Have that Google Hijacker too

Discussion in 'Malware Help (A Specialist Will Reply)' started by blackprophet, Dec 6, 2009.

  1. blackprophet

    blackprophet Private E-2

    My google is not working at all, redirecting all searches.
    I can't access Gmail from my computer (pain in the ***).
    Getting popups for all the websites I visit. When I run MBAM and Superantispyware I get a virus popup, but my virus checker finds nothing.
    Rootrepeal does not work for me.
    Logs are attached.

    Next post will have picture of Virus pop-up.
     

    Attached Files:

  2. blackprophet

    blackprophet Private E-2

    here is the popup I get from running MBAM and SAS.
     

    Attached Files:

  3. blackprophet

    blackprophet Private E-2

    Ran That TDSSKiller that I saw in another thread. Figured I would save you some trouble :). That got rid of all the crazy popups, but it hasnt fixed the google problem. Here is the log.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's see what happens after completing the below instructions:

    1. FYI- The MGTools you currently have is a couple versions out of date, so we will correct that further on down...

    2. Please go to Add/Remove Programs and uninstall the below out of date version of Java:

    3. Now we need to restore your host's file!

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    4.Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    5. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    DirLook::
    C:\SafetyCenter
    C:\Users\Lawnchair\AppData\Local\cnmapc
    
    File::
    C:\usc4l.bat
    C:\fpofmum.exe
    C:\1486608570
    C:\2.js
    C:\3.js
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    6. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    7. Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    8. Now run the new MGTools.exe and attach the C:\Mglogs.zip that it creates, also attach the log from Combofix and SUPERantispyware.

    9. Let me know how things are running now please.

    Thanks
    Kes13!
     
  5. blackprophet

    blackprophet Private E-2

    I had cleaned the host errors using HijackThis, I didn't post it because of the no bump rule. (I had already gotten bumped with the other post, before I read the no bump post!)

    I did run everything that you said, and it seems that everything is working fine. But some stuff was found in these new scans. The logs are below.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Almost there... little bit to do...

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Folder::
    C:\SafetyCenter
    c:\users\Lawnchair\AppData\Local\cnmapc
    
    DirLook::
    C:\ProgramData\TEMP
    C:\$RECYCLE.BIN
    
    Registry::
    
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "SpybotDeletingB2706"=-
    "SpybotDeletingD9453"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. blackprophet

    blackprophet Private E-2

    I don't know if I notice any marked difference from before. I think it was just a few small things to get rid of anyways. Logs are below.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Everything is ship shape ;) Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. blackprophet

    blackprophet Private E-2

    Thank you very much! I'm pretty savy at these things (I realize how much now that I have looked at some of the other threads) but its always nice to get help. You guys provide a great service here, keep it up.

    I do have one more question :). I am currently running Trend Micro PC-Cillin on my computer, but it has expired. Looking through the "how to protect yourself" thread, it suggests using a free scanner over a paid one. Do you guys really suggest using something free over resubscribing? What are the advantages of paying for one? Or is there not one? If there isn't, what is the business case for certain companies to offer a free version and a paid version. I am seriously considering getting Comodo cause its the AV and Firewall in one.

    I know, I know, only one AV :-D

    Lots of questions I know. :p Thanks again.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a problem :)

    Yes most of the paid for "all in one" security suites are a drain on resources especially for people who are low on memory anyway. There isn't much a paid for anti virus can do that a free one can't IMO.

    I remember starting off with Norton and the nightmares I had with it soon led me to uninstalling it and installing Avg instead. But that was the 7.5 version which I liked, since it has been updated, it too has become rather resource hungry, so I use Avast! which yes is the king of false positives, however I can easily recognise them and deal with them appropriately as and when they occur.

    Recent updates to Avast! caused some awful problems for some people where Avast was flagging legit system files as being "threats".

    It is best to protect your machine with the layered approach: install an anti virus, a seperate third party firewall, and some anti spyware programs. (I long ago uninstalled spybot search and destroy) I now use the free versions of both SAS and MBAM along side my avast, and PC Tools firewall on my XP machine. On Vista I have Avast! and only use the windows firewall.

    You will be sure to have lots more feedback and viewpoints on this if you were to post in the software forum where you can discuss it in depth if you wish.


    Safe surfing :)
    Kes13!

    wouldnt bother.... (personally) I'd go for the firewall but I wouldn't bother with threatfire
     
  11. blackprophet

    blackprophet Private E-2

    DAMN!

    My browser has started redirecting again. Hits in gogle will go to random websites on the first 3 clicks. The fourth click will work. I'll post my most recent logs. Combofix one is not there cause its down (not sure how long it will be). RootRepeal did not work (just like before).

    Also while I was running MGTools, I got the message "ProcDLL Logger has stopped working and must shut down", I'm not sure if that is relevent or not. if it is a Keylogger, clearly it is. I did get it back when I did this the first time.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does it redirect in both Firefox and IE? Does the same occur in safe mode?
    Part of MGTools, nothing to worry about, it most certainly isn't a keylogger.

    1. Download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    2. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Code:
    C:\Windows\[B]TEMP[/B]
    C:\Users\Lawnchair\AppData\Local\[B]temp[/B]
    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger.

    4. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  13. blackprophet

    blackprophet Private E-2

    Yes, I tried switching back and forth to see if one worked better than the other.

    Your Good! I tried to see if it happens in safe mode, and when my computer loaded in safe mode with networking, All I got was Privacy Center (Which is clearly Malware). When I tried closing it, I couldn't, it said that action was not allowed. When I stopped the process, Windows didn't even continue to load so I could see the start menu. I had to restart by using ctrl-alt-del.

    Google is still redirecting.

    The two logs are added below.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Combofix may be available again by the time you get this, if so do the below. If CF takes it time coming back online I will get back to you about what to do next.

    We need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    
    KILLALL::
    
    File::
    C:\Users\Lawnchair\Desktop\Privacy-Center.lnk   
    
    FCopy::
    C:\Program Files\Intel\Intel Matrix Storage Manager\Driver\IaStor.sys | C:\Windows\System32\drivers\iastor.sys
    C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5da5d093\atapi.sys | C:\Windows\System32\drivers\atapi.sys
    
    Folder::
    C:\Users\Lawnchair\AppData\Local\temp\694D.tmp
    C:\Users\Lawnchair\AppData\Local\temp\9F3B.tmp
    C:\Users\Lawnchair\AppData\Local\temp\B422.tmp
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Dec 14, 2009
  15. blackprophet

    blackprophet Private E-2

    Combofix is still down.

    I'll check again tomorrow, if you find out Combofix is back up, please let me know.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    will do, but It's 4am here so I'll be snoozing soon, be back in a few hours :)
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Let's use avenger again

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    2. Please do the below to create a batch file.

    • Click Start, click Run, type Notepad, and then press ENTER.
    • Copy the entire bold text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).

    • Now in the Notepad window, click Edit and select Paste. This should copy the above text you copied into notepade.
    • Now in Notepad, click File, and then select Save As.
    • Copy and paste the following path and file name (with the quotes) into the File name box, and then click Save:

    • Click Save. This will create a file names bakup.bat on your Desktop.
    • Double click the bakup.bat file to run it and this will create a backup of a file we need to replace.
    • When successful, you should get the below message within the Command Prompt:
    • "1 file(s) copied"
    • NOTE: If you didn't get this message, stop and tell me first. Executing any of the following instructions are dependent upon this file being successfully copied.
     
  18. blackprophet

    blackprophet Private E-2

    ok I didn't see your new instructions till today, but Combofix is working. So I did the combofix instructions instead. I did do the Avenger part of the second instructions. Do you need me to do the second part of them still. Logs for Avenger, getrunlogs and avenger are attached.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you still being redirected?

    No.

    Let's do this:

    1. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    C:\Windows\temp\SEPD653.tmp
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "DisableCAD"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    2.
    • Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter ( the quotes are required).
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please attach this log to your next reply.

    3. Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    4. Run the new MGTools.exe and attach the C:\Mglogs.zip into your next reply as well as the log from combofix and TDSSKiller.

    Thanks
    Kes13!
     
  20. blackprophet

    blackprophet Private E-2

    Doesn't seem like it, But I did say the same thing last itme. I am cautiously optimistic.

    Logs included below. The TDSKiller one didnt save. But it said it found nothing.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are clean, you can now follow the final steps I gave you back in post # 8 before your redirects started happening again. :)
     
  22. blackprophet

    blackprophet Private E-2

    Thanks again.

    Have a merry christmas and a happy new year.
    All the best.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Happy Christmas and all the very best for the new year ahead.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds