Came back to my laptop to find Firefox opened with a message telling me my PC has a problem and to click on the link to download a program to fix it. The web address is http://web.pastoralkb.com/c5/?secure=88AE1DF9732ECC11&puburl=&Section=D-firefox
Done a quick search but could find no clues. Anyone know about this and how to stop it?
it goes to some ad, win ipad and stuff, changes everytime you click it
Run AdwCleaner…click delete button…post log here
You find it here. http://forum.avast.com/index.php?topic=53253.0
Hello, i had the same problem, search under software about a zip program you have installed (you can see a symbol looks like a green house), remove it with the uninstall routine and it will be done. I found this in a forum, i think its better to remove the folder manually after deinstallation:
“I think I got it from a free unzipper I downloaded from Softonic. Norton and Norton power eraser did not detect it. I uninstalled the unzipper, as well as some “updater” that had come with it and now I think the problem is gone.”
“Anyhow, deleting the DSite directory and the scheduler entry seems to have stopped the popup message.” This message is from here: https://productforums.google.com/forum/#!mydiscussions/chrome/tr0bwDtHW0U
Hope it works…
Looks like the previous post had the right idea and AdwCleaner did the same thing.
Here’s the log it did for my computer which had the same issue opening up a web.pastoralkb.com tab and most recently a tab to way.clubsodanet.com/way/?astradslb…
AdwCleaner v2.303 - Logfile created 06/22/2013 at 18:27:26
Updated 08/06/2013 by Xplode
Operating system : Windows 8 (64 bits)
User : username
Boot Mode : Normal
Running from : C:\Users\username\Downloads\adwcleaner.exe
Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Users\username\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\windows\Tasks\DSite.job
Folder Deleted : C:\ProgramData\APN
Folder Deleted : C:\Users\username\AppData\Roaming\DSite
***** [Registry] *****
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\Software\InstallIQ
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
***** [Internet Browsers] *****
-\ Internet Explorer v10.0.9200.16537
[OK] Registry is clean.
-\ Mozilla Firefox v21.0 (en-US)
File : C:\Users\username\AppData\Roaming\Mozilla\Firefox\Profiles\3fspbhqr.default\prefs.js
Deleted : user_pref(“browser.search.defaultenginename”, “AVG Secure Search”);
-\ Google Chrome v27.0.1453.116
File : C:\Users\username\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\ Opera v12.15.1748.0
File : C:\Users\username\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
AdwCleaner[R1].txt - [1791 octets] - [22/06/2013 18:26:12]
AdwCleaner[S1].txt - [1750 octets] - [22/06/2013 18:27:26]
########## EOF - C:\AdwCleaner[S1].txt - [1810 octets] ##########