Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Relatively new redirect virus

Help

  • This topic is locked This topic is locked

#31
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts

This is the scan log from superantispyware

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/12/2015 at 08:21 PM

Application Version : 6.0.1204
Database Version : 12011

Scan type       : Complete Scan
Total Scan Time : 00:59:15

Operating System Information
Windows 8 Professional 64-bit (Build 6.02.9200)
UAC On - Limited User

Memory items scanned      : 771
Memory threats detected   : 0
Registry items scanned    : 64623
Registry threats detected : 0
File items scanned        : 40828
File threats detected     : 70

Adware.Tracking Cookie
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\C1QHV6C4.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\C1QHV6C4.txt [ /ml314.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\1XC57LA3.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\1XC57LA3.txt [ /spotxchange.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\8OMB7R66.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\8OMB7R66.txt [ /turn.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\AZW9MPWI.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\AZW9MPWI.txt [ /pixel.rubiconproject.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\DX9H978W.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\DX9H978W.txt [ /www.googleadservices.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\8LAZPA9X.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\8LAZPA9X.txt [ /tap.rubiconproject.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\OZ8SV3HT.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\OZ8SV3HT.txt [ /sitescout.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\9B1B8058.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\9B1B8058.txt [ /eyereturn.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\47G0Y7HH.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\47G0Y7HH.txt [ /demdex.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\3OB652IF.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\3OB652IF.txt [ /iasds01.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\MR1FNJO0.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\MR1FNJO0.txt [ /mookie1.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\W6BFGO7P.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\W6BFGO7P.txt [ /casalemedia.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\SL4RKJJA.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\SL4RKJJA.txt [ /adnxs.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\XI1FOI2O.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\XI1FOI2O.txt [ /doubleclick.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\XLAS6GG2.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\XLAS6GG2.txt [ /adsymptotic.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\6K9KH3CG.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\6K9KH3CG.txt [ /openx.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\3LAN5DA3.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\3LAN5DA3.txt [ /a.scorecardresearch.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\613EXFRI.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\613EXFRI.txt [ /bidswitch.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\J1JFCWO6.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\J1JFCWO6.txt [ /ads.pubmatic.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\145MRX60.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\145MRX60.txt [ /revsci.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\LCE0VHIH.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\LCE0VHIH.txt [ /liverail.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\E1IUU1KU.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\E1IUU1KU.txt [ /dotomi.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\W7IHJCTT.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\W7IHJCTT.txt [ /collective-media.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\TQPUCL89.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\TQPUCL89.txt [ /dmtry.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\1IPENEDD.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\1IPENEDD.txt [ /domdex.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\KT01G7QQ.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\KT01G7QQ.txt [ /taboola.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\8AC0462E.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\8AC0462E.txt [ /ads.servebom.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\CGDMS6CC.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\CGDMS6CC.txt [ /mxptint.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\HIWCPUCY.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\HIWCPUCY.txt [ /skimresources.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\SMSYD2ID.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\SMSYD2ID.txt [ /at.atwola.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\IFWXW60J.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\IFWXW60J.txt [ /pro-market.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\X1G5P581.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\X1G5P581.txt [ /agkn.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\W5BNO3ZO.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\W5BNO3ZO.txt [ /go.sonobi.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\MHDE1J5W.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\MHDE1J5W.txt [ /addthis.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\UMWE75Q2.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\UMWE75Q2.txt [ /tubemogul.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\99MPMDWV.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\99MPMDWV.txt [ /comcastresidentialservices.tt.omtrdc.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\7KG1OCKL.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\7KG1OCKL.txt [ /kontera.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\KSLTVK3E.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\KSLTVK3E.txt [ /bluekai.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\JVUTYP90.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\JVUTYP90.txt [ /wtp101.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\0KRF3PTR.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\0KRF3PTR.txt [ /scorecardresearch.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\N9HUIGM1.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\N9HUIGM1.txt [ /pubmatic.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\TEJIDVWL.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\TEJIDVWL.txt [ /convertro.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\Y529299B.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\Y529299B.txt [ /mathtag.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\LUSNXBWA.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\LUSNXBWA.txt [ /sp1.convertro.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\LHBEJ0BP.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\LHBEJ0BP.txt [ /adadvisor.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\EO9KAOXK.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\EO9KAOXK.txt [ /intentiq.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\7RPXUL7T.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\7RPXUL7T.txt [ /rubiconproject.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\3R54QXKD.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\3R54QXKD.txt [ /crsspxl.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\UEK75YAG.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\UEK75YAG.txt [ /pix.btrll.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\9XUPS60V.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\9XUPS60V.txt [ /cdn.turn.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\JJ971SUL.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\JJ971SUL.txt [ /gravity4.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\OS3GJLF3.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\OS3GJLF3.txt [ /w55c.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\6U9RHHHN.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\6U9RHHHN.txt [ /imrworldwide.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\ODR831N7.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\ODR831N7.txt [ /dmp.springserve.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\BYOFKREA.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\BYOFKREA.txt [ /dpm.demdex.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\39RNR7SF.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\39RNR7SF.txt [ /comcast.demdex.net ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\4OLWEEGW.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\4OLWEEGW.txt [ /chango.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\VNE8H73Z.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\VNE8H73Z.txt [ /btrll.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\117P8RUB.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\117P8RUB.txt [ /rhythmxchange.com ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\BPRPB4PW.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\BPRPB4PW.txt [ /adsrvr.org ]
 C:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\GQY2U4DD.txtC:\Users\poppag\AppData\Local\Microsoft\Windows\INetCookies\Low\GQY2U4DD.txt [ /simpli.fi ]
 .addthis.com [ C:\USERS\POPPAG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
 .addthis.com [ C:\USERS\POPPAG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
 .addthis.com [ C:\USERS\POPPAG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
 .addthis.com [ C:\USERS\POPPAG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
 .addthis.com [ C:\USERS\POPPAG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
 .addthis.com [ C:\USERS\POPPAG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
 .scorecardresearch.com [ C:\USERS\POPPAG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
 .scorecardresearch.com [ C:\USERS\POPPAG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
 .yadro.ru [ C:\USERS\POPPAG\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]

============
 End of Log
============


  • 0

Advertisements


#32
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
I also did a complete text search on http://www.you-home-page.netwith text crawler. Found nothing
  • 0

#33
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
I think this hack is a derivative of 4-you.net, and believe that name appeared in the url box early in the game, if this helps
  • 0

#34
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Are you there Joe?
  • 0

#35
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,806 posts
Yes. Just got in from late day at work.

What does superAntispyware say (Windows 8 Professional 64-bit (Build 6.02.9200))?
  • 0

#36
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
The report is above. Nothing significant though and the problem persists. Also ran zoek and did extensive text searches (see above)
  • 0

#37
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,806 posts
OK.

I'm looking at the logs now....
  • 0

#38
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
I just added http://www.your-home-page.netas a restricted site in the IE tools area. I had done this previously but thought I'd try it again. Unfortunately I have to give up for the day again. Appreciate your help and persistence. Leave a post If you have anything for me to try tomorrow.
Thanks
  • 0

#39
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,806 posts
I will leave a post for you. Still looking over logs.

Thanks
Joe :)
  • 0

#40
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,806 posts
A few items to fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
 
start
CloseProcesses:
CreateRestorePoint:
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2317217915-3030507882-558724183-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Task: {23E48B97-D27C-4CCD-9CC7-5ED99632C642} - System32\Tasks\{01F14956-5EF2-470B-869E-5B4526D24703} => pcalua.exe -a C:\Users\poppag\AppData\Roaming\VOPackage\Uninstall.exe
C:\Users\poppag\AppData\Roaming\VOPackage
2015-07-27 13:33 - 2015-07-27 13:33 - 00001977 _____ C:\Users\poppag\AppData\Roaming\Microsoft\Windows\Start Menu\Gaosuo.lnk
2015-07-27 13:33 - 2015-07-27 13:33 - 00001971 _____ C:\Users\poppag\AppData\Roaming\Microsoft\Windows\Start Menu\videos.lnk
2015-07-27 13:33 - 2015-07-27 13:33 - 00001953 _____ C:\Users\poppag\Desktop\Gaosuo.lnk
2015-07-27 13:33 - 2015-07-27 13:33 - 00001947 _____ C:\Users\poppag\Desktop\videos.lnk
2015-07-27 13:33 - 2015-07-27 13:33 - 00000000 ____D C:\Users\poppag\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gaosuo
2015-07-27 13:32 - 2015-07-27 13:33 - 00000000 ____D C:\Program Files (x86)\Gaosuo
2015-07-27 13:32 - 2015-07-27 13:32 - 00000000 ____D C:\WINDOWS\Gaosuo
2015-07-27 13:23 - 2015-07-27 13:23 - 00000000 ____D C:\Users\poppag\AppData\Roaming\Friendly Cactus
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
Emptytemp:
Click Format and ensure Wordwrap is unchecked.
Save as Fixlist.txt to your Desktop (Must be in this location)
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.
 
Next

1. Router Reset:
Reset the router to its default configuration. This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).

2. Reset the IP/DNS settings of your internet connection:
  • Go to Start -> Control Panel -> Double click on Network Connections.
    Right click on your default connection (usually Local Area Connection or Wireless Network Connection) and select Properties.
  • Select the General tab.
  • Double click on Internet Protocol (TCP/IP).
  • Under General tab:
  • Select "Obtain an IP address automatically".
  • Select "Obtain DNS server address automatically".
  • Click OK twice to save the settings.
  • Reboot if you had to change any setting.
Thanks
Joe
  • 0

Advertisements


#41
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts

Joe - the last suggestions did not resolve the problem BUT I did notice one change.  It appeared as if my default home page (google) flashed briefly before the redirect happened.  It was as if the last suggested changes set the machine properly, yet the hijack reinstated itself.  Could be nothing but I'm grasping at straws.  Not sure if you are available today but will check back after 4 est and if not again monday


  • 0

#42
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts

Tried the latest version of Hitman pro.  Nothing


  • 0

#43
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,806 posts
What other browser do you have installed ? Can you try another browser ?
  • 0

#44
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts

The laptop now refuses to boot properly after I tried to boot in safe mode.  Will try a boot disk and let you know what happens


  • 0

#45
doctordotcalm

doctordotcalm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts

I just tried Firefox.  No redirection  Yay!


  • 0






Similar Topics


Also tagged with one or more of these keywords: Help

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP