Hompage/background hijack among other things

Discussion in 'Malware Help (A Specialist Will Reply)' started by koochman, Oct 28, 2006.

  1. koochman

    koochman Private E-2

    I have been here before, and thanks to you fine people, my problems were solved. You can see what my problems were here.

    I come to you again with a similar problem. I have my friend's laptop, which is where my malware problems originated from through MSN Messenger. He has done nothing about the problems so his computer is worse off than mine was. Hopefully you can help.

    I followed the Read & Run Me First thread and have the required logs attached.

    I was unable to run Bitdefender.

    Forgive me if I have forgotten something.

    Thanks in advance. Tell me what to do next. :)
     

    Attached Files:

  2. koochman

    koochman Private E-2

    Here is the HJT file:
     

    Attached Files:

  3. matt.chugg

    matt.chugg MajorGeek

    Using add/remove programs which can be accessed from the control panel, uninstall the following: (If found)


    Download

    - Pocket KillBox

    Extract to its own folder somewhere that you will be able to locate later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)



    Run HijackThis. Click the 'Do a system scan only' button.

    Place a checkmark in the box next to the following lines:

    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.



    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.



    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)


    If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.


    REBOOT to Normal Mode.

    Let me know how things are running now

    Post a fresh HijackThis log, a fresh newfiles log and a fresh activescan log.
     
  4. koochman

    koochman Private E-2

    Thanks for the help. :)

    This:

    did not show up in HJT, so I didn't put a check by it(obviously).

    I received 2 errors when fixing the problems in HJT. The first I accidentally clicked past so I don't know what it said. The second said this:

    Everything is so far so good, though Active Scan shows differently, and it took a bit for the problems to show back up on my computer. I've included the requested logs...

    Thanks again.
     

    Attached Files:

  5. matt.chugg

    matt.chugg MajorGeek

    I need some more information about a file.

    Download the zip file attached to this post and extract the contents to a folder on your destop.

    Run GetDetails.exe

    Paste the following into the textbox and click run report.


    Upload the file it creates in the reports folder next to the exe.
     

    Attached Files:

  6. koochman

    koochman Private E-2

    Done. Here it is:
     

    Attached Files:

  7. matt.chugg

    matt.chugg MajorGeek

    OK

    Reboot into safe mode and delete the following

    Post a new HJT log and a new Shownew log.

    I think we are nearly done here, just a final check, (sorry for the delay!)
     
  8. koochman

    koochman Private E-2

    No problem, I'm just happy for the help. :)

    File deleted. Logs:
     

    Attached Files:

  9. matt.chugg

    matt.chugg MajorGeek

    Hmm it looks like this line that you couldn't find has changed itself to this one

    The chances are that if you have rebooted it will have changed AGAIN but have a look anyway and see if you can fix it with Hijack This and then delete the file using killbox.

    I don't think the file it points to actually exists, something is just putting fake startup entries in.
     
  10. koochman

    koochman Private E-2

    Looks like you are right, the file changes everytime the computer is rebooted. Looks like it starts with a d everytime, but that's about all I know about it.

    This file:

    was not in HJT for me to fix. I did however put the file path in Pocket Killbox, and received the PendingFileRenameOperations prompt.

    I am unable to leave the computer on, the power cord is bad and requires some special 'love' to get it to power the computer.

    I've included HJT logs and a new Shownew log. You didn't ask, but I figured you'd need them.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The problems you are having are due to a WareOut infection. Please run this procedure: WareOut Removal attach the requested log afterwards.

    Also attach a new HJT log.
     
  12. koochman

    koochman Private E-2

    Coolness. Thanks! :)

    Here are the logs:
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Startup: csrss.lnk = ?
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O21 - SSODL: IEFilter - {DC53D012-44C2-43C7-B233-B450A8AD07F0} - C:\WINDOWS\system32\IEFilter.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\Documents and Settings\MICHAEL B. WAHL\Start Menu\Programs\Startup\csrss.lnk
    C:\WINDOWS\SYSTEM32\DMKZO.EXE
    C:\WINDOWS\system32\{DF618E6F-CB26-4A49-ABBB-C3A01FD95CDF}.exe
    C:\WINDOWS\System32\service.exe <--- only delete service.exe DO NOT DELETE services.exe:

    Now run Ccleaner .
    Now reboot in normal mode

    Now download the current versions of SHowNew and GetRunKey. You have old versions!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  14. koochman

    koochman Private E-2

    Recieved a couple or errors when doing the fix in HJT. This is what I got:

    and:

    Found each file using Windows Explorer after a reboot into Safe Mode and deleted them.

    The computer is running stable and much faster and smoother than it was before we started this whole process. I have not noticed any problems as of late, but I haven't been using the computer either. Seems to be running just fine.

    Here are the logs:
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Something or someone has disable registry tools and also the display of the Admin page. Did you do this yourself? Was it only for this user account and for no others? How many user accounts are on this PC.

    We have more to fix but it may be difficult if registry edits have been disabled?
     
    Last edited: Nov 17, 2006
  16. koochman

    koochman Private E-2

    There is only one user account on the computer. 2 if you count Administrator. This is my buddy's laptop, so I do not know its history. I did not disable the tools, and I doubt he did....at least knowingly. Perhaps a previous user? Is there a way for me to re-enable them?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below and tell me if you get any error messages!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    If the above works without giving any error message, then get me a new log from GetRunKey now.
     
  18. koochman

    koochman Private E-2

    Received this error:

    Looks like the same sort of trouble we ran into when doing MY computer months ago. You had me download a registry editor and take a back door approach to things. Hmm...
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you get these same exact problems back again! At the end of the old thread you were all clean! Whatever you are doing or whereever you are surfing or downloading, you must stop doing it. Did you actually toggle system restore on and off at the end of fixing your problems last time?

    Do what I had you do in message number 24 of your previous thread: #24 You will need to reinstall Registrar Lite since you seem to have uninstalled it.

    Did it work again this time?
     
  20. koochman

    koochman Private E-2

    Once again, I am doing this for my friend and his computer. He has the same problems I had. In fact, his computer is where my problems originated from, through MSN Messenger. My computer continues to be clean thanks to you.

    At the end of the last thread, I asked if I could follow the same procedures to fix his computer, but was advised to start a new thread because his problems could be different, so I did. I only mentioned my last thread to see if it could help you out, looks like it did. :)

    Anyway, I followed the steps of message 24 again. They did work. The folder C:\WINDOWS\system32\uyhererli could not be found. I did however find a hidden folder containing csrss.ini. The folder is: C:\WINDOWS\system32\nmqjnh. I deleted this folder.

    A restart into normal mode and a double check shows the keys and weird folder are in fact still deleted.

    Sorry for the previous confusion. Here is an HJT log and a ShowNew log just in case:
     

    Attached Files:

  21. koochman

    koochman Private E-2

    A question....

    Yes, I did in fact uninstall Registrar Lite on my own computer. Should I not have?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's okay to uninstall it but it is not really necessary. It is a very useful tool (as you have seen twice ;) ) to have around.

    Those two logs are clean but I want to see a new GetRunKey log before we move on to the final cleanup steps. Please attach one.
     
  23. koochman

    koochman Private E-2

    Here it is:
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  25. koochman

    koochman Private E-2

    Sweet! Thank you so very much chaslang and matt.chug! :) :D

    I've set my buddy's computer up with the proper preventative measures. Hopefully I will not be back. Thanks again! :)
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds