Unable to remove browser hijacker plz help

Discussion in 'Malware Help (A Specialist Will Reply)' started by pinklemonade, Sep 13, 2012.

  1. pinklemonade

    pinklemonade Private E-2

    Let me start off by saying I have read the READ ME FIRST steps already. I also went to the "google redirecting" post and tried to follow those steps as well. Ive deleted all temp internet files and resseted the options, I did the DNS Cache flush but it said "the required operations requires elevation". I downlloaded the TDSSKiller i ran as admin and it wouldnt open i then downloaded the fixTDSS ran as admin and again wouldnt open. Before all this i did multiple scans that I spent hours watching and waiting for and STILL cannot seem to get rid of it. BUT this is not my complete story so let me start from the begining.

    I had gotten a virus..the "file recovery virus" not sure the exsact name of it but thats what it said it was when i looked it up on google. I couldnt find much on how to get rid of it and somehow i did cause its not bothering my computer anymore i found instructions on bleepingcomputer and followed them and it seemed like it worked. but my start up menu is different and my internet explorer look different and one of the folders this virus apparently hid is missing and i cant seem to find it or recover it PLUS my windows explorer doesnt always start up wen i start my comp i have to go to task manager and run iexplorer.exe from there. Anyways after all this i noticed my internet was acting funny i would click on a link and it would redirect me to a tottally diff website. I DID have a bunch of anti virus things on my computer that i now realize was stupid (im not very comp savy) but i deleted them I had mcafee-deleted i had ad aware- deleted now i have Avast and I have microsft securty essentials not sure which i should keep? and i also have malwarebytes anti malware (and the TDSSKiller). I ran the anti-malware when i had that yucky virus and had it remove everything it found (im attaching the log) I also had done a pandaactive scan and went into safe mode and deleted them one by one (computer guy taught me that) (ill attach the log) ive since done an avast scan...anti malware scan and a panda active scan and bitdyfender scan basicaly they arent finding anything.....I NEED HELP ...i dont want to continue without someone who knows what theyre doing to help ...this is very stressfull and im having nightmares because of it lol (yes nightmares) please save me????????

    I have a dell running on vista 34 bit had the laptop since 2008 but its only been giving me problems this past year
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am sure you do, and I will oblige. However, in order for me to help you, you need to attach all of the requested logs from the malware removal procedures. Without those, I am about as much use to you as an ashtray on a motorbike. ;)

    Link to procedures in case you need them to refer to = READ & RUN ME FIRST. Malware Removal Guide
     
  3. pinklemonade

    pinklemonade Private E-2

    Yay! Someone replied ! so happy lol

    Okay so i did the ccleaner I havent closed it yet cause im not sure what im suppose to do with everything it showed IM GUESSING close it lol cause it jus cleans temp files? I did the MBRscan which i attached the log. 2 days ago i tried running the micrsoft malware remover tool and it had runn for 2 whole hours had about 10 min left and decided to FREEZEEEEEEEE -_- .... shall I do that again ? any other scans? Ive seen people attaching hitman and hijackthis scans? should I bee doing those ? Let me know my next step!! Thank youuuuuuu
     

    Attached Files:

    Last edited: Sep 13, 2012
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No. Do not run anything that I do not ask you to run. :)

    Yes, if you actually check the link I gave you, all of the instructions for running the various tools are there ;)
     
  5. pinklemonade

    pinklemonade Private E-2

    I guess that was a blonde moment but thanks for adding smileys so it doesnt sound TOOOO mean when you have to repeat yourself lol

    Ok Roguekiller (had to rename it so it would save to my desktop) I am guessing all the things it found are really bad lol - Ive attached the Log

    TDSSkiller- as ive mentioned will not run even wen i run as admin

    Anti-malware - Ive attached in previous post

    MG tool - Attached

    Hitman pro - Attached

    Thanks for being patient ..I can already tell what they found look bad lol *closes eyes holds breath and waits*
     

    Attached Files:

  6. pinklemonade

    pinklemonade Private E-2

    OH NO!!!

    UPDATE: I just got the blue screen of death :cry I didnt get to read anything it said except for the words "crashdump" and then it restarted my computer ...not sure whatttt that meansss other then what people have said (that is was the screen of death)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My apologies, I was not being patronising, I just tend to have a very direct approach. :-D

    Now, it looks like you have an MBR infection. Do you have your Vista boot CD/DVD?

    Let's run this to see if it can tackle it or not.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run
     
  8. pinklemonade

    pinklemonade Private E-2

    I have done the steps on trying to run TDSSkiller it just wont open? i dont know why ..I click as run as admin and the user control window pops up i click continue and then it doesnt open up

    And I do have the operating system CD what shall I do with it?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's being blocked by the infection in place.
    Now that you have the DVD, you need to boot from it to access the Windows 7 System Recovery Environment. You can read details about this in the below link:

    http://www.bleepingcomputer.com/tutorials/tutorial161.html

    Once you have gotten to the command prompt, you need to run the below command

    bootrec.exe /fixmbr


    Then you will reboot normally back to Windows and attach a new log from MBRcheck please.
     
  10. pinklemonade

    pinklemonade Private E-2

    Sorry, I have vista, is it the same process as windows 7 ?

    Just making sure because I am at work and would like to do this when I get home just want to make sure it is the same as windows vista 1st and have the reply for when I get home.

    Thanks!!!!
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes same process. :)
     
  12. pinklemonade

    pinklemonade Private E-2

    Get ready for another blonde moment....So after confusingly trying to understand all these computer words trying to figure out WHY its not booting from the CD I pressed f8 and what bleepingcomputer says is suppose to be there is infact not theres no windows recovery option just these

    restore your comp (which i went to twice gave me an error msg first time and second time it brought me to the windows menu and askd me to log into a unnamed user account that i didnt have the name or pw for...MY USER account is the only account on the comp??? so i dont know)

    then 3 safe mode options one including with command prompt
    As i am not even the slightest intelligent in computers i decided to pick the comand prompt option so it then loaded all the files and the command prompt window came up i typed what you told me to and this was the msg it gave me

    "'bootrec.exe' is not recognizedas an internal or external command, operable program or batch file"

    Im really just confused :(
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So just to clarify, you couldn't get it to boot from CD first? :confused

     
  14. pinklemonade

    pinklemonade Private E-2

    My patient friend ..it would not boot from the CD automatically
    but 10 hour shifts make a confused girl even more confused i succesfully did what i was supposed to in the command prompt it said it was successfull. I did a MBRcheck (looks like it was fixedddd *gasppppp*)
    I tried searching in google MUCH FASTER NOW and doesnt seem like any redirection is happening

    Was everything ALLL those scans finding from this one infection? or do i have to do any removals...ugh what a weight lifted off my shoulders
    Thank you !!

    Waiting for your next steps
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, you did it. Let's now crack on.

    winlogon.exe <--- Why is this on your desktop??


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    • O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :files
    C:\Users\Elyse\AppData\Roaming\Microsoft\Windows\Templates\28v40388ynpx74ht1y0vi25358q03lkl3heatn0wqv82
    C:\Users\Elyse\AppData\Roaming\Microsoft\Windows\Templates\cdtf.exe
    C:\Users\Elyse\AppData\Roaming\Microsoft\Windows\Templates\lkli.exe
    C:\Users\Elyse\AppData\Roaming\Microsoft\Windows\Templates\sgfn.exe
    C:\Users\Elyse\AppData\Roaming\Microsoft\Windows\Templates\ulph.exe
    C:\ProgramData\-AuyIWyp0UZidk2
    C:\ProgramData\-AuyIWyp0UZidk2r
    C:\ProgramData\-iQpwYvd09sVLML
    C:\ProgramData\-iQpwYvd09sVLMLr
    C:\ProgramData\AuyIWyp0UZidk2
    C:\ProgramData\iQpwYvd09sVLML
    C:\Program Files\Enigma Software Group
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    • Re run HitmanPro and attach the log
    • Re run RogueKiller and attach the log.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  16. pinklemonade

    pinklemonade Private E-2

    That is actually Roguekiller I had to rename it so it would save and work (thats what the instructions said if it wouldnt save to my computer, to rename it "winlogon")
     
  17. pinklemonade

    pinklemonade Private E-2

    Done..Logs are attached

    Something you may want to know...all today my computer was starting up normaly and then when it restarted after the OG procedure, it didnt start up windows i had to run task manager and run explorer.exe for it to load. Dont know what thats about, but hopefully you do lol.

    Also i was able to finally run TDSSKiller log is attached

    Thanks!!
     

    Attached Files:

    Last edited: Sep 15, 2012
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good evening Pink lemonade! :)

    You mean OTM? Mere coincidence, only malware was removed, nothing to cause that. Have you tried further reboots since? I imagine all is ok now and if it persists this is something you will have to ask about in the software forum.

    Good, that has come up clean because the MBR infection has gone.

    You are *most* welcome. Safe surfing! Final steps below to follow when you are ready.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  19. pinklemonade

    pinklemonade Private E-2

    Thank you soosososoossoso much!!! couldnt be more greatfulll. Without you i would still be having nightmares !!!

    Now I know where i can turn for legitimate help and support! super greatful thank you so much!
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Majorgeeks always strives to be thorough. ;) Take care.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds