General Category => Tech Clinic => Topic started by: thegr8domain on June 10, 2005, 04:28:50 AM
Title: Need help plsss asap!!
Post by: thegr8domain on June 10, 2005, 04:28:50 AM
Hi my name is matt and my desktop has been hijacked I think. First was a trojan named Trojan.Zlob.B and Trojan.Zlob, i removed both successfully (i think) And next is some desktop hijack thing that changed my background to a picture that had something like "YOU MAY HAVE SPYWARE ON YOUR COMPUTER, CLICK LINK BELOW FOR REMOVAL INSTRUCTIONS" And so I clicked the link and it brought me to some SpyWare software that I can buy for $19.99 (HOW DARE THEY HIJACK ME TO SELL THEIR SOFTWARE GRRR) anyways...
Here is my hijack log
Logfile of HijackThis v1.99.1 Scan saved at 1:55:28 AM, on 6/10/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
I have managed to find the screen.html somewhere in system32 and i deleted it, so now instead of the black with text background i have a plain white background that keeps changing from tan to white randomly
Would appreciate some help on this issue!!! I've seen your other responses to threads you guys know what ur doing, pls help!!! /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' /> /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' /> /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
Title: Need help plsss asap!!
Post by: thegr8domain on June 10, 2005, 04:36:44 AM
I will be checking for responses often to see what i can do because i rarely sleep lol, i hate hijackers!!! /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
Title: Need help plsss asap!!
Post by: Cretemonster on June 10, 2005, 03:16:48 PM
This is a standardized Fix for the Smitfraud Infection!
Go ahead and follow the Directions just as they are laid out!
Please read these instructions carefully and print them out! Be sure to follow ALL instructions!
Please RIGHT-CLICK: [color=\"red\"]HERE[/color] (http://\"http://www.bleepingcomputer.com/files/reg/smitfraud.reg\") and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop.
Locate "smitfraud.reg" on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the "merged successfully" prompt then follow the rest of the instructions below.
Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:
Security IGuard Virtual Maid Search Maid
Exit Add/Remove Programs.
*IMPORTANT*CLICK THIS LINK TO LEARN HOW TO VIEW HIDDEN FILES (http://\"http://www.xtra.co.nz/help/0,,4155-1916458,00.html\")
* Please download the Killbox by Option^Explicit (http://\"http://www.geekstogo.com/modules.php?modid=5&action=download&id=4\"). [color=\"purple\"]*In the event you already have Killbox, this is a new version that I need you to download[/color].
* Save it to your desktop.
* Please double-click Killbox.exe to run it.
* Select "Delete on Reboot".
* Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C
* Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
* Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually.
[color=\"purple\"]While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.[/color]
Make sure you can view hidden files.
Using Windows Explorer, delete the following, if found, (please do NOT try to find them by "search" because they will not show up that way)
1.) Download The Hoster (http://\"http://www.funkytoad.com/download/hoster.zip\") Press "Restore Original Hosts" and press "OK". Exit Program.
2.) Right-Click HERE (http://\"http://www.mvps.org/winhelp2002/DelDomains.inf\") and Save As to download DelDomains.inf to your desktop. To use: RIGHT-CLICK DelDomains.inf on your desktop and select: Install (no need to restart) Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.
3.) Download, install, and run CleanUp! (http://\"http://www.spywareaid.com/index.php?file=showsoftware&id=1\")
4.) Run this online virus scan: ActiveScan (http://\"http://www.pandasoftware.com/activescan/\") - Save the results from the scan!
Post a new HiJackThis log along with the results from ActiveScan.
Title: Need help plsss asap!!
Post by: thegr8domain on June 11, 2005, 01:44:06 AM
Ok I went through and did everything you asked and ran into some problems
Problems: 1) When I was using killbox to copy the lines you asked me copy using CTRL + C i did exactly as u said to highlight and then copy by using ctrl + c but then when i hit file > "paste from clipboard" in killbox it didnt paste anything... i tried it many different ways and many different times and no luck with it, so instead i put each file path one by one, then restarted after all of them (im not sure if it worked or not because of that problem) 2) Still cannot get background to load 3) Background is still shading randomly white and tan colors... 4) During the activescan i think 5 infected files were found 5) Do i need to turn System restore back on in order for this process to work???
Here are the logs you requested, Hope you can help me /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
Logfile of HijackThis v1.99.1 Scan saved at 11:38:23 PM, on 6/10/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Adware:Adware/SaveNow No disinfected Windows Registry Adware:Adware/MyWay No disinfected C:\Program Files\MySearch Adware:Adware/NavHelper No disinfected C:\Program Files\Ares Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Matt\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-2a880e3-48eeeae1.zip[Gummy.class] Virus:Trj/WmvDownloader.A Disinfected C:\Program Files\Ares Lite Edition\My Shared Folder\college strippers xxx cd rip.wmv Possible Virus. No disinfected C:\Program Files\Course Technology\SAM 2003\Core2.5\png2swf.exe
Hope to see your response soon /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' /> - Thanks again for your help
Title: Need help plsss asap!!
Post by: thegr8domain on June 11, 2005, 01:46:28 AM
I also forgot to mention some wierd things that i noticed on my desktop
When I use the right click function on my mouse it brings up different menu options very often, for example i just right clicked the desktop and it brought up "Select All, Print, Google Search" i clicked on google search and it showed google as my desktop background picture. Seems very wierd to me, almost like differnet programs or executables are running as my background randomly... Just thought that might help you figure it out
-Thanks again, look forward to ur response !
Title: Need help plsss asap!!
Post by: Cretemonster on June 12, 2005, 05:18:18 AM
Dow you know what the below entry is,if not delete the file please!
C:\Documents and Settings\Matt\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-2a880e3-48eeeae1.zip<< File
C:\Program Files\Ares Lite Edition\My Shared Folder\college strippers xxx cd rip.wmv<< File
C:\Program Files\MySearch<< Folder
C:\Program Files\Ares<< Folder
Please Download Spywad Regonly.exe to your C:\ Drive ( This MUST run from the C:\ drive in order to work) http://www.bleepingcomputer.com/files/mosa...-2k-Regonly.zip (http://\"http://www.bleepingcomputer.com/files/mosaic1/XP-2k-Regonly.zip\")
Unzip and be sure to "Extract All Files"
Double Click "Clean Spywad Regonly.exe" This should automatically open the "Clean Spywad Regonly" folder!
Double Click on the "Reg only XP2k Spywad.vbs" (Please DO NOT run any of the other files until asked)
If you have script blocking enabled you will get a warning about a malicious script wanting to run. Please allow this script to run. It is not malicious.
If you get a message when you first run it, just doubleclick the cleandesktop.vbs script again you sometimes get that message when a script blocker blocks the script
It will then kill Explorer. You will lose your taskbar and desktop. It will repair the registry entries returning your normal desktop and context menu functions.
It will restart Explorer.
Once that is completed, If there are any other Users on the System,they will need to log in under that User Name to clean up their desktop and regain the right click.
Included is another vbs to do this. It is named "Other Profiles Regfix.vbs"
Have each User sign in and run "Other Profiles Regfix.vbs" Locate C:\Clean Spywad Regonly folder> Double click on Other Profiles Regfix.vbs
Explorer will be ended and that user's active desktop registry entries will be repaired. Explorer will be restarted.
To restore the desktop to whatever picture you normally have right click on a blank part of desktop & select properties/desktop & select your prefered picture press apply & then ok to exit and then press F5
You will need to do this step for every user account
Click START>>RUN and in the address bar Copy and Paste >
Then go to C:\ drive and find Key.txt <---a notepad file.
Copy and Paste the contents back here along with a fresh HijackThis log!
Title: Need help plsss asap!!
Post by: thegr8domain on June 13, 2005, 04:25:17 PM
Ok did all the things you told me
Current Problems: 1) Desktop still wont load a picture in the background 2) In the login screen before i get inside windows i see my background picture but once i log in the picture dissapears and back comes the white & tan screen that flickers 3) I think its something in my registry thats messed up still, is it possible that there is a windows xp SP2 desktop registry recontstruction file to wipe out and replace my desktop reg's
Logfile of HijackThis v1.99.1 Scan saved at 2:22:32 PM, on 6/13/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Im so confused /blink.gif\' class=\'bbc_emoticon\' alt=\':blink:\' />
Thanks for all your help, will be looking forward to your response
Title: Need help plsss asap!!
Post by: thegr8domain on June 16, 2005, 01:02:35 AM
Just wondering if my reply got burried under all the other threads, but dont worry i am still here waiting for a response, thanks /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
Title: Need help plsss asap!!
Post by: Cretemonster on June 16, 2005, 02:35:39 AM
Sorry for the wait,just getting settled back in at home froma hellish road trip!
Download the ZIp file attached and Unzip it to your desktop!
Search the entire system again for any fo these entries
Locate the reg file you unzipped to your desktop and double click it to merge it into the registry,make you to answer "Yes" when asked if you want to merge this file!
Restart the PC and Let me know how the desktop is now!
Title: Need help plsss asap!!
Post by: thegr8domain on June 17, 2005, 12:56:39 AM
[quote name=\'Cretemonster\' date=\'Jun 16 2005, 01:35 AM\']Download the ZIp file attached and Unzip it to your desktop!
[post=\"45247\"]<{POST_SNAPBACK}>[/post]
[/quote]
Don't see any zip file attached ???
Title: Need help plsss asap!!
Post by: guestolo on June 17, 2005, 01:04:01 AM
Stick with Cretemonster's instructions on removing files Here is a link to a Registry fix to download and try
Click here to download and UNZIP to desktop this version of Smitfraud.zip (http://\"http://www.thetechguide.com/forum/index.php?act=Attach&type=post&id=266\") So you now have Smitfraud.reg extracted to desktop
Double click on Smitfraud.reg and allow to add or Merge to the registry
Restart your computer Let us know how the desktop is Cretemonster will probably have further recommendations
Title: Need help plsss asap!!
Post by: Cretemonster on June 17, 2005, 04:44:54 AM
Sorry about that,the original Zip file didnt upload for some reason!
The new one will be attached this time for sure!
Use the same instructions as before and let me know if you find any of the files I listed,also,look in the Program Files folder for a program called Antivirus Gold,if you see a folder with that name,delete it!
Title: Need help plsss asap!!
Post by: thegr8domain on June 17, 2005, 04:20:58 PM
WOOHOO!!!! ty so much!!! Got my desktop back and my own backgroudn and its staying!!! YAY!!! ur so nice cretemonster thx man!
Here is a hijack log just incase And by the way there was an Antivirus Gold folder in my program files folder, it has been deleted and erased /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
Logfile of HijackThis v1.99.1 Scan saved at 2:19:47 PM, on 6/17/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
IE Spyad: http://www.bleepingcomputer.com/forums/ind...showtutorial=53 (http://\"http://www.bleepingcomputer.com/forums/index.php?showtutorial=53\") There is a direct download inside and great tutorial also!
Progs to help keep the Temp Files to a Minimum
CCleaner: http://www.filehippo.com/download_ccleaner.html (http://\"http://www.filehippo.com/download_ccleaner.html\") This is to help keep those Temporary Files Cleaned Up!
All you will want to use on this is the Opening Page(Windows Tab)Just Click Run Cleaner and let it do its thing!
If that Link doesnt work,just go to Google.com and Search for CleanUp!
It should be the First Return!! Once Installed,Open and Click CleanUp! and When Prompted to Log Off,do so!
Time to Disable and Reset System Restore
Disable System Restore http://service1.symantec.com/SUPPOR...src=sec_doc_nam (http://\"http://service1.symantec.com/SUPPOR...src=sec_doc_nam\")
Restart the PC and Create a New Restore Point
To create a new System Restore Point in Windows XP Home Edition, click Start -> All Programs -> Accessories -> System Tools -> System Restore. When the System Restore Utility opens, click "Create a Restore Point" then click Next. Enter a name for this Restore Point (for instance, "Before Installing Office XP"), and click Create. The utility will then take a snapshot of your system so that you can restore to that point sometime in the future.
Keep Windows Updated http://windowsupdate.microsoft.com/ (http://\"http://windowsupdate.microsoft.com/\")
Just so i know you know what I know
So how did I get infected in the first place? (http://\"http://forums.net-integration.net/index.php?showtopic=3051\")
Browser Hijacking & How to Stop It! (http://\"http://www.pcstats.com/articleview.cfm?articleID=1579\")
What are Hackers looking for on your PC? (http://\"http://forums.thetechguys.com/showthread.php?t=8859\")