IE taken over by morwellsearch.com...plz help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by iLLestOne, Oct 17, 2005.

  1. iLLestOne

    iLLestOne Private E-2

    This is on my gf's laptop. I'm in santa barbara, and she's in the Bay Area.

    I've had her run (in and not in safe mode) Ad-aware, spybot, ewido security, xoftspy (found stuff, but can't delete it cause i dont want to buy it) cwshredder, Stinger, CCleaner and nothing fixed it.

    PLEASE help!!! She says it now opens other search pages (about.com, zip.com, etc...)

    I've done everything your help file says before posting, so here is her hijackthis log.

    I followed this completely
    http://forums.majorgeeks.com/showthread.php?t=35407

    Any help would be GREATFULLY appreciated, and I thank you in advance.

    EDIT: I will only going home this weekend (10/19 - 10/22) and REALLY need help before then so I can fix this for her. She knows nothing of computers, so I really need this information before I go down please.

    I have hijackthis log and ewido logs if needed.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have followed the procedures in here: Downloading, Installing, and Running HijackThis

    And then post the HJT log. Also attach the Ewido log. I would uninstall Xoftspy as it is of no use unless you buy it. Thus it is just a waste of resource that other tools (that actually can fix problems) can use.
     
  3. iLLestOne

    iLLestOne Private E-2

    Here they are
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please EXTRACT HijackThis from the ZIP File to a Safer location. Here's how:

    To create a new folder:
    Click START > My Computer > Local Disc C: > Program Files
    Now, Right Click on an Empty Area and select New > Folder & name it HijackThis and ENTER

    To Extract HijackThis:
    Now, Right Click your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder
    (C:\Program Files\HJT) and click Next.

    Now run HJT from there. Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    The reason HJT needs its own safe folder is so that backups will be safely preserved. That way, if a mistake is made in the removal process, the mistakenly deleted entry can be restored.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's all in the link I gave already: Downloading, Installing, and Running HijackThis

    But the bigger problem is the fact that ALL the steps in the sticky thread were not run! Please run ALL steps in the sticky thread.

    You should also run: Symantec Trojan.Vundo Removal Tool 1.3.1
     
  6. iLLestOne

    iLLestOne Private E-2

    Sorry, I had her make the hijackthis.log a couple days ago. I did however follow every step on the sticky thread, except the one about hijackthis. That was the last step (after around 3 hours) and she was getting very annoyed, so I just told her to run it and send it to me on aim.

    I have a midterm tomorrow so I won't be able to get her to do those steps (she's not computer savvy) until tomorrow.

    Sorry again about not fully following the sticky. I have to do all this over the phone while trying to tell a person who doesn't know much about computers what to do.

    Thanks again for the quick responses and I will post a new hijackthis.log as soon as I can. I will also send her the "Symantec Trojan.Vundo Removal Tool 1.3.1".

    Thanks again
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log shows not signs of any of the online scanners being run (step 5 in the sticky). This is why I said the sticky was not completed. Try to run at least two.

    Make sure you get HJT installed correctly too. You do have signs of a Vundo problem. Perhaps the Symantec tool will fix them. But there are other items we must fix. All of the below need to be fixed:


    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\java\trustlib\bakw.dll (file missing)
    O2 - BHO: Bho - {EFDAC3FE-F44A-4030-8589-1E23BC6573D5} - C:\WINDOWS\system32\wgerfxfy.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O20 - Winlogon Notify: bakw - C:\WINDOWS\java\trustlib\bakw.dll (file missing)

    And the below file must be deleted (you may need to boot to safe mode to delete it):
    C:\WINDOWS\system32\wgerfxfy.dll

    Afterwards attach a new HJT log.
     
  8. iLLestOne

    iLLestOne Private E-2

    Alright, I had her delete all that stuff and she is running the online scanners now. I will post the new hijackthis log shortly.

    thanks
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I'll be around for just a few more minutes. (Need sleep! Been up 20 hrs! :eek: )
     
  10. iLLestOne

    iLLestOne Private E-2

    It's cool, you can go to bed. It's taking forever to run. She ran http://www.windowsecurity.com/trojanscan/ and she is now running "Bitdefender" and it is taking forever. She has a like 1 year old Hp laptop, so it is going slow :(

    I'll post back later tonite when it's done though. Thanks again for all the help.
     
  11. iLLestOne

    iLLestOne Private E-2

    Alright, here is the hijackthis log and a bitdefender log

    Thanks again for all the help, it is very appreciated
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The HJT log is clean now. Are you having anymore malware problems?
     
  13. iLLestOne

    iLLestOne Private E-2

    She said google works again now, and that her computer is running faster so I guess everything is fine now. Thanks again for the help! I tried everything I could to clean her comp and nothing worked, so thanks a lot for the help! She really appreciates it.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds