MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 08-30-13, 12:29
richelle richelle is offline
Private E-2
 
Join Date: Jan 2013
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default My Reports

Hi,

I've lotsa of advertisement popups and my browser keep setting PortalDoSites as the default homepage. Pls help. Thanks!
Attached Files
File Type: txt RKreport[0]_S_08312013_002716.txt (2.0 KB, 1 views)
File Type: zip MGlogs.zip (308.3 KB, 0 views)
File Type: log HitmanPro_20130831_0053.log (9.8 KB, 1 views)
File Type: txt mbam-log-2013-08-31 (00-28-22).txt (217.1 KB, 1 views)
File Type: txt TDSSKiller.2.9.2.0_31.08.2013_00.45.08_log.txt (137.5 KB, 0 views)
Reply With Quote
Sponsored links
  #2  
Old 08-30-13, 14:54
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,460
Thanks: 431
Thanked 4,591 Times in 4,344 Posts
Default Re: My Reports

Rerun RogueKiller and have it fix this:
Code:
 Scheduled tasks : 1 
[V1][ROGUE ST] schedule!3036567561.job : C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe - /schedule /profile "c:\programdata\bettersoft\optimizerpro\3036567561.ini" [-][-] -> FOUND
Now run Hitman and have it delete these items:
C:\Users\Richelle\AppData\Local\temp\eIntaller\D48440412F21492f88D60D88C7B73986\eGdpSvc.exe

And all of the:
Potential Unwanted Programs

Now:
Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Attach JRT.txt to your next message.


Now rescan with both RogueKiller and Hitman and attach the new logs.


Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

Attach the new C:\MGLogs.zip
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #3  
Old 08-30-13, 20:23
richelle richelle is offline
Private E-2
 
Join Date: Jan 2013
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: My Reports

here's the logs
Attached Files
File Type: zip MGlogs.zip (309.6 KB, 0 views)
File Type: txt RKreport[0]_S_08312013_090338.txt (2.1 KB, 1 views)
File Type: txt JRT.txt (6.5 KB, 2 views)
File Type: log HitmanPro_20130831_0858.log (4.7 KB, 1 views)
Reply With Quote
  #4  
Old 08-31-13, 14:49
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,460
Thanks: 431
Thanked 4,591 Times in 4,344 Posts
Default Re: My Reports

Download OTM by Old Timer and save it to your Desktop.

  • Right-click OTM.exe And select " Run as administrator " to run it.
  • Paste the following code under the area. Do not include the word Code.


Code:
:Processes
explorer.exe
:Files
C:\Users\Richelle\Local Settings\temp\Desk365
C:\Users\Richelle\Local Settings\temp\eIntaller

:Reg
[-HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}]
[-HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo]
[-HKLM\SOFTWARE\hdcod]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86]
[-HKLM\SOFTWARE\portaldositesSoftwar]
[-HKLM\SYSTEM\ControlSet001\services\eventlog\Application\desksv]
[-HKLM\SYSTEM\ControlSet001\services\eventlog\Application\WsysSvc]
[-HKLM\SYSTEM\ControlSet002\services\eventlog\Application\desksvc]
[-HKLM\SYSTEM\ControlSet002\services\eventlog\Application\WsysSvc]
[-HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\desksvc]
[-HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\WsysSvc]
[-HKU\S-1-5-21-129588198-472293293-2279542875-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]

:Commands
[purity]
[ResetHosts]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
  • Push the large button.
  • OTM may ask to reboot the machine. Please do so if asked.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.


Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

Now rescan with Hitman and attach the new log.

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

Attach the new C:\MGLogs.zip
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #5  
Old 09-04-13, 07:56
richelle richelle is offline
Private E-2
 
Join Date: Jan 2013
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: My Reports

attached logs
Attached Files
File Type: log HitmanPro_20130904_2054.log (8.5 KB, 1 views)
File Type: zip MGlogs.zip (27.9 KB, 1 views)
File Type: log 09042013_203837.log (9.1 KB, 1 views)
Reply With Quote
Sponsored links
  #6  
Old 09-04-13, 13:22
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,460
Thanks: 431
Thanked 4,591 Times in 4,344 Posts
Default Re: My Reports

MGLogs did not run to completion.

Rerun Hitman and delete the PUP's.

Tell me what issues remain, if any.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #7  
Old 09-05-13, 07:21
richelle richelle is offline
Private E-2
 
Join Date: Jan 2013
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: My Reports

Hi,

my browser startup page is still default as

portaldosites.com
Attached Files
File Type: zip MGlogs.zip (318.3 KB, 3 views)
File Type: log HitmanPro_20130905_2013.log (9.8 KB, 2 views)

Last edited by Kestrel13!; 09-05-13 at 08:42.. Reason: made link unclickable for others!!!
Reply With Quote
  #8  
Old 09-05-13, 13:35
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,460
Thanks: 431
Thanked 4,591 Times in 4,344 Posts
Default Re: My Reports

Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
Quote:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.portaldosites.com/web/?
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.portaldosites.com/web/?
After clicking Fix, exit HJT.

Now tell me if that fixed it.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #9  
Old 09-06-13, 22:35
richelle richelle is offline
Private E-2
 
Join Date: Jan 2013
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: My Reports

Nope... am still having the same issue of having the following page below whenever i open any of my browser.

http://www.portaldosites.com/?utm_so...&ts=1377875164
Reply With Quote
  #10  
Old 09-07-13, 15:13
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,460
Thanks: 431
Thanked 4,591 Times in 4,344 Posts
Default Re: My Reports

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

Attach the new C:\MGLogs.zip
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
Sponsored links
  #11  
Old 09-07-13, 15:16
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,165
Thanks: 61
Thanked 7,581 Times in 4,079 Posts
Default Re: My Reports

@TimW, It is embedded in Firefox. You can see the below in the previous MGlogs.zip
Quote:
("browser.search.defaultenginename", "portaldosites");
("browser.search.defaultenginename,S", "");
("browser.search.defaultthis.engineName", "");
("browser.search.order.1", "portaldosites");
("browser.search.order.1,S", "");
("browser.search.selectedEngine", "portaldosites");
("browser.search.selectedEngine,S", "");
("browser.search.useDBForOrder", true);
("browser.newtab.url", "http://www.portaldosites.com/?utm_source=b&utm_
("browser.keywordURLPromptDeclined", 1);
("extensions.34AMckGQ.scode", "new function(){var a=this;a.domain_stora
("extensions.yljxp7Ad65H.scode", "(function(){try{if(window.opener&&win
("extensions.enabledItems", "{3eed6c8f-efd7-44c3-89b8-05ac2f79d35b}:1.0
JRT does not fix this junk. I suggest that the below be run for Firefox.

Reset Firefox to Defaults

If Chrome also has a problem, manual removal of the addons or extensions is needed or reinstall
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
The Following User Says Thank You to chaslang For This Useful Post:
TimW (09-07-13)
  #12  
Old 09-07-13, 23:38
richelle richelle is offline
Private E-2
 
Join Date: Jan 2013
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: My Reports

i did a reset for firefox but still having the same problem.
Attached Files
File Type: zip MGlogs.zip (323.1 KB, 1 views)
Reply With Quote
  #13  
Old 09-08-13, 00:40
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,165
Thanks: 61
Thanked 7,581 Times in 4,079 Posts
Default Re: My Reports

Okay then since the reset removed the addons from Firefox, it is most likely also in your link file that you use to run Firefox. Also probably in links to other browsers like IE. You should either edit the link files to remove the junk from them or delete the link files and then create new ones. The below two have likely been changed:


C:\Users\Richelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
The Following User Says Thank You to chaslang For This Useful Post:
richelle (09-09-13)
  #14  
Old 09-09-13, 06:49
richelle richelle is offline
Private E-2
 
Join Date: Jan 2013
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: My Reports

I've edit the link files and seems ok now!

Thanks so much TimW & chaslang!
Reply With Quote
  #15  
Old 09-09-13, 10:15
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,165
Thanks: 61
Thanked 7,581 Times in 4,079 Posts
Default Re: My Reports

You're welcome.

If you are not having any other malware problems, it is time to do our final steps:
  1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
  2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
  3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
  4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
  5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
  6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
  7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
    • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
    • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
    • Then we want you to Enable System Restore to create a new clean Restore Point.
  8. After doing the above, you should work thru the below link:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
Sponsored links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
my reports marty1960 Malware Removal 3 08-31-13 13:26
Crystal Reports Help Mada_Milty Software 1 01-04-08 10:49
malware reports TomLove Malware Removal 4 01-10-07 23:24
Crystal Reports metavian Software 0 10-24-06 13:19
Error Reports? Splinter Malware Removal 1 05-28-06 23:21


All times are GMT -5. The time now is 20:18.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger