Babylon Toolbar/Redirect Removal (FireFox) & Funmoods Toolbar/Redirect (IE)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SonyFan, Aug 1, 2012.

  1. SonyFan

    SonyFan Private E-2

    I am presently attempting to fix my grandfathers computer, and unfortunately this thing has a ton of issues, but that's simply because he *thinks* he knows what he's doing. It's so bad I've actually brought his desktop home with me and I've been working on it for the better part of the past 4-5 days. Thus far, I've removed over 20 different toolbars, add-ons, etc. that have no purpose, but I can't seem to get rid of these two.

    In regards to the Babylon toolbar, I've tried everything I can think of, but it's still showing up all over Mozilla Firefox. I have removed Babylon Toolbar from the control panel, I've changed the FireFox homepage back to the default, I've removed Babylon as a search provider, and I've attempted to uninstall Babylon from the FireFox Add-on tab. However, there are still Babylon entries all over the about:config page and google searches somehow automatically become Babylon tabs. I've also tried completely uninstalling FireFox (using Revo Uninstaller), however after re-installing Firefox, the about:config is still riddled with Babylon entries.

    And it's pretty much the same thing with Funmoods and IE. I've uninstalled Funmoods through the control panel, and I can't find it anywhere else, but any search automatically redirects through funmoods.

    Thus far, I've run (individually over the past few days): Avast! full scan (both running and through startup), Malwarebytes full scan, SpyBot S&D scan (both running and through startup).

    Now I've run the programs required to see the logs, and they're attached. If there is anything else you need to know, I'd be more than happy to provide it.

    eMachine ET1831
    Microsoft Windows 7 Home Premium x64
    6.1.7601 Service Pack 1 Build 7601
    Pentium Dual-Core CPU E5300 @ 2.60GHz
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox (USE REVO UNINSTALLER!!!) and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Running better now?
     
  3. SonyFan

    SonyFan Private E-2

    Would here be any issues running MozBackup to save the usernames/passwords he has currently saved in the browser as well as the bookmarks?
     
    Last edited by a moderator: Aug 2, 2012
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's just stick to doing it this way for now. In case anything goes wrong with MozBackup.
     
  5. SonyFan

    SonyFan Private E-2

    Is it normal to have 25+GB in the AppData\Roaming\Mozilla folder?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not too sure. You could ask in the software forum and THEN we can continue here with malware removal if you like. :) Or go ahead with MozBack up, whatever you prefer.
     
  7. SonyFan

    SonyFan Private E-2

    Haha, no worries. I'm followed your directions exactly as written and I was just shocked to see how long it was taking to delete the file. Then I checked the properties of the folder and I was double shocked.

    BTW, that worked perfectly, and I can't seem to find any hint of Babylon or Funmoods being present in either browser. Thank you very much.

    I am having a problem updating the driver for the graphics card though. Can you help me out with that or should I start a thread in the hardware section (or somewhere else) instead?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yuk, sorry, not my area :-D You can post in the software forum. Or Drivers forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. SonyFan

    SonyFan Private E-2

    I will do just that.


    Once again, thank you for all your help.
     
    Last edited by a moderator: Aug 4, 2012
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome! Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds