Bowser Hijacked and Win Min Shutdown error

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jrpadar, Aug 23, 2004.

  1. jrpadar

    jrpadar Private E-2

    My browser has been "permanently" hijacked and I get the Win Min error at every shutdown. I am running Windows XP-Service Pack 2 (SP2 installed after the hijack)

    I have followed each step of your two excellent guides, "Basic Spyware..." and "Hijack This..." to no avail. I think it is probably time to submit a Hijack This log with your permission.

    Please advise...

    Jim Padar
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Jim,
    What Hijack do you have? Make sure system restore is disabled before scanning, as your Hijack may be saved in a restore point. Check Add\Remove programs as well. Did you try Chaslangs tutorial on removing the Home Search assistant?

    http://forums.majorgeeks.com/showthread.php?t=38772

    Let us know!
     
  3. jrpadar

    jrpadar Private E-2

    Re: Browser Hijacked and Win Min Shutdown error

    To tell you the truth, I have no idea what Hijack I have.

    I did disable system restore before scanning and I did the scanning in Safe Mode. CWShredder and Kill2me reported that my system was clean. Spybot comes up with "DSO Exploit" which I understand is a Spybot bug and also an (working from memory here) "ATAEvent" entry. Adaware identified some "data miner" cookies and the VX2 plug-in did not find anything.

    My hijacked browser goes to any one of three sites:

    http://youriskalka.com/index.htm

    http://www.iknndvlcjlupvjawde.com/GN_kjaeEjuI6E0eQ_WRUm31rJxnrBmlMJK3yBzn8GuY.html

    http://www.mokckhlelyzhokhvvyvskdhq...9Z/h_MiDlQhqSBjRYZH_dFSYJrMlANrQAcd2bG07v.cgi

    I looked at the Chaslang link. His procedure is certainly more comprehensive than the previous two procedures. I never disconnected from the internet during the other exercises. I looked over his sample Hijack This log and I do not seem to detect any of the patterns that he references when I compare it to my log.

    Is there any way to determine what hijack I have?
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Re: Browser Hijacked and Win Min Shutdown error

    Chaslang is the man in this. I know my way around, but not to his extent. Hopefully he will check in on this one. A wild guess would be that at least one of your links goes to a search page. Chaslang's tutorial is pretty specific to the Home Search Assistant, but I would try it as a next step.

    Either way, your doing a great job so far, you have even recognized the spybot DSO exploit as a bug.
     
  5. jrpadar

    jrpadar Private E-2

    You are correct... the youriskalka.com link is a search page.

    Also, upon closer inspection, the Hijack This log shows one entry that matches chaslang's pattern. It's an 04 entry that runs a file called eulalog.exe.
    The only reference I can find on the interent to this file is at

    http://www.annoyances.org/exec/forum/win2000/1089386993

    which is also regarding a hijack problem.

    It will probably be Thursday before I can get back to the infected machine (my brother-in-law's). Meantime he'll have to tough it out.

    I'll post my results when I complete chaslang's HSA procedure. Thanks for your suggestions.

    Jim Padar
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If still having Win Min problems, try the following:

    Even if you did this already do it again.

    - First make sure you have CWShredder Version 1.59.1
    - Close all browser windows, UnZip the file, click on the cwshredder.exe then click "Fix" (Not "Scan only") Let me know if it finds anything!
    - As soon as it completes reboot your computer.

    - Make sure you have the following patches from Microsoft to avoid the vulnerabilities that this hijacker exploits:

    http://www.microsoft.com/technet/tr...in/ms03-011.asp

    http://www.microsoft.com/technet/tr...in/MS00-075.asp


    I'm not sure if those two patches are going to really do anything right now since you said you put int SP2. But I also wonder whether SP2 gets installed correctly in the hijack was already in place before putting in SP2.

    The best way to make sure you have all the security patches is to go to Windows update and install all "Critical Updates" (now the are being called High Priority updates).

    After this, if still having a problem, post a hijack this log (as an attachment) and we will look at it.
    You may have some lines similar to the below which are problems:

    A process running called winlgn.exe. Like:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlgn.exe

    Be careful, with spelling winlogon.exe is legitimate

    Lines like the below in HJT:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://youriskalka.com/sp.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://youriskalka.com/index.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://youriskalka.com/index.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://youriskalka.com/sp.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://youriskalka.com/index.htm
    O4 - Global Startup: winlgn.exe
     
  7. jrpadar

    jrpadar Private E-2

    SUCCESS REPORT!

    Voila! I am clean!

    First of all let me thank you for the time and effort that went into your carefully prepared instructions. It is deeply appreciated.

    To wrap things up, I found the following malware running on my machine via the HJT log:

    Acid Flap.exe
    eulalog.exe
    winlgn.exe

    Also found several R0 and R1 entries that pointed to unfamiliar sites.

    Interestingly, I only found one BHO:

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    I elected to “fix” it with HJT, no harm done.

    I also noted that Acid Flap was at the top of my prefetch directory... I didn’t take the time to search for the others, I just deleted all the prefetch files.

    Several runs of Ccleaner failed to find anything.

    The Microsoft update site tells me that my XP Service Pack 2 is the latest, no further updates are available.

    I think that the above reasonably outlines what worked for me... hardly seems like 10-12 hours of effort does it? Never-the-less, none of it would have come about without your expert help! Thanks again.

    Jim Padar
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The BHO you fix is for SpyBot S&D you should restore that from your HijackThis Backups (automatically made). You should not just delete (fix) lines in HijackThis unless you really know what you are doing. You can really break things since you are modifying your registry.

    Ccleaner does not find things. It cleans temporary folders (automatically when you click clean) and can be used to show a variety of items in the resgistry. That you can choose to fix.

    And.... you're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds