Webpages redirecting to spam/Browser closing

Discussion in 'Malware Help (A Specialist Will Reply)' started by thierry1, Mar 25, 2009.

  1. thierry1

    thierry1 Private E-2

    Hi, I've been watching this forum closely for a few days and following the help of moderators, so far to no avail.

    I'm having similar problems to people who are being redirected to spam sites and have browsers closing randomly.

    So far I have ran full scans with:

    Super antispyware
    Rogueremover
    Malwarebytes
    Avast
    Norton
    Spybot
    Vundofix

    They've all found different things which I've deleted/quarantined.

    I've also ran:

    CC Cleaner
    ATF Cleaner
    N Cleaner

    They are picking up lots of MBs of usage within a short space of time.

    My computer is also slowing down and something is using up my processor speed.

    I've also removed Windows Messenger which I think brought the Malware originally.

    Today I've tried running Combofix which doesn't launch from my desktop. But it was downloaded OK. On some occasions when I tried to download it from a from mirror my browser shut down - this has been happening a lot when surfing webpages.

    What I have been able to run is Hijack This and Rootrepeal and I have logs if needed.

    I've followed the forum's guide and done scans with Super antispyware and Malwarebytes and I've attached logs for them along with a MGlog zip - they showed up clean.

    I hope someone can help and look forward to following your instructions for removal. Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are running both Norton and Avast!! Uninstall one!

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 3

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\wswdfyox.bat
    C:\WINDOWS\system32\w32apiw.dll
    C:\WINDOWS\system32\drivers\sgmabekr.sys

    Now reboot and download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  3. thierry1

    thierry1 Private E-2

    Hi Tim, thanks for the reply.

    Ok I did as you suggested, but had some problems:

    - Uninstalled J2SE ok
    - Deleted the two files you said
    - Registry didn't seem to merge - it just refreshes my screen when I double click it
    - Deleted the three other files from C:
    - Re-installed Java
    - Can't open the .bat file as it does the same as the registry file above - refreshes my screen without doing anything
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you save the registry patch correctly?

    Have you tried running the MGTools bat file in safe mode?

    Did you try Combo in safe mode? Did you rename it?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds