browser hijack?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by epoclaen, Mar 18, 2014.

  1. epoclaen

    epoclaen Private E-2

    My father is having pop-ups when using internet explorer. These typically show when a link or search button is selected. Attached are the logs from my scans as outlined in the malware removal procedures. The sixth will have to be in a reply to this post.

    Thanks,
    Jeff
     

    Attached Files:

  2. epoclaen

    epoclaen Private E-2

    Here is the last log file.

    Jeff
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is your Father deliberately set up to use a proxy? (Doubt it, but have to be sure)
     
  4. epoclaen

    epoclaen Private E-2

    No but when attempting to fix the issue myself prior to turning to the pros for help, his browser settings kept having the checkbox next to "Use a proxy server for your LAN settings" checked even after I unchecked it.

    Jeff
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Jeff,



    Re run Hitman Pro and have it remove these:




    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=127.0.0.1:13828 [Country: (Private Address) (XX), City: (Private Address)]) -> FOUND

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Delete these if you see them:
    • C:\Windows\tasks\Select-N-Go Update.job
    • C:\Windows\tasks\Select-N-Go_wd.job


    Now re run RogueKiller once more (just a scan) and attach that log too please.
     
  6. epoclaen

    epoclaen Private E-2

    Kestrel,
    I ran Hitman Pro, left everything in the results as they were with the exception of having it delete the two iPumper entries. This requested a reboot which I did.

    After running RogueKiller, there was no matching entry under the "Registry" tab. I checked under the "Proxy" tab and found the entry there. I tried selecting it (no checkboxes were available) and hit the "delete" button. The entries ender the "Proxy" tab then said to use "fixProxy" so I did nothing more.

    Rebooted as requested and deleted the Select-N-Go entries (both were found). I then re-ran RogueKiller and the logs are attached.

    Thanks,
    Jeff
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    RogueKiller still finds:

    • [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=127.0.0.1:13828 [Country: (Private Address) (XX), City: (Private Address)]) -> FOUND
    • [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyEnable (1) -> FOUND

    You need to use it to try again to get rid of those.

    Try this also:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    What is your Father using for Anti-Virus?


    Please download Combofix to your desktop. Please refer to these instructions prior to running.

    Once done running Combofix attach the log.
    Rescan with RogueKiller again so I can see if those entries went ot not.
     
  8. epoclaen

    epoclaen Private E-2

    Kestrel,
    My father is using a paid version of AVG which is been updated to the latest virus definitions. It had detected c:\windows\temp\is-9GG82.tmp\Bundle.exe but was unable to remove it.

    Attached are the log files you requested.

    Jeff
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, seems like it's gone.

    Re run RogueKiller once more please and attach the log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds