Goored or variant. Help please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by amo, Nov 8, 2010.

  1. amo

    amo Private E-2

    I was using Firefox, Antivir, XP's firewall when I clicked on a Google link and apparently picked up some sort of malware. I was able to eradicate part of it, but Firefox/Google was still redirecting me to some site I couldn't see because McAfee SiteAdvisor blocked it. I couldn't stop the redirects, so I (probably in error) uninstalled Firefox. After uninstalling Firefox, *then* I came here and followed the directions. Oops. I also tried to restore to an earlier restore point before I was having problems and that didn't work. It said I had insufficient disk space, even though I have plenty.

    I have followed the READ & RUN ME FIRST instructions, and RootRepeal apparently found something but did not appear to fix it!

    My questions:
    1. Do I need to do something else to fix the problems RootRepeal detected?
    2. Is it "safe" to reinstall Firefox now?
    3. Anything else I need to know?

    I'll attach the logs as directed.
     

    Attached Files:

  2. amo

    amo Private E-2

    The rest. I'd be happy to furnish any additional information required.

    Thanks so much!
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\WINDOWS\system32\(app)
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-
    [-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [-HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"=-
    [-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [-HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    RegLock::
    [HKEY_USERS\S-1-5-21-789272640-1166441867-1707686431-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{895B1351-875F-F950-787D-9E23FD6CBDA2}*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    "oaccbplhloanibmfkhpckbeobplmam"=hex:64,61,62,69,6f,65,69,68,00,85
    "oaoabpecndpobjaelhpnlgipfnkenb"=hex:6a,61,62,69,6f,65,64,67,6d,68,66,70,6a,69,
       63,61,6c,6b,6a,65,00,02
    "naechafbciopcgijfigocofmjfkh"=hex:6a,61,62,69,6f,65,64,67,6d,68,66,70,6a,69,
       63,61,6c,6b,6a,65,00,02
    Folder::
    c:\program files\AskBarDis
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Run this

    GMER - running with a random name

    We don't know that they are problems yet but the strange characters do make it look odd. I would suggest that you have the E:\Drive plugged in whilst doing a full scan with both Malware Bytes and SUPERantispyware, if you opt for a full/complete scan you can choose other drives to scan.
    Let me know if they find anything. Attach the logs if they do.

    Run RootRepeal again and attach the log.
    Yes.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running for you now.
     
  5. amo

    amo Private E-2

    1. Ran TDSSKiller. Log attached.
    2. Ran MGtools/HJT and selected and fixed items as instructed.
    3. ComboFix with script. Log attached.
    4. GMER. Log attached. After a significant portion of the scan had already been completed, I noted that my E: drive had not been checked to be included in the scan. Should I re-run with E included?
    5. I ran Malware Bytes and SUPERantispyware on C: and E:. Both scans came up negative, so I didn't attach the log files.
    6. RootRepeal seemed to show the same problems/issues on E: that were there before. I can't think of a logical reason for those strange characters/filenames to be there. It's just a backup drive. Log attached.
    7. I reinstalled Firefox but haven't put it through its paces yet.
    8. MGLogs.zip attached to next message.

    Should I try to re-create the problem with a Google search in Firefox or is there more cleanup to do?

    Thanks so much for your help!
     

    Attached Files:

  6. amo

    amo Private E-2

    MGlogs.zip
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yep. Might as well.

    Yes, surf around a while, see how things are.

    You're welcome!

    Re-run with GMER, attach the log, let me know how things are and we'll see what to do next.
     
  8. amo

    amo Private E-2

    I tried to re-run GMER, and it stalled/hung. I couldn't even get to the point where I could check the box for E: to be scanned.

    So I started up Firefox and was able to reproduce my earlier problem. When I searched for dictionary.com on Google, first result was a McAfee Site Advisor approved link to dictionary.com that worked. When I searched for "ingenuous" and clicked on the first Google result that was also supposed to be at dictionary.com, I got a McAfee Site Advisor warning.

    So I uninstalled Firefox again, rebooted, and tried to run GMER again. I got far enough to check the box to scan E: but the program stalled/hung after only scanning a few items.

    My guess is that I partially fixed the problem with the "run me first" directions and then reintroduced it when I reinstalled Firefox. How should I proceed?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this and attach the results. (have your back up drive plugged in)

    Using ESET's Online Scanner

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    I may not have an internet connection tonight at my Father's house, so if not I will return tomorrow night.
     
  10. amo

    amo Private E-2

    ESET result attached. It found and fixed 3 items.
    New MGLogs.zip attached.

    What's next? :)
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please delete this:
    C:\Documents and Settings\Angela\Local Settings\Application Data\Orzeszek

    Now tell me what malware issue, if any, that you are still having.
     
  12. amo

    amo Private E-2

    Deleted Orzeszek.

    I am not currently having any problems.

    But my problems were originally in Firefox with Google search redirects and I uninstalled Firefox.

    When I reinstalled it, my problems came back, so I uninstalled it again. Should I reinstall and see what happens?

    I did (of course) go to mozilla and get a fresh download last time, and when I uninstalled, I deleted my personal information/settings/bookmarks, so I don't know how/why the redirect came back unless I never got rid of it in the first place. But if my logs are clean, I guess I should try again?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. amo

    amo Private E-2

    Oops. I didn't notice that you gave me a link until I had already downloaded it again from mozilla.

    Anyway, upon further investigation, it looks like McAfee Site Advisor had a false (or real, doesn't really matter) positive on www.dictionary.com that *looked* like it was related to my previous problems but was not actually related to my previous problems.

    I did several other Google searches with no redirects, so if my logs are clean, then I guess I'm good to go.

    Many, many thanks!
     
  15. amo

    amo Private E-2

    Sorry. My link in my previous message should probably be removed in case McAfee Site Advisor is right!
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    McAfee is wrong. I just went to that site and WOT marks it as excellent.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  17. amo

    amo Private E-2

    Hm. My computer is booting slowly. During the course of cleanup, I seem to recall adding/running something that added an extra step to the boot sequence, but I don't see it right now and I don't remember what it was. It flashes on the screen too quickly for me to read it, although I guess if I need to, I can reboot and try to catch it/select from the list. Any ideas?
     
  18. amo

    amo Private E-2

    It's the Microsoft Recovery Console, which got added during the course of my clean-up. Can I turn that off or should I just live with it? Also all sounds related to startup play many seconds after the events they're associated with.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is best to keep the recovery console installed in case of future malware attacks. It only adds a second or two to your start up time. As to your delayed sound issue, I suggest you post in the software forum for that issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds