shopnav and 2020search revived???

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ronin7, Jun 7, 2004.

  1. ronin7

    ronin7 Private E-2

    My son has gotten a hijacker loaded on his system. It appears to be a revival of the "shopnav" and "2020search" hijackers-- only this time on steroids.

    Adaware won't remove these, even cloaked. Removal instructions I've found in various places (most at least a year old) don't quite match up to what I'm finding in the registry. HijackThis doesn't tell me anything that I haven't already found out-- it only lists the hostile registry entries that I have already identified and tried to remove.

    Every attempt to delete the components fails. They are almost immediately reinstalled. Registry keys that I delete are replaced within 30 seconds. Whatever is replacing them is cloaked-- no obviously questionable processes show up on the task manager (Win 98se), Adaware log, HijackThis log, nor on AIDA32. The only oddities are "pstore.exe" and "wmiexe.exe"-- which appear to be NT protection components.

    Furthermore, the system will no longer boot into safe mode. In an act of desperation, I tried forcing it into safe mode by powering it down in the middle of a boot. (I've already backed up the data and I'm going to reload the OS anyway). It booted to safe mode, but the keyboard and mouse were locked out. This wasn't just a quirk of timing-- it did this three times in a row.

    Did my son accidentally cause this mess, or is this a new breed of Monster Scumware? Am I overlooking something blantantly dumb? Any ideas? Know of any other places I could go for help? (I've tried several that are linked through this forum--- no help, but I'm still looking.)

    Thanks!

    P.S. I'll post the HT log if anyone requests it. I didn't on this message because I haven't provide full specs and info on the system...
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. ronin7

    ronin7 Private E-2

    Thanks--- This looks helpful. I'll check it out and let you know how it goes. (Or doesn't.)
     
  4. ronin7

    ronin7 Private E-2

    Yes indeed-y, it does boot to safe mode that way. I have successfully removed every particle of hijacker I could find, but the system is still acting a little hinky, and still won't boot to safe mode by any other method but through msconfig. I'm going to reload the OS anyway.

    Thanks for the advice, though!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean "acting a little hinky"? Besides having a problem booting in safe mode using the F8 method which has always been troublesome for many people. The msconfig method is really the best method for Win98 & Me. Why do you want to reload the OS?
     
  6. ronin7

    ronin7 Private E-2

    "Hinky"-- doesn't shut down the same as it used to, some browser defaults have changed, I'm getting blue-screens in situations I didn't get them before. (The F8 key is definitely changed, because I've never had any problems using it to access safe mode before, and I've done it a lot on this machine.)

    Why? Basically, because I don't know what else may have changed, and I don't trust that all the system settings are restored correctly.

    Experience has taught me that when these things start happening after doing major registry surgery due to this kind of attack, the performance of the OS often continues to degrade. Windows inherently keeps "dirt" in the registry, and unless you're really good at cleaning it up (which takes time), it will eventually come back to bite you.

    In my case, I was considering reloading the OS anyway, because this is an old work system I gave to my son to use, and formatting & reloading was a faster way to clean it up than uninstalling and deleting all of my old stuff.

    Seriously, though, I think the practically of wiping & reloading a system is often underestimated. I've seen MANY people spend countless hours trying to fix a busted registry-- often many more hours than it would take to make a "clean start"-- only to get a "hinky" system that annoys them for months afterward. (The use of Norton Ghost -- or similar program -- can make the reload process even more practical and less painful.)

    You're right that using msconfig to access safe mode is a more reliable method. (Providing the system will boot at all.) Embarassingly, I use that method so rarely that I had forgotten about it. Thanks for jogging my memory, though-- you gave good advice!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ronin, Okay! Don't get me wrong sometimes re-installing your OS (and maybe doing an OS upgrade if the PC can handle it) are good ideas and in some cases may be less time consuming. For some people it is a nightmare though because they have so much stuff on their system that have to get reinstalled and/or have lots of personal (i.e., loads of MP3s) info to backup. I just hate to see it done to quickly with out trying to fix first. It's always good to learn some new stuff before taking the easy way out. :)
     
  8. ronin7

    ronin7 Private E-2

    I took no offense at your question. (Got to start using the smilies again...) Many people (still) don't backup enough (groan!) and in those cases, there's a good reason to keep at it.

    As I said, I was already going to reload the OS anyway. Actually, I only kept at it because (as you suggested) I wanted to see if I could defeat the monster. I did learn some things that could help me in the future, so thanks again!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool! :cool: It's good to learn! Knowledge is power! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds