  1. Hi, Ron. The update's working. I removed the exclusion and there are no notifications and the access to Toya web is not being blocked. Thank you very much!
  2. Hello, Ron. Sorry for a late response, but there was a horror in my job during last two weeks. Date & time are correct. Please, be aware that I live in UTC+01:00 time zone. ;) Today before I used KVRT few events happened during standard everyday scannings by F-Secure and MB. Nexo (old HR & payroll software) installer and an old Gimp installer have been treated by F-Secure as threat and removed. Few seconds later the similar procedure was done by MB. Moreover I found out that F-secure blocked one uknown website many times at the beginning of the month. I don't know if it
  3. Hello, Ron. I refreshed FF and there's no efect. Still notifications appear (maybe less frequently) and Toya website is being blocked by MB or the screen appears with words like: safe connection unsuccessful. SSL received the record that exceeds maximum allowed length (whatever it means). The error code is: SSL_ERROR_RX_RECORD_TOO_LONG (see the attachment below, please).
  4. Mozilla Firefox Quantum 65.0.2 (64bit) - that's the browser, I'm using now. The problem was, when I used Opera before I unistalled it, and the same problem is now, when I use Fire Fox.
  5. Maybe indeed it is bound with Java and json files. I just looked on the report...
  6. Nope. I don't use Adobe cloud service. But I guess there are miscellaneous ways of getting any virus or other unwelcome code.
  7. Hello, 3rone. Imho I don't think it's the Toya Co.'s fault (old DLS or something like that). The notifications appear even if I don't surf to toya.net.pl website. So it looks like any process tries to direct the browser to the website (or to malicious fake web pretending Toya website).
  8. Hello, Ron. As you know, I had used Opera browser till I removed it. Now I'm using FF Quantum 65.0.2 (64bit). The notifications appear only when a browser is open. The earliest alerts appear not before I open a browser. And apparently It doesn't matter whether I use FF or Opera. Maybe MB is infected (it would sound as one in the eye for MB Labs). Or maybe just to make an exclusion for this "wpad.toya.net.pl"?.. On the other hand I wouldn't get a trojan nor other *****. I attached the last alert log, as you asked. Please, find the file below. report 03-15-2019 21_08.txt
  9. I ran the fixlist, rebooted, added ad blocking and scanned. Here are the logs below. Do I have still any malicious adware or something more serious in the system?.. Addition.txt Fixlog.txt FRST.txt
  10. Now I'm bombarded with a bunch of notifications again. Even during loggin into the forum. Ok, gonna download the foxlist, run it and I'll send the logs. And Ad blocker of course and will see.
  11. Hello, Ron. Yesterday evening when FF was opened one notification popped up, despite I didn't go to any suspicious web. I hope it was caused by something within Opera remnants . I ran the new fixlist today, rebooted and scanned the system with FRST. Please, find the files attached below. Addition.txt Fixlog.txt FRST.txt
  12. Hi, Ron. Opera has been definitely removed. I rebooted the system and decided to install FF. So far there are no notifications from MB. You can find the files attached below after the scanning system by FRST tool. Do I need to use the fixlist you sent me? FRST.txt Addition.txt
  13. Hello, again. I resetted my browsers, rebooted machine and still have the same problem.
