Hijacked internet explorer 9 and infected pc

Discussion in 'Malware Help (A Specialist Will Reply)' started by greg660, Aug 21, 2012.

  1. greg660

    greg660 Private E-2

    Dear MajorGeeks,

    First, thank you for your useful website and forum and for sharing your knowledge and skills.
    After some days trying to clean on my own I finally leave it in the hands of experts.
    I did the whole Read & Run me first thing.
    What I can mention with Internet explorer:
    -> The home page was locked to MyStart.incredimail. I forced it manually to google through the register key.
    -> Settings and favorite buttons are unoperational
    -> IE is closing if I try to type something in the address bar
    -> I can't update IE through windows automatic updates in spite it is proposing this update: when I proceed, windows update finally tells me that I already have a newer version
    -> I can't manually install IE9 through the .exe file
    -> I can't uninstall IE9 as this update can't be found in the microsoft updates list
    Firefox seemed to be infected as well but I simply troobleshot the problem by uninstalling it. Chrome seems to work fine.

    Now, it seems that the closer I get to the source of the problem, the worse the pc is running, now it is even freezing while surfing on chrome.

    Hereunder the different logs.
    I, and mostly my mother who owns this pc, would be very thankful if you could help.

    Regards from France,
    Greg660
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this file:
    C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml

    Delete these folders:
    C:\Users\Annick\AppData\Roaming\Babylon
    C:\ProgramData\Babylon

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    How are things running, any better or not?
     
  3. greg660

    greg660 Private E-2

    Dear Kestrel13!,

    I have deleted the files and folders related to Babylon.
    I had a success message to the registry merge.

    But there is no improvement so far.

    One strange thing about the IE9 update: there was one successful update on July 2011, and after that he kept trying to update it and always failed.

    Shall I regenerate logs with the new status? (after cleaning Babylon)

    Thanks!
    Greg660
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. greg660

    greg660 Private E-2

    After 4 trials I always get the same result:
    -> First error, OTL asking me to insert a disk in Harddisk1. After several clicks on continue it allows me to.
    -> Once arrived at the System event log record 49209, I get a Win32 Error Code 23. (something like data error - Cyclic Redundancy Check)
    -> In the end I don't get far enough to have the Extras.txt

    Attached you can find the OTL.txt and the 2 screen shots of the errors

    Thanks!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download this file to your desktop

    BITS.reg

    • Now please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the BITS.reg file saved to your Desktop and double click it. Allow it to be added to the registry.
    • Now run the C:\MGTools\GetLogs.bat and attach the resulting MGlogs.zip.
     
  7. greg660

    greg660 Private E-2

    Here it is
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    BITS service is still not back, repeat my previous steps in safe mode please?
     
  9. greg660

    greg660 Private E-2

    Here is the new MGLogs with the merge of bits.reg and the getlogs.bat both executed in safe mode.
    I have to mention that the first time, after I got the success message for adding Bits.reg to the registry, I had deleted the Bits.reg file on my desktop. I did the same with the fixME.reg. Was I wrong?
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like for you download Combofix to your desktop. Do NOT run it yet! (Before you do you must disable all anti spyware and anti virus!) See below for how we are going to run it.

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    ClearJavaCache::
    KILLALL::
    Registry::
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS]
    "DisplayName"="@%SystemRoot%\\system32\\qmgr.dll,-1000"
    "ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,\
    32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
    "Description"="@%SystemRoot%\\system32\\qmgr.dll,-1001"
    "ObjectName"="LocalSystem"
    "ErrorControl"=dword:00000001
    "Start"=dword:00000002
    "DelayedAutoStart"=dword:00000001
    "Type"=dword:00000020
    "DependOnService"=hex(7):52,70,63,53,73,00,45,76,65,6e,74,53,79,73,74,65,6d,00,\
    00
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,65,43,72,65,61,74,65,47,6c,6f,62,61,6c,50,72,69,\
    76,69,6c,65,67,65,00,53,65,49,6d,70,65,72,73,6f,6e,61,74,65,50,72,69,76,69,\
    6c,65,67,65,00,53,65,54,63,62,50,72,69,76,69,6c,65,67,65,00,53,65,41,73,73,\
    69,67,6e,50,72,69,6d,61,72,79,54,6f,6b,65,6e,50,72,69,76,69,6c,65,67,65,00,\
    53,65,49,6e,63,72,65,61,73,65,51,75,6f,74,61,50,72,69,76,69,6c,65,67,65,00,\
    00
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
    00,01,00,00,00,60,ea,00,00,01,00,00,00,c0,d4,01,00,00,00,00,00,00,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters]
    "ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
    33,32,5c,71,6d,67,72,2e,64,6c,6c,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Performance]
    "Library"="bitsperf.dll"
    "Open"="PerfMon_Open"
    "Collect"="PerfMon_Collect"
    "Close"="PerfMon_Close"
    "InstallType"=dword:00000001
    "PerfIniFile"="bitsctrs.ini"
    "First Counter"=dword:00000774
    "Last Counter"=dword:00000784
    "First Help"=dword:00000775
    "Last Help"=dword:00000785
    "Object List"="1908"
    "PerfMMFileName"="Global\\MMF_BITS_s"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum]
    "0"="Root\\LEGACY_BITS\\0000"
    "Count"=dword:00000001
    "NextInstance"=dword:00000001
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]
    "PreshutdownTimeout"=dword:036ee800
    "DisplayName"="@%systemroot%\\system32\\wuaueng.dll,-105"
    "ImagePath"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,6d,33,\
    32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
    "Description"="@%systemroot%\\system32\\wuaueng.dll,-106"
    "ObjectName"="LocalSystem"
    "ErrorControl"=dword:00000001
    "Start"=dword:00000002
    "DelayedAutoStart"=dword:00000001
    "Type"=dword:00000020
    "DependOnService"=hex(7):72,70,63,73,73,00,00
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,65,41,75,64,69,74,50,72,69,76,69,6c,65,67,65,00,\
    53,65,43,72,65,61,74,65,47,6c,6f,62,61,6c,50,72,69,76,69,6c,65,67,65,00,53,\
    65,43,72,65,61,74,65,50,61,67,65,46,69,6c,65,50,72,69,76,69,6c,65,67,65,00,\
    53,65,54,63,62,50,72,69,76,69,6c,65,67,65,00,53,65,41,73,73,69,67,6e,50,72,\
    69,6d,61,72,79,54,6f,6b,65,6e,50,72,69,76,69,6c,65,67,65,00,53,65,49,6d,70,\
    65,72,73,6f,6e,61,74,65,50,72,69,76,69,6c,65,67,65,00,53,65,49,6e,63,72,65,\
    61,73,65,51,75,6f,74,61,50,72,69,76,69,6c,65,67,65,00,53,65,53,68,75,74,64,\
    6f,77,6e,50,72,69,76,69,6c,65,67,65,00,00
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
    00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters]
    "ServiceDll"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,6d,\
    33,32,5c,77,75,61,75,65,6e,67,2e,64,6c,6c,00
    "ServiceMain"="WUServiceMain"
    "ServiceDllUnloadOnStop"=dword:00000001
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum]
    "0"="Root\\LEGACY_WUAUSERV\\0000"
    "Count"=dword:00000001
    "NextInstance"=dword:00000001 
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. greg660

    greg660 Private E-2

    Hello,

    That was really tough!
     

    Attached Files:

  12. greg660

    greg660 Private E-2

    There is now an improvement with IE9: now I can type in the address bar without IE9 closing.
    Favorites and settings buttons are still unoperational.

    greg660
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Go to start > run > and type in services.msc
    • Scroll down to the Background Intelligent Transfer Service if it shows, let me know its status and start up type?
     
  14. greg660

    greg660 Private E-2

    Background Intelligent Transfer Service
    Status: started
    Start up type: Automatic (delayed start up)

    I don't know if that's the exact english words because what i can see is in french.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, so would you say you are ready for final steps? No other issues?
     
  16. greg660

    greg660 Private E-2

    Hello,

    I am not so sure. Combofix was really a pain:

    - 1st trial in normal mode:
    I mentionned only afterwards that windows defender was switched on.
    Avast and windows firewall were disactivated.
    The pc froze while shutting down. I had to hard reboot it.
    The logs were generated anyway.
    But I also mentionned afterwards that user account control had swithed on by itself.
    Combofix found one infected file that he had to delete.

    - 2nd trial in safe mode
    No way to switch avast off. (well it was supposed to be off but I had messages from Combofix saying it was on)
    Windows defender and windows firewall were off.
    User account control off.
    Combofix found another infected file that he had to delete (not found the first time)

    - 3rd trial in normal mode
    All securities off
    It proceeded the 50 steps but stopped after these whereas there are still actions that he usually does.
    Windows blocked while closing session

    - 4th trial
    Everything seemed to be OK.

    All logs are attached.

    But the laptop still seems strange, it is always really warm (boiling) and the fan always runs really fast.
    Futhermore it has just frozen 2 times in 2 starts, I had to hard reboot it again. But it was shortly after I used a usb key to transfer the log files. I am currently analysing this usb key with sophos on my work laptop.

    Do you think there's anything else to do?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Overheating laptops are not topic for this forum I'm afraid, :) nor the other stuff you mention. I don't know why you ran Combofix as many times as you did. What I was asking, is, are there any more actual malware problems or is everything running as it should?
     
  18. greg660

    greg660 Private E-2

    I thought it could be linked.
    I ran combofix several times because there was each time a problem. (I spent the night doing it...)

    Otherwise it seems to work properly.
    I would say the only thing I can still mention is the IE9 update that windows automatic update is proposing to me and that I can't do + unoperational favorites and settings buttons.
    Shall I open a new topic for this?

    Anyway, I'll just follow your guidelines, so if you think it is the moment to close, let's do it!

    Thanks,
    Greg
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes I would ask about this in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  20. greg660

    greg660 Private E-2

    Dear Kestrel13!,

    Many thanks for your help and time.
    All steps were sucessfuly passed.
    To make the laptop safer I've installed:
    Comodo firewall
    Avast
    SuperAntiSpyware with license
    Spywareblaster
    Spybot S&D
    as per advice from referred topic.

    I will now look after the little improvements to be done one by one in the other sections of the forum.
    I wish you much success in your fight against malware ;)
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome :)

    Thankyou! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds