@gunther.seymus
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
BHO: No Name -> {B23287E9-D626-858A-E88F-6822FBC14E55} -> No File
BHO-x32: No Name -> {B23287E9-D626-858A-E88F-6822FBC14E55} -> No File
CHR Extension: (NexetCuooup) - C:\Users\Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjklemlmfkaidjindgbebdplabcfkkgm [2014-07-06]
CHR Extension: (savve oin) - C:\Users\Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmnljmkjnboacncemcopkijfnbhncpaa [2014-07-04]
CHR Extension: (NeexTCoup) - C:\Users\Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlhfglfbaceojifphbiipckokaaodnac [2014-07-20]
CHR Extension: (savve oin) - C:\Users\Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmnljmkjnboacncemcopkijfnbhncpaa\2.14 [2014-07-04]
CHR Extension: (NeexTCoup) - C:\Users\Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlhfglfbaceojifphbiipckokaaodnac\1.0 [2014-07-20]
2014-07-04 23:09 - 2014-07-20 02:05 - 00000000 ____D () C:\ProgramData\24faa408ba0ad5b3
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Gunther\AppData\Local\Torch
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Gunther\AppData\Local\Chromatic Browser
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Gast\AppData\Local\Torch
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Gast\AppData\Local\Chromatic Browser
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-07-04 23:09 - 2014-07-04 23:09 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
2014-07-06 03:25 - 2014-07-20 02:10 - 00000000 ____D () C:\ProgramData\NexetCuooup
2014-07-06 03:25 - 2014-07-06 03:25 - 00000000 ____D () C:\Program Files (x86)\NexetCuooup
CMD: bitsadmin /reset /allusers
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
REBOOT:
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download Junkware Removal Tool to your desktop.
[]Right-mouse click JRT.exe and select “Run as Administrator” the tool will open and start scanning your system
[]please be patient as this can take a while to complete depending on your system’s specifications
[]On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
[]post the contents of JRT.txt into your next message.