hi jack this log

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by 61300g, Nov 3, 2004.

  1. 61300g

    61300g Private E-2

    Would you please review my hi jack this log? I am running XP. I tried to fix the obvious intruders but I must be missing something because my home page remains hijacked and the evil-doers magically reappear in my log. Thanks in advance for your help.
    [log removed]
     
    Last edited by a moderator: Nov 3, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is the last step and we have rules about how and when to post a log.

    Please follow all the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HJT Version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. 61300g

    61300g Private E-2

    I'm really sorry for not following the required steps. My frustration got the best of me; it won't happen again. I had already tried spybot, spyware blaster, and adaware. I will follow your suggestions and try again before posting my hjt log.
     
  4. lschmidt

    lschmidt Private E-2

    Just Curious,how are you able to tell what a person has or has not done when
    they send you a HJT log?
     
  5. Kodo

    Kodo SNATCHSQUATCH

    experience and I wrote a program to scan the logs and feed me the info I need. :)

    we can also tell if they haven't done the scans because their registration won't show up in the log.
     
  6. 61300g

    61300g Private E-2

    OK, let's try this again. Here is my problem and what I have tried to do about it so far:
    I came home to discover that my IE home page had been hijacked and was now a porn site who's address starts with mk:MSITStore. Any attempt to go to another web site redirects me to a page called "heretofind".

    I disabled system restore and restarted in safe mode. I checked for "Network Security Service", "Workstation Netlogon Service", and "Remote Procedure Helper". None were found.

    I ran CCleaner, Ad-Aware, and Spybot. Ad-Aware came up clean but Spybot found 2 nasties listed as "Prolivation". I removed them both.

    Next I ran HSRemove which came up clean.

    I then ran a HJT scan and checked to fix the obvious nasties. They disappeared (temporarily).

    I restarted my computer and tried to enter IE. It came up "about blank". When I attempted to reset my home page I was hijacked back to MSITStore.

    Should I try one of the alternate scans listed in the tutorial or should I submit a HJT log?

    Thanks again for your time and help.
     
  7. 61300g

    61300g Private E-2

    Since my last post I have run Bitdefender and Trojan scan. Both came up clean.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said in message # 2:

    After doing ALL of the above if you still have a problem:

    Make sure you have HJT Version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  9. 61300g

    61300g Private E-2

    OK. I updated my HJT version and ran a new scan. Using the guide provided in your tutorial, I tried to fix the bad guys but everything still reappears.
    For some reason I am having trouble saving as a .txt file and uploading it under "manage attachments". I apologize for copying it here but I don't know what else to do.

     

    Attached Files:

    • hjt.txt
      File size:
      6.3 KB
      Views:
      4
    Last edited by a moderator: Nov 3, 2004
  10. PhilliePhan

    PhilliePhan Guest

    Hi 61300g,

    Please Extract HijackThis from the ZIP to its own folder C:\Program Files\HijackThis.

    Make sure System Restore is OFF and you have enabled the viewing of hidden files.

    Then check the boxes for the following:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=0&q=%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:mad:MSITStore:C:\spe\start.chm::/start.html#
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=0&q=%s
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:mad:MSITStore:C:\spe\start.chm::/start.html#
    O9 - Extra button: Corel Network monitor worker - {A4FB975F-7754-463B-BB6C-851218D57CBF} - (no file)
    O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {A4FB975F-7754-463B-BB6C-851218D57CBF} - (no file)
    O9 - Extra button: Corel Network monitor worker - {A4FB975F-7754-463B-BB6C-851218D57CBF} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {A4FB975F-7754-463B-BB6C-851218D57CBF} - (no file) (HKCU)
    O13 - DefaultPrefix: http://www.heretofind.com/show.php?id=0&q=
    O13 - WWW Prefix: http://www.heretofind.com/show.php?id=0&q=
    O13 - Home Prefix: http://www.heretofind.com/show.php?id=0&q=
    O13 - Mosaic Prefix: http://www.heretofind.com/show.php?id=0&q=
    O13 - Gopher Prefix: http://www.heretofind.com/show.php?id=0&q=


    Make sure ALL browser windows are Closed when you Click FIX.

    Now, boot into Safe Mode and use Windows Explorer to find and DELETE a folder labelled \spe. See above - C:\spe\start.chm::/start.html#

    Reboot to Normal Windows and attach a fresh log and tell us how things are working.

    I just gave your log a quick glance. I'm sure Chas will check back soon.

    Best,
    PP
     
  11. 61300g

    61300g Private E-2

    Thank you for the help. Here is the latest:
    I ran a new HiJack This and fixed the items that you listed. I tried to delete the spe folder but received an error message: "Cannot delete file: Cannot read from the source file or disk".
    I rebooted in normal mode and clicked on IE. The "about:blank" page was displayed. I went to tools and internet options and it did let me reset my homepage. What can I expect now?
     
  12. PhilliePhan

    PhilliePhan Guest

    Hi 61300g,

    If you are not able to delete that C:\spe, then your problem may return.

    Are things working any better now?
    Did you run CWShredder?

    If the problem should come back, try this tool: http://tools.zerosrealm.com/startchmfix.exe
    You may extract this one to the Desktop and run it from there. Note that IE and items in the system tray must be closed when you run this.

    I am not going to be around for a while, but I'm sure Chas will check back ;)

    PP
     
  13. 61300g

    61300g Private E-2

    My fingers are crossed and I'm knocking on wood, but so far things seem to be OK. I really appreciate the help. I've spent an entire day fighting this thing. Not my idea of fun.
    Thanks again.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounding good! You should probably post another HJT log attachment so we can make sure nothing came back or was missed.
     
  15. 61300g

    61300g Private E-2

    Will do. I'm a bit worried that the "corel network" items I fixed were involved with my new Epson printer. Oh well. I'll close this and pull up a new HJT log. Stay tuned...
     
  16. 61300g

    61300g Private E-2

    Here is my new HJT log. Just as a side note, my IE was working fine all day today but now when I open IE I get a "cannot find server" message. GRRR!


    INLINE LOG DELETED.
     
    Last edited by a moderator: Nov 4, 2004
  17. 61300g

    61300g Private E-2

    Correction; I am getting a "page cannot be displayed" message now when I open IE. For all the wonderful things these machines can do they still drive me nuts.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please stop posting your logs inline. We have asked you four times to post your HJT logs as an attachment. Whenever we request a log, they must always be posted as an attachment.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you install Kazaa? It was not here before? Kazaa is crap and should not be used. Even KazaaLite which you have is bad.
     
  20. 61300g

    61300g Private E-2

    I know about the HJT log issue. I'm not doing it to aggavate you, I just can't get it to save as a text file. Every time I try to post my log as an attachment I get an invalid file type message. I'm just barely able to use this infernal machine at all and I've spent two whole days trying to clean the *!!#*! thing up, so lighten up, OK?
    Kazaa has been here all along. My kids download it, I remove it, they re-download it, etc. I know that's where half the crap on my computer comes from. But you know that teenagers are way smarter than us doddering old adults.
    Thanks again for all of your time and help. I really do appreciate it.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not ask me to lighten up. Those are our processes that we expect everyone to follow. If you were having a problem uploading you should have mentioned it. Our directions tell you to save the log as a .txt file. You are saving it as a .log file which cannot be uploaded. So either save the file to a .txt file to begin with or rename the file so it ends with a .txt extension. Try saving it this way: when you click save log, change the Save as type: to All Files (*.*). Then change the File name: from the default hijackthis.log to hjt1.txt. And click save. Next time you need to use hjt2.txt and so on. You cannot upload the same filename multiple times (even if you try to do it in a different thread).

    Kazaa was not in your log in message number 11. Look for yourself. Did you create the logs from different user accounts each time. By the way, if you do have multiple user accounts, it is important to run the cleaning procedures on all of them.

    So try it now! Post a new HJT log as an attachment.
     
  22. Kodo

    Kodo SNATCHSQUATCH

    make sure when you try to post your log file that is does NOT have the extension of .LOG. it must have a .TXT extension or it will not upload.
     
  23. 61300g

    61300g Private E-2

    I'm sorry about the "lighten up" comment. I understand the importance of rules and procedures as well as anyone. Surely you must know that not all of us out here are computer experts and by the time we turn to you for help we are at peak levels of frustration. I did mention that I was having trouble uploading my log as an attachment seven messages ago. Instead of helping me with the instructions back then, you wait until now when we are both growing more impatient.
    Look, I'm not here to argue with you. I am here because I need your help (which I really do appreciate). I'm sure that you are forced to deal with ingrates, knuckleheads, and people who intentionally ignore the rules all day long. I apologize for adding to your aggravation levels. It was not my intent. I just need your help more than I need your scolding. If I must endure the scolding in order to receive the help then I am perfectly willing to do so. Fire away.
    Anyway, I am going to try the upload again, wish me luck:

    Again, I apologize for my short temper and I thank you very much for your help.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't truly consider it scolding, just an enforcement of our rules. And we only do it as necessary not for the heck of it. Literally hundreds of times we change the logs to attachments for people but that requires more work on our part. We are just getting too busy to keep doing that. But note this change: Kodo finally saw enough of these problems that users had in posting .log files (the default from HJT) and modified the allowable upload file types to include .log files. So this should result in fewer of these kinds of discussion result from frustration on both sides of the fence.

    I working on your log now. I'll be back in a little bit.
     
    Last edited: Nov 5, 2004
  25. 61300g

    61300g Private E-2

    Rules are good. I'm sure you waste way too much time correcting other peolpes' procedural errors when you could be doing more constructive work.
    As for the KaZaa thing, it realy has been on my computer this whole time and I believe that I was only using my own user account so I can't explain why it wasn't there and then was. I will take your advice and check all other user accounts.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only other problem (other than Kazaa) I see in your log that should be fixed is:
    O4 - HKLM\..\Run: [iframeworks.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\idmm.dat


    Questions:
    1) Did you install and then uninstall Yahoo Companion? The below file is missing. You should fix this line if you uninstalled it. Otherwise you may need to reinstall or copy the file from someplace else.
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_19_0.dll (file missing)

    2) Is there a reason you never ran the online scans from Symantec and TrendMicro that were given in the tutorial?


    Note, you really need get your updates from Microsoft. You are seriously out of date. You should at least get yourself updated to SP1 at a minimum.
     
  27. 61300g

    61300g Private E-2

    I will fix the other problem that you found in the HJT log.

    I didn't do anything with Yahoo Companion so I don't know what happened there. That is another program that my teenagers installed. I don't use it myself.

    I don't know how it happened but I totally missed the online scans you mentioned. I have since run the TrendMicro and came up clean.

    I thought that I had gotten some updates from Microsoft. I'll give it a try.

    Thanks again.
     
  28. 61300g

    61300g Private E-2

    While waiting I downloaded the Microsoft updates. Thanks for the heads-up.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install them? You needed quite a few updates which were going to be many megabytes in size.

    The only update I would not do until 100% clean, is to WinXP SP2
     
  30. 61300g

    61300g Private E-2

    There were 9 listed and I got them all.
     
  31. 61300g

    61300g Private E-2

    Oh by the way, I keep getting a low disk space warning bubble popping up at the bottom of the screen. Any ideas?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post a new HJT log as an attachment.

    For you diskspace problem, right click Start, select Explore, then right click the drive in question (I assume it is drive C) and then select Properties. It will show your free and used space. How much do you have for each?

    Did you run CCleaner?
     
  33. 61300g

    61300g Private E-2

    OK, I had run CCleaner and did a disk clean-up. I am showing 18.6GB used and only 2.71MB free. I guess it's time to start getting rid of some stuff.
    Here is the latest HJT log:
     

    Attached Files:

  34. 61300g

    61300g Private E-2

    I'm up to 5.36GB and still deleting
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have not installed the Microsoft Updates:
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000

    Go here: http://v4.windowsupdate.microsoft.com/en/default.asp

    And accept the MS certificate and then install the Update Software.
    After that is finished click Custom Install. It will scan for updates. You should look to see what updates are available for you. Just do not do SP2 yet. See if an SP1 update is offered.
    You may have to click on a Review other updates selection (or something like that).
     
  36. 61300g

    61300g Private E-2

    I went to the link you provided (which is the same page I went to before) and viewed my installation history. It showed 9 updates successfully installed today. I clicked on "Custom Install" (I had used "Express" before) and got an error message. I am working the resolution now. Stay tuned...
     
  37. 61300g

    61300g Private E-2

    Apparently, in order to use "Custom Install" I need to use a proxy server. I don't use a proxy server. While I was at the update site, a bubble popped up at the bottom of my screen telling me that updates were available. The only available update was SP2. I did not download it as per your instructions.
    The Microsoft update page does show the 9 updates I downloaded as successfully installed as of today. What's going on?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are the package numbers? Where any of them WinXP SP1? Or IE6 SP1?
     
  39. 61300g

    61300g Private E-2

    There is no mention of SP1. These were individual updates rather than a service pack. They were the only updates listed as being available.
    Critical Update for Windows XP (KB887882), Security Update for Windows XP (KB840987), (KB835732), (KB828741), 329834, 823559, MSXML 4.0, and Cumulative Security Update for IE6 (KB834707). There was also an update successfully installed 11/03/04 listed as Update for BITS 2.0 and WinHTTP 5.1 (KB842773).
    Is this helping at all?
    Just out of curiosity, how many threads are you helping at any given time? How many problems per day?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try going here to get IE SP1:
    http://www.microsoft.com/downloads/details.aspx?FamilyID=1e1550cb-5e5d-48f5-b02b-20b602228de6&displaylang=en

    What kind on connection do you have to the Internet? Dial-up, cable mode, dsl modem?

    The reason I ask is that these downloads are going to be big. Especially WinXP SP1a (when I find the link).
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It all depends on how busy things are. I'm in the middle of helping about 30 users since yesterday at this time. If you look back over the last 2 to 3 days, I probably have about 60 to 70 in progress threads.
     
  43. 61300g

    61300g Private E-2

    I don't know how you keep from getting burned out. You either really love doing this or you have the patience of a saint.
    I went to the link you gave me for SP1 and after following all of the instructions, I was told that the only update available is SP2.
    Should I give up and install the SP2?
     
  44. Kodo

    Kodo SNATCHSQUATCH

  45. 61300g

    61300g Private E-2

    Hey, that link worked great. I really appreciate the heads up on my need for the update. So, what's next?
     
  46. Kodo

    Kodo SNATCHSQUATCH

    get all the post SP1a hotfixes and then seriously consider the move to SP2

    http://v4.windowsupdate.microsoft.com

    If are 100% sure that your machine is clean then you can make the move to SP2, but make sure ALL of your drivers are up to date, all software that loads at startup is up to date and there are ZERO running programs including systray programs before you do it (yes, your antivirus too!!!). Don't forget to make a backup of ALL personal information just incase it doesn't go as planned.
     
  47. 61300g

    61300g Private E-2

    Will do. You guys are my heroes. I really and truely appreciate all the time, help, and advice. Without your help I would have fired several rounds of 12 gauge, #4 buckshot into this infernal machine.
    And to chaslang, sorry again for my short temper earlier. My anger was directed at this machine not at you. Thank you very much for your help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds