Meloco Browser Hijacker

Discussion in 'Malware Help (A Specialist Will Reply)' started by atraugott, Jun 5, 2006.

  1. atraugott

    atraugott Private E-2

    Thank you for your assistance, it is very greatly appreciated. My daughter had been visiting a music download site (she thinks it is "letitsing.com" or "letssingit.com"). The McAfee software popped up, indicating that a Qoologic trojan had been picked up and deleted. The location was C:\Docs and Settings\Kate\Local Settings\Temp Internet Files\Content.IE5\ADVGD0FU\installer_252[1].exe

    I ran a full McAfee Virus Scan, which was clear. I ran Ad-Aware SE Pro and Spybot. However, the next day when my daughter went to use IE again, she called me because the homepage had been reset to a suspicious page that looked like a MySpace type site. http://www.meloco.com/index.php?i=sm. I ran McAfee again, which picked up Webhancer, as well as Ad-Aware SE pro, which picked up 50 or 60 cookies and trackers. A-A SE also reported possible browser hijacker. I had been helped by Major Geeks folx on a previous occasion w a browser hijacker, so I went directly to your site.

    As per your Read/Run First directions, we have done the following. I ran the whole suite a second time in safe mode without rebooting, because I had to reboot several times in normal mode during first pass when I was trying to download updates, and there were reinfections.

    Ran FindQool, RKTOOL, WinPfind

    Ccleaner, Ad-Aware SE pro, Windows Defender, Spybot SD, MS Windows Maliscious Software Removal Tool, Bit Defender, ActiveScan

    Ran HJT, report is attached. Also reports for BD, ActiveScan, A-A SE, CCleaner, WD, MSWMSRT, FindQool

    I can see in the HJT report that opening IE page for my daughters account is set to Meloco.com, but I don't know enough to recognize whether there are other suspicious files. It would be much appreciated if you could Pls review and provide me direction on removing the browser hijacker and any other maliscious files.

    again, thank you for your help.

    Alan Traugott
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not start multiple threads. Remain in one thread until your problems are resolved. All correspondence about your problems belong in this thread.

    As far as I know, McAfee cannot fix Qoologic so they are probably incorrect in telling you they delete it.

    You need to attach all the logs! You did not attach anything. If you are having problems adding attachments, See: HOW TO: Attach Items To Your Post

    You can only add 3 attachments in a single message, so you will have to make multiple posts to attach more than 3. Make sure you attach the BitDefender and PandaActive scan logs too.
     
  3. atraugott

    atraugott Private E-2

    I had attached two HJT files and Active Scan log. When I realized I could only attach 3 files, I tried to remove one HJT log and replace w BDScan log, but came back w errors. When I tried to post again w attachments, the program gave me errors. I will reread "how to post" and try again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any attachments anywhere. I also do not see any editing being done. Just attach the logs and if you have more than three logs, just use multiple messages to attach them all.
     
  5. atraugott

    atraugott Private E-2

    These are first 3 runs of BDscan, activescan and HJT. I will upload separate 2nd round of same files, plus some additional scans from other programs
     

    Attached Files:

  6. atraugott

    atraugott Private E-2

    2nd batch of files
     

    Attached Files:

  7. atraugott

    atraugott Private E-2

    3rd batch
     

    Attached Files:

  8. atraugott

    atraugott Private E-2

    2nd BD Scan log

    PS one of the programs also found unstall.exe, which I deleted
     

    Attached Files:

  9. atraugott

    atraugott Private E-2

    In reviewing the Read/Run instructions, I saw that HJT should be run from Normal Boot mode. I think the last scan, HijackThis2.log was run from Safe Mode w Networking, so I reran and attached as HijackThis 3.log. In rebooting and opening IE, McAfee popped up w several cookies, one of which was from Winantivirus, which I denied. New window opened indicating error with following URL.


    http://winantivirus.com/pages/scanner/index.php?aid=nm_go_wav_r5&ed=0&ex=1&ax=1&lid=keyin
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You only needed to run the READ ME one time.

    First look in Add/Remove programs for media-motor and uninstall if found.

    Now let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Print or save the below steps locally so you can follow them while disconnect and with NO Browsers open.
    Now disconnect from the internet (unplug your cable to be safe).Now shutdown or kill all protection software you are running and then continue with the below.
    Now close all browsers!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.meloco.com/index.php?i=sm

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings (make sure you use majorgeeks as your home page for now):
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Also delete the below file if it still exists:
    c:\windows\unstall.exe

    Make sure you tell me how things are working now.
     
  11. atraugott

    atraugott Private E-2

    Thanx for your help and patience. I checked Add/Remove Software, no media-motor program. I started up HJT, went to Misc Tools, Uninstall Mgr, tried to save list, but program just closes, no save option. I am in safe mode w networking, do I need to be in normal boot mode? Can I do fixme.reg without uninstall log?

    I looked for C:\Windows\unstall.exe, does not seem to be there.

    Do I need to do the Disable System Restore steps, as last step?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try it again and make sure you follow the steps ecactly. I have run into a problem with having anyone do this so I'm not sure why you would.

    Yes run the registru patch anyway.

    Well it depends on whether you are still having problems or not!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  13. atraugott

    atraugott Private E-2

    OK, couple of things:

    Did all steps as per your instructions

    still could not get HJT to save the uninstall list, even after rebooting in normal mode, but in normal mode program just sits there, doesn't close.

    After running the scan and saving logfile, program comes up w application error:

    Instruction at "0x01608620"referenced memory at "0x01608620" and memory could not be read. Click OK to terminate.

    Then, when starting up IE to post reply/logfile, McAfee Privacy service pops up and is blocking MajorGeeks.com, and another window with Internet Explorer Error shows a site http://winantivirus.com/pages/scanner/index.php?aid=nm_go_wav_r5&ed=0&ex=1&ax=1&lid=keyin

    I closed windows, added MajorGeeks.com to Accepted Cookies in McAfee Privacy Service so MajorGeeks opened as homepage, but when I clicked Support Forum, same thing happened.

    Whole series of windows, looking semi-legit, trying to get me to run a scan from the following site:

    http://scanner.sysprotect.com/pages/scanner/?p=20&ex=1&ax=2&aid=nm_go_spt_r5&lid=keyin

    I've cancelled out of everything, closed windows, turned off McAfee Privacy Service while I post log
     

    Attached Files:

  14. atraugott

    atraugott Private E-2

    When opening IE to MajorGeeks.com, McAfee has been intercepting multiple cookies:
    62.4.84.53
    cpvfeed.com
    xctrk.com
    autoweb.com

    I rejected all

    new window opens on top of homepage (MajorGeeks)

    http://count.exitexchange.com/exit/1281705

    seems like my daughters bug has morphed to my acct or I've picked up something new from MSN or one of the scan sites.
     
  15. atraugott

    atraugott Private E-2

    I reran Bitdefender, Spybot, WMST, nothing found.

    I reran adaware and it picked up a few cookies again. pls see attached log.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download & run Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the Blacklight log file here.


    Now for our next step, I want to see if anything is attaching itself to Internet Explorer. Please download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on iexplore.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.

    Now for a third step, I want to run Kaspersky Online Virus Scanner! It is only a scanner, it will not fix anything. Follow the below steps:
     
    Last edited: Jun 7, 2006
  17. atraugott

    atraugott Private E-2

    Thanx for your followup. I have run Blacklight, Process Explorer and Kaspersky. the logs are attached.

    When I went to download Process Explorer, another window popped up - http://www.amaena.com/securityworm5/?aid=nm_go_amn_kw1&lid=ad ware. seems like another fake redirect.

    Kaspersky seems to have found several viruses. Pls let me know next steps when you can. thanx for the help
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I think I may have found the problem. You still have a hidden Virtumonde infection and the reason we are have not been able to find it is probably due to McAfee getting in the way. It is probably blocking some aspects from installing/showing up but it is not fixing/removing the problem.

    Okay let's use my older manual approach. Start by downloading another tool we will need:

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later. You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer (downloaded in a previous message)

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of awvts.dll once and then click the kill button. After you have killed all of the awvts.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of awvts.dll and kill it.

    Now just exit Process Explorer.

    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.



    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.


    C:\WINDOWS\SYSTEM32\stvwa.ini
    C:\WINDOWS\SYSTEM32\stvwa.ini2
    C:\WINDOWS\SYSTEM32\stvwa.bak
    C:\WINDOWS\SYSTEM32\stvwa.bak1
    C:\WINDOWS\SYSTEM32\stvwa.bak2
    C:\WINDOWS\SYSTEM32\stvwa.tmp
    C:\WINDOWS\System32\awvts.dll

    If you find any other files in this folder that begin with stvwa and ending with any other extension ( the .ini is an an extension) delete them to.

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log and tell me how the steps went. Also attach a new Process Explorer log for iexplore.exe (like we did in message # 16).

    Also tell me how things are working.
     
  19. atraugott

    atraugott Private E-2

    Thanx I've received your msg and I will run these steps this evening. I have printed the post so that I have it available offline. A couple of questions to make sure I have it right:

    First I download Killbox to own folder
    then, unplug cable
    reboot in Normal mode (does it matter whether Restart or Shutdown?)
    Exit processes in system tray, ie, ATI, AOL, network, McAfee, etc (right click, exit on dropdown menu)
    Run Process Explorer as directed for winlogon.exe and explorer.exe (or iexplorer.exe?)
    Run fixVundo.reg
    Run Pocket Killbox as directed
    Run Killbox.exe as directed
    Reboot Normal mode (shutdown?)
    Post new HJT log

    The scan from Kaspersky seemed to indicate virus files in the restore directory, do I need to delete any of those lines/files somewhere in the above process before a final reboot?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When I say reboot, it just means restart. You do not have to shutdown. I would tell you if I wanted you to shut of the PC. explorer.exe means explorer.exe (which is Windows Explorer) not iexplore.exe. They are two different processes.

    Don't worry about System Restore. We will fix that when we finish all other malware removal.
     
  21. atraugott

    atraugott Private E-2

    Got it thanx, starting download and rest of process
     
  22. atraugott

    atraugott Private E-2

    OK, our story so far...

    don't know if this means anything. I've been leaving pc on w screen saver, cable unplugged. when I came home and went to PC to start process, screen had been reset to 480x640, when I went to change settings back to higher rez, pc was acting very sluggish, balky. I think McAfee may have been doing an automatic download. Anyway did as instructed, downloaded Killbox, saved fixVundo.reg in notebook, etc. went to reboot and pc froze. finally had to hit power switch to reboot.

    uplugged cable, ran Process Explorer
    clicked on winlogon.exe, threads tab
    found no instances of asvts.dll

    clicked on explorer.exe, found no instances of asvts.dll

    merged fixVundo.reg with registry, successful

    ran Killbox.exe
    tools>Delete Temp Files (for each user) and exited.

    pasted stvwa.* files into killbox, w delete on reboot, unregister DLL checkbox not available

    clicked yes on last file and rebooted, rebooted OK

    Have attached HJT and Process Exp log for Iexplore. While checking logs, noticed that there is a C:\!Killbox directory, checked and found a log subdirectory w log of killbox steps, which is also attached. However also noticed that there are 3 files in same directory: stvwa.ini, stvwa.bak1, stvwa.bak2, should they be there, be deleted? pls advise. thanx!!
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The !Killbox folder is where killbox saves backups of things it deletes. It is a safety net incase you delete the wrong thing. You can delete anything in that folder once you are sure you do not need it. So go ahead and delete any files in that folder.

    You forgot to answer my question:
     
  24. atraugott

    atraugott Private E-2

    Oops, sorry about that.

    PC seems to be fine, in normal mode, I am able to log on to Majorgeeks.com and support forum, altho McAfee asks whether OK to accept a bunch of cookies, including mediaplex, tribalfusion, atdmt, revsci all of which I've rejected. Also asks permission for majorgeeks.com,which i accepted.

    When I switched users to my daughters user acct, and started up iexplorer, it tried to go to meloco home page, but IE said page not available. I switched default homepage to msn and started IE OK. As MSN loading, McAfee asked whether OK to accept multiple cookies, including meloco, 207net, doubleclick, adbrite, live.com, statcounter, all of which I denied.

    When I used Killbox to delete temp files, I probably deleted McAfee privacy service database, so I had to remove the program and reinstall it. After reinstalling, restarted PC. Restarted OK. this evening, McAfee Privacy Service also updated and restarted.

    As I mentioned on last post, last nite pc was sluggish and balky and screen was reset to 480x640, maybe following a power failure, altho I have pC on APC UPS. I tried to reset screen resolution, but pc hung. When I tried to clear by restarting, PC froze towards end of restart and I had to push and hold power button to reset. I think the PC froze twice and had to be reset.

    But now, other than the flurry of maliscious cookies, pc feels normal at moment, fingers crossed, I think you did it. I've opened IE under different users, and everything appears normal, stays on correct homepage. I've restarted a couple of times, still seems normal.

    I can't tell you how much I appreciate your help and expertise. I am happy to make a donation to the cause, but you guys ought to consider some kind of subscription service. I understand the satisfaction of volunteering for a worthy cause (I am very involved in developing and promoting "green" buildings for over 15 years), but I would gladly pay a monthly or annual fee to have access to this invaluable service. My IE homepage is set to MajorGeeks.com!

    Pls let me know final steps. thanx again!!! Alan T
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Each user account on a PC should really be cleaned but you do not need to run the online scanners in step 6 on each account. They only need to be run once. If you are not having any problems with malware though, you do not need to run the READ ME on each account. Sounds more like you have hardware or software issues now due to a possible power failure. A sluggish PC could be due to what you are running (like McAfee).

    Cookies are not problems. When you work thru the below you will see a step talking about cookies.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  26. atraugott

    atraugott Private E-2

    OK, proceeding to Disable and Enable System Restore.

    Again, many thanx for your invaluable help!

    cheers, alan t
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  28. atraugott

    atraugott Private E-2

    Well, this is disappointing, but I did the disable/enable restore, and then updated Adaware and scanned and it found 12 instances of MediaMotor, which I deleted. And then, McAfee popped up and said it had found and deleted a Vundo trojan in file
    c:\windows\system32\vtsqr.dll.

    I've attached adaware log, and process explorer logs for Winlogon.exe, and explorer.exe. I will post a sep log w iexplorer.exe log

    did I just get reinfected?
     

    Attached Files:

  29. atraugott

    atraugott Private E-2

    iexplorer.exe log from process explorer
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You logs are clean! Are you still seeing any notifications from McAfee?

    You could run the below (attach the log later) as a backup but I doubt it will detect anything.

    Virtumonde aka Trojan Vundo Removal
     
  31. atraugott

    atraugott Private E-2

    No further notifications. I have downloaded Vundofix, will run and attach log next post.
     
  32. atraugott

    atraugott Private E-2

    no files found, log attached
     

    Attached Files:

  33. atraugott

    atraugott Private E-2

    I had also updated and run ccleaner, I think that was before the trojan msg popped up. After the Mcaffee msg showed up, I also ran the fixVundo.reg, so don't know if that impacted process exp logs.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So can I assume you are not having any other malware problems?

    Have you completed the rest of the How to protect thread?
     
  35. atraugott

    atraugott Private E-2

    I have printed and read How to Protect thread, but have not implemented all of the steps. I will do so this evening. Ran Kaspersky online scanner, which found NSIS. log attached. McAfee scan found nothing else. Blacklight found nothing else. Have not yet run Bitdefender or Panda or Windows Defender. can also do this evening?
     

    Attached Files:

  36. atraugott

    atraugott Private E-2

    PS don't think I'm having any other problems as far as browser redirects or popups.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what the below folder is for (that is, what is SG2?)
    C:\Program Files\SG2

    Delete the below file:
    C:\WINDOWS\chadch.exe
     
  38. atraugott

    atraugott Private E-2

    SG2 is SkyGolf folder. GPS based navigation for golf courses, distances to green, pin. SG2 Browser enables downloads from SG database for specific courses.

    deleted Chadch.exe from Windows

    ran windows defender, found nothing
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! If you are not having any other problems make sure you complete what I gave in message # 25.
     
  40. atraugott

    atraugott Private E-2

    thanx! will run thru process once more as per #25. Again, much appreciated. Hopefully this does it for a bit. cheers
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds