Please help with malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by employee1107, Jul 9, 2013.

  1. employee1107

    employee1107 Private E-2

    Hi
    I ran the 5 malware removal tools as instructed and I'm attaching the logs. The problem I'm having is when I click on links I get redirected to other websites. I have no problem when I type in the address bar. Please help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You must uninstall the below immediately because you already have McAfee Internet Security installed.

    Microsoft Security Client
    Microsoft Security Essentials

    Is this problem only happening when you use Firefox? Please close Firefox and run Internet Explorer and see if you have the same problem or not.
     
  3. employee1107

    employee1107 Private E-2

    Thanks chaslang,

    I removed MS Security Essentials but I don't see MS Security Client.

    Yes, you're right, it seems I have the problem only while using Firefox.
    Should I get rid o Firefox?
    Also, I noticed that Hitman Pro found some problems but as instructed I ignored them. Do I have to do anything with that?

    Thanks again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this >> Reset Firefox to Defaults


    We will get to other issues, but first a question about what is in Hitman. I want to be sure that the StlMobileWeb it showed is not something you have knowingly installed.
     
  5. employee1107

    employee1107 Private E-2

    chaslang,

    I don't remember installing StlMobileWeb. But I think my problems started after I dawnloaded Sumsung Kies software for my phone networking (I removed that from my pc already). May they be related?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No Samsung Kies is legit. See >> http://www.samsung.com/us/kies/

    Did you do the reset to Firefox? If so, shutdown Firefox and then reopen. See how it is working.
     
  7. employee1107

    employee1107 Private E-2

    I did not reset Firefox because I uninstalled it before I read your previous message. I downloaded it now and it seems to be working fine so far.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now rerun Hitman Pro and allow it to fix the items it detected as malware. Then reboot. After reboot, run a new scan with Hitman Pro and attach the new log.

    Also tell me if you are still having any malware problems now.
     
  9. employee1107

    employee1107 Private E-2

    I did as instructed. On the first run Hitman detected 2 items that were quarantined. I rebooted and ran it again and I'm attaching the log.
    I'm not sure if I still have problems, I thought I don't but just now when I clicked to upload the file for this message a new window opened that said:
    "Attention It is recomended that you download FLV MPlayer to continue"
    The page address started with: http:/bizcoaching.info/......
     
  10. employee1107

    employee1107 Private E-2

    Here is the log file
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well based on this last log, everything should be fine now. The StlMobileWeb junk is gone.

    You will have to explain whether you are really still having problems.
     
  12. employee1107

    employee1107 Private E-2

    chaslang,
    Thank you very much for your help. I think everything is working fine. Do I have to do anything with the files that were quarantied by Hitman? I'm not sure where they are...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    The below should take care of it.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds