ComboFix Wont run, Browser Hijacks, Slow Computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rjcaldwell, Nov 28, 2010.

  1. rjcaldwell

    rjcaldwell Private E-2

    Due to a very slow computer I recently did a reinstall of XP from my Acer Laptop Restore Disks. I did the same thing about a year ago and everything went well and computer speed was great. That restore was full of browser hijacks and the inability to update XP. I did another restore but with the same bad results. I have an Acer Travel Mate 290 laptop with a Pentium M 1,30ghz processor and 512 mb of ram, running Windows XP SP3 and IE7. (the system disks are SP2 and I had previously downloaded SP3 to use with this reinstall.
    I am continually getting an error "Generic Host Process for Win32 Services had a problem and must close" The computer runs slowly and it seems that 100% of the cpu is being used with no special programs running. Ctrl, Alt, Del shows that Svchost for the system is using most of the memory and the cpu.
    Since the reload of XP I have been unable to access the Windows Update site for updates and a little badge in my tray tells me that it is trying to download updates but nothing is ever downloaded. I am continually getting browser hijacks ending up on search sites I have never heard of or on porn sites I don't wish to visit. Pop-ups are also common from "freegivawayoffers.com" informing me of the $1000 I have won at
    WalMart.
    I have tried to follow your written instructions on your site but, SuoerAnti Spyware reports no problems, Malwarebytes finds nothing, and ComboFix informs me that my MBR is infected, runs for a while, performs no tests, produces no results and eventually freezes with no disk activity going on. I have waited up to 1.5 hrs for it to move along but nothing. I have had a similar freezing reaction from MGTools - program freezes but I did get a log from MGTools..
    I do have logs from SAS, Malbytes, MGTools and 1 other to attach.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rename Combofix.exe to fgh6y.com and then reboot into safe mode to try and run it again.

    MGTools did not run to completion. It will need to be re-run, this time let it go all the way through it's process, until it says hit any key to continue.

    Run this too:
    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Attach the C:\MGlogs.zip.
     
  4. rjcaldwell

    rjcaldwell Private E-2

    Neither Combofix nor MGTools will run to completion and both stop and freeze my system causing me to power off by holding down the power button. My computer does not like that method.
    I have tried renaming them and get the same result, and same result in the safe mode.
    Combofix starts, backs up the registry, warns me that my MBR is infected and after 30 or 40 minutes of inactivity it freezes my system. Virtually the same with MGTools - starts, gives a few messages and after a long period of time it locks up my computer.
    TDSSKiller, on the other hand, found a virus - Rootkit.Win32.TDSS.TdL4 and after a restart said it had been removed! Hurray!
    MGTools does produce a log but it might not be useful.
    Attached are the TDSSKiller log and the MGTools zipped logs.
    Where to go next?
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Any luck?
     
  6. rjcaldwell

    rjcaldwell Private E-2

    I had some luck and some not-so-luck.
    This morning, after TDSSKiller finally found something, my system was much more well behaved - no browser hijacking, no lengthy disk accesses using up CPU and memory.
    I performed your requests and all but the final command in the DOS window worked - the final command, "GetRunKey" didn't do so well. "Running scan with getrunkeys.bat....by Chaslang. Ignore any error messages about not finding registry keys - Just wait for the program to finish" the cursor went down a line and continued to blink but went no where after 20 minutes. I couldn't get it to move along and found when I touched the screen with my mouse pointer the system froze-up and the only way to do anything else was to manually shut it off (I hate doing that).
    But, the other programs, for the most part, ran well and the logs are attached. (the black screen with information, after running MBRCheck, would not take a right click/select all option but I found a file on my desktop never the less.
    Thanks, so far...
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs look good. Let's just do this:

    C:\MGlogs.zip <-- Attach this to your next message.
     
  8. rjcaldwell

    rjcaldwell Private E-2

    Hopefully you wanted the MGlogs prepared about 2 days ago. It is attached. If you want one from today let me know.
     

    Attached Files:

  9. rjcaldwell

    rjcaldwell Private E-2

    Sorry for probably responding too soon but I figured you wanted an MGTools log run after TDSSKiller found a rootkit virus yesterday so I ran one and, like every time I run that program it crashes my system after stalling for 25 to 30 minutes causung me to use the power button to reboot. However, it does seem to produce a .zip log, attached from about an hour ago.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. rjcaldwell

    rjcaldwell Private E-2

    Thank you for your help. This infection was fascinating to me. Conventional scanners did not see it. I use Malwarebytes about once a week. I scan with my anti-virus program (Microsoft Security Essentials) atleast once per week and it is always active. Occassionally I scan with Spybot. Windows and the virus program are always updated. Windows and my D-Link router supply a firewall.

    Where does the Master Boot Record reside and what is its function?
    If I can't find it how can a piece of malware find it and embed itselt in it? This computer travels with me and my teenager has no access to it. Very little had been downloaded to it. A little bit of Email, Facebook, a little internet surfing.

    I did a total Windows XP restore with my Acer restore disks and, from what I thought, formatted the drive and reloaded Windows with a fresh install. Is it possible that my SP3 update (downloaded from the internet) disk was infected? Does a reinstall even touch the MBR?

    I turned off my wireless so that nothing could infect the system while I reinstalled Windows. I did the SP3 upgrade and installed the anti-virus with the wireless turned off. When I turned the wireless back on and used IE7 I was immediately hijacked.

    Fascinating.
    Thanks.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Brief description here
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds