I need help removing something that is hijacking my homepages for both Chrome and FF. The unwanted homepage URL is:




I've done some cleaning but haven't had luck removing this issue.





DDS (Ver_2012-11-20.01)
Microsoft Windows 7 Ultimate 
Boot Device: \Device\HarddiskVolume2
Install Date: 4/13/2012 3:15:43 PM
System Uptime: 8/25/2013 1:14:31 PM (0 hours ago)
Motherboard: Gigabyte Technology Co., Ltd. |  | P55A-UD3
Processor: Intel® Core i5 CPU         760  @ 2.80GHz | Socket 1156 | 2794/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 238 GiB total, 92.226 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 932 GiB total, 719.328 GiB free.
G: is FIXED (NTFS) - 1863 GiB total, 851.459 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Realtek PCIe GBE Family Controller
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_06\4&43FAD29&0&00E1
Manufacturer: Realtek
Name: Realtek PCIe GBE Family Controller
PNP Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_06\4&43FAD29&0&00E1
Service: RTL8167
==== System Restore Points ===================
RP1262: 8/16/2013 2:00:17 AM - Automatic creation
RP1264: 8/17/2013 2:00:17 AM - Automatic creation
RP1267: 8/18/2013 2:00:17 AM - Automatic creation
RP1271: 8/19/2013 2:00:18 AM - Automatic creation
RP1273: 8/20/2013 2:00:18 AM - Automatic creation
RP1277: 8/21/2013 2:00:18 AM - Automatic creation
RP1281: 8/22/2013 2:00:10 AM - Automatic creation
RP1285: 8/23/2013 2:00:10 AM - Automatic creation
RP1295: 8/24/2013 4:06:26 PM - Automatic creation
RP1299: 8/25/2013 2:00:07 AM - Automatic creation
==== Installed Programs ======================
7-Zip 9.20 (x64 edition)
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader XI (11.0.02)
Akamai NetSession Interface
Amnesia: The Dark Descent
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AutoGreen B09.1014.2
Beat Hazard
BUG Mod 4.4
CutePDF Writer 2.8
dBpoweramp DSP Effects
dBpoweramp Music Converter
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
DES 2.0
DisplayFusion 3.4.1
Easy Tune 6 B10.0521.1
EPSON NX410 Series Printer Uninstall
Evernote v. 4.5.4
Exact Audio Copy 0.99pb5
foobar2000 v1.1.11
Foxit Reader
GIMP 2.6.12
Glary Utilities
Google Chrome
Google Earth
Google Talk Plugin
Hotline Miami
Java 7 Update 7
Java 7 Update 9 (64-bit)
Java Auto Updater
Java 6 Update 31
Java SE Development Kit 7 Update 2
JavaFX 2.0.2 SDK
JavaFX 2.0.3
K-Lite Codec Pack 8.6.0 (Full)
Kerbal Space Program Demo
LastPass (uninstall only)
Left 4 Dead 2
MagicDisc 2.7.106
Malwarebytes Anti-Malware version
MBSS Galaxies  6.0
Microsoft .NET Framework 4.5
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office Office 32-bit Components 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared 32-bit MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Visio 2010
Microsoft Office Visio MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Outlook 2010
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Visio 2010 Service Pack 1 (SP1)
Microsoft Visio Premium 2010
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Microsoft XNA Framework Redistributable 3.1
Microsoft XNA Framework Redistributable 4.0
Mozilla Firefox 11.0 (x86 en-US)
Mp3tag v2.52
Mumble 1.2.4
NEC Electronics USB 3.0 Host Controller Driver
NVIDIA 3D Vision Controller Driver 296.10
NVIDIA 3D Vision Driver 311.06
NVIDIA Control Panel 311.06
NVIDIA Graphics Driver 311.06
NVIDIA HD Audio Driver
NVIDIA Install Application
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.11.3
NVIDIA Update Components
ON_OFF Charge B10.0427.1
Oracle VM VirtualBox 4.2.6
Really Slick Screensavers 0.2
Realtek Ethernet Controller Driver For Windows 7
Realtek High Definition Audio Driver
Rosetta Stone Version 3
S.T.A.L.K.E.R.: Clear Sky
Security Update for Microsoft .NET Framework 4.5 (KB2737083)
Security Update for Microsoft .NET Framework 4.5 (KB2789648)
Security Update for Microsoft .NET Framework 4.5 (KB2804582)
Security Update for Microsoft .NET Framework 4.5 (KB2833957)
Security Update for Microsoft .NET Framework 4.5 (KB2840642v2)
Security Update for Microsoft Excel 2010 (KB2597126) 64-Bit Edition
Security Update for Microsoft Filter Pack 2.0 (KB2553501) 64-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687422) 64-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2760406) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553371) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2687501) 64-Bit Edition
Security Update for Microsoft Office 2010 (KB2687510) 64-Bit Edition
Security Update for Microsoft OneNote 2010 (KB2760600) 64-Bit Edition
Security Update for Microsoft Publisher 2010 (KB2553147) 64-Bit Edition
Security Update for Microsoft Visio 2010 (KB2810068) 64-Bit Edition
Security Update for Microsoft Visio Viewer 2010 (KB2687505) 64-Bit Edition
Security Update for Microsoft Word 2010 (KB2760410) 64-Bit Edition
Sid Meier's Civilization V
Skype™ 5.9
Smart 6 B10.0422.1
TagScanner 5.1.620
Team Fortress 2
TeraCopy 2.27
The Binding of Isaac
Total Commander 64-bit (Remove or Repair)
Ubisoft Game Launcher
Unity Web Player
Update for Microsoft .NET Framework 4.5 (KB2750147)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 64-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 64-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition
Ventrilo Client for Windows x64
VLC media player 2.0.1
VMware Player
VNC Mirror Driver 1.8.0
VNC Printer Driver 1.8.0
VNC Server 5.0.1
VNC Viewer 5.0.1
WinSCP 4.3.7
Zen Bound® 2
==== Event Viewer Messages From Past Week ========
8/25/2013 1:16:48 PM, Error: Service Control Manager [7038]  - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error:  Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
8/25/2013 1:16:48 PM, Error: Service Control Manager [7000]  - The NVIDIA Update Service Daemon service failed to start due to the following error:  The service did not start due to a logon failure.
8/25/2013 1:14:48 PM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  mv91cons mv91xx
8/25/2013 1:13:17 PM, Error: Service Control Manager [7034]  - The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly.  It has done this 1 time(s).
==== End Of File ===========================
Hello cadetpirx and :welcome:! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Please tick the Scan All users. Next, click the Quick Scan button. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic.
Hi Borislav,


Thanks for taking this on! Extras.txt was not created but OTL.txt is pasted below:



Step 1


  • Under the Custom Scans/Fixes box at the bottom, paste in the following


    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}

    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

    IE - HKLM\..\SearchScopes,DefaultScope =

    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

    IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-21-384163472-3497793350-581274558-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve

    IE - HKU\S-1-5-21-384163472-3497793350-581274558-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =

    IE - HKU\S-1-5-21-384163472-3497793350-581274558-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp

    IE - HKU\S-1-5-21-384163472-3497793350-581274558-1000\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-21-384163472-3497793350-581274558-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

    IE - HKU\S-1-5-21-384163472-3497793350-581274558-1000\..\SearchScopes\{FA77F656-8D08-4DC9-8160-84E22417429F}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=714647&p={searchTerms}

    FF - prefs.js..browser.search.defaultenginename: "Yahoo"

    FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=714647"

    FF - prefs.js..browser.search.selectedEngine: "Yahoo"

    FF - prefs.js..browser.startup.homepage: "http://search.yahoo.com/?type=714647&fr=spigot-yhp-ff"

    FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=714647&p="

    [2012/11/06 09:19:24 | 000,214,034 | ---- | M] () (No name found) -- C:\Users\Stoffel\AppData\Roaming\Mozilla\Firefox\Profiles\k346xno4.default\extensions\putlockerdownloader@putlockerdownloader.com.xpi

    [2013/08/24 13:31:37 | 000,000,915 | ---- | M] () -- C:\Users\Stoffel\AppData\Roaming\Mozilla\Firefox\Profiles\k346xno4.default\searchplugins\yahoo.xml

    CHR - homepage: http://search.yahoo.com/?type=714647&fr=spigot-yhp-ch

    CHR - Extension: OneTab = C:\Users\Stoffel\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall\1.5_0\

    [2013/08/24 15:38:43 | 000,000,000 | ---D | M] -- C:\Users\Stoffel\AppData\Roaming\uTorrent


    ipconfig /flushdns /c



  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Please post the OTL fix log in your next reply.
Note: A copy of an OTL fix log is saved in a text file at C:\_OTL\MovedFiles

Step 2

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 3

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Clean.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[s1].txt as well.
In your next reply, post the following log files:
  • OTL Fix log
  • Junkware Removal Tool log
  • AdwCleaner log
Ok, logs pasted below. No change so far to Chrome homepage.



OTL (08262013_091433.txt)



# AdwCleaner v3.001 - Report created 26/08/2013 at 09:33:52
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Stoffel - SHARDIK
# Running from : C:\Users\Stoffel\Desktop\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16618
-\\ Mozilla Firefox v11.0 (en-US)
[ File : C:\Users\Stoffel\AppData\Roaming\Mozilla\Firefox\Profiles\k346xno4.default\prefs.js ]
-\\ Google Chrome v
[ File : C:\Users\Stoffel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
AdwCleaner[R0].txt - [4874 octets] - [24/08/2013 14:56:22]
AdwCleaner[R1].txt - [4934 octets] - [24/08/2013 14:57:33]
AdwCleaner[R2].txt - [1066 octets] - [24/08/2013 15:03:47]
AdwCleaner[R3].txt - [1187 octets] - [24/08/2013 15:42:13]
AdwCleaner[R4].txt - [1247 octets] - [26/08/2013 09:31:41]
AdwCleaner[R5].txt - [1308 octets] - [26/08/2013 09:33:17]
AdwCleaner[s0].txt - [4822 octets] - [24/08/2013 14:58:53]
AdwCleaner[s1].txt - [1128 octets] - [24/08/2013 15:05:53]
AdwCleaner[s2].txt - [1229 octets] - [26/08/2013 09:33:52]
########## EOF - C:\AdwCleaner\AdwCleaner[s2].txt - [1289 octets] ##########
