Chrome (and Ie) Being Redirected

Discussion in 'Malware Help (A Specialist Will Reply)' started by batch, Mar 6, 2016.

  1. batch

    batch Private E-2

    After clean with malwarebytes, Chrome works ok for a bit. then suddenly we get redirected to random popup websites that have no way to close. Instead of clicking their popups, I just kill the browser app w/ taskmanager.

    Malwarebytes identifies and cleans. Hitman still finds stuff (but I don't let it clean as per instructions). Redirect behavior reoccurs after some seeming random time following cleaning/log generation procedure.

    Attached are logs as well as a screenshot of the browser history showing one of the redirected websites (but there are others)

    Also, these logs were generated according to the procedure except I unintentionally skipped the Defogger disable disk emulation software step. However I just ran defogger before posting this message and when i clicked disable, there was nothing to disable apparently b/c it didn't ask to restart the computer. Either way, i'll start re-running the scans and logs and attach them as soon as they are done.

    TIA :)
     

    Attached Files:

  2. batch

    batch Private E-2

    screenshot of redirect
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I work thru the rest of your logs, run Hitman Pro again and then activate the 30 day free trial license. Then allow it to cleanup the malware and potentially unwanted programs that it reported. Then immediately reboot. After reboot, run a new scan with Hitman Pro and attach the new log.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing my previous instructions with Hitman Pro, please continue with the below.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of the code box
    • Make sure that you scroll all the way to the bottom of the code box to get the whole fix!
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\ProgramData\2378617a-0695-1
    C:\ProgramData\2378617a-0891-0
    C:\ProgramData\2378617a-4a21-0
    C:\ProgramData\2378617a-51f1-0
    C:\ProgramData\2378617a-5b83-0
    C:\ProgramData\2378617a-6033-0
    C:\ProgramData\2378617a-7161-1
    C:\ProgramData\2378617a-7323-0
    C:\ProgramData\2378617a-77b7-0
    C:\ProgramData\2378617a-7961-1
    C:\ProgramData\2378617a-7ea7-0
    C:\ProgramData\8639195a-6ad5-1
    C:\ProgramData\8639195a-6fc1-0
    C:\ProgramData\cee5ef33
    C:\ProgramData\{026bf527-012c-1}
    C:\ProgramData\{159b01b6-312c-0}
    C:\Users\3elite\AppData\Local\Temp\*.*
    
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, Win7, 8 or 10, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7, Win8 or Win10, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. batch

    batch Private E-2

    Ok, will do. I just finished rerunning all the intro scans after disabling disk emulation with defogger. Just in case, they are attached here. I'll go to hitmanpro as instructed above and post log as instructed. thx
     

    Attached Files:

  6. batch

    batch Private E-2

    Complete. Thx. Report on behavior in next post w/ screenshots
     

    Attached Files:

  7. batch

    batch Private E-2

    Chrome still misbehaving. I was able to get to google and do random searches. Appeared ok. But...

    Searched majorgeeks, no problem. search "major geeks malware" and i get Capture 1 popup. click the x in right corner and get redirected to Capture 2. hit the Chrome application X (to terminate the Chrome app) and get capture 3. Finally killed w/ task manager.
     

    Attached Files:

  8. batch

    batch Private E-2

    One more note about how I'm executing these instructions. I'm not opening Chrome unless you or the procedure instruct me to do so expressly to see if the problem has cleared.. I download all the tools on another PC, transfer them by flash drive. Same w/ the logs and screenshots.

    Thanks for your assistance w/ this persistent booger.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let's reset Chrome to defaults to remove any potentially unwanted extensions. See the below link for how to do this.

    Reset Chrome to Defaults

    Let me know this helped.
     
  10. batch

    batch Private E-2

    I reset the Chrome settings. closed, then reopened Chrome. Search "majorgeeks malware removal" and get Capture 4 popups.

    Did a malwarebytes scan only - attached. Same stuff is back.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please re-run the C:\MGtools\GetLogs.bat per my previous instructions again. Your last log was not fully updated. It looks like you did not wait for it to finish running before grabbing the log.

    Also run a new scan with Hitman Pro and attach a new log.

    Do you still have these same issues if you shutdown Chrome completely and then only use Internet Explorer?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also please follow the below instructions.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8/10 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    Please download the latest version of FRST the below link.

    Farbar Recovery Scan Tool and save it to your Desktop.

    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  13. batch

    batch Private E-2

    Yes, IE has same behavior. See screencaptures 5-7. First a countdown popup appears in bottom left capture 5, then redirect capture 6, then when close app, the wait don't go appears capture requiring taskmanager to kill IE.

    Reran getlogs.bat (sorry bout that). Attached.

    Reran Hitman Attached.
     

    Attached Files:

  14. batch

    batch Private E-2

    Ran ADW. Attached

    Ran FRST. Attached.

    Haven't opened IE or Chrome to test if all clear. Awaiting instructions. Thanks again.

    Oh, one note to be clear on order of events: I did the IE behavior test (captures 5-7) before performing MGTool\getlogs.bat, hitman, adw, FRST.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.

    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.

    Also at this point, I want to double your status by having you run another scan with FRST like in my last message and attach the new FRST.txt logs.

    How are things working now?

     

    Attached Files:

    Last edited: Mar 9, 2016
  16. batch

    batch Private E-2

    Ugh. Somehow the windows 10 update was kicked off. Once started, i couldn't stop it. Neither wife or i or kids remember asking it to update but we must have.

    OS updated. Chrome still misbehaving. Same behavior.

    Should i rescan, redisable UAC, Defogger, etc or proceed with above instructions?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the my last fix anyway and attach the logs that were requested.
     
  18. batch

    batch Private E-2

    Alrighty. Ran FRST Fixlist.txt. FixLog attached. Ran getlog.bat. MGlogs.zip attached. Ran FRST scan. FRST.txt attached.

    After doing all that, i opened chrome. Same problem. doesn't really seem to matter what website i go to.

    Again, appreciate your help.
     

    Attached Files:

  19. batch

    batch Private E-2

    Sorry, important detail. I disabled internet adapters prior to FRST fixlist and throughout the scans. Re-enabled before opening Chrome.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This looks better. The DNS hijacks are gone. How is it working?
     
  21. batch

    batch Private E-2

    So it's still behaving poorly (see capture 1.jpg). Those scans that are clean are from before i open a browser to test it out... here are scans (only scans) after i've run browser (FRST.txt and malwarebytesscan.txt)....

    Looking at my installation history (capture.jpg), i installed malwarebytes a little after the issue popped up. So if no objections, i'd like to remove Roblox program... it's a browser based game...."freeware". the kink that i've warned my kids about but they're kids and make mistakes. Would it hurt to remove roblox, then clean using FRST as above, then see if it's gone?

    What do you think?
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That snapshot does not look like a redirect. It just looks like advertising. This can happen on many websites that have double underlined links appearing under certain keywords on the webpages. This is context sensitive advertising and websites use this to help offset costs of running the websites. When your mouse moves over any of these double underlined keywords, a popup will appear. This would not be a redirect.

    But I cannot see all of what that popup is for. It shows Advertisement | Powered by but it does not show by who. What does the pull down arrow/button to the right of Powered by cause to show up.

    Now there are some forms of these popups that will appear when various junkware is installed on a PC but we have removed all of your junkware. So if it keeps coming back then it may be due to someone reinstalling extensions and addons. Or it can be due to automatic resyncing from online backups.

    What version of Chrome are you running and what additional addons/extentions do you have because it does not look like it is default. It looks like you have things installed into it based on the icons I see. There is an addition icon to the left of the Star in the URL box and there are two icons to the left of the Customize and Control Google Chrome button. What are these? Are any from Avast?
     
    Last edited: Mar 19, 2016
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot to answer this. Yes you can uninstall it but it is not known to be malware.

    Now this comment brings up an interesting point/observation. I see that there is only one user account that is being used and it has administrator permissions! Are you allowing your kids to use this account with that permission level? Not recommended especially since it appears that you use this PC for financial stuff. I see TurboTax installed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds