Redirecting Browser/popup browsers/ plus Antispyfond.com trojan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dd29, Sep 6, 2010.

  1. dd29

    dd29 Private E-2

    Hello,

    I followed the directions in the READ & RUN Sticky post. Yesterday I originally just used MalwareBytes, but it didn't seem to fix everything, then I found this site and hopefully by following the directions my computer will get back to normal. Please find attached the logs from the following programs.

    SuperAntiSpyware
    MalwareBytes
    Combofix
    RootRepel
    MGTools (next post)

    I appreciate the help that you all provide to those of us that are less than tech savvy.

    Please advise if there is anything else that I should do.

    Thanks,
    Dave
     

    Attached Files:

  2. dd29

    dd29 Private E-2

    MGTools.zip attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why am I not seeing any antivirus installed??

    You REALLY need to tidy up your desktop.
    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    jwfrcqs 
    
    File::
    c:\windows\system32\drivers\sdmftbv.sys
    c:\windows\Lbalesiqaquzuw.bin
    c:\windows\Nzanim.dat
    
    FileLook::
    C:\WINDOWS\system32\aniwzc~1  
    C:\WINDOWS\system32\aniwzc~2
    C:\Documents and Settings\David\Templates\N6B46J
    
    DirLook::
    C:\_ABOT 
    c:\documents and settings\David\Local Settings\Application Data\{D1FF0F75-C72A-4FB5-9BAC-F22DBAC6127E}
    
    Folder::
    c:\documents and settings\David\Local Settings\Application Data\myofjbcsc
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Run C:\MGTools\analyse.exe (which is really Hijackthis) do a system scan and save a log file. Attach that log into your next response here.

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\Documents and Settings\David\Templates\N6B46J
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below files and also let me know the results:

    Code:
    C:\WINDOWS\system32\aniwzc~1
    C:\WINDOWS\system32\aniwzc~2
    Could you please get this: aniwzc~1 into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Also attach the collect.zip, the Jotti results and also the HijackThis log.

    Let me know how things are running, please! :)
     
    Last edited: Sep 6, 2010
  5. dd29

    dd29 Private E-2

    C:\Documents and Settings\David\Templates\N6B46J
    http://virusscan.jotti.org/en/scanresult/fd899d355d5b7ee801a025e50af9668303ec3029

    C:\WINDOWS\system32\ANIWZCS2.dll
    http://virusscan.jotti.org/en/scanresult/9d55cb05f7f381d4dfa1b221ce5b36fbd1ec5b1a

    The other file C:\WINDOWS\system32\aniwzc~1 is just a text file with my name in it

    and this file C:\WINDOWS\system32\aniwzc~2 is a text file with the word System in it.

    I have still attached the collect.zip anyway. I believe the aniwzc(...) files are for my Dlink wireless connection.


    I will work on decluttering my Desktop, it's mostly text files and Excel files, and of course program shortcuts.

    Thank you VERY much for your help.

    My computer seems to be running very smoothly now, but if you notice anything out of the ordinary please let me know.

    Best Regards,
    Dave
     

    Attached Files:

  6. dd29

    dd29 Private E-2

    Oh.. on other thing that I noticed from reading other posts... you are having the CFScript.txt name problem because your instructions say

    notice lowercase "s" - should be uppercase.

    Hope that helps.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not sure about that, because after all, I have been using the same boilerplate/template for a very long time, and I see cases where lower case or upper case has been used. I used it on a friends PC just last week with the same lower case s

    Anyway, I need to go to bed, I will review your logs once I have had some sleep.
    In the mean time, why is it that you are not running any antivirus? This is leaving yourself wide open to all kinds of crap.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not case sensitive. CFscript.txt = cfscript.txt = CFScript.txt Windows is not case sensitive like UNIX. :)

    However where many problems come from is when people do not name it cfscript.txt. Sometimes because they have file extensions hidden, they name it CFscript.txt.txt and sometimes the name we give is completely ignored and people name it a random name. ;)
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes that's correct, I should have spotted that.

    Now there is a folder we need to be rid of, that will stop any redirects you may still be having. Also, combofix previously addressed an infected file.

    Use windows explorer to find and delete the following folder:

    Reboot the machine.

    You forgot the HJT log. Follow my previous instructions for this.

    Also you need to install antivirus at this point!

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this, also attach the HJT log.

    Let me know how things are running, please.
     
  10. dd29

    dd29 Private E-2

    Hey guys,

    It was just a thought on the cfscript.txt issue, for the record I did not have a problem with it.

    --------------------------

    steps completed

    Deleted: c:\documents and settings\David\Local Settings\Application Data\{D1FF0F75-C72A-4FB5-9BAC-F22DBAC6127E}

    Rebooted

    CCleaner ran
    HJT ran - log included
    MGTools/GetLogs.bat completed - zip included

    I haven't had any problems whatsoever since running everything yesterday. You guys are saints!


    Could really use some advice on a good free antivirus program. I don't want to end up with the Security Suite from antispyfond.com.

    Thanks so much,
    Dave
     

    Attached Files:

  11. dd29

    dd29 Private E-2

    Oh, one other question. When all this happened, I uninstalled my google toolbar, thinking that it was the security flaw or issue that was tampered with, causing the redirects.

    Should it be safe to reinstall it from google site?

    Thanks,
    Dave
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yep, don't see why not.
    Nothing much remains to be done:

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now... install some antivirus because if ever there is another time you need to turn to us for assistance with malware removal, you could be refused help until you install some!

    Double click the C:\MGTools.exe and agree to the Trend Micro Hijackthis license when prompted (may need to click on agree or accept button twice, it's a bug)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    (Hopefully this time your logs will reflect you installed AV ;))
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds