Hijacked Hugh Hosts file

Discussion in 'Malware Help (A Specialist Will Reply)' started by flints, Feb 20, 2007.

  1. flints

    flints Private E-2

    Avast boot scan had no effect.

    SpyBot -found the Hosts hijack but couldn't remove it.

    Counter Spy -scan hung near beginning.

    AVG Anti-Spyware -ran but didn't seem to do much good
    Quarantined 2 High risk files and some medium risk files many med risk could not be deleted. Log file was to big to upload.
    Attaching the start of log file.

    Bitdefender -The scan page was unreachable.

    Panda - ran after turning off popup blocker
    log attached

    Runkeys and Hijack next post
     

    Attached Files:

  2. flints

    flints Private E-2

    runkeys
    newkeys
    hijack

    Logs attached
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    NOTE: Running this utility will reset your HOSTS file to it's original state!

    Please download HOSTER and then follow the below steps.
    • Unzip HOSTER to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program.
    Try running counterspy and bitdefender again.
     
  4. flints

    flints Private E-2

    Ran Hoster.exe
    Still no luck with CounterSpy or Bitdefender

    CounterSpy hangs and Bitdefenser scanner unreachable

    New Hijack file attached
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and run:
    Prevx1.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=...zgAfSNA8R/mV/7FSOjyFToXkq+v0rQ0wHWsy/Dd+5/1k=
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Aadvark

    After clicking Fix, exit HJT.

    Now attach new logs for:
    * Prevx1
    * GetRunKey - please download the current version first!
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  6. flints

    flints Private E-2

  7. flints

    flints Private E-2

    Post Prevx1 logs


    CounterSpy still will not run
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete these files:
    C:\WINDOWS\system32\drivers\etc\hof54e~1.bac
    C:\WINDOWS\system32\drivers\etc\hosts2~1.bac
    C:\WINDOWS\system32\drivers\etc\hosts2~2.bac
    C:\WINDOWS\system32\drivers\etc\hosts2~3.bac
    C:\WINDOWS\system32\drivers\etc\hosts2~4.bac

    I'm not seeing anything else ...how are things running?
    Have you downloaded counterspy in the past?

    Can you run BitDefender online scanner?
     
  9. flints

    flints Private E-2

    Yes I have downloaded Counterspy in the past.
    I downloaded it again and it hangs at approx the same place everytime.
    Usually after scanning 16625 files.
    Before it gets there it reports 1 error
    "Hotbar | Toolbar"
    When I end the program with Task Manager I get a Microsoft Send Report popup.

    The report details are

    Error signature
    $zAppName: counterspy.exe $AppVer: 2.1.0.917 $zModName: hungapp
    $zmodVer: 0.0.0.0 offset: 00000000

    Error Report Contents
    C:\WINDOWS\TEMP\WERebfd.dir00\Counterspy.exe.mdmp
    C:\WINDOWS\TEMP\WERebfb.dir00\appcompat.txt

    appcompat.txt attached

    Bitdefender did finally run It found two errors in some zip files sorry I didn't get the log.

    Other than counterSpy everything seems to be running Ok so far.

    Thanks for your help. I'll run it for awhile and let you know how things are going.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Counterspy gives you a trial usage ....if you have run it in the past, it will not run...which is why we tell you to run AVGAnti-spyware.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds