Redirecting Virus/malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by larmar88, Dec 19, 2015.

  1. larmar88

    larmar88 Private E-2

    a few days ago i downloaded a bad file wich later gave me problems with my internet browser (chrome). fromt time to time i get redirected to other sites. i did try to resolve the issue with various porograms before i came here, hope that doesn't make it harder for you guys. i saw in the guide with ccleaner that you didn't want me to cleanup the registry, but i have already done that a few days ago with advanced systemcare.

    anyway, here are my logs

    i have also run junkware removal tool, and it came up with this:

    File System: 2

    Successfully deleted: C:\ProgramData\productdata (Folder)
    Successfully deleted: C:\Users\Marius\AppData\Roaming\productdata (Folder)



    Registry: 0
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Files tab and locate these detections:

    • [PUP][Folder] C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} -> Found
    • [PUP][Folder] C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Follow the below instructions to reset Google Chrome:

    Reset Google Chrome to defaults

    Let me know how things are running.
     
  3. larmar88

    larmar88 Private E-2

    here is the log, still having problems though. the first thing that happened after reboot was that i got redirected to some game-site
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And this only happens with Google Chrome?
     
  5. larmar88

    larmar88 Private E-2

    Chrome is the only browser i use. i haven't downloaded any other browsers to check
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would back up your bookmarks and then uninstall Google Chrome and Google Update Helper using Revo Uninstaller.

    Then use Internet Explorer to download Google Chrome again, reinstall and let me know how it's going....
     
  7. larmar88

    larmar88 Private E-2

    as far as i know i don't have a google update helper. i did the delete chrome and it found some ad-ons i didn't knew about. haven't had any problems since. i will let u know if i get redirected again, but it seems to be working fine.
    thanks for the help :)
     
    Kestrel13! likes this.
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. Surf around a while and then get back to me if it starts happening again. : - )
     
  9. larmar88

    larmar88 Private E-2

    it is back :( the link that appears before i get redirected this time is newpoptab.com if that is to any help
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  11. larmar88

    larmar88 Private E-2

    here are the logs
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I see you have Opera installed. Can you surf around using Opera afterwards and let me know whether it is redirecting, too?

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.

    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.

    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Then attach the below logs:
    • Fixlog.txt
    How are things running?
     

    Attached Files:

  13. larmar88

    larmar88 Private E-2

    when i use opera i get some pop-ups and i get some warnings by Iobit malwarefighter (i disable this when i scan, but i use when not), also, the "go back"-button don't work.
    u tell me to Download Fixlist.txt, but i don't see a link, how do i download it?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I uploaded a file (look at the very end of my post)
     
  15. larmar88

    larmar88 Private E-2

    got it :) i ran the fix, but the first thing that happened after reboot was another redirect. here is the log
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Where did it redirect to this time?

    What were the warnings please from Iobit?

    Uninstall Google Chrome again using Revo Uninstaller. Do NOT reinstall Chrome until I say so.

    Next do this....

    Please download AdwCleaner by Xplode and save to your Desktop.


    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: All Chrome related folders need to be deleted afterwards and also even the shortcut link used to start Chrome. Leaving any of these around could be a cause of bringing back the same issue if the problem really is in Chrome.

    Examples of what to delete:

    C:\Users\Marius\AppData\Local\Google\Chrome
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    C:\Users\Public\Desktop\Google Chrome.lnk
    C:\Program Files (x86)\Google\Chrome

    I would also delete the below and get a new copy
    C:\Users\Marius\Desktop\ChromeSetup.exe
     
    Kestrel13! likes this.
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thankyou.

    Take note of what Chaslang has said, larmar88, delete all that he has explained in the post, (if you see the files/folders...) AFTER uninstalling Chrome with Revo, and once you attach the requested logs I shall see if anything remains. Again, as stated, do not reinstall Chrome until I say.
     
  19. larmar88

    larmar88 Private E-2

    is still redirects to newpoptab.com first, than i redirected to a random site, sometimes unibet, sometimes some google-site.

    the warnings from iobit was something like.....we have blocked a potensial harmful internet-site, , i can't remember exactly, haven't had any redirects from opera today. the new tab still pops up, but it is blank. (in opera the whole page shows, iobit doesn't block it)

    i have used Adwcleaner before i came to this forum, so i uploaded Quarantine.log as well, don't know if it has any interest to you. this time i only ran the scan and got the log, i haven't cleaned it.

    i searched my computer for "chrome" and deleted everything i suspected had something to do with google chrome, including the folders i found Chaslang mentiod. i did this after the scans though.

    when i was deleting chrome using Revo, i had to manually close "chrome-installer" from task manager. Revo would proceed past post 3. i didn't have this problem last time
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes it was useful to see the adwcleaner quarantine log. Thanks for attaching that too.

    Do this:


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Surf around using Opera for now until I make another post to you. It's very late here in the UK and I have to sleep.

    Let me know about the reg patch and if you got a success message or not.
     
  21. larmar88

    larmar88 Private E-2

    i got a message telling me that it was added to the registry.
    thanks, i will do that :) good night
     
    Kestrel13! likes this.
  22. larmar88

    larmar88 Private E-2

    just got redirected again using opera, the above links are copied from my history. the newspoptab-link is always coming first, than i get redirected, this time into 30-day-change, been redirected to this site several times using opera before.
    i,m using a newer version of opera now that i also had on my computer, the one i used before was from 2013 and horribly slow
     
    Last edited by a moderator: Dec 22, 2015
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Last edited: Dec 22, 2015
  24. larmar88

    larmar88 Private E-2

    this was on the new version. i didn't have any problems on the old version, had it running 4-5 hours yesterday.
    when i said i have been redirected to this several times before, it was of cource with chrome, not opera, sorry about that.
    my avast antivirus just blocekd this link, also using the new version of opera:

    trackmyvoluum

    i will run it tonight, i have to get to work now
     
    Last edited by a moderator: Dec 22, 2015
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So just to be absolutely clear on this... are there any redirects in opera? You said you are, so I presume you are, but then you said this which confused me:

    So just to clarify.... let me know. ;)

    Delete these:

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore
    C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA

    Me too actually. So I'll post something else for you to try as well when you have finished work. I am seeking guidance about this in the background.

    Run this and upload the results.

    Using ESET's Online Scanner

    Also I want you to run a FULL system scan with Avast and let me know if it finds anything.
     
    Last edited: Dec 22, 2015
  26. larmar88

    larmar88 Private E-2

    i have redirects on my new opera, not on the old one. on the old one a new tab opens, but it is blank, probably because of IObit.

    deleted :)

    attached the log from eset.

    just after i ran eset, avast blocked an attempt to redirect me to nowpops on the new opera. i still got redirected at a later time though

    bitdefender did't find anything
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning. I have to dash off very soon to do a few things. In the mean time let me ask you, did you indeed run a full system scan with Avast?
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also... I'm wondering... does Internet Explorer redirect as well?
     
  29. larmar88

    larmar88 Private E-2

    sorry, forgot to post that :) yes, avast didn't find anything either
     
    Kestrel13! likes this.
  30. larmar88

    larmar88 Private E-2

    i have not used IE much, but i can try surf around on it tonight. have to go to work again
    i will leave on a christmas-holliday tomorrow morning, so i won't be able to do much more this week. but i will let u know about IE
     
    Kestrel13! likes this.
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK first thing to try now is this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKCU\..\Run: [BingSvc] C:\Users\Marius\AppData\Local\Microsoft\BingSvc\BingSvc.exe

    After clicking Fix exit HJT.



    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.


    Surf using Opera and let me know if you get redirects.
     
    Last edited: Dec 23, 2015
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Got to pop out for a little while, but I'll be back soon...
     
  33. larmar88

    larmar88 Private E-2

    here is the log. today both opera and IE open up new tabs, but the redirects are blocked. (the page says it can't be loaded) get this message from avast wich i also attached.
     

    Attached Files:

  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK hang in there... I have to dash out for a quick half an hour or so, I'll post back with a response asap :)
     
  35. larmar88

    larmar88 Private E-2

    no problem :)
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    I'd like you to power cycle your router (reboot it)

    • Switch off and unplug the power from your modem/router.
    • Leave both unplugged for 30 seconds.
    • Plug the power back into the modem/router and verify that you are again connected to the Internet.

    Also follow the instructions here for Windows 7 to >>> Reset your Host File

    Try the 'easy fix' option.

    Reboot the machine and surf around using both IE and Opera.
    Report back to me how each browser behaves.

     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The latest MGlogs.zip does not contain all new log files. Either you did not wait for it to finish running before getting the log or some problem occurred. You must wait for Run the C:\MGtools\GetLogs.bat to tell you that it is finished.
     
  38. larmar88

    larmar88 Private E-2

    the "run"-window did Close without me pushing a button, so there might be a error involved. unfortunately i don't have more time to do anything more this week, i have to Wake up in 7 hours to og on a 5-days holliday for Christmas. i will get back to the thread the 28/12.

    after the "Reset your Host File" i have experienced a redirect on IE, but not on opera yet. have been running it about 1 hour.

    i am using a mobile internet (usb-plug With sim-card), don't know if that affect anything. i did unplug it for about 1 minute.

    i'm very thankfull for the help so far. i will get back to you next week
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you try not using this and use a direct wired connection to see what happens. The source of you redirects could be related to how you are connecting since it would be a common point no matter which browser is being used. And your logs are not really showing any signs of problems
     
    Kestrel13! likes this.
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you still with us, Larmar88?
     
  41. larmar88

    larmar88 Private E-2

    I'm coming home tomorrow night. I will get back to you then.
     
    Kestrel13! likes this.
  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahhh I forgot you said you'd be away a while. Catch you tomorrow. ;)
     
  43. larmar88

    larmar88 Private E-2

    C:\MGtools\GetLogs.bat don't seem to be working as it should be. the run-window closes before it tells me it has completed. should i try delete and re-download mgtools?
    i don't have any other way to connect to the internet than the usb-plug. i have wifi on my phone, but no wireless network card on my computer
     
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Larmar88,

    Let's see what Chaslang says about this. Hang in there. ;)
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Back in message # 38, I had requested that you use a direct connection ( a wired connection ) rather than wireless because your problems seem to be related to using wireless. Can you use a wired connection?

    Is Avast uninstalled or uninstalled? We need it to remain uninstalled.
    Are there any other protection programs installed that could be causing issues?
     
  46. larmar88

    larmar88 Private E-2

    i don't have access to a wired connection in my home.

    avast is installed, but i turn it off when i run scans.
    iobit malware fighter and superantispyware is on my computer, but i exit it anytime i run a scan
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Really! You don't have a switch or a router that has a physical Ethernet port? Does this mean that you only tether to your phone?

    Previously you had said the below:
    It is possible that this is the source of the redirects you had been seeing.


    But we want you to uninstall them to make sure that they are not getting in the way or causing any other problems. Simply turning them off is not good enough because some aspects of the program would still be running.

    Also please indicate what exact problems still remain.
     
    Last edited: Dec 29, 2015
  48. larmar88

    larmar88 Private E-2

    no switch, no router, only a usb-plug with sim-card that connets to the network. works kind of like a mobile phone, but it is not connected to my phone in any way.

    i have now deleted all programs i can think of providing any security, avast, superantispyware, all iobit-programs, ccleaner.
    C:\MGtools\GetLogs.bat still won't run as it should.

    the problem has not changed much since i first posted here, i get redirected when i am surfing on internet. usually i can tell that it is going to happen, when i hover over a link f.ex. , the link will not highlight, instead i get redirected to a new tab when i click. sometimes i get redirected on the same tab i stay on, can happen instantly, can happen hours after i last used it. it is not a big problem, as i can do everything on my computer as before, it is more of a big annoyance, and of cource i worry that it will damage my system more.
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But there is a network!!! If there is a network then some kind of router/switch must exist inorder to provide you with internet service. Who is providing your internet service?

    Please try the below:

    It may not be malware! It may be related to how you are connecting to the internet.
     
    Kestrel13! likes this.
  50. larmar88

    larmar88 Private E-2

    Telenor is providing my internet service. it is called "mobile broadband". if i take this if i take this usb-plug and put it in another computer on the other side of the country, or other side of the world for that matter, it will still provide me with internet on the computer i put it into, i don't have something in my home to make a wired connection. the usb-plug works just like a phone in the way it connects to the internet (it is not a wifi). (sorry if this is confusing, english isn't my native language, i'm trying my best to explane this)

    i get this message after 2 of the scans: "C:\MGtools\process.exe is not recognized as an internal or external command, runable program or batch file"
    here is the log
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds