Hijacked browser when bad URL is typed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TristansPower, Sep 25, 2004.

  1. TristansPower

    TristansPower Private E-2

    Hello from Munich,

    I kind of have the same problem as hifriend2004. When I type in a bad URL, I get redirected to http://www.hitpointer.com/ssredir/de.html.

    I have run the latest versions of ad-aware, trend micro and norton anti-virus, but the problem still exists (and the scans don't give any results). Reading all the threads I see HijackThis is a program a lot of people use. However, I am not that experienced and don't want to ruin my computer.

    Can anybody help me or give me an advise what to do?

    Tristan
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  3. TristansPower

    TristansPower Private E-2

    Of course I am a good student and followed (most of) the instructions from the tutorial before I posted my thread:
    1) Completed
    2) I have a German OP-system. The filenames mentioned do not exist on
    my computer. However....translated I do have an idea which files it may
    be. My question....is the disabling a must or are there other options
    3) Did Ad-adware 3 times. No registry-infections
    CWShredder: according to the information, it referred to other sites than
    the site I become, but I may be mistaken.
    4) Did the scanning and cleaning steps from Trend Micro and Symantec.
    Deleted the temp files.

    However, I didn't do McAfee. Will try that then.
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Alright, then toss me a log file, will look at it as soon as I can.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This step is only necessary if you have the about:blank or home search hijack. Which it does not sound like you have from what you said thus far. Also I would expect that it does not matter what language your OS is in. I would expect that the hijackers always say the same thing. But I cannot be positive of that since I never saw a system where the OS is for another language.

    Questions:
    1) when we say use "services.msc" what do you use to get the service window to come up.
    2) Windows has a valid service name RpcSs which is Remote Procedure Call (RPC). What is this in your OS? I would expect the same filenames. The path to executable is: C:\WINDOWS\system32\svchost -k rpcss. (AGAIN NOTE THIS IS NOT A BAD PROCESS. I'M NOT SAYING TO SHUT IT DOWN. I'm just trying to learn if the services are actually listed differently in your system.
     
  6. TristansPower

    TristansPower Private E-2

    OK Chaslang and Major Attitude,

    Chaslang
    First...the Hijack only happens when a bad URL is typed or when I want to find additional information on the Microsoft site for autosearch or some other things like security. Futhermore I keep getting pop ups from Live Feeds (IP 204.177.92.193), eventhough the virus-scanners don't find any threats.

    To run service.msc I go to Start and then Ausführen (Run in german). I get all the file-names in German. The file you mentioned is called 'Remoteprozeduraufruf' (RPC).

    Major,
    I've read all the notes about the log-files. I do not want to trouble you unless it is really necessary.

    Tristan
     
  7. TristansPower

    TristansPower Private E-2

    But anyway, here's my logfile:
     

    Attached Files:

    Last edited by a moderator: Sep 26, 2004
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the German lesson Tristan. By the way in the future please attach HijackThis logs to your message. See how I have changed yours.

    Also you need to extract HijackThis from the ZIP file and put it into its own directory as indicated in the HijackThis tutorial. You will not get any backups the way you are running it.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have viewing of hidden files enabled and that system restore is disabled.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below process and End it:
    sysdpt.exe
    dluxde.exe
    jhqnmlgz.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F3 - REG:win.ini: run=c:\windows\system32\sysdpt.exe
    O2 - BHO: Saristar - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE50} - C:\WINDOWS\System32\saristar.dll
    O4 - HKLM\..\Run: [DLuxde] c:\program files\dialers\dluxde\dluxde.exe /nocomm
    O4 - HKLM\..\Run: [Sysdpt] c:\windows\system32\sysdpt.exe
    O4 - HKLM\..\Run: [JHQNMLGZ] c:\windows\system32\jhqnmlgz.exe /install
    O4 - HKCU\..\Run: [Unldr16] c:\windows\system32\unldr16.exe
    O4 - HKCU\..\Run: [Dlldmt] c:\windows\system32\dlldmt.exe
    O4 - HKCU\..\Run: [Sysdpt] c:\windows\system32\sysdpt.exe
    O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://217.73.66.1/minidialler/mddl...006_geopro_.exe
    O16 - DPF: {D909E944-3A96-4280-9983-9D00001973A4} (Access Control) - http://www.browserplugin.com/plugin...ess_special.ocx

    Normally I would boot in safe mode and delete these problem files but for now I'm going to have your just rename some of them (and delete others I'm sure must be deleted) to make sure they are not needed for anything. So boot in safe mode and do what I say for each of the below files. USe Windows Explorer

    C:\WINDOWS\System32\saristar.dll <--- delete this one
    C:\windows\system32\sysdpt.exe <--- rename to sysdpt.bad
    C:\program files\dialers\dluxde\dluxde.exe <--- rename to dluxde.bad
    C:\windows\system32\jhqnmlgz.exe <--- rename to jhqnmlgz.bad
    c:\windows\system32\unldr16.exe <--- rename to unldr16.bad
    c:\windows\system32\dlldmt.exe <--- rename to dlldmt.bad

    Now boot in normal mode and post a new HJT log attachment and tell me how things are working.
    After a couple days if everything seems okay, I would delete those files we renamed and then enable system restore again.
     
  10. TristansPower

    TristansPower Private E-2

    Hello back from Germany,

    OK, followed the instructions and thankfully got rid off the pop-up of naughty girls in dirty poses. However, when I type a bad URL, I still get redirected to http://www.hitpointer.com/ssredir/de.html. I ran the usual antivirus/-adaware programs, but no results.

    Enclosed the current logfile after 'Hijack this'. Can it be that I have to change something in the registry manually?

    Greetings.

    Tristan
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure system restore is disabled and viewing of hidden files is enabled as mentioned in the tutorials.

    These two processes running look to be bad to me:
    unldrexe.exe
    ugjpyezq.exe
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find those processes and End them.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F3 - REG:win.ini: run=c:\windows\system32\unldrexe.exe
    O4 - HKLM\..\Run: [UGJPYEZQ] c:\windows\system32\ugjpyezq.exe /install
    O4 - HKLM\..\Run: [Unldrexe] c:\windows\system32\unldrexe.exe
    O4 - HKCU\..\Run: [Cmt101] c:\windows\system32\cmt101.exe
    O4 - HKCU\..\Run: [Unldrexe] c:\windows\system32\unldrexe.exe

    Boot in safe mode and delete:
    C:\windows\system32\unldrexe.exe
    C:\windows\system32\ugjpyezq.exe
    c:\windows\system32\cmt101.exe

    Reboot normal and post a new log and tell me how things look.
     
  12. TristansPower

    TristansPower Private E-2

    Hello Chaslang,

    Followed your instructions, but the problem with the redirect still exists.

    New log attached.

    Schöne Grüssen

    Tristan
     

    Attached Files:

  13. Kodo

    Kodo SNATCHSQUATCH

    these are possibly a trojan

    in safe mode:

    Run HijackThis and select the following lines

    C:\windows\system32\cmx32.exe
    F3 - REG:win.ini: run=c:\windows\system32\cmx32.exe
    O4 - HKLM\..\Run: [Cmx32] c:\windows\system32\cmx32.exe
    O4 - HKCU\..\Run: [Cmx32] c:\windows\system32\cmx32.exe

    then try to find the file and delete it manually.

    Then run

    Peperfix
    http://tools.zerosrealm.com/PeperFix.exe

    then run A-squared again.

    post a new log.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like unldrexe.exe mutated to cmx32.exe. We may get a similar result again. There could be something else hiding somewhere.
     
  15. Kodo

    Kodo SNATCHSQUATCH

    that it does.. guess we wait for a new log and do some searchin'
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Maybe A2 will pick something up. The items that look like PepeTrojans keep occurring too.
     
  17. TristansPower

    TristansPower Private E-2

    First of all, I want to thank you (Chaslang and Kodo) very much for your help. It is amazing you are trying to help all these people around the world.

    Anyway, here is a slightly stupid question (yes I am blond):
    I assume I download A-square and Peperfix and run the *.exe-files when finished (no unzipping or something). I am asking this, because I made the mistake of unzipping "Hijackthis" the wrong way.

    Grüssen

    Tristan
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bitte schoen (I don't have an umlout on my keyboard. :) )

    Yes download them and run them. But for A2 you will need to connect to them and give them a valid email address to get a key. It is free. A2 needs to be installed whereas the peperfix.exe file is merely run.
     
  19. TristansPower

    TristansPower Private E-2

    Hello guys,

    I am back. Followed the instructions:
    1) In safe mode, Hijackthis only found 04-HKLM\..\Run: <cmx32>
    2) I ran Peperfix and A2. Peperfix found nothing, A2 1 Trojan in the back
    up of Hijackthis
    3) I can't find the file C:\system32\cmx32.exe (but I also couldn't find
    the earlier mentioned files in the replies and I did select the option 'show
    all files')
    4) When rebooted in the normal mode, the F3-reg and 04-HKCU showed up
    in Hijackthis (so I fixed them, because I couldn't find them earlier)
    5) When typed the bad URL, I still get redirected.

    I hope you can find some extra clues. I made a log-file after Safe mode and
    after reboot (so 2 files attached)

    Schöne Grüssen (love the german keyboard)

    Tristan
     

    Attached Files:

  20. Kodo

    Kodo SNATCHSQUATCH

    for chas

    why would he have this
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

    if he has an nvidia card? eh? sounds suspicious..
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good question Kodo!

    Tristan,
    Did you have an ATI Video Card in here at one time?

    Also, do you know what this line is for or from:
    O18 - Filter: text/html - {5E64FD1E-A390-4D8D-BF28-BD115145BCF1} - C:\Dokumente und Einstellungen\John\Lokale Einstellungen\Anwendungsdaten\microsoft\internet explorer\V0.26.dat
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note the F3 line is gone. Perhaps A2 also fixed this. But the other trojan has changed names again.
    O4 - HKLM\..\Run: [MYZHANLO] c:\windows\system32\myzhanlo.exe /install

    Tristan,
    I have a feeling these may be changing names at each reboot making each time we tell you to fix something uesless since it will not be there the next time you come back. When you come back see if this process is running:
    C:\windows\system32\myzhanlo.exe

    If so, end it with Task Manager. FIx the O4 line in HJT with that filename on it. And then try to delete the the file using Windows Explorer.

    Earlier you said you had "Show all file" enabled. To me that does not mean the same thing as doing the below:
    Click Start.
    Open My Computer.
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.
    Click OK.
     
  23. TristansPower

    TristansPower Private E-2

    Hello Kodo and Chaslang,

    To answer your questions:
    1) ATI Video Card: Bought this computer in May 2004 and never had another videocard/installed another card. However, I did change modems (had an internal DSL/ISDN-modem, which made the computer freeze up).
    2) File: I haven' got any idea what O18 - Filter: text/html - {5E64FD1E-A390-4D8D-BF28-BD115145BCF1} - C:\Dokumente und Einstellungen\John\Lokale Einstellungen\Anwendungsdaten\microsoft\internet explorer\V0.26.dat is for or from
    3) Show hidden files. I am pretty sure I checked 'Show hidden files and folders' and 'Uncheck the Hide extensions for known file types'. Am not sure I also did the Uncheck the Hide protected operating system files'. Will check on that when I am back from work.

    Grüssen

    Tristan
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you also have a built in graphics display (in particular Nvidia) on the mother board? The reason we are asking this is that we also so a file in your processes that relates to an Nvidia card. The file is C:\WINDOWS\System32\nvsvc32.exe If you do not have a built-in Nvidia card then this file would have to be suspect as being possible something bad. Try right clicking on it (from Windows Explorer) and select Properties and then the Version tab and go thru the item name list and get version and company info etc.

    Did you get the O4 line fixed?

    Fix that O18 line too!
     
  25. TristansPower

    TristansPower Private E-2

    Grüss Gott,

    OK, here are the results of my investigion:
    Nvidia-thing: This is the information from the properties:
    Name nvsvc32.exe
    Description NVIDIA Driver Helper Service, Version 45.23
    Created Monday, July 28, 2003, 3:19:00 PM
    Version 6.14.10.4523
    Copyright (C) NVIDIA Corporation. All rights reserved.
    Firm NVIDIA Corporation

    O4-thing: Of course <Myzhanlo> is gone (the file and it doesn't run anymore in taskmanager). However, I think a new one appeared (xghytuyj)

    Attached the results of hijackthis and information about the above mentioned file.

    Tristan
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tristan,

    Ooooh! "Greetings God?"

    It does not look like you had HJT fix the below line, please do so:
    O18 - Filter: text/html - {5E64FD1E-A390-4D8D-BF28-BD115145BCF1} - C:\Dokumente und Einstellungen\John\Lokale Einstellungen\Anwendungsdaten\microsoft\internet explorer\V0.26.dat

    Also fix the below line with HJT:
    O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab


    Please rename the nvsvc32.exe file to nvsvc32.badexe.

    Also, go back and delete the file we renamed awhile ago (we ranamed them to .bad files):
    C:\windows\system32\sysdpt.exe <--- rename to sysdpt.bad
    C:\program files\dialers\dluxde\dluxde.exe <--- rename to dluxde.bad
    C:\windows\system32\jhqnmlgz.exe <--- rename to jhqnmlgz.bad
    c:\windows\system32\unldr16.exe <--- rename to unldr16.bad
    c:\windows\system32\dlldmt.exe <--- rename to dlldmt.bad

    Run A2 again a let me know if and what it finds.

    For that xghytuyj.exe file please click the Version tab and see what information can be found there by clicking on each of the item name fields.

    And do you have an Agere Modem. If so, that will explain the existence of AGRSMMSG.exe;

    agrsmmsg.exe is the SoftModem Messaging Applet for your AMR modem.
    Author: Agere Systems Inc.
    Part Of: AMR modem drivers
     
    Last edited: Oct 6, 2004
  27. TristansPower

    TristansPower Private E-2

    Chaslang, I've you (and Kodo) are able to solve the redirect-problems, you are gods to me.

    Anyway,

    Strangely enough the file xghytuyj.exe disappeared (in system32 and taskmanager), but a new one appeared: dvsvbeve.exe. Apart from the versionnr, everything else is blank. And I didn't even turn off the computer!

    Enclosed the new log-file and info about dvsvbeve.

    Futhermore, I will follow your instructions/run A2 next week, since I am going on a short trip to Athens.

    Finally,

    1) I did fix the O18-filter.
    2) Modem: I don't know if I have an Agere modem, but it is an external dsl-modem from German Telecom, that didn't need any software (it is connected to the ethernetcard). Can the files be from the old modem?

    Tristan
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tristan,

    Did you try clicking on the Elementname: fields (under the version tab) for dvsvbeve.exe to see if anymore info showed?

    Kodo and I have been talking about this problem and we have two ideas. One I'm going to have you try now, the other Kodo will leave a message about later. If what I have you do in this message does not work then just move on to Kodo's message (when available).

    You have to print this instructions or save them locally to a file because it is very important that you disconnect physically from the Internet (that means unplug the ethernet cable from between your DSL modem and your PC - either end is okay). This way no process that may be hiding in the background can sneak out to get information or download anything while we try to fix the problem. The next important step is that you must shut down all Internet Explorer (IE) sessions before continuing and do not run IE again until I ask yo to do so. Make sure you do not run anything else put what I ask you to run. In other words, basically only run HijackThis and Windows Explorer.

    1) Make sure your ethernet cable is disconnected and all IE sessions are closed.
    2) run Task Manager and right click on the dvsvbeve.exe process and select end process tree.
    3) run HijackThis and have it fix the below line:
    O4 - HKLM\..\Run: [DVSVBEVE] c:\windows\system32\dvsvbeve.exe /install
    4) see if you can delete c:\windows\system32\dvsvbeve.exe (tell me the results of this step). If it does not delete right now in normal boot mode then boot into safe mode and repeat steps 1 to 4 in safe mode (let me know if this was necessary).
    5) After getting the file deleted, imediately get a new HJT log (hjt1.txt).
    6) Now reboot again into normal mode and get a second HJT log (hjt2.txt).
    7) Now connect your ethernet cable back to your PC.
    8) Open one IE session (do not surf anywhere) and then close it.
    9) Get another HJT log (hjt3.txt).
    10) Now run IE again and come back here and post the 3 HJT logs and tell me how the steps went especially step 4.
     
  29. Kodo

    Kodo SNATCHSQUATCH

    Ok,
    If Chas' instructions don't do the trick I would like you to repeat his steps 1 and 2. Then after you end the trojans process, I want you load up A-squared and leave it open. Next I want you to end task EXPLORER.. yes, go ahead. You'll lose your desktop temporarily but A-squared will still remain up. Close the taskmanager and scan your PC with A2. Once you're done, hit CTRL+SHIFT+ESC to bring the task window back up. Go to file , new task and type in Explorer.exe , then load up HJT and post a new log.
     
  30. TristansPower

    TristansPower Private E-2

    Hello,

    like I said, I will do it after the weekend, but the name changed again. Apart from which version and language (English (Australia)), everything else is blank.

    Tristan
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Guten Tag Tristen! Your up early and I'm up way too late. :eek:

    Just substitute in the new name. Should be easy enough to recognize now. Let us know how it works out.
     
  32. TristansPower

    TristansPower Private E-2

    Hello Kodo and Chaslang,

    Enclosed, you'll find the 3 logs. Since there is a max of 3, the 3rd one is in the next reply.

    I followed the instructions. Of course the name DVSVBEVE didn't exist anymore. It was now something like ZGFX....I was able to delete the file in normal mode (so I didn't do anything in safe mode).

    As you may have guessed, I wanted to see if the problem was solved and typed a bad URL and.........NO REDIRECTION HAPPENED!!! I got the MSN search site. No sex-things!!!

    I am extremely thankful to the both of you. I owe you big time!

    Greetings from Munich.

    Tristan
     

    Attached Files:

  33. TristansPower

    TristansPower Private E-2

    And here is the 3rd log

    Tristan
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like we finally go this one fixed! Good job Tristan!
     
  35. TristansPower

    TristansPower Private E-2

    Chaslang/Kodo,

    Like I said before, without your input, I would have been trapped in a world of dirty girls and porn sites forever. Now the sun shines again in my peaceful and happy little computerland. I will have the people build you a little temple and you'll be worshipped for eternity (or until the next virus/trojan/worm threatens their lives). ;) :)

    Tristan
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! And we appreciate the praise! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds