Possible Hijack/Malware: IE8 + Chrome (Contains Requested Logs)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kion, May 20, 2009.

  1. Kion

    Kion Private E-2

    Hello my new computer savvy friends i have an issue that nothing seems to solve. It started when i was using IE8 as i was looking at mixed martial arts videos on yahoo video. The free Mcaffee that my school provides blocked something with a title similar to JSbiogen exploit. i scanned my computer and spybot scanned it but nothing was found so i assumed it must have been an attack that was dealt with. Later while i was playing chess with a facebook application my mcafee blocked the same exploit. I scanned again but found nothing. I uninstaled my mcafee since i was no longer at school and installed avast which has always been good to me. Then i scanned again and found nothing. while i was researching this i found that IE8 started locking up. pages would load and never stop loading. my memory usage was fine and everything else was good but the browser would not go anywhere. i would close the program and reopen it and it still wouldn't work. i also tried logging out and back in and it still wouldn't work, nether would putting the computer in standby or hibrinating it. the only way to fix the problem was to reboot the computer. I then switched to chrome which i find to be awesome lol. the problem happened less frequently but sometimes when it did happen it would take me to a random ad page which is suspicious to say the least. I also noticed that chrome was still alive in the processes even after i closed it and when i tried to end the process or it and its tree it would not end. finally my little brother suggested your cleaning procedures. i had to uninstall my zone alarm to perform them so i disconnected my internet while performing the scans. After them my computer seemed fine. ran faster but had a few glitches which i think were a small consequences of such harsh scans (nothing too bad). But today my google chrome locked up again like 3 times. It doesn't stick around in the processes like it used to but it just stops working.

    Main problems: browsers lock up (IE8 and Chrome both updated), occasional webpage redirection.

    Worries: blocked exploit/Trojan

    Specs: Intel(R) Core(TM)2 Duo T9600 @2.80GHz, 4.00GB, 32-bit Vista Home Premium Service pack 1, NVIDIA GeForce 9600 GT. notebook

    Often used Miscellaneous Programs: Various Games, Skype, Ccleaner, Defraggler.

    Security: MCafee and Vista Firewall (in the relevant past). Avast and Zone Alarm (Currently). SUPERAntiSpyware (installed just a few days ago). Spybot and SpywareBlaster (Consistently).

    majorgeek's cleaning procedures attached
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome. We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    kestrel13!
     
  3. Kion

    Kion Private E-2

    Thank you miss. The problem might be getting worse but it still occurs relatively rarely. Last time it happened i couldn't shut down properly and chrome stuck around in in the processes after the program was closed. It also might be interfering with my battlenet on Warcraft 3 but that could be paranoia lol.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Kion

    1. Run the below:

    Using GooRedFix


    2. Now empty your firefox cache

    3. Run Ccleaner!

    4. Run ATF Cleaner

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.

    If you use Firefox browser

    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
    • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
    • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    5. Let me know how things are running now. It may be that you have to visit the software forum to resolve any issues you are having.
     
  5. Kion

    Kion Private E-2

    I dont have firefox installed all i have is IE8 and Chrome. I use chrome often and IE8 occasionally. can i use these cleaners the same way with chrome and IE8
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    it's not only for Firefox so go ahead and run it yes indeed :) @ GooRedFix

    Skip ATF Cleaner
     
  7. Kion

    Kion Private E-2

    Done and done... and ahh mystery girl, if i may call you that; what does this program do just for curiosity sake.

    no fix log attached
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    One of your complaints was:

    So I thought we would give that a run. But the log doesn't show anything suspicious anyway.


    I shall be giving you final steps more than likely in the morning. How is your machine running now? :)
     
  9. Kion

    Kion Private E-2

    i just ran it so theres no way to know since it happens infrequently. though i think it locked up last night
     
  10. Kion

    Kion Private E-2

    btw if you dont already know i only ran the no fix
     
  11. Kion

    Kion Private E-2

    hey, not sure if this is relevant but when i went to a websight searching for a fight video through yahoo i got this message from avast:

    26.05.2009 00:44:40 Network Shield: blocked access to malicious site scanner.rapidantivir09.com/35/?advid=6643&ref=0&p=1000000000 [ C:\Users\Wisdom\AppData\Local\Google\Chrome\Application\chrome.exe ( 3120 ) ]


    I imediately unpluged my comp from the network, closed chrome and crap cleaned.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Avast! is just doing it's job, Kion, any issues you are still having should be worked out in the software forum because your logs are clean. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  13. Kion

    Kion Private E-2

    Thank you Kestrel it has been a pleasure despite the impersonal nature of these forums ;) . I hope we cross paths again on here. Lol maybe you can help me with my software issues.

    I'll run the final steps tomorrow but i was wondering, does doing these final steps reverse anything i've done since the scans. I just installed a game, a printer driver and a "Game Booster" program. i was wondering if this will uninstall those and restore my computer to what it was when i did the cleaning procedures.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are very welcome :cool


    Perhaps I can, I sometimes drift into software!

    No, not at all, only thing you will be doing appart from uninstalling Combofix and MGTools is flushing out your restore points and creating a new one. This will not affect the installation of any games you have.

    Glad you're all sorted, see you around the forums sometime.

    Kes
     
  15. Kion

    Kion Private E-2

    o'shnap hold the phone... umm my computer was overheated while i was playing titan quest so i figured i would play Call of Duty for a while online. the moment i entered a game Avast told me it found what may be malware using hueristic software in my punkbuster program. So i submitted the file for analysis and it had me do a bootscan. its scanning now, was it just a false positive or should i be worried.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Kion

    Give me the exact file path of where Avast! is finding the "threat"
    More than likely it is a false positive but we will see.... let me know.

    Kes
     
  17. Kion

    Kion Private E-2

    i dont know how to file path. can you tell me how to get it from avast?
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    what exactly did avast! offer to do with whatever it was finding? Did it offer to quarantine it for example? Did it not tell you specifically where it was finding this "threat"? For example C:\Program Files <insert name of prog here>

    Look in your system tray > right click the blue "A" Avast! logo > Avast! log viewer...

    Look thru the various tabs along the left hand margin there and see if anything was recorded.

    Thanks
    Kes
     
  19. Kion

    Kion Private E-2

    it offered to ignore or to delete the file. since it recommended that i ignore the file i ignored it. once i ignored it it said it wanted to perform a boot scan. i allowed it to do the boot scan.

    i looked at the boot scan log and nothing was found.

    and yes, i checked the logs i was just unable to find any entry. could you perhaps tell me where exactly to look?
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What Avast! is finding is more than likely a false positive. It's a wonderful AV however it is well known for it's FP's. If you like you can run Combofix and MGTools again and get me the logs to have a look thru.

    Another thing to do is if Avast! alarms again, take note of the file and where it resides, and upload it to an online scanner such as Jotti

    Thanks
    Kestrel13!
     
  21. Kion

    Kion Private E-2

    i kinda agree on the false positive cause i looked though some forums on google and they indicated that it probably was. so i went through the finnal cleaning/uninstaling proceedures and i think im good to go.

    Again its been a pleasure and thanks for all the help
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    you're most welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds