Have completed Read & Run Me First: help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Camilla, Nov 25, 2010.

  1. Camilla

    Camilla Private E-2

    Our PC started to act up this morning, reporting malware during normal browsing (I believe my partner was trying to play a kid's programme on the BBC iPlayer site initially, but other than that we were just visiting normal pages like Amazon). I also noticed frequent hijacks, eg attempting to visit MajorGeeks from Google, I got redirected to eBay, and other similar misdirections to random sites. This is still happening.

    I have run all the checks and I'm attaching the logs I have. I managed to run RootRepeal, and it seemed to complete fine, but when I hit the save button it showed the window you would normally get to save it, with text in the top bar saying it was unable to create the file. Nevertheless, it appears to have done it; I'm just mentioning in case it means anything.

    Hope you can help. Many thanks. :)

    Camilla
     

    Attached Files:

  2. Camilla

    Camilla Private E-2

    Here is the final attachment.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix may have fixed your hijacker. A TDL4 infection was found in your MBR. Are you still being hijacked?


    Please download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After looking thru all of your logs, I see you also picked up some other malware ( besides the hijacker ) too.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Camilla\Local Settings\temp\WZ5AA6

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Camilla

    Camilla Private E-2

    Hello, thanks for your replies. Still being hijacked I'm afraid, but I only just rebooted after following first orders and will move on to your last post momentarily (allowing for kids' diiner, bedtimes etc)...

    Log attached.
     

    Attached Files:

  6. Camilla

    Camilla Private E-2

    Hi, I tried temporarily disabling AVG prior to starting as instructed, but when Combofix ran it gave me an error message requesting I uninstall AVG. I began to do this, using the uninstall tool in C-cleaner (out of habit, it's what I always use to uninstall anything). However, it stopped me partway through as it said it was unable to uninstall AVG Watchdog, and that I had to verify that I had privileges to do this before I could continue.

    Weirdly, I didn't get this message earlier in the day, last time I uninstalled AVG to run Combofix.

    I'll try again, but meanwhile, do you have any idea what might be going wrong here? Thanks. Sorry for the hiccup.
     
  7. Camilla

    Camilla Private E-2

    OK, I attempted the temporary disabling of AVG again, to no avail; Combofix still asked me to uninstall. I then tried uninstalling again using Ccleaner, and then using Add/Remove Programs. Both attempts failed, both because of the warning popping up that AVG Watchdog could not be stopped and that I had to verify I had the privileges to remove system something-or-other.

    :confused

    Sorry, I feel like this is a stupid little thing holding us up but I'm not sure how to proceed.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bad habit. You should first always try using a programs built-in uninstaller.

    Many antivirus programs have problems trying to properly uninstall. I suggest that you run the correct AVG removal tool from the below link:

    http://www.avg.com/us-en/download-tools

    Do not reinstall AVG until we have completed your cleanup.
     
  9. Camilla

    Camilla Private E-2

    OK, thank you again. Here are the two logs.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That looks better but we have some more to do. First a question. Is the below something you installed? And if yes, then do you really need this to run everytime your PC starts up? Can't you just run it when needed?

    O4 - Startup: BBC iPlayer Desktop.lnk = C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
     
  11. Camilla

    Camilla Private E-2

    Hi, yes, it's something we want and use semi-regularly; but we absolutely don't want it to launch every time we start up. We just aren't clear on why it does this, or how to stop it.

    It has been prompting me to install the latest update today, but I have been ignoring; so whatever we can do to resolve it, I will need to learn how to do it again if the new version causes the same problem.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then we will stop it with the below fix. ;)


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O4 - HKLM\..\Run: [C0130Mon.exe] C:\WINDOWS\C0130Mon.exe
    O4 - Startup: BBC iPlayer Desktop.lnk = C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
    O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Please make sure you tell me how things are working now!
     
  13. Camilla

    Camilla Private E-2

    Hi there, here you go :)
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to reply to the below
     
  15. Camilla

    Camilla Private E-2

    Oh, sorry! Well, we haven't been browsing extensively, but I have not noticed any redirects since the last time I mentioned them (so, a few hours ago now). We will probably be going to bed soon. :zzz

    At what point would you say we can safely decide this is fixed and reinstall our antivirus?

    I'm very grateful for all your help.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You can reinstall your antivirus at the end of the below where you see the link for the How to protect yourself from malware. Installing an antivirus is part of that.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. Camilla

    Camilla Private E-2

    Just to say all still seems to be running well, thanks again. :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds