Browser Hijacking

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by quietblue, Sep 18, 2013.

  1. quietblue

    quietblue Private E-2

    Getting redirects on Google links.

    No issues when I ran tdskiller and mb.

    Logs attached for hitman, mgtools, and rk.

    Thanks for checking into the problem.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. :)

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. You should always be in normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You would be better served using a third party start up manager rather than depending on msconfig.


    Please re run Hitman and have it delete Malware remnants.



    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 4 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : (C:\Users\Mike\AppData\Local\Temp\irb700.exe [x]) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\Run : Microsoft (rundll32 "C:\Users\Mike\AppData\Local\Stardock_Corporation\Microsoft\acpioj.dll",DllRegisterServer [x][-][x]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-2457565460-2395524819-1261518412-1001\[...]\Run : (C:\Users\Mike\AppData\Local\Temp\irb700.exe [x]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-2457565460-2395524819-1261518412-1001\[...]\Run : Microsoft (rundll32 "C:\Users\Mike\AppData\Local\Stardock_Corporation\Microsoft\acpioj.dll",DllRegisterServer [x][-][x]) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Delete these if they show:
    • C:\Users\Mike\AppData\Local\Temp\irb700.exe
    • C:\Users\Mike\AppData\Local\Stardock_Corporation


    • Re run RK again, just a scan and attach log.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Sep 19, 2013
  3. quietblue

    quietblue Private E-2

    Logs attached.

    Changed the startup back to normal in msconfig. Was that likely changed due to the malware installed because I don't recall changing that setting. Which 3rd party startup manager would you recommend for Windows 7?

    No apparent hijacking is occurring.

    A couple of the RK hits you listed disappeared after rerunning hitman.

    The hitman log listed MGtools (which I ignored), but there was nothing called "Malware remnants" so I assumed you meant that as a general statement about the other items found during the scan. I deleted everything listed except for the MGtools and I'm not having any problems, so I don't think I deleted anything needed.

    Thanks once again for your time/attention. Let me know how the logs look and any other recommendations per the above.

    Regards,
    QB
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there.

    Apparently you didn't. :(

    Can you do this now and re run MGTools and attach the new MGlogs.zip? Thanks.
     
  5. quietblue

    quietblue Private E-2

    Hmmmm...changed it first thing as you directed, but apparently it didn't take. I wonder if running any of the tools subsequent to changing the startup mode could have made it revert back? Nonetheless, looks like it's good now.

    I changed it to normal, ran MGtools, and rebooted and it still indicates normal.

    New log attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks good. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  7. quietblue

    quietblue Private E-2

    Thanks so much for all your help! Very much appreciated. I don't see a donation button on the site anywhere...donations not accepted?

    Sincerely,
    QB
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :) Glad to hear all is running well again!

    We don't have donate buttons like alot of sites do. At the end of all my posts you will see a blue link to geekwear, hoodies and T shirts etc. You could take a look thru there and see if anything catches your eye.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds