Hacked Audio and Browser Re-direction from Google and G-mail

Discussion in 'Malware Help (A Specialist Will Reply)' started by Cubasa, Jan 29, 2011.

  1. Cubasa

    Cubasa Private E-2

    A couple days ago I was using the Google image search engine when I was bombarded with an abundance of infections (Trojans, malware, etc.). Microsoft Security Essentials was left inaccessible.

    A false anti-malware program (Personal Internet Security 2011) was installed as well. I took steps to fully remove it from my computer (www.bleepingcomputer.com) which seemed to solve at least that problem. Upon downloading and running Malwarebytes I found over 170 infected files which the program seemed to remove quite easily. I have attached a log of this under the name mbam-original.txt for further reference.

    Four visible issues remained after the removal process and reboot:

    1) When using either internet browser (Internet Explorer or Firefox) and Google as a search engine, every third site will re-direct me to another search/spam site. A blank white screen is displayed that simply reads, "The document has moved, redirecting," which then it directs me to a site such as Monster Marketplace.

    2) When using either internet browser (etc.) I cannot access gmail at all. It reads "The connection was interrupted - The connection to www.google.com was interrupted while the page was loading."

    3) When trying to access any site with re-captcha displays (such as signing onto your site) the picture of the words that you must type in is not displayed. It is as if the re-captcha image is being blocked.

    4) The most intimidating problem is that while using Internet Explorer and the Google search engine, it has occasionally redirected me to a site and when I try to close the window a odd window (total height of screen with only 1/5 the length) appears asking "Are you Sure you Want to Close Internet Explorer?" When I try to exit the window or click YES the window remains and unknown audio starts to come through my speakers (starting off with a blast of lasers and then a bunch of advertisements). Due to this issue I have not been using internet explorer but after performing the complete instructions in the READ & RUN ME FIRST section, this problem has not happened yet.

    I have followed all steps in the Read and Run ME First guide, including:

    1)Fixing Google Redirection/Hijacking Problems - no difference was made

    2) No issues with connecting to internet so no ProxyServer-Changing Settings

    3)Limited my Anti-virus/Anti-malware programs to Microsoft Security Essentials and Windows Firewall

    4) Performed all House cleaning procedures including CCleaner

    5) Use all programs for cleaning and which SuperAntiSpyware found two more threats. After running ComboFix some ghost files (gray icons) have appeared on my desktop, some of which I previously deleted and some I am unaware of (desktop.ini, ~WRL000, etc.) so I am not sure what they are.

    6) I have returned my Use Account Control to their full settings, which is the only thing I changed from your directions until I get a reply.

    I am running a HP Pavilion dv7 Notebook Pc with a 64-bit op (Windows 7). Lots of memory (6.00GB RAM) so that is not the problem. If there is any other information you need I will be happy to supply it.

    I have been reading many posts on your site about similar problems and I believe this is a much worse problem then I originally imagined. I really appreciate you looking at my logs and look forward to your response. I really appreciate your team's work!
     

    Attached Files:

  2. Cubasa

    Cubasa Private E-2

    Sorry I may have doubled my original post my accident. For this I apologize.
     

    Attached Files:

    Last edited by a moderator: Jan 29, 2011
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:25527

    After clicking Fix exit HJT.


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\programdata\ac31ca
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{A9DB8F31-C852-4A14-8E79-6764BD89638A}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A9DB8F31-C852-4A14-8E79-6764BD89638A}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  4. Cubasa

    Cubasa Private E-2

    I apologize for my untimely response however I now am able to fully dedicate myself.

    I have attached the logs for:

    Combofix
    bootkit_remover
    MGlogs

    I hope this helps. I have noticed files that are currently quarantined in a file within my C drive

    Qoobox - which I believe is related to Combofix

    Should I be doing anything with these files?

    I really appreciate your guidance with this issue.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this folder if it lets you.

    You will need to change the boot order in the bios to make the cd-rom the first boot device.

    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr, and then press ENTER. ( There is a space after the .exe and the / ).

    Now reboot into normal mode and run this tool.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. Cubasa

    Cubasa Private E-2

    I deleted the program data ac31ca and it successfully deleted.

    However I do not have either a Windows 7 nor a Vista installation disc. I do have the recovery discs (3 in total) I created when I purchased the HP machine. I tried putting in the first disc and pressing F11 and it gave me several options:

    F1 System Information
    F2 System Diagnostics
    F9 Boot Device Options
    F10 BIOS Setup
    F11 System Recovery
    F12 Network Boot

    After selecting system recovery an HP Recovery Manager was executed and gave me 3 options:

    1) To either perform Microsoft System Restore or System Recovery

    2) Run Computer Checkup

    3)File Backup Program

    Can I access the command prompt by selecting System Recovery in the 1st group of choices? Or is there another way of performing Bootrec.exe?

    Thanks for your continued assistance!
     
  7. Cubasa

    Cubasa Private E-2

    Sorry, but I forgot to mention that it is running unbelievably better.

    There are no more redirection problems at all for Firefox (haven't tried internet explorer yet fully). Loading time is reduced. No Audio intrusions.

    Overall, it is working fantastically!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just run MBRCheck as instructed and attach its log.

    Then if I am still seeing a problem then you can start looking at this (considering you do not have your disk)

    Windows Vista Recovery Disc Download
     
  9. Cubasa

    Cubasa Private E-2

    Ran the MBRCheck and it gave me two logs so I attached them both.

    Thanks
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Take a look at the Windows Vista Recovery Disc Download link in post # 8 as I am seeing a problem still.
     
  11. Cubasa

    Cubasa Private E-2

    No problem.

    Since my operating system is Windows 7 (64 bit) should I run the Windows Vista 64-bit Recovery Disc Torrent or should I run the Windows 7 Recovery Disc 64 Bit Edition?

    This might seem a pointless question but you have referred to downloading the Vista recovery disc so I want to make sure I download the right recovery disc.

    Thanks for your continued help!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes.
     
  13. Cubasa

    Cubasa Private E-2

    I ran the recovery disc (had to bring it up by selecting it from my boot options).

    I followed the exact steps that you mentioned in the previous post.

    I took the initiative of running MBRCheck again and attached both logs that were created... Seems like it might've worked?
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. It has. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. Cubasa

    Cubasa Private E-2

    I went through the entire end process and everything seems to be working just like new.

    I truly appreciate your service and Majorgeeks' for providing me the invaluable assistance. You are all saints in my book but thanks to you Kestrel13! in particular.

    Wow I can't believe you got this problem fixed! Thanks again
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds