HELP!!! Virus, possibly Spybot?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shauno2, Sep 8, 2004.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your right it probably is. I had found a reference to it that indicated it was from XoftSpy but the mc does appear to indicate McAfee.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have to run now. I'll be back later!
     
  3. shauno2

    shauno2 Private E-2

    Thanks chaslang, I'll try that. Is there a way I can update my McAfree definitions without going to their website, as it crashes during the registration. Is there a link on this site similar to what IMOG said about Norton updates?

    As I've said, McAfree does find the hxdefdrv.sys but we want it to find the 'Mother File' so to speak?
     
  4. shauno2

    shauno2 Private E-2

    I tried the link to Hijack This but explorer gets closed straight away. It does that on every helpful page I try to go to - thats why I've been using another computer to post here.
     
  5. shauno2

    shauno2 Private E-2

    ! ! ! ! GUYS, I THINK I'VE DONE IT ! ! ! !

    Right, I'll talk you through what I've done...

    As I've mentioned before, I have been running a program called DiamondCS Process Guard (free version) which protects programs from rootkit virii, which is what my virus is. This trial version allows you to protect one program.

    It finally clicked in my head that the reason I couldn't find the infected registry files in safe mode was because the virus wasn't active in safe mode, so the only way I could get to them in order to delete them was by accessing Regedit in normal mode, which until now has been disabled by the virus.

    So I set DCSPG to protect Regedit and whilst doing this, noticed that there was a list of programs that had been run. Lokking down this list I saw the illusive SVHOST.EXE and therefore changed its setting of 'allow' to 'block always'.

    Then when I ran Regedit, it worked and was not terminated by the virus. I then located the 2 files I needed to remove and exited. At that point I also deleted the svhost.exe file in C:\Windows\Prefetch\ and replaced the hosts file in ...System32\Drivers\etc\. (although this has been replaced again.)

    Hopefully after a reboot, all the symptoms will have been cleared. Please don't let this be false optimism!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds good Shauno! That's what I was saying back a number of messages when I said I need to see the processes in normal mode. And I could not understand why we did not see svhost.exe. Yet is was in the Prefetch folder which meant it was there at one time. Some other process could be spawning it too. I'm still concerned about those other two files:
    cexi.exe
    doai.exe

    That we saw before. I would still like to see a HijackThis log (attachment) if you can do that now.
     
  7. shauno2

    shauno2 Private E-2

    I've been trying to re install an uncorrupt version of Norton but for some reason it won't install Norton AntiVirus, or at least Norton Systemworks doesn't recognise its installed. I was weary of going on the internet without this.

    I noticed that the cexi file was in one of the same registry lists that I deleted the two main entries from, so I moved the file from the target folder (system32) rather than delete the registry because that way I could put it back if it was important. I have since deleted the file.

    In reference to the doai file, I tracked it down, terminated the process and deleted it as well.

    None the less, I am still finding hxdefdrv.sys in the windows folder after every reboot even after removing cexi & doai.

    I will now download Spybot and Hijack This and post back the results when done. Any ideas/comments in the meantime would be appreciated.
     
  8. shauno2

    shauno2 Private E-2

    Damn, It still won't let me download Hijack This or Spybot. They download butI get the message 'cannot read from source disk' at 99%. I've tried loads of different places but none will work.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you able to download anything at all (try something non-virus/spyware cleaner related). Try this link as a test: http://www.majorgeeks.com/download1385.html
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way earlier, you said you did not have the problem in safe mode. Can you boot in safe mode with networking and download the files? I would think not.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. shauno2

    shauno2 Private E-2

    I could download the file from the link in post #59 so its only spy-related stuff that is the problem.

    I'm going to try to download in Safe mode with networking but don't think I'll have a connection.

    I have followed all the points on the last link you posted, but I will try again.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but previously you had Process Guard running and you did not find the registry entries.
    So with it shutdown maybe ALL steps can be perform as indicated.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know how to use Windows Explorer to make a file read only?

    If so, perhaps you can try deleting all the lines in your host file again and only have the single default line I gave you earlier:

    127.0.0.1 localhost

    This is the same as what I.M.O.G gave in the ZIP file earlier. But this time immediately after saving the file as quick as possible change its attributes to read only. Maybe this will stop the virus from changing it.


     
  15. shauno2

    shauno2 Private E-2

    I'm currently running the online TM scan again but there has been no change.

    I disabled the Process Guard and went through the points again but it hasn't made any difference.

    I don't need to worry about the hosts file as it has been fine since I deleted the 2 registry files. I do still keep getting hxdefdrv.sys appear and I can't understand why if I have removed the registry files that are supposed to put it there. There's no sign of svhost.exe being run, even after disabling Process Guard.

    What I am really concerned about is when I try to cleansweep my temporary files, 430kb come back immediately. It says this is made up of 3 files in internet history. No matter how many times I hit 'clean' it keeps coming back. Seems very suspicious to me, especially as I read somewhere that this is where virii like to hide. Could this be what is reproducing hxdefdrv.sys?

    Anyway, its 2:30am here in England so I'm calling it a night. Thanks for your help and no doubt we'll continue this tomorrow!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would guess the 430kb that comes back is due to an index.dat file that is typcially stored in that folder (others too). I don't think it is the problem. Try doing a registry search for hxdefdrv.sys. If you find it, write down the full registry key info and then hit F3 to continue the search to look for more occurrences. Keep doing that until you reach the end of the registry.
     
  17. I.M.O.G.

    I.M.O.G. Private E-2

    Wow, a lot to catch up on here... Another way to accomplish this would be to create a hosts file in another directory then set its attributes to "read only", and copy and paste it into its proper directory. ;)

    If I've got the time, I will try to catch up on this thread later.

    If either of you are interested, you may also want to take a look here, as there may be something that gives you another useful idea:

    http://www.ocforums.com/showthread.php?t=307720
     
  18. shauno2

    shauno2 Private E-2

    This morning I searched the registry for hxdefdrv.sys as suggested but no results. I then searched for svhost and found there was another entry the same as the 2 before, this time in HKEY_USERS/software/microsoft/windows/current version/run/ so I deleted this one but still after a reboot the hxdefdrv.sys was in my windows folder.

    I decided to open up hxdefdrv.sys with notepad to see if I could make sense of any of it. Amongst the gobbly gook was reference to...

    C:\drv\objfre\i386\driver.pdb
    IoCreateDevice ntoskrnl.exe (isn't that something to do with boot up?)
    objfre\i386\driver.sys

    and alot of things that sound like commands, for example...

    ReferenceObjectByHandle
    KeattachProcess
    LookupProcessByProcessID
    ...plus many more

    Mean anything to you guys? I'm going to have a go at deleting the index.dat files mentioned in IMOG's link.

    BTW IMOG, since I removed the first two registry entries, I'm no longer having problems with the hosts file.
     
  19. shauno2

    shauno2 Private E-2

    I've just searched the registry for 'hack' and there's loads of folders and files refering to...

    HACKERDEFENDER100
    HACKERDEFENDERDRV100
    ImageTasks that mention hxdefdrv.sys and winunins.exe (mentioned in this link http://forums.devshed.com/archive/t-148783 ).

    I didn't want to delete all the folders because I didn't really know what I was doing but i deleted everything that mentioned hxdefdrv.sys and winunins.exe. I don't know why they didn't come up when I searched hxdefdrv.sys before, probably because they're not part of the entry name.

    Anyway, I've just rebooted and Objectdock has loaded for the first time and there's no sign of hxdefdrv.sys!!!!!

    All I need to know now is should I delete all the folders named HACKERDEFENDER100 and HACKERDEFENDERDRV100 from the registry?

    I'm now going to see if I have completely rid of the symptoms, for example, I'll try and download Hijack This and Spybot.
     
  20. shauno2

    shauno2 Private E-2

    All is well!!! I can download anything I choose.

    If you guys can let me know what I should do about the remaining HACKERDEFENDER100 related registry folders and files. I want to make sure I'm rid of this for good.

    Thanks for all your help by the way!!!!

    I'm a happy bunny, just in time for the weekend!!!
     
  21. shauno2

    shauno2 Private E-2

    Now that I've got Hijack This, can you please check through it for anything I shouldn't have. I see that doai.exe is there...


    Edit by chaslang: Inline log changed to attachment.
     

    Attached Files:

    Last edited by a moderator: Sep 11, 2004
  22. I.M.O.G.

    I.M.O.G. Private E-2

    Shauno, it is too late now, but in the future do not post your hijack logs like this... Post them as a text attachment. Major Attitude will fix that post for you, but it would be nice to reduce his workload for simple things like this. It might be useful for you to read the sticky guides here which explain these sorts of things (stickys are at the top of the list of threads in this forum).

    MG seems to be attempting to not contribute to the problem of destroying search engine spyware inquiries (googleing and finding nothing but pages and pages of hijackthis logs can be annoying).
     
  23. I.M.O.G.

    I.M.O.G. Private E-2

    You will want to attempt removal of some of those items in the hijackthis log... Anything that looks sketchy which you didn't install or configure.

    At a glance... The 016 line with the eroticaccess link needs to go. The line right above that with x.exe in it needs to go also. I think Chaslang told you to get rid of doai.exe earlier too, so that line can go also (that line represents a command in your registry which attempts to execute that file at startup).

    There's more likely, but thats just from a glance - I'm sure if you look you can recognize some things that don't belong. Slap anything that looks as shifty as a politician in a sorority house. ;)
     
  24. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I am coming in late, Chaslang has been busy, but ill try, so dont mind if I repeat, I am going from your logfile. Your Hijack This is old. Get a new copy. Your Windows Updates looks way out of date. Do that. Try safe mode with networking, then setup automatic updates. Rescan, do at least 2 of the online virus scans, THEN clean up with Hijack This.

    Remove:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sportnetwork.net/boards/list/s150.htm?f=149
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://
    R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.zpecialoffer.com/indexie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.zpecialoffer.com/results.asp?keyword=%s
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O2 - BHO: (no name) - {1BDD55B8-3985-4E59-B906-5E0AD56D6710} - (no file)
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O2 - BHO: Saristar - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE50} - C:\WINDOWS\System32\saristar.dll

    Not required, but wont hurt:
    O8 - Extra context menu item: Search with Freeserve - res://C:\PROGRA~1\FREESE~1\FSBar\FSBar.dll/VSe

    If this is unfamiliar, delete:
    O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk

    Continue removing:
    O16 - DPF: {10000000-0000-0000-0000-000000000000} - http://213.159.118.226/x.exe

    Dont recognize, delete:
    O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\system\intra
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In addition to what MA and I.M.O.G have already stated:

    Fix these with HijackThis:
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKCU\..\Run: [Lstt] C:\Documents and Settings\James O'Shaughnessy\Application Data\doai.exe

    Boot into safe mode and delete:
    C:\WINDOWS\System32\saristar.dll
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds