This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Homepages hijacked?

61 min read

This thread's last reply is from July 20, 2011, 5:21 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

No, the file found by E-Set is just an encrypted backup that OTL made. It can't re-infect you and we'll dispose of it when we remove OTL from your computer.

As far as I can see there's no further sign of infection on your computer.

Time for a little tidying up ......

Let's clear out OTL and the files and folders it created. This will also remove GMER (except for the random named file on your Desktop).
  • Double click OTL.exe to launch the programme.
  • Click on the CleanUp! button.
  • OTL will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
  • You will be prompted to allow the clean up procedure, click Yes
  • When finished exit out of OTL
  • Now delete OTL.exe (if still present).


Next

To remove ERUNT use Control Panel > Programs > Uninstall a program

Next

Delete the random named .exe file for GMER from your Desktop.

As far as I can see, your computer looks clear of infection now.

Are you still noticing any problems ?
  • If you are let me know about them.
  • If not it's time to make your computer more secure.


Please read the article below which will give you a few suggestions for how to minimise your chances of getting another infection.


If your computer is running slowly after your clean up, please read.
When I deleted GMER.exe Norton flashed up stating that it is processing security risk Trojan.Gen.2. - I presume this is a false alarm and is due to a "mis-diagnosis" by Norton due to the programming code inside GMER?

Other than that, all seems to be sorted.
Again thanks for all your help, and the prompt replies, I really appreciate it.
You're welcome, glad we could help. :)

As you suspected, GMER contains a number of processes that operate in a similar manner to some malware, it is sometimes false flagged by AV programs because of this.
As your problems appear to have been resolved,