Malware Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by I_HateMAlware, May 22, 2013.

  1. I_HateMAlware

    I_HateMAlware Private E-2

    I've been having trouble with my browser being redirected, but it is not happening automatically and/or all the time. It usually happens sometimes when I click search results provided by a search engine or use the back button on my browser. I noticed that during the redirect the tab in below the address bar will have a random IP address and sometimes I will briefly see Way-search.net in the address bar. I'm usually redirected to a sort of friends with benefits type of site. Fling.com or something like that and a different site as well that I can't remember or a search engine that has some medical categories listed with the address searchmd.com or something similar to that and some site trying to sell me some antimalware software.

    I don't use any file sharing programs or download porn or cracks. I actually simply clicked on a link a few hours before this started searching for the difference between white and black pepper and AVG popped up claiming that the threat was blocked. I navigated away and thought all was good until a couple hours later when I clicked a result for a different search. I'm using IE 10 on a 64-bit Windows 7 OS. I followed through the guide for fixing redirects and that did not solve my problem. I've run all the programs for Windows 7 and have attached all logs.
     

    Attached Files:

  2. I_HateMAlware

    I_HateMAlware Private E-2

    Before someone gets too far into my issue I just want to post an update on the situation. While I was at work my roommate was messing with the computer and apparently ran some scans and decided to do some cleaning. While I'm happy to report that my problems seem to have been solved, I am not 100% confident in his abilities. I'm not sure exactly what scans/tools he used. Also, he decided to do some cleanup and got rid of the tools I downloaded and cleaned up the clutter from the logs I had saved. I'm not sure how this will impact the solutions to the logs I've already posted and the process, but I would still like help from someone that really knows what they are looking for. Where should I go from here? Should I start the cleaning process over and post new logs?
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.
     
  4. I_HateMAlware

    I_HateMAlware Private E-2

    Here are the new logs, but for some reason tdsskiller won't create a log this time around. While it was starting up an error popped up stating "Can't initialize log." It did not find anything when it ran.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it fix everything it found.

    Reboot and rescan with Hitman and attach the new log.

    Be sure to tell me how things are running.
     
  6. I_HateMAlware

    I_HateMAlware Private E-2

    Reran Hitman as instructed and had it fix everything found. Rebooted and reran and attached new log. When my buddy did whatever it was that he did the redirects stopped and internet explorer seemed to be running really well again for about a day. Today I had noticed that it seemed to be struggling sometimes. Although I did rerun CCleaner and dump the temp files and cache and that may contribute to longer loading times, I rarely experience issues with my connection or with IE running like that. I'm not sure now that I have done as you have asked and will browse around and see if it has improved.

    ***Update***
    I'm not sure if that had anything to do with it, but performance does seem to be improved. Pages are loading very quickly and it also seemed that some pages would load fine while others would not.
     

    Attached Files:

    Last edited: May 24, 2013
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, that came back clean. Let me know what issues remain.
     
  8. I_HateMAlware

    I_HateMAlware Private E-2

    Everything is still running smoothly and seems to be working as it was before the redirects started.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds