Lloydel Posted March 5, 2018 ID:1221518 Share Posted March 5, 2018 I have this same problem starting thhis morning. Using Firefox on Windows 10, my Google and Bing search pages are taken over by a semi-look-alike RocketTab page. I am Malwarebytes Premium with all protections turned on. A full scan did not identify RocketTab. Looking for advice. Link to post Share on other sites More sharing options...
kevinf80 Posted March 5, 2018 ID:1221519 Share Posted March 5, 2018 Hello Lloydel and welcome to Malwarebytes, Follow the instructions at this link and post the requested logs: https://forums.malwarebytes.com/topic/9573-im-infected-what-do-i-do-now/ Thank you, Kevin Link to post Share on other sites More sharing options...
Lloydel Posted March 5, 2018 Author ID:1221549 Share Posted March 5, 2018 Addition.txt FRST.txt scan report 3-5-18.txt Link to post Share on other sites More sharing options...
kevinf80 Posted March 5, 2018 ID:1221553 Share Posted March 5, 2018 Thanks for those logs, continue: Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into. "Do not open that file when running FRST fix" NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work. Open FRST and press the Fix button just once and wait. The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply. Next, Download AdwCleaner by Malwarebytes onto your Desktop. Or from this Mirror Right-click on AdwCleaner.exe and select Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users) Accept the EULA (I accept), then click on Scan Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all the active processes Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply Next, Please download Zemana AntiMalware and save it to your Desktop. Install the program and once the installation is complete it will start automatically. Without changing any options, press Scan to begin. After the short scan is finished, if threats are detected press Next to remove them.Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please re-boot your computer manually. Open Zemana AntiMalware again. Click on icon and double click the latest report. Now click File > Save As and choose your Desktop before pressing Save. Attach saved report in your next message. Let me see those logs, also tell me if there are any remaining issues or concerns... Thank you, Kevin... fixlist.txt Link to post Share on other sites More sharing options...
Lloydel Posted March 6, 2018 Author ID:1221571 Share Posted March 6, 2018 Nope. RocketTab is still taking my Google search page. I see the real page for a second then it flashes to the fake page. Image is attached. Thank you for helping me. I hope there is something more to try. Lloyd 2018.03.05-15.41.20-i0-t92-d6.txt AdwCleaner[C1].txt Fixlog.txt Link to post Share on other sites More sharing options...
kevinf80 Posted March 6, 2018 ID:1221576 Share Posted March 6, 2018 Does this only happen with Firefox browser.. Link to post Share on other sites More sharing options...
Lloydel Posted March 6, 2018 Author ID:1221580 Share Posted March 6, 2018 Yes. Does not happen in Chrome or Explorer. Link to post Share on other sites More sharing options...
kevinf80 Posted March 6, 2018 ID:1221585 Share Posted March 6, 2018 Ok, lets go for a clean install of Firefox: Use the following link for instructions how to back up your bookmarks, same link can be used to import saved Bookmarks:https://support.mozilla.org/en-US/kb/export-firefox-bookmarks-to-backup-or-transfer Next, Remove all synced data from Firefox to stop possible re-infection or exploitation.https://support.mozilla.org/en-US/questions/1037353 Next, Go here: http://www.mozilla.org/en-US/ download save the latest version of Firefox.. We will install this later... Next, Lets totally remove Firefox and start over. Go here: https://support.mozilla.org/en-US/kb/uninstall-firefox-from-your-computer and follow those instructions... Ensure when the uninstall completes to navigate to and delete the firefox installation folder (if present): (32-bit Windows) C:\Program Files\Mozilla Firefox (64-bit Windows) C:\Program Files (x86)\Mozilla Firefox It is essential the installation folder is removed. Re-boot your system when that is completed.... Next, To remove all remaining data and profile information... Press "Windows key + R" to open the Run box In the Run box, type in or copy and paste %APPDATA% Click OK. A Windows Explorer window will appear. In this window, choose/open in succession Mozilla > Firefox > Profiles. Select Delete on each entry in reverse, eg Profiles > Delete. Firefox > Delete. Mozilla > Delete. Re-boot your system when complete! Next, Use the Mozilla Firefox installer to reinstall your Browser.... When Firefox is installed and open select these keys together :- Ctrl - Shift - A that will access Addons manger, this gives access to find addons/extensions, use, start, stop or disable those features etc.... uBlock-Origin can be installed from here: https://addons.mozilla.org/en-GB/firefox/addon/ublock-origin/ <<--- Recommended. Does that help..? Link to post Share on other sites More sharing options...
Lloydel Posted March 6, 2018 Author ID:1221588 Share Posted March 6, 2018 Ok. Looks like it will take a while., I'll check in tomorrow. Nice to know I can save my Bookmarks. Link to post Share on other sites More sharing options...
kevinf80 Posted March 6, 2018 ID:1221589 Share Posted March 6, 2018 Yes is 30 after midnight local time for me, catch up later.... Link to post Share on other sites More sharing options...
Lloydel Posted March 6, 2018 Author ID:1221820 Share Posted March 6, 2018 Yes that worked, Kevin. Thank you Did take a while to reinstall and then to set Firefox the way I like it. Will make a donation. Link to post Share on other sites More sharing options...
kevinf80 Posted March 6, 2018 ID:1221829 Share Posted March 6, 2018 Yo`re very welcome Lloydel, it was a pleasure to work with you. We still need to clean up: Uninstall Zemana http://www.askvg.com/how-to-completely-uninstall-remove-a-software-program-in-windows-without-using-3rd-party-software/ Next, Download "Delfix by Xplode" and save it to your desktop. Or use the following if first link is down:"Delfix link mirror" If your security program alerts to Delfix either, accept the alert or turn your security off. Double Click to start the program. If you are using Vista or higher, please right-click and choose run as administrator Make Sure the following items are checked: Remove disinfection tools <----- this will remove tools we may have used. Purge System Restore <--- this will remove all previous and possibly exploited restore points, a new point relative to system status at present will be created. Reset system settings <--- this will reset any system settings back to default that were changed either by us during cleansing or malware/infection Now click on "Run" and wait patiently until the tool has completed. The tool will create a log when it has completed. We don't need you to post this. Any remnant files/logs from tools we have used can be deleted… Next, Read the following links to fully understand PC Security and Best Practices, you may find them useful....Answers to Common Security Questions and best PracticesDo I need a Registry Cleaner? Take care and surf safe Kevin... Link to post Share on other sites More sharing options...
Lloydel Posted March 6, 2018 Author ID:1221839 Share Posted March 6, 2018 Ok. Thanks. I am curious why it is important to remove the zemana, and to do it so carefully. Link to post Share on other sites More sharing options...
kevinf80 Posted March 6, 2018 ID:1221843 Share Posted March 6, 2018 There is no real reason to remove it, If you prefer to keep it please feel free to do so. I`ve got the free version and use it as and when required, i`ve also got the portable version on a USB stick along with other stuff I carry for call outs... Access to the portable version is under the main Download tab here: https://www.zemana.com/Download Link to post Share on other sites More sharing options...
Lloydel Posted March 7, 2018 Author ID:1222133 Share Posted March 7, 2018 Might you have a clue about this, Kevin? After re-installing Firefox the formating button / bar in Gmail shows but doesn't function. It's ok in Chrome. Lloyd Link to post Share on other sites More sharing options...
kevinf80 Posted March 7, 2018 ID:1222136 Share Posted March 7, 2018 Is that an addon or extension for Firefox..? Link to post Share on other sites More sharing options...
Lloydel Posted March 7, 2018 Author ID:1222140 Share Posted March 7, 2018 2 minutes ago, kevinf80 said: Is that an addon or extension for Firefox..? The Gmail website. mail.google.com Link to post Share on other sites More sharing options...
kevinf80 Posted March 7, 2018 ID:1222147 Share Posted March 7, 2018 Ok thanks, try Firefox in Safe Mode, see it works from there: https://support.mozilla.org/en-US/kb/troubleshoot-firefox-issues-using-safe-mode#w_how-to-start-firefox-in-safe-mode Link to post Share on other sites More sharing options...
Lloydel Posted March 7, 2018 Author ID:1222164 Share Posted March 7, 2018 Ok. Yes it worked in Safe Mode The culprit seems to an extension called Drag To Scroll. It let me screen by holding down the left mouse button and dragging. I kind of like it but could live without. I was using it before without problem. I will check it's settings. Link to post Share on other sites More sharing options...
kevinf80 Posted March 7, 2018 ID:1222176 Share Posted March 7, 2018 Excellent, at least you`ve found the culprit. Any other issues or concerns...? Link to post Share on other sites More sharing options...
Lloydel Posted March 7, 2018 Author ID:1222202 Share Posted March 7, 2018 Not yet. Thanks Link to post Share on other sites More sharing options...
kevinf80 Posted March 7, 2018 ID:1222211 Share Posted March 7, 2018 Thanks for the update... Link to post Share on other sites More sharing options...
kevinf80 Posted March 18, 2018 ID:1225214 Share Posted March 18, 2018 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks Link to post Share on other sites More sharing options...
Recommended Posts