need help, internet isnt working

Discussion in 'Malware Help (A Specialist Will Reply)' started by hazza07, Jan 24, 2005.

  1. hazza07

    hazza07 Private E-2

    hi, ive been hijacked i think with the home page hijacker etc, but now my internet wont run (im using another computer) i need to use it really soon and i cant do the requested steps because i cant use the internet... requesting hijack this log file, ive got to post it now to save time...please help..oh and imn sure all of those first ones are part of the virus... thanks
     

    Attached Files:

  2. TheOldThug

    TheOldThug First Sergeant

    Hi

    First of all your HJT is not updated. You do not have the current version. Please follow the following instructions to post a HJT file.
    Hopefully Chaslang or PP will ask you to do so.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT

    TheOldThug
     
  3. hazza07

    hazza07 Private E-2

    ohh k, i thought i did it right...anyway heres the v1.99 hijack this log file...i put it onto floppy disc. I hope i post it right because ive done it this way every other time ive done it...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a whole load of problems in your log! What have you been doing since you where last here?
    Do you implement all of the stuff in How to Protect yourself from malware! as was suggested?

    I'm looking at your log now.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what the following are:

    O4 - HKCU\..\Run: [RocketPipe] C:\Program Files\RocketPipe\rpclient.exe -autorun

    O14 - IERESET.INF: START_PAGE_URL=http://pcworld.idg.com.au
     
  6. hazza07

    hazza07 Private E-2

    um...this is on a different computer, ive put a firewall on it but ive been pretty slack with other stuff, that computer was defending fine before last night with what it had, from now on im going to apply more protection. no i dont have a clue waht they are, i dont use them. all of this stuff happened last night at once.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have learned your lesson from your previous infection.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have run all of the READ ME FIRST and then possible some of the Alterantive Scans. But let's see if we can make a dent in this. This may take some work and some repetition.

    First goto Add/Remove programs and check for uninstalls to WareOut and RocketPipe.
    Uninstall if found. I'm leaving fixes in below too just incase there are no uninstalls.

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    IPCFG
    SCANDS32
    SNNPAPI

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://fastsearchweb.com/srh.php?q=%s
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\SNNPAPI.DLL/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\SNNPAPI.DLL/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\SNNPAPI.DLL/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\SNNPAPI.DLL/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\SNNPAPI.DLL/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\SNNPAPI.DLL/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R3 - URLSearchHook: (no name) - {3793D6D1-4522-0534-AE28-11BBFB5737B7} - clamav.dll (file missing)
    O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINDOWS\SYSTEM\IECUST.DLL
    O4 - HKLM\..\Run: [ipcfg.exe] C:\WINDOWS\SYSTEM\IPCFG.EXE
    O4 - HKLM\..\Run: [scands32.exe] C:\WINDOWS\SYSTEM\SCANDS32.EXE
    O4 - HKLM\..\Run: [SysTray] C:\WINDOWS\SYSTEM\SNNPAPI.EXE
    O4 - HKLM\..\Run: [pizda] msag.exe
    O4 - HKLM\..\Run: [NukeSpan] Shaitan1678.exe
    O4 - HKCU\..\Run: [RocketPipe] C:\Program Files\RocketPipe\rpclient.exe -autorun
    O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
    O4 - HKCU\..\Run: [10010] EXE32EXE.exe
    O4 - HKCU\..\Run: [MON76234] bhoserv.exe
    O4 - HKCU\..\Run: [MNTP] driver32.exe
    O9 - Extra button: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - C:\Program Files\WareOut\WareOut.exe (file missing) (HKCU)
    O9 - Extra 'Tools' menuitem: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - C:\Program Files\WareOut\WareOut.exe (file missing) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=http://pcworld.idg.com.au
    O15 - Trusted Zone: http://*.63.219.181.7
    O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://c:\nosuch.mht!http://ultimately-yours.com/dl/files.chm::/file.exe
    O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
    O18 - Filter: text/html - {8698C5C0-6E48-11D9-BF4A-4445F9519AB2} - C:\WINDOWS\SYSTEM\SNNPAPI.DLL
    O18 - Filter: text/plain - {8698C5C0-6E48-11D9-BF4A-4445F9519AB2} - C:\WINDOWS\SYSTEM\SNNPAPI.DLL

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\WareOut <--- the whole folder
    C:\Program Files\RocketPipe <--- the whole folder
    C:\WINDOWS\SYSTEM\IPCFG.EXE
    C:\WINDOWS\SYSTEM\SCANDS32.EXE
    C:\WINDOWS\SYSTEM\SNNPAPI.EXE
    C:\WINDOWS\SYSTEM\IECUST.DLL

    These next 5 files must be deleted too. They could be in c:\windows or c:\windows\system or even somplace else. If you do not find them in one of the two windows folders mentioned, use the built-in windows search and see if you can located them and delete them.
    msag.exe
    Shaitan1678.exe
    EXE32EXE.exe
    bhoserv.exe
    driver32.exe


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. hazza07

    hazza07 Private E-2

    yeah sorry, i thought that the other computer could handle it (especailly with the firewall). sorry after this im going to do all of the steps.
     
  10. hazza07

    hazza07 Private E-2

    oh....sorry for not telling you, the infected computer has windows 98, so the processes tab isnt there in task manager...and im also not to sure about system restore, if its there i dont know how.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yeah but it shows processes by default but I forgot to remove the comment about system restore which does not apply to Win98
     
  12. hazza07

    hazza07 Private E-2

    oaky i did all of those steps...i couldnt find any of the last 5 that you told me to find, i did the search using the start bar because i dont have a mmouse in safe mode and i couldnt get that one to work. i ope they're the same. heres the log, ill try the internet when you tell me if you think its okay.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Better! But I missed one the first time.

    Make sure you have system restore disabled and viewing of hidden files enabled.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {8698C5C1-6E48-11D9-BF4A-4445961D3F29} - C:\WINDOWS\SYSTEM\SNNPAPI.DLL

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\SYSTEM\SNNPAPI.DLL

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  14. hazza07

    hazza07 Private E-2

    alright heres the new log...my computers running alright but not perfect...i can do the other steps now if you recommend???? Does it matter that those five werent there?
    Oh and that SNNPPAPI.DLL wasnt there in explorer...i may, just may have deleted it the previous time, im not 100% sure but i remember doing something like that.
     

    Attached Files:

  15. hazza07

    hazza07 Private E-2

    okay, i just downloaded AVG anti virus and it has found a "trojan horse dialer" on start up. When i did a scan with it it found 9 viruses which all had to do with a trojan horse, it deleted them at the end of the scan...i didnt do this in safe mode does that mean that it wont properly delte them? oh and i was looking in C drive and there was a program called m.exe. i looked it up on google and it said it had something to do with a trojan. how do i go about deleting this? thanks
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean but did you forget to shut this down before running HJT:

    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

    or is it running on its own. If running on its own, that would be a problem.

    You should take all the steps in the below link:
    How to Protect yourself from malware!

    You said "my computers running alright but not perfect". What makes you say that? What problems are you experiencing?
     
  17. hazza07

    hazza07 Private E-2

    well i thought i disconnected but heres one i just did now, i definatley diconncected and exited all windows. When i deleted all of those trojans, and when i restarted i got a message saying
    Cannot find a device file that may be needed to run windows or a windows application.

    The windows registry or SYSTEM.INI file refers to this device file, but the device file no longer exists.

    If you deleted this on purpose, try uninstal;ling the associated application using its uninstall or setup program.

    If you still want to use it reinstall that application to replace the misssing file.

    C:\VET\VETMON9X.VXP


    Im not sure waht this is, it may have something to do with me deleting VET anti virus, without uninstall because i couldnt find it.
     

    Attached Files:

  18. hazza07

    hazza07 Private E-2

    well im very sure the AVG deleting didnt work because it started another scan on its own and it found two of the same trojans, but not the dialer. i stopped it because i dont have time to wait for the whole process. How should i go about permanatley deleting these trojans?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I believe have referred you to How to Protect yourself from malware! at least three times within this thread and I know I also did in the past too. Please read step 2 again and note at the end of that step these works "Only run ONE AV!"

    Why did you install AVG if you hav VET?

    Which on do you want to keep? Right now it looks like you broke Vet. You should probably uninstall it, but are you saying there is no uninstall program?

    I have no idea what files AVG found and what you deleted. You never provided me with any info on that.
     
  20. hazza07

    hazza07 Private E-2

    i installed AVG because i couldnt update VET. the plan was to only run one anti virus because i was going to get rid of Vet. If you want i can run AVG again and print screen for you? yeah i dont want Vet, i deleted the folder, ill try to delete everything else associated with VEt?
     
  21. hazza07

    hazza07 Private E-2

    I sent the VET folder to the recycle bin and i retrieved it but there is no uninstall icon. should i put it in the recycle bin and empty trash?
     
  22. hazza07

    hazza07 Private E-2

    I sent the VET folder to the recycle bin and i retrieved it but there is no uninstall icon. should i put it in the recycle bin and empty trash? Also should i do a series of scans i.e ad-aware,spybot and AVG in safe mode and delete anything i find. if you want i can do an AVG scan and tell you which trojans i have?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Tell me what trojans AVG is finding. Are you scanning in safe mode too? And are you saying it finds them but does not fix them?

    Did you get the latest update to AVG which just came out today or yesterday?
     
  24. hazza07

    hazza07 Private E-2

    okay...false alarm, AVG must of deleted the trojans permanatley because i just did a system scan(fully upgraded) and they werent found (not in safe mode). I still think theres something slowing my computer down though. How should i fully delete VET anti virus?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post another HJT log. You said you deleted all the Vet files and folders....right?
    Also, didn't you say you could not find Vet in add/remove programs to uninstall?
     
  26. hazza07

    hazza07 Private E-2

    okay, i found VET in add/remove programs. that problem is solved.
    Should i go through all of the steps in removing viruses now because there is still that m.exe (recognized as some type of worm), LaCqaRha.exe (which google doesnt recognize), maSszDni.exe (that google doesnt recognize),...these three are in the c drive (c:\)

    and Jdbgmgr.exe (which is recognized as a hoax virus in program files)

    heres the hijack this log anyway, disconnected etc.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would start by renaming those thread files as below:
    m.exe to m.xxx
    LaCqaRha.exe to LaCqaRha.xxx
    maSszDni.exe to maSszDni.xxx

    Then reboot and perform a full virus scan with your antivirus application. You log was clean.

    Are you noticing any problems with your computer?
     
  28. hazza07

    hazza07 Private E-2

    well the computer is just running more slow than usual. What do i do with the Jdbgmgr.exe. Should i rename it as well. So i scan with AVG. Should i also do a spybot and an ad aware scan? and all in safe mode...
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where are all these coming from? Are these all new problems or where they always here and you never mentioned them?

    Run a full scan with AVG and then do these:

    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan
     
  30. hazza07

    hazza07 Private E-2

    okay thanks, do i rename them all first to *.xxx? and should i do the AVG in safe mode? i pretty sure i got them when i got the virus.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rename that later (if still necessary) after doing all the scans. Run all the scans in normal boot mode. If AVG cannot fix any problems it finds then re run AVG in safe mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds