Need Help with Generic Solution

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by momscheapsupport, Aug 31, 2004.

  1. momscheapsupport

    momscheapsupport Private E-2

    Hi there! So glad you're out there!

    I have a hijacked browser on a brand spanking new laptop. home page now goes to about:blank and I have a lovely assortment of popups.

    I've loaded all recommended programs, and followed the generic solution thru step 7. I'm stuck on step 8. Don't know what is legit and what is not. I'm troubleshooting my son's new pc which was hijacked on his 1st day of using it. (yeah!) We had a little talk about firewalls, undersirable web sites, etc... I've copied the Hijackthis log that I printed early this morning before starting the gen. sol. Can't tell from which of the O4 listings are legit. He didn't have time to save anything to the hard drive so if there is an easy way to restore the whole system and then load appropriate proactive software as an alternate solution, please let me know. Thanks in advance for any and all help. Leaving for soccer game... school starts tomorrow for 2 kids... and thurs for college son.... may not check back for a few hours but will check asap. :)
     

    Attached Files:

    • hjt.txt
      File size:
      6.1 KB
      Views:
      2
    Last edited by a moderator: Aug 31, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should have followed this this Sticky thread first:
    < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    And note there are guidelines in another Sticky thread on posting HijackThis logs (when and how).
    < Hijack This Tutorial And How To Post Your Log File >

    Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message.

    Update! Due to Hijack This logs destroying search engine and web site searches, we now ask you do not post your Hijack This log file unless requested by us. It is for advanced users, so if you do not understand how to use it, you do not need it....yet. Instead, please tell us in your post what symptoms you are experiencing so we can try and resolve it that way. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    I changed you log into an attachment.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before continuing with the Generic Solution steps you should run HijackThis (HJT) and fix the following lines:

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O15 - Trusted Zone: *.05p.com
    O15 - Trusted Zone: *.my-internet.info
    O15 - Trusted Zone: *.scoobid

    The only O8 line I see is:
    O4 - HKLM\..\Run: [ipjr.exe] C:\WINDOWS\system32\ipjr.exe

    But that could change (along with other items) if you have rebooted your PC since posting your HJT log.

    I don't like the looks of this: C:\WINDOWS\accessories.ico:kvuhp showing in your processes list.
    It looks like ADS (Alternate Data Stream). Make note of whether About:Buster catches this later when you run it.

    Did you find NSS or WNS in step 6?
     
  4. momscheapsupport

    momscheapsupport Private E-2

    Sorry about the errors with my initial post. I'll be more careful. I have got the laptop offline and disconnect from the phone line. I have not rebooted since I started the Generic Solution this morning and the Hijackthis info I posted if from the last time it was run on the current boot. I don't want to reconnect that one at this point and am hoping I can copy any info I need to post from the affected laptop to CD and then transferring to my PC which is not affected by this. I'll let you tell me the best way to do it.

    I did find NSS but not WNS in Step 6.

    When I tried to update Windows at the before starting, I got an error, 0x80072EE2 and was not able to update. However Windows Update was done at purchase which was within 24 hours of hijack.

    Also on my last reboot before attempting this repair process, I had an error message "Cannot open kvuph" and I has suspected this problem. I will next go thru the Read Me First info and run HijackThis and correct the lines you've listed and then I will post again.

    Thanks again for your assistance.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well if you go thru that read me first sticky now it will require a reboot to safe mode which is going to require a new HijackThis log. I would really like you to try something first though before you start or continue the Generic Solution. It will be faster (if it works). It is something that came out from Symantec and sounds to me like it may be useful.

    Please try this: Backdoor.Agent.B Removal Tool 1.0.1.2:
    http://www.majorgeeks.com/download4337.html

    Follow the directions on that link exactly. Tell me how it works out.
     
  6. momscheapsupport

    momscheapsupport Private E-2

    I ran Symantec Backdoor Agent B removal Tool 1.0.1.2 and got the following result:

    c:\System Volume Information: (not scanned)
    Backdoor.Agent.B has not been found on your computer.

    This was returned as a Notepad message.

    I don't know if I've already removed things it would have otherwise found.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I guess you did not have the exact form they look for. Reading thu their info I see there are similarities and also major differences to the HSA hijack. So back to the Generic Solution. I assume you now have a new HJT log we will have to look at because your PC may now have been rebooted?
     
  9. momscheapsupport

    momscheapsupport Private E-2

    completed steps but still have problems. aboutbuster did not pick up the O14 IERESET ....

    on restart from safe mode, reran hijackthis and ddl file has changed names. have not connected laptop to internet or phone line.

    right now I'm inclined to call it a night and take another crack at it tomorrow.

    I have everything printed out and checked off each step as I went. Only thing I can think of is that I missed some registry keys. What is best way to ensure everything is found?

    thanks again for your help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    About:Buster does not do anything with O14 lines.

    You should have posted the About:Buster logs and also post a new HijackThis log. Post then as an attachment or attachments. It is not unusal to have to try some repetition to fix this problem. Especially since the hijackers are constantly evolving. However, this also happens if a particular instruction is not followed correctly, a step is skipped, or we fail to see a particular running process that is part of the problem and we do not end it and delete it.

    Did this go away? C:\WINDOWS\accessories.ico:kvuhp
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds