Hi Juliet I have no idea what C:\ProgramData\Puohxiilsri\1.0.4.1\hanuxlin.exe is and google is no help either. Now for the FRST scans I have them on desktop I managed to make fixlist.txt which I found in Documents and have made shortcut to desktop , but I'm lost on how to "Fix" you mention a quote box but I'm sorry I dont understand what you mean?. Sorry
Copy and paste the below (beginning with start) should be saved as fixlist.txt , Please open Notepad save it to the Desktop as fixlist.txt
Both should be on desktop, then open Farbar Recovery Scan Tool, look for and click on the FIX button and it should carry out the script that was created.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
start
CreateRestorePoint:
CloseProcesses:
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: Expat Shield Class -> {3706EE7C-3CAD-445D-8A43-03EBC3B75908} -> No File
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKU\S-1-5-21-4116000945-235673462-3313673197-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-4116000945-235673462-3313673197-1000 -> No Name - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - No File
FF Extension: (No Name) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [not found]
CHR HKU\S-1-5-21-4116000945-235673462-3313673197-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Nigel\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx <not found>
C:\ProgramData\fontcacheev1.dat
Task: {0AD379C5-5504-43E6-A142-8F50E0E3D24C} - System32\Tasks\{4BE954A3-3C41-4AB0-AC89-E19A30EB9F15} => pcalua.exe -a "C:\Program Files\Hola\app\hola_setup.exe" -c --remove-hola --no-rmt-conf --hola-cr
Task: {0F0DC27D-9F40-4E52-8BF2-2AA4C8A4BDAD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {1383606C-BC21-4B80-98A7-C5E01E568454} - \{49E65517-C6FF-4662-926A-722036CEACED} -> No File <==== ATTENTION
Task: {17B7ADFC-F0C7-4A13-A09F-26840081CD9A} - System32\Tasks\{FCA8B98D-7B6E-4847-AA86-EAD1A463EB8F} => pcalua.exe -a "C:\Program Files\Hola\app\hola_setup.exe" -c --remove-hola --no-rmt-conf --hola-cr
Task: {1DB3DD4E-A51F-4B7C-98D8-31843575334C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {2C08F93E-4D64-4926-9F70-779510E5F131} - \{3BCAB8DD-A9A8-467A-9DF8-252117296EF5} -> No File <==== ATTENTION
Task: {3C9B9881-3C6A-4575-A3FB-5ABCF44C3A4B} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {57759F43-E8BD-403C-B4E9-04221655B39B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {5AD5A731-ACC5-4A85-BB0E-E14B5EB5BC40} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {8951E175-2CFB-4385-AED6-C503308B4852} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {8B3EDE07-409A-4578-962A-7B68D3E4CDFC} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {AA191788-5067-4364-8E02-D592A650CB85} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {AB7F661F-4B3B-403F-BD46-B7B14F74B4AD} - System32\Tasks\{BB7CBED7-C704-4865-80F9-D7034E5EB1CE} => pcalua.exe -a C:\Users\Nigel\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=slbnew <==== ATTENTION
Task: {AB8D459A-9DF3-4165-8B86-405730A3E3AF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {ABD943F4-1266-443F-BF02-653F006F58C1} - \{5E281035-07E3-4953-9823-2E84881987F6} -> No File <==== ATTENTION
Task: {B6F5E4F0-B8F9-44BB-BD67-0478C4EB57C5} - \{02776CF1-FDD5-44F5-8243-916C10FDFA96} -> No File <==== ATTENTION
Task: {E33473C9-4870-4013-BE3E-6C5A0F72E8E9} - \{2413066B-5A68-422E-B866-0F489CA77B20} -> No File <==== ATTENTION
Task: {EE0EBC6F-4E44-49CC-A1FE-89A2B2C21B68} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {FC449D2B-AB91-463F-925F-EB33227FBD07} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
ShortcutWithArgument: C:\Users\Public\Desktop\Telstra USB+Wi-Fi.lnk -> C:\Program Files (x86)\Hostless Modem\Telstra USB+Wi-Fi\LaunchWebUI.exe () -> hxxp://m.home
AlternateDataStreams: C:\ProgramData\Temp:1D32EC29 [129]
AlternateDataStreams: C:\ProgramData\Temp:373E1720 [118]
AlternateDataStreams: C:\ProgramData\Temp:93DE1838 [133]
IE trusted site: HKU\S-1-5-21-4116000945-235673462-3313673197-1000\...\hola.org -> hxxp://hola.org
EmptyTemp:
Hosts:
End
~~
Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan
click on Browse, and upload the following file for analysis:
C:\ProgramData\Puohxiilsri\1.0.4.1\hanuxlin.exe
Then click Submit. Allow the file to be scanned, and then please copy and paste the results link (for Virus Total) here for me to see.
If it says already scanned -- click "reanalyze now"
Please post the results in your next reply.