Browser redirects & other issues

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by khix, Jul 19, 2010.

  1. khix

    khix Private E-2

    (Thanks for the readme!)

    OK, here are my symptoms (started last week, around the 14th/15th, I think...my dh said he was looking at bicycle images online that night when Avira detected a virus or something...but I think that occasional visits to bad websites may be to blame)....(now, remember, I'm not too computer savvy):

    1) Sometimes CPU runs at 100%....it appears to be a svchost.exe that's the culprit....not sure what it is...if I kill the task, computer speeds up. Also, I noticed some weird tasks running every once in a while...sfrvyrotssd.exe (I ended this task & found where it was on my PC & sent to recycle bin) and verclsid.exe (this one went away before I could end the task or research it)...I think there were others, but I can't remember them (didn't write them down)

    2) Windows update has not been working lately. It will download, but not install. When you think the downloaded updates are ready for install, the taskbar icon says "downloading updates: 0%" and it will STAY there. Also, can't access the Windows Update website. (I'm thinking the excessive svchost.exe thing has something to do with the "fake" downloading updates 0% thing...it seems that whenever the fake downloading thing is there, the computer is slow/freezes & that svchost.exe is in task manager).

    3) I'm having browser redirects...If I do a search, & click on a link, it goes to a completely different page. Also, tabs/websites will open up by themselves.

    I'm using Firefox 3.6.6....I also have IE8 on my computer, but haven't used/tested it. I do know that Windows update does not open in IE8 either. My OS is Windows XP home. 32 bit.

    I have ZoneAlarm firewall (the free one). I have Avira AntiVir (the free one).

    I looked for the listed known malware in Add/remove programs, and only found Viewpoint Media Player...got rid of it.

    My Sun Java is updated, and I believe I got rid of all quarantined items in Avira.

    My recycle bin is not empty at the moment (in case I need restore the thing from #1 above)

    I ran CCleaner.

    I enabled viewing of hidden files & folders. I did not yet change MSconfig to normal startup, as I'm afraid to do given the warnings...I've been using MSconfig to change startup stuff, and since my system seems to be compromised, I don't want to mess it up even more by switching to normal startup.

    I did the defogger thing.

    I am attaching the SuperAntispyware Log & the Malwarebytes log. Those scans seemed to work as they should.

    After those scans, I then did the Combofix (took forever, lol!) and I think it worked correctly. Attached is the log.

    Then I tried to do the RootRepeal. I followed directions (disabled Avira, Zonealarm, and Windows Defender), extracted the exe file, and double clicked on it, but it didn't do anything...my computer froze...would not do anything...so after about 20 minutes of waiting, I restarted computer.

    Afraid to try RootRepeal again, I moved on to MGTools, followed directions, and that seemed to work fine. Attached is the zip folder for that.

    So, the only thing that is not attached is the RRLog. Do I need to try & do that again?

    So far, since I've been online after doing the MGTools, my browser (firefox) has not done any browser redirect or opened up web pages on its own....but I'm still not sure if it's completely fixed.....cautiously optimistic, I guess.

    CPU usage is low so far, and I do not see any weird tasks or excessive svchost.exe things going on. And the Windows Update webpage also opens correctly now!

    I hope I did everything correctly. It's so scary to do all this when you're so uncertain about everything!

    Everything seems to be ok, but I want to start a thread post all the logs to get your expert opinions.

    Thank you for all you do!!! Thank God for this site!!
     

    Attached Files:

    Last edited: Jul 19, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. I am assuming that you did in fact have MBAM fix what it found.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds