My computer has been popping up a bunch of ads when I open a new window and it doesn't go to my home page anymore it gets redirected to some google page but never fully opens that page.Does anyone know of some sights I could go to to download a malware/spybot cleaner? I'm kind of technotarded so make it easy for me.
Announcement
Collapse
No announcement yet.
Computer infected?
Collapse
X
-
I don't think I have anything for antivirus right now or if I do I don't know what it is, I know pretty bad, but I've had this computer for years and years and never had any issues.Originally posted by Nash B.Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.
Comment
-
it's been stuck at a green screen trying to download something for the last 20 minutes when I went to http://goo.gl/yPsBOriginally posted by Nash B.Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.
Comment
-
Originally posted by Tx Redneck View PostTry this.
Saved and Texan by the Grace of God, Redneck by choice.
Ok I downloaded that and it's scanning right now. So far 60 things detected and it keeps popping up in the corner saying it is blocking potentially malicious websites!Originally posted by Nash B.Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.
Comment
-
SO it found 60items and I removed them and restarted the computer. However when I open the internet it still goes to a random google page? It doesn't open up another page anymore though so I think it's a little better.Originally posted by Nash B.Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.
Comment
-
Originally posted by Tx Redneck View PostDL this, make sure DNS cache is checked and run it.
Also, post the log from mbam please.
Saved and Texan by the Grace of God, Redneck by choice.
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
Malwarebytes offers real-time antivirus, advanced anti-malware and privacy protection for all your devices. Launched in 2004 as a free virus scan, we still offer a free basic version 20 years later. Learn more.
Database version: v2012.11.26.10
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: AL-AWMTR8HF9U3 [administrator]
Protection: Enabled
11/26/2012 8:38:14 PM
mbam-log-2012-11-26 (21-39-55).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 68782
Time elapsed: 1 hour(s), 49 second(s) [aborted]
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 1
C:\WINDOWS\system32\fastsrch.dll (IPH.GenericBHO) -> No action taken.
Registry Keys Detected: 53
HKCR\CLSID\{E932FCCC-C424-4613-B195-BFCD4AE1C038} (IPH.GenericBHO) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{E932FCCC-C424-4613-B195-BFCD4AE1C038} (IPH.GenericBHO) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{E932FCCC-C424-4613-B195-BFCD4AE1C038} (IPH.GenericBHO) -> No action taken.
HKCR\CLSID\{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
HKCR\CLSID\{84718935-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{84718935-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{84718935-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{84718935-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
HKCR\CLSID\{05FC4875-A1F4-42d6-A733-EE1F68372D01} (Adware.ShoppingGuard) -> No action taken.
HKCR\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} (Adware.ShoppingGuard) -> No action taken.
HKCR\Interface\{2F0AB503-EF91-4F4C-A688-30F22831F1A4} (Adware.ShoppingGuard) -> No action taken.
HKCR\escort.escortIEPane.1 (Adware.ShoppingGuard) -> No action taken.
HKCR\escort.escortIEPane (Adware.ShoppingGuard) -> No action taken.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{05FC4875-A1F4-42D6-A733-EE1F68372D01} (Adware.ShoppingGuard) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{05FC4875-A1F4-42D6-A733-EE1F68372D01} (Adware.ShoppingGuard) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{05FC4875-A1F4-42D6-A733-EE1F68372D01} (Adware.ShoppingGuard) -> No action taken.
HKCR\CLSID\{A3ED2449-E049-4ab9-A059-DD0F9BA1BA44} (Adware.ShoppingGuard) -> No action taken.
HKCR\shpngrd.hlpr.1 (Adware.ShoppingGuard) -> No action taken.
HKCR\shpngrd.hlpr (Adware.ShoppingGuard) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A3ED2449-E049-4AB9-A059-DD0F9BA1BA44} (Adware.ShoppingGuard) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{A3ED2449-E049-4AB9-A059-DD0F9BA1BA44} (Adware.ShoppingGuard) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{A3ED2449-E049-4AB9-A059-DD0F9BA1BA44} (Adware.ShoppingGuard) -> No action taken.
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (PUP.MyWebSearch) -> No action taken.
HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (PUP.MyWebSearch) -> No action taken.
HKCR\Typelib\{CF710E35-C62E-4D48-ABA4-CA9509B28EC2} (Adware.ShoppingGuard) -> No action taken.
HKCR\Interface\{16493E0D-5DB5-4386-AFF9-6ACFA7490BA9} (Adware.ShoppingGuard) -> No action taken.
HKCR\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (PUP.MyWebSearch) -> No action taken.
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{B67544A0-D1AC-4C74-8D28-1E3421CFFB77} (Adware.ShoppingGuard) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{B67544A0-D1AC-4C74-8D28-1E3421CFFB77} (Adware.ShoppingGuard) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B67544A0-D1AC-4C74-8D28-1E3421CFFB77} (Adware.ShoppingGuard) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{8B2C7C9D-716D-4E9E-9358-B9C80A81B7ED} (Adware.Adparatus) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (PUP.MyWebSearch) -> No action taken.
Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> Data: 4‰q„*Ö*O´”k&oH± -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> Data: 0 -> No action taken.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 4
C:\WINDOWS\system32\fastsrch.dll (IPH.GenericBHO) -> No action taken.
C:\WINDOWS\system32\c578.dll (Adware.Mirar) -> No action taken.
C:\Program Files\Shoppinguard.com\shpngrd\1.3.61.1\shpngrd.dl l (Adware.ShoppingGuard) -> No action taken.
C:\RECYCLER\S-1-5-21-823518204-764733703-839522115-1003\$5a519532f37dabdd9a43bb956fa6e9f9\n (Trojan.0Access) -> No action taken.
(end)Originally posted by Nash B.Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.
Comment
-
OK,it did the scan but you didn't have the check box marked to remove infections. Also, do not use system restore, there is at least one restore point infected with a Trojan. Rerun mbam,full scan and have it remove everything it detects. Reboot, google eset online scanner and run it if you're able to get to it. If not, try to DL and install Avast free from avast.com If you're able to do that, run a full scan with rootkit detection enabled.
I'll check this in the AM.
Saved and Texan by the Grace of God, Redneck by choice.
Comment
-
I also had this log as I did it a second time and enabled it to detect a different type of thing DOn't know if this is the other one you asked about. I will let it do a full scan and let it run all night and try the other stuff you suggested tomorrow. I really appreciate the help as the cmputer is already 10x faster and it now goes back to my regular yahoo home page when I start the internet.
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
Malwarebytes offers real-time antivirus, advanced anti-malware and privacy protection for all your devices. Launched in 2004 as a free virus scan, we still offer a free basic version 20 years later. Learn more.
Database version: v2012.11.26.10
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: AL-AWMTR8HF9U3 [administrator]
Protection: Enabled
11/26/2012 9:48:02 PM
mbam-log-2012-11-26 (21-48-02).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 51877
Time elapsed: 21 minute(s), 14 second(s) [aborted]
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 1
C:\RECYCLER\S-1-5-18\$5a519532f37dabdd9a43bb956fa6e9f9\n (Trojan.0Access) -> Delete on reboot.
Registry Keys Detected: 20
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (PUP.MyWebSearch) -> No action taken.
HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (PUP.MyWebSearch) -> No action taken.
HKCR\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (PUP.MyWebSearch) -> No action taken.
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (PUP.MyWebSearch) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (PUP.MyWebSearch) -> No action taken.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 8
C:\WINDOWS\Temp\SPA240.tmp\upgrade.exe (PUP.Zwangi) -> No action taken.
C:\RECYCLER\S-1-5-18\$5a519532f37dabdd9a43bb956fa6e9f9\n (Trojan.0Access) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\shpngrd.exe (Adware.ShoppingGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\SkypeSetupo.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\stub-9945.exe (Adware.Adparatus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\uninstall.exe (Adware.GabPath) -> Quarantined and deleted successfully.
(end)Originally posted by Nash B.Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.
Comment
-
I wouldn't recommend that for two reasons.
1There will likely be updates to those programs in the near future.
2They're hosted from my personal dropbox and if I delete the files, the links are no good.
I hosted them there to reduce the probability of being blocked/redirected as it appeared he was experiencing.
Saved and Texan by the Grace of God, Redneck by choice.
Comment
-
ya noticed that after I looked at the links. I'll just do the same as needed with my dropbox. Still a good idea. I had to use mine to show screenshots to Dell tech support on my busted laptop to get em to replace the drive. Also a good idea to link there and naming etc as lots of malware tries to stop/avoid the common cleanup tools2013 F150 STX Supercab 5.0L w/3.55 LSD
1990 GT Convertible
Comment
Comment