MalwareRemoval.com provides free support for people with infected computers.

Malware Removal Instructions

Infected with linkataraby redirect malware!!!!

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Infected with linkataraby redirect malware!!!!

Hassan Jaroudi » October 5th, 2013, 4:24 am


I am infected with this stupid :x redirect on chrome, and things are getting worse now, i have been redirected to tuvaro, al naddy, youtradefx, search toolbars..

i may got this malware/virus (i dont know what should be called) 1 month ago when i downloaded a couple of free AV softwares from the web.

So please i need your help to get red of this.. :(

and here is the logs that you asked for..

The DDS log
And the Attach log
Re: Infected with linkataraby redirect malware!!!!

Cypher » October 5th, 2013, 5:43 am

Checking your log now be right back.
Re: Infected with linkataraby redirect malware!!!!

Unread postby Cypher » October 5th, 2013, 5:50 am

Hi and welcome to Malware Removal Forum.
My name is Cypher, and I will be helping you with your malware problems.
This may or may not, solve other issues you have with your machine.
If you no longer require help i would be grateful if you would let me know.

Before we start please note the following important guidelines.
  • If you don't know or understand something, please don't hesitate to ask.
  • Only post your problem at One help site. Applying fixes from multiple help sites can cause problems.
  • Only reply to this thread do not start another, Please continue responding until I give you the "All Clean"
    Remember, absence of symptoms does not mean the infection is all gone.
  • Please DO NOT run any other tools or scans whilst I am helping you.
  • Please DO NOT install any other software (or hardware) during the cleaning process.
  • Print each set of instructions... if possible...your Internet connection will not be available during some fix processes.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  • Note: No Reply Within 3 Days Will Result In Your Topic Being Closed!

Note: If you haven't done so already, please read this topic ALL USERS OF THIS FORUM MUST READ THIS FIRST where the conditions for receiving help here are explained.
Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start

A couple of questions..
Is this computer used for business purposes?
I am infected with this stupid redirect on chrome

Is Chrome the only browser affected?

Please download MGA Diagnostic Tool and save it to your Desktop.

  • Right click on MGADiag.exe and select Run As Administrator to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in the window.
  • Save this file and copy/paste it in your next reply.


Run CKScanner

  • Please download CKScanner from Here
  • Important: - Save it to your desktop.
  • Important: Run this scan once and once only.
  • Right-click CKScanner.exe > select " Run as administrator " then click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify the file saved. Please Run the program only once.
  • Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

Logs/Information to Post in your Next Reply

  • Your answers to my questions.
  • MGADiag log.
  • CKFiles.txt.
Re: Infected with linkataraby redirect malware!!!!

Unread postby Hassan Jaroudi » October 5th, 2013, 9:23 am

Dear Cypher

thank you for your kind reply,
This is my personal laptop, I use it for my work also...
Internet explorer also some times start the home page with tuvaro or alnaddy. but once i delete it from the internet explorer options it goes.

here are the generated files.

Diagnostic Report (1.9.0027.0):
Windows Validation Data-->

Validation Code: 0
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-BFF84-6GFC2-BWX77
Windows Product Key Hash: EkRG02noirn1etiserf2jJnVqlM=
Windows Product ID: 00359-OEM-8992687-00017
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {3F27EEAC-0F78-4C9F-A981-A652673BA4D1}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.110622-1506
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 100 Genuine
Microsoft Office Enterprise 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Disabled
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Disabled
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Disabled
Script ActiveX controls marked as safe for scripting: Disabled

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{3F27EEAC-0F78-4C9F-A981-A652673BA4D1}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-BWX77</PKey><PID>00359-OEM-8992687-00017</PID><PIDType>2</PIDType><SID>S-1-5-21-2660595134-93515350-1600975375</SID><SYSTEM><Manufacturer>TOSHIBA</Manufacturer><Model>Satellite L650</Model></SYSTEM><BIOS><Manufacturer>INSYDE</Manufacturer><Version>1.80</Version><SMBIOSVersion major="2" minor="6"/><Date>20100901000000.000000+000</Date></BIOS><HWID>62153207018400FC</HWID><UserLCID>0809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Arab Standard Time(GMT+03:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>TOSINV</OEMID><OEMTableID>TOSINV00</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90120000-0030-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val>C0A25836FDBE5AC</Val><Hash>FmDbcrRY1pTOcrz4ZUZRHhpUuc0=</Hash><Pid>89388-726-2958074-65076</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/><App Id="BA" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>

Spsys.log Content: 0x80070002

Licensing Data-->
Software licensing service version: 6.1.7601.17514

Name: Windows(R) 7, HomePremium edition
Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00359-00178-926-800017-02-1033-7600.0000-1262010
Installation ID: 009013214300441021838643214862295490316891421553365225
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: BWX77
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 05/10/2013 15:58:32

Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 9:8:2013 11:52
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:

HWID Data-->

OEM Activation 1.0 Data-->

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value

and for the other one

CKScanner 2.4 - Additional Security Risks - These are not necessarily bad
c:\program files (x86)\pov-ray for windows v3.6\insert menu\h0 - patterns 1 (a-m)\crackle.txt
c:\program files (x86)\pov-ray for windows v3.6\scenes\textures\patterns\crackle1.pov
c:\program files (x86)\pov-ray for windows v3.6\scenes\textures\patterns\crackle2.pov
c:\program files (x86)\pov-ray for windows v3.6\scenes\textures\patterns\crackle3.pov
c:\program files (x86)\pov-ray for windows v3.6\scenes\textures\patterns\crackle_form.pov
c:\program files (x86)\pov-ray for windows v3.6\scenes\textures\patterns\crackle_solid.pov
c:\program files (x86)\pov-ray for windows v3.6\scenes\textures\pigments\crack1.pov
c:\users\toshiba\downloads\pixillion image converter v2.22 keygen at4re.rar
hosts activate.adobe.com
hosts practivate.adobe.com
hosts ereg.adobe.com
hosts activate.wip3.adobe.com
hosts wip3.adobe.com
hosts 3dns-3.adobe.com
hosts 3dns-2.adobe.com
hosts adobe-dns.adobe.com
hosts adobe-dns-2.adobe.com
hosts adobe-dns-3.adobe.com
hosts ereg.wip3.adobe.com
hosts activate-sea.adobe.com
hosts wwis-dubc1-vip60.adobe.com
hosts activate-sjc0.adobe.com
hosts activate.adobe.com
hosts practivate.adobe.com
hosts ereg.adobe.com
hosts activate.wip3.adobe.com
hosts wip3.adobe.com
hosts 3dns-3.adobe.com
hosts 3dns-2.adobe.com
hosts adobe-dns.adobe.com
hosts adobe-dns-2.adobe.com
hosts adobe-dns-3.adobe.com
hosts ereg.wip3.adobe.com
hosts activate-sea.adobe.com
hosts wwis-dubc1-vip60.adobe.com
hosts activate-sjc0.adobe.com
scanner sequence 3.ZZ.11.UHNABZ
----- EOF -----
Re: Infected with linkataraby redirect malware!!!!

Unread postby Cypher » October 5th, 2013, 10:12 am

Cracked - Illegal Software

May I draw your attention to the topic: ALL USERS OF THIS FORUM MUST READ THIS FIRST, which you should have read before posting for help.
The section here explains why we bring this to your attention.

If you wish to receive help from us, you must remove any and all of the following from your computer:
  • Illegal software
  • Cracked software
  • illegal software key generators

Once the software and/or keygens have been removed, if you still need help, please start a new thread... include a link to your closed topic and include NEW DDS logs :
  • DDS.txt.
  • Attach.txt.
  • Details of the problems you're experiencing.
Wait for a new helper. Do not reply to your topic before a helper has replied.

This topic is now closed.
