Results 1 to 10 of 10

Thread: IE redirects

  1. #1
    Join Date
    Feb 2008
    Posts
    11

    IE redirects

    1. As per the instructions,I downloaded AVg Anti Spyware, Microsoft defender, ATf-Cleaner and Hijack This.

    2. I switched to Safe mode and ran the tools as instructed.

    3. Switched back to normal mode. Found some problems starting up. Active desktop could not be restored. system also gave message that svchost.exe is missing.
    4. The problem did not go away. URLs continue to be redirected In addition i am unable to restore my Active desktop. AM now uploading the log files.

    Assistance is resolving would be much appreciated.
    Attached Files Attached Files

  2. #2
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Please follow the instructions below to run ComboFix.
    1. Download this file and save to desktop - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log back here
    Note:
    • Do not mouseclick combofix's window while it is running. That may cause it to stall.
    __________________

  3. #3
    Join Date
    Feb 2008
    Posts
    11

    Combofix Log

    Hello,
    Combofix log attached. Thanks for your assistance.
    Attached Files Attached Files

  4. #4
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    One thing I don't understand is why all these items are showing in TEMP files. Didn't you run the ATF-Cleaner BEFORE running anythng else?

    I would like for you to run the ESET Online Scanner again but this time please tell it to fix everything found.
    Be sure to save the log.

    After that then run a new Combofix scan. Post back here with both logs.

  5. #5
    Join Date
    Feb 2008
    Posts
    11

    Combofix and Eset online logs

    Hello,

    1. I believe I ran the tools in the order specified -- windows malicious software removal, eset online,atf cleaner, avg, microsoft defender, hijack this. I'm not certain but i may have connected to the internet in between tools -- there was a point where the F8 didnt work and had to log back into your post to print out the safeboot using safe configuration utility.Could that be the reason?

    2. Combofix and eset online logs attached.


    Thanks very much for your assistance. Much appreciated.
    Attached Files Attached Files

  6. #6
    Join Date
    Aug 2006
    Posts
    578

    Lightbulb

    Hello Surdbird,

    You are making some progress, but there is still much left to do. In a large infestations such as yours, it is not unusual to find a lot of things to be messed up . . . Often a clean reinstall of the Operating System is the best course of action. But, for now, let's see what we can do:

    First, you need to Uninstall Limewire via Add/Remove Programs.
    I would recommend you do the same for BitTorrent.
    Those are probably major culprits in your huge infestation of malware.....

    Also, you should be aware that you have an infested USB drive somewhere that has come into contact with your computer and left evidence of itself.A tool such as Flash-Disinfector by sUBs
    http://www.techsupportforum.com/sect...isinfector.exe may help....


    After uninstalling the above, please do this:


    -- Please delete your copy of ComboFix and download a fresh one to your Desktop - not a folder on your desktop
    -- Download the attached file CFScript.txt to your Desktop as well
    -- Close ALL browser windows and then drag CFScript.txt into ComboFix.exe to start ComboFix


    -- Let Combofix run as before and post that log along with a fresh HJT Log for Judy.She will probably have additional steps for you based on the new logs. Just those two logs ought to do for now.


    Best Luck
    PP
    Attached Files Attached Files

  7. #7
    Join Date
    Feb 2008
    Posts
    11

    Combofix and HijackThis Logs

    Hello,

    1. I uninstalled Limewire and BitTorrent.

    2. Deleted and re-downloaded Combofix to desktop.

    3. Combofix and HijackThis Logs attached.

    Thanks
    Attached Files Attached Files

  8. #8
    Join Date
    Aug 2006
    Posts
    578

    Lightbulb

    Hello Surdbird,

    Sorry for the delay - I thought Judy was going to continue....

    The logs look better, though I did miss one file that you will need to delete manually:
    C:\WINDOWS\system32\kfnybhor.dll

    You can also scan with HijackThis and FIX the following entries:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://kqworld
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =


    -- You should definitely Update your Java here ---> http://www.java.com/en
    -- Then, look in Add/Remove Programs and Remove ALL traces of any older Java versions! If you do not uninstall ALL older versions, you may remain at risk for a number of baddies such as Vundo.


    Other than that, thing look OK. Are you still experiencing any problems?

    PP

  9. #9
    Join Date
    Feb 2008
    Posts
    11
    Hello Phillie,
    I am not experiencing any problems now. Thank you for all your assistance. It has really helped.
    Best,

  10. #10
    Join Date
    Aug 2006
    Posts
    578

    Cool

    Quote Originally Posted by surdbird View Post
    I am not experiencing any problems now. Thank you for all your assistance. It has really helped.
    Glad to hear it!

    We are happy to help

    PP

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •