We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
The Forum is currently experiencing technical issues which the team are working to resolve. Thank you for your patience.
Please help with Reg Clean Pro...Laptop only 3 weeks old

xxlaurissaxx
Posts: 2,253 Forumite
in Techie Stuff
My OH parents bought a laptop from large chain 3 weeks ago which has windows 8.
After each switch on and after fully loading a pop up keeps appearing with a red banner which says alert.
Note on pop up -
Advanced System Protector has detected 1 items. It is highly recommended to clean them immediately.
Underneath the wording there is a green box with clean now and underneath that it has Microsoft Partner Gold ISV.
I noticed they had Reg clean pro which I uninstalled as I read that this programme is a scam but still getting this pop up.
Can someone tell me what this is and how to get rid of it please?
I have ran avast and AVG but nothing was detected also they already Norton on the laptop. Any help and advice would be greatly appreciated.
Thanks
After each switch on and after fully loading a pop up keeps appearing with a red banner which says alert.
Note on pop up -
Advanced System Protector has detected 1 items. It is highly recommended to clean them immediately.
Underneath the wording there is a green box with clean now and underneath that it has Microsoft Partner Gold ISV.
I noticed they had Reg clean pro which I uninstalled as I read that this programme is a scam but still getting this pop up.
Can someone tell me what this is and how to get rid of it please?
I have ran avast and AVG but nothing was detected also they already Norton on the laptop. Any help and advice would be greatly appreciated.
Thanks
0/2013
:beer:
:beer:
0
Comments
-
if the uninstaller doesn't work, you could try malwarebytes and kaspersksy, or factory restore it.!!
> . !!!! ----> .0 -
AdwCleaner - http://www.bleepingcomputer.com/download/adwcleaner/
Sample log - http://www.bleepingcomputer.com/forums/t/487099/malwarebytes-found-svchost-virus/?p=2991271# AdwCleaner v2.113 - Logfile created 03/01/2013 at 09:04:53
# Updated 23/02/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Narayan - NARAYAN-VAIO
# Boot Mode : Safe mode with networking
# Running from : C:\Users\Narayan\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted : C:\Program Files (x86)\Advanced System Protector
Folder Deleted : C:\Program Files (x86)\Ask.com
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\Free_TV_Bar_c3
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
Folder Deleted : C:\ProgramData\Partner
If that doesn't do the job...
Junkware Removal Tool - http://www.bleepingcomputer.com/download/junkware-removal-tool/
sample log - http://www.geekstogo.com/forum/topic/329044-removal-of-opitmizer-pro-speed-guard/page__view__findpost__p__2282263Successfully deleted: [Registry Key] hkey_current_user\software\systweak
Successfully deleted: [Registry Key] hkey_local_machine\software\systweak
Successfully deleted: [Folder] "C:\ProgramData\systweak"
Successfully deleted: [Folder] "C:\Users\Don\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Program Files (x86)\advanced system protector"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\advanced system protector"0 -
thank you, I will give those a go tonight when I get home and report back0/2013
:beer:0 -
ok did malwarebytes and it never found anything so ran adw and this is what I got -
# AdwCleaner v2.301 - Logfile created 05/30/2013 at 21:48:04
# Updated 16/05/2013 by Xplode
# Operating system : Windows 8 (64 bits)
# User : ANNE - ANNED-PC
# Boot Mode : Normal
# Running from : C:\Users\ANNE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XGZ2FNK3\AdwCleaner.exe
# Option [Search]
***** [Services] *****
Found : CltMngSvc
***** [Files / Folders] *****
File Found : C:\Users\Public\Desktop\eBay.lnk
Folder Found : C:\Program Files (x86)\Advanced System Protector
Folder Found : C:\Program Files (x86)\Begin-download_FLV_B2
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\SearchProtect
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
Folder Found : C:\Users\ANNE\AppData\Local\Conduit
Folder Found : C:\Users\ANNE\AppData\LocalLow\Begin-download_FLV_B2
Folder Found : C:\Users\ANNE\AppData\LocalLow\Conduit
Folder Found : C:\Users\ANNE\AppData\LocalLow\PriceGong
Folder Found : C:\Users\ANNE\AppData\Roaming\SearchProtect
***** [Registry] *****
Key Found : HKCU\Software\AppDataLow\Software\Begin-download_FLV_B2
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BD8006AA-6E85-4B36-BB42-7F97053D5B70}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{97601339-4946-46E8-B272-7434FA69E066}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD8006AA-6E85-4B36-BB42-7F97053D5B70}
Key Found : HKCU\Software\SearchProtect
Key Found : HKLM\Software\Begin-download_FLV_B2
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3297964
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{97601339-4946-46E8-B272-7434FA69E066}
Key Found : HKLM\Software\SearchProtect
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97601339-4946-46E8-B272-7434FA69E066}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BD8006AA-6E85-4B36-BB42-7F97053D5B70}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0A1F77D0-2BBB-4066-8CC5-F79878E217DD}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BBB96EA5-DDEF-4BC4-8DFD-6DE1B0566927}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BD8006AA-6E85-4B36-BB42-7F97053D5B70}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Begin-download_FLV_B2 Toolbar
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BD8006AA-6E85-4B36-BB42-7F97053D5B70}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BD8006AA-6E85-4B36-BB42-7F97053D5B70}]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [searchprotect]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{BD8006AA-6E85-4B36-BB42-7F97053D5B70}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{BD8006AA-6E85-4B36-BB42-7F97053D5B70}]
***** [Internet Browsers] *****
-\\ Internet Explorer v10.0.9200.16537
[OK] Registry is clean.
*************************
AdwCleaner[R1].txt - [3807 octets] - [30/05/2013 21:48:04]
########## EOF - C:\AdwCleaner[R1].txt - [3867 octets] ##########
Is there anything there I should worry about?0/2013
:beer:0 -
Get revo uninstaller!
Just the free one should do, then you can REALLY delete the offending program:A:jLibertas Supra Omnia:j:A0 -
I did junkware removal and this is what I got? -
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 8 x64
Ran by ANNE on 30/05/2013 at 21:54:20.91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Failed to stop: [Service] cltmngsvc
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotect
Failed to delete: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotectall
Failed to delete: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\searchprotectall
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\systweak
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\pricegong
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\systweak
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT3297964
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A7F76DB8-51F8-493A-8C42-95C1C3B26DB1}
~~~ Files
~~~ Folders
Failed to delete: [Folder] "C:\ProgramData\systweak"
Successfully deleted: [Folder] "C:\Users\ANNE\AppData\Roaming\searchprotect"
Successfully deleted: [Folder] "C:\Users\ANNE\AppData\Roaming\systweak"
Failed to delete: [Folder] "C:\Users\ANNE\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\ANNE\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\ANNE\appdata\locallow\pricegong"
Failed to delete: [Folder] "C:\Program Files (x86)\advanced system protector"
Failed to delete: [Folder] "C:\Program Files (x86)\conduit"
Failed to delete: [Folder] "C:\Program Files (x86)\searchprotect"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\advanced system protector"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30/05/2013 at 21:57:32.03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~0/2013
:beer:0 -
So does that mean that systweak is still on my computer? as it says at the top its deleted then failed to delete.....ill try revo just now0/2013
:beer:0 -
Run AdwCleaner again but select Delete option.0
-
Please download the uninstaller from the link below:
http://systweak.s3.amazonaws.com/test/rcpsetup_uninstaller.exe
Please save it on your system and then double click on it.
The program will be removed from your PC.
Found this0 -
I went to uninstall programme and removed the systweak and conduit which seems to have worked as the pop up has stopped and I can't see it anywhere else. Thanks everyone0/2013
:beer:0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 350K Banking & Borrowing
- 252.7K Reduce Debt & Boost Income
- 453.1K Spending & Discounts
- 242.9K Work, Benefits & Business
- 619.8K Mortgages, Homes & Bills
- 176.4K Life & Family
- 255.9K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 15.1K Coronavirus Support Boards