Recently I've been getting redirected to this clearly bogus site and a thorough Google search has led me to believe this is a virus. I've experience it on both Chrome and Firefox. I've done multiple malware/virus searches and it's still happening.

Any and all advise will be greatly appreciated.

I apologize, here are the requested logs.


Welcome to the forum.

Please remove any usb or external drives from the computer before you run this scan!

Please download and run RogueKiller.

For Windows XP, double-click to start.

For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Click Scan to scan the system (don't run any other options, they're not all bad!!!!!!!)

Post back the report.


OK, that scan looks OK, please do this.........

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.


If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.


As a novice with these sorts of programs, I seem unable to get ComboFix to work properly. Is there something else I could run?

What particular problems are you having??

ComboFix is very easy to run. MrC

It's giving me error messages repeatedly and since I'm not accustomed to using these types of programs I'm afraid for my computer. The culprit shows up on the first log "C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe".

OK, do this instead......

Please download OTL from one of the links below: (<---renamed version)

Save it to your desktop.

Double click on the icon on your desktop.

Click the Scan All Users checkbox.

Push the Quick Scan button.

The scan will take about 10 minutes...depends on your hard drive size.

Two reports will open, copy and paste them in a reply here: (or attach them as .txt files)

OTL.txt <-- Will be opened

Extra.txt <-- Will be minimized


Please do this..............

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

4. If ComboFix wants to update.....please allow it to.


uStart Page = hxxp://


C:\ProgramData\blekko toolbars



Save this as CFScript.txt, in the same location as ComboFix.exe


Refering to the picture above, drag CFScript into ComboFix.exe

CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

After reboot, (in case it asks to reboot)......

Please provide the contents of the ComboFix log (C:\ComboFix.txt) in your next reply.


Please do this:


  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    FF - "Blekko"
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O3 - HKU\S-1-5-21-2021167427-2316871478-3002587922-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    IE - HKU\S-1-5-21-2021167427-2316871478-3002587922-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
    [2012/06/16 21:25:34 | 000,000,000 | ---D | C] -- C:\Users\Alicia\AppData\Local\blekkotb_031
    C:\ProgramData\blekko toolbars
    C:\ProgramData\blekko toolbars

  • Then click the Run Fix button at the top
  • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
  • Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


I've done as requested but now it's saying that my Window's Security Center cannot be turned on. What did this removal do to my Security settings for Windows? I'm slightly worried now.


Security Center doesn't show up on that list. All I see is Security Accounts.

Please download Farbar Service Scanner and run it on the computer with the issue.

  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update

    [*]Press "Scan".

    [*]It will create a log (FSS.txt) in the same directory the tool is run.

    [*]Please copy and paste the log to your reply.


Download wscsvc.reg from the link below:


Double click on it or right click on it and choose "Run as Administrator" and allow it to merge into the registry.

Reboot and run another FSS scan.


Thank you so much! I genuinely appreciate it. Does this mean that the domain advisor garbage is gone? I checked and it's no longer in that folder.

Also, does that mean it's safe to download Chrome again?

Yes, go a head and use it, let me know how it is, MrC

I'll probably give Chrome about a day or so then I'll be back. Thank you so much for your help <3

