This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Pop-ups & Automatically opening tabs

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

[external image: goGMWSt.gif]P2P Warning

β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
I see you have peer-to-peer (P2P) file sharing software installed on your computer (uTorrent). I advise you avoid P2P file sharing programmes; they are a security risk which can make your computer susceptible to malware. File sharing networks are thoroughly infected and infested with malware - worms, backdoor Trojans, IRCBots, and rootkits propagate via P2P file sharing networks, gaming, and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans, and spyware. The best way to reduce the risk of infection is to avoid these types of web sites and not use P2P applications. Please read the following articles for more information.
  • Risks of File-Sharing Technology
  • P2P Software User Advisories
  • More malware is traveling on P2P networks these days
Your P2P software can be removed by following the instructions below.
  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the aforementioned programme(s), right-click and click Uninstall.
If you choose not to, please refrain from using the programme(s) during this process.

**

Running from C:\Users\[removed]\Downloads

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CloseProcesses:
() C:\ProgramData\webzoom\1.1.0.29\cozahost.exe
() C:\ProgramData\webzoom\1.1.0.29\cozwdhost.exe
() C:\ProgramData\webzoom\1.1.0.29\cozaghost.exe
() C:\ProgramData\webzoom\1.1.0.29\coz32host.exe
() C:\ProgramData\webzoom\1.1.0.29\coz64host.exe
() C:\ProgramData\webzoom\1.1.0.29\cozahost.exe
R2 cozaghost; C:\ProgramData\webzoom\1.1.0.29\cozaghost.exe [481776 2015-02-05] ()
R2 cozwdhost; C:\ProgramData\webzoom\1.1.0.29\cozwdhost.exe [247280 2015-02-05] ()
HKLM-x32\…\RunOnce: [Import FF:0] => "C:\Users\Josh\AppData\Local\browser extensions\Resources\certutil.exe" -A -n "DO_NOT_TRUST_FiddlerRoot" -t "TCu,TCu,TCu" -i "C:\Users\Josh\AppData\Local\browser extensions\TrustedRoot.cer" -d "C:\Use (the data entry has 66 more characters).
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
CHR HKLM-x32\…\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
2015-02-06 20:52 - 2015-02-06 20:52 - 01513574 _____ () C:\Windows\shost.bin
C:\Users\Josh\AppData\Local\Temp\Quarantine.exe
C:\Users\Josh\AppData\Local\Temp\sqlite3.dll
C:\Users\Josh\AppData\Local\Temp\{92622AAD-05E8-4459-B256-765CE1E929FB}_NST_11551.exe
2015-02-05 06:18 - 2015-02-05 06:18 - 00247280 _____ () C:\ProgramData\webzoom\1.1.0.29\cozwdhost.exe
2015-02-05 06:19 - 2015-02-05 06:19 - 00481776 _____ () C:\ProgramData\webzoom\1.1.0.29\cozaghost.exe
2015-02-05 06:19 - 2015-02-05 06:19 - 00073728 _____ () C:\ProgramData\webzoom\1.1.0.29\coz32host.exe
2015-02-05 06:19 - 2015-02-05 06:19 - 00081920 _____ () C:\ProgramData\webzoom\1.1.0.29\coz64host.exe
2015-02-05 06:19 - 2015-02-05 06:19 - 00106496 _____ () C:\ProgramData\webzoom\1.1.0.29\cozahost.exe
EmptyTemp:
Hosts:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~~

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click Scan.
  • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
  • Follow the prompts and allow your computer to reboot.
  • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
  • – File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

    ~~~~~~~~~~~~~~~~~~`

    Download Malwarebytes' Anti-Malware to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
    [external image: MBAMDashboard_zpsddef9b5f.gif]
    • On the Dashboard click on Update Now
    • Go to the Setting Tab
    • Under Setting go to Detection and Protection
    • Under PUP and PUM make sure both are set to show Treat Dections as Malware
    • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
    • Then on the Dashboard click on Scan
    • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished and the log pops up…select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
  • ***************************************

    Please post
    fixlist.txt
    AdwCleaner.txt
    Malwarebytes log
Wish MalwareBytes would tell us, or in a better way, if it deleted items found or not.

How's the computer?

What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.


[external image: GzlsbnV.png]ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.
  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme.
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points.
  • Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
  • Push the Back button.
  • Place a checkmark next to [external image: xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png] and click [external image: SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png].
  • Re-enable your anti-virus software.
  • Copy the contents of the log and paste in your next reply.
======================================================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI