View Single Post
Old 04-11-2009, 05:45 AM   #6 (permalink)
amateur
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,420
OS: XP SP3


Re: seneka, ndler2, browser hijack at Google

Hi,

I missed or didn't get the notification for your post and just saw it while going through my subscribed topics. Did you do all that between the time of your first post and my reply? I would have preferred that you didn't do anything either before or after.

Quote:
Also, ComboFix was not able to make a Restore Point (at least so far as I can see). System Restore has not been working for at least the last couple of weeks. I don't know why not.
Download http://www.kellys-korner-xp.com/regs...temrestore.reg and save it to your desktop. Double click on systemrestore.reg and allow it to merge with the registry. Reboot and see if you can set a system restore point manually.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it ( something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

============================

Quote:
This redirection seems no longer to be happening but I continue to see the status bar message about looking for v1.adwarefeed.com.
Quote:
Immediately after posting the CF report I noticed my browser looking up jbrlsr.com
Were these happening on IE or FireFox?

============================

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

==============================

Quote:
shutdown time has greatly increased and now includes a new "Closing Network Connections" message that I've never seen before.
My research on that says that it's normal and not malware related. Try this utility
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline