Request for help - istart123

Discussion in 'Malware Help (A Specialist Will Reply)' started by sens, Aug 23, 2014.

  1. sens

    sens Private E-2

    Hi - I have a problem my computer always goes to the istart123 website. Upon reboot my internet get disconnected and I have to disable and reable ethernet manually to get online, then the first page it goes to is istart123.

    I have completed all steps to disinfect yet still have the same issue detailed above.

    Please see attached logs - please help!!!!!!:banghead
     

    Attached Files:

  2. sens

    sens Private E-2

    More attachments - Thank you.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks

    *You have two anti-virus appls installed and active:
    Windows Defender
    Rogers Online Protection Basic

    Since Windows Defender is built into Windows - see this link How to Turn On or Off Windows Defender in Windows 8 and 8.1

    Re-run RogueKiller and have it delete these:

    ¤¤¤ Registry Entries ¤¤¤
    • [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 64.71.255.204 64.71.255.198 -> FOUND
    • [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 64.71.255.204 64.71.255.198 -> FOUND
    • [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{39875994-5A60-4A5F-A0D6-EE13B0ECF40F} | DhcpNameServer : 64.71.255.204 64.71.255.198 -> FOUND
    • [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{39875994-5A60-4A5F-A0D6-EE13B0ECF40F} | DhcpNameServer : 64.71.255.204 64.71.255.198 -> FOUND



    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Now download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach the JRT.txt to your next message.

    Re-run RogueKiller - do a scan ONLY and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double-clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  4. sens

    sens Private E-2

    Hello Sir - Thank you for your assistance.

    I have uninstalled the Rogers Online Protection, but could not disable the Windows Defender - it told me it was already off so I could not access the settings options to disable(?)

    I followed the instructions you wrote last. Still, when I go on the internet it still always brings me to http://www.istart123.com automatically.

    Please see attached logs - thank you very much.
     

    Attached Files:

    Last edited: Aug 24, 2014
  5. sens

    sens Private E-2

    Hi - I dont know if my last post displayed, so please excuse if this is duplicate.

    Please my most recent from following your instruction.

    I still get the istart123 redirect when I open Firefox. Thanks for your help!!!!

    (I can not attach the most recent MGlog because it says its a duplicate already in my first post.)
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Un-install the outdated program below . If you do not find it or it will not un-install, just keep going.
    Java 7 Update 55

    Re-run AdwCleaner.exe
    • Click on the Scan button
    • When the scan is ready click on the Clean button
    • A log file will automatically open after the scan has finished
    • Please attach the log file, located at C:\AdwCleaner[S0].txt

    Try resetting your browsers -

    Reset Internet Explorer 9, 10, and 11 to Defaults
    Reset Firefox to Defaults
    Reset Chrome to Defaults

    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. You do not want to add what most people consider malware to your PC. Also just in case Oracle changes the Java installation in the future to possible install other junk, uncheck all but just installing Java.

    Now run the C:\MGtools\GetLogs.bat file by double-clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. sens

    sens Private E-2

    Hello sir, thank you again for the assistance its much appreciated.

    Please see attached the log you requested - is the computer virus resolved? I dont get redirected to the istart123 page but maybe there is still a virus lingering?

    Thank you again.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, sens.

    I'm about to run some errands; please remember to attach the
    C:\AdwCleaner[S0].txt log so it'll be waiting for my return.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome. Those logs are clean, but do this last scan before we finish up.

    Now run the following online scan -
    Using ESET's Online Scanner

    Attach the ESETScan.txt log, please.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds