Jump to content

Hijacked Search results and browser shutting


Recommended Posts

  • Replies 62
  • Created
  • Last Reply

Top Posters In This Topic

Hi ya,

I need you to run a couple of tools for me and post back all logs :(

1)STEP 01

Please visit this webpage for instructions for downloading ComboFix to your
DESKTOP
:

Please ensure you read this guide carefully and install the Recovery Console first.

NOTE!!:
You must save and run
ComboFix.exe
on your DESKTOP and not from any other folder.
Also,
DO NOT
click the mouse or launch any other applications while this is running or it may stall the program

Additional links to download the tool:

Note:
The
Windows Recovery Console
will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.
Please continue as follows:
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click
    Yes
    to allow ComboFix to continue scanning for malware.

  • When the tool is finished, it will produce a report for you.

  • Please post the
    C:\ComboFix.txt
    along with a
    new HijackThis log
    so we may continue cleaning the system.

2)Please download GooredFix and save it to your Desktop.

http://jpshortstuff.247fixes.com/GooredFix.exe

Select "2. Fix Goored" by typing 2 and pressing Enter.

Make sure all instances of Firefox are closed at this point.

Type y at the prompt and press Enter again.

A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).

Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.

Link to post
Share on other sites

Hi and thanks for your help.

1st problem I have is trying to read the how to use instructions for combofix, clicking the link you added above 'how-to-use-combofix' closers my broswer, tried copying the url into AOL and that completly shuts AOL down. :(

Link to post
Share on other sites

Done, see report below:

GooredFix v1.92 by jpshortstuff

Log created at 23:01 on 25/03/2009 running Option #2 (Compaq_Administrator)

Firefox version 3.0.7 (en-GB)

=====Goored Deletions=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]

"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]

"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]

"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]

"{1d5287d1-8a92-0001-1f31-1cec198018d8}"="C:\Program Files\AVG\AVG8\ToolbarFF"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]

"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]

"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

Link to post
Share on other sites

OK, got the instructions from another PC, followed then:

- closed all anti virus programmes and windows firewall

- downloaded ComboFix to my desktop

- closed all windows and double clicked ComboFix

- Clicked Run

I now get this message ' Errors encountered while performing the operation Look at the information window for more details. If I click OK there is just a small box with ComboFix written above a row of green lines.

Reboot is needed to clear it.

Link to post
Share on other sites

Ok something definetly not letting me unpack my toolkit on your pc but hey i love a challenge :(

Time to bring is some powerful tools and see if we can crack it!

1) Download the following tool and only use as directed!

http://rootrepeal.googlepages.com/

Install RootRepeal and select *Report* scan only.Next place tick in all box's except for SSDT report.Next press scan and then save the log generated.

Please Copy and Paste the output log generated in a reply post.

2nd report log needed-

Download and install Autoruns.

http://technet.microsoft.com/en-us/sysinte...s/bb963902.aspx

When you first run it it will generate an extensive listing and the word "Ready" will appear in the bottom left of the sofware GUI.

At this point goto options and place check(tick) against verify coded signatures and hide Microsoft & windows entries.Next press F5 button to refresh.

Once Ready status by software is gained then goto File option.Select "Export as" and save output file as Autoruns.txt

Can you please then copy and paste the contents of that text file into your next reply for analysis.

Link to post
Share on other sites

post-11517-1238092592_thumb.jpgOK, stuck on the 1st hurdle again downloaded rootrepeal but see no *Report* option etc, see image.

1) Download the following tool and only use as directed!

http://rootrepeal.googlepages.com/

Install RootRepeal and select *Report* scan only.Next place tick in all box's except for SSDT report.Next press scan and then save the log generated.

post-11517-1238092592_thumb.jpg

Link to post
Share on other sites

No worries.

Download and save file from link to your desktop.

Next right click on file and select extract(Winrar) and then confirm(OK).

This will create new folder on desktop that has been decompressed from the downloaded file.Go into that folder and click on Rootrepeal .exe to run it .

Link to post
Share on other sites

Right I took the bit between the teeth are retried, See log below :(

ROOTREPEAL © AD, 2007-2008

==================================================

Scan Time: 2009/03/26 20:10

Program Version: Version 1.2.3.0

Windows Version: Windows XP Media Center Edition SP3

==================================================

Drivers

-------------------

Name: dump_atapi.sys

Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys

Address: 0xF2C9E000 Size: 98304 File Visible: No

Status: -

Name: dump_WMILIB.SYS

Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS

Address: 0xF7AF2000 Size: 8192 File Visible: No

Status: -

Name: rootrepeal.sys

Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys

Address: 0xB9B65000 Size: 45056 File Visible: No

Status: -

Hidden/Locked Files

-------------------

Path: C:\Documents and Settings\All Users\Application Data\AOL\storage\server.lock

Status: Allocation size mismatch (API: 8, Raw: 0)

Path: C:\Documents and Settings\Compaq_Administrator\Local Settings\Apps\2.0\CL0Z8EA0.Y16\320N6JQ6.BXA\manifests\clickonce_bootstrap.exe.cdf-ms

Status: Locked to the Windows API!

Path: C:\Documents and Settings\Compaq_Administrator\Local Settings\Apps\2.0\CL0Z8EA0.Y16\320N6JQ6.BXA\manifests\clickonce_bootstrap.exe.manifest

Status: Locked to the Windows API!

Path: C:\Documents and Settings\Compaq_Administrator.YOUR-E6F02835AE\Local Settings\Apps\2.0\ERQX1MV9.4O5\W43NXRKK.C30\manifests\clickonce_bootstrap.exe.cdf-ms

Status: Locked to the Windows API!

Path: C:\Documents and Settings\Compaq_Administrator.YOUR-E6F02835AE\Local Settings\Apps\2.0\ERQX1MV9.4O5\W43NXRKK.C30\manifests\clickonce_bootstrap.exe.manifest

Status: Locked to the Windows API!

Path: C:\Documents and Settings\Compaq_Administrator.YOUR-E6F02835AE\My Documents\Work\private audits\Spirita Limited\Completed DDA Audits\DDA 21 Trinity RD + Hall Rd + Bradley Crt\DDA 21 Trinity Rd + Hall Rd + Bradley Court\Bradley Court images\Thumbs.db:encryptable

Status: Locked to the Windows API!

Link to post
Share on other sites

Ok from the Autoruns log there was one suspicious entry.

MHNDRV Multimedia Home Network component driver (Not verified) Microsoft Corporation c:\windows\system32\drivers\mhndrv.sys

If possible could you locate and upload the file to VirusTotal service for 39 second opinions :(

http://www.virustotal.com

Please post back a link to the generated report page.

Also please attempt to download ComboFix via Firefox but using the following method.

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  1. If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".

[*]During the download, rename Combofix to Combo-Fix as follows:

CF_download_FF.gif

CF_download_rename.gif

[*]It is important you rename Combofix during the download, but not after.

[*]Please do not rename Combofix to other names, but only to the one indicated.

[*]Close any open browsers.

[*]Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

-----------------------------------------------------------

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    -----------------------------------------------------------


  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

-----------------------------------------------------------

[*]Double click on combo-Fix.exe & follow the prompts.

[*]When finished, it will produce a report for you.

[*]Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

If you still cannot get this to run, try booting into Safe Mode, and run it there.

To boot into Safe Mode, tap F8 after BIOS, and just before the Windows logo appears. A list of options will appear, select "Safe Mode."

Link to post
Share on other sites

If possible could you locate and upload the file to VirusTotal service for 39 second opinions
Please see below, will now go back to your post to continue.

File mhndrv.sys received on 02.26.2009 11:30:32 (CET)

Current status: finished

Result: 0/39 (0.00%)

Compact Print results

Antivirus Version Last Update Result

a-squared 4.0.0.93 2009.02.26 -

AhnLab-V3 2009.2.26.0 2009.02.25 -

AntiVir 7.9.0.88 2009.02.26 -

Authentium 5.1.0.4 2009.02.25 -

Avast 4.8.1335.0 2009.02.25 -

AVG 8.0.0.237 2009.02.26 -

BitDefender 7.2 2009.02.26 -

CAT-QuickHeal 10.00 2009.02.26 -

ClamAV 0.94.1 2009.02.25 -

Comodo 986 2009.02.20 -

DrWeb 4.44.0.09170 2009.02.26 -

eSafe 7.0.17.0 2009.02.25 -

eTrust-Vet 31.6.6375 2009.02.26 -

F-Prot 4.4.4.56 2009.02.25 -

F-Secure 8.0.14470.0 2009.02.26 -

Fortinet 3.117.0.0 2009.02.26 -

GData 19 2009.02.26 -

Ikarus T3.1.1.45.0 2009.02.26 -

K7AntiVirus 7.10.647 2009.02.25 -

Kaspersky 7.0.0.125 2009.02.26 -

McAfee 5536 2009.02.25 -

McAfee+Artemis 5536 2009.02.25 -

Microsoft 1.4306 2009.02.26 -

NOD32 3890 2009.02.26 -

Norman 6.00.06 2009.02.25 -

nProtect 2009.1.8.0 2009.02.26 -

Panda 10.0.0.10 2009.02.26 -

PCTools 4.4.2.0 2009.02.25 -

Prevx1 V2 2009.02.26 -

Rising 21.18.32.00 2009.02.26 -

SecureWeb-Gateway 6.0.0 2009.02.26 -

Sophos 4.39.0 2009.02.26 -

Sunbelt 3.2.1858.2 2009.02.25 -

Symantec 10 2009.02.26 -

TheHacker 6.3.2.5.265 2009.02.25 -

TrendMicro 8.700.0.1004 2009.02.26 -

VBA32 3.12.10.0 2009.02.26 -

ViRobot 2009.2.26.1624 2009.02.26 -

VirusBuster 4.5.11.0 2009.02.25 -

Additional information

File size: 11008 bytes

MD5...: 7f2f1d2815a6449d346fcccbc569fbd6

SHA1..: 3085859db0bf86a7014c1222321d68b0605768dd

SHA256: 1c5a321ce95ce4d9aa2cb5a00e9b7e711521a6bbb25d36f7f49a397c361585c6

SHA512: fd1cc04ebe6043f5fcee6fe5bc57185b050f07a88b8c1dba7d60d292b929bdcb

bfaf1c0c93e5d4fcd537b939d8b11ca46c065fd8b6006a8d5f2ff0847e9364e8

ssdeep: 192:6L9DvB9rtRzH8chmCWnh6RIBLQsOyh8iOIoJRaO0LmCsW1pvvW5DXVmVw:6L

1vB9rrccWzZtlh0dJRh+/sW1pvvWe

PEiD..: -

TrID..: File type identification

Generic Win/DOS Executable (49.9%)

DOS Executable Generic (49.8%)

Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)

PEInfo: PE Structure information

( base data )

entrypointaddress.: 0x12085

timedatestamp.....: 0x4118a72e (Tue Aug 10 10:45:02 2004)

machinetype.......: 0x14c (I386)

( 6 sections )

name viradd virsiz rawdsiz ntrpy md5

.text 0x300 0x1af4 0x1b00 6.24 e85d995947c2851c7b7da2fa6ab865df

.rdata 0x1e00 0x1a4 0x200 3.13 1e44126c3497709bada215832493fd75

.data 0x2000 0x44 0x80 0.38 0c41a08c90a7d5e81bf065649ebabedc

INIT 0x2080 0x32a 0x380 4.98 eac5e44018d7b0f8ed40eed75a287e33

.rsrc 0x2400 0x440 0x480 3.31 1fd1baf851cca727b2ec3ee4fbb367bc

.reloc 0x2880 0x248 0x280 5.79 d40d025ca4fa1787c2f6b0336a028023

( 2 imports )

> ntoskrnl.exe: KeInitializeSpinLock, IoCreateDevice, RtlInitUnicodeString, MmUnlockPages, IoFreeMdl, ExAllocatePoolWithQuotaTag, _except_handler3, IoReleaseCancelSpinLock, IoAcquireCancelSpinLock, ExFreePoolWithTag, KeAcquireInStackQueuedSpinLockAtDpcLevel, MmMapLockedPagesSpecifyCache, MmProbeAndLockPages, IoAllocateMdl, ProbeForWrite, SeSinglePrivilegeCheck, SeExports, KeTickCount, IoDeleteDevice, KeReleaseInStackQueuedSpinLockFromDpcLevel, IofCompleteRequest

> HAL.dll: KeReleaseInStackQueuedSpinLock, KeAcquireInStackQueuedSpinLock

( 0 exports )

Link to post
Share on other sites

Please see below, will now go back to your post to continue with your instructions.

File mhndrv.sys received on 02.26.2009 11:30:32 (CET)

Current status: finished

Result: 0/39 (0.00%)

Compact Print results

Antivirus Version Last Update Result

a-squared 4.0.0.93 2009.02.26 -

AhnLab-V3 2009.2.26.0 2009.02.25 -

AntiVir 7.9.0.88 2009.02.26 -

Authentium 5.1.0.4 2009.02.25 -

Avast 4.8.1335.0 2009.02.25 -

AVG 8.0.0.237 2009.02.26 -

BitDefender 7.2 2009.02.26 -

CAT-QuickHeal 10.00 2009.02.26 -

ClamAV 0.94.1 2009.02.25 -

Comodo 986 2009.02.20 -

DrWeb 4.44.0.09170 2009.02.26 -

eSafe 7.0.17.0 2009.02.25 -

eTrust-Vet 31.6.6375 2009.02.26 -

F-Prot 4.4.4.56 2009.02.25 -

F-Secure 8.0.14470.0 2009.02.26 -

Fortinet 3.117.0.0 2009.02.26 -

GData 19 2009.02.26 -

Ikarus T3.1.1.45.0 2009.02.26 -

K7AntiVirus 7.10.647 2009.02.25 -

Kaspersky 7.0.0.125 2009.02.26 -

McAfee 5536 2009.02.25 -

McAfee+Artemis 5536 2009.02.25 -

Microsoft 1.4306 2009.02.26 -

NOD32 3890 2009.02.26 -

Norman 6.00.06 2009.02.25 -

nProtect 2009.1.8.0 2009.02.26 -

Panda 10.0.0.10 2009.02.26 -

PCTools 4.4.2.0 2009.02.25 -

Prevx1 V2 2009.02.26 -

Rising 21.18.32.00 2009.02.26 -

SecureWeb-Gateway 6.0.0 2009.02.26 -

Sophos 4.39.0 2009.02.26 -

Sunbelt 3.2.1858.2 2009.02.25 -

Symantec 10 2009.02.26 -

TheHacker 6.3.2.5.265 2009.02.25 -

TrendMicro 8.700.0.1004 2009.02.26 -

VBA32 3.12.10.0 2009.02.26 -

ViRobot 2009.2.26.1624 2009.02.26 -

VirusBuster 4.5.11.0 2009.02.25 -

Additional information

File size: 11008 bytes

MD5...: 7f2f1d2815a6449d346fcccbc569fbd6

SHA1..: 3085859db0bf86a7014c1222321d68b0605768dd

SHA256: 1c5a321ce95ce4d9aa2cb5a00e9b7e711521a6bbb25d36f7f49a397c361585c6

SHA512: fd1cc04ebe6043f5fcee6fe5bc57185b050f07a88b8c1dba7d60d292b929bdcb

bfaf1c0c93e5d4fcd537b939d8b11ca46c065fd8b6006a8d5f2ff0847e9364e8

ssdeep: 192:6L9DvB9rtRzH8chmCWnh6RIBLQsOyh8iOIoJRaO0LmCsW1pvvW5DXVmVw:6L

1vB9rrccWzZtlh0dJRh+/sW1pvvWe

PEiD..: -

TrID..: File type identification

Generic Win/DOS Executable (49.9%)

DOS Executable Generic (49.8%)

Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)

PEInfo: PE Structure information

( base data )

entrypointaddress.: 0x12085

timedatestamp.....: 0x4118a72e (Tue Aug 10 10:45:02 2004)

machinetype.......: 0x14c (I386)

( 6 sections )

name viradd virsiz rawdsiz ntrpy md5

.text 0x300 0x1af4 0x1b00 6.24 e85d995947c2851c7b7da2fa6ab865df

.rdata 0x1e00 0x1a4 0x200 3.13 1e44126c3497709bada215832493fd75

.data 0x2000 0x44 0x80 0.38 0c41a08c90a7d5e81bf065649ebabedc

INIT 0x2080 0x32a 0x380 4.98 eac5e44018d7b0f8ed40eed75a287e33

.rsrc 0x2400 0x440 0x480 3.31 1fd1baf851cca727b2ec3ee4fbb367bc

.reloc 0x2880 0x248 0x280 5.79 d40d025ca4fa1787c2f6b0336a028023

( 2 imports )

> ntoskrnl.exe: KeInitializeSpinLock, IoCreateDevice, RtlInitUnicodeString, MmUnlockPages, IoFreeMdl, ExAllocatePoolWithQuotaTag, _except_handler3, IoReleaseCancelSpinLock, IoAcquireCancelSpinLock, ExFreePoolWithTag, KeAcquireInStackQueuedSpinLockAtDpcLevel, MmMapLockedPagesSpecifyCache, MmProbeAndLockPages, IoAllocateMdl, ProbeForWrite, SeSinglePrivilegeCheck, SeExports, KeTickCount, IoDeleteDevice, KeReleaseInStackQueuedSpinLockFromDpcLevel, IofCompleteRequest

> HAL.dll: KeReleaseInStackQueuedSpinLock, KeAcquireInStackQueuedSpinLock

( 0 exports )

Link to post
Share on other sites

Combofix

Out of the two links you posted Please download ComboFix from Here or Here to your Desktop.

Right link closes my browser

Left link works, changed setting as you suggested and downloaded.

Saved Combo-Fix to desk top (after name change as left)

Closed all browsers and hit run after disabling anti v etc as suggested.

A green box comes up with Combofix in it, that goes away after about 5 seconds and my PC stays as is, still connected to the net etc. Combofix does not run.

Regards.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.