Home computer issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by ONEEYEMAN, Aug 8, 2014.

  1. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    On my home machine I'm using FireFox and Avira. Both are the latest and greatest versions.
    Recently, so (yesterday) I started experiencing following symptoms:

    With the Firefox opened, when started to move from one tab to another, or when just sitting in the idle, or just waiting for the page download I started getting following message:

    and the current FireFox page becomes randomly selected, but usually not the one I wanted.

    So I ran R&R and am attaching the logs, hoping that someone will take a look at them and tell me whether my system is really infected.
    Running MGTools was unsuccessful as it didn't complete the run. I tried couple of times and both times it just didn't finish - program just crashed.

    Thank you.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ONEEYEMAN

    Re-run HitmanPro and remove all Potential Unwanted Programs

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Now download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach the JRT.txt to your next message.

    Now run a new scan with HitmanPro and attach the new log.

    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  3. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    Logs are attached.

    Thank you.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re-run AdwCleaner.exe
    • Click on the Scan button
    • When the scan is ready click on the Clean button
    • A log file will automatically open after the scan has finished
    • Please attach the log file, located at C:\AdwCleaner[Sx].txt

    How is your machine running now?
     
  5. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    Log attached.

    Thank you.
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    That log looks good. How is your machine running??
     
  7. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    Preliminary check with FF looks good. Hopefully this stuff is gone. ;-)

    Thank you.
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool

    Let me know if/when you're ready for the final clean-up steps.
     
  9. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    Sorry for the late reply.
    It is around 2300 here.

    Can we do it tomorrow?

    Just post the process here and I will follow ;-)

    Thank you.
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:

    Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds