browser hijacked, norton not working

Discussion in 'Malware Help (A Specialist Will Reply)' started by chiepler, Oct 20, 2010.

  1. chiepler

    chiepler Private First Class

    I have a computer running Win7x64 that can't get on the web in normal mode. I can get online fine in safe mode with networking. I can't do anything with Norton 360 in normal or safe mode, not even able to remove it. I ran the mbam & sas scans, but nothing was found. I tried booting with all startup programs and non-Microsoft services running - no difference. The browser doesn't show that it's trying to connect to a proxy. I deleted all browser history items - no difference. Here's my logs...
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    On second thoughts, is this another customer of yours? I am not saying I am going to refuse you help but how would you feel about giving your customers our web address so that they can come here and go through malware removal processes?
     
  4. chiepler

    chiepler Private First Class

    Yes, it is. I always recommend MG to people who have viruses, but many times they're either too busy or not technical enough to do this kind of stuff. It's like they're scared of it or something! When I mention MG to my customers, they say that they'd rather let me deal with it. I do the best I can, but there are times I get stuck as well.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    C:\Users\Wood\Local Settings\TEMP\29A2.tmp
    C:\Users\Wood\Local Settings\TEMP\4AE5.dir
    C:\Users\Wood\Local Settings\TEMP\4AE5.tmp
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    TDSSKiller is not designed for 64 bit systems but it will run in a reduced functionality mode and we have seen it find and fix things before now.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  6. chiepler

    chiepler Private First Class

    Thanks for taking the time to help with this!
    Norton still not working, IE can't get to web yet. Here's my logs...
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  8. chiepler

    chiepler Private First Class

    I ran this scan & got the following message:
    GMER hasn't found any system modification.
    I saved a log file, but when I opened it there wasn't any text so I'm not adding it to this message.

    Another note - the owner said he had to reset his machine to a restore point in order to get to the web. I haven't attempted this yet myself.
     
    Last edited: Oct 22, 2010
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Perhaps you should try doing a system restore. Then re-run SAS and MBAM to make sure there is no malware in the restore point.
     
  10. chiepler

    chiepler Private First Class

    I tried restoring the system from several restore points & each time it failed. I'm probably looking at a fresh reinstall at this point. Thanks for your time & effort!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Perhaps all you need to do is a repair install. Try that first before you consider a fresh install.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds