adware.massafv removal?

Discussion in 'Malware Help (A Specialist Will Reply)' started by wcurugby, May 22, 2005.

  1. wcurugby

    wcurugby Private E-2

    my usual homepage is www.wcupa.edu (my schools website) but now its being hijacked by a DSN error and this website http://www.popfinder.net/... i scanned with the symtec online scan and i couldnt remove it. i use McAfee and it wont pick up the adware.massfav. please help me remove this because even if i try to type in my schools website it redirects me to this DNS error page and its really starting to piss me off
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the steps given in the below and also take a look at this thread:
    HELP! I've done everything on the 'do this first post' & my system is still eaten up!

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. wcurugby

    wcurugby Private E-2

    i downloaded all the tools and did the online scans as perscribed in the tutorial. the second online scan found the adware.massfav and adware.minibug, but i couldnt remove them because i dont subscribe to norton. i ran the other tools and removed whatever was found but that still hasnt fixed the problem and now my homepage has changed again to startsearches.net and in the window it was uninstall hompage powered by uninstaller XP. here is my log fils for HJT.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download ABIremover and save it to a location like C:\ABIremove
    Extract the executable file from the ZIP file to that folder too.

    Reboot into Safe Mode with not network suppost, be sure you have ALL browsers closed while running this removal tool.

    Next, start the ABIRemover.exe, press install, wait (explorer window will disapear)

    Reboot into normal mode and attach a new HJT log. There may be an additional problem we need to fix. After posting this log, do not reboot or power down your PC. Please wait for a response to see what to do next. You can disconnect youself from the Internet to be safe but do not power down.

    Do you use any Cisco products (like a router or modem etc)?
     
  5. wcurugby

    wcurugby Private E-2

    here is the new HJT log... i use and linksys router by cisco systems. its set to run xbox live as well as mine and my housemates computers.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not install HijackThis as requested. You are running it like this:
    C:\Documents and Settings\Rick Heist\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    That means you are running it directly from the ZIP file which we specifically requested you not do.
    Also you MUST exit browsers ( C:\Program Files\Internet Explorer\iexplore.exe ) before using HJT.

    You only have one item to fix in your HJT log.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpE42D.tmp

    No exit HijackThis.

    Did check out the link I gave you in message #2? That user had a load of items add to his Favorites that need to be fixed.

    Are you still having any problems?
     
  7. wcurugby

    wcurugby Private E-2

    sorry about that i could have sworn i made a new directory for HJT... anyway since i clicked that link you sent me on the last post i really havent had any more problems... im not that computer literate so that last thing you told me about closing my browsers and the path i didnt quite understand. but if i do ctrl+alt+dlt and close IE explorer will that take care of what you were talking about and then can i run HJT?... im sorry for not knowing much but you guys are a huge help
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not need to use Task Manager (CTRL-ALT-DEL) to kill you browsers like IE. Just close the browser itself (all of them) by click on the X on the top right of the browser window. When I say ALL that means even the one like you are reading right now.

    You do not need to apologize. But it is always a good idea to inform people helping you of your PC knowledge level so we have a better feeling for how to write instructions for you.

    SInce it sounds like you are all cleaned up now, you should work through the steps in the below thread to help keep you clean:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds