IE funmoods removal, mozilla crashing with adobe flash

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mum25, Jul 13, 2012.

  1. mum25

    mum25 Private E-2

    I have 2 problems, not sure if they are related.
    Constantly had trouble with IE so swapped to Mozilla ~18 months ago.
    Recently have had trouble with moz just shutting down. Most recently trying to upload a photobook and the website used adobe flash, needed to update adobe FP and moz won't let me, continual shutdown.

    gave up on moz and went back to IE, could update Adobe FP and was able to upload photobook finally.
    BUT...
    IE has funmoods which insists on opening a new window for every page, extremely slow to load anything, very slow to start up.
    Have tried to remove - control panel> but not there?
    Have run malware bytes (even uninstalled and reinstalled from different computer, found nothing - open IE, funmoods still there.
    have done please read and google redirect probs, nothing showing????

    Please help, nothing else to try :cry

    Sharon
     

    Attached Files:

  2. mum25

    mum25 Private E-2

    the hitman log wouldn't attach? copied from log;

    Log computer="WINXPSP3" scan="Normal" version="3.6.0.160" date="2012-07-10T21:21:21" timeSpentInSecs="379" filesProcessed="16916">
    - <Item type="Malware" malwareName="Trojan" score="116.0" status="None">
    - <Scanners>
    <Scanner id="DrWeb" name="Trojan.MulDrop3.58135" />
    </Scanners>
    <File path="C:\Documents and Settings\Main\Desktop\MGtools.exe" hash="BF0F6DDB1927531A37FD2B971B580F5979516A76A9B4ED39E5AB2349CB5425F4" />
    </Item>
    - <Item type="Suspicious" score="107.0" status="None">
    <File path="C:\Program Files\bfgclient\bfgcommon.dll" hash="C5AE4CB3E9D58CEB02E39E3202BECA254C52DAA4C714683D7F0D8530B1803A23" />
    </Item>
    - <Item type="Suspicious" score="107.0" status="None">
    <File path="C:\Program Files\bfgclient\bfggameservices.exe" hash="94D299E53D62961CC2E6B984B37BF67BB0C1AD5E9354A46B05E7733FB0330049" />
    </Item>
    - <Item type="Suspicious" score="101.0" status="None">
    <File path="C:\Program Files\bfgclient\bfgprocess.exe" hash="E2DA148C148B6EDBF2607956B429F0FC63DF17C6D44524BC3C1D4D96F2BC52C0" />
    - <References>
    <Key path="HKU\S-1-5-21-1220945662-1202660629-682003330-1005\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program Files\bfgclient\bfgprocess.exe" />
    </References>
    </Item>
    - <Item type="Malware" malwareName="Trojan" score="107.0" status="None">
    - <Scanners>
    <Scanner id="DrWeb" name="Trojan.DownLoader6.10733" />
    </Scanners>
    <File path="D:\My Documents\Downloads\Fifty_Shades_of_Grey(2).exe" hash="97D3B3D79262D724CE7A348B5EDE7D1CE1C6F5281825661665211696CAD12D14" />
    - <References>
    <File path="C:\Documents and Settings\Main\Desktop\Download\Download Fifty_Shades_of_Grey.lnk" />
    </References>
    </Item>
    </Log>
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Java(TM) SE Runtime Environment 6 Update 1 <--- uninstall this.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running?
     
  4. mum25

    mum25 Private E-2

    Firstly thank you so much for your quick reply!

    MSConfig - done
    Java(TM) SE Runtime Environment 6 Update 1 <--- uninstall this - done

    My computer restarted and when it did so I had a ballon in the bottom L) hand side corner appear saying "new hardware"???

    I am accessing majorgeeks on IE, so opened IE funmoods still there :( but when I click on bookmarks> majorgeeks a second window doesn't open now, and I go to the saved page. So better.

    fixME.reg - done successfully
    C:\MGtools\GetLogs.bat - done, not sure where the log went? but have found, copied and pasted 'filelog.txt' below:

    ******************************************************************************
    MGtools installation folder and files at Start of Scans
    ******************************************************************************
    Volume in drive C has no label.
    Volume Serial Number is 78C2-1DE0

    Directory of C:\MGtools

    07/13/2012 11:37 PM <DIR> .
    07/13/2012 11:37 PM <DIR> ..
    07/13/2012 11:37 PM 228 filelog.txt
    07/13/2012 11:37 PM <DIR> temp
    1 File(s) 228 bytes
    3 Dir(s) 109,056,851,968 bytes free
    ******************************************************************************

    ******************************************************************************
    * File Versions Used: *
    * GetLogs.Bat - 07/05/2012 Version 2.46 *
    * 32 bit Windows OS found *
    ******************************************************************************


    ******************************************************************************
    MGtools installation folder and files at End of Scans
    ******************************************************************************
    Volume in drive C has no label.
    Volume Serial Number is 78C2-1DE0

    Directory of C:\MGTools

    07/13/2012 11:37 PM <DIR> .
    07/13/2012 11:37 PM <DIR> ..
    07/13/2012 11:37 PM 1,336 filelog.txt
    07/13/2012 11:37 PM 6,876 sysinfo.txt
    07/13/2012 11:37 PM <DIR> temp
    2 File(s) 8,212 bytes
    3 Dir(s) 109,056,393,216 bytes free
    Volume in drive C has no label.
    Volume Serial Number is 78C2-1DE0

    Directory of C:\

    ******************************************************************************
    End scan time
    Fri 07/13/2012 at 23:37:22.18


    When it restarted, VERY slow to start and still quite a delay from clicking IE to when it finally opens.
    Have to go now, will check in again tomorrow and let you know how it's running.

    haven't tried Mozilla yet.

    Cheers,
    Sharon
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. Copying and pasting isn't for the best. You should run C:\MGTools.exe again and attach the new MGlogs.zip. :)
     
  6. mum25

    mum25 Private E-2

    Hi Kestrel

    I tried MGtools again and it ran and created a log so I must have done something wrong the second time last night.

    Please find it attached.

    after closing down last night and restarting this morning, I still have funmoods on IE, and so far have been able to stay on Mozilla.

    Cheers,
    Sharon
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=nv1
    • O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (file missing)
    • O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (file missing)

    After clicking Fix exit HJT.



    Delete these folders.
    • C:\Documents and Settings\Main\Application Data\Babylon
    • C:\Documents and Settings\Main\Local Settings\Application Data\Babylon
    • C:\Documents and Settings\All Users\Application Data\Babylon


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    How are things running now?
     
  8. mum25

    mum25 Private E-2

    I got the success message!

    Thank you is too small a word - well 2 words!:-D:-D:-D:-D:-D:-D:-D:-D

    funmoods is gone and IE is running correctly, I went to the adobe site and i think they have changed the way mozilla installs flash as it was different this time and worked.

    Thank you SSSSSOOOOOO much, it seems to be all fixed .

    Your help is very much appreciated and was very easy to follow - even for a novice like me.

    Thanks again,

    Sharon :wave
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. Safe surfing! ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds