BSOD, Internet Redirection, Trojan? Help please!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by May_Chile, May 2, 2011.

  1. May_Chile

    May_Chile Private E-2

    I have a Toshiba Satellite A305-S6905 with an upgraded (formerly Win Vista) Windows 7 Professional 32-bit OS. I've found something called "click.giftload" under Spybot. Nothing under MWAM or CCleaner. Multiple BSOD, including when I attempt to run combofix. Click.giftload keeps returning, no matter how many times I've cleared it. Please help, I'm at my wits end.

    --I do not have the installation disc, I only have the recovery disc--

    I'm attaching a DDS report, since it seems to be the only log that will scan and save as of right now. Hope it helps.
     

    Attached Files:

    • DDS.txt
      File size:
      9.7 KB
      Views:
      3
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.


    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. May_Chile

    May_Chile Private E-2

    Thanks:

    Combofix = no. As I've previously stated. BSOD keeps coming up when I attempt to run it, citing an "irql_not_less_or_equal" error code: 0x000000a0; even in safe mode.

    SuperAntispyware = found issues, quarantined and "deleted". Asked for reboot, I clicked okay..BSOD comes up citing "internal_power_failure" same error code as above. No log produced. Ran more than once, same situation.

    RootRepeal = nothing. Warning box pops up: "FOPS - deviceiocontrol error! Error code: 0x0000024. Extended info (0x000000dc).

    Attached MWAM log and MGlog.
    Did everything else I could from the link that was posted.
    I've also tried something called TDSSKiller (which was recommended by someone else the other day)..that would only load 80% and then "encounter a problem".

    Spybot still finds "click.giftload". Still removes, and it still comes back upon reboot.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah!!! This is important information. You have a new form of Master Boot Record infection. Do you have your Windows 7 Boot DVD. We need to boot into the System Recovery Environment to fix this problem.
     
  5. May_Chile

    May_Chile Private E-2

    As in a Windows 7 Recovery Disc? Yes, I do. (The actual Windows 7 installation disc, however, no). I've tried to run from Recovery Disc multiple times before and there were many instances in which Windows would just not start and I'd have nothing but a black screen.

    I'm listening though..I have the disc in my hand waiting for further instruction :)

    **My Display also tends to jump from standard Windows 7 to what looks like Safe Mode/Windows 95ish lookin...I find it very odd..**
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure if this is the correct disk or not. Is this a bootable disk that allows you to get to the System Recovery Options screen which looks like the below?

    http://forums.majorgeeks.com/chaslang/images/Win7/SysRecOptions.jpg
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try something that may be able to spare us from needing a bootable Win 7 DVD. Please download, install and run the below tool from Kaspersky which may be able to locate and fix the root cause of this problem which will be a .sys files that has been infected by a TDL infection:

    Kaspersky Virus Removal Tool

    Attach a log from this tool and let us know if it help.
     
  8. May_Chile

    May_Chile Private E-2

    Yes!! I have that DVD which displays those options.

    I've tried the Kaspersky Virus removal..it won't open. I've downloaded and attempted to Burn to a CD etc as instructed. My drive won't recognize blank cds anymore for some reason, so it won't burn to them (as has been instructed in order to run that particular tool). I've also just attempted to download and run it and see what happens..a no-go.

    :(
     
  9. May_Chile

    May_Chile Private E-2

    ok kaspersky ran...odd. i attached it :)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It did not find what we are looking for.

    Good you will need it now.

    Put the disc into the drive and reboot with the DVD. We are going to be running the Bootrec.exe command from the Command Prompt per the below instructions.
    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Now type Bootrec.exe /fixmbr and then press ENTER.
      • NOTE: There is a space before the /fixmbr
    Then reboot your PC and see how things are working. Also see if you can get TDSSKiller to work properly now. If it runs 100%, all is likely good.
     
  11. May_Chile

    May_Chile Private E-2

    Um okay so now im replying to you from my cellphone bc i cannot log into my laptop. I did everything you said. Upon reboot, a BSOD flashes really quick with error code: 0x0000007B or what have you..but 7B is the end portion. Then it states that windows failed to start and try to launch startup repair. Im trying to boot from the disc and rollback to when before i tried the bootrec.exe.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that's not good. :( When you ran the bootrec command did you run into any problems? Were there any messages?

    Can you still boot up this CD and get to the Command Prompt?
     
  13. May_Chile

    May_Chile Private E-2

    I feel like crying :'( um when i did the bootrec.exe it said that it was successful/complete REALLY fast. Literally as soon as i pressed enter. I rebooted and got the quick BSOD. The stop code was the one i posted before 0x000000fb. I've tried everything, i can't get back into windows. I can boot the cd and get to command prompt. Ive run chkdsk and sfc /scannow. I had an unknown bugcheck of 0x870f02c0 (whatever that means). So yes, i can still boot from the cd..but startup repair cant fix it and system restore does nothing :'(
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh and just a note. The 0x0000007B type error message can sometimes occur when there is a master boot record infection and that is exactly what we are trying to fix. Thus it almosts seems like the rewrite of the MBR did not completely work for some reason.

    It could also occur do to a faulty driver which again could be due to the infection.
     
  15. May_Chile

    May_Chile Private E-2

    Any other suggestions? :(
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thinking about it. Not sure what went wrong since we have used this many many times without a problem. Even used it quite a few times on this new infection that you have.

    Try getting into the command prompt and running a slightly different command

    Bootrec.exe /fixboot
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still get a BSOD, tell me if it mentions and .SYS file name in the error message.
     
  18. May_Chile

    May_Chile Private E-2

    It said it completed successfully, but still can't start windows. There is no .SYS file mentioned. The only thing is the stop: 0x0000007B (0x80786B58, 0xc000000D, 0x00000000, 0x00000000) I've also tried booting from last known config...nothing.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you first get to the command prompt, exactly what text do you see in the window?
     
  20. May_Chile

    May_Chile Private E-2

    Microsoft Windows [Version 6.1.7600]

    X:\windows\system32>
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay type in the below and hit enter and tell me what the prompt changes to.

    C:
     
  22. May_Chile

    May_Chile Private E-2

    Changed to
    C:\>

    :)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then now enter the below commands and hit enter after each one. Remember the space after bootrec and make sure of the direction of the /

    bootrec /fixmbr

    exit


    Will Windows run now?
     
  24. May_Chile

    May_Chile Private E-2

    No :(

    again it said the operation completed successfully, but upon reboot i got the WINDOWS RECOVERY: WINDOWS FAILED TO START and then i selected START WINDOWS NORMALLY and got the same BSOD
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I want to see if we can diagnose your BSOD further and if anymore info is present.
    • When you boot your machine, press F8 to list the startup options, exactly as you would if you were trying to enter Safe Mode
    • Select "Disable Automatic Restart on System Failure" from the menu which should look something like below:
    http://forums.majorgeeks.com/chaslang/images/WinAdvOptionsMenu.jpg
    • When your system BSODs, write down the STOP error code, as well as any written out error messages back here. The STOP error will always appear, but the message may not. See if any file names are mentioned anywhere.
     
  26. May_Chile

    May_Chile Private E-2

    Nothing. Just says the same STOP codes i've listed before and talks about the whole "check for viruses on your computer. Remove any newly installed hard drives or hard drive controllers. Check your hard drive to make sure it is properly configured and terminated".
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. Does it allow you to get past the BSOD now without rebooting?
     
  28. May_Chile

    May_Chile Private E-2

    "Get past"? The bsod still shows up, but instead of auto reboot, it just sat there. I rebooted, now its doing a continuous auto reboot and im back at the Windows Error Recovery Screen now..
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot from your DVD again ( see the image in message # 6 ) and this time instead of selecting the Command Prompt, select the Startup Repair option and see if that helps.
     
  30. May_Chile

    May_Chile Private E-2

    Yeah I've tried that. When i boot from the CD it says that startup repair cannot automatically fix the problem. Then i click finish and am brought back to the system recovery options again. I run startup repair again and it says that it couldn't detect any problems..which doesn't make sense.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well let's try the System Restore option and go back to a restore point from a day or two back.
     
  32. May_Chile

    May_Chile Private E-2

    Tried it. Still BSOD..
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running out of options..... Will it boot up in Safe Mode?
     
  34. May_Chile

    May_Chile Private E-2

    No it won't boot in any safe mode
     
  35. May_Chile

    May_Chile Private E-2

    Okay, so I posted a thread in the SOFTWARE forum and they were able to boot my laptop back up. Something about the partition. Anyway, now that I've logged in, Windows Update is functioning and currently updating. I've run MWAM and of course, it can't find anything, but Spybot is still coming up click.giftload. I'm printing out the instructions I was given in the Software forum in case this happens again so I know what to do. Any suggestions on the Spybot and click.giftload issue? I honestly don't care if I have to wipe the slate clean and lose files..I just want a clean PC now.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry, I was not able to be around for awhile due to real work.

    Excellent! I did not read all of your other post but that was the direction I was headed in too. It seem like the information for which partition had the active Windows installation was lost somehow.


    What I want you to run now is TDSSKiller and attach the log as requested in the below.

    TDSSkiller - How to run
     
  37. May_Chile

    May_Chile Private E-2

    It's okay, I figured you would be online around this time anyway. I understand there's "real work" out there as well. :)

    10 steps ahead of ya. I ran all of the scanners as listed in the READ NOW MALWARE post and am attaching all the logs. The only one I was unable to run was rootrepeal. I keep getting an error.

    Also, I notice in my My Computer, the drive E: System Reserved. Do you know if this means I'm pretty much not running on my full system? It shows 70MB of 99.9MB is free, I don't know what that means, and I wonder if I'll forever see this drive E now.

    Anyway, logs attached. :)
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like those cleaned up a few more issues ( different ones ). Looks good now but note that you are way out of date with Malwarebytes and need to get properly updated to the current version and the current database.

    It due to how you have your drive partitioned. In the MGlogs.zip file you can see the below info which is snipped out of the sysinfo.txt log. I edited this to shorten up and to display only important info.

    Code:
    Drive C: 
    Description Local Fixed Disk 
    File System NTFS 
    Size 297.99 GB (319,965,622,272 bytes) 
    Free Space 229.14 GB (246,039,773,184 bytes) 
     
    [Disks]
    Item Value 
    Description Disk drive 
    Model FUJITSU MHZ2320BH G1 ATA Device 
    Media Type Fixed hard disk 
    Partitions 2 
    Size 298.09 GB (320,070,320,640 bytes) 
    Partition Disk #0, Partition #0 
    Partition Size 100.00 MB (104,857,600 bytes) 
     
    Partition Disk #0, Partition #1 
    Partition Size 297.99 GB (319,965,626,368 bytes) 
     
    Notice that you have a couple of partitions. Partition # 0 is the 100 MB one you mentioned. Not sure what you had on it but it may be from a old system or setup of some sort since it is too small to be a factory recovery partition.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  39. May_Chile

    May_Chile Private E-2

    Okay, I've read and completed the Final Steps (and updated MBAM). Is it okay to keep TDSSKiller, or should I uninstall that as well? (I've removed Combofix, MGTools, etc).

    I'm running Spybot once more to be 100% that the dreaded click.giftload doesn't reappear.

    Also, one last question: so...I understand about my drive being partitioned, but is it necessary for me to see E:\System Reserved every time I open My Computer? I know it's not a big deal, but it kind of freaks me out like I'm running on a backup drive or something. Can it be "deleted" per se?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It should have been removed when you ran MGclean.bat. But the answer is no do not keep it. It should be download anytime the program is needed so that you have the correct version since it updates frequently.

    You can check discuss this more in the Software Forum if you need to after reading the below, because it is not a malware issue. See:

    http://answers.microsoft.com/en-us/windows/forum/windows_7-performance/can-i-delete-the-system-reserved-partition-from/656014d2-a516-46e6-a841-d0f9333ecb48


    http://social.technet.microsoft.com/Forums/en-US/w7itproinstall/thread/76116c99-f69a-421b-b188-0ebad4a19b9d/
     
  41. May_Chile

    May_Chile Private E-2

    Okay. Thank you soooo much for your help!! Hopefully, I won't have such a horrible issue to the point that I have to return here, but if something ever happens again, I know EXACTLY where to go. You're the best!!



    **Thread can be closed now** :)
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds