Author Topic: Yourtv malware  (Read 5179 times)

0 Members and 1 Guest are viewing this topic.

Offline hamzamb

  • Jr. Member
  • **
  • Posts: 44
Yourtv malware
« on: September 27, 2015, 09:40:34 AM »
My browsers are infected by yourtv.link

please find attached my logs below.

thanks in advance for the help

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Yourtv malware
« Reply #1 on: September 27, 2015, 12:45:51 PM »
Let me know how the computer is after this

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-3321735017-2395750582-1160152328-1001\...\Run: [pleasant] => C:\ProgramData\pleasant.exe [12740169 2015-08-18] (Newark Tech, Inc.)
CHR HKU\S-1-5-21-3321735017-2395750582-1160152328-1001\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
Startup: C:\Users\Hamza B\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hamza B.exe [2015-08-19] (Newark Tech, Inc.)
2015-09-25 11:16 - 2015-05-23 14:43 - 00000000 __SHD C:\Users\Hamza B\AppData\Local\EmieUserList
2015-09-25 11:16 - 2015-05-23 14:43 - 00000000 __SHD C:\Users\Hamza B\AppData\Local\EmieSiteList
2015-09-25 11:16 - 2015-05-23 14:43 - 00000000 __SHD C:\Users\Hamza B\AppData\Local\EmieBrowserModeList
015-08-19 20:56 - 2015-08-18 02:29 - 12740169 ___SH (Newark Tech, Inc.) C:\ProgramData\pleasant.exe
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.

Offline hamzamb

  • Jr. Member
  • **
  • Posts: 44
Re: Yourtv malware
« Reply #2 on: September 28, 2015, 11:14:20 AM »
Hi,

   I ran the programs as you asked. Find attached the logs below. I didn't find the file as you said. but I found this in the adwcleaner folder

Thanks,
Hamza

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Yourtv malware
« Reply #3 on: September 28, 2015, 11:35:20 AM »
and the fix log?


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Yourtv malware
« Reply #4 on: September 28, 2015, 03:50:37 PM »
How is the computer now ?

Offline hamzamb

  • Jr. Member
  • **
  • Posts: 44
Re: Yourtv malware
« Reply #5 on: September 28, 2015, 06:59:23 PM »
Is this the Fix log?

also when i open a new tab and search on google it uses this search engine by default. (image attached below)

Thanks,
Hamza.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Yourtv malware
« Reply #6 on: September 28, 2015, 07:16:26 PM »
Are you still getting it in Chrome ?  DO you have chrome set to synch ?

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: Yourtv malware
« Reply #7 on: September 29, 2015, 09:06:51 AM »
hey see essexboys first replay to you. please follow his instruction and run the fix he have posted for you:)
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline hamzamb

  • Jr. Member
  • **
  • Posts: 44
Re: Yourtv malware
« Reply #8 on: October 01, 2015, 02:38:32 PM »
yes I am signed into chrome

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Yourtv malware
« Reply #9 on: October 01, 2015, 04:13:08 PM »
OK then each time you start chrome it will download it again.  We need to stop the synch and then clean it up again 

1. I need you to go Google Sync and sign into your account
2. Scroll down until you see the "Stop and Clear" button and click on the button. At the prompt click on "Ok"

Then run a fresh FRST scan

Offline hamzamb

  • Jr. Member
  • **
  • Posts: 44
Re: Yourtv malware
« Reply #10 on: October 05, 2015, 06:48:01 AM »
Hi,

    Sorry about that here is the new scan.

Hamza.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Yourtv malware
« Reply #11 on: October 05, 2015, 04:21:51 PM »
Let me know how the computer is after this

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
CHR StartupUrls: Default -> "chrome://newtab/"
2015-08-19 20:56 - 2015-08-18 02:29 - 12740169 ___SH (Newark Tech, Inc.) C:\ProgramData\pleasant.exe
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

Offline hamzamb

  • Jr. Member
  • **
  • Posts: 44
Re: Yourtv malware
« Reply #12 on: October 06, 2015, 07:27:14 PM »
here is the FRST log

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Yourtv malware
« Reply #13 on: October 06, 2015, 07:30:57 PM »
How is chrome behaving now ?

Offline hamzamb

  • Jr. Member
  • **
  • Posts: 44
Re: Yourtv malware
« Reply #14 on: October 07, 2015, 06:38:16 AM »
chrome is still using that custom search. In settings that search engine is set as default and when I try to change, it says "this setting has been enforced by your administrator". see attached image. thanks
« Last Edit: October 07, 2015, 06:39:53 AM by hamzamb »