Scans say clean, yet infection(s) remain

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Blaze92z2, Mar 30, 2009.

  1. Blaze92z2

    Blaze92z2 Private E-2

    Hi,

    I've run numerous malwarebytes, superantispyware, and other scans (spyware doctor, bitdefender online, etc. etc.), in normal and (some) in safe mode, and they report no infection. Yet, whenever I open Firefox to any page, I get two problems: (1) Avast reports "HTML:Iframe-gen and HTML:Iframe-inf" and (2) shortly thereafter, Zone Alarm reports "Trojan-Downloader.JS.Iframe.ane" and sometimes "Trojan-Downloader.HTML.IFrame.ds" in location C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\h3gr9uk3.default\Cache\14A92338d01. This has been going on for about a week.

    I uninstalled Firefox, reinistalled it, run NoScript with the "no iframe" options checked, but it didn't help (I guess once you're infected, those steps are useless).

    In reading your guidelines, I now have my computer boot normally (I changed this in msconfig per your strong suggestions); I used to use CCleaner's startup control, which I now see is a no-no. I've just stopped doing that.

    In preparing the combofix log for attachment to this post, it's very long, but when I searched for the word "infected" nothing came up. Last month you helped somebody with an Iframe infection, and his combofix log reported infections, which I don't see in mine, but obviously something's wrong.

    So I'm stumped and will follow the experts' advice from this point forward. Any help would be greatly appreciated. Thanks much, Blaze
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are using a very outdated version of MGTools....please go back to the Read and Run First instructions and download the current version. You can just let it install over your old version...then get me the new MGLogs.zip.
     
  3. Blaze92z2

    Blaze92z2 Private E-2

    Thank you, Tim.

    I just downloaded the up-to-date MGTools and ran it; attached are the logs.

    Kind regards,

    Blaze
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer to find and delete:
    C:\Program Files\HAS

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file,

    Please tell me what issues you are still having.
     
  5. Blaze92z2

    Blaze92z2 Private E-2

    I followed your instructions exactly.

    I am now NO LONGER getting signs of virus infection when I start Firefox! It is truly awesome how you pinpointed the problem so precisely. What I don't understand is this: HAS is a program I used for years with no problem (it's a synchronization utility); can a virus take over a "good" program and turn it into a problem?

    Just to be sure things are o.k., attached is the latest MGtools logs, as you requested.

    Thanks again for your outstanding expertise.

    Blaze
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes it is possible, but I also want you to find and delete this:
    C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\chrome\content\ffjcext\ffjcext.xul.

    You can reinstall HAS and see if you still have issues.
     
  7. Blaze92z2

    Blaze92z2 Private E-2

    I deleted the file "ffjcext.xul" and reinstalled HAS. Everything seems o.k., except Firefox was ultra-slow. I think that's because my computer is 8 years old (very underpowered by today's standards), and because I updated to the 3.07 release of Firefox, which I discovered had many plug-ins running. I pulled the plug on most of the plug-ins, and all seems alright for now.

    Blaze
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know....If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  9. Blaze92z2

    Blaze92z2 Private E-2

    Thanks, Tim; your help was great!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome......safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds