HELP needed, hijacked by 'Search for...'

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by photek, Jul 6, 2004.

  1. photek

    photek Private E-2

    I need serious help. My startpage is hijacked by a search site 'Search for...' (http://s1di.d8t.biz/index.php?aid=20038) but no mather what I do, it keeps comming back.

    I've used:
    -HJT v1.98.0
    -CWShredder v1.59.1
    -About:Buster v1.24
    -Ad-aware v6.0
    -Spyware Doctor

    They all detect files, but after the fixing of the files, the Search for... site still pops up when I start Internet Explorer instead of google.nl, the startpage i'd like to have.

    I really need help because I'm absolutely no pro at this. This is the first time something like this is happened to me, so I have no experience either. The things I know about hijacking, CoolWebSearch and registerfiles are from a 2 days struggle to get this darn thing out of my computer.

    Thanks,

    photek (Netherlands)
     
  2. Dr. Woodz

    Dr. Woodz Private E-2

    these things are running absolutely rampant right now, aren't they???


    ...and they're tending to be the very worst kind that are out of reach of current software solutions... it's either go down a very long list and hunt that multi-headed hydra monster down or backup and format the drive... i just had to format and start clean after having apps appear everywhere on the machine, and filenames morphing and hiding in different places each time... truly bad news... and i can't get windows back on yet, grr... time for a new machine.
     
  3. photek

    photek Private E-2

    Yes it's terrible! But the problem is, that I can't find a full proof solution. Every computer has it's own weird files and every user has it's own ways to clean (if the person is able to) a PC. So when I go down a 'to do list' I'll get stuck somewhere, 'cause it's not exact the same PC, Windows or files or whatever that's messing things up... Besides that, I'm not good in solving problems like this. Me = n00b :rolleyes:

    Too bad you had to format your PC. And till now, I see no other option either... Thanks for your reaction :)
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Did you try HSRemove?
     
  5. photek

    photek Private E-2

    No I haven't. But I'll try it. Thanks
     
  6. photek

    photek Private E-2

    HSRemove doesn't help either. It says 'no items removed'
     
  7. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I hope its not a new variant. A new tool is out called About:Buster in our spyware section. The download page has specific instructions on removing it as well Try that.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post a complete HijaakThis log. I gotta see this one. I agree Major....I hope we do not have a new one on our hands.
     
  9. photek

    photek Private E-2

    Already did. But it came up with nothing:

    "About:Buster Version 1.24
    Attempted Clean Of Temp folder.
    Pages Reset... Done!"


    Okay I'll post it.
     
  10. photek

    photek Private E-2

    Logfile of HijackThis v1.98.0
    Scan saved at 11:45:33, on 8-7-2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft Hardware\Mouse\point32.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Documents and Settings\Matthijs Meesters\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\MATTHI~1\LOCALS~1\Temp\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\MATTHI~1\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\MATTHI~1\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\MATTHI~1\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    F0 - system.ini: Shell=
    F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,
    O2 - BHO: (no name) - {5E997197-9239-4B6E-83C7-658BFE672D40} - C:\WINDOWS\System32\edicbaa.dll
    O4 - HKLM\..\Run: [POINTER] point32.exe
    O18 - Filter: text/html - {206E25BD-D98D-4092-BEDB-C5C1C40AFE9E} - C:\WINDOWS\System32\edicbaa.dll
    O18 - Filter: text/plain - {206E25BD-D98D-4092-BEDB-C5C1C40AFE9E} - C:\WINDOWS\System32\edicbaa.dll
    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1) go here and download Registrar lite and install it: http://www.resplendence.com/reglite
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls tell me exactly what you see in the Value.

    If you see a path to a file in step file above do the step 6 to 10 otherwise skip to 11.
    (An example path may be something like c:\windows\system32.xxxxx.dll where xxxxx is any random characters)

    6) Now click in the left pane of Reglite and rename the folder Windows to NotWindows.
    This folder should be hilited as a light blue (some people call it light purple)
    7) Now double Click "AppInit_DLLs" and clear the data value:
    C:\WINDOWS\System32\xxxxx.dll < delete this line , 'Apply' and 'ok' to set.
    8) Rename the NotWindows folder back to its original name Windows
    9) Restart computer
    10) This should make the file visible. Use Windows Explorer and see if you can find it in:
    C:\WINDOWS\System32\xxxxx.dll

    If you can't find it, make sure your have enable viewing of hidden
    files by doing this: http://www.xtra.co.nz/help/0,,4155-1916458,00.html


    11) Please download this about:buster again it changed today even though the version number is still 1.25.
    Get it here: http://www.majorgeeks.com/download4289.html

    But do not run yet.

    12) Double check to make sure your Ad-aware reference file is up to date. It should be 01R330 07.07.2004 at
    the time I wrote this. By double check again, they update frequently.

    13) You should print the remaining instructions because in the next step I am going to have you totally disconnect from the internet.

    14) This step is very important! Disconnect from the Internet completely (i.e., drop analog modem connections, unplugged ethernet cables,...etc).

    15) reboot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

    16) Make sure at this point all Internet Explorer and Win Explorer sessions are shutdown. Do not open them again until instructed to.

    17) Now start Hijack this and have it fix ONLY the following lines:

    O2 - BHO: (no name) - {5E997197-9239-4B6E-83C7-658BFE672D40} - C:\WINDOWS\System32\edicbaa.dll
    O18 - Filter: text/html - {206E25BD-D98D-4092-BEDB-C5C1C40AFE9E} - C:\WINDOWS\System32\edicbaa.dll
    O18 - Filter: text/plain - {206E25BD-D98D-4092-BEDB-C5C1C40AFE9E} - C:\WINDOWS\System32\edicbaa.dll
    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)

    Exit HijaakThis.

    18) Run about:buster and click start. Be patient, it takes awhile for this to go through all the files it has to look at.

    Save the log from about:buster.

    19) Run HijaakThis again and fix the following (if they still exist):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\MATTHI~1\LOCALS~1\Temp\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\MATTHI~1\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\MATTHI~1\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\MATTHI~1\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank


    20) Go C:\DOCUME~1\MATTHI~1\LOCALS~1\Temp directory and delete sp.html if you find it.

    21) Reset Web Settings by right clicking on your desktop Internet Explorer icon. Then click Tools, Internet Options, Programs, and click the Reset Web Settings button. Then go back to the General tab and set you home page back to what you prefer (like www.majorgeeks.com).


    22) Run a full scan with Ad-aware. Since I have you disconnected from the Internet, the following instructions explain how to set Ad-aware's settings to perform a "Full Scan."

    In Ad-aware click the Gear to go to the Settings area. The following items should be on a green check, not on a red X.

    Under the Scanning button:

    - Scan within archives
    - Under Memory & Registry, Check EVERYTHING
    - In Check Drives & Folders, make sure all of your hard drives are selected

    Under the Advanced button, check ALL under Log detail level (this makes it easier for visitors to the Lavasoft Support Forums to see what options you have selected should you require assistance.)

    Under the Tweak button...

    Some of these may not be an available option, depending on your version of Ad-aware and your version of Windows. Do not be concerned if you cannot select a certain item.

    In Scanning Engine:

    - Unload recognized processes during scanning
    - Include info about ignored objects in logfile, if detected in scan
    - Include basic Ad-aware settings in logfile
    - Include additional Ad-aware settings in logfile
    - Include used command line parameters in logfile

    In Cleaning Engine:
    - XP/2000: Allow unloading explorer to unload shell extensions prior to deletion
    - Let Windows remove files in use at next reboot
    - UNCHECK: Automatically try to unregister objects prior to deletion

    Click Proceed to save these settings. When you would like to perform a "Full Scan," switch the scan mode from SmartScan to Custom.

    23) Restart your computer in normal mode.

    24) Now go try to delete the file we found in steps 5 & 10 (if you did find one)
    This was the C:\WINDOWS\System32\xxxxx.dll file (replace xxxx by what you found).

    25) Reconnect to the internet now.
    26) Post a both the about:Buster log and a new HijaakThis log and let me know how things are working.
     
  12. photek

    photek Private E-2

    Wow that's a lot! I hope I can work through the whole list before I get to France (vacantion) tomorrow :eek: So my reply will be tomorrow or after my France trip :(

    Thanks for the help you've given me so far!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Get back in touch when you can!
     
  14. Dr. Woodz

    Dr. Woodz Private E-2


    yeh, if you do end up having to wipe clean (format) and reinstall windows, that will work a charm... pretty straightforward, just back your files up if you can, if you haven't already (once you're sure your files are not infected), get into dos mode and format the drive (find some dos commands, format is usually 'c: format' while in the \C:> dos prompt)... reinstall windows, update windows, and start rebuilding your machine... hope you have all your software and driver cds( and serial#s)! -change your internet browser from IE to anything else, i like firefox right now, has none of the backdoor security flaws like in IE that most adware is apparently written to exploit... best of luck, should you pull all that off yourself not only will you save yourself some bucks your machine will be like new
    :cool:
     
  15. photek

    photek Private E-2

    problem again :rolleyes: I've wiped my comp clean, but the 'search for...' is back on my browser. And I guess it was a backdoor thing. My Norton said that. I guess he couldn't fix it. So, back to zero. Same procedure over again now? greets photek
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It must be due to places you are surfing and you may need to get better protection on you PC.

    Are the symptoms exactly like last time and does a new HijackThis log look similar to last time?
     
  17. photek

    photek Private E-2

    Yeah I guess so. It's lame I have Norton 2003. The thing detects the prog, but can't block it or somethin. It's a backdoor thingy.

    The symptoms are the same, the log too:
     

    Attached Files:

    • hjt.txt
      File size:
      4.2 KB
      Views:
      1
    Last edited by a moderator: Sep 9, 2004
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay first, there is a new procedure. HijackThis logs should only be posted when requested and they must be a .txt file attachment. See this thread for more info: http://forums.majorgeeks.com/showthread.php?t=38752

    - Shut down browsers before running! Notice:
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    - Please download the latest about:Buster: http://www.majorgeeks.com/download4289.html Do not run yet.

    - Make sure you have downloaded and installed Ad-aware SE Version 1.04 with a reference file of SE1R1 06.09.2004. Get it installed on your system now. You need it later below. Get it here: http://www.majorgeeks.com/download506.html (Make sure you update ).

    - Make sure you have viewing of hidden files and folders enabled: http://forums.majorgeeks.com/showthread.php?t=37650
    - Make sure you know how to boot in safe mode (don't do it yet, wait till I tell you):
    http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

    - You should print all of this (or save locally) since when I have you exit all browser sessions below, I do not want you to reconnect or open any browsers again until I tell you to do so.

    - Exit all browser sessions and disconnect from the internet now!

    Now to your log:

    1) Run HijackThis and put checks on the following items BUT DO NOT CLICK FIX until make sure (as I said above) you have exited all browser sessions including the one you are reading right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {48649E5C-B688-41A0-9AED-5580D8E81DFF} - C:\WINDOWS\System32\jjo.dll
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O18 - Filter: text/html - {27EAF512-265F-46C5-947C-200433CE3683} - C:\WINDOWS\System32\jjo.dll
    O18 - Filter: text/plain - {27EAF512-265F-46C5-947C-200433CE3683} - C:\WINDOWS\System32\jjo.dll

    After fixing those in HijackThis, exit HijackThis.
    2) Now run About:Buster and save the log to ab1.txt

    3) Reboot in safe mode

    4) Use Windows Explorer (not IE) to locate and delete:
    C:\WINDOWS\System32\jjo.dll

    5) Reset your web settings by doing the following:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Remember do not reconnect to the Internet or run any browsers yet.

    6) Run about:Buster again and save the log to ablog2.txt.

    7) Now run Ad-aware SE and under the scan option select Full System Scan and run it.

    8) Now reboot in normal mode and connect back here and post your two about:Buster logs.

    9) Then exit Internet Explorer and start it up it again. Try that a few times to see if
    about:blank returns. If it does return, post a new HijackThis log attachment and DO NOT
    shutdown or reboot your PC. You can disconnect from the Internet to remain safe but do not reboot.
     
  19. photek

    photek Private E-2

    I'll start the procedure now.
     
  20. photek

    photek Private E-2

    It went fine! :) For how it looks now, the 'Search for...' page isn't comming back :D But no hasty joy, here's the ABlog. Log1 and Log2 are saved in the same txt.file

    Thanks!
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool! Sounds like success! Let me know if it comes back. Thanks for posting those two AB logs. They helped confirm my suspicions that this was NOT an about:blank or HSA related hijack (not that you said it was). I was worried for a second about a new breed.
     
  22. photek

    photek Private E-2

    Nice! Glad to be of service. Thanks a lot chaslang! I'll see you around :D
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds