Spyware hijackers winning

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sponk, Mar 2, 2005.

  1. Sponk

    Sponk Private E-2

    I have been problems with spyware hijackers and until recently I have been getting on top of them. However recently, dispite regular scans I have had both Aol and explorer showing that stupid search for engine :mad:

    I have hijack this and would like help in getting rid of the rubbish.

    Thanks!
     
  2. Sponk

    Sponk Private E-2

    Re: Spyware hijackers winning additional

    Forgot to mention I have used Adware, Spybot and CWShredder and they say that they have got rid of CoolWebsearch but they still come back. :rolleyes:
     
  3. PhilliePhan

    PhilliePhan Guest

    Hi Sponk,

    Generally, it is a good idea to take a spin through the Cleanup Tutorial below:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    There are only a few of us Volunteers who regularly offer advice in this forum. Running through the above Tutorial will remove a lot of stuff that would otherwise clog a HijackThis Log and save us valuable time.

    Please let us know the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99.1) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis! Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99.1

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Best luck :)
    PP
     
  4. Sponk

    Sponk Private E-2

    Thanks!

    Here is the file.
     

    Attached Files:

  5. tblue

    tblue Corporal

    Hi Sponk,
    You are not running the lateste version of HJ. Your version is v.199.0
    The new version is v.199.1, you can download it in the tutorial that Phillie asked you to follow. You should download and run again and post log.
    Good Luck, :)
    T.Blue
     
  6. Sponk

    Sponk Private E-2

    OK... Take two!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since PP is not around, I'll keep you moving along.

    First you must not have the below two items running when using HijackThis.
    C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
    C:\PROGRAM FILES\WINZIP\WINZIP32.EXE




    Please do the following:

    Download: "StartDreck", from here:
    http://www.niksoft.at/_data/startdreck.zip

    Unzip to its own folder and start the program,
    Press 'Config'
    Press 'Unmark All'
    Check the following boxes only:
    Registry -> Run Keys
    System/drivers> Running processes
    Press 'Ok'
    Press 'Save' and select the location to save the log file
    (default is the same folder as the application)

    Please attach the log in this thread.
     
  8. Sponk

    Sponk Private E-2

    Here is startdrek log and hijackthis log with nothing running...
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are going to have to boot to an MS DOS prompt to working on fixing this problem.
    You should print or write these instuctions down because you will be offline and not running Windows while doing this. Please read thru all of the steps first and ask any questions you may have before beginning. Make sure you understand all steps before starting

    Click Start and select Shutdown and in the Window that comes up choose the one that says Restart the computer in MD-DOS mode.

    When it boots you will be at the command prompt (full screen) enter the below commands each followed by the enter key. Let me know if you have any problems or get any error messages during these steps (tell me the exact error message).

    Now in command prompt window do the following:
    cd C:\WINDOWS\SYSTEM
    attrib -s -h -r COMN.DLL
    ren COMN.DLL COMN.DDD

    attrib -s -h -r HCALICA.DLL
    del HCALICA.DLL

    cd C:\WINDOWS\TEMP
    attrib -s -h -r se.dll
    del se.dll

    win

    After typing win and hitting enter your system will boot back to Windows. The very first thing you need to do after booting Windows is the following (make sure you do not run anything else):

    Run HijackThis and select the following lines and then click FIX
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {FAE34F47-82B6-11D9-9F4B-EC2588ACC88F} - C:\WINDOWS\SYSTEM\HCALICA.DLL
    O18 - Filter: text/html - {E8FE3385-8D6F-11D9-9F4B-E46A4B81A956} - C:\WINDOWS\SYSTEM\HCALICA.DLL
    O18 - Filter: text/plain - {E8FE3385-8D6F-11D9-9F4B-E46A4B81A956} - C:\WINDOWS\SYSTEM\HCALICA.DLL

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot your PC again into normal mode and post a new HJT log. And tell us how things are working. And how all the steps went too.
     
    Last edited: Mar 6, 2005
  10. Sponk

    Sponk Private E-2

    Followed your instructions and here is the new hijackthis file. So far it seems to to have worked. Spywareblaster and Spywareguard have managed to update with no problems. :D

    So far so good!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you actually find and delete all the files (including se.dll )?

    The below line is still in you HJT log and must be fixed:

    O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall

    If it does not go away, it may be due to some to the spyware protection programs blocking the changes to your registry. They may be seeing the change we are trying to make as a malware attempt at editing you registry. If that is the case we may have to uninstall all of them or at a minimum at list disable all their active blocking mechanisms and then fix the O4 line again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds