(Common?) Hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by danielm, Apr 1, 2005.

  1. danielm

    danielm Private E-2

    Hello Major Geeks,
    My computer has been taken over by some creature.
    I have followed your instructions on the basic ways of handling hijackers, but that didn't help.

    I think I know at least one of the methods the hijack uses: the winlogon notify method. There is a reference to a suspiscious dll there.
    In my system32 dir there are quite a few of these wiered named dlls (no identified manufacturer, etc).
    I have tried deleting the registry entry and it came back with a different dll's name. I
    have tried deleting the dll itself, but I got a "permission denied".

    I have run spybot and it claims there are two hijackers:
    IGETNET
    and "Common Hijacker"
    however, it cannot remove them (or if they are removed they keep coming back.

    I have run also pest patrol which found only spyware cookies

    I have run ad-aware which found nothing. the same goes for pc-cillin.

    any ideas?

    thanks,

    Daniel
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. danielm

    danielm Private E-2

    Thanks for the reply.
    I have tried everything you said:
    1. pc-cillin wouldn't run in safe mode
    2. spybot detected common hijacker and IGETNET. After removal they came back.
    3. ad-aware didn't detect anything
    4. pest patrol didn't detect anything.
    attached is the hijackthis log file.

    Thanks
    Daniel
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the ALL of the steps from the READ ME first. You have not done that. We did not ask for pc-cillin nor pest patrol but we do have a bunch of other things we want you to run. I can see that neither online scan was run? Is there a reason why? These are not optional steps as noted in the READ ME.

    Then please do the following:

    Please download the following tools and save them where you will be able to find them. I save stuff like this to a C:\downloads\Spyware-Stuff folder and I put each in their own subfolder. It makes it easy to find. Make sure you download them from the links below:

    L2MeFix Tool
    Generic Detection Tool - NT/2000/XP
    Pocket KillBox

    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing


    First Step:

    Extract all the files from the Generic Detection Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment (do it later when we reconnect).

    Second Step:
    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Third Step:

    Now reconnect and come back here and post as attachments the l2mfix log and the find.bat log (normally already named output.txt). Based on those logs, we will determine the next steps.

    Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  5. danielm

    danielm Private E-2

    It took me an entire day... No (good) results.
    Attached are the two reports (by the Generic Detection Tool & l2mfix).
    A summary of the previous tests I ranfollows.

    Thanks,
    Daniel

    Initial Tests - Results Summary
    ------------------------------
    1. Halted System Restore
    2. Downloaded, installed & updated security software
    3. Could not connect to Internet in Safe mode, running in normal mode.
    4. Trend Micro & Symantec on-line scans - Found Nothing
    5. Ad-Aware - Found redirections in the hosts file (I know they are there but they keep returning anyway).
    6. SpyBot - Claims he finds IGETNET & Comman Hijacker. Claims he removes them, but they return.
    7. CWShredder - claimed he removed CWS.BootConf, CWS.Svchost32, CWS.Look2Me.
    Fails to remove CWS.VXLook2Me. (keeps returning in subsequent test).
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    On the contrary, we have good results! We just have not finished fixing all of the problems yet. These kind of problems take a few steps.
    - initial standard cleanup
    - additional specialty scans
    - analyze scans
    - perform additional scans/cleaning using special tools and manual repair as necessary.

    What we are working on now is your L2Me VX2 problems. I'll post the next steps soon.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Moving along! Here are the next steps! I know this is tedious but we are making progress and these next steps are going to clean up a load of bad stuff.

    Step 1:

    Print or save these instructions locally now because you will have to be disconnected with no browsers open in the next step.

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log later when the remaining steps are completed.

    Again, don't run any other files in the L2MFix folder.

    Step 2:

    Reboot to normal mode. Now reconnect to the internet.
    Now download HOSTER and open it, select Restore Original Hosts > Press OK and then exit program.

    Step 3:

    Scan with HJT to create a new log.
    Come back here and post the new HJT log along with the L2MeFix Log from step 1.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also one other note! Did you install this:

    O4 - HKLM\..\Run: [sysmgr32] sa2

    As far as I know it is a key logger/password hacking tool. If you did not install it, I would have HJT fix that line.
     
  9. danielm

    danielm Private E-2

    Thanks for chearing me up a bit :)
    I'll do what you said, and get back to you with the information.

    Thanks again,
    Daniel
     
  10. danielm

    danielm Private E-2

    1. l2mfix option 2
    2. Hoster
    3. HJT
    logs attached

    Thanks,
    Daniel
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that fixed a bunch of problems.

    Please answer what I asked in message # 8. That's the only potential visible problem remaining.

    How are things working right now?
     
    Last edited: Apr 2, 2005
  12. danielm

    danielm Private E-2

    You mean it's over? Wow! thanks so much for that walktrough!!!

    I have been surfing for a few minutes now, and no popups appeared, so I guess/hope it's over (sa2 is not a problem)

    Last questions:
    Regarding user accounts:
    1. Is this solution general or user-specific, i.e. should I repeat anything with other user accounts on the same machine?
    2. Is it true that it is better not to use an administrator's account when connected to the internet?
    Prevention:
    3. Any other suggestions on prevention except from the one's that appear in the README?

    chaslang, you are really something for taking all that time to help me. It's nice to meet good people along the road :)

    Thanks (yet again),
    Daniel
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So what it it? Was my guess correct?


    You're welcome!

    You really need to check each user account individually to see what may be in them. Similar problems may be solved the same way (but not always).

    Some people feel that not having an admin count connected can be helpful. I personally have no problems being connected with an admin account and never have. It is a matter of proper security settings and software you use and also where you surf, what you click on, and reading license agreements before clicking OK.

    For addition suggestions, I always recommend that you make sure you have completed all steps in: How to Protect yourself from malware!
     
  14. danielm

    danielm Private E-2

    yes. sa2 also takes automatic screenshots, and monitors application's bahavior.

    I'll run the checks on the other accounts as you suggested.

    I'm off to work now.

    Have a great day,
    Daniel
     
  15. danielm

    danielm Private E-2

    I forgot to ask you another (unrelated) question :)
    Do you have any idea why windows doesn't save my 'Run' command history, and how to fix this?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not off the top of my head! Could it some how be related to sa2?

    Or maybe a registry key setting! The history is stored here:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU

    Someone in the Software Forum may know about this.
     
    Last edited: Apr 3, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds