Further advice on how to remove webalta.ru needed

Fiery

Level 1
Jan 11, 2011
2,007
Try reseting your browsers:

For IE: http://support.microsoft.com/kb/923737

For Chrome: Reinstall it.
 

Dante2001

New Member
Thread author
Verified
Aug 15, 2013
27
Fiery said:
Try reseting your browsers:

For IE: http://support.microsoft.com/kb/923737

For Chrome: Reinstall it.
I followed the steps for IE but webalta is still there.
 

Fiery

Level 1
Jan 11, 2011
2,007
Hi,

Please uninstall Anvisoft.

Next, Open OTL. Under custom scan/fixes, copy and paste the following:

:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
[2013/04/09 11:55:32 | 000,000,000 | ---D | M] -- C:\Users\Spiros\AppData\Roaming\Reason Software Company Inc
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:373E1720
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:5C321E34
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:DFC5A2B2

:Files
ipconfig /flushdns /c

:Commands
[EMPTYTEMP]

Then click Run Fix. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply.
 

Dante2001

New Member
Thread author
Verified
Aug 15, 2013
27
Fiery said:
Hi,

Please uninstall Anvisoft.

Next, Open OTL. Under custom scan/fixes, copy and paste the following:

:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
[2013/04/09 11:55:32 | 000,000,000 | ---D | M] -- C:\Users\Spiros\AppData\Roaming\Reason Software Company Inc
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:373E1720
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:5C321E34
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:DFC5A2B2

:Files
ipconfig /flushdns /c

:Commands
[EMPTYTEMP]

Then click Run Fix. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply.
Here's the new log.
 

Attachments

  • OTL newest log.txt
    5.2 KB · Views: 98

Fiery

Level 1
Jan 11, 2011
2,007
Right-click the IE and chrome icons. Select Properties. Under the shortcut tab, look for a line called Target. Copy and paste the content in the line
 

Dante2001

New Member
Thread author
Verified
Aug 15, 2013
27
Fiery said:
Right-click the IE and chrome icons. Select Properties. Under the shortcut tab, look for a line called Target. Copy and paste the content in the line
This looks problematic, here are the lines copied and pasted.
C:\Users\Dante\AppData\Local\Google\Chrome\Application\chrome.exe http://home.webalta.ru/?new
"C:\Program Files\Internet Explorer\iexplore.exe"
 

Fiery

Level 1
Jan 11, 2011
2,007
For chrome, go into Properties again. This time, delete the "http://home.webalta.ru/?new" extension so under the target, the value is only C:\Users\Dante\AppData\Local\Google\Chrome\Application\chrome.exe

For IE, are you using a shortcut on the desktop?
 

Dante2001

New Member
Thread author
Verified
Aug 15, 2013
27
Fiery said:
For chrome, go into Properties again. This time, delete the "http://home.webalta.ru/?new" extension so under the target, the value is only C:\Users\Dante\AppData\Local\Google\Chrome\Application\chrome.exe

For IE, are you using a shortcut on the desktop?
I deleted the extension on chrome but webalta still appears. I've just created a desktop shortcut for IE but the target still reads the same as the one I copied and pasted earlier.
 

Fiery

Level 1
Jan 11, 2011
2,007
Hi,

Please open up SystemLookup again but copy and paste this code into the text field:

:filefind
*webalta*

:folderfind
*webalta*

:Regfind
webalta

:service
webalta

and press scan. Post the results back here
 

Dante2001

New Member
Thread author
Verified
Aug 15, 2013
27
Fiery said:
Hi,

Please open up SystemLookup again but copy and paste this code into the text field:

:filefind
*webalta*

:folderfind
*webalta*

:Regfind
webalta

:service
webalta

and press scan. Post the results back here
Here are the results, seems similar to the previous scan.
 

Attachments

  • SystemLook.txt
    3.3 KB · Views: 73

Fiery

Level 1
Jan 11, 2011
2,007
Hi,

Please use 64-bit version of SystemLookup from here: http://jpshortstuff.247fixes.com/SystemLook_x64.exe

And re-run the scan with

:filefind
*webalta*

:folderfind
*webalta*

:Regfind
webalta

:service
webalta
 

Dante2001

New Member
Thread author
Verified
Aug 15, 2013
27
Fiery said:
Hi,

Please use 64-bit version of SystemLookup from here: http://jpshortstuff.247fixes.com/SystemLook_x64.exe

And re-run the scan with

:filefind
*webalta*

:folderfind
*webalta*

:Regfind
webalta

:service
webalta
Here it is.
 

Attachments

  • SystemLook.txt
    3.1 KB · Views: 88

Dante2001

New Member
Thread author
Verified
Aug 15, 2013
27
Fiery said:
This is an odd one.. Can't seem to find the root cause. Would you consider reformatting?
If you think it would help I'd be happy to try it. Any advice for reformatting my hard drive without screwing any of my important files up?
 

Dante2001

New Member
Thread author
Verified
Aug 15, 2013
27
Fiery said:
Do you have an external drive or USB that can hold your important files?
I don't have an external drive at the minute and my USBs don't have a large capacity. Does reformatting put a lot of the vital files at risk so that it requires backup or is not necessary?
 

Fiery

Level 1
Jan 11, 2011
2,007
Reformatting will restore your PC back to factory default (the state in which you bought the PC in). It will delete all your files and reinstall windows.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top