Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

I.E. Home Page taken over [Closed]


  • This topic is locked This topic is locked

#1
Willie321

Willie321

    New Member

  • Member
  • Pip
  • 6 posts

AVG called for an update - did it - then restart PCG "groovorio" took over as home page. Made sure IE settings were correct and changed home page to Yahoo. Groovorio took over anyways. Couple of days later AVG window popped up calling for a 'restart' - click anywhere and the PC went into restart. Now the internet connection was broken.

Going back to an earlier restore point was the only way to get back on line again.

Ran 'disc cleanup' internal window of Win7

Ran IOBOT 

Ran AVG which ended in another restart and had to go back to an earlier restore point to get back on line.

Ran 'disc cleanup'

Ran CC Cleaner

Ran ADW Cleaner

Ran JRT

Ran Malwarebytes

Tried to remove AVG which locked up the computer

Now have given up with trying to fix this myself.

Ran OTLAttached File  OTL.Txt   90.51KB   57 downloads

Attached File  Extras.Txt   60.63KB   53 downloads


  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi sorry for the delay could I have a fresh look at your system

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 0

#3
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

User returned


  • 0

#5
Willie321

Willie321

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts

Thanks for the return

Attached are the FRST file and the Addition file also.

Willie

Attached Files


  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets get at it

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\runonceex: [] => [X]
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] fastprox.dll ATTENTION! ====> ZeroAccess?
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://groovorio.com...=1544403511&ir=
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKCU - {47E40571-6518-4AC0-A11C-318BBA8AE641} URL =
Toolbar: HKCU - No Name - {00000000-0000-0000-0000-000000000000} - No File
Handler: linkscanner - No CLSID Value -
Handler-x32: linkscanner - No CLSID Value -
CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd [2014-05-17]
CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fopdddcinljmpmioaklghcalngfhbaen [2014-02-25]
CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod [2013-12-13]
CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla [2012-11-11]
CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2012-11-11]
CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd [2014-02-06]
CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnfegheljpcijmdgonkecjpcaopjlpac [2013-02-01]
2014-10-26 19:04 - 2014-10-26 19:04 - 00000000 _____ () C:\autoexec.bat
C:\$Recycle.Bin\S-1-5-18\$b12dd0ee5c02ba0f692fdb04412864d8
C:\$Recycle.Bin\S-1-5-21-2014975827-1299050775-2003155660-500\$b12dd0ee5c02ba0f692fdb04412864d8
C:\Users\Administrator\g2ax_customer_downloadhelper_win32_x86.exe
C:\Users\Administrator\jagex_cl_runescape_LIVE.dat
C:\Users\Administrator\random.dat
C:\Users\Public\AlexaNSISPlugin.3372.dll
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
FINALLY

Download and run farbar service scanner

fssscan.JPG

Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.
  • 0

#7
Willie321

Willie321

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts

Ok

Attached are the log files for each step requested to be made.

Willie

Attached Files


  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Could you download and run the following small programme http://www.tweaking....lt_startup.html this will reset your services to default as some have been changed

Once done could you let me know what problems you are experiencing
  • 0

#9
Willie321

Willie321

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts

OK I downloaded and ran the program.

Problem is that Groovorio still remains the Home Page for internet explorer. I tried to change it to Yahoo.com through internet options and 'apply'. Then I did a restart of the pc and it again came up groovorio.com search home page. Nothing I can think of changes that from reoccurring.


  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Could you run a fresh FRST scan for me and I will see if I can locate the blighter. This time can you also tick the shortcut.txt option

frst.JPG
  • 0

#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP