Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google Chrome keeps popping up new tabs when browsing


  • Please log in to reply
14 replies to this topic

#1 bayar3a

bayar3a

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 02 June 2014 - 01:40 AM

When I search with google chrome, new tabs keep popping up especially, if I search the web.  The tabs have videos playing on the them or audio.  Sometimes, I hear audio when browsing, it pops up randomly and it gives me no indication of where it is coming from.  I used Malwarebytes and SuperAntispy.  I have also run the ESET scan.  Nothing helps......need help!

 

Thanks in advance.



BC AdBot (Login to Remove)

 


#2 BLACKB0X

BLACKB0X

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:38 AM

Posted 02 June 2014 - 02:50 AM

I would double check your addons in chrome. Make sure you don't have any extra tools. I would also download AdBlock too for your browser. A good tool to scan is ADWCleaner which you can grab from the forums here ==> http://www.bleepingcomputer.com/download/adwcleaner/



#3 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:09:38 PM

Posted 02 June 2014 - 07:07 AM

Hello -

 

First -

Please download and run RKill by Grinler.

A black DOS box will briefly flash and then disappear.
This is normal and indicates the tool ran successfully.

Please Copy and Paste the log back here.

 

Important: Do not reboot your computer until you complete the next step.

 

Next -

Please download AdwCleaner by Xplode and save to your Desktop.
* NOTE : Please close or save all work, as the computer will be Rebooted
* Double-click on AdwCleaner.exe to run the tool.
* Vista/Windows 7/8 users right-click and select Run As Administrator.
* Click on the Scan button. (only once)
* AdwCleaner will begin...be patient as the scan may take some time to complete.

* Please review the list of items it wishes to remove.
** NOW

* Click on the Clean button. (only once)
* Press OK when asked to close all programs and follow the onscreen prompts.
* Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
* After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
* Copy and paste the contents of that logfile in your next reply.

* A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

 

Next -

* Download Malwarebytes Anti-Malware Free and save it to your desktop
* Double click the desktop icon, click Run, then OK
* Click Next
* Select I accept the agreement then continue to click Next then finally click Install
** Uncheck Enable free trial of Malwarebytes Anti-Malware Premium if you do not want the free trial of the paid version, then click Finish
* If you are notified the Database is out of date click Update Now
* Click Scan Now >>

 

** When completed click the down arrow on Export Log and select Text file (*.txt)
* Save the file to your desktop as MBAM
* Click Apply Actions then restart your computer if requested
* Copy and past the contents of MBAM.txt in your reply



#4 bayar3a

bayar3a
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 02 June 2014 - 12:12 PM

Rkill 2.6.6 by Lawrence Abrams (Grinler)
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 06/02/2014 10:09:26 AM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * No malware processes found to kill.
 
Active Proxy Server Detected
 
 * Proxy Disabled.
 * ProxyOverride value deleted.
 * ProxyServer value deleted.
 * AutoConfigURL value deleted.
 * Proxy settings were backed up to Registry file.
 
Checking Registry for malware related settings:
 
 * No issues found in the Registry.
 
Backup Registry file created at:
 C:\Users\David\Desktop\rkill\rkill-06-02-2014-10-09-29.reg
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * No issues found.
 
Checking Windows Service Integrity: 
 
 * No issues found.
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * No issues found.
 
Program finished at: 06/02/2014 10:11:15 AM
Execution time: 0 hours(s), 1 minute(s), and 49 seconds(s)


#5 bayar3a

bayar3a
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 02 June 2014 - 12:16 PM

# AdwCleaner v3.211 - Report created 02/06/2014 at 10:12:59
# Updated 26/05/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : David - DAVID-PC
# Running from : C:\Users\David\Downloads\AdwCleaner (1).exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17041
 
 
-\\ Mozilla Firefox v22.0 (en-US)
 
[ File : C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\y9kxnrdv.default\prefs.js ]
 
 
-\\ Google Chrome v35.0.1916.114
 
[ File : C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&tt=010412_crm&babsrc=SP_crm
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Search Provider] : hxxp://dts.search-results.com/sr?src=crb&appid=168&systemid=406&sr=0&q={searchTerms}
Deleted [Search Provider] : hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={86B74C65-71F5-11E1-9643-E89A8F696963}
Deleted [Search Provider] : hxxp://search.easylifeapp.com/?q={searchTerms}
Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&ctid=CT3220468
Deleted [Search Provider] : hxxps://isearch.avg.com/search?cid={D9454ABE-285B-45E6-B1F2-E90F32986EBA}&mid=3f6504c6a40a47d0b5f939d3c98d8090-eac4f29c2cacc41ff59b5e26adf33d33e365b58e&lang=en&ds=AVG&pr=pr&d=2012-06-05 19:43:36&v=12.2.5.32&sap=dsp&q={searchTerms}
Deleted [Search Provider] : hxxps://isearch.avg.com/search?cid={A56534DD-BAFF-4B63-89E9-A25272A4F779}&mid=b49059c4264c47d3acee39d3c98d8090-eac4f29c2cacc41ff59b5e26adf33d33e365b58e&lang=en&ds=is015&pr=sa&d=2012-06-05 19:43:36&v=17.1.0.27&sap=dsp&q={searchTerms}
 
*************************
 
AdwCleaner[R0].txt - [1102 octets] - [11/09/2013 21:35:35]
AdwCleaner[R1].txt - [1440 octets] - [06/10/2013 03:03:53]
AdwCleaner[R2].txt - [1138 octets] - [06/10/2013 12:39:41]
AdwCleaner[R3].txt - [3092 octets] - [26/05/2014 18:13:09]
AdwCleaner[R4].txt - [2619 octets] - [01/06/2014 23:51:07]
AdwCleaner[R5].txt - [1504 octets] - [02/06/2014 10:12:11]
AdwCleaner[S0].txt - [1168 octets] - [11/09/2013 21:37:01]
AdwCleaner[S1].txt - [1511 octets] - [06/10/2013 03:05:19]
AdwCleaner[S2].txt - [1200 octets] - [06/10/2013 13:05:44]
AdwCleaner[S3].txt - [4407 octets] - [26/05/2014 18:14:39]
AdwCleaner[S4].txt - [2700 octets] - [01/06/2014 23:52:40]
AdwCleaner[S5].txt - [2635 octets] - [02/06/2014 10:12:59]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [2695 octets] ##########


#6 bayar3a

bayar3a
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 02 June 2014 - 01:21 PM

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 6/2/2014
Scan Time: 11:09:34 AM
Logfile: file.txt
Administrator: No
 
Version: 2.00.2.1012
Malware Database: v2014.06.02.07
Rootkit Database: v2014.05.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: David
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 267275
Time Elapsed: 9 min, 17 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)


#7 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:09:38 PM

Posted 02 June 2014 - 06:21 PM

Uninstall AdwCleaner -

Open the program and hit Uninstall to remove it.

This is a 1 hit program, and will hold too much in quarantine if left installed.

You have used it 6 times (AdwCleaner[S5].txt) and the current results are [S5] findings.



#8 bayar3a

bayar3a
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 02 June 2014 - 10:07 PM

I uninstalled it......



#9 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:09:38 PM

Posted 03 June 2014 - 01:00 AM

Please run a Free Online Scan with the ESET Online Scanner

  • Temporarily Disable Any Active Anti-virus
  • Click on "Run ESET Online Scanner" button.
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives, and Remove found threats
  • Click Advanced settings, and select the following
     Scan potentially unwanted applications
     Scan for potentially unsafe applications
     Enable Anti-Stealth technology
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

NOTE. If Eset doesn't find any threats it will NOT produce any log.

 

EDIT for Typo only -

 

 

Report on any problems once completed -


Edited by noknojon, 03 June 2014 - 01:02 AM.


#10 bayar3a

bayar3a
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 03 June 2014 - 07:55 PM

C:\a\VLC_Media_Player_Setup.exe Win32/DownloadAdmin.G potentially unwanted application
C:\Users\David\Desktop\Dowmloads\Shockwave_Installer_Slim.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\David\Desktop\Dowmloads\VLCMediaPlayerSetup-22eQ1eF (1).exe Win32/Somoto.A potentially unwanted application
C:\Users\David\Desktop\Dowmloads\VLCMediaPlayerSetup-22eQ1eF.exe Win32/Somoto.A potentially unwanted application
C:\Users\David\Downloads\cbsidlm-cbsi118-Download_App-ORG-75864009 (1).exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\David\Downloads\cbsidlm-cbsi118-Download_App-ORG-75864009.exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\David\Downloads\drivermax_7_18_cnet.exe a variant of Win32/DealPly.I potentially unwanted application
C:\Users\David\Downloads\flstudio_11.0.4.exe Win32/OpenCandy potentially unsafe application
C:\Windows\System32\Adobe\Shockwave 12\gt.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Windows\SysWOW64\Adobe\Shockwave 12\gt.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application


#11 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:09:38 PM

Posted 03 June 2014 - 10:59 PM

Hi -

That is a good result and has removed quite a bit of garbage.

 

How is the computer running now, and any specific problems ?



#12 bayar3a

bayar3a
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 04 June 2014 - 12:03 AM

i'm going have to run eset again cause, i unchecked remove



#13 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:09:38 PM

Posted 04 June 2014 - 02:55 AM

No Problem-

 

Just let it run -



#14 bayar3a

bayar3a
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 04 June 2014 - 10:45 AM

ok, computer seems to run better, thanks



#15 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:09:38 PM

Posted 08 June 2014 - 05:24 AM

Leave it for a week, and tell us if all is still OK after that -  :thumbup2:






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users