Help! Am being plagued by adware.



  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112

    na wouldn't be a hardware problem id say. not sure much more advice I can give.

    where are the popups sending to you, and what sites give you them ?

  • Registered Users, Registered Users 2 Posts: 102 ✭✭WildSaffron

    The popups are gone now - just the problem morphed into weird changes on my computer and not being able to download files.

    Thanks for all your help with this - it is a headscratcher, alright.

  • Registered Users, Registered Users 2 Posts: 282 ✭✭The Bogman

    Apologies for jumping on this thread,but I'm having similar problems.
    Only in the last few hours, started having problems with ads. If it makes any difference,I use chrome. Some open tabs just randomly change to ads, as well as tabs with ads just opening by themselves. I've attached a pic of other ads that come up when I hover on words in text.
    Any help would be appreciated. Never had bother before and completely clueless here

  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112

    either of you use RSS reader or things like that ?

    bogman, do this

    Download OTL to your Desktop
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Quick Scan button. Do not change any settings. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files here

  • Registered Users, Registered Users 2 Posts: 282 ✭✭The Bogman

    SRV - [2013/12/16 20:34:22 | 000,247,968 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\\SeaPort.EXE -- (BBUpdate)
    ========== Driver Services (SafeList) ==========

    ========== Standard Registry (SafeList) ==========

    ========== FireFox ==========

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn\ [2012/04/06 09:42:24 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2014/04/06 10:48:06 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{10E4285F-D79B-4147-9447-81DFF109A394}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2014/02/06 18:19:29 | 000,000,000 | ---D | M]

    ========== Files/Folders - Created Within 30 Days ==========

    ========== Files - Modified Within 30 Days ==========

    ========== Files Created - No Company Name ==========

  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112

    this should help. go to add/remove programs and uninstall these

    "{7BCAC0EB-3993-2416-0531-848C39DF8B65}" = ExtraShouppEr
    "{70BD2558-27DA-8B02-02D0-D8704ECD2EDF}" = savinshoP

    open OTL copy this into the box

    O2:64bit: - BHO: (savinshoP) - {36A4A454-904F-B5FF-EBCA-88EA8E98CA1A} - C:\ProgramData\savinshoP\I1cfSLC.x64.dll ()
    O2:64bit: - BHO: (ExtraShouppEr) - {B431C372-C536-F46E-C08B-D6750754D1B7} - C:\ProgramData\ExtraShouppEr\XhyGBA.x64.dll ()
    O2 - BHO: (savinshoP) - {36A4A454-904F-B5FF-EBCA-88EA8E98CA1A} - C:\ProgramData\savinshoP\I1cfSLC.dll ()
    O2 - BHO: (ExtraShouppEr) - {B431C372-C536-F46E-C08B-D6750754D1B7} - C:\ProgramData\ExtraShouppEr\XhyGBA.dll ()
    [2014/04/05 00:09:57 | 000,000,000 | ---D | C] -- C:\ProgramData\savinshoP
    [2014/04/04 23:30:10 | 000,000,000 | ---D | C] -- C:\ProgramData\ExtraShouppEr
    [2014/04/04 23:30:24 | 000,000,000 | ---D | C] -- C:\ProgramData\977078e4f2aec587
    [2014/04/04 23:30:18 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Packages

    ipconfig /flushdns /c

    click run fix post the log it gives

  • Registered Users, Registered Users 2 Posts: 282 ✭✭The Bogman

    This might be a silly question, but how do I find add/remove programs to uninstall?

    All processes killed
  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112

    i'm not too familiar with your operating system, don't worry if you cant find it

    are you still getting the pop ups ?

  • Registered Users, Registered Users 2 Posts: 282 ✭✭The Bogman

    I actually fond it and when I clicked on the two programs it told me they had already been deleted. Yep, still happening. Havent had any new tabs pop up or change, but I still have the ones like in the image attached above, aswell as a couple of others. Like when I open I get two different pop-ups for ebay.

  • Advertisement
  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112

    run adwcleaner, delete what it finds, and post the log here

  • Registered Users, Registered Users 2 Posts: 282 ✭✭The Bogman

  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112

    hows it running, issue still there ? if so, download malwarebytes, update it and run a quick scan

  • Registered Users, Registered Users 2 Posts: 282 ✭✭The Bogman

    Issues are still there. Updated and ran the scan. Gives me the option to quarantine, add exclusion, or ignore 4 detected items

    Malwarebytes Anti-Malware

  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112

    you can quarantine those

    then open OTL click quickscan and post that log

  • Registered Users, Registered Users 2 Posts: 282 ✭✭The Bogman

    PRC - [2014/04/06 10:55:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
    ========== Services (SafeList) ==========

    ========== Driver Services (SafeList) ==========

    ========== Standard Registry (SafeList) ==========

    O1 HOSTS File: ([2014/04/06 11:48:00 | 000,000,098 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
    ========== Files/Folders - Created Within 30 Days ==========

    ========== Files - Modified Within 30 Days ==========

    ========== Files Created - No Company Name ==========

  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112

    can you go into the extension and add-on part of firefox and see if you can find anything relating to


    remove them if they are there

  • Registered Users, Registered Users 2 Posts: 282 ✭✭The Bogman

    Yep. Both were enabled as extensions. Deleted them and all seems to be running smoothly again. Thanks for all your help!
