Browser Trouble - Pages Don't Load

Discussion in 'Malware Help (A Specialist Will Reply)' started by ClocK_FiTS, Dec 6, 2009.

  1. ClocK_FiTS

    ClocK_FiTS Private E-2

    Mozilla Firefox (version = latest n greatest) has been acting up recently. How long I cannot say with any real clarity but a rough guess would be a couple of weeks to a month.

    Firefox will randomly be unable to open an address to anywhere. I can open a new tab and manually type in the address, right click and open it in a new tab or simply click on the link and nothing will work.

    So I've gone through all of the MajorGeek steps concerning winXP but to no avail. Further research made me think that perhaps it was not a malevolent bit of software but, rather, a simple conflict between add-ons. Safe-mode seemed to work but that didn't last long. Also, I am not too sure of this anymore either as I think that Google's Chrome may be experiencing the same difficulties.

    Right now I am using Opera and I have had no trouble at all opening up tabs with this lil' gem. However, I have a download manager that integrates into Firefox but not opera.

    I took a gander at Private Shishya's topic here: http://forums.majorgeeks.com/showthread.php?t=191050; a similar thread that was recommended to me by the forum, although, if it is the same issue, I'm not quite sure how to apply the advice to my own situation.

    I've tried the angles that I can see but have ended up at a brick wall.
    Please help.
     

    Attached Files:

    Last edited: Dec 6, 2009
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    FYI: You are using a very old version of MGTools! I will have you download and run the newest version in a little while.

    1. Please go to Add/Remove Programs and uninstall the following softwares:

    • Java(TM) 6 Update 13 <--- outdated Java
    • Viewpoint Media Player <--- should have been uninstalled as per step 1 of the R&R.

    Did you knowingly install the below? If not then please include it in our uninstall list.

    • winpcap-nmap 4.02


    2. Now using Windows Explorer please navigate to each of the following bold files, right click them and let me know the info on the properties if there is any.
    • C:\Windows\RELATION.INI
    • C:\Windows\wyvern.ini

    3. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    c:\documents and settings\Joshua\Local Settings\Application Data\prvlcl.dat
    
    Folder::
    C:\vghd
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    5. Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    6. Run the new MGTools.exe and attach the C:\Mglogs.zip that it creates into your next reply as well as the log from combofix. Also let me know about the properties on those files.

    Thanks:)

    Kes13!
     
  3. ClocK_FiTS

    ClocK_FiTS Private E-2

    Thank you for your help and sorry for missing the file!

    Glad to have Combofix back. :)
    I've followed your instruction and have attached the (up-to-date) logs.

    Again, thank you for taking the time to help out.
    Much appreciated.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let me know what you know about these .ini files
    • C:\Windows\RELATION.INI
    • C:\Windows\wyvern.ini
     
    Last edited: Dec 22, 2009
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you need to do the below:

    The Combofix version that you now have installed is running in reduced functinality mode which is of no use to us. You need to update.

    1. Download a fresh copy of Combofix

    and run it as per these instructions:

    Also refer to this guide:

    A guide and tutorial on using ComboFix

    2. Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    3. Run the new MGTools.exe and attach the new C:\combofixt.txt into your next reply as well as the C:\Mglogs.zip.

    Thanks
    Kes13!
     
  6. ClocK_FiTS

    ClocK_FiTS Private E-2

    I must confess, I dropped the ball on the properties request. Don't ask because I'm not sure myself but instead of querying the files for properties I deleted them.

    As far as Combofix and MGTools are concerned, however, I'm confused. I did follow the instructions when going through the process. I went to bleepingcomputer and download Combofix as soon as they announced that it had been deemed safe for use again. Saved it to desktop. Ran it once. Then, once it had finished the initial run, dragged the cfscript onto the icon as you requested.

    Afterwards, I ran Java6 from the link you pointed me to.

    Finally, I saved MGTools.exe from the link you specified and placed it into my C: drive. Ran it (winxp rules) and posted the log.

    I also disabled avg and my spyware prior to any of this.

    Just in case I upped the wrong file attached is the file: combofix.txt.

    Should I redownload everything and try again?
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No need to be confused, you did what I wanted you to do corrcetly. You just need to address the below:

    just attach the requested mglogs.zip which should be sat on your c drive.
    Do not re run anything. Do not do anything unless otherwise instructed.
     
  8. ClocK_FiTS

    ClocK_FiTS Private E-2

    I uploaded the file on my first response. Is it corrupted? The forums won't let me reload the file.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My bad. Do the below now:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Thanks
    Kes13!
     
  10. ClocK_FiTS

    ClocK_FiTS Private E-2

    File attached.

    (Sorry for the delay)
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    
    C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\prvlcl.dat
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\TEMP
    • C:\Documents and Settings\Compaq_Administrator\Local Settings\TEMP

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    5. How are things running now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds