Help to remove roings

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jsnide1, Sep 6, 2004.

  1. jsnide1

    jsnide1 Private E-2

    I have run adaware, spybot and CCleaner in safemode with system restore off as it says in hijack this tutorial. I then remove roings and it seems to come back as soon as I open internet explorer. Can you help?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean the READ ME FIRST: Basic Spyware, Trojan And Virus Removal sticky. Did you run everything in that thread?

    Check this out:
    http://www.pestpatrol.com/PestInfo/r/roings_com.asp

    What version of Ad-aware did you run? I seem to remember reading that they fixed this.
     
  3. jsnide1

    jsnide1 Private E-2

    Hello, Yes I mean Read Me First tutorial. My last Windows update was XP service pack 2 on Sept 1st. I have done the six steps to prepare the system for scanning and cleaning. I have also did steps 1 and 2 in the scanning and cleaning process and I have ran CWShredder in step 3. Ad-Aware SE Personal 1.0.4.0, with definitions file SE1R7 06.09.2004 loaded, it recognized 2 roings files and I deleted them. Restarted System in normal windows and opened internet explorer and after my home page loaded I went to this site and I ran Ad-Aware again and roings was back. I also made a Hijack This log

    Thanks Jeff
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Jeff! Post you HJT log as a .txt file attachment and I'll take a look at it. Make sure you have HJT version 1.98.2.
     
  5. jsnide1

    jsnide1 Private E-2

    Logfile of HijackThis v1.98.2
    Scan saved at 1:45:21 PM, on 9/8/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


    Thanks Jeff


    Edit by chaslang: Inline HJT log deleted
     
    Last edited by a moderator: Sep 8, 2004
  6. jsnide1

    jsnide1 Private E-2

    Hey! I got to looking at this post and noticed I didn't do avery good job the the first time so I'll try it again. I hope it is in txt like you requested.

    Thanks Jeff
     

    Attached Files:

    • hjt.txt
      File size:
      3.4 KB
      Views:
      3
    Last edited by a moderator: Sep 8, 2004
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Jeff,

    That's not an attachment. That's inline text.

    I changed it to an attachment for you. Notice the difference?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First thing you need to do is get HijackThis off your Desktop and into its own folder. It's safer for storing backups that way. (It automatically creates a folder called backups).

    Read thru the below stuff first to decide (where I have comments/questions) what you need to fix . Then run HijackThis and put check marks on all the lines put DO NOT CLICK FIX until you exit all browser sessions including the one you are reading this message in:
    These 4 lines must be fixed:
    O2 - BHO: jimmyhelp.CBrowserHelper - {85F7096C-E5F6-436D-BBB4-A25C5240C8B0} - C:\WINDOWS\knhnoxcof.dll
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/...bin/actxcab.cab
    O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} -

    If you put the below restrictions in place using SpyBot (or some other program) leave the two O6 lines alone. Otherwise have HijackThis fix those two line:
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Do you recognize the below IP addresses:
    209.153.128.4 = [ dns.voyager.net ]
    OrgName: Voyager Information Networks
    OrgID: VIN
    Address: 4660 S. Hagadorn Suite 320
    City: East Lansing
    StateProv: MI
    PostalCode: 48823
    Country: US
    NetRange: 209.153.128.0 - 209.153.191.255

    169.207.1.3 = [ asteroid.execpc.com ]
    OrgName: Executive PC Inc.
    OrgID: EXPC
    Address: 2105 S 170th
    City: New Berlin
    StateProv: WI
    PostalCode: 53151
    Country: US
    NetRange: 169.207.0.0 - 169.207.255.255

    If not fix the O17 line too with HijackThis:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{BCBAF29D-3166-4175-8961-B3CB74159C73}: NameServer = 209.153.128.4 169.207.1.3

    After fixing all the above.
    Enable viewing of hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650
    Reboot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406
    And delete the file:
    C:\WINDOWS\knhnoxcof.dll
     
  9. jsnide1

    jsnide1 Private E-2

    Hello, I removed the 4 lines you said must be fixed on the HJT log. On the two 06 lines, I don't know if I put the restrictions in place or not. How do I tell if I need the restrictions? The IP addresses belong to my service provider. I restarted in safe mode with viewing of hidden file and folders enabled and I couldn't find the file C:\WINDOWS\knhnoxcof.dll. I ran ad-aware, spybot, ccleaner and cwschredder,and deleted two roings from registry with ad-aware. I have used internet explorer the way I normally do two different times, running ad-aware after each time without roings reappearing! Spybot turned up VX2/f on one scan and something else ( I forgot to write it down) on the 2nd scan. I also installed SpywareBlaster today in between the two scans. I am going to try to attach a new HJT log in this thread to see if I can do it and to ask you if you see anything wrong with it or have any other suggestions that would help me out. Thanks Jeff
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log looks okay now. Has far as those restrictions (the O6 lines) you may have done that using SpyBot S&D in advance mode, tools, IE tweaks. Look at the miscellaneous locks to see if you have any check marks. There is nothing wrong with doing this. I just wanted to make sure you did it and not some malware.
     
  11. jsnide1

    jsnide1 Private E-2

    Chaslang, It's been 2 or 3 days now doing our normal things on the computer and no roings! Thanks alot, I appreciated all your help.

    Jeff
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Jeff. Happy I could help!
     
  13. jamjas

    jamjas Private E-2

    Hello,

    Spbot detected roings on my computer, when I try to fix it spybot freezes when it tries to create a restore point. Help please.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Jamjas,

    Welcome to MG's! You should start your own thread for your problem. But before starting a thread try following the steps in the following thread: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
     
  15. jamjas

    jamjas Private E-2

    Did all that stuff. I didn't even think to turn off system restore and have Spybot get rid of it. Well it's gone now thanks for your help. It was in System32, and it was called objsafe.tlb. any idea what it is?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds