Good afternoon from a wet, windy and miserable Cornwall
The automated tools have now done their job so it is time to clear the rest manually
Also, getting pop up window that says "Windows is updating and will restart your computer in [minutes]. Don't know what that's all about, but scares me.
This may be the legitimate windows update, we will check that later
1. Did you install
Barnes & Noble eBooks ?
2. What antivirus programme are you using ?
3. You will need to reset Chrome manually due to the way it is structured... However there is a nice step by step guide here
https://support.goog...296214?hl=en-GBWarning This fix is only relevant for this system and no other, using on another computer may cause problems Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot Run OTL
- Under the Custom Scans/Fixes box at the bottom, paste in the following
:Commands
[CREATERESTOREPOINT]
:OTL
IE - HKU\S-1-5-21-242505160-1997802447-1459611069-1000\..\SearchScopes\{6EC80DCE-924F-4D21-A6DB-99533CC89F4E}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3315827&CUI=UN14389472257264129&UM=2
IE - HKU\S-1-5-21-242505160-1997802447-1459611069-1000\..\SearchScopes\{AF75D30E-A7A7-402C-8ED6-68D7F6F65EC9}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000031&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=15E01AFB-2266-4228-BDFC-D1F91918C538&apn_sauid=5120A5AF-01C2-4499-B39E-C2BB7E62D3C2
[2013/04/11 17:14:13 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Beverly\AppData\Roaming\Mozilla\Firefox\Profiles\8ungfprm.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013/09/26 10:01:04 | 000,000,000 | ---D | M] ("QuickShare Widget") -- C:\Users\Beverly\AppData\Roaming\Mozilla\Firefox\Profiles\8ungfprm.default\extensions\{c9757d0b-0a67-7541-24ed-357408894e07}
[2013/04/11 17:14:12 | 000,000,000 | ---D | M] ("I Want This") -- C:\Users\Beverly\AppData\Roaming\Mozilla\Firefox\Profiles\8ungfprm.default\extensions\[email protected]
[2014/02/26 16:40:44 | 000,000,000 | ---D | M] (SavingsBull) -- C:\Users\Beverly\AppData\Roaming\Mozilla\Firefox\Profiles\8ungfprm.default\extensions\SavingsBull@jetpack
[2010/05/21 09:14:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2013/04/11 17:13:42 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2013/09/26 09:55:13 | 000,000,000 | ---D | M] (WordOv) -- C:\Program Files (x86)\Mozilla Firefox\extensions\[email protected]
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-242505160-1997802447-1459611069-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-242505160-1997802447-1459611069-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-242505160-1997802447-1459611069-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
[2014/03/01 10:38:38 | 000,000,000 | ---D | C] -- C:\30816ea773987a37db
[2014/02/26 16:40:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SavingsBull
[2014/02/24 13:53:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Uninstaller
[2014/02/24 13:34:33 | 000,000,000 | ---D | C] -- C:\Users\Beverly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Alerts
[2014/02/28 19:58:58 | 000,000,422 | ---- | M] () -- C:\Windows\tasks\DriverUpdate Startup.job
[2014/02/28 19:54:42 | 000,000,498 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job
[2014/02/28 18:17:44 | 000,000,468 | ---- | M] () -- C:\Windows\tasks\SparkTrust Registration3.job
[2014/02/26 19:09:02 | 000,001,364 | ---- | M] () -- C:\Users\Beverly\Desktop\SparkTrust PC Cleaner Plus.lnk
[2014/02/26 16:55:06 | 000,000,571 | ---- | M] () -- C:\Users\Beverly\AppData\Roaming\aps.scan.quick.results
[2014/02/26 16:52:03 | 000,000,391 | ---- | M] () -- C:\Users\Beverly\Desktop\FREE Games.url
[2013/01/17 14:27:02 | 000,000,498 | ---- | C] () -- C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
[2013/11/13 09:55:17 | 000,000,422 | ---- | C] () -- C:\Windows\Tasks\DriverUpdate Startup.job
[2014/02/26 19:09:23 | 000,000,468 | ---- | C] () -- C:\Windows\Tasks\SparkTrust Registration3.job
:Files
C:\Users\Beverly\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngaeinfoeljecnggcbonnohnjpepenmb
ipconfig /flushdns /c
ipconfig /release /c
ipconfig /renew /c
netsh winsock reset /c
netsh advfirewall reset /c
:Commands
[resethosts]
[emptytemp]
[Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
- Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.