File Found : C:\Windows\System32\Tasks\NCH Software
This is leftover task. Non-active task ...
-\\ Mozilla Firefox v
[ File : C:\Users\PatricK\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js ]
It is deleted the profile file firefox related. The result of this is when firefox load next time if he can’t find prefs settings it shall create it again with default settings.
Or in translation, FF did a half-reset itself. AdwC did not detect nothing important. The same goes for Chrome
But if you want to check the system, follow Pondus advice.
Havent tried safe mode, MBAM , hitmanpro, SAS,Avast (modified to high settings) all come back clean
but ive ran adwcleaner alot since last week and its usually clean (nch software usually popups up but not in system32)
about nch i check the folder and its contains 0 bytes and one of the group user name is CREATOR OWNER (though this account does have any ticked privileges), i posted it here because i ran adwcleaner alot since last 2 weeks and its popped up nch but nothing system32 related (only registry) and after than the log where clean, then this week i saw this popup so i was wondering how come especially since its in system32
but you say its no active so dont worry about it?
I havent had firefox for a long while, so i can delete the appdata entry? ( though chrome cpu usage has been off the charts when loading pages , jump to 90+ percent then dips ever since i updated)
I can confirm that NCH software does place something on your PC but I’m not sure what I would call it. Specifically, I noticed a link to their website kept reappearing in Firefox and this CNET review also warns of browser hijacking as well. I fixed mine with an image restoral but I’m sure there are other ways to deal with this issue so good luck.
Yup, even amazon has some weird bots running in the firewall even when your are not on the site
the thing is i dont know any active nch software is have , ill have to check again
thanks for the input
waiting for log reply from the guys
[*]Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
:FILES
C:\Users\PatricK\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\OneClickDownloader@OneClickDownloader.com.xpi
C:\Users\PatricK\Desktop\*.tmp
:OTL
O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No CLSID value found.
:COMMANDS
[CREATERESTOREPOINT]
[EMPTYTEMP]
[*]Then click the Run Fix button at the top.
[*]Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
[]Shut down your protection software now to avoid potential conflicts.
[]Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select “Run as Administrator”.
[]The tool will open and start scanning your system.
[]Please be patient as this can take a while to complete depending on your system’s specifications.
[]On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
[]Post the contents of JRT.txt into your next message.
OTL by OldTimer - Version 3.2.69.0 log created on 12052013_162713
Files\Folders moved on Reboot…
C:\Users\PatricK\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\temp_avast_\Webshlock.txt scheduled to be moved on reboot.
Yes, just was wondering why nch keep pooping up in adwarecleaner , even though weeks before its was clean
the only problem now is high cpu usage from chrome (which occurs since the ewer update, cpu usage jumps to 100% each page load then drop back to 2%)
another thing i forgot to tell you was, when windows started up and was showing a black screen before the desktop popped up , there was a sudden popup that came and disappeared in 1 second, ui always wondered what it was but not its gone
great work and thanks ;D
though my pc cant keep restore points, everytime its shuts down (via powercut) i have to reset the time and date and all my restore point are usually gone (i created many but they all disappear)
:o