IE opens to random websites

Discussion in 'Malware Help (A Specialist Will Reply)' started by speigel, Jul 9, 2010.

  1. speigel

    speigel Private E-2

    Hi -

    I'm new to this place but have read some previous threads. Here's my situation: I use Google Chrome as my browser. I recently noticed that every now and then the top bar would blink (go from blue to a dull blue and then return back to blue) as if I clicked outside of the browser and then back on the browser. I didn't notice any programs going on. So I pressed Alt+tab and saw an IE icon open with various web addresses. The IE icon would show up for a second and then go away, but no IE browser would actually open up in front of me. It was opening in the background.

    I've done Malwarebytes and Superantispyware several times. In fact, with Superantispyware I can't update the definitions through the program stating "There was an error trying to receive definitions. Make sure your firewall is not blocking SAS.exe from accessing the internet. (I use the Windows firewall). So I have to update the definitions manually. Neither Malwarebytes nor SAS has picked up on anything except for SAS picking up several Adware.Flash Tracking cookies. Yesterday, SAS picked up Trojan.Agent/Gen-Blarsa and deleted it. But IE is still acting up.

    I would be grateful for any help to fix this problem. I will attach the logs for SAS, Malwarebytes, Combofix, Rootrepeal, and MGlogs.

    I'm on a laptop using Windows XP 32 bits. Please let me know if you need more information from me.
     

    Attached Files:

  2. speigel

    speigel Private E-2

    Here is the last log.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you set this up:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80

    If not, then please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now see these instructions regarding proxy server settings:
    Change Proxy Settings.

    Now use windows explorer to find and delete:
    C:\Documents and Settings\errol\Local Settings\Application Data\eEdV21ps4J4C
    C:\Documents and Settings\errol\Local Settings\Application Data\msesbucf.txt
    C:\Documents and Settings\All Users\Application Data\eEdV21ps4J4C
    C:\Documents and Settings\errol\Templates\eEdV21ps4J4C

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 15
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7


    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe

    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.

    Reboot and download and install:
    Java Runtime 6
     
  4. speigel

    speigel Private E-2

    TimV,

    Thanks for taking your time to help me.

    I followed your instructions per post #3. I attached the inline from the remover.exe.
     

    Attached Files:

  5. speigel

    speigel Private E-2

    TimV,

    In case you ought to know, I just got another popup from IE going an advertisement. This was after following post #3 and am getting another one as I type this post.
     
  6. speigel

    speigel Private E-2

    TimV,

    I just realized that my wave balance volume was involuntarily set to the lowest setting. This is preventing me from hearing the "clicking" sounds (those sounds related to when you click on a link). When i reset the wave balance, I began to hear all these clicking sounds every several seconds (but still no IE page showing up on my screen). This is starting to become more annoying than I thought as neither Malwarebytes nor SAS is picking anything up.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.


    Now - please do the following:

    • Click Start, Run then copy and paste the below into the Run box and click OK.

    "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0

    • Now reboot your PC and after reboot continue with the below instructions.
    • Disable System Restore on all drives.
    • Look for the below folder and if if it sill exists, delete it.
      • C:\System Volume Information\Microsoft

    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

      Then attach the below logs:
      • C:\MGlogs.zip


    Make sure you tell me how things are working now!
     
  8. speigel

    speigel Private E-2

    TimW(not V, sorry!)

    I followed all the steps in the last post. But when I went to delete the Microsoft folder as you asked me to, I get an error message saying that System Volume Information folder is in accessible and therefore "Access is denied."

    Should I turn System Restore back on until your next post?
     
  9. speigel

    speigel Private E-2

    TimW,

    When I look at the properties on the System Volume Information folder, it says this:

    Size: 0 bytes
    Size on Disk: 0 bytes
    Contains: 0 Files, 0 Folders

    I still can't access the System Volume Information folder to determine if the Microsoft folder is there. I did disable System Restore and then reboot before trying to access the folder.

    I didn't run any steps (I didn't run MGtools) after where I was told to delete the Microsoft folder, which I can't check on.

    Thanks for your continuing help.
     
  10. speigel

    speigel Private E-2

    TimW,

    I was able to gain access to the System Volume Information Folder by following the steps from http://support.microsoft.com/kb/309531

    After opening the folder I didn't see a folder labeled Microsoft. I did find two files. One is "MountPointManagerRemoteDatabase" and another is "tracking.log"

    After opening the folder I followed with the MGtools step and ran the GetLogs.bat file. I attached the MGlogs.zip file.

    So far the volume has remained on the highest setting and it hasn't turned off yet. I'm still hesitant to think that my computer is free from whatever I had. If there is more steps for me to follow, please let me know. I still have my System Restore disabled for now. Let me know when I can turn it back on.

    Thanks again!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good!!!

    You do have a lot of crap running at startup, so you might want to use this:
    Startup_CPL

    Otherwise>
    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  12. speigel

    speigel Private E-2

    Thanks, Tim!

    I'm wondering if my logs indicate if I have any other malware issue outside of the Black Internet that I'm unaware of. For example, my cc number was stolen last month even though I had the card on me the whole time and I'm not sure how my number was stolen.

    I'll follow those last steps later on tonight.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is no indication of additional malware on your system. However, it you had used your CC while the computer was infected, that is more than likely the way it was stolen. This type of infection can steal personal info. I do hope you have contacted your CC company as well as your bank to make them aware that your info has been compromised. As a further precaution, you should use a different computer to change your online passwords. :major
     
  14. speigel

    speigel Private E-2

    I'll find a clean computer to change my passwords.

    Is the Black Internet the reason why I can't update the definitions through SAS? Otherwise I'll have to update the definitions manually.

    Thanks.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It might be best to uninstall SAS and then download and install the latest version. See if that doesn't allow you to update it.
     
  16. speigel

    speigel Private E-2

    TimW,

    I uninstalled and then reinstalled SAS, but the problem persists. I'll just have to live with manual updates.

    But I as far as I can tell, I am rid of the Black Internet. Thanks for your time and help. I understand that you do this voluntarily and I really appreciate that.

    This site rules.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You might want to post in the software forum for your problem with SAS.


    And, you are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds