Hijackthis problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bexleyboy, Sep 24, 2004.

  1. bexleyboy

    bexleyboy Private E-2

    I have an Internet problem, the screen freezes or I can't use other progs when I'm on the internet. I particularly have a problem when using the other user accounts on the same pc ( similar problem of freezing , etc ). I initially used all the anti spyware tools listed on this site, but still have the problem so I used Hijack This.I've used it on the admin account & got rid of a few things, still no real improvement.

    But when I run Hijackthis on any of the user accounts on my pc ( excepting administrator ) I get the following message :

    System denied write access to the hosts file. If any hijacked domains are in this file Hijack may not work.

    It then says I should edit the file : notepad "c\windows\system32\drivers\etc\hosts".

    I pull this up and at the bottom are the following lines:

    127.0.0.1 localhost
    127.0.0.1 searchkazza.com

    Am I supposed to remove these from the notepad Hosts file ?
    If I am they keep reapearing on reboot & there was no reference to these in the Hijack log.

    Anybody explain how I get rid of the kazzaa references ?
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Right click on file hosts and be sure that both read-only and hidden are unchecked.

    Your hosts file should look like this assuming your using XP, which I have to do because you neglected to include any system specs.

    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host

    127.0.0.1 localhost
     
  3. bexleyboy

    bexleyboy Private E-2

    Unchecked read only ( hidden was already unchecked ), but still get the same message in the user accounts ( not the admin ac )

    using XP SP2
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Thats only half the answer. Did you remove the other line, the Kazaa line? Is Kazaa uninstalled?
     
  5. bexleyboy

    bexleyboy Private E-2


    Sorry again Major !
    I deleted the line in the hosts file, but I was still unable to run the Hijack log file on the user accounts. I got the same message.

    Also I ran Kazzabegone on the admin ac & cleared a no. of files. but when I tried this on the user ac's I got a no. of files pulled up but could not delete them as they " were in use". It suggested I reboot & try again, but this didn't help. The files it mentioned in Kazzabegone were :

    Regkey [ Kazaa] HKCU\software\kazaa
    [Kazaa] C:\windows\temp\kmdb.html
    [onflow] C:\windows\temp\of_stub_ins_w_2071.exe
    [webhancer]C:\windows\temp\webhdll.dll
    C:\windows\temp\newdotnet4_50.dll
    C:\windows\temp\newdotnet3_36.dll
    C:\windows\temp\newdotnet3_23.dll

    Could these be causing my internet " freezes? " and how do I get rid of these ?

    I'm very grateful for you answering my queries anyway !
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should run SpyBot S&D but first we need to fix SpyBot's Ignore Products Bug:

    I want you to run SpyBot and get into the Advanced mode by selecting Mode and then
    Advanced mode. Then select Settings and the in the left column select Ignore Products.
    In the right window pane make sure the All products tab is selected. Then in that
    window, right click your mouse and choose "Deselect all". Now in the left pane click
    at the top on SpyBot S&D and then choose Search for Updates. Download any updates
    required. Now click Check for Problems. Fix any that are found.

    Let me know if this finds any of those newdotnet items.
     
  7. bexleyboy

    bexleyboy Private E-2

    Hi
    I didn't pick anything up when I ran Spybot
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run it on the other user accounts where you had the problems?
    I would have expected SpyBot to find:
    C:\windows\temp\newdotnet4_50.dll
    C:\windows\temp\newdotnet3_36.dll
    C:\windows\temp\newdotnet3_23.dll

    If SpyBot does not find and fix these, normally we would boot in safe mode and delete them. But first we have to make sure they are not included in yours LSP chain. You can do that with LSP Explorer for Ad-Aware SE 1.05 plugin for Ad-Aware. You need to run this in each user account.

    The file: C:\windows\temp\of_stub_ins_w_2071.exe should be delete too.

    You said you get the following message,
    "System denied write access to the hosts file. If any hijacked domains are in this file Hijack may not work."

    But does HijackThis run anyway. Can you at least get a scan for each account?

    Another question: Did you run READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal all steps on each user account?
     
  9. bexleyboy

    bexleyboy Private E-2

    Chas, Spybot didn't pick up any of the newdotnet files up on any of the accounts. Nor in safe mode, nor could I actually find the newdotnet files or the exe file in safe mode to delete ( I looked in windows\temp directory , thats right isn't it ? ) or in "normal" mode.

    When I run Hijack this, it actually scans & produces a log file for the user account and the admin account.

    I used the adaware plugin , It wasn't in the LSP and yes I followed your Readme guidelines

    Any other ideas ?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post the HJT logs for each user account. Post them as attachments and clearly label which user account they are for.
     
  11. bexleyboy

    bexleyboy Private E-2

    User ac log :


    Admin ac log:
     

    Attached Files:

    Last edited by a moderator: Sep 29, 2004
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right now I do not see anything obvious in your logs.
    Did you put these restrictions in place in the Admin login?
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    If you did this with SpywareBlaster or another tool you could try to remove these restrictions and then see if you still have a problem.
     
  14. bexleyboy

    bexleyboy Private E-2

    I didn't knowingly put them in. Shall I just check them in Hijackthis to remove them ?

    Doh !, sorry about the attachments or lack of them
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you did not run a program like SpywareBlaster or SpySweeper or anything else like that to put these restrictions in place?
     
  16. bexleyboy

    bexleyboy Private E-2

    I run Spyblaster & Spybot, I'm not sure where to look on spyblaster to see where restrictions would be. Also on spybot I think there is a page where I locked the start page, but I've now unchecked this. I've also checked the entries in the Hijackthis to remove them, however I found this hasn't made any difference ( AOL & IE still freezing, etc ). Also I found before I did the unchecking that the start the page had been changed on IE explorer to www.wethere ( or something similar ).
    I'm also wondering why the kazaa entries ( when they were picked up on Kazaabegone ) were picked up.
    I'm totally lost with all this ( its even affected my Lexmark printer, this stopped communicating when I tried to print, so I uninstalled it & tried to reinstall it, but I get an error message saying print monitor unknown. Is this totally unrelated to the Internet problem ? )
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which user are you talking about? We need to be clear which problems are for which user.

    Also awhile back I asked you:

    Did you run READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal all steps on each user account?

    You never answered. All steps need to be run for each user.

    By the way it's SpywareBlaster not SpyBlaster. At least I hope that is what you meant. SpywareBlaster is good. SpyBlaster would potentially be bad. I'm not even sure if it exists.
     
    Last edited: Sep 30, 2004
  18. bexleyboy

    bexleyboy Private E-2

    I have internet problems on user ac & admin ac. The kazzabegone entries come up on the user ac. I have run the readme 1st guidlines on both ac's ( I now only have a guest ac & an admin ac ). Yes its spywareblaster that I'm using
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A few messages back you said, "Also I found before I did the unchecking that the start the page had been changed on IE explorer to www.wethere ( or something similar ).
    "
    Can you tell me exactly what it was? Is it still that way? Does your HJT log show it?
    I see no signs of AOL software in your log other than a diag program.

    Answer these questions:
    1) Is AOL installed? What version?
    2) What is the exact problem?
    3) Are you saying you can connect using AOL or IE but it's slow?
    4) Or can you not connect at all?
    5) How are you getting here?
    6) Who is your ISP?
    7) What kind of connection (dial-up, DSL, cable)?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds