site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
753
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies

valkyrie5

join:2001-12-11
Laguna Niguel, CA

HJT log -still can't get rid of BHOs and popups

Hi, all:
Got an emergency call for help from a friend who initially reported a bugbear infection on her computer (AVG antivirus reported infection). When I got to her house, she said Norton AV (also running) was reporting Backdoor.Berber.F and she had no control over her browser homepage settings nor popups that were coming fast and furious.

I booted to safe mode and ran vcleaner from AVG. It stopped dead in the middle of processing. Also tried two online cleaners (TrendMicro and PandaScan). Same result. I then loaded up AVAST at boot and it reported and disinfected or deleted:
1) 01602615.exe infected with BugBear-B
2) Imscan.dll Kuang2 - this file is actually a PandaScan file that other antivirii throw false positives on
3) one file with the aforementioned Berber.F (reportedly this creates random system32 .exe filenames)
4) one file with Win32.Trojano-164[Trj]
5) 23 instances of CoolWebSearch

I then loaded up AdAware, SpybotS&D, SpywareBlaster and SpywareGuard. Also loaded up ZoneAlarm and caught an application call NTZD.EXE trying to call out. Any idea what this is? Unfortunately the browser is still being hijacked and unwanted popups are still appearing.

Here is the HijackThis log with several suspicious entries:
Logfile of HijackThis v1.98.0
Scan saved at 10:12:59 PM, on 7/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Roxio\GoBack\GBPoll.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\addix.exe
C:\WINDOWS\system32\ntzd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgdvh.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dgdvh.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgdvh.dll/index.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {EF8BB02A-9D77-7F04-941C-7146169FD55A} - C:\WINDOWS\system32\atlcm.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [ntzd.exe] C:\WINDOWS\system32\ntzd.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\RunOnce: [addix.exe] C:\WINDOWS\system32\addix.exe
O4 - HKLM\..\RunOnce: [ipbz.exe] C:\WINDOWS\system32\ipbz.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\inetrepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: ppctlcab - »www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - »messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - »security.symantec.com/sscv6/Shar···niff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - »www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - »us.dl1.yimg.com/download.yahoo.c···0510.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - »security.symantec.com/sscv6/Shar···absa.cab
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) - »ftp.hp.com/pub/automatic/player/isetupML.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - »a840.g.akamai.net/7/840/537/2004···an53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - »messenger.zone.msn.com/binary/Me···ient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - »www.pandasoftware.com/activescan···inst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - »us.dl1.yimg.com/download.yahoo.c···_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - »fdl.msn.com/public/chat/msnchat45.cab
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)

I'll be trying CWSShredder now that I know about it but I'm still concerned that I have a trojan or two here. Any input would be appreciated.

Val


rds24a
Teach Your Children
Premium
join:2000-12-13
Newton Upper Falls, MA
Reviews:
·Verizon FiOS
·RoadRunner Cable

1 edit

said by valkyrie5:
Hi, all:
5) 23 instances of CoolWebSearch

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049

O4 - HKLM\..\RunOnce: [addix.exe] C:\WINDOWS\system32\addix.exe
O4 - HKLM\..\RunOnce: [ipbz.exe] C:\WINDOWS\system32\ipbz.exe


I'm pretty sure CWShredder doesn't get that particular variant of CWS...it came out around the time he stopped updating CWSHredder. It is particularly nasty and particular tricky to remove.
--
"We cannot live in a grievance-based society any longer. Our best individual efforts will, in time, result in the improvement of the whole. Complaining is not productive."


John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

reply to valkyrie5
Try the analysis here. Just C&P your HJT log and hit analyse.

»hijackthis.de/index.php?langselect=english
--
Better to remain silent and be thought a fool, than to speak and remove all doubt.



John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

1 edit

reply to valkyrie5
If you think you have a virus or trojan, you could run this free AV. It does not have to be installed:just run.

Before you run it, disable "autoprotect" in NAV

Forgot to add the link, which is

»www.mwti.net/antivirus/free_utilities.asp



joepwpb
Premium
join:2000-12-15
West Palm Beach, FL

reply to John2g

said by John2g:
Try the analysis here. Just C&P your HJT log and hit analyse.

»hijackthis.de/index.php?langselect=english

John2g,

I like that analysis page!! It sure lightens the load for those on the Security forums that help with HJT logs.

Joe P


John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

said by joepwpb:
John2g,

I like that analysis page!! It sure lightens the load for those on the Security forums that help with HJT logs.

Joe P

It certainly helps to sort the wheat from the chaff very quickly. The results should not be taken as gospel: it is only as good as its database, which must be updated regularly. It does appear to be getting more accurate.
--
Better to remain silent and be thought a fool, than to speak and remove all doubt.


rds24a
Teach Your Children
Premium
join:2000-12-13
Newton Upper Falls, MA
Reviews:
·Verizon FiOS
·RoadRunner Cable

reply to joepwpb
Val:

If you do a Google search for "CWS" and "res://C" you'll get a list of other discussions and a bunch of proposed removal steps for this variant. There were too many to post here and they are definitely use-at-your-own risk...the big problem is that the .dll and supporting characters are all randomly named by CWS.

»russelltexas.com/malware/newexpl···pair.htm
--
"We cannot live in a grievance-based society any longer. Our best individual efforts will, in time, result in the improvement of the whole. Complaining is not productive."



joepwpb
Premium
join:2000-12-15
West Palm Beach, FL

reply to John2g
John2g,

I noticed two strange files in the HJT log which produced nothing when searched through Google:

addix.exe
ntzd.exe

Any thoughts on these files??

Joe P



John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

reply to valkyrie5
This tool claims to remove this CWS variant

»www.hsremove.com/



John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

1 edit

reply to joepwpb

said by joepwpb:
John2g,

I noticed two strange files in the HJT log which produced nothing when searched through Google:

addix.exe
ntzd.exe

Any thoughts on these files??

Joe P

In my experience, if Google can't find it, it is malware of some sort. The problem with these new CWS variants is that the name of the exes mutates.

Also, if I found them on my computer, I would stop them loading and delete them. This probably means in safe mode.

valkyrie5

join:2001-12-11
Laguna Niguel, CA

reply to valkyrie5
Wow, great suggestions from everyone. Kudos to John2g for the excellent HijackThis analysis page and to rds24a for the CWS variant removal page. I'll be trying the free AV as well.

Thanks to all.



John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

reply to valkyrie5
Another thought. Have you tried System Restore?

»camtech2000.net/Pages/System_Restore.htm
--
Better to remain silent and be thought a fool, than to speak and remove all doubt.



siggyx
Siggy
Premium
join:2003-12-10
Cambridge

reply to valkyrie5
I would be cautious about recommending that HJT log online review to anyone.

I ran about 20 HJT logs through it that I had resolved in Tom Koyote, from basic to difficult, and I received false/positives, poor information like "fix this" and bad information. "Fix This" is easy to say but they do not supply direction on how to fix it and some people will just have HJT fix it and could cause serious harm to their system. This is especially true with the 010 LSP lines. The direction given was "Have HJT fix this" which we know in many cases means bye-bye to your internet connection.

Tools like this while informative to the user can give a false sense of security that they can resolve their issue. All I can say is an old phrase "a little bit of knowledge is dangerous" and I think this tool will cause more harm than good for the uneducated in the review of HJT logs.

Ok off the soap box :P.
--
The next best thing to being smart is being able to quote someone who is.



John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

said by siggyx:
I would be cautious about recommending that HJT log online review to anyone.

I think you must have missed what I wrote above.

"It certainly helps to sort the wheat from the chaff very quickly. The results should not be taken as gospel: it is only as good as its database, which must be updated regularly. It does appear to be getting more accurate."
--
Better to remain silent and be thought a fool, than to speak and remove all doubt.

valkyrie5

join:2001-12-11
Laguna Niguel, CA

reply to John2g
Haven't run system restore but I'll look into it before making any HijackThis changes.



siggyx
Siggy
Premium
join:2003-12-10
Cambridge

1 edit

reply to valkyrie5
I didn't miss that. I have all the tools at hand to review logs and and these still are not 100% accurate and never will be.

As a tool to start to learn how their systems works and inspiring someone to join one of the help groups that would be a good thing but a HJT log is the last resort after running all the tools. Many of the people are desparate at the point that they are running HJT logs and desparate people take desparate actions, a recipe for disaster.

This will encourage people, in my mind, to go for the quick fix and this is where the danger lies because they don't have the knowledge needed to apply the quick fix.

I guess my point is that the site does not in anyway assist someone with the accurate removal of anything. It gives a false sense that the log can be managed by the person with the information that is supplied with the review. As I said I recieved many false/positives and some flat out BAD information from it.

Since we are talking in metaphors lol it's not a case of "sort the wheat from the chaff" but "throwing the baby out with the bath water".
--
The next best thing to being smart is being able to quote someone who is.



John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

We will have to agree to disagree.



siggyx
Siggy
Premium
join:2003-12-10
Cambridge

reply to valkyrie5
Please download AboutBuster from here and unzip it to your desktop but don't run it yet: www.downloads.subratam.org/AboutBuster.. »www.downloads.subratam.org/AboutBuster.zip

Please also download and install Ad-Aware from here if you haven't already: »www.lavasoftusa.com/software/adaware/ Once installed or if you already had it installed, while online start Ad-Aware, click on the "Check for Updates Now" link at the bottom right, then click "Connect". After it updates, click "Finish". Close Ad-Aware.

Follow the instructions here to enable viewing of hidden/system files: »www.xtra.co.nz/help/0,,4155-1916458,00.html

Next, go to Start->Run and type Services.msc then click ok. On the screen that comes up, scroll down to the service called "Network Security Service" and double-click on it. On the next screen, click the stop button, then in the Startup Type drop-down, change it to Disabled and click Apply then Ok.

Please print out the remainder of these directions, as you'll have to proceed in Safe mode and won't want to open IE again until they're complete.

Reboot to Safe Mode. Tap f8 while bios loads

In Safe Mode, scan with Hijack This, put checks next to all of these entries and then click "Fix Checked":

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgdvh.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dgdvh.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dgdvh.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgdvh.dll/index.html#37049

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {EF8BB02A-9D77-7F04-941C-7146169FD55A} - C:\WINDOWS\system32\atlcm.dll

O4 - HKLM\..\Run: [ntzd.exe] C:\WINDOWS\system32\ntzd.exe
O4 - HKLM\..\RunOnce: [addix.exe] C:\WINDOWS\system32\addix.exe
O4 - HKLM\..\RunOnce: [ipbz.exe] C:\WINDOWS\system32\ipbz.exe

Next, still in Safe-Mode, delete any of the following files that are present:

C:\WINDOWS\system32\atlcm.dll
C:\WINDOWS\system32\ntzd.exe
C:\WINDOWS\system32\addix.exe
C:\WINDOWS\system32\ipbz.exe

Double click the AboutBuster.exe file that you downloaded earlier. Click OK, click Start, then click OK. This will scan your computer for the bad files and delete them. Save the report it creates (copy and paste it into notepad or wordpad and save as a .txt file).

Finally, still in Safe Mode, scan with Ad-Aware and let it remove anything it finds.

Reboot to normal mode, the do an online virus scan and let it fix what it finds.

Trend Micro »housecall.trendmicro.com/

Then rescan with Hijack This and post a new log here along with the log you saved from AboutBuster.
--
The next best thing to being smart is being able to quote someone who is.



John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

1 edit

reply to valkyrie5
I don't see any significant differences between the automatic analysis and yours.

»hijackthis.de/logfiles/3bfa62ef6···562.html

What the automatic analyser doesn't know is that this CWS infection cannot be removed by HJT.



siggyx
Siggy
Premium
join:2003-12-10
Cambridge

reply to valkyrie5
I was not talking about this log in particular. As I stated I ran 20 or so HJT logs through it last night. That is what my comments are based upon.
--
The next best thing to being smart is being able to quote someone who is.


Monday, 04-Jun 10:02:55 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics