Jump to content

Marcin_

Members
  • Posts

    17
  • Joined

  • Last visited

Everything posted by Marcin_

  1. Hi, Ron. The update's working. I removed the exclusion and there are no notifications and the access to Toya web is not being blocked. Thank you very much!
  2. Hello, Ron. Sorry for a late response, but there was a horror in my job during last two weeks. Date & time are correct. Please, be aware that I live in UTC+01:00 time zone. ;) Today before I used KVRT few events happened during standard everyday scannings by F-Secure and MB. Nexo (old HR & payroll software) installer and an old Gimp installer have been treated by F-Secure as threat and removed. Few seconds later the similar procedure was done by MB. Moreover I found out that F-secure blocked one uknown website many times at the beginning of the month. I don't know if it has anything to do with my notification problem but I decided to inform you. Please, find the screens below. After that I used KVRT and the result is: no threat found. By the way, during scanning the computer by Kaspersky tool I saw any "Opera\stable" files but I couldn't to see the whole path. Maybe they are still somwewhere on my computer but I have no clue where to find them. Maybe it was visible in the FRST logs or maybe the remnants of Opera are still in the system. But I removed the browser properly I guess. MB notifications due to Toya website still appear but not often and of course the web is still being blocked by MB. Maybe I should just exclude the website from scanning and blocking and problem will be resolved. What you think?.. Anyway I will have to do that in this weekend, because I need to pay my bill. I get the bills for internet to my account on toya.net.pl (sorry, I'm not going to pay the interest for late payment). Best regards.
  3. Hello, Ron. I refreshed FF and there's no efect. Still notifications appear (maybe less frequently) and Toya website is being blocked by MB or the screen appears with words like: safe connection unsuccessful. SSL received the record that exceeds maximum allowed length (whatever it means). The error code is: SSL_ERROR_RX_RECORD_TOO_LONG (see the attachment below, please).
  4. Mozilla Firefox Quantum 65.0.2 (64bit) - that's the browser, I'm using now. The problem was, when I used Opera before I unistalled it, and the same problem is now, when I use Fire Fox.
  5. Maybe indeed it is bound with Java and json files. I just looked on the report...
  6. Nope. I don't use Adobe cloud service. But I guess there are miscellaneous ways of getting any virus or other unwelcome code.
  7. Hello, 3rone. Imho I don't think it's the Toya Co.'s fault (old DLS or something like that). The notifications appear even if I don't surf to toya.net.pl website. So it looks like any process tries to direct the browser to the website (or to malicious fake web pretending Toya website).
  8. Hello, Ron. As you know, I had used Opera browser till I removed it. Now I'm using FF Quantum 65.0.2 (64bit). The notifications appear only when a browser is open. The earliest alerts appear not before I open a browser. And apparently It doesn't matter whether I use FF or Opera. Maybe MB is infected (it would sound as one in the eye for MB Labs). Or maybe just to make an exclusion for this "wpad.toya.net.pl"?.. On the other hand I wouldn't get a trojan nor other *****. I attached the last alert log, as you asked. Please, find the file below. report 03-15-2019 21_08.txt
  9. I ran the fixlist, rebooted, added ad blocking and scanned. Here are the logs below. Do I have still any malicious adware or something more serious in the system?.. Addition.txt Fixlog.txt FRST.txt
  10. Now I'm bombarded with a bunch of notifications again. Even during loggin into the forum. Ok, gonna download the foxlist, run it and I'll send the logs. And Ad blocker of course and will see.
  11. Hello, Ron. Yesterday evening when FF was opened one notification popped up, despite I didn't go to any suspicious web. I hope it was caused by something within Opera remnants . I ran the new fixlist today, rebooted and scanned the system with FRST. Please, find the files attached below. Addition.txt Fixlog.txt FRST.txt
  12. Hi, Ron. Opera has been definitely removed. I rebooted the system and decided to install FF. So far there are no notifications from MB. You can find the files attached below after the scanning system by FRST tool. Do I need to use the fixlist you sent me? FRST.txt Addition.txt
  13. Hello, again. I resetted my browsers, rebooted machine and still have the same problem.
  14. Thanks a lot, Ron, for a quick response. Following your advise I downloaded fixlist and ran FRST tool to fixing. Please, find the attachment below. Unfortunately the problem seems to exist so far. I still get the notifications such as one attached here nad the web toya.net.pl is beeing blocked by MB. Maybe I should have run RFST as administrator?.. Fixlog.txt
  15. Hello. I'm just a layman in programming and whole this knowledge, so forgive me if I did something wrong or omitted any detail in describing my problem. I'll try to describe it as much precisely as I can. Two days ago MB started bombarding me with notifications like this: The problem is the notification window started to pop up very often, sometimes every 2 mins. Moreover, it seems unlikely that domain wpad.toya.net.pl would be infected with trojans (it's the tv & internet provider's website domain). All these connections concern different ports, but all the port numbers start from 49 (49704, 49728, etc.). As a result it occured to me that my computer must be infected. At the beginning I checked my task scheduler but I didn't find any suspicious task. Then I used rkill tool which found no threats, just terminated one process (see the attachment, please) and scanned the system with MB but the software found nothing. Even I used ADWCleaner and Hitman Pro with the same result. So I decided to ask you for a help. I ran FRST tool and you can find all the logs below. I hope my information will be helpful, if you have more questions, please let me know. P.S. Unfortunately all my uploads failed (I don't know why) so I had to insert the logs here: Addition.txt AdwCleaner[S02].txt FRST.txt HitmanPro_20190310_1705.log malwarebyteslog.txt MLBT report.txt Rkill.txt
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.