It is currently Tue Sep 01, 2026 3:14 pm


Help with Hijack Log

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Postby brad » Fri Jun 25, 2004 11:09 pm

brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Will do

Postby jerry » Fri Jun 25, 2004 11:39 pm

User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Didn't take long for this

Postby jerry » Sat Jun 26, 2004 12:34 am

Okay Brad here is the latest attack...............

Logfile of HijackThis v1.97.7
Scan saved at 6:30:11 PM, on 6/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.EXE
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\HFXP\hfxp.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {8DA3638B-085E-4B9A-B806-5326ACC35764} - C:\WINDOWS\System32\feid.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5805A85E-39E4-4A15-8241-186D31C9A78C}: NameServer = 151.164.8.201 151.164.1.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8

I just can't believe that none of the scanner software can find this dang thing...............jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Sat Jun 26, 2004 7:56 am

I know we ran CWShredder back in the beginning but still you have a CW infection.
CWShredder has also been updated so click on the "Check for updates" button. Then click the "Fix" button.
Try running it in "Safe Mode".
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Saturday Morning

Postby jerry » Sat Jun 26, 2004 3:07 pm

Good Morning Brad,

I downloaded the latest CWShredder and clicked update.
In Safe Mode - this is what I did..............

Ran CWShredder and this is the report it gave me:

Removed CWS.Searchx from your sustem
Host files not present
shell Registryvalue: HKLM\.\Winlog[shell]Explorer.exeR
Userlnt Registry value: HKLM\.\Winlog[userlnit]C:\WINDOWS\system32\userinit.exe

I ran HJT and it did not have the fake HBO with the crazy dll file in it. I told it to fix the rest of the bad entries.

Went to all of the TEMP files and deleted them. ONE exception - in the Admin temp file there was a Index.dat file and I did not delete it - what do you think about that one??????????

Also under Program files there is a folder named "Recycler" and I clicked on it and there were sever files that said they were files that I had deleted. I left them alone because I had already emptied the Recycle Bin.

Here is the latest HJT log:

Logfile of HijackThis v1.97.7
Scan saved at 8:54:51 AM, on 6/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.EXE
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kansascity.com/mld/kansascity/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5805A85E-39E4-4A15-8241-186D31C9A78C}: NameServer = 151.164.8.201 151.164.1.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Update Saturday Number 2

Postby jerry » Sat Jun 26, 2004 6:35 pm

Hi Brad --- see the previous post first please.

This thing seems to be clean - I have gone to every web site I can think of and clicked back to home and it remains clean and stable.

I was reading another post in this site and someone had deleted some of the system files accidently and one of the techs suggested the following
process to them -

from start--->run, type in

'SFC /scannow '-->restores system files--You'll be prompted to insert the xp cd to run this setup

Do you think I should do this to get all the good stuff that I deleted back???????? I do have the original Windows XP installation disk.

I will wait to hear from you and keep monitoring this PC to make sure I don't get hit again...................I also just reactivated the System Restore Monitoring........we will see.......

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Still Saturday

Postby jerry » Sat Jun 26, 2004 8:31 pm

It hit again about 2 pm Central Time so it is definitely on some kind of a timer ---
Here is the HJTY log:

Logfile of HijackThis v1.97.7
Scan saved at 2:27:19 PM, on 6/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A5387A1C-961E-4BFE-86FD-B18A1AEE8BB6} - C:\WINDOWS\System32\nifjbd.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5805A85E-39E4-4A15-8241-186D31C9A78C}: NameServer = 151.164.8.201 151.164.1.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby liljim » Sat Jun 26, 2004 8:45 pm

Man,this thing is really got it out for you!!

Im sure you know the routine by now..

Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.) Close all other open Windows and have HiJackThis Fix:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
O2 - BHO: (no name) - {A5387A1C-961E-4BFE-86FD-B18A1AEE8BB6} - C:\WINDOWS\System32\nifjbd.dll

Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab) (You may have to boot to "Safe Mode" in order to delete some Files/Folders)


C:\WINDOWS\System32\nifjbd.dll

Now, empty all your TEMP Folders (WinXp has up to 4 of them) / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.
User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top

Still Saturday

Postby jerry » Sat Jun 26, 2004 10:58 pm

Okay guys I did all that you noted for me to do - the HJT log is great and everything works great but...............this dang thing will execute in about 2 - 3 hours and we will be right back where we were.

Something is burried in the system somewhere and all of the spy checkers just can't find it. When I run CWShredder in Safe Mode it finds the corrupt dll file and cleans it out and says it found and deleted a CWS file - whomever developed this CoolWebSearch Trojan ought to have it stuck where the sun don't shine!!!!!!!!!!

I absoutely appreciate all of you sticking with me on this and I know it is driving you all just as crazy as it is me - it is unbelieveable that you all give so freely of your time for people like me - THANKS is all I can say.

Here is the latest HJT log:

Logfile of HijackThis v1.97.7
Scan saved at 4:48:30 PM, on 6/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5805A85E-39E4-4A15-8241-186D31C9A78C}: NameServer = 151.164.8.201 151.164.1.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby liljim » Sun Jun 27, 2004 3:12 am

User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top

Fixed

Postby jerry » Sun Jun 27, 2004 1:12 pm

Okay guys,,,,,,,,I found a fix for the problem -- I went to the site noted on the CWSHredder program by the developer - I searched the forums for a similar problem and found the following repair suggestion and my PC has been functioning properly since 6 pm Saturday night,,,no invasions........YES!!!!!!!!! finally!!!!!!!!! Following is the instructions from that other forum:

okay, I figured it out...this really works!!!!!!!!!!!!!!!

Most of the anti-hijacking programs seem to deal with deleting registry entries, but none of those dealt with .dlls except the browser helper object that HijackThis finds. However, after removing that, the intruder always comes back. There must be a way it's loaded at system boot and I thought it was via the startup options that are presented when you run "msconfig". Not so...

The invading dll loads via the registry entry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

This causes it to attach to every application at starup.

If there is a dll specified, like c:windows\system32\wini.dll, don't bother looking for it in that folder. As long as the intruder is active, it will hide the filename in any folder or directory listing.

YOU MUST DELETE THE REGISTRY KEY! (even if there is no dll listed in it)

However, if you delete it, the intruder will put it back since it is currently running.

1. in regedit, this key is in the Windows "folder" that you see in the left part of the window. Change the name of this folder to "Windows2".

2. Then delete the AppInit_DLLS key.

3. Then change the name of the folder back to "Windows"

I completed this operation and no attacks since, so I do believe it has worked for me.

I still have another questin and please tell me if I need to post it in a different forum but for now I will put it here as an addendum. As I was trying everything possible to fix the hijack (Trojan) problem I deleted some of the files on my computer needed to launch my internet connection to DSL automatically and one of the old programs to load that being an old version of Windows Cardfile. I have replaced the Cardfile program with a newer version and it now works great but I sure would like for the internet connection to be automatic so it will launch through my router. The suggestion posted on the other site is as follows:

from start--->run, type in

'SFC /scannow '-->restores system files--You'll be prompted to insert the xp cd to run this setup

I am not about to do this without your approval and I assume that I would have to go back and complete the previous functions as it would probably reload the Registry Key that I had to delete to stop the Trojan.

Will wait for your reply - if I need to post this in another forum please advise me of that also..............

Thanks again for all of your help and time.............

Jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Oops Very important

Postby jerry » Sun Jun 27, 2004 1:26 pm

Sheesh,,,,,,,,I left out something very important to the previous post:

I completed the task noted in the previous post only after completing the tasks noted to me by both brad and liljim - those being booting into Safe Mode running CWShreder - running HijackThis and cleaning out the bad items - clearing all of the Temp files - emptying the Recycle Bin - without doing these tasks I don't believe the fix would have been successful ---------- thanks to you guys for those instructions!!!!!!!!

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Previous

Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron