Trojan.Win32.LinkReplacer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by crombie1, Dec 13, 2007.

  1. crombie1

    crombie1 Private E-2

    I have done a search here and on the Internet for the system error I am receiving every time I open a new browser or ridiect to a new URL. The system error says "Your computer was hijacked by Trojan.Win32.LinkReplacer". Can anybody point me in the right direction?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. crombie1

    crombie1 Private E-2

    I have performed all of the instructions and attached the logs from AVG. The system error is still there. Help, please?
     

    Attached Files:

  4. crombie1

    crombie1 Private E-2

    by the way, I have not clicked "OK" on the system error message which says it will download antispyware....is this the right thing to do?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must attach all of the requested logs. You only attached MGlogs.zip. You need to attach the logs from ComboFix and AVG Antispyware.
     
  6. crombie1

    crombie1 Private E-2

    Shoot...okay...I'm sorry. Looking for them.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also need to disable Spybot's Teatimer as was requested in the READ ME.

    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
     
  8. crombie1

    crombie1 Private E-2

    okay...here is the AVG Report Scan...I'll find the last one and attach. Thanks for your help!
     

    Attached Files:

  9. crombie1

    crombie1 Private E-2

    ok...here is the ComboFix log...standing by.
     
  10. crombie1

    crombie1 Private E-2

    Rrrrrrrrrrrrrrrrrr.....I thought I did that. Okay...I'm going back there now.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach it.
     
  12. crombie1

    crombie1 Private E-2

    Here it is....sorry.
     

    Attached Files:

  13. crombie1

    crombie1 Private E-2

    I also reran the Spybot once the TeaTimer was off.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now run this sticky thread procedure:

    Trojan.Win32.Agent.akk Removal Procedure


    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     
  15. crombie1

    crombie1 Private E-2

    Will do...thanks.
     
  16. crombie1

    crombie1 Private E-2


    Where do I attach the new C:\MGlogs.zip file?
     
  17. crombie1

    crombie1 Private E-2

    Duh...sorry...lol
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    RIght here! Make sure you ran GetLogs.bat to create a new one or it will not attach.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do the below while I look thru your logs!


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 7
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After you finish the instructions in message # 19, continue with the below.


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe by double clicking on it.
      [*]click the Make Writeable? button.
      [*]click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O1 - Hosts: HP99DC2F HP0018FE99DC2F
    O1 - Hosts: HPF3E0AD HP0019BBF3E0AD
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.


    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  21. crombie1

    crombie1 Private E-2

    Done! :)
     
  22. crombie1

    crombie1 Private E-2


    I get an error message when I do this.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you do the step above that said:
     
  24. crombie1

    crombie1 Private E-2

    I did...hmmmm...I'm going to start again in the am. Thanks for your help today.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it does not work, after you are sure your click the Make Writeable button or you get an error when you click the button. Then exit antivirus and antispyware programs and try again. If you get any error messages, give me the exact word for word error message.
     
  26. crombie1

    crombie1 Private E-2




    When I do this, I get the following error message: "Error: Cannot create file c:\WINDOWS\system32\DRIVERS\ETC\hosts"
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    McAfee, StopZilla and AVG Antispyware could be getting in the way. Try shutting them down or at least disabling protection and also try booting in safe mode to make the change (if necessary).
     
  28. crombie1

    crombie1 Private E-2

    Ok...will do.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If that does not work, we may have to try deleting the c:\WINDOWS\system32\DRIVERS\ETC\hosts file with a special tool and then recreate the default with HostsXpert
     
  30. crombie1

    crombie1 Private E-2

    That worked! Moving onto:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O1 - Hosts: HP99DC2F HP0018FE99DC2F
    O1 - Hosts: HPF3E0AD HP0019BBF3E0AD
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great! Just attach the follow up log when you finish the other steps.
     
  32. crombie1

    crombie1 Private E-2

    Ok...have finished all steps and the requested log is attached. The system error message has stopped! :)
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds