Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Save clicker help


  • Please log in to reply
4 replies to this topic

#1 KristinaLJ

KristinaLJ

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:00 PM

Posted 01 August 2014 - 02:57 PM

Can someone tell me how to remove save clicker?  It is an extension on chrome. 

 

I have run rkill then

SUPERAntiSpyware

Malwarebytes

CCleaner

and Avast

 

No matter how many times I disable it and remove it, it keeps coming back.

 

There is no program in the uninstall programs to uninstall and when I ran the save clicker removal tool, It did not find anything.

 

Thanks


Edited by KristinaLJ, 01 August 2014 - 03:23 PM.


BC AdBot (Login to Remove)

 


#2 Alex&Vanko

Alex&Vanko

  • Banned
  • 1,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:00 PM

Posted 01 August 2014 - 03:24 PM

Hi KristinaLJ and :welcome:

Download Screen317 Security Check HERE and save it to your Desktop.
* Double-click SecurityCheck.exe
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Please post the contents of that document.
Note:: If any security program requests permission to access the Internet, allow it to do so

Please download MiniToolBox HERE to your desktop to run it.
Checkmark the following boxes:
* List content of Hosts
* Flush DNS
* Report IE Proxy Settings
* Reset IE Proxy Settings
* Report FF Proxy Settings
* Reset FF Proxy Settings
* List last 10 Event Viewer log
* List Installed Programs
* List Devices (do NOT change any settings here)
* List Users, Partitions and Memory size
Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
Click Go and Copy / Paste the result. (result.txt)

 

Thank you!



#3 KristinaLJ

KristinaLJ
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:00 PM

Posted 01 August 2014 - 03:26 PM

Will do that now.

Thank you



#4 KristinaLJ

KristinaLJ
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:00 PM

Posted 01 August 2014 - 03:32 PM

 Results of screen317's Security Check version 0.99.86  
 Windows 7 Service Pack 1 x86 (UAC is enabled)  
 Internet Explorer 10 Out of date! 
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
avast! Antivirus                        
AVG Internet Security Network Edition   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 SUPERAntiSpyware     
 CCleaner     
 Adobe Reader XI  
 Google Chrome 35.0.1916.153  
 Google Chrome 36.0.1985.125  
````````Process Check: objlist.exe by Laurent````````  
 AVG avgrsx.exe 
 AVG avgemc.exe 
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast avastui.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 0% 
````````````````````End of Log`````````````````````` 
MiniToolBox by Farbar  Version: 21-07-2014
Ran by Tyler (administrator) on 01-08-2014 at 16:30:41
Running from "C:\Users\Tyler\Desktop"
Microsoft Windows 7 Ultimate  Service Pack 1 (X86)
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================
 
 
127.0.0.1 d3oxij66pru1i3.cloudfront.net
127.0.0.1 d3oxij66pru1i3.cloudfront.net
 
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (08/01/2014 04:16:57 PM) (Source: Application Error) (User: )
Description: Faulting application name: Report.exe, version: 1.0.0.0, time stamp: 0x52de1640
Faulting module name: Report.exe, version: 1.0.0.0, time stamp: 0x52de1640
Exception code: 0xc0000090
Fault offset: 0x00022e7c
Faulting process id: 0x1528
Faulting application start time: 0xReport.exe0
Faulting application path: Report.exe1
Faulting module path: Report.exe2
Report Id: Report.exe3
 
Error: (08/01/2014 02:02:55 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1424) SUS20ClientDataStore: The version store for this instance (0) has reached its maximum size of 32Mb. It is likely that a long-running transaction is preventing cleanup of the version store and causing it to build up in size. Updates will be rejected until the long-running transaction has been completely committed or rolled back.
 
Possible long-running transaction:
 
SessionId: 0x012C0320
 
Session-context: 0x00000000
 
Session-context ThreadId: 0x00001218
 
Cleanup: 1
 
Error: (08/01/2014 02:00:59 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/01/2014 00:30:52 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (08/01/2014 11:15:33 AM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {0a3bc7b5-48e2-453a-ba9e-2a55f7f8bb3e}
 
Error: (08/01/2014 11:08:09 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15584
 
Error: (08/01/2014 11:08:09 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15584
 
Error: (08/01/2014 11:08:09 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (08/01/2014 11:07:06 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/01/2014 11:00:56 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.
 
 
System errors:
=============
Error: (08/01/2014 02:00:57 PM) (Source: Service Control Manager) (User: )
Description: The AVG WatchDog service terminated with service-specific error %%-536805315.
 
Error: (08/01/2014 02:00:52 PM) (Source: SNMP) (User: )
Description: The SNMP Service encountered an error while accessing the registry key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.
 
Error: (08/01/2014 11:05:37 AM) (Source: Service Control Manager) (User: )
Description: The AVG WatchDog service terminated with service-specific error %%-536805315.
 
Error: (08/01/2014 11:05:35 AM) (Source: SNMP) (User: )
Description: The SNMP Service encountered an error while accessing the registry key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.
 
Error: (08/01/2014 10:06:25 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (08/01/2014 10:06:25 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated with service-specific error %%-1073473535.
 
Error: (08/01/2014 10:05:44 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
hlnfd
 
Error: (08/01/2014 10:05:44 AM) (Source: Service Control Manager) (User: )
Description: The AVG WatchDog service terminated with service-specific error %%-536805315.
 
Error: (08/01/2014 10:05:42 AM) (Source: Service Control Manager) (User: )
Description: The SavingsbullFilterService service failed to start due to the following error: 
%%2
 
Error: (08/01/2014 10:05:42 AM) (Source: SNMP) (User: )
Description: The SNMP Service encountered an error while accessing the registry key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.
 
 
Microsoft Office Sessions:
=========================
Error: (08/01/2014 04:16:57 PM) (Source: Application Error)(User: )
Description: Report.exe1.0.0.052de1640Report.exe1.0.0.052de1640c000009000022e7c152801cfadc589f5d07aC:\Program Files\Save Clicker Removal Tool\Report.exeC:\Program Files\Save Clicker Removal Tool\Report.exec8df5073-19b8-11e4-bd6a-001e6816d68c
 
Error: (08/01/2014 02:02:55 PM) (Source: ESENT)(User: )
Description: wuaueng.dll1424SUS20ClientDataStore: 0320x012C03200x000000000x000012181
 
Error: (08/01/2014 02:00:59 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/01/2014 00:30:52 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\HP\HP Officejet 4620 series\DriverStore\Pipeline\amd64\hpinkins6412.exe
 
Error: (08/01/2014 11:15:33 AM) (Source: VSS)(User: )
Description: 0x80070005, Access is denied.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {0a3bc7b5-48e2-453a-ba9e-2a55f7f8bb3e}
 
Error: (08/01/2014 11:08:09 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15584
 
Error: (08/01/2014 11:08:09 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15584
 
Error: (08/01/2014 11:08:09 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (08/01/2014 11:07:06 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/01/2014 11:00:56 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
 
 
 
=========================== Installed Programs ============================
Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2021 - AVAST Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.16 - Piriform)
Google Chrome (HKLM\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version:  - )
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1102 - SUPERAntiSpyware.com)
 
========================= Devices: ================================
 
Name: Base System Device
Description: Base System Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Base System Device
Description: Base System Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
========================= Memory info: ===================================
 
Percentage of memory in use: 45%
Total physical RAM: 3070.43 MB
Available physical RAM: 1679.96 MB
Total Pagefile: 6139.14 MB
Available Pagefile: 4837.83 MB
Total Virtual: 2047.88 MB
Available Virtual: 1944.76 MB
 
========================= Partitions: =====================================
 
1 Drive c: () (Fixed) (Total:232.79 GB) (Free:180.49 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\PFLLCOFFICE04
 
Administrator            darco                    Guest                    
PFG                      Tyler                    
 
 
**** End of log ****


#5 Alex&Vanko

Alex&Vanko

  • Banned
  • 1,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:00 PM

Posted 01 August 2014 - 04:06 PM

Do you have two antivirus?It is not good.

Yes Save  clicker is not listed as installed program.Where did you get this Save Clicker removal tool?

 

For Internet Explorer Users:

To remove extension: click on the gear icon or Tools → select Manage Add-ons → go to Toolbars and Extensions tab → right click on Save Clicker and any other suspicious extensions → choose Disable in the drop-down menu → close the window and click on OK button

 

For Google Chrome Users:

To remove extension: Click on Customize icon (Wrench or 3 bar icon) > Tools > Extensions → locate Save Clicker and any unwanted or unknown extension → click the Recycling Bin to remove it

 

Please download AdwCleaner by Xplode HERE onto your desktop.

    Close all open programs and internet browsers.
    Double click on AdwCleaner.exe to run the tool.
    Click on Scan.
    After the scan is complete click on "Clean"
    Confirm each time with Ok.
    Your computer will be rebooted automatically. A text file will open after the restart.
    Please post the content of that logfile with your next answer.
    You can find the logfile at C:\AdwCleaner[S1].txt as well.

Please download Junkware Removal Tool HERE to your desktop.

    Shut down your protection software now to avoid potential conflicts.
    Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    The tool will open and start scanning your system.
    Please be patient as this can take a while to complete depending on your system's specifications.
    On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    Post the contents of JRT.txt into your next message.

 

Download HitmanPro x86 HERE from onto your desktop.

Double-click on the file named HitmanPro.exe.It will be updated.When the program starts you will be presented with the start screen.Click on the Next button.Accept to store a copy of the program to your computer and click Next and it will start to scan.
When it has finished it will display a list of all the malware that the program found.Below next to button buy now is option Save log.Save it to your desktop and paste it here.

 

Thank you!






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users