yes another hijack this

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jarcher, Aug 19, 2004.

  1. jarcher

    jarcher I can't handle a title

    I have gone through the sticky MA posted twice
    and I cannot get rid of the new dot net crap
    what the heckis it and why won't it go away

    I have run Spybot SD and LSPF fix to no avail
    ad aware spywareblaster and looked through the Pacman list
    I am lost here is my log






    again I have done everything in order as told by MA
    step by step

    cwshredder also
     
  2. PhilliePhan

    PhilliePhan Guest

    jarcher,

    New dot net is bad mojo. I'm not that familiar with it other than that it is a winsock hijacker as you know. If you are EXTREMELY lucky, you can get rid of it via Control Panel - Add/Remove Programs. Although, it has probably changed since I last saw it.

    Since we are talking about it, does anybody know why new dot net is checked in the Ignore All Products and Ignore LSP settings of SpybotSD?
    This is the default setting when you download Spybot.

    Bug in Spybot??

    PP
     
  3. skitz

    skitz Private E-2

    i believe they have released a new version of spybot s&d that fixes that issue, otherwise, just uncheck them and you are golden....
    skitz
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's true! There are 3 others check to ignore also (for a total of 4). You should look set all of the Ignore Products to unchecked when you install SpyBot S&D (unless you know there are certain ones you want to ignore but I think that is unlikely).

    jarcher, uncheck those items especially new.net and scan again. See if it helps. Also make sure you have the latest detection definitions. Also try the new Ad-aware SE.
    I would run both Ad-aware SE and SpyBot after booting in safe mode.

    And go thru the HJT tutorial again because you are not following directions.
    1) No one asked for a log.
    2) You HJT is out of date
    3) you are running it from a ZIP file and a temp directory (BAD BAD BAD idea).

    Also post your whole log next time (when we ask). We need to see what's in it. Looks like you edited yours. Don't do that. The tutorial told you to shutdown un-necessary processes (like printer control stuff, browser windows, things shown in your system tray) it did not say edit your log. If you did not edit the log, I apologize but I have never seen a log that would only have those lines and no others.

    By the way part of your problem is:
    O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxmlfilt.dll

    This is a CWS hijacker. Perhaps you need to go back and follow the stuff here again: http://forums.majorgeeks.com/showthread.php?t=35407

    This last link is always to be followed be for considering HJT.
     
    Last edited: Aug 20, 2004
  5. PhilliePhan

    PhilliePhan Guest

    Thanks Chas & Skitz,
    I unchecked those when I set up Spybot. Just wondering why they were checked in the first place. Thought it might have been similar to the DSO Exploit bug & they were checked so we didn't get false readings. Anyway, I don't want to hijack jarcher's thread, so carry on :cool:

    PP
     
  6. jarcher

    jarcher I can't handle a title

    that was the whole log
    and my hijack this will not update

    and when I run spybot SD
    it tells me to restart to fix it
    and it comes back
    system restore is off
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why not? Give more details? Where are you downloading it from?
     
  8. jarcher

    jarcher I can't handle a title

    I go to config then misc. tools and update and it says the website is unavail.
    then I tried to go an analize it here: http://hijackthis.de/index.php?langselect=english
    it told me it was outdated and said to visit the authors sit, which I did, and it was down


    and cws did not get rid of that 018 protocol

    I ran thru everything, safe mode and not
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are many items classified as CWS that CWShredder will not fix (don't say cws - cws is the hijacker). CWShredder is a tool used to fix many of the CWS hijacks.
     
  11. jarcher

    jarcher I can't handle a title

    I did that also
    hold on. . . . . .
    yea I got the right one
    1.98.2

    but I didn't get rid of the old one first
    I'll start over. . . . . .
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you extract it from the ZIP file into its own directory. Good examples:
    c:\Program Files\HJT
    c:\SpywareTools\HJT

    That means you would have a file called hijackthis.exe in which ever directory you put it in.
     
  13. jarcher

    jarcher I can't handle a title

    I uninstalled it and reinstalled it
    and installed adaware se

    sorry for pissn your time away
    thanks chaslang

    :beer:
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you update Ad-aware SE after installing it. Then run a scan with it and fix anything it finds. Now exit all applications (especially browser sessions like Internet Explorer) and run HijackThis. Save the log to a .txt file and post it back here as an attachment.
     
  15. jarcher

    jarcher I can't handle a title

    did that and the new adawar found stuff I've never seen before
    and when I ran HJT it didn't find anything to log


    thats good right?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HJT does not find things! We have to find them. HJT just gives you a listing of running processes and a variety of key registry values without any information relating to whether they are good or bad. That is why it is for experts to use and decipher.

    So is everything working okay or what?

    Did you ever fix the ignore product stuff I told you in my first message with SpyBot S&D and do a new scan? And do it after booting in safe mode? You should also run Ad-aware SE in safe mode one more time.
     
  17. jarcher

    jarcher I can't handle a title

    thats what I meant

    and i will run all of it again
    and in safe mode

    thanks
     
  18. jarcher

    jarcher I can't handle a title

    this is what it looks like now
    I did not edit it
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that rather a small log isn't it? The only thing I would guess is that all the changes that were made due to your installing WinXP SP2 have made a big change in what HJT normally would pickup from the registry. Was this a log from safe mode or normal mode?
     
  20. jarcher

    jarcher I can't handle a title

    normal mode
     
  21. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    That is the worlds smallest Hijack This log, I will give you that.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds