Hijack This Log- Help Eliminating Spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BlackCat, Aug 30, 2004.

  1. BlackCat

    BlackCat Private E-2

    The previous recommendations to delete a pesky invader which randomly opens up pop-ups when connected to the internet have failed, so I'm posting my Hijack This log. Some of the names the program goes by are QwyRa, XfyH, CzidS, Iel277g, YnuX, and VpfJE.
     

    Attached Files:

    • log.txt
      File size:
      2.5 KB
      Views:
      7
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I hope you have up to date anti-virus. I am not sure how Chaslang does this now, but my successes have been by going into safe mode and deleting the files you know are bad. Since you say anti-virus and trojan scanning found nothing, we have to go manual.

    AVG and most anti-virus programs should notify you if you go to the c:\Windows\system32\ folder with windows explorer. As you said, examples of these, and the only fishy ones I see are:

    C:\WINDOWS\System32\QwyRa.exe
    C:\WINDOWS\System32\XfyH.exe

    So, try browsing the Windows\system32 folder and see if your antivurus tags files and write them down in case there are more. Hidden files should be enabled per step 4 of the tutorial. You need to exact file names so you dont delete anything by mistake.

    Boot into safe mode and delete the files you know are bad.

    Still in safe mode... look to see if they are running in startup. Getting a startup tool from our admin section like StartupCPL would be helpful, otherwise, go to Start, run and type in msconfig and head to the startup tab.

    Still in safe mode.... Hijack This delete:

    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Wjdi.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

    What is Spyware stormer? Get rid of it, never heard of it. While your at it, check add\remove programs for anything else like Web Rebates... Hell, check it for anything suspicious, web rebates, shopping, porn sounding crap, whatever you may not have installed.

    Still removing:
    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com/files2/Install.cab

    Cross your fingers, pray if appropriate, reboot and shout back at us so we know how it went.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They failed because you never completed doing what you were supposed to do in the thread you already started on this problem. http://forums.majorgeeks.com/showthread.php?t=40598

    You had additional items to complete that you said you started. You never came back with results. Also I had request a few other steps to be done and then to follow up with a HJT log in that thread. A new thread was not necessary we were getting there. You just never completed what you had started and never did what I asked.

    I was not looking for a new thread to be posted by you, I was looking for one I already had been working in. Thus, I never saw this thread which I would have deleted with a message telling you to stay in your previous thread. Had MA not answered you already, I still would have deleted it.
     
    Last edited: Aug 31, 2004
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Never saw it bro, sorry. Maybe my steps will help hopefully.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem. And yes they will, if system restore is still disabled and the problem files should also be deleted while in safe mode.

    Also should look in Add/Remove programs for Web_Rebates to see if it can be uninstalled.

    I was getting there in the other thread. I was just working thru the process first and as I said there were things still not completed and I asked for an HJT log too.
     
  6. BlackCat

    BlackCat Private E-2

    Sorry, for some odd reason I misread and thought you said make another thread. I did everything you requested, so I posted the new topic because the additional steps did not help. There's no need to get flustered, it was just a mistake. I will try MA's steps and report my results.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No one got flustered! You just left me hanging in the other thread. But lesson to be learned....once you start a thread for a particular problem stay within that thread (no matter how long it takes) until the problem is resolved. New problem, new thread. Same problem, same thread.

    Okay! So complete those steps MA gave you and post your HJT log (as an attachment).
     
  8. BlackCat

    BlackCat Private E-2

    I found all of the appropriate programs in the Windows/system32 folder as hidden and deleted them, and that seems to have done the trick.

    Thanks for the great help, and my apoligies about the confusion again, chaslang.
     
  9. BlackCat

    BlackCat Private E-2

    Alright, here's my new Hijack This log.
     

    Attached Files:

    • log.txt
      File size:
      1.8 KB
      Views:
      2
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Your log looks clean! You should now work on getting your system updated. Your WinXP is not updated (at least get to SP1) and IE is old too. You really should try to get the Critical Updates (called High Priority now).

    Also you should get rid of the unsupported MS Java and switch to Sun Java. See this thread:
    http://forums.majorgeeks.com/showthread.php?t=25834
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait I have a question and I missed one:

    What is NetSurf? ----> C:\Program Files\Internet CD\Netsurf.exe
    I think I have seen it sometimes related to Optimum Online.


    Fix the below line with HJT:
    O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
     
  12. BlackCat

    BlackCat Private E-2

    I deleted O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binari...thv32_EN_XP.cab.

    NetSurf is the program I downloaded from my internet provider's installation disk. It's a window where you can connect, check e-mail, change settings, etc.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now check out the other stuff I gave you on Java and Windows Updates!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds