Browser Hijacked (i Think)

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheTick, Jun 4, 2016.

  1. TheTick

    TheTick Corporal

    Hi Guys

    I am having some problems with my browser, i think it has been Hijacked as it keeps loading Yahoo search on google chrome..
    I was downloading emulation software last night and think i must have missed a bundle installation (i am usually good at spotting them) Installed a Malware scanner and changed my internet browser..

    I have run all the relevant scans needed and shall attach them to this msg.

    Do i need to tell you about my spec? i forgot as its been a while since i posted on here..

    All scans ran well and i had no issues.. However I think it was when i run Tdsskiller a browser opened and showed me screen shots of possible PUMs on my system, i will attach the screen shot of that too :)
     

    Attached Files:

  2. TheTick

    TheTick Corporal

    Just adding MGlogs :)
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Let's see if these tools reveal anything before resetting your Chrome browser -

    Please download ZHPcleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
      • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
      • Then press the ''Repair'' button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
    Next download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.
     
  4. TheTick

    TheTick Corporal

    Hi

    Thanks for your response :)

    I have completed the scans you asked for and will attach them to this msg..
    Tick
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Please use MSconfig to reset your machine for normal startup mode. Any other mode is primarily used for temporary troubleshooting and diagnostic purposes only.

    How is your Chrome browser behaving, now?
     
  6. TheTick

    TheTick Corporal

    Hi

    Forgive me but i am unsure what you mean by MSconfig, is that throught MGtools or do i have to type that into command prompt?

    Also my browser seems to be still loading yahoo when i click chrome.. I have uploaded an image to show you :D

    Thanks
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Run Selective Startup using System Configuration
    Start orb > Control Panel > Administrative Tools > dbl-click on "System Configuration"
    Next Gui - choose the "General" tab and put a tick in the Normal startup box and click the OK radio button. RE-BOOT

    *Listed below are the softwares whose startups are being controlled/disabled by MSConfig. Please read Dealing with Startup Processes for better methods.
    Try resetting your default search engine. See -> https://support.google.com/chrome/answer/95426?co=GENIE.Platform=Desktop&hl=en-GB
     
  8. TheTick

    TheTick Corporal

    Hi

    I have completed the first step that you asked me to do and reset the computer to normal start up mode...

    As i am a noob i am unsure what to do with the MSconfig bit after the normal start up.. do i need to go into each piece of software and disable the load on start up?
    I have run Hijack this and got a log but am not sure what is bad or good in the findings..

    Also i have tried to reset chrome to default search engine and it hasnt worked..

    Also the comp seems to be running ok aside from the browser issue :)

    Thanks Mate
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Now using the first link I gave, with the help of a friend or our Software forum, choose and familiarize yourself with the workings of one of the recommended Third Party startup managers listed.

    Please review the following for directions on how to reset Chrome to default settings.
    Reset Chrome settings to default

    Did that correct the problem?
     
  10. TheTick

    TheTick Corporal

    Hi

    Yes that reset the Chrome link worked and i am no longer being redirected to Yahoo :)

    I have also used one of the programs in that link you suggested and have managed to stop some programs loading up on start up.. However i think i will make a post in the software forum to make sure i am doing this correctly :)

    Are my logs now clean?

    Thanks
    Tick
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome and your logs are clean! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  12. TheTick

    TheTick Corporal

    Hi dr moriarty

    I have completed the final steps for the clean up :) my comp seems to be running back to normal..

    Thank you soo much for your help :)

    Tick
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) You're very welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds