Customer's Hijack This logfile (pulling my hair out)

Discussion in 'Malware Help (A Specialist Will Reply)' started by philbobilbo, Jun 1, 2005.

  1. philbobilbo

    philbobilbo Private E-2

    Customer's computer, massive problems. Haven't kept it up to date with Windows Updates (only has SP1), and is a spyware factory as of now. I know she's infested with My Search Toolbar, My Web Search (Popular Screensavers), Trojan.Thun (which apparently changed Windows Firewall permissions--I can't even see the firewall under services.msc and Task Manager won't work) and naturally, the infamous CoolWebSearch garbage that is the bane of all us repair folks. It also had SpySherrif, which I believe I finally killed by removing the [bleep] "winstall.exe" file from it's folder, removing the SpySherrif folder and all registry crap with Registrar Lite. CoolWebShredder gets shut down every time I try to use (Safe or Normal mode), and this goofy thing continually shows up on the Desktop:

    "System Stopped System has been stopped due to a serious malfunction. Spyware activity has been detected. It is recommended to use spyware removal tool to prevent data loss. Do not use the computer before all spyware removed."




    As a matter of fact, it's so bad that I can't even run Hijack This from normal mode and give you a log. The program "encounters a serious problem" and closes with no log made. I'll give you one from Safe Mode: (it's all I can give for now).

    Any suggestions are appreciated. At this point, I've run AdAware, Sysclean, XCleaner, cleared all temp files and System Restore, MS Antispyware, all to no avail.



    Edit by chaslang: Unrequested inline log removed
     
    Last edited by a moderator: Jun 3, 2005
  2. B3aR

    B3aR Private E-2

    I'm not the person you are looking for. But for spyware like that i went to

    Microsoft Anti Spyware Beta

    Go there and download the beta if you can. It is the best i've used except HiJackThis, but that is for advanced. Let us know if it works.


    Edit: Well jeez. i think you already tried this one. lol. Sorry must of skipped them words. Good luck then.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested and then they must be attachments to your message. Also they must normally be created while you are in normal boot mode but I see that you say you cannot run HJT in normal boot mode. See if you can run the steps below. Try running them and note any that you could not run. But do not stop. Just keep going until you complete all steps as best as possible.

    Please follow the steps below:

    First run HJT and have it fix the below item:
    O4 - HKLM\..\Run: [WindowsUpdate] C:\WINDOWS\System\svchost.exe /s

    Note: do not delete C:\WINDOWS\System32\svchost.exe

    Then later when you boot to safe mode, delete C:\WINDOWS\System\svchost.exe

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    Also to get you started and to reduce the size of your HJT log. Do the following:


    After doing ALL of the above you still have a problem, boot into normal mode (if possible) and (make sure you follow these directions, you were running HJT from the ZIP file):


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. philbobilbo

    philbobilbo Private E-2

    Thanks chaslang. Here's what I've done since the last post:

    1. After running DelDomains.inf (a suggestion from elsewhere), Hijack This would indeed run, but alas, no reference to svchost.exe in the list! However, there WAS a reference to "winupdate67410503(1).exe", which I deleted, along with Network Security Service (appxv.exe) thingy.

    2. Booted into Safe Mode, found the "svchost.exe" in Windows\System (NOT 32) and deleted it. Also found that winupdate67410503(1).exe file and deleted it, too.

    3. Decided to manually search for "appxv.exe" in the Registry with Registrar Lite, found four items which were removed.

    4. Temporary files were all clean, as I'd done so earlier with EZPCFIX on my Ultimate Boot CD for Windows disk (I double-checked these).

    5. If you'll note in the HJT file, there's still a 023 file referring to a 11Fßä#·ºÄÖ`I file which, just by checking off and fixing, does not go away. There's about 12 files that I find in Registrar Lite referring to these, but they're in the "Enum" folder, so I didn't want to delete those before I posted here.
    6. CoolWebShredder actually began to run in Normal mode, but about 3/4 through being finished the computer instantly shutdown and rebooted. Something trying to "protect" itself I imagine.
    7. When I try to access Task Manager, I receive this error: 'Task Manager has been disabled by your Administrator."
    8. When I try to activate Windows Firewall, I get this error: "An error occurred while Internet Connection Sharing was being enabled. The specified service does not exist as an installed service."

    The HJT file is attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in my previous message prior to posting HJT logs you are supposed to complete the below sticky thread:
    The O23 service you are referring to was from an HSA hijacker. Also covered in the read me. See step 2 in particular.

    Try this! Open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Network Security Service (NSS)

    If that does not work, try using the short name of the service: 11Fßä#·ºÄÖ`I

    If that does not work, you will need to stop and disable the service first per the READ ME FIRST.


    You need a real firewall. The one in Windows is not a real fire wall. See the ones recommend in step 3 of: How to Protect yourself from malware!
     
    Last edited: Jun 2, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also, run the below for you Task Manager problem:

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixtm.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixtm.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.
     
  7. philbobilbo

    philbobilbo Private E-2

    Sorry for not following directions previously chaslang, but here's what I've done since your last posts.

    1. Did both items 1 and 2 (Regedit to get Task Manager back, is now ok, and deleted the short named version of the Network Security Service (NSS) with Hijack This.
    2. Had a look at the page regarding spyware/virus removal you told me to look at, and basically everything had been done previously in the following order:

    1. X Cleaner (removed several spyware items)
    2. HJT 1.99.1 was run and removed lots o'garbage, which kept coming back.
    3. All temp files were cleared and System Restore turned off.
    4. Trend Micro's Sysclean=0 items infected.
    5. Adaware SE found 122 ADS items, all related to CWS. Subsequent scan showed 0 items. Normal scan found 36 items, subsequent scan 15 more, subsequent scan 0.
    6. MS Antispyware = 6 items: Dosh (Remote Access Trojan), Trojan.Thun, WinFirewall, Mediatickets (lots of Trusted Zone garbage), PopUp Screensaver, CoolWebSearch, and something else called Kryptonic. Subsequent scan=0. And this wouldn't run, but only in Safe Mode. This is the point where I first posted about this issue.


    3. Ran all of the extra programs, in both Safe and Normal mode, and in both "Owner" and "Administrator" accounts, and found interesting results, but still no fix.

    a)About Buster-would find about 20 items and remove those every scan (damn thing has to be replicating). The first scan showed several .dat files in the Windows and System32 folders.
    b)Kill2Me--did not find anything in any scan.
    c)CoolWebShredder--ran properly, but found zilch.
    d)HSRemove--in every scan, found 8 items which were removed (replication again).

    4. Other problems: when I downloaded your zipped files, kept getting a "files corrupted" error when trying to examine or open. Had to DL those on a clean machine and move over with a thumb drive. And the Windows Firewall is still toast. I imagine once I have a clean enough machine to install SP2, that will take care of itself.

    So there you have it; she's returning over and over again, but I stumped at this point. I still have that goofy "System Stopped" appearing on the desktop.



    The latest HJT is attached. I don't think it will tell you anything.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than the lines remaining from running HSremove (which you can have HJT fix)

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    your log shows no problems. (Other then a ridiculous amount of crap for silly online games).

    If you are still having problems, it could be the MS Antispyware and SpySweeper are blocking them from showing us an info. You may need to uninstall them so we can see the problems and work on them. Sounds to me like you had an HSA hijacker at one point. (The O23 line we fixed wad a part of it.)
     
  9. philbobilbo

    philbobilbo Private E-2

    Greetings again Chas,

    Well, puter does seem to be clean, but one final problem. I cannot change the Desktop at all. When I go to Properties on the Desktop, under Display Properties and the tab Themes, I now have a white background, and the tab is permanently set on "Modified Theme" which I can't change (always reverts back to this). On the Desktop tab, the Background item is grayed out, and I can't select a different background. The item at the very bottom of the backgrounds to select is "desktop", so I searched for "desktop.html" and deleted the item. That got rid of the "System Stopped" garbage on the desktop, but that item still shows in the items to select. I also attempted to go to "Customize Desktop" and "Web" to delete the item, but "My Current Home Page" is permanenty selected, and the "Delete" button is grayed out. Some registry stuff is afoul I believe, but where I don't know.

    BTW, uninstalled Spysweeper and MS Antispyware, but the new HJT was no different.

    Thanks again.
     
  10. philbobilbo

    philbobilbo Private E-2

    One other thing, Screen Saver is set to Windows XP, 85 minutes. After changing it always reverts to that.
     
  11. philbobilbo

    philbobilbo Private E-2

    This post can now be closed. Customer elected to do a clean install of Windows. Thanks for your help, chaslang.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome! But just for reference, the remaining problems would have been easily fixed with a couple of small registry patches.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds