Occasional redirect post-cleanup from severe infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by landmouse, Mar 13, 2014.

  1. landmouse

    landmouse Private E-2

    A laptop was brought to me with malware with install dates as far back as 2009. These include but are not limited to: Conduit, Snap.do, AnyProtect, Driver Support, SpeedUpMyPC, and ARO 2012. I have cleaned with CCleaner, Malwarebytes, Spybot S&D, SuperAntiSpyware, and Avira Free with high heuristics, manually deleted many leftover files and folders, deleted startup entries and tasks that were scheduled, fixed the MBR via the recovery console, and removed addons from IE and Chrome.

    I was still seeing occasional redirect in Chrome, especially when searching for technical information - perhaps 1 in 4 searches - so I followed the directions here for Chrome redirects. It redirected again, so I followed the regular malware directions, and the logs are posted below. Thank you in advance for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First, let's have you rerun Hitman and remove everything it found. Reboot and rescan and attach the new log. Be sure to tell me if things improve.
     
  3. landmouse

    landmouse Private E-2

    The gentleman needed his laptop back this morning, unfortunately, so I no longer have access. However, I think the problem has been solved. I'll post the procedures I followed for your feedback and so that any that come after me might benefit.

    I got up at 5am and reran HitmanPro again (just because I'm anal like that) and found that 2 pieces of malware had recovered themselves. :banghead I removed everything this time, rebooted, then ran MBAM's full scan which came back clean. After reading through the forums here a bit more deeply, I DLd and ran JRT and ADWCleaner, each of which found quite a bit more to remove. I let them do their cleanups, rebooted, ran HitmanPro and RogueKiller again (the only 2 programs that found any problems to begin with), and everything came back shiny. I also deleted Chrome, manually removed the leftovers, and re-installed the latest version.

    I made approx. 20 tech-related searches and there were no more redirects, so hopefully everything is gone for good. Thank you to you and everyone else here who gives their time to help out folks like me.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds