Doginhispen skitodayplease etc, but ComboFix stopped/Malicious Script warning?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lorelei23, Mar 8, 2008.

  1. lorelei23

    lorelei23 Private E-2

    Hi
    It looks like I have the same problem as a lot of other people with doginhispen, skitodayplease, and 88.80.7...
    I am trying to run through the "do this first" instructions, I got everything done but ComboFix- during the last part after reboot Norton opened up and said Combofix wasn't running anymore (can't remember the exact phrase sorry) and it was a malicious script, recommended to stop running the script so I did.
    Anyone know if this is just a problem with Norton Antivirus starting up during ComboFix? I'm sure there is a setting on Norton I can turn off to keep it from starting up on reboot but I'm sort of reluctant to run ComboFix again in case its a different problem.
    Thanks !!!
     
  2. lorelei23

    lorelei23 Private E-2

    Sorry- I forgot to put them in the original post but here are the two logs I have so far.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Remove all internet explorer add-ons and toolbars.

    Download FindAWF and save the file to your Desktop
    Double-click FindAWF.exe to start the tool.
    Select Option 1 by pressing 1 and then Enter. The scan will start and a log will open (awf.txt)

    • Post back with with the contents of awf.txt
     
  4. lorelei23

    lorelei23 Private E-2

    Here is the AWF log- I don't have any add ons or toolbars that I know of. Also, I forgot to mention in my first post that Norton found something called Trojan.Zonebac in a file called roxwatchtray9.exe that it couldn't remove- it tried quarantining & deleting it but wasn't able to. I'm not sure if that is an extra virus or the one thats causing the doginhispen problems here.
    Thanks so much!
     

    Attached Files:

    • awf.txt
      File size:
      6.4 KB
      Views:
      3
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start FindAWF.exe
    Select option 2 by pressing 2 and then Enter. A text file will open (files.txt).
    In that files.txt, copy and paste the following list of files to be restored:
    Close the files.txt and click Yes to save the changes.
    FindAWF wil now terminate the bad processes if running, delete the bad files and restore/replace them with the good files.
    Then it will open a log. Copy and paste the contents of that log in your next reply.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
     
  6. lorelei23

    lorelei23 Private E-2

    Hi
    I ran the AWF and ATF. a.doginhispen is still popping up in my history, I'm not sure if its supposed to be gone yet. Here is the new log from AWF. Thanks.
    Edit to add- do I still need to try running combofix again or have we gone around that problem? Thanks so much for all your help!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start FindAWF, select Option 3, by pressing 3 and then enter.
    This will open the text file folders.txt
    Copy and paste the following list in it:
    Then close folders.txt and let it save the changes.
    FindAWF will now remove the bak folders and open a log afterwards.
    Post the log in your next reply.

    Double-click the FindAWF icon once again

    If a Security Alert shows, allow the program to run.
    As instructed, press any key to continue.
    Use the following option: Press 4 then Enter to reset domain zones

    This removes all entries from the domain zones.
    When the program returns to the main menu, use the following option:
    Press E then Enter to EXIT

    Please download DelDomains and unzip it to your desktop. Do not run it yet.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    (Please note if you have Spybot S&D installed you will need to "Immunize" again because deldomains will remove all of the sites Spybot adds.)

    Yes...a combofix log would be appreciated.
     
  8. lorelei23

    lorelei23 Private E-2

    Here are the logs you requested.
    I ran ComboFix after FindAWF and installing DelDomain but I'm not sure if I was meant to ComboFix first? I hope its OK. Let me know if I should do anything differently. DelDomain is installed but I haven't run it yet.
    Thanks
     

    Attached Files:

  9. lorelei23

    lorelei23 Private E-2

    Hey
    Sorry to post again, but I don't think I ran ComboFix correctly earlier so the log I posted a little while ago may not be what you wanted. I just opened it from the desktop when I ran it earlier this evening, which isn't how it should be done, right?.

    I just reran ComboFix correctly according to the instructions- hopefully the new log will post but I'm having some trouble getting it to upload. Thanks again
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run the DelDomains ....and if you haven't, re-run ATF Cleaner and delete your IE History and temps.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\Program Files\Common Files\Adobe\Updater5\bak
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\bak
    C:\Program Files\Java\jre1.6.0_03\bin\bak
    C:\Program Files\QuickTime\bak
    C:\WINDOWS\system32\bak
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.
     
  11. lorelei23

    lorelei23 Private E-2

    I'm not sure that I installed/ran Deldomains correctly. I rightclicked install on the deldomains.inf file, and a window popped up to open it. I clicked OK, the desktop blinked slightly and nothing happened after that. No icon showed up, no other deldomains files appeared anywhere that I could find? Does it just install/run instantly and leave no trace?
    Let me know if I screwed up somewhere- some computer stuff I know pretty well but I have a tendency to mess up the simplest things and not realize it.

    I ran ATF, ComboFix and MGTools though, I'm attaching the logs for you.
    Thanks again for all your help Tim- you have no idea how great it is to have your help:)
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I forgot to ask you how things were running...are you still having problems?
     
  13. lorelei23

    lorelei23 Private E-2

    Some of the problems are better, but I'm pretty sure the actual virus or whatever you call it is still here.
    My internet is much faster than it was before I ran the Read and Run First instructions, but doginhispen, 88.80.7.66, and skitodayplease are all still showing up in my internet history.

    I checked with a few different programs- the online scan from TrendMicro didn't pick up anything except a few cookies which I then forgot to delete before I closed the window, I ran SpyBot again after I redid the Immunize thing and it picked up the cookies too and deleted them.

    But Norton keeps finding this problem with a file called RoxWatchTray9.exe, it says the virus name is Trojan.Zonebac. Its still not able to quarantine or delete it. Do you think thats what causes the doginhispen stuff?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    c:\ program files\ common files\ roxio shared\ 9.0\ sharedcom\ roxwatchtray9.exe

    From Sonic Solutions. It calls home so Norton thinks its bad.....it isn't.

    Have you deleted the IE History in each user accounts? Are you getting re-directs?
     
  15. lorelei23

    lorelei23 Private E-2

    I have deleted the internet history/cookies/temp files a bunch of times, I also went through and looked at all the folders for the 'guest' account too, they were empty.

    I'm not getting any redirects at all. I tried to see if there was any kind of pattern in when these sites showed up in my history but there doesn't seem to be one.

    Has anything actually been showing up on the programs you've had me run?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No....nothing is showing up. Did you have Spybot re-immunize after doing the deldomains?

    Also look in your internet explorer settings under trusted site...it should be empty.

    I'd like you to do this: go to Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds