Have malware cause web redirect and desktop icon removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hafwhit, Feb 17, 2012.

  1. hafwhit

    hafwhit Private E-2

    I have a computer that has some malware that shut down the computer. The computer did not have antivirus software until I loaded Avast on it after the issue. I ran the antivirus software after the problem and it removed some items but the computer still has problems. When the computer comes up the Avast gives a warning that a web site has been blocked that starts with "renewanadiaper" in the URL address. I have gone through the "Fixing Google Redirection/hijacking and other redirection problems" http://forums.majorgeeks.com/showthread.php?t=230267 thread. I am posting this after following the instructions in the "Windows XP Malware Removal/Cleaning Procedure" http://forums.majorgeeks.com/showthread.php?t=139313 thread. I am attaching the logs from the process. When I ran the "ComboFix" process the computer did a system dump when it was processing the step to prepare the report.

    Do I need to attach any of the log files from processing the "Google redirect" process?
     

    Attached Files:

  2. hafwhit

    hafwhit Private E-2

    This is a message to add the MGlogs.zip attachment.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding much in the way of malware in your logs, so tell me what issues you are having. In the meantime:
    Please put ComboFix directly on your desktop, not here:
    C:\Download\ComboFix.exe

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    C:\Documents and Settings\REH\Application Data\556C33.dat
    C:\Documents and Settings\All Users\Application Data\F4D55F3B000023C10023F65BD151FC4E
     
  4. hafwhit

    hafwhit Private E-2

    I have placed ComboFix on the desktop.

    I ran C:\MGtools\analyse.exe and fixed the lines as indicated.

    I removed the two items in the Documents and Settings.

    The computer is working except it appears something is in the start up that is causing the Avast to detect a web page being accessed at start up.

    The URL link is like "http://renewanadiaper.com/cat/v3/main.php....etc" and the process appears to be "file///C:\WINDOWS\system32\svchost.exe" and the infection is listed as "url:Mal".

    If i do a search from Firefox it attempts to redirect me to another web site. I have the "noscript" add on that blocks the connection but I have to click the URL address line to get to the actual link. See the attached document.

    Do I need to run the ComboFix.exe program again now that it is on the desktop?

    Thanks for your help.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run Combo and also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  6. hafwhit

    hafwhit Private E-2

    ComboFix is running now. I will submit logs when I have completed both processes.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'll be here when you are ready.
     
  8. hafwhit

    hafwhit Private E-2

    Attached is a new MGlogs.zip file after running the Combofix from the desktop.

    Thanks for the assistance.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the latest Combo log. I still am not finding any cause for your issues.
     
  10. hafwhit

    hafwhit Private E-2

    I have attached the last ComboFix log and also a MBRCheck log I had ran.

    Thanks for your assistance.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have a faked MBR. Do you have your XP disc?


    If you have your disc, boot to the bios and change the boot order so the CD/DVD is first. Insert the disc and reboot. Go into the Recovery Console and type:
    fixmbr

    Reboot to normal mode and re-run MBRCheck. Attach the new log.
     
  12. hafwhit

    hafwhit Private E-2

    I have a backup running of the system so I will do the "fixmbr" as soon as it finishes.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know when you are ready.
     
  14. hafwhit

    hafwhit Private E-2

    Stop error message occurred when attempting to start "Windows Recovery Console. I am using the disk supplied with the system and also tried another Windows XP disk with the same result.

    I ran a CHKDSK to fix errors and tried again with the same error message. Can I fix the MBR with linux bootable CD such as "Trinity Rescue Disk"?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am personally not familiar with that disc. Try posting in the software forum for further advice with that program then come back when you are successful. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds