UNKOWN spyware!!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hitman9999, Sep 19, 2004.

  1. hitman9999

    hitman9999 Private E-2

    Hi major and everyone, I have been hunted by a spyware that I cannot control. I really dont know where to start. but I will start like this: I have read and did the read me first page that you have listed. I have gone through it very carefully. here is the spyware. it is a loop, I cant figure out where it starts and where it ends.

    it all starts (in my opinion) with any of these websites popups:

    http://searchmiracle.com/ads/search.php?qq=casino
    http://ads1.revenue.net/l?O_RANK=1&O_CREATIVE_ID=206179&O_SITE_ID
    http://ads1.revenue.net/l?O_RANK=-1&O_CREATIVE_ID=206179&O_SITE_ID=13417&
    http://ads1.revenue.net/r?site_id=13417&pplacement_id=1
    http://web.tickle.com/tests/uiq/index2.jsp?sid=2577&supp=banemedia1&z=
    http://install.searchmiracle.com/ads/search.php?qq=health insurance
    http://install.searchmiracle.com/ads/search.php?qq=viagra
    http://searchmiracle.com/ads/search.php?qq=debt consolidation
    http://images.trafficmp.com/tmpad/content/space.gif

    ----------------------
    then the homepages start to change to any of these:

    http://www.coolsearch.biz/over-frame.htm
    http://coolsearch.biz/over-frame.htm
    http://www.n-udd.com/?id=royal&c=jJj1i0jF9xw56xeZ1lAv9H5zmC70i7m3
    http://www.slotchbar.com/uninstall/removed.html
    http://www.slotch.com/
    ----------
    the add remove program unknown entries become like the following.

    active alert
    internet optimizer
    sidefind
    ( if removed then i get this)
    elitebar internet explorer toolbar

    ----------------------------------------------

    how on to what i have done so far.:
    1) in safemode
    - ran symantec anivirus client
    - ran mcafee antispyware
    - ran ad-aware se personal
    - ran plvx2cleaner
    - ran ccleaner
    - ran spybootsd
    - ran spywareblaster (though i disabled it because it was useless)
    - ran stinger
    - ran cwshredder
    - ran kill2me
    - ran jdtrmobr
    - ran hijackthis. (removed everything logically to be removed)
    - gone into regedit, removed searchmiracle entries values keys...
    - add remove program , removed the enties above.
    - i have used windows xp professional cd to remove internet explorer (thought it would still open misteriously)
    - downloaded sp 2 ( and ever since , i am not able to restore a point prior to its installation... bastards... even thats out of the question)
    - removed registery for elitebar: **** and please note this one::: every time i unregister the dll and i remove it from safemode and i restart, it reappears. both the in the windows folder and in the add remove.

    EVERY THING STATED ABOVE I HAVE TRIED ATLEAST 10 TIMES, AND EVERY TIME THIS SPYWARE/VIRUS/PIECE OF CRAP RELOOPS AND RE STARTS AT SQUARE ONE.

    now having said all that ... and having released some anger... this is the point at which i stand. i may have missed a couple of other thing.. here and their. but i feel that i have tried everything and I am about to throw this out the window (because my xp reinstall cd wouldnt even reinstall (for some reason))

    now my friends, this is my situation not to mention my life situations.... (I will leave that for another thread though)

    I am open to your help. I cant be the only one in this world who has cought this nasty thing. this is not a gradual process, i take care of my computer. this was a sudden thing. their is one thing that has/is causing this.. but again i dont know where to start.
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Give me a Hijack This log file, attached please.
     
  3. hitman9999

    hitman9999 Private E-2

    i have uploaded the txt file of my hijack log.

    please note that even after removing some obovious entries:

    popups like:
    http://searchmiracle.com/ads/search.php?qq=casino
    http://searchmiracle.com/ads/search.php?qq=debt+consolidation
    http://searchmiracle.com/ads/search.php?qq=viagra
    http://ads1.revenue.net/l?O_RANK=-1&O_CREATIVE_ID=206179&O_SITE_ID=13417&

    and the process of all the entries in add/emove program and homepage reloop
    even after running the below entries. my intuition tells me this is all relating to the elitebar. but for some reason it does not unregister.



    ------------
    some entries that i have removed in the past and have reappeared are:

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=137837
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=137837
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=137837
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
    ...
    ..
    O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81C3A} - C:\WINDOWS\EliteBar\EliteBar.dll
    O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA880F} - C:\WINDOWS\EliteBar\EliteBar.dll



    please advise. I appreciate your time major... i have great respect for you for helping people.
     

    Attached Files:

  4. hitman9999

    hitman9999 Private E-2

    other pop ups are from "searchmiracle" .com (these entries did not appear in my previous post).
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    My pleasure, I just try and take up the slack when Chaslang is busy :) Ok, some of these will require you know what they are, we cant always be 100% sure. It looks like you ran Hijack This from your desktop, it should be in its own folder, like C:\HJT or C:\ProgramFiles\HJT so you have a backup if you make a mistake and something stops working. So, please do this first. This is important because you got a lot of crap and were removing a lot of items that I can not identify, but can not promise either. Close your browser first.

    Remove:
    C:\WINDOWS\system32\mynsjtec.exe
    C:\WINDOWS\System32\?ttrib.exe
    C:\Documents and Settings\Superman\Application Data\hza?.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=137837
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=137837
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=137837
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
    O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81C3A} - C:\WINDOWS\EliteBar\EliteBar.dll
    O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA880F} - C:\WINDOWS\EliteBar\EliteBar.dll
    O4 - HKLM\..\Run: [golumm] C:\WINDOWS\system32\golumm\services.exe
    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winlsy32.exe
    O4 - HKLM\..\Run: [kfnhwje] C:\WINDOWS\system32\mynsjtec.exe
    O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe
    O4 - HKCU\..\Run: [window.exe] C:\WINDOWS\System32\window.exe
    O4 - HKCU\..\Run: [sysinit] C:\WINDOWS\system32\golumm\services.exe
    O4 - HKCU\..\Run: [Enziij] C:\WINDOWS\System32\?ttrib.exe
    O4 - HKCU\..\Run: [Ushs] C:\Documents and Settings\Superman\Application Data\hza?.exe
    O16 - DPF: {23FB727A-81BD-5CB9-2167-2C873151BF93} - http://69.50.188.54/1/gdnUS208.exe
    O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
    O16 - DPF: {3E47F7BC-21D3-6F88-CF30-3D2038CE9475} - http://69.50.188.54/1/gdnUS208.exe
    O16 - DPF: {628359A2-5EF8-6942-0E25-252F21BB9557} - http://69.50.188.54/1/gdnCA208.exe
    O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) - http://download.overpro.com/WildApp.cab

    Ok, last 1 need your knowledge:

    If this is your internet provider settings, leave it alone, if not delete it.

    O17 - HKLM\System\CCS\Services\Tcpip\..\{7215FC41-AAE7-4DB3-AC4E-501F53A916E4}: NameServer = 206.47.244.59 206.47.244.108

    Make sure theres nothing relating to porn, casinos, shopping, etc in add\remove programs, open your web browser, reset your home page (optionally do this from internet options in control panel) and cross your fingers.
     
  6. hitman9999

    hitman9999 Private E-2

    major,

    thanks for the help. its gone now. I o u a b e e r buddy
     
  7. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Sounds good :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds