So I downloaded something yesterday and ended up getting the v9 browser hijacker thing as well. I was able to fix my browser settings but i’m still getting random pop up adds everywhere. I ran the Malware bytes and OTL programs. The logs are attached.
First we shall target the OTL’s entries using zoek tool. Zoek will preform some additional cleaning routines as well. Then, we will re-check everything with FRST tool
[*]Close any open browsers
[*] Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.
[*]Double click on zoek.exe to run the tool . Please wait while the tool does not start…
[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:
Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.
[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Done and Done. I’ve somehow managed to not have anything this bad happen since I got this computer 4 1/2 years ago. Probably got a lot of little junk along the way.
Please note, this time your default browser should launch by itself. That’s normal, please allow that action. Browser shall open virustotal site. Just whait for zoek to finish his scanning …
When zoek pop ups the log, post (or paste) it here.
FYI:
Essexboy and myself have been discovered some new malware entries (file) in your logs so please stay with us to the end.
… … … … … … … … … …
=> When you’re done with second zoek script and uninstall the bad PUP, this is what you’re preform the next. So, this is the Step # 2.
This FixList shall target all present malware.
1. Open notepad and copy/paste the text present inside the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
2. Save notepad as fixlist.txt to your Desktop. NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
3. Run FRST/FRST64 and press the Fix button just once and wait. If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply. Note: If the tool warned you about the outdated version please download and run the updated version.
Ok, Both of those steps are done. I had to change some LAN proxy setting for Google chrome so that it would connect to the internet. Was that supposed to happen?
I had to change some LAN proxy setting for Google chrome so that it would connect to the internet. Was that supposed to happen?
Well, not exactly. I did say FRST to reset and/or kill some policy restriction related on Google Chrome but that's all.
In Step#1 we shall target the remnants.
In Step#2 we kind ask from you to upload Zoek’s and FRST’s Quarantine to the future analysis.
These Quarantine folders contains inactive (read: killed malware) removed by zoek.exe and FRST64.exe.
Step#1
1. Open notepad and copy/paste the text present inside the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Start
C:\Windows\Microsoft
Reboot:
End
2. Save notepad as fixlist.txt to your Desktop. NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
3. Run FRST/FRST64 and press the Fix button just once and wait. If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply. Note: If the tool warned you about the outdated version please download and run the updated version.
.
Step#2
Please zip-it /rar-it and upload both Quarantine folder the future analysis to us. We will send file sample to avast! and later to all other AV vendors.
You have installed 7-Zip on your mashine. Use that software to pack (zip it) the following folders:
C:[b]zoek_backup[/b]
C:\FRST[b]Quarantine[/b]
Please upload it to http://www.wikisend.com site.
Wikisend will generate the download link. Please post here download links (before posting, break link from http to hxxt).
example: hxxp://www.wikisend.com /upload/file.php
No more random pop up adds in Google Chrome. I thinks it’s even running a little faster over all. The time it takes to boot up when I start/ restart my computer has gone down quite a bit too. Thanks for all your help. That thing was really driving me nuts!
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.