Browser hijacker

Discussion in 'Malware Help (A Specialist Will Reply)' started by kia3563, Apr 5, 2015.

  1. kia3563

    kia3563 Private E-2

    My daughter's computer has a browser hijacker that causes pop-ups and redirects. The problem began about 3 weeks ago. Attached are the log files specified in the Read me guide.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am reviewing your logs and will get back to you with a response asap. :)
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    WSE_Astromenda <<< Uninstall this.



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc) -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc) -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc) -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc) -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    You did not let Malware Bytes fix what it found, if you did, the log does not reflect that, so please rescan, allow it to fix all it finds. Then rescan again attaching a hopefully clean log.


    Re run Hitman and have it fix all it finds too. Then again rescan and attach new log.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  4. kia3563

    kia3563 Private E-2

    Unfortunately, the effort was unsuccessful, browser pop-ups and redirects are still occurring after performing the actions below. Note that there were 2 items that I could not complete, as described below.

    I could not uninstall WSE_Astromenda, I got a message saying that an error occurred and it may have already been installed.

    When I ran RogueKiller again, as you instructed, the following item was not in the list. I deleted the other 4 items that you identified, log file attached.

    • [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} -> Found


    Ran Malware Bytes and allowed it to fix all finds, log file attached.

    Ran Hitman and allowed it to fix all finds, log file attached.

    Ran Junkware Removal Tool, log file attached.

    Ran MGTools, log file attached.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this for uninstallation of WSE Astromenda...



    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Re run RogueKiller (just a scan) and atach new log.



    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  6. kia3563

    kia3563 Private E-2

    Just got home from work. My daughter said that while I was at work today, she uninstalled and reinstalled Google Chrome, and that seemed to fix the problem with the browser pop-ups and redirects.

    I have not yet performed the last instructions that you recommended. I am inclined to wait a day or two, to see if the uninstall/reinstall of Google Chrome really fixed the problem.

    Do you still recommend that I attack removal of WSE_Astromenda, or do you concur with my thoughts to wait and see if the problem reoccurs?

    Thanks for your help thus far. I appreciate the work that you guys do in support of the forum members, and will contribute monetarily to the cause.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :)

    I'd like you to continue with my instructions please.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds