SE Redirects - Combofix shuts IE down

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by FabFlorida, Mar 25, 2009.

  1. FabFlorida

    FabFlorida Private E-2

    Whenever I click on anything in google, I am redirected to an advertisement. Some of the things that have flashed while adverts are loading are: afe.SpecificClick.com, bmxok, OpenClick.com, TheFindSearch.biz, FindResearchHere.com (and *.us).

    This has been happening since I rebooted yesterday morning. The day before, I had opened an email that I thought was real. The subject line was something like "Connect with Scott." What I opened was an advert for something called "Scott Free." I closed and deleted as quickly as I could. This weird hijacking of my internet searches started happening immediately after the next time I rebooted.

    I found your website and am stunned at the amount of information! It has taken me almost two days to do everything as instructed. I can't imagine how long it took you to write it including all possible variations on the outcomes! Thanks for doing it.

    I followed all directions on READ & RUN ME FIRST:
    1. SAS returned no infections.
    2. MalwareBytes removed one infection by Rogue.Multiple.
    3. I could not download ComfoFix after several attempts. This consistently caused everything to close. I tried to access BleepingComputer directly from Internet Explorer but again, everything just closed, leaving me at my desktop. I uninstalled my Avast, but this did not allow me to download ComboFix.
    4. I ran MGTools, but frankly don't understand anything it returned. :/

    - I'm still having the redirect problem.
    - I am still unable to download ComboFix.
    - I have not yet tried to reinstall Avast.
    - I did not try any system restores to dates before this
    started happening.

    I think I'm attaching everything I'm supposed to. This was all quite overwhelming to me because I am not at all techy. :/ If I lose this computer, I've lost all contact with the world!

    Thanks for your help,
    Christine
    P.S. I read other threads on this issue but all seemed slightly different than my results. I don't know anything about how computers work and am deathly afraid to start doing things listed in similar, but not exact threads.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Why are your running this PC with no protection software installed?

    Uninstall the below software:
    Java(TM) 6 Update 11
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
    O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Sony\Local Settings\Temp

    Now run Ccleaner to clean out only temp files and nothing else!

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Mar 29, 2009
  3. FabFlorida

    FabFlorida Private E-2

    Dear Chasling,
    Thank you SO MUCH for your reply. As I'm sure you can imagine, I have been going absolutely insane over this.

    In answer to your initial question about why I had no protection software running, I couldn't get combofix to load to safe my life so I disabled Avast. It still wouldn't load so I uninstalled Avast. Combofix still wouldn't load so I gave up on that and reinstalled Avast.

    Regarding Viewpoint Media Player, I missed it the first time, found it after I sent the logs, and then deleted it.

    Going to follow your instructions now--trembling all the while that I am going to make a mistake and lose everything. :/ I am not technically inclined when it comes to these things.
    Fingers crossed,
    Christine
    P.S. Thanks for working on a Saturday night. :)
     
  4. FabFlorida

    FabFlorida Private E-2

    Hi Chasling,
    I went to my root file to execute MGTools.exe. When I did, I did not have an option of "system scan only."

    Here's what happened:

    It opened the black box
    It did its scan
    Black box does not close automatically for me
    I have to "hit any key to continue"
    I am then left with my root files with no indication of the four lines that I was to "fix."

    Christine
    P.S. I also completed the items before the step of running MGTools.exe:
    1. I uninstalled Java 6 Update 11
    2. I confirmed that I had successfully uninstalled Viewpoint Media Player
     
    Last edited: Mar 29, 2009
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not say to run MGtools.exe. I said
     
  6. FabFlorida

    FabFlorida Private E-2

    Oy, so you did. :/
    Going to do that now.
     
  7. FabFlorida

    FabFlorida Private E-2

    Completed the MGTools\analyze.exe instruction.

    Downloaded Avenger from your link to my desktop.

    Ran the exe file.

    Copied everything in your text box and pasted it into the "input script here" box.

    Received following message (I couldn't copy what was in the message box so the following is my typing):
    Error: Invalid registry syntax in command
    "HKEY_CURRENT_USER\software\microsoft\windows\CurrentVersion\run\AdobeUpdater"
    Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program. Skipping line. (Registry key deletion mode).

    I had the option of continuing, but I cancelled pending further instruction from you.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to continue all the way thru. Just ignore any error messages.
     
  9. FabFlorida

    FabFlorida Private E-2

    Hi Chasling,
    Thanks for the advice. I did as you said and am attaching the Avenger and MGlogs files.
    Christine
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean but you should not have started using MSconfig again. See step 1 of the READ & RUN ME.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. FabFlorida

    FabFlorida Private E-2

    Hi Chasling,
    Thanks for the reply. Regarding your comment that I should not have restarted using MSconfig again, I don't understand this comment. I don't know anything about msconfig except what you told me to do there. :/ Anyway, I will follow your other instructions here.

    I do have a question about my logs: Did I have any spyware/key logger on my computer? At the same time the redirect/hijack activity started, I started getting repeated messages in Yahoo saying "You have been disconnected from chat because you ahve signed into Yahoo Messenger from another computer or device."

    1. This is confusing because I have never even used Yahoo messenger and don't even know how to, nor do I desire to. (I assume this requires downloading something from Yahoo and I have never done this.)
    2. This is alarming because it makes me think someone has my password and is signing into my account while I am online.

    Did I have any keyloggers on my computer?
    Thanks,
    Christine
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not sound correct. In your first set of logs you were not using MSconfig to control startups and now in your last set you are. MSconfig does not run by itself to disable startups from loading. Either you or someone else ran it and put your PC into selective startup mode by disabling startups.


    Yes you had an infection is all I can say specifically. We do not know that much about this infection at this time as it is fairly new and nothing is detecting it. We can just see it visually in are scans and know that it does not belong there and we remove it. One symptom we see from it is that ComboFix is blocked from running. To be safe, you should use another PC to change all of your internet passwords. Also you should change the passwords on your PC that was infected.

    If you don't use Yahoo then how are you getting messages in Yahoo?
     
  13. FabFlorida

    FabFlorida Private E-2

    Hi chasling. Thanks for the info. I suspected that there might be a key logger component because of the mysterious yahoo messenger activity. Yes, I use yahoo for email, but I have never used yahoo messenger. Yet I started receiving those wierd notices that my messenger account (which I don't even have) had logged into yahoo messenger from "another location". I have asked yahoo tech support about this also and am awaiting reply. I will do as you said about changing all passwords from another location.

    Bigger issue now is that windows will not load at all. Regarding your comments about msconfig/disabling startup, I don't know about any of that and no one has touched my computer, so I obviously did something by accident but have no idea what I did. I have now tried to start using F8 function

    "Start windows normally" took 35 minutes to return blue screen saying problem caused by PartMgr.sys PAGE_FAULT_IN_NONPAGED_AREA plus more tech info that I wrote down.

    "Last known configuration" took 20 mins to return blue screen asking me to check for adequate disk space, to check for driver updates, to try changing video adapters, to check for bios updates, and to disable bios options such as caching or shadowing.

    "Safe mode" took 45 minutes to scroll through lots of things in the system32 folder and finally gave a black screen with "safe mode" in all four corners but nothing in the middle. I waited more than one hour but nothing more materialized.

    My only lifeline to correspond with you now is the 2 inch screen on my blackberry!

    Christine
     
    Last edited: Apr 14, 2009
  14. FabFlorida

    FabFlorida Private E-2

    P.S. Because windows is not loading, I was unable to complete last set of instructions you gave me in your next to last post.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note, there is no "i" in my name. ;)

    It may not be a keylogger, it could just be something we call phishing. That is some one trying to get you to enter information somewhere to steal your info.

    You will have to post about this in the Software Forum. If your PC is unbootable, it more likely a problem with Windows or drivers. We cannot help you in this forum with this. Your previous logs were clean already so it was not a malware problem.
     
  16. FabFlorida

    FabFlorida Private E-2

    Thanks chaslAng. :)

    I will try to find that other forum on this crazy 2 inch screen! Thanks for all the help getting rid of the malware.
    Christine
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds