Hi and welcome
Google Chrome has been attacked.
We will have to uninstall it then have you download it again.
Instructions on how to backup your Favourites/Bookmarks and other data can be found below.
~~~
Please download and install
Revo Uninstaller Free
- Double click Revo Uninstaller to run it.
- From the list of programs double click on Google Chrome
- When prompted if you want to uninstall click Yes.
- Be sure the Moderate option is selected then click Next.
- The program will run, If prompted again click Yes
- when the built-in uninstaller is finished click on Next.
- Once the program has searched for leftovers click Next.
- Check/tick the bolded items only on the list then click Delete
- when prompted click on Yes and then on next.
- put a check on any folders that are found and select delete
- when prompted select yes then on next
- Once done click Finish.
Please also uninstall if found these
SW-Booster
SW-Sustainer
~~~~
Google Chrome can be downloaded from here
http://www.google.com/chrome/
~~~~~~~~~~~~~~`
Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as
fixlist.txt
NOTE. It's important that both files,
FRST/FRST64 and
fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)
start
CloseProcesses:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-2664552706-3889408751-4227966822-1003\User: Group Policy restriction detected <======= ATTENTION
SearchScopes: HKLM -> {403CE8DA-BA42-478B-945D-BCD60FB70B3C} URL = http://www.bing.com/search?q={searchTerms}&FORM=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {403CE8DA-BA42-478B-945D-BCD60FB70B3C} URL = http://www.bing.com/search?q={searchTerms}&FORM=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2664552706-3889408751-4227966822-1000 -> {193D1EA9-94CE-481B-A4A6-ECE4F1DCAA85} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-2664552706-3889408751-4227966822-1000 -> {397CFBAF-01FE-4A0D-950E-041F4905DC38} URL =
SearchScopes: HKU\S-1-5-21-2664552706-3889408751-4227966822-1000 -> {403CE8DA-BA42-478B-945D-BCD60FB70B3C} URL =
SearchScopes: HKU\S-1-5-21-2664552706-3889408751-4227966822-1000 -> {9C89CBA4-1A70-49E4-A1E4-2DCAA8BA5931} URL = https://www.flickr.com/search/?q={searchTerms}
Toolbar: HKU\S-1-5-21-2664552706-3889408751-4227966822-1000 -> No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
Toolbar: HKU\S-1-5-21-2664552706-3889408751-4227966822-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
C:\ProgramData\dsgsdgdsgdsgw.bat
C:\ProgramData\dsgsdgdsgdsgw.reg
C:\Users\helena\AppData\Local\Temp\ose00000.exe
C:\Users\helena\AppData\Local\Temp\Quarantine.exe
C:\Users\helena\AppData\Local\Temp\sqlite3.dll
C:\Users\Helena_2\AppData\Local\Temp\UnityWebPlayer9028982610306444668.exe
SW-Booster (HKLM-x32\...\S-1530452449) (Version: 3.1.0.1868 - SW-Booster) <==== ATTENTION
SW-Sustainer (HKLM-x32\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fc67e7a0}) (Version: - Genuine P Software) <==== ATTENTION
AlternateDataStreams: C:\Users\Helena_2\Desktop\Hoosier Kennel Club.jpeg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\Helena_2\Desktop\Hoosier Kennel Club.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\Documents\Image (2).jpg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\Public\Documents\Image (2).jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\Documents\Image (2).jpg.jpeg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\Public\Documents\Image (2).jpg.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\Documents\Image.jpg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\Public\Documents\Image.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\Documents\William Scott West.jpeg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\Public\Documents\William Scott West.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
EmptyTemp:
Hosts:
End
Open
FRST/FRST64 and press the
Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
~~~~~~~~~~~~~~~``
Malwarebytes Anti-Rootkit
- Download Malwarebytes Anti-Rootkit
- Once the file has been downloaded, right click on the downloaded file and select the Extract all menu option.
- Follow the instructions to extract the ZIP file to a folder called mbar-versionnumber on your desktop.
- Once the ZIP file has been extracted, open the folder and when that folder opens, double-click on the mbar folder.
- Double-click on the mbar.exe file to launch Malwarebytes Anti-Rootkit.
- After you double-click on the mbar.exe file, you may receive a User Account Control (UAC) message if you are sure you wish to allow the program to run. Please allow to start Malwarebytes Anti-Rootkit correctly.
- Malwarebytes Anti-Rootkit will now install necessary drivers that are required for the program to operate correctly.
- If you receive a DDA driver message like could not load DDA driver, click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer and will start automatically.
- Please click by the introduction screen on the Next button to continue.
- Next you will see the Update Database screen.
- Click on the Update button so Malwarebytes Anti-Rootkit can download the latest definition updates.
- When the update has finished, click on the Next button.
- Next you can select some basic scanning options. Make sure the Drivers, Sectors, and System scan targets are selected before you click on the Scan button.
- Malwarebytes Anti-Rootkit will now start scanning your computer for rootkits. This scan can take some time, so please be patient.
- When the scan with Malwarebytes Anti-Rootkit is finished, the program will display a screen with the results from the scan.
- Make sure everything is selected and that the option to create a restore point is checked.
- Next click on the Cleanup button. Malwarebytes Anti-Rootkit will then prompt you to reboot your computer.
- Click on Yes button to restart your computer.
- There will now be two log files created in the mbar folder called system-log.txt and one that starts with mbar-log.
- The mbar-log file will always start with mbar-log, but the rest will be named using a timestamp indicating the time it was run.
- For example, mbar-log-2012-11-12 (19-13-32).txt corresponds to mbar-log-year-month-day (hour-minute-second).txt.
- The system-log.txt contains information about each time you have run MBAR and contains diagnostic information from the program.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
post:
Fixlog.txt
MBAR log