Another Browser Hijack and Unable to Any Type of Security Update

Discussion in 'Malware Help (A Specialist Will Reply)' started by cchin, Feb 20, 2009.

  1. cchin

    cchin Private E-2

    My first time here, let me know if I missed anything that I should be able to do I will do it again.

    I am having a problem where my IE is no disabled. Searches I make on Google end up sending me ads and spam. I am unable to access malware removal program sites and get their required updates. Current windows securities are disabled and unable to resume.

    I did a bunch of reading on your forums and on previous posts of people who had the same time. I repeated most of the same steps to the best of my ability.

    BASIC COMPUTER MAINTENANCE
    Run CCleaner
    DONE cleaned unneeded files
    DONE removed/fixed invalid registry entries
    DID NOT remove any startup items
    DID NOT defrag

    Browse through Add/Remove Programs
    DID NOT find anything unfamiliar or suspicious
    TRIED to remove older versions of Java Update
    Error Message: The Windows Installer Service could not be accessed. THis can occur if the Windows INstaller is not correctly installed. Contact your support personnel for assistance.

    Normal Startup
    Already on. All this is done in safe mode w/ networking.

    Empty Quarantine type folders.
    DONE to the best of my ability.

    Empty Recycle Bin
    DONE

    Run CCleaner
    DONE ran again, but see above

    Show Hidden Files
    DONE

    VISTA CLEANING PROCEDURE
    Downloading
    DONE

    Disable UAC
    DONE restarted in safe mode /w networking

    SUPERAntiSpyware
    DONE received log, during reboot however I received a blue screen mem dump and had to reboot again. rebooted into normal windows

    Spybot S&D
    DID NOT install, was unable to install because connection to download and install errored out

    Malwarebytes
    UNABLE TO UPDATE or get file for manual update due to connection erroring out
    Performed Quick Scan regardless of unable to update
    Needed Reboot to remove
    C:\Windows\System32\senekaiitjsxnf.dll
    C:\Windows\System32\senekaxeklfpnc.dll
    C:\Windows\System32\senekaxvttprmh.dll

    ComboFix
    DONE

    MGTools
    DONE

    I decided to stop here and post. I am not sure about doing the system restore point thing yet.

    Thanks,

    Clifford
     

    Attached Files:

  2. cchin

    cchin Private E-2

    Here are the MGTools log files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Based on your logs you are in pretty good shape now but you do need to do the below.


    The infection you have is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    Uninstall the below software:
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\TEMP
    C:\Users\Clifford\AppData\Local\Temp


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. cchin

    cchin Private E-2

    Thanks for the response, been a bit busy atm. I'll be sure to do this tomorrow.
    How will I know whether or not my router is clean if it has been infected?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have other PCs using the same router and they have no problems or if your PC no longer has any problem after running the cleaning procedures, then your router is most likely not infected.
     
  6. cchin

    cchin Private E-2

    Uninstall the below software:
    Java(TM) 6 Update 7 DONE
    Java(TM) SE Runtime Environment 6 DONE

    Use MGTools on:
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) DONE

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\TEMP DONE was able to delete all files even from today
    C:\Users\Clifford\AppData\Local\Temp DONE besides the files from today, was unable to delete 2 files (FXSAPIDebugLogFile.txt dated 2/19/2009 and a webimage.jpg created on 2/19/2009 modified 2/25/2009

    Attached below is the new MGTools.zip.

    After I did all the steps posted on the forums on 2/19/2009 everything seemed fine the next day. However I haven't used my computer much since then so I am not too sure. But it seems like I can do updates on windows security, virus scanners, and anti-adware now. I have reset my router prior to doing the things posted here. Other computers on the browser seem to be working fine even after my computer got infected so I don't think the router got infected.

    Thanks, let me know.

    Clifford
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot verify your logs. If looks like you did not allow GetLogs.bat to finish running because most of your logs are old. Delete the current C:\MGlogs.zip file and then run the C:\MGtools\GetLogs.bat file again. Make sure you let it finish running. Then attach the new C:\MGlogs.zip file.
     
  8. cchin

    cchin Private E-2

    All of the above redone and the file was redone and attached.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still your logs are incomplete. You must make sure you are following the instructions for Vista users as given in the Using MGtools instructions given in the READ & RUN ME. You must have UAC disabled (a reboot is required after disabling) and you must right click C:\MGtools\GetLogs.bat and select Run As Administrator as requested in my instructions. Then you need to make sure you wait until it finishes running. See the snapshot in the above instructions.
     
  10. cchin

    cchin Private E-2

    Actually I did get to the screen shot, but I will repeat this again and post.
     
  11. cchin

    cchin Private E-2

    Repeated again via your last post. I was able to get to that finish screen again also. Here is the attachment.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this last log is complete. And it they are clean! :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  13. cchin

    cchin Private E-2

    All is done.

    Thanks a lot for all your help and patience on this matter. :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds