Continuing to become infected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Skull6, Oct 17, 2011.

  1. Skull6

    Skull6 Private E-2

    I noticed slowdowns & redirects early last week. I've researched what I could about the issues (Win32/Toolbar.Zugo & Win32/Kryptik.txq being but 2 of them). I am running Windows XP Pro (version 2002) SP3-32 bit as an OS & ESET Smart Security V 5 as an AV/ Firewall suite. I use both Firefox 7.0.1 and IE 8, but have FF as the default browser. I have tried to work through your posted guides, & have saved the logs that I could. Every AV that I've ran seems to find more infections--some that can be cleaned, others placed in quaranteen (except for the point of your guide where I ran MBam--which came up clean). I cannot seem to get RootRepeal to keep from hanging. (This might be because ESET re-activates AV & firewall protection on restart, no matter what I try.) Needless to say, I'm quite frustrated, but am not willing to give up--hence this thread. I read in one of the guides not to post any logs until told to do so. I am hoping that someone here at MajorGeeks.com will be willing to help me work through this problem.
     
  2. Skull6

    Skull6 Private E-2

    Update: After starting my computer after dinner, I received a "Error reading TrayIconClk->visible. Cannot create system shell notification icon." error--& numerous icons are missing from my system tray now. (The only ones present are the local area connection, Norton Ghost & ESET Smart Security.) I also had to right-click on the lower bar of my desktop to reactivate my quick lauch toolbar. Don't know if these are pertinent...
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete ALL of the instructions in the READ & RUN ME and attach the logs we asked for. If you cannot run RootRepeal, just skip it and continue all the way thru to the end where you attach the other 4 logs. The guides do not say not to post logs, the clearly ask you to attach them. Step 3 of the Windows XP cleaning procedure stated the below
     
  4. Skull6

    Skull6 Private E-2

    Logs (minus RRLog) attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than some items ComboFix already removed, your logs are clean. Even the MBRCheck and TDSSkiller logs you had were clean. However do you know what the below Tasks/jobs are for?

    Code:
    "C:\WINDOWS\Tasks\"
    config~1.job  Oct 18 2011         616  "ConfigExec.job"
    dataup~1.job  Oct 17 2011         580  "DataUpload.job"
     
  6. Skull6

    Skull6 Private E-2

    I think they have something to do with Microsoft's "Fix it center," which I plan on uninstalling anyway. Should I be more concerned with these?

    Thanks so much, Chas. I do appreciate your patience & assistance!
     
  7. Skull6

    Skull6 Private E-2

    One last quick question: This morning, as I was checking this thread, I noticed that FF was asking if I wanted to allow a redirect from this very page. Your thoughts?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you have some plugin or infection within Firefox itself. Let's remove it.




    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    C:\Program Files\Mozilla Firefox
    C:\documents and settings\UserAccount\Application Data\Mozilla

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Now see how Firefox is working. Do not reinstall any plugins, yet until you are sure it is working properly.
     
  9. Skull6

    Skull6 Private E-2

    Directions followed. Firefox 5 successfully installed. No hitches or glitches through the entire process. Thanks again. (Oh, & no pesky redirection warnings wile visiting Majorgeeks!)

    Now, should I stay at version 5, or upgrade?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yor're welcome.

    You can upgrade if you desire, but if your problems begin again it is Firefox that is your problem, not malware.



    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  11. Skull6

    Skull6 Private E-2

    Thanks very much, Chas. That pesky "redirect" warning is popping up again, but I figure I can live with it. It says "Firefox prevented this page from automatically redirecting to another page"--& has an "Allow" button on the far right of the bar. I figure that, if I don't allow, nothing changes (it's currently not actually sending me to any other websites automatically)--so I won't touch that allow button. It only seems to happen on certain websites (such as Majorgeeks.com's forum pages), but I haven't surfed to many other places since reinstalling FF this evening. Again, I can live with it.

    P.S. Which thread do I use in Majorgeeks just to pop in & say "Hi"? :D
     
    Last edited: Oct 21, 2011
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not having true redirection issues as related to malware redirection. You can change your Firefox settings to avoid seeing this message.

    Tools > Options > Advanced > General > Uncheck "Warn me when web sites try to redirect or reload the page"
     
  13. Skull6

    Skull6 Private E-2

    Thanks again, Chas!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds