utrack.pw Redirections

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thepspgamer, Aug 10, 2015.

  1. thepspgamer

    thepspgamer Private E-2

    Good Morning/Afternoon guys :)

    I am having a small issue with a redirecting infection on my computer. The strange thing about it, is that its very inconsistent.

    Its almost non-existent in Firefox (which is my main browser), it only seems to occasionally appear in IE/Edge and when im using Steam (As that uses IE as an overlay if i recall correctly)

    As per the title, the website that it seems to take me too most is utrack.pw, and other times, random other sites (amazon, sky sports, general junk downloads)

    The thing is, its so rare it happens, its almost not bothering me, but i know its there, so it is bothering me xD

    I have run every AV scanning tool i know to try and clear it, but it has persisted.
    On running them, they all came back clean, bar a few junk files

    I have run them all a second time and MGTools, and attached the logs :)
    Being an IT tech myself, this has me a little stumped, so all the help you guys offer will be much appreciated.

    I am running Windows 10

    Thanks in advance
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There aren't any real issue showing in your logs other than the items Malwarebytes showed. And you log from Malwarebytes shows that you did not fix the issues found related to Firefox. You need to run Malwarebytes again and this time fix what it finds.

    Also run the below.

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Are you still having problems with Firefox? If yes then it is probably worth running the instructions in the below link:

    Reset Firefox to Defaults
     
  3. thepspgamer

    thepspgamer Private E-2

    Thanks for the reply :)

    I have re-run malwarebytes and made sure to delete what it found

    Please find the JRT log attached, however, all this morning, i had no issues with Firefox

    Still got the issue with IE and Steam though...

    I have attached a picture of what Steam is doing also (http://i.imgur.com/jrjPaly.png)
     

    Attached Files:

    • JRT.txt
      File size:
      1.9 KB
      Views:
      1
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  5. thepspgamer

    thepspgamer Private E-2

    Please find the log attached :)

    I had a little bit of trouble with the odd redirection last night on firefox, so its know its still about :p Seems to be affecting all my browsers
     

    Attached Files:

    • OTL.zip
      File size:
      48.8 KB
      Views:
      5
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try resetting Firefox back to defaults as requested a few messages back?

    If you did and you still have problems, try flushing your DNS Cache.
    Also try resetting your router back to factory defaults and configuring it again for your network. Make sure you write down all of your settings first.

    One other suggestion would be to remove the Google free DNS setting you are using and use the one provided by your ISP. We have seen people have problems sometimes when using these free DNS sites.


    Also you should run the below and attach the requested log:

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  7. thepspgamer

    thepspgamer Private E-2

    I did reset Firefox back to defaults, made no difference.

    I flushed my DNS, and got rid of the Google DNS, forgot i had that setting there xD

    I had trying resetting my router prior, again, made no difference

    and here is the log for ADW attached.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello. Chaslang is going to be away for a few days so I have come in to continue working with you. :)

    This seems to be a bit of a mystery.

    For clarification remind me which browsers exactly you are being redirected in.

    Firefox
    MS Edge
    Internet Explorer
    What about Google Chrome?

    Can you take a screenshot of one of the pages you get redirected to please?

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop. Hopefully it will run on Win10... let me know.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  9. thepspgamer

    thepspgamer Private E-2

    I am at work at the moment, so I will pot the Farbar log when I get in tonight

    In answer to your other questions, I'm getting re-directed in all of my browsers. IE/Edge most of all, Firefox about once every half hour and I don't use my installed Chrome almost at all, though when I was testing, I did get one within a few minutes of browsing

    I am even getting re-directed in Steam, since steam uses an overlay browser (See image below)
    (http://i.imgur.com/jrjPaly.png)
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not expecting it to be able to run, but if it does that will be nice. I'm sat here in the background trying to think of other tools we can run as win 10 is so new and not everything is compatible right now.

    That's shocking that whatever it is is also affecting/hooked into your Steam!
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try and think of what you were doing at the time this first occurred.

    • Had you installed any new software?
    • Had you installed any new browser add on's?
    • Had you visited any websites different from your normal searches?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try Farbar, but if it does not run, I'd like you to move onto running Combofix because that is Win10 compat.

    Please download Combofix to your desktop. Please refer to these instructions prior to running. Attach log once done.

    I see some other people affected by this when I was surfing around, and I am following the one thread with interest.
     
  13. thepspgamer

    thepspgamer Private E-2

    I will be honest, this all started because of something that was downloaded

    My little brother tried to download a film that was clearly not out yet, and tried to open it. This caused several junk programs to be installed and my webpage to change to some generic rubbish

    So, I immediately deleted all the programs it had installed, and ran several scanners (MBAM, ADW, Hitman) and that for the most part, cleared everything out, and I reset my browser home pages

    Everything seemed fine, my temps were normal, and nothing was running that shouldn't have been in talk manager. Its only a day or so later that I noticed this redirecting issue.

    I first noticed it in Steam, when I went to buy something, and then about an hour later, while browsing with Firefox, it popped up once and then not again for about an hour later still

    I re-ran all the tools and scanners (MBAM, TDSS, ADW, Rougekiller, Hitman) and they all found very little, which is why I have come to you guys.

    Being an IT Tech myself, using these tools previously has always seemed to work in these situations, so the fact this one small bug is being this stubborn is frustrating. The issue itself isn't a massive issue, as its hardly hindering my use, its just a pain

    Hope this helps a bit, I will run Combofix when I get in, I have been reluctant to use it myself, due to its heavy nature...
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes we must get to the bottom of it.

    Excellent. Do try FARBAR first but let's hope if that doesn't run that Combofix can snag what is causing all this....

    I also want you to open up each browser and check for any strange add on's or extensions if you have not done so already.
     
    Last edited: Aug 13, 2015
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is this where you get redirected to? (See screenshot)

    I also found this today on the net "It is important to note that the Utrack platform is a legitimate service, and there are adware developers using it to facilitate their operations."
     

    Attached Files:

  16. thepspgamer

    thepspgamer Private E-2

    I have indeed already checked over all my browsers for extensions, there is nothing out of the ordinary in any of the browsers.
    And no, that's not where I am getting redirected, I will see if I can post an image for you when I get home

    I will post back once I have tried running farbar/combofix :)
     
  17. thepspgamer

    thepspgamer Private E-2

    Please find my FRST logs attached, it seemed to run fine
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you run Combofix for me too, please and attach log once done? :)
    Also if you could get me a screenshot of one of the sites it redirects you too I'd appreciate that.
     
  19. thepspgamer

    thepspgamer Private E-2

    I cant get it to run, keeps saying its not for anything above windows 8
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ah ok. I thought it would considering our page said win10 compatible

    Not seeing anything in the logs at all. I do have a question though, what is this?

    C:\Users\Daz\AppData\Roaming\3909



    Download Kasperky virus removal tool from here "KVRT.exe"
    • Double click KVRT.exe to start the program
    • Click Accept and let it finish loading...
    • Click on where it says "Change parameters"
    • Ensure that all 4 boxes have checkmarks in them and click on "OK"
    • Now click on Start Scan
    • Please note that it may take some time to complete
    • Once it is complete allow it to remove what it finds.
    • Let me know if it found anything.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also I'd like a screenshot including the web address of one of the sites you get redirected too please.
     
  22. thepspgamer

    thepspgamer Private E-2

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes all that was found, was stuff already in quarantine :(

    As you can probably gather, not much is known about this so far and a few people are in the same boat as you. Hang in there... I'm thinking and watching other threads where people are going thru this.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have to ask as it was the only strange thing I found, what's in this folder? :confused C:\Users\Daz\AppData\Roaming\3909
     
  25. thepspgamer

    thepspgamer Private E-2

    i figured

    also, in that 3909 folder are files for a game called Papers Please
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this (not that I expect it to make miracles happen)

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Also I want to run a test.... Google Chrome is affected by redirects, too correct?
     

    Attached Files:

  27. thepspgamer

    thepspgamer Private E-2

    I'm a little confused on how you want me to run this?

    Save to a flash drive and system recovery options?

    Can you elaborate a bit how i get FDST to run this fixlist?

    And yes, chrome occasionally gets redirects too
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ignore my previous instructions, do it this way.

    • Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)



    Let's focus on Google Chrome for the test.

    Back up any bookmarks you may have....

    Use Revo Uninstaller to uninstall the below:
    • Google Chrome
    • Google Talk Plugin
    • Google Update Helper

    Now reinstall Google Chrome and let me know if it redirects....
     
  29. thepspgamer

    thepspgamer Private E-2

    Here is the log from FRST

    and i would just like to point out, would be it be easier to just use Revo to uninstall chrome, i very rarely actually use it to browse (Firefox is my main), so getting rid of it wouldn't be a huge issue
     

    Attached Files:

  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You want to ditch Chrome completely? That's fine. Use Revo to uninstall it. Then proceed to backing up your Firefox bookmarks before using Revo to uninstall it. Now reboot and reinstall and let me know whether it still redirects.
    Can I have another screenshot of where it takes you, please?
     
  31. thepspgamer

    thepspgamer Private E-2

    OK, Firefox was removed and re-installed (I make sure to clear all leftover files too)

    and, it made no difference, just after i loaded back in, this came back up

    (http://i.imgur.com/6aAB0DT.png)

    I think i have come to the point where a reset is a good idea, i dont have any worries about losing anything as everything is constantly backed up on my computer, personal files wise...

    All i would need to do is re-install my programs after, which is no bother...
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like to to try and follow the instructions below for Win8 and resetting the host file, those instructions should work for Win 10 too.

    https://support.microsoft.com/en-gb/kb/972034

    Let me know if this makes any difference. I'm sorry there's been no quick fix for this but again, it's obviously a new infection and I'm finding it very difficult to get to the root cause.
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I can understand the way you feel, and if you did decide enough was enough I wouldn't blame you.
     
  34. thepspgamer

    thepspgamer Private E-2

    Indeed, i do think enough is enough, plus, i haven't had a proper clean out on here in a while, so it would probably do it some good

    I want to thank you for all your help though, you have been amazing
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) Safe surfing.
     
  36. thepspgamer

    thepspgamer Private E-2

    Just one final thing, if i do a reset through windows 10 recovery, that's effectively the same as a formal reload, right?

    It just i would rather not have to re-install 8 and go all the way back up...
     
  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should ask about that in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds