HomePage Re-directed & UserName Change

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Rich_Lovina, Jun 30, 2005.

  1. Rich_Lovina

    Rich_Lovina Private E-2

    1. Problem just hit in last 24 hours. Main viruses detected were Java_Bytever.A and Java_Bytever.A-1. Also had one called Html_Coolweb.A
    2. Used House Call & PC_Cillin. PCC showed files quarantined but I suspect not as problem tested with my ISP tech support today, as follows:
    Correct web address shows up, but not at the ISP server address, then a repeat pop-up changing my user name to one hijacked from my system.
    System is Win 2000 and am not sure where to disable 'restore programs'.
    3.When IE connected screen "Instafinder.com" appears. I found and removed this directory completely.
    4. Ad Aware also found 10 more, but I suspect a trojan or something more sinister as the past week many programs have started slowing. Usual system maintenance performed.
    Thanks in advance suggested solutions.
     
  2. catbro6166

    catbro6166 Corporal

  3. Rich_Lovina

    Rich_Lovina Private E-2

    Yep, thanks I only read half of it....its a very thorough step-by-step. Already found one main culprit by using AdAware in safe & switching those hidden files. Will revert back after trying all other options.
    Excellent...thanks thus far
     
  4. Rich_Lovina

    Rich_Lovina Private E-2

    Re: HomePage Hijacking....continued

    Okay, did all the things in the READTHIS announcement, got rid of many (c.230 files) with AdAware (safemode) & used all others relevant to Win2k.
    Am preparing back-ups for a re-format, but thought I'd ask:

    Safemode with Networking can't allow connection to ISP? Correct. How to resolve this issue. Tks
     
  5. Rich_Lovina

    Rich_Lovina Private E-2

    Up to HijackThis Logfile...AnyHelp?

    Working through the many useful threads, perhaps someone can interpret my logfile, as attached. Tks in advance. :( Tired of using my laptop as backup.
     

    Attached Files:

  6. Anon-068c403e2d

    Anon-068c403e2d Anonymized

    Re: Up to HijackThis Logfile...AnyHelp?

    You have sais.exe spyware.c:\program files\180solutions\sais.exe
    And your ie start/search pages need to be checked,grockester may be responsibe?
    I have never used HJT so you should wait for bjgarrick or chaslang on how to fix it.
     
  7. Rich_Lovina

    Rich_Lovina Private E-2

    Re: Logfile of Reg. Errors Identified

    Yes, tks mate. Using the tutorial Generic Solution to HSA (Only the Best) & About:Blank hijack , I've identified also:

    At R3 URL SearchHook...; O3 Toolbar (no name)... ; O4 sais....; then O16 DPF to a fizzlewizzle website

    Problem is tutorial states Run "notepad c:\path\xxxx, and as I've not been in here before, am not sure of the correct procedure. Am of course aware that, the .log is the backup.

    Perhaps can get an instruction on just this critical aspect of removing the nastys from the reg. file.
    Apology to Major for seeing the tutorial after attaching my logfile. Tks.
     
  8. Anon-068c403e2d

    Anon-068c403e2d Anonymized

    Re: Logfile of Reg. Errors Identified

    I gave your hjt log to the auto analyse sites in the tutorial and they found the same things,so maybe you should tick the items and click fix.
    The tuts doesnt include 023-win nt services?
     
  9. Rich_Lovina

    Rich_Lovina Private E-2

    Tks further, the tute talked about a generic path to notepad file which confuses a little, as an important step before going into safemode for HJ. Is it safe to go straight to HJ in safemode and run Fixes on the nasty lines. i.e. I can follow the tute on my laptop as I work on the problem PC?
    And then follow all the subsequent software recommendations?
     
  10. Anon-068c403e2d

    Anon-068c403e2d Anonymized

    I think you should stick with MAs tutorial and dont try any safe mode.
     
  11. Rich_Lovina

    Rich_Lovina Private E-2

    Even for an old-timer (in PCs since 1986) one tut re HSA calls for a notepad command before going into safemode to then use HijackThis. CW Shredder did not remove the nasty code.

    Grateful any help.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have an HSA or about:blank hijacker problem so you should not be running the Generic Procedure.

    The was also no reason for you to run HSremove or about:Buster (if you ran it).

    Did you run ALL of the steps in READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If so, look in Add/Remove programs for any of the below and uninstall if found:
    180Solutions or NCase or MSBB.

    Note:
    C:\Program Files\Shareaza\Shareaza.exe <--- this should not be running when using HJT or trying to fix problems. In fact why are you loading this at startup.

    Now continue with the below steps.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R3 - URLSearchHook: (no name) - _{855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O3 - Toolbar: (no name) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - (no file)
    O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
    O16 - DPF: {9076A11F-5EA6-4A67-BDE9-8D3C7C53DAC} - http://www.fizzlewizzle.com/installfiles/powertools.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\program files\180solutions <--- the whole folder

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Jul 2, 2005
  13. Rich_Lovina

    Rich_Lovina Private E-2

    Tks your great reply...back here now.
    1. Was confused with HSA generic procedure c.f. HJT instructions. Tks clarification.
    2. Could not run any live-updates of "Scanning And Cleaning Steps: (These 4 steps are NOT optional and must be run!!)" as blocked from all ISPs on the problem PC, so Step 4, online updates not possible. This laptop I am communicating on is virtually clean. Hence took latest software across from laptop downloads to problem PC for running.
    3. Did Add/Remove steps & Shareaza problems. Shareaza has entered from a download, thought I had removed it.
    4. There's no 180solutions (or the 2 others) directory/files on system. I removed shareaza.exe completely, incl. from recycle bin.
    5. Followed all steps and attached is new logfile.
    6. Have not re-connected that PC to net until I hear further from you.
    Tks in advance.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have Shareaza and I did not notice that you had Grokster last time. If these are not paid versions, you should uninstall both of them. The free versions contain malware. P2P programs are in general problematic and open the doors to getting all kinds of bad stuff installed onto your PCs.

    Notice the below lines in your log:

    O4 - HKLM\..\Run: [Grokster] C:\PROGRA~1\Grokster\Grokster.exe /SYSTRAY
    O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray

    After uninstalling these should be gone. If not, have HJT fix those entries then reboot into safe mode and delete the C:\Program Files\Shareaza and C:\Program Files\Grokster folders.
     
  15. Rich_Lovina

    Rich_Lovina Private E-2

    Thanks greatly, sure made a difference, esp general sys ops speed. Doing those final removes as suggested. Also now on that PC, 1st thing was c.37.5 Mb MS critical updates. Reckon the viruses cut out that working too!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well if you are all cleaned up now. My next message was for you to do the steps in:

    How to Protect yourself from malware!

    The first step there is Windows Update, so you have already started.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds