firefox rerouting problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by apoxacilin, Aug 19, 2009.

  1. apoxacilin

    apoxacilin Private E-2

    Hi ya'll,

    Thanks for all your help, very wonderful.

    For the past day or so, firefox in conjunction with google and other search engines has been strange, particularly in the way it reroutes. If I search for a term, google et al. will provide results; however, when I click on a result I get rerouted to some smart ad sites. Sometimes it doesn't happen but eventually it will start. quite annoying.

    I've attached logs,
    Thanks again
     

    Attached Files:

  2. apoxacilin

    apoxacilin Private E-2

    and here is my mgtools log
     

    Attached Files:

  3. apoxacilin

    apoxacilin Private E-2

    Hi guys,

    I know no one told me to, but i ran Gooredfix, and so the log is now posted here. Any ideas on what to do now?

    Thanks again,
    matt
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are about 18 months out of date with your copy of MGtools. You MUST ALWAYS use the current online version. If you save copies, you will most likely be out of date. We will start a fix and I will ask you to update during this fix.

    First you did not pay attention to the first instructions in the READ & RUN ME. You must not have multiple antivirus programs installed. You must immediately uninstall either AVG 8.5 or McAfee and then reboot before you do anything else.

    Next I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.


    Please double-click the RootRepeal.exe previously downloaded.
    • Select File then Scan
    • On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    • When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
      • C:\WINDOWS\system32\kbiwkmkbaqpqjd.dll
      • C:\WINDOWS\system32\kbiwkmrhncjmto.dat
      • C:\WINDOWS\system32\kbiwkmturyxmls.dll
      • C:\WINDOWS\system32\kbiwkmvelfsodc.dat
      • C:\WINDOWS\Temp\kbiwkmgyfqradmei.tmp
      • C:\WINDOWS\Temp\kbiwkmnqldwbcqfg.tmp
      • C:\WINDOWS\system32\drivers\kbiwkmtogrvfgv.sys
    • After Wiping all files, immediately reboot your pc!

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. apoxacilin

    apoxacilin Private E-2

    Hi chaslang!

    Thank you for helping, very much thanks.

    A couple things:
    1) Since posted last, my computer hasn't been able to start in normal mode.
    I was getting the following message:

    ""A problem has been detected and Window has been shut down to prevent damage to your computer.

    DRIVER_IROL_NOT_LESS_OR_EQUAL

    If this is the first time you've seen this Stop error screen,
    restart your computer. If this screen appears again, follow these steps:

    Check to make sure any new hardware or software is properly installed.
    If this is a new installation, ask your hardware or software manufacturer for
    any Windows updates you might need.

    If problems continue, disable or remove any newly installed hardware or software.
    Disable BIOS memory options such as cacheing or shadowing.
    If you need to use Safe Mode to remove or disable components, restart your computer,
    press F8 to select advanced startup options, and then select safe mode.

    Technical information:

    *** STOP: 0x000000D1 (0xE18AD000, 0x00000002, 0x00000000, 0xEF9B2225)

    Beginning dump of physical memory
    Physical memory dump complete.
    Contact your system administrator or technical support group for further assistance.""

    Since I have performed some of your steps, it has started normally.
    I believe after I ran avenger. (I did all the steps before running the updated MGtools in Safe Mode).

    2)About having both AVG and McAfee simultaneously; when I first started using AVG I tried to uninstall McAfree and was able to uninstall most of it. However, I have repeatedly thereafter not been able to uninstall "McAfee Security Center." I get the following message when I try:
    "The installation cannot continue because some components
    (c:\progra~1\mcafee\agent\uninst\screm.ui) are missing."


    After performing your recommendations, however; search engines have not redirected. I have only tried a couple times, and will obviously let you know if it started redirecting. My logs are attached.

    Thanks again for all your help. I tell everyone I know about this site.
    matt
     

    Attached Files:

  6. apoxacilin

    apoxacilin Private E-2

    OOPs!

    I forgot to run CCleaner after avenger and before MGTools.

    Attached to this post is the new MGTools log.


    thanks,
    matt
     

    Attached Files:

  7. apoxacilin

    apoxacilin Private E-2

    so, everything seems to be working fine with searches.

    however, about every other time I open firefox (and usually when I'm checking my yahoo mail) it crashes eating almost all of my pf usage.

    any idea? related?

    thank ya'll
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did you install AVG before you tried to uninstall McAfee?

    You could still try running the below since it still shows as installed: McAfee Consumer Product Removal Tool

    Then reboot and run it one more time. After doing this, attach a new log from MGtools ( you need to run the scan again first).
     
  9. apoxacilin

    apoxacilin Private E-2

    I believe that I did start using AVG before uninstalling McAfee. It was awhile ago, and if I installed AVG, after it was installed I immediately uninstalled McAfee.

    Attached is the new MGtools log.

    Thanks for all your help,
    Matt
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Just for future reference, always uninstall the 1st before adding a new one. Doing it the other way can lead to many problems.

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds