IBM Thinkpad R40 Browser Hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by mindworks, Feb 27, 2010.

  1. mindworks

    mindworks Private E-2

    I have been fixing a friend's ibm laptop with a bad browser hijack. Have run all of the software based on Majorgeeks instructions for xp< I made one mistake though which was turning off system restore at the start of the process. attached are my logs.

    It still hijacks from search results although wont hijack direct entered sites...some denial of service also.

    Bill
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    You didn't not follow the guide's instructions for the proper download & running directory of ComboFix - nor did you temporarily dis-able your anti-virus program.
    * Move ComboFix directly to your desktop.

    Please attach the requested MGLogs.zip

    Be patient after posting your logs and wait for one of the helpers to get to you. It can take a while to read thru all of the logs and to create individual fixes for you.
    • Also DO NOT BUMP your thread to try and get a faster answer. This will actually significantly delay getting an answer. See this: Don't Bump! It Only Hurts You!!!
    • Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. mindworks

    mindworks Private E-2

    ok will attach that after I re run all the tests again. Had to totally disable avg as the new version does not have a switch to disable. It was running constantly in hte background so I temporarily uninstalled it. The combofix log will be attached as soon as I figure out how to attach...now where is the link?

    Ahaa advanced does the trick... Once I redo the steps will repost the logs again


    \\Bill
     

    Attached Files:

  4. mindworks

    mindworks Private E-2

    Ok, following Dr. Moriarty's notation on incorrect following of the steps, I went back and checked and re performed all the steps, including a temporary uninstall of AVG 9.0. Step by Step, logs attached. THought I had it beat, first search inside google search box, produced no interference, however, the evil redirect started again. This originally was an "internet security 2010" install problem and efforts seem to have fallen flat.

    Logs attached help !!!! next message for sas log
     

    Attached Files:

  5. mindworks

    mindworks Private E-2

    here is my sas log. The browser redirects to various financial and similar sites...the last was a search of wikipaedia which had me end up offered a chance to download anti malware program.

    Bill
     

    Attached Files:

    • SAS.log
      File size:
      465 bytes
      Views:
      2
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The below fixes and advice are specific to this member's problem and should be used for issue(s) on this machine only.

    Hello, mindworks - please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Is your download (but NOT installed) version of Spyware Doctor.exe that you have here - C:\Program Files the "purchased" software version or just a useless trial that won't fix what it finds anyway? If just a trial, you may as well delete it.

    *These files do not belong in C:\Program Files or any subfolder within it. Downloads should not be saved here.

    Comment: For Windows XP, you need to upgrade your installed RAM memory to atleast 1GB for better performance.
    I strongly recommend that you clean up this account's Desktop immediately leaving only links.[ C:\Documents and Settings\MCE\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.


    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 2:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 3:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 4:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  7. mindworks

    mindworks Private E-2

    Dr. Moriarty,

    Thanks for the reply. I attach the logs. No restart yet but browser hijack still in play. A search in the browser search toolbar on bing produced results that were accurate, however on selecting and clicking on one of the results, I was redirected to the fanciest of sites for domain names and other unsolicited info. A click on majorgeeks as a result produced similar forays into cyberspace. Should I power off after all of this besides the automatic off by combofix?

    One point to note after I dropped the text document onto combofix, it automatically started running. I then allowed it to update per your instructions and also allowed it to restart as noted.

    Logs attached

    Step by step responses to your inquiries below.




    Hello, mindworks - please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    **OK, I went a little crazy after the original fixes didnt work. I will leave it alone.**

    Is your download (but NOT installed) version of Spyware Doctor.exe that you have here - C:\Program Files the "purchased" software version or just a useless trial that won't fix what it finds anyway? If just a trial, you may as well delete it.

    **It was a trial and was deleted.**

    These files do not belong in C:\Program Files or any subfolder within it. Downloads should not be saved here.


    Quote:


    avg_fr~1.exe Feb 24 2010 80328144 "avg_free_stf_en_90_730a1834.exe"
    bhblas~1.exe Feb 26 2010 402564 "bhblastersetup.exe"
    bhr450~1.exe Feb 27 2010 3139687 "bhr4.5.0.471.exe"
    ccsetu~1.exe Feb 28 2010 1154064 "ccsetup229_slim.exe"
    hjtins~1.exe Feb 26 2010 812344 "HJTInstall.exe"
    javase~1.exe Feb 26 2010 923936 "JavaSetup6u18.exe"
    pcd5se~1.exe Feb 27 2010 40905192 "pcd5setup_4329.exe"

    *THese were deleted*

    Comment: For Windows XP, you need to upgrade your installed RAM memory to atleast 1GB for better performance. I will suggest that to the owner for improved performance.

    Quote:
    Total Physical Memory -------- 768.00 MB
    Available Physical Memory --- 365.35 MB

    I strongly recommend that you clean up this account's Desktop immediately leaving only links.[ C:\Documents and Settings\MCE\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    *All of these will be removed and cleaned up after I fix the HJ.
    *

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    *Ran the program.*

    Quote:
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINDOWS\SYSTEM32\PLSRemote.exe (file missing)

    *Looked for these and couldnt find them, wonder if they might have been a casualty of my craziness after the first post instructions failure. or possibly deleted them and then wondering if I did it right, went back, checked again and not there. Sorry for the confusion.*

    After clicking Fix, exit HJT.

    Step 2:
    Now we need to use ComboFix.
    Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!

    *It is on the desktop.*

    If it is not on your Desktop, the below will not work.
    Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.

    *Had to uninstall avg...can find no disable button.*

    If ComboFix tells you it needs to update to a new version, make sure you allow it to update.

    *It did update*

    Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Quote:
    KILLALL::

    Driver::
    PLSRemoteSvc

    File::
    c:\windows\system32\emp101.exe
    C:\WINDOWS\SYSTEM32\PLSRemote.exe

    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

    *Created notepad doc and dropped onto combofix.exe and it automatically started upon doing so*

    Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    At this point, you MUST EXIT ALL BROWSERS NOW before continuing!

    *All browsers were closed*

    You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.

    *It did not ask*

    Now use your mouse to drag CFscript.txt on top of ComboFix.exe


    Follow the prompts.
    When it finishes, a log will be produced named c:\combofix.txt
    I will ask for this log below

    *Log attached, it did state that one file it was looking for could not be found?*

    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Step 3:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    *ran it*

    Step 4:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the C:\MGlogs.zip file to your next reply.
    log attached

    * Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    seems possibly to have morphed again?


    mindworks - Bill
    dr.m
     

    Attached Files:

  8. mindworks

    mindworks Private E-2

    I realized I may not have uploaded the proper combofix log.... here is the one you were asking for, apologies. THought I was being thorough...c'est la vie.

    Bill
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hmmm

    Let's do this -

    Step 1:
    Please update both SUPERAntiSpyware's and Malwarebytes' definitions, and run new "Quick Scans".

    Step 2:
    Next - run this:

    Using ESET's Online Scanner


    Step 3:
    Now -

    Download the latest version of Kaspersky GetSystemInfo (GSI) and save it to your desktop.

    * Close all other applications running on your system.
    * Double click GetSystemInfo.exe to open it.
    * Click the Settings button.
    * Set it to Maximum
    * IMPORTANT! Click Customize - choose Driver / Ports tab and
    * Uncheck Scan Ports.
    * Click Create Report to run it.
    * It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your desktop.

    * Upload the zip folder to the Kaspersky GSI Parser and click the Submit button.

    Copy and paste the URL (link in the address bar) of the GSI Parser report (not the log) in your next reply.


    Please attach the new logs and report link to your next reply:
    • SASlog.txt
    • MBAMlog.txt
    • GSI Parser report link ONLY

    dr.m
     
  10. mindworks

    mindworks Private E-2

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *Please tell me the complete filepath directory of what was detected. (Your other logs are clean).

    dr.m
     
  12. mindworks

    mindworks Private E-2

    All I recall is that there were 9 items found, 1 was in restore folders, at least they were the ones being scanned at the time when the notation showed. It called it variant of injector ayf trojan.Is there a way that I can generate this list, e.g. running it without fixing the items found?

    Another thing, after I completed all of your tasks on Sunday last week and restarted, I reinstalled avg to prtotect prior to going back online. I ran it , maybe I shouldn't have; it also found trojans, many of them, although it got held up in trying to remove or quarantine them. It removed some and wouldnt others. I think it was 32 of 40.

    I then left it alone after trying to empty the virus vault.

    I just re-ran the browser tonight after all of the latest tests, sweeps which I ran last night, it was too late last night. Browser still takes me on a tour of the far reaches of the internet redirecting me from a search for browser hijack from google or bing to other than that selected. Majorgeeks will run directly from the browser window but not when selected from a browser search.

    Bill
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, mindworks

    Let's get a fresh set of logs.

    Step 1:
    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Step 2:
    • Open SUPERAntiSpyware > click on the "Check for updates" button > once the update is complete - run a new "Quick scan"
    • Now open Malwarebytes > click on the "Update" tab > then the ""Check for updates" button > once the update is complete click on the "Scanner" tab > run a new "Quick scan"

    Step 3:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • TDSSKiller.2.1.1 log.txt
    • updated SASLog.txt
    • updated MBAMLog.txt
    • updated MGLogs.zip

    dr.m
     
  14. mindworks

    mindworks Private E-2

    Hi Dr. M.

    Started running the programs and realized I still had avg in. Ran tdss killersuper antispyware last night then stopped. These two logs will be attached to next message. These 4 log attachments were resulting from runs I just performed after removing avg again.
     

    Attached Files:

  15. mindworks

    mindworks Private E-2

    here are the two before removing avg

    Thanks for the help..
    Bill
     

    Attached Files:

  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, mindworks

    I only see a couple of things to take care of:

    Using Windows Explorer - navigate to and delete:
    • C:\Program Files\Internet Explorer\iexplore(2).exe <--- file
    • C:\Program Files\Spyware Doctor <--- folder

    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Now, open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  17. mindworks

    mindworks Private E-2

    I followed your steps to a tee and now the browser works exactly as it should search for majorgeeks brings up just that .

    Thanks very much for your patience and your assistance.

    Kindest regards

    Bill
     
  18. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Kewl!

    You're welcome, Bill. It is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work through the below link:

    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds