Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Please help a lost soul

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: Please help a lost soul

Unread postby nineinchheel » May 11th, 2009, 5:40 am

Okay Dan, I enabled Spy Bot S&D's TeaTimer feature and I have immunised my system with S&D. I installed the Install MVPS Hosts File and I am in the process of updating windows.
Unfortunately, I don't think I am clean yet. I have just been using Firefox to browse and I find that sometimes my google searches are being hijacked.
When I click on google search results, instead of going to the target website I get directed to

hxxp://c.incomeppc.com/?d=rAbIxfhBdxNNE ... c3c6a78bba

When this happens I get a Page Load Error. Is this evidence of malware still on the computer?
nineinchheel
Regular Member
 
Posts: 39
Joined: April 22nd, 2009, 5:04 am
Location: Coventry, West Midlands
Advertisement
Register to Remove

Re: Please help a lost soul

Unread postby dan12 » May 11th, 2009, 6:36 am

Ok, let's have a look.

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Double-click GooredFix.exe to run it.
  • Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: Do not run Option #2 yet.

dan :)
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: Please help a lost soul

Unread postby nineinchheel » May 11th, 2009, 6:41 am

GooredFix v1.92 by jpshortstuff
Log created at 11:40 on 11/05/2009 running Option #1 (George)
Firefox version 3.0.10 (en-GB)

=====Suspect Goored Entries=====

C:\Program Files\Mozilla Firefox\extensions\{EEF22C20-BA1A-4FDD-97B2-CAB4BEE19625}

C:\Program Files\Mozilla Firefox\extensions\{75CC35EF-3014-4CB8-85CF-17A2B1AA6F0A}

C:\Program Files\Mozilla Firefox\extensions\{5F3D4111-EFA2-46C4-90CB-6185ABEAEAAC}
GooredFix Log:

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\mozilla firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\mozilla firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"remoteExt@emusic.com"="C:\Program Files\eMusic Remote\remoteExt" (Folder Missing)
nineinchheel
Regular Member
 
Posts: 39
Joined: April 22nd, 2009, 5:04 am
Location: Coventry, West Midlands

Re: Please help a lost soul

Unread postby dan12 » May 11th, 2009, 6:55 am

We may have it. :) Have to go out now but will check in with you later to see if you have had any redirects.

Please double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.

dan
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: Please help a lost soul

Unread postby nineinchheel » May 11th, 2009, 7:03 am

GooredFix v1.92 by jpshortstuff
Log created at 12:02 on 11/05/2009 running Option #2 (George)
Firefox version 3.0.10 (en-GB)

=====Goored Deletions=====
C:\Program Files\Mozilla Firefox\extensions\{EEF22C20-BA1A-4FDD-97B2-CAB4BEE19625}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.
C:\Program Files\Mozilla Firefox\extensions\{75CC35EF-3014-4CB8-85CF-17A2B1AA6F0A}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.
C:\Program Files\Mozilla Firefox\extensions\{5F3D4111-EFA2-46C4-90CB-6185ABEAEAAC}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\mozilla firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\mozilla firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"remoteExt@emusic.com"="C:\Program Files\eMusic Remote\remoteExt" (Folder Missing)
nineinchheel
Regular Member
 
Posts: 39
Joined: April 22nd, 2009, 5:04 am
Location: Coventry, West Midlands

Re: Please help a lost soul

Unread postby dan12 » May 11th, 2009, 12:01 pm

How's it been since this morning?
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: Please help a lost soul

Unread postby nineinchheel » May 11th, 2009, 12:21 pm

I've had no more Firefox redirects. I also seemed to have solved Opera being very slow on the close by changing the memory cache size from 'automatic' to 20mb and then emptying the cache. Disk cache size is 20mb and I didn't change that.
Can I uninstall all the anti-malware programs from my computer now? Programs such as Malwarebytes' Anti-Malware. HijackThis! and GooredFix.

Dan I cannot thank you enough for your time, I am going to make a financial donation to malwareremoval
nineinchheel
Regular Member
 
Posts: 39
Joined: April 22nd, 2009, 5:04 am
Location: Coventry, West Midlands

Re: Please help a lost soul

Unread postby dan12 » May 12th, 2009, 12:59 pm

Thank you for your kind donation it will be appreciated. :)

let's just clear up goored fix for you.

malwarebytes is a good program to keep, just remember to update, before running a scan so you have the latest definitions available.

Click Start >> Run and then copy/paste the following into the box and hit Enter:
"%userprofile%\Desktop\GooredFix.exe" /uninstall
If any of your security programs query a new Registry/AutoStart value being added please allow the changes.

Was please dto here you had managed to solve the opera problem, have noted that myself.

Well if you have no questions I will wrap this one up and bid you good luck and safe surfing.
Kind regards dan
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: Please help a lost soul

Unread postby nineinchheel » May 13th, 2009, 4:56 am

Any special instructions for the removal of HijackThis! ?
nineinchheel
Regular Member
 
Posts: 39
Joined: April 22nd, 2009, 5:04 am
Location: Coventry, West Midlands

Re: Please help a lost soul

Unread postby dan12 » May 13th, 2009, 5:06 am

Go to control panel >"add and remove programs" click on HJT which will be highlighted, hit the remove button.
Hope that's helped.
dan :)
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: Please help a lost soul

Unread postby NonSuch » May 17th, 2009, 10:32 pm

As this issue appears to be resolved, this topic is now closed.

We are pleased we could help you resolve your computer's malware issues.

If you would like to make a comment or leave a compliment regarding the help you have received, please see Feedback for Our Helpers - Say "Thanks" Here.
User avatar
NonSuch
Administrator
Administrator
 
Posts: 27301
Joined: February 23rd, 2005, 7:08 am
Location: California
Advertisement
Register to Remove

Previous

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 42 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware