IE Hijack, F Drive Hijack, No Firefox

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SEGA, Mar 17, 2011.

  1. SEGA

    SEGA Private E-2

    Hey guys. Really having problems with this comp.

    Problem 1: Internet Explorer will not visit most anti spyware sites, or any microsoft site. This includes updates, etc. Some other sites, such as Mega Video are also affected.

    Problem 2: Google constantly (not ALWAYS) redirects to fastsitesearch or some other crappy search site.

    Problem 3: Firefox refuses to startup. Always says that Firefox has had a error and needs to restart. Never actually starts up.

    Problem 4: Not sure if this is related to the others, but whenever I connect an external sd drive (micro sd usb adapter) a whole bucnh of crap appears on the card. Couple of shortcuts and a RECYCLER folder, wich has a load of files with corrupted images inside. They do delete, but they come back after a while.

    I have tried to follow your steps.

    However, only Superantispyware and MGtools will download. The rest come up as 'Connection Problem' with a box underneath saying 'Diagnose Connection Problems'. I've included the log from Superantispyware, but everytime I run MGtools, the computer restarts (?).

    Task manager still works, msconfig works, ditto services.msc

    Spybot comes up clean, Smitfraudfix doesn't do anything even in safe mode and Trojan Remover comes up with the same virus everytime, even after restarting. STOPZILLA comes up with a load of viruses, but then asks for payment.

    Not sure what to do any more, as I can't download the other programs you recommend. Any help would be appreciated, as the two shops I've taken this to have no idea.

    EDIT: when I say smitfraud doesn't do anything, I mean it runs and cleans and resets the desktop but other than that........nothing seems to change.
     

    Attached Files:

    Last edited: Mar 17, 2011
  2. SEGA

    SEGA Private E-2

    Sorry I forgot to mention, my systems specs....

    EDIT: Eh? What happened to my first post? It's not showing up....
     

    Attached Files:

    Last edited: Mar 17, 2011
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.

    In addition to the other remaining scanner logs we need from running READ & RUN ME FIRST. Malware Removal Guide , please do this:

    Please download TDSSKiller.exe and save it to your Desktop. <-Important!!!
    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Click the Start Scan button.
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • Do not use the computer during the scan
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    In addition to what dr.moriarty has ststed

    See this and reset your Proxy settings to see if it helps >> Proxy Server - Changing Settings


    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    nwktst <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Now does the C:\MGlogs.zip file exist? If yes, please attach it.
     
  5. SEGA

    SEGA Private E-2

    Ok I don't have access to another pc at the mo. Tomorrow I'll try and get access.


    Thanks for welcoming me guys!


    BTW Chaslang....

    GetRunKey comes up with a load of:
    mgtools\swreg is not recognized as a command or batch file
    cannot load vdm ipk spx support
    temp\xlmint2.txt No such file or directory
    addingrun keys.txt 100 bytes security <79% deflated>

    ShowNew comes up with more commands, no error messages adding files, finding copies, etc

    NWKTST comes up with mgtools\swreg is not recognized,


    The proxy settings are unchecked. I'm using WirelessZeroConnection.

    Also CCleaner comes up as clean.
    And Conficker Removal Bot does as well.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not disable Spybot's Teatimer as requested in the READ & RUN ME. Please do this now. See this: How to disable Spybot's TeaTimer

    I will look at the logs you do have now.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How are you connecting here? Is it with the infected PC?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be best to start with running TDSSkiller as dr.moriarty suggested. Your logs from MGtools do not show much. Only that you should delete the below folder:

    C:\Program Files\vhpqohgy

    And also delete the below files.
    C:\DealioAu.log
    C:\StubInstaller.exe


    Also you did not uninstall the old Sun Java versions and update a requested but I assume this is due to having connection issues?

    What antivirus program are you using? I don't see any.

    I suggest that you uninstall StopZilla.
     
  9. SEGA

    SEGA Private E-2

    Hi again.

    Ok guys, here's the logs you wanted. I disabled tea timer and updated java and uninstalled old java as well. I also downloaded AVG from another comp as well.

    Spybot used to say there were 101 Global hosts it cannot remove.
    Also, aftre running Malwarebytes, the windows updates exclamation mark came back on.
    But.....left the comp alone for an hour running Rootrepeal, and now it's gone again. Websites are still blocked.

    Cannot delete C:\Program Files\vhpqohgy
    It says the directory is not empty. (?)

    BTW. other than AVG, no I have no Antispyware such as Norton or Symntec.

    Uninstalled Stopzilla. Yeah I can use the infected PC to connect to this website, but any microsoft sites are still blocked.
     

    Attached Files:

  10. SEGA

    SEGA Private E-2

    UPDATE: Again, the virus seemed to be gone as access to Microsoft.com sites was possible. Installed AVG Free edition and Microsoft security essentials. Ran both of them, they found viruses, had to restart computer, etc.

    HOWEVER, yet again upon restarting, sites revert back to being blocked. Every 5 minutes, Avg pops up with threats like win32/Zbot and VBS/generic etc. Certain threats it can't delete because they're inactive (?)

    And Microsoft Security Essentials detects threats, and then 'cleans' them. But then it finds another one in another five minutes. Suggests restarting computer. REstart comp, no difference.

    Also checking Task manager, everytime I restart, IE processes are already active before I've even opened it.

    Should I run the others again?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's be safe and run the below fix.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).
    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. SEGA

    SEGA Private E-2

    I ran combofix. Had to uninstall AVG, because I couldn't stop it from running, everytime I tried task manager it just told me I couldn't close the operation, access was denied. Here are the two logs anyway:
     

    Attached Files:

  13. SEGA

    SEGA Private E-2

    srry to double post, you wanted me to tell you how things are working now. Well, Microsoft sites seem permanantly unblocked, and things appear to be relativly normal. Some minor things, like two msmpEng processes will start up and slow comp, and the AppleMobileDevice process never goes away, even when I end the process.
    Other than that....seems fine. IE sometimes crashes when loading some sites. Can you recomend any way to increase comp performance?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your ComboFix logs and MGtools logs are still very incomplete. Did you see any errors while running them? Did you have AVG uninstalled before running ComboFix?

    You should not have even had AVG installed. You already have Microsoft Security Essentials installed and running which is why you see the msmpEng process you mentioned. The AppleMobileDevice is a service from your Apple software. You cannot stop services. If you don't want it to run, you will have to uninstall the software and then check to see if they have an option not to install as a service. Software will sometimes install as a service so that restricted user accounts will be allowed to run the software ( like antivirus programs ).

    It looks like you may have Spybot's Teatimer running so please goto Add/Remove Programs and uninstall Spybot for now.

    Now please shutdown Micosoft Security Essentials.

    Please go to the C:\MGtools folder with Windows Explorer. And double click on analyse.exe Does a license agreement from TrendMicro HijackThis show up? If yes, you must click the Accept button twice ( yes twice ) to get it to run. When it runs just select the option to Do a system scan and save a log. Then exit the program.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
     
  15. SEGA

    SEGA Private E-2

    Ok, sorry about long reply again. Here is the MGtools file run this time with no AVG, No spybot, and no Microsoft Security Essentials.
    BTW the My Computer and Recycle Bin have disapeared from the desktop. Do you know why this is?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really sure. It could be because ComboFix never finished running properly due to still having Microsoft Security Essentials still installed. See if you can just reenable MyComputer by right clicking on your Desktop and select Properties, Desktop, and then the Customize Desktop button. Then make sure you have selected to show MyComputer on the Desktop.


    We have a little more minor cleaning to do.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. SEGA

    SEGA Private E-2

    ok done as asked. Things do seem ok now, and you were right, the My computer checkbox was unchecked. How do you get the desktop items to order themselves tidly again?

    Also, do you have any tips to improve pc performance? I mean, it's good as it is, but I may not be taking advantage fully of it. Anything I should be doing? (barring any hardware modification such as overclocking, etc.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A topic better discussed in the Software Forum, but first order of business would be to uninstall anything you don't use and then remove all unnecessary startup programs ( you have to figure this out for yourself since we don't know what you use or don't use. Your needs are different than ours. ;) ).



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  19. SEGA

    SEGA Private E-2

    Sorry it took me so long to reply. I've been away.
    Judging by some of those logs, other people been using this PC as well.....


    BTW one last funny thing: whenever I type in Yahoo.com in address bar, it always redirects to the
    http://nl.yahoo.com/?p=us, which is the Netherlands version of the site. Do you know why this is? Hopefully not more malware....


    Anyway, here's my final list, after rescanning everything.






    Btw chaslang, You and the other guys here are real soldiers. You must get thousands of malware help requests, and how you must smile everytime you see a log that says something like ' deleted pornotube', and then people claim they have no idea. No idea at all how that got on there.

    Really appreciate the the work you guys are doing bro. You're the REAL internet heroes.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I don't understand why you are attaching new logs. I did not ask for more scans. My last message said you were all clean and gave you final instructions to remove all unnecessary tools and logs. Did you not complete the final instructions during the last13 days? And did new problems come up?
     
  21. SEGA

    SEGA Private E-2

    Well.....like I said, going to yahoo.com always redirects me to the netherlands version of the site. And I can't seem to access my modem at the default router address.
    I wanted to check if there was any extra traffic using it, but it looks like I can't access it at all for some reason..
    Also.....I installed AVG PC tune 2011 and AdvancedSystemCare, and ran them both. They both said I had thousands of registry errors and they would fix them/optimize pc for me. However pc is slightly slower now. Do they actaully do anything? or are they just more fake malware?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Reset it to factory defaults and see what happens.

    You need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.


    Very bad idea and we highly recommend against using registry cleaners and system tweakers. They can frequently cause more harm then good. And as you noticed, it did not improve performance.

    No they are not malware. They are just hyped up programs you don't need. In the hands of an expert who selectively knows what to do with them rather than letting them just do everything, there could be some use. But this is normally to try and fix very specific problems.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are still being redirected after resetting your router back to factory defaults, do the below.


    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )



    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
    Last edited: Apr 16, 2011
  24. SEGA

    SEGA Private E-2

    Uploaded those two files you asked for.

    BTW, I uninstalled those registry cleaner thingys. However, now messages pop up saying Windows Explorer needs to close, and Dr Watson Post Mortem Debugger (? I never installed this) needs to close. A few Data Execution Preventions pop up as well. Then Windows likes to enter suuuuuppperr slow mode.


    They're not too frequent, every 3 or 4 hours or so.

    But still......

    edit - oh and I can access my modem now. the ip address is some random 2.216 number....
     

    Attached Files:

    Last edited: Apr 16, 2011
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have your Windows XP boot CD so that we can use it to rewrite your Master Boot Record?

    Also do you have all of your important data backed up which you should have before fixing the MBR?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds