Solved Techbrowsing adware

Never mind its turns out i added them to block hotspot shield adds. Norton bootable recovery found trojan.gen but didnt tell me the location so ill check the log. This is on the first pc, second pc is running norton to see if its there. Thats the first time a scanner may have found something useful. I will be focusing on cleaning the first pc in this fourm and will then know what to do when i come to clean the second pc witch has no backup at all. Do you want me to run dds now?
 

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
Yes.. that's what I asked for, in the first place :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Yes.. that's what I asked for, in the first place :)
Had to borrow a pc to attach the log as im not loging into any accounts on the infected pc's and my phone would not let me attach it. Here is the DDS log, i changed my username throughout the log as its private, hope thats ok :D
 

Attachments

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
I see you have two antivirus programs running ...

AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}

Choose which one you want to be your full time Antivirus program. Running two at the same time causes your computer to slow down, as they are resource hogs. They may also fight each other's 'definitions'.
Uninstall one of them:

Download AVAST Software Uninstall Utility
Special Note: Needs to be started from Safe Mode, the program will offer to reboot you into Safe Mode on launch. If you did not install the Avast product to the default install location, you need to point to it in the box.

Download Fixit to Remove Microsoft Security Essentials v1 | v2
This is actually now part of the Microsoft Fix it suite and the uninstaller for version 2 should also work on version 4 of Security Essentials as well.
Read More:



Could you please post the
[*] Attach.txt <--- will be minimized in the task tray that I asked for too?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I see you have two antivirus programs running ...

AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}

Choose which one you want to be your full time Antivirus program. Running two at the same time causes your computer to slow down, as they are resource hogs. They may also fight each other's 'definitions'.
Uninstall one of them:

Download AVAST Software Uninstall Utility
Special Note: Needs to be started from Safe Mode, the program will offer to reboot you into Safe Mode on launch. If you did not install the Avast product to the default install location, you need to point to it in the box.

Download Fixit to Remove Microsoft Security Essentials v1 | v2
This is actually now part of the Microsoft Fix it suite and the uninstaller for version 2 should also work on version 4 of Security Essentials as well.
Read More:



Could you please post the
[*] Attach.txt <--- will be minimized in the task tray that I asked for too?


Here you go :D
 

Attachments

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
Thanks! :)

Download CKScanner by askey127 from HERE
Important - Save it to your desktop.
Doubleclick CKScanner.exe and click Search For Files.
After a very short time, when the cursor hourglass disappears, click Save List To File.
A message box will verify the file saved.
Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

This scan will NOT delete any of your files or change any settings.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
c:\program files (x86)\audiosurf\engine\crypt.dll
c:\program files (x86)\audiosurf\engine\channels\crypt.dll
c:\program files (x86)\pcsx2 1.4.0\pcsx2_keys.ini.default
c:\program files (x86)\qtracker\filters\game\call of duty 2\cracked\cracked.qtf
scanner sequence 3.IJ.11.KLLBQ0
----- EOF -----

Just a heads up the last entry is not a crack, Qtracker is a game server manager program and cracked servers is simply just one of the filters is my best guess.
 

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
Do you know this IP?

169.254.136.83
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
BTW ... 169.254.136.83 ...."Comment: Computers use addresses starting with "169.254." when they do not have a
manually configured address or when they are not told which address to use by a service on the
network. They are commonly called the "link local" addresses."

Whois Lookup Captcha
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
techbrowsing.com TechBrowsing.com WHOIS, DNS, & Domain Info - DomainTools
You might want to look at this pertaining to ANCHORFREE.COM

Look all the way down! Tell me if you really want to keep this in your "trusted" MS Hosts file.
I want to keep it as it blocks the pop up and redirects to local host instead :D. Im 80% sure it was hotspot shield causing the pop up but id like to continue just to be sure.
I also just brought a Seagate 2TB backup plus and used Macrium Reflect to schedule a full HDD image every week and only keep the latest 3 images at any one time
 
Last edited:

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
Up to you how you want to proceed :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Up to you how you want to proceed :)
Well you are the expert, id like to look into my strange rougekiller logs sometime in the next few days but you are the expert so what would you suggest checking for clues? [emoji14]
 

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
After looking over the 'rougekiller logs'.... But, like I said, it's up to you as to how you want to proceed. You can either follow my instructions or keep your backup as a re-install. I would also caution you to 'wipe' and do a "clean" installation.

Please use this tool to get to the target issues...Zoek:
Download > Download zoek.exe version 5.0.0.0
Click: Download Zoek.exe version 5.0.0.0 (Do not click .zip or .rar)

When the download shows, and you get the option to save, please do so to the Desktop.
Right-click zoek.exe and select: Run as Administrator (Give it a few seconds to appear.)

If your AntiVirus warns you about the program, either allow Zoek to run, or temporarily disable your AV program.
Info on how to disable your security applications > How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides

Next, copy and then paste the entire script inside the code box below to the input field of Zoek:


Code:
createsrpoint; process; filesrcm; startupall; installedprogs;installer-list; uninstall-list;hijackthis; firefoxlook; chromelook; srinfo; DIR /S /A:L "%systemdrive%\*">>"%temp%\log.txt";b
Now...

Close any open windows.

Click the Run script button and wait. It takes a few minutes to run all the script.

When finished, the zoek-results.log is opened in Notepad.
If a reboot is needed the log is opened after the reboot.

The log is also found on the systemdrive, normally C:\

:ar: Please post the zoek-results.log in your reply.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
After looking over the 'rougekiller logs'.... But, like I said, it's up to you as to how you want to proceed. You can either follow my instructions or keep your backup as a re-install. I would also caution you to 'wipe' and do a "clean" installation.

Please use this tool to get to the target issues...Zoek:
Download > Download zoek.exe version 5.0.0.0
Click: Download Zoek.exe version 5.0.0.0 (Do not click .zip or .rar)

When the download shows, and you get the option to save, please do so to the Desktop.
Right-click zoek.exe and select: Run as Administrator (Give it a few seconds to appear.)

If your AntiVirus warns you about the program, either allow Zoek to run, or temporarily disable your AV program.
Info on how to disable your security applications > How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides

Next, copy and then paste the entire script inside the code box below to the input field of Zoek:


Code:
createsrpoint; process; filesrcm; startupall; installedprogs;installer-list; uninstall-list;hijackthis; firefoxlook; chromelook; srinfo; DIR /S /A:L "%systemdrive%\*">>"%temp%\log.txt";b
Now...

Close any open windows.

Click the Run script button and wait. It takes a few minutes to run all the script.

When finished, the zoek-results.log is opened in Notepad.
If a reboot is needed the log is opened after the reboot.

The log is also found on the systemdrive, normally C:\

:ar: Please post the zoek-results.log in your reply.
May be a while as im not allowed on my computers during school days (only weekends). But i may be able to run it during school but likely not
 

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
May be a while as im not allowed on my computers during school days (only weekends). But i may be able to run it during school but likely not
Huh?? You've been posting to me during weekdays... how old are you?!
Headscratch2.gif
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
May be a while as im not allowed on my computers during school days (only weekends). But i may be able to run it during school but likely not
Huh?? You've been posting to me during weekdays... how old are you?!
Headscratch2.gif
That was the holidays and on my phone, not gonna say my age xD but im closer to 20 than 10 im not a kid
 

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
Please dont close the thread soon as i cant get onto the computers to run this for a week unfortunately, hope thats ok, sorry to keep you waiting around.
 

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
That popup hasent come back in the last few weeks now so would you suggest that its ok and that i dont need any help anymour? Of course if it came back id make a new thread :)
 

My Computer

OS
Windows 7 pro x64 (or win 10 pro)
Back
Top