Opera browser hijacked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Needahandovahere, Aug 25, 2015.

  1. Needahandovahere

    Needahandovahere Private E-2

    Hello. My friend told me his computer was hijacked, and I told him to install mbam. He said the first run it found over 1k things on his computer. (I cannot find the log for that first run though) A month later, he asked me to come look at it. I honestly don't know what is wrong, but Norton Anti-virus isn't finding anything, and the browser is still very hijacked.

    The first time MGTools ran, it froze on the net stat program. The second time it finished.

    Please help if you could. Thank you.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Run HitmanPro again and activate the 30 day trial license. Then allow it to remove all the Malware, Malware remnants, and Potential Unwanted Programs that it found. Reboot immediately after removing these items with Hitman. After reboot, run a new scan with Hitman Pro and attach the new log.

    Uninstall the below software:
    Trust Media Viewer
    videos MediaPlay-Air
    WSE_Astromenda


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the new Hitman Pro log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. Needahandovahere

    Needahandovahere Private E-2

    Thank you Chaslang for your years of service here at majorgeeks.

    I tried to uninstall these but they were unable to find files necessary to uninstall.
    Trust Media Viewer
    videos MediaPlay-Air

    I could not find this to uninstall.
    WSE_Astromenda

    The browser is still popping up with ads, and at the bottom corner of the browser I can see that it is still sending and receiving data to a ton of junk ad servers.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Goto your Settings in Opera and under Websites, use the Manage individual plug-ins... command to see what plugins are installed an disable any that you do not recognize. See if this helps. Also check to see that what setting you have for allowing popups. It should be
    Do not allow any site to show pop-ups (recommended)

    Also run the below.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  5. Needahandovahere

    Needahandovahere Private E-2

    Chaslang thank you!

    It was a browser extension. I made a screenshot of the name of it, although it simply looks like it is a random generated named.

    It looks like everything works fine now. Thank you so much!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. Needahandovahere

    Needahandovahere Private E-2

    Hey Chaslang,

    After browsing returned to normal, I restarted the computer, re-scanned with mbam, and after nothing came up, started up windows update.

    There were a ton of updates needed, and the updates would never download (as I monitored the status of the internet connection up and down), and the hard drive would go wild like the computer was creating its own update or something.

    I tried a few simple fixes, then came to majorgeeks and downloaded the "complete Tweaking.Com Windows Repair" program, and started that. While using it, I found that on this computer, my friend's son had downloaded a jail break program for iphone. I had an experience with someone using an old computer of mine to use a similar program, and it ended up installing some type of rootkit that ended up taking over the computer, so I know the authors of those programs intend users to run it so they can take control of the phone, and root the computer they ran it on too.

    The windows update program kept finding that a few certain directories were continually trying to remove themselves as actual connections, and something was replacing them with other directories.

    Is there anything in the logs that might help to limit or remove that stuff from a computer?

    I will update tomorrow as to how the repair went.

    Thanks again!

    I will also tell my friend to do a donation for your assistance.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really don't understand what you are trying to say here. Directories are not connections? Directories are just a special form of a file that can contain other folders and files.

    There are no remaining signs of any problems.
     
  9. Needahandovahere

    Needahandovahere Private E-2

    Sorry I wasn't specific. Tweaking.com - Windows Repair has a 'Repair Resparce Points' fixit tool, and there were points that weren't repairing. I managed to fix it by simply deleting the directory that was doing it.

    Windows Update is broken. I am running hotfix KB947821 to try and clean it all up.

    But everything else seems to be doing good now.
     
  10. Needahandovahere

    Needahandovahere Private E-2

    Hey Chaslang. I was running that windows update fix, and decided to run roguekiller again. It found some more stuff. Hitman didn't find anything though.

    Windows Update finally popped a bubble from the taskbar saying there are updates to download, but the windows update window is still searching for updates endlessly.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No, not really. Those are not problems.

    You should just wait to see what it comes up with. Any further issues related to Windows Update should be discussed in the Software Forum but you may want to try uninstalling Norton Antivirus and see if anything changes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds