Frustrated

Discussion in 'Malware Help (A Specialist Will Reply)' started by chuckyv, Feb 23, 2005.

  1. chuckyv

    chuckyv Private E-2

    I'm not very computer literate, but it appears that my browser may have been hijacked. I am continually getting redirected to other sites. I run Spybot after being on-line, and it shows I have the following CWS files:
    bootconf, loadbat, msconfd, oslogo, tapicfg, and xmlmimefilter. When I run CWshredder, it fixes the bootconf only. I run Ad-Aware, and it says I have "vx" but i can't delete all the files. I have Xoftspy which had been showing that I had the CWS Trojan combo, however that has not shown up on the last few scans.

    Any suggestions would be greatly appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. chuckyv

    chuckyv Private E-2

    Dr. C,

    Thanks for your reply. My computer seems to be operating a little better. Although, I am still getting re-directed periodically when I'm on-line. I ran all the scans that you recommended and updated all the items, however I could not run some of them in safe mode (I could not get connected to the internet in safe mode). I am running Windows XP and now have the Firefox browser.

    When I run Ad-aware, it says I have the VX2 malware (although I have the VX2 plugin) and it says I have a "redirect" (69.20.16.183 ieautosearch).

    Spypot and Xoftspy report nothing. CWshredder removes the bootconf file. My Antivirus (Solo) reports nothing.

    Do you have any further advice or suggestions?
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First:


    Download the following items:

    KILL 2 ME.zip

    L2MeFix Tool

    Generic Detection Tool - NT/2000/XP

    VX2.BetterInternet Finder XP/2k - Version Msg126

    Pocket KillBox

    DO NOT USE ANY OF THESE TOOLS UNTIL TOLD TO!


    Second:



    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT


    Third:

    Extract the Generic Detection Tool - NT/2000/XP to your desktop. Run findit.bat. Allow it as much time as it needs to complete. Once its completed post this log as an attachment as well.


    We are very busy here at MajorGeeks.Com Chaslang will check back when time permits.!







    You have to select "Safe Mode with Networking" to access the internet in safe mode.

    Edit by chaslang: Also if you really cannot connect in safe mode, did you run the online scans in normal boot mode as the READ ME indicates. If not, please do so.
     
    Last edited by a moderator: Feb 25, 2005
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To keep things moving right along, after downloading and running the items BJ requested and after posting the HJT log and the output.txt log from findit.bat, do the below.

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Now reconnect and come back here and post as an attachment the l2mfix log. Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  6. chuckyv

    chuckyv Private E-2

    Hey guys. I hope I did this right. I've attached the first two items you requested. I'll proceed with the other process.

    Thanks,

    ChuckyV
     

    Attached Files:

  7. chuckyv

    chuckyv Private E-2

    Dr. C,

    Here is the L2mfix log.
     

    Attached Files:

  8. PhilliePhan

    PhilliePhan Guest

    Hi Chucky,

    Looks like BJ & Chas are tied up.

    NEXT STEP:

    Please make sure ALL Browser Windows are Closed!

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go crazy for a bit, but just let it run. It should eventually cough out another log in Notepad.

    Again, don't run any other files in the L2MFix folder.

    Please attach that Log along with a fresh Find.bat log. One of us will try to check back shortly to take a look and give you the next set of steps!

    PP :)
     
  9. chuckyv

    chuckyv Private E-2

    PP,

    Thanks for your response. I've attach the log you requested.

    ChuckyV
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! That fixed a load of stuff.

    Extract PocketKillbox to its own folder and run Pocket Killbox.
    1) Now, Copy and Paste C:\WINDOWS\SYSTEM32\quxmwx.exe into the box
    2) Check the option to Delete on Reboot is selected
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click Yes.

    Allow Pocket KillBox to Reboot your computer. Reboot in normal mode. Tell me if you get any error messages on reboot and tell me the exact messages.

    Get us a new HJT log and also run find.bat again and post its output.
     
  11. chuckyv

    chuckyv Private E-2

    Dr. C,

    Here are the new logs you requested.

    Thanks,

    ChuckyV
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run Pocket KillBox and Copy and Paste the Following into the box: C:\RECYCLER\Desktop.ini - Click Red X to delete it using Standard File Kill.

    NOW:

    Open VX2Finder and Click on the "Find Vx2.Betterinternet" button.

    Then click on these buttons in the right pane unless they are "greyed" out:

    - UserAgent$ Button to remove the UserAgent from the registry
    - Guardian.reg
    - Restore Policy

    Exit and reboot in normal boot mode.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O2 - BHO: (no name) - {40276BE4-4DD4-899B-622D-F6B508F7EAA7} - (no file)
    O2 - BHO: (no name) - {E4947D86-EB24-BEEA-5187-ED7ABE07B673} - (no file)
    O2 - BHO: (no name) - {F5778509-07E9-0CE5-E802-9C7DFC2EF410} - (no file)

    Do you recognize the below? If not, fix them too!
    O16 - DPF: ChatSpace Full Java Client 2.1.0.84 - http://pressbox.rtsports.com:443/Java/cs4fs084.cab
    O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab

    After clicking Fix, exit HJT.
    Now:
    Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin
    And Click OK.

    Please download HOSTER and open it, select Restore Original Hosts > Press OK and then exit program.

    Now reboot in normal boot mode and post a new HJT log. And tell us how things are working.
     
  13. chuckyv

    chuckyv Private E-2

    Dr. C,

    I've attached the latest log. So far so good. Any other suggestions?

    ChuckyV
     

    Attached Files:

  14. PhilliePhan

    PhilliePhan Guest

    Hi Chucky,

    We have been seeing a lot of these cases where HJT cannot remove BHO remnants from the resistry. I'd like you to try three things to see if they work:

    Plan A

    Please Boot to Safe Mode.

    Now scan with HijackThis and Check the Boxes for the following:

    O2 - BHO: (no name) - {40276BE4-4DD4-899B-622D-F6B508F7EAA7} - (no file)
    O2 - BHO: (no name) - {E4947D86-EB24-BEEA-5187-ED7ABE07B673} - (no file)
    O2 - BHO: (no name) - {F5778509-07E9-0CE5-E802-9C7DFC2EF410} - (no file)

    Be sure All Browser Windows are Closed when you Click FIX.

    Reboot to Normal Windows and rescan with HJT to see if those 02 lines remain.



    If they remain, then on to Plan B:

    Please download the old HijackThis v1.98.2 from here: HijackThis v1.98.2

    Extract it from the ZIP to its own folder – C:\Program Files\HJT 1982

    Now, scan & fix with this version as per the previous instructions (Safe Mode, etc…) and see if that gets them!


    If that fails, then on to Plan C:

    Copy and paste the information below to notepad. Save it to your Desktop as type "all files" and name it FixBho.reg



    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID]
    "{40276BE4-4DD4-899B-622D-F6B508F7EAA7}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\Windows CurrentVersion\Explorer\BrowserHelperObjects]
    "{40276BE4-4DD4-899B-622D-F6B508F7EAA7}"=-

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID]
    "{E4947D86-EB24-BEEA-5187-ED7ABE07B673}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\Windows CurrentVersion\Explorer\BrowserHelperObjects]
    "{E4947D86-EB24-BEEA-5187-ED7ABE07B673}"=-

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID]
    "{F5778509-07E9-0CE5-E802-9C7DFC2EF410}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\Windows CurrentVersion\Explorer\BrowserHelperObjects]
    "{F5778509-07E9-0CE5-E802-9C7DFC2EF410}"=-




    Now:
    DoubleClick on the FixBho.reg file you made and follow the prompts to allow it to merge these entries into the registry.


    With luck, one of these methods ought to do the job! Let me know how you fare and which method worked (if any ;)) and any problems you may have run into.

    PP :)

    EDIT PP: Remove this line too - - > R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
     
    Last edited by a moderator: Feb 25, 2005
  15. chuckyv

    chuckyv Private E-2

    PP,

    No luck on removing the BHO. When I tried Plan C, I did not get any prompts after opening the file in notepad. Did I do something wrong?
     
  16. PhilliePhan

    PhilliePhan Guest

    Did you save it correctly as FixBho.reg?

    This is odd - a new batch of unknown BHOs that cannot be removed from registry.

    Please doublecheck Plan C procedure again and if that doesn't work, we can remove these manually via regedit.

    PP :)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for stepping in while I was out PP!

    I have seen a few of these hard/impossible to remove BHO lines lately on MG's. And there are hundreds of cases on the Web. I had even tried directed registry repair and they still came back. I think we need to use Regmon and/or Filemon to try to track what process may be doing this. In some cases, they only came back after reconnecting to the internet and/or running a browser.

    While it does not look like these are hurting anything since the files are already gone, it would be nice to find out why they will not go away.
     
  18. chuckyv

    chuckyv Private E-2

    PP,

    Sorry about the delayed response (had to work today). I think I did Plan C right that time, but it still did not fix the BHOs. However, my computer is running great!! I ran all my scans, and they all came up clean. Should I turn back on the System Restore now? I want to thank you guys so much for the help. I've already recommended the site to several friends.

    Thanks again,

    ChuckyV
     
  19. PhilliePhan

    PhilliePhan Guest

    You're welcome!

    No harm in turning System Restore back on. Chaslang is correct that we could use a guinea pig to poke around trying to delete those BHO Remnants, but we'll figure it out on our own - No worries!

    While you're here, be sure to check out Chaslang's Recommendations!!!

    PP :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds