Jump to content

Malicious website blocked


dentech

Recommended Posts

Good Morning

 

It seems like I have the same infection that shahinpb had listed on your forum starting 10 Aug 2015. It is a box with "Malicious Website Blocked" displayed and the IP listed is 8.34.112.228 (226 thru 229). With me it seems to happen constantly with Mazilla Firefox but not Google Chrome. I uninstalled and reinstalled Firefox with the same results. This problem was fixed by MrCharlie by 12 Aug 2015. I am running an older machine with Windows XP. Any help with this would be appreciated.

 

Thank You,   Dennis

 

Link to post
Share on other sites

Hello Dennis and welcome to Malwarebytes,

Please be aware the following P2P/Piracy Warning is a standard opening reply made here at Malwarebytes, we make no accusations but do make you aware of Forum Protocol....

If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

 

Please open Malwarebytes Anti-Malware.

  • On the Settings tab > Detection and Protection sub tab, Detection Options, tick the box "Scan for rootkits".
  • Under Non-Malware Protection sub tab Change PUP and PUM entries to Treat detections as Malware
  • Click on the Scan tab, then click on Scan Now >> . If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • With some infections, you may or may not see this message box.

            'Could not load DDA driver'
  • Click 'Yes' to this message, to allow the driver to load after a restart.
  • Allow the computer to restart. Continue with the rest of these instructions.
  • When the scan is complete, click Apply Actions.
  • Wait for the prompt to restart the computer to appear, then click on Yes.
  • After the restart once you are back at your desktop, open MBAM once more.



To get the log from Malwarebytes do the following:

  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have three options:

      Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
      Text file (*.txt)        - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
      XML file (*.xml)      - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
  • Please use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply…




If Malwarebytes is not installed follow these instructions first:

Download Malwarebytes Anti-Malware to your desktop.

  • Double-click mbam-setup and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
  • Launch Malwarebytes Anti-Malware
  • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish. Follow the instructions above....


Next,
 
Download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
    (Windows 8/10 users will be prompted about Windows SmartScreen protection - click More information and Run.)
  • Make sure Addition.txt and Shortcut.txt are checkmarked under "Optional scans"
  • Press Scan button to run the tool....
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The tool will also make logs named (Addition.txt) and Shortcut.txt Please attach those logs to your reply.

 

Next,

 

Please download RogueKiller and save it to your desktop from the following link: http://www.bleepingcomputer.com/download/roguekiller/

  • Quit all running programs.
  • For Windows XP, double-click to start.
  • For Vista,Windows 7/8/8.1/10, Right-click on the program and select Run as Administrator to start and when prompted allow it to run.
  • Read and accept the EULA (End User Licene Agreement)
  • Click Scan to scan the system.
  • When the scan completes select "Report",in the next window select "Export txt" the log will open as a text file post that log... Also save to your Desktop for reference. log will open.
  • Close the program > Don't Fix anything!

 

Let me see those logs...

 

Kevin.
 

Link to post
Share on other sites

Thanks for those logs, continue as follows:

 

Double-click RogueKiller.exe to run again. (Vista/7/8/10 right-click and select Run as Administrator)

When "initializing/pre-scan” completes  press the Scan button, this may take a few minutes to complete.

When the scan completes open the Registry tab and locate the following detections:

[PUP] HKEY_USERS\S-1-5-21-1801674531-790525478-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks | {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} :  (C:\Program Files\Yahoo!\Companion\Installs\cpn13\yt.dll)  -> Found
[PUP|VT.Unwanted-Program ( 004a9cf91 )] HKEY_USERS\S-1-5-21-1801674531-790525478-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run | K9-AM : "C:\Program Files\K9-PCFixer\k9schedule.exe" /verysilent [7][x] -> Found
[Hidden.From.SCM] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\uufdcjs (System32\drivers\ShortcutWithArgument: C:\Documents and Settings\dennis pengelly.DENTECH-CXSLVNS\Application Data\Real\RealPlayer\History\RealPlayer Cloud just launched.lnk -> C:\Program Files\real\realplayer\realplay.exe (RealNetworks, Inc.) ->  hxxp://www.real.com/ <==== ATTENTION
ShortcutWithArgument: C:\Documents and Settings\dennis pengelly.DENTECH-CXSLVNS\Application Data\Real\RealPlayer\History\RealPlayer Daily Videos.lnk -> C:\Program Files\real\realplayer\realplay.exe (RealNetworks, Inc.) ->  hxxp://videos.real.com/rp/web_videos?cd=home&CB=client&firstrun=1&PT=FREE&OS=WinNT%205.1.2600&LP=en%2DUS&OC=R81ENDF&PV=16.0.3.51&PBR=10485800&LI=en&PN=RealPlayer&DC=R81ENDF&DT=010714&u=bd9b0e23e99d4977a5e0148faa380a61#channel/BestOfWeb <==== ATTENTION) -> Found

Make sure those entries are Checkmarked (ticked) also ensure that all other entries are not Checkmarked.

Open the FilesTab and locate the following detections:

[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2115168$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2229593$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2296011$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2345886$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2347290$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2378111_WM9$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2387149$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2393802$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2412687$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2419632$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2423089$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2443105$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2447961_WM9L$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2467659$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2476490$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2476687$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2478960$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2478971$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2479628$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2479943$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2481109$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2483185$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2485376$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2485663$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2503658$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2503665$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2506212$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2506223$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2507618$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2507938$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2508272$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2508429$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2509553$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2510581$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2511455$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2524375$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2535512$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2536276$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2536276-v2$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2541763$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2544893$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2544893-v2$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2555917$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2562937$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2564958$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2566454$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2567053$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2567680$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2570222$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2570791$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2570947$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2584146$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2585542$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2592799$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2598479$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2603381$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2607712$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2616676$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2618451$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2619339$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2620712$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2621440$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2624667$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2631813$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2633171$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2633952$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2639417$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2641653$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2641690$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2646524$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2647518$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2653956$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2655992$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2659262$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2660465$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2661254-v2$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2661637$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2676562$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2685939$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2686509$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2691442$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2695962$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2698365$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2705219$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2705219-v2$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2707511$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2709162$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2712808$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2718523$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2718704$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2719985$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2723135$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2723135-v2$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2724197$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2727528$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2731847$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2736233$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2749655$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2753842$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2753842-v2$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2756822$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2757638$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2758857$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2761226$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2770660$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2778344$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2779030$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2779562$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2780091$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2799494$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2802968$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2803821-v2_WM9$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2807986$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2808735$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2813170$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2813345$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2820197$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2820917$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2829361$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2834886$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2834904_WM11$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2839229$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2845187$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2847311$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2849470$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2850851$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2850869$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2859537$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2862152$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2862330$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2862335$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2863058$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2864063$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2868038$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2868626$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2876217$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2876315$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2876331$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2892075$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2893294$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2893984$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2898715$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2898785$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2900986$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2904266$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2914368$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2916036$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2922229$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2929961$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2930275$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB2934207$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB822603$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB823182$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB824105$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB826939$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB828035$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB833987$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB835409$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB835732$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB837001$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB839643$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB839645$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB840374$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB840987$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB841356$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB841533$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB841873$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB842773$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB873339$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB873339_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB873376$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB885626$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB885835$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB885835_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB885836$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB885836_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB888302$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB888302_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB890046$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB890046_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB890859$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB890859_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB891781$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB891781_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB893756$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB893756_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB896358$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB896358_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB896423$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB896423_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB896424$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB896424_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB896428$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB896428_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB898461$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB899587$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB899587_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB899591$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB899591_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB900725$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB900725_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB901017$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB901017_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB901214$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB901214_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB902400$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB902400_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB904706$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB904706_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB904942$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB905414$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB905414_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB905495$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB905749$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB905749_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB908519$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB908519_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB908531$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB908531_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB910437$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB910437_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB911280$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB911280_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB911562$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB911562_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB911564$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB911567-OE6SP1-20060316.165634$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB911927$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB911927_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB912919$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB912919_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB913580$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB913580_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB914388$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB914388_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB914389$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB914389_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB914440$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB915865$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB917344$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB917344_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB917422$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB917422_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB917953$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB917953_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB918439-IE6SP1-20060530.145346$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB918899-IE6SP1-20060725.123917$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB919007$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB919007_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB920670$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB920670_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB920683$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB920683_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB920685$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB920685_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB921398$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB921398_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB921883$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB921883_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB922616$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB922616_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB922819$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB922819_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB923191$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB923191_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB923414$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB923414_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB923561$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB924191$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB924191_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB924496$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB924496_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB925486-IE6SP1-20060918.120000$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB946648$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB946648_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB950762$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB950762_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB950974$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB950974_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB951066_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB951376-v2$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB951376-v2_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB951698_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB951748_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB951978$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB952004$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB952069_WM9$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB952287$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB952287_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB952954$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB952954_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB954155_WM9$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB954211_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB954600_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB955069_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB955759$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB956572$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB956802_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB956803_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB956841_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB956844$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB957097_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB958644_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB958687_0$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB959426$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB960803$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB960859$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB968389$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB969059$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB970430$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB971029$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB971657$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB972270$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB973507$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB973540_WM9$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB973815$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB973869$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB973904$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB974112$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB974318$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB974392$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB974571$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB975025$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB975467$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB975558_WM8$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB975560$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB975713$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB977816$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB977914$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB978338$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB978542$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB978695_WM9$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB978706$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB979309$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB979482$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB979687$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB981997$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB982132$ -> Found
[ZeroAccess][Folder] C:\WINDOWS\$NtUninstallKB982665$ -> Found
[PUP][Folder] C:\Program Files\Coupons -> Found
[PUP][Folder] C:\Program Files\DriverToolkit -> Found
[PUP][Folder] C:\Program Files\globalUpdate -> Found
[PUP][Folder] C:\Program Files\K9-PCFixer -> Found
[PUP][Folder] C:\Program Files\TotalSystemCare -> Found

Make sure those entries are Checkmarked (ticked) also ensure that all other entries are not Checkmarked.

Hit the Delete button, when complete select "Report" in the next window select "Export txt" the log will open as a text file post that log... Also save to your Desktop for reference.

 

Next,

 

Read the following link before we continue and run Combofix:

ComboFix usage, Questions, Help? - Look here

Next,

Download Combofix from either of the following links :-

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

http://www.infospyware.net/antimalware/combofix/

  • Ensure that Combofix is saved directly to the Desktop <--- Very important
  • Disable all security programs as they will have a negative effect on Combofix, instructions available here  http://www.bleepingcomputer.com/forums/topic114351.html if required. Be aware the list may not have all programs listed, if you need more help please ask.
  • Close any open browsers and any other programs you might have running
  • Double click the combofix.gif icon to run the tool (Vista or Windows 7 users right click and select "Run as Administrator)
  • Instructions for running Combofix available here http://www.bleepingcomputer.com/combofix/how-to-use-combofix if required.
  • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
  • When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" for further review



****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell us when you reply. Read here  http://thespykiller.co.uk/index.php?page=20 why  disabling autoruns is recommended.

*EXTRA NOTES*


  •    
  • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
       
  • If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
       
  • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)



Post those logs in next reply please...

Kevin
 

Link to post
Share on other sites

Thanks for those logs, continue as follows..

 

Download AdwCleaner by Xplode onto your Desktop.

  • Double click on Adwcleaner.exe to run the tool.
  • Click on the Scan in the Actions box
  • Please wait fot the scan to finish..
  • When "Waiting for action.Please uncheck elements you want to keep" shows in top line..
  • Click on the Cleaning box.
  • Next click OK on the "Closing Programs" pop up box.
  • Click OK on the Information box & again OK to allow the necessary reboot
  • After restart the AdwCleaner(C*)-Notepad log will appear, please copy/paste it in your next reply. Where * is the number relative to list of scans completed...

 
Next,
 
thisisujrt.gif Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts. (re-enable when done)
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

Next,

 

dr_web_cureit_zpse80d87bf.jpg
Download Dr Web Cureit from here http://www.freedrweb.com/cureit save to your desktop. (Scroll to bottom of page)

  • The file will be randomly named
  • Reboot to safe mode <<<<<------------ http://support.eset.com/kb2268/
  • Run Dr Web
  • Tick the I agree box and select continue
  • Click select objects for scanning

    drwebselect.JPG
  • Tick all boxes as shown
  • Click the wrench and select automatically apply actions to threats

    drwebfolders.JPG
  • Press start scan
  • The scan will now commence

    drwebscan.JPG
  • Once the scan has finished click open report <<<--- Do not miss this step

    drwebscancomplete.JPG
  • A notepad will open
  • Select File > Save as..
  • Save it to your desktop



This log will be excessive,  Please attach it to your next reply…
 

Let me see those logs, also give an update on any remaining issues or concerns....

 

Thank you,

 

Kevin....

Link to post
Share on other sites

Hello again Kevin

 

I just tried the Firefox Browser for the first time since we started. Malwarebytest is still constantly flagging  "Malicious Website Blocked" messages rendering the browser useless (I am using Chrome to comunicate with you and it doesn't have this affliction). I have attached the FRST scans.

 

Dennis

FRST.txt

Addition.txt

Link to post
Share on other sites

Can you post the most recent Protection log from Malwarebytes, it will show the blocked website, also if inbound or outbound etc...

 

Open Malwarebytes, select > History > Application Logs > Double click on the most recent "Protection Log" then select "Export" > Text file (*.txt)  Name the file and save to your Desktop or somewhere familiar to you. Attach to next reply...

 

Also do you still use "Charter Security Suite"

 

Also do you use "RealPlayer"

 

Thank you,

 

Kevin...

Link to post
Share on other sites

Thanks for the update, can you uninstall Charter Security Suite and Real Player (Is listed as Real) After that is done re-boot, Scan with FRST again as you just did and post both logs...

 

So I need to see, Protection Log from MB and both logs from FRST, also an update on Firefox please....

 

I`m in the UK so I believe 7pm EST is about Midnight for me, i`ll still be up....

Link to post
Share on other sites

Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.
NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

Run FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply.

 

Next,

 

51a612a8b27e2-Zoek.pngScan with ZOEK

Please download ZOEK by Smeenk from here: http://hijackthis.nl/smeenk/ and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here or here

  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:



services_list;standardsearch;autoclean;emptyclsid;emptyfolderscheck;deletefirefoxlook;FFdefaults;


  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)



Please include its content in your next reply. Don't forget to re-enable security software!

 

Post those logs, also let me know if the issue is still active...

 

Thanks,

 

Kevin

Fixlist.txt

Link to post
Share on other sites

I get a repetitive pop up window reading;

Malwarebytes anti-malware

Malicious website blocked

Domain: su2.ff.avast.com

ip: 92.242.140.21

Port: 55878 (This number changes)

Type: Outbound

Process: C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

 

What is it and how do I stop it?  hxxp://goo.gl/Z7yG70  |  hxxp://goo.gl/8aE6LK

Link to post
Share on other sites

YES...... :)  :)  :)  :)  :)  :) 

 

These steps seemed to fix my problems with Firefox. Thank you Very much!

 

I have attached the results from the scans / procedures.

 

I do have one more issue with Chrome but I'm not sure if this is the proper Forum for it, It keeps Initializing with Yahoo (there are no extensions listed) and I just want it to start with the Google search engine.

 

Thank you, Dennis (by the way, my grandfather came from Cornwall)..... :D

Fixlog.txt

zoek-results.txt

Link to post
Share on other sites

Hiya Dennis,

 

Yes I know Corwall, been a couple of times; it`s opposite end of the country to me.... thanks for the logs and Info...

 

Run Zoek again as follows:

 

  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:



createsrpoint;autoclean;emptyalltemp;chromelook;CHRdefaults;


  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)



Please include its content in your next reply. Don't forget to re-enable security software!

 

Let me know if that clears the Chrome issue...

 

Thank you,

 

Kevin...
 

Link to post
Share on other sites

Good afternoon Kevin

 

I have run Zoek and attached the scan results. My issue with Google Chrome is still there. This is not a big issue because my mail is at Yahoo/Att (@prodigy.net). I just don't like things happenning which I haven't initiated (and I like like the Google search engine as the home page). Again, thank you with all your help to clean up my issues. I know my computer and operating system is old but I am trying to keep it going.

zoek-results.txt

Link to post
Share on other sites

Have a look at the following link for instructions to set Google Chrome Home and Startup Pages, might help?

 

https://support.google.com/chrome/answer/95314?hl=en-GB

 

Next,

 

Download "Delfix by Xplode" and save it to your desktop.

Or use the following if first link is down:

"Delfix link mirror"

Double Click to start the program. If you are using Vista or higher, please right-click and choose run as administrator

Make Sure the following items are checked:



  •    
  • Remove disinfection tools
       
  • Purge System Restore <--- this will remove all previous and possibly exploited restore points, a new point relative to system status at present will be created.
       
  • Reset system settings



Now click on "Run" and wait patiently until the tool has completed.

The tool will create a log when it has completed. We don't need you to post this.

Any remnant files/logs from tools we have used can be deleted…

 

Next,

 

Read the following links to fully understand PC Security and Best Practices, you may find them useful....

Answers to Common Security Questions and best Practices

Do I need a Registry Cleaner?

Take care and surf safe

Kevin...  busy.gif
 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.