http://horse-search.net/

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by I3eefy, Feb 25, 2005.

  1. I3eefy

    I3eefy Private E-2

    how do i get ride of this the target fule it comes from is c\:WINDOWS\blank but it comes up with this thing every so often.

    another thing in add and remove thier is a installed program called "Best Search Engine!!!" and it reinstalls itself when i turn the computer on so how do i remove it for good.

    thanx guys
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT


    We are very busy here at MajorGeeks.Com PhilliePhan, Chaslang or myself with check back when time permits.!
     
  3. I3eefy

    I3eefy Private E-2

    thx and i downlaoded oall your programs and followed step by step and it worked thx very much guys and girls if there are any
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    So, Your not experiencing anymore problems at the moment?
     
  5. PhilliePhan

    PhilliePhan Guest

    If you have the baddie I think you have, it's not going to go away that easily! You should attach a fresh HijackThis log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99.1) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis! Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99.1

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    PP :)
     
  6. Sokk1

    Sokk1 Private E-2

    Hi

    I did all the stuff but didn't fix the problem.

    Here's the hijack.log, maybe you can help

    Sok
     
  7. Sokk1

    Sokk1 Private E-2

    And since "Manage Attachments"-icon didn't work, for a reason I do not understand, and since my "EDIT-time" went off, I'll just paste the log here:

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Mar 4, 2005
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please print out these instructions so that you can operate with All Browser Windows CLOSED.

    Please make sure System Restore is OFF and the Viewing of Hidden Files & Folders is Enabled as per the tutorial.

    Please download: HSFix.zip
    DO NOT RUN IT YET!

    Now, look in Task Manager (Ctrl-Alt-Del) for the following running process and, if you see it, try to END it:


    open32.exe



    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = C:\WINDOWS\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\dlmax.dll
    O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\System32\DSMANA~1.DLL
    O2 - BHO: (no name) - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\snim.dll

    O4 - HKLM\..\Run: [Shell] open32.exe
    O4 - HKLM\..\Run: [ditphsa] c:\windows\system32\ditphsa.exe
    O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
    O4 - HKLM\..\Run: [Systems Restart] Rundll32.exe snim.dll, DllRegisterServer
    O4 - Startup: winupdate96216147[1].exe

    O18 - Filter: text/html - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\snim.dll
    O18 - Filter: text/plain - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\snim.dll

    O21 - SSODL: NTDBGTOOL - {0433CA07-C287-4D93-9A7B-3E6A33CE963F} - C:\WINDOWS\System32\ncpaulib.dll


    Again, make sure All Browser Windows are Closed when you Click FIX.



    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:


    C:\WINDOWS\System32\open32.exe

    C:\WINDOWS\System32\DSMANA~1.DLL

    C:\WINDOWS\System32\snim.dll

    c:\windows\system32\ditphsa.exe

    C:\WINDOWS\System32\ncpaulib.dll

    C:\WINDOWS\blank.htm

    C:\WINDOWS\dlmax.dll

    C:\WINDOWS\farmmext.exe

    winupdate96216147[1].exe



    NEXT:
    Now run the HSFix.zip

    Extract the tool from the ZIP File to a folder you can easily find (preferably in its own folder - like C:\HSFix). It should have a ReadME included with instructions on how to run it and how to collect the log it produces.

    Please run the tool as directed and attach the log it produces.



    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"



    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.




    Reboot to Normal Windows , Scan with HijackThis and HSFix and attach the new logs.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Good Luck!:)
     
  9. Sokk1

    Sokk1 Private E-2

    Hey

    Well, it seems everything is now working peachy after I did the things you told me to. I only ran into one problem during the manual. HSFix has a readme indeed, but it has no information on how to run the program, so I went and just ran the .exe that makes the log and the reg.fix, the rest i tried but I felt they didn't do anything.

    Big thanks for everyone who helped and if anyone is having problems in future, i've added the old/new hijackthis.logs in the attachments.

    Sok
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Just realized your not running HJT from a secure location. Relocate your HJT into a safe location, for example C:\Program Files\HJT

    Do this before fixing anything else so that your backups will be safely stored.



    Now, go ahead and do another scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = C:\WINDOWS\blank.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\dlmax.dll (file missing)

    O4 - HKLM\..\Run: [ditphsa] c:\windows\system32\ditphsa.exe

    O18 - Filter: text/html - {B72F75B8-93F3-429D-B13E-660B206D897A} - (no file)
    O18 - Filter: text/plain - {B72F75B8-93F3-429D-B13E-660B206D897A} - (no file)


    Again, make sure All Browser Windows are Closed when you Click FIX.


    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:


    c:\windows\system32\ditphsa.exe

    C:\WINDOWS\blank.htm


    NEXT:
    Run CCleaner




    Reboot and post a new HJT log that we can confirm your clean!

    It appears HSFix took care of that problem. Are you experiencing any problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds