Ready for help with HJT!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by paul_porter, Dec 29, 2004.

  1. paul_porter

    paul_porter Private E-2

    I've been through the mandatory steps in the "do not post until..." tutorial twice now , and my problems persist.

    On the first pass, Trend and Symantec found a few files.

    Every time I run it, HSRemove finds and deletes 8 items, occasionally 9
    Spybot shows CoolWWWSearch.Feat2Installer every couple of passes. Ad-aware show critical items every time I run it.

    I can keep things at bay by running HSRemove, Spybot and Ad-aware every so often, and I seem "clean" for a time, but then I get hijacked again (about:blank in the address bar, and "Home Search" at the top of the page, about 2 virus alerts (McAfee) every time I open an IE Window.)

    I'm using XP Pro, SP2.
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Paul,

    Please send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis v1.99

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’m not around this forum too often these days, but somebody will try to take a look when they get a chance.

    Best :)
    PP
     
  3. paul_porter

    paul_porter Private E-2

    Thanks for the reply, PP. Here's the first log.
     

    Attached Files:

  4. PhilliePhan

    PhilliePhan Guest

    Did you run About:Buster as prescribed in the Tutorial?

    Also, do you recognize the following as legitimate and needed:

    O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
    O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
    O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
    O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} (TSCCInstall Class) - http://www.techsmith.com/codec/tsccinst.cab
    O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\WINDOWS\myCIO\Agent\myRmProt2.8.1.144.dll


    You have quite a few issues, including a couple potentially nasty ones. Please address the above, run About:Buster and post a fresh log.

    I have to run and will not be here often enough to work through this with you - I'll leave a message for our resident expert Chaslang to have a look!

    Best luck :)
    PP
     
  5. tagged

    tagged Private E-2

    Hi Paul!

    You should also move your HJT file into your Programs file, like PP mentioned before-C:\Program Files\HijackThis!, because, like they say, it's not a document or setting. ;)

    Good luck
     
  6. paul_porter

    paul_porter Private E-2

    I did run about:Buster at least twice. I don't remember it finding anything the first time, I know that it didn't the second time, and I've attached the log file from when I just ran it.

    With regard to the other stuff, I only recognize "AlternaTIFF", which is used to view patent documents. I don't need it or any of the other stuff.

    Second HJT log file also attached.

    Thanks for the help and the hand-off!!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you say About:Buster (AB for short) did not find anything? It showed a bunch of things.

    You need to update About:Buster. You're using Reference List : 19 and they are already up to Reference List : 21. Start it and do the update. But do not run the scan yet.

    Also make sure you have HSremove (from the READ ME FIRST).

    Make sure during the scans below you are not connected to the internet and DO NOT open any browsers until told to. You should print these instructions of save them locally. Because you must close all browsers and disconnect from the internet before running the following steps.

    Then exit all programs do a new AB scan. Make sure you click yes to run it a second pass. When it completes make sure you do not run anything at all. Immediately reboot but boot to safe mode and run AB again and again let it do both passes. Save both AB logs.

    Now while in safe run an HSremove scan. After it completes, reboot in normal mode. And get a fresh HJT log (make sure you have put HJT in the proper directory) and save it to hjtlog1.log. Now finally open a browser and then close a browser. Now get a second HJT log (call it hjtlog2.log).

    Now reopen your browser and come back here and post both AB and both HJT logs (that will require two messages). And also give me feedback on anything you noticed or any problems you had.
     
  8. paul_porter

    paul_porter Private E-2

    Done, tagged!! Thanks.
     
  9. paul_porter

    paul_porter Private E-2

    OK, chas.

    Regarding AB: It did not find anything the first two times I ran it as part of the tutorial. I did not mean to imply that it didn't find anything when PhilliePhan had me run it.

    Also, it tells me that I am running the latest version, 21.

    I completed all the steps, with nothing noteworthy or any problems. When I opened IE before the second HJT scan (disconnected mode), the page was different than the one I get while connected.

    When I opened IE connected to post, I got the hijack page, but not the two virus notifications that I usually get when opening a new IE window.

    The AB log is attached.

    Thanks!!!
     

    Attached Files:

  10. paul_porter

    paul_porter Private E-2

    Here are the HJT logs.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First a question, I am assuming that www.sharpsystems.com is related to your ISP and am ignoring the following two lines. Just let me know if that is a correct assumption.
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sharpsystems.com/
    O14 - IERESET.INF: START_PAGE_URL=http://www.sharpsystems.com/

    You have a few additional problems beyond the hijacker which we need to get fixed before concentrating on the hijacker. So I don't expect after the below that the hijacker will be completely gone.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Using HijackThis to kill processes:
    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    C:\WINDOWS\system32\ati3duag.exe
    C:\Documents and Settings\Peter\Application Data\toro.exe
    C:\WINDOWS\system32\w?nspool.exe
    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\izdiy.dll/sp.html#10001
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\izdiy.dll/sp.html#10001
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\izdiy.dll/sp.html#10001
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\izdiy.dll/sp.html#10001
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\izdiy.dll/sp.html#10001
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\izdiy.dll/sp.html#10001
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {4982D30C-67C2-4EDC-B9FB-50B7DB64D84D} - C:\WINDOWS\system32\mfchb32.dll
    O4 - HKLM\..\Run: [Kzvwwqm6s] C:\documents and settings\peter\local settings\temp\Kzvwwqm6s.exe
    O4 - HKLM\..\Run: [cdf8b1a7a6a0] C:\WINDOWS\system32\ati3duag.exe
    O4 - HKCU\..\Run: [Oaad] C:\Documents and Settings\Peter\Application Data\toro.exe
    O4 - HKCU\..\Run: [Lvmx] C:\WINDOWS\system32\w?nspool.exe

    Do you know what this TriDef Control is in the next line? For your Video card? If so, skip it? Otherwise I'm considering fixing it too. Let's just skip for now.
    O4 - Global Startup: TriDef Control Panel.lnk = C:\WINDOWS\system32\rundll32.exe

    Then continue fixing the following.
    O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\system32\maxspeed.exe (file missing)
    O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\system32\maxspeed.exe (file missing)
    O15 - Trusted Zone: *.awmdabest.com
    O15 - Trusted Zone: *.awmdabest.com (HKLM)
    O15 - Trusted IP range: 206.161.125.149
    O15 - Trusted IP range: (HKLM)
    O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
    O16 - DPF: {11117711-1111-1711-7121-111177111157} - ms-its:mhtml:file://c:\bebe.mht!http://www.alarm-works.com/tx.chm::/ai.exe
    O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\ati3duag.exe
    C:\Documents and Settings\Peter\Application Data\toro.exe
    C:\WINDOWS\izdiy.dll
    C:\WINDOWS\system32\mfchb32.dll
    C:\documents and settings\peter\local settings\temp\Kzvwwqm6s.exe
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. paul_porter

    paul_porter Private E-2

    chas, I'll get to your new instructions in a couple of hours. But to answer your question, www.sharpsystems.com probably relates to my computer, which is made by Sharp.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let me know when you finish the other steps.
     
  14. paul_porter

    paul_porter Private E-2

    chas, I'm finished.

    I completed everything as directed with the exception of the files you directed me to delete after rebooting:

    C:\WINDOWS\system32\ati3duag.exe Deleted
    C:\Documents and Settings\Peter\Application Data\toro.exe There was not direct match. I did find a file C:\WINDOWS\prefetch\toro.exe-28D5173.pf, which I did NOT delete
    C:\WINDOWS\izdiy.dll No such file found
    C:\WINDOWS\system32\mfchb32.dllNo such file found
    C:\documents and settings\peter\local settings\temp\Kzvwwqm6s.exe I found two versions of this file name, one with no extension and one with a .dll, and I deleted both

    Upon rebooting, I have had no problems. I did run some of the spyware programs, and here are the results:

    Spybot: found and deleted Coolwwwsearch.feat2installer
    Ad-aware: found and deleted 15 coolwebsearch items
    HSRemove: the usual 8 items removed

    New HJT log is attached.

    Progress!!!
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the C:\WINDOWS\prefetch\toro.exe-28D5173.pf file (in fact you can delete all files in the prefetch folder as a safety precaution). Also make sure you empty your Recycle Bin.

    Then goto: C:\documents and settings\peter\local settings\temp
    and delete everything in that temp folder.

    Does HSremove give you any indication of the filenames it is removing?

    Download this tool: Generic Detection Tool
    Then, unzip the Generic Detection Tool to a safe folder of your choice and run "findit.bat" - Allow it as much time as it needs to run. You may get an error message of "File Not Found," but just let it go.

    The tool should generate a long text file. Please attach that to your next post.

    Do not reboot after that because that can cause the files to mutate.
     
  16. paul_porter

    paul_porter Private E-2

    Here it is.

    By the way, not problems since the last post. Spybot show nothing after multiple scans. Ad-aware shows only cookies. HSRemove still shows that it removed 8 items, but I don't how to know what they are.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you run Windows Explorer and go to C:\WINDOWS\System32, can you see the below files:

    12/27/2004 08:56 PM 98,816 mfchb32.dll
    12/22/2004 01:17 PM 389,120 w?nspool.exe

    Note the w?nspool.exe may show up differnently but it is not the same thing as winspool.exe. Note the file size and dates. Make sure you can view hidden and also system file. If you can locate those two files, delete them. You may need to do this in safe mode.
     
  18. paul_porter

    paul_porter Private E-2

    Hey, chas.

    I got the first one, but w?nspool.exe did not appear.

    I have two winspool.exe files:

    winspool.exe 2,112 Application 8/18/2001 6:00AM
    winspool.exe 389,120 Application 12/22/2004 1:17PM which shows up as the last "w" file alphabetically (right after wzcsvc.dll )with a different icon than any other. It also says it was created on 12-27, even though last modified on 12-22 (what's up with that?)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds