Lost Message re: Spyware, Homepage Hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by RPJ, Feb 19, 2005.

  1. RPJ

    RPJ Private E-2

    I posted an extremely long message on Friday morning (6:00am) and it has not shown up. No doubt I screwed something up but I sure hope it is retrievable somehow since it took 45 min to write all the details of my situation. I had been up all night trying to fix the problem and my brain was mush by that time but I also had never posted here before so didn't know what I was doing either. Can anyone help or do I need to retype the #$@( thing?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You message never made it! If you need to type it up again, do it locally on your PC in a notepad file and the either copy and paste here or attach the text file.

    But if you are having malware problems the first steps are always the same, so do the below first to see if they help!

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. RPJ

    RPJ Private E-2

    Thanks, I was hoping for a miracle but expected that it was lost. I have followed all the steps but I'll save the details and extra info for my next message that I'll create offline. Good idea.
     
  4. RPJ

    RPJ Private E-2

    Spyware, Homepage Hijack Can't Fix

    I have spent 2 days trying to cleanup an infected Acer laptop running Windows XP SP1 (had installed SP2 but had major network problems and had to get it uninstalled). The homepage is hijacked to a website in Germany (I think) and it keeps getting infected with viruses, worms, trojans. It disables many functions and won't allow changes. I went through all the steps in the "Do Not Post Until You Have Read This" message and the details follow.

    Getting Prepared

    1 System Restore Disabled
    2 Had to boot in Safe mode in order to be able to type anything in the Run slot. Did not find any of the 3 services.
    3 View already set up to see hidden files and extensions.
    4 Had to download the Tools on another computer, burn a CD and then copy them onto the laptop because laptop will not allow any downloads. Managed to finally get them all installed and updated etc. after much struggling.

    Scanning & Cleaning

    1a Had a real difficult time running Trend's Housecall even in Safe mode but finally got it to scan. It found and cleaned Worm_Rbot.AOA and allowed me to manually delete Worm.Sdbot.AKJ
    1b Ran Symantec Security Check which found the trojan Adware.istbar. I manually removed a similar (but not exact) file that their instructions mentioned (the exact file name was not there). Then went into Regedit and removed references to it and to the file P6.exe from the infection that Housecall found.
    1c Ran McAfee Stinger and found nothing.

    2 Ran CCleaner okay.

    3a Ran Ad-Aware & removed anything it found & ran VX2 Plug-in and it said computer was clean.
    3b Ran Spybot with patch & removed all it found and then immunized.

    4a Ran CWShredder and removed CoolWeb Search Trojan - CWS.smartsearch.2 and also an 'iffy' file called wiainst.exe when asked just to be sure.
    4b Ran Kill2me
    4c Ran about:Buster
    4d Ran HSRemove

    One of the above reported that it needed to run again using a printstring to start since something was trying to prevent it from running. I said yes run with printstring.

    Prior to trying all of the above steps, I had also run a cleaner app called A1Clean and also downloaded and ran a tool to remove MSN Messenger. Don't know if that really worked but the icon is no longer in the systray.

    I then crossed my fingers and rebooted in normal mode and swore a blue streak when IE immediately opened on bootup and went to the same damn webpage. I have two days into cleaning this #*%&@!^ laptop and am pulling out my hair. Please help.
    Thanks.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This! HijackThis logs must be from normal boot mode unless otherwise requested.

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  6. RPJ

    RPJ Private E-2

    The only things in the systray that I couldn't disable were the 'ATI icon' that allows you to set your screen attributes and the 'INCD icon' for sending files directly to the CD burner and the icon for 'safely remove hardware'. I disabled Norton AV but the icon is still in the tray with a red X on it. Attached is my logfile.
     

    Attached Files:

  7. RPJ

    RPJ Private E-2

    I should have mentioned that I had also disconnected my network cable before I ran Hijack This. I am not using the infected laptop for posting (I burned a CD of the logfile) because it won't allow me to type anything in the TO: slot. I can click on a person already in my address box but not type a fresh name. I am posting all these messages from a clean computer.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Documents and Settings\David Eryou\figgaz.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [Windows Service Pack Auto Update] C:\Documents and Settings\David Eryou\figgaz.exe
    O4 - HKLM\..\Run: [MDN] MDN.exe
    O4 - HKLM\..\RunServices: [MDN] MDN.exe
    O4 - HKCU\..\Run: [MDN] MDN.exe

    Nothing belongs in the Trusted Zone unless it is absolutely necessary to make something you use work!
    O15 - Trusted Zone: http://ql1.quicklaw.com


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\David Eryou\figgaz.exe
    C:\windows\system32\MDN.exe or c:\windows\MDN.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now:
    Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin
    And Click OK.
    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. RPJ

    RPJ Private E-2

    Went through all the steps and now the computer no longer boots to the German Web Site so that is progress. I still can't type anything in the To: slot in Outlook Express, nor type anything in the Run: slot, nor type anything in the slot for naming your disc when you Burn a CD so something must still be preventing me from doing this. I can't see anything else wrong but I don't know for sure. When I opened IE it went properly to the home page I had specified so that is okay. I am attaching a new log so maybe you can see something else. Thanks.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not see any other obvious problems but I do not know what this line is for:
    O4 - HKLM\..\Run: [LaunchApp] Alaunch

    Do you know what it is and what program it is running? Is there some file on your PC named Alaunch?
     
  11. RPJ

    RPJ Private E-2

    I wonder if it might be related to an Acer Utility that puts an icon in the systray called launch manager. I believe it allows you to use 4 quick buttons to immediately access e-mail, IE, and 2 user defined buttons. Its the only thing that seems likely. I also get an error message when shutting down saying hidden fax window is not responding. Now I know he has a Dell multifunction printer/fax/scanner at his house and so maybe it is looking for that since I don't have it here and maybe that is why the computer won't complete the shutdown process. I have to use the power button to shut it down. I have now tried typing in his word processing program and can't type anything there either. Do you think the viruses disabled his laptop keyboard somehow. Its like its not getting the message. Since it is the built-in keyboard it can't be a keyboard connection issue.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you cannot type, how are you getting hijackthis logs?

    I doubt a virus did this! It does not appear to be infected with anything.
     
  13. RPJ

    RPJ Private E-2

    I don't need to type to get the logs. I just need to click on stuff. I have a mouse attached because I hate glide pads. I have then been burning a CD of the log and bringing it over to my clean computer and sending it off from here.
     
  14. RPJ

    RPJ Private E-2

    I just disconnected my mouse and rebooted the laptop and neither the built-in keyboard or the built-in glide pad works. That file that I deleted using CWShredder that it said might be bad but it couldn't tell was called wiainst.exe. Do you think that had something to do with losing the function of the internal keyboard and glidepad?
     
  15. RPJ

    RPJ Private E-2

    $&%^&# I just got a pop up Virus Alert from Norton saying it had detected and removed the W32.Spybot.Worm from the laptop. That is one that I was getting when I first started this procedure. The object name is C:\Windows\system32\TFTP3464
    Arrrrggghhhhh!!!
     
  16. RPJ

    RPJ Private E-2

    Further to my last message last night, I booted into safe mode on the laptop today just to check that out and sure enough, I can type just fine in safe mode. I just have no control of the built-in keyboard or glide pad in normal mode. Something still has control of this laptop.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have no information on wiainst.exe. Are you sure of the spelling?
    Did you have CWShredder move it to the recycle bin (default option) or did you delete it?

    Look in C:\Windows\system32 and tell me if there are any other files named similar to TFTP3464 And was it TFTP3464 or did it have a .EXE or a .DLL or a .DAT at the end of it.
     
  18. RPJ

    RPJ Private E-2

    Wiainst is gone out of the recycle bin because the last step of a previous message instructed the recycle bin to be emptied. I have also gone in earlier today and deleted all the zero byte tftp files from Windows\System32. I am pretty sure that deleting wiainst.exe is not causing my keyboard/mouse problem because I can type just fine in safe mode. So something is active when I am in normal mode that disables the keyboard & glide pad.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Generate a StartupList log using HijackThis.
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.

    Also from normal boot mode run this program:
    c:\windows\PCHealth\HelpCtr\Binaries\msconfig.exe

    You should be able to do that without having to type. When it comes up tell me if you are set to Normal Startup.
     
  20. RPJ

    RPJ Private E-2

    Sorry for the delay getting back to you but I didn't get a notification that you replied so I've been waiting for you. I'll do what you outlined and get back to you right away. Thanks.
     
  21. RPJ

    RPJ Private E-2

    Here is the new Hijack This log called Startuplist. I also ran MSConfig and it says I am set for Normal Startup. Thanks.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this a laptop PC?

    Why is crypserv.exe running?

    what is it?
    crypserv.exe is a program included with some trial software titles.

    what does it do?
    crypserve.exe is a program that renders trial software useless after a period of time, usually 30 days.

    What software is this related to? Do you have any trial software that has expired?

    If you look in Device Manager, does your keyboard show up ok (no errors)?
     
    Last edited: Feb 25, 2005
  23. RPJ

    RPJ Private E-2

    It is the built-in keyboard and the built-in glide pad that don't work. The computer is an Acer TravelMate 650. I have attached a Microsoft USB mouse and that works. I have not tried attaching a keyboard and don't want to have to do that in order for this to work now. I don't know if this is related but I'm also having major problems shutting down and always have to resort to powering off manually. I hope we can make that stop too. Task Manager still doesn't function either.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re-read my previous message and answer questions.
     
  25. RPJ

    RPJ Private E-2

    There were some Windows Updates put on almost the same time as the virus/worm came in. Could that have caused a problem and just the bad timing is making it look virus related? I'm grasping at straws here.
     
  26. RPJ

    RPJ Private E-2

    I don't see any reference to the built-in glide pad but I don't know what should be there.
     
  27. RPJ

    RPJ Private E-2

    I think I know what it was. I found WinZip installed on the Laptop and removed it tonight. I might have done that after I ran the startuplist log. Sorry, I totally forgot since I did it automatically. That would have been a trial version and its gone now so who knows how long it was on there. Probably a long time. Its not needed on XP so when I see it I usually uninstall it. Duh! It was probably that.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your not saying the keyboard issue is solved? Just where you thought crypserv.exe came from. Right?

    Try hooking up an external keyboard and boot in normal mode. Does it work? If so, you may have a hardware or driver issue. And it would be time to hit the hardware forum.
     
  29. RPJ

    RPJ Private E-2

    No I was just saying that WinZip might have been the trial software you had me looking for.

    The keyboard and glide pad are still not functioning. I don't have a keyboard that will connect to the laptop so I'll have to get one from the office tomorrow and try it. I'll let you know what I find out.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I'll be waiting!
     
  31. RPJ

    RPJ Private E-2

    I picked up a USB keyboard and plugged it into the laptop and just like the USB mouse the USB keyboard works. Just the internal laptop keyboard and touch pad don't work. Should I delete the keyboard and mouse and then reboot to let windows try to re-install them?
     
  32. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ive seen this before, It turned out the user had removed some startup item with HJT and it wouldnt work. I installed the backups and everything worked fine from there.
     
  33. RPJ

    RPJ Private E-2

    I don't think this can be it because the keyboard and mouse had kicked out long before I ran Hijack This. That is why I had to post everything using another computer. I couldn't type anything on the laptop.
     
  34. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Oh ok, I would try to reinstall any drivers for it. Also, removing it and letting windows reinstall wouldnt hurt as it dont work already.
     
  35. RPJ

    RPJ Private E-2

    Well I tried uninstalling the devices and then letting windows reinstall them and it didn't help. They still don't work.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not at the moment! It does not appear to be anything we can see in an HJT log and it is not 100% dead either since you can use the keyboard in safe mode. Still seems driver related.
     
  37. RPJ

    RPJ Private E-2

    Sorry if this is a dumb question but you could tell me what things would load during normal startup that would not have loaded when I am in safe mode? Wouldn't it have to be one of these that is causing the problem?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I looked at your startup list log in message #21 and did not notice anything.

    Have you tried killing all non-necessary processes to see if if changes anything?

    You could also try temporarily using msconfig to control which items load at startup and see if that reveals anything.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds