DNS Unlocker/Browser hijack

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
I reset my router... back to factory settings. And the problem is affecting my IE now too...
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
Yessir... here's the attached logfiles.
 

Attachments

  • FRST.txt
    57.6 KB · Views: 2
  • Addition.txt
    47.9 KB · Views: 2

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Your PC isn't infected.

You said that it is happening on multiple devices? Does it happen in the same browsers, on the same websites? Do you have the same google account on these browsers? There must be some pattern.
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
See screenshot below - DNS unlocker ad + unwanted popups... it's still infected unfortunately...

upload_2016-2-23_7-27-48.png
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
It happens across different browsers but usually on the same websites as mentioned in my earlier post.

I don't have the same google account on both laptops.
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
I just connected a 3rd computer to the same network and the same problem is occurring on the same websites.
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
Hi Sorry I don't quite understand what you meant... do you mean to go to control panel and look for the router??
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
OK i figured out what you meant. Yes, I went to the Router setup -> tools -> system and clicked on restore to factory default.
Same problem is still appearing on Chrome, same sites.
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
One detail that may be relevant - I am using Chromecast to cast videos to my home TV.... not sure if the malware/hijacking is "stored" in the Chromecast device instead of the router since it's also connected to the network?
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
No it's not... i have 2 browsers on my computer and IE is also affected (together with Chrome).
BTW a number of malware removal software, TDSS, CODOMO, Zemana crashes my computer... MalywareBytes/AdwCleaner don't detect any malware.
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
Hi - I've reset IE, reinstalled Chrome (including deleting the localappdata google folder) and the problem seems to have gone away.

I'll monitor this and let you know if it's still clean after a couple of days. Perplexing problem!
 

JCheong

New Member
Thread author
Verified
Feb 17, 2016
23
The ads/pop-ups came back and it's on the same sites.

Tried some different settings on Chrome and found that disabling Javascript is the only way to disable the ads. Will see if the situation improves.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top