Unable to remove maleware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by theremotedr, Oct 5, 2015.

  1. theremotedr

    theremotedr Master Sergeant

    My homepage has been taken over by ESURF.BIZ
    I have tried to remove /clean it using the following but shown all ok ?
    Avg
    Avast
    Malwarebytes anti malware
    Jrt
    Hitmanpro
    Adwcleaner

    Restarted pc but still loads as home page.
    Please advise steps to remove this.

    Thanks
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What browser are you using? You may just have to reset it to defaults.
     
  3. theremotedr

    theremotedr Master Sergeant

    Hi,
    I am using Firefox.
    I did refresh it on the troubleshooting page but still the same.
     
  4. theremotedr

    theremotedr Master Sergeant

    Just an update.
    The address url changes every now & then so its not just Esurf.biz
    I have run Spy Hunter and it has found a number of items.
    In order to delete them you must purchase the full package.
    So i have taken screen shot of their findings.
    Hope this will help & point you in the right direction.
    I am using Win 7 32 bit with Firefox

    http://i670.photobucket.com/albums/vv62/ipbr21054/FORUM POSTS/mw1.jpg

    http://i670.photobucket.com/albums/vv62/ipbr21054/FORUM POSTS/mw2.jpg

    http://i670.photobucket.com/albums/vv62/ipbr21054/FORUM POSTS/mw3.jpg

    http://i670.photobucket.com/albums/vv62/ipbr21054/FORUM POSTS/mw4.jpg
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the requested logs.

    In the meantime:

    [​IMG] Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  6. theremotedr

    theremotedr Master Sergeant

    Hi,
    Here is the 2 log files requested.
    Jrt would not run as admin so just double cliked on it.
    The other was run on admin no problem.

    Looking at the logs i see Jzip of which i use.
    In the meantime i will run spy hunter again and see if i can get a log file for you.
    I do remember spring files etc before it happened.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    @TimW, No logs from Malwarebytes, Hitman Pro, or MGtools were ever posted! READ& RUN ME FIRST has not been followed as required.

    Also SpyHunter should be uninstalled as very not recommended software.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, Chaslang....I asked for them in post 5. Waiting on them.
     
  9. theremotedr

    theremotedr Master Sergeant

    Sorry,
    Here we go attached as requested.

    Also i have removed spyhunter now.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you went through the Read and Run First instructions, I also need the RogueKiller log. ;)
     
  11. theremotedr

    theremotedr Master Sergeant

    I did,but i went by this No logs from Malwarebytes, Hitman Pro, or MGtools were ever posted! READ& RUN ME FIRST has not been followed as required.

    I will do it now.
     
  12. theremotedr

    theremotedr Master Sergeant

    Here we go.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will check your RogueKiller log.....but I am not seeing any malware in your other logs.


    Once you have RogueKiller, do this:

    Reset Firefox to Defaults
     
  14. theremotedr

    theremotedr Master Sergeant

    I have refreshed firefox but still the same when i start it again,see image attached
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see what RogueKiller says.
     
  16. theremotedr

    theremotedr Master Sergeant

    Did you see the r killer log i uploaded ?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ah...sorry, I missed it. It is clean. Did you reset Firefox? If so, uninstall, run CCleaner to clean out temp and other folders and after a reboot, reinstall. Tell me how that goes.
     
  18. theremotedr

    theremotedr Master Sergeant

    So uninstall Firefox.
    Run ccleaner.
    Install firefox.

    Is that correct
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, but also remove:

    C:\Program Files\Mozilla Firefox
    C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox
    where UserAccount is the actual user account name being used.
     
  20. theremotedr

    theremotedr Master Sergeant

    After deleting Firefox and then installing again the issue has now gone.

    Thanks
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:

     
  22. theremotedr

    theremotedr Master Sergeant

    All done,thanks
     
  23. theremotedr

    theremotedr Master Sergeant

    Hi,
    Ive noticed a few of my shortcuts have the run as admin on them ?
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Topic for the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds