Browser Hijacker, Can't Run ComboFix or MGTools

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bleepbleepcomp, Feb 26, 2009.

  1. bleepbleepcomp

    bleepbleepcomp Private E-2

    A few days ago, when I signed onto my computer in the morning, my initial problem was just that MSN messenger was crashing. It seemed like nothing at the time (and is now working as it should), but when I tried to start Winamp, it also would not load properly, and still won't, even after a complete uninstall/reinstall. I hadn't changed anything in Winamp the night before so I really don't know what the issue is there. When I did a search for problems with it, clicking on the result redirected my browser so I began searching for a malware problem. The logs are showing nothing though and ComboFix and MGTools now refuse to run properly. ComboFix will run its small loading window, but will not open the prompt. MGTools will run until it does the .COM search and then does not go past that point, but it has created a zip so I included it. I am also unable to run the DisableUAC.reg and GetLogs.bat files. Both cause all items on my desktop and the taskbar to disappear until I logout or restart. I also tried to run one of the alternative scans, Panda ActiveScan, which was showing 12 results at 17% but my browser crashed around that time and that was also 5 hours of scanning later so I have not attempted to run it again.
     

    Attached Files:

    Last edited: Feb 26, 2009
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach this log:
    C:\ComboFix.txt

    And delete this:
    C:\Documents and Settings\All Users\Application Data\AZCNQHOB
     
  3. bleepbleepcomp

    bleepbleepcomp Private E-2

    Thank-you for your reply, Tim. The AZCNQHOB folder was deleted and attached is the combofix text.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me what problems you are still having. :)
     
  5. bleepbleepcomp

    bleepbleepcomp Private E-2

    Same =/ Still being redirected, mgtools/combofix won't run properly, and winamp is still getting an error. I'm also noticing that at times I need to click things twice for the click to register at all, for instance the Run buttons before mgtools/combofix, and links as well.
     
  6. bleepbleepcomp

    bleepbleepcomp Private E-2

    Sorry for the re-reply. I'm sleepy and I don't see an edit button. I've noticed that the redirects sometimes contain the word "clickshield" in them D= I'm afraid this probably has to do with a codec I have since winamp has been killed in the process. I don't want to do anything else without instruction though. Thanks again!
     
  7. bleepbleepcomp

    bleepbleepcomp Private E-2

    I have to apologize again for another post on my part, but I felt my logs were lacking due to the problems with running two of the tools so I have run a scan with a-squared now and wanted to include the results it gave me. It found something called Dc1.exe and a few other things that look strange. I could only get a screenshot.

    Sorry again for another reply.. :hammer
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All the files indicated are in your system restore folders, except for the first one. Empty your trash bin.

    Now do this:
    Using BitDefender Online Scan.
     
  9. bleepbleepcomp

    bleepbleepcomp Private E-2

    Hi Tim, thanks again. First of all, I'm happy to report that I haven't experienced any redirecting for about 24-36 hours! I don't know what changed because I've only done scans and no removals since you asked me to remove that folder. As well, Winamp is working again, as are ComboFix and MGTools, so I did go ahead and do some scans with them after finishing with BitDefender, and have attached all of those logs. I also re-did the scan with a-squared after all that just to see if it still picked up anything and it is still showing one of the results: Virus.Win32.Agent.DDN in C:\System Volume Information\_restore{77175A35-3D26-4847-AF63-85D7EBC210B6}\RP85\A0035006.dll.

    Thank-you!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Bit removed items in your thunderbird account. Then combo finished up. The remaining file is in your system restore folder and will be remove when you do the following:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  11. bleepbleepcomp

    bleepbleepcomp Private E-2

    I think it's all clear now, but just out of curiosity, I've been tracking other threads that sounded a lot like my problem, particularly http://forums.majorgeeks.com/showthread.php?t=183542 and http://forums.majorgeeks.com/showthread.php?t=183386. In the second, the user was asked to check the size of cmd.exe, so I decided to do this as well and mine is exactly the same size as theirs, which chaslang said is not right. Guess I'd just like to know if this could signify that there is still a problem, or if it is nothing to worry about?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, your cmd.exe is just fine.
     
  13. bleepbleepcomp

    bleepbleepcomp Private E-2

    Okay, thank-you once again for your help, and especially your patience =)
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds