redirecting from all sites

Discussion in 'Malware Help (A Specialist Will Reply)' started by Deans, Nov 11, 2011.

  1. Deans

    Deans Private E-2

    got it to upload
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are again clean. I wonder if you aren't being infected by a game. Do you know what this is:
    C:\ProgramData\Alawar
    It appears to be a game site, but it isn't in your add/remove programs list.

    I would also suggest that you make seperate user accounts. Rename the one to you and create a new one for your wife. That way you may be able to narrow down your activities to see what may be causing the issues.
     
  3. Deans

    Deans Private E-2

    I have no idea what that file was but I have deleted it. I have also deleted deamon tools and it seems my redirects have once again stopped.

    im the only one that users this computer, my husband would rather play his ps3 lol. so you suggest using a different user account? not administors account?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are the only one using the computer, then no, you probably don't need to create a new account.

    Do let me know if you run into problems again. Don't do the final clean up steps again until you are sure your issues are resolved. :)
     
  5. Deans

    Deans Private E-2

    ok thank you, Ill keep an eye on it. It usually starts again when my virus protecter does a full scan, so I will do one today and see what happens, but since I have removed Daemon Tools lite, the problem has left but I don't want to speak to soon ;)
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Fingers crossed!! ;)
     
  7. Deans

    Deans Private E-2

    Bad news, its back again!!!!!!

    I did the scan a few days ago and it was working fine up until last night, just started redirecting back :cry
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What did you do last night? Any thing that might have caused it? I need to see a new log, so if you already removed OTL:

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  9. Deans

    Deans Private E-2

    I seem to be only getting the OTL.txt not the extras.txt.
     

    Attached Files:

    • OTL.Txt
      File size:
      81 KB
      Views:
      4
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\Windows\SysWow64\3096 ... also look for a C:\Windows\SysWow32\3096 file.

    Now since you still have MGTools installed, run the C:\MGtools\GetLogs.bat file and attach a new C:\MGLogs.zip.
     
  11. Deans

    Deans Private E-2

    log below
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    Extract avenger.exe from the Zip file and save it to your desktop.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  13. thisisu

    thisisu Malware Consultant

    Posting for future reference.
    Code:
    O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} hXXps://www.select2perform.com.au/cabs/QOLCheck.ocx (QOLCheck Control)
    Seen in HJT and OTL
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds