Fast Browser Removal issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by xatsmann, Dec 16, 2009.

  1. xatsmann

    xatsmann Private E-2

    My computer had the Fast Browser Search Bar malware installed on my machine so I uninstalled it but it kept coming back. I have followed all the READ & RUN ME FIRST: Malware removal guide recommendations including the "Basic computer maintenance everyone should do" as well.

    My problem now is that I am still having issues with Firefox. I removed and reinstalled it and it came up with some add-ons. I thought this was strictly a Firefox issue so I posted to the forums on Mozilla for Firefox and explained that the I could not open a second window with the 'default' add-ons that came as part of Firefox. I was informed that there are NO add-ons that should load with a clean copy of Firefox. I also cannot use the customize feature unless I enter Firefox in safe mode and I was told that this shouldn't happen in firefox.

    This has lead me to believe that my install of Fast Browser was causing a problem. I also cannot remove Fast Browser from my wife's version of FF when I am logged on with her log on. I have removed all of but I cannot get the Keysearch.URL to change to another search URL--the rest of Fast Browser I was able to change under about:config but not the Keysearch.URL.

    I also could not get the manage files window open in FF but I was able to do it Opera.

    I am attaching files below and will post a second message in this threat the last file.
     

    Attached Files:

    Last edited: Dec 16, 2009
  2. xatsmann

    xatsmann Private E-2

    Re Fast Browser Removal issues

    Here is the last file attached.
     

    Attached Files:

    Last edited: Dec 16, 2009
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to first uninstall the illegal Adobe software. RE: "adobe keycrack" Also uninstall any other illegal software or cracks/keygens. Any still seen in any other necessary fixes will automatically be deleted since they may be the reasons for malware problems. See our policies: Warning about Porn, Keygens, Cracks, and other Illegal Software

    Please remove MGtools.exe and ComboFix.exe from the below folder as they do not belong here as stated in our instructions.
    C:\Cleaning_Tools

    Did you knowingly install FreeNet?

    You need to run MSconfig and set it to Normal Startup mode as requested in step 4 of the READ & RUN ME.

    Now disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer

    You need to follow our instructions properly. It can be the difference between success and failure and working PC or a broken PC.

    Shutdown Sandboxie before doing any of the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we are going to uninstall a few things including FireFox (again) so shutdown FireFox now and use either Internet Explorer or Opera to continue.

    Is the copy of Spyware Doctor 6.0 that you installed a paid version? If not then uninstall it immediately.

    Uninstall the below old versions of software:
    Ad-Aware 2007
    Ask Toolbar
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Development Kit 6 Update 4
    Mozilla Firefox (3.5.5)
    Search Guard Plus (My Face LOL)
    Search Guard Plus Updater (My Face LOL)



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
    Now download and reinstall FireFox from here: Mozilla FireFox How is it working now?
     
  4. xatsmann

    xatsmann Private E-2

    Actually I fixed the Firefox problem on the Firefox support forum but I went a head and did your malware removal anyway. I removed the adobe software and the keygenI figure it can't hurt to get rid of all the other stuff. I did remove and reinstall FF anyway just to be on the safe side.

    I've attached my files as well.

    To answer your other question--yes I did install FreeNet on purpose. I read about it on line and thought it was okay but I thought it was giving me a performance hit. I wasn't using it anyway so I took it off.

    About moving combofix.exe and mgtools from the c:\Cleaning_Tools folder--does it matter? Does it need to be in the root of c:? I just moved it there so I could find it quicker.

    Anyway, thanks for the help.

    xatsmann
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it matters which is why the instructions specify to install them in the locations given in the instructions. ComboFix needs to be on the Desktop and MGtools needs to be in the root folder.

    Since you did not post any follow up logs from the previous instructions, I cannot continue with you to tell you if things are clean.
     
  6. xatsmann

    xatsmann Private E-2

    c.,

    I did attach them. I think I took to long to finish the message so it did not upload them. Here they are again.

    x.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. That would not be a problem. You most likely forgot to click the upload button after browsing to the files which only selects them for upload. They do not upload/attach until the Upload button is clicked.

    Your logs are clean, but you should do the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - AutorunsDisabled - (no file)
    O9 - Extra button: (no name) - AutorunsDisabled - (no file)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -

    After clicking Fix, exit HJT.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Jack\Local Settings\temp


    Then if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds