Having trouble with Browsers

Discussion in 'Malware Help (A Specialist Will Reply)' started by MamaLoca, Feb 8, 2010.

  1. MamaLoca

    MamaLoca Private E-2

    My son is having trouble with his computer. He was experiencing problems with pop-ups and with both EI 6 I think (I told him he needed to upgrade) and Firefox. with IE whenever he uses the back button he goes to various sites that he has not gone to, in Firefox the google search embedded in the browser results in a 302 error.

    I ran the Malware removal Howto and here are the logs.
     

    Attached Files:

  2. MamaLoca

    MamaLoca Private E-2

    And the rest

    CClean file is 1.5MB and will not upload. Do you want me to break it down into smaller files?
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. :)

    No, I do not wish to see a log from ccleaner as one was not requested. Only attach what our procedures require.

    1. You neglected to attach one of the most important logs, that being: C:\Mglogs.zip from running MGTools.exe.

    Also...


    2. Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    3. Please also open up Malware Bytes > update > re scan > fix all it finds and attach the requested log.

    4. You have combofix running from inside a directory which it should not be. You need to take it out of the folder and place it directly on your desktop as requested in the instructions.

    So to summarise:

    • Attach the logs from both MBAM and SAS
    • Ensure combofix is on your desktop
    • Attach the Mglogs.zip.

    And then I can build a complete fix for you.
     
  4. MamaLoca

    MamaLoca Private E-2

    My bad, I'm on it. :-o
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK. I will be here waiting :)
     
  6. MamaLoca

    MamaLoca Private E-2

    Well, here are the files BUT, I think things are fixed.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're not entirely out of the woods just yet.

    1. Please disable BitTorrent from running at start up whilst I am helping you remove malware! Thankyou :)

    2. I see that you are using avg 8.5. The latest version is 9, so you can either upgrade to that or opt for a different anti-virus. Either way this is something to do after we have finished malware removal.

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\program files\schtml
    
    File::
    c:\program files\skynet.dat
    C:\Your PC Protector.lnk
    C:\horj.exe
    C:\ojjw.exe
    C:\dqccpnq.exe
    c:\windows\system32\lukopijo.dll
    c:\windows\system32\vusiluya.dll
    c:\documents and settings\Owner\Start Menu\Programs\Startup\AntiVirus Plus.lnk
    c:\documents and settings\All Users\Start Menu\Programs\Startup\AntiVirus Plus.lnk
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. You are using an outdated version of MGTools.exe. I do not understand why as we always host the latest version and if you followed the R&R correctly you would already have it and not this old one.

    Please do this:

    Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    6. Run the new MGTools.exe and attach the C:\Mglogs.zip that it creates (Before we continue I would like for you to ensure that MGTools.exe is indeed directly on your C Drive and not in any other location, such as the below like you had it running from before.
    7. Attach the log from combofix and MGTools into your next reply.

    8. Let me know how the computer is behaving now.
     
  8. MamaLoca

    MamaLoca Private E-2

    I do apologize, This is not the first time I've cleaned this computer and should have re downloaded the programs instead of using the ones from before.

    One question, can I use "LogMeIn" to run these instructions? I would guess not but it would be much easier then having to go there myself.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not familiar with logmein, but you can certainly try yes :) I have done similar through TeamViewer I believe it was.
     
  10. MamaLoca

    MamaLoca Private E-2

    I will get back to you about how the computer is acting.

    Thanks so much for all your help!
     

    Attached Files:

  11. MamaLoca

    MamaLoca Private E-2

    Alas, it's still acting squirrely. :(
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And describe to me in more detail exactly what's wrong?

    1. You didn't disable BitTorrent from running at start up as requested. Please do this before we continue.


    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    c:\program files\schtm
    Registry::
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "ctfmon.exe"=-
    "AntiVirus Plus"=-
    "SansaDispatch"=-
    "TomTomHOME.exe"=-
    "Aim6"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "C-Media Mixer"=-
    "SunJavaUpdateSched"=-
    "QuickTime Task"=-
    "KernelFaultCheck"=-
    "WinampAgent"=-
    "Adobe ARM"=-
    "tokogariyo"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Let us know of any problems you may have encountered with the above instructions and also tell me exactly what's wrong with the machine now.
     
  13. MamaLoca

    MamaLoca Private E-2

    Yikes! It would seem I am back to square one here. I was trying to describe exactly waht was happening. Google would preform a search but the links would redirect me elsewhere. Then I had the bright idea of trying Yahoo. That's when all heck broke loose and I ended up with a blue screen. Doing this remotely I could not see the blue screen at my end only the first attached image
    http://forums.majorgeeks.com/attachment.php?attachmentid=131500&stc=1&d=1265993788

    After I had my son do a hard restart we received the second image. It appears that "AntiVirus 2010" has reinstalled itself on the system so I'm back to square one. I am guessing I should restart the whole process all over again.

    I think we are just going to try and save as much off the computer as we can and do a clean install. I have told him the risks of downloading willy nilly off the internet.

    Unfortunately I can not get the Combo Fix and MGLogs files from his computer until I go there personally. I can't do much of anything remotely now. Sheesh.

    Thank you for all your help and patience.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes wait until you can get there and run the procedures again. You can stay in this thread. Or have your son himself run the procedures. The he may well see what's involved and not be tempted to download willy nilly off the net :)
     
  15. MamaLoca

    MamaLoca Private E-2

    My son just called and he can't even log in to the computer. It immediately logs him back off again.

    I'll need to try and run off a CD. any suggestions on what to use to get his files onto a thumb drive?
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If he cannot even log in then this then becomes a software problem. You can post in software and receive assistance until you are in a fit state to run logs again. Then start a new thread in malware removal :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds