Desktop IE shortcut problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Stannies, Jun 7, 2010.

  1. Stannies

    Stannies Private E-2

    Complete Newbie to forums, I apologise in advance.
    I have just followed the Windows XP clean up process on my sons PC to rid it of AntiSpyware soft.
    Wow that took some doing for a novice but all seems to be back to normal now except a strange shortcut problem.
    If a desktop shortcut is created to a web page - like facebook. When selected it opens two tabs
    The facebook page as expected and another page (porn but only a front page not too nasty)
    I created another shortcut to a different webpage and this time the secondary page was a gambling site.
    After the big clean up I installed Avira Antivir (Free one).
    Should I run more clean ups?
    Nothing else seems to be detected.
    I must also say Thank you for the well detailed clean up processes.
    Much appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!



    Per the cleaning procedure, you need to attach your logs. Do not run the cleaning procedure again. Attach the original logs from the first time run. The below is a direct quote from the procedure.
     
  3. Stannies

    Stannies Private E-2

    Thanks for quick reply.
    Sorry I did read and follow the procedure but at the time I had not created a new shortcut on the desktop so had not realised I still had a problem.
    I did carry on and follow the procedure as if it was all ok. It was only later we found the shortcut thing.
    I also have a problem finding the malwarebytes antimalware log. I did run it and it did find stuff.
    I had a lot of problems getting the exe's etc onto the computer and getting them to install in the first place. I renamed them as instructed but the virus stopped them running. I ended up creating a few new users and had to be very quick to set them running one at a time before the virus stopped me. Could not even run task manager or Msconfig.
    Attached logs and will carry on searching for the missing one.
    Thanks
     

    Attached Files:

  4. Stannies

    Stannies Private E-2

    Found the MBAM log - attached.
    Thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 13
    Sky-Banners browser enhancer
    Street-Ads Browser Enhancer

    If any of the above cannot be found or will not uninstall, just continue on to the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
    R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: Street-Ads Browser Enhancer fnkgbesg - {383E9897-E204-4585-923E-3AC8E5F051C5} - C:\WINDOWS\system32\fnkgbesg.dll
    O2 - BHO: Sky-Banners Browser Enhancer bvjjmzcq - {93419A48-50A6-4543-AE93-916CBD483F3C} - C:\WINDOWS\system32\bvjjmzcq.dll
    O4 - HKLM\..\Run: [skb] rundll32 "bvjjmzcq.dll",,Run
    O4 - HKLM\..\Run: [MChk] C:\WINDOWS\system32\enrcspco.exe
    O4 - HKCU\..\Run: [{CAA86409-E226-7F03-E4EE-838CBA2FE44C}] "C:\Documents and Settings\Josh\Application Data\Pedop\alhi.exe"
    O4 - HKCU\..\Run: [{5AE054D5-819B-5DD2-94EE-C22185FE22B7}] "C:\Documents and Settings\Josh\Application Data\Poubhy\gyhy.exe"
    O4 - HKUS\S-1-5-21-515967899-261903793-725345543-1006\..\Run: [notepad] rundll32.exe C:\DOCUME~1\louise\ntload.dll,_NtLoad@0 (User 'louise')
    O23 - Service: AVG8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
    O23 - Service: AVG8 Firewall (avgfws8) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgfws8.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. Stannies

    Stannies Private E-2

    Not been able to try your last set of instructions yet, I cannot get the thing to boot - not even in safe mode.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why? What happened between now and your previous posts? What exactly happens when you try to boot up? How far do you get?

    Have you tried Last Known Good Configuration?
     
  8. Stannies

    Stannies Private E-2

    Sorry, my son in his infinite wisdom - or lack of listening decided to carry on using his pc as if it was fixed. When I went back to it with my list of tasks it would not boot in any mode - including last known config. I created a boot disc which got me part way in and then tried using the windows xp repair disc. This just reinstalled windows again but SP1. This has enabled me to back up docs (school homework) and photos to cd's. I have to say I have now sent it away to my daughters boyfriend to clean up. Hopefully he will sort it or format it and reinstall his software etc. Thank you for all your help it was much appreciated. I may be back if my future son in law does not manage but I will create a new post.
    A shame really I was rather enjoying the challenge and learning new stuff.
    Thanks again.
    Mrs Stannie.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good luck.

    Only for malware issues in this forum. If you still have bootup or installation issues, you will have to post those in the Software Forum. ;)

    You should also check out the below as an FYI:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds