Extra or wrong Firefox windows opening (1 of 2)

Discussion in 'Malware Help (A Specialist Will Reply)' started by treeppl, Nov 21, 2009.

  1. treeppl

    treeppl Private E-2

    Firefox has recently started opening extra tabs or going to incorrect sites after clicking on Google search results.

    I've run AVG and it's found Cryptor a couple of times and says it has removed it, but each time I run it again, it finds it again.

    I uninstalled AVG and ran through all your malware steps and have attached log files to this and a second thread.

    Thanks for any help!
     

    Attached Files:

  2. treeppl

    treeppl Private E-2

    Extra or wrong Firefox windows opening (2 of 2)

    Attaching MG tools log to this thread.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your ComboFix long is totally incomplete. Did you have any problems trying to run it? Your logs are basically clean. We just have a little minor work to do.

    Did you knowingly install Ask Toolbar? If not, uninstall it now.



    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. treeppl

    treeppl Private E-2

    I may have had problems running ComboFix. I remember at the time that I never saw the "Almost done...This window, etc." window, and maybe not the one before that - "Preparing log report...", but I wasn't sure if I should rerun or not.

    No, I didn't mean to install the Ask Toolbar. Thanks for catching that.

    Other steps followed and MGlogs.zip attached.

    We'll see how things are working, keeping an eye out for pop-ups...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. We will need to see a ComboFix log if you are still having problems. Shutdown all protection before running ComboFix and if necessary, even try running ComboFix in safe mode. You do not appear to be having malware problems based on only the logs provided.
     
  6. treeppl

    treeppl Private E-2

    I have tried running ComboFix twice today. Both times I got the following messages -

    32788R22FWJFW\iexplore.exe
    Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.

    I got that message for the iexploer.exe file, hidec.exe, n.pif, and hircmd.cfxxe.

    I am logged on as an administrator.

    I ran COMODO in between the two attempts to run ComboFix. It found several items that I quarantined. I can send that log if it will help.

    Also tried starting the computer up in all three versions of safe mode, regular,
    with networking and with command prompt, and none of those would work. It just continues and boots to regular mode.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was AVG still installed? Was it enabled or disabled?

    You ran Comodo what? I did not ask you to run anything else. Are you talking about their antivirus? If so, first you should not be doing anything but what we ask you to do. Comodo may only be finding things we have already removed that are in quarantines or System Restore. Or it could just be finding the tools we use to be problems when they are not. Without a log showing exactly what was found, I cannot say for sure.

    What actual malware problems are you still having? The fact that ComboFix will not run is not necessarily malware. Especially since your other logs were clean. Also inability to boot in safe mode is most frequently a problem with Windows itself.
     
  8. treeppl

    treeppl Private E-2

    AVG is uninstalled.

    Comodo antivirus.
    My bad.

    Still being redirected from websites. Click on a link and end up at another site. Extra tabs popping up in Firefox.

    But that's all moot right now. The computer has started just looping through the boot sequence. It gets to the Windows logo with the "Cylon/Kit (the car)" progress bar, stays on that for a few seconds then the screen goes black and starts the boot seq. again. I sure don't know enough about malware and it's relatives to know if it's causing this problem, maybe I've got two problems?

    I do appreciate your help and will definitely avoid any "unauthorized" scans from here on out. IF there's anything else I can do.

    Thanks again.

    Jeff.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you done anything else at all on your own. Nothing that we have done would cause this as we have not even located or remove any real malware yet. Do you remember exactly what you removed with Comodo???

    This is pointing towards issues within Windows itself and perhaps this is even the reason for the problems trying to run ComboFix.

    If you cannot bootup, we cannot continue to do malware cleanup. Have you tried booting in safe mode? How about last known good configuration? If those do not work, you will need to try what is in the below to try and restore registry hive that could fix this boot issue:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds