Browser not working right after using "Generic Solution to HSA"

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by buzzsaw, Oct 14, 2004.

  1. buzzsaw

    buzzsaw Private E-2

    I got Hijacked with the about:blank amoung other things I am sure and I found the documentation " When all else fails - Generic Solution to HSA (Only the Best) & About:Blank hijack " to be great! I used all the tools involved with the exception of cccleaner. Using the tools, I found the offending processes and files. And I appear to be no longer infected ... but ...

    Now my IE 6 browser does not seem to function correctly on some sites. I "believe it to be ssl related redirection links, but I am not sure. Specifically, I cannot login to myebay with secure login I get page cannot be displayed and same with my wireless phone sprintpcs.com - I cannot text message or view pictures - always getting page cannot be displayed after login. I spoke with both tech support thinking I am missing a setting in IE and they know what it is, but yeah, right. So, I tried resetting browser settings, deleting cookies and cache. Nothing has worked so far.

    Any ideas ... help! Thanks in advance!
     
  2. buzzsaw

    buzzsaw Private E-2

    Bump. Anyone with ideas?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From Internet Explorer click Tools, Internet Options, Advanced. Scroll down to Security and make sure that yo have checks on:
    Use SSL 2.0
    Use SSL 3.0

    If that does not help, try just resetting to defaults.
     
  4. buzzsaw

    buzzsaw Private E-2

    Nope. Still no workie. This is a trip.

    More info. When I try to login to the ebay portal, I will get "page cannot be displayed" right after I click login, but if I click back twice to main page it thinks I am logged in. So it takes the login information but cannot redirect me. Same with the sprint site but I cannot use the online tools (text messaging, photos, etc.) It logins me in, but when I go to use the personal tools - blank. I am sure it will happen with other sites I would "secure login" to, but I don't use any others.

    Help?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. MKWCrowe

    MKWCrowe Private E-2

    I am having the same problem, although it was related to trying to clean a W32.spybot worm. After finally achieving a clean scan with Norton and SpySweeper, the IE browser doesn't allow access except to the initial page. At the same time, it appears to be blocking access to spyware and adware protection software sites (same for this site as well as directly accessing download sites).

    I have reset the defaults on the security levels for trusted sites, but it appears to want me to lower the firewall, something I am not willing to do until I have downloaded the recommended spyware/adware programs recommended by Major Geeks.

    I am going to attempt to download the recommended software to disk and run it on the system. I believe these problems are related to the "suge.exe" and "systemrun" files that do not have certificates or identification of the publisher. Both files are located in System32. I have posted a question on these elsewhere in this forum. Anyone with an understanding of how the page blocks are being set up, please respond!

    At this point, I may lower the firewall and allow these programs to run in order to gain access to the sites. I definitely can't lose anything. The system is unusable as it currently exists. Is it possible to obtain a disk containing the recommended software listed under Major Attitude's "How to: Spyware..." notice?

    Hope to hear a reply to this thread. Something in River City stinks. I notice that several threads indicate a similar problem with disabled browsers. I have also talked to local tech folks who are saying that reinstalling IE is a problem under SPG2. As such, resetting IE controls (or lack thereof) is another major undertaking.

    Help
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MKWCrowe,

    I'm not sure this problem is at all related to your problem. There are literally a dozen or more malware programs that cause problems with Internet access to various sites. Especially sites that help to resolve malware problems. There is no end to the jerks out there writing malware to do just that.
     
  8. buzzsaw

    buzzsaw Private E-2

    I am still having these problems accessing many https login sites with redirection. Although I have no traces of spyware via spybot, adaware, etc.
    Even resetting all the defaults in IE, lowering the security settings to low, enabling ssl2 and 3, etc.

    Which leads me to the question what is malware, and is it causing these problems or is my browser permantely damaged?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Malware is a generic term covering all kinds of possible harmful, annoying programs. For example, viruses, trojans, adware, hijackers, popups, etc.

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser (i.e, Mozilla, IE, Netscape) , e-mail. Close before running Hijack This!


    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of \Documents and Settings, or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT
     
  10. buzzsaw

    buzzsaw Private E-2

    For example here is what ebay gives me after sigining in -

    "If you are seeing this page, your browser settings prevent you from automatically redirecting to a new URL.

    Please click here to continue. "

    Of course clicking on 'here' does not work. Redirections seem to work with non-ssl sites, such as majorgeeks. When I click reply and it prompts me to sign-in, I can and the redirection to the post works fine.

    Any ideas?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! As I said in my last message, post your HijackThis log.
     
  12. buzzsaw

    buzzsaw Private E-2

    Sorry. I must of missed that you wanted the log. Please do, here it is.

    Logfile of HijackThis v1.97.7

    Edit by chaslang: Inline, old version of HJT log deleted
     
    Last edited by a moderator: Oct 24, 2004
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now go back and get the proper version of HijackThis and read the stuff in message # 9 in this thread again on how to post a HijackThis log, where to install, what to shut down on your system before running etc. Please read the directions we post. Fix this before continuing any further with the instructions below.

    Note: you also never ran the steps in READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal This is supposed to be done before posting.


    Also another note:

    The below GameSpy Arcade application can contain adware: see http://www.giantcompany.com/antispyware/research/spyware/file-aphex.exe.aspx

    C:\Program Files\GameSpy Arcade\Aphex.exe

    You should uninstall this and fix the below line with HijackThis:
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/sof...nch/alaunch.cab

    You also have a trojan: C:\WINDOWS\System32\kxnfbr.exe

    To fix this torjan, make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    kxnfbr.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - (no file)
    O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - (no file)
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O4 - HKLM\..\Run: [iqlrgaeivxsvb] C:\WINDOWS\System32\kxnfbr.exe

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\kxnfbr.exe

    Now reboot in normal mode and post a new HJT log (with the correct version and installed correcly). And tell us how things are working.
     
    Last edited: Oct 24, 2004
  14. buzzsaw

    buzzsaw Private E-2

    OK log is attached. Please advise. Thank you very much.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is basically clean now. But you did not tell me how everything is working.
     
  16. buzzsaw

    buzzsaw Private E-2

    The original problem still persists. Like I said I believe following your steps throughly, I removed the spyware and trojan from the beginning, but since then the browser does not work correctly with "from what I can tell", SSL redirection logins.

    For example, it works fine here at majorgeeks, but the problem is still there with sprintpcs.com and ebay.com, any of my "personal" logins.

    Here is some more information. For example when I login to ebay and get the - "If you are seeing this page, your browser settings prevent you from automatically redirecting to a new URL.

    Please click here to continue. "

    I click continue and nothing. I then hit the back button and go to a "page cannot be refreshed" and back again and again until I am on the main ebay page and I am then shown as logged in. So the login actually takes, but it cannot redirect me to the appropiate page afterwards. Unfortunately things don't work as well with the sprint site, as I cannot access my personal pages to my phone at all.

    Throw me another bone?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In an earlier message I ask about trying FireFox. Did you try it?
     
  18. buzzsaw

    buzzsaw Private E-2

    Those sites work with Mozilla Firefox.

    When accessing those areas (logins) of ebay and sprint, mozilla gave me the pop-up box that "you are leaving a secure site connection, do you want to continue". Meaning that it was redirecting me from a SSL site to another SSL site (example from login to account infomation), but the browser is prompting, are you sure you want to leave the secure connection, although it has no idea I am just going to another secure connection.

    Which leads me to believe that ebay, sprint, and countless others do the same way. And my IE bombs on it. I would assume it is a setting, but I have reset them all.

    Any more bones to throw me? besides keep using mozilla :rolleyes:

    I really need the integration of IE. Must be a setting somewhere. And I KNOW someone else must have this problem.

    Thanks!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds