Hosts Hijack Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by johnstag, May 16, 2009.

  1. johnstag

    johnstag Private E-2

    I have a significant problem with my PC which I think is a Hijack problem

    I have followed 'Read and Run Me First' but the problem remains

    Additionally, I could not fix the Winsock problem after using SuperAntiSpyWare Free with the repair option but did correct the problem with WinsockxpFix

    System Restore was 'greyed out' before trying to correct problem and remains 'greyed out'

    ComboFix would not run for me so no Log file included

    The problem continued to be manifested through Pareto Logic dialogue which lists 123 items that the hosts file has changed, on selecting Block the message then changes to 'This threat has occurred multiple times, may be in a cycle, and cannot be blocked. It is recommended that you run a scan' On selecting Quick Scan the 123 items appear again, Select Clean and go round again in this never ending loop.

    I have attached the log file from Pareto Logic in addition to the log files requested

    I am using a different PC to access your forum as access is blocked on the PC with the problem

    I hope you can give me some assistance to clear the problem

    Regards

    johnstag
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    But you did not do what was requested. You need to attach the logs we requested. Until you do that, you have not finished. The below is a direct quote from the instructions
    Oh and by the way, the only comment you will get from us on Pareto is to uninstall it.
     
  3. johnstag

    johnstag Private E-2

    Apologies I thought I had uploaded them

    I think I now have the problem resolved but it took considerable time

    I will make a second post and attach the log files which may be of interest

    Thank you for your site and the great information contained there in

    Regards

    johnstag
     

    Attached Files:

  4. johnstag

    johnstag Private E-2

    I used Trojan Remover (trjsetup678.exe) which eliminated the recurring problem and allowed me to gain contol of the PC

    I then was able to restore to 04 May 09 as the System Restore was re-enabled but when I restarted there was still trojan activity - Microsoft Money install kept being initiated which I cancelled

    I used Trojan Remover again which killed this and other threats then ran Malwarebyte again which identified the disablement of two McAfee security centre features

    I then ran avg free Virus Scan - more than 6 hours and 1.8 million objects and it found 30 threats, a few were cookies but two thirds were Trojan threats which it cleaned - no log as I cannot find it in avg

    This morning everything still looks good as I have run Trojan Remover with a clear result and no alerts with avg

    I still have some checking to do and one feature at least that I know is a problem is an inactive 'Help and Support' feature as I was going to make a restore point but discovered this feature inactive - so far have had no time to search for a cause and correct it

    I hope my experience may be of assistance to others - the message is keep the viruses out as it takes a long long time to clean them if you get infected

    Regards

    johnstag
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You have some more to do but I need the requested log from ComboFix before I can continue. Did you run it as requested? Did you have any problems? You need to shutdown all protection software before running it. We will need to use ComboFix ( or another tool ) to finish your cleanup.
     
  6. johnstag

    johnstag Private E-2

    I was previously unable to run ComoFix which is why no log file but I have tried again today after killing all and any processes that I thought were connected with virus scanning and proved successful.

    Please find attached the log file from ComboFix

    Regards

    johnstag
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
    O20 - Winlogon Notify: hblogon - C:\WINDOWS\SYSTEM32\hblogon.dll

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds