Still having problems after following Read & Run Me First

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jtownsend1254, Feb 10, 2009.

  1. Jtownsend1254

    Jtownsend1254 Private E-2

    Hello,

    I have followed all of the instructions listed under the "RUN & READ ME FIRST" topic and it seemingly has corrected a few of the problems I am/was having, but not all of them.

    I'm not sure when or how my computer got infected, but as of yesterday (Feb 9th) I was getting a popup message from my icon tray telling me my computer was infected and that I should run Spyware Removal Tools. Clicking on the popup bubble sent me to a website for a bogus spyware tool, along the lines of AdwareRemovalXP2009 or something similar. My homepage for Internet Explorer was deleted, though I primarily use Firefox and it's homepage was unaffected. My desktop would sometimes change to solid black instead of the normal picture I use. All of these problems seemed to have disappeared after running all of the programs recommended in the read me first topic.

    The only problem remaining is that when using a search engine such as Google, I am sometimes taken to a random advertising site instead of the site listed when I click on a link. I have tried searching for solutions to this and this site has helped me out the most so far, thank you.

    Attached are the log files for SUPERAntiSpyware, MalwareBytes Anti-Malware, and ComboFix. I will attach the log for MGtools right after this post as I can only attach 3 files at a time.
     

    Attached Files:

  2. Jtownsend1254

    Jtownsend1254 Private E-2

    Here is the MGTools.zip log file.

    Thank you so much for all the help so far.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me what problems you are still having and whether they are related to your MBAM log which indicates that you took no action against what it found.

    You can also tell me what this is:
    C:\Documents and Settings\Jack Townsend\Application Data\4EE9D3 --> if you don't know, delete it.
     
  4. Jtownsend1254

    Jtownsend1254 Private E-2

    Thank you for the response,

    I am still having the problem where when I use Google, the links will sometimes take me to advertising websites or something similar instead of where the link should have directed me. I also get a lot of weird popup ads when I'm browsing the internet that only show up when I highlight a word that is double underlined in an article.

    I don't know why the logs say no action was taken against those things as I thought I followed the instructions to delete them. I saw that myself and ran it again and they didn't show up in the list the second time.

    I don't know what that file is, but it says it was last modified Jan 28th, which is before I remember noticing any problems. I took your advice and deleted it anyway.

    Thanks for the response.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Does this problem exist in all browsers? Have you removed all toolbars and addons? Have you removed all of your internet temp files?

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
     
  6. Jtownsend1254

    Jtownsend1254 Private E-2

    I didn't have any add-ons or toolbars to begin with.

    The problem only appears to happen in Firefox, IE appears unaffected.

    I ran ATF Cleaner by following your instructions and cleared about 50MB worth of files, but it didn't appear to fix anything with Firefox.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Okay here is what I want you to do. Read ALL of this and/or print it because you MUST HAVE all FireFox windows closed before doing it.

    Locate the below file using Windows Explorer.

    C:\Program Files\Mozilla Firefox\extensions\{03CA0C23-8373-4D0F-B276-2C11E0ED47FC}\chrome\content\overlay.xul

    Then right click on the overlay.xul file and rename it to overlay.BAD

    Now restart FireFox and tell me if you still have the problems
     
  8. Jtownsend1254

    Jtownsend1254 Private E-2

    This appears to have fixed the search engine problem, thank you!

    I'm still getting the ContentLink ads on different websites, where an ad will pop up in a bubble when you highlight certain words denoted by a double underline like a hyperlink. I don't know if this is a kind of malware or not, but if it can be fixed somehow I'd greatly appreciate the tips.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is typical.....many sites will do this. Your best bet is to install a pop up blocker. It is a feature in IE....and is also in FF.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds