Trusted Site: http:\\*.63.219.181.7

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kfor, Nov 25, 2004.

  1. kfor

    kfor Private E-2

    I'm new to this forum, but have logged on to check posts regarding spy ware.

    I recently have had problems with pops telling me my computer was not secure, and asking me to go to different sites. When I try to add this website that I'm being sent to, as a restricted site, in Internet Explorer, I get the error message telling me that it is a trusted site. When I remove the only web site listed as a trusted site in internet explorer (http://*.63.219.181.7) it returns as a trusted site in less than 1 second.

    I ran Hijack this, and the only thing I have in the Hijack this log is
    O15: Trusted Zone: http://*.63.219.181.7
    (I had major virus issues for the past week, and deleted everything from Hijack this, but everything has been running smoothly for the last week, makes me wonder what all these entries are for??)


    and when I try to delete the entry for Trusted Site, it comes back the next time I run HiJackThis (within a second).

    I did have a very nasty virus I could not get rid of until I used reg edit and took the virus out of a registry. Does any one know where the registry would be that controls Tursted Zones for Internet Explorer??

    Yes I have run Ad-aware (it always finds two things, which I delete), and I have run every other program you recommend (CCShreader, AntiVir, etc.) Nothing seems to work.

    Any help would be appreciated.

    Thanks,
    Kevin
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't think manual editing of the registry will help you. That is basically what you already did using IE and HijackThis anyway. You must have a process running that is doing this.

    That IP address belongs to:

    If you have run ALL steps of the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal then you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
  3. kfor

    kfor Private E-2

    Thanks for the help.

    Here is my HiJAckThis Log file (it is the version you requested, and it is in a separate file:

    EDIT by chaslang: Change inline log to an attachment

    (vptray is from Norton's antivirus)
    ---------------------------------------------------------------------
    You are probably right that I have a process running, but no anti virus program can find it. Ad-aware can find two, they get deleted, and I run the program again, and it finds the same two.

    I've had problems with heretofind just prior to this, which I've gotten rid of (I think), but still have problems with 4 pop-ups:
    1) adultgaming.com
    2) findspyware.com
    3) 24.108.222.162 coming up with a window, telling me it is scanning my computer and that I have thousands of viruses, please visit a website and by spyware
    4) Windows Security Centre: Warning Windows firewall detected suspicious network activity.

    Any help would be appreciated.

    Kevin
     

    Attached Files:

    • hjt.txt
      File size:
      1.1 KB
      Views:
      3
    Last edited by a moderator: Nov 28, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that really your whole HijackThis log? It seems highly unlikely. Did you filter out lines or have you delete lots of items using HJT? You also do not show any signs of having run the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal thread I mentioned. You really need to run this. I suspect a few items that are running as being bad.

    C:\WINDOWS\System32\dllhostxp.exe
    C:\WINDOWS\System32\pxhping.exe
    C:\WINDOWS\System32\mqbckup.exe

    I need to see a full HijackThis log. Also do not post your logs in line. Attach them to you message. See how I changed yours.
     
  5. kfor

    kfor Private E-2

    Chaslang, :)

    Thank you for your help. As I said in the original message, that was all of my HJT log as I had cleared out many of the programs in an attempt to rid myself of heretofind virus. Yes, I did follow all of the instructions exactly on before posting my HJT to the forum (with the exception of updating windows, as I've found the latest Service Pack 2 has major bugs, and I can not use an internet based program for work, WAY TO GO MICROSOFT!!).

    I have looked in other forums, and in the past week, several people have had the exact same virus that I recently became infected with (probably during the heretofind virus infection).

    Here's what seemed to work for me:
    I re-booted in Safe mode.
    Scanned with Adaware, with latest update.

    Went to Dos prompt, and typed:
    cd C:\windows\system32
    renamed the following files:

    by typing
    ren clfmon.exe clfmon.exe.old
    ren dllhostxp.exe dllhostxp.exe.old
    ren mqbackup.exe mqbackup.exe.old
    ren msacmx.dll msacmx.dll.old
    ren pxhping.exe pxhping.exe.old

    For the last 2 days I have had no problems (not even the Microsoft Security Centre popping up telling me I have security problems, and then redirecting me to a site to buy spyware, which is definitely part of this virus)

    I hope that this helps someone else, as these viruses have been a huge hassel, wasting tonnes of time for me.

    The whole virus problem seems more complicated than it should be. Would it not be a better forum, to have seperate threads for each particulair virus?? I found the forum a bit difficult to navigate, and find people with similair problems so that I can follow their solution. Is there a place that we can upload fixes to common viruses, that are not fixed with conventional virus programs??

    I thank you for your help, and I enjoy reading your forum.

    Kevin :)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log showed no signs of running the online scanners that is why I question if you ran the full READ ME. If all the steps are followed, there is a Symantec and a Trend Micro online scan that should be run. Both will always leave traces in the O16 section of a HJT log. Your log stop at the O4 section with only one O4 line (extremely unusal) and did not have the O16 lines for the scanners. So either they were not run, or you are using HJT's ability to filiter out certain items. Or a third possibility is you delelete the items already using HJT.

    There should be more O4 lines for sure too. Most startup programs (include in that virus detection apps and more) will show an O4 line.

    Your log also show no signs of some of the files you said you renamed (like clfmon.exe ).

    When you say you cleared out many programs, what were they? Looking in HJT backups.
     
  7. kfor

    kfor Private E-2

    Re: Trusted Site: http:\\*.63.219.181.7 and HeretoFind

    I'll post my HJT log again, (as an attachment this time, as you requested). I ran every step in your instructions (Read me before Post HJT) twice, I did the major HJT clean up about 2 days before the message to you.

    Unfortunately, I looked in the archives, and can not find my old HJT log file, or back-up... If you can tell me what I am looking for I can send it (in the HJT dir, I have mostly 1 kb short cuts, no text files).

    In the mean time, here is the thread that I followed to get rid of my previous problem ( Windows Security Center" keeps popping up asking me to download spyware cleaning software), seems like this is very rampant, and I'm sure you'll get lots of posts on it. Not a bad idea to put this in its own thread.

    http://computercops.biz/postx84967-0-30.html

    I got rid of Heretofind virus by reading this thread, and then being a bit creative with reg edit (follow first 2 links on page).
    http://www.joewein.de/sw/hijack-heretofind-com.htm

    I wasted over 2 weeks on this. If this in any way saves someone from wasting anymore time on this, then please use it.

    I should also mention that I did follow the instructions on this website (Read me Before posting HJT log files), and did find multiple other "suspicous programs", although not as problematic as heretofind. I did buy Adaware, professional version also and have installed it yesterday after all was fixed, just as an extra insurance package and keep things running smoothly (very tiny investment of less than $40.00 when you consider I wasted 2 weeks on this)

    Hope this helps,

    Kevin :) :) :) :) :) :) :) :) :) :) :) :) :) :) :)
     
    Last edited: Dec 1, 2004
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trusted Site: http:\\*.63.219.181.7 and HeretoFind

    The backups for HJT are store in the folder you run HJT from. You currently have it in C:\Program Files\HiJAckThis. So if anything was fixed while HJT was there a backups folder will be there. However, if before coming here you had HJT someplace else when you did the other fixes, you would have to look in the previous folders.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds