DoJ Hijacker Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by hopson2462, Jan 3, 2014.

  1. hopson2462

    hopson2462 Private E-2

    Hi -

    Trying to clean up my brother-in-law's computer and this is one that's a bit above my abilities. He has the DoJ Hijacker. I've installed FRST64.exe and run it from a flash drive and attached the FRST.txt results here. Would love some help on next steps for getting his laptop back up and running.

    Much appreciated!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    ------------------------------

    Now see if you can work your way through the READ & RUN ME FIRST - Malware Removal Guide
     

    Attached Files:

  3. hopson2462

    hopson2462 Private E-2

    Hey -

    I ran it and I have attached the log file here. In addition I made it through the Malware Removal Guide and I have attached the appropriate logs as well if they are helpful.

    Thanks again, really appreciate the help.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : Google Update (regsvr32.exe C:\Users\William\AppData\Local\Google\3cfax.dll [x][-]) -> FOUND
    • [HJ INPROC][SUSP PATH] HKCR\[...]\InprocServer32 : (\\?\globalroot\Device\HarddiskVolume2\Users\William\AppData\Local\Temp\sxdypuk\sixbvxl\wow.dll [x]) -> FOUND
    • [V1][SUSP PATH] Security Center Update - 1385182120.job : C:\Users\William\AppData\Roaming\Syboave\ipoqyq.exe [-] -> FOUND
    • [V1][SUSP PATH] Security Center Update - 1505904406.job : C:\Users\William\AppData\Roaming\Avuvorix\ikizf.exe [-] -> FOUND
    • [V1][SUSP PATH] Security Center Update - 178651454.job : C:\Users\William\AppData\Roaming\Uderzux\pyapobl.exe [-] -> FOUND
    • [V1][SUSP PATH] Security Center Update - 3951269610.job : C:\Users\William\AppData\Roaming\Beawroo\olodit.exe [-] -> FOUND
    • [V2][SUSP PATH] Security Center Update - 1385182120 : C:\Users\William\AppData\Roaming\Syboave\ipoqyq.exe [-] -> FOUND
    • [V2][SUSP PATH] Security Center Update - 1505904406 : C:\Users\William\AppData\Roaming\Avuvorix\ikizf.exe [-] -> FOUND
    • [V2][SUSP PATH] Security Center Update - 178651454 : C:\Users\William\AppData\Roaming\Uderzux\pyapobl.exe [-] -> FOUND
    • [V2][SUSP PATH] Security Center Update - 3951269610 : C:\Users\William\AppData\Roaming\Beawroo\olodit.exe [-] -> FOUND
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Re run Hitman Pro and have it delete items under the heading Malware.


    Delete these if you see them:

    • C:\Program Files (x86)\GUMC85D.tmp
    • C:\Program Files (x86)\GUTC9D4.tmp


    Re run RogueKiller again (just a scan) and attach the log.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. hopson2462

    hopson2462 Private E-2

    Hi -

    Did everything. No problems running anything. Logs are attached. Computer seems to be running fine now.

    Thanks!
     

    Attached Files:

  6. hopson2462

    hopson2462 Private E-2

    Might have attached the MGtools logs too quickly. Most recent version is here.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  8. hopson2462

    hopson2462 Private E-2

    All set Kestrel13!. Appreciate the help, take care.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. Safe surfing! :=)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds