Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

trovi.com in address bar


  • Please log in to reply
13 replies to this topic

#1 toncat

toncat

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 24 November 2014 - 10:32 AM

Every time I open google chrome trovi.com is in the address bar and my search engine changed on its own. The computer has had a lag for a few weeks and I am not sure what to do. Can someone please help me or tell me where to look so I can follow steps to figure out what is wrong? I am running windows vista.


Edited by toncat, 24 November 2014 - 10:48 AM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:33 PM

Posted 24 November 2014 - 11:00 AM

Hello toncat

First open Search Protect by double clicking it's icon in the system tray,
Now click on Home Page and change to Google or another.
Then click on New Tab and change to Browser Default.
Finally click Error Page and UNcheck  Enhance my search experience.

Go into Control Panel and Uninstall Search Protect.
Restart the machine and run these.
 
ADW Cleaner
Please download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
  • -- Note: The contents of the AdwCleaner log file may be confusing. Unless you see a program name that you recognize and know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on each one and uncheck any items you want to keep (except you cannot uncheck Chrome and Firefox preferences lines).

    .
    thisisujrt.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
  • .

    Finally

    Please download Malwarebytes Anti-Malware and save it to your desktop.
    • Important!! When you save the mbam-setup file, rename it to something random (such as 123abc.exe) before beginning the download.
    • Double-click on the renamed file to install, then follow these instructions
    • for doing a Quick Scan in normal mode.
    • Don't forget to check for database definition updates through the program's interface (preferable method) before scanning.
    • If you cannot update Malwarebytes or use the Internet to download any files to the infected computer, manually update the database by following the instructions in FAQ Section A: 4. Issues
    Malwarebytes may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
    • After completing the scan, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab .
    • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows the database version and your operating system.
    • Exit Malwarebytes when done.
    Note: If Malwarebytes encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally will prevent Malwarebytes from removing all the malware.

    -- Some types of malware will target Malwarebytes and other security tools to keep them from running properly. If that's the case, use Malwarebytes Chameleon and follow the onscreen instructions. The Chameleon folder can be accessed by opening the program folder for Malwarebytes Anti-Malware (normally C:\Program Files\Malwarebytes' Anti-Malware or C:\Program Files (x86)\Malwarebytes' Anti-Malware).


    Things should be good now.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 toncat

toncat
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 24 November 2014 - 01:27 PM

Thank you so much for your response. I am not sure where to find the search protect at? I do not see anything in the system tray.  Also I can not figure out how to disable my avast. I looked last night because I downloaded malwarebytes. I also downloaded adwcleaner last night. 


Edited by toncat, 24 November 2014 - 01:36 PM.


#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:33 PM

Posted 24 November 2014 - 01:40 PM

Ok, Look next to the click for SP.. If not there then just move on down... If


AVAST
Right-click on the avast! icon in system tray (looks like this: avast.jpg but orange in color starting with v5). Select avast! shields control and there will be options to disable avast for 10 minutes, 1 hour, until the computer is restarted or permanently.

If no joy then scan with it on.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 toncat

toncat
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 24 November 2014 - 01:50 PM

Ok thanks...could not find it so moved on to adwcleaner...running that now.



#6 toncat

toncat
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 24 November 2014 - 02:11 PM

OMgosh I feel so stupid!! I am using windows 7 not vista!  Heres the file:

# AdwCleaner v4.102 - Report created 24/11/2014 at 12:55:06
# Updated 23/11/2014 by Xplode
# Database : 2014-11-24.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Cathy - CATHY-VAIO
# Running from : C:\Users\Cathy\Pictures\Quotes and sayings\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
[#] Service Deleted : vToolbarUpdater18.1.9
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\iolo
Folder Deleted : C:\Users\Cathy\AppData\Roaming\iolo
 
***** [ Scheduled Tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17420
 
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
 
-\\ Mozilla Firefox v32.0.2 (x86 en-US)
 
[k7zo78ln.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M2C39D853-0DB4-4C0B-B162-6FB84B78D649&SearchSource=55&CUI=&UM=6&UP=SP64D6A1B2-1F31-4307-8F9C[...]
[k7zo78ln.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Trovi search");
[k7zo78ln.default\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M2C39D853-0DB4-4C0B-B162-6FB84B78D649&SearchSource=69&CUI=&SSPV=&Lay=1&UM=6&UP=SP64D6A1B2-1F31-430[...]
 
-\\ Google Chrome v
 
 
*************************
 
AdwCleaner[R0].txt - [8293 octets] - [23/11/2014 22:58:01]
AdwCleaner[R1].txt - [9267 octets] - [23/11/2014 23:44:42]
AdwCleaner[R2].txt - [1945 octets] - [24/11/2014 12:49:30]
AdwCleaner[S0].txt - [8837 octets] - [23/11/2014 23:47:19]
AdwCleaner[S1].txt - [1729 octets] - [24/11/2014 12:55:06]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1789 octets] ##########


#7 toncat

toncat
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 24 November 2014 - 02:22 PM

Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.9 (11.15.2014:2)
OS: Windows 7 Home Premium x64
Ran by Cathy on Mon 11/24/2014 at 13:16:05.24
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{00B0C373-5676-40D0-8DD0-3423C197235E}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{02861FAB-E092-4455-A356-750C503FB5C8}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{02F30320-A489-4CC9-BEB3-E469348CDEA9}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{06C3B96F-3C4F-4A88-9EA3-EC982C415070}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{097F2CF4-A50A-4523-B0C7-2D3B647BDB81}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{0BE31B99-AE1B-436C-8FF1-83B44DFCB11B}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{0C09384F-8519-4F20-B903-245C127265DD}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{0DA58324-36EA-4F82-B0D8-25B0681EC473}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{0DBBDE76-3B4F-4D3D-8D70-AFA0F04DB463}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{0F3F2241-CAC5-4141-BDC5-C0B0A865774A}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{121A41B4-A66B-4178-B581-0F9ABBC5A0E8}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{12E16AF9-DC51-434B-8382-D6B99F3B71D6}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{12E75B05-EAC0-460F-BAB2-9919EAC94D03}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{130787F2-0A75-4C65-8154-AFEE8727C299}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{17C99C8B-315C-4175-B9B5-ECB1D614250B}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{26A69C27-DE6B-4604-98BC-511DC59D75BD}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{26F093F3-B368-4663-A58C-622778C3A53A}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{284E099A-BC11-4E5F-8EBD-8010365FFEB1}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{288D1117-7215-453E-B992-0974E68937D5}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{290D1F6D-780D-4A64-9F3C-8F5F7E00D86E}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{2948D04F-8092-4841-B488-EE86E6410623}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{2DE4F264-721E-4089-B5F0-DD76911A3F76}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{2E89AEC1-8C77-4A7D-8C64-B234BFEF9B38}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{2F83473E-D649-4AB6-ABC7-E87EA78354A2}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{3250EEA1-31E8-4C10-822C-834A09BC9793}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{33336E58-C02B-4813-8D95-AA600928BA35}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{368DCED6-DB65-49B5-B424-13FD92E1814F}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{3A68DCA8-D140-4527-9994-4B4895BA49E4}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{3C19AE0E-4BAC-48E0-B3F5-405F10798005}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{3E95A7C8-0E8D-49BE-AAEA-AE8A70263674}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{40D56DD6-47AE-4DC1-8F2D-4EE6245ECF75}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{418C5507-A56B-454E-B97A-7FBCC536387E}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{431BBF32-D443-45AE-B2D0-C5BD9C171659}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{43731049-F06B-4BC0-B73E-32EB6F37011F}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{4461C46E-3760-4D31-8623-140597AB80F1}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{44D19283-C9C3-43B5-932E-0D12D1AEE8DD}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{461F559E-0852-4EE3-A68E-BF91C2357776}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{48C50B39-84BD-4F53-BF37-FA2DF5E58F4C}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{4AD5A27A-52CC-4C25-BE4E-CAB7448D4DC0}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{50FDB4A4-0865-4386-ADC3-79525E4E3B05}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{54BB64F3-9645-417A-B2F3-C15179A27312}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{5516A55F-8128-4A02-8C29-195BFD023382}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{55987F14-10F8-4BAF-A30F-F049BC8DF8DC}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{56D38E55-14BE-4811-945A-2B42CA8457A7}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{6069485B-A166-4FC8-9C9D-4FF42145EFDE}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{662FA552-8EC2-4D3B-9199-BD700D75D02C}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{68EF780E-1585-40EF-849E-EAA3A7436A8B}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{698409EE-6FB2-4CC0-81D7-53D2D7FD05F1}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{6B3ACD78-DB70-4552-861C-798288565C16}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{6C3CA1ED-C82B-4A7B-BB78-EE54A0D7BE14}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{6CB3F337-5555-4075-88A8-B29C40D69021}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{6DA1483E-C26C-458A-95A7-AA7CD1899958}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{700E947A-2C08-4263-B84F-35DB49D92E17}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{740BD2B6-B2F6-4BE5-A4AC-E76FEB691137}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{74ABBF05-BC30-44E7-A1D9-ABBFD307BF57}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{7532A1CD-FB27-4826-B2D3-6C1B8ED7F6D6}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{7CD97B54-54F2-44C2-9160-BF7B06FF7DC3}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{7F0F1E50-787D-4BFC-B0F2-2BF0C3302F10}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{822B3FD1-96A5-48BC-94CE-A2E4A238C5BE}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{8682AEEF-B37F-462A-8369-C060539AEC7A}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{8695F56A-0051-45C3-91E6-E9F7638F3FD0}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{8B2216CA-6C58-4B7F-AF95-A17BE95E1F6A}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{8DCB7A94-333F-47ED-8CAB-D57F65A39CE0}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{9042F3FC-001C-4D28-8D94-31921FC1106D}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{94C911E1-2261-4292-8045-120830F33A69}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{95AC5A33-AB7D-4F7E-A666-B6C2D7D38117}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{967626D0-1E53-4DA4-A5FE-C79DAC631019}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{97324228-DD32-4DF8-A7D0-3EF1D4BE45EF}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{97C04E94-FBC4-4E86-AF86-BCD36C4FC7DF}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{9B87C010-96FA-478E-A8DB-EF6B47DC245A}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{9BF95197-F616-466C-AC94-243B30D8413E}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{A715476F-686C-444C-9C59-567C03A4AFA7}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{A7970E07-C178-4181-A190-93917C706798}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{A7F0BCD7-7668-4936-984F-03C00A0E3CBB}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{A946FBDB-1A79-450D-85CA-C059AC2D20E3}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{AA4AA053-F513-4153-B15C-77CF752D2493}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{AB091C67-49EA-4564-873A-1316C669A83D}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{AB6AF364-D245-44F0-8578-51AC88B1722D}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{AC0DD61B-0340-4AE6-BD7B-0C59DB4F5092}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{AC1A09E6-600A-4C95-B140-1FBCA5B91CF0}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{AD6C2E1A-FD0F-4A91-9C87-E0FCBDFD454E}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{AF94AC0E-27E5-4D27-B836-9C5E922BAE90}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{B33DC925-BD49-4430-BB4B-906B4ED62F9E}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{B440D3FB-F855-4EC4-9E08-B8654537D916}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{B9057AB7-9175-46A7-9858-9D8FF76C7614}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{BB6B09BA-F813-4ABC-AD29-4CB37E1D6CC4}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{BC09FED3-D14F-45C8-B34C-27AF5924603F}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{BE1DCFFB-1D14-4400-B63E-F9B636517709}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{BE5E08F1-3261-4422-B766-30D41C300E1D}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{C05A6D19-FF09-4A83-9AE1-5F3B647A233A}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{C0AC5FC6-84E9-4913-9073-1DD04238278D}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{C4B2C14A-458D-40A3-AA1B-18EB6687E302}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{C557D1C7-6A5C-4969-A0B6-C3469F5FCD62}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{C55E8FC0-51A9-483B-8CD8-E3CB9A9ADD39}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{C88855C8-4656-4819-A3D2-4CBBB71D8A94}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{C9AEF8EA-BDF8-4EAB-B7B7-A22732C4EC13}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{CE674185-DDEA-4740-A5FC-85A94C2E50DC}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{D3BDDC91-8E0C-4762-B606-F165B62A226D}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{D69E00EE-D6B7-439D-A3EA-E628A4234857}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{D70011E7-BAB7-49E7-868B-55FAE1999ADE}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{D8C94341-3AB3-42DD-AE02-CDA4A52E06AD}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{DABE310F-797D-475E-A160-AE2666E774B5}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{DD13B191-D44E-4174-9E26-4A6682D5BA48}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{E1DAF342-1EA2-4A33-B6FF-6C06FA8028AB}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{E4E92DDC-7BA1-429F-AEAB-1430AB11B029}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{E5935988-696B-4656-997F-020BA81704AA}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{E765ABFF-13B6-45F2-9035-DC3AB1704E49}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{E7D6451E-B9A7-4DBE-815F-B70A479ECAB2}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{E8F0202A-1ED3-4922-A34B-DE4F0B9746EE}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{EA4C6DBA-20DD-4077-96FF-E9F4D5623F60}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{EC60B06F-06B6-4EC9-8AF4-49973A5F9C2C}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F0C95FC1-D875-44D5-8D75-7F3D5B8D4588}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F1C3B08F-C215-405B-AAD5-C367C97F9121}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F1C7517F-D3FE-4DF5-839A-364DDD06D3EE}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F2C9FA63-F023-4BA4-B350-288DF5349859}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F41CAC82-EC18-4D8A-99B2-8C5946AD2D03}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F4BB49CE-891A-436D-8F73-EF90E97D6CF1}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F5345D20-CBD0-487F-8AD4-6CD0ACC516BC}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F6E14A4E-4F69-4644-9E66-CB3555FB9FC0}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F83D1A8F-E6A3-43B3-BA17-68CFB3DC38E1}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{F8B5AD28-F60D-4C98-9D5A-01878624DDC5}
Successfully deleted: [Empty Folder] C:\Users\Cathy\appdata\local\{FD3C37EB-6699-4149-955F-C026A8966F6F}
 
 
 
~~~ FireFox
 
Emptied folder: C:\Users\Cathy\AppData\Roaming\mozilla\firefox\profiles\k7zo78ln.default\minidumps [1 files]
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 11/24/2014 at 13:20:39.49
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#8 toncat

toncat
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 24 November 2014 - 02:24 PM

do i need to download another version of malwarebytes or is the one I downloaded last night ok to run now?



#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:33 PM

Posted 24 November 2014 - 03:09 PM

That one is OK just update it before the scan..
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 toncat

toncat
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 24 November 2014 - 05:58 PM

Ran the scan and have tried everything possible to copy and paste it but it will not let me do it. Not sure why. 



#11 toncat

toncat
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 24 November 2014 - 09:39 PM

Its still doing the same thing . If i open google chrome it shows this in the address bar:

 

http://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M2C39D853-0DB4-4C0B-B162-6FB84B78D649&SearchSource=55&CUI=&UM=6&UP=SP64D6A1B2-1F31-4307-8F9C-CD17DB568E75&SSPV= 

 

If I open google chrome again while the first google chrome is still open (and remains open) I then get a normal google chrome page with my normal search bar.

It is driving me batty!!  



#12 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:33 PM

Posted 25 November 2014 - 10:30 AM

Appears we need a deeper look as it must be being protected.

Please follow this Preparation Guide, do steps 6,7 and 8 and post in a new topic.
Let me know if all went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#13 toncat

toncat
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 25 November 2014 - 07:32 PM

I think it is gone now. When I ran malwarebytes (the night before posting on here), it had put a bunch of "search protect" items in quarantine. Once I went and deleted all of the items out of there, it now seems to be gone. Prior to that it was showing up in settings on google chrome under ON STARTUP  in the OPEN A PAGE OR SET OF PAGES area. Since deleting everything out of malwarebytes quarantine it is no longer showing up there. I can now open google chrome without finding it in the address bar. I hope that took care of it!!!  :bananas:  If not I will follow your directions and post a new topic. Thank you so much for your help!!   :thumbup2:



#14 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:33 PM

Posted 25 November 2014 - 11:42 PM

Sounds OK

Empty your temp folders using TFC (Temporary File Cleaner)
  • Please download TFC by Old Timer and save it to your desktop.
    alternate download link
  • Save any unsaved work. (TFC will close ALL open programs including your browser!)
  • Double-click on TFC.exe to run it. (If you are using Vista, right-click on the file and choose "Run As Administrator".)
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway allowing Windows to load normally (not into Safe Mode) to ensure a complete clean.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users