Solved Excessive pop-ups and redirecting of websites on all browsers

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


It would really help if you could tell me what programs you used detected. It would help to attach as much reports as you can.

  • Open Zemana AntiMalware again.
  • Click on
    4zu6vb.jpg
    icon and double click the latest report.
  • Now click File > Save As and choose your Desktop before pressing Save.
  • The only left thing is to attach saved report in your next message.

Also it would be good to open AVG and ESET and to show me what they deleted. If you need guidance, let me know.
 

aVenger9966

New Member
Thread author
Mar 29, 2016
9
Thank you for your response!

Unfortunately when I installed ESET it made me uninstall AVG. I assume that the uninstall process deletes all the logs...or at least I don't know how to salvage them at this point. Is there a way to get to them?

I have attached reports from Zemana and ESET. I don't think that ESET detected anything on it's scan. However, since it was installed I have noticed that it keeps on blocking a certain website (screenshot attached). I have attached the log from Spybot S&D as well (no significant findings).
 

Attachments

  • Zemana Report.txt
    14.2 KB · Views: 5
  • ESET Report.txt
    29.9 KB · Views: 4
  • ESET Boot Sector Report.txt
    293 bytes · Views: 1
  • ESET C Drive Report.txt
    66.8 KB · Views: 1
  • ESET Filtered Websites Screenshot.jpg
    ESET Filtered Websites Screenshot.jpg
    292.2 KB · Views: 4
  • SBSD - Checks.160328-2145.txt
    26.9 KB · Views: 2

aVenger9966

New Member
Thread author
Mar 29, 2016
9
I scavenged around and found a few remnants of AVG in the temp and Windows folders. This file seemed to be most pertinent. Is this report helpful or should I be looking for something else?
 

Attachments

  • avgrep.txt
    11.3 KB · Views: 8

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
It helps very much. Do you have AVG folder in this location?

%programdata%

Just press Windows key + R and type %programdata%
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
No need for this. Let's scan one more time for fresh system reports:


FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    2.7 KB · Views: 8

aVenger9966

New Member
Thread author
Mar 29, 2016
9
Done.

It looks like everything was successfully executed? I am no longer receiving the messages from ESET stating that it is blocking unwanted websites.
 

Attachments

  • Fixlog.txt
    8.6 KB · Views: 3

aVenger9966

New Member
Thread author
Mar 29, 2016
9
Done.

It looks like everything was successfully executed? I am no longer receiving the messages from ESET stating that it is blocking unwanted websites.
 

aVenger9966

New Member
Thread author
Mar 29, 2016
9
It seems to be behaving normally, at least for now. Thank you so much for your help!

How will I know that it is 100% okay though? I'm sort of worried because the anti-virus and anti-malware programs didn't detect problems even when things weren't right, so I feel like I can't depend on them to know that this problem has been finally fully resolved.

Is reformatting the only way to be 100% sure that everything is now safe and secure again?
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Your PC is now clean and infection is removed. Let me quote you:

Yesterday I (VERY stupidly) opened a .iso file that I wasn't 100% about the origin of.

There is no antivirus or security program that can protect you from yourself. 90% of computer problems are caused by one sitting in front of it or how some like to call it PEBKAC (Problem Exists Between Keyboard And Chair).

Reformat is always the safest option, but I really don't see a need for it. Your call.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top