Brower Redirection and other issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by screamingcaterpillar, Feb 9, 2009.

  1. screamingcaterpillar

    screamingcaterpillar Private E-2

    Hi Majorgeeks,

    Sorry about the long post following, I've been having problems since friday 6th of February and have tried numerous solutions until finding the malware removal guide on this forum today, and was not sure what information to include...

    When my computer first appeared to come under attack my Bullguard antivirus program closed and I began to experience pop ups in internet explorer. Programs such as Prunnet.exe were downloaded to my computer. Since then when I reopened Bullguard it began to find numerous different infections, but after about 45 mins of scanning I got the error message "generic host process for Win32 services has encountered a problem and needs to close" followed by a message that Windows needed to restart because of the DCOM server process launcher service terminated unexpectedly. On occasions when it did finish it found a trojan ".dll" file it could not delete, I was advised to delete it in safe mode but even then it wouldn't let me delete it. I found some advice by searching google to right click the file in safe mode and in the security settings to uncheck the box labelled "inherit from parent" and then click remove, then on reboot to delete the file, which I did. The DCOM shutdowns stopped-however it happened again when I ran virus checks in safe mode. On Sunday I noticed that google results about fixing malware in firefox and internet explorer were being redirected. Other symptoms included the security centre being disabled (not by me). Before finding this forum I did scans with spybot and ad-aware and removed the numerous infections they found.

    After following this site's guide it appeared that all the problems had stopped- there was no more browser redirection, and I restarted in safe mode to do a virus scan and test if DCOM shutdown kicked in, which it didn't. However when i rebooted again the browser redirection was back, although that appears to be the only symptom left at the moment. I have attached my logs below- the reason there is two SuperAntiSpyware ones is that I did one before running Ccleaner, installing new Sunjava and empyting the quarantine on various programs, then the other one is from when I began following the guide through in order.

    I hope that some of that information is useful, please ask if you need to know anything else.

    Any help you can give me would be very much appreciated.
     

    Attached Files:

  2. screamingcaterpillar

    screamingcaterpillar Private E-2

    The other logs:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs, you are clean. Any reamining problems with BullGuard may need to be debugged with them or in our Software Forum. You may need to look at Event Logs to possibly track down why it is crashing. I first step may be to uninstall it, reboot (do not skip) and then reinstall to see if that will fix it.

    You do have some minor things I suggest that you fix.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (file missing)

    After clicking Fix, exit HJT.



    Are you still having browser redirection isssues. If yes, which browser..... FireFox or IE or does it happen with both. If only with FireFox please follow the below instructions.

    Download this View attachment FFFred.zip to your C:\MGtools folder. Then extract the FFFred.bat file from the FFFred.zip file into the C:\MGtools folder. Then double click the FFFred.bat file to run this batch file. It runs very quickly. A notepad log will popup. You can just close this notepad window because the log will already be added to the C:\MGlogs.zip file. Just attach the new C:\MGlogs.zip file.
     
  4. screamingcaterpillar

    screamingcaterpillar Private E-2

    Hi Chaslang, thanks for getting back to me

    I've removed Windows Messenger now.

    I checked and the browser redirection only seemed to be happening with Firefox so I followed your instructions and have attached the new MGtools log.

    Thanks for all your help so far.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You MUST HAVE your FireFox browser completely shutdown while doing the below. So print this if necessary.

    • Right click Start and select Explore
    • Navigate to the below folder:
    C:\Program Files\Mozilla Firefox\extensions\{3854C210-E262-4E6C-8E91-001DD47F4A9A}\chrome\content
    • locate this file overlay.xul
    • Right click on the file and select Delete.
    Now run FireFox and see how things are working.
     
  6. screamingcaterpillar

    screamingcaterpillar Private E-2

    I've deleted that file and (so far) it seems to have stopped the browser redirection issues. Do I need to do anything else?

    Thanks again for everything.
     
  7. screamingcaterpillar

    screamingcaterpillar Private E-2

    Sorry, realised I had a question I forgot to ask. I have an flash mp3 player that I've probably used on my computer since I got the virus and I stupidly didn't think to attach it when doing the malware removal guide the other day. Do you think it would be unsafe to connect it again (i.e. could the virus potentially have moved onto it?) It's only a cheapo one so I can just stop using it if needs be.

    Cheers
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your problems began after using this then I would uninstall/delete it.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds