newbie that has the hijacked funmoods redirect

Discussion in 'Malware Help (A Specialist Will Reply)' started by resoxcvb, Jun 4, 2013.

  1. resoxcvb

    resoxcvb Private E-2

    Hi....newbie here,

    I followed the instruction that i came across while researching this annoying PUP or Malware or whatever it is ...I got all the way down to the part of the GooredFix and I am posting the log....so far it seems to have worked but I am leary....

    I will check back to see what your thoughts are...meanwhile I will check again for this pain.

    reso
     

    Attached Files:

  2. resoxcvb

    resoxcvb Private E-2

    resoxcvb back again....

    wel I went and closed all tabs and browsers....back to the desktop. Clicked back on Chrome....and it is back....funmoods, vGrabber, and whitesmoke....so I did the next step with the TDSS and here are the results

    Interestingly, in the file folders I saw the file for conduit (vgrabber and whitesmoke) but it was empty....also when I first started TDSS it said Symantec...not Kapersky so I redid the process again....IDK what happened but I am impressed with the tenaciousness of this redirect...I mean gotta say that much...lol

    back to the next on the list..

    check back asap.
     

    Attached Files:

  3. resoxcvb

    resoxcvb Private E-2

    I now have another search bar added to funmoods, whitesmoke, and vGrabber....it is the AVG search bar....even after I checked not to install it, it did it anyway...I am going to run the MBRcheck because I want to follow orders...lol I will post the results in a new post.

    resoxcvb
     
  4. resoxcvb

    resoxcvb Private E-2

  5. resoxcvb

    resoxcvb Private E-2

    ah.. here's the TDSSKiller...sorry just tired...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are running the Google hijack thread fixes but you need to complete the instructions in the last step which send you bac to the below link which is what we need you to run.


    READ & RUN ME FIRST. Malware Removal Guide


     
  7. resoxcvb

    resoxcvb Private E-2

    Aloha Chasling,

    I appreciate your time but I had to change computers.....I was first posting to you via my work laptop (Lenovo) but I got nervous with the Daemon thing....its my work laptop and they run Lotus notes and I saw that on there so I went to my PC.... which coincidentally has the same issue. :cry

    So I re-did the process again for my windows 7 Home Premium, x64-bit based desktop and it is an eMachines :(

    I also had STOPx000000 msgs that I think I fixed but still stalls once in a while. The re-direct is still omnipresent....I restore back to factory settings last week but the funmoods et al are still here.

    Here are the uploads of the RR Me instructions
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything. Make sure you click Upload.
     
  9. resoxcvb

    resoxcvb Private E-2

    Awe crappola....I apologize.....here are the fix reports
    reso

    I am re-reading the RR Me and then I will check back as I begin this process.

    Thanks for your patience.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still no logs attached.
     
  11. resoxcvb

    resoxcvb Private E-2

    ok here it is ....again...:-o
    hmmm it kept saying "Invalid file" but I finally got them off and uploaded...



    I wanted to say that I just finished the DNS router hijacking instructions because I can do it on this router and I reset it to default factory settings. I just powered back up 10 minutes ago and so far so good....:)

    I will check back after I go all the way out and log on again to see if indeed the hijackers are gone....

    a thanks ahead of time:major

    brbs
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please see my first post!!! You do not need to run the Google Redirection thread at all. You need to run the main sections of the READ & RUN ME FIRST. Even the end of the Google Redirection thread tells you this. The last few lines say
     
  13. resoxcvb

    resoxcvb Private E-2

    ok...ok...yes sir :major

    sorry. I got it ....I was doing the wrong posts first......I got excited.

    Ok...here are the logs....:-o


    thanks again,
    resoxcvb
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not seeing any signs of Funmoods in your logs. Perhaps it has all been cleaned up already. But let's run one more check.


    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  15. resoxcvb

    resoxcvb Private E-2

    thanks major....I do not see the pesky tab horders...thanks and I will be running the junkware removal tool asap....meanwhile
    just a quick update and to ask if you know of some answers or help for the other problem I'm having
    I have a norton pop-up saying... I have a high memory usage
    ... the frequency is out of range then the
    computer crashed Blue screen of death.... and system error message - 6.1.7601.2.1.0.768.3 ID 1033 BCCode:50 OS Version 6_1_7601 Service Pack 1_0 Product 768_1

    got it to reboot....loaded the updates one at a time....and then crashed again
    System error msg...Fltmgr.sys Address FFFFF 880011A6166 base at FFFFF880011A2000, Datesstamp 4ce7929c

    This time the emachines no can start up....had to reboot with the OS disk....
    it booted up and is currently in safe mode with networking

    So what do you think I should do?

    resoxcvb
     
  16. resoxcvb

    resoxcvb Private E-2

    Back again....here is the JRT.txt :major and Major thanks.

    resoxcvb
     

    Attached Files:

    • JRT.txt
      File size:
      920 bytes
      Views:
      1
  17. resoxcvb

    resoxcvb Private E-2

    back again and I wanted to say thanks for all your patience....i still do not see the redirect hijackers and I just completely finished reading the forum for the IE 7 crash site....and hmmm....so far so good.....I never would have thought it to be shell.exe

    I will check back tomorrow to let you know if all is still good....I can still remain a member ....right.

    resoxcvb
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes this is because you do not have enough memory in your PC to properly run Windows 7. You do not even have enought to properly run Windows XP. Your logs show
    Code:
    Installed Physical Memory (RAM) 1.00 GB 
    Total Physical Memory 894 MB 
    Available Physical Memory 196 MB 
    You have 1 GB installed but only 894 MB available for Windows and other applications to use because 128 MB is likley used for an on board graphics card. And you only have 196 MB free. You really need to have at least 3 GB installed.


    You will have to post in the Software Forum for non-malware problems. There really was no malware on you PC based on the logs.

    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds