Omiga-plus Hijack

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by And21ob, Jul 20, 2014.

  1. And21ob

    And21ob Private E-2

    Hi

    Not sure how, but a bad click has meant that every time I open Firefox or IE the search page is Omiga-plus.com. Any additional tabs opened are the correct google homepage.

    I've run the browser hijack procedure and the Read Me for malware removal and its still there.

    The only problem was that whilst saving the Malwarebytes log to txt Malwarebytes crashed and the log was not created. It has quarantined quite a lot of items, but I can't figure how to export these to a log to send you.

    I've attached all the other logs, so any help is gratefully accepted.

    Cheers
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it remove everything that it finds.


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\catchme -> FOUND
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IePluginServices -> FOUND
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WindowsMangerProtect -> FOUND
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\catchme -> FOUND
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IePluginServices -> FOUND
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WindowsMangerProtect -> FOUND
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\catchme -> FOUND
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\IePluginServices -> FOUND
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WindowsMangerProtect -> FOUND

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Re run RogueKiller again (just a scan) and attach log.

    Explain how things are running.
     
  3. And21ob

    And21ob Private E-2

    Thanks for the response Kestrel.

    Followed the instructions and Hitman Pro deleted what was found.

    Roguekiller didn't show any of the registry entries you indicated, so didn't delete anything, log attached. There is no change and the browsers are still opening on Omiga-plus.

    Another query I have is when I delete Malwarebytes from my computer, what about the items that were quarantined, is it worth removing Malwarebytes but not deleting the quarantined items and trying to create that log again?

    Any more help appreciated
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Malware Bytes please and fix anything that it finds. Attach log in correct format.

    Also run this:

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Let me know if the problem is still there.
     
  5. And21ob

    And21ob Private E-2

    Hi Kestrel

    Followed instructions and logs attached. Unfortunately still opening browsers on Omiga-plus search page.

    Thanks
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

    Run the below:

    Reset Internet Explorer to defaults

    Reset Mozilla Firefox to defaults.

    Let me know if any of that made a difference.
     
  7. And21ob

    And21ob Private E-2

    Hi Ketsrel

    I've run ADWCleaner and viewed the log, I can't see any programs that I need to keep.

    Attached ADWCleaner log.

    Cheers
     

    Attached Files:

  8. And21ob

    And21ob Private E-2

    Sorry Kestrel forgot to say that I've reset the browsers and there is no change.

    Thanks
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  10. And21ob

    And21ob Private E-2

    Attached OTL logs.

    Thanks
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm... this is hiding itself well.
    Try and think very hard what was going on at the time. Did you by any chance try and update Flash Player or Java from somewhere that could have been a non genuine website? :confused

    Was there any other kind of software that you were downloading at the time?

    Let's focus on Chrome for now...
    Open up Google Chrome, go to TOOLS > EXTENSIONS > is there anything odd listed there?

    Do you click a shortcut on your desktop to open up Chrome? If so right click and select Properties > select Shortcut tab and look at target: does it mention omiga plus anywhere in the path??
     
  12. And21ob

    And21ob Private E-2

    Thanks for the help Kestrel

    I don't have Chrome installed, I use Firefox and have IE installed but don't use it.

    Cheers
     
  13. And21ob

    And21ob Private E-2

    This started after I clicked a link to a survey site on a messageboard, but can't remember the link site.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except please use Revo Uninstaller to do so) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bookmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\documents and settings\UserAccount\Application Data\Mozilla

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Has Omiga plus gone away from Firefox?
     
  15. And21ob

    And21ob Private E-2

    That seems to have worked Kestrel.

    Which is strange as thats exactly the first procedure I tried before posting. Thanks, so how do I get rid of the rest of what might be left?

    Cheers
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do not know what is left unfortunately because the logs don't show it.

    You said you don't use Chrome, fair enough, but open it up and at least let me know if Omigaplus is a problem in that browser too. Same for IE please.
     
  17. And21ob

    And21ob Private E-2

    Hi Kestrel

    Many apologiEs for the delay getting back to you, but I've had a few personal problems that meant I couldn't get on my computer.

    It's not that I don't use Chrome, I don't have it installed.

    Omiga is still there in IE. As you know I'm using an old XP machine and unless I upgrade to IE 8, I can't do the reinstall I think. Can I just live without IE, or can we try something else with it.

    Sorry, I'm probably jumping the gun here.

    Cheers
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Open up IE, go to Tools ---> Manage add on's ----> Select search providers > what is listed in there? If Omiga Plus is listed, remove it.

    Also right click the Internet Explorer shortcut you are using and select properties. Select shortcut tab and in Target field remove Omigaplus if you see it. Click okay to save changes. there should only be a path to the internet explorer executable.

    Then go to tools > options and check your home page is not set up for Omigaplus.

    Let me know how you get on.
     
  19. And21ob

    And21ob Private E-2

    Hi kestrel

    Only Bing in add-ons search providers.

    Omiga plus was in the shortcut properties and I have removed it. Everything is now fine with IE.

    Thanks
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds