Browser hijacking - Maxthon and Firefox

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by netrate, Jul 5, 2011.

  1. netrate

    netrate Private E-2

    I have run Rkill and Anti-Malaware on my Xp drive in safe mode. I have also run Spybot and SuperAntispyware (all in Safe Mode). They have found and eliminated all of the trojans and viruses - BUT, my browser is still hijacked when I turn on the computer.

    I have run AFT (http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25) and cleaned up all of the temp files. I used the EasyCleaner to clean out the other temp files that might have been left over.

    In Normal startup:
    As soon as windowsXP loads, Maxthon browsers opens up (it is a browser shell that runs on the IE). It is always the same set of websites. I can close it, but it opens up periodically on its own.
    With Firefox, when I click a link, 25% of the time, it does not take me to that link, but hijacks me to another link.

    * I used EasyCleaner and there isn't anything in the start up that would cause this.

    I should note that I am running a dual boot xp/win 7 - and the hijack AFFECTS BOTH of the Operating systems.

    In Safe mode :
    The browser DOES NOT automatically start. So, that is tells me that the virus isn't loaded.

    Also, I had heard that running the Windows Recovery wasn't the best idea, so I am trying to avoid this route.


    Here is the Hijack This! log from Safe mode

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 8:59:32 PM, on 7/4/2011
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Safe mode

    Edit by chaslang: Inline HJT log removed. READ & RUN ME FIRST. Malware Removal Guide sticky not followed.
     
    Last edited by a moderator: Jul 5, 2011
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    HijackThis logs are of no use to us and the forum stickies even instructed you not to post them. You should be reading the sticky/pinned threads. Start with the below which is at the top of every page in the Malware Forum.

    Fixing Google Redirection/Hijacking Problems
     
  3. netrate

    netrate Private E-2

    Thank you for the reply. I did read through some of it originally and I had tried what was stated there before in an effort to get rid of this. My issue I thought might be unique because I am running a dual boot system where the google hack is on both OS's - and this maxthon hack which brings up the browser each time windows boots up.

    I will read through it again and follow the instructions fully.
     
  4. netrate

    netrate Private E-2

    Maxthon Browser keeps opening on its own!!

    I think I have fixed the problem with Firefox google redirecting, but my original problem of the MAXTHON Browser opening on its own is still giving me issues. I went through this :
    http://forums.majorgeeks.com/showthread.php?t=230267

    but I am still having the issue. Any ideas?

    Here is the problem : Maxthon (a shell of IE) continues to open, not matter what I do when I boot the computer. This does not happen in Win 7 (dual boot) because I do not have Maxthon load there...
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please stay in one thread for your current problems. I merged you back to your first thread. If you want help, please complete the instructions already given and attach the logs requested. Based on the logs we can decide whether you are having malware problems and what to do about it. Without the logs, we cannot help you and do not even know if you are having malware problems. If you are having a browser run without you actually asking it to run, this is a typical sign of a TDL or MR infection. Hence you may not have fixed your hijack issue.
     
  6. netrate

    netrate Private E-2

    Ok, following the steps and instructions - this is run in NORMAL mode XP.
    I run Rkill to start. This is the only way I can stop the Maxthon browser from popping up during the following steps. The curious thing is that, Rkill does not say that there is anything terminated when it finishes, but Maxthon does not pop up after that.

    I thought I would put down each step so others can have a look.
    AFT -Firefox, IE deleted files. Opera doesn't have anything to delete it says.
    Java - flushed - wondered if I should uncheck the "keep temp files on this computer"?
    Firefox - in the newest version, it only has "Clear your recent History" and "Remove individual Cookies" - it does not have "Clear Now". I cleared all the cookies and as otherwise stated.
    IE - With IE, the new version is different, but has DELETE and then give check boxes for cache, etc what you want to delete. I checked them all and deleted.
    DNS - flushed the cache

    Ran the Gooredfix and have the log ready.

    When I run tdsskiller.exe, nothing happens. I renamed it as per the instructions and it still does not run.
    I am presently running HouseCall to see if this can find something. Yesterday, I ran HouseCall for a few hours and it find a virus. but my internet shut down before it could complete the scan.

    GooredFix by jpshortstuff (03.07.10.1)
    Log created at 10:34 on 06/07/2011 (David)
    Firefox version 5.0 (en-US)

    ========== GooredScan ==========

    Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{FBCB1676-10D0-4A5A-AD60-EE875FCE90C8} -> Success!
    Deleting C:\Documents and Settings\David\Local Settings\Application Data\{FBCB1676-10D0-4A5A-AD60-EE875FCE90C8} -> Success!
    Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{511654F1-A563-4EE3-A66F-36BE1B110574} -> Success!
    Deleting C:\Documents and Settings\David\Local Settings\Application Data\{511654F1-A563-4EE3-A66F-36BE1B110574} -> Success!

    ========== GooredLog ==========

    C:\Program Files\Mozilla Firefox\extensions\
    {972ce4c6-7e08-4474-a285-3208198ce6fd} [02:15 30/04/2007]
    {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [01:08 17/10/2008]
    {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [05:41 17/01/2009]
    {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [00:30 14/09/2010]
    {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [22:20 03/10/2010]
    {D6D05E6F-D5C1-4e03-8E33-73F92B05E262} [16:04 15/05/2011]

    C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\f8x4uzcl.David March 19 2010\extensions\
    optimizegoogle@optimizegoogle.com [16:46 11/12/2010]
    {02450954-cdd9-410f-b1da-db804e18c671} [03:22 25/01/2011]
    {20a82645-c095-46ed-80e3-08825760534b} [22:40 14/05/2010]
    {b9db16a4-6edc-47ec-a1f4-b86292ed211d} [20:54 21/06/2011]
    {d47a9f51-8281-43fa-f450-f28ef8735e9a} [00:23 27/01/2011]
    {d5ea4520-61a1-11da-8cd6-0800200c9a66} [02:15 22/06/2010]

    C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\q55q1jcz.default\extensions\
    artur.dubovoy@gmail.com [23:10 01/03/2010]
    checkplaces@andyhalford.com [02:49 19/03/2010]
    dlembed@aeruder.net [18:16 25/08/2008]
    firebug@software.joehewitt.com [23:39 16/03/2010]
    firefox-ext@youtubekeep.com [02:49 19/03/2010]
    max@subfighter.com [01:08 22/02/2010]
    VacuumPlacesImproved@lultimouomo-gmail.com [16:51 17/03/2010]
    YoutubeDownloader@PeterOlayev.com [02:49 19/03/2010]
    {20a82645-c095-46ed-80e3-08825760534b} [16:35 02/09/2009]
    {635abd67-4fe9-1b23-4f01-e679fa7484c1} [18:34 17/03/2011]
    {b9db16a4-6edc-47ec-a1f4-b86292ed211d} [23:39 16/03/2010]
    {c50ca3c4-5656-43c2-a061-13e717f73fc8} [19:32 20/11/2009]
    {DDC359D1-844A-42a7-9AA1-88A850A938A8} [05:21 20/02/2010]

    C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\xpe8qeob.david\extensions\
    {20a82645-c095-46ed-80e3-08825760534b} [15:32 17/03/2010]
    {635abd67-4fe9-1b23-4f01-e679fa7484c1} [18:34 17/03/2011]

    [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
    "{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [13:03 21/08/2009]
    "jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [00:30 14/09/2010]

    -=E.O.F=-
     
    Last edited: Jul 6, 2011
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete ALL of the instructions ( that includes all the way through step 5 too if you still had problems after step 4 ) also please note that we ask you not to post any logs inline. Logs must be attached to your messages. See the instructions.
     
  8. netrate

    netrate Private E-2

    Ok fair enough, but how come I can't run the kdsskiller program?
    I will continue after housecall is finished and try step 5.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly because you have an infection that it would remove if it could run and the infection has learned how to block TDSSKiller from running. If this is the case, you likely have an infected Windows system file which may need to be replace manually from the Recovery Console.

    Note 1: We did not ask you to run Housecall

    Note 2: It is advisable to back up important data before continuing. Some of these new forms of infections are nasty and when removed, it can sometimes cause a problem where a PC cannot be booted. This occurs becausem, as stated, the infections are in important Windows system files and removing the hooks of the infection result in breaking the boot process due to how the infection has link into the operating system.
     
  10. netrate

    netrate Private E-2

    Ok, I am going through all of the steps again. This time I tried it in Safe Mode (it did not specify that I can remember whether it mattered or not). I did all the steps and went onto step 5, but not I need to uninstall Java and cannot download the runtime environment without the internet, so I am rebooting in normal mode so I can get the internet back.

    Lastly, a question - when in Safe Mode, I don't have any issue of the Maxthon Browser showing up or starting itself up. What is this an indication of?
    AND, I thought I should note that I have several computer connected to the router and none of the others are affected as this one is.

    Thanks again for all of your patience and help - I do finally understand why you must get frustrated when you painstakingly put all of the instructions in order and people like me don't follow them exactly. My apologies.

    Going to uninstall Java runtime next and follow the rest of the steps.
     
  11. netrate

    netrate Private E-2

    Ok, when I rebooted after uninstalling Java (as per the instructions), I cannot install the new Java Runtime that I previously downloaded. It tells me that it is:

    unable to download 1.6.0-26-b03.xml

    So, I suspected that the internet might be down. I ran Firefox to see and this is what appeared:

    The Proxy Server is Refusing Connnections

    This is a recent event and I have seen it before, if I click TRY AGAIN, it will connect to the internet. But I am wondering if this is the root of the problem?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use a proxy to connect to the internet? If not, then I refer you back to step 1 of the READ & RUN ME FIRST which had the below line:

    Also even before step 1 the below instructions existed:

    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    You need to keep going and finish everything and attach the logs. Until you do, we cannot help you.
     
  13. netrate

    netrate Private E-2

    I cannot install the new version of Java runtime. I am connected to the internet, I can surf the web, but it tells me :

    Download failed : from =/jre1.6.0_26-c to=C\documents and settings\David\applications data\sun\java\jre1.6.0_26\jre1.6.0_26-c.msi

    I am not sure if I use a proxy to connect to the internet. I looked at the link you sent (most of it is the old version of IE and Firefox and even Chrome) but I think I figured it out.
    Chrome's CHANGE PROXY SETTING takes me to IE connection. I didn't think that Chrome was a shell of IE?
     
    Last edited: Jul 6, 2011
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See message # 12
     
  15. netrate

    netrate Private E-2

    Ok, I am going to continue working as per the instructions.

    I am on the Combo Fix stage and found it stops installing at "outfolder folder C:\32788R22FWDIN" (I know this because I clicked on DETAIL in the installation box and it shows me the progress bar along with which part it is working on).

    When it stopped installing the first time, it sat for 30 minutes (uninterrupted) and then the computer froze. I rebooted and tried again, this time it sat again (same place installation - if you click on details) and sat for another 25 minutes, but this time it did not freeze at all. I did read that you are not supposed to touch anything or click on anything during this time, but I thought at 25 minutes and it being 1:00am, that I would try again the next day (being on the computer for 2 days straight is starting to wear me down).

    I noticed this morning that there is a new file folder called :

    32788R22FWJFW on my hard drive. Should I delete this before trying to start combofix again?

    PS - I requested information about Combofix on bleepingcomputers because of it not installing and the files I wanted to delete that it created. I thought they were the "authors" of the software, so I asked them on bleepingcomputer but they asked me to stay in this forum.

    Continuing onto 'Rootrepeal' and 'MGtools' next.
     
  16. netrate

    netrate Private E-2

    It did not fix the redirection problems - just tried googling Major Geeks and it redirected me to some spam site. Here are the logs:

    Again, Combofix did not install completely, so there is no log.

    Thank you again for the time. I have to say, there have been points where I just would have formatted and started over. Hopefully I can get this thing eliminated.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have your Windows XP boot CD?



    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  18. netrate

    netrate Private E-2

    Yes, it claims it is a fake Master Boot Record.
    I have the WinXP CD
    Here is the log. Thank you for your time, I know it is the weekend!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then see if you can boot from this CD and get into the Recovery Console. See the second section in the below link where it says "How to use the Recovery Console"

    http://support.microsoft.com/kb/307654

    If you can get to the command prompt of the Recovery Console, type fixmbr and hit enter. After it finishes type exit to reboot and remove the CD to allow Windows to boot normally.

    If you were able to run fixmbr, rerun MBRCheck and attach a new log. Also tell me how things are working.
     
  20. netrate

    netrate Private E-2

    Is this going to erase my drive? I don't want to start the process and find out that I went too far with it...
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is going to fix the master boot record ( MBR ) which as you saw in the MBRcheck log, has been modified by malware. However, as with many modern day infections, things can sometimes go wrong and a drive could become unbootable. This will not erase your data. It will still be there but you would need to get at using other methods. Thus it is alwasys a good idea to backup important data first.

    Note, that these MBR infections are fixed all the time ( many per day ) without any problems occurring, but we cannot guarantee you that nothing will go wrong. Problems sometimes even occur just by running an antivirus scan.
     
  22. netrate

    netrate Private E-2

    I don't think I have an admin password, but it tells me I do. Can't get past this point in the Recovery Console. Any suggestions? I followed the instructions and hit 'enter' when I thought there wasn't any password. Then I hit "admin" and that didn't work either.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot backup normally into your user account which has admin priviledges. Then goto Control Panel > User Accounts and change the password for the Administrator user account to something you know. ;)
     
  24. netrate

    netrate Private E-2

    Ok, got to the command prompt:

    c:\windows

    Typed fixmbr

    It says
    "This computer appears to have a non-standard or invalid MBR
    Fixmbr may damage your partition tables if you proceed
    This could cause all partitions on the current hard drive to become inaccessible
    IF you are not having problems accessing your drive, do not continue"

    Is this is what is expected?
     
  25. netrate

    netrate Private E-2

    Forgot this part at the bottom of the screen:

    Are you sure you want to write a new MBR?
     
  26. netrate

    netrate Private E-2

    How is the FIXBOOT command different than the FIXMBR command?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If any non-standard MBR is recognized, this is the message you will receive. Some PC manufacturers ( i.e., Dell, HP, and others ) commonly use special MBRs to allow for special factory recovery partitions and other info. Some end user's ( like possibly you ) could also create special MBRs to allow for special multiboot type operating systems ( which perhaps you did since you have two Win XP partitions and one Win 7 partition ). We have sometimes asked users questions like below before fixing their MBRs.
    Take special note of what is in #7 since you don't really have a choose. Your MBR is infected and needs to be repaired which will put it back to a default Window XP MBR when you use the fixmbr command.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is in the link I gave you from Microsoft. ;)


    Fixboot writes a new startup sector on the system partition.


    Fixmbr repairs the startup partition's master boot code. The variable device is an optional name that specifies the device that requires a new Master Boot Record. Omit this variable when the target is the startup device.
     
  29. netrate

    netrate Private E-2

    cancel post

    Trying to delete post. Please cancel this one.
     
    Last edited: Jul 12, 2011
  30. netrate

    netrate Private E-2

    Ok, I wrote the new MBR (I guess) - log is attached.
    It only took about one second and was done. Maybe that is normal.

    Another thing I found very strange. When I used the XP CD to tried and run the REPAIR, when I got to the screen that asked me to pick a drive and then type a password, it wouldn't accept any password that I had picked. I tried about 10 times (rebooting each time, and in some cases rebooting normally and changing the password again and again), but the only thing that seemed to work was the ENTER key. Is this normal?

    Lastly and most importantly, I have Win 7 boot as well. I know that it has the same redirection problems, but I haven't run anything on it as of yet (except an occasional malware and spybot). I don't want to reinfect my system (and it seems that Winxp did just that to my Win7), so how should i proceed with fixing Win7 now? I am afraid to boot to Win7 because it might affect my fixMBR with Win xp?

    Any, after about 20 minutes that Maxthon browser did not pop up, so some success! I haven't tried Mozilla yet.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! And it fixed it too.

    Yes because you never set a password on your Administrator user account. You were trying to use the password that you have on your user account and that is not the password for the Administrator which is the account that must be used at the Recovery Console.

    You only have one physical hard disk which means you only have one master boot record and rewriting the one with Win XP MBR should have fix it. You should boot into the Win 7 setup to see.


    On your Win XP boot, you need to do the below.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 15, 2011
  32. netrate

    netrate Private E-2

    Ok, presently running Combofix.

    It asked me to install Recovery Console. I did.

    It went through the 50 stages.

    It asked me to delete some folders in my c:\document and settings\David...
    and I did .

    It is now asking me "Are you sure you want to remove the folder "windows" and move it to the recycle bin?"

    Now, I am a little worried, because the tutorial on Combofix did not go into this much detail. Should I do this?
     
  33. netrate

    netrate Private E-2

    Ok, here are the logs. Ran everything, didn't have any issues with programs running.
    I ran
    • photoshop
    • mozilla
    • chrome

    Please advise on how to proceed. Again, thank you for everything...
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that fixed a lot but we have more to do.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 15, 2011
  35. netrate

    netrate Private E-2

    Ok, here goes the logs.
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to tell me how things are working so I will assume everything is good since your logs are clean.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  37. netrate

    netrate Private E-2

    MGtools - MGclean.bat - ran DOS in a flicker, hardly saw it, so not sure if it worked or not.

    System restore flush - there is already a check mark ON for the system restore (following the instructions here) - so should I uncheck it, and then recheck it and then uncheck it again?
    http://forums.majorgeeks.com/showthread.php?t=31668
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what it should look like. If the C:\MGtools folder and other misc items we had you download are gone, then it worked.

    Yes to remove old restore points you need to first disable ( turn off ) system restore on all drives and then reenable it. We suggest a reboot inbetween even though it is not really supposed to be necessary. ;)
     
  39. netrate

    netrate Private E-2

    Ok, I did the system restore uncheck, check and reboot - BUT, I am getting this now, using Anti-vir.

    Begin scan in 'C:\System Volume Information\_restore{96A452B5-369C-4F10-940D-980699AFEE2C}\RP3\A0000274.exe'
    C:\System Volume Information\_restore{96A452B5-369C-4F10-940D-980699AFEE2C}\RP3\A0000274.exe
    [DETECTION] Is the TR/Buzy.1177.3 Trojan
    [NOTE] The file was moved to the quarantine directory under the name '4dbd877c.qua'.

    I am not sure why this is still here, but it could be from a backup drive that I have been using to backup my entire drive (it has no OS on it, just used for storage).

    I am not experiencing anything with the browser problem anymore (that was fixed), but now experiencing this issue. Did I go wrong somewhere? Can a trojan be inside a backup drive that has no OS on it? Maybe in the autorun feature of USB plug and play?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Keep your removable drive plugged in and disable System Restore again on ALL drives. Then reboot. DO NOT reenable System Restore yet. Do a full scan with Avira and fix anything it finds. Then reboot again ( if anything was found ). If anything was found on this first scan then rescan again after the reboot.

    Let me know the results. Every once in awhile, some files do get locked into the System Restore folder and just don't get deleted as they should when it is disabled.


    A drive does not have to have a bootable copy of your OS on it to get infected. Almost any file can carry an infection. And backup drives without an OS still have a master boot record which can be infected too. However note that you appear to have two Win XP partitions on your hard disk. One you called "XP drive old" and one you called "Win XP NEW". And then you have a third partition called "Win 7". All of these I assume are bootable and all of them could have infections on them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds