Malware issues/ popups redirects

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bignich49, Apr 30, 2011.

  1. bignich49

    bignich49 Private E-2

    Hello, I got some malware that resulted in my most of my desktop icons, all pictures and documents going missing. Also I get google redirects to the point I can't search at all.

    I read all the steps here to take and didn't skip any although some didn't work. Where I got so far was, I got my icons back and pic and doc files but they are like ghost images. The were hidden files that I was able to access.
    I still get ruthless popups in the for of "a scrip error has occured" bla, bla, bla,
    and chronic google search redirects where I can't search at all. I also get page redirect popups.

    I have tried to use "hijack this" but am running Vista and can't remove anything in my registry. It says to run as "admin", I've tried to but maybe don't know how to fill out the dialog boxes correctly. So Hijack isn't doing me any good.

    I have gone to an earlier restore point to get to my 'puter to at least work where before all I had was a black screen with a fake hard disc error report. I also did a clean up, and Spybot scan and came up clean.

    So help me be able to run Hijack this, as I think I can fix the other issues. Any help in the right direction will be appreciated.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. bignich49

    bignich49 Private E-2

    Ok, re: Fixing Google Redirection/Hijacking Problems
    Trying to flush the DNS cache.
    I get a message, "OPERATION REQUIRES ELEVATION"

    How do I get around this? I am the only user on this computer, bought it brand new at Best Buy.

    another thing, in step 4, the link TDSSKiller does not work, all I get is a blank page.


    TIA
     
    Last edited: Apr 30, 2011
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on.

    Try using the instructions in the below link instead:

    TDSSkiller - How to run
     
  5. bignich49

    bignich49 Private E-2

    Downloaded TDSSKiller to desk top tried to run as Admin, wouldn't do anything. Changed the name to fun.com, clicked to run and got blue screen and a crash, twice in a row, then clicked to delete, crashed again.

    Ran SAS, yielded 99 issues, removed and quarentined.

    Still pop ups, less frequent though and google is inoperative because of constant redirects.

    now what?

    TIA
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Move TDSSKiller to your C: drive. You will need to have your installation cd so that you can boot into the recovery console. This will require that you first boot to the bios and change the boot order to cd/dvd drive as the first boot device. Put in your CD and boot. Go into the recovery console and type in:
    fixmbr.

    Reboot to normal mode and see if you can then run TDSSKiller.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's already on the C drive Tim. ;)

    bignich49,

    What Tim meant to say was to move the TDSSKiller.exe file to the root folder of your C drive so that you have C:\TDSSKiller.exe which can be accessed from the System Recovery Environment of Vista.

    Also you need to finish ALL of the instructions in READ & RUN ME FIRST. Malware Removal Guide and attach the logs we asked for. We are still waiting for them. You said you ran SAS but you did not attach a log.
     
  8. bignich49

    bignich49 Private E-2

    How do I move TDSSKiller to C root drive? It's on my desk top. I'm attempting to run it as Admin, I checked the box. I changed the file name, then the extension to .com, when I click the icon on my desktop all I get is a dialog box asking for permission to run, I click OK, then a quick flash, nothing else. The program wont open.

    What I've done:
    ATF Cleaner
    Flushed Java Cache
    Rebooted DSL modem router
    Downloaded TDSSKiller
    unchecked tea timer on SBSD
    downloaded SAS and run several times (latest 1 adware found)
    Defogger.exe
    Malwarebites Anti-Malware, run (no threats found)
    MG Tools.exe
    Root Repeal.exe

    I've restarted 'puter several times, still have redirect problems with Google and Bing

    I still can't getTDSSKiller to run.


    spent over 3 hours today alone.

    What now?

    TIA
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Forget moving it for now. Since you last posted, a new version of TDSSKiller.exe has come out that runs successfully against these TDL infections. Redownload it and run it again following the instructions in the below link:

    TDSSkiller - How to run
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still did not attach the logs!!!!!!!
     
  11. bignich49

    bignich49 Private E-2

    I'll work on attaching the logs.

    I downloaded the 'killer just a couple of hour ago and all I get when clicking it is a "user account control" dialog box that I click OK, then a quick flash and nothing. I'm running it as Admin, and have changed the name to a .com extension.

    BTW for the last week or so I continually get popups, "an error has occured running scripts...."

    What now?
     
  12. bignich49

    bignich49 Private E-2

    Here's a log
     

    Attached Files:

    Last edited by a moderator: May 12, 2011
  13. bignich49

    bignich49 Private E-2

    another log from today
     

    Attached Files:

    • SAS.txt
      File size:
      9.7 KB
      Views:
      1
    Last edited by a moderator: May 12, 2011
  14. bignich49

    bignich49 Private E-2

    Sorry, correction, from today

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 05/09/2011 at 02:03 PM

    Application Version : 4.52.1000

    Core Rules Database Version : 6977
    Trace Rules Database Version: 4789

    Scan type : Quick Scan
    Total Scan Time : 00:08:49

    Memory items scanned : 599
    Memory threats detected : 0
    Registry items scanned : 2234
    Registry threats detected : 0
    File items scanned : 10888
    File threats detected : 1

    Adware.Tracking Cookie
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@adserv.brandaffinity[1].txt
     
  15. bignich49

    bignich49 Private E-2

    another
     

    Attached Files:

    Last edited by a moderator: May 12, 2011
  16. bignich49

    bignich49 Private E-2

    First scan a few days ago showing removed items
     

    Attached Files:

    Last edited by a moderator: May 12, 2011
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Last edited by a moderator: May 10, 2011
  18. bignich49

    bignich49 Private E-2

    I got the MGtools log, but I can't get the Combofix to run. When I try to download it, I get a popup, click on it and get a blank screen, nothing happens. Ideas?
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your Newfiles.txt was empty. Download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe and get me a new C:\MGLogs.zip.
     
  20. bignich49

    bignich49 Private E-2

    MGtools log file attached

    Thanks, appreciate all the help you're giving me and your patience.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log still did not populate any info.

    Download OTL by Old Timer. and save it to your Desktop.

    * Double click on OTL.exe to run it.
    * Under Output, ensure that Minimal Output is selected.
    * Under Extra Registry section, select Use SafeList.
    * Click the Scan All Users checkbox.
    * Click on Run Scan at the top left hand corner.
    * When done, two Notepad files will open.
    o OTListIt.txt <-- Will be opened
    o Extra.txt <-- Will be minimized
    * Please post the contents of these 2 Notepad files in your next reply.
     
  22. bignich49

    bignich49 Private E-2

    Wondering why you cannot see the contents of the MBToolsZip file?
    It works for me. Did I not post the link correctly? Is there another way like copy and paste or ???

    Here are the others you asked for, hope these work for you, they did for me.

    Thanks again for all your help.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The zip opens fine, it is the NewFiles log that is empty again.

    Download OTM by Old Timer and save it to your Desktop.


    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.


    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\ProgramData\jFe01843fGgKm01843
    C:\ProgramData\~38854408
    C:\ProgramData\~38854408r
    C:\ProgramData\38854408
    
    :Commands
    [purity]
    [ResetHosts]
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach that document back here in your next post.

    Tell me what malware issues you are still having, if any.
     
  24. bignich49

    bignich49 Private E-2

    Log results

    All processes killed
    ========== PROCESSES ==========
    No active process named explorer.exe was found!
    ========== FILES ==========
    C:\ProgramData\jFe01843fGgKm01843 folder moved successfully.
    C:\ProgramData\~38854408 moved successfully.
    C:\ProgramData\~38854408r moved successfully.
    C:\ProgramData\38854408 moved successfully.
    ========== COMMANDS ==========
    C:\Windows\System32\drivers\etc\Hosts moved successfully.
    HOSTS file reset successfully
    Restore point Set: OTM Restore Point

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 56502 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Nick
    ->Temp folder emptied: 433779 bytes
    ->Temporary Internet Files folder emptied: 1265755809 bytes
    ->Java cache emptied: 53192 bytes
    ->Flash cache emptied: 206673 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 15706 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 2936317 bytes
    RecycleBin emptied: 1633652 bytes

    Total Files Cleaned = 1,212.00 mb


    OTM by OldTimer - Version 3.1.17.2 log created on 05132011_191946

    Files moved on Reboot...

    Registry entries deleted on Reboot...


    Hope you can see one of these.

    I still get a redirect every time I use google search or bing. Also get "script error" pop up boxes every minute or so.

    Thanks, sounds like a tough fix, I'll keep going, thanks for your help!
     

    Attached Files:

  25. bignich49

    bignich49 Private E-2

    Still have redirect every time I use Google search. Script error pop up boxes don't seem to happen any more.

    Making some progress.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your Vista install cd? Since you can't get TDSSKiller to run, we may need to have you boot into the Recovery Environment to try to do a fixmbr.

    If you don't have your disc, do this:
    Vista and Win7 Recovery disc

    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr, and then press ENTER.

    Reboot into normal mode and tell me if you are still being redirected.
     
  27. bignich49

    bignich49 Private E-2

    I followed your instructions explicitly. Typed "bootrec.exe/fixbr", got a few paragraphs of info, then prompt again.

    I closed the program and started in normal mode.

    I still get script error popups btw, at startup and more or less depending upon what I'm doing. Also first time doing a google search, a redirect as before.

    Maybe I'll try again.

    I also tried to download 'Killer a few times and execute it but I can't get it to run.

    A script error popup I got just now was from: http://celebrity-gossip.net/sites/all/modules/web_widgets/iframe/web_widgets_iframe.js

    I don't know where they come from by I can't do anything when the box pops up. Should I choose "keep running scripts" ? or what? or just click the X?

    Anyway what next?

    TIA
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you put the space in between the exe and the / ?? It should be:
    bootrec.exe space /fixmbr

    You can try troubleshooting the script errors HERE.
     
  29. bignich49

    bignich49 Private E-2

    Forgot the m in fixmbr and gave it the space. Message after hitting enter, "Fixed successfully".

    Unfortunately still have the redirect issue.

    I'll try your link on the script popups.

    Any other ideas?

    TIA
     
  30. bignich49

    bignich49 Private E-2

    Got it fixed!

    After creating and running a recovery disc I was able to run combofix. I ran it and it cleaned up some problems but also wiped out my local drivers for my DSL internet networking. I couldn't get online, tried everything I knew, then used system restore and went back as far as I could pre infection date. Everything is perfect now. First thing I tried was a system restore pre infection date before getting on this forum, didn't work then.

    Thanks for all your help!
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know you got it fixed. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds