I've been hijacked!

Discussion in 'Malware Help (A Specialist Will Reply)' started by langermr, Apr 3, 2006.

  1. langermr

    langermr Private E-2

    Often, when I try to follow a link (such as a link resulting from a google search), I am diverted to an advertisement page. The address for these ad pages are often titled "www.carsearch..." or something similar. My computer is operating substantially slower than usual. Further, every time I reboot, Microsoft Antispyware locates (relocates?) toolbar spyware that is trying to load. I may have a number of problems.

    I have gone through the procedure outlined in the MajorGeeks Thread "READ & RUN ME FIRST." I should let you know, however, that when I tried to run Spybot Search and Destroy, the program completely hung my computer. Further, when Adaware attempted to DeepScan my Registry, Adaware also hung the computer (I therefore only used Adaware to scan and clean all of the other files besides my Registry). Other than these problems, I was able to perform all of the scans requested in the "READ & RUN ME FIRST" thread. Attached is the HijackThis log, as well as the BitDefender and PandaScan logs.

    I don't know how much of this information you want/need, but for what its worth, I am running Windows XP Professional version 2002 with Service
    Pack2. My computer has an AMD Athlon Processor (1.30 GHz) and 256 MB of RAM. I have a 40GB System hard drive, and a 120GB External USB hard drive. If you need any other system information, please let me know.

    Thanks you sooooooo soooooo much for your time/help!

    Mike
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have a Wareout infection!

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    R3 - URLSearchHook: (no name) - {BC86EBA6-A9B9-F637-F834-DB90202DDC47} - mozilla-text.dll (file missing)
    O4 - HKCU\..\Run: [killall] MSTCPDLL.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{080E84DF-154E-4CF6-A7DE-104DE586AB27}: NameServer = 85.255.116.37,85.255.112.184
    O17 - HKLM\System\CCS\Services\Tcpip\..\{2C95559F-868B-4B4B-BCC0-E2FD7D06E944}: NameServer = 85.255.116.37,85.255.112.184
    O17 - HKLM\System\CCS\Services\Tcpip\..\{B6E06F45-2817-4455-8048-34F70E2D5408}: NameServer = 85.255.116.37,85.255.112.184
    O17 - HKLM\System\CS1\Services\Tcpip\..\{080E84DF-154E-4CF6-A7DE-104DE586AB27}: NameServer = 85.255.116.37,85.255.112.184
    O17 - HKLM\System\CS2\Services\Tcpip\..\{080E84DF-154E-4CF6-A7DE-104DE586AB27}: NameServer = 85.255.116.37,85.255.112.184

    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:

    C:\c002.chm
    C:\WINDOWS\Help\SPAlert.chm
    C:\WINDOWS\rdt.ini
    C:\WINDOWS\system32\MSTCPDLL.exe
    C:\Program Files\UnSpyPC <--- delete the whole folder if found

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Also attach a new HijackThis log.
     
  3. langermr

    langermr Private E-2

    I followed all of your instructions, and now have attached the fixwareout report, and a new HijackThis log.

    Mike


    P.S. Could a wareout infection cause any permanent damage to my system? Also, should I change all of my passwords and/or usernames that I have used from this computer to prevent the possibility of identity theft?

    Thanks again for all of your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You passwords are probably okay, but if you want to feel more secure then change them.

    We have one more file to delete. Locate below file and delete it:
    C:\WINDOWS\System32\CSYNF.EXE


    Now I'm also suspicious of the below line in your HJT log.
    O4 - HKLM\..\Run: [vdrdpup] C:\WINDOWS\system32\rundll32 C:\WINDOWS\system32\vdrdpup.dll,RegisterVirtualChannel

    Do you know what this file is for?
     
  5. langermr

    langermr Private E-2

    I deleted:
    C:\WINDOWS\System32\CSYNF.EXE

    I have no idea what the vdrdpup.dll file is for (related to the EOL UniversalPrinter, whatever that is?). I also googled vdrdpup.dll, and nearly every hit I got was from a tech website saying to fix the file in HijackThis, and to delete the file C:\Windows\vdrdpup.dll.

    What do you think I should do?

    Mike
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No sites provide positive identification on what the file really is. I think they all just removed it because it seems suspicious. Just like I find it suspicious. But that does not always mean something is bad.

    Does anything at the following sites ring a bell:
    http://80.161.249.153/EOL-Universal-Printer-Driver/docs/Tech.-Info
    http://www.amtsoft.com/universalprint/

    Please put the vdrdpup.dll file into a zip file and upload it here as an attachment. Also goto the below site and have it do a filescan on the vdrdpup.dll file and report the findings.

    http://virusscan.jotti.org/


    Also, how is your PC currently running?
     
  7. langermr

    langermr Private E-2

    I checked the websites you referred me to. Apparently this file is related to a universal print driver supported by the Citrix MetaFrame. I use Citrix to remotely connect to my work computer network, and it likely came from installing Citrix on my home computer.

    Attached is a zip file with the file.

    Also, I performed the online virsu scan, and it came back clean.

    As for my computer's performance, it is running normally again. I think I may have run into problems partially as a result of using the MSWindows FireWall. I'll remedy this problem as soon as we're done.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything but don't worry about it. It seems my intuition on it being related to those links was correct and it is not a problem.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:


    How to Protect yourself from malware!


    The above link also discusses firewalls!
     
  9. langermr

    langermr Private E-2

    Thank you so much for your help! :cool:
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds