Chitka and other pop ups

Having an issue with chitka and some other kind of pop up. Also a separate issue with certain Microsoft updates not downloading properly. Have run CCleaner, ADW, MBAM, Spybot, Microsoft Ess, Avira and am still having issues…each found an issue and was subsequently cleaned but am still having problems. I did have the mini search bar redirecting or not connecting but that looks like it has been resolved. I am on my in-laws computer so I have no idea what they have done, but it is beyond my expertise at this point…HELP!!!

original ADW log is here but I have cleaned the issue

The Microsoft update errors I have gotten are codes:
5AA
57C
57E

hey and welcome to the forum. thanks for attaching the needed logs.
A malware expert will help you from here when ob is online later today.

:wink:

No sign of Chitka there unless they have changed their methods

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:OTL
FF - prefs.js..extensions.enabledAddons: browserprotect%40browserprotect.com:1.1.3
[2013/03/16 17:13:37 | 000,047,822 | ---- | M] () (No name found) -- C:\Users\Test\AppData\Roaming\Mozilla\Firefox\Profiles\j962rqu2.default\extensions\browserprotect@browserprotect.com.xpi

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download the latest version of TDSSKiller from here and save it to your Desktop.

[*]Doubleclick on TDSSKiller.exe to run the application

https://dl.dropbox.com/u/73555776/tdss%20start.JPG

[*]Then click on Change parameters.

https://dl.dropbox.com/u/73555776/tdss%20Change%20param.JPG

[*]Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

[*]Click the Start Scan button.

[*]If a suspicious object is detected, the default action will be Skip, click on Continue.

https://dl.dropbox.com/u/73555776/tdss%20threat.JPG

[*]If malicious objects are found, they will show in the Scan results and offer three (3) options.
[*]Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

[*]Get the report by selecting Reports

https://dl.dropbox.com/u/73555776/tdss%20report.JPG

[*]Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

Please copy and paste its contents on your next reply.

Running everything now, also having an issue using the mini search engine in the browser. When using Google it sometimes gives a connection lost error, but if I change to yahoo it works fine…?

OTL report posted

18:02:24.0703 2580 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
18:02:25.0265 2580 ============================================================
18:02:25.0265 2580 Current date / time: 2013/03/18 18:02:25.0265
18:02:25.0265 2580 SystemInfo:
18:02:25.0265 2580
18:02:25.0265 2580 OS Version: 6.0.6000 ServicePack: 0.0
18:02:25.0265 2580 Product type: Workstation
18:02:25.0265 2580 ComputerName: GUIDALANDSCA-PC
18:02:25.0265 2580 UserName: Test
18:02:25.0265 2580 Windows directory: C:\Windows
18:02:25.0265 2580 System windows directory: C:\Windows
18:02:25.0265 2580 Processor architecture: Intel x86
18:02:25.0265 2580 Number of processors: 2
18:02:25.0265 2580 Page size: 0x1000
18:02:25.0265 2580 Boot type: Normal boot
18:02:25.0265 2580 ============================================================
18:02:26.0419 2580 BG loaded
18:02:28.0338 2580 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type ‘K0’, Flags 0x00000050
18:02:28.0447 2580 ============================================================
18:02:28.0447 2580 \Device\Harddisk0\DR0:
18:02:28.0463 2580 MBR partitions:
18:02:28.0463 2580 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x244D3718
18:02:28.0463 2580 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x244D3757, BlocksNum 0xF59F6A
18:02:28.0463 2580 ============================================================
18:02:28.0634 2580 C: ↔ \Device\Harddisk0\DR0\Partition1
18:02:28.0853 2580 D: ↔ \Device\Harddisk0\DR0\Partition2
18:02:28.0853 2580 ============================================================
18:02:28.0853 2580 Initialize success
18:02:28.0853 2580 ============================================================

There should be a longer TDSSKIller log at C:\TDSSKiller date time could you attach that

this?

How is the computer behaving now ?

Looks like the popups have stopped and the Google search bar redirecting has also stopped. Still having a slight issue with windows update, any ideas?

update just ran malwarebytes and this came up

What is the problem with windows updates ?

Download Windows Repair (all in one) from this site

Install the programme then run

https://dl.dropbox.com/u/73555776/waio%20start.JPG

Go to step 3 and allow it to run SFC

https://dl.dropbox.com/u/73555776/waio%20step3.JPG

On the start repairs tab click start

https://dl.dropbox.com/u/73555776/waiostart%20rep.JPG

Select the following items and tick restart system when finished

https://dl.dropbox.com/u/73555776/waio%20rep%20list.JPG

I kept having updates not download properly. I ran the program you told me to and now its looking for updates…taking a long time though.

I have attached the log to the cleaning.

updates still wont come in

error codes
5AA
57C
57E

Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760586)
The 2007 Microsoft Office Suite Service Pack 3 (SP3)
Microsoft .NET Framework 3.5 Service Pack 1 and .NET Framework 3.5 Family Update (KB951847) x86

Could you run a standalone update from here http://support.microsoft.com/kb/2760586 and let me know if that works

Also what other problems are apparent