Need help with Browser Hijack Malware

PJinFL

New member
I've been fighting to clean a virus off my wife's Win 7 laptop. We've battled to a standstill, but I believe the enemy is still lurking on the battlefield (the laptop) and I need help to find the ultimate weapon to win this war!

I'm going to put the details of my battles to date here in case this helps someone else identify a similar problem and find a solution quicker that I have.

The Battle

In Internet Explorer 8, I first noticed the malware when I clicked on a link in Google that went to an obviously wrong website, but using (right-click)"Open in new tab" went to the correct webpage. I then looked for Microsoft Security Essentials (MSE) in the systray to run a full scan, but it wasn't there. The malware was apparently disabling MSE and would also kill it immediately every time I tried to run MSE manually from the Start menu.

After some research (on another PC), I booted into Safe Mode and ran SuperAntiSpyware and Malwarebytes. Both were freshly downloaded on another PC and transferred to the infected PC via a USB stick. Neither scanner found anything.

Further research listed some possible suspects and a process to use to kill (even temporarily) the offending item. Running AUTORUNS (from MS Sysinternals), I found a suspicious .DLL in an unusual location. The file, BITSADMINQ.DLL, was located in the C:\Users\...\AppData\Roaming\ folder. The malware was loaded via a registry key in
"HKCU\Software\Microsoft\Windows\CurrentVersion\Run"
I used AUTORUNS to remove it.

Using the information from AUTORUNS, I located the RUNDLL entry using Process Explorer and killed the process. I could then start MSE and I ran a full scan. Still no hits!

To verify this file was indeed malware, I uploaded the .DLL file to VirusTotal. The results were mixed. Only 7 of the 42 scanners run identified the file as malware: Avast 4 and 5, BitDefender, F-Secure, GData and Ikarus. The other scanners were happy with it. Thinking I now had a process that could completely identify and clean the offender, I burned the bootable BitDefender CD (again on another PC), and rebooted the infected PC using this CD. I was running the ISO file dated January 2011, but the CD did not detect my WiFi network connection so it couldn't download the updated signature list. This scan also didn't identify any malware, especially this .DLL file, so this file was still just "suspect".

Since running with the .DLL file renamed didn't appear to cause anything to break, I shredded the file, but I still get the feeling there may be pieces of malware lingering.

The Aftermath
I know it's impossible to prove a negative, but I'd like some way to feel good about this system again. I feel "icky" using that laptop because of my lingering doubts.

Also, I'm concerned the USB stick I used may have gotten infected, so I'm looking for advice to safely verify it is clean.

Suggestions and comments very welcome!
 

My Computer

OS
Win 7 Home Premium 64 bit
Hi PJinFL,

You did a good job of hunting it down. So, to date:

Malwarebytes - no trace
MSE - no trace
VirusTotal - no trace on suspect DLL
Bootable BitDefender - no trace (usually these require the ethernet cable to be plugged in to update)

I'm not sure anything else is going to give you any better results than the 7/42 result from VirusTotal, but one last possibility is to do an online scan using ESET on line scanner.

Your last line of defense to be completely comfortable with your laptop again might be a secure wipe and reinstall. It sounds drastic, but perhaps its the only thing that might give you peace of mind.

Before you consider that, I am going to to request that some of our security experts (Corinne, Jaccee, or Carolyn) here have a look at this.

Hang tight - I have requested some help with this.

Regards,
Golden
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Hi! PJinFL, welcome to 7F :)

I have had good results with SuperAntiSpyware you can use their on-line scanner here if you like.

Concerns with using the product? SAS Online Safe Scan - SUPERAntiSpyware Forums

For USB sticks. Whichever scan you use, check the letter of the Drive that it is occupying, and the scan will only do that Drive.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Gateway DX4831-01e (Mid-Tower Desktop)
OS
Originally Win 7 Hm Prem x64 Ver 6.1.7600 Build 7601-SP1 | Upgraded to Windows 10 December 14, 2019
CPU
Intel i3 530 2.93GHz, 2933MHz 2 Cores 4 Logical Processors
Motherboard
Gateway H57M01 133 megahertz
Memory
6GB of 1,333MHz DDR3 SDRAM
Graphics Card(s)
32MB Intel Graphics Media Accelerator HD IGChip
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Gateway HX2000 20inch TFT active matrix TN
Screen Resolution
1600 x 900 x 59 hertz
Hard Drives
WDC WD10EADS-00M2B0 [HDD] (1000.20 GB) -- drive 0,
HL-DT-ST DVDRAM GH41N [CD-ROM dr]
Four card readers, and Four USB 2.0
PSU
300watts.
Case
Mid-Tower Desktop
Cooling
Stock from Gateway
Keyboard
Natural Ergonomic Keyboard 4000, see Other Info
Mouse
Orig. Gateway wore out now using Insignia USB wired optical
Internet Speed
Vz FIOS 10ms png 57.64Mbps down 65.53Mbps up Speedtest.org
Antivirus
Zamana Anti-logger with Anti-malware, MSE, Windows Firewall,
Browser
IE11.0.9600.19399-Upd ver11.0.135, Firefox 68.0.1 x64
Other Info
System Specs by Belarc.

BIOS: American Megatrends Inc. P01-A0 11/17/2009

Replaced the MS 'Natural' Standard PS/2 Enhanced 101-102 Keyboard with a new Natural Ergonomic Keyboard 4000 on August 1st 2014.

Canon Pixma MG3222 Printer.

Updated to IE11 on 12102015 | Fios Quantum Router g1100

Additional AV: SpywareBlaster, manual Mbam, SAS
@Golden & Anak - Thanks for taking time to read my (rather length) post!

SuperAntiSpyware was one of the first scanners I tried, but it also found nothing, even with the "suspect" .DLL still on the system.

I have run ESET online scanner successfully with nothing found.

I'd really like to avoid the "nuclear option", so I'll probably tell the Better Half to go ahead and use the PC cautiously, but do not click anything on popups! We suspect a scam job listing (she recently was searching jobs in INDEED.COM) was the source of the problem. With so many sites requiring Javascript I'm not sure turning JS completely would be an option, but I am considering switching her browser from IE to Firefox with WOT and Noscript plugins.

I'll probably use one the Kaspersky rescue CD to rescan the laptop and also the USB stick before I plug it in anywhere else. I'll post a follow-up should anything else come up.

Thanks again for the advice!
 

My Computer

OS
Win 7 Home Premium 64 bit
You could give Norton Power Eraser a shot, just use it carefully:

http://security.symantec.com/nbrt/npe.asp?lcid=1033

Because the Norton Power Eraser uses aggressive methods to detect these threats, there is a risk that it can select some legitimate programs for removal. You should use this tool very carefully, and only after you have exhausted other options.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Emsisoft has a free scanner that may work for you.
When your computer is clean again, do yourself a favor and install Sandboxie;)and worry no more about such things.:D
 

My Computer

OS
Win 7 64 premium
Other Info
7 fw, LUA, UAC on high, IE-9 w/ smartscreen on, SANDBOXIE
We suspect a scam job listing (she recently was searching jobs in INDEED.COM) was the source of the problem. With so many sites requiring Javascript I'm not sure turning JS completely would be an option, but I am considering switching her browser from IE to Firefox with WOT and Noscript plugins.
I will have to keep that in mind. I am using INDEED also.

You can check here to Verify Java Version

There has also been recent updates to Adobe.
This one is for Verifying Adobe - Flash Player
................for Adobe - Test Adobe Shockwave Player

There has also been an update to Adobe Air if you are wondering if you really need it see This .

I felt just like the OP. When I went to uninstall Air it did tell me Reader would stop working.
The only reason I keep Air is because the DW likes Reader, and is comfortable with it.

WOT, and QFX Software - Anti-Keylogging Software will work in IE.
Both work in all versions of win7, 32 or 64bit.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Gateway DX4831-01e (Mid-Tower Desktop)
OS
Originally Win 7 Hm Prem x64 Ver 6.1.7600 Build 7601-SP1 | Upgraded to Windows 10 December 14, 2019
CPU
Intel i3 530 2.93GHz, 2933MHz 2 Cores 4 Logical Processors
Motherboard
Gateway H57M01 133 megahertz
Memory
6GB of 1,333MHz DDR3 SDRAM
Graphics Card(s)
32MB Intel Graphics Media Accelerator HD IGChip
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Gateway HX2000 20inch TFT active matrix TN
Screen Resolution
1600 x 900 x 59 hertz
Hard Drives
WDC WD10EADS-00M2B0 [HDD] (1000.20 GB) -- drive 0,
HL-DT-ST DVDRAM GH41N [CD-ROM dr]
Four card readers, and Four USB 2.0
PSU
300watts.
Case
Mid-Tower Desktop
Cooling
Stock from Gateway
Keyboard
Natural Ergonomic Keyboard 4000, see Other Info
Mouse
Orig. Gateway wore out now using Insignia USB wired optical
Internet Speed
Vz FIOS 10ms png 57.64Mbps down 65.53Mbps up Speedtest.org
Antivirus
Zamana Anti-logger with Anti-malware, MSE, Windows Firewall,
Browser
IE11.0.9600.19399-Upd ver11.0.135, Firefox 68.0.1 x64
Other Info
System Specs by Belarc.

BIOS: American Megatrends Inc. P01-A0 11/17/2009

Replaced the MS 'Natural' Standard PS/2 Enhanced 101-102 Keyboard with a new Natural Ergonomic Keyboard 4000 on August 1st 2014.

Canon Pixma MG3222 Printer.

Updated to IE11 on 12102015 | Fios Quantum Router g1100

Additional AV: SpywareBlaster, manual Mbam, SAS

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Hi, PJinFL.

You have most likely eliminated the problem, but I suggest you now run updated Malwarebytes Anti-Malware in normal mode. MBAM does its most thorough findings in normal mode. If anything is detected, please post the log here as a reply.

I also suggest you follow Anak's advice to verify the most current versions of Java and Adobe products are installed on the laptop. There are critical vulnerabilities in older versions of those products.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Back
Top