Virus stopping browsers

Discussion in 'Malware Help (A Specialist Will Reply)' started by adscottie, Nov 19, 2010.

  1. adscottie

    adscottie Private E-2

    Hi,

    I read Reddit and recently they had a post saying a number of users had reported a virus from them, so I did a virus scan and found some (using SAS), I deleted these however this led to my main browsers (Opera and firefox) not working (IE still works and my opera mail client still works).

    I then, stupidly, tried to solve the problem myself, I uninstalled and reinstalled Java, used Hijack this and fixed a thing I saw in other threads (R1..... Proxyserver = http=127.0.0.1.50370) and used microsoft security essentials to delete some trojans.

    However these did not solve my problem, I then followed the steps in the malware removal guide. Attached are the logs (I included the SAS scans where something was found (I rushed and didnt let the original scans finish)) and a couple of screenshots relating to the opera message and MSE.

    All these problems have been this week however the viruses may have been on for longer.

    Many thanks for any help.
     

    Attached Files:

  2. adscottie

    adscottie Private E-2

    Here are the two images of MSE and opera.

    Thanks again,

    Adam.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any additional malware in your logs. Have you tried uninstalling those browsers, running CCLeaner and then reinstalling them? Is that your only issues ( Opera and FF? )
     
  4. adscottie

    adscottie Private E-2

    Hi thanks for the reply, I uninstalled both opera and firefox, used CCleaner and then reinstalled them, firefox now works however Opera does not. I uninstalled Opera again and deleted the folder in program files (x86) and reinstalled it but still no luck.

    Any other ideas? If not shouldn't matter too much.

    Thanks,

    Adam
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can post in the software forum to see if anyone has a solution to your Opera browser. Otherwise, I don't see any malware that is causing this. If you want to do an online scan, then please try this:

    eSet Online Scan.

    If that does not help, then try posting in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  6. adscottie

    adscottie Private E-2

    Ok, thanks very much for your time, I will try the software forum as you suggest.

    Adam
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     
  8. adscottie

    adscottie Private E-2

    Hey, just in case anyone else had this problem, after fiddling around I got Opera working -

    I went into the opera menu - settings - preferences - advanced - network - proxy servers

    and there was a HTTP proxy server ticked for 127.0.0.1 Port 50370

    I unticked this and it now works (I don't know what a proxy server is but I saw you had told people to delete things with those numbers in Hijack this before).

    Cheers
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, that would do it. Good to know you got it fixed. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds