Browser Problems enlarged font and still win fixer 2005

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gazman1983, Sep 21, 2005.

  1. gazman1983

    gazman1983 Private E-2

    All

    I have followed to the letter the sticky thread on how to remove spyware trojans etc. After installing and running all the programs I still cannot get rid of these things. Also one of the programs could not remove svrinet.dll and when I tried to remove it with spybot it went but then kept re-appearing.

    My browser text on some sites eg. google has doubled in size and also the win fixer re-direct and also a few others still occur. I have attached the log file as instructed.

    Any advice/comments would be appreciated.

    Regards

    gazman1983
     

    Attached Files:

  2. gazman1983

    gazman1983 Private E-2

    Sorry my hijack this log is now attahced
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please print these instructions out for use in Safe Mode.

    Please download VundoFix.exe to your desktop.
    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at. Iit should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\svrinet.dll

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\tenirvs.*

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:
    O2 - BHO: (no name) - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - C:\WINDOWS\svrinet.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: svrinet - C:\WINDOWS\svrinet.dll



    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Once your machine reboots please attach a new HJT log from normal mode.
     
  4. gazman1983

    gazman1983 Private E-2

    Hi there have performed vundofix and hjt in safe mode and now attach my new HJT log. Also everytime I boot up a common name settings modifier microsoft spyware beta thing and has to be removed each time which is a ballache.

    Thanks for a swift reply chas lang.

    Sorted the browser size was paranoid about this spyware stuff and forgot about control + mouse wheel to zoom in/out!!

    Still getting some diverting screens though to various sites such as VIP fares and Match date or something like that
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please translate the above into English. ;)

    You need to install HJT properly as given in the HJT sticky thread. You are running it directly from the ZIP file using WinRAR:
    C:\DOCUME~1\GARRYM~1\LOCALS~1\Temp\Rar$EX00.656\HijackThis.exe

    You will not get any backups of changes this way.
     
  6. gazman1983

    gazman1983 Private E-2

    Hi sorry I have insatalled it properly now here is the new log...
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below may not work with Spybot's Teatimer running and also note your Spybot installation is broken anyway because the O2 line below with the missing file is for Spybot. You should probably uninstall Spybot make these fixes and then reinstall it. I personally do not use Spybot's Teatimer.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: C:\WINDOWS\system32\ssf.dll - {04FEB29F-9D60-4E28-AF29-5AF89C44EFF6} - C:\WINDOWS\system32\ssf.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\ssf.dll

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. gazman1983

    gazman1983 Private E-2

    What I meant to say was:

    When system boots up common name settings modifier tries to install

    Microsoft anti spyware beta removes it but says it is an elevated threat.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete the rest of my previous message and if Microsoft is still picking up something, run a full scan with it in safe mode and then post the log. Also if it gives you info on finding anything always post exact messages, exact filenames and paths etc (if given).
     
  10. gazman1983

    gazman1983 Private E-2

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: C:\WINDOWS\system32\ssf.dll - {04FEB29F-9D60-4E28-AF29-5AF89C44EFF6} - C:\WINDOWS\system32\ssf.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)

    DONE ABOVE

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\ssf.dll

    -No file when looked in safe mode with protected system file viewing enabled

    Ran CCLeaner no Problem - new log attached

    Deleted Windows/Prefetch files
     

    Attached Files:

  11. gazman1983

    gazman1983 Private E-2

    Have changed the prev. msg a bit as it may have been unclear

    How bad is the security threat do you think so far?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The file may have been removed by HJT while fixing the O4 entry.

    You log is clean. Are you having any other malware problems?
     
  13. gazman1983

    gazman1983 Private E-2

    It would seem not now will be in touch if I do!

    The only thing I have is google.com diverts to google.co.uk don't know if it's an easy fix?

    Basically thank you very much for your help, I will recommend your site to friends as you have sorted my problems!!! :D
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this:



    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now you should also check out the below to help keep you clean:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds