Hijackthis Log...

Discussion in 'Malware Help (A Specialist Will Reply)' started by bluesbuff, Jan 16, 2007.

  1. bluesbuff

    bluesbuff Private E-2

    I have completed all steps in read-me-first and removed everything found. The problem that has not been fixed appears to be rd.companion.yahoo.com or red.clientapps.yahoo.com hijacks. Also a number of games that keep appearing in the windows/downloaded files folder. Attached are all logs requested..Hope you can help.
     

    Attached Files:

  2. bluesbuff

    bluesbuff Private E-2

    additional logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of this is malware. They are all things that whoever uses the PC downloaded or configured.

    Who is going to Yahoo to play all the games??? If you fix those lines they will just come back if you or someone else goes there and plays them again.

    The red.clientapps stuff is also something you (or other) configure are setup due to using stuff from Yahoo!

    If you want to remove all of these, do the below!

    HOWEVER first answer a question why your HJT log does not appear to be from the same PC as your logs from ShowNew & GetRunKey. ShowNew & GetRunKey both indicates that you have Norton Internet Security 2006 installed and running and they also show Window Defender being use. And they show no signs of AVG. Whereas you HJT log shows AVG and no signs of Norton or of Windows Defender. Why are these logs showing differnet information!

    First you will need to shutdown ZoneAlarm during this because it could block changes so I suggest you unplug your cable to the internet first. Then shutdown ZoneAlarm. Then uninstall CounterSpy since we are finished with it and it could also block the changes.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.companion.yahoo.com/slv/ycheck/as/*http://
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.insightbb.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.companion.yahoo.com/slv/ycheck/as/*http://search.yahoo.com/search?p=%s
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O9 - Extra button: Dell Home - {EE117DAA-A30B-40FC-945C-38AE1B80C1FA} - http://www.dellnet.com (file missing) (HKCU)
    O16 - DPF: Toki Toki Boom - http://download.games.yahoo.com/games/clients/y/vtm_x.cab
    O16 - DPF: Tornado 21 - http://download.games.yahoo.com/games/clients/y/t21t0_x.cab
    O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
    O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
    O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
    O16 - DPF: Yahoo! Go - http://download.games.yahoo.com/games/clients/y/gt2_x.cab
    O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
    O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt1_x.cab
    O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst3_x.cab
    O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
    O16 - DPF: Yahoo! Sheepshead - http://download.games.yahoo.com/games/clients/y/dt0_x.cab
    O16 - DPF: Yahoo! Spelldown - http://download.games.yahoo.com/games/clients/y/sdt1_x.cab
    O16 - DPF: Yahoo! Towers 2.0 - http://download.games.yahoo.com/games/clients/y/ywt0_x.cab
    O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt0_x.cab

    You can also fix the below if you don't need them (more games!!)
    O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
    O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_games/tikgames/cinematycoon/cinematycoon.cab

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now plug in your cable to the internet and continue!

    Now attach the a new HJT log


    What is the below file from? Panda detected malware in the cab file.
    C:\undo\backup.cab
     
  4. bluesbuff

    bluesbuff Private E-2

    This is an old computer that my daughter uses... There will be no more games downloaded to it and Im sure she is going to love the new Home Page. All logs were done on the same computer. I ran all logs except HJT first, then did some additional cleaning including the advice from this forum and dumped Norton for AVG. Then I ran the HJT log. Sorry, wasn’t trying to confuse the issue. I will also be installing Foxfire.

    I think C:\undo\backup.cab is leftover from upgrading to XP?
    Three files in the folder
    Backup. 1KB
    Backup.cab 427,100KB
    Boot.cab 4,918KB
    Should I just delete the folder?

    Thanks, you guys are great.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you don't need it for anything, yes!

    Looks like your problems are all fixed now! ;) If you have not done so already, make sure you check out the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds