Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93081 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

ebay search for item redirects me to this page (pages.ebay.com) [Solve


  • This topic is locked This topic is locked
18 replies to this topic

#1 TomTom

TomTom

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:Landscaping, Photography and Computers

Posted 26 April 2017 - 07:33 PM

Only e-bay does this.  No other site.  I go to www.ebay.com and while in e-bay I search for an item and I get this pop up window:  pages.email.com   I do not open it but I can tell it is trying to sell gift cards.  I have to close the pop up by clicking on the X and then I get the item that I have searched for.

 

This happens all the time when I search for an item in e-bay.com.  No other site gives me this pop up.  I called e-bay support and they tried a few removal programs and then said I should go to a geek squad type place and have my computer cleaned.

 

I might add that this is a computer that is only about a week old.  I have Kaspersky Internet Securities and Malwarebytes Pro installed on my computer which is up to date and run very often.  They do not find any problem.

 

I am attaching the 3 files per instructions.,

 

Thanks in advance for your help.

 

Attached Files


    Advertisements

Register to Remove


#2 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 27 April 2017 - 08:08 AM

:welcome:

 

First lets reset your hosts file and see if that helps

 

Open notepad , Go to Start --> All Programs --> Accessories --> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#3 TomTom

TomTom

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:Landscaping, Photography and Computers

Posted 27 April 2017 - 11:03 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-04-2017
Ran by Tom (27-04-2017 12:58:00) Run:1
Running from C:\Users\Tom\Desktop
Loaded Profiles: Tom (Available Profiles: defaultuser0 & Tom)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
========= ipconfig /flushdns =========

Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
Could not move "C:\Windows\System32\Drivers\etc\hosts" => Scheduled to move on reboot.
=========== EmptyTemp: ==========
BITS transfer queue => 3024454 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 26649367 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 1364364 B
Edge => 1257293 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
defaultuser0 => 3313153 B
Tom => 229085938 B
RecycleBin => 0 B
EmptyTemp: => 252.4 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 27-04-2017 13:00:02)
C:\Windows\System32\Drivers\etc\hosts => Is moved successfully
Could not restore Hosts.
==== End of Fixlog 13:00:02 ====


#4 TomTom

TomTom

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:Landscaping, Photography and Computers

Posted 27 April 2017 - 11:05 AM

Did not fix it.   Still get this pop up requested page in e-bay.com



#5 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 27 April 2017 - 01:21 PM

It shows that the hosts file will be fixed upon reboot, reboot your system and  see if it helped

 

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
AdwCleaner4.201_zpsxrbk2llq.jpg
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
Capture_zpsge1t2tk9.jpg Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#6 TomTom

TomTom

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:Landscaping, Photography and Computers

Posted 27 April 2017 - 02:11 PM

I only save to desktop

I have rebooted many times since then

Here are logs:

 

 

# AdwCleaner v6.046 - Logfile created 27/04/2017 at 16:06:42
# Updated on 24/04/2017 by Malwarebytes
# Database : 2017-04-25.1 [Local]
# Operating System : Windows 10 Home  (X64)
# Username : Tom - DESKTOP-Q1AN705
# Running from : C:\Users\Tom\Desktop\adwcleaner_6.046.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support
 
***** [ Services ] *****
 
***** [ Folders ] *****
 
***** [ Files ] *****
 
***** [ DLL ] *****
 
***** [ WMI ] *****
 
***** [ Shortcuts ] *****
 
***** [ Scheduled Tasks ] *****
 
***** [ Registry ] *****
 
***** [ Web browsers ] *****
 
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [1049 Bytes] - [25/04/2017 00:00:00]
C:\AdwCleaner\AdwCleaner[C2].txt - [1268 Bytes] - [27/04/2017 15:55:42]
C:\AdwCleaner\AdwCleaner[C3].txt - [898 Bytes] - [27/04/2017 16:06:42]
C:\AdwCleaner\AdwCleaner[S0].txt - [1184 Bytes] - [24/04/2017 23:57:45]
C:\AdwCleaner\AdwCleaner[S1].txt - [1290 Bytes] - [25/04/2017 00:23:34]
C:\AdwCleaner\AdwCleaner[S2].txt - [1364 Bytes] - [26/04/2017 18:05:50]
C:\AdwCleaner\AdwCleaner[S3].txt - [1436 Bytes] - [27/04/2017 15:55:31]
C:\AdwCleaner\AdwCleaner[S4].txt - [1582 Bytes] - [27/04/2017 16:06:30]
########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [1335 Bytes] ##########

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 10 Home x64
Ran by Tom (Administrator) on Thu 04/27/2017 at 16:00:48.32
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

File System: 0
 

Registry: 0
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 04/27/2017 at 16:01:34.40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Problem is still there.



#7 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 27 April 2017 - 03:08 PM

What browser are you using when this happens, any perticular one or all of them. IE, FF, Chrome , Edge



 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#8 TomTom

TomTom

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:Landscaping, Photography and Computers

Posted 27 April 2017 - 03:20 PM

Edge was all I used.  I have internet explorer if you want me to use it let me know.



#9 TomTom

TomTom

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:Landscaping, Photography and Computers

Posted 27 April 2017 - 03:31 PM

Must be a problem in Edge.  I used Internet Explorer and searched from ebay.com about 20 straight searches and never got the page at all.



#10 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 27 April 2017 - 03:44 PM

Lets clean Edge up, I am posting a link, it will be easier than writing everything in

 

https://www.groovypo...fault-settings/

 

 

Set it back to defaults

 

To reset the entire browser, check all options, then click Clear



 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

    Advertisements

Register to Remove


#11 TomTom

TomTom

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:Landscaping, Photography and Computers

Posted 27 April 2017 - 04:14 PM

Cleared everything but passwords.  I don't want to clear my passwords.

To9m



#12 TomTom

TomTom

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:Landscaping, Photography and Computers

Posted 27 April 2017 - 04:25 PM

Did not help.  Still happens.

 

Here is what page pulls up.  I tried to copy and paste it but could not so here is the site that it wants to pull up.

 

http://ir.ebaystatic...CsDflt_MREC.jpg



#13 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 27 April 2017 - 04:58 PM

Zemana AntiMalware  <--You have this installed and also Malwarebytes, you only need one Anti Malware program and Malwarebytes would be my choice, That program also may be blocking up resetting the hosts file, so go a head and uninstall it and then lets see if we can fix the host file now

 

 

 
Open notepad , Go to Start --> All Programs --> Accessories --> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
2017-04-14 19:21 - 2017-04-14 17:17 - 00003062 _____ C:\Windows\system32\Drivers\etc\hosts.dat
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#14 TomTom

TomTom

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:Landscaping, Photography and Computers

Posted 27 April 2017 - 06:56 PM

I had already uninstalled Zemana earlier.  I only have Malwarebytes and Kaspersky and I stopped both of them before doing the procedure.

 

Here is the Log.

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-04-2017
Ran by Tom (27-04-2017 20:48:53) Run:2
Running from C:\Users\Tom\Desktop
Loaded Profiles: Tom (Available Profiles: defaultuser0 & Tom)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
2017-04-14 19:21 - 2017-04-14 17:17 - 00003062 _____ C:\Windows\system32\Drivers\etc\hosts.dat
CMD: ipconfig
/flushdns
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
C:\Windows\system32\Drivers\etc\hosts.dat => moved successfully
========= ipconfig =========

Windows IP Configuration

Ethernet adapter Ethernet:
   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::71bb:3367:cb:bd4e%14
   IPv4 Address. . . . . . . . . . . : 192.168.1.13
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.1
Wireless LAN adapter Wi-Fi:
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
Wireless LAN adapter Wi-Fi 2:
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
Wireless LAN adapter Local Area Connection* 4:
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
Ethernet adapter Ethernet 2:
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
Ethernet adapter Bluetooth Network Connection:
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
Tunnel adapter isatap.{810517E1-088C-49FC-BECB-F260D5C5B8F1}:
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
Tunnel adapter Teredo Tunneling Pseudo-Interface:
   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::c56:1fc:3f90:b4b1%20
   Default Gateway . . . . . . . . . :
========= End of CMD: =========
/flushdns => Error: No automatic fix found for this entry.
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 1120859 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 42230783 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 1706077 B
Edge => 28136125 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 4102 B
NetworkService => 0 B
defaultuser0 => 0 B
Tom => 17731755 B
RecycleBin => 0 B
EmptyTemp: => 86.7 MB temporary data Removed.
================================

The system needed a reboot.
==== End of Fixlog 20:49:04 ====


#15 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 27 April 2017 - 07:07 PM

It looks like the hosts file was restored.  Things any better ?



 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users