Adware and Browser problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by raysim, Feb 18, 2008.

  1. raysim

    raysim Private E-2

    Apparently my son downloaded some adware. I have used the general guidelines but I still am having problems. My ie7 will crash and the details list iebrowserc.dll and iebrowsercmp module as the problem area. Mozilla firefox will run, but when i try to sign on to yahoo or juno to get my email it goes to a search page. I use bellsouth dsl. If I boot up with linux, I can read my email. I have apparently gotten dcads, superior ads, coolwebsearch. I am useing xp home sp2 with a amd 17 gig processor. I will attach the appropriate files. I could use the help. Thanks

    This my first post. I hope it is done correctly.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    ComboFix did not run properly for you. Please go to the READ ME and follow the instructions there which have been just changed. These new instructions could help to get it to run properly.

    Also you did not install and run SUPERAntispyware as requested. Please run it and attach the requested log for it.

    Is your copy of Spy Sweeper a paid version or free trial? If free, uninstall it now. If paid, then uninstall Windows Defender.

    Do you know what this bandoo program is? I would bet it is part of your problems.
    O20 - AppInit_DLLs: c:\progra~1\bandoo\bndhook.dll


    Uninstall the below programs:
    iMesh
    MySidesearch Search Assistant

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: MySidesearch Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\WINDOWS\system32\mysidesearch_sidebar.dll
    O2 - BHO: BrowserCmp - {1D8282E6-BC4F-469B-AAED-7E4FF077AD93} - C:\WINDOWS\system32\iebrowserc.dll
    O2 - BHO: (no name) - {335A8B82-6A43-4709-8F92-B0397A0A9EF1} - C:\WINDOWS\system32\clbcate.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Ray\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    And don't forget the ComboFix log ( if it ran ) and SuperAntispyware log.

    Make sure you tell me how things are working now!
     
  3. raysim

    raysim Private E-2

    combofix will not run properly even with the new directions. It says that the comspec environmental variable was found to be corrupt.Combofix has attempted repairs and will need to restart. I click ok and it does it over and over. So I downloaded super anti spy. It would not install at first, but finally it did. I updated my .net framework files and ran the winstaller installer program. When I ran super anti spy, it found quite a few problems and I told it to correct them. I rebooted and windows would not come up. I had to pick the last know good configuration. After I did that, my ie7 will work normally and I was able to install h and r block tax software. However, whenever I try to access my juno or yahoo email I am directed to an at and t search page when I attempt to log in using mozilla firefox. I can log on fine using linux and ie7. I have removed bandoo and webroot spysweeper, and my side search assistant and imesh. I will enclose the log from the super anti spyware. I wasn't sure if I should continue on with your instructions until I updated you. Thanks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just finish the remainder of the instructions. Note that some items in the HijackThis part of the fix may not be found due to some of the uninstalls and running SUPERAntispyware. Just ignore anything not found and continue.
     
  5. raysim

    raysim Private E-2

    I have finished the steps and I still cannot log in for my juno or yahoo email. The message I got for Juno is Sorry, we could not find "http://www.juno.com/s/webmail?cf". Everything else seems to work. Any ideas would be appreciated.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your logs Bandoo is still installed. What is it and I recommend uninstalling it anyway from Add/Remove programs.

    Also do you know what the below is from?
    O20 - Winlogon Notify: fsp_abwl - C:\WINDOWS\SYSTEM32\fsp_abwl.dll

    The best I can tell is it may be related to something from FSPro Labs. Maybe My Lockbox?? Does this sound familiar. Or does the FSPro Labs sound familiar.. See this: http://www.fspro.net/folder-lock-box/

    What browser are you using to acccess Juno?
    Try another browser?
     
  7. raysim

    raysim Private E-2

    I thought that I had uninstalled Bandoo. My son said bandoo works with his msn. I uninstalled it. Also, my avg caught a trogan called pakes.I . It said it is quaranteened. I do not know what the 020 line is. I only download from reputable sites. I check every day giveawayotheday.com and I subscribe to gizmos support alert newsletter. If he says it is a good program, I usually trust him and may download and install. Consequently, I have a lot of software that I don't actually use.
    I can access my juno email and my yahoo email via ie7 now, but it won't work with mozilla. I really want to make mozilla my default browser to increase my security and it seems to run better. I hope that I am not being too much trouble.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did the below sound familar at all to you or your son?
    Then your first order of business should be to uninstall anything you don't actually use. And if it is not installed but you just have saved the download/installation files, decide if you really want them and if not delete them. Good housekeeping is a must.


    Uninstall FireFox, reboot and then delete the below folders:

    C:\Program Files\Mozilla Firefox

    Then reinstall FireFox. Does it work now? If not, the only other choice is to uninstall again and this time delete the below which will also remove all bookmarks, extension...and other config information for FireFox. It may or may not work.

    C:\Program Files\Mozilla Firefox
    C:\Documents and Settings\USERACCOUNT\Application Data\Mozilla\Firefox\Profiles

    Where USERACCOUNT is then user account name you are having the problems with FireFox and Juno.

    Did any of that help?
     
  9. raysim

    raysim Private E-2

    Neither me or my son knows what the FSPro labs is. My computer works now. Thank you for your assistance. I probably would have never got it fixed without a complete reimage.
    Thank you
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome.
    Then do the below.


    Continue by downloading a tool we will need

    - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    fsp_abwl.dll
    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)


    Now just exit Process Explorer.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - Winlogon Notify: fsp_abwl - C:\WINDOWS\SYSTEM32\fsp_abwl.dll

    After clicking Fix, exit HJT.

    Now reboot and after reboot, delete the below file if found.
    C:\WINDOWS\SYSTEM32\fsp_abwl.dll



    Then if you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds