system
1
Came back to my laptop to find Firefox opened with a message telling me my PC has a problem and to click on the link to download a program to fix it. The web address is http://web.pastoralkb.com/c5/?secure=88AE1DF9732ECC11&puburl=&Section=D-firefox
Done a quick search but could find no clues. Anyone know about this and how to stop it?
Pondus
2
it goes to some ad, win ipad and stuff, changes everytime you click it
Run AdwCleaner…click delete button…post log here
You find it here. http://forum.avast.com/index.php?topic=53253.0
system
3
Hello, i had the same problem, search under software about a zip program you have installed (you can see a symbol looks like a green house), remove it with the uninstall routine and it will be done. I found this in a forum, i think its better to remove the folder manually after deinstallation:
“I think I got it from a free unzipper I downloaded from Softonic. Norton and Norton power eraser did not detect it. I uninstalled the unzipper, as well as some “updater” that had come with it and now I think the problem is gone.”
“Anyhow, deleting the DSite directory and the scheduler entry seems to have stopped the popup message.” This message is from here: https://productforums.google.com/forum/#!mydiscussions/chrome/tr0bwDtHW0U
Hope it works…
system
4
Looks like the previous post had the right idea and AdwCleaner did the same thing.
Here’s the log it did for my computer which had the same issue opening up a web.pastoralkb.com tab and most recently a tab to way.clubsodanet.com/way/?astradslb…
AdwCleaner v2.303 - Logfile created 06/22/2013 at 18:27:26
Updated 08/06/2013 by Xplode
Operating system : Windows 8 (64 bits)
User : username
Boot Mode : Normal
Running from : C:\Users\username\Downloads\adwcleaner.exe
Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Users\username\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\windows\Tasks\DSite.job
Folder Deleted : C:\ProgramData\APN
Folder Deleted : C:\Users\username\AppData\Roaming\DSite
***** [Registry] *****
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\Software\InstallIQ
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
***** [Internet Browsers] *****
-\ Internet Explorer v10.0.9200.16537
[OK] Registry is clean.
-\ Mozilla Firefox v21.0 (en-US)
File : C:\Users\username\AppData\Roaming\Mozilla\Firefox\Profiles\3fspbhqr.default\prefs.js
Deleted : user_pref(“browser.search.defaultenginename”, “AVG Secure Search”);
-\ Google Chrome v27.0.1453.116
File : C:\Users\username\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\ Opera v12.15.1748.0
File : C:\Users\username\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
AdwCleaner[R1].txt - [1791 octets] - [22/06/2013 18:26:12]
AdwCleaner[S1].txt - [1750 octets] - [22/06/2013 18:27:26]
########## EOF - C:\AdwCleaner[S1].txt - [1810 octets] ##########