Mozilla/IE both fail eventually....

Discussion in 'Malware Help (A Specialist Will Reply)' started by NZRic, Dec 8, 2009.

  1. NZRic

    NZRic Private E-2

    Using Mozilla on WinXP SP3 machine... have been fine for years... all of a sudden Mozilla is going wonky. My home page is Google. I do a search say for 'Excel Formulas'. I get a full list of results, and can click to open in a new tab, etc. After about five minutes or so, depending on the number of tabs and returns - I no longer get the new tab to open. Rather - the tab opens but the data in the tab is not there. I try reloading - sometimes it reloads in basic HTML other times it reloads as normal. If the site has many pictures they do not load but leave place holders. On reload - some of the pictures show. Eventually nothing happens when opening a new tab or clicking on any link.

    I have uninstalled and reinstalled Firefox (version 3.0.1.5) twice. First time all was good for about 2 minutes, then the problem reoccured. Second time, I uninstalled - and went to registry and removed every 'MOZIL' reference. Then reinstalled - same again. I then repeated the second uninstall technique, and then reinstalled. Before anything was run - I copied a 'clean' install version from another of my machines into Mozilla installed directory. Same same again.

    I have checked IE (which I almost never use) and the same thing is happening there.

    I have followed the WIN XP cleaning process and please find the logs required as attached.
     

    Attached Files:

  2. NZRic

    NZRic Private E-2

    Part II - logs as attached in the zip....

    Thank you very much in advance - I am kind of sheepish here in that I am very good with my security (I thought)...


    Ric
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    IMPORTANT: Please try not to turn off or reboot the computer!

    **The version of MGTools that you are using is slightly out of date: I will have you download and run the new version a few steps down...**

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    Not wise to place ANY site into your TZ!


    After clicking Fix exit HJT.

    2. May I ask what you did with HJT?

    3. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    c:\windows\system32\zzzwdmaud.drv
    
    Folder::
    C:\Documents and Settings\Administrator\Local Settings\temp\foxtab
    C:\Documents and Settings\Administrator\Local Settings\temp\nsh56.tmp
    
    RegLock::
    [HKEY_USERS\S-1-5-21-1645522239-1757981266-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
    @Denied: (2) (Administrator)
    "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
       d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3c,71,72,db,eb,d5,4e,4f,9d,2c,1a,\
    "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
       d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3c,71,72,db,eb,d5,4e,4f,9d,2c,1a,\
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\Documents and Settings\Administrator\Local Settings\temp

    5. Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    6. Run the new MGTools.exe and attach the C:\mglogs.zip into your next reply here as well as the log from running combofix.

    7. Let me know how the machine is behaving now.
     
    Last edited: Dec 10, 2009
  4. NZRic

    NZRic Private E-2

    Thank you very much for your help...

    Here are the logs as requested...

    The machine ran fine for about 30 minutes... now it is the same again... very sad... but hopefully this time?

    The file threatfound.txt shows what I did with HijackThis.

    Note - that file zzzwdmaud was a backup I made when I thought it might be a wdmaud infection.. no joy as when I did that it just came back as wdmaud.drv.

    Ric
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well wdmaud.drv is not present at all on your machine now according to the lgs.

    Go to Start > click on search > all files and folders > "look in C drive" > enter in wdmaud and hit enter to let it search for the file. I cannot see it's presence in your logs.

    In any case I am not seeing any malware in your logs, what malware issues are you still having right now?
     
    Last edited: Dec 15, 2009
  6. NZRic

    NZRic Private E-2

    Ran the search: I have two wdmaud.drv files. One of the other posts here said wdmaud.drv is the malware, and the realy wdmaud.sys in the \system32\ folder is okay. Does this sound right?

    The system is running pretty stable but is still dummying up after about 30 min...
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Yes there have been cases when the real wdmaud.sys is in system32\drivers and is about 82KB.
    The fake wdmaud.sys is in system32 and is about 21KB.

    I am doubting malware as being the cause of this problem. Let's have you run an online scan:

    Using ESET's Online Scanner

    Attach the ESETScan.txt to your next reply.
     
    Last edited: Dec 16, 2009
  8. NZRic

    NZRic Private E-2

    Hi Kestrel,

    FYI it was the fact the fake WDMAUD as you posted... I set restore off, erased the file and did a regedit for references to that file id... removed them using spybot... and bam!!! all up and good... I have load tested eight and nine windows of mozilla with multiple tabs in each and it is all well and good..

    I want to say thank you very much for all of your time... I wish I could buy you the JB... at the very least out of all of this I have switched to avast which I did not use before (was on AVG)...

    well done and thanks again...
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I did not claim that your wdmaud.sys file was infected, I merely pointed out that it can be and sometimes has been the case.

    You had a valid copy in system32\drivers and another valid copy in your DLL Cache at the time of reading your last logd. I do not understand what you have done on your own, but you didn't even give me the results of the eset scan.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds