ib.adnxs.com ?

Thanks. I wish they’d stop changing their formats though - i used Malwarebytes for years without any problem at all.

Hi,

Am still getting http://ib.adnxs.com/ which opens multiple windows of adverts on my pc. How can I get rid of it please?

Thanks again.

Looks like you need to run adwcleaner and if it still appears we can go for a manual cleanup

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

If you bought it before version 2, you will have will always have the lifetime license forever.

OK thanks. File attached. No sign of adnxs though - this bug has attached itself to my IP browser I think which is AOL, I don’t recall seeing it pop up on Chrome or Firefox

So it is on the AOL branded IE only ??

Download OTL to your Desktop
Secondary link

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif

[*]Select All Users
[]Select LOP and Purity
[
]Under the Custom Scan box paste this in

netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir “%systemdrive%*” /S /A:L /C
/md5start
rpcss.dll
/md5stop
CREATERESTOREPOINT

[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs

Thanks :slight_smile:

For some reason I didn’t get notified of your reply.

Anyway, here are the files.

Please advise further -

AV

Let me know if it still appears after this

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKU\S-1-5-21-3183433093-2047692126-102195025-1001\..\SearchScopes,DefaultScope = {151D2E4E-0B8C-4D94-87FB-78C43EE3CED1}
O3:64bit: - HKLM\..\Toolbar: (no name) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [] File not found
[2014/04/21 13:50:50 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2014/04/20 20:29:48 | 000,000,000 | ---D | C] -- C:\Users\Ric\AppData\Local\{FE545A5E-2080-4012-B979-E4B3A8CDC2CA}
[2014/04/19 20:03:18 | 000,000,000 | ---D | C] -- C:\Users\Ric\AppData\Local\{85524F23-C5A5-44CF-8CFE-57B436C9EA0F}
[2014/04/06 20:20:11 | 000,000,000 | ---D | C] -- C:\Users\Ric\AppData\Local\{F8EEB722-2679-4750-BA3D-52284B0F073A}

:Commands
[resethosts]
[emptytemp]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

OK will update - thanks :slight_smile:

Thanks again,

ib.adnxs vanished so I have left it at that :slight_smile:

Had another bout :o here are the logs, thanks (attached) -

Any further advice please?

If I were you I’d ask myself: Why am I repeatedly getting infections?

Do you feel you’re saving money by repeatedly battling infections instead of putting tools in place that will prevent them and potentially changing your computer usage habits?

-Noel

Don’t know. Adnxs appeared after I opened a reply from another forum - Dell Community - no idea what’s causing this. Can you be a little more precise in terms of tools to prevent adnxs and computer usage habits please? Many thanks.

It’s hard to recommend specifics to others, because there is much context involved, but in broad strokes, here’s what I do… Whether you want to try to do similar things is up to you.

  1. Use the MVPS hosts file to block the name resolution of tens of thousands of parasite web sites. This also has the welcome side effect of blocking most ads. Not even allowing most badware to get near your computer is a good first line of defense.

  2. Reconfigure Internet Explorer to not run ActiveX, and while allowing scripts lock down the facilities the scripts can use. Ads running their ActiveX are a big source of malware.

  3. Go through your Internet Explorer Add-Ons and disable those you don’t know you need.

  4. Practice good habits, including not downloading handy toolbars, cleaners, etc. that are more likely to cause problem than to help with anything.

  5. Make sure Avast is on task and in good working order. It’s my understanding that with the Avast Shields in place (and no exclusions) people just don’t get very many infections. But note: This is a safety net, nothing more. Steps 1-4 above are the real things that will keep you safe.

This is just my recommendation. I’m sure there are others here who would recommend other approaches as well.

-Noel

By the way, go through the Avast settings with a fine tooth comb. There are a lot of things (like the thoroughness of scans) that can be strengthened. Avast tries to strike a balance between efficiency and protection.

-Noel

1. Use the MVPS hosts file to block the name resolution of tens of thousands of parasite web sites. This also has the welcome side effect of blocking most ads. Not even allowing most badware to get near your computer is a good first line of defense.
or setting up your router with OpenDNS would be easier
2. Reconfigure Internet Explorer to not run ActiveX, and while allowing scripts lock down the facilities the scripts can use. Ads running their ActiveX are a big source of malware.
how to do it http://blogs.norman.com/2014/for-consumption/securing-your-browser-internet-explorer

Sorry, but saving a single file in a single location on your computer is hard to beat for ease of application.

-Noel

does it not have to be updated? … something you dont have to think about with OpenDNS

anyway, some like this and some like that

OK, I stand educated - thank you, Pondus. Adding a couple of DNS addresses to the router configuration turned out to be quite easy. Still, I think it’s easier to download and save a file, but only a little. :slight_smile:

I see no reason not to use them both. :slight_smile:

-Noel

Many thanks, Noel,

I shouldn’t think Avast would pick up adnxs because it does not appear to be a virus. I am surprised Malwarebytes hasn’t listed adnxs as at the very least a PUP but they obviously have not - Malwarebytes never picks up on adnxs when it invades my AOL browser.

Adnxs is authored by a data collection company called AppNexus. It is a stealth ‘web beacon’ and the unsuspecting web surfer picks it up visiting the Internet.

Adnxs may be a cookie - I have deleted all the cookies in AOL but analogous to a virus adnxs has always bounced back with altered pre- and/or suffix, I mean it changes its shape everytime I block it. In the past an OTL scan has seen it off but not this time. My guess is that adnxs also hides under other names.

Maybe someone should take AppNexus to court over this issue, if nothing more it is an unwarranted invasion of privacy. I am pretty certain a court action would stop the proliferation of adnxs in its tracks - it is not a robot - it is being deliberately sent out by AppNexus.

http://www.theguardian.com/technology/2012/apr/23/adnxs-tracking-trackers-cookies-web-monitoring