This might help others

Discussion in 'Malware Help (A Specialist Will Reply)' started by GratefulGeezer, Jan 11, 2013.

  1. GratefulGeezer

    GratefulGeezer Private E-2

    hello all

    I have been having a very annoying new tab created created in both firefox and iexplorer, the only thing that used to happen is a site comes up, and then it changes to something else quickly.

    I have managed to catch the site name and put it in my firewall rules, and now I see this:

    http://clickserv.sitescout.com/clk/...FMkNFNThBMkI4MzkyMjM5RjRCODU2Rjc4Nzc3RDAvLy8v

    I am quite sure now that this is what causes the problem.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. GratefulGeezer

    GratefulGeezer Private E-2

    hello

    I have done all the tests and please find attached the logs.

    thank you
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Overall your logs look good. I just have a couple minor things for your to do and a couple questions. First the questions:
    • Do you know what the below startup process is?
      • O4 - .DEFAULT User Startup: TaskBar.vbs (User 'Default user')
    • Did you knowingly install Amazon Browser Bar and is it something you use and always want present?
    Uninstall the below very old versions of software:
    Java(TM) 6 Update 37

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    After clicking Fix, exit HJT.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  5. GratefulGeezer

    GratefulGeezer Private E-2

    hello

    I am ever so grateful for your quick reply ..

    As for the first question, please find here the contents of the taskbar.vbs file:

    2- As for Amazon, you guessed right, it was forced on me. I found it in Add/Remove and managed to rid of it.


    the java6up26 has been uninstalled now.

    * New version has been installed.

    * The analyse.exe has been executed with the options followed to the letter.
    The entries [and corresponding files] have been fixed.


    All the other steps were followed exactly to the letter.

    However, I have one question please:

    I am not too sure if you use paltalk [some kind of virtual chat program], I have noticed in the address which I get jacked into the following:

    http://clickserv.sitescout.com/.../advertising.paltalk.com%2Fnewbanners%2Fads%2Fnew_groupBanner.php//cidentNTBFMkNFNThBMkI4MzkyMjM5RjRCODU2Rjc4Nzc3RDAvLy8v

    Could this be due to paltalk forcing itself on me?

    I only noticed it today, and to be honest, I am not sure if that redirection happens only when paltalk is running or just happens.

    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So then I assume you installed this to pin items from your Quicklaunch to the tray?


    Paltalk is something we don't recommend and normally have people uninstall unless there is some reason they really need it. From your statement above, it sounds like you did not choose to install Paltalk. If that is the case then uninstall it. If you did install it and use it, then you will have to live with the ads that they will send you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds