Redirect virus still present after trying all protocols

Discussion in 'Malware Help (A Specialist Will Reply)' started by swimmy711, Nov 25, 2012.

  1. swimmy711

    swimmy711 Private E-2

    Hello, I've been reading extensively through all the forums topics on removal of redirect viruses. I've done all of the protocols, beginning with the READ ME FIRST post, and all through to the step 3 where you use the Roguekiller, Malware Bytes, HitmanPro, TDSSKiller, and MGTools. I am attaching all logs. I'm not sure if MGTools scanned properly or not. TDSSKiller would not run on my computer, so I have no log for that.

    It would appear that both Internet Explorer and Firefox are infected. 2 days ago (11/23) I tried and ran Goored Fix and MB check, so i attached logs for MB check in case it's helpful. (No room to attach the Goored Fix log.)

    I had a redirect virus about a year ago and your forums helped me fix it without needing to post a thread. However, this time it seems much worse. It's been happening for about 2 weeks now, give or take. I started noticing it just after my hard drive crashed seemingly randomly, but my husband was able to restore my computer and recover all my files.

    thanks for any help.
    Steph
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your Win7 disc?

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKUS\S-1-5-21-3670494382-1231431073-2166377199-1001_Classes[...]\Run : IlividUpdate (C:\Users\Steph\AppData\Local\Ilivid Player\IlividUpdate\Ilividupdt32.exe) -> FOUND
      [TASK][SUSP PATH] win4036e0 : C:\Users\Steph\AppData\Local\Temp\win4036e0.dat -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    Now click the Files/folders tab and locate these detections:

    • [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-3670494382-1231431073-2166377199-1001\$98b6b1bd2581720063b7b3bc2cc89f69\@ --> FOUND
      [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-3670494382-1231431073-2166377199-1001\$98b6b1bd2581720063b7b3bc2cc89f69\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-3670494382-1231431073-2166377199-1001\$98b6b1bd2581720063b7b3bc2cc89f69\L --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now re-scan with both RogueKiller and Hitman and attach those logs as well.

    Now, if you have your disc, boot into the bios and change the boot order to CD as first boot device.

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr, and then press ENTER.

    Reboot to normal mode and re-run MBRCheck and attach that log as well.
     
  3. swimmy711

    swimmy711 Private E-2

    Thank you, yes I still have my Win7 disk somewhere. I will locate it, and try this and get back to you. Appreciate it!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know. :)
     
  5. swimmy711

    swimmy711 Private E-2

    Hello again,
    I ran the Rogue Killer and deleted the registry items you instructed. Then, when I clicked on the File tab, there was nothing there. So I was unable to delete those 3 items. I've attached the report it generated.

    Also, I noticed it also generated a folder on my desktop called "RK Quarantine." Not sure if that is important or not. what should I do next?

    I can't find my Win7 disc anywhere. How important is having that? Should i buy or somehow find one?

    Thanks.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run RogueKiller and attach the new log.

    You need to have your install disc to fix your faked MBR.
     
  7. swimmy711

    swimmy711 Private E-2

    Ok, I will find a Win7 disc. In the meantime, I ran Rogue Killer again and attached the log.

    Thanks again.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know when you beg, borrow or find the disc. ;)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You probably do not need it. Just use Hitman to fix it, but I do recommend that important data is backed up first no matter how the fix is attempted.
     
  10. swimmy711

    swimmy711 Private E-2

    Hello again,
    Sorry it's been awhile. Holidays and all...
    I cannot find a copy of Win7 anywhere. If I have to spend the $ on that, I'm wondering if I got a copy of Win8, if that would do the trick? Serve the same purpose?

    Thanks.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As Charlie suggested, re-run Hitman and see if it won't fix your MBR> attach the new log.
     
  12. swimmy711

    swimmy711 Private E-2

    It would appear that Hitman has fixed the problem. Thank you! I'll post further if something else happens, but for right now my issues appear to be solved.

    I appreciate it!

    Stephanie
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  14. swimmy711

    swimmy711 Private E-2

    Hello for (hopefully) one last question. I've attached the log from when I ran Hitman one last time, and I don't know whether to delete the files listed. Not sure if they're malware or not. Please advise?
    Thanks again.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can delete those PUP's. You might also want to run this:

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  16. swimmy711

    swimmy711 Private E-2

    Here's the JRT log.
    Thanks.
     

    Attached Files:

    • JRT.txt
      File size:
      4.8 KB
      Views:
      3
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So how are things running now?
     
  18. swimmy711

    swimmy711 Private E-2

    Everything seems to be running great!
    Thanks so much.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds