Hello and......... help!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by shaun_ryan, Nov 6, 2006.

  1. shaun_ryan

    shaun_ryan Private E-2

    Hey,

    am new here so thought I'd say "Hi!".

    I've recently been blessed with iewarning and so have been searching the WWW to find some guidance on exactly how to get rid of it - hence my discovery of this great place.

    I am on step 4 of "read & run me first" but have to amit that I am in over my depth. Any Vet's willing to offer some guidence or should I just knuckle down and start learning?

    Cheers

    Shaun
     
  2. Lev

    Lev MajorGeek

    Hey shaun..welcome to MGs. Which bit of Step 4 are you struggling with exactly, so someone can help you through the process :)

    I'll ask the Admins to transfer your post to the Malware Forum too, so you can get the expert assistance on to it.
     
  3. shaun_ryan

    shaun_ryan Private E-2

    Thanks!

    Step 4 itself isn't really an issue, i'm just getting paranoid as i have scanned the following steps and am concerned that i may make a mistake and perhaps damage my system.

    Is the removal of iewarning something that my local PC repair shop (as a generalisation) would be able to repair/sort out easily? I am asking because although you guys have provided what seems to be a v detailed guide i am sooo nervouse that i'd almost rather let a pro do it. This is my first laptop, it's brand new, has all my uni work on it and i'm a total novice so am a little aprehensive.

    Thanks again!
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Shaun, we can remove you problem with a little time and work. What's most important is the online scans in the READ ME. If you are afraid to run something then just run the online scanners and HijackThis. Once complete the those three logs and we will go from there.

    Good Luck!:)
     
  5. shaun_ryan

    shaun_ryan Private E-2

    Hey

    Ok here are the first of the logs (attached) please see the next post for the rest...

    Thanks

    Shaun
     

    Attached Files:

  6. shaun_ryan

    shaun_ryan Private E-2

    (please see above for more logs)

    i have reached step 7 of READ & RUN ME FIRST.

    I am attempting to remove iewarning and all other unwanted rubbish that may also be on my system that i don't know about.

    Many thanks

    Shaun
     

    Attached Files:

  7. shaun_ryan

    shaun_ryan Private E-2

    Does anyone know what i should do next?

    Thanks
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add/Remove Programs for the following and uninstall them if found:

    VidCodecs

    VirusBursters


    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/?ok
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/default.aspx?c=uk&l=en&s=gen
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default.aspx?c=uk&l=en&s=gen
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=6061011
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=6061011

    O2 - BHO: (no name) - {274c0420-ebe0-4f1d-b473-edd1aa9b85dd} - C:\Program Files\VidCodecs\isaddon.dll

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\Program Files\VirusBursters Delete this whole folder if it exist!

    C:\Program Files\VidCodecs Delete this whole folder if it exist!

    Next, run CCleaner to clean up cookies and temp files.

    After you complete the above, REBOOT and proceed with the rest of this fix...

    Reset Web Settings & Default Security Settings:

    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK


    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.

    After you complete this post, reboot once more and attach a fresh HJT log, also let me know how things are running.
     
  9. shaun_ryan

    shaun_ryan Private E-2

    First of all:

    Thank you soooooooo much bjarrick you have been very very helpful!

    I have completed the above steps and all seems well now, the browser now goes to the homepage that i set and theer is no sign of malfunction in any way.

    Please find attached the latest HJT log as requested for your inspection

    Many thanks

    Shaun
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your log looks good!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds