Hacked by MOOzila

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by seshgeek, May 9, 2007.

  1. seshgeek

    seshgeek Private E-2

    Hello All,
    I just had installed a new harddisk for my laptop and few softwres were installed by the support person. When I started to work yesterday found that the title bar of Internet Explorer displaying the message "hacked my Moozila" along with the regular title. Tried removing it using spyware doctor but could not remove the malicious program. And in one of the other forums it was suggested that I use HijackThis. I used it and generated a log file. Tried removing two entries that pointed to "Hacked by Moozila" but the malware could not be removed. As I am totally clueless on the system side request your guidance for removing this. Please find the logfile given below and guide me. Thanks for your help.


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.

    Regards,
    SeshUser :cry
     
    Last edited by a moderator: May 9, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Sounds like you may have the VBS.Solow.D worm. HijackThis logs are not an adequate measure of a PCs malware status. You need to run our full cleaning procedures so that we can be sure we remove all your malware.

    Why are you running this PC without an antivirus and without a real firewall? A good up to date antivirus probably would have prevented this worm from getting on your PC.

    Also your Spyware Doctor program does not appear to be running properly. Either that or it is an old out of date version of the program. What version is it and is it a paid subscription that is kept up to date?

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. seshgeek

    seshgeek Private E-2

    Thanks a lot for your guidance..
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I assume that means you are going to follow those directions?
     
  5. seshgeek

    seshgeek Private E-2

    Hi Chaslang,
    Please find attached the log files (Part - I). But think still the problem persists. i.e. IE title bar still shows "Hacked by MOOzila"

    Online Virus And Trojan Scanning could not be run from SafeMode.

    Two users
    1. Administrator
    2. Sys

    I was not able to generate the report for CouterSpy. I have taken a screenshot of the result. The problem identified is with Alexa Toolbar.

    Thanks,
    S
     

    Attached Files:

  6. seshgeek

    seshgeek Private E-2

    Please find attached the log files (Part - II).
     

    Attached Files:

  7. seshgeek

    seshgeek Private E-2

    Please find attached the log files (Part - III).
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is an easy thing to change to anything you want.
    Run Spybot and click Mode, and select Advanced mode.
    Then in the left column click on Tools to expand it.
    Then doule click IE tweaks.
    You will see an Internet Explore custom title line with Current user and also for All users.
    Either erase what is on the lines, or put in something of your own choice and then click the Apply buttons.

    Did that work?

    I will get back to you later when I have a chance to go thru your logs. I have run out for awhile.
     
  9. seshgeek

    seshgeek Private E-2

    Thanks, Chaslang..

    I will wait for your feedback, before start using the machine..

    Regards
     
  10. seshgeek

    seshgeek Private E-2

    Hi Chaslang,
    Each of my drive has a folder called RECYCLER and System Volume Information. Are they required or were they planted by malware.

    Thanks,
    S
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal!! That's your Recycle Bin and System Restore.


    Did you run PandaActiveScan before running BitDefender? It is strange that Panda is finding what BitDefender says it deleted.

    Why are you running this PC without an antivirus and without a real firewall?

    Is your copy of Spyware Doctor a paid version of free trial? If free, uninstall it.


    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [MS32DLL] E:\WINDOWS\IISDLL.dll.vbs

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now use Windows Explorer to find the below files and delete them if found.
    E:\autorun.inf
    E:\IISDLL.dll.vbs
    E:\WINDOWS\IISDLL.dll.vbs
    F:\autorun.inf
    F:\IISDLL.dll.vbs
    G:\autorun.inf
    G:\IISDLL.dll.vbs
    H:\autorun.inf
    H:\IISDLL.dll.vbs

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. BitDefender online scan
    2. HJT


    Make sure you tell me how things are working now!
     
  12. seshgeek

    seshgeek Private E-2

    Hi Chaslang,

    Thanks a lot for your help and guidance.

    Did you run PandaActiveScan before running BitDefender? It is strange that Panda is finding what BitDefender says it deleted.
    Nope. BitDefender was run before running PandaActiveScan.

    Why are you running this PC without an antivirus and without a real firewall?
    That was a mistake. Replaced the HardDisk and got the machine back from the vendor just last week.

    Is your copy of Spyware Doctor a paid version of free trial? If free, uninstall it.
    Free. And now it has been uninstalled.

    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MS32DLL] E:\WINDOWS\IISDLL.dll.vbs
    After clicking Fix, exit HJT. Now reboot in normal mode
    Done

    Now use Windows Explorer to find the below files and delete them if found.
    E:\WINDOWS\IISDLL.dll.vbs - Not Found
    Removed all other autorun.inf and IISDLL.dll.vbs from E:, F:, G: and H:

    I also found the following anonymous files (i.e. not under any folder like Windows or Program Files) directly under E drive i.e. my C Drive.
    boot.ini
    NTDETECT.COM
    ntldr (System File)
    pagefile.sys

    Can you also suggest some good anti-spyware and anti-virus (3 licences) that is not costly.

    Regards,
    Sesh
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal required system files!

    In my final steps (at the end of this message), I will give you a link of instructions to follow and there will be a bunch of very good free tools (and some pay tools if you prefer) to use.


    Now run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKCU\..\Run: [Spyware Doctor] E:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q

    After clicking Fix, exit HJT



    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. seshgeek

    seshgeek Private E-2

    Thanks a lot, Sir. Think the malware is removed (there is no additional title message when I open IE). Will definitely follow the instructions given in point 10. Only the programs listed in point no. 8 ShowNew.Zip and GetRunkey.Zip were installed and all other tools listed were not installed.. But I have these tools installed during the cleaning process.. Do I have to remove these.
    1. CCCleaner (in Point 10 this tool has been recommended. So Dont Remove)
    2. SpyBot - Search & Destroy
    3. CounterSpy

    One more question. In my case it was easy to find the system being affected because of the IE title. But how to find if a system is affected if there were no messages. Agreed, (Prevention is better than CURE). But is there a way to find without running these tools.

    Regards,
    Sesh
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall CounterSpy since it is only a trial that expires. Keep the others as they are very useful. Run periodic scans with Spybot and keep it updated and always reimmunize after each update. Run Ccleaner at least weekly to clean up the junk that accumulates.

    There are literally tens of thousands of infections. Some will have an outward effect that is noticeable and many will not. You need to run scans to find most of them because doing it manually yourself requires two things:
    • a very large amount of time every week
    • a vast knowledge of all Windows OS's and file systems so that you can recognize good from bad and so you know where to look.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds