Spyware that has crippled my laptop; pop-unders, frequent freezing.

Discussion in 'Malware Help (A Specialist Will Reply)' started by matt46_2, May 6, 2009.

  1. matt46_2

    matt46_2 Private E-2

    I'm not really sure exactly where I got the infection, but I've had it for a little over a week, it caused my laptop to freeze almost immediately on startup, causes pop-unders and attempts to open pop-ups when it does run longer. On top of that it would not allow my regular anti-spyware programs to update (S&D, Ad-Aware). For the most part, I've had to follow the cleaning steps given in this forum in safe mode, the logs are enclosed, Thank you for your time.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello and welcome. We are currently reviewing your logs. Please be patient until I have worked up a fix for you.

    Thanks
    Kes13!
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Why am I not seeing an anti-virus or third party firewall protecting this machine? You are leaving yourself wide open to attack!


    2. Spyware Doctor 6.0 <-- is this a free trial which is useless and doesn't fix anything anyway or is it paid for software? If a free trial then please include it in our list of software to be uninstalled below:


    3. Please go to Add/Remove Programs and uninstall the following softwares:

    HijackThis 1.99.1 <--- outdated, most up to date version was installed with MGTools.
    Ad-Aware <--- not as effective as SAS or MBAM which you downloaded during the R&R

    4. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    5. Now we need to use ComboFix.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
     
    Registry::
    [HKEY_LOCAL_MACHINE\system\controlset003\services\tcpip\parameters]
    "DhcpNameServer"="1.2.3.4"
     
    [HKEY_LOCAL_MACHINE\system\controlset003\services\tcpip\parameters\interfaces\{b7700561-9800-4670-aa12-2583ee896bd2}]
    "DhcpNameServer"="1.2.3.4"
     
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
     
     
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    6. You had signs of a DNS hijacker infection that has mostly been removed. The infection you have is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup. After doing this, continue with on with the below.


    Download HostsXpert and then follow the below steps.

    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    7. Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).


    8. Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    9. Run the new MGtools.exe

    10. Attach logs from:

    • Combofix
    • The new MGTools.exe
     
    Last edited by a moderator: May 12, 2009
  4. matt46_2

    matt46_2 Private E-2

    My computer locked up a few times during this process, but seems to be doing just fine now. I was unable to remove Ad-Aware from the add/remove programs, I will see if I can fix that as soon as possible. Other than that, everything seems better, thank you very much for your help, the logs you requested are enclosed.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    GMER's MBR.exe

    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.


    Now delete the current mbr.log file and then run the below instructions.
    Click Start > Run and copy & paste the following text in the code box into the Run box and then click OK. You must copy and paste or type in this exactly. The quotes must be exactly as shown and there is a space before the -f
    Code:
    
         "%userprofile%\desktop\mbr.exe" -f
    
    Now double click on the mbr.exe file and attach the new mbr.log



    1.
    Now we need to use ComboFix again

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    
    File::
    C:\WINDOWS\Temp\rg4sfay     
    C:\WINDOWS\Temp\ydf8dk
    
    
    Registry::
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"="1.2.3.4"
    
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters\interfaces\{b7700561-9800-4670-aa12-2583ee896bd2}]
    "DhcpNameServer"="1.2.3.4"
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    2. Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    3. Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    C:\WINDOWS\Temp

    4. Run the new MGtools.exe and attach the logs it generates into your next reply along with the log from running combofix.
     
    Last edited by a moderator: May 24, 2009
  6. matt46_2

    matt46_2 Private E-2

    mbr log
     

    Attached Files:

    • mbr.log
      File size:
      571 bytes
      Views:
      4
  7. matt46_2

    matt46_2 Private E-2

    new mbr log
     

    Attached Files:

    • mbr.log
      File size:
      572 bytes
      Views:
      4
  8. matt46_2

    matt46_2 Private E-2

    mg tools and combofix logs
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK we have made good progress, please reboot with the xp cd and get into the recovery console....once there, type fixmbr and then hit enter.

    Next...

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  10. matt46_2

    matt46_2 Private E-2

    I don't know if this will have made a difference, but I have an Acer Aspire One, which has no CD ROM drive, I did however boot into the recovery console using F8 on start-up. When I typed in FIXMGR, I was given a message, as follows;

    "CAUTION

    This computer appears to have a non-standard or invalid master boot-record

    FIXMBR may damage your partition tables if you proceed

    This could cause all the partitions on the current hard disk to become inaccessible

    If you are not having problems accessing your drive, do not continue"


    I did not continue from there as I was unsure if it was safe.

    I assumed you would want to see the MGtools log after this step was completed, so I will wait for further instructions before creating and attaching one, unless otherwise requested.


    The computer is running much better now, it has not locked up since the last step and is running smoothly, I have also downloaded and installed AVG antivirus and COMODO Firewall pro.
     
  11. matt46_2

    matt46_2 Private E-2

    EDIT: MGR should be *MBR*. Sorry!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds