This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

How do you get rid of totaladperformance [Solved]

479 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Don't know where to start, but after a month of this web site popping up in Chrome and numerous attempts to locate within files, I am exhausted! 

 

Currently running Chrome Version 44.0.2403.125 m.  

 

Windows 10 Home version

Trend Micro  Internet Security 

 

Toshiba Satellite Radius P55W-B

INTEL CORE I7-451OU CPU  @ 200gHZ 260gHZ

RAM 8GB

64-bit  OPERATING SYSTEM, x64 based processor

 

 

Started having this total performance popping up and so I began using the Block Site extension which stopped those from this site from loading. It does stop this site from loading, but even their notification is getting to me. I  foolishly click on a link for the "new AOL" and since then my life has been hell!

 

I have run numerous security scans and one from google. Each comes up clean. I have uninstalled Chrome 2 times. I searched for any new programs or apps which I did not download.  Yesterday, I downloaded Spy Hunter and found 2 files in the registry and removed them. Computer started running great and then today this popped up again….I surrender!  I am just to this point I am ready to remove Chrome from files and  registry. 

 

The programs which you suggest will not work on Windows 10! So tired of all this foolishness! Thanks in advanced for any suggestions.

:welcome:

 

The programs that i will have you run will run on Win 10

 

 
Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Please make sure All Users is checked
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
  • Ken, I download and followed your directions and get a notification screen which says, "This app can't Run on your PC.  To find a version for you PC, check with the software publisher" and only option it gives is to close the notification screen. 

     

    I did d/l the 64bit as this is the OS I have as you can see in my first post.  What next? 

    I upgraded to Win 10 and have a 64 bit OS as well and it just ran fine on my system

     

    Lets try running these and see what happens, if one wont run just go to the next, these also ran just fine on my system

     

     
    -AdwCleaner-by Xplode
     
    Click on this link to download : ADWCleaner TO YOUR DESKTOP
    Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
    Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
     
     
    Do not click on any links in the top Advertisment.
     
    [external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
     
    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Scan.
    • After the scan is complete click on "Clean"
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the content of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
    •  
       
      ===============================================================================
       
       
      [external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
      • Shut down your protection software now to avoid potential conflicts.
      • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
      • The tool will open and start scanning your system.
      • Please be patient as this can take a while to complete depending on your system's specifications.
      • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
      • Post the contents of JRT.txt into your next message.
      •  
         
         
        ===============================================================================
         
        Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
         
        • Windows XP : Double click on the icon to run it.
        • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
        •  
          [external image: MBAM_zpsr1ew7hep.png]
           
          • On the Dashboard click on Update Now
          • Go to the Setting Tab
          • Under Setting go to Detection and Protection
          • Under PUP and PUM make sure both are set to show Treat Detections as Malware
          • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
          • Then on the Dashboard click on Scan
          • Make sure to select THREAT SCAN
          • Then click on Scan
          • When the scan is finished and the log pops up…select Copy to Clipboard
          • Please paste the log back into this thread for review
          • Exit Malwarebytes
          • This is the log from the AdwCleaner. Since we have hughesnet it takes time for me to d/l, so I will do each of these you have listed and post after each. I am sorry to be such a pain, but honestly our internet access right now is not that great. Please bear with me.
             
            ***** [ Shortcuts ] *****
             
             
            ***** [ Registry ] *****
             
             
            ***** [ Web browsers ] *****
             
            -\\ Internet Explorer v11.0.10240.16384
             
             
            -\\ Google Chrome v44.0.2403.130
             
             
            *************************
             
            AdwCleaner[R0].txt - [856 bytes] - [06/08/2015 11:55:40]
            AdwCleaner[R1].txt - [914 bytes] - [06/08/2015 12:04:57]
            AdwCleaner[R2].txt - [897 bytes] - [06/08/2015 12:07:02]
            AdwCleaner[S0].txt - [651 bytes] - [06/08/2015 12:05:34]
            AdwCleaner[S1].txt - [823 bytes] - [06/08/2015 12:07:36]
             
            ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [881  bytes] ##########
             
            This is the JRT log:
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            Junkware Removal Tool (JRT) by Malwarebytes
            Version: 7.5.5 (08.05.2015:1)
            OS: Windows 10 Home x64
            Ran by [removed] on Thu 08/06/2015 at 12:21:04.79
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
             
             
             
             
            ~~~ Services
             
             
             
            ~~~ Tasks
             
             
             
            ~~~ Registry Values
             
             
             
            ~~~ Registry Keys
             
             
             
            ~~~ Files
             
             
             
            ~~~ Folders
             
            Successfully deleted: [Folder] C:\users\Public\Documents\downloaded installers
            Successfully deleted: [Folder] C:\Users\Wendy\AppData\Roaming\alawarentertainment
            Successfully deleted: [Folder] C:\Users\Wendy\AppData\Roaming\getrighttogo
             
             
             
            ~~~ Chrome
             
            Successfully deleted: [Folder] C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic
             
            [C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
             
            [C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
            gpdjojdkbbmdfjfahjcgigfpmkopogic
             
            [C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
             
            [C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
            [
              gpdjojdkbbmdfjfahjcgigfpmkopogic
            ]
             
             
             
             
             
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            Scan was completed on Thu 08/06/2015 at 12:22:55.08
            End of JRT log
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
             

            And the final Malwarebytes AntiMalware log

             

             

            Malwarebytes Anti-Malware
            www.malwarebytes.org
             
             
            Protection, 8/6/2015 1:06 PM, SYSTEM, HOPE2, Protection, Malware Protection, Starting, 
            Protection, 8/6/2015 1:06 PM, SYSTEM, HOPE2, Protection, Malware Protection, Started, 
            Protection, 8/6/2015 1:06 PM, SYSTEM, HOPE2, Protection, Malicious Website Protection, Starting, 
            Protection, 8/6/2015 1:06 PM, SYSTEM, HOPE2, Protection, Malicious Website Protection, Started, 
            Error, 8/6/2015 1:19 PM, SYSTEM, HOPE2, Update, Bad md5 or size: akadomains, 11, 
            Error, 8/6/2015 1:19 PM, SYSTEM, HOPE2, Update, Bad md5 or size: akaips, 11, 
            Update, 8/6/2015 1:19 PM, SYSTEM, HOPE2, Manual, Domain Database, 0.0.0.0, 2015.7.24.2, 
            Update, 8/6/2015 1:19 PM, SYSTEM, HOPE2, Manual, IP Database, 0.0.0.0, 2015.7.24.3, 
            Update, 8/6/2015 1:19 PM, SYSTEM, HOPE2, Manual, Remediation Database, 2015.5.13.1, 2015.7.28.1, 
            Update, 8/6/2015 1:19 PM, SYSTEM, HOPE2, Manual, Rootkit Database, 2015.6.2.1, 2015.8.4.1, 
            Update, 8/6/2015 1:20 PM, SYSTEM, HOPE2, Manual, AKA IP Database, 0.0.0.0, 2015.8.6.1, 
            Update, 8/6/2015 1:22 PM, SYSTEM, HOPE2, Manual, AKA Domain Database, 0.0.0.0, 2015.8.6.1, 
            Update, 8/6/2015 1:46 PM, SYSTEM, HOPE2, Manual, Malware Database, 2015.6.3.3, 2015.8.6.6, 
            Protection, 8/6/2015 1:46 PM, SYSTEM, HOPE2, Protection, Refresh, Starting, 
            Protection, 8/6/2015 1:46 PM, SYSTEM, HOPE2, Protection, Malicious Website Protection, Stopping, 
            Protection, 8/6/2015 1:46 PM, SYSTEM, HOPE2, Protection, Malicious Website Protection, Stopped, 
            Protection, 8/6/2015 1:46 PM, SYSTEM, HOPE2, Protection, Refresh, Success, 
            Protection, 8/6/2015 1:46 PM, SYSTEM, HOPE2, Protection, Malicious Website Protection, Starting, 
            Protection, 8/6/2015 1:46 PM, SYSTEM, HOPE2, Protection, Malicious Website Protection, Started, 
            Scan, 8/6/2015 2:11 PM, SYSTEM, HOPE2, Manual, Start:8/6/2015 1:46 PM, Duration:24 min 54 sec, Threat Scan, Completed, 0 Malware Detections, 0 Non-Malware Detections, 
             
            (end)
             
            And to add to the mix, as I began d/l this program this popped up: 
             
            12:24 PM
            Support
            truesupport.info
             
             
            12:24 PM
            www.tradeadexchange.com
             
             
            12:24 PM
            www.tradeadexchange.com
             
             
            12:24 PM
            www.tradeadexchange.com
             

            Locked up Chrome and had to use task manager to get out of Chrome. It did not come up again, but this is driving me crazy. Thanks Ken for your patience with me.

             

            Wendy 

            Hi, been away for most of the day but i am back now

             

            You posted the Malwarebytes Protection log, I need to see the log from the scan you just ran, maybe it will tell us what to look for now

             

            • Open Malwarebytes and on the Dashboard click on History
            • Then Application Logs 
            • Then Scan log 
            • Select the date of the scan you just ran
            • Then click Export
            • On the dropdown list select Copy to Clipboard and paste it into this thread
            • Here is the log you asked for. I hope you can figure this out because honestly I am totally lost. Sorry, I kinda got sidetracked with Under the Dome.
               
              Malwarebytes Anti-Malware
              www.malwarebytes.org
               
              Scan Date: 8/6/2015
              Scan Time: 1:46 PM
              Logfile: 
              Administrator: Yes
               
              Version: 2.1.8.1057
              Malware Database: v2015.08.06.06
              Rootkit Database: v2015.08.04.01
              License: Trial
              Malware Protection: Enabled
              Malicious Website Protection: Enabled
              Self-protection: Disabled
               
              OS: Windows 10
              CPU: x64
              File System: NTFS
              User: Wendy
               
              Scan Type: Threat Scan
              Result: Completed
              Objects Scanned: 437101
              Time Elapsed: 24 min, 54 sec
               
              Memory: Enabled
              Startup: Enabled
              Filesystem: Enabled
              Archives: Enabled
              Rootkits: Disabled
              Heuristics: Enabled
              PUP: Enabled
              PUM: Enabled
               
              Processes: 0
              (No malicious items detected)
               
              Modules: 0
              (No malicious items detected)
               
              Registry Keys: 0
              (No malicious items detected)
               
              Registry Values: 0
              (No malicious items detected)
               
              Registry Data: 0
              (No malicious items detected)
               
              Folders: 0
              (No malicious items detected)
               
              Files: 0
              (No malicious items detected)
               
              Physical Sectors: 0
              (No malicious items detected)
               
               
              (end)

              Drag Junkware Removal Tool to the trash and lets download and run a different version

               

               

              [external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
              •  
              • Download the one from Bleeping Computer
              • Shut down your protection software now to avoid potential conflicts.
              • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
              • The tool will open and start scanning your system.
              • Please be patient as this can take a while to complete depending on your system's specifications.
              • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
              • Post the contents of JRT.txt into your next message.
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
              Junkware Removal Tool (JRT) by Malwarebytes
              Version: 7.5.5 (08.05.2015:1)
              OS: Windows 10 Home x64
              Ran by [removed] on Fri 08/07/2015 at  8:13:39.10
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
               
               
               
               
              ~~~ Services
               
               
               
              ~~~ Tasks
               
               
               
              ~~~ Registry Values
               
               
               
              ~~~ Registry Keys
               
               
               
              ~~~ Files
               
               
               
              ~~~ Folders
               
               
               
              ~~~ Chrome
               
              Successfully deleted: [Folder] C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic
               
              [C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
               
              [C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
              gpdjojdkbbmdfjfahjcgigfpmkopogic
               
              [C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
               
              [C:\Users\Wendy\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
              [
                gpdjojdkbbmdfjfahjcgigfpmkopogic
              ]
               
               
               
               
               
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
              Scan was completed on Fri 08/07/2015 at  8:15:29.70
              End of JRT log
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

              Do this also

               

               

              Download Avast-browser-cleanup to your desktop
               
              • There is nothing to  install, just right click on it and Run As Adminstrator
              • When its finished scanning it will list Browser Add ONs
              • If if finds Total Ad Performance or any other bogus toolbars
              • Just high light them and select REMOVE
              • Close out the program
              • Reboot your system and test your browsers
              •  
                 
                =======================================================================
                 
                • Open Internet Explorer
                • Click on Tools up on the top right
                • Click on Manage Add Ons from the dropdown list
                • In this window you can manage the Internet Explorer add-ons
                • Click on Search Providers
                • Click on the option Toolbars and Extensions on left side of the window.
                • Then click on the malicious items to remove Total Ad Performance
                • Make Google you default
                • Close IE and then open it again and see if Total Ad Performance are gone
                •  
                   
                  ======================================================================
                   
                  • Open Chrome
                  • Click the Chrome menu [external image: Clipboard01_zps2e55f676.jpg]on the browser toolbar.
                  • Click on Settings
                  • Then Manage Search Engines
                  • Highlite Total Ad Performance and select Delete
                  • Then go to Other Search Engines and remove all you dont want
                  •  
                     
                    ===========================================================================
                     
                     
                    • Open Firefox
                    • Up on the Top Right in the Search Box , click on the down arrow and select Manage Search Engines 
                    • Highlite Total Ad Performance and select Delete
                    • This the log from the AVAST browser-clean up. Nothing there for Total Performance, but now this site is beginning to do the same tradeadexchang. Please do not click on this just in case it did not type as text.   Would it be worth it to delete Chrome and the registry? This has been a nightmare.
                       
                      07.08.2015 09:57:49 (TID: 9736)
                      ProductVersion: 9.0.0.224
                      Mozilla Firefox Browser
                      Mozilla Firefox Warning: Failed to find install path
                      Google Chrome Browser
                      Version: 44.0.2403.130
                      Install Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                      Profile Path: C:\Users\Wendy\AppData\Local\Google\Chrome\User Data\
                      Google Chrome Profiles
                      Name: Default Path: C:\Users\Wendy\AppData\Local\Google\Chrome\User Data\Default
                      Opera Browser
                      Opera Warning: Failed to find install path
                      Apple Safari Browser
                      Apple Safari Warning: Failed to access Safari
                      Google Chrome
                      Extensions
                      Homepages
                      Microsoft IE
                      Extensions
                      ID: {2933bf90-7b36-11d2-b20e-00c04f983e60} Name: XML DOM Document
                      ID: {31d09ba0-12f5-4cce-be8a-2923e76605da} Name: Skype for Business Browser Helper
                      ID: {6bf52a52-394a-11d3-b153-00c04f79faa6} Name: Windows Media Player
                      ID: {8856f961-340a-11d0-a96b-00c04fd705a2} Name: Microsoft Web Browser
                      ID: {88d96a05-f192-11d4-a65f-0040963251e5} Name: XML DOM Document 6.0
                      ID: {959a5673-7971-48e6-af54-58f745ac4abc} Name: TmIEPlugInBHO Class
                      ID: {9b4b91fc-ec4d-4018-9575-96fa5a3c03c5} Name: Trend Micro Password Manager ToolBar
                      ID: {bbacbafd-fa5e-4079-8b33-00eb9f13d4ac} Name: Trend Micro IE Protection
                      ID: {ca8a9780-280d-11cf-a24d-444553540000} Name: Adobe PDF Reader
                      ID: {ccac5586-44d7-4c43-b64a-f042461a97d2} Name: Trend Micro Security Toolbar
                      ID: {d27cdb6e-ae6d-11cf-96b8-444553540000} Name: Shockwave Flash Object
                      ID: {ed8c108e-4349-11d2-91a4-00c04f7969e8} Name: XML HTTP Request
                      ID: {f6d90f16-9c73-11d3-b32e-00c04f990bb4} Name: XML HTTP
                      Homepages
                      HKCU: about:blank
                      Search Engines
                      http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
                      Homepages
                      Homepages
                      HKCU: about:blank
                      Search Engines
                      http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
                      BCURequest:
                      os_language : en-us
                      location: en-us
                      osType: 6.2
                      browser: chrome is_default: 1
                      browser: iexplorer is_default: 0
                      id: {2933bf90-7b36-11d2-b20e-00c04f983e60} name: XML DOM Document
                      id: {31d09ba0-12f5-4cce-be8a-2923e76605da} name: Skype for Business Browser Helper
                      id: {6bf52a52-394a-11d3-b153-00c04f79faa6} name: Windows Media Player
                      id: {8856f961-340a-11d0-a96b-00c04fd705a2} name: Microsoft Web Browser
                      id: {88d96a05-f192-11d4-a65f-0040963251e5} name: XML DOM Document 6.0
                      id: {959a5673-7971-48e6-af54-58f745ac4abc} name: TmIEPlugInBHO Class
                      id: {9b4b91fc-ec4d-4018-9575-96fa5a3c03c5} name: Trend Micro Password Manager ToolBar
                      id: {bbacbafd-fa5e-4079-8b33-00eb9f13d4ac} name: Trend Micro IE Protection
                      id: {ca8a9780-280d-11cf-a24d-444553540000} name: Adobe PDF Reader
                      id: {ccac5586-44d7-4c43-b64a-f042461a97d2} name: Trend Micro Security Toolbar
                      id: {d27cdb6e-ae6d-11cf-96b8-444553540000} name: Shockwave Flash Object
                      id: {ed8c108e-4349-11d2-91a4-00c04f7969e8} name: XML HTTP Request
                      id: {f6d90f16-9c73-11d3-b32e-00c04f990bb4} name: XML HTTP
                      BCUResponse:
                      Browser: chrome provider_modified: 0
                      Browser: iexplorer provider_modified: 0
                      id: {2933bf90-7b36-11d2-b20e-00c04f983e60} intarnal_id: 2191 rating: 5
                      id: {31d09ba0-12f5-4cce-be8a-2923e76605da} intarnal_id: 5000 rating: 5
                      id: {6bf52a52-394a-11d3-b153-00c04f79faa6} intarnal_id: 5300 rating: 5
                      id: {8856f961-340a-11d0-a96b-00c04fd705a2} intarnal_id: 8000 rating: 5
                      id: {88d96a05-f192-11d4-a65f-0040963251e5} intarnal_id: 5200 rating: 5
                      id: {959a5673-7971-48e6-af54-58f745ac4abc} intarnal_id: 8000 rating: 5
                      id: {9b4b91fc-ec4d-4018-9575-96fa5a3c03c5} intarnal_id: 1 rating: 3
                      id: {bbacbafd-fa5e-4079-8b33-00eb9f13d4ac} intarnal_id: 8000 rating: 5
                      id: {ca8a9780-280d-11cf-a24d-444553540000} intarnal_id: 8000 rating: 5
                      id: {ccac5586-44d7-4c43-b64a-f042461a97d2} intarnal_id: 1 rating: 3
                      id: {d27cdb6e-ae6d-11cf-96b8-444553540000} intarnal_id: 2081 rating: 5
                      id: {ed8c108e-4349-11d2-91a4-00c04f7969e8} intarnal_id: 5000 rating: 5
                      id: {f6d90f16-9c73-11d3-b32e-00c04f990bb4} intarnal_id: 5000 rating: 5
                      Detected a potential browser protector: {
                         "Services" : {
                            "Description" : "provides support for the running object table for installshield drivers",
                            "DisplayName" : "installdriver table manager",
                            "FileInfo" : {
                               "Path" : "\"c:\\program files (x86)\\common files\\installshield\\driver\\11\\intel 32\\idrivert.exe\"",
                               "md5" : ""
                            },
                            "Name" : "IDriverT"
                         }
                      }
                      Detected a potential browser protector: {
                         "Services" : {
                            "Description" : "@%programfiles%\\windows defender\\mpasdesc.dll,-242",
                            "DisplayName" : "@%programfiles%\\windows defender\\mpasdesc.dll,-320",
                            "FileInfo" : {
                               "Path" : "\"c:\\program files (x86)\\windows defender\\nissrv.exe\"",
                               "md5" : ""
                            },
                            "Name" : "WdNisSvc"
                         }
                      }
                      Detected a potential browser protector: {
                         "Services" : {
                            "Description" : "manages all components of trend micro password manager",
                            "DisplayName" : "trend micro password manager central control service",
                            "FileInfo" : {
                               "Path" : "\"c:\\program files\\trend micro\\tmids\\pwmsvc.exe\"",
                               "md5" : ""
                            },
                            "Name" : "PwmSvc"
                         },
                         "runKeys" : {
                            "PwmConsole.exe" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\PwmConsole.exe=\"c:\\program files\\trend micro\\tmids\\pwmconsole.exe\" -s"
                         },
                         "uninstallInfo" : {
                            "{3075404F-5657-4f31-A064-FEF98661BDD4}" : {
                               "DisplayName" : "Trend Micro Password Manager",
                               "Publisher" : "Trend Micro Inc.",
                               "UninstallString" : "c:\\program files\\trend micro\\tmids\\remove.exe"
                            }
                         }
                      }
                      Detected a potential browser protector: {
                         "runKeys" : {
                            "cAudioFilterAgent" : "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\cAudioFilterAgent=c:\\program files\\conexant\\caudiofilteragent\\caudiofilteragent64.exe"
                         }
                      }
                      Detected a potential browser protector:1148FDAC0C4B01E9F7C925E22F0E13CA0ECA3DB8AE13F3303E99AB03D4E7B644 {
                         "Services" : {
                            "Description" : "intel(r) content protection heci service - enables communication with the content protection fw",
                            "DisplayName" : "intel(r) content protection heci service",
                            "FileInfo" : {
                               "CompanyName" : "Intel Corporation",
                               "FileDescription" : "IntelCpHeciSvc Executable",
                               "Path" : "c:\\windows\\syswow64\\intelcphecisvc.exe",
                               "ProductVersion" : "9.0.31.9000",
                               "md5" : "A6B9FD89353D6005DD74485F591F2A83"
                            },
                            "Name" : "cphs"
                         },
                         "runKeys" : {
                            "StubPath" : "HKCU\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath=c:\\windows\\syswow64\\rundll32.exe c:\\windows\\syswow64\\mscories.dll,install"
                         }
                      }
                      Homepages
                      Homepages
                      HKCU: about:blank
                      Search Engines
                      http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
                      APP::removeEvilToolbars: /removeprotector="" 
                      GUI:ECMD: /removeprotector=""  /user=S-1-5-21-1738210461-3613639603-2110639779-1002
                      APP::removeEvilToolbars: 0
                      execute: /remove="<1>{9b4b91fc-ec4d-4018-9575-96fa5a3c03c5}" /resetsettings=""  /user=S-1-5-21-1738210461-3613639603-2110639779-1002
                      Google Chrome
                      Extensions
                      Homepages
                      Microsoft IE
                      Extensions
                      ID: {2933bf90-7b36-11d2-b20e-00c04f983e60} Name: XML DOM Document
                      ID: {31d09ba0-12f5-4cce-be8a-2923e76605da} Name: Skype for Business Browser Helper
                      ID: {6bf52a52-394a-11d3-b153-00c04f79faa6} Name: Windows Media Player
                      ID: {8856f961-340a-11d0-a96b-00c04fd705a2} Name: Microsoft Web Browser
                      ID: {88d96a05-f192-11d4-a65f-0040963251e5} Name: XML DOM Document 6.0
                      ID: {959a5673-7971-48e6-af54-58f745ac4abc} Name: TmIEPlugInBHO Class
                      ID: {9b4b91fc-ec4d-4018-9575-96fa5a3c03c5} Name: Trend Micro Password Manager ToolBar
                      ID: {bbacbafd-fa5e-4079-8b33-00eb9f13d4ac} Name: Trend Micro IE Protection
                      ID: {ca8a9780-280d-11cf-a24d-444553540000} Name: Adobe PDF Reader
                      ID: {ccac5586-44d7-4c43-b64a-f042461a97d2} Name: Trend Micro Security Toolbar
                      ID: {d27cdb6e-ae6d-11cf-96b8-444553540000} Name: Shockwave Flash Object
                      ID: {ed8c108e-4349-11d2-91a4-00c04f7969e8} Name: XML HTTP Request
                      ID: {f6d90f16-9c73-11d3-b32e-00c04f990bb4} Name: XML HTTP
                      Homepages
                      HKCU: about:blank
                      Search Engines
                      http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
                      Homepages
                      Homepages
                      HKCU: about:blank
                      Search Engines
                      http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
                      BCURequest:
                      os_language : en-us
                      location: en-us
                      osType: 6.2
                      browser: chrome is_default: 1
                      browser: iexplorer is_default: 0
                      id: {2933bf90-7b36-11d2-b20e-00c04f983e60} name: XML DOM Document
                      id: {31d09ba0-12f5-4cce-be8a-2923e76605da} name: Skype for Business Browser Helper
                      id: {6bf52a52-394a-11d3-b153-00c04f79faa6} name: Windows Media Player
                      id: {8856f961-340a-11d0-a96b-00c04fd705a2} name: Microsoft Web Browser
                      id: {88d96a05-f192-11d4-a65f-0040963251e5} name: XML DOM Document 6.0
                      id: {959a5673-7971-48e6-af54-58f745ac4abc} name: TmIEPlugInBHO Class
                      id: {9b4b91fc-ec4d-4018-9575-96fa5a3c03c5} name: Trend Micro Password Manager ToolBar
                      id: {bbacbafd-fa5e-4079-8b33-00eb9f13d4ac} name: Trend Micro IE Protection
                      id: {ca8a9780-280d-11cf-a24d-444553540000} name: Adobe PDF Reader
                      id: {ccac5586-44d7-4c43-b64a-f042461a97d2} name: Trend Micro Security Toolbar
                      id: {d27cdb6e-ae6d-11cf-96b8-444553540000} name: Shockwave Flash Object
                      id: {ed8c108e-4349-11d2-91a4-00c04f7969e8} name: XML HTTP Request
                      id: {f6d90f16-9c73-11d3-b32e-00c04f990bb4} name: XML HTTP
                      BCUResponse:
                      Browser: chrome provider_modified: 0
                      Browser: iexplorer provider_modified: 0
                      id: {2933bf90-7b36-11d2-b20e-00c04f983e60} intarnal_id: 2191 rating: 5
                      id: {31d09ba0-12f5-4cce-be8a-2923e76605da} intarnal_id: 5000 rating: 5
                      id: {6bf52a52-394a-11d3-b153-00c04f79faa6} intarnal_id: 5300 rating: 5
                      id: {8856f961-340a-11d0-a96b-00c04fd705a2} intarnal_id: 8000 rating: 5
                      id: {88d96a05-f192-11d4-a65f-0040963251e5} intarnal_id: 5200 rating: 5
                      id: {959a5673-7971-48e6-af54-58f745ac4abc} intarnal_id: 8000 rating: 5
                      id: {9b4b91fc-ec4d-4018-9575-96fa5a3c03c5} intarnal_id: 1 rating: 3
                      id: {bbacbafd-fa5e-4079-8b33-00eb9f13d4ac} intarnal_id: 8000 rating: 5
                      id: {ca8a9780-280d-11cf-a24d-444553540000} intarnal_id: 8000 rating: 5
                      id: {ccac5586-44d7-4c43-b64a-f042461a97d2} intarnal_id: 1 rating: 3
                      id: {d27cdb6e-ae6d-11cf-96b8-444553540000} intarnal_id: 2081 rating: 5
                      id: {ed8c108e-4349-11d2-91a4-00c04f7969e8} intarnal_id: 5000 rating: 5
                      id: {f6d90f16-9c73-11d3-b32e-00c04f990bb4} intarnal_id: 5000 rating: 5
                      execute: /remove="<5000>{31d09ba0-12f5-4cce-be8a-2923e76605da}" /resetsettings=""  /user=S-1-5-21-1738210461-3613639603-2110639779-1002
                      Google Chrome
                      \mscories.dll,install"
                         }
                      }
                      07.08.2015 09:58:12 (TID: 9104)
                      ProductVersion: 9.0.0.224
                      Mozilla Firefox Browser
                      07.08.2015 09:58:12 (TID: 9104)
                      Mozilla Firefox Warning: Failed to find install path
                      Mozilla Firefox Warning: Failed to find install path
                      Google Chrome Browser
                      Version: 44.0.2403.130
                      Install Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                      Profile Path: C:\Users\Wendy\AppData\Local\Google\Chrome\User Data\
                      Google Chrome Profiles
                      Name: Default Path: C:\Users\Wendy\AppData\Local\Google\Chrome\User Data\Default
                      Opera Browser
                      Opera Warning: Failed to find install path
                      Opera Warning: Failed to find install path
                      Apple Safari Browser
                      Apple Safari Warning: Failed to access Safari
                      Apple Safari Warning: Failed to access Safari
                      07.08.2015 09:59:07 (TID: 5652)
                      ProductVersion: 9.0.0.224
                      Mozilla Firefox Browser
                      07.08.2015 09:59:07 (TID: 5652)
                      Mozilla Firefox Warning: Failed to find install path
                      Mozilla Firefox Warning: Failed to find install path
                      Google Chrome Browser
                      Version: 44.0.2403.130
                      Install Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                      Profile Path: C:\Users\Wendy\AppData\Local\Google\Chrome\User Data\
                      Google Chrome Profiles
                      Name: Default Path: C:\Users\Wendy\AppData\Local\Google\Chrome\User Data\Default
                      Opera Browser
                      Opera Warning: Failed to find install path
                      Opera Warning: Failed to find install path
                      Apple Safari Browser
                      Apple Safari Warning: Failed to access Safari
                      Apple Safari Warning: Failed to access Safari
                      Remover:
                      RemoveInfoRequest:
                      RemoveInfoResponse: OK
                      internal_id: 1
                      07.08.2015 09:59:35 (TID: 6388)
                      ProductVersion: 9.0.0.224
                      Mozilla Firefox Browser
                      07.08.2015 09:59:35 (TID: 6388)
                      Mozilla Firefox Warning: Failed to find install path
                      Mozilla Firefox Warning: Failed to find install path
                      Google Chrome Browser
                      Version: 44.0.2403.130
                      Install Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                      Profile Path: C:\Users\Wendy\AppData\Local\Google\Chrome\User Data\
                      Google Chrome Profiles
                      Name: Default Path: C:\Users\Wendy\AppData\Local\Google\Chrome\User Data\Default
                      Opera Browser
                      Opera Warning: Failed to find install path
                      Opera Warning: Failed to find install path
                      Apple Safari Browser
                      Apple Safari Warning: Failed to access Safari
                      Apple Safari Warning: Failed to access Safari
                      Remover:
                      RemoveInfoRequest:
                      RemoveInfoResponse: OK
                      internal_id: 5000

                      I deleted the live link you posted about the new site, please dont post any live links like that so we dont get someone else browsing the forums infected

                       

                      Did you do all my other steps for removing this pest from your browsers

                      I did and there was no totalperformance on IE or Chrome . And now this tradeadexchange has started. Have you ever had feeling it is deep somewhere in Chrome? 

                      Ask AI

                      AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

                      Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI