Newbie with a problem..

Discussion in 'Malware Help (A Specialist Will Reply)' started by Eamonn, Apr 8, 2006.

  1. Eamonn

    Eamonn Private E-2

    Hi all,

    My browser (IE) does not go to the desired page on entering a search. I tried Firefox and get the same issue. I've seen the hijack stuff that sticks a different homepage in and I've figured out how to deal with that, but this presents differently- after the search (google) is entered the google engine changes to a different one (MSN, etc.), but the new engine has the original search request.
    Thanks in advance of any info you might share.

    Eamonn
     
  2. Eamonn

    Eamonn Private E-2

    I've just noticed that new engine does not retain the original search. I cannot download any of the remedies found on this site, without a re-direct to an unrelated page.

    suggestions?
     
  3. Eamonn

    Eamonn Private E-2

    Hijackthis log

    I can't download any fresh versions of HiJackThis, but I found an exe on my drive and ran it. Here's the log:


    Edit by chaslang: Inline log attached. 1.99.0 version of HJT!

    Thanks. E
     

    Attached Files:

    Last edited by a moderator: Apr 8, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijackthis log

    Please do not start multiple threads. I assume this is related to the thread you already started. You must remain in one thread.

    Also, even though you are implying you cannot download anything, that does not mean you cannot read the instructions in the sticky threads. No logs should be posted inline. They must be attachments.

    I'm merging you back to your first thread. And I will look at your HJT log after I attach it.
     
  5. Eamonn

    Eamonn Private E-2

    Re: Hijackthis log

    Sorry, I tried to edit and add that the issue I'm looking at seems to hijack my browser to another website when I try to download anything that I could use to help myself. I cannot download anything current without the use of my browser. I've run the Norton virus stuff (that i can download, but it turns up nothing in both safe and normal modes. Tried disable too prior to doig n this stuff.

    Got your post. Thanks! Await your comments
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijackthis log

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    F2 - REG:system.ini: Shell=
    O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - C:\WINDOWS\system32\winbrume.dll
    O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hp5903.tmp (file missing)
    O2 - BHO: (no name) - {C8F21DFE-B35C-4274-82EC-1E072D09025E} - C:\WINDOWS\system32\winbrume.dll
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\winbrume.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. Eamonn

    Eamonn Private E-2

    Sorry I couldn't get back to you sooner. I had a flood in my basement..

    I can't download anything to help myself here. I can't get Ccleaner- my browser redirects to another site. It doen't matter if I use mozilla or IE- same result.

    Lol...How screwed am I?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already gave you steps to do in message # 6. Just run them. And if you do not have CCleaner, just empty the below manually:
    C:\windows\Temp <--- delete all files and folder in this Temp folder. A few from the current date will not be deleteable.
    Then click Start, Run, and enter %temp% and click OK! Now select all files in this folder that pops up. This folder will be something like:
    C:\DOCUME~1\username\LOCALS~1\Temp

    where username will be your actual user account name.

    Then empty the Prefetch folder as mentioned.
    Then empty your Recylce Bin.
     
  9. Eamonn

    Eamonn Private E-2

    Thanks, I've done as instructed.


    Edit by chaslang: Inline log attached!

    I did not see a file System32\winbrume.dll when I looked in safe mode- found all others.

    I managed to obtain Ccleaner after following your instructions. The browser now goes where I want it to. How does the log look now?

    Many thanks!
     

    Attached Files:

    Last edited by a moderator: Apr 10, 2006
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post logs inline! You must ATTACH them to your messages as the directions in the READ & RUN ME FIRST Before Asking for Support sticky thread indicate. Also you now need to try to follow the READ & RUN ME sticky. Make sure you get the proper version of HijackThis as given in step 7 of the sticky. Attach the two online scanner logs from step 6 and a new HJT log when finished.
     
  11. Eamonn

    Eamonn Private E-2

    Whoops
     

    Attached Files:

  12. Eamonn

    Eamonn Private E-2

    The first of the other scans didn't work -SP2 interference

    I was running a popup stopper. Took me a sec to get panda to load. Running now......
     
  13. Eamonn

    Eamonn Private E-2

    Panda is finished

    interesting that Norton did not find these
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really! Norton misses many things! So do other antivirus programs. Also remember there is a difference between antivirus and antispyware programs. While there is overlap, they are not the same.

    You have signs from a SmitFraud infection. Run the steps in the two below procedures. You may not see many of the things mentioned in the second procedure for SmitRem (like various filenames and process names), just skip that name and continue thru all steps and attach the Ewido, smitfiles.txt, and also get a new Panda log when finished.

    Running Ewido Anti-Malware

    SpywareQuake Removal Procedure
     
  15. Eamonn

    Eamonn Private E-2

    There's the reports. I was a bit surprised by the panda report-
    just to see I ran a new 2nd Ewido and saw nothing there, so I'll guess that these utilities do different jobs.

    :)
     

    Attached Files:

  16. Eamonn

    Eamonn Private E-2

    I thought I'd run another Hijackthis as well. No harm?:rolleyes:
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Delete the below if still found:
    C:\w.exe
    C:\Program Files\Internet Explorer\setup45.exe
    C:\Program Files\Internet Explorer\update.exe
    F:\save folder\ops\Security\Arsenal\IRC MegaPac\ae.zip
    F:\save folder\Save4mail\Internet Stash\stuff\Downloaded Progs\Download agents\GetRight\TSUninstaller.exe
    F:\save folder\Save4mail\Internet Stash\stuff\Downloaded Progs\Winamp\Plug ins\milkdrop_099c.exe

    Empty your Recycle Bin and Norton Nprotect folder as indicated in step 0 of the READ ME.

    After this you should be clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  18. Eamonn

    Eamonn Private E-2

    I can't thank you enough for taking the time:D

    I'll be watching here for other people's issues. I like this site.

    E
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds