Explorer Reloads on Startup (?), Hijacking of Searches

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sidecutter, Jan 6, 2006.

  1. Sidecutter

    Sidecutter Private E-2

    Hey Guys,

    A couple weeks back, I got a drive by that tossed UnspyPC on my computer, and also seems to have inserted the IE window popups and fake system message popups for Winfixer as well. These popups could circumvent popup stoppers. I uninstalled UnspyPC and was able to rid myself of those bothersome popups after doing a little research. However, I suspect this infection or another has left some artifacts of note behind.

    Just to start, let me say that Spybot S&D, Ad-Aware SE Personal, AVG Free, and Webroot Spysweeper all seem to agree that my system is clean, yet some odd behavior persists. I have also handled all the suspicious entries all of them found, and removed anything that seems remotely "not right" with Hijack This (I am a tech, so no, I didn't just go willy-nilly fixing items, no worries there). They keep all showing clean with no new entries or reappearing removed items now. I am also unable to pin down anything odd in my processes running or using Startup List.

    When I boot the machine, my desktop and background appear, but then the screen will flick to black for a moment, and return to normal. This happens as much as 2-3 times before the system finishes. I suspect this is indicative of Explorer.exe being altered and forced to reload to accomodate something. Also, on the final instance, I can see the outline trace of a window of some kind appear for just a split second, not even long enough for the screen to fill in the window and let me see anything about it. It occupies maybe the top quarter of the screen.

    In addition, website links and searches get hijacked. Es[ecially if the links have to do with spyware removal and the like, it will redirect me to other, probably bogus software sites. For instance, attempts to search for and then go to the homepage for Spybot S&D will be redirected to any number of bogus tools, such as Stopzilla, to name one that I recall off the top of my head. Other types of links are also hijacked and redirected to "relevant" (sorta) Google search results.

    Anyone got any tips/info/ideas? I really want to kill this garbage once and for all. Some work with Spyware Blaster and Hosts file editing has killed the redirects, but I still hear IE trying to click through several pages fairly often, apparantly with these attempts failing due to the Host file edits. It's annoying, and I hate running a dirty system, when I normally am able to keep it tidy and clean.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Normally UnSpy comes with a WareOut infection so I would be guessing you have that.

    To find out what you have and to initiate the cleaning, follow the below.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. Sidecutter

    Sidecutter Private E-2

    OK, ran through the instructions as given.

    -CCleaner ran and I had it remove what it found.
    -MS Malicious Software Removal - Found nothing.
    -Ad-Aware SE - Found nothing
    -Spybot S&D - Found nothing.
    -MS AntiSpyware - Found nothing.
    -CWShredder - Found and removed cws.svchost32 and cws.smartsearch
    -Kill2Me - Found nothing.
    -BitDefender - Found and removed/healed some items. Everything it found was in my old Sent Mail folders as near as I could see.
    -Panda - Says it found things, but I can't see what or post the log, because in safe mode, the window it opened was too small to see the right hand side of the readout where it gave this info, and I had no ability to scroll over or enlarge the window.

    Since BitDefender found some Swen traces, I also ran a quick instance of Symantec's FixSwen tool to be sure it wasn't actively working. No problems found there, either.

    I still have the issue at startup with apparant reloading of Explorer (seems to have settled into doing it twice every time), and the window-flicker. I've attached the BitDefender log, and HJT log.

    I've also uploaded a short (15sec) MPG video of my computer as it loads up, so that you can see exactly what I do. It's not big, but serves well enough to show the issue. You can see the screen flick to black at about 5 seconds, then it returns and flicks immediately back to black at about 6-7 seconds, then you can make out the window tracing at 9-10 seconds or so for just a brief moment. The files is 320x240 and about 1.5MB in size. You may need to doublesize it to be able to see the window-trace depending on your resolution. That MPG is at http://www.capturedprey.com/images/startup.mpg
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow directions properly. I have attached step 7 of the READ ME here. You did not follow any of it and thus are using an improperly installed version of HJT that has not been used in almost two years.

    Please follow those steps exactly to get the correct version of HJT and have it installed properly. Then attach a new log.
     
  5. Sidecutter

    Sidecutter Private E-2

    I may have overlooked that the HJT version has been updated since I got the one I had on hand, but I certainly did follow everything exactly as your instructions directed, other than getting ahold of the new version.

    Here is the new logfile for the current version of HJT.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I see no signs of the typical lines indicating WareOut however something could be hiding. So let's run the below to check.

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please just close or do not run HJT as your log showed nothing to fix
    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt
     
  7. Sidecutter

    Sidecutter Private E-2

    Did the whole Uninstallation of Unspy and the Wareout remover bit when I first found the fixes to remove that bothersome Winfixer crud. But did it again to be sure.

    Unspy has not reappaeared in the Add/Remove programs dialogue. Here's the report for Wareout.

    Just for reference, immediately upon Wareout completing, the same double-flicker of the screen and the phantom window
    trace appeared.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well one additonal file was found:

    C:\WINDOWS\SYSTEM32\DMDES.EXE

    You need to delete the above. It may be necessary to be in save mode. I'm not sure this has anything to do with your screen flicker.

    You may want to run a couple other scans and post the logs:

    Please run this Running Ewido Security Suite and attach the Ewido log

    I would also suggest this one as it has sometimes been useful in uncovering infections in explorer.exe:

    Kaspersky On-line Scanner - read the Requirements and limitations


    Question: Is your SpySweeper a paid version and do you keep it up to date. If so, uninstall MS Antispyware. Having both can be a huge resource drain. It is okay as a temporary cleanup measure but not long term.
     
  9. Sidecutter

    Sidecutter Private E-2

    Alright, backed up DMDES to a safely removed memory stick, and delete the original from safe mode. Also did a Registry search. Found two references to it. Both were in HKLM\software\webroot\spysweeper\startup\id24, and I deleted both keys after exporting them to the same memory stick to be safe.

    I've attached the Ewido log. I had it take care of the little it found (1 item IIRC).

    I've also attached a Kapersky log and a fresh HJT log. Kapersky didn't find any Explorer infections, but did find the same (apparantly latent) infection attempts in my old mail storage folders (unfortunately, I havn't got the option of deleting these without dire need to do so, I have a fair bit of necessary stuff in those folders, and it would be insanely arduous to manually find and destroy all the individual messages from the two programs that found things in them). I did go in and destroy the four folders on my external drive that Kapersky indicated contained Trojans and such in the program zip files, and shooed them out of my recycle bin.

    The good news is, I only saw the screen "skip" once this reboot. The split-second window still appeared.
     

    Attached Files:

  10. Sidecutter

    Sidecutter Private E-2

    **PS**

    Normally I'd have assumed DMDES was a Spy Sweeper file, but the fact that googling it comes up with zilch for results, would instead indicate it was a randomly generated file.

    **EDIT** Scratch that, just did it one more time to see if Wareout would find any odd files again, and I got the double-flicker again. Grah.

    Also, yes, Spysweeper is a paid version, but I intend to "return" it, so to speak. Although it found a lot during it's free trial that got me to buy it, it didn't actually solve it, and I suspect the same issues would have been found/foxed by a couple of these other tools we've used here anyhow.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to delete whole folder of email you just need to delete the infected messages (probably one containing attachments).

    The below stuff if not a good idea to be using and could be the source of your problems. See it list in this infected list here: http://www.spywareinfo.com/articles/p2p/
    G:\Installation File Downloads\File Sharing\Warez\WarezP2P.exe/stream/data0005 Infected: Trojan-Downloader.Win32.Small.apc
    G:\Installation File Downloads\File Sharing\Warez\WarezP2P.exe/stream Infected: Trojan-Downloader.Win32.Small.apc
    G:\Installation File Downloads\File Sharing\Warez\WarezP2P.exe Infected: Trojan-Downloader.Win32.Small.apc

    You HJT log is still clean as it was before. You do not want that file you backed up to your memory sticky unless you are planning on reinfecting yourself with WareOut. It is not at all related to SpySweeper. Those registry keys from SpySweeper were just tracking the baddie being run.

    SpySweeper is one of the most effective tools on the market and fixes things that many other not only do not fix but do not even find.
     
  12. Sidecutter

    Sidecutter Private E-2

    I am aware that Warez is not a particularly friendly product. But it is most definately not the source of this issue. The program was downloaded on my old PC quite some time ago, and proved ineffective anyway. For that reason, as well as it;s known shaky reputation, it was never used again, and never installed in this computer at all. It existed only as an unopened, untouched file on my external mass storage drive where my massive archive of installer files goes. So no worries there. At any rate, all four of those folders and the unopened Zips inside them are destroyed now.

    I take it, then, that you are suggesting I keep Spysweeper and see if I change my mind.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's your decision but as far as we have seen, there is nothing better. Yes you can go out and buy something else and possible find some other tool will fix something it does not. But the same is true in reverse and for all products. But based on what we see in fixing hundreds of problems per week, it is the best all around.

    If you are keeping it, uninstall MS Antispyware (if still installed). And also Ewdido too (it is a very good tool too) to save system resources and avoid conflicts.
     
  14. Sidecutter

    Sidecutter Private E-2

    Understood. Personally, I am opposed to paying for something unless it does a remarkably better job than free tools I can find with a little effort searching.

    That aside, apparantly it looks fairly clean. Any more thoughts, or should I remove my Host files protections and pray? Because beyond that, I'm about *this* close to reloading the system from scratch to eliminate the issues for sure.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What host file protections? Do you mean the stuff Spy Sweeper put in there?

    Personally I do not put anything in the hosts file. I like it at default. I prefer to use tools like SpywareBlaster, Spyboy's Immunize, and IE-SpyAd. To block things via the Restricted Zone settings and active x controls. Any smart malware program (and there are loads of them) can easily start playin with you Hosts file and change it or even delete it. Yes, if SpySweeper is protecting it with its controls you will know so that can be useful. But if you remove SpySweeper, you remove that protection and locking of your hosts file. With a thousand or more lines of stuff added to the hosts file it is hard to find bad stuff if it sneaks in. Also large hosts files can slow your surfing down.
     
  16. Sidecutter

    Sidecutter Private E-2

    I have used IE Spyad. SpywareBlaster has also been put to use. I also found a tool that was recommended by other sites, during my earlier general search for help removing the Browser Hijacker problem. Among the solutions and help ideas was a file which could be simply run, and would add a whole mess of problematic sites to the Hosts file, preventing them from ever loading by simply redirecting them to the system at the "dead" IP addy.
     
  17. Sidecutter

    Sidecutter Private E-2

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know lots of people use it and recommed it. I don't and think it is a bad idea.

    I sure more than most people and have more than 12 pcs in my home network and 4 are used by kids. I do not use a hosts file and we do not have problems with malware. Just proper education and protection as documented in:

    How to Protect yourself from malware!
     
  19. Sidecutter

    Sidecutter Private E-2

    Well, I removed the Hosts file alterations (actually, just renamed them and tossed in a new Hosts file with just Localhost as normal). Seems, for now at least, as if the redirector got busted by something we did. I suppose I can live with the screen flickings if that;s the worst I have left.

    Shall I keep Broweser Hijack Blaster, or is that one generally not worth the effort?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What redirector? Do you mean the hosts file was not working to connect the bad URL back to local hosts. Nothing we did would have any affect on this. However if you are using a current SpySweeper they add their own stuff and lock the file. This also does not break it.

    I don't use Browser Hjack Blaster nor do I see a need for it.
     
  21. Sidecutter

    Sidecutter Private E-2

    No, what I meant was that the Hosts file was redirecting anything on the list of sites installed into it by what I showed you previously to the Localhost address that is always in the host file by default. That's what the MVPS Hosts file does, effectively.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and that is what I said too. But you said it was not working. You said:
     
  23. Sidecutter

    Sidecutter Private E-2

    Err, no, sorry. What I meant is that it looks, for now at least, as if the browser hijacker got busted by something we did here. I am now able to do a Google on, to usemy old example, Spybot, and not be redirected.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still not sure what you are trying to explain.

    I think maybe you are trying to say everything is working properly now but using a word like "busted" makes it sound like you are having a problem with something.

    If everything is working OK! We are done and let's leave it at that.
     
  25. Sidecutter

    Sidecutter Private E-2

    Think "busted" like the reference used when you get busted by the cops. Hence, since I'm not being redirected when I try and do things that used to trigger the hijacker to redirect me, it seems that the Hijacker got "busted" by some part of what you had me run through.

    I still have the odd flicker at startup, but I suppose if that's the worst of it, I can handle that.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many PCs will show one to several blanks of the Desktop as certain applications startup. This may be happening as antivirus, antispyware, and or firewalls hook themselves in. I'm not saying this is an absolute fact. It is more of an observation I have noted on several systems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds