Browser Misdirects and Blocked Win Update 1of3

Discussion in 'Malware Help (A Specialist Will Reply)' started by jefzef, Oct 15, 2010.

  1. jefzef

    jefzef Private E-2

    My first time posting. I hope I've followed your guidlines correctly.

    Here is the first of three machines and the appropriate logs.

    SuperAntiSpyware does not show the log in the program, though a series of SDB files can be found in the directory through Explorer. SDB is not an accepted file type for attachment, so it is not included. It didn't really find anything anyway. Hopefully you'll have enough to work with.

    Thanks
    Jeff
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Running from: c:\documents and settings\Zephyr\My Documents\Downloads\ComboFix.exe <--- Combofix needs to be directly on your desktop before we continue.
    Okay that's fine. But remember one thread for each machine. Don't piggy back off this one and post logs for the next machine. (Edit, I see you have created seperate threads. Thanks)

    Important. Check that you have version 4.44.0.1000 of SUPERantispyware, if you have an earlier version, you will have to uninstall it and reinstall the new version. Let me know!

    Uninstall this ---> Viewpoint Media Player


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\program files\Microsoft\DesktopLayer.exe
    c:\windows\system32\MsiExecSrv.exe
    c:\program files\Windows Media Player\WMPNSCFGSrv.exe
    c:\windows\system32\lsp46.tmp
    c:\windows\Nfajihikilugoqor.bin
    c:\windows\Jbiyabivebax.dat
    
    Folder::
    C:\Documents and Settings\Zephyr\Local Settings\temp\Rar$DR01.485
    c:\program files\system
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe," 
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Give this a run:

    Using ESET's Online Scanner

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Then run The ESET scanner twice more, attach logs from each of the three runs.

    Let me know how the machine is behaving.
     
  3. jefzef

    jefzef Private E-2

    Did all, logs attached. Still behaving badly. Last ESET log is smaller because I manually deleted over 3000 files that it deemed infected which I have backed up elsewhere.

    I'm also including a SuperAntispy log from a scan I ran after I followed your instructions. I plan to run Malwarebytes again after I post this, and I will send that log later.

    Thanks
     
  4. jefzef

    jefzef Private E-2

    more logs
     

    Attached Files:

  5. jefzef

    jefzef Private E-2

    ESET logs were too big, now all three are zipped
     

    Attached Files:

    Last edited: Oct 16, 2010
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry for the delay in a response. Very busy weekend.

    Run a further 3 Eset scans, one after the other, without rebooting, attach logs from each sweep and then:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    How is the computer running?
     
  7. jefzef

    jefzef Private E-2

    Machine is painfully slow. I'll let you know more after I play around a bit.
     

    Attached Files:

  8. jefzef

    jefzef Private E-2

    This machine is badly off. It's running intolerably slow, and still getting redirects. I don't have the patience to examine any further. I'm hoping the logs will show you something.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this folder:
    • C:\Program Files\System

    And this file:
    • C:\WINDOWS\system32\iexplore.sy_

    (Let me know if they delete fine or if you have problems)

    You either persevere with the cleaning to get your machine back to normal if we can or you give up :( Choice is yours, you came to me with an infected computer and it is my job to clean it, but that is your choice whether you want to persist or not.

    If you want to persist I shall be asking that you run three more ESET scans and attach logs and then run the C:\MGTools\Getlogs.bat again and attach the C:\Mglogs.zip
     
  10. jefzef

    jefzef Private E-2

    I should have qualified that with "because it's 2:45am".


    I made your deletions without any problems. Even after a reboot, they were still gone. Those scans take a long time. I'll have the logs for you when they're done.

    Thanks.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay. Keep going! :) I will be here waiting.
     
  12. jefzef

    jefzef Private E-2

    Latest logs.

    Thanks.
     

    Attached Files:

  13. jefzef

    jefzef Private E-2

    I should mention this to you also. It's been happening fairly often. Here is the complete error message:

    Generic Host Process for Win32 Services has encountered a problem and needs to close. We are sorry for the inconvenience.


    szAppName : svchost.exe szAppVer : 5.1.2600.5512 szModName : ntdll.dll
    szModVer : 5.1.2600.5755 offset : 00023845


    C:\DOCUME~1\Zephyr\LOCALS~1\Temp\WER29f3.dir00\svchost.exe.mdmp
    C:\DOCUME~1\Zephyr\LOCALS~1\Temp\WER29f3.dir00\appcompat.txt
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Zephyr\Local Settings\temp\gstD8.tmp
    c:\program files\microsoft\desktoplayer.exe
    C:\Documents and Settings\Zephyr\Application Data\Xizor\imyhp.exe
    Folder::
    C:\Documents and Settings\Zephyr\Application Data\Xizor
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "{99F8E7B9-2A61-A027-3401-75722DAEE40E}"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe," 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Run the ESET scanner three more times without rebooting in between as usual and attach all of the logs.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  15. jefzef

    jefzef Private E-2

    Very helpful.

    The following line didn't show up in the HJT scan.
    All but two files were cleaned by ESET.

    That error is still showing up:

    It's certainly running a lot faster now. The attached logs were run before a reboot. Let me know if you need to see more to confirm the bad files haven't returned.

    Thanks. This is really great.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please post as an attachment the appcompat.txt file. You may be having a software compatibility problem. The file may be too large to post and you may need to compress it with WinZip or similar before posting. (But I am pretty sure you may have to resolve this in the software forum as it is not a malware issue) You could also give ccleaner a run, or delete thoe whole WER2382.dir00 folder.

    Well we are not quite out of the woods yet but have made significant progress.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\program files\microsoft\desktoplayer.exe
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe,"
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Back to the ESET scanning, three times in a row without rebooting as usual. Attach those logs and then:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. jefzef

    jefzef Private E-2

    Third run of ESET came up clean.

    Logs attached.
     

    Attached Files:

  18. jefzef

    jefzef Private E-2

    Just in case you want to see the MGlogs after reboot. The machine does slow down after reboot.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, those logs look good to me now. :) If you wish you can have a rip through a couple more ESET scans? Let me know, if I was you I probably would do a couple more. But I think we will be headed towards final steps soon now. Any other non malware related issues will have to be further discussed in software.
     
  20. jefzef

    jefzef Private E-2

    Ever since the reboot, it runs extremely slowly. ComboFix is still detecting rootkit activity. Still getting unsolicited tabs/windows popping up. Sorry for the bad news.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run Combofix again.

    Then:

    GMER - running with a random name

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds