My mom has given me the task of fixing her computer for Mother's Day. Me being the great son I am said sure thing
She complained that Firefox would crash and Google searches redirect her to other sites. BTW she's running Windows XP. Steps I took to fix it were
1) Update firefox to latest version
2) Ran Spybot Search and Destroy and removed the following:
Fraud.InternetSecurity2011 - 26 entries
Microsoft.Windows.AppFirewallBypass - 2 entries
Microsoft.WindowsSecurityCenter.AntivirusOverride - 2 entries
3) Ran Malwarebytes' Anti-Malware
Quick Scan
c:\documents and settings\christine\local settings\Temp\1CA.tmp (Rogue.SecurityTool) -> Quarantined and deleted successfully.
c:\documents and settings\christine\application data\microsoft\stor.cfg (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\christine\application data\chkntfs.dat (Malware.Trace) -> Quarantined and deleted successfully.
Full Scan
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\ggr.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\ggr.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\ggr.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\exefile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\ggr.exe" -a "%1" %*) Good: ("%1" %*) -> Quarantined and deleted successfully.
4) Ran Avira Anti-Vir
Here's a snippet of it where it found a "JAVA/Exdoer.BE.2 Java" virus:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\0R2DSLC5\swflash[1].cab
[0] Archive type: CAB (Microsoft)
--> FP_AX_CAB_INSTALLER.exe
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\cache\6.0\61\23dbfa3d-3c8ade4b
[0] Archive type: ZIP
--> olig/aret.class
[DETECTION] Contains recognition pattern of the JAVA/Exdoer.BB.2 Java virus
--> manty/rova.class
[DETECTION] Contains recognition pattern of the JAVA/Exdoer.BE.2 Java virus
Beginning disinfection:
C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\cache\6.0\61\23dbfa3d-3c8ade4b
[NOTE] The file was moved to '4e252656.qua'!
After doing all of this, Spybot, Malwarebytes, and Antivir comes back clean yet FF still crashes and redirects. Help please...
Thanks,
Mike

Help
This topic is locked


Back to top




button.
.
button.
and check Remove found threats 
, and save the file to your desktop as ESETScan.txt.
button, then Finish.
> Run..., and in the Open dialog box, type: services.msc








