Skip to main content

malware keeps opening new tabs

  • September 9, 2015
  • 4 replies
  • 84 views

Have this malware that keeps opening new tabs, randomly. 
 
one was betrad, and the other one was something else,  s.arlime.com  or something
for the betrad, from my research it was in the flash cache which i cleared.     Still getting new tabs. 
 
Full scan with webroot, nothing
I spent 8 hours per one scanning with malwarebytes and  adaware and spyware searchu and destroy ... Nothing.
 
I tried watching the webroot logs on chrome,  So I clicked on a link from skype. 
there was a bunch of dlls sent to chrome and the new tab opened from skype.
 
So i'm not sure how to follow those event logs.   I tried searching with the process id, but none of the numbers were from skype.
Nothing looks funny in the process list, and services.msc     Is there anyway to track this thing down, so I can submit it to webroot? 
usually malware is pretty obvious, but this one is probably super new...   
 
 
The issue is, it opens up new tabs randomly at random times...    And then webroot will tell me that the pages have been blocked.    Like i'll be playing a game and it'll popup.       
 
It would be nice to figure this out before I re-install windows.   :) 

4 replies

Ssherjj
Moderator
Forum|alt.badge.img+62
  • Moderator
  • 21900 replies
  • September 9, 2015
Hello ?,
 
i would think the the best thing would be to submit a support ticket so they can check your logs for you and see what is going on.
 
Submit a ticket before reinstalling don't you think?
 
Regards,

  • 1 reply
  • September 9, 2015
{Edited}hen check your DNS settings for static addresses. (Network and Sharing Center > Change Adapter Settings > Local Area Connection [for ethernet] or Wireless > IPv4 settings. Make sure there are no numbers entered in the boxes and the "Automatic" setting is enabled). I've seen a lot of these coming around lately. 
 
{Edited} may help as well.
 
This post has been edited per Community Guidelines.  Other malware products are not allowed to be advertised or suggested.  In cases like this, a Trouble Ticket should be made to allow Webroot Support to assist with removal.  shorTcircuiT

shorTcircuiT
Gold VIP
  • Gold VIP
  • 7721 replies
  • September 9, 2015
Before changing ANY settings, please check with your ISP.  Although rare these days, some ISP's DO still use static settings and changing these as noted above may cause more problem than it solves.
 
The best thing is as noted by ? and to Submit a Trouble Ticket.

  • Author
  • Popular Voice
  • 172 replies
  • September 10, 2015
@ wrote:
{Edited}hen check your DNS settings for static addresses. (Network and Sharing Center > Change Adapter Settings > Local Area Connection [for ethernet] or Wireless > IPv4 settings. Make sure there are no numbers entered in the boxes and the "Automatic" setting is enabled). I've seen a lot of these coming around lately. 
 
{Edited} may help as well.
 
This post has been edited per Community Guidelines.  Other malware products are not allowed to be advertised or suggested.  In cases like this, a Trouble Ticket should be made to allow Webroot Support to assist with removal.  shorTcircuiT
I'm currently using google dns  8.8.8.8 and 8.8.4.4
 
i'll post a ticket here in a minute. 
 

Reply