Here are my logs, for your kind consideration, thanks in advance

Discussion in 'Malware Help (A Specialist Will Reply)' started by GratefulGeezer, Dec 1, 2012.

  1. GratefulGeezer

    GratefulGeezer Private E-2

    hello all,

    please find attached my logs, I have done as instructed, and here is the story:

    Today, I started having a new tab opening to a website about a prize draw, which was very irritating, and I came to this site, did all that is required in terms of house cleaning, and then used the tools, so far the tab hasn't popped up, but I have a feeling this is due to having installed 'SuperAntiSpyWare' trial edition running, so I will put it just in case, even though I don't see the window at the moment.

    thanks in advance.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which browser does this occur in please?

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  3. GratefulGeezer

    GratefulGeezer Private E-2

    hello

    thank you very much for your kind reply, please find attached the scan result.
     

    Attached Files:

    • JRT.txt
      File size:
      809 bytes
      Views:
      8
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And can you tell me please, which browser this occurs in?
     
  5. GratefulGeezer

    GratefulGeezer Private E-2

    Hello

    I apologise for the delay in answering, it was actually 'FireFox 16. something"
    However, I have just checked the version and it is 17.0.1.

    thanks for your patience.

    yours truly.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to be uninstalling your old version of FireFox and installing the new version. Except we will be using Revo Uninstaller. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Any better?
     
  7. GratefulGeezer

    GratefulGeezer Private E-2

    hello all

    I really thank you ever so much, however, yesterday I saw the problem happen again, and tried to do a scan, and midway through the process the screen resolution changed, i tried to fix it but couldn't so I tried to reboot, the system has not responded since.

    thanks anyway.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What scan did you try to do??
     
  9. GratefulGeezer

    GratefulGeezer Private E-2

    hello

    I managed to get imagex.exe and used a wmi file to restore the whole system.
    But it was during 'Malwarebytes Anti-Malware' the version is [(Trial) 1.65.1.1000].
    The screen resolution went big, and I couldn't restore it. so I restarted the PC, but this time it never restarted.

    thanks very much.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If the machine is having troubles booting up now you should post about it in the software forum.
     
  11. GratefulGeezer

    GratefulGeezer Private E-2

    It has booted alright, and right after installing the service pack,
    guess what happened?

    the prize is on offer again!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which browser(s)?
     
  13. GratefulGeezer

    GratefulGeezer Private E-2

    firefox only.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Follow my instructions in post # 6. Then tell me how things are running.
     
  15. GratefulGeezer

    GratefulGeezer Private E-2

    hello

    I have done that and it's been a few minutes since, so all is well so far.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Give it a bit longer and then come back and hopefully tell me all is good! :) Then I'll post final steps.
     
  17. GratefulGeezer

    GratefulGeezer Private E-2

    hello

    I am sorry to say it, but it seems like it's back but this time on both, i.e. is doing it too.

    the message is always the same, it tries to open a site:

    life-localized.com/prize/uk/index.htm

    the same one over and over again.
     
    Last edited by a moderator: Dec 6, 2012
  18. GratefulGeezer

    GratefulGeezer Private E-2

    here's a new mgtools scan attached just in case.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.

    Also...


    Run this and attach the results.

    Using ESET's Online Scanner
     
  20. GratefulGeezer

    GratefulGeezer Private E-2

    hello

    please find the two files attached.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you run the online ESET scanner too? Did it find anything?
     
  22. GratefulGeezer

    GratefulGeezer Private E-2

    here's the result:

    Threats found

    probably a variant of

    win32/Qhost.FGNKYRH/RH trojan

    in file:

    c:\windows\win7_eula.exe

    it has been quaranteed.
     
  23. GratefulGeezer

    GratefulGeezer Private E-2

    hello

    I have removed MCafee, and installed AVG full edition, and it has given me this after restarting

    *screen shot*
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, so is the redirection still ocurring?
     
  25. GratefulGeezer

    GratefulGeezer Private E-2

    it seems to have stopped now.

    mind, everyday first time I run the PC it is happening, and it is a (new tab) being opened rather than a page gets changed to something else.
    today it happened first twice (before installing AVG) then never since.

    AVG found 5 other threats and removed them when installed first.
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run for a while and then come back and let me know.
     
  27. GratefulGeezer

    GratefulGeezer Private E-2

    hello

    looks like it's fixed now, the AVG and adblockplus have done it.
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds