Bunuh semuanya!
Ini dia hasil kerja AdwCleaner di komputer saya sekaligus menghapus malware Sweet-Page.com.
# AdwCleaner v3.023 – Report created 04/04/2014 at 23:35:16
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Ultimate (32 bits)
# Username : 1 – 1-PC
# Running from : D:DOWNLOADSadwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:ProgramDataboost_interprocess
Folder Deleted : C:ProgramDataSNT
Folder Deleted : C:ProgramDataWPM
Folder Deleted : C:Program FilesMega Browse
Folder Deleted : C:Program FilesSNT
Folder Deleted : C:Users1AppDataLocalMobogenie
Folder Deleted : C:Users1AppDataLocaltorch
Folder Deleted : C:Users1AppDataLocalTempMega Browse
Folder Deleted : C:Users1DocumentsMobogenie
Folder Deleted : C:UsersFAMILYAppDataLocalConduit
Folder Deleted : C:UsersFAMILYAppDataLocalNativeMessaging
Folder Deleted : C:UsersFAMILYAppDataLocaltorch
Folder Deleted : C:UsersFAMILYAppDataLocalTempNativeMessaging
Folder Deleted : C:UsersFAMILYAppDataLocalLowConduit
Folder Deleted : C:UsersFAMILYAppDataRoamingbaidu
File Deleted : C:END
File Deleted : C:Users1AppDataRoamingMozillaFirefoxProfilesg9ak8vl0.defaultsearchpluginsWebSearch.xml
File Deleted : C:Users1AppDataRoamingMozillaFirefoxProfilesg9ak8vl0.defaultuser.js
File Deleted : C:Users1AppDataRoamingMozillaFirefoxProfilesmuewrru8.defaultuser.js
File Deleted : C:UsersFAMILYAppDataLocalGoogleChromeUser DataDefaultLocal Storagehxxp_app.mam.conduit.com_0.localstorage
File Deleted : C:UsersFAMILYAppDataLocalGoogleChromeUser DataDefaultLocal Storagehxxp_app.mam.conduit.com_0.localstorage-journal
File Deleted : C:UsersFAMILYAppDataLocalGoogleChromeUser DataDefaultLocal Storagehxxp_storage.conduit.com_0.localstorage
File Deleted : C:UsersFAMILYAppDataLocalGoogleChromeUser DataDefaultLocal Storagehxxp_storage.conduit.com_0.localstorage-journal
***** [ Shortcuts ] *****
Shortcut Disinfected : C:UsersPublicDesktopGoogle Chrome.lnk
Shortcut Disinfected : C:Users1DesktopFirefox NEW.lnk
Shortcut Disinfected : C:Users1DesktopFirefox OLD.lnk
Shortcut Disinfected : C:ProgramDataMicrosoftWindowsStart MenuProgramsMozilla Firefox.lnk
Shortcut Disinfected : C:ProgramDataMicrosoftWindowsStart MenuProgramsMozilla FirefoxMozilla Firefox (Safe Mode).lnk
Shortcut Disinfected : C:ProgramDataMicrosoftWindowsStart MenuProgramsMozilla FirefoxMozilla Firefox.lnk
Shortcut Disinfected : C:ProgramDataMicrosoftWindowsStart MenuProgramsGoogle ChromeGoogle Chrome.lnk
Shortcut Disinfected : C:Users1AppDataRoamingMicrosoftWindowsStart MenuProgramsInternet Explorer.lnk
Shortcut Disinfected : C:Users1AppDataRoamingMicrosoftWindowsStart MenuProgramsAccessoriesSystem ToolsInternet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:Users1AppDataRoamingMicrosoftInternet ExplorerQuick LaunchGoogle Chrome.lnk
Shortcut Disinfected : C:Users1AppDataRoamingMicrosoftInternet ExplorerQuick LaunchLaunch Internet Explorer Browser.lnk
Shortcut Disinfected : C:Users1AppDataRoamingMicrosoftInternet ExplorerQuick LaunchMozilla Firefox.lnk
Shortcut Disinfected : C:Users1AppDataRoamingMicrosoftInternet ExplorerQuick LaunchUser PinnedTaskBarGoogle Chrome.lnk
Shortcut Disinfected : C:Users1AppDataRoamingMicrosoftInternet ExplorerQuick LaunchUser PinnedTaskBarInternet Explorer.lnk
Shortcut Disinfected : C:Users1AppDataRoamingMicrosoftInternet ExplorerQuick LaunchUser PinnedTaskBarMozilla Firefox.lnk
***** [ Registry ] *****
Key Deleted : HKLMSOFTWAREMicrosoftTracingau__rasapi32
Key Deleted : HKLMSOFTWAREMicrosoftTracingau__rasmancs
Key Deleted : HKLMSOFTWAREMicrosoftTracingLiveSupport_RASAPI32
Key Deleted : HKLMSOFTWAREMicrosoftTracinglivesupport_rasmancs
Key Deleted : HKLMSOFTWAREMicrosoftTracingMobogenie_RASAPI32
Key Deleted : HKLMSOFTWAREMicrosoftTracingMobogenie_RASMANCS
Key Deleted : HKLMSOFTWAREMicrosoftTracingoptprostart_rasapi32
Key Deleted : HKLMSOFTWAREMicrosoftTracingoptprostart_rasmancs
Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp PathsMobogenieAdd
Value Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun [mobilegeni daemon]
Key Deleted : HKLMSOFTWAREMicrosoftTracingSoftonicDownloader_for_utorrent_RASAPI32
Key Deleted : HKLMSOFTWAREMicrosoftTracingSoftonicDownloader_for_utorrent_RASMANCS
Key Deleted : HKLMSOFTWAREClassesCLSID{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLMSOFTWAREClassesInterface{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLMSOFTWAREClassesInterface{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLMSOFTWAREClassesInterface{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLMSOFTWAREClassesTypeLib{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerSearchScopes{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Data Restored : HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetGoogle Chromeshellopencommand
Key Deleted : HKCUSoftwareAppDataLow{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLMSoftware{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLMSoftware{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLMSoftwaresupWPM
***** [ Browsers ] *****
-\ Internet Explorer v8.0.7600.16385
Setting Restored : HKLMSOFTWAREMicrosoftInternet ExplorerMain [Search Page]
-\ Mozilla Firefox v28.0 (en-US)
[ File : C:Users1AppDataRoamingMozillaFirefoxProfilesg9ak8vl0.defaultprefs.js ]
Line Deleted : user_pref(“browser.search.defaultenginename,S”, “WebSearch”);
Line Deleted : user_pref(“browser.search.defaulturl”, “hxxp://websearch.amaizingsearches.info/?pid=1091&r=2014/04/04&hid=10235128211098029313&lg=EN&cc=ID&unqvl=51&l=1&q=”);
Line Deleted : user_pref(“browser.search.order.1”, “WebSearch”);
Line Deleted : user_pref(“browser.search.order.1,S”, “WebSearch”);
Line Deleted : user_pref(“browser.search.selectedEngine,S”, “WebSearch”);
Line Deleted : user_pref(“extensions.0sd.scode”, “(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(“acebook”)>-1||url.indexOf(“txtlnkusaolp00000800”)>-1||url.indexOf(“sumorob[…]
Line Deleted : user_pref(“extensions.2Mua0n5fa.scode”, “(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(“acebook”)>-1||url.indexOf(“txtlnkusaolp00000800”)>-1||url.indexOf(“s[…]
Line Deleted : user_pref(“extensions.IwfG.scode”, “(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(“acebook”)>-1||url.indexOf(“txtlnkusaolp00000800”)>-1||url.indexOf(“sumoro[…]
Line Deleted : user_pref(“extensions.L1CjSWwAf.scode”, “(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(“acebook”)>-1||url.indexOf(“txtlnkusaolp00000800”)>-1||url.indexOf(“s[…]
Line Deleted : user_pref(“keyword.URL”, “hxxp://websearch.amaizingsearches.info/?pid=1091&r=2014/04/04&hid=10235128211098029313&lg=EN&cc=ID&unqvl=51&l=1&q=”);
[ File : C:Users1AppDataRoamingMozillaFirefoxProfilesmuewrru8.defaultprefs.js ]
Line Deleted : user_pref(“browser.startup.homepage”, “hxxp://websearch.amaizingsearches.info/?pid=1091&r=2014/04/04&hid=10235128211098029313&lg=EN&cc=ID&unqvl=51”);
[ File : C:UsersFAMILYAppDataRoamingMozillaFirefoxProfilescttpyw9p.defaultprefs.js ]
-\ Google Chrome v33.0.1750.154
[ File : C:Users1AppDataLocalGoogleChromeUser DataDefaultpreferences ]
[ File : C:UsersFAMILYAppDataLocalGoogleChromeUser DataDefaultpreferences ]
*************************
AdwCleaner[R0].txt – [39744 octets] – [28/02/2014 21:45:46]
AdwCleaner[R1].txt – [9773 octets] – [04/04/2014 23:33:36]
AdwCleaner[S0].txt – [36508 octets] – [28/02/2014 21:48:20]
AdwCleaner[S1].txt – [7978 octets] – [04/04/2014 23:35:16]
########## EOF – C:AdwCleanerAdwCleaner[S1].txt – [8038 octets] ##########