Browser shuts, redirects Trojan.CWS or Worm.IM.Sohanad

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dc399uk, Mar 27, 2009.

  1. dc399uk

    dc399uk Private E-2

    Folks

    I seem to be having real issues with my computer.

    It started a couple of days ago with Firefox freezing. Once restarted firefox now randomly redirects to spam type pages when clicking links (usually these are rubbish 'search' pages or porn). Firefox also shuts down when clicking other links, particularly when trying to download a file. This happens in IE and Safari also.

    I started to try to address the issue. Interestingly when trying to diagnose the problem certain pages prompt the browser (Firefox, IE and Safari) to shut down straight away, such as www.bleepingcomputer.com (I have been trying to get to www.bleepingcomputer.com/forums/topic58874.html as the google preview looks like it might be similar to my issues but I can't get there - even when someone cuts and pastes the page into an email I can't open that!). I've tried following the Majorgeeks malware removal guide as much as I could but can't get to the page to download combofix (the browser shuts down everytime I click the link).

    I've run AVG (which can't seem to update at the moment), Superantispyware, Trojan Remover, Malwarebytes Anti-Malware, Spyware Doctor and CC Cleaner. Apart from a few tracing cookies, the only thing that has been picked up is by Spyware Doctor. These are:
    Trojan.CWS
    Worm.IM.Sohanad
    Neither of these have been picked up by anything else - I have to pay £30 to register and have Spyware Doctor 'fix' this, which I'm hesitant to do as entering credit card details when security is compromised plus I don't even know if this is the problem!

    I'd really appreciate any suggestions (just hope my browser continues to let me access this forum!).

    Thanks

    dc399uk
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. dc399uk

    dc399uk Private E-2

    Hi again.

    I followed the Malware Removal Guide. Logs at the bottom of this message. Results as follows:
    - Add/remove programs: Removed Viewpoint Media Player
    - Uninstalled all old versions of Sun Java
    - Normal Start up mode set
    - CCleaner Run (57MB removed)
    - Spybot Teatimer turned off
    - SUPER ANTISPYWARE: Trojan.DNSChanger-Codec found and removed from registry.
    - MALWAREBYTES ANTI-MALWARE: No infections found
    - COMBOFIX - Unable to download from mybleepingcomputer.com. Cannot access site. Have managed to download program from another site but cannot access instructions on mybleeping computer.com so have not run. For some reason this is one of the sites my computer has 'blacklisted' and I am not able to access.
    - MGTOOLS - run. No errors.

    The symptoms remain exactly the same - the browser seems very unstable and closes down totally randomly and frequently directs to a spam browser / porn site.

    Hope someone is able to help.
    Many thanks
    Dave
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do this until I get a chance to review your logs:

    The infection you have is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup. After doing this, continue with on with the below.


    Download HostsXpert and then follow the below steps.

    * Unzip HostsXpert.zip
    * It will create a folder named HostsXpert in whatever folder you extract it to.
    * Run HostsXpert.exe by double clicking on it.
    * Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    * Click Restore Microsoft's Hosts File and then click OK.
    * Click the X to exit the program
     
  5. dc399uk

    dc399uk Private E-2

    I've carried out these steps - still no change. Firefox seems a lot more unstable than IE though. Is it worth reinstalling Firefox? I'm going to try to view the combofix instructions on another computer and run that this weekend.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK..let's do this:

    I want you to use windows explorer to find and delete:
    C:\Documents and Settings\Dave\Local Settings\Application Data\oqoeoqi_navps.dat.vir
    C:\Documents and Settings\Dave\Local Settings\Application Data\oqoeoqi_nav.dat.vir
    C:\Documents and Settings\Dave\Local Settings\Application Data\oqoeoqi.exe.vir
    C:\Documents and Settings\Dave\Local Settings\Application Data\oqoeoqi.dat.vir
    C:\WINDOWS\system32\flh.qvk
    C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\chrome\content\ffjcext\ffjcext.xul

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download the latest version of MGTools.exe, let it overwrite the existing file and then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  7. dc399uk

    dc399uk Private E-2

    Hi

    Thanks for the help.

    I've deleted:
    C:\Documents and Settings\Dave\Local Settings\Application Data\oqoeoqi_navps.dat.vir
    C:\Documents and Settings\Dave\Local Settings\Application Data\oqoeoqi_nav.dat.vir
    C:\Documents and Settings\Dave\Local Settings\Application Data\oqoeoqi.exe.vir
    C:\Documents and Settings\Dave\Local Settings\Application Data\oqoeoqi.dat.vir
    C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\chrome\content\ffjcext\ffjcext.xul

    I was unable to locate
    C:\WINDOWS\system32\flh.qvk
    There IS an flh.qvk file in the C:\WINDOWS directory - is this the one you mean? I have not deleted it yet.

    I did not get a success message after running fixME.reg

    I attach the latest MGTools logs

    Cheers

    Dave
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have TeaTImer running which is why the reg fix did not work.

    Please Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  9. dc399uk

    dc399uk Private E-2

    Thanks so much for the replies and assistance.

    I decided to format the hard drive and start again. It actualy has been a surprisingly painless and easy process so far, and all symptoms do not seem to have come back.

    I've also installed Kaspersky Internet Security so hoping that will keep me safe for the time being...

    Thanks again for the help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds