Adware:Win32/OpenCandy Virus is a malicious adware program. Our expert team classified is as Adware. This infection, Adware:Win32/OpenCandy Virus, makes your personal computer almost unusable. Sometime this change Proxy setting to block any external communication to other web site. It also blocks downloads. It is important to get rid of this, Adware:Win32/OpenCandy Virus, as soon as possible to avoid further damage to you computer or even worst losing important files, pictures and video files. Like all other rogueprogram like this parasite it is extremely difficult to remove manually. To fix your pc yourself and remove infection program like Adware:Win32/OpenCandy simply follow these steps.

How to remove Adware:Win32/OpenCandy Steps :

Step 1:Print out these instructions as you will need to shutdown the computer in next step.

Step 2:Now power down the Adware:Win32/OpenCandy infected computer. And wait for 30 Seconds before you turn on

Step 3:Now please turn ON the computer and immediately keep hitting F8 until you see WINDOWS ADVANCED OPTIONS MENU as shown below.
Adware:Win32/OpenCandy Virus - F8 Key

Step 4:In the WINDOWS ADVANCED OPTIONS MENU, go down to the SAFE MODE WITH NETWORKING using the arrow keys on the board. Then press ENTER on the keyboard. This will take your computer to Safe mode. Safe Mode will cause the display and desktop icons to appear changed. This is normal. No need to Panic as it is due to Adware:Win32/OpenCandy.

Adware:Win32/OpenCandy Virus - Safe mode Option

Step 5:This, Adware:Win32/OpenCandy, infection may change computer windows settings to use a proxy server that will not allow you to browse any pages on the Internet with Internet Explorer. We will first need to fix this as we will need to download malware removal utilities. They are safe and very reputed in Computer Industry. Now hold down the WINDOWS key and then press the R key.
Adware:Win32/OpenCandy Virus - Run command Prompt

Step 6:The RUN dialog box will appear. Type iexplore.exe In the RUN dialog and click OK button.
Adware:Win32/OpenCandy Virus - Run command Prompt

Step 7:You will see Internet Explorer. On the top navigation click TOOLS then under the sub-menu of TOOLS choose INTERNET OPTIONS as shown below.
Adware:Win32/OpenCandy Virus - IE Option

Step 8: Now find the CONNECTIONS tab within the INTERNET OPTIONS dialog box and click on it. Then click the LAN SETTINGS button.
Adware:Win32/OpenCandy Virus - LAN settings

Step 9:If there is a check-mark in the box named ‘Use a proxy server for your LAN’, under the PROXY SERVER section, then uncheck the box. If there is not a check mark located in the box then you can skip this step and move on to next step.
Adware:Win32/OpenCandy Virus - proxy

Step 10:Now hit the OK button to close the LOCAL AREA NETWORK dialog box. Then press the OK button to close the INTERNET OPTIONS dialog box.

Step 11Now we must end all the processes that belong to Adware:Win32/OpenCandy so that it does not interfere with your ability clear your computer. Inspector-[random char].exe and Protector-[ random char].exe are the processed that needs to be stopped. To do this we need to download Rkill, developed by Bleepingcomputer to help stop the computer process of Adware:Win32/OpenCandy. Now please hold down the WINDOWS key and the R key simultaneously to open RUN dialog box.
Adware:Win32/OpenCandy Virus - Run command Prompt

Step 12Now type ‘iexplore.exe’ and hit the OK button.
Adware:Win32/OpenCandy Virus - Rkill

Step 13:Save the Rkill.exe on your desktop. Double-click the Rkill icon and run Rkill.exe. You will see a black MS DOS dialog box. Now it will kill all the processes of Adware:Win32/OpenCandy. It will take several minute before a Notepad file containing log information on what Rkill found will open. You may review it and close notepad file.

Step 14:Now you are ready to removal all the infection related to Adware:Win32/OpenCandy. For the you need to Malwarebytes. Malwarebytes is a very popular malware and spyware removal application. Now please hold down the WINDOWS key and the R key simultaneously to open RUN dialog box. Type ‘iexplore.exe’ and hit the OK button.
Adware:Win32/OpenCandy Virus - Malwarebytes

Step 15:Save the mbam.exe on your desktop. Double-click the Malwarebytes icon and run mbam.exe. Now the SELECT SETUP LANGUAGE dialog box will appear. Select your preferred language and hit press OK button.
Adware:Win32/OpenCandy Virus - Malwarebytes Language

Step 16:The Malwarebytes SETUP WIZARD will show blow screen Hit the NEXT button to continue.
Adware:Win32/OpenCandy Virus - Malwarebytes Wizard

Step 17:Now the LICENSE AGREEMENT screen will appear as shown. Accept the agreement and hit NEXT button.
How to remove Adware:Win32/OpenCandy Virus - Malwarebytes License Agreement

Step 18:Now the Information screen will appear. Click on next button and continue following the steps.
How to remove Adware:Win32/OpenCandy Virus - Malwarebytes Information

Step 19:SELECT DESTINATION LOCATION screen will appear now. You can choose the location where Malwarebytes can be install. We recommend to choose the default location as shown then click NEXT button.
How to remove Adware:Win32/OpenCandy Virus - Malwarebytes Install path

Step 20:Now the SELECT START MENU FOLDER screen will appear. Let the default as it is and click NEXT button.
How to remove Adware:Win32/OpenCandy Virus - Malwarebytes Folder

Step 21:Now the SELECT ADDITIONAL TASKS screen will appear. If you want a Desktop Icon or Quick Launch icon then check appropriate boxes.
How to remove Adware:Win32/OpenCandy Virus - shortcut

Step 22:READY TO INSTALL screen will come next. Hit the INSTALL button to install Malwarebytes.
Remove Adware:Win32/OpenCandy Virus - Ready to Install

Step 23:In this step let the UPDATE and LAUNCH checked as it is to update the application with latest malware definition to capture all the malwares then click FINISH button.
How to remove Adware:Win32/OpenCandy Virus - Updates

Step 24:Once update is done then Scanner screen will launch. Make sure to select PERFORM FULL SCAN is selected to clean up Adware:Win32/OpenCandy infection. Click on SCAN button to start the scan.
How to remove Adware:Win32/OpenCandy Virus - full scan

Step 25:Now choose the local drives that you want to scan from the dialog box and click SCAN button.
How to remove Adware:Win32/OpenCandy Virus - drive

Step 26:Be patient as the scan will take several minutes before it cleans up Adware:Win32/OpenCandy infection. Once the scan is finished, a message box saying the scan is complete will appear. Click OK button to close the box then click SHOW RESULTS button.
How to remove Adware:Win32/OpenCandy Virus - drive

Step 27:From results dialog box choose REMOVE SELECTED button to remove all the infections found. Malwarebytes will also delete all of the files and registry keys affected by Adware:Win32/OpenCandy and add them to the quarantine.
Adware:Win32/OpenCandy Virus - quarantine

Step 28:Malwarebytes may required you to reboot the PC to complete the removal of Adware:Win32/OpenCandy. After completion reboot your computer Malwarebytes will be relaunched, please follow the instructions on the screen and continue the removal process. Once everything is clean out a log will be open created by Malwarebytes. Please reviewed it and closed it. Now your computer should be free of Adware:Win32/OpenCandy. Enjoy.
Adware:Win32/OpenCandy Virus - Complete

Technical Details of Adware:Win32/OpenCandy files :
You need to delete following Adware:Win32/OpenCandy files:

%AllUsersProfile%\Application Data\~
%AllUsersProfile%\Application Data\~r
%AllUsersProfile%\Application Data\.dll
%AllUsersProfile%\Application Data\.exe
%AllUsersProfile%\Application Data\
%AllUsersProfile%\Application Data\.exe
%UserProfile%\Start Menu\Programs\Adware:Win32/OpenCandy\
%UserProfile%\Start Menu\Programs\Adware:Win32/OpenCandy\Uninstall Adware:Win32/OpenCandy.lnk
%UserProfile%\Start Menu\Programs\Adware:Win32/OpenCandy\Adware:Win32/OpenCandy.lnk
Windows Vista & 7:
%UserProfile%\Start Menu\Programs\Adware:Win32/OpenCandy\
%UserProfile%\Start Menu\Programs\Adware:Win32/OpenCandy\Uninstall Adware:Win32/OpenCandy.lnk
%UserProfile%\Start Menu\Programs\Adware:Win32/OpenCandy\Adware:Win32/OpenCandy.lnk

Also please delete Adware:Win32/OpenCandy registry file:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ‘.exe’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings ‘CertificateRevocation’ = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System ‘DisableTaskMgr’ = ’1′
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system ‘DisableTaskMgr’ = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings ‘WarnonBadCertRecving’ = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop ‘NoChangingWallPaper’ = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations ‘LowRiskFileTypes’ = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments ‘SaveZoneInformation’ = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download ‘CheckExeSignatures’ = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main ‘Use FormSuggest’ = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ‘Hidden’ = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ‘ShowSuperHidden’ = 0′

Adware:Win32/OpenCandy Symptoms:

Changes browser settings
Shows popping ads
Browser window open up itself
Slow running computer

Removal guide of Adware Win32/ Open Candy virus(how to remove it using YouTube Video):

15 Thoughts on “How to get rid of Adware:Win32/OpenCandy Virus

  1. Followed the directions to a tee…MSE is still saying I have it!!!

  2. Pingback: Evan Litchfield

  3. gonna try it out 😐

  4. Kid blue on August 6, 2012 at 7:29 am said:

    I am sure this will fix my laptop but how am I suppose to download anything if the virus won’t let me go on the Internet at all? Please help. Thx!

  5. Sabrina Lai on July 27, 2012 at 12:59 pm said:

    Thank you for sharing this. I was able to remove this adware myself.

  6. Kathy Weed on June 7, 2012 at 6:29 am said:

    Searched for this issue on Google and after flipping couple of site I found you. I had doubt that your solution would work but I gave shot and it did work. There are some issues still left. But it worked. Thank you,

  7. Ivan Hodge on June 2, 2012 at 1:01 pm said:

    To the point and this what exactly I was looking for. My computer is back online and working fine. Only issue I have left with hidden encrypted file. But I guess I can live with it. Thanks for doing this.

  8. Alan Grahm on May 26, 2012 at 12:23 pm said:

    Working like Charm. Thanks.

  9. Denise Gillmore on May 25, 2012 at 8:30 pm said:

    Good Article. This really worked as it says.

  10. James on May 25, 2012 at 3:43 pm said:

    I like your blog. It really help me over come my issues. Love you guys.

  11. Richard on May 23, 2012 at 5:35 pm said:

    First I tried spyware doctor but realized I have to pay for it. Then I follow your instruction and downloaded and ran software your mentioned in safe mode with networking. Now my problem with this issue is gone.

  12. Steve Potter on May 21, 2012 at 2:45 am said:

    This really worked. Thanks for helping me out and save me some money….

  13. Betty Cook on May 11, 2012 at 6:30 am said:

    Hi my friend! I wish to say that this post is awesome, nice written and include approximately all important infos. I’d like to see more posts like this.

  14. George Wills on May 6, 2012 at 4:30 pm said:

    Thanks for sharing this articles. I was able to fix my PC using this help tool.

  15. Rick Sary on May 2, 2012 at 2:09 am said:

    I was recommended this website by my cousin. I am no sure whether this publish is written by him as nobody else know such distinct approximately my difficulty. You are wonderful! Thank you!

Leave a Reply

Your email address will not be published. Required fields are marked *

Post Navigation