Followed all instructions, please review HJT log

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hogwild, Jan 15, 2006.

  1. Hogwild

    Hogwild Private E-2

    I have followed the intructions to the best of my ability on "READ & RUN ME FIRST Before Asking for Support" (did it twice) and "NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting". Thank you, Major!
    Unfortunately, my Google search links are still being hijacked and redirected to other 5th rate search engines. Also, I have had a problem getting rid of the Yahoo toolbar and Yahoo has shwn up uninvited on occasion. I recently installed the Skype toolbar and now there is a yahoo search window on the Skype bar. I find it hard to believe that this is intended by Skype. Can you confirm?
    Attached os my HJT log. Can you help?

    With sincere appreciation....

    The Hog
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    Please complete step 6 of the READ ME and attach the requested logs.

    Also perform step 7 of the READ ME and get HJT installed properly as in the instructions.

    You have a Wareout infection that we must fix. But first please do the above and attach a new HJT log and the two online scanner logs.
     
  3. Hogwild

    Hogwild Private E-2

    Chaslang,

    Thank you for the response. Sorry, I forgot to post the bdscan log. See attached.

    I remember now that yesterday Panda Active Scan just stopped about 40% into the scan. I tried it again today and the same problem is happening. It's stuck at 21696 files scanned so it doesn't look like I am going to get a report. It indicated 32 spyware files detected. this is what the info bar says: 21696 Files scanned ...%26%40%24%3Ag62%3A%2AE%14QXO%2.

    Any suggestions at this point?

    The Hog
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you installed HJT properly yet? I requested a new HJT log be posted after installing it correcly.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After getting HJT installed properly, continue with the below:

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{59E1A42E-F7CF-4AD3-8B61-0443A2EED95A}: NameServer = 85.255.115.2,85.255.112.8
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8FBEC085-09B2-4736-83A5-5E19B04901DA}: NameServer = 85.255.115.2,85.255.112.8
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F70F8AB6-E6C9-47DE-871C-5C0939E254F5}: NameServer = 85.255.115.2,85.255.112.8

    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:
    C:\WINDOWS\system32\hhk.
    C:\Program Files\UnSpyPC <--- delete the whole folder if found

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Also attach a new HijackThis log.
     
  6. Hogwild

    Hogwild Private E-2

    I'm on it! Thanks...
     
  7. Hogwild

    Hogwild Private E-2

    Chaslang,

    I properly installed HJT. Thanks...
    I did not find UnSpyPC in Add/Remove programs.
    I installed and ran FixWareout

    I deleted these files with HJT:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{59E1A42E-F7CF-4AD3-8B61-0443A2EED95A}: NameServer = 85.255.115.2,85.255.112.8
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8FBEC085-09B2-4736-83A5-5E19B04901DA}: NameServer = 85.255.115.2,85.255.112.8
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F70F8AB6-E6C9-47DE-871C-5C0939E254F5}: NameServer = 85.255.115.2,85.255.112.8

    I had seen and suspected those files before on HJT and checked them out on Sysinfo but they are my ISP's correct numbers so I left them alone. Anyway, as I said, they're gone now.

    I explored but did not find:
    C:\WINDOWS\system32\hhk.
    C:\Program Files\UnSpyPC

    Attached are the latest HJT log and the FixWareout log.

    What's next?

    Thank you!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If these IP address belong to you ISP, you need to change ISPs.

    They belong to inhoster which is a well know malware site and is being added to many black lists
    I don't think they are for your ISP.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still did not install HJT as requested. You have it exactly where we specify not to install it (on your Desktop & in Docs & Settings)
    C:\Documents and Settings\Thomas Warton\Desktop\hijackthis\HijackThis.exe

    But right now it may not matter since we could almost be finished. However for future use, you must get it installed properly.

    Look for the below two files and delete them:
    C:\WINDOWS\SYSTEM32\CSGNT.EXE
    C:\WINDOWS\SYSTEM32\DMWUS.EXE

    Let me know how things are working now.
     
  10. Hogwild

    Hogwild Private E-2

    I'm sure you are right. I still have the Google hijack and redirect problem. Any more ideas?
     
  11. Hogwild

    Hogwild Private E-2

    SOrry, didn't see your second post. I'm on it!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry I missed one (and you should get HJT installed properly first) why are you having such a big problem doing this.


    Have HJT fix the below line:
    O4 - HKLM\..\Run: [dmpej.exe] C:\WINDOWS\system32\dmpej.exe

    Also look for C:\WINDOWS\system32\dmpej.exe and delete if found. Delete in safe mode if necessary.

    Then reboot and see how things are working.
     
  13. Hogwild

    Hogwild Private E-2

    Chaslang,

    Okay, finally I've got HJT installed in a proper place(I hope). C:\hijackthis

    HJT found and fixed :
    O4 - HKLM\..\Run: [dmpej.exe] C:\WINDOWS\system32\dmpej.exe

    I might not be searching properly. I am using the Start Menu Explore link. I searched through the folders but did not find:
    C:\WINDOWS\SYSTEM32\CSGNT.EXE
    C:\WINDOWS\SYSTEM32\DMWUS.EXE

    I then looked for CSGNT.EXE and DMWUS.EXE with Windows Search. I did not find CSGNT.EXE but I did find:
    DMWUS.EXE-23E3A2FD.pf in C:\WINDOWS\Prefetch

    Is this any concern?

    I will reboot now and let you know if I still have the Google redirect and Yahoo pollution problem.

    Microsoft Antispyware caught dmpej trying to reinstall and we didn't allow it.

    Forget the War on Terror, can't we start shooting these Malware propagators? I'm not suggesting full-scale carnage, just one or two to the firing squad might send a message.

    Thank you!
     
  14. Hogwild

    Hogwild Private E-2

    Chaslang,

    Rebooted. Same problems. Googles found links redirect to other search engines I never heard of AND yahoo is still on my menu bar.

    Is there anything else I can do?

    The Hog
     
  15. Hogwild

    Hogwild Private E-2

    Sorry forgot to include latest HJT log. See attached.:eek:
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do not use Windows Search. We did not enable it to look for hidden and system files. We enabled Windows Explorer to show hidden and system files in step 1 of the read me. This a manual procedure where you expand the folders yourself and look for files. For Windows Search to work you would need to follow the steps in the below:

    Searching for Hidden Files on WinXP

    You system is still infected and it may be Wareout.

    First right click on the MS Antispyware icon in your system tray and select Shutdown Microsoft Antispyware (answer yes or ok when it prompts you).


    Now we will run the Wareout fix again.

    Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    Your system may take longer than usual to load; this is normal.
    When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:

    O4 - HKLM\..\Run: [dmpfx.exe] C:\WINDOWS\system32\dmpfx.exe

    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:
    C:\WINDOWS\system32\dmpej.exe
    C:\WINDOWS\SYSTEM32\DMWUS.EXE
    C:\WINDOWS\system32\dmpfx.exe

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Now run the following procedure and attach the Ewido log: Running Ewido Security Suite

    After running Ewido, make sure you are in normal boot mode and attach a new HijackThis log.
     
  17. Hogwild

    Hogwild Private E-2

    Chaslang,

    I did all as instructed, although I wasn't completely clear what report to run with Ewido.

    I did not find:
    O4 - HKLM\..\Run: [dmpfx.exe] C:\WINDOWS\system32\dmpfx.exe,
    in HJT

    Did not find, using windows explorer, any of the following:
    C:\WINDOWS\system32\dmpej.exe
    C:\WINDOWS\SYSTEM32\DMWUS.EXE
    C:\WINDOWS\system32\dmpfx.exe

    Attached are the Ewido, Wareout and HJT reports.

    I still have the exact same problems with Google being redirected and alsoo the Yahoo Web Search bar on my Skype Menu Bar.

    On a positive note my Thinkpad is running alot quicker!

    Any more suggestions? :confused:

    Thanks very much!

    The Hog
     

    Attached Files:

  18. Hogwild

    Hogwild Private E-2

    Chaslang,

    I did some more searching and got a little smarter and found the following file and deleted it:
    C:\WINDOWS\SYSTEM32\CSGNT.EXE

    Files not found:
    C:\WINDOWS\system32\dmpej.exe
    C:\WINDOWS\system32\dmpfx.exe


    As I mentioned earlier, I could not find:C:\WINDOWS\SYSTEM32\DMWUS.EXE
    But I did find these files in the prefetch folder:
    DMWUS.EXE-23E3A2FD.pf,
    DMPFX.EXE-24C7D4BB.pf
    Are they problem files?

    Ran Wareout again. Attached are new Wareout and HJT reports.

    Thank you!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problem keeps mutating. Possibly at each reboot or upon attempting some fixes. You must try to watch for the above type O4 lines in HJT and recognize them. The reason you did not find the above one is because it probably renamed itself. In the last log you posted, it is now:

    O4 - HKLM\..\Run: [dmtuy.exe] C:\WINDOWS\system32\dmtuy.exe

    It should be easy for you to find any new line(s) since it would be the only new or changed line since posting your last log. Also note the process name in the [ ] is the same as the file name at the end of the line.

    Thus, if you do not find what I put into a cleanup procedure, locate that actual problem line and substitute in whatever it is at the present time.

    Also when trying to delete files, you must make absolutely sure you have done all of step 2 in the READ ME correctly. Why is it that now all of a sudden you could find C:\WINDOWS\SYSTEM32\CSGNT.EXE when you could not find it before? It was always there. Also it would be a good idea to sort make sure you have selected View, Details in Windows Explorer and then make sure you sort the contents of the C:\windows\system32 folder by Date Modified. This way all the problem files will probably show current dates and you may find more of them.

    Let's try the procedure again (keeping in mind the above) and with a slight change in directions. I want you to make sure you are physically disconnected (unplug the cable) from the internet while running the steps. I will tell you when to disconnect.

    Please delete your previous copy of FixWareOut and download FixWareout again (just in case a new version is out) from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop.
    • Physically Disconnect from the internet now (so print the instructions or save locally to refer to while disconnected). Do not reconnect until specified.
    • Run fixwareout.exe by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    O4 - HKLM\..\Run: [dmtuy.exe] C:\WINDOWS\system32\dmtuy.exe

    Or whatever the new name is.



    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for any of the below files and delete if found (remember to try sorting by Date Modified and look for others):
    C:\WINDOWS\system32\dmtuy.exe
    C:\WINDOWS\SYSTEM32\CSGNT.EXE
    C:\WINDOWS\SYSTEM32\DMDZU.EXE
    C:\WINDOWS\SYSTEM32\DMQWO.EXE

    Goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner and let in cleanup.

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    Also attach a new HijackThis log. Please do not reboot or power down after posting these logs.
     
  20. Hogwild

    Hogwild Private E-2

    chaslang,

    Thanks very much for staying on this one!

    I did everything you suggested. But even after several atempts, I could not get FixWareout to run properly. I went ahead anyway and ran HJT and used Windows Explorer to delete the files you listed as well as the Perfetch folder contents. I rebooted and was able to download FixWareout and run it. Please see attached logs.

    Things appear to be clean. I'm keeping my fingers crossed...

    I will not reboot or powerdown without your command.

    Looking forward to your reply.


    The Hog
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This all sounds a little contradictory. Are you saying that you could not run FixWareOut but then you rebooted and you were able to run it without a problem?

    What happened during the time you said it would not run?

    The below should not be running anymore when you get a log to attach here.
    C:\fixwareout\SUB\BFU.exe

    It should only be running during the fix interval.

    At anyrate, your HJT log was clean. Is it still clean?
    The below file from the fixwareout log must be deleted:
    C:\WINDOWS\SYSTEM32\DMFLQ.EXE

    Let me know if everything is still clean (look for any of those O4 lines).
     
  22. Hogwild

    Hogwild Private E-2

    chaslang,

    Let me explain in more detail as best I remember it.

    Yes, I could not run FixWare out. As instructed I deleted the original version I had. It had been located on my C drive folder with my HJT folder. Using your link I saved it to my desktop as instructed. I tried several times to run it. The black DOS box came up(I don't know the what you call it) and instructed "hit any key to continue". I hit a key and it wrote out 30-40 lines of text and intstructed again "hit any key to continue". The window disappeared and I waited knowing htat the reboot took longer than normal but nothing happened. I went through this two more times. Same result.

    So I went ahead with your other instructions to run HJT and delete said files.

    I then rebooted in Safe Mode. I may have tried reinstalling FixWareout again but I can't remember. I then searched explorer with date modified(as you suggested)and found some suspect .EXE files in the prefetch folder. I deleted them and all the contens of the prefetch folder.

    I then ran CCleaner and then sucessfully reinstalled FixWareout and sent you my last email.:eek:


    I don't know what you mean by "The below should not be running anymore when you get a log to attach here.
    C:\fixwareout\SUB\BFU.exe"

    I just ran HKJT and did not see any suspect files. See attached. I did not run FixWareout but attached the current log. I'm not exactly clear what FixWare out does and how it interacts with HJT. I'm guessing it eliminates Wareout malware and then uses HJT to check if it was successful? Am I close?

    I assume I can only eliminate "C:\WINDOWS\SYSTEM32\DMFLQ.EXE" or it's ilk by checking the appropriate HJT box and hitting Fix.

    I just ran a few test searches on Google and SN and the was no redirect! I think I'm clean! You did it! If so, should I reboot in Normal or Safe Mode? and run FixWareout again? Also, I have had system restore off. When I reboot can I turn it on again?

    The Hog
     

    Attached Files:

  23. Hogwild

    Hogwild Private E-2

    Looks like I'm not able to attach Missing (old) Fixwareout log
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If that was still running, it means that the fiwwareout program had not completed its task yet. BFU is Brute Force Uninstaller which is part of what fixwareout uses to help clean the problem up. So I was just indicating it was not the correct time to be getting a log to post since the tool had not finished running.

    The tool removes a bunch of registry keys created by the infection and also attempts to locate all the bad executable & other files to remove them (there are many of them). The log shows possible suspect files that remain. Not all items shown in the log are always bad (like ipsec6.exe which is valid).

    No! As you noted there are no lines in HJT anymore. You need to delete the file yourself as we did in previous messages using Windows Explorer.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  25. Hogwild

    Hogwild Private E-2

    Cahslang,

    Hey, I am totally clean now. Thanks for your incredible support. You made my day. What can I do to make yours?

    The Grateful Hog

    p.s. Isn't it past your bedtime?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Just send your friends to MGs for help!

    Malware never sleeps so we are not allowed to either! :D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds