Browser redirects, Black screen with cursor, no MSCONFIG in search resutls T.T

Discussion in 'Malware Help (A Specialist Will Reply)' started by Katibree, Jan 14, 2010.

  1. Katibree

    Katibree Private E-2

    Hello guys, I've been browsing the threads trying to fix my browser redirect problems with the Malware Removal guide that is posted, but have run into another problem all together.

    First off, I run a model CQ70-12OUS COMPAQ notebook with Vista Home on it. It did't come with any addidtional disks or anything.

    The original problem I was trying to remedy was browser redirects, extra spam explorer pages, and problems with one page closing all pages on IE and then restarting a Mywebsitesurveys.com page. (I'm not sure if that's exactly what it was called.)

    Anyway, I know the problem orignally started from Limewire. I know the rules and I ignored them while trying to get a hold of two discontinued PC games. (Dungeon Keeper, and Dungeon Keeper II)

    I got a message from Norton Antivirus (3 month subscription that came with the Laptop) saying that it blocked some Trojans, rolled my eyes in not-surprise and ran Spybot Search and Destroy, along with Advanced System Care after deleting what I'd uploaded. I found a few trackig cookies and that's it.

    Then the problems started with my IE. Addresses typed into the address deal where not redirected, but any links clicked after a search on Google or Yahoo were.

    I pulled out my secondary laptop to navigate my searches with and then followed the instructions in the Malware Removal Guide on the infected computer. I'm sorry, I don't have any logs yet... I originally thought that I've dealt with spyware before and was just fine reading other peoples fixes that I won't even need to ask for help, let alone post my results. (WRONG)

    SUPERantispyware, loaded and ran as well as Malwarebytes, but MGtools was auomaticly closed everytime I tried to initiate a download. I burned it to disk from a clean computer and then installed and ran it on the infected one.

    I was still having the redirect problem after all of that and then said fine, I'll rerun everything and get the logs this time to post. Re-ran SUPERantispyware and found 7 infections, amoung those a worm with some Vundo and Trojans.

    SUPERantispyware prompted me to reboot (again) to remove the rest of the infections on start up. On start up, I logged on as Admistrator and was faced with a black screen with moveable cursor. This happens on all modes and accounts.

    I looked that problem up online (only found the problem for XP in Majorgeeks) and tried the pushing shift 5-10 times to bring up the Access Center and typed MSCONFIG in the search. Not found. I then turned off the laptop and wrote this. Is there anything I can do or have I pretty much screwed the pooch by not getting my logs and seeking assistance earlier? :-o

    Any help is appreciated, thanks.
     
  2. Katibree

    Katibree Private E-2

    I managed to get this as well by openning up the Easy Access deal and mailing the information to myself before everything closed again. I still have the Black Screen of Death and anything that is up and running for... I'd say over a minute is closed down with no error message. (unable to complete malware scans)



    Hopefully this helps.
     

    Attached Files:

    • HJT.txt
      File size:
      8.6 KB
      Views:
      2
    Last edited by a moderator: Jan 16, 2010
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes you caused yourself a lot of unnecessary grief by not following our instructions which clearly stated to run scans only once and attach the logs if still having a problem. Also they stated to try all steps but keep on going if any particular step does not work.

    Can you get Task Manager to open by by pressing CTRL+SHIFT+ESC ?

    Can you get Windows Explorer to run from Task Manager?

    Can you get a command prompt window to open from Task Manager?

    Can you run C:\MGtools\analyse.exe from Task Manager?

    If you can run analyse.exe from Task Manager, do the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\Windows\system32\winlogon32.exe
    O4 - HKLM\..\Run: [smss32.exe] C:\Windows\system32\smss32.exe

    After clicking Fix, exit HJT.

    Then reboot and see where things stand.
     
  4. Katibree

    Katibree Private E-2

    I was able to open Taskmanager with CTR+SHIFT+ESC and following the instructions brought the desktop icons back, thank you so much!

    Now am I to follow the Malware Removal Guide from here and post my findings, or are there other special instructions that I need to follow now?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should run the READ & RUN ME FIRST cleaning process and attach the 5 requested logs. Don't do anything else on your own and don't follow procedures given in a thread belonging to someone else. The only common thing to run is the READ & RUN ME FIRST. From that point on, all instructions are unique to user posting in the thread.
     
  6. Katibree

    Katibree Private E-2

    I was able to run everything but MGTools. When I tried to run the GetLog.bat file, the Comand Prompt box would appear and then vanish right afterwards. Other than that, here are the other logs requsted.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your ComboFix log, you ran MGtools before combofix and already have a log per the below
    Code:
    2010-01-12 06:21 . 2010-01-12 06:43 193402 ----a-w- C:\MGlogs.zip
    What is this log from? Did you already run MGtools a week ago? What happens if you download the current version of MGtools.exe and run it again.
     
  8. Katibree

    Katibree Private E-2

    Yes I ran MGTools a week ago right before I had the blackscreeen with cursor deal. It was run while I made the mistake of running the other malware scans multiple times instead of just once and posting the results.

    Then I was getting an error basicly saying that I didn't have authorization to download the application so I burned it to a CD and copied it to the C drive of the computer and ran it from there. That was the version I was trying to use this time.

    Anyway, with most of the infection gone I was able to download the most current version right onto the laptop as you suggested and here is the log I got after running MGTools.
     

    Attached Files:

    Last edited: Jan 19, 2010
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running this PC with NO protection????

    You need to put ComboFix.exe directly on your Desktop as requested!!! You ran it from the below folder:
    Running from: c:\users\Administrator\Downloads\ComboFix.exe

    You used shortcuts on your Desktop to do this and that is not what we specified to do. You will not be able to follow the below instructions until you do this properly.

    Delete the below files from your Desktop:
    C:\Users\Administrator\Desktop\ComboFix - Shortcut.lnk
    C:\Users\Administrator\Desktop\combofixlog.txt
    C:\Users\Administrator\Desktop\ComboFix.exe - Shortcut.lnk

    Also delete the below folder:
    C:\Users\Administrator\Desktop\MGtools



    Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Katibree

    Katibree Private E-2

    I followed the instructions up to dragging the CFscript.txt onto the Combofix.exe on the desktop and rebooted when prompted. As the laptop began to shutdown a error flashed sayng something along the lines of: catchme.exe failed to initialize. The error was gone and the computer already shutting down before I could get the exact message.

    When the computer started back up, I let combofix prepare it's log and then went to try and run CCleaner and got the following message:

    C:\Program Files\CCleaner\CCleaner.exe

    Illegal operation attempted on a registry key that has been marked for deletion.

    I now get this same message for just about any other program I try and run as well. For IE the message is:

    C:\Program Files\Internet Explorer\iexplore.exe

    Illegal operation attempted on a registry key that has been marked for deletion.

    I'm unable to even open the Combofix log that was just created due to the same error.

    Did I run something incorrectly?

    Oh and I did have Norton Antivirus as protection, but it came with the laptop and the subscription was expiring in a few days so I just uninstalled it instead of disabling what needed to be disabled.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.

    After running the above, reboot your PC and see if you can continue with previous instructions from the point after ComboFix was run. Do not run ComboFix again.
     
    Last edited: Jan 24, 2010
  12. Katibree

    Katibree Private E-2

    I ran the scan and was able to access everything again after the reboot. Everything seems to be running fine now with no browser redirects or spam IE pop ups like before, thank you so much! Here are the logs requested.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds