IE Opening on it's own, WMP Streaming on it's own, ect.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DriverDerp, Nov 21, 2011.

  1. DriverDerp

    DriverDerp Private E-2

    Hi I recently have contracted an unknown dilemma of Firefox redirecting searches of its own volition, and Media player and IE opening of their own accord to things like twitter, and facebook trying to capture my log in, after following the Read and Run I am now at this step.
    And even though I followed everything to the letter the logs are missing, and this minor annoyance has now become a major headache.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Did you have any problems trying to run the procedure? Did you run all 5 of the below scans?
    1. SUPERAntiSpyware
    2. Malwarebytes Anti-Malware
    3. ComboFix
    4. RootRepeal
    5. MGtools
    If yes, look for the C:\combofix.txt and C:\MGlogs.zip files from running ComboFix and MGtools and attach them.

    Also look on your Desktop for the log from RootRepeal.
     
  3. DriverDerp

    DriverDerp Private E-2

    All Programs ran without fail, but all that I apparently have are the MgLogs.
     
  4. DriverDerp

    DriverDerp Private E-2

    My apologies I forgot to hit upload.
     

    Attached Files:

  5. DriverDerp

    DriverDerp Private E-2

    I have ran searches for the files as they are listed I have also gone and checked the program directories for logs they are not there, though something in the read me helped I am no longer getting audio attacks, nor is WMP opening and trying to stream media. The IE seems to only goto certain sites as follows : Twitter, A Facebook Page, and Amazon which leads me to believe it is Phishing for information. Firefox will redirect through only one website which at the moment it appears not be since I switched over to chrome as my primary browser which seems to be unaffected entirely. Since I cannot supply logs I figured it would be best to be as detailed as possible I did not run RootRepeal as I am on x64bit. Thank you for your assistance in advance.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your logs, SUPERAntiSpyware was not even installed.

    Also ComboFix appears to have had some kind of problem because it never finished running. Didn't you notice any problems while running it?





    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Please also download MBRCheck to your desktop.




    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
    The log from Malwarebytes is the below file
    Code:
    C:\Users\Oni\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2011-11-18 (15-54-37).txt
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on what I see in your log from MGtools, it looks like you have one of the new TDL4/Zero Access infections going around that adds an infected partition to your hard disk.
     
  8. DriverDerp

    DriverDerp Private E-2

    Logs as requested~
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Preferably from a clean computer, I need you to download the below files:
    Now from these ISO image files create two bootable CDs. One for Gparted and one for the Windows 7 Recovery Enviroment. You can use ImgBurn do this.

    Now boot off of the newly created Gparted CD.

    [​IMG]
    You should be here...
    Press ENTER
    [​IMG]
    By default, "do not touch keymap" is highlighted. Leave this setting alone and just press ENTER.
    [​IMG]
    Choose your language and press ENTER. English is default [33]
    [​IMG]
    Once again, at this prompt, press ENTER
    You will now be taken to the main GUI screen below
    [​IMG]
    According to your logs, the partition that you want to delete is 1.70 MB (1,785,856 bytes)
    Click the trash can icon to delete and then click Apply.
    You should now be here confirming your actions:
    [​IMG]
    Now you should be here:
    [​IMG]
    [​IMG]
    Is "boot" next to your OS drive?
    If "boot" is not next to your OS drive under "Flags", right-mouse click the OS drive while in Gparted and select Manage Flags
    In the menu that pops up, place a checkmark in boot like the picture below:
    [​IMG]
    Now double-click the [​IMG] button.
    You should receive a small pop up like this:
    [​IMG]
    Choose reboot and then press OK.


    Now reboot from the Windows 7 Recovery Environment CD and execute the following commands:
    • bootrec /FixMbr
    • bootrec /FixBoot
    • exit
    Once back in Windows continue with the below instructions.

    Please rerun MBRCheck and attach the new log.
     
  10. DriverDerp

    DriverDerp Private E-2

    Currently BootMgr is missing, and I am having to reboot
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run both of the below commands

    bootrec /FixMbr
    bootrec /FixBoot
     
  12. DriverDerp

    DriverDerp Private E-2

    Yes it was resistant to accepting them being entered from the command line so I had to use the fix windows startup automated button to get it to take. MBRcheck log as requested
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your MBR looks good now. So how are things working.
     
  14. DriverDerp

    DriverDerp Private E-2

    Excellent things, aren't opening up browsers aren't redirecting, feels good.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds