Jump to content

Mao117

Members
  • Posts

    12
  • Joined

  • Last visited

Posts posted by Mao117

  1. Hey Jeff. As aforementioned in my first post, it's Firefox only. I suspect that's only because it's my default browser.

    Also, today, the ad didn't come and everything seems fine. Thought every now and then MalwareBytes says it blocked an outgoing ip address and the program name (the exe it refers to) is avast. Is that related to the ad or is it the updates of avast that are being blocked?

    Anyway, I shall post the results by tomorrow or day after, whenever I am able.

  2. Well, the stupid pop-up is back.

    All scans are clear. MBytes did not pick anything up.

    The ESET online scan only picked up really old stuff I've had, mostly tools to edit windows themes and trainers for games. They're very old and I haven't used them for more than a year.

    ESET:

    C:\Users\Ammaar\Desktop\Others\DriverSweeper_3.2.0.exe    Win32/OpenCandy application
    C:\Users\Ammaar\Desktop\Others\DTLite4453-0297.exe Win32/OpenCandy application
    C:\Users\Ammaar\Desktop\Others\Setup-MsgPlus-510.exe a variant of Win32/MessengerPlus.A application
    C:\Users\Ammaar\Desktop\Others\Setup-MsgPlus-511.exe a variant of Win32/MessengerPlus.A application
    C:\Users\Ammaar\Desktop\Others\SoftonicDownloader_for_open-freely.exe Win32/SoftonicDownloader.D application
    D:\Documents and Settings\Ammaar-117\Application Data\OpenCandy\OpenCandy_B48E56AA55A74842B96A05CCB7C830AA\RegistryReviverSetup.exe a variant of Win32/SlowPCfighter application
    D:\Documents and Settings\Ammaar-117\Local Settings\Temp\OpenCandy\OCSetupHlp.dll Win32/OpenCandy application
    D:\Documents and Settings\Ammaar-117\Local Settings\TempDIR\BetterInstaller.exe a variant of Win32/Somoto.A application
    D:\WINDOWS\CameraFixer.exe probably a variant of Win32/KillProc.A application
    E:\Programs\winamp563_full_emusic-7plus_all.exe Win32/OpenCandy application
    H:\Ammaar's\Downloads\DriverSweeper_2.7.5.exe Win32/OpenCandy application
    H:\Ammaar's\Downloads\DriverSweeper_3.1.0.exe Win32/OpenCandy application
    H:\Ammaar's\Downloads\MsgPlusLive-490.exe a variant of Win32/MessengerPlus application
    H:\Ammaar's\Downloads\Setup-MsgPlus-502.exe a variant of Win32/MessengerPlus.A application
    H:\Ammaar's\Downloads\Setup-MsgPlus-511.exe a variant of Win32/MessengerPlus.A application
    H:\Ammaar's\Downloads\SUPERsetup.exe Win32/OpenCandy application
    H:\Ammaar's\Downloads\VistaGlazzSetup.exe Win32/OpenCandy application

  3. Hi guys

    I've been having this strange pop-up for nearly a week now.

    I'm very security conscious and I have a good idea of how viruses and whatnot work, being a programmer and I have mostly manually removed viruses from my system before. This is probably the second time in nearly 6 years that I've got spyware, but this is the first time no tool has found it.

    So, it started as a single, random pop-up that would open every 15 or so minutes in a new tab in Firefox (my default browser).

    After a few days and its current behaviour, is it opening ONLY ONCE. It only opens when I start Firefox and only opens when the system starts up. But I must manually start Firefox for it to open (thus far). It does not immediately open, but after about 10 or so minutes after Firefox has started.

    It goes to this link: http://aff.ringtonepartner.com/geo/preset/1706/4/?subid=1793

    and this link re-directs very quickly to some "mozzi" URL that contains an IQ-test. It also has logos of my local telecommunication companies at the bottom of the page.

    I have tried numerous programs, including Malware Bytes, SpyBot S&D, Windows Security Essentials, Avast! (my primary AV), SUPERAntiSpyware, but none of them have caught whatever it is that is causing this SEEMINGLY benign thing.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.