Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Begin your free trial now
Pay-as-you-go options starting at $10/user/month
Pay-as-you-go options starting at $10/user/month
Various Trojan Problems - Logon, Logoff loop / Google Redirect
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Various Trojan Problems - Logon, Logoff loop / Google Redirect
Hi, I'm new here. This looks like a pretty busy place, you guys seem to help a lot of people, and since I didn't get a reply in the other forum I found a few days ago I thought I'd try this place. Thanks in advance to anyone who takes the time to read.
![]() The following is a detailed description of the issues I've encountered the past week. I apologize that it's so long, I just don't want to leave out any important details. I have also included the logs from the 8-step process. It actually looks like I've cleaned everything out, but I'd like an experts opinion to make sure. About a week ago, I managed to infect my system. I believe it happened when I accidentally clicked a third-party ad on a website, and silly me had my avast turned off at the time. D: My desktop picture suddenly changed itself to a .gif file that said "Your system has been comprimised! Run a virus check now! Vulnerable to third-party.... etc etc" and there was red X icon on my system tray that I had never seen before. I ran avast and it found some corrupted files which I removed, but I still could not change my desktop picture back to normal. When I tried (by right clicking into the display properties as i normally would) it would not allow me to browse for a new picture. I could not alter the desktop in any way, so I knew something was still wrong. Also, when i did a google search, and clicked on a search result link, it took me to unwanted websites. For example, even though the file path of the link pointed to techspot, when I clicked it, it took me to some random site. I found the link problem to be changes in my registry and also the internet settings of my browser. Firefox was setup to access internet through a proxy server called 7171. I disabled the proxy and deleted the 2 registry files that pointed to the proxy: HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings, ProxyServer =http=localhost:7171 and HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings, ProxyOverride = *.local;<local> that fixed the google problem. I also found registry files that said "disabletaskmanager" "noactivedesktopchanges" and "noactivedesktop" so I deleted those. I also found a file called m3SrchMn.exe. Then I ran malwarebytes, and it found a few things that I removed. Malwarebytes seemed to have fixed everything, though. I restarted and all was well. This was 1 week ago. Today, I turned my computer on, and found that I was stuck in the Log-on, Log-off loop. I managed to fix that by booting from my Windows XP CD and using the recovery mode. I then downloaded Adaware, and it turned up malware files called Win32.TrojanD\.\ader.NewMedia along with a few other things. But after that, I was suddenly unable to connect to the internet. I tried using a restore point but that didn't work. So I ran a check with internet explorer and it told me the problem was (LSP): Web Guardian. I got onto my husbands computer and learned that malware uses LSP's to mess with the firewall. (or something) So anyway, I deleted it as IE suggested, then rebooted and now I'm online again. I have since removed Avast and installed Avira. Before starting the 8-steps recommended by this board, I ran a full Avira scan, and it found quite a few things, so I enclosed the Avira log along with my Malwarebytes, SuperAntiSpyware and HTJ logs. I ran the CCleaner twice as suggested, and it removed quite a bit. Malwarebytes found absolutely nothing, but SuperAntiSpyware found a lot. My systems clean, everything is working normally. I believe i'm ok, but I would appreciate anyone who can verify that for me. This has been quite the nightmare, I've never infected myself like this before. D: Last edited by kimsland; 03-16-2009 at 09:45 PM.. |
|
#2
|
||||
|
||||
|
Fix entries using HiJackThis
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll (file missing) O2 - BHO: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll (file missing) O3 - Toolbar: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll (file missing) O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx O20 - AppInit_DLLs: c:\program,files\permissionresearch\prai.dll nydorj.dll
Do you know the highlighted red folder? If not delete the following folder c:\program files\permissionresearch\
WARNING: Do not mouseclick combofix's window whilst it's running. That may cause it to stall |
|
#3
|
|||
|
|||
|
That was a quick reply, thanks!
When ComboFix finished, my whole desktop was blank except for the background picture. My desktop icons and my tray was gone, so I rebooted. Everything is where it should be now. Is this normal after running ComboFix? |
|
#4
|
||||
|
||||
|
It can happen yes.
What about that folder? EDIT\\\\\\\\\\\\\\\\\\\ You also have a couple of open ports, did you open them on purpose? If not that's another sign of this particular virus. You also have file sharing software, I would get rid of them. COMBOFIX-Script
Please download ATF Cleaner by Atribune.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
Run HijackThis again and post a log back along with the combofix log. Last edited by kritius; 03-16-2009 at 05:25 PM.. |
|
#5
|
|||
|
|||
|
I don't know what that folder was, so I checked it along with everything else. When I went looking for it to delete it like you suggested, it wasn't listed in c:\program files anymore so I assumed HJT deleted it for me.
I'm not sure what it means to leave a port open, so I don't think it's anything I would have done on purpose, unless it has to do with the fact that I'm connecting to the internet through an ethernet cable, which is plugged into the router, which is plugged into our modem. :-/ My IE folder was located here: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\ instead of here: C:\Windows\Temporary Internet Files Not sure if that's important or not. I deleted the folders, and there were two other things in the content.ie5 folder - one was "index DAT File" and the other one was "desktop configuration settings". You didn't say to delete those so I left them alone, but I thought I should mention them. Here are the logs. How am I looking so far? |
|
|
|
#6
|
||||
|
||||
|
Looking over now.
|
|
#7
|
||||
|
||||
|
OTMoveIT
Please download the OTMoveIt3 by OldTimer
Code:
:Processes explorer.exe :Services :Reg [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "80:TCP"= "7171:TCP"= :Files c:\windows\t55ft3518f44.dat :Folders c:\windows\SxsCaPendDel c:\windows\9gdfgjf23 :commands [purity] [emptytemp] [start explorer] [Reboot]
Download random's system information tool (RSIT) by random/random from HERE and save it to your Desktop.
|
|
#8
|
|||
|
|||
|
Here they are. I had to reboot after OTMoveIt3 but not after the RSIT.
|
|
#9
|
|||
|
|||
|
The best software I have come across to stop this problem is Spybot. If you download that latest version, it will block any nasties affecting your System files where all the damage is done.
|
|
#10
|
||||
|
||||
|
Ok, that looks better.
P2P Warning!
I would like you to do an online scan so that we can what else may be in your system, Run Kaspersky online scanner With the exception of Internet Explorer, which must be used for this scan, keep ALL programs closed Note: It is recommended to disable onboard antivirus program and antispyware programs while performing scans to speed up scan time and to make sure there are no conflicts. Do not go surfing while your resident protection is disabled! Once the scan is finished remember to re-enable resident antivirus protection along with whatever antispyware application you use. Do an online scan with Kaspersky Online Scanner in Internet Explorer. You will be prompted to install and run an ActiveX component from Kaspersky, Click Yes. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75%. Once the licence accepted, reset to 100%.
|
|
#11
|
|||
|
|||
|
I only use Limewire in Ubuntu, so Viruses are not really a problem, plus in Windows, Spybot and AVG keeps the computer clean
|
|
#12
|
|||
|
|||
|
Sorry it took me so long to reply, I was battling a migraine today.
I went to the kapersky site, but it didn't prompt me to run any activex program. It did say "You need to install Java version 1.5 or later to run Kaspersky Online Scanner 7.0." which doesn't make any sense because my java is up to date. I went to java.com to confirm, and it said "You have the recommended Java installed (Version 6 Update 12)." What should I do? (edit) About Limewire, I haven't used it about 6 months, but I used to use it all the time for years and never had a problem with getting infected, so I always assumed it was safe enough. I mainly needed it for certain favorite bands so I could listen to their new songs before they were available for purchase, I'm a big music junkie and can't always wait for CD release dates. But after this whole scare, it isn't worth putting myself at risk. I'm going to take a look at the links you provided, and will probably end up deleting it. Thank you for pointing that out to me.
Last edited by leaht; 03-18-2009 at 12:33 AM.. Reason: forgot to comment on the suggestion to delete limewire. |
|
#13
|
||||
|
||||
|
ok,
lets do this then. PANDA ONLINE SCAN Please go >here< to run Panda's ActiveScan
|
|
#14
|
|||
|
|||
|
Here it is!
|
|
#15
|
||||
|
||||
|
How is the computer running right now?
|
|
#16
|
|||
|
|||
|
Wonderfully. I can't thank you enough for taking the time to walk me through all of this!
As for all the different programs that I've downloaded, should I keep them and run them occasionally, to check my system? I never dreamed that malware could get this complicated - I've had Malwarebytes for a long time, and I always ran it about once a month to make sure nothing unusual was hiding in my computer. If it didn't come up with anything, I thought that was enough. Apparently not. Do you think I should change all my passwords to websites and email now? I just remembered, I actually have them saved to a notepad file on my computer, because there's so many. Is it possible for someone to have accessed them? |
|
#17
|
||||
|
||||
|
It really couldn't hurt.
As for the programs, keep malwarebytes and SAS and we'll take care of the rest now. Please download the OTMoveIt2 by OldTimer.
Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt2 attempting to contact the internet, please allow it to do so.
Re-enable system restore with instructions from tutorial above
Here are some additional utilities that will enhance your safety
Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference! The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware. Also, please read this great article by Tony Klein So How Did I Get Infected In First Place |
|
#18
|
|||
|
|||
|
I've done everything you suggested. I feel so much more secure and I learned a lot. Thank you again for all your help! You're a lifesaver!
|
|
#19
|
||||
|
||||
|
Any time.
Safe surfing!! |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Google Redirect Problems
|
1 | Virus and Malware Removal | ||
Trojan in the SVChost file + Google redirect
|
0 | Virus and Malware Removal | ||
Google redirect and trojan horse dropper -- 8 steps completed
|
6 | Virus and Malware Removal | ||
Google redirect virus and a series of other problems
|
14 | Virus and Malware Removal | ||
Google redirect among other problems
|
1 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 03:29 PM.






But after this whole scare, it isn't worth putting myself at risk. I'm going to take a look at the links you provided, and will probably end up deleting it.
Thank you for pointing that out to me.

Google Redirect Problems