Problems with Midaddle

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mariah, Oct 1, 2004.

  1. mariah

    mariah Private E-2

    I have been working to rid my computer of the "scum" Midaddle. I have read and completed all the scanning and cleaning steps and have a HJT log...I see some problems to fix but I'm afraid to do anything until an expert looks at the log. Any help you might give me would be greatly appreciated.

    Mariah
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have completed all the steps in READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Then you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    And then post a HijackThis log as a text document attachment to your message. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT
     
  3. mariah

    mariah Private E-2

    Thanks so much, here's my HJT logfile :
     
  4. Kodo

    Kodo SNATCHSQUATCH

    no log file.. try again ?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to save it to a .txt file instead of a .log file. .log file cannot be uploaded.
     
  6. mariah

    mariah Private E-2

    I will try again to send my HJT log file...I saved it as a text file so if it doesn't show up I am apparently doing something very wrong? Please have patience with me as I am "brain drained" over this problem that I guess I could live with but refuse to give up on. I just got a message from Nortons saying I have bloodhound.Exploit 6. I ran a full system scan and it was clear. My homepage is being hijacked and has to be restored constantly by Spysweeper. Once again, any help is greatly appreciated. Mariah

    I clicked Manage attachments but still no attachment.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not say say it as a text file. The log file is always a text file. The filename extension must be .txt (that's DOT TXT) not .LOG. When you save with HijackThis change the save as type to All files *.* and then change the name from the default hijackthis.log to anything ending in .txt. For example hjt.txt Make sure you are not trying to upload hjt.txt.log that will not work.
     
  8. mariah

    mariah Private E-2

    OK I'm trying again...here's my log. Thanks for your patience. Mariah
     

    Attached Files:

    • .txt
      File size:
      6.3 KB
      Views:
      5
  9. Kodo

    Kodo SNATCHSQUATCH

  10. mariah

    mariah Private E-2

    Yes, I went through the tutorial. Mariah
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I don't think she did. You can tell by looking at the HijackThis log. There is no evidence that the online scans were run. And there are a load of trojan type files in the log. Also the O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll line (for Coupon Deals), I would have expected that to get fixed. But maybe not.

    Mariah, what else did you skip. You also did not follow directions for shutting down your browsers before scanning with HijackThis. You had two IE sessions open:
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    Also, next time, please name the log file properly. You have to put something in front of the period. Your file was call .txt[1]. Please name it something like hjtlog.txt or hjt1.txt. Each time you post a log, you will need to give it a new name. So using hjt1.txt then hjt2.txt (and so on) is a good example.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. mariah

    mariah Private E-2

    No, I do not recognize that URL

    I ran :AdAware SE and plug-in
    Spybot Spyblaster
    CWShredder
    Kill2me
    I ran HJT and fixed the files I felt comfortable fixing without checking with MajorGeeks
    McAfee Avert Stinger for some reason did not work
    Sorry, I did not shut down the browser...
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are supposed to run all steps of the tutorial (except as noted with the about:blank and HSA hijacker tools). Why didn't you run the online scans? And what do you mean Stinger did not work? Be specific.

    Why didn't you run CCleaner?
     
  15. Kodo

    Kodo SNATCHSQUATCH

    yes, please. We're trying to help you. Following the tutorial to the letter is key to a successful cleaning of your PC.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Mariah,

    I'm going to try to get you started fixing this anyway. Please follow directions exactly and completely. I need you to do the below first before we do anything else with HijackThis.

    Also, you have a bad file in the LSP chain. Download LSPFix (http://www.cexx.org/lspfix.htm) and run it.
    Check the "I know what I am doing" box Click on cdlsp.dll on the left window and click on the
    arrow pointing to the right. Click Finish and follow the prompts.

    Now run Windows Explorer (click Start and select Explore). Locate and delete (if found):
    c:\windows\system32\cdlsp.dll

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit ALL browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://findloss.com/home.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://findloss.com/home.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.vrqlexkwjpvmtqjwrck.com/PGw6jia1baC_fdcy91SbQfFlkDVvb24eKAS6FriwX9KjJr6AEOkgfokrxVL/Q_On.jsp
    O2 - BHO: (no name) - {000B7009-B5AA-1927-3BC8-499C4E4B6A3C} - C:\PROGRA~1\INTERN~2\EXIT BAGS.exe
    O2 - BHO: (no name) - {5BC885AF-2874-1D7F-6DF1-527A8A9EF2F0} - C:\PROGRA~1\INTERN~2\EXIT BAGS.exe
    O4 - HKLM\..\Run: [4S2NSLA3QS#366] C:\WINDOWS\System32\Dtck1376.exe
    O4 - HKLM\..\Run: [info program] C:\PROGRA~1\CREATI~1\Trans Tray.exe
    O4 - HKLM\..\Run: [pFsk3nh] aclc32.exe
    O4 - HKLM\..\Run: [Wipe book bird delete] C:\Documents and Settings\All Users\Application Data\FIVEWINDOWWIPEBOOK\InfoLoud.exe
    O4 - HKLM\..\Run: [Download Platform Fast Setup] C:\Documents and Settings\All Users\Application Data\PHONE CAKE DOWNLOAD PLATFORM\Armyknob.exe
    O4 - HKCU\..\Run: [Yo3qRhN7S] forcconf.exe

    Boot in safe mode and run Windows Explorer (click Start and select Explore). Locate and delete (if found):
    C:\PROGRA~1\INTERN~2\EXIT BAGS.exe <--- note this is a shortened filename path. It is really something beginning with C:\Program Files\
    C:\WINDOWS\System32\Dtck1376.exe
    C:\PROGRA~1\CREATI~1\Trans Tray.exe <--- note this is a shortened filename path. It is really something beginning with C:\Program Files\
    c:\windows\system32\aclc32.exe
    c:\windows\system32\forcconf.exe
    c:\windows\system32\cdlsp.dll <--- just in case it did not delete above.
    C:\Documents and Settings\All Users\Application Data\FIVEWINDOWWIPEBOOK <--- delete the whole directory
    C:\Documents and Settings\All Users\Application Data\PHONE CAKE DOWNLOAD PLATFORM <--- delete the whole directory

    Reboot in normal mode and post a new HJT log attachment (hjtlog2.txt) and tell us how these steps went.
     
  17. mariah

    mariah Private E-2

    I did run Ccleaner...the only thing I did not run was McAfee AVERT Stinger which did not want to run. Should I start all over again? Mariah
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You did not run the online scans either. Please follow my steps below. You just missed them.
     
  19. mariah

    mariah Private E-2

    Chaslang,
    I downloaded LSPFix and ran it. Then I located the cdlsp.dll file but was unable to delete it....the error message said to make sure the disk was not full or write-protected or in use. Should I try it in safe mode? To close all browser sessions can I just Ctrl,alt, del and close them under applications? I will wait to continue the instructions you sent until I hear back from you. Thank you for your time. Mariah
     
  20. Kodo

    Kodo SNATCHSQUATCH

    Mariah,
    yes, try to delete the file while in safe mode. To close all browser session, you must view the processes tab (ctrl+alt+del) and end task each one of the iexplore processes listed.
     
  21. mariah

    mariah Private E-2

    I downloaded SSPFix and got rid of the cdlsp.dll file (in safe mode) then I ran HJT and fixed the files that Chaslang listed . I went into safe mode and found trans tray.exe,fivewindowwipebook and phonecake, and deleted them. I rebooted into normal mode, ran a new HJT log and it is attached. Thank you all....I await further instructions. Mariah
     

    Attached Files:

  22. Kodo

    Kodo SNATCHSQUATCH

    Looks good to me! :)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well not completely! There's still these to fix. Unless you know that findloss.com is okay, I would fix those two lines. The R0 line definitely has to be fixed.

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://findloss.com/home.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://findloss.com/home.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.jgjwzuwmucuurivs.com/PGw6jia1baC_fdcy91SbQfFlkDVvb24eKAS6FriwX9L8Lp2TObwNBokrxVL/Q_On.jpg

    Then post a new and hopefully final log.
     
  24. Kodo

    Kodo SNATCHSQUATCH

    damn and it was only 11:30pm.. I'm losin it.
     
  25. mariah

    mariah Private E-2

    Here is my 3rd logfile.....had some trouble trying to close iexplore processes before running the scan for the logfile. I would end the task and they would reappear. Mariah
     

    Attached Files:

  26. Kodo

    Kodo SNATCHSQUATCH

    Mariah,
    there are still problems. Chas and I are discussing further options.
     
    Last edited: Oct 7, 2004
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, and not only did the R0 line come back (morphed to something else) but the other items we cleaned up came back:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.rhceenjursmusstfgpqkpvj.com/PGw6jia1baC_fdcy91SbQfFlkDVvb24eKAS6FriwX9IgdjI/sled4YkrxVL/Q_On.html
    O2 - BHO: (no name) - {5BC885AF-2874-1D7F-6DF1-527A8A9EF2F0} - C:\PROGRA~1\INTERN~2\EXIT BAGS.exe
    O4 - HKLM\..\Run: [info program] C:\PROGRA~1\CREATI~1\Trans Tray.exe
    O4 - HKLM\..\Run: [Download Platform Fast Setup] C:\Documents and Settings\All Users\Application Data\PHONE CAKE DOWNLOAD PLATFORM\Tray Remote.exe
     
  28. Kodo

    Kodo SNATCHSQUATCH

    and I love this
    C:\PROGRA~1\INTERN~2
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yeah! They try to make it look like Internet Explorer.

    Mariah, what is the real full directory name? This is a shortened (8 character file name).
     
  30. mariah

    mariah Private E-2

    C:\PROGRA~1\INTERN~2\EXIT BAGS.exe I found it in program files, internetbrowsr eal folder then exit bags.exe file. Should I delete it (in safe mode)?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, you can repeat all the stuff I gave you last time in message #16

    Make sure you get all the items in message #27.

    Then post a new log.
     
  32. mariah

    mariah Private E-2

    OK, Chaslang, I repeated your instructions and hopefully this 4th log will be useful to you. Once again, I had trouble closing iexplore applications because they kept reappearing. Thanks for your help. Mariah
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    iexplore.exe does not appear in your log. Where they actually opening still? Next time if you do not have any IE windows open do not attempt to close the iexplore.exe sessions.


    Did you ever fix the below with HJT:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://findloss.com/home.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://findloss.com/home.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.jgjwzuwmucuurivs.com/PGw6jia1baC_fdcy91SbQfFlkDVvb24eKAS6FriwX9L8Lp2TObwNBokrxVL/Q_On.jpg
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do a file search on your PC for iexpIore.exe. Tell me where it is found.
    Do the same for explorer32.exe .
     
  35. mariah

    mariah Private E-2

    Here are the files I found when I searched iexplore.exe:

    1. C:\programfiles\internet explorer
    2. Windows\servicepackfiles
    3. program files\compaq\work...
    4. compaq\msmoney\ie\iemil
    5. windows\softwaredist...
    6. windows\prefetch (this was found under iexplore.exe-odfo7eco.pf)
    7. windows\prefetch (this was found under iexplore.exe-27122324.pf)

    I found no files under explorer32.exe

    Mariah
     
  36. mariah

    mariah Private E-2

    another iexplore file appeared...it is

    windows\prefetch--28a0b06f.pf
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you have Advanced search options enable so you search hidden and system files/folders?

    Also search for explorer.exe!
     
  38. mariah

    mariah Private E-2

    I did a search for explorer.exe and this is what I found:

    1. C:\windows
    2. C:\windows\prefetch (explorer.exe-082f38a9.pf)
    3. windows\servicepackfiles\i...
    4. Compaq\msmoney\ie\ie4shl...
    5. Compaq\msmoney\ie\ie4shl...
    6. windows\softwaredistribut...

    I select start, then search. Under tools, folder options,view, I have show hidden files and folders checked and I also have display system folders checked. Should I be searching another way? Mariah
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That does not setup search options. It only sets up options for what Windows Explorer displays.

    Click Start, Search, All Files and Folder, More advanced options! And under that you will see options to enable you to:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders

    Make sure those three are selected. Then do your searches.
     
  40. mariah

    mariah Private E-2

    I have attached the log of files I found searching iexplore.exe and explorer.exe.....I found nothing in explorer32.exe . Thanks again.

    Mariah
     

    Attached Files:

  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These attachments are not text files. What exactly did you attach?
     
  42. mariah

    mariah Private E-2

    Here is what I found searching explorer.exe

    1. C:\Documents and settings\Adm
    2. Windows
    3. Windows\$NTServicePackU...
    4. Windows\Prefetch (explorer.exe-082F38A9.pf)
    5. Windows\ServicePackfiles\i...
    6. Compaq\MsMoney\IE\IE4SHL
    7. Compaq\MsMoney\IE\IE4SHL
    8. Windows\Softwaredistribut...

    Here is what I found searching iexplore.exe

    1. C:\Documents and Settings\Adm
    2. Same as above
    3. Same as above
    4 C:\Program files\Internet Explorer
    5. Windows\$NTServicePackU... (this appears in blue)
    6. Windows\Prefetch (iexplore.exe-0DFD7ECO.pf)
    7. Windows\Prefetch -27122324.pf
    8. Windows\Prefetch -28AOBO6F.pf
    9. Windows\ServicePackfiles\i...
    10 Compaq\MsMoney\IE\IEMIL_...
    11. Windows\SoftwareDistribut...
    12. Program files\COMPAQ\work...

    Nothing under explorer32.exe

    Thanks,
    Mariah
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Mariah,

    Forget about seaching for explorer32.exe.

    I need the fullpath. For example you gave:
    C:\Documents and Settings\Adm

    That would appear to be incomplete. It is probably something like
    C:\Documents and Settings\Administrator\Local Settings and maybe more

    I need fullpath for all lines above. Also make sure the filename being match is really explorer.exe and iexplore.exe

    But just a note, there should be no instances of explorer.exe or iexplore.exe in any directory under C:\Documents and Settings
     
  44. mariah

    mariah Private E-2

    Here is what I found searching explorer.exe

    1. C:\Documents and settings\Administrator\local setting\temp\AAWTMP\C1814953
    2. Windows
    3. Windows\$NTServicePackUninstall$
    4. Windows\Prefetch (explorer.exe-082F38A9.pf)
    5. Windows\ServicePackfiles\i386
    6. Compaq\MsMoney\IE\IE4SHL95.CAB
    7. Compaq\MsMoney\IE\IE4SHL.CAB
    8. Windows\Softwaredistribution\download\6Ca7b3a8efd5A9b6f87fff395a2eb989

    Here is what I found searching iexplore.exe

    1. C:\Documents and Settings\Adm (same as #1 above but in iexplore.exe)
    2. Same as above but ending in ient_l.CAB
    3. Same as above but ending in ie_l.CAB
    4 C:\Program files\Internet Explorer
    5. Windows\$NTServicePackUninstall$
    6. Windows\Prefetch (iexplore.exe-0DFD7ECO.pf)
    7. Windows\Prefetch -27122324.pf
    8. Windows\Prefetch -28AOBO6F.pf
    9. Windows\ServicePackfiles\i386
    10 Compaq\MsMoney\IE\IEMIL_2.CAB
    11. Windows\SoftwareDistribut... (Same as #8 under explorer.exe)
    12. Program files\COMPAQ\works6.0\Redist\IE5\Iemil_2.CAB



    Thanks,
    Mariah
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shut down all applications and please delete all files in this directory

    C:\Documents and settings\Administrator\local setting\temp

    After this post a new HJT log and tell me what our outstanding problems are now.
     
  46. mariah

    mariah Private E-2

    I deleted all C:\documents and settings\adminstrator\local setting\temp

    When I deleted the files the following happened when I searched under explorer.exe

    Windows\Prefetch (explorer.exe-12DOB496.pf) was added
    Windows\Prefetch (explorer.exe-082F38A9.pf) was modified

    Under iexplorer.exe the following happened:

    Windows\Prefetch-28A0B06F.pf disappeared
    Windows\Prefetch-27122324.pf modified

    I am still having my browser hijacked. I have attached a new HJT log. I tried to shut down all applications hope it worked.

    Thanks,
    Mariah
     

    Attached Files:

  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those Prefetch file are ok. But what I still need you to do is run the online scans you never ran.
    Please go back to the tutorial and run them. Also download the latest update (today) of Stinger and try running it too. Run them in safe mode. If you have a problem running in safe mode, then run in normal boot mode. Tell me what results you get. If you get any error messages, tell me the exact message.

    Also go to the Alternative Scans section of the READ ME and run A-squared.
     
  48. mariah

    mariah Private E-2

    Here's what I did:
    Trend Micro's Virus Scan....clean
    Symantec Security Check....clean
    McAfee AVERT stinger (Updated)...clean
    CCleaner.....cleaned files and deleted index.dat
    Ad-Aware SE ...clean
    Oh, I didn't run Spybot....I run it all the time though and it always has CoolWeb and I delete it. I will run it when I log out.
    CWShredder...removed 2 infected IE registry values
    Kill2me...no infection
    Ran a new HJT log and it is attached.

    My Spy sweeper is telling me that my home page is being changed and wants me to restore....

    I'm sorry I didn't run the logs last time but I thought I had...apparently, I just installed the files? Guess that's a clue to how really computer literate I am.
    Thanks, Mariah
     

    Attached Files:

  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These lines came back again. You need to repeat the procedure from message # 16 and only insert these lines as the rest are gone. If you need me to spell out the exact steps, let me know.

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mwmkzwqjgzlyxippaybhmc.com/PGw6jia1baC_fdcy91SbQfFlkDVvb24eKAS6FriwX9Kt6wMhwXz42IkrxVL/Q_On.asp
    O2 - BHO: (no name) - {5BC885AF-2874-1D7F-6DF1-527A8A9EF2F0} - C:\PROGRA~1\INTERN~2\EXIT BAGS.exe
    O4 - HKLM\..\Run: [info program] C:\PROGRA~1\CREATI~1\Trans Tray.exe
    O4 - HKLM\..\Run: [Download Platform Fast Setup] C:\Documents and Settings\All Users\Application Data\PHONE CAKE DOWNLOAD PLATFORM\flag vga.exe
     
  50. mariah

    mariah Private E-2



    I repeated the steps in message #16 and when I ran HJT the R1 findloss.com/home.html was there again so I removed both files. The 04 HKLM\..\Run:[info program[ C:\Progra~1\CREATI~1\Trans Tray.exe was not there....there was a file that looked similiar but I will wait until you say to remove it. I have attached another log. Thanks, Mariah
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds