Hyperlinking/redirecting virus...ughh!

Discussion in 'Malware Help (A Specialist Will Reply)' started by juliefabian5, Nov 12, 2013.

  1. juliefabian5

    juliefabian5 Private E-2

    I'm baaaack:cry. The problem I had before and that you all so kindly helped me with is back: On my home page in Google or Ustart hyperlinking apears all over and if I pass over one it shows a link to an ad site. I've also noticed that I'll get random live ads while using projectfreetv (after I've navigated all the initial ad minefield). The hyperlinking appears on most every internet page I visit. It's impossible to move the cursor without triggering one.

    I'm using Windows 8, Chrome.

    I've gone through the whole Malware protocol and so will attach all logs. I remembered afterward that what had finally worked the last time was uninstalling my Avira (because it had been hijacked by the virus) and Chrome, completing all the malware steps, then reinstalling. So I did that, but this time it didn't work.

    I think the virus came in with a bogus Java update. The last thing I remember before noticing the virus was back was a Java update, then, oddly, another a short while later.

    I also tried folowing the search engine redirect protocol but had trouble because I need specific Windows 8 instructions.

    Oh yes, I also have shadow copies of files all over the place.

    Thank you in advance for any help you can give me.

    Julie

    (I can't seem to attach my PDF doc with print screen images of some of the no virus logs TDSSKiller, etc.) View attachment HitmanPro_20131111_1859.log

    View attachment MBAM-log-2013-11-11 (16-42-00).txt

    View attachment mbam-log-2013-11-11 (16-46-41).txt
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the log from running RogueKiller and MGTools - C:/MGLogs.zip.
     
  3. juliefabian5

    juliefabian5 Private E-2

    Sorry about that. Here they are.

    Thanks for your time.

    Julie
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So far I am not seeing any malware in your logs. All I find are the remains of some PUP's.

    You did not attach the correct log.....it should be C:\MGLogs.zip.
     
  5. juliefabian5

    juliefabian5 Private E-2

    I think I screwed up at that point and unzipped the log into a folder. I just rezipped it but there might be other logs in there as well.:-o

    Thanks.

    Julie
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. Are you having this issues with different browsers?
     
  7. juliefabian5

    juliefabian5 Private E-2

    Tim,

    Thanks. No, I only seem to have the problem in Chrome for the time being. The first time I had this virus deleting Chrome and reinstalling it (along with Avira which had also been corrupted) did the trick. This time around it didn't. I have been using Chrome for a couple of years, since I read that it is more secure than Firefox, and better for banking, etc.

    Thanks.

    Julie
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This time, Uninstall Chrome but also delete these folders:
    C:\Users\User Name\AppData\Local\Google\Chrome
    C:\Program Files (x86)\Google\Chrome

    Run CCLeaner and then reboot and reinstall.

    Tell me how that works.
     
  9. juliefabian5

    juliefabian5 Private E-2

    Thaaaaaaaaank you, Tim!! That seems to have worked. I forgot to reboot after doing it the first time and the malware was still there after reinstalling Chrome. Then I repeated with the reboot and voila!

    Thank you so much again.

    Would you mind telling me what you think is the best browser to use? Considering the trouble I've had with Chrome maybe I should use another. Which is the most secure?

    Thanks, Tim. I really appreciate your help and your time.

    Julie:wave
     
  10. juliefabian5

    juliefabian5 Private E-2

    Tim,

    Well I spoke too soon. The malware reappeared after using the browser a bit (on my usual sites - NYTimes, Coursera). I just went through your last instructions again but added deleting Avira and then reinstalling it after reinstalling Chrome. I'll let you klnow.

    Thank you so much again.

    Julie
     
  11. juliefabian5

    juliefabian5 Private E-2

    Tim,

    I still have it. Ughh!

    Julie
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun both RogueKiller and Hitman again and attach the logs, please.
     
  13. juliefabian5

    juliefabian5 Private E-2

    Tim,

    Thanks. Here they are.

    Julie
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and remove the PUP;s. I am not seeing any other issues. Are you sure the issue is not with your download helper?
     
  15. juliefabian5

    juliefabian5 Private E-2

    Tim,

    Thanks, I will do that, but what is a "download helper"?

    Julie
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Look at your RogueKiller log:

    • ¤¤¤ Registry Entries : 10 ¤¤¤
      [RUN][SUSP PATH] HKCU\[...]\Run : AmazonMP3DownloaderHelper (C:\Users\Julie\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [7]) -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-3715041362-360776210-1917054062-1001\[...]\Run : AmazonMP3DownloaderHelper (C:\Users\Julie\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [7]) -> FOUND
    .

    You can remove them if you aren't using it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds