Browser Hijacker

Discussion in 'Malware Help (A Specialist Will Reply)' started by Infected, Dec 30, 2008.

  1. Infected

    Infected Private E-2

    Haven't been able to get rid of a browser hijacker for quite some time... any google search redirects the links from my search results to sights such as "lowpriceshopper.com", etc.

    Tried many different AV/malware programs with no success.

    Finished the run me first steps to my best ability, and here are the logs. I believe the only step I overlooked is to empty my quarantine folders... hope that doesnt mess anything up.

    Also, I'm still running xp with SP1, which I'm sure might be the cause of my infection. Perhaps after this is all completed, I could try to install SP2 again (with assistance). I've never been able to sucessfully install it.
     

    Attached Files:

  2. Infected

    Infected Private E-2

    last log
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    Kestrel13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    1) Important Notice: A new version of SUPERAntiSpyware is out. The version you are running is outdated.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later
      [*]


    2) Please go to Add or Remove Programs and uninstall the following softwares:

    • SpywareBlaster v3.5.1 <--- This is now outdated. Visit this link here to get the latest version SpywareBlaster 4.1 and install it after uninstalling the old version and rebooting your machine.
    • Spybot - Search & Destroy 1.4 <--- Outdated.



    3) Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    Driver::
    vwyldnag
    
    NetSvc::
    hqghxavd 
    
    File::
    c:\windows\SYSTEM32\tmp7731A.FOT
    c:\windows\System32\drivers\timmhfhz.sys
    
    
    
    DirLook::
    C:\WINDOWS\system32\EV19
    
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"=-
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    4) Your desktop is dis-organised... a messy desktop provides an ideal place for malware to hide. I would advise you to do a tidy up.



    5) Now Run Ccleaner!

    6) Now install Microsoft .NET Framework 1.1

    7) Now goto this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    8) Run the new MGTools.exe and attach the MGLogs.zip it generates

    9) Also attach the log from Combofix please.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  5. Infected

    Infected Private E-2

    Here ya go... only problem, combofix initially told me it was expired, so I had to install the newest version before proceeding.

    Google search does seem to be working normally... :wine
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Now we need to use ComboFix to remove some malware

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    
    Drivers::
    hqghxavd 
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    2) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  7. Infected

    Infected Private E-2

    Here are the newest requested logs.

    BEFORE I ran these 2 programs, the browser hijack problem had returned.

    AFTER these 2 scans, google is working properly again.

    NOTE: Combofix froze up my computer after step 50 (i needed to turn off my computer and reboot) but a log WAS produced. If you need me to run again, please let me know.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry for the slight delay, we have been extremely busy.


    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now tell me how things are running.
     
  9. Infected

    Infected Private E-2

    Here's the avenger log.

    As of right now the browser hijacker is still active. Google is not working properly after the scan.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) OK, let's see if we've nailed this now.

    We have to use Combofix again:- but you need to download the new version. Uninstall the combofix you have following the instructions below:

    Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    "%userprofile%\Desktop\combofix" /u

    Notes: The space between the combofix" and the /u, it must be there.
    This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    Delete the C:\combofix folder from combofix (if it exists)


    Then hit the below link and scroll down until you see Combofix to download the newest version.

    Windows XP Cleaning procedure

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    File::
    C:\Windows\system32\wdmaud.sys
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux4"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    2) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger or Combofix

    3) Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Thanks
    Kes
     
  11. Infected

    Infected Private E-2

    Thanks for the continued assistance.

    Attached are the requested logs.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome! :)


    Your logs look good. Just a couple of miscellaneous things to take care of...

    1) We need to use Combofix one more time:



    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    Folder::
    C:\WINDOWS\system32\EV19
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    2) I see some McAfee remnants in your logs.

    Please download the McAfee Consumer Product Removal Tool

    Run this > Reboot your machine > and Run it again to get rid of remnants of McAfee.

    3) You only have Service Pack 1 installed, if you are hesitant about installing SP3 you should at least ensure you have SP2


    4) I want to emphasize how important it is to get this PC updated. In the future we will not fix PCs that have not been updated since it is causing too much work for us when people do not properly protect their PCs as our instructions require.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  13. Infected

    Infected Private E-2

    1) ran combofix
    2) THANK YOU, been wanting to get rid of that leftover McAfee junk for years. One issue: I ran the prog, rebooted, and ran again like you said... on the 2nd run, i get the error message "cleanup failed, cleanup is already running".
    3) Thanks for mentioning service packs also. As I stated on my first post, I've tried to get SP2 multiple times, but it never installs correctly. Can I go straight to SP3 without ever getting SP2? And why would I be "hesistant" for SP3? Are there issues with it? Would love to attempt to install either with your guidance (if you have the time).
    4) If you need any final logs, let me know... computer seems clean for now, but I've been fooled before ;)
     
  14. Infected

    Infected Private E-2

    ... guess we should hold off on my post below, because unfortunately the hijacker is back again... :mad
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are infected again, then please attach the 4 requested logs.
     
  16. Infected

    Infected Private E-2

    With all due respect, I don't think it was ever fully removed. :confused

    Attached are the logs; 4th one coming next post.
     

    Attached Files:

  17. Infected

    Infected Private E-2

    4th scan
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    You are out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.


    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.


    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • the new SUPERAntiSpyware and Malwarebytes logs.
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    No you need to have SP2 to upgrade to SP3. No there are no issues with using SP3 and infact you really should have the most current version to address a security issues. Problems with installing SP2 and SP3 should be addressed in the Software Forum.
     
  19. Infected

    Infected Private E-2

    Hey Chas, I believe you helped me last time I had an issue a couple years back... thanks for 'stopping by' to assist again!

    Here are the logs, one more to follow. Only mistake I made was installing the new mgtools to my desktop, rather than copying over... hopefully it didn't effect the results.

    Also, combofix gave me the blue screen of death after it completed running. It did produce a log, however.
     

    Attached Files:

  20. Infected

    Infected Private E-2

    4th log
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log is very incomplete but the other logs seem to indicated everything we want to remove was removed.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
      • Delete the C:\Qoobox folder from combofix (if it exists)
      • Delete the below files from ComboFix failing to finish running:
        • C:\WINDOWS\SYSTEM32\CF17936.exe
        • C:\WINDOWS\SYSTEM32\CF17946.exe
        • C:\WINDOWS\SYSTEM32\CF18057.exe
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  22. Infected

    Infected Private E-2

    The browser hijacker is still very much active.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where are you being hijacked to and does it happen in both FireFox and with IE? I think the reason you are having problems like this and like you had last time is because your system is not updated.


    You are going to have to get me a full ComboFix scan so to make sure the reason was not due to software your are running. Uninstall a-squared (too many false positive issues with this program anyway) and then shutdown AVG7 and run ComboFix and attach a new log. You may have to download a new version of ComboFix first since your copy may be ready to expire.

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.



    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
    Also please do one more thing. I assume you have a router? Follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup. After doing this, do you still have problems?
     
  24. Infected

    Infected Private E-2

    1) yes, the problem exists in both IE and firefox. Search results redirect me to sites like: findlinks.com, areaconnect.com, antivirus-scan.com, and dozens of other random .com's.

    2) I do have a wireless router, but it's not hooked up, and I haven't used it in months. If there's software I should uninstall that's a security risk, please advise.

    3) browsers working fine at the moment, but they always do immediately after I run the scans. Then the bug will reattach/reinstall/recreate itself (or whatever the correct term is), and I'm frustrated again.

    4) combofix ran fine this time... logs attached.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Part of this last infection from wdmaud.sys are still there. Let's try again to finish removing it.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  26. Infected

    Infected Private E-2

    Can't run combofix ... after dragging the CFscript.txt file onto the CF icon, i get the error message: "prep.com has encountered a problem and needs to close".

    I tried deleting my old combofix and redownloading, but still get the same error message. Any thoughts?

    Oh, also one last note... I don't have audio on my PC, haven't for a while. Probably a symptom of the same bug (attacking my audio drivers?) Just figured I'd mention, since I don't think I brought it up previously.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's try using Avenger which you previously downloaded.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  28. Infected

    Infected Private E-2

    Had to re-dl avenger, but here are the logs requested.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that deleted what we wanted.

    You did not tell me how things are working. Your logs are clean.
     
  30. Infected

    Infected Private E-2

    Everything seems fine (crossing my fingers that nothing will 'pop' back up).

    There is one exception... I still have no audio. Would you happen to know how to reinstall the driver this bug seemed to knock out?

    Also, of course, after we're through here, I also need assistance installing SP2. I believe you mentioned the Software Forum here could help? I've had no success in my previous 2 attempts.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also a topic for another forum. Hardware Forum normally would be suggest but you may be able to post this along with a help request for installing SP2 in the Software Forum. It may just be a matter of enabling the Windows Audio service or reinstalling the drivers for you sound card.

    Yes work this in the Software Forum but my suggestion would be to download SP2 to your PC and then disconnect from the internet and shutdown (possibly uninstall if necessary) all protection software and then try installing SP2.

    You can download and use this: http://www.microsoft.com/downloads/details.aspx?FamilyId=049C9DBE-3B8E-4F30-8245-9E368D3CDB5A&displaylang=en


    Also see this: http://support.microsoft.com/xpsp2getinstall


    I suggest you now complete my final instructions from message # 21.
     
    Last edited: Feb 6, 2009
  32. Infected

    Infected Private E-2

    I am so angered (at the bug, not you) to say that the infection has returned.

    You need me to run the standard 4 logs again?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! At this point I have to assume that you are getting reinfected due to the fact that your Windows OS is out of date and there must be security wholes that the infection is taking advantage of. I would prefer to see you get your OS updated first if possible since there is no sense just running in circles removing the infection only to get reinfected again. It is either due to this, or due to something that you are doing (like where you are surfing ....etc).
     
  34. Infected

    Infected Private E-2

    Well, I'm the beggar and you're the boss in this relationship, so I'll definitely install SP2 first if you think it would be beneficial... I was just hesitant to install any permanent software onto an infected PC.

    But that said, from where I'm sitting this has nothing to do with my surfing habits. Not certain I even used the PC between my last report that I was 'clean' and when I noticed I had become reinfected. I think i noticed some 6 hours after I posted I was clean... just didn't have time to come back here to notify you until a couple days later.

    From where I'm sitting, my computer has appeared clean 5 times during this thread, and on every occasion, the bug has returned usually after a few hours, or on my next reboot.

    I'll head on over to the software forum, hopefully later tonight, and then I'll report back here when it's complete.

    Thanks again for all your support... this website is fantastic!
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes it is necessary to do things like this to be sure that problems are not reoccurring due outdated software.

    There is always an alternative of reinstalling from scratch when something like this keeps happening. If a system appears clean based on the logs then typcically it is clean; however, malware can always be hiding in places that the scans and logs are not reporting. Or as I'm implying a PC just can have too many security holes due to outdated/unpatch software being used and a PC can just be susceptible to reinfection.

    This last infection that we were removing with wdmaud.sys has been successfully removed on dozens of PCs without a problem of it returning. Yours is the only one it is coming back on. So either you have some new form, which is unlikely since we also see more than one case of all infections, or there is something else at play causing the reinfection. After we get your system properly updated/patched, we will be able to at least rule out that as a source of the problem.

    After you get SP2 (at a minimum SP2) installed, you then need to also check for other Windows Updates because there will be a ton of them and you need to get them all installed to be secure. You can stop short of installing SP3 and IE7 or IE8 if you wish, but all other updates need to be installed.
     
  36. Infected

    Infected Private E-2

    Ok Chas, got SP3 and IE 7.

    You're right... think I had around 35 updates. Question: looks like windows firewall and virus protection turned themselves back on with the service pack and security additions. Should I disable since I'm running AVG and ZoneAlarm?

    Also, you ready for my 4 logs, or are there other steps first?

    As always, thanks a million for the support.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just disable the Windows firewall as long as ZoneAlarm is still actively working.

    Download the current version of MGtools and run it. Attach the new log. Let's see what it shows before doing anything else.

    Also tell me what problems ( if any ) you are currently having.
     
  38. Infected

    Infected Private E-2

    I was wrong about windows firewall... was misreading windows security center. apparently it was just picking up on the fact that I currently have avg and zone alarm. :hammer

    Here are the logs. Right now I don't see any sign of the hijacker.
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please delete the below folder left over from ComboFix:

    C:\32788R22FWJFW

    Also delete the below files left over from ComboFix:
    C:\WINDOWS\SYSTEM32\CF26581.exe
    C:\WINDOWS\SYSTEM32\cmd.execf

    Yes but I do. ;)

    Repeat all the steps from message # 27 again and attach the new logs.
     
  40. Infected

    Infected Private E-2

    Here ya go, all done.

    Avenger log couldnt seem to find those 3 files... not sure what that means, but I'll leave that part up to you :major
     

    Attached Files:

  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It just means the files were already gone and only the registry key remained.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  42. Infected

    Infected Private E-2

    trying to uninstall combofix... each time i've tried, i get that same error message as before when I was trying to run it and it failed: "prep.com has encountered a problem and needs to close". Immediately afterwards, AVG finds a backdoor trojan, which I need to 'heal'; last bug had the name of: BackDoor.SmallX.vx

    thoughts?
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! AVG is getting in the way. You can either remove all the ComboFix files and folders manually (including the QooBox folder) or you can retry in safe boot mode, or the third option is to uninstall AVG and try again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds