"Fast Browser Search" spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by ragexzero, Oct 31, 2009.

  1. ragexzero

    ragexzero Private E-2

    Hello,

    My sister recently got a stupid Facebook app called "My Tatoons" or something along those lines, and it automatically installed a toolbar in Firefox and IE, called "Fast Browser Search". I cant seem to get rid of it.

    I did the "Read and Run Me First" and its still there. Spybot S&D detects it, and it says its removing it, but then its still there.

    Here are my logs, just in case theres something there that can help. RootRepeal froze and then when I tried to run it again it gave me some errors so I skipped it.

    There IS an entry to remove the program on the "Add/Remove programs" in control panel, but it doesnt work either.

    MBAM and SAS, say Im clean, but I cant get rid of this thing. Ive tried some workarounds I found online with no luck.

    Thanks for any help.
     

    Attached Files:

  2. ragexzero

    ragexzero Private E-2

    SAS log attached here.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are 7 months out of date with your version of MGtools. You must ALWAYS download and use the current version to avoid being out of date.

    Did you simply try going to Add/Remove Programs and uninstall it? Fast Browser Search (My Tattoons)

    Also delete this file from it after uninstalling: c:\users\Public\MyWebTattoo.exe
     
    Last edited: Nov 2, 2009
  4. ragexzero

    ragexzero Private E-2

    Am I? wow, thats weird cuz I made a point of loggin on here before making my post to get the latest versions of both ComboFix and MGTools. I already had the old version on my hard drive and when I re-downloaded the new one, it asked me if I wanted to replace the old one. Of course I said yes, and moved on to the scanning later on. I must have messed up somehow. Ill try downloading again and running it once more. Thanks for the heads up.

    Yes, I did try the Add/Remove programs method of removing, but clicking on "Uninstall program" doesnt do anything and the program remains. A lot of people are able to remove it from their Firefox add-ons menu, but I dont even see it listed in there.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed that you said that Add/Remove Programs did not work. Try using the below and see if it helps.

    Your Uninstaller! 2009
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the Your Uninstaller does not help, try the below.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 15

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\temp
    C:\Users\pcromero\AppData\Local\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. ragexzero

    ragexzero Private E-2

    I ran into a bunch of problems doing what you told me.

    1. I ran Your Unistaller, and it said the program was uninstalled successfully, but no dice. It still there. It did take the programs entry away from the Add/Remove list tho.

    2. Then I could only find one of the three lines in HijackThis. The first and third one, were not there.

    3. ComboFix said "This application has requested the Runtime be terminated in an unusual way". And a Windows message popped up and said some application had failed and it was trying to find a fix. I hit cancel.
    Then ComboFix finished the run and I got the log.

    4. I went into the temp folders, and on one of them, there was just one file, with the current date, so couldnt delete it. On the other folder, there were more files and one subfolder. All with the current date. One file was from october tho, and I tried deleting it, and still didnt let me.

    5. After ComboFix rebooted, I noticed an extra icon on my system tray. Its a computer screen with two lil people. It wasnt there before I ran ComboFix. And I also got a notice from ZoneAlarm that "ipconfig" was trying to access the internet. I hit "Deny", as it seemed fishy.
    This icon doesnt do anything when I right click it, hover the mouse over it, double click it, etc. And also, I should mention that my AVG icon, is not working properly anymore. I right click on it to Open the AVG interface, and it doesnt respond. The other menu items do work (Exit and Update).

    Logs attached. Thanks for any help. I hope I didnt mess things up more than they were!

    EDIT: I thought I should also add that before I run ComboFix, I deactivate the AVG Resident Shield, but ComboFix still says AVG is active. I dont know how else to deactivate it. And I also dont know how to deactivate Windows Defender.

    I also re-started the computer and the lil systray icon is gone and AVG tray icon is working again. Pheew. What was that tho? weird.
     

    Attached Files:

    Last edited: Nov 3, 2009
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your log, you did not shutdown ZoneAlarm nor did you get AVG properly shutdown (which you also noted) before running the fix. This is necessary as stated. They will get in the way of the fix. (Sometimes this will work: http://www.avg.com/us-en/faq.num-1209 ) But sometimes, it is even necessary to uninstall AVG since it can be quite problematic. Let's try a new fix.

    Not fishy at all. Since you did not shutdown protection, ComboFix could not run properly and was trying to repair your network connection that is disabled while ComboFix is running.
    Logs attached. Thanks for any help. I hope I didnt mess things up more than they were!

    Click Start, Run, and copy and paste the below into the Run box and click OK.

    notepad c:\users\pcromero\AppData\Roaming\Mozilla\Firefox\Profiles\h0nriuj8.default\prefs.js

    This should bring up your preferences file for FireFox in a notepad window. Look for lines containing the below information and delete the whole line where it appears.

    browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=4&q=
    keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=4&tid={28B3A99A-A2A3-3DE5-6286-AADDFBBDBB4E}&q=

    After deleting those lines, click File, and select Save. If you cannot save the file, close all browsers first before saving.

    Now locate the below file and delete it.
    c:\users\Public\MyWebTattoo.exe

    Now close ALL browsers and then reopen one and see how things are working.
     
  9. ragexzero

    ragexzero Private E-2

    Still no dice. Do you think if I go through the trouble of uninstalling AVG so that ComboFix can run properly, this thing will finally disappear? cuz if its gonna stay regardless, Id rather not run my computer without antivirus even for a short time.

    I cant believe these people make malware like this and they make it so hard to get rid of. They even provide a phone number for you to call if you want help removing it, but Im sure that will open up a whole new bunch of problems, with my phone number being sold to telemarketers and other crap like that. So no way Im calling.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Did you find the lines in the pref.js file that I asked you to delete? The config settings in FireFox should allow you to edit and remove these. Type about:config in the address bar in Firefox. In the filter, type fast. This should show the instances of where Fast Browser Search appears. Also you should try filtering on fbs . Right click on each of the Fast Browser Search entries and select reset. This should put most of them back to google. Also you should look under Add-Ons and remove any related to FBS. Also click the down button next to Search and select Manage Search Engines and remove any related to FBS.
    • Did you find the file I asked you to delete and did it delete?
    • Do you see any or the below files/folders?
    C:\Program Files\Fast Browser Search\IE\basis.xml
    C:\Program Files\Fast Browser Search\IE\fbsSearchProvider.xml
    C:\Program Files\Search Guard Plus\fbsSearchProvider.xml
    C:\Program Files\Search Guard PlusU\Tmp
    C:\Program Files\FBrowser
    C:\Program Files\FBSeach Toolbar
    C:\Program Files\SGPSA
    c:\users\Public\MyWebTattoo.exe


    Perhaps but since this is hooked into FireFox, it may just be easier to uninstall FireFox, reboot (don't skip), then delete the FireFox folders. Then download and install it again ( Mozilla FireFox )


    Does any of the above help?
     
  11. ragexzero

    ragexzero Private E-2

    -I did find the .js files you mentioned and did delete them. I also DID find "MyWebTattoo.exe" and successfully deleted it. Still no luck.

    -No, I dont see any of the mentioned folders.

    -I tried the mentioned fix for Firefox, where you go into the config and delete all Fast Browser Search related items (or reset them in this case), but it still didnt work. I found that fix online but still nothing.

    -What if I uninstall both Firefox and Explorer and when I re-install I still get this piece of crap? How can I make sure its gone before re-installing? I dont know if I mentioned that this malware affects both IE and FF.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My last message suggested uninstalling FireFox.


    First try deleting the below two files. Make sure FireFox is closed when you delete these:

    C:\Program Files\Mozilla Firefox\searchplugins\fast.png
    C:\Program Files\Mozilla Firefox\searchplugins\fast.xml

    Then open FireFox. If you still have a problem. Don't say things like "no dice". Please describe the exact problem.
     
  13. ragexzero

    ragexzero Private E-2

    First of all, thanks for all the help. I appreciate it. I am lost as to what to do with this thing.

    -I was aware you suggested uninstalling FF, but I was asking: what if I DO uninstall it, and then when I re-install, I still get this thing? How should I go about it to ensure that doesnt happen?

    -Also, this malware is stuck to IE as well, so I guess Id have to uninstall that too right?

    Sorry about being vague with my "no dice" comment. I thought by saying that, it was clear that I had tried what your last post suggested, with no luck. Ill know better next time.

    -I deleted: C:\Program Files\Mozilla Firefox\searchplugins\fast.png
    C:\Program Files\Mozilla Firefox\searchplugins\fast.xml

    But the problem remains. Toolbar from hell is still active and plaguing my browsers.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will not know until you try it. If it is an addon to the browser, it should be gone after the reinstall as long as you don't install anything but FireFox.

    Possibly or at least start checking thru the list of Addons and Toolbars and disabling them to see what happens.
     
  15. ragexzero

    ragexzero Private E-2

    Ok, just got done uninstalling then re-installing Firefox (I did re-boot after uninstalling) and the toolbar is still there. I wouldnt care if it didnt redirect me to its own website when I open new tabs. If it could be just hidden and forgotten about, I wouldnt care.

    I also read online that the toolbar connects with some website and self-updates. Thats malware behavior if Ive ever seen it, isnt it?

    I really need to get rid of it but I dont know what to do anymore!

    In both Firefox AND Explorer, disabling the toolbar and deleting it from the Add-ons/Toolbars/Search Engines menu, doesnt do anything. Help!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is this WebMate program you have installed? It appears to have something to due with browsing. Perhaps you should uninstal it for now. You can always reinstall it later if it is not part of the problem.

    FYI to disable Windows Defender: Disabling & Enabling Windows Defender in Vista




    Please do ALL of the below exactly as written and do it in the order written ( no exceptions ).
    • Downloaded and save the current version of ComboFix.exe to your Desktop but do not run it. Get it here: combofix.exe
    • Download and save the current version of Mozilla FireFox to your Desktop but do not run this yet.
    • Uninstall AVG to make sure that it is not getting in our way of removal by interferring with ComboFix.
    • Uninstall your current copy of FireFox. Use Internet Explore for now.
    • Complete the below procedure with ComboFix:
    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.




    After reboot, use Internet Explorer to download Registry Search (see the link titled RegSearch Download Link )
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independen) and click Ok... option, enter the below string (use copy and past)
      • 8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then immediately attach the below logs before doing anything else:
    • C:\ComboFix.txt
    • RegSearch.txt
    • C:\MGlogs.zip

    Now print the below instructions or save locally so that you do not have to open up IE or FireFox until FireFox is install and runs itself. After printing or saving locally in a text file continue.
    • Now install the new version of FireFox. Do not add and addons or special tools to it just install FireFox.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • Now use FireFox to attach the new C:\MGlogs.zip file
    • Is the toolbar still present in FireFox?
    Reinstall your AVG protection now so that you are not surfing unprotected.
     
  17. ragexzero

    ragexzero Private E-2

    Before I go ahead with the latest instructions, I wanted to ask: does it matter that I dont have a "Program Files" directory in C:? My Windows version is in Spanish and I have "Archivos de Programa" instead, two versions of it actually.

    Just wondering. Maybe that has something to do with why ComboFix hasnt been able to get rid of this thing? I dunno.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true. You do have a Program File directory. It shows in all of your logs and even a few messages back I asked you delete a couple of files in it and you said
    So how could you have deleted these files if the Program Files folder did not exist?
     
  19. ragexzero

    ragexzero Private E-2

    I had to double check this to be sure, but I really dont see any "Program Files" directory in Windows Explorer. I see TWO "Archivos de Programa" directories, one has only a few folders that say Windows Update and other things, and the other has all the installed programs' folders in it.

    Thats where I deleted the files you told me to delete from. I have hidden files showing so I dunno why I cant see it and you can on the logs. Do you think it might have anything to do with Windows UAC? I re-enabled it after the last clean-up attempt cuz this computer is used by my family and I always feel safer with UAC on. (I'll know to disable it before any further clean-up attempts of course).

    Do you think it has to do with me not having enough permissions to see it? cuz sometimes when I try to download something to C:, it says I dont have enough permissions to save the file there. It happened when I tried to DL MGTools directly to C:. I had to choose another location and then move MGTools to C:.

    Edit: I should mention that I DO have a "ProgramData" folder that I can see in Windows Explorer.
     
    Last edited: Nov 14, 2009
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Must be something to do with automatic language translation because if you look at the logs you are posting for us you will see that is shows things like below and show C:\Program Files which is even where it shows FireFox, iTunes,....etc running from. This is just a small snapshot from the HijackThis log:
    Run my previous fix anyway. It will not hurt anything if it cannot find the files it would just fail to find them. Let's see what happens.

    NOTE: It is okay if you reneable UAC inbetween fixes but you must remember that each time before running any fix you will have to disable it and then you MUST reboot for it to take effect. And then you can run the fix. You cannot run the fix if UAC has not been disabled and you have not rebooted.
     
  21. ragexzero

    ragexzero Private E-2

    OK, here are the requested logs. Will let you know what happened after I re-install FF as per your instructions.
     

    Attached Files:

  22. ragexzero

    ragexzero Private E-2

    Im sad to inform that after all we did, the toolbar lives still in FireFox. Its gone from IE apparently but not from FF.

    Im gonna go re-install AVG now and consider myself defeated by this thing. I dont use this computer much anyway, but I still like to keep it clean, so this blows.

    Anything else you can think of that might help? Short of calling the stupid number they provide and screaming at them so they TELL me how to remove this?
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay perhaps the problem really is that the logs are displaying the English folder name of C:\Program Files and possibly also various registry keys in English terms but when we run the fixes, the programs are not really able to find the associated items. Based on your logs, I could see things that should haven been deleted that are still there. So let's try the fix using the Spanish names and see if that changes anything. Let's run a similar fix to last time with these changes.

    Remember to disable all protection first.



    Please do ALL of the below exactly as written and do it in the order written ( no exceptions ).
    • Downloaded and save the current version of ComboFix.exe to your Desktop but do not run it. Get it here: combofix.exe
    • Download and save the current version of Mozilla FireFox to your Desktop but do not run this yet.
    • Uninstall AVG to make sure that it is not getting in our way of removal by interferring with ComboFix.
    • Uninstall your current copy of FireFox. Use Internet Explore for now.
    • Complete the below procedure with ComboFix:
    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).




    Then immediately attach the below logs before doing anything else:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Now print the below instructions or save locally so that you do not have to open up IE or FireFox until FireFox is install and runs itself. After printing or saving locally in a text file continue.
    • Now install the new version of FireFox. Do not add and addons or special tools to it just install FireFox.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • Now use FireFox to attach the new C:\MGlogs.zip file
    • Is the toolbar still present in FireFox?
    Reinstall your AVG protection now so that you are not surfing unprotected.
     
  24. ragexzero

    ragexzero Private E-2

    Tried to follow the above steps to completion but couldnt. ComboFix just sits there in the window that says "the scan will take about 10 minutes, or double for badly infected machines" for over thirty minutes. The meter on the CPU use widget is on zero, so I know the program is not scanning or doing anything. I just closed it after two attempts with the same results.

    Do you think it might have something to do with the fact that I have TWO "Archivos de Programa" folders in C:? I dunno, just throwing that out there.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is all protection software shutdown? Windows Defender too?

    It's impossible to have two folders with the same name in the same location. Are you sure that you are seeing exactly the same names on the folders? Is one a file and one a folder. Does one have different spaces between the letters?
     
    Last edited: Nov 21, 2009
  26. ragexzero

    ragexzero Private E-2

    I have two folders that look like they have exactly the same name. One folder's name can be edited, and the other cant, so Im not sure what the difference is between the names.

    Im gonna attach a screenshot so you can check it out. One of the folders has some weird uninstall info and windows stuff, and the other has all the program folders.

    Yes, I disabled Windows Defender with your instructions and never re-enabled it after the previous fix actually.

    ZoneAlarm is still installed but shut down when I run ComboFix. I thought it wasnt a problem since you didnt tell me to uninstall that. Its only an internet firewall tho, not a full one (free version). Should I uninstall that too?
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure how this is happening. One folder must have hidden characters in it or it belongs to the system and there is a junction on it giving what appears to be a dfferent name as far as the file system would be concerned.


    Download and save the below to your PC and save it to the C:\MGtools folder! Then right click on it and select Run As Administratort.

    FLook.bat

    It should take a only a few seconds to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\MGtools\Dlog.zip file that is created. Then continue on to the below.



    Please do ALL of the below exactly as written and do it in the order written ( no exceptions ).
    • Download and save the current version of Mozilla FireFox to your Desktop but do not run this yet.
    • Uninstall your current copy of FireFox. Use Internet Explore for now. Do not reinstall FireFox until I ask you to do so.
    • Complete the below procedure with Avenger:
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Sean Walsh\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • make sure you have atttached the C:\MGtools\Dlog.zip file
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 21, 2009
  28. ragexzero

    ragexzero Private E-2

    OK, heres the rundown:

    -Flook.bat ran fine. Took a split second, produced log. Its attached.

    -Avenger gave me a syntax error and then it seemed to be stuck on a loop. But as I was writing about it here, trying it over and over again, it finally worked and rebooted. Produced log. Its attached here. Youll see all the aborts and problems in the log most likely.

    -Mozilla Firefox folder was still there after reboot, I deleted it. Deleted temp files too, but couldnt delete:

    C:\Documents and Settings\Sean Walsh\Local Settings\Temp

    because Windows said I dont have access to the Docs and Settings folder.

    -These files:

    C:\Archivos de Programa\Fast Browser Search
    C:\Archivos de Programa\Search Guard Plus
    C:\Archivos de Programa\Search Guard PlusU
    C:\Archivos de Programa\FBrowser
    C:\Archivos de Programa\FBSeach Toolbar
    C:\Archivos de Programa\SGPSA

    Were never on the computer even before running this fix. Or at least I never could see them. Still dont. So I couldnt delete them obviously. If you see them on the logs, then somethins weird with that.

    -MGTools ran fine. Logs attached.

    Still havent re-installed FF, just cuz you didnt mention I should do it on your post and cuz the fix didnt seem to run that smoothly.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were not suppose to delete this folder or the other one in Windows. I only asked you to delete what is in these temp folders.

    Based on your logs which is a direct output from the Windows Dir command ( Dir stands or Directory ), you have both of the below folders:
    Code:
     Directorio de C:\
    10/10/2008  20:06    <DIR>          archivos de programa
    17/11/2009  09:13    <DIR>          program files
    So thus you actually do have a Program Files folder. And you need to look in it too to make sure that any Mozilla Firefox folder has been deleted before reinstalling FireFox. Search your PC for FireFox and delete anything related to it except the installer program you downloaded to install the new version of FireFox.

    I assume right now with FireFox being uninstalled that all is good?

    After cleaning up any remaining files and folders for FireFox, disconnect your cable to the internet and then reinstall FireFox and only FireFox. See if the toolbar appear right now and choose the appropriate below
    • If the toolbar does appear, get a new log from MGtools and then reattach your cable to come here and post your log.
    • If the toolbar does not appear, reconnect your cable to the internet and see if the toolbar comes back after connecting. Also open and close FireFox to see if it only comes back after FireFox is restarted.
     
  30. ragexzero

    ragexzero Private E-2

    I know you see it in the logs, but I cant see the "Program Files" folder in Windows Explorer at all. Why do you think this is? Do you think Windows just "renames" the folder into Spanish because thats the language I chose for the computer? (When I got the computer, Vista had everything in English, but I had to go into the settings to change it into Spanish).

    I dont know. In any case, how can I get access to this seemingly hidden "Program Files" folder, since I dont even see it? (hidden files are set to show already).

    But yeah, Internet Explorer seems to be rid of the damn toolbar, and thats all Im using on that computer for the moment. (I would just use IE from now on but I need Firefox installed, to display certain websites that wont work well in IE)
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! If you open a command prompt and run a dir command on the root folder you will see what I see.

    Try installing this ExplorerXP and see what it shows you.

    You really don't need to manually search anyway. You could just do a file search to try and locate remnants of FireFox or Mozilla.
     
  32. ragexzero

    ragexzero Private E-2

    I did a file search and so far the count for Mozilla related folders/files is 736!

    Theres a lot of things, between folders within iTunes, cookies, "browser" files, etc, and I dont feel that comfortable deleting all these. What should I do?

    I couldnt install ExplorerXP cuz the requirements in the download page listed only XP and 2000 as the supported versions for the program.

    (Results for the search grew to 936 items just while I typed this post! and still growing).
     
  33. ragexzero

    ragexzero Private E-2

    OMG! Its gone! I decided to re-install FF just for the hell of it. I was gonna try the "about:config" fix again, and now the toolbar is gone! How could this happen? I didnt think the last fix was that successful! I guess Avenger must have done the trick after all, or ANY of the other things you had me do the last time.

    I didnt even delete the Mozilla related files and its still gone! wow.

    Im gonna re-start the computer and check if its still gone after that. I dont want to claim victory just yet. Ill let you know what happened.

    EDIT: It IS in fact gone! Im posting this from FF. Thanks! (I forgot theres such a thing as the "Thanks" button on each post. Sorry, I would have thanked you for each post before).
     
    Last edited: Nov 25, 2009
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Excellent.


    It will work which is why I asked you to try it. ;) I have used it with Vista. Not necessary any more unless you just wish to play with it.:)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds