unable to remove adtrgt

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by AlaskaTom, Dec 6, 2008.

  1. AlaskaTom

    AlaskaTom Private E-2

    I have been unable to remove adtrgt from my daughters computer, running win xp pro.
    IE generates tons of popup adds, virus removal tools etc. Perhaps there is more than one virus/malware on here.
    I tried to install Hijack This, but when I double click the icon, it spawns a process in task manager, but nothing happens.
    I tried to download windows defender, but as soon as I get to the place where it actually downloads the file, the page is unavailable (almost like that domain is blocked). I am also unable to connect to norton live update to downoad latest virus definitions.
    I have tried all the above both in safe mode, and a limited config (using msconfig)
    I notice after unchecking a bunch of boxes in msconfig with random filenames like okiditem rundll32.exe "C:\WINDOWS\okidetem.dll,e" or some such names, there are always 2 more new ones checked the next time I boot and run msconfig.

    Being unable to install Hijack This makes it very difficult. Does any body have any suggestions please?

    Thanks!

    Tom
     
  2. AlaskaTom

    AlaskaTom Private E-2

    Just in case anybody finds this post, I thought I would post my own solution. Finally after searching for hours, I found a post on Experts exchange suggesting renaming the hijack this executable so it wasnt recognized and blocked, so I tried that and it worked! I was able to do the same thing for malwarebytes and combofix.
    Anyway, after running those, a ton of vundo and antivirus and a bunch of other malware was found and removed. Everything seems to be working fine. I will post my final hijackthis log in case it looks like there is some stuff left over.

    Thanks!

    Tom

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:33:41 PM, on 12/6/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal
     

    Attached Files:

    Last edited by a moderator: Dec 7, 2008
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    I would be tempted to run our guide below and attach all the logs requested as you have some known rogue/malware sites in your IE trusted zone, easy to infect yourself again if not already.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.

    plus a guide on how to attach the logs HOW TO: Attach Items To Your Post
     
  4. AlaskaTom

    AlaskaTom Private E-2

    Halo,
    Thank you for taking the time to help! I have followed the very detailed (thank you) instructions. Everything worked as stated. Several things were found early on in the process.
    I am attaching the MBAM log, the SAS log, and the ComboFix log to this post, and will attach the MGtools log to the next post.

    Let me know what you think.

    Thanks again!
    Tom
     

    Attached Files:

  5. AlaskaTom

    AlaskaTom Private E-2

    Halo,
    And here is the MGtools log.

    Thanks.
    Tom
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Just a quick post to let you know I'm looking at your logs, AlaskaTom.

    Thanks for being patient.
    dr.m
     
  7. AlaskaTom

    AlaskaTom Private E-2

    Thanks for the heads-up. No worries. I appreciate all you guys do on this forum!
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, AlaskaTom


    Can you tell me what these are?
    Code:
    [b]c:\program files\mbihope
    c:\windows\ka.ini [/b]

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 2:
    Now we need to use ComboFix to remove some malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\wojsrewydca.exe
    c:\windows\system32\drivers\HSFCCNXTT.sys  
    
    Folder::
    c:\windows\Q29ubmVjdGlvbnM
    
    Driver::
    HSFCCNXTT
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Step 3:
    Run Ccleaner


    Step 4:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt


    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!


    Thanks!
    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds