Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Firefox redirecting in work offline method


  • Please log in to reply
7 replies to this topic

#1 high

high

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 24 January 2010 - 11:42 AM

First, hi to all of you.

I have a problem with mozilla work offline method. I need it for a certain game.
When I put it in offline method, normal thing would be that it says to me that it can't reload that page. And sometime it does. But in most ways it shows me this.

Where does it send me?
It sends me to this link. After = is written something that's also in search bar.

hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=

MBAM( Sorry that it's on Croatian. If you can't read it, I'll change):

Malwarebytes' Anti-Malware 1.44
Verzija baze podataka: 3510
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18882

24.1.2010 13:25:49
mbam-log-2010-01-24 (13-25-49).txt

Tip provjere: Brza Provjera
Provjerenih objekata: 104565
Vrijeme trajanja: 6 minute(s), 0 second(s)

Zaraženi procesi u memoriji: 2
Zaraženi moduli u memoriji: 1
Zaraženi ključevi u registru: 1
Zaražene vrijednosti u registru: 0
Zaraženi podaci u registru: 0
Zaraženi spremnici: 1
Zaražene datoteke: 4

Zaraženi procesi u memoriji:
C:\Program Files\RelevantKnowledge\rlservice.exe (Spyware.MarketScore) -> Unloaded process successfully.
C:\Program Files\RelevantKnowledge\rlvknlg.exe (Spyware.MarketScore) -> Unloaded process successfully.

Zaraženi moduli u memoriji:
C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.MarketScore) -> Delete on reboot.

Zaraženi ključevi u registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.

Zaražene vrijednosti u registru:
(Zlo€udne stavke nisu otkrivene)

Zaraženi podaci u registru:
(Zlo€udne stavke nisu otkrivene)

Zaraženi spremnici:
C:\Program Files\RelevantKnowledge (Spyware.MarketScore) -> Delete on reboot.

Zaražene datoteke:
C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.MarketScore) -> Delete on reboot.
C:\Program Files\RelevantKnowledge\rloci.bin (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Program Files\RelevantKnowledge\rlservice.exe (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Program Files\RelevantKnowledge\rlvknlg.exe (Spyware.MarketScore) -> Quarantined and deleted successfully.


Thanks for help in advance.

Enjoy

EDIT:I also see that this topic is written xy times. Sorry for my internet connection.

Edited by Orange Blossom, 24 January 2010 - 02:37 PM.
Deactivate link. ~ OB


BC AdBot (Login to Remove)

 


#2 high

high
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 24 January 2010 - 12:37 PM

Here is SS
http://i50.tinypic.com/2lji9ma.jpg

My apologies for multiple topics again :thumbsup:

#3 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,595 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:06:29 PM

Posted 24 January 2010 - 01:55 PM

Please do not start new threads or duplicate topics as this causes confusion and makes it more difficult to get the help you need to resolve your issues. Further, it necessitates staff spending time with housecleaning...time which could have been provided to others needing assistance. You had 7 other duplicate topics opened which I had to remove.

Now rescan again with Malwarebytes Anti-Malware, but this time perform a Full Scan in normal mode and check all items found for removal. Don't forgot to check for database definition updates through the program's interface (preferable method) before scanning and to reboot afterwards. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. When done, click the Logs tab and copy/paste the contents of the new report in your next reply.

The database in your previous log shows 3510. Last I checked it was 3627.

If you cannot update MBAM through the program's interface and have already manually downloaded the latest definitions (mbam-rules.exe) shown on this page, be aware that mbam-rules.exe is not updated daily. Another way to get the most current database definitions if you're having problems updating, is to install MBAM on a clean computer, launch the program, update through MBAM's interface, copy the definitions (rules.ref) to a USB stick or CD and transfer that file to the infected machine. Copy rules.ref to the location indicated for your operating system. If you cannot see the folder, then you may have to Reconfigure Windows to show it.
  • XP: C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware
  • Vista: C:\Documents and Settings\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#4 high

high
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 24 January 2010 - 02:35 PM

I know that there's no need for duplicate topics and I apologized for it because it was my dumb mistake, that I haven't done with an intention. Nevermind, thank's a lot for the answer. I'll do what you said and then come back.

#5 high

high
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 24 January 2010 - 04:02 PM

Updated and fully scanned.

Malwarebytes' Anti-Malware 1.44
Verzija baze podataka: 3628
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18882

24.1.2010 21:58:01
mbam-log-2010-01-24 (21-58-01).txt

Tip provjere: Kompletna Provjera (C:\|D:\|F:\|)
Provjerenih objekata: 266425
Vrijeme trajanja: 1 hour(s), 21 minute(s), 22 second(s)

Zaraeni procesi u memoriji: 0
Zaraeni moduli u memoriji: 0
Zaraeni ključevi u registru: 0
Zaraene vrijednosti u registru: 0
Zaraeni podaci u registru: 0
Zaraeni spremnici: 0
Zaraene datoteke: 1

Zaraeni procesi u memoriji:
(Zloćudne stavke nisu otkrivene)

Zaraeni moduli u memoriji:
(Zloćudne stavke nisu otkrivene)

Zaraeni ključevi u registru:
(Zloćudne stavke nisu otkrivene)

Zaraene vrijednosti u registru:
(Zloćudne stavke nisu otkrivene)

Zaraeni podaci u registru:
(Zloćudne stavke nisu otkrivene)

Zaraeni spremnici:
(Zloćudne stavke nisu otkrivene)

Zaraene datoteke:
C:\Users\luka\AppData\Roaming\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.

#6 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,595 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:06:29 PM

Posted 24 January 2010 - 04:16 PM

Lets do another anti-malware scan to see if we find anything else that MBAM may have missed.

Please download TFC (Temp File Cleaner) by Old Timer and save it to your desktop.
alternate download link
  • Save any unsaved work. TFC will close ALL open programs including your browser!
  • Double-click on TFC.exe to run it. If you are using Vista, right-click on the file and choose Run As Administrator.
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • TFC will clear out all temp folders for all user accounts (temp, IE temp, Java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.
Note: It is normal for the computer to be slow to boot after running TFC cleaner the first time.

Please download and scan with SUPERAntiSpyware Free
  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If it will not start, go to Start > All Prgrams > SUPERAntiSpyware and click on Alternate Start.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
  • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen and exit the program.
  • Do not run a scan just yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with SUPERAntiSpyware as follows:
  • Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes" and reboot normally.
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
-- If you cannot boot into safe mode or complete a scan, then perform your scan in normal mode.

-- If you have a problem downloading, installing or getting SAS to run, try downloading and using the SUPERAntiSpyware Portable Scanner instead. Save the randomly named file (i.e. SAS_1710895.COM) to a usb drive or CD and transfer to the infected computer. Then double-click on it to launch and scan. The file is randomly named to help keep malware from blocking the scanner.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#7 high

high
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 24 January 2010 - 04:34 PM

wow, man, thanks.

I can't do written now, but first thing in morning will be doing it and contacting you with latest news.

Again, thank you.

Enjoy

#8 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,595 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:06:29 PM

Posted 24 January 2010 - 04:38 PM

Not a problem.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users