Did all the steps, still getting hijacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by rlibrizzi, Jul 23, 2010.

  1. rlibrizzi

    rlibrizzi Private E-2

    Did the steps in READ & RUN ME FIRST, yes- even the Java one. The problem persists however. When i open a new window it gets redirected to an ad site. I have learned to get around it by opening links in new tabs, but am tired of that already. The scans didnt seem to find very much. I attached some logs, hope you can help.
     

    Attached Files:

  2. rlibrizzi

    rlibrizzi Private E-2

    Ok, i tried to get ComboFix to run after realizing that i was missing a log but it keeps warning me that AVG is still active and may interfere. Apparently it did interfere since it refuses to run. I cannot figure out how to disable it either. help?
     
  3. rlibrizzi

    rlibrizzi Private E-2

    just realized i did not attach the Super AntiSpyware log, so here it is.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  5. rlibrizzi

    rlibrizzi Private E-2

    Ok i finally got ComboFix to run after shutting down AVG and rebooting several times, so here is the log. I thought the attachment called MBAM-log-2(14-38-21).txt was the MG logfile, but have since found the file called MGlogs.zip so i attached it as well. I'm still getting hijacked.
     

    Attached Files:

  6. rlibrizzi

    rlibrizzi Private E-2

    OK, running ComboFix apparently repaired the redirect issue, but I want to know how and why. Can anyone help?

    I also just started a new thread because apparently now my system doesnt have enough memory for WMP11 to play video links from email since i ran all the Malware removal tools. it worked fine before...
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    rlibrizzi

    You have SpyBot Search & Destroy's TeaTimer function running, which can interfer with cleaning your machine. Please see the below link to disable it:
    How to disable Spybot's TeaTimer


    *You also need to run MSconfig and put your PC into normal startup mode as requested in step 4 of the READ & RUN ME guide.

    Use MSconfig to setup for Normal Startup Mode

    You were instructed to saveMGTools.exe to your C:\ directory - not to run it before downloading it.
    C:\Documents and Settings\Rob\Local Settings\Temporary Internet Files\Content.IE5\W6W8RUBE\MGtools[1].exe

    I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Documents and Settings\Rob\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 2:
    b]Run C:\MGtools\analyse.exe[/B] by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 4:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 5:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  8. rlibrizzi

    rlibrizzi Private E-2

    just tried to follow your instructions and disable Spybot's Tea Timer. It was already unchecked. should i continue?
     
  9. rlibrizzi

    rlibrizzi Private E-2

    OK, tried to follow step 2 of your instructions below, and my machine is already in normal startup mode. what gives?
     
  10. rlibrizzi

    rlibrizzi Private E-2

    Re: Did all the steps, no longer getting hijacked... but how?

    Ok I am no longer comfortable following your instructions since the first three steps you outlined were already completed, so i am stopping here. I checked and MGTools is in its own folder in the C: drive. I just downloaded it again just be sure; so now there are two copies.

    My previous post stated that i am no longer experiencing the browser redirect issue; but i wasnt sure how it got fixed. Everything seems to be back to normal- except for WMP11 now says it cant play video links due to not enough memory and my login screen now looks like Win NT, not XP.

    I want to prevent this from happening again, since it has already wasted significant time to fix, and my current prevention methods are obviously not working.
     
  11. rlibrizzi

    rlibrizzi Private E-2

    Ran ComboFix again, this time following your instruction. it worked as stated, but on reboot I now get a StartupMonitor Warning that says 'The program ctfmon.exe has registered the executable C:\WINDOWS\system32\ctfmon.exe to run at system startup. Do you wish to allow this change? Y/N' I have no idea what this is or if I should allow the change...

    will the fun ever end?
     

    Attached Files:

    Last edited: Jul 31, 2010
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No. You don't need Combo to be running on start up. But you should attach this latest Combo log. I have reviewed your last MGLog.zip and am not seeing any issues.
     
  13. rlibrizzi

    rlibrizzi Private E-2

    Thanks, TimW. I wasnt sure what it was... maybe if it was called ComboFix.exe i wouldve connected the two. I answered no just to be safe. I also just ran MGLog.dat so let me know if Im back to 'normal'. This time it rebooted and came back up looking like it usually does- the XP style sign in; so that's a good sign!

    I did attach the combofix logfile- but as an edit to the original post. I'll attach it again here just in case.
     

    Attached Files:

  14. rlibrizzi

    rlibrizzi Private E-2

    ok, scratch that. Forum rules dont allow me to up load the same file twice. That pitch was just a bit out of my strike zone... a swing and a miss.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Fortunately, Combo gets bundled in with the other logs in MGLogs.zip. Your logs are clean. I am not seeing any malware on your system. Are you still having any malware issues?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  16. rlibrizzi

    rlibrizzi Private E-2

    Ready to FINISH. Step 4-Toggle System Resore

    Sorry- watchin baseball. no apparent problems, seems to be running normal for a 5 year old laptop thats just been cleaned. gonna wait a while before i toggle sys restore in case anyone posts a reason not to. thanks for the help, this really is the best place to get real assistance. Great tool selection too!
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    None of your logs indicated any infection in your system restore folders. It is just a precaution to toggle it once you are satisfied that all is well.

    And you are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds