Jump to content

Change Mode

Recommended Posts

I somehow have gotten this voice in the background that runs every few minutes saying congratulations you have won crap.....this is a new pc and do not want to hear this. How do I get rid of it. I do have norton but does not get it. ran scan here and says delete cookies, but this thing keeps talking to me... :angry: any help would be greatly appreciated.

Link to post
Share on other sites

Download Malwarebytes' Anti-Malware to your desktop

http://majorgeeks.com/download5756.html

 

* Double-click mbam-setup.exe and follow the prompts to install the program.

* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

* If an update is found, it will download and install the latest version.

* Once the program has loaded, select Perform full scan, then click Scan.

* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location. Copy and Paste that log into your next reply.

Link to post
Share on other sites

Download Malwarebytes' Anti-Malware to your desktop

http://majorgeeks.com/download5756.html

 

* Double-click mbam-setup.exe and follow the prompts to install the program.

* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

* If an update is found, it will download and install the latest version.

* Once the program has loaded, select Perform full scan, then click Scan.

* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location. Copy and Paste that log into your next reply.

 

 

ok I did it and below is the result. Thank you. Not sure if it worked yet.

 

Malwarebytes' Anti-Malware 1.45

www.malwarebytes.org

 

Database version: 3937

 

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

 

3/31/2010 10:56:06 AM

mbam-log-2010-03-31 (10-56-06).txt

 

Scan type: Quick scan

Objects scanned: 121214

Time elapsed: 4 minute(s), 30 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 1

Registry Keys Infected: 17

Registry Values Infected: 2

Registry Data Items Infected: 1

Folders Infected: 3

Files Infected: 10

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

C:\Windows\SysWOW64\irdfmoaw.dll (Adware.Adrotator) -> Delete on reboot.

 

Registry Keys Infected:

HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{e0ec6fba-f009-3535-95d6-b6390db27da1} (Adware.EZlife) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\crhclcltbkiiiyz (Adware.Adrotator) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CscrptXt.CscrptXt (Adware.EZlife) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\cscrptxt.cscrptxt.1.0 (Adware.EZlife) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\ezLife (Adware.EZlife) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\adshothlpr.adshothlpr (Adware.Adrotator) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\adshothlpr.adshothlpr.1.0 (Adware.Adrotator) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{605c6b6a-d96d-ccb1-87c6-b7565870e7f8} (Adware.AdRotator) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{605c6b6a-d96d-ccb1-87c6-b7565870e7f8} (Adware.AdRotator) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fb095a26-54c0-4436-837c-8d38947af23f} (Trojan.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{fb095a26-54c0-4436-837c-8d38947af23f} (Trojan.BHO) -> Quarantined and deleted successfully.

 

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ezlife (Adware.EZlife) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\iyieysitmtyyh (Trojan.Agent) -> Quarantined and deleted successfully.

 

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

 

Folders Infected:

C:\Program Files (x86)\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.

C:\Program Files (x86)\ezLife\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.

C:\Program Files (x86)\ezLife\ezLife\1.4.2.0 (Adware.EzLife) -> Quarantined and deleted successfully.

 

Files Infected:

C:\Windows\SysWOW64\irdfmoaw.dll (Adware.Adrotator) -> Delete on reboot.

C:\Program Files (x86)\Mozilla Firefox\Components\ffxShot.dll (Adware.Adrotator) -> Quarantined and deleted successfully.

C:\$Recycle.Bin\S-1-5-21-1315025616-2406693041-3518982452-1001\$RR1QWZ7.exe (Trojan.Dropper.A) -> Quarantined and deleted successfully.

C:\Windows\System32\crhclcltbkiiiyz.exe (Adware.Adrotator) -> Quarantined and deleted successfully.

C:\Windows\System32\irdfmoaw.dll (Adware.Adrotator) -> Delete on reboot.

C:\Users\Aurelia\AppData\Local\Temp\COM Security Update Level 6 (Adware.Adrotator) -> Quarantined and deleted successfully.

C:\Program Files (x86)\ezLife\ezLife\1.4.2.0\uninstall.exe (Adware.EzLife) -> Quarantined and deleted successfully.

C:\Program Files (x86)\Mozilla Firefox\components\nsFFxSHot.xpt (Adware.Adrotator) -> Quarantined and deleted successfully.

C:\Windows\System32\pxaumeyigfnol.dll (Trojan.Agent) -> Delete on reboot.

C:\Windows\SysWOW64\pxaumeyigfnol.dll (Adware.AdRotator) -> Delete on reboot.

Link to post
Share on other sites

Did you install EzLife, or was it a drive-by download? Reboot/restart your computer and run Malwarebytes again.

Let me know if you are having anymore problems.

 

 

have no idea what ezlife is....must be a drive-by. I will run it again be back in a few, and thank you again.

Link to post
Share on other sites

have no idea what ezlife is....must be a drive-by. I will run it again be back in a few, and thank you again.

 

 

ok here is the new scan

 

Malwarebytes' Anti-Malware 1.45

www.malwarebytes.org

 

Database version: 3937

 

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

 

3/31/2010 2:08:57 PM

mbam-log-2010-03-31 (14-08-57).txt

 

Scan type: Quick scan

Objects scanned: 119380

Time elapsed: 4 minute(s), 8 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

(No malicious items detected)

 

Registry Values Infected:

(No malicious items detected)

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...