Can't Get Rid of Browser Hijacker

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hoyasox, Feb 22, 2006.

  1. hoyasox

    hoyasox Private E-2

    Hi,

    I generally use Mozilla but had to use IE the other day because of a compatibility issue and ended up allowing an ActiveX install for a trustworthy site that I guess wasn't so trustworthy. My computer downloaded a ton of malware, trojans etc.

    I have followed all the directions on the Read and Run This First post (except for running the Panda scan, which for some reason does not work) and have attached the logs from BitDefender and HijackThis.

    There were incidences of WebHancer, CoolWebSearch, Mirar and Look2Me among many others. I ran Adaware SE twice and each time it found infected objects but was unable to delete one dll file (different each time).

    The last few times I have restarted/rebooted (my OS is Windows XP), I have received an error message about an exception when attempting to run "C:\Windows\system32\SLNSCFG.DLL, "DllGetVersion"

    Any advice?

    Thanks for the help!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    Can you please remember to attach a HijackThis logs from normal boot mode. Safe mode logs do not always reveal everything we may need to see. Do not get a new one yet. Wait until completing the other steps below.

    Did you purchase AdwareAlert? At one time it was on the rogue tool list.

    Did you have Ewido installed at one time and is it now uninstalled?

    You have a Look 2 Me infection. Please run the steps in the below and attach the Spy Sweeper log as requested.

    Running Spy Sweeper

    Make sure you reboot after running Spy Sweeper. Then continue to the below.

    Now attach a new HJT log from normal boot mode.
     
    Last edited: Feb 22, 2006
  3. hoyasox

    hoyasox Private E-2

    Both Ewido and Adware Alert are currently installed. I've had Adware for a while but just installed and used Ewido after I recently got inundated with all the malware.

    I've attached the logs from SpySweeper and HijackThis (normal boot).

    Thanks again for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But my question was did you purchase Adware Alert. It used to be on the rogue antispyware list and was removed from the list awhile ago. But it is not on our list of tools we would recommend using. If you did not buy it, I would uninstall it.

    It would be best to shutdown Ewido and Spy Sweeper while doing the below or the could interfere with the changes. When you do make the fixes, if any messages popup about canges being made to your start or search pages etc, just accept them since we are the ones making the changes.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R3 - Default URLSearchHook is missing
    O15 - Trusted Zone: http://click.getmirar.com (HKLM)
    O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. hoyasox

    hoyasox Private E-2

    Ok, I uninstalled Adware Alert because I can't remember if I purchased it or downloaded it for free. At least, I tried to uninstall it. First I tried add/remove through the control panel but it said it was unable to uninstall the program and that it might have already been uninstalled. That sounded reasonable since it had somehow disappeared from my startup in the course of my running the other spyware programs and I figured it got targeted and deleted. But then I found Adware Alert still there in my spyware tools folder. I ran the uninstall program that it provides and it said the program had been uninstalled, but all the files are still there (with the exception of the uninstall program!).

    In any case, I followed all your directions from the last post and I've attached the latest hijackthis log. Everything seems to be working perfectly (no error message on startup, no hijacked browsers). Hopefully I get to delete those restore points now! Thanks.
     

    Attached Files:

  6. hoyasox

    hoyasox Private E-2

    Forgot to mention that Spy Sweeper has been catching an application that keeps attempting to install itself in the Startup: ctfmon.exe
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should allow ctfmon.exe to startup. It is a valid application!

    Let's finish remove Adware Alert.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.Exe -boot

    After clicking Fix, exit HJT.

    Then delete the C:\Program Files\AdwareAlert folder. You may need to reboot first or you may need to delete it in safe mode.

    Make sure you tell me how things are working now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds