desktop and homepage hijack

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by svenwenna, Jul 24, 2005.

  1. svenwenna

    svenwenna Private E-2

    Hi,

    Have read "Read me first etc." thread, see below for details.

    Have problem with a desktop hijack which has replaced desktop with message "You are visiting illegal porn sites etc. Followed by click here to remove thie threat. The link leads to http://www.cleanprivacy.info/?adv=164&sub=dc1. This has also hijacked my homepage (which can't be reset) Occasionally a system box comes up that says "Warning your computer is full of evidence Click yes to clean your PC now" This also links to the site mentioned above. Also on every IE window there appears a red band at the top and bottom which say "Your personal data successfully tracked Click here to clean all tracks now" with same link. Occasionally i get a box come up with "Runtime error 229 at 004113d6" I don't know if this is related but started at the same time.

    I have read and followed instructions in "Read me first etc." thread. I was unable to run bitdefender and Ravantivirus in safe mode as I couldn't connect to the internet. They were run in normal mode. Some things were detected and removed but the problem remains.

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below exactly as written:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. svenwenna

    svenwenna Private E-2

    Log file attached as requested.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to WindowInstallSystem (or look for 8f3f44bc46bsvr) Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    WindowInstallSystem


    If that does not work, look for: 8f3f44bc46bsvr

    After doing the above exit HJT this and if told that you need to reboot to complete the process, do not reboot yet. We will restart HJT to use different options in a few lines.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe
    O4 - HKCU\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O23 - Service: WindowInstallSystem (8f3f44bc46bsvr) - Unknown owner - C:\WINDOWS\8f3f44bc46b.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\8f3f44bc46b.exe
    C:\WINDOWS\8f3f44bc46b.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. svenwenna

    svenwenna Private E-2

    Neither Windowinstallsystem or 8f3f44bc46bsvr show up in services.msc, so I coudn't perform this step.

    I tried the next step and when entering "WindowinstallSystem" got this reply : "Service WindowinstallSystem was not found in the registry. Make sure you entered the short name of the service., vbExclamation"

    I then entered "8f3f44bc46bsvr" as suggested and got this message : "The service "8f3f44bc46bsvr" is enabled and/or running. Disable it first using Hijackthis itself (from the scan results) or the services.msc window"

    I followed the rest of the instructions anyway.but when i rebooted in safe mode I couldn't find the ""8f3f44bc46bsvr" files in system32 and windows folders.

    I have attached another Hijackthis log.

    thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to go back and look for the service and the file related to it again. It is running on your PC and the file does exist. Make sure you have enable viewing of hidden and system files. The below items need to be fixed.


    O4 - HKLM\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe
    O4 - HKCU\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe
    O23 - Service: WindowInstallSystem (8f3f44bc46bsvr) - Unknown owner - C:\WINDOWS\8f3f44bc46b.exe


    Repeat the steps related to them from my last post. You must find the WindowInstallSystem (8f3f44bc46bsvr) service running and stop it and disable it. Then delete it with HJT. If necessary go thru all listed service slowly until you find it. DO NOT stop or disable anything else unless it matches this service and file name.
     
  7. svenwenna

    svenwenna Private E-2

    Viewing of hidden and systems filed is enabled.

    I have gone through the services one by one even checking the properties for each and I can't find it. I have attached a snagit screenshot of all the services that come up in services.msc
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm that's strange!

    If you look right now while in normal boot mode, do you see the below files (or any with similar strange names)?

    C:\WINDOWS\System32\8f3f44bc46b.exe
    C:\WINDOWS\8f3f44bc46b.exe
     
  9. svenwenna

    svenwenna Private E-2

    No, I can't find those files there. I also did a search of my C drive but they did not show up. Here's a capture of the files in windows and the first few in System32 attached. There is one program with no title in system32.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on these images you did not follow the step # 3 of the Getting Prepared; Steps to be sure your system is ready to be scanned section of the READ ME FIRST. Please go back on follow that step properly and then look for the files again.


    Also not Windows search will not find hidden or system files either with the default settings that it has. You would also have to make changes to its defaults to find files. This is not the same thing as what you are doing in step # 3 of the READ ME. Step 3 applies to Windows Explorer.
     
  11. svenwenna

    svenwenna Private E-2

    I have checked this section thoroughly once again and all steps have been followed, if you are referring to the fact that the file extension types are hidden in the snagit image of windows , that is because I hid them again after I had performed the requested tasks and prior to doing the capture, sorry.

    Anyway I stiil couldn't find the files.

    Have attached windows folder capture with file extensions showing
     

    Attached Files:

  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    svenwenna,

    Chaslang is on vacation for a few days so I will be assisting you from here. First please attach a current HJT log from normal mode. Also let me know what problems your currently experiencing.
     
  13. svenwenna

    svenwenna Private E-2

    Hi

    Still having the same problems described in first post.

    HJT log attached

    Thanks
     

    Attached Files:

  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, I need you to uninstall Microsoft AntiSpyware as it will block parts of my fixes.

    Now, go thru the steps on this sticky thread SpySheriff (aka SpywareNo) Removal

    After you complete the above reboot and procede with the below:

    Download this trial version of Ewido Security Suite

    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:


    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report


    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report along with a fresh HJT log.
     
  15. svenwenna

    svenwenna Private E-2

    Followed all instructions, no problems completing any steps. Problem remains. Have attached 2 reports as requested.
     

    Attached Files:

  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O4 - HKLM\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe
    O4 - HKCU\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe

    O23 - Service: WindowInstallSystem (8f3f44bc46bsvr) - Unknown owner - C:\WINDOWS\8f3f44bc46b.exe

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Click Start > Run > type services.msc and Click OK

    Locate WindowInstallSystem (8f3f44bc46bsvr) and RightClick on it to bring up the Service Properties Window.
    First: Stop the service by clicking the Stop Button.
    Next: Disable it by changing the Startup Type to Disabled and click Apply

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    C:\WINDOWS\8f3f44bc46b.exe

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     
  17. svenwenna

    svenwenna Private E-2

    Followed instructions. WindowInstallSystem does not show up in services.msc
    8f3f44bc46b.exe file is not showing in windows folder. Problem remains. New HJT log attached.
     

    Attached Files:

  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O4 - HKLM\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe
    O4 - HKCU\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe

    O23 - Service: WindowInstallSystem (8f3f44bc46bsvr) - Unknown owner - C:\WINDOWS\8f3f44bc46b.exe

    Again, make sure All Browser Windows are Closed when you Click FIX.

    Click Start > Run > type services.msc and Click OK

    Locate WindowInstallSystem (8f3f44bc46bsvr) and RightClick on it to bring up the Service Properties Window.
    First: Stop the service by clicking the Stop Button.
    Next: Disable it by changing the Startup Type to Disabled and click Apply

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    8f3f44bc46bsvr

    You may be told to reboot at this point. Do not reboot just exit HijackThis and we will be restarting it with different options in a moment.


    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\System32\8f3f44bc46b.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.

    After you complete the above, reboot and attach a fresh HJT log.
     
    Last edited: Aug 8, 2005
  19. svenwenna

    svenwenna Private E-2

    Followed instructions , but when trying to "delete an NT service" following message comes up:

    "The service "8f3f44bc46bsvr" is enabled and/or running. Disable it first using Hijackthis itself (from the scan results) or the services.msc window"

    Have attached another log as requested.
     

    Attached Files:

  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O4 - HKLM\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe
    O4 - HKCU\..\Run: [8f3f44bc46b] C:\WINDOWS\System32\8f3f44bc46b.exe

    O23 - Service: WindowInstallSystem (8f3f44bc46bsvr) - Unknown owner - C:\WINDOWS\8f3f44bc46b.exe

    Again, make sure All Browser Windows are Closed when you Click FIX.

    Click Start > Run > type services.msc and Click OK

    Locate WindowInstallSystem (8f3f44bc46bsvr) and RightClick on it to bring up the Service Properties Window.
    First: Stop the service by clicking the Stop Button.
    Next: Disable it by changing the Startup Type to Disabled and click Apply

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    8f3f44bc46bsvr

    You may be told to reboot at this point. Do not reboot just exit HijackThis and we will be restarting it with different options in a moment.


    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\System32\8f3f44bc46b.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.

    After you complete the above, reboot and attach a fresh HJT log.
     
  21. svenwenna

    svenwenna Private E-2

    The problem is WindowsInstallSystem does not show up in services.msc as you can see in the attached snagit screen shot.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is under the Service that says Windows User Mod...

    Also do the below files exist (can you see them):
    C:\WINDOWS\System32\8f3f44bc46b.exe
    C:\WINDOWS\8f3f44bc46b.exe
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the Registry Search Tool from here:

    http://www.billsway.com/vbspage/vbsfiles/RegSrch.zip

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    8f3f44bc46b

    Press 'OK'

    The search will run for a while then alert you when it is finished.

    Press 'OK' and copy the contents of the WordPad window and post in this thread.
     
  24. svenwenna

    svenwenna Private E-2

    The service is : Windows user mode driver framework - Enables window user mode drivers.Path to executable : C:\WINDOWS\System32\wdfmgr.exe

    I cannot find the files in Windows or system32 folders.

    Regsearch attached
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file killsvc.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the killsvc.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes


    Then boot into safe mode and look for the below files and delete them:
    C:\WINDOWS\System32\8f3f44bc46b.exe
    C:\WINDOWS\8f3f44bc46b.exe

    Now reboot into normal mode and post a new HJT log.
     
  26. svenwenna

    svenwenna Private E-2

    I was able to see and delete the files this time. All main problems now gone, well done and thanks.
    There is one small problem remaining, where there was a message on my desktop there is now a blank white screen which cannot be changed in display settings (Desktop icons are still visible) Any ideas?

    Thanks again
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below:

    Fixing Locked Desktop
    Also you should right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.

    If that does not work go to the below thread and run step # 8:

    SpySheriff (aka SpywareNo) Removal


    Let me know the results.
     
  28. svenwenna

    svenwenna Private E-2

    Yes your first instructions worked. Once again, many thanks
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds