Author Topic: Browser Hijacked  (Read 20969 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Re: Browser Hijacked
« Reply #15 on: October 10, 2014, 07:19:09 PM »
Nah I still can`t up date avast program and when I connect my device the main screen show everything as ok but when I open the device info it says Realtime shields are off and Virus Definitions up dates are also off and I can`t seem to enable it.

REDACTED

  • Guest
Re: Browser Hijacked
« Reply #16 on: October 10, 2014, 07:44:08 PM »
Pondus, the issue above is a separate issue right? Should I open a new post?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37545
  • Not a avast user
Re: Browser Hijacked
« Reply #17 on: October 10, 2014, 07:47:26 PM »
Tried avast repair?

Controlpanel > ad/remove programs > avast > uninstall/change > repair option ..... wait a minute and reboot


See instructions here   https://forum.avast.com/index.php?topic=53253.0
Scroll down to Farbar Recovery Scan Tool ..... follow instructions and attach the two diagnostic logs


REDACTED

  • Guest
Re: Browser Hijacked
« Reply #18 on: October 10, 2014, 07:48:35 PM »
Yes and have tried uninstalling but nothing

REDACTED

  • Guest
Re: Browser Hijacked
« Reply #19 on: October 10, 2014, 07:49:28 PM »
It`s like avast is blocked somehow but I have no idea how to look let alone fix

REDACTED

  • Guest
Re: Browser Hijacked
« Reply #20 on: October 10, 2014, 07:52:28 PM »
I just looked in the firewall setting under friends and I`m not seeing any ips

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Browser Hijacked
« Reply #21 on: October 10, 2014, 08:11:37 PM »
Using tghe same link Asyn gave you, attach FRST, you may have an IFEO or Group policy set against avast.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: Browser Hijacked
« Reply #22 on: October 10, 2014, 08:15:51 PM »
Here is the first log...

REDACTED

  • Guest
Re: Browser Hijacked
« Reply #23 on: October 10, 2014, 08:16:42 PM »
Here is the second...

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37545
  • Not a avast user
Re: Browser Hijacked
« Reply #24 on: October 10, 2014, 08:19:09 PM »
I will notify a log expert .....


REDACTED

  • Guest
Re: Browser Hijacked
« Reply #25 on: October 10, 2014, 08:19:51 PM »
Okay thanks heaps Pondus :)

REDACTED

  • Guest
Re: Browser Hijacked
« Reply #26 on: October 10, 2014, 08:27:38 PM »
BTW do I just close this scan or do u want me to wait?

REDACTED

  • Guest
Re: Browser Hijacked
« Reply #27 on: October 10, 2014, 10:41:18 PM »
I have same problem, earlier I had ransomware (arma di carabinieri) or FBI browser ransom. BUt I deleted it with the help of Avast free version Yesterday, but today it came back while login in to BBC.com. and since then I can only log in into avast website or MSN. nothing else and sometimes that ransomware is appearing on browser and then same alert by avast  and it continues. I will try ADW now.
but still I am fed up ... does anyone has any solid solution or any  information about good anti malware software?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37545
  • Not a avast user
Re: Browser Hijacked
« Reply #28 on: October 10, 2014, 10:47:23 PM »
I have same problem, earlier I had ransomware (arma di carabinieri) or FBI browser ransom. BUt I deleted it with the help of Avast free version Yesterday, but today it came back while login in to BBC.com. and since then I can only log in into avast website or MSN. nothing else and sometimes that ransomware is appearing on browser and then same alert by avast  and it continues. I will try ADW now.
but still I am fed up ... does anyone has any solid solution or any  information about good anti malware software?
If you need help, start your own topic ..... instructions found at top in this forum section

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Browser Hijacked
« Reply #29 on: October 11, 2014, 11:02:28 AM »
Here is the first log...

Hello,


This script for FRST tool (FixList) shall target some bad entries, done some fixes, preform some additional checks, it shall remove junk ... etc
We will re-check all that with ComboFix.





1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
Start
Folder: C:\ProgramData\iyogi-scc-528B3AD8
CloseProcesses:
HKU\S-1-5-21-2309721919-2532912108-3705383954-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2309721919-2532912108-3705383954-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-2309721919-2532912108-3705383954-1001\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-2309721919-2532912108-3705383954-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
ShellExecuteHooks:  - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} -  No File [ ]
Hosts:
S3 tuzblana; No ImagePath
EmptyTemp:
C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
End
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.







.







1. Please download ComboFix by sUBs () from here and save it to your Desktop.
If you are unsure how ComboFix works, read this guide.

--------------------------------------------------------------------
2. Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
If you are unsure how to do this please read this or this Instruction.

Instructions how to disable avast:
• Right click on the avast! system tray icon () in the lower right corner of the screen and scroll up to avast! shield controls;
• In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.

Note:  Do not forget to turn back on this option after the cleaning by choosing avast! shield controls > Enable all shield options.


--------------------------------------------------------------------
3. Run ComboFix. Then, on disclaimer window, click I Agree! button.

- ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

-If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
- ComboFix will scan your computer in stages, total of 50 stages.
Do not mouse-click around while ComboFix is running.
- If malware is detected, ComboFix will begin with its removal, and may need to restart Windows.
Note:If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart your computer.

--------------------------------------------------------------------
4. When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt)
=> Attach log report (ComboFix.txt) back to topic.

ComboFix shall also create addition log (typical location: C:\Qoobox\ComboFix-quarantined-files.txt)
=> Please attach that report (ComboFix-quarantined-files.txt) as well.