Multiple Internet Explorers

Discussion in 'Malware Help (A Specialist Will Reply)' started by mrbarcode, Jan 9, 2011.

  1. mrbarcode

    mrbarcode Private E-2

    Hello there !

    Now, like many others, I got infected with this "Multiple Internet Explorer and Mute" thingy. I think its called Whistler or Black Internet or something like that. I guess you guys here know what I mean.

    So, I got infected already months ago, but I found a way to block this "mute" and the Internet Explorer. It still kept opening, but it couldnt load any sites. Well, now I know that wasnt so smart, but now I need some help to remove this. Or, to be honest, Im not sure if its not already removed. I followed the Sticky with all the programs, and Combofix said he removed some Whistler stuff. But well, I'll post all my logs here, I hope you guys can tell me what to do next (IF theres something to do left)

    Oh, and here is what Bootkit Remover says (it's different now as well, before I used Combofix he said there was an unknown Boot code, now hes says:


    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: 6def5ffcbcdbdb4082f1015625e597bd

    Size Device Name MBR Status
    -----------------------------------------------------
    931 GB \\.\PhysicalDrive0 OK (DOS/WIN32 Boot code found)


    Press any key to quit...
     

    Attached Files:

  2. mrbarcode

    mrbarcode Private E-2

    Here the rest of the logs !
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you got the log from running MGTools? C:\MGlogs.zip?

    Tell me how the computer is behaving after running all the scans.

    [edit by chaslang] The version of TDSSkiller that was used is way out of date. The current version should be download and used to scan again and attach a new log.
    Also Malwarebytes is extremely out of date and needs to be updated and a new scan run.
     
    Last edited by a moderator: Jan 9, 2011
  4. mrbarcode

    mrbarcode Private E-2

    Okay, here are the logs with the new versions and the MGlog.zip as well!
    Malwarebytes found a little Trojan, but besides that nothing.


    Well... since i used Combofix the iexplorer.exe stopped opening itself in the background, and the error sounds without error message (i guess they were just like the Internet Explorers in the background) stopped as well.
    Also, I can allow Internet Explorer again ( I blocked it before with Norton) to use the Internet without getting my sound muted or hearing Ads.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below:

    • Ask Toolbar
    • Java(TM) 6 Update 11
    • Messenger Plus! Live <--- This actually will invite nasties in, so be rid of it.
    • WinPcap 3.1 <--- Uninstall this if you did not deliberately install it yourself.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Dokumente und Einstellungen\User\2dbf~1     
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AC129BF9-68BF-4bc4-A1DC-ECB62712FF99}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run TDSSKiller again and attach the log.

    Reboot.

    Re run MBRCheck as well and attach it's log.

    Install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions.
     
  6. mrbarcode

    mrbarcode Private E-2

    Okay, I followed your instructions and uninstalled the stuff you told me to. Here are the logs !

    Oh, and I wanted to say thanks for your help, especially for the step-by-step instructions, so even people like me understand what to do !
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    C:\Dokumente und Einstellungen\User\2dbf~1    
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Re-run TDSSKiller and attach the log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. mrbarcode

    mrbarcode Private E-2

    Okay, here are the logs !
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's better. Now you are ready to follow final steps (Rename combofix/MGTools back to their proper names before doing so if you renamed them)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. mrbarcode

    mrbarcode Private E-2

    Okay, I followed the last instructions! Thank you so much again for helping me with this !
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds