Browser redirects & weird wallpaper - 1 of 2

Discussion in 'Malware Help (A Specialist Will Reply)' started by skipstocks, Oct 18, 2007.

  1. skipstocks

    skipstocks Private E-2

    Greetings all...
    Daughter's machine, <sigh>. While searching for videos on mySpace, she clicked on authentic-looking alert box that warned of viruses & spyware, 'click here to clean' or similar message.

    Spyware took over browser, spawned mass popup boxes, & replaced wallpaper with red background & big bio-haz symbol in the center of the desktop with a message to the effect that the PC was at risk. Duh.

    Calmed the daughter, retrieved the laptop, followed steps in R&RMF. On startup, SpySweeper still detects an attempt to open a browser and go to site 81.29.248.59.

    Files attached - would appreciate guidance for next steps.
     

    Attached Files:

  2. skipstocks

    skipstocks Private E-2

    Browser redirects & weird wallpaper - 2 of 2

    Add'l files...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Browser redirects & weird wallpaper - 2 of 2

    You forgot to attach your HijackThis log. Please follow the instructions in step 7 of the READ ME and attach a HijackThis log. Make sure you follow those instructions properly.

    Is your copy of Spy Sweeper a paid version or a free trial? What about AVG Antispyware?

    Uninstall the CounterSpy trial now becaue we are finished with it.

    Also uninstall Spybot - Search & Destroy 1.4 which is the old version.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below files need to be deleted. See if you can delete them! Try safe mode if necessary.

    C:\WINDOWS\bndsrfst.dll
    C:\WINDOWS\bndsrsqo.dll
    C:\WINDOWS\msvb.dll

    If they will not delete, I will give you another way to remove them later.
     
  5. skipstocks

    skipstocks Private E-2

    Re: Browser redirects & weird wallpaper - 2 of 2

    You also asked me to delete the following:
    C:\WINDOWS\bndsrfst.dll
    C:\WINDOWS\bndsrsqo.dll
    C:\WINDOWS\msvb.dll
    They are deleted. Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Browser redirects & weird wallpaper - 2 of 2

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: MSVPS System - {15272B08-F6FE-4E71-B2BD-A59AD23EBE3C} - C:\WINDOWS\bndsrfst.dll (file missing)
    O3 - Toolbar: The netadv - {D1413F77-5B69-4562-84E1-78F997794E9D} - C:\WINDOWS\netadv.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.
    Delete the below folders if found:

    C:\Documents and Settings\Jessica.RUNNERBUG\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Sunbelt Software
    C:\Program Files\Viewpoint

    Now run Ccleaner
    Now reboot

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  7. skipstocks

    skipstocks Private E-2

    Re: Browser redirects & weird wallpaper - 2 of 2

    S2: Seems to be working much better. Popups gone, biohaz wallpaper gone. Will turn her loose on MySpace again and see what happens...

    You guys rock. Is there a way to contribute to keep the forum going? Plz advise. God bless,
    S2
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Browser redirects & weird wallpaper - 2 of 2

    You did not attach any of the requested logs. And to address your question yes you need to run GetRunKey and ShowNew again. That is the only way to get new logs ;) which is what the last step requests.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds