Jump to content

Search the Community

Showing results for tags 'tradeadexchange'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


Forums

  • Announcements
    • Malwarebytes News
    • Beta Testing Program
  • Malware Removal Help
    • Windows Malware Removal Help & Support
    • Mac Malware Removal Help & Support
    • Mobile Malware Removal Help & Support
    • Malware Removal Self-Help Guides
  • Malwarebytes for Home Support
    • Malwarebytes for Windows Support Forum
    • Malwarebytes for Mac Support Forum
    • Malwarebytes for Android Support Forum
    • Malwarebytes for iOS Support
    • Malwarebytes Privacy
    • Malwarebytes Browser Guard
    • False Positives
    • Comments and Suggestions
  • Malwarebytes for Business Support
    • Malwarebytes Endpoint Protection
    • Malwarebytes Incident Response (includes Breach Remediation)
    • Malwarebytes Endpoint Security
    • Malwarebytes Business Products Comments and Suggestions
  • Malwarebytes Tools and Other Products
    • Malwarebytes AdwCleaner
    • Malwarebytes Junkware Removal Tool Support
    • Malwarebytes Anti-Rootkit BETA Support
    • Malwarebytes Techbench USB (Legacy)
    • Malwarebytes Secure Backup discontinued
    • Other Tools
    • Malwarebytes Tools Comments and Suggestions
  • General Computer Help and Security Updates
    • BSOD, Crashes, Kernel Debugging
    • General Windows PC Help
  • Research Center
    • Newest Rogue-Ransomware Threats
    • Newest Malware Threats
    • Newest Mobile Threats
    • Newest IP or URL Threats
    • Newest Mac Threats
    • Report Scam Phone Numbers
  • General
    • General Chat
    • Forums Announcements & Feedback

Find results in...

Find results that contain...


Date Created

  • Start

    End


Last Updated

  • Start

    End


Filter by number of...

Joined

  • Start

    End


Group


AIM


MSN


Website URL


ICQ


Yahoo


Jabber


Location


Interests

Found 5 results

  1. Hi, My computer seems to be infected with something which causes new tabs to open when on clicking somewhere in my browser. This will open a website tradeadexhange which transfers the tab to different websites. I cant get it off my computer using my antivirus or the free malwarebytes. Could you help me? These posts also have problems with tradeadexchange: https://forums.malwarebytes.org/index.php?/topic/171981-tradeadexchage-infection/ https://forums.malwarebytes.org/index.php?/topic/171668-tradeadexchange-infection/ I ran a scan with farbar and will attach the frst and addition results files. Thanks in advance! Timo Addition.txt FRST.txt
  2. Hello, I need help at removing tradeadexchange.com redirection. It seems to be blocked in google chrome and opera (extensions privacy badger, ublock origin), but affects other browsers like steam and arc browser. I click on a link and it tries to redirect to tradeadexchange.com. Happens not every time. Usually two times, then it stops for a time. Malwarebytes can't find anything. I manipulated my hosts file for this domain to 127.0.0.1 . Seems to work because in steam browser it says that it cannot connect. Windows 10 Pro (x64)Malwarebytes no resultstradeadexchangeadded rule in hosts file for tradeadexchange.com with kind regards Sebastian
  3. Hello. I have seen this post. https://forums.malwarebytes.org/index.php?/topic/171668-tradeadexchange-infection/ I have same problems. So I downloaded and ran the zoek.exe as requested. I need your help. **************************************************************************************************************** Zoek.exe v5.0.0.0 Updated 04-May-2015Tool run by 재원 on 2015-08-24 at 20:13:00.69.Microsoft Windows 8.1 K 6.3.9600 x64Running in: Normal Mode Internet Access DetectedLaunched: C:\Users\재원\Downloads\zoek.exe [scan all users] [script inserted] ==== System Restore Info ====================== 2015-08-24 오후 8:15:12 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\Users\재원\AppData\Local\EmieBrowserModeList deleted successfullyC:\Users\재원\AppData\Local\EmieSiteList deleted successfullyC:\Users\재원\AppData\Local\EmieUserList deleted successfullyC:\Users\재원\AppData\Local\PackageStaging deleted successfullyC:\Users\재원\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Batch Command(s) Run By Tool====================== Windows IP 구성 DNS 확인자 캐시를 플러시했습니다. ==== Deleting Files \ Folders ====================== C:\Users\Public\Pokki deletedC:\install.exe deletedC:\Users\재원\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Start Menu.lnk deletedC:\Users\재원\AppData\Roaming\ProductData deletedC:\Users\재원\AppData\Roaming\GetRightToGo deletedC:\PROGRA~3\ProductData deletedC:\PROGRA~3\Package Cache deletedC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deletedC:\windows\wininit.ini deletedC:\windows\tasks\Nok Nok LabsMFACUpdaterTaskMachineCore.job deletedC:\windows\tasks\Nok Nok LabsMFACUpdaterTaskMachineUA.job deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]"FIDOaddon@noknok.com"="C:\Program Files\Nok Nok Labs\Multifactor Authentication Client\bin\firefox\x86\FIDOaddon" [2015-04-24 오후 12:42][HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]"online_banking_08806E753BE44495B44E90AA2513BDC5@kaspersky.com"="C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\online_banking@kaspersky.com" [2015-08-24 오후 03:32] ==== Chromium Look ====================== Google Chrome Version: 44.0.2403.157 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensionsdbhjdbfgekjfcfkkfjjmlmojhbllhbho - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho[]hdokiejnpimakedhajhdlcegeplioahd - No path found[]mbgbpjganndfjjmlamggkkkjafblbahl - C:\Program Files\Nok Nok Labs\Multifactor Authentication Client\bin\Chrome\x86\FidoExtension.crx[2014-10-17 오전 05:25] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensionslmjegmlicamnimmfhcmpkclmigmmcbeh - No path found[] LastPass - 재원\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahdChrome Hotword Shared Module - 재원\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkgLastPass - 재원\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahdChrome Hotword Shared Module - 재원\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg ==== Chromium Startpages ====================== C:\Users\재원\AppData\Local\Google\Chrome\User Data\Default\Preferences5226EA226E759AD0929BF2942EBADA97E68CEAC721B5","gfdkimpbcpahaombhbimeihdjnejgicl":"C6CD754C048CC1DE48F1578D19546741D74111D8E1A843F70EC1820DB8C8F587","hdokiejnpimakedhajhdlcegeplioahd":"D9EFFC49C7A20F35439B57131B8362DD6ADD98041ADE7FF8FB7BE9E82FD524FA","kmendfapggjehodndflmmgagdbamhnfd":"4F52BECD1CC34DB19C89A2F6031DB225E9ED34FE74D74744E840F8672B4BCF14","knebimhcckndhiglamoabbnifdkijidd":"AD6CF552FE5C613C0CF443589246BFABD2FA2DC83181E837C28B8E542B3BEC8C","lccekmodgklaepjeofjdjpbminllajkg":"E57995E2B82F6B6AE17DD42B1F1F74BEAB3F80579953A67BCE4EBC9F09630820","lmjegmlicamnimmfhcmpkclmigmmcbeh":"3B2BF064409E8A717B6F02477E2B430683F4009AB4DE13E3D29E5EFA7E92F16D","mbgbpjganndfjjmlamggkkkjafblbahl":"23572159D5A4C04BB4F00D86A84EC1EF36B513565A451CD67E82D4994BB1B075","mfehgcgbbipciphmccgaenjidiccnmng":"1F473BF0452B0C1E06CDEED76B32C63660A94A53878E7703FAD9BC3B0A6C53CA","mfffpogegjflfpflabcdkioaeobkgjik":"401D980983E3B50656DF5D23355AC760C6969C48ECAA9E0032933014277FAFBE","mgndgikekgjfcpckkfioiadnlibdjbkf":"696C963629DD7374AF174A23B32652F4F35486E7EE06BF36DB6CDEBD643A4E67","mhjfbmdgcfjbbpaeojofohoefgiehjai":"70D2338C95084797007022623365467314870B1E2F19CAA0907800BA343B7A39","nbpagnldghgfoolbancepceaanlmhfmd":"7D14FE694D2BC0B02590F601697F179FC70F0E0A92476B98AB9AC5D6F5547E61","neajdppkdcdipfabeoofebfddakdcjhd":"5A63F2F62C36DEFAC05736000342AD3E202FC2C86BFDB1EA16B75B4F108E0DFF","nkeimhogjdpnpccoofpliimaahmaaome":"8EBA455B2FD409A81A52DB9B0839E8E0683DCC2461BA8D0F6C15E7F6CF6703F1","nmmhkkegccagdldgiimedpiccmgmieda":"C4C9A157D294A2A905DEFB9CD497F942A14CBBAB1FECDA8C10BF58EAE6967813","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"592949D6C7098DE5A02D10EE4CA2F70E5643BDFD0BF4C2777932E7F71D117911","pjkljhegncpnkpknbcohdijeoejaedia":"BA7A905EEED5F5916CC8BE5FB5A8B954BA0B45F3E1D70AC0AB31C192B1046761"}},"google":{"services":{"account_id":"01A4DDA4853EB89C4D059D1FFDD178F6A783B7575DACCA505A163FBA62D98D89","last_username":"14BA23A3B1A848C69A7E540FD75F8103B7F464D34AEFD6DB1CCEBA6AD85081E5","username":"A7F96F563A60C7A0AB61061FC51704A2D4F3CB328B0BD26E71E93D10F61454E9"}},"homepage":"86F99BB17833A2C3627232C56BC7C81155A9336B5F3C45B0FF857D62643FD79F","homepage_is_newtabpage":"5868B75AFB5F5B5D3B5081029A57578F99A49DB4432868D4A1799A302CDD1D3F","pinned_tabs":"748EB777BC5A8079580D4B85A63BAACAD9F4CDED43C818699E4F083906B48B80","prefs":{"preference_reset_time":"C7EAD987A75067469128F49BED42FAEE128AEB7D71A99DAAAC64813463D8D8A3"},"profile":{"reset_prompt_memento":"E94EA1906FEC16E40355B9E31D91D4DAD172C2CFD4A586DDEE841DD16DC54929"},"safebrowsing":{"incidents_sent":"448E35D8B9F5FD7E96BE7A361ADBBA3C993FC59FBE94EB56B068BBA7C3D52AD0"},"search_provider_overrides":"E7D9963C09DAD2DEC93BC97492347295FBF5855F5CF418EE67797D3FA930B5AB","session":{"restore_on_startup":"65CC5C5482FA2EBB1D0926CA3C0CD4827A01C4D2EEE6E7F0FA3C44D702E6294A","startup_urls":"163EC4FF92DC85D78CCBD0C149698B26E396342ACF30A64D53C0C72D0CBE931E"},"software_reporter":{"prompt_reason":"24049FD10992BA5E8FA8B310E74D8BC4AFF88A614C16268782E7ACA28D8CF40B","prompt_seed":"DD12BF4B9B0B58428C23487829C5BF17A8BE7BF8952F2A2099F86BFB26A63EAF","prompt_version":"305A78995838A142504B088A37CC74F4CD39620DB6282F87D1E0D41AF4DE7F19"},"sync":{"remaining_rollback_tries":"5D7744DDE8C0D205292EE58282F28317D710965F9E2975E2D2E0A438F829854E"}},"super_mac":"6E1307BA09FBAB5407EC8F1C02D93865F49C43ADE4E4BA1EBC430B73726304F4"},"session":{"restore_on_startup":4,"startup_urls":["http://www.google.com/]},"sync":{"remaining_rollback_tries":0}} C:\Users\재원\AppData\Local\Google\Chrome\User Data\Default\Preferences5226EA226E759AD0929BF2942EBADA97E68CEAC721B5","gfdkimpbcpahaombhbimeihdjnejgicl":"C6CD754C048CC1DE48F1578D19546741D74111D8E1A843F70EC1820DB8C8F587","hdokiejnpimakedhajhdlcegeplioahd":"D9EFFC49C7A20F35439B57131B8362DD6ADD98041ADE7FF8FB7BE9E82FD524FA","kmendfapggjehodndflmmgagdbamhnfd":"4F52BECD1CC34DB19C89A2F6031DB225E9ED34FE74D74744E840F8672B4BCF14","knebimhcckndhiglamoabbnifdkijidd":"AD6CF552FE5C613C0CF443589246BFABD2FA2DC83181E837C28B8E542B3BEC8C","lccekmodgklaepjeofjdjpbminllajkg":"E57995E2B82F6B6AE17DD42B1F1F74BEAB3F80579953A67BCE4EBC9F09630820","lmjegmlicamnimmfhcmpkclmigmmcbeh":"3B2BF064409E8A717B6F02477E2B430683F4009AB4DE13E3D29E5EFA7E92F16D","mbgbpjganndfjjmlamggkkkjafblbahl":"23572159D5A4C04BB4F00D86A84EC1EF36B513565A451CD67E82D4994BB1B075","mfehgcgbbipciphmccgaenjidiccnmng":"1F473BF0452B0C1E06CDEED76B32C63660A94A53878E7703FAD9BC3B0A6C53CA","mfffpogegjflfpflabcdkioaeobkgjik":"401D980983E3B50656DF5D23355AC760C6969C48ECAA9E0032933014277FAFBE","mgndgikekgjfcpckkfioiadnlibdjbkf":"696C963629DD7374AF174A23B32652F4F35486E7EE06BF36DB6CDEBD643A4E67","mhjfbmdgcfjbbpaeojofohoefgiehjai":"70D2338C95084797007022623365467314870B1E2F19CAA0907800BA343B7A39","nbpagnldghgfoolbancepceaanlmhfmd":"7D14FE694D2BC0B02590F601697F179FC70F0E0A92476B98AB9AC5D6F5547E61","neajdppkdcdipfabeoofebfddakdcjhd":"5A63F2F62C36DEFAC05736000342AD3E202FC2C86BFDB1EA16B75B4F108E0DFF","nkeimhogjdpnpccoofpliimaahmaaome":"8EBA455B2FD409A81A52DB9B0839E8E0683DCC2461BA8D0F6C15E7F6CF6703F1","nmmhkkegccagdldgiimedpiccmgmieda":"C4C9A157D294A2A905DEFB9CD497F942A14CBBAB1FECDA8C10BF58EAE6967813","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"592949D6C7098DE5A02D10EE4CA2F70E5643BDFD0BF4C2777932E7F71D117911","pjkljhegncpnkpknbcohdijeoejaedia":"BA7A905EEED5F5916CC8BE5FB5A8B954BA0B45F3E1D70AC0AB31C192B1046761"}},"google":{"services":{"account_id":"01A4DDA4853EB89C4D059D1FFDD178F6A783B7575DACCA505A163FBA62D98D89","last_username":"14BA23A3B1A848C69A7E540FD75F8103B7F464D34AEFD6DB1CCEBA6AD85081E5","username":"A7F96F563A60C7A0AB61061FC51704A2D4F3CB328B0BD26E71E93D10F61454E9"}},"homepage":"86F99BB17833A2C3627232C56BC7C81155A9336B5F3C45B0FF857D62643FD79F","homepage_is_newtabpage":"5868B75AFB5F5B5D3B5081029A57578F99A49DB4432868D4A1799A302CDD1D3F","pinned_tabs":"748EB777BC5A8079580D4B85A63BAACAD9F4CDED43C818699E4F083906B48B80","prefs":{"preference_reset_time":"C7EAD987A75067469128F49BED42FAEE128AEB7D71A99DAAAC64813463D8D8A3"},"profile":{"reset_prompt_memento":"E94EA1906FEC16E40355B9E31D91D4DAD172C2CFD4A586DDEE841DD16DC54929"},"safebrowsing":{"incidents_sent":"448E35D8B9F5FD7E96BE7A361ADBBA3C993FC59FBE94EB56B068BBA7C3D52AD0"},"search_provider_overrides":"E7D9963C09DAD2DEC93BC97492347295FBF5855F5CF418EE67797D3FA930B5AB","session":{"restore_on_startup":"65CC5C5482FA2EBB1D0926CA3C0CD4827A01C4D2EEE6E7F0FA3C44D702E6294A","startup_urls":"163EC4FF92DC85D78CCBD0C149698B26E396342ACF30A64D53C0C72D0CBE931E"},"software_reporter":{"prompt_reason":"24049FD10992BA5E8FA8B310E74D8BC4AFF88A614C16268782E7ACA28D8CF40B","prompt_seed":"DD12BF4B9B0B58428C23487829C5BF17A8BE7BF8952F2A2099F86BFB26A63EAF","prompt_version":"305A78995838A142504B088A37CC74F4CD39620DB6282F87D1E0D41AF4DE7F19"},"sync":{"remaining_rollback_tries":"5D7744DDE8C0D205292EE58282F28317D710965F9E2975E2D2E0A438F829854E"}},"super_mac":"6E1307BA09FBAB5407EC8F1C02D93865F49C43ADE4E4BA1EBC430B73726304F4"},"session":{"restore_on_startup":4,"startup_urls":["http://www.google.com/]},"sync":{"remaining_rollback_tries":0}} ==== Chromium Fix ====================== C:\Users\재원\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.nid.naver.com_0.localstorage deleted successfullyC:\Users\재원\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.nid.naver.com_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values:[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]"Start Page"="http://www.naver.com/"[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]"DefaultScope"="{0E4AC09B-5BBD-49F2-BFCD-BD1BEFBAA0AE}" New Values:[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]"Start Page"="http://www.naver.com/"[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"{0E4AC09B-5BBD-49F2-BFCD-BD1BEFBAA0AE} Unknown Url="Not_Found" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-593337814-833741486-1504065185-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0E4AC09B-5BBD-49F2-BFCD-BD1BEFBAA0AE} deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0E4AC09B-5BBD-49F2-BFCD-BD1BEFBAA0AE} deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E4AC09B-5BBD-49F2-BFCD-BD1BEFBAA0AE} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Policies\Chromium deleted successfully ==== Empty IE Cache ====================== C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfullyC:\Users\재원\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\Users\재원\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfullyC:\Users\재원\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\Users\재원\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfullyC:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\Users\재원\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\Users\재원\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfullyC:\Users\재원\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\Users\재원\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfullyC:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\재원\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfullyC:\Users\재원\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=58 folders=40 103260071 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfullyC:\Users\Default User\AppData\Local\Temp emptied successfullyC:\Users\재원\AppData\Local\Temp will be emptied at rebootC:\Users\재원\AppData\Local\Temp will be emptied at rebootC:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfullyC:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfullyC:\windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\windows\Temp successfully emptiedC:\Users\재원\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on 2015-08-24 at 20:30:09.97 ====================== ****************************************************************************************************************
  4. I saw the other posts about tradeadexchange infection but could not make a fix myself, so here I am. I runned farbar and zoek. The logs are attached here. Thank you for the help. zoek-results.txt Addition.txt FRST.txt
  5. Hello everyone, I have become infected with a chrome "thing" that will open a new tab with www.tradeadexchange.com, then quickly move on to some other ad type of webpage. This will always happen on a click somewhere on the browser page. It could be an actual link (which does not open the link asked for) or simply a click on the page (to make that window active, for example). I actually tried to change the hosts file to send this to 127.0.0.1, but while this worked for an earlier instance of this problem, but a different starting URL, this hasn't stopped the problem and the page opens and redirects. Here are the two issues I've been trying to deal with in hosts: 127.0.0.1 totaladperformance.com127.0.0.1 www.totaladperformance.com 127.0.0.1 www.tradeadexchange.com/127.0.0.1 tradeadexchange.com/ I found a previous posting that dealt with the same tradeadexchange posted by Kicker83 and responded to by Maniac (Borislav) . I followed the first set of instructions from Maniac and downloaded Farbar. BTW: Norton rejected it at first, but I white listed it. I ran the scan and have the following 2 txt files, FRST and Addition. I would very much appreciate any help you can give me as this has now spread to my laptop from my PC. I can only guess it is sharing info via my google account?? Thanks in advance, Brian Cacchiotti Addition.txt FRST.txt
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.