Virus Removal Help Please

Discussion in 'Malware Help (A Specialist Will Reply)' started by CommandrKeen, Dec 27, 2012.

  1. CommandrKeen

    CommandrKeen Private E-2

    Did the scans here are the reports. Hitman Pro log is not here but not threat was detected with it.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    I'm reviewing your logs CommandrKeen, and will work up a fix shortly.

    dr.m
     
  3. CommandrKeen

    CommandrKeen Private E-2

    Alright Thanks Doctor
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Users\John Doe\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance. ;) You have some nice oldies, by the way.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:
    • [STARTUP][SUSP PATH] GamersFirst LIVE!.lnk @John Doe : C:\Users\John Doe\AppData\Local\GamersFirst\LIVE!\Live.exe -> FOUND
    Place a checkmark on this item, but leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message.
    Do not reboot your computer yet.

    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.

    Yontoo 1.10.03
    Java 7 Update 7 (64-bit) <-- outdated
    Java 7 Update 9 <-- outdated
    Java Auto Updater <-- outdated
    Java SE Development Kit 7 Update 7 (64-bit) <-- outdated

    Please disable all anti-virus and anti-spyware programs while we do the following steps(re-enable before coming back online):

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Next download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\Users\John Doe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk
    C:\Users\John Doe\AppData\Local\GamersFirst
    C:\Program Files (x86)\Yontoo
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Please install the latest Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double-clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how your machine is now working.
     
  5. CommandrKeen

    CommandrKeen Private E-2

    It is working pretty good so far. The problem was that I had a Google redirect virus and it isn't messing with my Google search results as of right now. It's spotty though. I won't get any redirects and then suddenly sometimes I will.

    I uninstalled Yontoo and GamersFirst before I got your instructions so these were missing:

    Yontoo 1.10.03
    Java Auto Updater <-- outdated [unrelated to what I just said]

    These weren't in the HJT scan results

    O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
    O4 - Startup: GamersFirst LIVE!.lnk = John Doe\AppData\Local\GamersFirst\LIVE!\Live.exe
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your logs are looking better, CommandrKeen.

    Please download AdwCleaner and save it to your Destop.
    • Double-click AdwCleaner.exe to run it. (Vista & Win7 users should right-click and "Run As Administrator")
    • Click on Delete
    • Your pc should now automatically re-boot
    • AdwCleaner will display a log showing the files, folders, and registry entries that were removed.
    • Attach this log to your next reply.
    Now test for any re-directs. If so, with which browser is it happening?
     
  7. CommandrKeen

    CommandrKeen Private E-2

    Alright, there are no more redirects. Here is that log from ADWCleaner.exe.
     

    Attached Files:

  8. CommandrKeen

    CommandrKeen Private E-2

    Shit. Just got a redirect in Chrome to Findgala.com...
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please refer to the below link to reset Chrome to its default settings.

    http://www.tothepc.com/archives/reset-google-chrome-to-default-settings/

    Now download OTL by OldTimer.
    Is Chrome still being re-directed?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds