JS:SaveByClick-B [Adw]

Every time I start up Chrome I get a pop-up from Avast saying it has blocked something called JS:SaveByClick-B [Adw] :

http://i61.tinypic.com/fk0goj.png

I have followed the instructions in the sticky and attached logs for MBAM, Farbar and aswMBR.
Before coming to this forum I ran scans with MBAM, Spybot Search and Destroy, and Avast itself. MBAM and Spybot found a few minor cookies and adware but the warning pop-up continues unabated.

Let me know any other information that can be helpful and I’ll provide it.
Thanks in advance!

  • Heather

Hi the first priority is to uninstall chrome and then run the following fix. You may reinstall chrome when we are done

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:55922;https=127.0.0.1:55922 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-868611142-120256812-1016054692-1002 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = BHO: No Name -> {C6A3F727-7142-1F67-84C2-A44577679926} -> No File 2014-12-27 09:18 - 2014-12-27 18:04 - 00000480 _____ () C:\WINDOWS\Tasks\RegCure Pro Startup.job 2014-12-27 09:18 - 2014-12-27 09:32 - 00000583 _____ () C:\WINDOWS\Tasks\RegCure Pro_sch_9ABFB627-8DDB-11E4-BF32-3085A9A9321A.job 2014-12-27 09:18 - 2014-12-27 09:32 - 00000462 _____ () C:\WINDOWS\Tasks\ParetoLogic Update Version3_triggeronce.job 2014-12-27 09:18 - 2014-12-27 09:18 - 00003998 _____ () C:\WINDOWS\System32\Tasks\RegCure Pro_sch_9ABFB627-8DDB-11E4-BF32-3085A9A9321A 2014-12-27 09:18 - 2014-12-27 09:18 - 00002924 _____ () C:\WINDOWS\System32\Tasks\ParetoLogic Update Version3_triggeronce 2014-12-27 09:18 - 2014-12-27 09:18 - 00002618 _____ () C:\WINDOWS\System32\Tasks\RegCure Pro Startup 2014-12-27 09:13 - 2014-12-27 09:13 - 06824304 _____ (ParetoLogic, Inc.) C:\Users\Heather\Downloads\RegCureProSetup.exe 2014-12-27 09:08 - 2014-12-27 09:08 - 03044736 _____ (Enigma Software Group USA, LLC.) C:\Users\Heather\Downloads\SpyHunter-Installer.exe C:\Program Files (x86)\Google\Chrome C:\Users\Heather\AppData\Local\Google\Chrome EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.