Symptom(s):
- Google.com searches yield results. When clicking on results, a 2nd window opens with bogus websites with content based upon search query.
- no other symptoms known or presenting as of yet.
Scan results:
I have not scanned the computer with Norton yet, nor have I gone into various Safe Modes for scan/removal.
Computer scanned with Malwarebytes (log attached), HitmanPro, Spybot Search and Destroy, and TDSS Killer; all updated before scanning.
Hitman showed clear. Spybot's initial load showed 9 temp files, but could not clear 2. Malwarebytes got hits on 2 trojans, quarantined and deleted.
- Trojan.Happili
- Trojan.Ransom
File locations were same for both...
- C:\Users\Chris\AppData\Local\Temp\0.5812232367648337 (Trojan.Happili)
- C:\Users\Chris\AppData\Local\Temp\wgsdgsdgdsgsd.exe (Trojan.Ransom)
System Info:
Window 7 Pro 64-bit (will run Windows Update while waiting for reply(ies))
Norton Internet Security Version 18.7.2.3 (up to date)
Various flash medias available if needed (compact flash cards, and thumb drives)
IE 9.0.8112.16421 (Update Version 9.0.10 (KB2744842))
Additional thoughts:
Dealt with Trojan.Ransom 2 months ago. Thought I was clear following google searched instructions short of going this route of posting and going through loading of various removal programs. System "appeared" recovered with no traces being found in registry and desktop not being hijacked with black FBI warning screen. My concern now is both positive hits on Ransom and Happili.
Thanks in advance thus far for researched info seen posted here. Quads, you're a work horse as of lately!
I have not tinkered beyond what is listed above, thus why I'm here.
Edit: Since being hit with Ransom a while back I've updated Flash, but chose to completely disable (both as a program and within IE) it with hopes of an update fixing vulnerabilities. Oddly, I did also have issues a few months back with java updating, though I'm forgetting specifics upon that. Not certain if any of this additional info is needed.