NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
start CloseProcesses: CreateRestorePoint: HKLM-x32\...\Run: [] => [X] CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION URLSearchHook: HKU\S-1-5-21-2524362192-1030358035-3349164945-1001 - (No Name) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - No File SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes:HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2524362192-1030358035-3349164945-1001 -> {C7D11109-9DB6-4F16-BF00-D3877CF4895A} URL = BHO: No Name -> {BAC72C85-CEC6-4B86-AF06-FA20C259FAB8} -> No File BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File BHO-x32: No Name -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> No File Toolbar: HKU\S-1-5-21-2524362192-1030358035-3349164945-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-2524362192-1030358035-3349164945-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Toolbar: HKU\S-1-5-21-2524362192-1030358035-3349164945-1001 -> No Name - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - No File Toolbar: HKU\S-1-5-21-2524362192-1030358035-3349164945-1001 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?tpid=ORJ&o=100000031&pf=V5&p2=%5ETV%5EOSJ000%5EYY%5EUS&gct=&itbv=12.10.3.24&doi=2014-02-04&apn_uid=74D8080F-3096-45F9-A138-67D67895FCF2&apn_ptnrs=%5ETV&apn_dtid=%5EOSJ000%5EYY%5EUS&apn_dbr=ie_8.0.7601.17514&psv=&trgb=ALL&q={searchTerms} CHR DefaultSearchKeyword: Default -> ask search AlternateDataStreams: C:\Users\Norma\Desktop\Facebook.website:TASKICON_0news-1751121550 [2302] AlternateDataStreams: C:\Users\Norma\Desktop\Facebook.website:TASKICON_1messages-431041656 [2302] AlternateDataStreams: C:\Users\Norma\Desktop\Facebook.website:TASKICON_2events-250898981 [2302] AlternateDataStreams: C:\Users\Norma\Desktop\Facebook.website:TASKICON_3friends-215113587 [2302] AlternateDataStreams: C:\Users\Norma\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_0news-1751121550 [2302] AlternateDataStreams: C:\Users\Norma\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_1messages-431041656 [2302] AlternateDataStreams: C:\Users\Norma\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_2events-250898981 [2302] AlternateDataStreams: C:\Users\Norma\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_3friends-215113587 [2302] CMD: bitsadmin /reset /allusers CMD: netsh winsock reset catalog CMD: ipconfig /flushdns Emptytemp:
- Click Format and ensure Wordwrap is unchecked.
- Save as Fixlist.txt to your Desktop (Must be in this location)
- Run FRST/FRST64 and press the Fix button just once and wait.
- If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
- The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.