Hijacked again????

Discussion in 'Malware Help (A Specialist Will Reply)' started by mneenee, Feb 2, 2007.

  1. mneenee

    mneenee Corporal

    Well hello again I'm back lol.

    Well here is my problem after fixing computer last week (thanks TimW) I am having problems again. I noticed a redirect in ie7. Computer is super slow on start up, All the scans found nothing but I have noticed a few strange findings in HJT. Maybe I am just being paranoid but something isn't right!! Was looking at:

    R1 etc.
    RO etc.
    O3-Toolbar etc.
    O11-Options Group etc.

    Also thought I should mention that my CD burner isn't burning anymore it worked fine last week now when I burn a cd it says it is burning spits the disk out when done then when trying to play the disk it shows a blank cd and then the cd isnt writable anymore. Could this be related or hardware problem??
    Please let me know what you think Thanks

    Mneenee
     

    Attached Files:

  2. mneenee

    mneenee Corporal

    Other logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing anything in your logs that would be malware.

    You do have two anti-virus programs running:
    "Panda ActiveScan Pro"
    "Panda ActiveScan"
    "AVG Free Edition"
    You should only have one.

    Have you looked at what is loading at startup thru msconfig?
     
  4. mneenee

    mneenee Corporal

    Looked in msconfig and yes there are 2 entries that are just a bunch of symbols that look like japanese writing then HKCU\Software Microsoft\Windows NT\Current.... Cant see the rest???? What is this? Thanks

    Mneenee
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    "The Windows NT subkey stores configuration data for components of Windows 2000. The subkeys of the Windows NT subkey represent versions of the operating system, such as CurrentVersion, which refers to the version currently running on the computer. Each version subkey contains subkeys representing components that run on that version of the system.The Windows NT subkey in HKEY_CURRENT_USER stores entries that apply only to the current user of the computer. The SOFTWARE\Microsoft\Windows NT subkey in HKEY_LOCAL_MACHINE stores entries that apply to all users of the computer."



    You would need to give me some more info. What exactly are the two items in the startup?
    Where is this HKCU item that you are referring to?
     
  6. mneenee

    mneenee Corporal

    in msconfig under the start up tab at the bottom of the list under start up items it says "symbols" then under command more "symbols" and under location it says HKCU|SOFTWARE\Microsoft\Windows NT\CurrentVersion... and i cant see the rest of it is there another way to see the whole location?

    Thanks

    Mneenee
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Slide the "Location" header to the right to show the command ....I'm thinking that this has something to do with your language settings. You can disable it and see if you have any problems.
     
  8. mneenee

    mneenee Corporal

    ok why for one would something from windows 2000 be loading on start up as i am running xp home? And # 2 it wont let me slide the header over grrrconfused

    Mneenee
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    T'was just a definition of the key ...xp is built on the NT platform (win2000).

    I really think this is not malware ...you should try posting in the software section.

    Did you disable the item (s) and does your startup run faster?
     
  10. mneenee

    mneenee Corporal

    nope just gonna do that and see what happens

    Thanks again if it doesn't work will post in software.

    mneenee
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'll be looking for it.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you are on the Startup tab, you will see three column labels.
    1. Startup Item
    2. Command
    3. Location
    To see more of what is showing in any column, use the below procedure:
    • If you put your mouse cursor on the column label bar you should be able to highlight the vertical bar ( | ) to the left of the Location title.
    • Your cursor will change to something like <--|-->
    • Once you see this, left click and dragged the mouse to the left so that you can see more of what is in the Location column.
    • This will basically hide the Command column.
    • If this is still not enough to see what you want, Undo this so you can see the Command column and the vertical bar in front of it.
    • Then drag the Command column to the left to hide the Startup Item column.
    • Now again drag the Location column to the left to hide the Command column.
    • Now the whole screen is showing the Location column information.
    • Tell us exactly what you see here on the lines in question.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tim,

    I do see some issues in the GetRunKey log:

    The first is malware and needs to be removed. Including the folder too. In fact to be exact, the below folder and also one from Morpheus must be deleted:
    C:\Program Files\Morpheus Upgrades
    C:\Program Files\Common Files\{3871D914-087B-1033-0318-040805030002}

    The next two, we need to question whether mneenee set these!
    The second setting prevents the system from conducting a comprehensive search of the target drive to resolve a shortcut.
    The third I thought was a Vista setting used to disable User Account Control In Vista. I'm not sure what it does to XP.
     
  14. mneenee

    mneenee Corporal

    ok deleted the first registry entry as well as the 2 folders.

    How do i tell if i set these other 2 entries? As far as vista goes not sure why it would be on here.

    I noticed that in advanced windows care under start up items there are 2 ctfmon.exe This program is for office xp right? I dont have office xp would it be okay to disable it? I know that it can also be a form of malware. Waiting for instructions on what to do about the other 2 registry items. Thanks

    P.S. I should also mention that windows firewall cannot be started ? Someone here told me to ignore it though as I have zone alarm but since you mentioned disabling stuff thought i should mention it.
    Mneenee
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  16. mneenee

    mneenee Corporal

    Ok not gonna worry about ctfmon.exe However will it hurt to change these registry entries back to 0? Not sure what to do now :eek: I guess I'm asking if I change these keys will it hurt anything Oh and before i forget what about these annoying Symbol start up items that i cant get rid of??? I cant boot in normal start up mode is there a fix?
    Thanks so much for everything:) .

    Mneenee
     
    Last edited: Feb 2, 2007
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Always set a system restore point before making changes in the registry. No, I don't think it will be a problem changing them to 0.

    Could you tell us exactly what it is showing in msconfig ....if you can't reproduce the "symbols" ...could you attach a screen shot?
     
  18. mneenee

    mneenee Corporal

    K have attatched a screenshot of msconfig now you can see the full path which is where I found them when working with adryn in software. I think the big problem here is that the HKCU isn't in front of the location anymore.
    Gonna set a restore point and change those values to 0. God I hope this works lol wish me luck.

    K reset those values, didn't change much as I can tell I decided to see how long it took my desktop and system tray to load and it took over 3 mins. Thats nuts!!! Also noticed that my desktop icons load very last now before they loaded first? Anyhow...


    Mneenee
     

    Attached Files:

    Last edited: Feb 3, 2007
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the &quot;Save as&quot; type is set to &quot;all files&quot; Once you have saved it double click it and allow it to merge with the registry.
    How does it look now? See if you can set MSconfig to Normal Startup now. If so, attach a new HJT log.
     
  20. mneenee

    mneenee Corporal

    Ok did what you said. One of the Start up items is now enabled again but the other still isn't. found the registry key for it and it is symbols as well. Still cant start up in normal mode due to the other symbol not being found. HJT found it as well it is the F3 line. Will attatch another screenshot of msconfig and HJT. I also exported and zipped up the reg info for you to see if you want it. Waiting on instructions of what to do next. Thanks again

    Mneenee

    P.S. Do you know what these symbols are? Just curious as I have never seen anything like this beforeconfused .
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try it a different way!


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    When you apply this registry patch, make sure you get a success message. Tell me what happens.
     
  22. mneenee

    mneenee Corporal

    K did what you said and it said it merged successfully. It fixed the one path but still doesn't find the other one and am still in selective start up. Wasn't sure if you were aware that I was also in the Software forum and I fixed some things in HJTwith adryn they were:

    F3 - REG:win.ini: load=????
    F3 - REG:win.ini: run=????
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe


    After fixing these 3 things is when the other 2 new startups appeared and I couldn't reenable these last ones. Hope this helps maybe it is the run path we need but what do I know lol just trying to learn attatching another screenshot of msconfig. Thanks

    Mneenee
     

    Attached Files:

  23. mneenee

    mneenee Corporal

    Sorry thats not right after disabling the original 2 symbols in start up, after restarting, the other 2 showed up. Then HJT showed the F lines so we fixed them. This fixed the 2 new start ups but not these last ones. Sorry for any confusion.

    Mneenee
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please don't do anything other than what I ask you to do. That includes running HijackThis. Based on your snapshot, I don't think you even have a valid Windows registry key. It is showing as starting with SOFTWARE and not as starting with one of the base key entries like HKCU or HKLM....etc. I suspect that is why we are not finding the key.



    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!
    • Run Registrar Lite
    • when it opens look in the left window pane. Here is what you should see from top to bottom

    Is this what you see? I guessing that you may see an entry that looks like + SOFTWARE

    Note: If you see a + sign in front of Registry click it so it becomes expanded and shows a - sign.
     
  25. mneenee

    mneenee Corporal

    Okay first of all I ran registrar and it looks exactly like you said

    - Registry
    + HKEY_CLASSES_ROOT
    + HKEY_CURRENT_CONFIG
    + HKEY_CURRENT_USER
    + HKEY_LOCAL_MACHINE
    + HKEY_USERS

    but no +SOFTWARE

    I think you misunderstood me in my last 2 posts. The HJT things that I fixed earlier were before you were helping me and I was in sotware. I was just letting you know because the start up programs had HKCU in front of them before Tim told me to try to disable them here in post #7.

    After disabling them, the HKCU disappeared and 2 new start ups appeared enabled with the other 2 disabled for a total of 4 "symbol" start ups 2 with HKCU in front of them and 2 "now" without.

    That is when we found the new F3 entries in HJT, Adryn advised me to remove the new 2 starups as well as another line in HJT, which, got rid of the 2 new ones but left the old without HKCU in front.

    Now after we did the steps in post #19 it put the HKCU back in front of the first Symbol startup but not the second (refer to screenshots in post #18 without HKCU) then( #22 with HKCU).

    Then when doing the steps in post #21 it deleted that start up leaving me with only 1 symbol startup and still no HKCU in front of it which is why I was thinking that it could be the run line as the 2 I got rid of with adryn were "load" and "run" lines Whew.

    So again sorry for any confusion I really appreciate the help.

    Mneenee
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try one more patch.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    If you still see any strange startups that cannot be selected in MSconfig, use the below utility to see if you can clean them up:

    MSConfig Cleanup


    Attach another reginfo.zip file (but a new one) like you did in message # 20

    Also attach a new HJT log and a new log from GetRunKey.
     
  27. mneenee

    mneenee Corporal

    ok tried the fixme no luck but msconfig cleanup seemed to do the job woohooo thank you:D , thank you:D , thank you:D . Am attaching the files you requested.

    Mneenee
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  29. mneenee

    mneenee Corporal

    Thanks again Chaslang. Enjoy the Super Bowl!!!

    Mneenee
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks! I just hope it's a good game! How is the weather up there in iceland? ;)
     
  31. mneenee

    mneenee Corporal

    It's not quite Iceland LOL. But the weather has been pretty chilly just mellowed out today about 0 today yesterday about -12 Celcius or so. But the igloo's keep us pretty warm LOL. Have a good one

    Mneenee
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    :D :D
    You too. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds