F Browsing Advisor

Discussion in 'Malware Help (A Specialist Will Reply)' started by Oooops!, May 6, 2008.

  1. Oooops!

    Oooops! MajorGeek

    I'm receiving pop ups from F Browsing Advisor.

    I played a game called Mahjong Titans that was on a friends computer. I liked it and tried to download the game off of an unfamiliar website. I learned later that the game is only for Vista. I have XP. I'll understand if it goes against helping me.

    I'm an idiot and I know better. I should practice what I preach.
    :eek:

    I have the following programs installed.
    All are the latest version with current updates.
    Pop ups have not been removed eventhough I have scanned with each program several times and had results of items that I did delete.

    AdAware 2007
    Spybot Search And Destroy
    Windows Defender
    Windows Malicious Software Removal Tool
    Spyware Blaster
    AVG AntiVirus
    Zone Alarm Firewall
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Oooops!

    Oooops! MajorGeek

    Thank you very much, I appreciate your help.
    :)

    1. Add/Remove - Deleted an entry "F Browser Advisor" as well as a couple of other entries I discovered that were included on MG's list.
    2. SuperAnti Spyware - Clear
    3. Spybot - Clear
    4. Malwarebytes - 7 infections
    5. ComboFix - I don't remember seeing results in a window, only a log?
    6. MG Tools - Unable to run and got confused about it. (The pop ups from F Browsing Advisor seemed to have stopped prior to this).

    I believe the pop ups ended after using Malwarebytes.
    Toggle System Restore completed.

    Currently, my clock is still in 24 hour mode. Must shut down for now, I'll check it again tomorrow when I can get back on the computer.

    Logs Attached
    SASlog
    MBAMlog
    CFlog

    Thank you again!
    :wave
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Without this log we cannot verify if you are really clean. Yes Malwarebytes did remove things related to F Browsing Advisor but it would be a good idea to get the log from MGtools and check for other issues. It is not that complicated. Just follow the steps 1 at a time. There is a lot of info in the steps but most of it is instructional to help people who don't know that much about Windows and computers.

    This is a sign that ComboFix did not run 100%. Since you attached a log named log.txt which is not the correct log as specified in the READ ME, it sounds like it never finished running to make the C:\combofix.txt log which would be the correct log.

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.
     
  5. Oooops!

    Oooops! MajorGeek

    Please see attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you are in pretty good shape. We just having some finishing steps to do.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 8
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1
    Java(TM) SE Runtime Environment 6

    Now reboot your PC after uninstalling all of the above.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!


    Then if you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. Oooops!

    Oooops! MajorGeek

    Success!
    :)

    Ran CCleaner
    Deleted ComboFix, etc.
    Created a new restore point.

    Whew. What an ordeal to go through for a stupid preventable mistake on my behalf. I cannot thank you enough for your patience and time.
    Much Appreciated,
    Oooops!
    :wave
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds