Java update plugin redirection problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by LaineyYo, Apr 22, 2014.

  1. LaineyYo

    LaineyYo Private E-2

    Hello! Sometimes my webpage will redirect to a "outdated java plugin detected" page. It happens on any of my browsers (internet explorer, firefox, google chrome). I doubt this is how java gets people to update.

    I have tried uninstalling firefox and reinstalling, I have tried clearing the caches from all my browsers, including the DNS.

    Before majorgeeks I googled the problem and malwarebytes was suggested, so the reason the logs are empty is likely because I have used it a few times already, but I did not know how to take the logs at the time; same with hitman pro

    I have tried JRT, adwcleaner, avg, norton, I have tried a full system scan using microsoft security essentials,

    I have run RogueKiller, Malwarebytes Anti-Malware (after finding MG), TDSSKiller, HitmanPro (after MG), and MGlogs.zip during safe mode.

    This java malware of some sort has not infected the other computers in the household so I do not think it is a DNS poisoning/hijacking

    After using MGlogs, I believe that one was the one that required me to turn off UAC. After using the scanner I tried to turn the UAC back on but some of my folders/files became unaccessible, I'm not sure why. So I did a system restore.

    I have disabled any disk emulating software using the defogger (still disabled)

    I will make a second post for the remainder of the logs.

    I'm sorry if I miss something(s)
     

    Attached Files:

  2. LaineyYo

    LaineyYo Private E-2

    Oh! I also ran CCleaner, but on normal mode

    I think that is everything. When I googled the problem I saw that there were some videos of deleting? some registry... things. However the files in my registry did not match anything in the video so of course I didn't want to randomly delete something and didn't do anything.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    I still need to see the MGlogs.zip from you running MGTools.exe please.
     
  4. LaineyYo

    LaineyYo Private E-2

    whoops! sorry about that!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.

    If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. LaineyYo

    LaineyYo Private E-2

    Hello again!

    I ran the messenger disable and it tells me it cannot locate it.

    I ran the MG getlogs.bat and similar to last time there were some folders that appeared that are unaccessible, which i wasn't sure what they were and didn't want to delete, which is why I ran the system restore.

    Still have the java update thing. :(
     

    Attached Files:

  7. LaineyYo

    LaineyYo Private E-2

    Also... I'm not sure what you mean by using MSConfig? I figured normal mode was not safe mode or safe mode with network, which I think is just starting up the computer and not pressing F8?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just press the start button, type in msconfig and it will pop up for you to click on.
     
  9. LaineyYo

    LaineyYo Private E-2

    Okie dokie. I await your next instructions!

    Also, I asked a friend of mine to see if he could fix it and I will let you know whether he fixes it or not. I would still really appreciate your help though :)
     
  10. LaineyYo

    LaineyYo Private E-2

    Uh... somehow using MSConfig and clicking on normal startup seemed to clear it up. I have been browsing the internet with no problems so far...

    I'm really not sure how that works. Am I being too optimistic to say that it is fixed? Should I run the getlogs.bat again?
    I'm embarassed to say, but I ran the getlogs.bat before using MSConfig :-o so the logs i posted might not be accurate?

    Can you explain what might be happening/what happened? Either here or in a pm or something?
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do this again now you're in normal start up:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  12. LaineyYo

    LaineyYo Private E-2

    thank you
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs look lovely. :) Ready for final steps?


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  14. LaineyYo

    LaineyYo Private E-2

    Hello!

    Sorry to have appeared again...

    So, unfortunately the java redirection thing has come back, or sort of never left?

    Anyhow, it seemed fine the last time I posted, which was when I tried clicking on normal startup with MSConfig. And it seemed like it was okay for a little bit. But after the windows update it seems to have come back. I tried a system restore to the time and day that I tried MSconfig; normal startup and again it seemed to, I don't know, hide?

    Anyway after the last update, I tried system restore once again, and to no avail. The java update is here to stay.

    I brought my laptop to a friend who tried using spyware terminator and I will post logs from a few scans.

    I have not tried any previous scans because I don't believe they will yield any results different from last time.

    Is it possible that this whole thing might be easier if I uninstall Windows 7 (what I have) and install a different type of windows? Would that work on a laptop?
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those scan results are not showing anything useful either, so please yes... repeat our procedures and be sure you begin a NEW thread. Let's not continue in this one, it will get long and messy. Thanks. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds