Malware Issues, maybe virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by llcoolbiggs, Jan 11, 2015.

  1. llcoolbiggs

    llcoolbiggs Private E-2

    Dear MajorGeeks

    My computer is acting very slow, additionally a chrome extension was installed called VaudIxu that every time i open a website it shows ads by VaudIxu and even after i disable the extension/delete it, the extension keeps appearing. Additionally i can barely get on to the internet, it keeps saying: "This webpage is not available"; Erro code: ERR_FAILED. So I am using my friends computer to post this and download the programs from. I cant update Malwarebytes Anti-Malware. I had comodo on my computer, but after doing some research on them; it seems that may be part of the problem as; so i removed it hoping to fix this problem; that didn't work. I noticed the problem on 15Jan2015; not sure how long the problem has been going on, as I dont use the computer much until it gets closer to school time (next week). Also various temp/weather programs were on my computer, i removed them; but computer is still not working properly. Can you please help. And thanks in advance for all your help. Attached are the logs from the malware removal forum you have requested.

    Regards,

    Biju
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it remove all that it finds. It may or may not repair you broken internet. Let me know!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: YoutubEAdBlocke - {a4feca26-7e62-428b-9224-3a0e98d1f515} - (no file)
    • O2 - BHO: VaudIxu - {c4bd7036-5ea6-461b-944c-a05c618fe328} - (no file)
    After clicking Fix exit HJT.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. llcoolbiggs

    llcoolbiggs Private E-2

    Dear Kestrel13,

    Thank you for getting back to; the first fix did restore my internet. Thank you for that. I have followed the additional steps you mentioned on the thread however, vaudix is still on my computer. Is there any additional items that can be done to correct this and any other issues that I am unaware of? Attached are the logs you requested. Thanks again for all your help and patience with me.

    Regards,

    Biju
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this folder:

    C:\Program Files (x86)\VaudIxu


    Reboot, problem gone away?
     
  5. llcoolbiggs

    llcoolbiggs Private E-2

    Unfortunately no. Anything else I can do to fix it? Thanks again for all your help.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below appropriate for your operating system and save it to your Desktop.
    Download 32 Bit
    Download 64 Bit

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :Regfind
      VaudIxu
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  7. llcoolbiggs

    llcoolbiggs Private E-2

    Dear Kestrel13!,

    Attached is the log. Thanks again for all your help.

    Regards,

    Biju
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c4bd7036-5ea6-461b-944c-a05c618fe328}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Reboot if not prompted... has the issue gone away?
     
  9. llcoolbiggs

    llcoolbiggs Private E-2

    Dear Kestrel13! ,

    Attached is the log you have requested. VaudIxu still appears as a extension on chrome; if I uninstalled chrome and reinstalled chrome fix the issue? Thanks for all your help.

    Regards,

    Biju
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall ALL of the below with Revo Unistaller. Search Protect is garbage, but obviously we're uninstalling all the google components for good reason (to clear Chrome and reinstall afterwards)
    • Google Chrome
    • Google Talk Plugin
    • Google Update Helper
    • Search Protect


    Now before you reinstall Google Chrome, do this (and do not reinstall until I say)

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. llcoolbiggs

    llcoolbiggs Private E-2

    Dear Kestrel13!,

    I have used Revo uninstaller to uninstall the programs you have mentioned and then ran the MGTools as you have mentioned and was getting ready to attach the log; now a new problem arose. My computer restarted on me and now I cant log in the my main account, I have forgotten my password and instead use a fingerprint scanner to log into my computer but now when I use the scanner it says please input password; any suggestions to fix this? Anyway attached is the log I was able to obtain through my guest account hopefully this helps. Thanks again for all your help.

    Regards,

    Biju
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Surfing Protection <<< Uninstall this.

    C:\Program Files (x86)\Google <<< Delete this folder.

    Now reinstall Google Chrome and let me know the situation.
     
  13. llcoolbiggs

    llcoolbiggs Private E-2

    I can't live get into my main account on my computer to delete the file, it keeps asking for a password which I don't remember. Is there a way around this?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That is topic for the software forum I'm afraid. :(
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What main account? Your user account that you have been using to post logs here is a member of the admin group so you can delete this yourself. You may need to delete any files and subfolders in that Google folder first.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds