63.219.181.7 help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gandhixmas, Dec 9, 2004.

  1. gandhixmas

    gandhixmas Private E-2

    ive got problems with this, can anyone here give some help?

    thanks
    gandhi.
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I have problems too, can you help me? ;)

    Seriously, what problems are you having? The DNS goes back to BeyondTheNetwork, which is one of our file servers.
     
  3. PhilliePhan

    PhilliePhan Guest

    Hi Gandhi,

    I assume you are referring to this baddie: O15 - Trusted Zone: http://*.63.219.181.7

    Generally, it is a good idea to start with the Cleanup Tutorial HERE:
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    This will remove a lot of stuff that would otherwise clog a HJT log and make things easier when we go after the Trusted Zone Hijacker.

    Please let us know the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it - you didn't give OS) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Somebody will take a look when they get a chance.

    Best luck :)
    PP
     
  4. gandhixmas

    gandhixmas Private E-2

    thanks for responding. im getting pop ups and whatever this thing is is hijacking my favorites. the popups are about playing poker with naked ladies and hhow i need spyware removal and such. in my favorites it is leaving things like, viagra, phentermine, work at home. ive been reading posts and it sounds like others are having similiar problems.
     

    Attached Files:

  5. PhilliePhan

    PhilliePhan Guest

    BEFORE you do anything else, you MUST Extract HijackThis from the ZIP File to its own safe folder ---> C:\Program Files\HijackThis

    Then, please download this tool: REM.ZIP

    Please do this and then attach a fresh HJT Log. It's 2:30AM my time, so I have to check back tomorrow.

    PP :)
     
  6. gandhixmas

    gandhixmas Private E-2

    OK, Hijack this is extracted into its own folder. I have downloaded REM.ZIP. HEre is a new HJT log. Thnak you for taking the time to help with this amazingly annnoying problem!

    gandhi
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We prefer that HJT be properly located as Phillie suggested in c:\Program Files\HJT
    Not in: C:\Documents and Settings\Justin\My Documents\hijack this\hijackthis\HijackThis.exe
    HijackThis is a program. Not a document and not a setting. It should be located where it can be properly run from any login and where it can safely save backups.


    Now extract the two files from the REM.Zip file PP had you download. The files are rem.bat and zip.exe. You must extract them to the C:\Windows\System32 folder.

    NOW:
    Boot into Safe Mode and double click the rem.bat file to run it.

    Then, while still in Safe Mode, scan with HijackThis and save the log.

    Next, Reboot to Normal Windows, scan with HJT again and save that log.

    Please attach those logs. Label them Safe & Normal.

    THEN:
    Look in Local Disk C: and find log.txt. Open it and copy and paste the contents into your post.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way these three processes should be ended using Task Manager:
    rdshost32.exe
    pxhping.exe
    mqbckup.exe

    And the lines below should also be fixed with HJT:
    R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://fastsearchweb.com/srh.php?q=%s
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab

    Boot in safe mode and delete:
    C:\WINDOWS\system32\rdshost32.exe
    C:\WINDOWS\system32\pxhping.exe
    C:\WINDOWS\system32\mqbckup.exe
     
  9. gandhixmas

    gandhixmas Private E-2

    Thank you. Thank You. Thank You.

    You Guys are rock-n-roll.

    I did what you said, and my problems are gone. You are the force of light in this horribly cynical universe of high tech.

    Thank You. PP and clang.

    Im not posting the follow up logs because everything seems to work great. no more "favorite" hijacks, no more lame pop-ups ..etc..

    i will post them if it will help you out, or if you think im too confident in the results of your fix.


    but in any event....

    thank you. thank you. thank you. im in eternal debt and look forward to learning more about PCs.

    gandhi
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy we could help! Post a final HJT log just as a precaution.
     
  11. PhilliePhan

    PhilliePhan Guest

    Happy to help :)

    I do agree with Clang, though. A new HJT log would be a good idea as REM.Zip flushes out some baddies along with the fix.

    PP
     
  12. gandhixmas

    gandhixmas Private E-2

    sorry it took so long to get this to you. here is my log.txt

    Microsoft Windows XP [Version 5.1.2600]
    C:\WINDOWS\SYSTEM32
    "Files found"
    ---------------------------------------------------------------------
    clfmon.exe
    dllhostxp.exe
    winsrv32.dll
    d3dxov.dll
    msacmx.dll
    hdr.dll

    Zipping files............
    ---------------------------------------------------------

    deleting files........
    ---------------------------------------------------------

    "Files Not Deleted"
    ---------------------------------------------------------------------

    Checking for version 2 files..........
    Files Found
    ------------------------------------------------------------

    Zipping files............
    ---------------------------------------------------------

    deleting files........
    ---------------------------------------------------------

    Files Not deleted
    ------------------------------------------------------------

    Merging registry entries
    -----------------------------------------------------------------
    The Registry Entries Found...
    -----------------------------------------------------------------

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ms4Hd]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ms4Hd\Files]
    "service.exe"=""
    "msacmx.dll"=""
    "d3dxov.dll"=""
    "winsrv32.dll"=""
    "ie4unit.exe"=""
    "ipxroutex.exe"=""
    "rdshost32.exe"=""
    "rshe.exe"=""
    "net2.exe"=""
    "mqsvch.exe"=""
    "dllhostxp.exe"=""
    "extrac16.exe"=""
    "mqbckup.exe"=""
    "pxhping.exe"=""
    "rdpnr.exe"=""
    "slservc.exe"=""
    "clfmon.exe"=""
    "hdr.dll"=""

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ms4Hd\Processes]
    "ie4unit.exe"=""
    "ipxroutex.exe"=""
    "service.exe"=""
    "rdshost32.exe"=""
    "rshe.exe"=""
    "net2.exe"=""
    "mqsvch.exe"=""
    "dllhostxp.exe"=""
    "extrac16.exe"=""
    "mqbckup.exe"=""
    "pxhping.exe"=""
    "rdpnr.exe"=""
    "slservc.exe"=""
    "clfmon.exe"=""

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ms4Hd\RegKeys]
    "{98DBBF16-CA43-4c33-BE80-99E6694468A4}"=""
    "{A5366673-E8CA-11D3-9CD9-0090271D075B}"=""
    "Files"=""
    "Ms4Hd"=""
    "Processes"=""
    "RegKeys"=""
    "RegValues"=""
    "Vendor"=""

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ms4Hd\RegValues]
    "clfmon.exe"=""
    "dllhostxp.exe"=""
    "pxhping.exe"=""
    "service.exe"=""

    -----------------------------------------------------------------

    Done
     
  13. PhilliePhan

    PhilliePhan Guest

    Hi Gandhixmas,

    Please post a fresh HijackThis Log. Sometimes remnants are left from the REM.Zip process. Note that there is a new version of HijackThis and you should use it in the future, but also keep v1.98.0.2 on hand because this particular baddie that you removed crashes the new version.

    PP :)
     
  14. gandhixmas

    gandhixmas Private E-2

    Ok here is an attachment of a new hijack this log in normal mode. I am having a hard time figuring out how to cut and paste the contents into this reply box. Again, im an amateur at this for sure.

    Anyway, everything is working good as far as i know, except that my windows media viewer literally "flys off" the screen when it is maximized. I think i noticed this happeneing after i downloaded widows security pack 2, but i really do not know. IS this a spyware issue? what happens is i open windows media player and in opens itself in a domain beyong the reach of the monitor. as i click on the toll WMp icon as tool bar it shows the player fly off the screen toward the upper right hand corner, off into nowhere land.
     

    Attached Files:

  15. PhilliePhan

    PhilliePhan Guest

    Looks like you got everything associated with the Trusted Zone Hijacker. You could clean these remainders:

    O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
    O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) -
    O16 - DPF: {D27CDB70-AE6D-11cf-96B8-444553540000} (Macromedia Flash Factory Object) -

    Regarding WMP, I don't know off the top of my head. Perhaps post a thread in Software Forum?

    Sorry rushed - Dinner is burning !:rolleyes:

    PP :)
     
  16. gandhixmas

    gandhixmas Private E-2

    Thanks again PP, you have been invaluable.

    gandhi
     
  17. PhilliePhan

    PhilliePhan Guest

    You're welcome :) Hope the Software thread proves fruitful!

    PP
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds