Browser Hijacker- Posting TDSSKILLER Log

Discussion in 'Malware Help (A Specialist Will Reply)' started by Grimmer, May 11, 2012.

  1. Grimmer

    Grimmer Corporal

    Running through the steps in read and run me first sticky. I am stuck at running TDSSKILLER not sure what to keep or what to remove. Help is greatly appreciated.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no problems in your TDSSKiller log to fix. Just run the READ & RUN ME FIRST.
     
  3. Grimmer

    Grimmer Corporal

    Ok thank you Chaslang! :)
     
  4. Grimmer

    Grimmer Corporal

    Quick question. I have a IDE/SATA to Usb adapter after I configure infected system prior to scans in Read and Run me first, can I remove the infected systems HDD and scan from clean system it would be faster I think on scan time. Or will scans not work properly?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Will not work to properly find malware as you would be primarily scanning the uninfected computer. It it were absolutely impossible to run anything on the infected computer, then this would be a possible thing to do just to attempt to get started. But it is still necessary to boot Windows on the infected hard disk to properly find all malware.
     
  6. Grimmer

    Grimmer Corporal

    Ran procedures and scans as directed by Read and Run Me First. After completion of combofix, a dialog from AOL anti-spyware popped up saying it found spyware backdoor something. It gave me three options block, view details or I could hit the red x and exit program. I exited program and it popped up again so I removed it.
    Thought I disabled all anti-spyware/anti-virus apps but apparently was wrong. Hope this does not effect scans.
    I disabled AOL anti-spyware before running RootRepeal.

    Tried running MGtools.exe from C:/ a few different times but it did not start so I am posting the logs that I have.
     

    Attached Files:

  7. Grimmer

    Grimmer Corporal

    Note: Not sure if this will effect anything or not but after posting logs and shutting down my pc windows update popped up and automatically installed 1 update. I know I'm running service pack 2 so I am pretty sure it might be going through the process of installing SP3.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown your protection software and download MGtools.exe to your Desktop. Then try running it. There does not appear to be any malware reason why you should not be able to run it.

    What browser are you using when you have hijack problems?
     
  9. Grimmer

    Grimmer Corporal

    o using internet explorer 8. went to go online the othr day and i was redirected to a suspicious website, it took longer than usual to load browser and where ie dispays website at bottom the address started with loopback addy 127.0.0.1.


    nyways was able to run mgtools after removing aol anti spyware
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well this is not a hijack. It is just as you stated, a loopback to your PC. You probably added something to your hosts file to loopback whatever URL you were going to. Perhaps AOL even added the address to your hosts file. Just put your hosts file back to default with the below.

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
     
  11. Grimmer

    Grimmer Corporal

    ok sounds good glad to hear all is alright. thank you very much for your time. will run the tool you suggested.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds