HIJACKED by SWAPX

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dcross, Nov 23, 2004.

  1. dcross

    dcross Private E-2

    Hi,

    This thing is very frustrating. Swax has taken over. I have followed the complete instructions, but still having the problem. Re: HJT, I cannot get it into it's own folder. I create a folder, but somehow, it always goes to a temp folder.

    Please help.

    Darren
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you downloaded HJT from Majorgeeks, it is in a compresses ZIP file. You need to extract it from the ZIP file using a utility like WinZip. Extract it to a directory like we indicated. If you have run ALL steps of the READ ME FIRST, then shut down all applications and post your HJT log as an attachment. Make sure you have HJT version 1.98.2.
     
  3. dcross

    dcross Private E-2

    Thanks for the help. Looking forward to the response.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next time please remember to exit your browser before running HJT. You had the below running:
    C:\Program Files\Internet Explorer\iexplore.exe

    What is your expected home page?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run the READ ME FIRST tutorial yet. Why not? You stated you followed the complete instructions.

    If you had followed the tutorial, I believe some of your problems would have been fixed.

    Please run ALL steps from: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you run CWShredder and the online scans. Do not skip anything.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://win-eto.com/hp.htm?id=9
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://win-eto.com/hp.htm?id=9
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\W8C6S4~1.DLL
    O20 - AppInit_DLLs: r5kmzg136n121edll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\W8C6S4~1.DLL
    C:\WINDOWS\System32\r5kmzg136n121edll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Nov 24, 2004
  6. dcross

    dcross Private E-2

    Sorry.....I thought I went through all of the steps. I am not sure what I missed. I still have the online scans to do, but since the instructions call for me to run HJT first, I am posting the log.

    My desired startpage= www.nprealtygroup.com

    Thanks for your help. I will get back to you after the online scans.

    Darren
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First make sure System Restore is disabled and the viewing of Hidden Files is enabled as per the tutorial.

    Please download this tool: Pocket KillBox http://www.downloads.subratam.org/KillBox.zip

    Please print out or save these instructions locally because you must perform the below steps with ALL Browser sessions CLOSED.

    First use Windows Explorer and navigate to C:\WINDOWS\System32\w8c6s4xcm66o9zdll.dll and verify that this is the correct path for the DLL.
    Also look for r5kmzg136n121edll.dll
    If those two DLL's are not in the system32 folder, try looking for then in C:\WINDOWS

    After you find the correct path, run Pocket Killbox and choose the Delete on Reboot option. Navigate to w8c6s4xcm66o9zdll.dll and press the Delete button (red X) and then Yes or OK until your machine reboots.

    After your machine reboots, navigate to where the file should be and make sure it is gone.
    Now repeat using Pocket Killbox to delete r5kmzg136n121edll.dll (which I assume is in C:\WINDOWS\System32)


    After both files are deleted, scan with HijackThis and Check the Boxes for the following:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://win-eto.com/hp.htm?id=9
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\W8C6S4~1.DLL
    O20 - AppInit_DLLs: r5kmzg136n121edll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll

    Again, make sure All Browser Windows are Closed before you Click FIX.


    Now boot into Safe Mode and DELETE the following if they show up again:
    C:\WINDOWS\System32\w8c6s4xcm66o9zdll.dll
    C:\WINDOWS\System32\r5kmzg136n121edll.dll

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to http://www.nprealtygroup.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Now skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to http://www.nprealtygroup.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Reboot to Normal Windows and Scan with HJT and attach that log.
     
  8. dcross

    dcross Private E-2

    It worked!

    Thanks for all your time.

    Darren
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. But it may be a good idea to post a final HJT log just to double check.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds