This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE/Firefox open tabs and go to random ad pages

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

sc518,

Please be sure to disable all of your security programs before running this script:

πŸ–ΌClick to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
    FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q="
    FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={5EC2975F-2FCC-96EA-BA7C-3E1A6E11DD3C}&q="
    [2010/03/24 21:15:55 | 000,003,700 | β€”- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.png
    [2010/03/24 21:15:55 | 000,001,963 | β€”- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.xml
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
    O2 - BHO: (no name) - MRI_DISABLED - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
    
    :Commands
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
  • Open OTL again and press "Quick Scan" to produce a fresh log ( don't check the boxes beside LOP Check or Purity this time )
aaaaaah :pullhair:
I ran the first sweep with the code but for whatever reason, no log popped up. Then I opened Firefox really quick to see if FBS was gone and the drop-down search engine was gone, but neither the toolbar, nor the new tab thing were gone. Then after I ran the quick scan of OTL like you said, they all came back! :pullhair:

anyway, here is the OTL log. Hopefully this is actually working :(

OTL logfile created on: 6/13/2010 10:14:18 PM - Run 3
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Tracey Carpenter\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 47.00 Mb Available Physical Memory | 9.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.18 Gb Total Space | 23.27 Gb Free Space | 32.69% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CARPHOME
Current User Name: Tracey Carpenter
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Webroot\Spy Sweeper\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\TrueAssistant\TrueAssistant.exe (Esaya, Inc.)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (WRConsumerService) – C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) – C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (TmProxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (tmxpflt) – C:\WINDOWS\SYSTEM32\DRIVERS\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\SYSTEM32\DRIVERS\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\SYSTEM32\DRIVERS\vsapint.sys (Trend Micro Inc.)
DRV - (SSIDRV) – C:\WINDOWS\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (SSHRMD) – C:\WINDOWS\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (ssfs0bbc) – C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (tmactmon) – C:\WINDOWS\SYSTEM32\DRIVERS\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) – C:\WINDOWS\SYSTEM32\DRIVERS\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmcomm) – C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\SYSTEM32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\SYSTEM32\DRIVERS\PalmUSBD.sys (PalmSource, Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SSKBFD) – C:\WINDOWS\SYSTEM32\DRIVERS\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (Afc) – C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys (Arcsoft, Inc.)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (tfsnudfa) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (netrcacm) – C:\WINDOWS\SYSTEM32\DRIVERS\netrcacm.sys (Thomson Inc.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
IE - HKCU\..\URLSearchHook: {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v;=19&q;="
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://my.msn.com/"
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.7.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.3.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v;=19&tid;={5EC2975F-2FCC-96EA-BA7C-3E1A6E11DD3C}&q;="


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/06 20:33:15 | 000,000,000 | β€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/13 22:01:25 | 000,000,000 | β€”D | M]

[2010/03/24 20:37:33 | 000,000,000 | β€”D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Extensions
[2010/06/13 22:06:03 | 000,000,000 | β€”D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions
[2010/04/27 15:43:27 | 000,000,000 | β€”D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/24 20:56:12 | 000,000,000 | β€”D | M] (AniWeather) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2010/05/02 14:39:08 | 000,000,000 | β€”D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/03/24 20:37:41 | 000,000,000 | β€”D | M] (No name found) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}
[2010/06/06 21:43:31 | 000,000,000 | β€”D | M] (Adblock Plus) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/06 21:43:32 | 000,000,000 | β€”D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\[removed]
[2010/06/13 20:34:28 | 000,000,000 | β€”D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/02 14:38:16 | 000,000,000 | β€”D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/02 14:36:27 | 000,411,368 | β€”- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/06/13 22:13:09 | 000,003,700 | β€”- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.png
[2010/06/13 22:13:08 | 000,001,963 | β€”- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.xml

O1 HOSTS File: ([2010/06/12 22:34:31 | 000,000,027 | β€”- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Ask Search Assistant BHO) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (Ask.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Tracey Carpenter\Start Menu\Programs\Startup\TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe (Esaya, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1237139453218 (MUWebControl Class)
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} http://us-download.mcafee.com/products/protected/mvt/mvt.cab (McAfee Virtual Technician Control Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab (PhotosCtrl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} http://zone.msn.com/bingame/cnma/default/cinematycoon.cab (TikGames Online Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} http://www.trueswitch.com/sbc/TrueInstallSBC.exe (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Security Packages - (ecurity Packages settings…) - File not found
O30 - LSA: Security Packages - (or) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 15:04:08 | 000,000,000 | β€”- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/06/13 20:11:47 | 000,000,000 | β€”D | C] – C:\Documents and Settings\Tracey Carpenter\Desktop\JavaRa
[2010/06/13 14:43:23 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/06/13 14:36:40 | 000,000,000 | β€”D | C] – C:\_OTL
[2010/06/13 12:56:59 | 000,572,416 | β€”- | C] (OldTimer Tools) – C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe
[2010/06/12 22:59:34 | 000,000,000 | β€”D | C] – C:\ComboFix
[2010/06/11 11:03:35 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/06/11 10:42:41 | 000,212,480 | β€”- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/06/11 10:42:41 | 000,161,792 | β€”- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/06/11 10:42:41 | 000,136,704 | β€”- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/06/11 10:42:41 | 000,031,232 | β€”- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/06/11 10:42:06 | 000,000,000 | β€”D | C] – C:\WINDOWS\ERDNT
[2010/06/11 10:32:40 | 000,000,000 | β€”D | C] – C:\Qoobox
[2010/06/08 14:05:20 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/06/08 14:05:05 | 000,000,000 | β€”D | C] – C:\Documents and Settings\Tracey Carpenter\My Documents\My RoboForm Data
[2010/06/08 13:32:46 | 000,000,000 | β€”D | C] – C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\Temp
[2010/06/07 13:04:10 | 000,000,000 | β€”D | C] – C:\WINDOWS\pss
[2010/06/06 21:54:12 | 000,000,000 | β€”D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/06 21:54:08 | 000,000,000 | β€”D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/05 11:21:12 | 000,000,000 | β€”D | C] – C:\Documents and Settings\Tracey Carpenter\Application Data\Malwarebytes
[2010/06/05 11:20:48 | 000,038,224 | β€”- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/05 11:20:43 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/05 11:20:42 | 000,020,952 | β€”- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/05 11:20:39 | 000,000,000 | β€”D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/05 07:54:21 | 000,000,000 | β€”D | C] – C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\gnloyljux
[2010/05/02 14:39:40 | 000,000,000 | β€”D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/03/24 20:57:54 | 000,000,000 | β€”D | C] – C:\Documents and Settings\Tracey Carpenter\My Documents\Downloads
[2010/03/24 20:37:05 | 000,000,000 | β€”D | C] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla
[1980/01/01 02:00:00 | 000,151,552 | β€”- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll

========== Files - Modified Within 90 Days ==========

[2010/06/13 22:09:08 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/13 22:09:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/06/13 22:09:04 | 534,925,312 | -HS- | M] () – C:\hiberfil.sys
[2010/06/13 22:08:15 | 004,980,736 | -H– | M] () – C:\Documents and Settings\Tracey Carpenter\NTUSER.DAT
[2010/06/13 22:08:15 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Tracey Carpenter\NTUSER.INI
[2010/06/13 22:00:46 | 004,855,756 | -H– | M] () – C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\IconCache.db
[2010/06/13 20:52:46 | 000,000,087 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\jagex_runescape_preferences2.dat
[2010/06/13 20:21:15 | 000,000,045 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\jagex_runescape_preferences.dat
[2010/06/13 20:11:17 | 000,071,798 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\JavaRa.zip
[2010/06/13 12:56:49 | 000,572,416 | β€”- | M] (OldTimer Tools) – C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe
[2010/06/12 23:10:44 | 000,000,227 | β€”- | M] () – C:\WINDOWS\system.ini
[2010/06/12 22:41:57 | 003,706,758 | Rβ€” | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\ComboFix.exe
[2010/06/12 22:34:31 | 000,000,027 | β€”- | M] () – C:\WINDOWS\System32\drivers\ETC\HOSTS
[2010/06/12 10:54:06 | 000,001,324 | β€”- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/12 03:38:30 | 000,307,600 | β€”- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 03:21:34 | 000,001,374 | β€”- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/12 03:08:43 | 000,503,304 | β€”- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/12 03:08:43 | 000,442,466 | β€”- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2010/06/12 03:08:43 | 000,071,732 | β€”- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2010/06/11 11:03:44 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2010/06/10 19:30:27 | 000,293,376 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\gmer.exe
[2010/06/09 10:31:55 | 000,002,137 | β€”- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/08 16:25:40 | 000,359,929 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\dds.scr
[2010/06/08 13:59:50 | 000,000,104 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\Internet Explorer.lnk
[2010/06/08 09:01:31 | 000,000,775 | β€”- | M] () – C:\WINDOWS\WIN.INI
[2010/06/08 09:01:31 | 000,000,211 | β€”- | M] () – C:\Boot.bak
[2010/06/06 21:55:53 | 000,001,641 | β€”- | M] () – C:\Documents and Settings\All Users\Desktop\Webroot AntiVirus.lnk
[2010/06/06 21:52:37 | 000,000,164 | β€”- | M] () – C:\WINDOWS\install.dat
[2010/06/05 14:59:07 | 000,000,284 | β€”- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/05 11:20:56 | 000,000,696 | β€”- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/02 19:27:01 | 000,056,578 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\Application Data\wklnhst.dat
[2010/06/01 17:42:41 | 000,035,774 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\P100416_Pete Carpenter_portal-1 (2).jpg
[2010/05/23 13:32:10 | 000,026,112 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\John Muir.doc
[2010/05/09 09:16:51 | 000,019,968 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Friendship.doc
[2010/05/02 14:48:34 | 000,000,000 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\jagex__preferences3.dat
[2010/04/29 15:39:38 | 000,038,224 | β€”- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | β€”- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 15:58:12 | 000,256,512 | β€”- | M] () – C:\WINDOWS\PEV.exe
[2010/04/04 12:40:33 | 000,002,206 | β€”- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/03/29 08:40:32 | 000,332,800 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Employment Application.doc
[2010/03/28 16:37:16 | 000,019,968 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Summer Party.doc
[2010/03/24 21:15:42 | 000,001,602 | β€”- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/03/17 18:52:11 | 000,187,904 | β€”- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Meaghan's Business 3.doc

========== Files Created - No Company Name ==========

[2010/06/13 20:11:17 | 000,071,798 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\JavaRa.zip
[2010/06/12 22:27:45 | 534,925,312 | -HS- | C] () – C:\hiberfil.sys
[2010/06/11 11:03:44 | 000,000,211 | β€”- | C] () – C:\Boot.bak
[2010/06/11 11:03:37 | 000,260,272 | β€”- | C] () – C:\cmldr
[2010/06/11 10:42:41 | 000,256,512 | β€”- | C] () – C:\WINDOWS\PEV.exe
[2010/06/11 10:42:41 | 000,098,816 | β€”- | C] () – C:\WINDOWS\sed.exe
[2010/06/11 10:42:41 | 000,080,412 | β€”- | C] () – C:\WINDOWS\grep.exe
[2010/06/11 10:42:41 | 000,077,312 | β€”- | C] () – C:\WINDOWS\MBR.exe
[2010/06/11 10:42:41 | 000,068,096 | β€”- | C] () – C:\WINDOWS\zip.exe
[2010/06/11 10:31:30 | 003,706,758 | Rβ€” | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\ComboFix.exe
[2010/06/10 19:30:38 | 000,293,376 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\gmer.exe
[2010/06/08 16:25:35 | 000,359,929 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\dds.scr
[2010/06/08 13:59:50 | 000,000,104 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\Internet Explorer.lnk
[2010/06/06 21:55:53 | 000,001,641 | β€”- | C] () – C:\Documents and Settings\All Users\Desktop\Webroot AntiVirus.lnk
[2010/06/05 11:20:56 | 000,000,696 | β€”- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 17:42:41 | 000,035,774 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\P100416_Pete Carpenter_portal-1 (2).jpg
[2010/05/20 17:15:24 | 000,026,112 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\John Muir.doc
[2010/05/09 09:16:51 | 000,019,968 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Friendship.doc
[2010/05/02 14:48:34 | 000,000,000 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\jagex__preferences3.dat
[2010/03/29 06:28:21 | 000,332,800 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Employment Application.doc
[2010/03/28 16:37:15 | 000,019,968 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Summer Party.doc
[2010/03/24 20:36:15 | 000,001,602 | β€”- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/03/17 18:52:09 | 000,187,904 | β€”- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Meaghan's Business 3.doc
[2009/11/06 12:00:28 | 000,031,088 | β€”- | C] () – C:\WINDOWS\System32\wrLZMA.dll
[2008/02/02 17:05:50 | 000,000,074 | β€”- | C] () – C:\WINDOWS\TaxACT07.ini
[2007/03/13 19:20:47 | 000,001,214 | β€”- | C] () – C:\WINDOWS\Sdcache.ini
[2007/03/13 19:20:41 | 000,002,679 | β€”- | C] () – C:\WINDOWS\System32\SDUSBPDR.INI
[2007/03/13 19:16:10 | 000,002,204 | β€”- | C] () – C:\WINDOWS\System32\drivers\UNINST2K.SYS
[2007/02/03 18:31:54 | 000,000,097 | β€”- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2007/02/03 18:30:04 | 000,000,054 | β€”- | C] () – C:\WINDOWS\System32\EAL32.INI
[2007/02/03 18:28:50 | 000,000,044 | β€”- | C] () – C:\WINDOWS\EPCX6000.ini
[2005/11/13 16:39:42 | 000,000,565 | β€”- | C] () – C:\WINDOWS\hegames.ini
[2005/06/19 18:44:44 | 000,065,536 | β€”- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2005/04/01 16:52:37 | 000,000,002 | β€”- | C] () – C:\WINDOWS\msoffice.ini
[2005/03/24 19:23:32 | 000,000,029 | β€”- | C] () – C:\WINDOWS\RRK.INI
[2005/01/26 14:53:29 | 000,000,008 | β€”- | C] () – C:\WINDOWS\System32\PdSACKey.sys
[2005/01/21 20:11:50 | 000,000,159 | β€”- | C] () – C:\WINDOWS\TLCAPPS.INI
[2005/01/08 14:39:17 | 000,000,814 | β€”- | C] () – C:\WINDOWS\dellstat.ini
[2005/01/04 22:31:46 | 000,031,917 | β€”- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/12/31 12:20:10 | 000,000,190 | β€”- | C] () – C:\WINDOWS\disneysy.ini
[2004/12/31 10:26:16 | 000,000,165 | β€”- | C] () – C:\WINDOWS\ka.ini
[2004/12/26 11:02:49 | 000,000,050 | β€”- | C] () – C:\WINDOWS\upst.ini
[2004/12/26 11:02:49 | 000,000,029 | β€”- | C] () – C:\WINDOWS\atid.ini
[2004/12/25 18:34:22 | 000,000,191 | β€”- | C] () – C:\WINDOWS\QTW.INI
[2004/12/25 18:02:13 | 000,001,622 | β€”- | C] () – C:\WINDOWS\disney.ini
[2004/12/04 02:38:04 | 000,000,061 | β€”- | C] () – C:\WINDOWS\smscfg.ini
[2004/12/04 02:32:34 | 000,000,264 | β€”- | C] () – C:\WINDOWS\wininit.ini
[2004/12/04 02:26:45 | 000,000,376 | β€”- | C] () – C:\WINDOWS\ODBC.INI
[2004/12/04 01:57:50 | 000,000,520 | β€”- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/09/16 00:03:14 | 000,000,000 | β€”- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 15:13:12 | 000,000,780 | β€”- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/04 07:00:00 | 000,001,793 | β€”- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[1980/01/01 02:00:00 | 000,086,016 | β€”- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[1980/01/01 02:00:00 | 000,012,288 | β€”- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:17639624
< End of report >
ok I uninstalled Firefox and reinstalled it and I thought it worked. It appeared to have worked, at least. It is not in the search engine, but there is still a toolbar option and when you open a new tab, it is FBS :pullhair:
sc518,

This is getting annoying (like I need to tell you that, right).

πŸ–ΌClick to load external image (Posted Image) Go to Control Panel > Add/Remove Programs and remove the following:

Search Guard Plus (My Web Tattoo)
Search Guard Plus Updater (My Web Tattoo)


πŸ–ΌClick to load external image (Posted Image) Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    fbsearchtoolbar.jar
    fbsearchtoolbar.manifest
    :folderfind
    *Search Guard*
    :regfind
    *My Web Tatto*
    *Fast Browser Search*
    *Search Guard*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please include the following in your next post:
  • SystemLook log
k the first two programs weren't even on the Add/Remove Program list. However, I do remember seeing them there a while back and wondering what they were. Systemlook log: SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 12:35 on 14/06/2010 by Tracey Carpenter (Administrator - Elevation successful) ========== filefind ========== Searching for "fbsearchtoolbar.jar" No files found. Searching for "fbsearchtoolbar.manifest" No files found. ========== folderfind ========== Searching for "*Search Guard*" C:\Qoobox\Quarantine\C\Program Files\Search Guard Plus d—– [16:13 11/06/2010] C:\Qoobox\Quarantine\C\Program Files\Search Guard PlusU d—– [16:13 11/06/2010] ========== regfind ========== Searching for "*My Web Tatto*" No data found. Searching for "*Fast Browser Search*" No data found. Searching for "*Search Guard*" No data found. -=End Of File=-
ugh I really just don't know what to do. FBS does not show up as an Add-on on either browser, their are no program files, there is no "search guard plus," and yet it's still on my browsers. :pullhair: i am installing Spybot S-D or w/e it's called. This is such a pain edit: idk if this is from FBS, but I just saw that in the quarantine section of my Webroot AntiVirus with Spysweeper, there is something called "Mal/TDSSRt-A" I hope this isn't something different all-together that we missed; I am really freaking out right now and hoping that everything we have done so far has been a waste of time oh and guess what? FBS is back as the default search engine.
SpySweeper probably found this:

C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\SYMC8XX.SYS.vir

That is the driver that was patched by TDSS that we removed and replaced - it's safely tucked away in the ComboFix quarantine.

I don't know what to tell you about this Firefox / Fast Browser thing though……….I'll do some more checking - let me know if you have any luck.
okay so I am safe on that virus? I am scanning my computer with Spybot Search and Destroy. Hopefully that does something…… okay i scanned it and rebooting now following instructions it says. It has been scanning something called "Virtumonde.sdn" for a long time. Googled it- it's a trojan. fml. HEY!!! I found Search Guard Plus and Search Guard Plus Updater!!! They are in the Qoobox quarantine! how do i delete them for good?
Your scan is probably finding infections already in quarantine and/or old system restore points. If you go back to post 21 and follow those instructions you will clear our the ComboFix quarantine and your old system restore points. You also had some malware in your Trend Micro quarantine. Anything in quarantine is out of play though, so that won't solve the FBS issue.
yes!!! I found the FBS manifest/jar that mirror or w/e was unable to find and FBS is FINALLY gone!!!! do you think I am safe to remove combofix et al.?
Excellent! I'd like you to complete the instructions in post 21 now, then run another Kaspersky scan just to make sure none of those detections you were getting are still active.

πŸ–ΌClick to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • Kaspersky log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI