Solved Why won't all my browsers' URL or search bars work in Win 7?

June 3, 2015 at 09:33:03
Specs: Windows 7
Search bars and URL bar not working in any browser. I have tried IE, FF, and Chrome and when I type anything into the search bar or the URL bar, I get the spinning wheel and eventually an error message that the page can't load. My internet is working fine. I can click links, send email, go on Facebook, etc. I just can't type in an address or search using the search bar. I'm guessing it's malware or virus related, but I really don't know for sure.

See More: Why wont all my browsers URL or search bars work in Win 7?

Report •

✔ Best Answer
June 6, 2015 at 15:46:43
For security reasons, these need updating.

Java 7 Update 21
[color=red][b]Java version 32-bit out of Date![/b][/color]

Google Chrome 42.0.2311.152 [color=red][b] Google Chrome out of date![/b][/color]

Run ESET Online Scanner, Copy and Paste the contents of the log in your reply please. This scan may take a very long while, so please be patient. Maybe start it before going to work or bed.
http://www.eset.com/us/online-scann...
http://www.eset.com/home/products/o...
If your comp is unbootable, or won't let you download, you will have to download ESET from a good computer, put it on a flash/thumb/pen/usb drive & run it from there.
Create a ESET SysRescue CD or USB drive
http://kb.eset.com/esetkb/index?pag...
How do I use my ESET SysRescue CD or USB flash drive to scan and clean my system?
http://kb.eset.com/esetkb/index?pag...
Configure ESET this way & disable your AV.
http://i.imgur.com/3U7YC.gif
How to Temporarily Disable your Anti-virus
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
Which web browsers are compatible with ESET Online Scanner?
http://www.nod32.fi/eset-online-sca...
http://kb.eset.com/esetkb/index?pag...
Online Scanner not working
http://kb.eset.com/esetkb/index?pag...
My ESET product detected a threat—what should I do?
http://kb.eset.com/esetkb/index?pag...
Why Would I Ever Need an Online Virus Scanner? I already have an antivirus program installed, isn't that enough?
http://www.squidoo.com/the-best-fre...
Once onto a machine, malware can disable antivirus programs, prevent antimalware programs from downloading updates, or prevent a user from running antivirus scans or installing new antivirus software or malware removal tools. At this point even though you are aware the computer is infected, removal is very difficult.
5: Why does the ESET Online Scanner run slowly on my computer?
If you have other antivirus, antispyware or anti-malware programs running on your computer, they may intercept the scan being performed by the ESET Online Scanner and hinder performance. You may wish to disable the real-time protection components of your other security software before running the ESET Online Scanner. Remember to turn them back on after you are finished.
17: How can I view the log file from ESET Online Scanner?
http://kb.eset.com/esetkb/index?pag...
http://www.eset.com/home/products/o...
The ESET Online Scanner saves a log file after running, which can be examined or sent in to ESET for further analysis. The path to the log file is "C:\Program Files\EsetOnlineScanner\log.txt". You can view this file by navigating to the directory and double-clicking on it in Windows Explorer, or by copying and pasting the path specification above (including the quotation marks) into the Start ? Run dialog box from the Start Menu on the Desktop.
If no threats are found, you will simply see an information window that no threats were found.
http://www.trishtech.com/security/s...



#1
June 3, 2015 at 10:27:13
Are these the native searchbars and URL bars or are they add-on bars like the Yahoo or Google bars?

Report •

#2
June 3, 2015 at 10:42:30
These are the natives. And in Chrome its just the one URL/search bar that contains both functions.

Report •

#3
June 3, 2015 at 10:57:19
Try deleting the cache, temp files, browsing history, etc. You might also run a scan with Malware Bytes.

http://tinyurl.com/ptrq9ll


Report •

Related Solutions

#4
June 3, 2015 at 11:31:32
Run these two widely used and safe little freebies which often unearth browser malware:
(run them in the order given)

AdwCleaner:
http://www.bleepingcomputer.com/dow...
(blue Download button near top - not anything else on the page).
Download and "Save" the file somewhere. Go to the saved file then double click it to run the program. Use the "Scan" button, followed by the "Cleaning" button.

Junkware Removal Tool (JRT)
http://www.bleepingcomputer.com/dow...
(blue Download button near top - not anything else on the page).
Download and "Save" the file somewhere. Go to the saved file then double click it to run JRT. It might appear to have stopped at times or flash the screen but sit tight until it has finished.

If they find anything please copy/paste the logs on here because there might be further malware about.

Always pop back and let us know the outcome - thanks


Report •

#5
June 5, 2015 at 13:23:02
I deleted the cache, temp files, browsing history, and ran a scan with Malware Bytes. The scan found 328 threats and removed them all. I also ran AdwCleaner and JRT. Here is the log file from AdwCleaner:

# AdwCleaner v4.206 - Logfile created 05/06/2015 at 13:38:57
# Updated 01/06/2015 by Xplode
# Database : 2015-06-05.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Owner - OWNER-PC
# Running from : C:\Users\Owner\Downloads\AdwCleaner.exe
# Option : Cleaning

***** [ Services ] *****

[#] Service Deleted : CouponPrinterService

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eSupport.com
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
Folder Deleted : C:\Program Files (x86)\Coupons
Folder Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eofcbnmajmjmplflapaojjnihcjkigck_0.localstorage
File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eofcbnmajmjmplflapaojjnihcjkigck_0.localstorage-journal
File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\jt7y6357.default\user.js

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\eSupport.com
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows5.0.1.4
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>;*.local

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17801


-\\ Mozilla Firefox v38.0.5 (x86 en-US)


-\\ Google Chrome v43.0.2357.81

[C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [3277 bytes] - [05/06/2015 13:36:57]
AdwCleaner[S0].txt - [3025 bytes] - [05/06/2015 13:38:57]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3084 bytes] ##########

I'll add the log file from JRT in a separate post.


Report •

#6
June 5, 2015 at 13:24:25
Log file from JRT:

Junkware Removal Tool (JRT) by Thisisu
Version: 6.8.8 (06.03.2015:1)
OS: Windows 7 Home Premium x64
Ran by Owner on Fri 06/05/2015 at 13:51:46.66
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~ Services

~~~ Tasks

~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-529444480-1176797499-2697102583-1000\Software\Microsoft\Internet Explorer\Main\\Start Page

~~~ Registry Keys

~~~ Files

Successfully deleted: [File] C:\windows\couponprinter.ocx

~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\best buy pc app
Successfully deleted: [Folder] C:\Users\Owner\appdata\local\best buy pc app

~~~ FireFox

Emptied folder: C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\jt7y6357.default\minidumps [5 files]

~~~ Chrome


[C:\Users\Owner\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Owner\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Owner\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Owner\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 06/05/2015 at 14:10:06.98
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I just tried the search function in Firefox and it still isn't working. Any additional ideas?


Report •

#7
June 5, 2015 at 14:28:26
Yes, run MalwareBytes again too. The best order is ADWCleaner first, then JRT, then MalwareBytes.

Before doing MalwareBytes Scan go to "Settings > Detection and Protection" and put a checkmark in "Scan for rootkits". Quarantine anything it finds.

Let us know how you get on and paste the log on here if it finds anything. Looks like a deep clean is necessary. If a certain helper "Johnw" doesn't spot this I'll alert him, as he is particularly expert at cleaning computers.

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#8
June 5, 2015 at 15:43:03
Thanks Derek, shall just wait for the Malwarebytes log.

Ben47, we are on the right track, just a matter of dismantling the nasties bit by bit.


Report •

#9
June 5, 2015 at 17:25:01
Thank you guys for all of your help so far. The Malwarebytes scan didn't find any threats. I can paste the log in here if needed. Otherwise, I'll wait to hear from you as to what the next step should be.

Report •

#10
June 5, 2015 at 17:26:18
Next step.

Please download Farbar Recovery Scan Tool and save it onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
http://www.bleepingcomputer.com/dow...
If we have to run Farbar more than once, refer this SS.
http://i.imgur.com/yUxNw0j.gif
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) on the Desktop.
The first time the tool is run, it makes also another log (Addition.txt).
The logs are large, upload them using this, or upload to a site of your choosing. No account needed. Give us the links please.
http://www.zippyshare.com/
Instructions on how to use ZippyShare.
http://i.imgur.com/naG6t2T.gif
http://i.imgur.com/Vi9ZdIh.gif
http://i.imgur.com/1IZu5kP.gif


Report •

#11
June 5, 2015 at 17:45:14

Report •

#12
June 5, 2015 at 17:52:35
Thanks, got them.

Download ComboFix onto your Desktop & then run. If your default download location is not the Desktop, drag it out of it's location onto the Desktop. Copy & Paste the contents of the log in your next post please. ComboFix's log should be located at C:\COMBOFIX.TXT.
The logs are large, upload them using this, or upload to a site of your choosing. No account needed. Give us the links please.
http://www.zippyshare.com/
Instructions on how to use ZippyShare.
http://i.imgur.com/naG6t2T.gif
http://i.imgur.com/Vi9ZdIh.gif
http://i.imgur.com/1IZu5kP.gif
http://www.bleepingcomputer.com/dow...
http://download.bleepingcomputer.co...
http://www.forospyware.com/sUBs/Com...
A guide and tutorial on using ComboFix
http://www.bleepingcomputer.com/com...
http://www.winhelp.us/index.php/gen...
Manually restoring the Internet connection
http://www.bleepingcomputer.com/com...
There are circumstances ComboFix will hang, crash or stall at various stages due to malware interference, failure to disable other real-time protection tools or the presence of CD Emulators (Daemon Tools, Alchohol 120%, Astroburn, AnyDVD) so that it does not complete successfully. Also, depending on how badly a system is infected, ComboFix may take longer to complete its routine than it normally does or fail to run properly. While that is not normal behavior, it is not unusual"
If you think it's frozen, look at the computer clock.
If it's running, Combofix is still working.
NOTE: Do not mouseclick combofix's window while it is running. That may cause it to stall.
NOTE: ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
**Please Note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.
The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.
Allow ComboFix to download the Recovery Console.
Accept the End-User License Agreement.
The Recovery Console will be installed.
You will then get this next prompt that asks if you want to continue the malware scan, select yes.
If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
Can't Install an Antivirus - Windows Security Center still detects previous AV
http://www.experts-exchange.com/Vir...
We are almost ready to start ComboFix, but before we do so, we need to take some preventative measures so that there are no conflicts with other programs when running ComboFix. At this point you should do the following:
* Close all open Windows including this one.
* Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix. Instructions on disabling these type of programs can be found in this topic.
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
Once these two steps have been completed, double-click on the ComboFix icon found on your Desktop.
Please Note: Once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all. The scan could take a while, so please be patient.


Report •

#13
June 6, 2015 at 08:01:48
Alright, ComboFix just finished running, and I uploaded the log file at the following link:

http://www64.zippyshare.com/v/VxHzN...

Please let me know what to do next as the search and url functions still aren't working.


Report •

#14
June 6, 2015 at 14:14:11
Download Security Check by screen317 from one of the following links and save it to your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
http://screen317.spywareinfoforum.o...
http://screen317.changelog.fr/Secur...
Please restart the computer before running this security check.
* Double click SecurityCheck.exe. If you run Windows Vista or 7/8, right click and choose 'Run as Administrator'.
o If you are asked by Windows to run this program or not, please click 'Yes' or 'Run'.
o When you see a console window, press any key to continue scanning.
o Wait while it scans.
o If your firewall alerts you of Security Check, please press 'Allow' or similar.
* A Notepad document should open automatically after scan is completed. It will be called checkup.txt; Please Copy and Paste the contents into your reply.
Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

Report •

#15
June 6, 2015 at 14:50:38
Thanks for the advice! I ran Security Check, and it gave me the following log file:

Results of screen317's Security Check version 1.003
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
[b][u]``````````````Antivirus/Firewall Check:``````````````[/b][/u]
Windows Firewall Enabled!
Kaspersky Internet Security
avast! Antivirus
Antivirus up to date! (On Access scanning [b]disabled[/b]!)
[b][u]`````````Anti-malware/Other Utilities Check:`````````[/b][/u]
Java 7 Update 21
[color=red][b]Java version 32-bit out of Date![/b][/color]
Adobe Flash Player 17.0.0.188
Adobe Reader XI
Mozilla Firefox (38.0.5)
Google Chrome 42.0.2311.152 [color=red][b] Google Chrome out of date![/b][/color]
[b][u]````````Process Check: objlist.exe by Laurent````````[/b][/u]
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastui.exe
Kaspersky Lab Kaspersky Internet Security 15.0.2 avp.exe
Kaspersky Lab Kaspersky Internet Security 15.0.2 avpui.exe
[b][u]`````````````````System Health check`````````````````[/b][/u]
Total Fragmentation on Drive C: 0%
[b][u]````````````````````End of Log``````````````````````[/b][/u]


Report •

#16
June 6, 2015 at 15:03:37
Which AV ( antivirus ) are you using?

Report •

#17
June 6, 2015 at 15:10:21
My Kapersky subscription just ran out, so I downloaded Avast and have been using that for the last couple of weeks.

Report •

#18
June 6, 2015 at 15:15:14
"have been using that for the last couple of weeks"
That's fine Ben, but they are conflicting.

Use this uninstaller & let me know when you have done so please.

Kasperksy Lab Products Remover
http://support.kaspersky.com/common...
http://www.bleepingcomputer.com/dow...

message edited by Johnw


Report •

#19
June 6, 2015 at 15:23:25
Ok, I'm a little confused. The first link is for the Kapersky Virus Removal tool. Do you want me to use that and then uninstall all Kapersky products?

Report •

#20
June 6, 2015 at 15:25:17
Opp's, use the last link.

Report •

#21
June 6, 2015 at 15:46:07
Ok, no problem. I ran the uninstaller, and as far as I can tell the Kapersky product was removed.

Report •

#22
June 6, 2015 at 15:46:43
✔ Best Answer
For security reasons, these need updating.

Java 7 Update 21
[color=red][b]Java version 32-bit out of Date![/b][/color]

Google Chrome 42.0.2311.152 [color=red][b] Google Chrome out of date![/b][/color]

Run ESET Online Scanner, Copy and Paste the contents of the log in your reply please. This scan may take a very long while, so please be patient. Maybe start it before going to work or bed.
http://www.eset.com/us/online-scann...
http://www.eset.com/home/products/o...
If your comp is unbootable, or won't let you download, you will have to download ESET from a good computer, put it on a flash/thumb/pen/usb drive & run it from there.
Create a ESET SysRescue CD or USB drive
http://kb.eset.com/esetkb/index?pag...
How do I use my ESET SysRescue CD or USB flash drive to scan and clean my system?
http://kb.eset.com/esetkb/index?pag...
Configure ESET this way & disable your AV.
http://i.imgur.com/3U7YC.gif
How to Temporarily Disable your Anti-virus
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
Which web browsers are compatible with ESET Online Scanner?
http://www.nod32.fi/eset-online-sca...
http://kb.eset.com/esetkb/index?pag...
Online Scanner not working
http://kb.eset.com/esetkb/index?pag...
My ESET product detected a threat—what should I do?
http://kb.eset.com/esetkb/index?pag...
Why Would I Ever Need an Online Virus Scanner? I already have an antivirus program installed, isn't that enough?
http://www.squidoo.com/the-best-fre...
Once onto a machine, malware can disable antivirus programs, prevent antimalware programs from downloading updates, or prevent a user from running antivirus scans or installing new antivirus software or malware removal tools. At this point even though you are aware the computer is infected, removal is very difficult.
5: Why does the ESET Online Scanner run slowly on my computer?
If you have other antivirus, antispyware or anti-malware programs running on your computer, they may intercept the scan being performed by the ESET Online Scanner and hinder performance. You may wish to disable the real-time protection components of your other security software before running the ESET Online Scanner. Remember to turn them back on after you are finished.
17: How can I view the log file from ESET Online Scanner?
http://kb.eset.com/esetkb/index?pag...
http://www.eset.com/home/products/o...
The ESET Online Scanner saves a log file after running, which can be examined or sent in to ESET for further analysis. The path to the log file is "C:\Program Files\EsetOnlineScanner\log.txt". You can view this file by navigating to the directory and double-clicking on it in Windows Explorer, or by copying and pasting the path specification above (including the quotation marks) into the Start ? Run dialog box from the Start Menu on the Desktop.
If no threats are found, you will simply see an information window that no threats were found.
http://www.trishtech.com/security/s...


Report •

#23
June 6, 2015 at 17:50:40
I just ran ESET online scanner and it said no threats were found. Here is the log file:

# utc_time=2015-06-06 11:20:13
# local_time=2015-06-06 06:20:13 (-0600, Central Daylight Time)
# country="United States"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 24206
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=a312fee71ef4594b9c9245f8646b03d4
# end=updated
# utc_time=2015-06-06 11:23:31
# local_time=2015-06-06 06:23:31 (-0600, Central Daylight Time)
# country="United States"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=a312fee71ef4594b9c9245f8646b03d4
# engine=24206
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-06-07 12:43:11
# local_time=2015-06-06 07:43:11 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 71 91 0 1733669 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 0 185181241 0 0
# scanned=208513
# found=0
# cleaned=0
# scan_time=4779


Report •

#24
June 6, 2015 at 18:01:04
Copy & Paste the text in Blue below & save it into Notepad on your Desktop & name it fixlist.txt
NOTE:It is important that Notepad is used. The fix will not work if Word or some other program is used.
NOTE: It is important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.

closeprocesses:
emptytemp:
C:\Users\Owner\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-529444480-1176797499-2697102583-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-529444480-1176797499-2697102583-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-529444480-1176797499-2697102583-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
Task: {2F2B76CA-EF2A-4B4B-8F63-5BE1C3155BA3} - \ProPCCleaner_Popup No Task File <==== ATTENTION
Task: {3ED59E2B-0215-47E2-B28E-E3C47C2FB01B} - \ProPCCleaner_Start No Task File <==== ATTENTION
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-529444480-1176797499-2697102583-1000\...\MountPoints2: {0c97b6ce-44a6-11e3-8c30-b870f45e4a59} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-529444480-1176797499-2697102583-1000\...\MountPoints2: {0c97b7b6-44a6-11e3-8c30-b870f45e4a59} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-529444480-1176797499-2697102583-1000\...\MountPoints2: {8110057d-5232-11e3-9223-b870f45e4a59} - E:\HTC_Sync_Manager_PC.exe
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
SearchScopes: HKLM -> {451EC4F0-5BC8-42C0-AA42-DA5EC8DBA6E5} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNF
SearchScopes: HKLM-x32 -> {897EA092-B1F9-4373-886A-9EEBF885D26E} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNF
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-529444480-1176797499-2697102583-1000 -> {451EC4F0-5BC8-42C0-AA42-DA5EC8DBA6E5} URL =
SearchScopes: HKU\S-1-5-21-529444480-1176797499-2697102583-1000 -> {897EA092-B1F9-4373-886A-9EEBF885D26E} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNF
SearchScopes: HKU\S-1-5-21-529444480-1176797499-2697102583-1000 -> {FA6776CB-666A-405D-A71F-4A6870D1BC86} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNF_en
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2014-12-03] (Coupons, Inc.)
S1 Avgfwfd; system32\DRIVERS\avgfwd6a.sys [X]

Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that, let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please Copy & Paste the contents into your reply.

message edited by Johnw


Report •

#25
June 6, 2015 at 18:04:14
I adjusted colors to suit.

message edited by Johnw


Report •

#26
June 6, 2015 at 19:19:25
Both the URL and search functions are working in all of my browsers! Thank you so much for your help! If possible, I would like to continue cleaning my computer following any instructions you can give me. I ran FRST64 using the fix button and this is the log that it generated:

Fix result of Farbar Recovery Scan Tool (x64) Version:03-06-2015
Ran by Owner at 2015-06-06 21:01:13 Run:1
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Boot Mode: Normal
==============================================

fixlist content:
*****************
closeprocesses:
emptytemp:
C:\Users\Owner\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-529444480-1176797499-2697102583-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-529444480-1176797499-2697102583-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-529444480-1176797499-2697102583-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
Task: {2F2B76CA-EF2A-4B4B-8F63-5BE1C3155BA3} - \ProPCCleaner_Popup No Task File <==== ATTENTION
Task: {3ED59E2B-0215-47E2-B28E-E3C47C2FB01B} - \ProPCCleaner_Start No Task File <==== ATTENTION
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-529444480-1176797499-2697102583-1000\...\MountPoints2: {0c97b6ce-44a6-11e3-8c30-b870f45e4a59} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-529444480-1176797499-2697102583-1000\...\MountPoints2: {0c97b7b6-44a6-11e3-8c30-b870f45e4a59} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-529444480-1176797499-2697102583-1000\...\MountPoints2: {8110057d-5232-11e3-9223-b870f45e4a59} - E:\HTC_Sync_Manager_PC.exe
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
SearchScopes: HKLM -> {451EC4F0-5BC8-42C0-AA42-DA5EC8DBA6E5} URL = http://www.google.com/search?source...
SearchScopes: HKLM-x32 -> {897EA092-B1F9-4373-886A-9EEBF885D26E} URL = http://www.google.com/search?source...
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-529444480-1176797499-2697102583-1000 -> {451EC4F0-5BC8-42C0-AA42-DA5EC8DBA6E5} URL =
SearchScopes: HKU\S-1-5-21-529444480-1176797499-2697102583-1000 -> {897EA092-B1F9-4373-886A-9EEBF885D26E} URL = http://www.google.com/search?source...
SearchScopes: HKU\S-1-5-21-529444480-1176797499-2697102583-1000 -> {FA6776CB-666A-405D-A71F-4A6870D1BC86} URL = http://www.google.com/search?source...
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2014-12-03] (Coupons, Inc.)
S1 Avgfwfd; system32\DRIVERS\avgfwd6a.sys [X]
*****************

Processes closed successfully.
"C:\Users\Owner\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File" => File/Folder not found.
"HKU\S-1-5-21-529444480-1176797499-2697102583-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => key removed successfully
"HKU\S-1-5-21-529444480-1176797499-2697102583-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}" => key removed successfully
"HKU\S-1-5-21-529444480-1176797499-2697102583-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F2B76CA-EF2A-4B4B-8F63-5BE1C3155BA3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F2B76CA-EF2A-4B4B-8F63-5BE1C3155BA3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Popup" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3ED59E2B-0215-47E2-B28E-E3C47C2FB01B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3ED59E2B-0215-47E2-B28E-E3C47C2FB01B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Start" => key removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value not found.
HKU\S-1-5-21-529444480-1176797499-2697102583-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c97b6ce-44a6-11e3-8c30-b870f45e4a59} => key not found.
HKCR\CLSID\{0c97b6ce-44a6-11e3-8c30-b870f45e4a59} => key not found.
HKU\S-1-5-21-529444480-1176797499-2697102583-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c97b7b6-44a6-11e3-8c30-b870f45e4a59} => key not found.
HKCR\CLSID\{0c97b7b6-44a6-11e3-8c30-b870f45e4a59} => key not found.
HKU\S-1-5-21-529444480-1176797499-2697102583-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8110057d-5232-11e3-9223-b870f45e4a59} => key not found.
HKCR\CLSID\{8110057d-5232-11e3-9223-b870f45e4a59} => key not found.
C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe not found.
C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{451EC4F0-5BC8-42C0-AA42-DA5EC8DBA6E5}" => key removed successfully
HKCR\CLSID\{451EC4F0-5BC8-42C0-AA42-DA5EC8DBA6E5} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{897EA092-B1F9-4373-886A-9EEBF885D26E}" => key removed successfully
HKCR\Wow6432Node\CLSID\{897EA092-B1F9-4373-886A-9EEBF885D26E} => key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-529444480-1176797499-2697102583-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{451EC4F0-5BC8-42C0-AA42-DA5EC8DBA6E5}" => key removed successfully
HKCR\CLSID\{451EC4F0-5BC8-42C0-AA42-DA5EC8DBA6E5} => key not found.
"HKU\S-1-5-21-529444480-1176797499-2697102583-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{897EA092-B1F9-4373-886A-9EEBF885D26E}" => key removed successfully
HKCR\CLSID\{897EA092-B1F9-4373-886A-9EEBF885D26E} => key not found.
"HKU\S-1-5-21-529444480-1176797499-2697102583-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FA6776CB-666A-405D-A71F-4A6870D1BC86}" => key removed successfully
HKCR\CLSID\{FA6776CB-666A-405D-A71F-4A6870D1BC86} => key not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll => moved successfully.
Avgfwfd => Service removed successfully
EmptyTemp: => 650.7 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 21:01:38 ====


Report •

#27
June 6, 2015 at 21:28:30
"Both the URL and search functions are working in all of my browsers!"
Beautiful.

" I ran FRST64 using the fix button and this is the log that it generated:"
Perfect.

"I would like to continue cleaning my computer following any instructions you can give me"
No problem, I have been out singing, got to leave for another commitment in 3/4 of an hour, shall get back ASAP. Will need to look a lot deeper in the logs.
I'm here.
http://www.timeanddate.com/worldclo...

message edited by Johnw


Report •

#28
June 7, 2015 at 05:22:31
Have not had enough time to go deeper into the logs, let me know when you have done this please.

Here is how the USER got into this mess, no AV would have prevented USER error. Go to any Malware forum & no matter what AV they have installed, they got infected.

As you can see from your logs, you had a lot of stuff installed, that you do not know, how it got installed.
A lot of programs, now give you the choice to install toolbars & other during the install. Either uncheck these items during install, or use Custom install. No more click, click during an install, you have to read after each click.

WARNING: CNET Download.com downloads now come bundled with opt-out crapware and toolbars ( Same applies to Softonic & Brothersoft )
http://www.groovypost.com/unplugged...

I use Softpedia & FreewareFiles.com, they make you aware what Ad-supported programs the author of the program has included.
http://win.softpedia.com/index.free...
http://www.freewarefiles.com/new_fi...
Sample pages
http://www.softpedia.com/get/CD-DVD...
First and foremost, extra attention needs to be paid during installation as ImgBurn offers to create desktop shortcuts to third-party apps, as well as install a browser toolbar onto the host computer, which are not required to ensure the smooth running of the app.
SS of above.
http://i.imgur.com/jgGYNsP.gif
http://i.imgur.com/rqSpp1e.gif
This is what ImgBurn tries to install.
http://i.imgur.com/ms4DzE9.gif
http://i.imgur.com/vVkd39a.gif
http://i.imgur.com/rqFVaHs.gif
http://i.imgur.com/sm1T7h6.gif
http://i.imgur.com/vhkKLYo.gif

Use Unchecky to help prevent these third party installs. Nothing is perfect, the badies are always ahead of the goodies, so be vigilant.
http://www.softpedia.com/get/System...
http://www.freewarefiles.com/Unchec...
http://unchecky.com/
A reliable application that aims to protect your computer against third-party components often offered during software installations.


Report •

#29
June 7, 2015 at 08:49:09
Yes, I try to go through the installation windows and uncheck all of the boxes for additional toolbars and software that I do not want or need. I probably miss one from time to time. Did you see anything else that should be removed from my PC? If not, can you tell me which of the programs that I installed that I should keep for future use? Will I need ComboFix, JRT, Security Check, FRST64, etc.?

Report •

#30
June 7, 2015 at 15:46:36
" I probably miss one from time to time"
Did you install Unchecky?

"Will I need ComboFix, JRT, Security Check, FRST64, etc.?"
Put ESET in a safe place, I keep it on a thumb drive & other places, it is part of my toolkit. It updates itself when run.

All the others have new versions weekly, use Delfix to remove.

Run DelFix. Copy & Paste the contents of the log please.
https://toolslib.net/downloads/view...
DelFix is designed to delete all removal tools used during a disinfection.
Indeed, these tools are often updated. It's recommended not to have and use outdated versions on computer.
It's compatible with Windows XP, Vista, 7, 8 in 32 & 64 bits.
Run the tool by right click on the DelFix icon and Run as administrator option.
Make sure that these are checked:
Activate UAC (optional; some users prefer to keep it off)
Remove disinfection tools
Create registry backup
Purge system restore
Reset system settings
Click Run and wait until the tool completes it's work.
Tool will create an report for you (C:\DelFix.txt)


Report •

#31
June 8, 2015 at 11:52:49
"Did you install Unchecky?"
Yes

I ran DelFix and the log file is copied below:

# DelFix v1.010 - Logfile created 08/06/2015 at 13:41:40
# Updated 26/04/2015 by Xplode
# Username : Owner - OWNER-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\Qoobox
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\RegBackup
Deleted : C:\ComboFix.txt
Deleted : C:\Users\Owner\Desktop\Addition.txt
Deleted : C:\Users\Owner\Desktop\ComboFix.exe
Deleted : C:\Users\Owner\Desktop\Fixlog.txt
Deleted : C:\Users\Owner\Desktop\FRST.txt
Deleted : C:\Users\Owner\Desktop\FRST64.exe
Deleted : C:\Users\Owner\Desktop\JRT.txt
Deleted : C:\Users\Owner\Desktop\SecurityCheck.exe
Deleted : C:\Users\Owner\Downloads\AdwCleaner.exe
Deleted : C:\Users\Owner\Downloads\esetsmartinstaller_enu.exe
Deleted : C:\Users\Owner\Downloads\FRST64.exe.part
Deleted : C:\Users\Owner\Downloads\JRT.exe
Deleted : C:\windows\grep.exe
Deleted : C:\windows\PEV.exe
Deleted : C:\windows\NIRCMD.exe
Deleted : C:\windows\MBR.exe
Deleted : C:\windows\SED.exe
Deleted : C:\windows\SWREG.exe
Deleted : C:\windows\SWSC.exe
Deleted : C:\windows\SWXCACLS.exe
Deleted : C:\windows\Zip.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

~ Creating registry backup ... OK

~ Cleaning system restore ...

I also put ESET on a thumb drive for future use. Anything else you recommend?


Report •

#32
Report •

#33
June 10, 2015 at 07:34:12
I used the disk cleanup program to delete some files. Is there anything else to do?

I have noticed that for some reason my browsers, especially Firefox, are still running pretty slowly despite the fact that my Internet speed is good. Is there anything I can do to speed them up?


Report •

#34
June 11, 2015 at 20:31:04
"I have noticed that for some reason my browsers, especially Firefox, are still running pretty slowly despite the fact that my Internet speed is good. Is there anything I can do to speed them up?"
When they get corrupted, it best to uninstall them, then reinstall.

Use this 2 step uninstaller.

Wise Program Uninstaller
http://www.softpedia.com/get/Tweak/...
http://www.freewarefiles.com/Wise-P...
http://www.freewarefiles.com/screen...
http://wisecleaner.com/wiseuninstal...


Report •

#35
June 12, 2015 at 19:51:38
Ok, I uninstalled and reinstalled firefox and it seems to be working better now.

Johnw, thank you again for all of your help! If there is anything else that you would recommend, please let me know.


Report •

#36
June 12, 2015 at 22:05:58
" If there is anything else that you would recommend, please let me know"

Kaspersky installs content blocker, if you want to cut down your ads & speed up browsing, I use this.

Ad Muncher
http://www.softpedia.com/get/Intern...
https://www.admuncher.com/


Report •

Ask Question