Help!! W32.Myzor virus/Safetytool homepage issues IE

Discussion in 'Malware Help (A Specialist Will Reply)' started by wiggedywack, Dec 3, 2006.

  1. wiggedywack

    wiggedywack Private E-2

    Hi,

    I seemed to have picked up some virus/spyware/malware problems... My home page on IE gets overridden with http://safetytool.com/ and a pop up alert informing me Warning that I have a w32.myzor.FK@yf virus. Initially I was also getting a new icon on the bottom right Windows toolbar, and a balloon warning that directed to a site... There was also a new toolbar for a while on IE.. the icon and balloon and toolbar have now disapeared..since following all the steps in your guide..
    The Panda scan still shows there is some spyware and other problems..

    I attach all the attachments as requested..(3 here 3 in next message)

    PLEASE help me to get rid of this problem.

    Thanks! I hope I've done everything.. please let me know if there is more information required.
     

    Attached Files:

  2. wiggedywack

    wiggedywack Private E-2

    further attachments..
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to re-run CounterSpy and this time have it fix what it finds. Last time you had it ignore everything. Attach a new log.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thesafetytool.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - (no file)
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxuk101KPGB

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot your PC

    Now attach a new HJT log
    Make sure you tell me how things are working now!
     
  4. wiggedywack

    wiggedywack Private E-2

    chaslang,

    Really greatful for your help. Thanks!
    I did all the stuff you told me. Starting with the CounterSpy Scan, and got it to delete everything it found.
    Uninstalled both J2SE bits of software.
    Ran HJT and fixed the lines suggested. The last one:
    O8 - Extra context menu item: &Search - edits.mywebsearch.com/toolbar...p=ZNxuk101KPGB
    Wasn't in the list - I assumed maybe the counterspy had changed that?!

    Then I did the Reset Web Settings.. accidently forgot to write a new URL for the home page.. which I think was why my NORTON protection was going crazy.. and possibly this activity is shown on the HJT Log I attached below. Once I added a URL it settled down..

    I also did the fixWLK.reg part and it worked. (I assume i can delete this from the desktop now?)
    And rebooted.

    Things seem to be pretty much back on track..I think. No more warnings etc..

    Is there anything else I should do? can you see any other problems?

    Also should i keep NORTON or is there an equally good/better etc free equivalent.. as I'm on a 3 month free trial, and to be honest it didn't stop these problems and I'm never quite sure if I should allow certain things to connect to iNet or not?? Any advice would be appreciated.

    ONCE AGAIN.. THANKS FOR ALL THE HELP!

    I attach the HJT file and new Counterspy File.
     
    Last edited by a moderator: Dec 4, 2006
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please reattach your logs. Somehow they got removed or they did not attach.
     
  6. wiggedywack

    wiggedywack Private E-2

    Hi,

    Sorry, not quite sure why they didn't attach. I definately didn't forget!

    Lets try again.

    Cheers.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall CounterSpy now since it is only a trial!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new HJT log!

    Now if you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. wiggedywack

    wiggedywack Private E-2

    ok. Think I did everything

    Attached another HJT file as requested. Did the fixme.reg thing and worked ok. and went back and toggled system restore stuff.
    deleted reg patches..

    greatful for feedback on the HJT log.

    Should I keep all the programmes.. HJT, ccleaner, NoAdaware, spybot s&D Adaware Personel SE... or can I get rid of any?!?

    Cheers will also change my NORTON to one of the free ones recommended. Thanks a lot
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Everything looks good.

    You can uninstall HijackThis and NoAdaware (which did not come from us anyway). Keep Ccleaner, Spybot, and Ad-Aware SE Personal installed and keep them updated. Run them weekly if possible an never less than once a month to help keep things clean.

    You're welcome! Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds