Search Redirecting problem (XP + Firefox)

Discussion in 'Malware Help (A Specialist Will Reply)' started by BigBrother70, Feb 10, 2009.

  1. BigBrother70

    BigBrother70 Private E-2

    Yep, I got one. It started last night along with another piece of malware called Antivirus 2008. Before finding this site, I had tried the following programs/steps:

    ATF Cleaner
    FixWareout
    Malwarebytes Anti Malware
    SUPERAntiSpyware
    Gooredfix
    KillBox
    SDFix
    ComboFix

    I now went through the steps here, though I am using logs from my previous runs earlier today. If it's really a problem I'll run again, I'm just so exasperated I figured these should suffice. I also just run MGTools.

    Thanks *so* much for your help!!!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need to see the combofix log. In the mean time, do this:

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5"
    Java(TM) 6 Update 7"
    Viewpoint Media Player

    Now use windows explorer to find and delete:
    C:\WINDOWS\ofkohmov

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Here is what I want you to do. Read ALL of this and/or print it because you MUST HAVE all FireFox windows closed before doing it.

    Locate the below file using Windows Explorer.

    C:\Program Files\Mozilla Firefox\extensions\{03CA0C23-8373-4D0F-B276-2C11E0ED47FC}\chrome\content\overlay.xul

    Then right click on the overlay.xul file and rename it to overlay.BAD

    Now restart FireFox and tell me if you still have the problems.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
    Last edited: Feb 12, 2009
  3. BigBrother70

    BigBrother70 Private E-2

    Thanks for your help, TimW. In response:

    1. I received a successful message after the registry add.

    2. I couldn't locate the file you mentioned (the directory didn't exist within extensions.) I did try the same however in these two directories:

    {883ACB39-5B6D-4964-8E4D-59663A8F47BB}

    {F1055970-1EBF-409E-8CA0-FC246039F462}

    which contained chrome files. It worked! No more redirects.

    3. Attached is my latest MGLogs.zip

    4. Oddly though, my Firefox just exhibited some weird behavior- it wouldn't restore when I clicked on the open window in the task bar, and then when I restarted it, it started in a very small window. Is this due to the chrome renames?

    Thanks again, I really appreciate it.
    -BB
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can go back to those files that you renamed and delete them.

    Now:

    I would like to get some more info on the C:\Program Files\irw.exe file. Locate it using Windows Explorer and then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too.

    You also need to go back to the Read and Run First instructions to download the latest MGTools.exe......just let it overwrite the current folder. Then get me that log.
     
    Last edited: Feb 14, 2009
  5. BigBrother70

    BigBrother70 Private E-2

    Okay, IRW.exe wasn't found in Program Files, but I did find it in Windows\system32. To answer your questions: under Version info it says Apple Inc. and lists it as an IR Receiver application. FYI this is a MacBook Pro running bootcamp, so I'm assuming (?) this is legit.

    Attached is my latest MGLogs using the version off the Read and Run First page..
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK....not to worry. It is a legit file. I am not seeing any malware in your logs. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  7. BigBrother70

    BigBrother70 Private E-2

    TimW, thank you so much!! The fact that you guys do this stuff for free is quite admirable!

    As another paranoia question, is there any way for me to know if backdoors or key listeners are installed? I saw it in another posting and it sounds quite scary.

    Thanks!
    BB
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The best way to deal with those kind of issues is to be fairly vigilant in your scanning...and keeping all software updated.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds