PC Hijacked (Internet wont run on browsers etc)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jomox, Nov 19, 2010.

  1. Jomox

    Jomox Private E-2

    Hi,

    I posted here a few weeks back with problems with this same pc on this thread. All has been running fine since the last cleaning until not long ago I was browsing the net (normal safe sites) when everything slowed down. The windows browser froze, and I had to do a log off via taskmanager to regain control again. After this AVG found lots of malware and it come up with pop-ups with it's moving to vault etc.

    I then checked to make sure the internet was still okay but when I loaded firefox it said: The proxy server is refusing connections. So I tested IE and again it would not connect despite the machine being connected to the net fine. At this point I unplugged the net from the machine.

    I tried to run SAS and combofix but when I try to load them they don't come up, I can only manage to run malwarebytes and mgtools, while rebooting though the system would not shut down (stuck on the windows shut down screen) And I had to do a hard shut down to reboot. I am right now sitting on another one of my PC's on the same internet which is running fine. (Have not shared any files since this has happened apart from the logs from a USB Flash drive)

    I have just gotten into safemode and the latest version of combofix won't run due to AVG being installed so I would like to know what to do about this, should I uinstall AVG? And what would be used for free real time protection then? SAS still won't run though so right now I only have the MB & MG logs attached.

    The problem I have is I need this machine back on the internet very soon for work releated stuff. (Tonight really otherwise am in a bit of trouble) As this PC is not suitable for this workreleated stuff, so I am considering risking a system restore and hope that works as you guys do have allot on and a big list of people to help so you may not be able to help me in time before it effects my work and stuff.

    Thanks in advance for your kind work.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Users\DHR\AppData\Local\5532155.exe.vir
    C:\CIAxxxxxxx.exe

    Now run CCLeaner and then make sure this folder is cleaned out:
    C:\USERS\DHR\LOCALS~1\TEMP\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!

    I am logging off for the evening.......so you will have to wait until Kestrel logs on for further assistance.
     
    Last edited: Nov 19, 2010
  3. Jomox

    Jomox Private E-2

    Thanks so much for your very quick reply.

    Everything is done, apart from could not find C:\CIAxxxxxxx.exe to delete manually, and am not 100% sure if the C:\USERS\DHR\LOCALS~1\TEMP\ folder was cleaned out, or though ccleaner was set to clean out all temp files and such so I guess it should of cleaned it. There was a sucess message on the reg edit.

    Am sorry for the delay also, I was still in safe mode as you was replying and had managed to get SAS to start to scan but after your reply I did a reboot to start windows up normally (should of stayed in safe mode?) but when windows was starting up it failed to start and windows started up it's recovery, lukily it recoverd okay and started up without needing a system restore, but it took a little time to fix it's self .

    The only thing now is the machine wont connect to the net at all, I think it may need a reboot (it does sometimes when i switch the net from the machines, the one infected is the host usually) however I don't want to risk another reboot untill you or Kestrel have checked the MG logs and gave it the all clear to reboot. I do beleive a reboot could fix it as firefox no longer says "The proxy server is refusing connections." and just goes server not found etc.

    The PC is actually running okay once started up, still very snappy etc, It was just a little slow at starting up, and of course the other problems that I reported before, but the real test I guess will be what's in the logs and how the next reboot goes.

    Again thanks for your swift response, it's greatly appreicated and hope you have had a good night.
     

    Attached Files:

    Last edited: Nov 19, 2010
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing any issues ......do use windows explorer to find these and delete them:
    You should be able to connect. If not, you may need to post in the networking forum.
     
  5. Jomox

    Jomox Private E-2

    Sorry thought you had gone.

    Those are all deleted now.

    I gues will be okay to reboot now to get the net back on?

    Thanks again!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, reboot, are you able to connect now?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download Cleano 0.61

    Download it to your desktop, Right click the cleano.exe file and run as admin > and place check marks in the boxes as follows

    • Clean user's temp
    • Clean windows temp

    Click clean now and exit the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. Jomox

    Jomox Private E-2

    Hi Kestrel, thanks for the reply.

    The log is attached.

    Little update also, the net is running on the machine we have been cleaning after a good reboot, but again the browsers won't connect and firefox is saying the proxy thing again. This system I am on now is running as a client on the machine we have been cleaning (which is the host, this pc is firewalled, password procted etc so should be okay) So there is still something wrong I feel with the browsers, the malware has messed them up somewhere I think as the actual networking on the machine is all still fine.

    Edit:

    Screw all that I was being dumb, I just needed to go into firefox settings and turn proxy connect of, now it connects to the net fine, sorry for my sillyness, it's a bit late here in Europe so I am not fully on things.
     

    Attached Files:

  9. Jomox

    Jomox Private E-2

    Okay last reply for me tonight.

    I think all it's fixed now I beleive, all running smooth again (on startup and shut down, net etc)

    I just want to say thanks for your wonderful help, you make surfing so much better for all of us. It's great to have people like you lot here at MG to help us resolve and fix these nasty malware issue's. :major
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Put this machine into normal start up mode using MSCONFIG, any other mode is primarily used for trouble shooting and diagnostic purposes. You should always be in normal mode.

    Did you set this proxy yourself or not?

    The reason I ask is Because you fixed it once under Tim's instructions but now I am seeing it again. Let us know!

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Delete these files:
    • C:\ProgramData\hpe411A.dll
    • C:\ProgramData\hpe646D.dll
    • C:\ProgramData\mtbjfghn.xbe

    Uninstall the below:

    • Java(TM) 6 Update 16
    • Java(TM) 6 Update 18
    • Messenger Plus! Live

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now download a fresh version of Combofix, let it overwrite the old version and reattempt running it from your desktop.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. Jomox

    Jomox Private E-2

    I don't know about the proxy thing I have not set anything manually, all i done is changed firefox settings to no proxy. I fixed it the first time but indeed it seems to be back again, shall I again fix it?

    I merged the code into registry and got the success message.

    Successfully deleted those files and uninstalled the requested software, and updated Java.

    CF still won't run as it says need to uninstall AVG again.

    MG log attached.

    I am very grateful for all the help once again.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Fix this proxy then as shown in post # 2 by TmW.

    Uninstall avg, then run combofix as per the instructions. (We will reinstall it later don't worry)

    Then...

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. Jomox

    Jomox Private E-2

    Okay all done and sorry for delay.

    Windows is still a touch slow at start up then how it should be and winamp/ie still don't connect but that's because I need to change those proxy settings the malware changed (like I did on FF) Other then that performance is fine.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's just check one more thing:

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  15. Jomox

    Jomox Private E-2

    During the scan it says 1 object found. And then I get to this screen and only have these options on the skip button as shown.

    [​IMG]

    When I click continue it says system scan complete infection not found etc, no other options. Attached the report log. Am guessing I should selete delete as cure is not there and skip was set as the default action.

    Will wait for your next reply before taking any further action.
     

    Attached Files:

    Last edited: Nov 20, 2010
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have Dameon tools or some other disc emulation software, as I believe that is what that file is from. Also tell me what issues you are having.
     
  17. Jomox

    Jomox Private E-2

    Yes I got Dameon tools lite installed.

    Only issue's I have is with IE/Winamp not connecting to the net but as said before that's going to be settings in the software that needs fixing, just need to find where, other then that everything is running good. I'll test start up some more though after a run of ccleaner and a defrag.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Here is a guide on resetting the proxy settings:

    Change Proxy Settings.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  19. Jomox

    Jomox Private E-2

    Thanks for all the help Tim and Kestrel also, appreciated. I'll run the final steps and then we should be good. :major
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    On behalf of Kestrel and myself, you are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds