Please review hjt log file.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by stickman57, Nov 20, 2011.

  1. stickman57

    stickman57 Private E-2

    Thanks to the posted guides, I believe I've gotten rid of a google redirection problem. However, upon further review of the hjt log file, I have some concerns with the logfile 023 items. Hopefully I can get some guidance. My concerns are the windows system files that show up in the log as file missing. I have no idea if these will cause problems and need to be addressed. Suggestions?

    Thank you.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    HJT doesn't read the 023 files correctly in Win7. In fact, HJT is very little used these days. If you want us to check your system for malware, please do the following:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. stickman57

    stickman57 Private E-2

    Aah. I see. Thanks. I believe the malware has been removed.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have problems, let us know. Otherwise, safe surfing. :)
     
  5. stickman57

    stickman57 Private E-2

    Well ....
    I was just informed that the google redirection has returned. How frustrating. 2 days ago ran mbam and spybot and tdskiller. The computer currently has an up-to-date Norton package. I was just following the instructions at the thread "Fixing Google Redirection/hijacking and other redirection problems". TDSKiller found no problem. I don't know if this helps, but I've attached the mbrcheck logfile. I see that it has found some faked mbr code. Drive0 is the system/boot for this Windows7-64 machine.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. stickman57

    stickman57 Private E-2

    Ok. I've gone through all the steps. I've collected the log files. I'll post regarding the results in a few hours. Bottom line is that the search engine redirection is still in control.
     
  8. stickman57

    stickman57 Private E-2

    Ok...

    Problem = search engine redirection from links presented in results.

    I started with the READ & RUN ME FIRST which I follwed to Fixing Google Redirection/Hijacking Problems, then to Vista & Windows 7 Malware Removal/Cleaning Procedure

    After going through the procedures, the problem seemed to have been eliminated. I left the computer on with the Internet Explorer Running for about 12 hours. When I checked it, the redirection problem was back (Oh no!). There was also a popup box asking permission to install something from mevio.com (uh oh), which I canceled.

    This is a Windows 7 64 system.

    Fixing Google Redirect - performed steps 1,2,4,5
    TDSKiller did not detect any malware.
    MBRCheck log attached

    back to READ & RUN ME FIRST
    Norton Business Suite is only antivirus program installed
    No MyWay or Viewpoint installions found
    I was unable to find a way to remove quarantined files
    Did not find any known malware & unwanted software to remove
    Ran defogger, no disk emulation present, but I clicked on Disable anyway

    SUPERAntiSpyware hung 1st time. After removing checks from Direct File & Direct Reg Access, it ran completely and removed bing adware.zugo

    Thanks for your help.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  10. stickman57

    stickman57 Private E-2

    I ran the file BDRemovalTool_TDSS-Clones_64.exe
    Unfortunately the scan completed with 0 files cleaned & 0 infected files.
    Same issue(s) still exist.

    {I like your picture,btw}
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Preferably from a clean computer, I need you to download: gparted-live-0.10.0-3.iso (115.1 MB)
    Windows 7 64-Bit (x64) Recovery Environment

    Create a bootable CD, 1 for Gparted and 1 for the Windows 7 Recovery Enviroment, from the ISO images. You can use ImgBurn do this.

    Now boot off of the newly created Gparted CD.

    [​IMG]
    You should be here...
    Press ENTER

    [​IMG]
    By default, "do not touch keymap" is highlighted. Leave this setting alone and just press ENTER.

    [​IMG]
    Choose your language and press ENTER. English is default [33]

    [​IMG]
    Once again, at this prompt, press ENTER

    You will now be taken to the main GUI screen below
    [​IMG]
    According to your logs, the partition that you want to delete is the 1MB no name partition.
    Click the trash can icon to delete and then click Apply.

    You should now be here confirming your actions:
    [​IMG]

    Now you should be here:
    [​IMG]

    [​IMG]
    Is "boot" next to your OS drive?

    If "boot" is not next to your OS drive under "Flags", right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    [​IMG]

    Now double-click the [​IMG] button.

    You should receive a small pop up like this:
    [​IMG]
    Choose reboot and then press OK.

    Now reboot from the Windows 7 Recovery Environment CD and execute the following commands:


    • bootrec /FixMbr
    • /FixBoot
    • exit


    Once back in Windows.

    Download MBRCheck.exe to your desktop.

    • Be sure to disable your security programs
    • Double click on the file to run it (Confirm the UAC prompt)
    • A window will open on your desktop
    • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
    • If nothing unusual is found just press Enter
    • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
    • Attach that file.
     
  12. stickman57

    stickman57 Private E-2

    Ok.
    I got through the GP with no problem, thanks to your explicit instructions.

    However, I cannot type any windows commands because the console hasn't loaded yet.

    The Recovery CD boot displays the following:
    title bar = System Recovery Options
    buttons = "Repair and restart" and "No"
    wording = Windows found problems with your computer's startup options. Do you want to apply repairs and restart your computer?

    view details:
    Name: Windows 7 Professional (recovered)
    path: windows
    Windows Device: Partition = C:\ (286065MB)
    [similar wording for the Windows Recovery Environment]

    I suppose I need to do "Repair and restart", then again boot from the Recovery CD. BUT, I'm not touching a thing until you read & reply. Thanks.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, this is often the case with this infection. So do the start up repair and let me know how you get on with it.
     
  14. stickman57

    stickman57 Private E-2

    After letting windows do the repair, I ran executed the commands you had give to me, then restarted the computer. It's up & running and does not appear to have any redirection issues. I'll monitor it and let you know. If all is well, then it will be a couple days before my next post.
    Thanks.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like that took care of the infection, but what is this drive:
    149 GB \\.\PhysicalDrive2 RE: Unknown MBR code
     
  16. thisisu

    thisisu Malware Consultant

    @Tim
    It's an external drive. see sysinfo.txt ;)

    Code:
    Description	Disk drive	
    Manufacturer	(Standard disk drives)	
    Model	[B][COLOR="DarkRed"]WD 1600BEV External USB Device[/COLOR][/B]	
    Bytes/Sector	512	
    Media Loaded	Yes	
    Media Type	External hard disk media	
    Partitions	1	
    SCSI Bus	Not Available	
    SCSI Logical Unit	Not Available	
    SCSI Port	Not Available	
    SCSI Target ID	Not Available	
    Sectors/Track	63	
    Size	[B][COLOR="DarkRed"]149.05 GB[/COLOR][/B] (160,039,272,960 bytes)	
    Total Cylinders	19,457	
    Total Sectors	312,576,705	
    Total Tracks	4,961,535	
    Tracks/Cylinder	255	
    Partition	Disk #2, Partition #0	
    Partition Size	149.05 GB (160,039,240,704 bytes)	
    Partition Starting Offset	32,256 bytes	
     
  17. stickman57

    stickman57 Private E-2

    The issue has been resolved. Thanks so very much....
    (Now I've just need to repair some Windows registry issues that the malware must have created.)
     
  18. thisisu

    thisisu Malware Consultant

    What registry issues? I would not tamper with the registry if you are not having any problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds