keep getting j0r.biz page online

Discussion in 'Malware Help (A Specialist Will Reply)' started by scarycat, Jan 30, 2005.

  1. scarycat

    scarycat Private E-2

    Wondered if you could help.

    When I go online after a few seconds the page I am on will transfer into http://j0r.biz/ It then trys to download wallpaper. The only way you can exit is the ctrl Alt Del method

    I have run all the instructions on the How to: Basic Spyware Trojan and Virus removal but still no joy.

    I am unable to spot it in the logfiles from HijackThis

    Internet searches for this page with help seems to bring up 2 spyware forums, one is in German the other in French!

    Any advise would be welcome

    P.S. On a side note run all instructions on the 'How to' for another computer with Cool Web Search / About Blank problems and so far 7 free days from this virus! Has taken 3 months to get rid of finally, so fingers crossed. Thanks for such a good article majorgeeks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. scarycat

    scarycat Private E-2

    Hi

    Have done a logfile but seem to be unable to upload it in the manage attachments section. This just jams when I try to use it. Perhaps I have missed something?

    Also the j0r.biz keeps cutting into my current page.

    Is it possible to cut and paste into this area instead?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must make sure the file name extension is valid for upload. We prefer .log or .txt files. The default for HJT saved logs is .log. Note the Manage Attachments window when you click upload. It does give an error message if there is one. You just have to watch for it because it does not stand out.

    If you cannot get it to work, post it inline and I will change it for you. Make sure you don't cut anything out of the log.
     
  5. scarycat

    scarycat Private E-2

    Hi
    The file extension is correct. Unfortunately I cannot get to the upload stage, it is freezing when I press the browse!

    Sorry for posting the logs in here, turning out to be one of those days!


    Edit by chaslang: Inline log change to attachment
     

    Attached Files:

    Last edited by a moderator: Jan 30, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    C:\WINDOWS\System32\n3vasap23.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MSNPluginSrIvcs] n3vasap23.exe
    O4 - HKLM\..\RunServices: [MSNPluginSrIvcs] n3vasap23.exe
    O4 - HKCU\..\Run: [MSNPluginSrIvcs] n3vasap23.exe

    O15 - Trusted Zone: *.sony-europe.com
    O15 - Trusted Zone: *.sonystyle-europe.com
    O15 - Trusted Zone: *.vaio-link.com

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\n3vasap23.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. scarycat

    scarycat Private E-2

    Hi

    Still can't get into the manage attachments browse! May be a problem I have had installing Service pack 2 during the week which crashed and I had to remove it. Still suffering from the odd remnants!

    So sorry to paste the log in AGAIN!

    Couldn't find the piece in C:\\WINDOWS\System32\n3vasap23.exe in Safe mode, but it appears to be gone in the log.

    So far so good with the internet pages no diversions as yet so thank you. The true test will come during tommorrows usage so i will let you know.

    Thank you very very very much oh wonderful chaslang. Brilliant

    Here is the log:

    Edit by chaslang: Inline log change to attachment
     

    Attached Files:

    Last edited by a moderator: Jan 30, 2005
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. scarycat

    scarycat Private E-2

    Hi

    I'm afraid I have just logged on this morning (UK time) and it is back again.

    Its really persistant.

    Why oh why!!!

    Any ideas?

    I will check my logs to see if those bits have reappeared.
     
  10. scarycat

    scarycat Private E-2

    Hi

    It has reappeared in the logs again. I have removed them again following your directions and also run ad-aware and spybot in safe mode to clean out, but unfortunately every time I restart it reappears

    Any further ideas?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you done the steps I requested:


    How to Protect yourself from malware!

    If not complete all of them and then post a new HJT log. Part of your problem may be related to not having a firewall.
     
  12. scarycat

    scarycat Private E-2

    Hi,

    I have ordered norton firewall which I will install as soon as I get it and take it from there.
    Thanks for your advice, I shall let you know what happens
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     
  14. AliWiseman

    AliWiseman Private First Class

    I too have had a similar experience with j0r.biz

    The file n3vasap was a pain to get rid of, but was removable manually in safe mode.

    A couple of things to add to whats been put here. I run AVG and this got by undetected. This problem attacked me running firefox so browser isnt an issue. I ran a trend micro housecall scan and it detected 4 java infiltrations, which apparently come from runing yahoo games and leave an open doorway. Trend could not delete these but they were removable in safe mode via windows explorer at the pathway C:\Documents and Settings\USERNAME\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar

    I then ran a spybot SnD scan and it picked up CallingHome.biz and removed it, although before the removal of the java files this problem was not found. Seems likely that the two were related.

    I only noticed the problem as when logging into my xp area Firefox opened automatically, and i dont have it set like that. The j0r page was a copy of Yahoo's start page, but i looked at the source code and it was linking to crazywinnings which shows what it really was.

    The removal of these files has stopped the problem, but id not be suprised if norton misses it if it's still there. I used norton for 6 months and got rid.

    Hope this helps :)

    Alistair Wiseman
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Interesting notes Alistair. Did crazywinnings (or does it now) show in your Trusted Zones sections of a HijackThis log (also viewable in Internet Explorer)?
     
  16. AliWiseman

    AliWiseman Private First Class

    No.. the only place it showed was the call from the script in the View > Page Source , so i assume that firefox was blocking this.
    I never entered a thing in the fake yahoo page so im wondering if it would have been initiated on entering / clicking on the page, ie like an auto redirect where irrespective as to what you type, you get sent to there?
    Since posting my first post (on a diff forum) and googling the problem there are now several pages appearing with this problem floating around.
    I feel sure that the sudden appearence of it must be connected with the java breach which was related to playing yahoo's version of FreeCell (as this was the only yahoo game i played) and with the removal of the files found by trend the failure of the re initialisation would be a remarkable coincidence.

    Hopefully this thread will be picked up by google and the solution be made available to all :)

    Alistair
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the info! I always tell people to stop playing those dumb online games that need active x components or other crap downloaded to your PC. No one wants to listen.
     
  18. AliWiseman

    AliWiseman Private First Class

    lol... well i reckon your right to do so n Trend seem to think so too. All i wanted was a timed version of Freecell to play! lol
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not worth the problems you can get into. I keep telling people to buy Playstation, XBOX, or whatever if you want to play games.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds