Hijacked by topsecurity.net - Hijack this log

Discussion in 'Malware Help (A Specialist Will Reply)' started by Thom_D, Jun 17, 2006.

  1. Thom_D

    Thom_D Private E-2

    My PC, and Internet Explorer are infected by (at least) topsecurity.net Every time I open Internet Explorer it is redirected from my home page ( A blank browser) to topsecurity.net. There is a yellow icon in the system tray that keeps telling me my computer has a virus and that I should click the icon (I did not do this). I realized that I had been hijacked and went in search of helpl. Major Geeks kept coming up along with Hijack this so I decided to try here.

    I ran through all of the steps listed in the READ & RUN ME FIRST Before Asking for Support post. and have attached my Hijack This log, the BitDefender log and the Pandaware Log.

    I hope you can help me get this cleaned out. I am tired of the casino popups and porn ads.

    HELP!!!

    Thanks

    Thom
    TDoonanII@aol.com
     

    Attached Files:

    Last edited: Jun 17, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to run the below procedure and then attach the smitfiles.txt log:

    SpywareQuake & SpyFalcon Removal Procedure


    Then also attach a new HJT log and let me know if there is any change to your problems.
     
  3. Thom_D

    Thom_D Private E-2

    OK I ran the procedures you directed me to. I only found one file in my c:\windows\system32 folder - dxole32.exe and deleted it.

    I have attached a fresh hijackthis log file and the smit log file as well. Iexplorer is still hijacked cy topsecurity.net and I periodically get trojans that pop up on my virus checker, McAfee Virus Scan.

    Whats next?

    Thanks

    Thom
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have one of the more recent forms of the infection that I have just added to the procedure today. You need to run the procedure again. Make sure you download the fixquake.reg patch again because it has changed a bunch.

    Also the key file you will be looking for is %System32%\rmzdzx.dll but look for the all anyway because as you can see there are dozens of forms of this crud.

    You have a few other problems will need to fix too after getting SpywareQuake removed.
     
  5. Thom_D

    Thom_D Private E-2

    I will do this tonight when I get home.

    One problem that showed up is that windows stopped powering down the PC when I quit. It gets past the logging out scripts and then just hangs.

    I will post new info tonight.

    Thom
     
  6. Thom_D

    Thom_D Private E-2

    OK. I ran through all the steps again, still didn't find any of the files, folders or programs listed.

    Updated the Fixquake.reg file and installed that.


    Iexplorer seems to not be hijacked now.

    But my PC will still not power down when quitting windows.

    And everytime I start my PC back up in normal mode with internet connection McAfee finds two trojans and deletes them.

    Where do I go from here.

    Thanks again, we seem to be getting there.

    Thom
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must be more specific! What is it finding and where? Give file & path names! Give virus/trojan names.....etc.

    Let's continue fixing the other problems that I mentioned you still have!

    First download about:Buster
    Now continue with the below. Some items may be gone due to running the above. Just ignore and continue if not found.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Thom\LOCALS~1\Temp\sp.dll/sp.html
    O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\iiffcbc.dll
    O2 - BHO: (no name) - {F8765124-5F7E-448D-A159-7B112FB2A931} - (no file)
    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)
    O18 - Filter: text/html - (no CLSID) - (no file)
    O20 - Winlogon Notify: iiffcbc - C:\WINDOWS\SYSTEM32\iiffcbc.dll
    O20 - Winlogon Notify: winhab32 - winhab32.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\iiffcbc.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. Thom_D

    Thom_D Private E-2

    OK, I followed all of the steps you outlined in your latest post. I did not find any of the files you asked me to look for.

    I have attached the AB log file and the last two HJT log files that I ran. The number 3 file is the first of the two files.

    So far everything is running OK. I have not had any more trojans identified by McAfee so hopefully we got those. If any others show up, I will get the path and name for you.

    Windows is again shutting down properly so that is OK.

    There is one odd thing that I noticed. I went to reset my desktop wallpaper and discovered that all of the windows jpegs are gone. I got out my Windows install disc but was not able to figure out in which folder the media files are stored.

    Let me know what else you find.

    Thanks for your help with this.

    Thom
     
  9. Thom_D

    Thom_D Private E-2

    Not sure if the files uploaded or not. Trying again.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't believe I asked for two HijackThis logs????


    You did not do the below step. At least you did not do it exactly as requested. If you did as requested you start page would no be about:blank.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    You still have one of the infections present. I wanted to try the simple method first but it does not work so on to the more complex method.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps (it will not work otherwise) and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of iiffcbc.dll once and then click the kill button. After you have killed all of the iiffcbc.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of iiffcbc.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\iiffcbc.dll
    O20 - Winlogon Notify: iiffcbc - C:\WINDOWS\SYSTEM32\iiffcbc.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:

    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.


    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\SYSTEM32\iiffcbc.exe
    C:\WINDOWS\SYSTEM32\iiffcbc.dll


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.


    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!
     
    Last edited: Jun 20, 2006
  11. Thom_D

    Thom_D Private E-2

    I will go through this tonight when I get home.

    For now McAfee picked up two new trojans.

    C:\Documents and Settings\Thom\Local Settings\Temporary Internet Files\Content.IE5\G9M3C1I7\ff3[1] Infected by Vundo

    And

    Windows\System32\awvtr.dll Infected by Vundo.

    McAfee found and cleaned them.

    Let me know what else to do.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the Reset of Web Settings was done, it should have removed the above file. The awvtr.dll file would have to have been removed manually though. It was however inactive because this infection was not showing in your HJT log.

    Just complete the latest instructions and attach the new HJT log and let me know how things are working. Make absolutely sure you DO NOT have any browsers opened while running those steps.
     
  13. Thom_D

    Thom_D Private E-2

    OK, I followed the steps you outlined for today. I did actually do the web browser reset steps, I just set my home page to blank so the browser will load faster.

    So far it seems OK. but McAfee keep finding the same two trojans as listed above and in the same place. Not sure if it is a false positive because I can't find the indicated files in either location.

    I am considering dropping McAfee and going with Pandaware, do you have any recommendations on a good AV program that also catches some spyware? I run AdAware and Spybot S&D weekly and I guess now I will run Windows Defender as well. What a hassel.

    Let me know if I need to do anything else.

    You have been a lot of help and I appreciate it. I could never have done this without some expert guidance.

    Thanks

    Thom
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you have enabled viewing of hidden files and extensions etc per the READ ME. It could also be that you are looking for them after McAfee has already deleted them and then perhaps something is bringing them back after reboot. Try uninstalling McAfee and then reboot and look for the files.

    Antivirus and Antispyware are two different things and you need both. If you install security suites from McAfee, Symantec, Panda, etc, you will typically get both of those and then some more (like firewall, popup blocker, antispam). I don't recommend these security suites because they are usually tremendous resource hogs.

    You also still have Ewido and AOL'S antispyware applications running. I personally would not use AOL's stuff at all. And if Ewido is the free version, you really should uninstall it to avoid possible conflicts with Windows Defender and also the excess use of system resources. If Ewido is a paid subscription version, I would keep it and uninstall Windows Defender.

    What we recommend and you should do anyway since we have clean your PC is the below.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
    Last edited: Jun 23, 2006
  15. Thom_D

    Thom_D Private E-2

    OK, everything seems to be ok with the spyware now. Thanks for your help with all of this.

    I now have a new problem that may be related or not, I am not sure.

    Windows starts up fine, but when the screen saver kicks in the screen clears of everything but the mouse cursor and hangs. The mouse cursor stays live but nothing else works. CTRL+ALT+DEL does nothing. I can shut down holding the power button or hit the reset button to restert windows but I know that can't be good for the Windows installation.

    I am running Windows XP SP2 with all of the latest patches.

    Let me know if you can help or if I need to post this somewhere else.

    Thanks

    Thom
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not sound like malware but I will check one more thing first before sending you to the Software Forum.

    Run the below procedure and attach the runkeys.txt log.
     
  17. Thom_D

    Thom_D Private E-2

    Tim,

    Here you go. Thanks for looking deeper into this with me.

    I am mostly hoping I don't have to reinstall windows so what ever you can tell me is great.

    Thanks

    Thom
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Lets try one more thing!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now reboot and let me know if there is any change. I don't expect this to fix the symptoms you were descrbing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds