Browser Hijack in IE and FF

Discussion in 'Malware Help (A Specialist Will Reply)' started by panther1, Mar 25, 2009.

  1. panther1

    panther1 Private E-2

    I had a vundo trojan problem which I successfully (?) cleaned using your guides. However, my browsers are still hijacked. Everytime I do a search in google and click on the links I'm redirected to different sites. I followed all the steps from the read and run post, but it didnt solve the problem.

    Additionally, earlier on when I was cleaning out the trojan, I could not run any kind of scan (vundo fix, mbam etc) in safe mode because my computer would just shut down. It ran these programs perfectly fine in normal mode just not in safe mode.

    I've attached all the logs. Can anyone please help?
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Except for the main one I need. C:\mglogs.zip ---> attach that into your next reply and I can start to work out a fix for you.

    Thanks
    Kestrel
     
  3. panther1

    panther1 Private E-2

    Sorry about that. Here are the logs for that.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) First of all I would like to draw your attention to one of our "stickies" which you should have read already:

    Warning about Keygens, Cracks, and other Illegal Software

    You are running software which allows you to bypass the free time-limited version of NOD32 AV and also allows you to download updates without a password.

    Before we continue, you must now uninstall this, and we can also tidy up remnants from Symantec if you are no longer using that as an Anti-Virus, and at the end of the fix you can install some AV from our list of recommended.


    2) I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation.


    3) Spyware Doctor <--- Is this a trial or paid for software? If it is only a trial then please uninstall it from Add/Remove Programs as well as the below:

    • J2SE Runtime Environment 5.0 Update 6


    4) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT


    5) Please use Windows EXplorer to find and delete the following bold files:

    C:\Documents and Settings\Omemma\Desktop
    ~WRL0241.tmp
    ~WRL1383.tmp
    ~WRL1813.tmp
    ~WRL3037.tmp
    ~WRL3111.tmp



    6) Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    7) Now install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    8) Now Run Ccleaner!

    9) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    10) Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    • Also let me know whether you use WildTangent Web Driver or not.

    FYI: To prevent files like the below littering your C Drive:

    sqmnoopt12.sqm

    Open up Windows Live Messenger > go to Tools > Options > and on the "General" tab uncheck the option to be a part of the customer improvement program.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also, please use windows explorer to find and delete the below bold file:

    • C:\Program Files\Mozilla Firefox\extensions\{2444883F-81FD-44C5-A295-8DB4B40D57ED}\chrome\content\overlay.xul
     
  6. panther1

    panther1 Private E-2

    I didn't know about the Nod32, somebody installed it for me...anyways I deleted that and everything else you asked for.

    I've also attached the new logs for MGtools. Also you asked if I use Wildtangent Web driver, the answer to that is no, I don't.

    The steps you recommended seem to have solved the browser hijack problem for both FF and IE.

    Do you have any recommendations of AV or Firewalls I can use to keep my pc protected?
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, if you do not use Wild Tangent then please check add/remove programs for it if it is listed. It is more than likely a part of My HP Games

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds