 | HJT log -still can't get rid of BHOs and popups Hi, all: Got an emergency call for help from a friend who initially reported a bugbear infection on her computer (AVG antivirus reported infection). When I got to her house, she said Norton AV (also running) was reporting Backdoor.Berber.F and she had no control over her browser homepage settings nor popups that were coming fast and furious.
I booted to safe mode and ran vcleaner from AVG. It stopped dead in the middle of processing. Also tried two online cleaners (TrendMicro and PandaScan). Same result. I then loaded up AVAST at boot and it reported and disinfected or deleted: 1) 01602615.exe infected with BugBear-B 2) Imscan.dll Kuang2 - this file is actually a PandaScan file that other antivirii throw false positives on 3) one file with the aforementioned Berber.F (reportedly this creates random system32 .exe filenames) 4) one file with Win32.Trojano-164[Trj] 5) 23 instances of CoolWebSearch
I then loaded up AdAware, SpybotS&D, SpywareBlaster and SpywareGuard. Also loaded up ZoneAlarm and caught an application call NTZD.EXE trying to call out. Any idea what this is? Unfortunately the browser is still being hijacked and unwanted popups are still appearing.
Here is the HijackThis log with several suspicious entries: Logfile of HijackThis v1.98.0 Scan saved at 10:12:59 PM, on 7/20/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\Program Files\Roxio\GoBack\GBPoll.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\addix.exe C:\WINDOWS\system32\ntzd.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\System32\devldr32.exe C:\Program Files\Alwil Software\Avast4\ashSimpl.exe C:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgdvh.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dgdvh.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgdvh.dll/index.html#37049 R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {EF8BB02A-9D77-7F04-941C-7146169FD55A} - C:\WINDOWS\system32\atlcm.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [ntzd.exe] C:\WINDOWS\system32\ntzd.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe O4 - HKLM\..\RunOnce: [addix.exe] C:\WINDOWS\system32\addix.exe O4 - HKLM\..\RunOnce: [ipbz.exe] C:\WINDOWS\system32\ipbz.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\inetrepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\inetrepl.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O16 - DPF: ppctlcab - »www.pestscan.com/scanner/ppctlcab.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - »messenger.zone.msn.com/binary/msgrchkr.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - »security.symantec.com/sscv6/Shar···niff.cab O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - »www.pestscan.com/scanner/axscanner.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - »us.dl1.yimg.com/download.yahoo.c···0510.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - »security.symantec.com/sscv6/Shar···absa.cab O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) - »ftp.hp.com/pub/automatic/player/isetupML.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - »a840.g.akamai.net/7/840/537/2004···an53.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - »messenger.zone.msn.com/binary/Me···ient.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - »www.pandasoftware.com/activescan···inst.cab O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - »us.dl1.yimg.com/download.yahoo.c···_416.dll O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - »fdl.msn.com/public/chat/msnchat45.cab O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)
I'll be trying CWSShredder now that I know about it but I'm still concerned that I have a trojan or two here. Any input would be appreciated.
Val |
|
 rds24aTeach Your ChildrenPremium join:2000-12-13 Newton Upper Falls, MA Reviews:
·Verizon FiOS
·RoadRunner Cable
1 edit | said by valkyrie5: Hi, all: 5) 23 instances of CoolWebSearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049
O4 - HKLM\..\RunOnce: [addix.exe] C:\WINDOWS\system32\addix.exe O4 - HKLM\..\RunOnce: [ipbz.exe] C:\WINDOWS\system32\ipbz.exe
I'm pretty sure CWShredder doesn't get that particular variant of CWS...it came out around the time he stopped updating CWSHredder. It is particularly nasty and particular tricky to remove. -- "We cannot live in a grievance-based society any longer. Our best individual efforts will, in time, result in the improvement of the whole. Complaining is not productive." |
|
 John2gQui Tacet ConsentitPremium join:2001-08-10 England | reply to valkyrie5 Try the analysis here. Just C&P your HJT log and hit analyse.
»hijackthis.de/index.php?langselect=english -- Better to remain silent and be thought a fool, than to speak and remove all doubt. |
|
 John2gQui Tacet ConsentitPremium join:2001-08-10 England 1 edit | reply to valkyrie5 If you think you have a virus or trojan, you could run this free AV. It does not have to be installed:just run.
Before you run it, disable "autoprotect" in NAV
Forgot to add the link, which is
»www.mwti.net/antivirus/free_utilities.asp |
|
 joepwpbPremium join:2000-12-15 West Palm Beach, FL | reply to John2g said by John2g: Try the analysis here. Just C&P your HJT log and hit analyse.
»hijackthis.de/index.php?langselect=english
John2g,
I like that analysis page!! It sure lightens the load for those on the Security forums that help with HJT logs.
Joe P |
|
 John2gQui Tacet ConsentitPremium join:2001-08-10 England | said by joepwpb: John2g,
I like that analysis page!! It sure lightens the load for those on the Security forums that help with HJT logs.
Joe P
It certainly helps to sort the wheat from the chaff very quickly. The results should not be taken as gospel: it is only as good as its database, which must be updated regularly. It does appear to be getting more accurate. -- Better to remain silent and be thought a fool, than to speak and remove all doubt. |
|
 rds24aTeach Your ChildrenPremium join:2000-12-13 Newton Upper Falls, MA Reviews:
·Verizon FiOS
·RoadRunner Cable
| reply to joepwpb Val:
If you do a Google search for "CWS" and "res://C" you'll get a list of other discussions and a bunch of proposed removal steps for this variant. There were too many to post here and they are definitely use-at-your-own risk...the big problem is that the .dll and supporting characters are all randomly named by CWS.
»russelltexas.com/malware/newexpl···pair.htm -- "We cannot live in a grievance-based society any longer. Our best individual efforts will, in time, result in the improvement of the whole. Complaining is not productive." |
|
 joepwpbPremium join:2000-12-15 West Palm Beach, FL | reply to John2g John2g,
I noticed two strange files in the HJT log which produced nothing when searched through Google:
addix.exe ntzd.exe
Any thoughts on these files??
Joe P |
|
 John2gQui Tacet ConsentitPremium join:2001-08-10 England | reply to valkyrie5 This tool claims to remove this CWS variant
»www.hsremove.com/ |
|
 John2gQui Tacet ConsentitPremium join:2001-08-10 England 1 edit | reply to joepwpb said by joepwpb: John2g,
I noticed two strange files in the HJT log which produced nothing when searched through Google:
addix.exe ntzd.exe
Any thoughts on these files??
Joe P
In my experience, if Google can't find it, it is malware of some sort. The problem with these new CWS variants is that the name of the exes mutates.
Also, if I found them on my computer, I would stop them loading and delete them. This probably means in safe mode. |
|
|
|
 | reply to valkyrie5 Wow, great suggestions from everyone. Kudos to John2g for the excellent HijackThis analysis page and to rds24a for the CWS variant removal page. I'll be trying the free AV as well.
Thanks to all. |
|
 John2gQui Tacet ConsentitPremium join:2001-08-10 England | reply to valkyrie5 Another thought. Have you tried System Restore?
»camtech2000.net/Pages/System_Restore.htm -- Better to remain silent and be thought a fool, than to speak and remove all doubt. |
|
 siggyxSiggyPremium join:2003-12-10 Cambridge | reply to valkyrie5 I would be cautious about recommending that HJT log online review to anyone.
I ran about 20 HJT logs through it that I had resolved in Tom Koyote, from basic to difficult, and I received false/positives, poor information like "fix this" and bad information. "Fix This" is easy to say but they do not supply direction on how to fix it and some people will just have HJT fix it and could cause serious harm to their system. This is especially true with the 010 LSP lines. The direction given was "Have HJT fix this" which we know in many cases means bye-bye to your internet connection.
Tools like this while informative to the user can give a false sense of security that they can resolve their issue. All I can say is an old phrase "a little bit of knowledge is dangerous" and I think this tool will cause more harm than good for the uneducated in the review of HJT logs.
Ok off the soap box :P. -- The next best thing to being smart is being able to quote someone who is. |
|
 John2gQui Tacet ConsentitPremium join:2001-08-10 England | said by siggyx: I would be cautious about recommending that HJT log online review to anyone.
I think you must have missed what I wrote above.
"It certainly helps to sort the wheat from the chaff very quickly. The results should not be taken as gospel: it is only as good as its database, which must be updated regularly. It does appear to be getting more accurate." -- Better to remain silent and be thought a fool, than to speak and remove all doubt. |
|
 | reply to John2g Haven't run system restore but I'll look into it before making any HijackThis changes. |
|
 siggyxSiggyPremium join:2003-12-10 Cambridge 1 edit | reply to valkyrie5 I didn't miss that. I have all the tools at hand to review logs and and these still are not 100% accurate and never will be.
As a tool to start to learn how their systems works and inspiring someone to join one of the help groups that would be a good thing but a HJT log is the last resort after running all the tools. Many of the people are desparate at the point that they are running HJT logs and desparate people take desparate actions, a recipe for disaster.
This will encourage people, in my mind, to go for the quick fix and this is where the danger lies because they don't have the knowledge needed to apply the quick fix.
I guess my point is that the site does not in anyway assist someone with the accurate removal of anything. It gives a false sense that the log can be managed by the person with the information that is supplied with the review. As I said I recieved many false/positives and some flat out BAD information from it.
Since we are talking in metaphors lol it's not a case of "sort the wheat from the chaff" but "throwing the baby out with the bath water". -- The next best thing to being smart is being able to quote someone who is. |
|
 John2gQui Tacet ConsentitPremium join:2001-08-10 England | We will have to agree to disagree. |
|
 siggyxSiggyPremium join:2003-12-10 Cambridge | reply to valkyrie5 Please download AboutBuster from here and unzip it to your desktop but don't run it yet: www.downloads.subratam.org/AboutBuster.. »www.downloads.subratam.org/AboutBuster.zip
Please also download and install Ad-Aware from here if you haven't already: »www.lavasoftusa.com/software/adaware/ Once installed or if you already had it installed, while online start Ad-Aware, click on the "Check for Updates Now" link at the bottom right, then click "Connect". After it updates, click "Finish". Close Ad-Aware.
Follow the instructions here to enable viewing of hidden/system files: »www.xtra.co.nz/help/0,,4155-1916458,00.html
Next, go to Start->Run and type Services.msc then click ok. On the screen that comes up, scroll down to the service called "Network Security Service" and double-click on it. On the next screen, click the stop button, then in the Startup Type drop-down, change it to Disabled and click Apply then Ok.
Please print out the remainder of these directions, as you'll have to proceed in Safe mode and won't want to open IE again until they're complete.
Reboot to Safe Mode. Tap f8 while bios loads
In Safe Mode, scan with Hijack This, put checks next to all of these entries and then click "Fix Checked":
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgdvh.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dgdvh.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgdvh.dll/index.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {EF8BB02A-9D77-7F04-941C-7146169FD55A} - C:\WINDOWS\system32\atlcm.dll
O4 - HKLM\..\Run: [ntzd.exe] C:\WINDOWS\system32\ntzd.exe O4 - HKLM\..\RunOnce: [addix.exe] C:\WINDOWS\system32\addix.exe O4 - HKLM\..\RunOnce: [ipbz.exe] C:\WINDOWS\system32\ipbz.exe
Next, still in Safe-Mode, delete any of the following files that are present:
C:\WINDOWS\system32\atlcm.dll C:\WINDOWS\system32\ntzd.exe C:\WINDOWS\system32\addix.exe C:\WINDOWS\system32\ipbz.exe
Double click the AboutBuster.exe file that you downloaded earlier. Click OK, click Start, then click OK. This will scan your computer for the bad files and delete them. Save the report it creates (copy and paste it into notepad or wordpad and save as a .txt file).
Finally, still in Safe Mode, scan with Ad-Aware and let it remove anything it finds.
Reboot to normal mode, the do an online virus scan and let it fix what it finds.
Trend Micro »housecall.trendmicro.com/
Then rescan with Hijack This and post a new log here along with the log you saved from AboutBuster. -- The next best thing to being smart is being able to quote someone who is. |
|
 John2gQui Tacet ConsentitPremium join:2001-08-10 England 1 edit | reply to valkyrie5 I don't see any significant differences between the automatic analysis and yours.
»hijackthis.de/logfiles/3bfa62ef6···562.html
What the automatic analyser doesn't know is that this CWS infection cannot be removed by HJT. |
|
 siggyxSiggyPremium join:2003-12-10 Cambridge | reply to valkyrie5 I was not talking about this log in particular. As I stated I ran 20 or so HJT logs through it last night. That is what my comments are based upon. -- The next best thing to being smart is being able to quote someone who is. |
|