Wondering about my HJT log...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JoDark, Dec 18, 2005.

  1. JoDark

    JoDark Private E-2

    Hey guys, I think I was able to get rid of this nasty "oaind.com" or whatever it's called spyware last night (with thanks to your forums). I finished with getting a HJT log and felt I should post it...just to be sure. Because I just KNOW Im going to get another one of those pop ups (non yet, but give it time :() I'll also post my log from Spy Sweeper. Thanks guys
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spy Sweeper found some rootkits. Let's do a double check. Download Blacklight to its own folder...

    F-Secure Blacklight

    After download is complete, double click to run the program. Click "Accept" to procede. Then click SCAN to begin scanning your system.

    Once the scan is complete it will attempt to clean the found infections. There should be a log in the folder that you ran the program from, attach this log to your next post along with a new scan from Spy Sweeper too.
     
  3. JoDark

    JoDark Private E-2

    OK thanks! All done, here ya go :)

    Oh and ya know, it's funny. Ever since I ran spysweeper the first time yesterday, I havn't gotten any of those popups. And as SOON as I thought that, I got one. This is by far the worst spyware I've ever had. Usually I was able to manually get rid of it. Not this time :(
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before we continue, you first you need to properly install HJT per the directions in:

    Downloading, Installing, and Running HijackThis


    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\??crosoft.NET\explorer.exe
    C:\Program Files\lerh\pcrc.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {03BC7734-076F-9AF6-B10F-9CA72B458600} - C:\WINDOWS\edcaslao.dll
    O2 - BHO: (no name) - {502A47B1-D674-A9A9-7EF5-D0F8FB96CD9E} - C:\WINDOWS\System32\gdwirna.dll
    O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
    O3 - Toolbar: Search - {926B1042-C7C0-8A6B-C70C-A3291E8B1540} - C:\WINDOWS\edcaslao.dll
    O4 - HKLM\..\Run: [Windows Media Player] wmediaplayer.exe
    O4 - HKLM\..\RunServices: [Microsoft QMGR] msnqmgr.exe
    O4 - HKLM\..\RunServices: [CMD] cmd32.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] wmediaplayer.exe
    O4 - HKCU\..\Run: [Coti] C:\WINDOWS\System32\??crosoft.NET\explorer.exe
    O4 - HKCU\..\Run: [Hwto] "C:\Program Files\lerh\pcrc.exe" -vt ndrv
    O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to d
    elete:
    C:\WINDOWS\edcaslao.dll
    C:\WINDOWS\System32\gdwirna.dll
    C:\WINDOWS\System32\wmediaplayer.exe
    C:\WINDOWS\System32\msnqmgr.exe
    C:\WINDOWS\System32\cmd32.exe
    C:\WINDOWS\System32\??crosoft.NET\explorer.exe
    C:\Program Files\lerh <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Dec 18, 2005
  5. JoDark

    JoDark Private E-2

    Alright I did everything...pretty much.

    When I rebooted in safe mode and used Windows Explorer to delete these files:

    C:\WINDOWS\edcaslao.dll
    C:\WINDOWS\System32\gdwirna.dll
    C:\WINDOWS\System32\wmediaplayer.exe
    C:\WINDOWS\System32\msnqmgr.exe
    C:\WINDOWS\System32\cmd32.exe
    C:\WINDOWS\System32\??crosoft.NET\explorer.exe
    C:\Program Files\lerh <--- the whole folder

    I couldn't because I could not find them ANYWHERE. Is that weird? I even did Searches. HOWEVER, I was able to delete:

    C:\Program Files\lerh <--- the whole folder

    But the others were no where to be found. I rebooted into Normal mode and ran HJT, here's its log. I'd tell you how things are running, but I cant be for sure yet since I dont know when I'll experience the popups. Thanks again...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Well one new item showed up and you either missed a few items last time when fixing lines with HJT or they came back. If they came back, then it would have to be that the files you said you could not find are still there and they must be hidden. Make sure you enabled viewing of hidden and system files per the READ & RUN ME.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Windows Shell Command] loadsh.exe
    O4 - HKLM\..\Run: [Microsoft QMGR] msnqmgr.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] wmediaplayer.exe
    O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\loadsh.exe
    C:\WINDOWS\System32\wmediaplayer.exe
    C:\WINDOWS\System32\msnqmgr.exe

    If not found in the c:\windows\system32 folder look in c:\windows

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Note to use Windows Search, you must also set appropriate options to locate hidden and system files. See this: Searching for Hidden Files on WinXP
     
  7. JoDark

    JoDark Private E-2

    Alrighty I did all that and once again I couldnt find those 3 files you mentioned. I guess that's a good thing then, since they're no where to be found :D (I even made sure I was searching for hidden files/folders). I havn't had a pop up yet in a whole day! That means it's gone, since I'd usually get 32489324 a day :p Anyway, here's my HJT log just in case. I really appreciate this once again guys. Great job with the site and happy holidays :D
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well the appear to be gone but I'm not sure since now I see for some reason you started using:
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    Why? What are you stopping from loading with it?
     
  9. JoDark

    JoDark Private E-2

    I don't even know if that was intentional. Should I go ahead and repeat the process?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not run by itself! Click Start, Run and enter msconfig and click OK! Then select Normal Startup and then exit msconfig and reboot your PC into normal mode. Now get a new HJT log and attach it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds