Unsolved

This post is more than 5 years old

14 Posts

5169

April 27th, 2004 12:00

Hijackthis Results / Autosearch.cc

I recently had my home page hijacked to "autosearch.cc" .   I spoke to a Dell representative that had me run the hijackthis program.  The results were 45 hits!   The representative had me fix (delete) them all.  Now after talking to a few people, I am concerned that I may have damaged my system or registry keys by deleting everything as the representative told me.  Is this true?  So far, my system is working fine althought I noticed the Norton products were disabled and needed reloaded.  Can you please advise if there is a permanent damage.  Thanks!!!!

 

14 Posts

April 27th, 2004 12:00

Thanks for your post.  My most recent log is posted on spywareinfo under my username "Dell2"   I had someone last night on the chat trying to help me recover a few items.  When I clicked on backup, nothing was there.  I think the Dell rep. had me uncheck the backup box when I first ran the program and before I found out about these forums.  If you get a chance, do you minf looking at my log.  Also, do you think I did any major damage?  Lastly, are any of these recommended programs preventative instead of reactive? 

Thanks for all of your kind help!!!!!!!!!!!!!!

2 Intern

 • 

3.9K Posts

April 27th, 2004 12:00

Hijackthis is a diagnostic tool - MOST of what it lists is vital to the workings of your machine.

If you used hijackthis from an unzipped copy from a proper folder you may be able to recover.
If you used from inside a zip (compressed) folder you will have lost those.

Use:-

Hijackthis- config - backups - restore those items you removed.

=======

Please then reboot and do a fresh hijackthis log and post it here for us to advise.
Here are my normal instructions
================================
Use these to remove Malware (Virus, Spyware and Adware).

1) SpyBot Search and Destroy
After installing SpyBot Search & Destroy, first press Online, and search for, put a check mark at, and install all updates.
Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all the items it marks in red.

2) Get Ad-Aware
After installing Ad-Aware, and before running the program, first press “check for updates now".
Click "Connect" and install all updated components available. Click 'Finish'.
Press "Scan Now", then 'next', and let Ad-Aware scan your drives.
It will find a number of "bad" files and registry keys. Click 'Next' again.
Check all found items, and click 'next' once more.
It will ask you whether you'd like to remove all checked items. Click OK.

Always reboot the computer between each program - both of these may find things that they need to have a reboot of the machine to clear - please reboot and let them finish .

Failing those solving your problems a post of a hijackthis log for the experts to advise.
HijackThis From Here
or one of these other links:-
http://www.merijn.org/files/hijackthis.zip
http://www.aluriasoftware.com/tools/hijackthis.zip
http://mjc1.com/mirror/hjt/

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Unzip HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary. Then run, scan, save log, then in notepad copy the FULL log by copy and paste as a reply to this post and an expert with HijackThis Knowldge, will have a go at giving advice. Please note the list of experts names below, very few forum regulars here have had this training.

DO NOT FIX ANYTHING WITH HIJACKTHIS WITHOUT EXPERT ADVICE
, most of what it finds you need for normal MS Windows tasks.

Known Spyware HijackThis fighters in DellTalk - If you are, and are not on the list please PM Me.

TomCoyote (of http://tomcoyote.org/forums/index.php fame)
YoKenny (Accredited Expert at TomCoyotes)
baskar1234 (Teaching Assistant at TomCoyotes, Trusted Advisor Spywareinfo)
ChrisRLG (Classroom Coordinator at TomCoyotes, Trusted Advisor Spywareinfo)
Tuxedo Jack (Teaching Assistant at TomCoyotes, Trusted Advisor Spywareinfo)
Yellowhammer (Trusted Advisor at Net-Integration, First Responder at Computer Cops)
tashi (Helper at Spywareinfo, in training at TomCoyotes)
therock247uk (In Training at TomCoyotes and Spywareinfo)
irelynmisses (In Training at TomCoyotes and Spywareinfo)
Texruss (In Training at TomCoyotes and Spywareinfo)
PGPhantom (In Training at Spywareinfo)

You could also go to one of the more specalist forums where more experts will be able to help.
http://tomcoyote.com/forums/index.php
http://forums.spywareinfo.com/index.php
http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi (Home of Spybot S&D)
http://boards.cexx.org/index.php
http://www.wilderssecurity.com/index.php
Do read the sites FAQ before posting, and advise your problem and what steps you have already done to try to cure your problem.

I, and the other hijack experts mentioned above, are in all those sites (and more) with the same login names. You might get one of us at those sites also to anwser your log, but other experts will also be available.

2 Intern

 • 

3.9K Posts

April 27th, 2004 14:00

Provide a link here to the SWI topic and I will look at it (I will try to find it). I was in the chat last night, (My time - UK) and if you got help there you should be OK. I also post at several other forums including SWI. 

If it still runs it should be possible to get it back working OK - but it may require some reinstall of programs.

Look on my website for recommended programs, I get asked that so much - I keep the list handy. Link below to my website.

2 Intern

 • 

3.9K Posts

April 27th, 2004 15:00

Seen your log - it is here http://www.spywareinfo.com/forums/index.php?showtopic=43303&st=0&#entry217769

You have at least one malware still in your system - that trainee will be told so that they recognise it in the future.
=============Your Log==================
Logfile of HijackThis v1.97.7
Scan saved at 12:08:56 AM, on 4/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [svchost] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac...ta/SymAData.dll
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB1FF719-F3DA-4E94-863E-84253120BE85}: NameServer = 151.201.0.39 151.201.0.38
============end log================
I am at work and will provide a post for you later on what you should do - say 3 hours from now.

2 Intern

 • 

3.9K Posts

April 27th, 2004 15:00

Have these IP addresses been given to you by your ISP as gateway or DNS servers. It would be in the paperwork that they gave when setting up.

151.201.0.39

151.201.0.38

2 Intern

 • 

3.9K Posts

April 27th, 2004 20:00

LOL.

Already replied to you at SWI.

14 Posts

April 27th, 2004 20:00

I am still having some problems.  Please go to  http://www.spywareinfo.com/forums/index.php?showtopic=43303&st=0&#entry217769    as I can't get my log file to post here.    THANKS!

14 Posts

April 28th, 2004 01:00

I posted more detail at swi.  However, since then, I have ran spybot and the folllowing came up.  They all seem to deal with some type of zones.   Should I fix these???

 

DSO Exploit: Data source object exploit (Registry change, nothing done)
  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
  HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
  HKEY_USERS\S-1-5-21-507921405-1844823847-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004=W=3

Windows Media Player: Client ID (Registry change, nothing done)
  HKEY_USERS\S-1-5-20\Software\Microsoft\MediaPlayer\Player\Settings\Client ID=

Windows Media Player: Client ID (Registry change, nothing done)
  HKEY_USERS\S-1-5-19\Software\Microsoft\MediaPlayer\Player\Settings\Client ID=


--- Spybot-S&D version: 1.2  ---
2003-03-16 Includes\Cookies.sbi
2003-03-16 Includes\Dialer.sbi
2003-03-16 Includes\Hijackers.sbi
2003-03-16 Includes\Keyloggers.sbi
2003-03-16 Includes\Malware.sbi
2003-03-16 Includes\plugin-ignore.ini
2004-03-09 Includes\Revision.sbi
2003-03-16 Includes\Security.sbi
2003-03-16 Includes\Spybots.sbi
2003-03-16 Includes\Temporary.sbi
2003-03-16 Includes\Tracks.uti
2003-03-16 Includes\Trojans.sbi

 


---

2 Intern

 • 

3.9K Posts

April 28th, 2004 07:00

If Spybot S&D marks them in RED you should fix them. If not they would not be your problem.

14 Posts

April 28th, 2004 12:00

I'll fix the items marked in RED. Is Spybot S&D different than Hijackthis?  I mean is it safe to generally delete Everything that comes up in RED in Spybot S&D? 

Also, should I fix O4 - HKLM\..\Run: [svchost] C:\WINDOWS\svchost.exe  in Hijackthis. 

If you want, you can take a look at my recent posts as Dell2 in swi site.  Thanks again!!!!!!!!!!!!!!!!!!!!1

 

2 Intern

 • 

3.9K Posts

April 28th, 2004 18:00

Spybot S&D is an automated program that removes malware of various types, the bad ones it marks in red, the others are less of a problem.

Hijackthis is a manual removal tool, it needs an expert to decide what to choose to remove and what to keep.

14 Posts

April 29th, 2004 12:00

Thanks for all your help Chris. If I post a hijackthis log this evening (it is early morning here), can you take a lot at it to make sure everything in now cleaned up?

2 Intern

 • 

3.9K Posts

April 29th, 2004 20:00

Yes Texruss or myself will check your log for you.

14 Posts

May 1st, 2004 01:00

Hi Chris and Texruss!

Can you please go to the following link at SWI and let me know by posting your comments here if my Hijackthis log is clean?

http://www.spywareinfo.com/forums/index.php?showtopic=43303&st=0&#entry220899

I am unable to post my log here because I keep getting some type of annoying HTLM error messages on this site!

 

Message Edited by goldentee14 on 04-30-2004 10:59 PM

2 Intern

 • 

3.4K Posts

May 2nd, 2004 15:00

I'd prefer a fresh one today if you can take the time.

Texruss

No Events found!

Top