doubleclick.net, extreshopper malware pop up everytime I open browser. Scanned system, shows no infections.
Hi let me know if this clears them
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint: HKU\S-1-5-21-1144654968-3185280589-1066749937-1000\...\Policies\Explorer: [] GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Toolbar: HKU\S-1-5-21-1144654968-3185280589-1066749937-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File 2015-03-03 08:36 - 2015-03-14 17:07 - 00000000 ____D () C:\Program Files (x86)\BetterPiriiceChec 2015-03-03 08:36 - 2015-03-03 08:36 - 00000000 ____D () C:\Program Files (x86)\History Calendar Button 2015-03-03 08:35 - 2015-03-03 08:35 - 00000000 ____D () C:\Program Files (x86)\QueoenCoupon 2015-02-20 14:57 - 2015-03-03 08:50 - 00000000 ____D () C:\Program Files (x86)\LuckyeShopper 2015-02-20 14:57 - 2015-02-20 14:57 - 00000000 ____D () C:\Program Files (x86)\TiCTACiouopoN 2015-02-20 14:57 - 2015-02-20 14:57 - 00000000 ____D () C:\Program Files (x86)\Domain to IP 2015-02-20 14:38 - 2015-02-20 14:38 - 00000000 __SHD () C:\Users\Walter OSI\AppData\Local\EmieBrowserModeList 2015-02-15 19:38 - 2015-02-15 19:39 - 00000000 ____D () C:\Program Files (x86)\ShhOpperMasteer 2015-02-15 19:38 - 2015-02-15 19:38 - 00000000 ____D () C:\Program Files (x86)\Pea vs Zombies 2015-02-15 19:38 - 2015-02-15 19:38 - 00000000 ____D () C:\Program Files (x86)\ExetraShhoppeer 2015-03-14 17:07 - 2015-01-07 11:36 - 00000000 ____D () C:\ProgramData\SAverPro 2015-03-14 17:07 - 2015-01-07 11:36 - 00000000 ____D () C:\ProgramData\deAAlsterr 2015-03-03 08:50 - 2015-01-02 14:20 - 00000000 ____D () C:\ProgramData\SAllesCheckerr 2015-03-03 08:42 - 2014-10-23 09:54 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 2015-03-03 08:36 - 2015-01-28 08:32 - 00000000 ____D () C:\ProgramData\13793435594282784048 2015-02-20 15:04 - 2014-12-16 15:09 - 00000000 ____D () C:\ProgramData\KingCouponn 2015-02-20 15:04 - 2014-12-09 08:24 - 00000000 ____D () C:\ProgramData\shoipnedrropa 2015-02-20 15:04 - 2014-11-07 08:10 - 00000000 ____D () C:\ProgramData\deal4real RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.
here’s the log generated after running the fix.
and AdwCleaner log?