IE is directed to Allsecuritynotes.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by dkdragon, Feb 6, 2007.

  1. dkdragon

    dkdragon Private E-2

    Hello,

    Newbie here, first post so I pre apologize for any newbie errors. I have followed the read and run me first procedures, and also ran the smitfraud fix, but to no avail. So here are the logs that I believe I am supposed to attach.

    Thank you in advance for any help.
    Dkdragon
     

    Attached Files:

  2. dkdragon

    dkdragon Private E-2

    Here are the other three logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: (no name) - {f4d74aaa-a178-4463-846b-b4bc87a024e0} - C:\WINDOWS\system32\ixt0.dll
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - Startup: PowerReg SchedulerV2.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
    O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab G
    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab G
    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
    O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab G
    O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab
    O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab

    After clicking Fix, exit HJT.

    Please run F-Secure's online virus/spyware scan:
    http://support.f-secure.com/enu/home/ols3.shtml
    Follow the directions in the F-Secure page for proper Installation.
    Accept the License Agreement.
    Once the ActiveX installs,Click ‘Custom Scan’ and be sure the following are checked:

    1.Scan whole System
    2.Scan all files
    3.Scan whole system for rootkits
    4.Scan whole system for spyware
    5.Scan inside archives
    6.Use advanced heuristics

    Once the download completes,the scan will begin automatically.
    The scan will take some time to finish,so please be patient.
    When the scan completes, click the ‘I want to decide item by item’ button.
    For each item found,Select ‘Disinfect’ and click ‘Next’.
    Click the ‘Show Report’ button,then copy and paste the entire report into your next reply.

    Please attach new logs for:
    ShowNew
    GetRun
    HJT
    And don't forget the F-secure log.
     
  4. dkdragon

    dkdragon Private E-2

    WOW! That f-scan tool did take FOREVER! You said it would! Ok, i followed your instructions. When I open IE it's still going to allsecuritynotes.com. Here are the new logs you instructed me to attach.
     

    Attached Files:

  5. dkdragon

    dkdragon Private E-2

    and one last one.... (Thank you by the way!)
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-Run Counterspy and have it remove/quarantine everything it finds.

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {f4d74aaa-a178-4463-846b-b4bc87a024e0} - C:\WINDOWS\system32\ixt0.dll

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.
    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  7. dkdragon

    dkdragon Private E-2

    By jobe i think you got it!! IE went to google like it should have! Here are my logs! is there anything i need to do to keep this from happening again? And some where along the long path I've been on to repair this infestation I ran a registry cleaner and it said I had (Approx) 129 reg errors, but would only fix 15 of them. Is this something i need to worry about? Thank you so much for your help!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to install Java Runtime 6

    Also Kill the messenger

    Run CCleaner ...the cleaner and the issues (make the backup when prompted) ...this will fix bad registry items.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds