- Oct 11, 2014
- 22
Hi fellow wise man and infected PC users, I'm new at this forum and found it very helpful, I'm asking your help today for the following reason: last Friday I was at work (I'm a maintenance guy at a school) and some kid asked me to lend my PC so I said go ahead you can use it, I have to say that I was not watching, and the kid was unsupervised, as it only took less than 1 minute since he only copied some homework file from Facebook to his (now I know) infected usb, so I got back to my PC and everything went fine until I opened Firefox.... HOLYYYYYYYYY!!!
all it did was redirecting me to this site "http://login.lataminternet.com/search.php?q=" and intermediately checked my usb ports and all my files had a little shortcut arrow and started generating hidden normal folders, and renamed visible ones with folders with shortcuts putting all my good files inside a hidden folder called .TRASHES and regenerating another empty folder with the number 687 and I knew for certain that the kid infected my laptop... of course I got really mad at the kid but after all he was a first grader and I'm pretty sure he didn't do it on purpose, so next step was eset smart security, malware bytes, Norton, and kapersky, all of them with up-to-date definitions and the only one that kind of found something was Norton but it didn't really remove nothing I guess... luckily (or maybe all those scans did something) the virus allowed me to visit malware removal sites and the .trashed folder and folders with shortcut arrows disappeared and my usb ports are fine again so I went ahead on the internet and I found this:
http://malwaretips.com/blogs/remove-browser-redirect-virus/
I tried all of the solutions found there and some detected something but again didn't remove fully the infection the only one that helped me track something was rogue killer and that thing was a so called pum.hijack.homepagecontrol and I got a hint of what I kinda guess I'm dealing with, next step for me and my little knowledge in this matter was hijack this which is a tool I use since 15 years ago if I can recall right and did the scan and erased only the entries with "http://login.lataminternet.com/search.php?q=" all of this on safe mode under win 7 ultimate 64bit restarted and that damn page was there again, (REALLY sorry, little frustrated) redo the process, reappeared on different locations every time, sorry again it took this long but that is my little dilemma with this browser hijacker, I've been looking for a solution non-stop since yesterday and I found you guys, hope you can help solve my issue, and sorry for being so repetitive and also my lame English, I'm not very skilled at it, I hope I could have explained myself.
I'll attach the farbar and the hijack this logs as requested on the site rules for helping each other
THANK YOU VERY MUCH.
P.D. Almost forgot to mention... ALL of my usb ports have the auto-run feature deactivated, but I guess that doesn't matter if you click only once one of the created folders by the virus with an shortcut arrow
all it did was redirecting me to this site "http://login.lataminternet.com/search.php?q=" and intermediately checked my usb ports and all my files had a little shortcut arrow and started generating hidden normal folders, and renamed visible ones with folders with shortcuts putting all my good files inside a hidden folder called .TRASHES and regenerating another empty folder with the number 687 and I knew for certain that the kid infected my laptop... of course I got really mad at the kid but after all he was a first grader and I'm pretty sure he didn't do it on purpose, so next step was eset smart security, malware bytes, Norton, and kapersky, all of them with up-to-date definitions and the only one that kind of found something was Norton but it didn't really remove nothing I guess... luckily (or maybe all those scans did something) the virus allowed me to visit malware removal sites and the .trashed folder and folders with shortcut arrows disappeared and my usb ports are fine again so I went ahead on the internet and I found this:
http://malwaretips.com/blogs/remove-browser-redirect-virus/
I tried all of the solutions found there and some detected something but again didn't remove fully the infection the only one that helped me track something was rogue killer and that thing was a so called pum.hijack.homepagecontrol and I got a hint of what I kinda guess I'm dealing with, next step for me and my little knowledge in this matter was hijack this which is a tool I use since 15 years ago if I can recall right and did the scan and erased only the entries with "http://login.lataminternet.com/search.php?q=" all of this on safe mode under win 7 ultimate 64bit restarted and that damn page was there again, (REALLY sorry, little frustrated) redo the process, reappeared on different locations every time, sorry again it took this long but that is my little dilemma with this browser hijacker, I've been looking for a solution non-stop since yesterday and I found you guys, hope you can help solve my issue, and sorry for being so repetitive and also my lame English, I'm not very skilled at it, I hope I could have explained myself.
I'll attach the farbar and the hijack this logs as requested on the site rules for helping each other
THANK YOU VERY MUCH.
P.D. Almost forgot to mention... ALL of my usb ports have the auto-run feature deactivated, but I guess that doesn't matter if you click only once one of the created folders by the virus with an shortcut arrow