Search-to-find .....been hijacked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by EDR, Jul 26, 2004.

  1. EDR

    EDR Private E-2

    First off due to the nature of this spyware/hijacker I've come to understand that it's pretty specific to the individual pc it has hijacked.......am I right? well that being the case I have ran and logged with HijackThis but before I corrupt any files I thought I best ask for assistance.I have read a few of the other posts concerning this same matter and that is why I figured that it's removal is specific to the pc that was hijacked. So........I got hijacked by the "Search-To-Find" anoyance (though I gotta say whomever developed it is pretty smart,just devious) anyways I'd like to rid my pc of it without killing anything important so heres my log if anyone can helpme out here I'd appreciate it.


    [log removed. ALL LOGS MUST BE UPLOADED AS A TXT FILE ]
     
    Last edited by a moderator: Jul 26, 2004
  2. Kodo

    Kodo SNATCHSQUATCH

    Download:

    HSRemove
    About Buster
    Ad-Aware
    Spy-Bot: Search and Destroy
    HiJackThis

    and do the following:
    install ad-aware and spy-bot. Update the programs but do not run them.
    Make sure you have an updated antivirus installed (AVAST is recommended if you do not)

    once updated, reboot into safe mode and run HSRemove followed by About Blaster
    then run Ad-Aware followed by Spy-Bot S&D. Then Scan using your AV and Then run HijackThis and copy your log to a text file.

    Reboot normally and upload your logfile to a post here for us to look at.
    DO NOT POST YOUR LOG DIRECTLY TO A POST. it must be uploaded as a text document file.
     
  3. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  4. Kodo

    Kodo SNATCHSQUATCH

  5. EDR

    EDR Private E-2

    I'm back and forth today cause I'm painting the house <-----yuk ...Anyways Sorry bout posting a log I know better now ;) I will do as suggested Kodo Question I run AVG currently is Avast better? also in your oppinion what is the best anti virus proggie (I don't mind the cost) (this pc I'm on is my bro in laws) mine is not connected on-line yet but when it is I want the best prog avalible cause I use it for music video rendering (my hobby) I'd hate to loose any files on my pc.I also run Bazooka and Pop This on this pc I already had Ad-aware and spyware DR should I get rid of some of these?
    Thanks for the responses peeps.........EDR
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I prefer AVG. NOD32 is killer, but not free. Avast is excellent as well. Bazooka? I would like more info on what your running, some popup blockers and prograsm are spyware themselves. I suggest hitting our browser section and getting atested, safe, free popup blocker. Ad-Aware and Spybot should cover you. Finally, try Mozilla Firfox, lot of people converting to it for good reason. Less hijacks, popup blocking built in , etc.
     
  7. EDR

    EDR Private E-2

    Hello again, Major A....... http://www.kephyr.com/spywarescanner/index.html?source=appvisit this is Bazookz scanner it is a pretty cool tool if it finds a threat it tells you how to get rid of it step by step instructions via regedit.. I'm not too sure that it blocks anything but it finds stuff real well. Thanks for all the help anyone who has been kind enough to give their advise to me. (guess I'll be busy tonight getting rid of a bug) btw the auto buster deal tells me to fix random stuff from the HijackThis prog in except R1 R0 's before running it? Whats that all about?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because About:Buster fixes those R0 & R1 lines when it runs.
     
  9. EDR

    EDR Private E-2

    Well I ran HSR,About Blaster,Ad-Aware,Spy-Bot,and Avast in safemode and all of which found something.........theres still apop up present and Search-to-Find is still here too :rolleyes: I attached the Hijack this log.....what now?I,m confused....
     
  10. Kodo

    Kodo SNATCHSQUATCH

    I don't see your HJT log.. if you can't figure out how to upload a file, just post the text and one of the mods will copy it to a text file for you...this time.. ;)
     
  11. EDR

    EDR Private E-2

    ooops it wasnt in the right format....here it is
     

    Attached Files:

    • log.txt
      File size:
      5.9 KB
      Views:
      3
  12. Kodo

    Kodo SNATCHSQUATCH

    you're infected with a Trojan called TROJAN AGENT.AE

    you have to get rid of that first.. but in order to do this, you must NOT be connected the internet and should be in safe mode. HSRemove should take care of it but if it doesn't you may need to run another application that seems to work called a2 (A-squared).
    http://www.majorgeeks.com/download.php?det=4281

    the attached file is what you should remove in HiJackThis.
     

    Attached Files:

    • hjt.txt
      File size:
      1.6 KB
      Views:
      7
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kodo, this line is okay:
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
     
  14. Kodo

    Kodo SNATCHSQUATCH

    woops.. didn't think I copied that..
     
  15. EDR

    EDR Private E-2

    The list of anti spyware progs I mentioned is what I ran in Safe mode so I guess it didnt do it right? Well then I'll download A2 and give it a try in safe mode then remove the stuff on the attached list with Hijackthis..........Is this correct?
     
  16. Kodo

    Kodo SNATCHSQUATCH

    yes. That Trojan is a nasty one for sure. I worked on a machine the other day and had to run HSremove in safemode several times before it was terminated and then ran an AV to clean up any leftovers. Apparently A-Squared is a good program to use for this Trojan.
     
  17. EDR

    EDR Private E-2

    OK I ran HSR again and the a2 in safe mode heres the new log
     

    Attached Files:

  18. NeoNemesis

    NeoNemesis Moutharrhea

    I just thought i would add this in:

    O9 - Extra button: (no name) - {91663649-416A-42A5-8E54-B63C1ECA0548} - (no file)
    O9 - Extra 'Tools' menuitem: PopThis! Options... - {91663649-416A-42A5-8E54-B63C1ECA0548} - (no file)

    You might want to delete those since theres nothing there.
     
  19. NeoNemesis

    NeoNemesis Moutharrhea

    I just thought i would add this in:

    O9 - Extra button: (no name) - {91663649-416A-42A5-8E54-B63C1ECA0548} - (no file)
    O9 - Extra 'Tools' menuitem: PopThis! Options... - {91663649-416A-42A5-8E54-B63C1ECA0548} - (no file)

    You might want to delete those since theres nothing there.

    Oh and didn't someone here at MG say that messenger plus had spyware in it?

    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
     
  20. EDR

    EDR Private E-2

    Thanks for the added advise........Q. should I be in Safe mode to do the list with Hijack this? and also did that last try get rid of the Trogen.AE? So just so I'm real clear the list Kodo posted minus the one line and plus the 3 lines NeoNem added are the things I should check in Hijack this?
     
  21. EDR

    EDR Private E-2

    Another Question.....If I come online before going through the Hijack this list and repairing ....does that mean I need to go back through the "cleaning " process again? or can I just go into safe mode and do the hijack list?
     
  22. EDR

    EDR Private E-2

    And another......I notice on the list to check in Hijackthis .......R1 Hklm with Coopernik 2000 pro ........ this is a bought program I installed (it's an awsome search engine.....is it spyware? cause it never gave me a problem? and also the acid planet ...it's my preference for home page........
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I believe that it is okay. Probably just an oversight when Kodo was cutting and pasting. Correct me if I'm wrong Kodo. But I have seen this Copernic 2000 Pro program many times and thought it was okay.
     
  24. EDR

    EDR Private E-2

    Grrrrrrrrrrrrrrrrrrrrrrrrrrrr! I went into safe mode ran All of the progies again then did the hijack this list and I still have the search-to-find...... I just don't get it.....lol I posted the new log file after I did the list.......every few minutes my homepage is trying to be jacked to by some //res.(random).dll(blah blah htlm) ?
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need a log from normal boot mode. A safe mode log will not show the problem.
    Do not fix any lines with HJT. I need to see an unmodified log.
     
  26. EDR

    EDR Private E-2

    this time I ran the CWprogram and just about all the others came up clean but lo and behold it's till there? LOL I'm going nutz!!! btw I did turn off the sys restore and the NSS as suggested in the tutorial....the sys restore though is now back on...but I did it before I went online
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should leave system restore off until this is fixed.

    I also want you to download ProcessExplorer from here: http://www.sysinternals.com/files/procexpnt.zip
    Then run it and kill these processes:
    iepl.exe
    imapi.exe
    appov32.exe

    Then enable viewing of hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650
    Find and delete those two files:
    C:\WINDOWS\system32\iepl.exe
    C:\WINDOWS\System32\imapi.exe
    C:\WINDOWS\system32\appov32.exe

    Now quickly reboot in safe mode: http://service1.symantec.com/SUPPOR...src=sec_doc_nam
    Run HSremove. Save log.
    Run about:Buster twice (that's two complete times. which will give 4 scans) Save each log.

    Reboot normal mode and post HSremove log, both AboutBuster logs, and a new HJT log (put them in one attachment file).
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should also have HijackThis fix this lines (not related to HSA hijack):
    O9 - Extra button: (no name) - {91663649-416A-42A5-8E54-B63C1ECA0548} - (no file)
    O9 - Extra 'Tools' menuitem: PopThis! Options... - {91663649-416A-42A5-8E54-B63C1ECA0548} - (no file)
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
    O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab
     
  29. EDR

    EDR Private E-2

    when I have hijack fix stuff do I need to be in safe mode or not?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not for the stuff I gave you. Did you do the other steps with ProcessExplorer yet.
     
  31. EDR

    EDR Private E-2

    ok ....I killed the iepl.exe and the appov32.exe the other wasn,t there and the only one I found that I can delete is the imapi.exe
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Quickly do the other steps!!!! If you see this before rebooting, physically disconnect your internet connection (unplug the cable) too before continuing.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait!!! Did you mean you found the others but could not delete them?
     
  34. EDR

    EDR Private E-2

    I fixed the 4 things with hijack but I'm waiting for a reply on the other :)
     
  35. EDR

    EDR Private E-2

    the iepl.exe and the appov32.exe are the only ones showing in the process explorer prog....and the imapi.exe is the only one I can find in the winows/system32 folder
     
  36. EDR

    EDR Private E-2

    I killed the 2 processes I found but did not delete anything in the sys32 folder
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Start with running ProcessExplorer to double check that they have not started up again and run right thru the procedure quickly. Make sure to physically disconnect from the internet (even before killing the processes if they exist again.)
     
  38. EDR

    EDR Private E-2

    HS remove and About buster didnt give me and log options.......but
    -- Scan 1 --------
    About:Buster Version 1.31
    Attempted Clean Of Temp folder.
    Pages Reset... Done!

    -- Scan 2 --------
    About:Buster Version 1.31
    Attempted Clean Of Temp folder.
    Pages Reset... Done!




    HSR 12 items removed
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It came back. See these processes.
    O4 - HKLM\..\Run: [crhs.exe] C:\WINDOWS\crhs.exe
    O4 - HKLM\..\RunOnce: [iepl.exe] C:\WINDOWS\system32\iepl.exe
    O4 - HKLM\..\RunOnce: [mfcrf32.exe] C:\WINDOWS\system32\mfcrf32.exe

    I think we are going to have to do my long step by step. Procedure with some additional new steps.

    This was my Generic Procedure. See if you can follow along with it but add the below steps when you get to step 13 (after these continue on with step 14 and above from the Generic Solution).

    Before starting make sure you download and install CCleaner from here:
    http://www.majorgeeks.com/download4191.html

    13A. Search the registry for every instance of xxxxx.dll (the file from step 5). Change the values for your home and search pages to what you want (www.majorgeeks.com will do).
    13B. Search the registry for every instance of the suspicious exe files found by Hijack This from step 8. Delete every instance.
    13C. Run CCleaner and on the Windows tab (you'll see when you run it) leave the defaults and click Run Cleaner.
    13D. Search your computer for xxxxx.dll. Delete each instance.
    13E. Search your computer for the suspicious exe files. Delete each instance.
    13F. Delete the Prefetch folder in C:\WINDOWS.
    13G. Delete Memory.dmp in C:\WINDOWS or was it C:\WINDOWS\System32
    13H. Run HSRemover.
    13I. Run about:Buster.

    I gotta go now I'll check back tomorrow (later today). Gotta sleep!!!!!
     
  40. EDR

    EDR Private E-2

    Hmmmm tryed it .... seems it's here to stay, it's my bro-in-laws pc and I'm going back to Montana tomoro and I am finishing the painting of his house today so I'm back and forth.If you can help that would be cool (1-on-1) I'll check back between coats.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand this. The Generic Solution has always worked. Something is missing here. Send me a new HijackThis attachment and do not shutdown, reboot, or clean anything up by hand. You must leave the PC running otherwise the problem will mutate and do not try to change any HijackThis lines or kill any process either. You can disconnect your PC from the Internet just don't shutdown or reboot. I will work up a step by step procedure tailored for your log.

    The HSA and About:Blank hijackers are quite difficult to remove and they do find ways to respawn themselves from many different files. It does take a lot of repetition to get everything. So they cannot respawn. Also, the order of the steps and doing exactly as requested are very importane. For example, physically disconnecting from the Internet. These hijackers have many different processes, DLL, DAT files etc all loading/running. Anyone of them can try to find a pathway out of your PC even if Internet Explorer is not running. I say "unplug the cables" to make it impossible for them to get out.

    One other useful item you can give me with the HijackThis log it a list of the running processes as found by ProcessExplorer. Run ProcessExplorer and click on File and then Save As. And save the list as a text file. Attach it with the HJT log.

    Also, while waiting for me to come back with a procedure to follow, answer these questions:
    - what version of HSremove do you have
    - what version of About:Buster do you have
    - what version of Ad-aware do you have and what reference list version too

    Also run these two online scans and fix what they find (tell me if and what they find):
    http://housecall.trendmicro.com/housecall/start_corp.asp select Auto Clean
    http://www.pandasoftware.com/activescan/com/activescan_principal.htm
     
  42. EDR

    EDR Private E-2

    Ummmmmm well before I got to your new response ...I ran an on-line scan and found 3 things...Troj Stillen.a,CHM PSYME.Y and JS INOR.M I coulnt delete them cause they were in use so I turned off the dsl connection at the switch, turned off the sys-restore, disabled Network Security Service and went into safe mode. This system is updated too. I used the "CrapCleaner" then scaned with norton and again with the cleaner.I next ran HSR twice, About Blaster twice, Adaware and the plugin, Spybot, and the CWshredder. This round the progies all found stuff. I am running HSR v2.39,HiJackThis v1.98,About Blaster v1.31, Adaware 6.0.1.181 with PLVX 1.1 I attached the following 3 logs....Adaware, HiJack This and the processes
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your not up to date with about:Buster. That's why we keep saying check for updates.
    Version 1.32 came out two days ago. I'm not saying it is going to change any of the results but each time I have been asking you to run it, you are out of date. You did not tell me the reference file version for Ad-aware. It shows right on the main screen.

    What was the Path to Executable for the Network Security Service?

    Edit: okay I got your reference file version from the log. It is current.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The last logs you sent me show everything to be clean. Are you still having problems with the HSA hijacker? If so, show me the HJT log and ProcessExplorer list when the problem has occurred and do not fix anything and do not shutdown or reboot.
     
  45. EDR

    EDR Private E-2

    At the moment I'm not experiencing any hijacks.....do you think it's gone??
     
  46. EDR

    EDR Private E-2

    I must have sent the last reply just as you did......same time......Um no I think it's gone...so would now be a good time to turn on the sys restore?
     
  47. EDR

    EDR Private E-2

    here's the latest hijack log ... I don't see anything bad, do you?
     

    Attached Files:

  48. EDR

    EDR Private E-2

    ummmm spy bot keeps finding DSO EXPLOIT and some msc tracking cookies
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good! Is this the expected home page:
    http://www.acidplanet.com/artist.asp?songs=270011&T=6170

    If you have rebooted a couple of times and tried opening and closing Internet Explorer a few times and do not have anymore problems, yes enable system restore.

    Got to run for awhile. Be back later tonight!
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are up to date with all Microsoft Critical Updates ignore SpyBot's DSO Exploit messages. It is a bug in SpyBot. You can disable them from Advanced mode, Ignore Products.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds