cannot get rid of shopnav

Discussion in 'Malware Help (A Specialist Will Reply)' started by le floof, Jan 19, 2005.

  1. le floof

    le floof Private E-2

    Hi there

    Just hoping that someone can help me get rid of this malware called shopnav. I have tried to follow the instructions posted on various websites, however the srng files are not present in my registry. AdwareSE finds the virus as a process in normal mode but cannnot delete it, and then it cannot find it in safemode or start-up. It says that it is located in Windows\System32\??rss.exe.

    I've been having all sorts of issues with my PC. It kept freezing, could only hold down the on off to re boot. Then installed XP sp2, but it found two virus' in Winhlp32.exe and Twain_32.dll so did not complete, got very messy, but think I've managed to reinstall this with a slight scarey problem that I couldn't then open any explorer windows. I disabled a shellex file and explorer now works ok, but I still think that there are lots of dodgy things going on here. Please help!

    Thanks
    le floof
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After checking out what Star gave you, if you still have a problem then proceed with the below.

    I don't believe that C:Windows\System32\??rss.exe is related to ShopNav. And note that filename is not csrss.exe which is valid. There will be a hidden/system file actually named ??rss.exe in your system32 folder.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. le floof

    le floof Private E-2

    Star

    Yeh I found that link but couldn't find any of the files in my registry. I will follow the guidelines from Chaslang, as its been a few months since I have done anything that thorough. Normally I just use Spybot and Adware, and AVG of course. I will post my Hijackthis log after I have finished if that's ok?

    cheers
    le floof
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well as I said, if you still have a problem after the clean up procedure, post your log.
     
  5. le floof

    le floof Private E-2

    Ok did followed all the processes as explained and nothing was found.

    A few strange things happened while I was in safe mode however:
    1. On closing safe mode, message came up saying, Ending Program Sample
    2. I kept losing internet connection in safe mode with networking had to reboot everytime I closed IE.
    3. Couldn't do the online scans at Symantec as it stalled on opening the webpage for the scan.

    Anyway I've attached my Hijackthis log, hope this explains more.

    Thanks
    le Floof
     

    Attached Files:

  6. le floof

    le floof Private E-2

    Just to add

    This is from Adspy; 4 alternative datastreams:
    c:\WINDOWS\River Sumida.bmp : bioqm
    c:\WINDOWS\River Sumida.bmp : sxjko
    c:\WINDOWS\VB.INI : brmbe
    c:\WINDOWS\VB.INI : uaswz

    Not sure if these are bad....?

    Also firefox keeps timing out on websites, a new thing, starting to drive me mad!!! :rolleyes:
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you disabled the built-in firewall of WinXP SP2? If not, you need to do that. You must not use more than one software firewall and you have ZoneAlarm running already. And it is better than the WinXP firewall.

    Do you use this Wanadoo Toolbar stuff? Did you install it? I'm not saying it's bad, I just asking if you require it.
    O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll

    Is this a Dell PC? I wondering what the below service is:
    O23 - Service: dlbt_device - Dell - C:\WINDOWS\System32\dlbtcoms.exe
     
    Last edited: Jan 20, 2005
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this LSP - Fix Don't run it! We may or may not need it.

    You have traces of an HSA/about:blank hijacker in your log. It's possible after fixing some of the problems below that this may show its ugly head.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.

    Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\??rss.exe


    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yofwh.dll/sp.html#29126
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.zpecialoffer.com/results.asp?keyword=%s
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
    O4 - HKLM\..\Run: [HPZEZLEW] c:\windows\system32\hpzezlew.exe /install
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKCU\..\Run: [Qpx] C:\WINDOWS\System32\??rss.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O15 - Trusted IP range: 206.161.125.149
    O15 - Trusted IP range: (HKLM)


    After clicking Fix, exit HJT.


    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\yofwh.dll
    C:\Program Files\NewDotNet <--- the whole folder



    Now reboot in normal mode and post a new HJT log. And tell us how things are working.



    What do you know about this ErrorNuker program?
    O4 - HKLM\..\Run: [Error Nuker] C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
     
  9. le floof

    le floof Private E-2

    My windows firewall was already turned off.
    I'm connected through wanadoo
    And this is a dell pc
     
  10. le floof

    le floof Private E-2

    Ok so the results from the fixes are:

    It couldn't remove the 010 winsock LSP

    I couldn't find c:windows\system32\yofwh.dll

    It would not delete NewDoNet directory

    Also Errornuker is a program that I downloaded to try and fix things but i uninstalled it.

    I've posted my new Hijackthis log

    Cheers
    Le Floof
     

    Attached Files:

  11. le floof

    le floof Private E-2

    Sorry should have answered question better about the wanadoo thing. I don't use t at all, that includes the dell thing, they were both just installed automatically
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of Spybot are you using? What is the detections list version?

    You can get this by running Spybot and the click Help and select About!

    Then with Spybot open and want you to do the below to fix a few problems with certain malware (include new.net) being ignore by default.

    Fixing SpyBot's Ignore Products Bug:
    I want you to run SpyBot and get into the Advanced mode by selecting Mode and then
    Advanced mode. Then select Settings and the in the left column select Ignore Products.
    In the right window pane make sure the All products tab is selected. Then in that
    window, right click your mouse and choose "Deselect all". Now in the left pane click
    at the top on SpyBot S&D and then choose Search for Updates. Download any updates
    required. Now click Check for Problems. Fix any that are found.

    If that does not fix the new.net problem, try it again after booting to safe mode. Let me know what happens.
     
  13. le floof

    le floof Private E-2

    I'm using spybot 1.3.1TX, last udated 6.1.2005, no new updates available.

    After doing what you suggested it got rid of all but 2 of the new.net problems. The remaining 2 cannot be deleted even in start up or safe mode.

    HKEY_USERS\S-1-5-18\Software\New.net
    HKEY_USERS\DEFAULT\Software\New.net

    I have enclosed my new hijackthis file incase this helps catch these little blighters!

    Le Floof
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixnew.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)
    Double-click on the fixnew.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.

    Let me know if that finishes it off or not.
     
  15. le floof

    le floof Private E-2

    That seemed to get it. I ran spybot again and nothing was detected. However there was another problem that occurred. When I went to run Notepad it wouldn't work from clicking on Program files\accessories..... I searched on explorer and I seem to have a few Notepad.exe's. I'm sure that this isn't right, what do you think??

    Thanks
    Le Floof
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These HSA hijackers sometimes delete certain files on your PC. Tell me where you are finding notepad.exe and also tell me the filesize and dates.
     
  17. le floof

    le floof Private E-2

    Here is a screen grab of the search results.

    I have already deleted one file notepad.exe that was in a download folder and i was sure was not genuine. This was dated 04/08/2004 07:56 I think.

    Le Floof
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should rename the file in c:\windows\system32 from notepad.exe.bak to notepad.exe
    See if everything works now.

    If not, you should look at your Accessories shortcut and see where it is pointing to.
     
  19. le floof

    le floof Private E-2

    Still doesn't work.

    The icon for the shortcut which is not the correct one is pointing to:

    @%SystemRoot%\system32\shell3

    And the shortcut itself is pointing to:

    C:\WINDOWS\SYSTEM32\APPEND.EXE
    and works:
    C:\DOCUME~1\user
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So fix them so that the Target and Start in: info are correct.

    Target: %SystemRoot%\system32\notepad.exe

    Start in: %HOMEDRIVE%%HOMEPATH%


    I would be worried that you may have more problems like this.
     
  21. le floof

    le floof Private E-2

    Sorry not sure how to do this.

    I clicked on properties of the shortcut and then the program tab, but where do I input the info?

    Also do you know what has caused this? Is there another Virus still in my computer?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to click Start, All Programs, Accessories and right click the notepad icon and then select the Shortcut tab and enter the info I already gave you in the fields as labeled"

    Target: %SystemRoot%\system32\notepad.exe

    Start in: %HOMEDRIVE%%HOMEPATH%

    I cannot tell where this came from. Yes some piece of malware could have done it to prevent you from using notepad. This happens sometimes with HSA hijackers and some other CWS infections.
     
  23. le floof

    le floof Private E-2

    Had to delete that shortcut as it wasn't even a shortcut, it was a program file or something opening up a command window.

    I seem to have fixed things by copying over another file however I don't feel this is really a secure method.

    I have enclosed my lastest hijackthis, could you see if there is anything else lurking in there.

    Thanks
    le floof
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're HJT log is clean! Are you having any problems?
     
  25. le floof

    le floof Private E-2

    Things seem to be ok now, a lot more stable now. One thing that's a bit weird however is that everytime I reset my computer from safe mode, it comes up with cannot end program sample. Not sure what this is about.

    Le Floof
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean when you REBOOT?

    Do you have this file on your computer:

    Zerocfgsvc.exe which is pert of Intel ProSet.

    See info about it here: http://www.answersthatwork.com/Tasklist_pages/tasklist_z.htm
     
  27. le floof

    le floof Private E-2

    Yes, only when I reboot from safe mode.

    I do have the file you mentioned, and it sounds as if it is required as I am using a wireless network.
    I guess its not too much of a problem if that is all it is, so I'll probably leave well while things are working well!!

    Thanks for all your help
    Le Floof
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! You could try checking for new drivers for your hardware. Perhaps that would help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds