Browser hijacked randomly

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cjs56, Jul 16, 2010.

  1. cjs56

    cjs56 Private E-2

    When using Firefox or IE to do a search (google or yahoo), the browser gets hijacked to a random search engine (ie mamma.com, aicse, zubican, etc.).

    This does not always happen. Last night it was okay. But today it started again.

    I ran the Read Me with various success:
    SuperAntispyware ran without finding a problem.
    MalwareBytes ran without a problem

    Combofix runs but during a reboot the system goes into a restart loop. The system boots up, but before it can load windows it resets. I cannot get into safe mode. I was able to use a Vista CD and do a Repair Startup. Even then, I get a StartRep.exe error: exception Breakpoint. However, the system restarts normally afterwards.

    RootRepeal causes a BSD (blue screen).

    MGTools ran successfully.

    I have attached the logs.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, cjs56.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    cjs56

    Step 1:
    Please disable TeaTimer as instructed in the R & R ME First guide.
    How to disable Spybot's TeaTimer

    Step 2:
    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
    Step 3:
    Delete this as it's no longer needed - wasn't saved where instructed.
    c:\Users\davidc\Desktop\MGtools.exe

    Step 4:
    I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ c:\Users\davidc\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Step 5:Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 6:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 7:
    Now install the latest Sun Java Runtime Environment

    Step 8:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • TDSSKiller log.txt

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  4. cjs56

    cjs56 Private E-2

    Step 1. disabled TeaTimer (thought I had disabled it last month.)
    Step 2. download and ran TDSSKILLER (no problems detected)
    Step 3. deleted MGtools.exe from desktop
    Step 4. cleaned up the desktop by moving file folders and files into My Documents
    Step 5. uninstalled HiJackThis and Java update 20
    Step 6. ran ccleaner
    Step 7. installed Jave runtime
    Step 8. ran the GetLogs.bat file

    attached logs

    Tried a search with Firefox and it is still being hijacked to another search site.

    Thanks for the help.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Are other browsers also hijacked?

    Please run the below online scanner from Kaspersky and attach the log:

    Running Kaspersky Online Scanner
     
  6. cjs56

    cjs56 Private E-2

    Both Firefox 3.6.3 and IE8 are begin hijacked.

    Ran the Kapersky scan and attached the log.

    After restarting, both browsers are still being hijacked. Includes searches with iGoogle, Google and Yahoo.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Ok -

    If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup. It would even be a good idea after the reset, to look for any available router firmware update and install it.

    Did that help?
     
  8. cjs56

    cjs56 Private E-2

    I can do that, although I have two other machines on the same network (one cabled directly and the other wirelessly) that do not have the same problem.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Do you have the same problem, when you disconnect the Aspire desktop from the network and bypass the router for a direct connection?
     
  10. cjs56

    cjs56 Private E-2

    Correct. The Aspire has the same problem when connected directly to the cable modem and when I run it through my router.
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    cjs56

    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the "Input script here:" part of the window.
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now - flush your caches!

    (1) To flush IE 8 cache
    • From the Safety menu in the upper right, click Delete Browsing History... .
    • Deselect "Preserve Favorites website data", and select "Temporary Internet files,
      Cookies, and History".
    • Click Delete.

    (2) To flush FireFox cache
    • From the "Tools/Options" menu
    • Click on the "Clear" button next to "Cache".
    • Click on "OK" to close the window.

    (3) To flush Java cache - see this link:

    http://www.java.com/en/download/help/plugin_cache.xml]

    (4)To flush DNS for a computer running Windows, please follow these steps:

    Windows Vista
    • Click the Vista icon to display the Start menu.
    • Click the Command Prompt option.
      If that option is not available, type cmd in the search box at the bottom and press Enter.
    • Within the prompt, type ipconfig /flushdns.
    • Hit Enter
    • *You should receive a "Successfully flushed the DNS Resolver Cache" message
    • Exit the command window

    Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  12. cjs56

    cjs56 Private E-2

    That helped!

    I ran The Avenger
    Flushed the IE8 cache
    Flushed Firefox cache (Tools/Options/Advanced/Network-Offline storage [Clean now)
    Flushed Java cache
    Flushed DNS
    Ran MGTools

    attached the logs

    Rebooted and successfully ran searches without being hijacked with both IE8 and Firefox.

    Thanks!

    PS How do i 'Thank' someone?
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :highfive

    You're welcome!
    At the bottom right of someone's post reply, you can click on this button: [​IMG]

    Finally, please delete all files in the below bold folders except ones from the current date <--- Windows will not let you delete the files from the current day.

    *Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! [​IMG]
     
    Last edited: Jul 24, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds