Jump to content

zork824

Members
  • Posts

    6
  • Joined

  • Last visited

Posts posted by zork824

  1. With the premium trial MalwareBytes has picked up something. Firefox tries to connect to tradeadexchange (which I've never seen opening, probably due to my adblocker) multiple times, and now MalwareBytes premium is blocking said connection. However, neither the adware cleaner nor malware bytes could detect the actual virus and it keeps being blocked. I just deleted my cookies and for now it is not being blocked anymore, but in case the issue is still here, what do I have to do? I'm also surprised as I rarely download stuff from the internet, and when I do is from trusted sources, so I have no idea how such virus could get in. I also have a good adblocker so there's no way I randomly clicked on a shady ad.

     

    EDIT Deleting the cookies hasn't worked, Firefox just tried to connect again. I'm adding the FRST scan results.

    FRST.txt

    Addition.txt

  2. 1 hour ago, shadowwar said:

    Please update your mbam and this should no longer be detected. You are at

    Versione: 3.0.6.1469

    when 3.2.2 is the current version.

    You can download the installer from the website to upgrade to the current version

    https://downloads.malwarebytes.com/file/mb3/

    Updated. The premium trial activated itself and I discovered that firefox is trying to connect to a website called tradeadexchange.com. I am scanning now and already tried scanning with ADWCleaner, it did find something but it didn't fix the issue.

  3. The DLLs in questions are called "portcls.sys" and "USBAUDIO.sys". MalwareBytes is flagging them both as Rootkit, however VirusTotal says they are both clean, 0 infection detected from every antivirus (MalwareBytes included). MalwareBytes' Anti Rootkit is also not detecting anything.

    Report.zip

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.