AdWare
Moderator: Wiz Feinberg
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
AdWare
My Kaspersky shows that I have the following
"Not-A-Virus: AdWare.Win32.Bromngr.b"
Any suggestions for Removal ?? when I google it it wants me to go to SpyWare.org 7 get a free scan.
I did download FireFox, & Babylon came with it.. Would that have done it??
"Not-A-Virus: AdWare.Win32.Bromngr.b"
Any suggestions for Removal ?? when I google it it wants me to go to SpyWare.org 7 get a free scan.
I did download FireFox, & Babylon came with it.. Would that have done it??
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
I download a new version of Firefox every month and not once has Babylon shipped with it. Where did you download Firefox from?
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
Golly Wiz I can't remember, I just typed in Firefox & a bunch came up & I downloaded it. Then Babylon came with it & when I tried to use Firefox or Chrome, Babylon came up all the time so I uninstalled Babylon, Firefox, & Chrome in add/remove programs..but now keeps telling me I have Not-a-Virus:AdWare.Win32.Bromngr.b
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
You have been scammed into downloading the browser from a rogue source. They have bundled adware with it, earning commissions for each installation.
If you have followed my previous posts concerning spyware, etc, you will be aware of Malwarebytes' Anti-Malware. You can download it and use it manually for free. See if it detects and offers to remove your adware.
If MBAM fails to detect the adware, try Ad-Aware, from Lavasoft. Ad-Aware is specifically made to look for ad serving PUPs (Potentially Unwanted Programs).
If you have followed my previous posts concerning spyware, etc, you will be aware of Malwarebytes' Anti-Malware. You can download it and use it manually for free. See if it detects and offers to remove your adware.
If MBAM fails to detect the adware, try Ad-Aware, from Lavasoft. Ad-Aware is specifically made to look for ad serving PUPs (Potentially Unwanted Programs).
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
This is no surprise, because MBAM is geared toward detecting real malware, not popup or search adware. Those items are usually less damaging than actual malicious software (malware).jolynyk wrote:Thanks Wiz. Yes I bought MBam, but it didn't remove it. I will run adaware.
If Ad-Aware doesn't detect the program, try Spybot S&D.
BTW: Have you looked in Control Panel > Add/Remove Programs to see if you can just uninstall the adware?
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Jolynyk;
Please download SuperAntiSpyware from http://www.superantispyware.com/. Install and update it then run a full scan. It may be necessary to reboot into Safe Mode, then run a second scan.
Furthermore, it is possible that this badware has been backed up in your System Restore folder. If this is the case, you'll need to turn off System Restore, then rescan for and remove the threat.
If this fails, Hitman Pro may do the trick. Contact me for details later on.
Please download SuperAntiSpyware from http://www.superantispyware.com/. Install and update it then run a full scan. It may be necessary to reboot into Safe Mode, then run a second scan.
Furthermore, it is possible that this badware has been backed up in your System Restore folder. If this is the case, you'll need to turn off System Restore, then rescan for and remove the threat.
If this fails, Hitman Pro may do the trick. Contact me for details later on.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Firefox contains a download manager with pause and resume functions.jolynyk wrote:Is there a download manager I can get that if a my download quits or hangs up, it will resume where the download left off, rather than start the download from the beginning again??
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Jolynyk;
I found the following files to be deleted on another forum. They are related to your adware/virus and should be deleted if found.
C:\Windows\tasks\At1.job
C:\Windows\tasks\At2.job
C:\ProgramData\x5tdXKBkN6o
I found the following files to be deleted on another forum. They are related to your adware/virus and should be deleted if found.
C:\Windows\tasks\At1.job
C:\Windows\tasks\At2.job
C:\ProgramData\x5tdXKBkN6o
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
Thanks Wiz, I really appreciate your help..
What is the procedure for me to find & remove those 3 items..
Incidentally, when I want to reply to these posts, it asks me for my name & password, I enter that & check the box to log me on automatically, but even if I come back every 5 minutes I have to re-enter everything. It doesn't remember my input..
Can you suggest a link for me to download Firefox from.. ??
What is the procedure for me to find & remove those 3 items..
Incidentally, when I want to reply to these posts, it asks me for my name & password, I enter that & check the box to log me on automatically, but even if I come back every 5 minutes I have to re-enter everything. It doesn't remember my input..
Can you suggest a link for me to download Firefox from.. ??
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Here's your Firefox link! http://www.mozilla.com/en-US/firefox/.jolynyk wrote:Thanks Wiz, I really appreciate your help..
What is the procedure for me to find & remove those 3 items..
Incidentally, when I want to reply to these posts, it asks me for my name & password, I enter that & check the box to log me on automatically, but even if I come back every 5 minutes I have to re-enter everything. It doesn't remember my input..
Can you suggest a link for me to download Firefox from.. ??
Your other browser must be optioned to not accept cookies or to not remember logins, or your credentials would remain in effect across sessions.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Then they are not on your PC. Out of curiosity, could you look up and list anything that is under your Tasks folder?jolynyk wrote:Thanks for the link Wiz.I can't find those 3 items to delete them.. will keep looking.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
Wiz, that stxmenumgr.exe says it's a FreeAgent Launcher...
AdAware.exe
adawarebp.exe
avp.exe
CameraHelperShell.exe
COCIManager.exe
csrss.exe
dwm.exe
EEvenManager.exe
explorer.exe
firefox.exe
FlashUtil32_11_5_502_11_ActiveX.exe
FUFAXSTM.exe
hkcmd.exe
hmpsched.exe
iexplore.exe
iexplore.exe
iexplore.exe
igfxpers.exe
igfxsrvc.exe
LWS.exe
sidebar.exe
Skype.exe
stxmenumgr.exe
SuperAntiSpyware.exe
taskhost.exe
taskmgr.exe
TeaTimer.exe
winlogon.exe
wuaudt.exe
[/b]
AdAware.exe
adawarebp.exe
avp.exe
CameraHelperShell.exe
COCIManager.exe
csrss.exe
dwm.exe
EEvenManager.exe
explorer.exe
firefox.exe
FlashUtil32_11_5_502_11_ActiveX.exe
FUFAXSTM.exe
hkcmd.exe
hmpsched.exe
iexplore.exe
iexplore.exe
iexplore.exe
igfxpers.exe
igfxsrvc.exe
LWS.exe
sidebar.exe
Skype.exe
stxmenumgr.exe
SuperAntiSpyware.exe
taskhost.exe
taskmgr.exe
TeaTimer.exe
winlogon.exe
wuaudt.exe
[/b]
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Tasks are found in C:\Windows\Tasks folder, as .job files. You can find the friendly names for tasks by navigating to Start > All Programs > Accessories > System Tools >>> Task Scheduler
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Look under you Program Files directory for a subdrectory that has a name that resembles your Adware. There must be either a .exe or a .dll files somewhere that gets launched to activate the adware.
With a folder name one can do further searches in one's Registry, to see which keys are used to launch this PUP.
With a folder name one can do further searches in one's Registry, to see which keys are used to launch this PUP.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
jolynyk
- Posts: 1295
- Joined: 22 Sep 2000 12:01 am
- Location: Prince Albert Sask. Canada