ATDMT Redirect Removal/Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bullitt_390, Jul 24, 2011.

  1. Bullitt_390

    Bullitt_390 Private E-2

    HI All,

    I have recently come up against this and am at a loss as to how to remove it, not through lack of trying however.

    It manifests itself as a redirect, e.g. I wanted to buy some travel insurance from Tesco, Googled it, clicked on the top link and was presented with a new tab entitled: "atdmt.com" which is a blank page.

    I have tried Lavasofts Adaware, Spywareblaster, SpyBOT S&D, SuperAntiSpyware and my fully updated AVG Anti Spyware tool.

    AVG actually found some instances of atdmt and removed them, but the issue still exists.

    I am now working through this thread: http://forums.majorgeeks.com/showthread.php?t=35407

    and have started the "Fixing Google Redirection/Hijacking problems thread (which I'm guessing my problem is??).

    In the redirection thread, the first step is flushing the Java cache. I have a new laptop and am new to Windows 7 and cannot find Java. Is it possible I don't have it installed yet? Anyway, I've carried on with the thread instructions and gotten to the MBR part. TDSSKILLER didn't find anything.

    The MBR log seemed to find something, so I attach the log.

    Can anyone assist me with the next steps for removing this, please?

    Many thanks in advance,
    B
     

    Attached Files:

  2. Bullitt_390

    Bullitt_390 Private E-2

    After working through the Windows 7 cleaning thread, I have been able to run MGTools and provide the attached logs from that.

    Combofix would not run because I have AVG installed and I am loath to uninstall that just yet.
    I'm know I'm supposed to do each and every step, but I don't want to start uninstalling things just in case one of the previous logs gives details of my problem and is able to fixed.

    Thanks for looking at this guys, I appreciate it.

    B
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go here and download the Win7 Recovery Console. Once you have created the disc, boot to the bios and make your cd/dvd player the first boot device. Reboot with the disc in the drive.

    Once you get into the Recovery Console, go to the Command prompt and type this:
    Bootrec.exe /fixmbr

    Exit and reboot into normal mode and re-run MBRCheck. Attach the new log.
     
    Last edited: Jul 24, 2011
  4. Bullitt_390

    Bullitt_390 Private E-2

    Tim, thank you very much for your prompt reply.

    I have done this and attached the report.

    Thank you again.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good job!! ;)

    Your MBR is fixed now. Tell me if you are still having issues.
     
  6. Bullitt_390

    Bullitt_390 Private E-2

    Still having the same problem unfortunately :-(

    Also, what is MBR?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MBR is Master Boot Record.

    I think it is now time for you to download ComboFix to your desktop, uninstall AVG and run Combo.

    Please go here and download and run the AVG Removal Tool

    Then also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  8. Bullitt_390

    Bullitt_390 Private E-2

    Thanks for your time so far, Tim.

    I've done all that and attached the MG log file.

    Thanks again, this is much appreciated.

    B
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run Combo? It should have been included in your MGLog.zip.

    Go to start / run and type:
    %temp%
    Delete all it finds.

    click start menu/select run/type regedit in search box/click on my computer to highlight it/on the menu at top of page click edit/scroll down to find and click it/type atlassolutions in the search box/in the menu that appears you will see a folder named atlassolutions.com/click on this and the values show up on the right side of the page/double click on each value shown and delete the values that show up in the box that comes up/when you finish this go back to the folder atlassolutions in the left column right click on it and select delete

    you will also see a folder above it named atdmt/deleted its values in the same manner and then delete the atdmt folder. prest, gone.

    Attach the Combo log in your next reply as well as logs for SAS and MBAM>
     
  10. Bullitt_390

    Bullitt_390 Private E-2

    Tim, I did run Combo - it produced its own report but I will run it again once I've reinstalled SAS and MBAM.

    I also deleted everything I could from the temp folder, but there were 3 things I couldn't delete. Screen dump attached FYI.

    There are no entries for atlassolutions in the registry - I tried to find these before coming to this forum (the instructions you provided were, word-for-word, the ones I originally used!).

    I will carry on with the instructions (SAS, MBAM and Combo) tomorrow.

    Tim, thank you very much for your time thus far.

    B
     
  11. Bullitt_390

    Bullitt_390 Private E-2

    Didn't realise the screendump had exceeded the limit.

    Now compressed and attached.
     

    Attached Files:

  12. Bullitt_390

    Bullitt_390 Private E-2

    Ok, I have now run SAS, MB and Combo.

    Logs attached.

    The issue still remains unfortunately.

    Thanks Tim.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are basically clean. But let's try doing this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Tell me how things are running.
     
  14. Bullitt_390

    Bullitt_390 Private E-2

    Tim, I have done what you've asked and.....


    ..... THE PC SEEMS TO BE FIXED!!!!!!!!!!!!!!!!

    I cannot thank you enough for this. I will certainly be donating to the website based on the help that Ive received.

    You guys - and you specifically, of course - are legends for what you do.

    Thank you.
    Thank you.
    Thank you!!

    I am currently reading the "How to protect yourself from malware" thread...

    Tim, thank you again.

    What did that last registry process do by the way? Just curious!
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It reset your defaults. Good to know it is working well now.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds