Redirect and Random Application Shutdown Issues

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fipj, Nov 9, 2011.

  1. fipj

    fipj Private E-2

    Major Geeks Team,

    I had an issue appear a couple weeks ago where it looked as though my hard drive crashed. After some research I found out my computer became infected with something that hid all of my applications/documents, etc. I ran a fix from a link I found on another site. That resolved that issue, but since then I now am having an issue where I am being redirected to other sites when performing a 'google' type search and clicking on the selected site. Applications such as Internet Explorer, Outlook, Excel, etc. also now randomly shut down.


    I have performed the “Read & Run Me First” steps. I have also completed the first 3 steps of the "Vista and Win 7 Malware Removal/Cleaning Procedure". Initially this fixed the problem, but after rebooting my PC the same issues returned. Logs for the following are attached.


    [*]SuperAntiSpyware
    [*]Malwarebytes
    [*]ComboFix
    [*]MGtools


    Please help!

    Regards,

    fipj
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello and welcome. :) You have an MBR infection. Please be warned that you would be wise to back up any important data before proceeding with the next step of attempting to fix your MBR.



    If you don't have your Win7 disc, you can create a Recovery Environment disc for your system here:

    Win7 64bit Recovery Environment

    Win7 32bit Recovery Environment

    You can use ImageBurn to create the disc.

    Once the disc is created, boot into the bios and change the boot order to CD/DVD as first boot device. Put in the disc and reboot. Once in the RE, type this:

    Bootrec.exe /fixmbr

    Note the space after the exe.

    Exit out when done and boot back into normal mode. Re-run MBRCheck and attach the new log.
     
    Last edited: Nov 9, 2011
  3. fipj

    fipj Private E-2

    Hello,
    Thanks for the feedback. So far I have done the following:

    • Backed up my important data.
    • Created a Win7 64bit recovery CD (.iso format).
    • Went into the BIOS to change the boot order. It listed 4 priorities for booting and based on what I saw already had the CD-rom as # 1 in the priority list.
    • Rebooted the PC with the recovery CD in.

    At this point I either missed something in the prior steps or am missing something during the reboot because I cannot get the recovery CD to run. Should this come up prior to Windows startup (similar to when you go into the BIOS) or is this to be run after Windows starts?

    I’m not sure if I have provided enough information to troubleshoot what I am missing, but any assistance you can provide for getting the recovery CD to run is greatly appreciated.

    Regards,
    fipj
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am seeking advice, hang in there.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you have another go at making the CD? Repeat everything again and see if it works this time.
     
  6. fipj

    fipj Private E-2

    Do you know if the data needs to be in a specific format when writing to the CD? I made 2 originally - the first was zipped and the second unzipped in .ISO format. Tried both with no luck. Thanks
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It should not be zipped. What did you use to create the disc? Did you use ImageBurn to create the disc? Are you booting up with the disc in the drive, which should take you to a screen that is blank except for the message to hit any key to boot from the disc?
     
  8. fipj

    fipj Private E-2

    I did not use ImageBurn to create the CD but did everything else previously described. I will start over with creating the recovery CD using ImageBurn to create this time and then try again. Thanks.
     
  9. fipj

    fipj Private E-2

    Hello,

    I recreated the disc using ImageBurn and had better results this time. I was able to get the recovery disc to load. Once in the RE I went to the repair area and selected the command prompt. Once the command prompt opened I input "Bootrec.exe /fixmbr" and then enter (hopefully this is where I was supposed to do this). I expected this to run for at least a minute or two, but it finished as quickly as I hit enter with the message "The operation completed successfully." I then restarted the PC and re-ran MBRCheck. Attached is the latest MBRCheck log.

    Thanks,
    fipj
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are seeing a hidden partition.

    According to what we've read, we need to delete this partition (the one highlighted in red), and THEN, we can attempt to fix the MBR.

    Since I have not seen this first hand, can you tell me if you can see this 1KB partition when you open My Computer and look under "Hard Disk Drives"?

    What about if you go into Storage > Disk Management
     
  11. fipj

    fipj Private E-2

    Don't see the partition referenced. Attaching what I see in disk management. Thanks.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    First, download Download gparted-live-0.10.0-3.iso (115.1 MB)
    You will need a blank CD to burn this ISO to. You can burn the .ISO using software like ImgBurn.

    Now boot off of this newly created CD.

    [​IMG]
    You should be here...
    Press ENTER

    [​IMG]
    By default, "do not touch keymap" is highlighted. Leave this setting alone and just press ENTER.

    [​IMG]
    Choose your language and press ENTER. English is default [33]

    [​IMG]
    Once again, at this prompt, press ENTER

    You will now be taken to the main GUI screen below
    [​IMG]
    According to your logs, the partition that you want to delete is 1,016.00 KB (1,040,384 bytes)
    Click the trash can icon to delete and then click Apply.

    You should now be here confirming your actions:
    [​IMG]

    Now you should be here:
    [​IMG]

    Now double-click the [​IMG] button.

    You should receive a small pop up like this:
    [​IMG]
    Choose reboot and then press OK.

    Now follow the steps in my post # 2 again.
     
  13. fipj

    fipj Private E-2

    Hello,

    I did all steps using gparted-live with no issues. Then went back and did the RE steps (Bootrec.exe /fixmbr). I entered the command using the command prompt option on the third screen (I think third?) and received "The operation completed successfully" again and then rebooted. Note, my PC was not listed in the area where it talked about needing to load drivers if your PC is not listed. When I rebooted the PC was getting hung up in a command prompt type area and would not load Windows. I went back into RE again and this time selected the first option on the third screen (system repair I believe) and it ran through and then restarted the PC (I did not input "Bootrec.exe /fixmbr" this time around). When the PC rebooted Windows did load this time. I then re-ran MBRCheck. Attached is the most recent log. I also tried search sites and at the moment am not being redirected. If there are further steps to be taken, please let me know. Thanks for all of your assistance thus far.

    Regards,
    fipj
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good job, that seems to have taken care of it. Let Kes know if you have any more issues. ;)
     
  15. fipj

    fipj Private E-2

    Thank you both! I really appreciate the assistance. Kes, thanks for walking me through this process step by step and for your quick replies. Hopefully the headache and frustration is behind me, but won't hesitate to let you know if the issue rears its ugly head again. Thanks again! fipj
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can thank Thisisu for the clear and easy to follow steps, he created those. I am glad it worked for you. :) I still need to review the rest of your logs though, but will not get chance to do this until tomorrow evening now. I have just finished a shift at the bar, and it's late.

    Please make a response to this, any kind of response to let me know you recieved my reply and then it will appear in my subscribed threads as one I need to look at.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\{6132F318-293F-43B9-866F-2ED6A2A19608}
    C:\ProgramData\{0BA93836-BC46-4268-B5B7-7C67A4C2A7E8}
    File::
    C:\vseqrntn.bin
    C:\ProgramData\~6DSS92c31Apgjk
    C:\ProgramData\~6DSS92c31Apgjkr
    C:\Users\Jason\Local Settings\TEMP\2147483647.dat
    Registry::
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  18. fipj

    fipj Private E-2

    All set with the last set of instructions - no problems encountered during the process. Do you need to review those logs as well? Thanks.
     
  19. thisisu

    thisisu Malware Consultant

    Yes, please attach them.
     
  20. fipj

    fipj Private E-2

    Here you go...
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below:

    • CyberDefender Early Detection Center
    • CyberDefender Link Patrol

    Delete this folder.
    C:\{6132F318-293F-43B9-866F-2ED6A2A19608}

    Delete this file.
    C:\ProgramData\6DSS92c31Apgjk

    Reboot, has the file and folder definately been deleted?

    If so you can follow final steps. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  22. fipj

    fipj Private E-2

    I have uninstalled the following:

    CyberDefender Early Detection Center

    I have deleted the following:

    Delete this folder.
    C:\{6132F318-293F-43B9-866F-2ED6A2A19608}

    Delete this file.
    C:\ProgramData\6DSS92c31Apgjk

    I have unsuccessfully attempted to uninstall the following 3 times (rebooted after each attempt).

    CyberDefender Link Patrol

    The first time I tried to delete it tried to have me download something, but I canceled out of it instead.

    Any ideas for uninstalling a program that keeps rising from the dead?

    Funny thing about this particular program is that I was actually attempting to purchase Malwarebytes and an ad for this was on the screen and I mistakenly purchased this instead of Malwarebytes. :cry
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    :-D Try this.

    Try Revo Uninstaller. http://majorgeeks.com/Revo_Uninstaller_d5706.html
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.
     
  24. fipj

    fipj Private E-2

    Thanks! I ran Revo Uninstaller and it FINALLY appears to be gone now. :celebrate

    I have a couple more issues to run by you before I move forward with the final steps as I don't know that I'm quite in the clear yet.

    I have a missing .dll error that is coming up each time I boot up (started after I ran Gparted Live and the Win7 repair. I have run Norton Utilities registry repair/cleanup, but haven't been able to fix the error message. Any suggestions for fixing this error?

    An even bigger issue (I think) that I learned of last night from some family members. I recently switched email addresses from AT&T (home service only - not cell phone) to Comcast. The AT&T account was recently closed, however, the email account still works. A couple family members said that they received spam emails from my AT&T email address yesterday. So it appears that my old email address was somehow hijacked. I don't even know how many people received these bogus emails from my old email address as it doesn't appear to be linked to my current contacts list. My current contact list is very limited (only 2 contacts). One of the people who received the emails isn't in my current contacts list, but I have sent/received emails from that person before. Is this related to the MBR infection or is this something different? Any idea how to clear this up and prevent it from occurring going forward?

    Appreciate it.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, you would need to give me the exact word for word error and name of the .dll. ;)
    This is something you would be better off informing AT&T about.
     
  26. fipj

    fipj Private E-2

    Error message attached. Thanks.
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Again, something to ask about in the software forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds