Review detected changes - continues to display same error

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I receive a notice that there has been a change, but even when I say to block
it, it keeps popping up with the same information, see below. I think the
entire file should be deleted, but the only option I have is to allow or
block. I started receiving the error yesterday.

I posted before about a problem with quick scan finding nothing, full scan
finding quite a few problems, but Defender not being able to delete them -
error 0x800040005 unspecified error. All the problems it finds are in
PestPatrol quarantine. Neither pest patrol or defender have been able to
remove them, and I am still getting a lot of pop-ups when I am online.

Anyone having any information or suggestions on how to solve this would be
most appreciated.

Thanks.

Summary:
System Configuration change occurred.

This agent monitors security related configuration changes made to Windows.

Detected changes:

Changed:
Original: 127.0.0.1 localhost sds-qckads.com status.qckads.com
www.qoolaid.com www.qoologic.com www.CLKPrecision.com www.urllogic.com
www.clkoptimizer.com www.isearch.com isearch.com www.idownload.com
idownload.com www.mytotalsearch.com mytotalsearch.com www.lop.com lop.com
www.websearch.com websearch.com www.page-not-found.net page-not-found.net
www.isearchhere.com isearchhere.com as.adwave.com sr.adwave.com
www.adwave.com adwave.com EVENT:HOST:127.0.0.1 www.pacimedia.com
www.exactsearch.net www.contextplus.net www.contextplus.net
www.contextplus.net www.contextplus.net www.contextplus.net
New: 127.0.0.1 localhost sds-qckads.com status.qckads.com
www.qoolaid.com www.qoologic.com www.CLKPrecision.com www.urllogic.com
www.clkoptimizer.com www.isearch.com isearch.com www.idownload.com
idownload.com www.mytotalsearch.com mytotalsearch.com www.lop.com lop.com
www.websearch.com websearch.com www.page-not-found.net page-not-found.net
www.isearchhere.com isearchhere.com as.adwave.com sr.adwave.com
www.adwave.com adwave.com EVENT:HOST:127.0.0.1 www.pacimedia.com
www.exactsearch.net www.contextplus.net www.contextplus.net
www.contextplus.net www.contextplus.net www.contextplus.net
www.contextplus.net


file (Changed):
@S-1-5-21-308160770-141380541-600855091-500\C:\WINNT\system32\drivers\etc\hosts

Advice:
Allow this configuration change only if you trust its origin. It is
recommended that you run a quick scan if you choose to block this change.
 
Have you tried having Pest Patol deleting those items in Safe Mode? If it
can, the run full scan with it and with Defender while still in safe mode.
 
Pest Patrol, Spybot and Defender - that is all....
I did finally get this one continual "change" fixed.

When I run a full scan in defender it shows OK
Pest Patrol and Spybot find 3 issues, but can not fix them
- Pest Patrol says they are in the registry and access is denied.
- Spybot says they may still be in use and can not be deleted - even when it
runs on restart.

I am still getting a lot of pop ups on the internet that did not use to
happen - any other ideas, or should I still try to run these programs in safe
mode to see if that will fix it?

Thanks!!!
 
Yes, you should try to run all the scans in safe mode. But it would be
helpful if you could post the names of the items that Pest Patrol and Spybot
are finding. Both those programs should list a name; it might be something
that requires a special removal tool. More info please!
 
Back
Top