Malware Problem, any help appreciated

Discussion in 'Malware Help (A Specialist Will Reply)' started by genius34, Feb 6, 2008.

  1. genius34

    genius34 Private E-2

    About a week ago, I started experiencing some type of malware problem that I haven't seen before. Whenever I attempt to login to my hotmail account, I get a basic "IE cannot access" error. The same thing happens when I try to go to my bank login page, or my fantasy football login page. Otherwise, my Internet is working, the only time I have problems is when I try to login on particular sites or go to sites with login options.

    I went through all of the basics recommended in the malware removal guide, with no success. For some reason, AVG would not generate me a scan report, even though I followed the guidelines twice (it may be because I've been running the trial freeware version for some time now). Each time I scanned, it only came up with two tracking cookies anyway.

    Otherwise, both of the other scans are attached below. Any help will be appreciated because this is driving me crazy. If a subsequent AVG scan and attachment is necessary, let me know, I'll give it another shot. Also, if there is another similar scanning program that I can post a log from, let me know and I'll do that.

    Thank you.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this first:
    Download FindAWF and save the file to your Desktop.
    Start FindAWF.exe
    Select option 2 by pressing 2 and then Enter. A text file will open (files.txt).
    In that files.txt, copy and paste the following list of files to be restored:
    Close the files.txt and click Yes to save the changes.
    FindAWF wil now terminate the bad processes if running, delete the bad files and restore/replace them with the good files.
    Then it will open a log. Copy and paste the contents of that log in your next reply.
     
  3. genius34

    genius34 Private E-2

    The text from the log:

     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    To be sure...re-run ComboFix and attach that log.
     
  5. genius34

    genius34 Private E-2

    ComboFix log attached.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....Your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  7. genius34

    genius34 Private E-2

    Well, I guess this is where things get interesting then. I still can't access my email, my bank page, or my fantasy sports page. I get this generic error message:

    But the rest of my internet works fine, and I'm obviously able to login here. Could this be something stupid and security related that I did on my end? I haven't changed anything recently, this just popped up out of nowhere.
     
  8. genius34

    genius34 Private E-2

    Just realized that I have doginhispen/skitothedayplease, too. Seems like this is beginning to be an epidemic. Should I follow the instructions in the other threads? What a mess.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download DelDomains and unzip it to your desktop. Do not run it yet.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    (Please note if you have Spybot S&D installed you will need to "Immunize" again because deldomains will remove all of the sites Spybot adds.)

    Download HostsXpert and then follow the below steps.

    * Unzip HostsXpert.zip
    * It will create a folder named HostsXpert in whatever folder you extract it to.
    * Run HostsXpert.exe by double clicking on it.
    * click the Make Writeable? button.
    * click Restore Microsoft's Hosts File and then click OK.
    * Click the X to exit the program

    Next please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me how things are.
     
  10. genius34

    genius34 Private E-2

    Thanks, I'll be off the system until Sunday, I'll update then.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My bad...skipped a step or two...

    Start FindAWF, select Option 3, by pressing 3 and then enter.
    This will open the text file folders.txt
    Copy and paste the following list in it:
    Then close folders.txt and let it save the changes.
    FindAWF will now remove the bak folders and open a log afterwards.
    Post the log in your next reply.

    Double-click the FindAWF icon once again

    If a Security Alert shows, allow the program to run.
    As instructed, press any key to continue.
    Use the following option: Press 4 then Enter to reset domain zones

    This removes all entries from the domain zones.
    When the program returns to the main menu, use the following option:
    Press E then Enter to EXIT

    Tell me how things are now.
     
  12. genius34

    genius34 Private E-2

    I followed all of those directions. The required log is attached. Unfortunately, as soon as I accessed internet explorer, I checked my browser history, and a.doginhispen appeared immediately. Next suggested course of action?
     

    Attached Files:

    • awf.txt
      File size:
      2.6 KB
      Views:
      1
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start FindAWF.exe
    Select option 2 by pressing 2 and then Enter. A text file will open (files.txt).
    In that files.txt, copy and paste the following list of files to be restored:
    Close the files.txt and click Yes to save the changes.
    FindAWF wil now terminate the bad processes if running, delete the bad files and restore/replace them with the good files.
    Then it will open a log. Copy and paste the contents of that log in your next reply.

    Have you run CCleaner to remove the history?
     
  14. genius34

    genius34 Private E-2

    Here is the newest log. I have run CCleaner to eliminate the browser history. Thank you for you continued help.

     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start FindAWF, select Option 3, by pressing 3 and then enter.
    This will open the text file folders.txt
    Copy and paste the following list in it:
    Then close folders.txt and let it save the changes.
    FindAWF will now remove the bak folders and open a log afterwards.
    Post the log in your next reply.

    Double-click the FindAWF icon once again

    If a Security Alert shows, allow the program to run.
    As instructed, press any key to continue.
    Use the following option: Press 4 then Enter to reset domain zones

    This removes all entries from the domain zones.
    When the program returns to the main menu, use the following option:
    Press E then Enter to EXIT

    Now run deldomains again.
     
  16. genius34

    genius34 Private E-2

    Newest Log:

     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good ...so how are things running now?
     
  18. genius34

    genius34 Private E-2

    a.doginhispen and b.skitodayplease no longer show up in my browser history. I can get to hotmail.com, but I still can't access my email, or login to my fantasy team, or get to my bank page. There seems to be some improvement, but I still seem to be having problems.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me exactly what happens ....can't get a login screen? Can't or it won't recognize your login?
     
  20. genius34

    genius34 Private E-2

    When I try to login to hotmail, I immediately go to an error page, without any hesitation. I can't even get to my bank page, it just goes straight to an error when I type in the address and hit enter. My fantasy sports page, at yahoo, is similar to my email. I can access anything on yahoo, but when I try to login in, it goes straight to an error page without even trying to access my account.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This may be related to LogMeIn ....whicn may have been corrupted with the malware.

    Try uninstalling it and see if the problem persists.
     
  22. genius34

    genius34 Private E-2

    As far as I can tell, I don't have LogMeIn on my computer. Nothing comes up through a file search, and it isn't in my add/remove programs. Could it be elsewhere?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No..I rechecked your logs and don't see it ...try turning off Norton Internet Security and see if the problem persists.
     
  24. genius34

    genius34 Private E-2

    In some areas, Norton shows that it is already disabled. In others it shows that it is currently working, and if I try to turn it off, then it says it is already off. The entire program is acting flaky, and I'm not convinced that it's actually doing anything. When these problems are fixed, I'm planning on using something different anyway, so could I just remove it now?

    Edit: it also actually shows that I'm missing some files that are required to run Norton. Specifically something called caApp.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  26. genius34

    genius34 Private E-2

    My login issues have been resolved. Awesome!

    I installed Avast and it located and quarantined one problem, Win32:CTX.

    Attached are new logs.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely a false positive especially if you have used/installed anything related to Panda Antivirus or Online Scanner. See the below:

    http://www.avast.com/eng/faq_panda.html
     
  28. genius34

    genius34 Private E-2

    Yes, that makes sense, I'm sure that's it.

    Everything seems to be in good working order, thank you!
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.....If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds