Firefox hangs after malware/rootkit removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by hitekrednek, Nov 29, 2011.

  1. hitekrednek

    hitekrednek Private E-2

    Greetings. I wasn't playing in my sandbox like I should have been and got hit by malware/rootkit while on a forum (would post name if I recalled which one). The result after running Malwarebytes, Superantispyware, and Combofix...all of which I had from an infection a couple years ago appears to have removed the infection at the cost of hurting a couple features in Firefox (can't download any file in any way, cannot browse to a file on my system and attach to a forum post, cannot access Tools, Options, General -- while other parts are avail in Tools, Options). If I attempt any of those operations, it sits and does nothing. Clicking to go elsewhere or close the window is met with a dialogue to end the Firefox session as it is "not responding."

    After trying multiple solutions to rectify the problem up through and including a 100% clean install of Firefox (all old data removed including registry entries and files/profiles), the issue continues. It also happens in Firefox's safe mode.

    IE 7.x works fine for downloading. It's also what was used to post this so I could attach files. I'm fairly certain that my infection is cured, but some key file(s) that Firefox is dependent upon may be corrupt or missing and I'd appreciate any ideas folks here may have.

    Win XP Pro SP3
    Firefox 8.0.1
    Logfiles attached for review. Much thanks!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.


    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Download a fresh version of Combofix, let it overwrite the old copy. Run the new combofix.exe.


    • Were you able to run Rootrepeal? (If on 64 bit windows do NOT run)
    • Were you able to run MGTools?

    I need to see logs from them.
     
  3. hitekrednek

    hitekrednek Private E-2

    Old version Superantispyware removed, new version installed and run. Found lots of adware trackers. Log attached.

    Tdsskiller run and found nothing.

    Mbrcheck run and log attached.
    Combofix redownloaded, run, logs attached.

    I failed (and it's important) to advise that I had removed AVG and Nmap, and then reinstalled thinking there could be missing DLLs from them. The combofix log will show that.

    I did not run Rootrepeal or MGTools prior to my post because everything I had done had been prior to coming back here. I didn't want to cause anymore problems than I may already have done by running more stuff. If you need me to run them, please advise and I'll make it so.

    Much thanks!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. :)
     
  5. hitekrednek

    hitekrednek Private E-2

    Thanks for the amazingly fast response. Didn't expect that and so I'm tardy on mine. The logs as you requested are attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    AVG 8.5 <--- You really ought to be running the current version of AVG not this very outdated version.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
    O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    After clicking Fix exit HJT.


    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\All Users\Application Data\K58ht5x.dat
    C:\Documents and Settings\Shanen\Templates\5rsib6l462hk4lw57
    C:\Documents and Settings\Shanen\Templates\txq0352edo0f38t42o3413ud5p
    C:\Documents and Settings\Shanen\Templates\ueu4ue45lg20w7c4ddf
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. hitekrednek

    hitekrednek Private E-2

    I thought it was. I haven't modified it to be otherwise knowingly. Is that was this process is designed to do?

    I agree. Will take care of that when the system is functioning normally again.

    No problems encountered in following the instructions except one item that was out of the ordinary.
    -Run of GetLogs.bat gave me an error on the Hijackthis portion of type 5 I think it was. I ignored and allowed it to keep running.
    The system rebooted itself durring the Combofix routine. Things seem to function normally as they have been since the original stuff I did on my own. Firefox still hangs and goes to "Not Responding" if I try to access the Tools, Options, General. Trying to do a download continues to yield the same behavior as well.

    I do appreciate the help and you sticking with me on this. I have confidence! :)
     

    Attached Files:

  8. hitekrednek

    hitekrednek Private E-2

    Things just got worse. I was running the laptop last night, hibernated at the end of the session like usual, and now when I try to start it up, I get "Loading PBR for descriptor 2...done" with a blue line across the top saying "www.dell.com."

    I have nothing plugged into it in the way of a USB drive or anything. It just doesn't pass this screen now. Something tells me I'm going to have to use a linux boot, burn data to a CD, and wipe this thing. But I'm open to other options if they exist!
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. Sorry to hear you have run into problems. I know you only posted a couple hours ago but has there been any change? Are you able to boot up the computer in safe mode?
     
  10. hitekrednek

    hitekrednek Private E-2

    No, I can't access safe mode at all. I found some info online that may prove helpful (http://www.nairaland.com/nigeria/topic-94562.0.html) although it doesn't say "Bad PBR" in my case. I'll be trying that tonight (I'm in US Eastern time) to see if I can get in with the windows CD to run a fixboot (unless you tell me bad idea).

    If that doesn't work, and barring other suggestions, I'll be using a Linux boot, getting my data that I want, and wiping the system. One thing is certain...that will kill any virus that was there unless it somehow crept into data files and I don't think that's the case.

    Thanks for the response and I'll watch to see if you have anything else within the next 5 hours or so before I start working on it.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    To be honest I would be more comfortable with you posting about this in the software forum, the guys and gals in there can hopefully help get you back up and running into a state where you can return here to continue on with malware removal. :)
     
  12. hitekrednek

    hitekrednek Private E-2

    It's all good. I backed up my data and reinstalled the OS after I thoroughly researched the error that seems to effect only Dell systems. If a couple of very distinct things don't initially work, the only hope is a reinstall of the OS which I've done on my own many times.

    That has been accomplished at this point. So we can call my system clean and 100% functional (as Firefox is behaving the way it should too.) :) I don't know what caused it to fail in the way it did and I'm not going to worry about it. I do appreciate your attempts to help. Thanks again.

    This issue is closed.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad everything is running as it should be. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds