1
   

Virus? Hijack? What to Do?

 
 
Reply Mon 20 Sep, 2004 10:21 am
On or about Aug 23, I lost my search capabilities. When I click on "Search" in IE, I get a "g.msn.com cannot be found" message. If I right click on blue terms in the "error" page they show links to casino's and other junk.

I have run Spybot, AdAware, Trend Micro Housecall, Bazooka, and Norton.

Norton found three Backdoor.Trojan virus files, but they are in C:\System Volume Information\_restore followed by a long number/letter combo ending in .scr. I have done a search on C: including hidden files, but am told I cannot access Syst. Volume info file.

Trend micro Housecall says I have a virus called TROJ SMALL.EL, which I am unable to find any info on. It is supposed to be in C:\Documents and Settings\Me\Local Settings\Temp\i3.tmp but I don't see a Local Settings folder in my Windows explorer. Trend Micro Housecall said it was non cleanable.

Here's my HJT log, but I don't think it is showing anything:

Logfile of HijackThis v1.98.2
Scan saved at 12:19:49 PM, on 9/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nc.rr.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D798803-E796-4C16-9BBA-5834FEA3F448}: NameServer = 209.47.15.118,64.157.143.38,24.25.4.108,24.25.4.109
O17 - HKLM\System\CS1\Services\Tcpip\..\{3D798803-E796-4C16-9BBA-5834FEA3F448}: NameServer = 209.47.15.118,64.157.143.38,24.25.4.108,24.25.4.109


Any ideas? I just want my internet search to work.
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 2,318 • Replies: 17
No top replies

 
squinney
 
  1  
Reply Mon 20 Sep, 2004 10:26 am
BTW, the same "fake" MSN error page appears on the right hand side of my screen on A2K, where the banner ads are suppose to be.
0 Replies
 
squinney
 
  1  
Reply Mon 20 Sep, 2004 10:29 am
Here's a copy/paste of what is on the right side of my screen. In this case it says tribalfusion, whereas on my sidesearch it says g.msn cannot be found.

__________________________________________


We can't find "a.tribalfusion.com"

You can try again by typing the URL in the address bar above.
Or, search the Web:


Go to MSN Search to see complete results for "a.tribalfusion.com".



Check availability or register the domain name 'a.tribalfusion.com'.
--------------------------------------------------------------------------------

More information about this error.
About Results

Powered by MSN Search


?2003 Microsoft Corporation. All rights reserved. Terms of Use TRUSTe Approved Privacy Statement
0 Replies
 
jespah
 
  1  
Reply Mon 20 Sep, 2004 10:31 am
tribalfusion is an ad network used by A2K. Can't tell you about the rest of it, though, sorry.
0 Replies
 
squinney
 
  1  
Reply Mon 20 Sep, 2004 10:51 am
Oh, okay. That would explain the persistant cookie Very Happy

But, I wonder why the ads suddenly aren't showing up anymore. This coincided with the sidebar search problem.
0 Replies
 
squinney
 
  1  
Reply Mon 20 Sep, 2004 11:57 am
Ooooh! I may have fixed it. I'll tell you what I did in case anyone else has this problem, or in case Craven or Don comes along to tell me what I did was a major boo boo.

This is what I did:

Start
Run
Regedit
In Regedit, I clicked Edit and then I clicked "find"
Typed in the {590814B4.....} number that Norton gave me (the one Norton said was in my C:\system Volume information\_restore that I couldn't find or access elsewhere.)

Found two references. One was under .cfr and the other was in Restore folder as Machine GUID.

I deleted both. Restarted computer. I now have my MSN search sidebar.


I don't want to trust this, but it may have worked. My fear is that Norton gave me 3 infected files and the regedit find only came up with two references. Not sure if the one remaining is one of the two Norton identified as .exe or the one .scr. Norton didn't identify a .cfr, which was one of the ones I deleted, at all.

Rest assured I'll return if I continue to have problems with this. What a pain in the behind for the last couple of weeks!!!
0 Replies
 
squinney
 
  1  
Reply Mon 20 Sep, 2004 04:16 pm
Never mind. It's Baaaack!

I have no idea what else to do.

My temp / temp internet/ cookies/ cache/ are all empty.

Any suggestions?
0 Replies
 
Cyanure
 
  1  
Reply Mon 20 Sep, 2004 04:30 pm
Quote:
Norton found three Backdoor.Trojan virus files, but they are in C:\System Volume Information\_restore

You just need to turn off your system restore to get rid of these trojans.
They are not in the system but in the archive.
Do the following:
Right click My Computer and click Properties.
Click System Restore and check Turn Off System Restore On All Drives.
Click Apply and OK
Restart your PC
Right click My Computer and click Properties.
Click System Restore and uncheck Turn Off System Restore On All Drives.
Click Apply and OK

Rescan your PC and it's free from these trojans
0 Replies
 
Don77
 
  1  
Reply Mon 20 Sep, 2004 05:53 pm
Hi squinney, Your log looks fine,
I must say you done good!!! Cyanure hit it on the head, Follow his advice and you should be all set,
Let us know how you make out
0 Replies
 
squinney
 
  1  
Reply Mon 20 Sep, 2004 07:21 pm
Well, it worked for three searches and then got hijacked again.

It's back to saying:

We can't find "g.msn.com"

You can try again by typing the URL in the address bar above.
Or, search the Web:


Go to MSN Search to see complete results for "g.msn.com".



Check availability or register the domain name 'g.msn.com'.
--------------------------------------------------------------------------------

More information about this error.
About Results

Powered by MSN Search


?2003 Microsoft Corporation. All rights reserved. Terms of Use TRUSTe Approved Privacy Statement
0 Replies
 
Jestah
 
  1  
Reply Tue 21 Sep, 2004 05:39 pm
I've had this happen to me. It doesn't seem that any antivirus/anti-spyware tool can completly clean it. Ad-aware detects and cleans it but when the browser executes again, it's back.

There's probly some way of cleaning it out there but after searching for ages I couldn't find it. I ended up using system restore to return my system to the previous day and it worked fine.

Your search page is referenced from the registry key:
"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchPage"

Although changing it is probably pointless as the hijacker seems to change it back every time you run the browser.

The temp folder you mentioned is where the pages that the hijacker replaces (search page) are loaded from. These are replaced if you delete them.

The "restore" files are the records that System Restore uses to restore youre computer to a previous date. These may be marked as infected by your antivirus but they are harmless. This just means that at a previous date, a virus was on you computer and was archived by the restorer.

I wouldn't recommend you take Cyanure's advice and disable system restore as this would disable the easiest and most certain method to get your browser back.

Use system restore and return to a date just before you got hijacked. Then run a virus/spyware scan just to make sure its all clean.

Hope that helps.
0 Replies
 
squinney
 
  1  
Reply Wed 22 Sep, 2004 03:35 pm
Thanks, Jestah. Sounds like you know EXACTLY what I'm dealing with. I tried the "restore" first thing when I started dealing with this, and it wouldn't allow me to do so for any of the dates, even though "Restore" had always been on.

Think I'm gonna just backup my important files and reload Windows.

Anyone want to stop me? I'll give you a few hours to respond and then I'm taking the plunge.

BTW, I clicked on the fake search which took me to findwhatevernow .com. I clicked on the "contact Us" and sent them a message re: tell me how to get you off my computer.

Here's the message I got back the next day:

Pop Up Removal Instructions

You are not subscribed to any of our Opt-In Mailing lists. In order to
remove pop-ups, please follow these instructions:

Click this link http://www. rapidremove.com/uninst/LPUninstaller2004.exe and it will ask you if you want to save the file or open it. Save it into a file that you will recognize on your computer. Please note that this will NOT install anything on your computer that is unwanted. When the file is done installing "open" this file and you should receive a message that the installation was successful. This will remove you from any pop ups that you receive on your computer. You will then have the program RapidBlaster (RB32) removed from your computer. If clicking the link does not work, open your browser and cut and paste the link instead.

Sorry for any inconvenience. Should you experience any further problems, please email support@ rapidblaster.com.

Customer Service


Needless to say I wrote them back. Haven't heard anything yet. Maybe I'll back up files I need and then click their install suggestion before I try reloading Windows. I'm starting to think that if I blow anything up it'll actually be good therapy at this point! Confused
0 Replies
 
squinney
 
  1  
Reply Wed 22 Sep, 2004 03:54 pm
Craven- If you stop by... I tried your suggestion but it won't let me download SP2. When I clicked on the "download SP2" through the link you gave me I got instructions for setting my computer for automatic downloads or a link for ordering the CD.

I spoke with Bears band buddy at Microsoft today. He had the same thing last week and said Adaware and Spybot cleared it up for him.

Also said DO NOT download / Install SP2 until the virus is completely gone. Otherwise, the virus gets integrated / accepted as normal by SP2 and won't protect against it, or any related virus/malware/spyware. For example, I've identified joystick, bargain buddy, rapid blaster, mediamacro (tricky with the name, huh?) iwon, and a couple of others that are all somehow related to findwhatevernow .com. If I install SP2, I won't be protected from any of those named if they are really all coming from findwhatever - this according to our buddy at Microsoft.
0 Replies
 
cjhsa
 
  1  
Reply Wed 22 Sep, 2004 04:02 pm
I highly recommend this triage:

Adaware (http://www.lavasoft.de)
Spybot S&D (http://www.safer-networking.org)
and finally
Pest Patrol (http://www.pestpatrol.com -- not free, but worth every penny)
0 Replies
 
Don77
 
  1  
Reply Wed 22 Sep, 2004 05:07 pm
Hi squinney
See if this helps you out RapidBlaster Killer 1.61

After that Check Ad-aware, Spybot and your Anti Virus for updates, Reboot to safe mode and run a scan with them,
Next restart your computer see if that helps you out, Post back let us know how you make out
0 Replies
 
Jestah
 
  1  
Reply Wed 22 Sep, 2004 05:40 pm
Like I said, none of the big antivirus or spyware tools fix this at the moment. Ad-aware, spybot and pest patrol are all useless here, although rapidblaster killer might be worth a try.

I know from first hand knowledge that all the obvious methods will not work and if 'system restore' isn't an option maybe reinstalling isn't such a bad idea. Unless rapidblaster killer works.
0 Replies
 
Jestah
 
  1  
Reply Wed 22 Sep, 2004 06:21 pm
I've just checked out RapidBlaster Killer and it seems like it will do the job. I wouldn't advise using 'RapidRemove' as anything other than a last resort - anyone evil enough to make the thing in the first place cant be trusted to remove it.

Oh and by the way here's a copy of a little something I sent to [email protected] in reply to the message they sent:

"How have you got the nerve to send this? You install invasive, intrusive and downright malicious applications without any consent being given and then you have the nerve to make it out to look like some sort of mistake or oversight. Surely an organisation with such degraded morals would not even bother to reply to or help with such a matter, let alone have a dedicated support contact. I am acting on behalf of someone else in sending this and may not be fully aware of the facts but one fact I am fully aware of is that RapidBlaster is much more than just a 'mailing-list' or 'popup'.

I hope you realise that this RapidBlaster software is highly illegal. You'd better hope your domain isn't registered to a traceable address."
0 Replies
 
squinney
 
  1  
Reply Wed 22 Sep, 2004 08:13 pm
Hmmm. Now that is really interesting. It was Findwhatevernow. com that referenced Rapid Blaster. I hadn't seen anything on my computer called Rapid Blaster or RB32, but since the e-mail from findwhatever called their "uninstaller" that, I thought it might be... But, apparently not.


Thanks for the link, Don. I downloaded the program and ran it but it found no processes at this time. I ran it with IE open and closed. Perhaps that was just a way for Findwhatever to throw me off the real path?

Wow! Jestah - You wrote the e-mail I wanted to send but couldn't since I was still hoping they would be of help. LOL! Yeah, right! I'm perhaps expecting a miracle?

Spoke with Craven earlier. He suggested reloading IE, so I will try that and see what happens. It won't let me go to any microsoft or msn sites so I'll get it from Bear's computer.

Thanks so much for helping me with this. I'm extremely grateful. (And, I've learned SO much about computers - so perhaps there is an upside.)
0 Replies
 
 

Related Topics

YouTube Is Doomed - Discussion by Shapeless
So I just joined Facebook.... - Discussion by DrewDad
Internet disinformation overload - Discussion by rosborne979
Participatory Democracy Online - Discussion by wandeljw
OpenDNS and net neutrality - Question by Butrflynet
Internet Explorer 8? - Question by Pitter
 
  1. Forums
  2. » Virus? Hijack? What to Do?
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.04 seconds on 05/05/2024 at 12:11:15