Lately I've been getting redirected in my web browser. There aren't any popups or redirects to unknown pages, but instead it's redirecting me to pages that we've bookmarked or frequently visited. When I got malware like this a couple of years ago, the innocuous redirects became more frequent and started to redirect to commercial/scam sites. It seems that the mouse is funtioning erratically, too, sometimes requiring 2-3 clicks instead of one (this mouse issue may or may not be related) I've pasted the HijackThis log below.
Thank you - Radrodidodi
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:57:18 AM, on 2/26/2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16533)
Boot mode: Normal
Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com) There are 6 different versions. If one of them won't run then download and try to run the other one. Vista and Win7 users need to right click and choose Run as Admin You only need to get one of them to run, not all of them.
rkill.exe
rkill.com
rkill.scr
rkill.pif
WiNlOgOn.exe
uSeRiNiT.exe
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please download Farbar Recovery Scan Tool
(use correct version for your system…..Which system am I using?) and Tutorial http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
Press Scan button.
It will produce a log called FRST.txt in the same directory the tool is run from.
Please copy and paste log back here.
The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
Hi Juliet - thanks for your help! Here are the two reports that you requested:
FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-02-2014 02
Ran by [removed] (administrator) on CRYSTAL-PC on 28-02-2014 22:10:12
Running from C:\Users\[removed]\Downloads
Microsoft® Windows Vista™ Home Basic Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
Please go to add/remove programs list and uninstall Coupon Printer for Windows
Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy. Paste this into the open notepad. save it to the Desktop as fixlist.txt NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)
Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
*******************
-AdwCleaner-by Xplode
Click on this link to download : ADWCleaner Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Do not click on any links in the top Advertisment.
[external image: adwcleaner_download.png]
Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next answer.
You can find the logfile at C:\AdwCleaner[S1].txt as well.
[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.
1) uninstall Coupon Printer for Windows –> partially completed. After uninstalling the first instance, the second one said something like "this program cannot be found… it's possible that it's already been removed." So I continued. I think there was one instance for Firefox and one for IE.
2) FRST –> ran this program and it created a log. However, its no longer on my desktop as some files have been moved around - see below
3) ADWcleaner –> ran this program and it created a log, too, but it was moved and cannot be found
4) ran JRT after shutting down Symantec–> log is posted below
5) after completing all of this, there are some funny things going on:
a) even though I'm logged onto "Michael," my start menu shows "Crystal"
b) most of the exe's and log files on my desktop have been removed or possibly hidden
c) I cannot open the control panel, my computer, or any folders (double click –> spinning wheel 1 sec–> nothing happens)
d) I have a new shortcut/icon on my desktop for "CouponActivator" and a 7z922 icon
e) several of the icons in my taskbar are not showing (where the network, speakers, time, etc are shown)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows Vista (TM) Home Basic x86
Ran by [removed] on Mon 03/03/2014 at 19:49:20.69
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 03/03/2014 at 19:55:01.43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
after restarting, all of the oddities mentioned in 5) above have all returned to normal. While it looks good on the surface, it kind of worries me but I'm assuming the logs will tell you what you need to know. Here are the logs that were not posted above
Fixlog.txt
C:\AdwCleaner[S1].txt –> I didn't have an S1 file, but I had an S0 file, which is pasted below.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 02-03-2014 03
Ran by [removed] at 2014-03-02 21:31:13 Run:1
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
HKU\S-1-5-21-1218617016-3022421040-3124855728-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully.
C:\Users\Crystal\AppData\Roaming\Dropbox\bin\Dropbox.exe not found.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-1218617016-3022421040-3124855728-1001\User => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{70D46D94-BF1E-45ED-B567-48701376298E} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} => Key deleted successfully.
HKCR\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} => Key deleted successfully.
C:\Users\Crystal\AppData\Roaming\Mozilla\Firefox\Profiles\s63sz2m5.default\Extensions\wecarereminder@bryan => Moved successfully.
C:\Users\Crystal\AppData\Local\temp\lowproc.exe => Moved successfully.
C:\Users\Crystal\AppData\Local\temp\stubhelper.dll => Moved successfully.
"C:\Users\Michael\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpizyh1u.dll" => File/Directory not found.
The system needed a reboot.
==== End of Fixlog ====
# AdwCleaner v3.020 - Report created 02/03/2014 at 21:46:25
# Updated 27/02/2014 by Xplode
# Operating System : Windows Vista (TM) Home Basic Service Pack 2 (32 bits)
# Username : Crystal - CRYSTAL-PC
# Running from : C:\Users\Michael\Desktop\AdwCleaner.exe
# Option : Clean
OK, this looks better, was worried there for a few minutes.
How is the computer now?
Please Run TFC by OldTimer to clear temporary files:
Download TFC from here http://oldtimer.geekstogo.com/TFC.exe and save it to your desktop.
Close any open programs and Internet browsers. Double click TFC.exe to run it on XP (for Vista and Windows 7 right click and choose "Run as administrator") and once it opens click on the Start button on the lower left of the program to allow it to begin cleaning. Please be patient as clearing out temp files may take a while. Once it completes you may be prompted to restart your computer, please do so. Once it's finished you may delete TFC.exe from your desktop or save it for later use for the cleaning of temporary files.
~~~~~~~~~~~~~~~~~
Go here to run an online scanner from ESET.
Turn off the real time scanner of any existing antivirus program while performing the online scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activeX control to install
Click Start
Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
Click Scan
Wait for the scan to finish
When the scan completes, press the LIST OF THREATS FOUND button
Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
Include the contents of this report in your next reply.
Hi again - I ran TFC, and then ESET, with the results below:
C:\iPhone Jailbreak\for iPhone 3gs\Setup.exe a variant of Win32/Adware.iBryte.G application
C:\Users\Michael\Downloads\cbsidlm-cbsi3_2_5_41-RealPlayer-10073040.exe a variant of Win32/CNETInstaller.A potentially unwanted application
C:\Users\Michael\Downloads\FoxitReader514.0104_enu_Setup.exe a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy. Paste this into the open notepad. save it to the Desktop as fixlist.txt NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)
start C:\iPhone Jailbreak\for iPhone 3gs\Setup.exe C:\Users\Michael\Downloads\cbsidlm-cbsi3_2_5_41-RealPlayer-10073040.exe C:\Users\Michael\Downloads\FoxitReader514.0104_enu_Setup.exe Reboot: end
Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please run this security check for my review.
Download Security Check by screen317 from here.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Hello - here are the two logs. We haven't noticed any redirects or odd mouse behavior.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-03-2014 01
Ran by [removed] at 2014-03-09 22:26:50 Run:2
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
C:\iPhone Jailbreak\for iPhone 3gs\Setup.exe
C:\Users\Michael\Downloads\cbsidlm-cbsi3_2_5_41-RealPlayer-10073040.exe
C:\Users\Michael\Downloads\FoxitReader514.0104_enu_Setup.exe
Reboot:
end
*****************
C:\iPhone Jailbreak\for iPhone 3gs\Setup.exe => Moved successfully.
C:\Users\Michael\Downloads\cbsidlm-cbsi3_2_5_41-RealPlayer-10073040.exe => Moved successfully.
C:\Users\Michael\Downloads\FoxitReader514.0104_enu_Setup.exe => Moved successfully.
The system needed a reboot.
==== End of Fixlog ====
====================
Results of screen317's Security Check version 0.99.80
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8 ``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
Symantec Endpoint Protection
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
SpywareBlaster 4.5
Java(TM) 6 Update 30 Java version out of Date!
Adobe Flash Player 12.0.0.70
Adobe Reader 10.1.9 Adobe Reader out of Date!
Mozilla Firefox (27.0.1)
Google Chrome 33.0.1750.117
Google Chrome 33.0.1750.146 ````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0 % ````````````````````End of Log``````````````````````
We haven't noticed any redirects or odd mouse behavior.
Music to my ears!
uninstall some programs
NOTE** Because of the cleanup process some of the programs I have listed may not be in add/remove anymore this is fine just move to the next item on the list.
Programs to remove Adobe Reader 10.1.9 Java 6 Update 30
~~~~~~~~~~~~~~~~~~~~~~~`
Update Adobe reader Recently there have been vulnerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version.
After installing the latest Adobe Reader, uninstall all previous versions. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.
If you don't like Adobe Reader (53 MB), you can download Foxit PDF Reader(7 MB) from here. It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, be careful not to install anything to do with AskBar. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Install Java: Please go here to install Java click on the Free Java Download Button click on Agree and start Free download click on Run click on run again click on install when install is complete click on close
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Any questions?, see any other malware issues on the computer?
If not I think we're ready to close this out and remove quarantine folders and I'll post a few preventive tips.
Thanks again for the tips. I went through your instructions without any problems, and we don't see any other malware issues at this time. You guys are the best! OldMan960 helped me a lot a couple of years ago, and this has been another positive experience! Thank you!
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI