happili redirect and shutting down

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ghostpiper, Apr 21, 2012.

  1. ghostpiper

    ghostpiper Private E-2

    The past week I have been getting a google redirect on firefox. Twice in the past 2 days my monitor has gone blank and I was frozen. Also a few times in the past days windows has encountered a problem and shut down.

    I have gone through the read and run me faq and the windows 7 malware removal guide. Here are my attachments. The RootRepeal log is not attached as I am running windows 7 64 bit.

    Thanks so much in advanced, I never knew places like this existed to make the online world a nicer place.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Do they also occur in Internet Explorer. Test after rebooting your PC and DO NOT OPEN Firefox. Only run IE.


    Also please do the below so that we can boot to System Recovery Options to run a scan.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. ghostpiper

    ghostpiper Private E-2

    I realized that I did not have my antivirus or adaware realtime protection disabled on startup so that several of those scans were run with those actively running. I hope I didn't waste your time. Does it matter and should I continue with your instructions?
     
  4. ghostpiper

    ghostpiper Private E-2

    Ok, so I rebooted and neither ie 64 bit or 32 bit seem to be redirecting. I did like 6 different searches and clicked on probably 60 different links and no redirect. 64 bit was redirecting yesterday for sure though.
    Here is the log requested.

    i am realizing though explorer was only redirecting after I had already used firefox and had not rebooted

    also to clarify, i am using avast free antivirus and adaware adwatch live and those were probably running when doing most of my original scans
     

    Attached Files:

    Last edited: Apr 22, 2012
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so it sounds like Firefox is actually your problem.


    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla Firefox 12.0 Final

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.

    After reboot, make sure you manually delete the below folders, if you don't delete these, the redirections will still occur:
    C:\Users\ghostpiper\AppData\Roaming\Mozilla\Firefox
    C:\Program Files (x86)\Mozilla Firefox

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    See if you still have redirection problems when using the new Firefox install.
     
  6. ghostpiper

    ghostpiper Private E-2

    seems to be better, no redirects so far.
    one thing i forgot to mention is I get 2 run dll errors now on startup. It started sometime around running the 4 scans yesterday but I was also being dumb and stopping processes and such.
     
  7. ghostpiper

    ghostpiper Private E-2

    ok, so no more redirects so far.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If these are still occurring, you will have to tell me what the exact word for word messages are. There is no malware in your logs.
     
  9. ghostpiper

    ghostpiper Private E-2

    There was a problem starting
    C:\Users\GHOSTP~1\AppData\Local\Temp\wbrsi.dll
    The specified module could not be found

    There was a problem starting
    C:\Users\GHOSTP~1\AppData\Local\Temp\widrom.dll
    The specified module could not be found

    thank you for your help
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this >> View attachment fixlist.txt

    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows to see if you are still getting messages about these missing DLLs
     
  11. ghostpiper

    ghostpiper Private E-2

    no more run dll errors, everything seems to be working great.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. ghostpiper

    ghostpiper Private E-2

    Thank you so much, really great work you guys do here. A shining light in what can be a dark and cold online world sometimes. Is there a way to donate to the cause?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    No there is no official process. You can send your friends here and also do your downloading of programs at our main site ( www.majorgeeks.com ) and send your friends there too. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds