Browser redirects after MoneyPak even after scans

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MSSmallBiz, Aug 7, 2013.

  1. MSSmallBiz

    MSSmallBiz Private E-2

    I've ran every cleaner there is to run. Malwarebytes, TDSSKiller, FixTDSS, Roguekiller, SuperAntispyware, eset online, MS Defender Offline, MS Malicious full, aVast boot and CD boot, the list goes on. I have removed a host of things like ShopAtHome, checked Process Explorer and Autoruns. Proxy and host checked. TCP stack reloaded.

    User had Moneypak. After removal browsers are still redirected. IE will crash on load however will run in Admin mode or after resetting security settings then on next run it crashes again.

    MGLogs attached, what else do you need? Darn if I see what's doing the redirection.
     

    Attached Files:

  2. MSSmallBiz

    MSSmallBiz Private E-2

    more
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like to see logs from Malware Bytes, RogueKiller and Hitman Pro please.

    Also... [​IMG] Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )
     
  4. MSSmallBiz

    MSSmallBiz Private E-2

    JRT running now, will search for Rogue logfile, may have to re-run it. Attached are HitMan and Malwarebytes.

    I also ran F-Secure's MBR Root Kit Boot CD, again nothing found. Tried running Hitman Kick but after 6 hours it really just seemed to be sitting there. It said it was still scanning but the drive was only being accessed once every few minutes.
     

    Attached Files:

  5. MSSmallBiz

    MSSmallBiz Private E-2

    JRT found something that may have fixed the bulk of this, still testing. Initial browsing was better however IE still crashes on opening. Run the MS FixIt to reset the browser which turns off Protected Mode and IE runs but let it turn Protected Mode back on and it crashes before a page can load which tells me something is still hooked into it. Running more scans now.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like to see the logs from RogueKiller and JRT please.
     
  7. MSSmallBiz

    MSSmallBiz Private E-2

    Got the machine stable finally however it was returned with a warning that at the level it was infected we do not trust this machine to be either stable or secure going forward and suggest a wipe and load with a low level disk wipe. Up to the end use at this point to make the call.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So you didn't really need my help at all then?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds