| View previous topic :: View next topic |
| Author |
Message |
Corrine
 Administrator Joined: 18 Jan 2001 Posts: 13527 Location: Upstate, NY
|
Posted: Thu Mar 04, 2004 21:45 pm Post subject: |
|
|
Clinton, please don't do anything right now. Your HijackThis log is being reviewed as I type. _________________ Freedomlist.com (March 1, 2000 - 2013)
Take a walk through my Security Garden
Last edited by Corrine on Thu Mar 04, 2004 21:47 pm; edited 1 time in total |
|
| Back to top |
|
 |
Die Hard
Joined: 29 Feb 2004 Posts: 10
|
Posted: Thu Mar 04, 2004 21:45 pm Post subject: |
|
|
clinton, hi
Please close all open applications and IE, run HJT and put a checkmark next to those details.Then click on "fix checked" :
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://brutal-video.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://drusearch.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://drusearch.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://brutal-video.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://drusearch.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://brutal-video.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://brutal-video.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://drusearch.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://drusearch.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://drusearch.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://drusearch.com/search.html
O4 - HKLM\..\Run: [Windows Security Assistant] C:\WINDOWS\system32\rundll32.vbe
O4 - HKCU\..\Run: [Windows Security Assistant] C:\WINDOWS\system32\rundll32.vbe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
Then you need to reboot, preferably into safe mode.(Press F8 repetedly at start)
If you please could move this file, in bold:
C:\WINDOWS\system32\rundll32.vbe
to a temp folder and have it submitted for us at: http://www.lavahelp.com/submit/index.html
Then rid you of the file and empty your dustbin
regards
Die Hard [/b] |
|
| Back to top |
|
 |
winchester73
 Malware Response Team 
Joined: 01 Mar 2004 Posts: 481 Location: Somewhere along Tobacco Road, North Carolina
|
Posted: Thu Mar 04, 2004 21:49 pm Post subject: |
|
|
Die Hard ...
You beat me ... but my tired eyes see 3 entries, not 2:
O4 - HKLM\..\Run: [Windows Security Assistant] C:\WINDOWS\system32\rundll32.vbe
O4 - HKLM\..\RunServices: [Windows Security Assistant] C:\WINDOWS\system32\rundll32.vbe
O4 - HKCU\..\Run: [Windows Security Assistant] C:\WINDOWS\system32\rundll32.vbe
 _________________ Speak softly, but carry a Winchester
Member of , the Alliance of Security Analysis Professionals
Last edited by winchester73 on Thu Mar 04, 2004 21:51 pm; edited 1 time in total |
|
| Back to top |
|
 |
Corrine
 Administrator Joined: 18 Jan 2001 Posts: 13527 Location: Upstate, NY
|
Posted: Thu Mar 04, 2004 21:51 pm Post subject: |
|
|
Thanks for coming so quickly, DieHard! Appreciate the fast response.
Clinton, I've been working with these folks for a while now. They really know what they're doing so you are in good hands. Just follow the instructions carefully and let us know how it works out.
Don't forget to submit the file. Doing that will get it added to the reference files & help the next person clean it easily. _________________ Freedomlist.com (March 1, 2000 - 2013)
Take a walk through my Security Garden |
|
| Back to top |
|
 |
winchester73
 Malware Response Team 
Joined: 01 Mar 2004 Posts: 481 Location: Somewhere along Tobacco Road, North Carolina
|
Posted: Thu Mar 04, 2004 21:53 pm Post subject: |
|
|
So as to make sure there is no confusion ... fix everything in DieHard's list, and also this one item:
O4 - HKLM\..\RunServices: [Windows Security Assistant] C:\WINDOWS\system32\rundll32.vbe _________________ Speak softly, but carry a Winchester
Member of , the Alliance of Security Analysis Professionals |
|
| Back to top |
|
 |
clinton
Guest
|
Posted: Thu Mar 04, 2004 22:51 pm Post subject: |
|
|
not sure how to do what die hard wants?
What is a safe mode, press F8 when the computer starts up again. How do I move the file?
Then you need to reboot, preferably into safe mode.(Press F8 repetedly at start)
If you please could move this file, in bold:
C:\WINDOWS\system32\rundll32.vbe |
|
| Back to top |
|
 |
clinton
Guest
|
Posted: Thu Mar 04, 2004 23:13 pm Post subject: |
|
|
Corrine,
I did what was suggested and it seems to work. But, (as always) the sites continue to show in my favorites? How can i get them out of there? |
|
| Back to top |
|
 |
clinton
Guest
|
Posted: Thu Mar 04, 2004 23:17 pm Post subject: |
|
|
Corrine,
I also have 15 new icons on mt desktop that different things like:
back-20040304-230233-650
All have this similar lettering and numbering. What do i do with these?
Clinton |
|
| Back to top |
|
 |
Die Hard
Joined: 29 Feb 2004 Posts: 10
|
Posted: Fri Mar 05, 2004 3:58 am Post subject: |
|
|
clinton,
Those files on your desktop are the "backup"-files from HJT.
They end up there, when you have HJT on your desktop:
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
You could delete those files , they are of no use.
Please scan again with HJT and post a new log and letīs have a look at it .
regards
Die Hard  |
|
| Back to top |
|
 |
Clinton
Guest
|
Posted: Fri Mar 05, 2004 5:48 am Post subject: |
|
|
Mr. Die Hard,
At a little before 6:00 am in Atl, Ga things seem to be working well. Only small problem is I this have the drusearch and coolsearcher.net icons on my desktop. If I must life with those I can. Just thrilled to no long have the porn %^$&#*@(@(@.
Thank You and everyone else for the help.
The new Highjack log:
Logfile of HijackThis v1.97.7
Scan saved at 5:43:26 AM, on 3/5/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SDPAPIS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.se1.attbb.net;<local>
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [zSPGuard] c:\program files\pjw\spguard\spguard.exe /s
O4 - HKLM\..\Run: [SDPAPIS] C:\WINDOWS\SYSTEM\SDPAPIS.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...wflash.cab |
|
| Back to top |
|
 |
Die Hard
Joined: 29 Feb 2004 Posts: 10
|
Posted: Fri Mar 05, 2004 8:10 am Post subject: |
|
|
Clinton
There are a couple of things you could do to rid you of the shortcuts. The first, which you already tried I guess, is to delete them from the desktop. But isnīt it so, that they return after a reboot?
The other thing you could try is to right click on the icons, then click "properties" and under tab "shortcut" you will have the filepath. Copy it into the search feature and the file will show. Then rightclick on the file and choose (Iīm a little uncertain here as I have to translate, but I think it would be) "open the folder of the object" or something similar. Once there, delete the source of the shortcut, which I think is a IE-icon.
Regards
Die Hard  |
|
| Back to top |
|
 |
Original Guest 1
Guest
|
Posted: Fri Mar 05, 2004 10:59 am Post subject: Drag your Icons into the recycle/trash bin. |
|
|
Drag your Icons into the recycle/trash bin.
Empty bin.
Restart your PC
Icons gone.
For "favorites" delete
highlight
right click mouse button
select and left click "delete" |
|
| Back to top |
|
 |
Clinton
Guest
|
Posted: Fri Mar 05, 2004 12:12 pm Post subject: |
|
|
Corrine, Die Hard, Winchester73, Original Guest1:
Thank You for all the help!!! Whatever I had is gone.
Thanks Again,
Clinton |
|
| Back to top |
|
 |
Corrine
 Administrator Joined: 18 Jan 2001 Posts: 13527 Location: Upstate, NY
|
Posted: Fri Mar 05, 2004 12:28 pm Post subject: |
|
|
Wonderful news! Thanks for letting us know. If you have any more problems along this line, don't hesitate to ask. _________________ Freedomlist.com (March 1, 2000 - 2013)
Take a walk through my Security Garden |
|
| Back to top |
|
 |
winchester73
 Malware Response Team 
Joined: 01 Mar 2004 Posts: 481 Location: Somewhere along Tobacco Road, North Carolina
|
Posted: Fri Mar 05, 2004 13:16 pm Post subject: |
|
|
Top job ...  _________________ Speak softly, but carry a Winchester
Member of , the Alliance of Security Analysis Professionals |
|
| Back to top |
|
 |
tad12
๑۞๑ Joined: 06 Mar 2002 Posts: 1257
|
Posted: Fri Mar 05, 2004 15:13 pm Post subject: |
|
|
| Hope you installed SpywareBlaster. Also SpywareGuard which will monitor your homepage and alert you to any attempted change. |
|
| Back to top |
|
 |
homepage problem
Guest
|
Posted: Sat Mar 13, 2004 12:39 pm Post subject: |
|
|
| ok i have a problem similar to clintons. my homepage keeps changing to C:\WINDOWS\homepage.htm. i've tried spybot, adaware, and i have spyware blaster. none of them worked. i have downloaded hijack this. can you please help me with this? it's really annoying. |
|
| Back to top |
|
 |
lion6644
Joined: 13 Mar 2004 Posts: 17
|
Posted: Sat Mar 13, 2004 13:08 pm Post subject: |
|
|
| this is homepage problem. i just registered. i started a new thread in the help tips and tricks about this. i really need help. thanks. |
|
| Back to top |
|
 |
Corrine
 Administrator Joined: 18 Jan 2001 Posts: 13527 Location: Upstate, NY
|
|
| Back to top |
|
 |