Malware yourtv.link

I see that this is a common infection lately. I am using Firefox and am able to change my homepage though it keeps resetting itself to the yourtv.link site. I ran Malwarebytes Anti-Malware and am providing the log. Any help would be appreciated!

Attach your basic diagnostic logs. (FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0

Monitoring…

Ran all scans. attached logs. Thanks for the quick reply!

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Fix with Farbar Recovery Scan Tool

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[B] This fix was created for this user for use on that particular machine.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[/B]

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

[*]Right-click on
https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
[*]Press the Fix button just once and wait.
[*]If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
[*]When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.

I need you to upload one folder after you finish with FRST fix:

Folder I need:

C:[b]FRST[/b]

Right click on folder → Send to Compressed (zipped) folder

After that, you’ll see zipped folder.

Upload zipped folder here and post download links:

http://zippyshare.com/

http://www24.zippyshare.com/v/wHT0S8NU/file.html
http://www24.zippyshare.com/v/wHT0S8NU/file.html

It seems to have fixed it. Hopefully so.

Thanks!

Yes, malware should be gone now. How is your PC behaving?

It’s functioning pretty normally though it was normal with malware still on it. It wasn’t running slowly or anything. I am just going to play around and see how it goes.

Thanks so much for your help! This was my first forum experience. lol

I really appreciate the help.

-S

after a few days of normal use, chrome and firefox default pages are producing search results yourtv.link in the link. though it is not changing my chosen default in firefox. Any suggestions?

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

[*]Right-click on
https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
[*]Make sure that Addition option is checked.
[*]Press Scan button and wait.
[*]The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.

Here they are:

https://sites.google.com/site/cannedfixes/home/hosted-images-tools/51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

[*]Right-click on
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/51a612a8b27e2-Zoek.png
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
[]Wait patiently until the main console will appear, it may take a minute or two.
[
]In the main box please paste in the following script:

createsrpoint;
autoclean;
emptyalltemp;
ipconfig /flushdns;b

[*]Make sure that Scan All Users option is checked.
[*]Push Run Script and wait patiently. The scan may take a couple of minutes.
[*]When the scan completes, a zoek-results logfile should open in notepad.
[*]If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.

zoek results:

PC seems clean. How is it behaving now?

machine running great. I cleared browser history, cookies, and cache. Also reset defaults again and I can’t seem to replicate the problem and link isn’t returning. I am sure it’s probably fine now. Thanks for taking a second look!

-S