Avast WEBforum

Other => Viruses and worms => Topic started by: monkeybones on February 17, 2012, 07:10:40 AM

Title: redirect/browser hijack
Post by: monkeybones on February 17, 2012, 07:10:40 AM
hello, all. 

i would appreciate some help getting rid of a particularly nasty bug.  i'm trying to avoid a wipe.  please let me know what you would like me to install and which reports you'd like to get the ball rolling. 

thank you in advance
Title: Re: redirect/browser hijack
Post by: Gargamel360 on February 17, 2012, 07:21:11 AM
Follow this guide>>http://forum.avast.com/index.php?topic=53253.msg451454#msg451454 , then post the resulting logs in this topic as attachments.
Title: Re: redirect/browser hijack
Post by: monkeybones on February 17, 2012, 07:42:25 AM
malwarebytes logs attached
Title: Re: redirect/browser hijack
Post by: monkeybones on February 17, 2012, 08:22:49 AM
the captcha is no longer showing up when i try to reply from the infected computer which means i cannot post a reply.  when it's resolved i will post the otl logs.
Title: Re: redirect/browser hijack
Post by: monkeybones on February 17, 2012, 08:40:56 AM
trying to post from another computer.  please let me know if it works for you.
Title: and because i'm sure it's helpful
Post by: monkeybones on February 18, 2012, 01:19:53 AM
the little bugger that sent me in search of help is MBR:\\.\PHYSICALDRIVE0

i'm hoping i can find a work around that won't require a wipe. 
the problem is on my sister's computer.
she is using vista.
we do not have boot discs
Title: Re: redirect/browser hijack
Post by: monkeybones on February 18, 2012, 09:39:20 AM
last log
Title: Re: redirect/browser hijack
Post by: essexboy on February 19, 2012, 11:42:05 AM
Here you go this should fix it

Re-Run aswMBR

Click Scan

On completion of the scanClick the   Fix  Button

(http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRFix.gif)


Save the log as before and post in your next reply
Title: Re: redirect/browser hijack
Post by: monkeybones on February 19, 2012, 11:51:07 PM
this crashed the computer.  it will not stay on now, even in safemode.  windows starts the repair process but it shuts off the middle and the whole things starts over again. 
Title: Re: redirect/browser hijack
Post by: essexboy on February 20, 2012, 12:05:58 AM
OK lets retrace our steps and try again

From the safe mode menu select a restore point when you reboot run aswMBR please for a scan
Title: Re: redirect/browser hijack
Post by: monkeybones on February 20, 2012, 01:00:30 AM
i can't.  the computer won't start, even in safemode. 

it tried running the system disc check but failed.

session details
______________________

system disk = \device\harddisk0
windows directory = C:\windows
autochk run = 0
number of root causes = 1

every test completed succesfully error code 0x0

root cause found:
____________

unspecified changes to system configuration might have caused the problem. 






that is the last thing i got from the computer.  when it tries to restart, it blue screens.  if it makes i past blue screen, it will turn off a few seconds after booting, even in safe mode.  most times it will not make it to the safe mode screen at all.
Title: Re: redirect/browser hijack
Post by: monkeybones on February 20, 2012, 05:33:19 AM
test
Title: Re: redirect/browser hijack
Post by: essexboy on February 20, 2012, 08:33:47 PM
Are you back in now ?

Do you have the windows CD so the we can access the deeper repairs

If you are in could you run a fresh OTL scan for me please
Title: Re: redirect/browser hijack
Post by: monkeybones on February 20, 2012, 10:01:58 PM
she doesn't have a cd, no.


i can get in for a moment at a time.  i set things up bit by bit so i could scan, then save, then email the scan to myself on successive tries.  i may be able to keep it open longer- it's being finicky.  i am responding from my personal computer atm. 

i will attempt the otl scan as soon as i get home from work this evening. 
thanks for responding.
Title: Re: redirect/browser hijack
Post by: essexboy on February 20, 2012, 10:48:22 PM
As soon as i can get to my computer I will post a link for you to burn a recovery console disc
Title: Re: redirect/browser hijack
Post by: essexboy on February 20, 2012, 11:45:20 PM
OK here we go

Download win Vistax86 iso from here http://www.forum.probz.net/index.php?/files/file/21-windows-vista-recovery-environment-iso/
Burn to a cd as bootable -  You can use ImgBurn (http://download.imgburn.com/SetupImgBurn_2.5.6.0.exe) do this.

Now reboot from the Windows Vista Recovery Environment CD and execute the following commands:
 
When you reboot you will  see this although yours will say windows 7. Click repair my computer
(http://i1224.photobucket.com/albums/ee362/Essexboy3/RepairVista_7275.jpg)
 
Select your operating system
(http://i1224.photobucket.com/albums/ee362/Essexboy3/RepairVista_7277202.jpg)
 
Select Command prompt
(http://i1224.photobucket.com/albums/ee362/Essexboy3/RepairVista_7277.jpg)
 
At the command prompt type the following 
 
Bootrec.exe /FixMbr 
 
If that does not work then :



For x32 (x86) bit systems download Farbar Recovery Scan Tool (http://download.bleepingcomputer.com/farbar/FRST.exe) and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool x64 (http://download.bleepingcomputer.com/farbar/FRST64.exe) and save it to a flash drive.
 
Plug the flashdrive into the infected PC.
 
Enter System Recovery Options.
 
To enter System Recovery Options by using Windows installation disc:
On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[/list]
Title: Re: redirect/browser hijack
Post by: monkeybones on February 21, 2012, 01:25:50 AM
is that going to delete any files from her computer?  should i try to save her photos/docs etc before i run the repair?
Title: Re: redirect/browser hijack
Post by: monkeybones on February 21, 2012, 01:32:53 AM
OTL LOGS
Title: Re: redirect/browser hijack
Post by: essexboy on February 21, 2012, 09:10:43 PM
No none of the tools I use will delete files until they are told to do so - What is the current state of play, I see you are running from safe mode.  Can you achieve normal mode

Did the Fixmbr allow you to get this far

Title: Re: redirect/browser hijack
Post by: monkeybones on February 23, 2012, 01:13:44 AM
can't get in at all right now.  it keeps prompting start up repair then shutting down while it's loading files. 

Title: Re: redirect/browser hijack
Post by: essexboy on February 23, 2012, 09:16:20 PM
OK could you follow the destructions to download the farbar recovery tool and the windows recovery console ISO and I will get you up and running again
Title: Re: redirect/browser hijack
Post by: monkeybones on February 25, 2012, 07:18:11 AM
sorry.  flu.  been out of commission.  still not up to snuff.

tried the disc, but no dice.  i will try the farbar tool again and report back.  there will likely be some lag between posts still while i'm recovering. 
Title: Re: redirect/browser hijack
Post by: essexboy on February 25, 2012, 12:04:08 PM
FRS will not do any repairs untill I tell it to.  The initial run will be to determine the problem
Title: Re: redirect/browser hijack
Post by: monkeybones on February 27, 2012, 09:55:08 PM
it keeps saying "the device is not ready" when i try to open the flash drive from cp
Title: Re: redirect/browser hijack
Post by: essexboy on February 27, 2012, 10:07:22 PM
OK this is not the ideal way but could you run FRS from safe mode
Title: Re: redirect/browser hijack
Post by: monkeybones on February 27, 2012, 10:09:31 PM
log
Title: Re: redirect/browser hijack
Post by: essexboy on February 27, 2012, 10:14:56 PM
here (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) and save it to your Desktop.
 
 
A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
[/list]
Title: Re: redirect/browser hijack
Post by: monkeybones on February 27, 2012, 11:04:23 PM
is there a way to get this on the infected machine without downloading?  it's difficult to keep the computer on long enough to get online, let alone download.  right now it's just cycling through the blue screen over and over and i can't get it to stay on at all.
Title: Re: redirect/browser hijack
Post by: essexboy on February 28, 2012, 12:06:39 AM
I thought you had manage to achieve safe mode ( Use safe mode with networking)
Title: Re: redirect/browser hijack
Post by: monkeybones on February 28, 2012, 06:33:04 AM
it works SOMETIMES.  and in spurts.  the computer is still cycling over and over and over, restarting itself.  sometimes it won't turn on at all.
Title: Re: redirect/browser hijack
Post by: essexboy on February 28, 2012, 09:18:11 PM
Do you have a USB drive that you can use ?

We will use an mobile operating system called xPUD, and a script called rst.sh to restore your computer.

Download http://unetbootin.sourceforge.net/unetbootin-xpud-windows-latest.exe & http://noahdfear.net/downloads/bootable/xPUD/xpud-0.9.2.iso to the desktop of your clean computer

(http://i1224.photobucket.com/albums/ee362/Essexboy3/Misc%20screen%20shots/XPud.jpg)
bash rst.sh

Title: Re: redirect/browser hijack
Post by: monkeybones on February 29, 2012, 08:42:11 PM
the first steps worked and i got everything on the usb. 
f12 did nothing, but i was able to find the key i needed to boot from the usb
when it loaded xpud nothing happened
it says "no job control on this shell"
Title: Re: redirect/browser hijack
Post by: essexboy on February 29, 2012, 08:47:31 PM
Could you confirm that you copied the Xpud ISO  when you ran unetbootin

As per my screenshot
Title: Re: redirect/browser hijack
Post by: monkeybones on February 29, 2012, 09:04:08 PM
yes, i did
Title: Re: redirect/browser hijack
Post by: essexboy on February 29, 2012, 09:21:34 PM
Could you get a fresh copy of Xpud - reformat the USB and try again please
Title: Re: redirect/browser hijack
Post by: monkeybones on February 29, 2012, 10:18:03 PM
now it says
"could not find kernal image: linux
boot: _"
Title: Re: redirect/browser hijack
Post by: DonZ63 on February 29, 2012, 10:29:28 PM
I can say from experience that many of the newer AMD based motherboards have problems with the newer Linux kernnels. I can't use the latest Kapersky recovery CD since it uses a later Linux kernnel and my Gigabyte BIOS chokes on it.
Title: Re: redirect/browser hijack
Post by: monkeybones on February 29, 2012, 10:47:48 PM
i feel like each successive step is making it worse and worse...
Title: Re: redirect/browser hijack
Post by: monkeybones on February 29, 2012, 11:12:58 PM
i was given safemode option.  still in sm w/ networking. 

anything else i can do while i'm in here?
Title: Re: redirect/browser hijack
Post by: essexboy on March 01, 2012, 09:12:24 PM
Did TDSSKiller find anything ? as the report is not complete

Now reboot from the Windows Vista Recovery Environment CD and execute the following commands:
 
Title: Re: redirect/browser hijack
Post by: monkeybones on March 04, 2012, 08:06:33 AM
what do i select to get to that point?
Title: Re: redirect/browser hijack
Post by: monkeybones on March 04, 2012, 08:34:00 AM
with tss i mean.  what i posted is everything it saved.  the scan ran to completion.


what do i do after the boot commands?  each said "completed successfully"
Title: Re: redirect/browser hijack
Post by: monkeybones on March 04, 2012, 09:09:16 AM
the object found by kaspersky is:

TDSS File System
Physical drive: \Device\Harddisk0\DR0
Suspicious object, medium risk


my options are:
skip
copy to quarantine
delete


there is never a "cure" screen
Title: Re: redirect/browser hijack
Post by: true indian on March 04, 2012, 09:32:49 AM
U have to select delete for tdss file system and continue...reboot if asked and attach the tdsskiller log.
Title: Re: redirect/browser hijack
Post by: monkeybones on March 04, 2012, 11:19:07 AM
can't upload log. get error "Your file is too large. The maximum attachment size allowed is 200 KB.
"
Title: Re: redirect/browser hijack
Post by: monkeybones on March 04, 2012, 11:44:59 AM
log attempt
Title: Re: redirect/browser hijack
Post by: essexboy on March 04, 2012, 12:21:36 PM
Just post the bottom section of the log please

The last 20 lines or so
Title: Re: redirect/browser hijack
Post by: monkeybones on March 04, 2012, 12:43:09 PM
i was able to post the whole thing.  it's in the post preceding yours.
Title: Re: redirect/browser hijack
Post by: essexboy on March 04, 2012, 12:49:48 PM
Can you now access normal windows ?
Title: Re: redirect/browser hijack
Post by: monkeybones on March 05, 2012, 12:04:56 AM
no.  it doesn't stay on.
Title: Re: redirect/browser hijack
Post by: monkeybones on March 05, 2012, 03:28:16 AM
what does it look like to you?  can you tell me more about what it is i'm trying to do? 

is there anything i can be doing in between communication that would be helpful?
Title: Re: redirect/browser hijack
Post by: essexboy on March 05, 2012, 09:25:43 PM
From safe mode we will use SFC to check out the system file structure

Go start > All Programs > Accessories
Right click command prompt and select run as administrator
In the black box type :

sfc /scannow

Then press enter
Let me know if it repairs any files

Also are there any dump files in c:\Windows\minidumps
Title: Re: redirect/browser hijack
Post by: monkeybones on March 06, 2012, 08:04:42 AM
the scan is running.

there are no files in minidump
Title: Re: redirect/browser hijack
Post by: monkeybones on March 06, 2012, 08:35:01 AM
Microsoft Windows [Version 6.0.6002]
Copyright (c) 2006 Microsoft Corporation.  All rights reserved.

C:\Users\Alexandra>sfc/scannow

Beginning system scan.  This process will take some time.

Beginning verification phase of system scan.
Verification 100% complete.
Windows Resource Protection found corrupt files but was unable to fix some of th
em.
Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example
C:\Windows\Logs\CBS\CBS.log

C:\Users\Alexandra>
Title: Re: redirect/browser hijack
Post by: essexboy on March 06, 2012, 09:09:00 PM
Could you zip the CBS log and upload to mediafire and post the sharing link
Title: Re: redirect/browser hijack
Post by: monkeybones on March 07, 2012, 10:41:37 PM
i'm sorry, i don't know how to do that on her computer. 

can i post it here in parts for you, or would that be prohibitive?  save it in separate text files perhaps, in successive posts?
Title: Re: redirect/browser hijack
Post by: essexboy on March 07, 2012, 11:05:18 PM
Could you scan the log and look for files that it was unable to repair.  Then let me know what they were 

Title: Re: redirect/browser hijack
Post by: monkeybones on March 07, 2012, 11:14:14 PM
got it... just had to restart a few times until networking would connect :)

http://www.mediafire.com/?n231yub28nsxja5
Title: Re: redirect/browser hijack
Post by: essexboy on March 07, 2012, 11:46:25 PM
OK got it - it will take a while to interpret though
Title: Re: redirect/browser hijack
Post by: monkeybones on March 08, 2012, 03:43:34 AM
thank you for your time and help. 
Title: Re: redirect/browser hijack
Post by: essexboy on March 08, 2012, 09:37:05 PM
The only file it had problems with is an ini file which is of no consequence

Could you try a startup repair from the Vista CD to see if that can progress any further than the one on the hard drive
Title: Re: redirect/browser hijack
Post by: monkeybones on March 09, 2012, 12:54:33 AM
yes, i will... and then what?  will it also create a log?
Title: Re: redirect/browser hijack
Post by: essexboy on March 09, 2012, 09:19:33 PM
If that does not complete a repair could you set the computer not to auto restart on failure. 

This will give a blue screen with data on the driver/file that is failing

Details here

http://pcsupport.about.com/od/windowsvista/ht/arestartvista.htm

Then try normal mode and let me know what is written on the blue screen
Title: Re: redirect/browser hijack
Post by: monkeybones on March 13, 2012, 06:06:01 AM
no repair was made from disc

i have followed the directions to prevent automatic restart, but the selection is not holding between shut down and restart.  i have already made multiple attempts.

i will keep trying until i hear back from you
Title: Re: redirect/browser hijack
Post by: essexboy on March 13, 2012, 12:02:51 PM
I feel it may be time to consider resetting the system
Title: Re: redirect/browser hijack
Post by: monkeybones on March 13, 2012, 11:05:05 PM
what would cause it to do this?
Title: Re: redirect/browser hijack
Post by: polonus on March 13, 2012, 11:29:50 PM
Hi monkeybones,

This should be essexboy's decide, but at the end of the day when no more options open to you without being able to boot, then you could consider to backup all your data and then reinstall, see:
http://www.howtogeek.com/howto/windows-vista/use-ubuntu-live-cd-to-backup-files-from-your-dead-windows-computer/

polonus

Title: Re: redirect/browser hijack
Post by: essexboy on March 13, 2012, 11:39:37 PM
It could one of any of a number of problems a corruption of a system file, missing data from a service registry key.  This is the sort of problem that you could spend months chasing.  But at some stage you must cut your losses and bite the bullet
Title: Re: redirect/browser hijack
Post by: monkeybones on June 08, 2012, 08:11:49 AM
how do we do that.