Hijacked by C2 Media Ltd

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lina, Oct 5, 2004.

  1. lina

    lina Private E-2

    Please help!!!! My Internet Explorer have been hijacked. I mistakingly downloaded this malicious program responding to the buble in my tray, which was saying that I need to update my Windows. Stupid me, I believed them!
    I performed everything that you listed in your DO NOT POST UNTIL YOU HAVE READ THIS: How to: Spyware, Trojan And Virus Removal. The only thing that I didn't do was a safe mode. I am not very familiar with the PC details and was scared by the message I've got.
    Unfortunately I wasn't able to get rid of the problem. My last resource is probably Hijack This, but I need a guidance. Please, please help me. I have WindowsXP and my Internet provider is Verizon DSL. I'll appreciate any help.
     
  2. jarcher

    jarcher I can't handle a title

    and what message was that?

    one thing you do need to do is do it in safe mode and complete the "how to"
    that may take care of anything that wasn't taken care of in normal mode
    it is an important step in the procedure


     
  3. lina

    lina Private E-2

    I ran all the scans in safe mode. Didn't help. My Internet Explorer browser is still hijacked. should I try to run HJT?
     
  4. jarcher

    jarcher I can't handle a title

    go ahead
    as long as it is in its own folder and not on the desktop
    make sure you close any running applications you don't need
    and post your HJT log as a .txt file
     
  5. lina

    lina Private E-2

    jarcher, attached please find my HJT log. thanks for help in advance.
     

    Attached Files:

  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I see the hijack as well as a Trojan for starters, I would really try for safe mode and some scans again if you can. The reason being is Windows can not, for security reasons, delete a file in use. In safe mode, these files that cause the problems are not loaded, so they can be deleted. There are some really tricky lines in here too, so this may require you getting to safe mode to resolve this... Anyhow, lets dive in:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.traffer.ru
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://start.traffer.ru
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ucfbbdwxjufmvj.com/kobdyOEsjhQlsoUNmtT0dKJJ8YjJXKM7HFxb1sQ0_oU.cgi
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.uygbulbxggnhokbnyuy.com/...pCc3eyoZzdvemoXcHN0PrB_NPCDjsPL4KDiISLwR5.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
    R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\JUSearch\SearchEnh1.dll
    O2 - BHO: (no name) - {896F405C-571A-345F-BB3F-E824E571228C} - C:\PROGRA~1\SETUPM~1\meowplus.exe
    O2 - BHO: (no name) - {D2ACB5FA-CAC4-3007-ED06-F3C221A4BA40} - C:\PROGRA~1\SETUPM~1\meowplus.exe
    O4 - HKLM\..\Run: [DVD VIEW SOFT DOWNLOAD] C:\Documents and Settings\All Users\Application Data\SetupDefyDvdView\delete cast.exe
    O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\twink64.exe internat.dll,LoadKeyboardProfile
    O4 - HKLM\..\Run: [LONGBOWSBARBOWNS] C:\Documents and Settings\All
    Users\Application Data\Boldwarnlongbows\TRAYMANAGER.exe
    O4 - HKCU\..\Run: [spc_w] "C:\Program Files\JUSearch\hcm.exe" -w

    Not sure, if you dont recognize Bash City, remove it:
    O4 - HKLM\..\Run: [Bash City] C:\PROGRA~1\KNOBDA~1\FILETRANSSIGN.exe

    O15 - Trusted Zone: *.searchmeup.cc
    O15 - Trusted Zone: *.searchmiracle.com
     
  7. jarcher

    jarcher I can't handle a title

    never mind
    MA is here
    this may be removed
     
    Last edited: Oct 10, 2004
  8. lina

    lina Private E-2

    So, if I understood you correctly, here is what I need to do now:
    1. Close all applications.
    2. Disable Norton Antivirus, which is running on the background.
    3. Restart in safe mode.
    4. Run HJT again and make it fix the files listed in Administrator's emai message.
    What scans would you recommend me to re-run, since I already ran most of them in the safe mode before my first HJT scan?
    Thanks.
    lina
     
  9. lina

    lina Private E-2

    I fixed what you suggested me to fix. I am attaching the new log.
    I opened the Internet Explorer and the message said that the page couldn't be found. Also here is what appeared in the the address window of the browser:
    http://www.ucfbbdwxjufmvj.com/kobdyOEsjhQlsoUNmtT0dKJJ8YjJXKM7HFxb1sQ0_oU.cgi

    Does it mean that we achieved our goal?

    Also I ran again CCleaner in Safe mode before HJT scan. So the log should reflect it.
    Thanks.
    lina
     

    Attached Files:

  10. jarcher

    jarcher I can't handle a title


    you could run all of them, actually
    won't hurt anything, really
     
  11. lina

    lina Private E-2

    Just sent my new log.
    Thank you, jarcher.
    lina
     
  12. lina

    lina Private E-2

    jarcher!!! I just opened Internet Explorer and the thing is still there:
    http://search200.com/
    and all 9 yards of it.... Nothing helped yet?
     
  13. jarcher

    jarcher I can't handle a title

  14. lina

    lina Private E-2

    jarcher, actually after I posted my new log I realized that it was only reflecting what I fixed in the safe mode. I went to the regular mode and scanned again. Many of the bad files were still there. So I fixed them. When I opened Internet Explorer after that I do not see WebSearch anymore but instead in the address window I see "about:blank" and a blank page. I typed some address and got the page I was asking for. Does this mean that I only need to pick the default page? Did we beat that ugly thing?
    I am attaching my newest new log.
    Hope it is clean now.
    Please let me know whether you can see it.
    Thank you.
    lina.
     

    Attached Files:

  15. jarcher

    jarcher I can't handle a title

    the last link explains about:blank. . . .

    but I think your clean
    i'll be back, shortly
     
  16. jarcher

    jarcher I can't handle a title

    did you put in your wanted startpage?
    is everything ok then?
     
  17. lina

    lina Private E-2

    jarcher, yes, I was able to set up a start page on the IE using Tools-Internet Options. Everything looks good to me, but I am still a little bit afraid to celebrate yet since I still can see the toolbar, which was on the WebSearch page. It contains entertainment tabs, like Football, Hockey, College... I do not know how to remove it.
    I am going to read the link you recommend about:blank.
    But I do not see about:blank in my log anymore. Does it mean that it's been removed?
    thanks.
    lina
     
  18. PhilliePhan

    PhilliePhan Guest

    Hi Lina,

    I didn't see any About:Blank problems on your log.

    Regarding your toolbar issue, take a look at this thread and see if your problem is similar:
    http://forums.majorgeeks.com/showthread.php?t=44402

    Perhaps the tool I suggested there may do the trick for you as well? Let me know if it helps. I'll try to check back later.

    Best luck,

    PP
     
  19. jarcher

    jarcher I can't handle a title

    the about blank you are reffering to
    is just the IE default
    looks like yer all good. . . .
    thanks for choosing MG
     
  20. lina

    lina Private E-2

    PP, I am trying to download OmegakillerSM. I was prompted to register, which I did. Still I am not able to download a file, only an HTML document. What do I need to do?
    lina
     
  21. PhilliePhan

    PhilliePhan Guest

    Hi Lina,

    Are you using IE?
    I had no problem downloading the ZIP file here:
    http://www.short-media.com/download.php?d=294


    No registration required. Try again. I am going to be away from my computer for a bit, but I WILL check back when I get a chance.

    I've never had the toolbar problem, so I want to see how effective this tool is. If you are able to run it, let me know. :)

    PP

    *** again, M.A. - I apologize for the foreign link :)
     
  22. lina

    lina Private E-2

    Dear PhilliePhan, I was trying to download it from MSN browser. I attached files where you can see what I was getting. I'll try again tomorrow from IE. may be this will help. Too tired tonight... after spending the entire day sifting through the files and logs. Talk to you tomorrow.
    lina.
     
  23. PhilliePhan

    PhilliePhan Guest

    Hi Lina,

    Try IE and use this link:
    http://www.short-media.com/download.php?d=294

    If we need to, go into your profile here at MGs and enable e-mail and I'll send the ZIP file to you. (Don't post your e-mail in this thread, if it comes to that)

    - - I take it your problem toolbar is similar to the one in the other thread?? You didn't say. . .

    You should also note that I've not used this tool - I've never had this toolbar problem myself. So, I do not know whether it works or not. It's probably worth a try.
    If you have any misgivings about using the OmegaKillerSM, you don't have to try it :) I find the SM site to be reputable and trustworthy.

    Talk to you tomorrow - Most likely in the evening.

    Best,
    PP
     
  24. lina

    lina Private E-2

    Dear jarcher, administrator, PhilliePhan! Guys, you are life savers! Thank you so very much for your amazing help and for your advises, for taking time to analyze my logs. World is not lost yet when people like you exist. Wish all bad malisious companies to burn in hell! :p
    I hope I am much smarter know, at least more knowledgable and careful. Although it cost me couple days of searching, reading, scanning, and a lot of stress and frustration.

    PP, I took your advise and successfully downloaded OmegakillerSM in IE (remember, it didn't download in MSN browser).
     
  25. jarcher

    jarcher I can't handle a title


    so do we all. . . . . . . .'
    thank you for coming to MG. . .
     
  26. PhilliePhan

    PhilliePhan Guest

    Hi Lina,
    We are all happy to help. :)
    Most people walk away from a battle with malware with their eyes opened. Chaslang has finally pinned his excellent malware safeguard recommendations. Check them out!
    How to Protect yourself from malware!
    Did the tool work as advertised? Please let me know so I will know whether to recommend it to others!

    Happy & Safe Surfing ;)

    PP
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds