Trouble removing spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MrGrogs, Apr 3, 2009.

  1. MrGrogs

    MrGrogs Private E-2

    For about the last week I have been trying many solutions to ridding a problem of web page redirects. I have been through the full process described under the Windows XP Cleaning Procedure and therefore am coming to this forum for assistance. SuperAntiSpyware and Malwarebytes came up clean.

    When I click down on a link (but not release it) you can see the web page in the bottom of the browser change from the supposed original target (shown when you do a mouse roll-over) to one involving the web site poiskin.ru. If you release the mouse click at that point it will take to you one of several general web directories, instead of your intended target web site. Funny thing is that it is inconsistent. Sometimes when you click down, the original target is not changed and the web page will load as expected upon the mouse release. Other times it is as described above.

    I hope someone can assist with this. Thanks.
     

    Attached Files:

    Last edited by a moderator: Apr 3, 2009
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, MrGrogs

    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Question: What did you do on April 1st to cause all of these new files and .dlls in:
    C:\WINDOWS\system32\


    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    Using Windows Explorer navigate to and delete the below bold file:

    E:\Program Files\Mozilla Firefox\extensions\{D071BC20-B639-4D66-87AF-0D9B0FFBA91D}\chrome\content\overlay.xul

    Step 4:
    Now run Ccleaner

    Step 5:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • C:\MGlogs.zip

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  4. MrGrogs

    MrGrogs Private E-2

    Dr M.

    Thanks very much for your response. Regarding the April 1 activity, this is probably when I had to reinstall system files from backup. Previous spyware removal attempts had corrupted my userinit.exe file and god knows what other files in the system32 directory. I couldn't log back into the system no matter what I did...when going into my user account it would log me in then log me straight out again. My solution was to boot to Acronis True Image from CD and reload all the system 32 files from backup, even though I knew that these were from an infected backup. Then I started again to try to disinfect the system.

    I have gone through all of your suggested steps. The MGlogs.zip files is attached. I want to thank you guys and compliment you on a robust and clear process for dealing with malware issues. Great job!

    Having tried firefox for a while I haven't been subjected to any more redirects. So it looks like I am clean. I will post back here if they re-emerge.

    Thanks again!
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're Welcome, MrGrogs!

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    Safe surfing! [​IMG]
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds