Browser Hijacked, can't complete cleaning

Discussion in 'Malware Help (A Specialist Will Reply)' started by punkette, Apr 3, 2009.

  1. punkette

    punkette Private E-2

    Hello...I'm new here and desperately need some help getting rid of malware. I've run the Readme but couldn't complete all the cleaning steps. I'm running Windows XP.

    Problem: Firefox and IE7 both crash very frequently and redirect to random sites from search engines. I can often backup to the desired site and/or reach it through history, but not always. I can get into some antivirus sites but not bleepingcomputer.com. It is a totally blank white screen.

    This has been going on for a few weeks. At my brother's suggestion I downloaded Malwarebytes and SuperAntiSpyware a week or so ago. I removed whatever they found during full scans. I also have Symantic Antivirus and had Ad-Aware and Spybot, all scans coming up clean. In an effort to fix this problem I downloaded Registry Mechanic (ran and cleaned up what it found) and uninstalled Ad-Aware and Spybot. Nothing seems to make a difference...if anything, the crashes are getting more frequent.

    Read-Me:

    1) removed Viewpoint Media Player & Logitech Desktop Manager
    2) removed old Java's & installed current
    3) changed msconfig to normal
    4) emptied quarantine folders
    5) downloaded & ran Ccleaner
    6) ran SuperAntiSpyware (previously installed and ran last week) complete scan...nothing found, log attached
    7) ran Malwarebytes (previously installed and ran last week) quick scan...nothing found, log attached
    * can't access bleepingcomputer site to download Combofix and instructions. I thought I downloaded combofix.exe from an alternate site, but when I tried to run it nothing happened.
    * Installed MGTools in C drive. Ran & it extracts, cmd window opens, but no programs appear to run automatically. I doubleclicked GetRunKey.bat in explorer window and nothing happens. I can't close the command window without an "End Program" error.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are way out of date with SUPERAntiSpyware and Malwarebytes so let's get updated and run new scans just to be safe.

    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    Now let's see if we can find out why MGtools did not work properly.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  3. punkette

    punkette Private E-2

    Hmm, yes. I am unable to update SuperAntiSpyware and Malwarebytes from inside the programs...getting error messages.

    SAS: uninstalled and reinstalled new version, but when I try to update I get "error trying to retrieve definitions." I've checked and Windows Firewall is not blocking it.

    MWB:when I try to update "has encountered a problem and needs to close." The Error Signature (if that's helpful) says: AppVer 1.34.0.0 ModName: unknown ModVer 0.0.0.0 Offset: 18021e39

    Re checking MGTools, now I can't even open the command window through start-run or through cmd.exe in the Windows folder. (I could do this last time I checked, probably last week).

    Any suggestions? Thanks so much for your help.
     
  4. punkette

    punkette Private E-2

    OK, after some updates to Windows I tried again to update SAS and Malwarebytes and was able to do so (downloaded SAS definitions from their website and MWB I could now update from the Update tab in program).

    I'm attaching new logs. SAS found and quarantined some threats; MWB nothing.

    I still cannot open my command window. Firefox is crashing even more frequently, especially upon opening, and redirecting more persistently from Google.

    Please help! Thanks!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you are not updated. Tiy have only version 1.34 and the current version is 1.36 also your way out of date with the datebase which should be version 1961.

    If you cannot update online, download and run the below.

    Malwarebytes' Anti-Malware Database


    Also see if the below procedure will run:

    Using Dr.Web CureIt
     
  6. punkette

    punkette Private E-2

    Ahh, progress! Thank you so much.

    OK, I updated Malwarebytes as you said, although the link and most current definitions I could find were version 1954 not 1961. Full scan, log attached.

    Ran Dr. Web Cureit, log attached.

    And now I can access bleepingcomputer, so I downloaded and ran combofix according to directions, log attached.

    AND now I can run MGTools! Zip file attached.

    Also, I noticed Symantic found some threats during an autorun that were quarantined and cannot be removed. Can I/should I do anything about these:
    Trojan Horse,ComboFix.exe.part,C:\,Infected,4/2/2009 6:02:03 PM
    Trojan Horse,D38DBCBAd01,C:\Documents and Settings\The Hotchki\Local Settings\Application Data\Mozilla\Firefox\Profiles\uotj0lv6.default\Cache\,Infected,4/2/2009 6:01:50 PM
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As of 4/9/2009 1961 was the current version which you would get if you update within the program. The manual update site is frequently behind where it should be. As of 4/12/2009, they are on 1979.

    Not problems.

    Your logs are all clean. I just have a few minor things for you to do.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now let's flush the Java Cache
    • Click Start > Settings > Control Panel
    • Double click the Java icon (be patient, it may take a while to open)
    • Now click the General tab and under the Temporary Internet File area
    • Click the Settings button and then click the Delete Files... button.
    • In the next popup click OK.
    If you have multiple Java plugin icons in Control Panel follow the above to clear all their caches.


    Now let's flush the FireFox Cache
    To flush your FireFox Cache:
    • click Tools
    • select Options
    • select Privacy
    • in the section labeled Private Data click Clear Now
    Now let's flush the Internet Explorer Cache
    To flush your Internet Explorer Cache:
    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.
    Now run Ccleaner!


    Are you having any malware problems at this time?
     
  8. punkette

    punkette Private E-2

    No problems! Life is beautiful again.

    Thank you SO much.

    May you live as long as you want,
    And never want as long as you live.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  10. punkette

    punkette Private E-2

    Done, thanks!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds