This thread's last reply is from November 7, 2013, 6:24 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
MtMercy+
My computer has had a problem for several months. Actually 2 problems. (1) If I do a search (doesn't matter if Google, Yahoo, etc.), and hit enter, different choices show up at left. I scroll down until I see one with the proper .com at the end, click on it, and almost always a website comes up that is different. I cancel it out, and go back to the original one I had selected, click on it, and it does then come up. (2) A lot of times when I am typing text, and if I pause for a bit, when I resume typing my curser has moved back up into what I have already typed. If I don't do a visual check, I end up typing new material where it shouldn't be. I don't know if these 2 problems are related or not.
My computer is a 1 1/2 years old. I have run McAfee Internet Security on it since new. I don't do anything with updates manually. I assume they are done automatically. My phone/internet provider provided me with free internet security also. Once a month they send me an e-mail informing me of the status. For 3-4 months they have shown an alert stating my computer has a "moderate risk" due to "Win32.Hijacker.Medfos.B-Runtime Detection". They recommended I run their "Super Spy-Ware" software to remove it. It didn't remove it. I have done total scans with McAfee Stinger, Malwarebytes, and several Windows tools.
Other than those 2 problems, my computer works fine. I'm just not computer savy enough to know if I'm at risk on this computer doing financial transactions. I've been using a different computer for those. I'm just really tired of these nuisances, and would like some help. Thanks, Jim
I can't get the DDS.txt and Attach Text to copy and paste. They are both on my desktop, I click on them and they copy, but the pasting part isn't working! Help
Gary R
Can you attach the necessary files ?
Open the text editor here by clicking the Full Editor button, then scan down to below the main text input field, click on the Upload Attachment button, hit the Browse button and browse to the DDS.txt file, double click on it to select it then click on Add the file to attach it. Repeat for Attach.txt
When both have been attached, click on the Submit button.
If you can't do that, can you copy files to a USB drive, in which case copy the two files to a USB drive, then plug the drive into your uninfected machine and use that to post them here.
MtMercy+
When I go to download the 2 tools (Adw cleaner and OTL), McAfee is telling me in a bold red warning not to go there. It says both of those sites are known to contain viruses, spyware, and other things that can damage my computer.
Gary R
Ignore McAfee, neither of those tools contains any infection, though because of their functionality they can sometimes get flagged by heuristics as being dangerous/hazardous.
No tool I ask you to download will contain anything that is malicious.
MtMercy+
Hopefully, this is the Adw cleaner download. Seems to have failed again. Says "the extension exe is not allowed". Now what? Jim
MtMercy+
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-3943551816-2030989817-4046163665-1000\Software\Microsoft\Internet Explorer\SearchScopes\{D4274864-471C-4BC5-A1C6-F18A41FEFA33}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4274864-471C-4BC5-A1C6-F18A41FEFA33}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
C:\Users\Jim\AppData\Local\dnpxlclg moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56466 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Guest
->Temp folder emptied: 53611 bytes
->Temporary Internet Files folder emptied: 556255 bytes
->FireFox cache emptied: 8502766 bytes
->Flash cache emptied: 56466 bytes
User: Jim
->Temp folder emptied: 618165427 bytes
->Temporary Internet Files folder emptied: 232402003 bytes
->FireFox cache emptied: 101823247 bytes
->Google Chrome cache emptied: 103861801 bytes
->Flash cache emptied: 205403 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 736632136 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42287446 bytes
RecycleBin emptied: 103293742 bytes
Total Files Cleaned = 1,858.00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.69.0 log created on 11062013_101930
Files\Folders moved on Reboot...
C:\Users\Jim\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Jim\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
MtMercy+
C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe a variant of Win32/HiddenStart.A application
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe a variant of Win32/HiddenStart.A application
C:\Users\Jim\Downloads\ArcadeCandyGames(1).exe a variant of Win32/Adware.Gamevance.DD application
C:\Users\Jim\Downloads\ArcadeCandyGames(2).exe a variant of Win32/Adware.Gamevance.DD application
C:\Users\Jim\Downloads\ArcadeCandyGames(3).exe a variant of Win32/Adware.Gamevance.DD application
C:\Users\Jim\Downloads\ArcadeCandyGames(4).exe a variant of Win32/Adware.Gamevance.DD application
C:\Users\Jim\Downloads\ArcadeCandyGames(5).exe a variant of Win32/Adware.Gamevance.DD application
C:\Users\Jim\Downloads\ARO2013_tbt.exe a variant of Win32/Bundled.Toolbar.Ask.D application
C:\Users\Jim\Downloads\iTunes_Setup.exe Win32/Spy.Zbot.ZR trojan
C:\Users\Jim\Downloads\ZipExtractorSetup.exe a variant of Win32/InstallCore.CW application
I managed to cut/paste both the logs you wanted. Sorry about my lack of expertise on a computer. Jim
MtMercy+
C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe moved successfully.
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe moved successfully.
C:\Users\Jim\Downloads\ArcadeCandyGames(1).exe moved successfully.
C:\Users\Jim\Downloads\ArcadeCandyGames(2).exe moved successfully.
C:\Users\Jim\Downloads\ArcadeCandyGames(3).exe moved successfully.
C:\Users\Jim\Downloads\ArcadeCandyGames(4).exe moved successfully.
C:\Users\Jim\Downloads\ArcadeCandyGames(5).exe moved successfully.
C:\Users\Jim\Downloads\ARO2013_tbt.exe moved successfully.
C:\Users\Jim\Downloads\iTunes_Setup.exe moved successfully.
C:\Users\Jim\Downloads\ZipExtractorSetup.exe moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Jim\Downloads\cmd.bat deleted successfully.
C:\Users\Jim\Downloads\cmd.txt deleted successfully.
OTL by OldTimer - Version 3.2.69.0 log created on 11062013_165922 I will try it out and let you know.