Jump to content


  • Posts

  • Joined

  • Last visited


0 Neutral

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. Hi kevinf80, The problem has apparently been solved by eliminating the spybot anti-beacon task. It had been generating the C:\windows\hosts file. Malwarebytes generated a clean scan immediately thereafter and again following reboot. Thank you very much for your time and patience.
  2. The first time through I received no file on the desktop. The 2nd time I got two files rkill.exe and rkill64.exe. I ran rkill64.exe as administrator. The resulting black box is still on screen. No boxes to choose from. I searched for rkill.txt, which was supposed to have been created, with Windows Explorer. Nothing was found. Your thoughts? I will get back to this at a later time.
  3. Is RKill short for RougeKiller? I didn't see the black box. There were 4 green boxes; not 3 and I got a popup offering version I'm just trying to make sure this is correct. There have been a lot of downloads in the pass weeks.
  4. Hi. This is win7, 64 bit. Neither Firefox nor Opera is able to reach find the server at jpshortstuff.247fixes.com.
  5. Hi, The file is back. It has no file type. It looks like I have to rename it and give it a file type. .docx apparently didn't work. Do you have any suggestions?
  6. Hi, The second file looks OK when I open it but I must have moved it instead of copying it. If you still can't read it, I will have to reboot and see if it gets recreated because it isn't there now and I haven't been able to restore it. Did you read the posts by redwolfe_98 on this topic? FRST.txt S_S&D.docx
  7. Hi Kevinf80, I also attached a copy of the file which Malwarebytes identifies as the location of Tangent.Agent. I don't know if it will help. My limited understanding of this type of hosts list is to misdirect programs attempting to reach a web location and prevent them access. Addition.txt S_S&D.docx
  8. Hi, As far as I can tell, I am following the instructions in MalwareBytes. Following a scan it asks if it should remove the malware and I allow it to do so. It then wants to reboot to complete the process. Following reboot, if I immediately rescan, it again finds the Trojan.Agent in the previous location. If I am messing up the instructions, I don't recognize where. What am I missing? malwareBytes scan 7-16-2016 0952.txt
  9. Hi, I haven't had time to work on the problem. Malwarebytes still finds Trojan.Agent when it scans and on scans following removal and rescans. I will get back to this over the weekend. Thank you.
  10. Why does MB still find this? Malwarebytes 7-10-2016-1419.txt
  11. That was good to see. Thank you for all your help. Any suggestions about avoiding this or similar problems in the future? I had been visiting used car sites when this started but of course I cannot be sure of the origin.
  12. Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 7/10/2016 Scan Time: 1:00 PM Logfile: Administrator: No Version: Malware Database: v2016.07.10.05 Rootkit Database: v2016.05.27.01 License: Premium Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Enabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Scan Type: Threat Scan Result: Completed Objects Scanned: 238010 Time Elapsed: 2 min, 57 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 1 Trojan.Agent, C:\Windows\hosts, Delete-on-Reboot, [07562af80892d561f96919103dc6a25e], Physical Sectors: 0 (No malicious items detected) (end)
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.