about:blank->http://www.updatesearches.com/ + AntivirusGold=Virus+desktop warnings+

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jornsen, Jun 6, 2005.

  1. Jornsen

    Jornsen Private E-2

    ...you name it, I've got it... :) :eek:

    Hi

    I have an about:blank hijack that redirects me to http://www.updatesearches.com/, obscene security warnings on desktop, suddently a new desktop.ini file on my desktop.
    I also suddently had AntivirusGold installed, uninstalled it and it reappeared, uninstalled and expect to see it again soon...

    I followed the instructions in the "DO NOT POST UNTIL YOU HAVE READ THIS: How to: Spyware, Trojan And Virus Removal" thread. This and manual action caused a - regretably poorly undocumented - number of programs, viruses and other stuff to be removed. But I didn't get rid of the about:blank hijack and desktop warnings, and as I said: I expect to see more of AntivirusGold.

    The most interesting - and best documented - of the scan runs was the Trend Housecall. It found 4 trojans:
    troj.small.ahz in c:/documents and settings/jojo/Local Settings/tmp/hmbp.exe
    troj.super.m in c:/documents and settings/jojo/Local Settings/tmp/tmp.frA9E3
    troj.small.ahz in c:/documents and settings/temporary internet files/Content.IE5/6PVV7M9Q1/dd[1].exe
    troj.small.ahz in c:/winnt/system32/hookdump.exe

    First and second were in use (althoug I deleted second manually!?) and couldn't be removed by the program, the others were removed OK by the program (although I didn't have the path: c:/documents and settings/temporary internet files/Content.IE5 !!!!????)
    When I looked manually for the first after restart in manual mode, my normal virusscanner found "Spyre" in it and Deleted it - may be back after next reboot.. ;)

    msconfig has the fourth in startup now. There may be other strange stuff in msconfig:startup.

    During clean in safe mode I had process csrss.exe running from time to time - could have been approx. every time AntivirusGold was "warning" about infections... (I know - I am shooting at every moving target)

    ehm.. help!!??

    I'm ready for upload of system config. doc and hijackthis log, and of course for answering questions.

    Thanks in advance
    /Jornsen
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using msconfig to disable anything from loading at startup, run msconfig and select Normal Startup. Then reboot and continue with the below.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. decimal

    decimal Private E-2

    hi there, i have the same problems :eek: , followed the sticky threads steps, and have downloaded and run all the applicable spyware programs except hijack this....
    can you be of any assistance to me? thanks a heap
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thread hijacking is considered to be just as bad as the hijacker on your PC. Please post in your own thread.
     
  5. decimal

    decimal Private E-2

    sorry bout that...geuss thats why im only a private e-2 :eek:
     
  6. Jornsen

    Jornsen Private E-2

    Hi

    Sorry about my response time - a lot of work...

    Here is my hijackthis log.

    Thx
    /jornsen
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of DAP are you using? Older version contained malware.

    Look in Add/Remove programs for AntivirusGold and uninstall if found.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Open Control Panel and select Add/Remove Programs look for the below programs and uninstall them if found:
    Search Maid
    Security IGuard
    Virtual Maid

    Now exit Add/Remove Programs.

    NOTE: Some of the items mentioned in the below steps may or may not be there. If not found just ignore them and continue. These problems come in a variety of forms and different filenames can be used each time.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINNT\system32\cmd.exe
    C:\WINNT\popuper.exe
    C:\WINNT\system32\intmonp.exe
    C:\WINNT\System32\msole32.exe
    C:\WINNT\system32\shnlog.exe
    C:\WINNT\system32\intmon.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesearches.com/search.php?qq=%1
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.updatesearches.com/bar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.updatesearches.com/search.php?qq=%1
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.updatesearches.com/search.php?qq=%1
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.updatesearches.com/search.php?qq=%1
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.updatesearches.com/search.php?qq=%1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.updatesearches.com/
    F2 - REG:system.ini: Shell=explorer.exe, msmsgs.exe
    O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINNT\System32\hp57EF.tmp
    O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
    I do not like the looks of this next line. Do you know what it is? If not then fix it!
    O4 - HKLM\..\Run: [After] c:\MNet\after.vbs
    O4 - HKLM\..\Run: [RegSvr32] C:\WINNT\System32\msmsgs.exe
    O4 - HKLM\..\Run: [AntivirusGold] C:\Program Files\AntivirusGold\AntivirusGold.exe /h
    O4 - HKCU\..\Run: [Intel system tool] C:\WINNT\System32\hookdump.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\svcproc.exe
    C:\WINDOWS\system32\msmsgs.exe
    C:\WINDOWS\system32\shnlog.exe
    C:\WINDOWS\system32\intmonp.exe
    C:\WINDOWS\System32\intmon.exe
    C:\Windows\System32\helper.exe
    C:\Windows\System32\ole32vbs.exe
    C:\Windows\system32\msole32.exe
    C:\WINNT\System32\hp57EF.tmp
    C:\wp.exe
    C:\wp.bmp
    C:\bsw.exe
    C:\Windows\sites.ini
    C:\Windows\popuper.exe
    C:\Program Files\Search Maid<--- the whole folder
    C:\Program Files\Security IGuard<--- the whole folder
    C:\Program Files\Virtual Maid<--- the whole folder
    C:\Windows\System32\Log Files <--- the whole folder
    C:\Program Files\AntivirusGold <--- the whole folder


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and continue with the below.

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixwp.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixwp.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.
    Now please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    Now post a new HJT log. And tell me how things are working.
     
  8. Jornsen

    Jornsen Private E-2

    Hi
    Sorry again for my response times....

    I have been through your procedure - and I don't really know how I am doing... :)
    I have REAL about:blank as homepage, and no programs and stuff pop'ing up all the time, but still have a nasty warning on my desktop that I don't know how to get rid of...

    I think I will restart the sticky thread procedure when (if) you think my HiJackThis log is OK and I get rid of the desktop warning - just to be sure...
    :)

    Anyway, here is my log.

    btw, my DAP is main module 7.4.0.1 - downloaded a couple of months ago.

    Thanks in advance
    /Jornsen
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what this MREG.EXE program is? There is one floating around to find keys or cracks for software. If that is what this is, you should not be using it.
    c:\winnt\system32\MREG.EXE


    Why are the below items running? There is no reason for a command prompt or Winword to be running. And all browsers MUST be closed before using HijackThis.
    C:\WINNT\system32\cmd.exe
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    What are your remaining problems specifically? If you still have a locked Desktop, try the below:

    Fixing Locked Desktop
    Right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.
     
  10. Jornsen

    Jornsen Private E-2

    Hi

    I'm not sure what my mreg.exe is, but I trust the company it is marked with (and the fact that it is a danish company, makes it unlikeley that the label is false) - I will check it further, though.

    I was running winword because i copied your text to word to avoid staying online. I don't really know about the others, but I might have had several other programs open that I didn't realize were browsers etc. (services.msc etc.)
    Sorry about that.

    Here you have a log from HJT run without other applications open.

    btw, I forgot to tell you that I couldn't kill cmd.exe from HJT - "windows is protecting the process", or something like that. The new posted log has no cmd. I think maybe windows explorer has a "background" command prompt (cmd)? I may have had this open...

    Best regards - and thanks a lot for your help
    /Jornsen
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log is clean now.

    I still see C:\WINNT\system32\cmd.exe running! Something that you are using must need it as a backgroung process. As long you are not having any problems, we will not worry about it.

    So how are things working now.


     
  12. Jornsen

    Jornsen Private E-2

    Hi

    I disabled all my oracle services - that took down cmd.exe as well, so I guess cmd.exe must be OK.

    Everything seems to be OK now. Thanks a lot for your help.

    Best regards
    /Jornsen
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds