Author Topic: Browsers compromised  (Read 16713 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Browsers compromised
« Reply #15 on: April 17, 2015, 10:41:28 PM »
What problems remain ?

REDACTED

  • Guest
Re: Browsers compromised
« Reply #16 on: April 17, 2015, 10:45:45 PM »
I ran the adware cleaner too. Here goes the log! I removed chrome too.

I will send the first set of logs from the third computer in a minute.

REDACTED

  • Guest
Re: Browsers compromised
« Reply #17 on: April 17, 2015, 10:48:30 PM »
Computer # 3 log.

Here they go!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Browsers compromised
« Reply #18 on: April 17, 2015, 10:57:00 PM »
This one also has McAfee still running

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
2015-04-17 08:14 - 2015-04-17 08:14 - 00000000 __HDC () C:\Users\Todos os Usuários\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}
2015-04-17 08:14 - 2015-04-17 08:14 - 00000000 __HDC () C:\ProgramData\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Browsers compromised
« Reply #19 on: April 17, 2015, 11:33:31 PM »
Everything seems fine now. The fourth dell, computer, the one that has windows 7. Does not seem compromised after all.  :)

Here go the final logs!

REDACTED

  • Guest
Re: Browsers compromised
« Reply #20 on: April 18, 2015, 02:38:55 AM »
Bad Luck!  >:(

Russian sites are back.

Internet Explored is compromised again in the third computer.

I will run the tests again.

REDACTED

  • Guest
Re: Browsers compromised
« Reply #21 on: April 18, 2015, 04:22:38 AM »
Here they go.

Good night for all.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Browsers compromised
« Reply #22 on: April 18, 2015, 02:25:48 PM »
This is just in IE ?

REDACTED

  • Guest
Re: Browsers compromised
« Reply #23 on: April 18, 2015, 02:34:36 PM »
Good morning.

I uninstalled Chrome from computer #3, after yesterday's cleaning. All simptoms disapered for some time. But then both IE and Firefox were compromised again.

I'am using computer #1 and so far its browsers seem OK.

REDACTED

  • Guest
Re: Browsers compromised
« Reply #24 on: April 18, 2015, 02:48:08 PM »
Ooops. Firefox has been compromised on computer #1 too. I used it for quite some time after yesterday's removal processth with no problems at all. But it now infected too.  :'(

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Browsers compromised
« Reply #25 on: April 18, 2015, 02:52:25 PM »
The problem may be in the router I feel

Could you reset the router..  There should be a small hole at the back labelled reset.  Use a biro to press and hold until the lights start flashing

REDACTED

  • Guest
Re: Browsers compromised
« Reply #26 on: April 18, 2015, 03:00:33 PM »
I reset the router and ran IPCONFIG /flushdns on computer #1. The problem with firefox on computer # 1 persists.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Browsers compromised
« Reply #27 on: April 18, 2015, 03:07:22 PM »
OK that one may be the root cause.  Could you run FRST on that one again please

REDACTED

  • Guest
Re: Browsers compromised
« Reply #28 on: April 18, 2015, 03:19:06 PM »
I got a ERUNT access violation error when I first tried Farbar Recovery Scan. But then it worked OK. It happened yesterday too but I forgot to report.

I checked my router's configuration and it uses a couple of DNS servers that belong to my Internet Provider (I checked through whois). My router's DNS server is set through my Internet Provider's DHCP server.

Here go Log files from computer #1.

REDACTED

  • Guest
Re: Browsers compromised
« Reply #29 on: April 18, 2015, 03:39:15 PM »
One more thing. Now that computer #1 is compromised, when I try to load some pages I get error messages telling me I don't have an Internet Conection at the moment. That may be a network problem or maybe something creepy.  :-X

My Internet connection is usually very good.