My nephew installed a bunch of Minecraft mods on his new laptop and it’s now riddled with malware. Had them run MalwareBytes and that seemed to get most of it. I’m here now and noticed his search was being redirected by MaxWebSearch or something like that but Adwcleaner seemed to take care of it.
Removed Security Essentials and installed Avast. Scan was clean, but now we’re getting constant WebShield pops for sites like robertsbom5DOTmeSLASHtaskSLASH4001 and MalwareBytes is blocking jubmoz788DOTme.
I had to hop on my brother’s computer to access this forum and download some of the recommend files, browsing is very slow on the infected PC and often fails, especially for security-related sites.
Tempted to restore from partition but I’m reading that may not solve the problem.
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Download and Install Combofix
Download ComboFix from one of the following locations: Link 1 Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
Not sure if relevant, but I think ComboFix created a 32788R22FWJFW folder in C: (with a screen icon). If you click it you basically get the same behavior from as if you had clicked Computer from the Start menu (ie, lists your drives).
Still can’t connect to the Avast forums (server not found error), but the WebShield pop-ups seem to have stopped.
Actually, having trouble getting pretty much anywhere other than Google… go to CNN and it appears to be stuck on the ad server lookups, then the page will load very slowly without CSS.
Web performance is still the same, server not found error for the Avast forums (search Google, find forums, click link, eventual server not found error).
Sorry, more or less the same. Google loads. Avast forums won’t load (server not found). Minecraft.net loads, but the embedded YouTube video generates a server not found error. Cnn.com doesn’t load (server not found error).
DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: 76.73.6.108
This appears to be a DNS problem. Initially follow the steps here http://www.pctools.com/kb/article/protection-software-resetting-your-dns-settings-519.html and let me know if that cures it