Redirect Malware/Virus Resistant

Discussion in 'Malware Help (A Specialist Will Reply)' started by johndobbs, Jan 16, 2014.

  1. johndobbs

    johndobbs Private E-2

    Greetings. I have a 64 bit HP Pavilion Laptop, running the horrible Windows 8. In a hurry I foolishly downloaded a youtube downloader and the troubles began a few months ago. I ran all the virus checks I have access to, to no avail. I reset the laptop to factory condition, but it did nothing to solve the problem. I have had it in our local shop three times, with no success. I have now run through the READ ME procedures and still on most pages there are underlined words that lead to other sites, at times when I click on links popups come that appear to be legitimate products / sites, but they are not the links I'm trying to reach. Sometimes a small popup opens up and a commercial begins to play. So I'm thinking of submerging this laptop in water and calling it a loss!

    I was able to do all the steps but RogueKiller did not creat a log, it created a .ini file called quarantine. I didn't think I should attach that.

    I cannot find a Malware Bytes log file anywhere in my system.

    Attaching the requested files and hoping someone can provide an answer for this novice who did a dumb thing and has been paying the price for it! Thanks for any help you can offer.

    John
     
  2. johndobbs

    johndobbs Private E-2

    John's Computer Misadventures

    This is my second try...neglected to attach the required files on the first try. :-o

    Hopefully the first try is approved and you can see that I have run the required tests.

    Malwarebytes did not leave a .log file
    RogueKiller left a quarantine .ini file that I did not upload

    I've had this computer in the shop 3 times. HP Pavilion g7 64 bit running the horrible windows 8. I acquired the redirect virus/malware downloading a youtube downloader ... I was in a hurry and not cautious as I should have been...a few months ago. Multiple scans and such as are available to me have been run ... to no avail.

    I still have underlined words on web pages that direct me to other websites. I have popups that come up when I click on links. And occasionally popups will happen and a commercial will start. None of these are porn, they all appear to be legitimate links.

    Any questions? Thank you for your effort to help a novice such as myself.:confused

    John
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It explains where to find it right here.

    Can you attempt to run RogueKiller again please, hopefully this time it produces a log. It should be on your desktop.
     
  4. johndobbs

    johndobbs Private E-2

    Thank you. i will try to get by my office today and do those two things.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you still with me? :)
     
  6. johndobbs

    johndobbs Private E-2

    Yes! I'm so sorry I have not been able to get back to the office over the weekend. I very much appreciate your help and will possibly be able to do that late this afternoon.:-o
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, and in the mean time, as soon as you are able to you can follow these instructions too:

    Re run Hitman and have it delete the item under the heading Malware (reimage item)



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O23 - Service: Reimage Real Time Protection (ReimageRealTimeProtection) - ReimageĀ® - C:\Program Files\Reimage\Reimage Repair\ReiGuard.exe

    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
    C:\Program Files\Reimage
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
    C:\WINDOWS\Reimage.ini
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.




    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now! And don't forget to attach the missing logs. :)
     
  8. johndobbs

    johndobbs Private E-2

    ______________

    Rogue Killer tells me it is an out of date version. When I try to download the up to date version it downloads something called BearShare ... a song sharing service (more malware I suspect). grrrr
     
  9. johndobbs

    johndobbs Private E-2

    Thanks you so much for your help... but I can't even run the tools... this is beyond my simple skills. I'm just going to pay someone to wipe the hard drive and start over. I appreciate this website and the helpful people who assist here. Thank you!
    John
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) Best of luck!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds