Will some expert please analyze this hijackthis log. I know this computer has been infected with spyware and probably the Sasser worm. I have run Ad-aware, Spybot Search & Destroy, CWShredder and now Hijackthis. Computer had slmss, mwsvm, Keyhost, fash, sysupd, View Mgr, winnet, AdDestroyer running at startup which I disabled. I also got rid of LSA Shell(Export Version) error. Please offer any other suggestions.
Thanks for your help! This is the latest hijackthis log:
Logfile of HijackThis v1.97.7 Scan saved at 9:08:05 AM, on 6/13/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
While the previous poster had you remove entries and correct the Winsock hijacking there were a few things left undone. Well-done illukka for a first effort (would you be interested in joining our Classroom to become an expert responder?) .
Fixing things in Hijackthis fixes registry entries and cuts the head off the snake...to fully clean we need to delete the bad files also in Windows Explorer or they may mutate and return. After looking at the latest log and the previous one I see this one did: C:\Program Files\MULTIC~1
Run Hijackthis, scan and check the box left of these numbered line items:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search200.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search200.com/searchbar.html R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: (no name) - {69EB272B-AFC1-2FB2-586F-2AE51DAA139B} - C:\PROGRA~1\MULTIC~1\media knob.dll O2 - BHO: (no name) - {BA25708B-154D-4D40-8607-67AA5190C395} - C:\PROGRA~1\INTELL~1\ISengine.dll (file missing) Comments: looks like your Intellistopper program is whacked...uninstall in Control Panel/ Add/Remove Programs O4 - HKLM\..\Run: [Piolet] C:\Program Files\Piolet\Piolet.exe SILENT Comments: Don't check, but I would never let a peer-to-peer autoload on any of my machines. O4 - HKLM\..\Run: [BibRdr] C:\PROGRA~1\MAGSSO~1\KindAudioPop.exe Comments: Looks like random Trojan to me..if you know it is legit do not check. O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\updater\wupdater.exe Comments: malware... http://www.winpatrol.com/db/freesample/wupdater.html O16 - DPF: {9656B666-992F-4D74-8588-8CA69E97D90C} -
With no other windows open click on fix checked button in Hijackthis.
Exit Hijackthis.
Reboot to SAFE MODE and Show HIDDEN FILES and folders (VERY IMPORTANT!)
Next...Download and run these two programs (Spybot S&D and Adaware) at the link below. Use Spybot first.
Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.
Follow the directions in this detailed guide for Spybot and Adaware...print out the directions in the custom scan tutorial as a reference while you set these options for the custom setup of Adaware. These custom settings will be retained for future custom scans so don't go nuts thinking you have to do this every time you run it! It may take you five minutes to set them up, but it's worth it.
Thanks Texruss! Is it safe to assume that if BHO has "(no name)" then it can be deleted? I could not find up-to-date BHO list. Also illukka had me to delete the XXPatchInstaller.CAB-- some logs I saw had this and were considered clean. What was the key to knowing this was bad? Was it the CLSID? I would love to join your classroom!
This is the latest hijack log. Hope this one is clean. Thanks for your help.
Logfile of HijackThis v1.97.7 Scan saved at 7:27:05 AM, on 6/16/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
>Also illukka had me to delete the XXPatchInstaller.CAB-- some logs I saw had this and were considered clean. What was the key to knowing this was bad? Was it the CLSID?
As far as I know the CLSID is clean and that is an entry for the XP SP1 patch upgrade from the MS Security CD (I see another entry in your 016's below). It does look evil though and I see a lot of people fix it, but probably for non-hostile reasons. Probably it's good to remove it to slim down the non-essential ActiveX scripts loading.
>I would love to join your classroom!
I appreciate the interest, but you misread my original quote: "Well-done illukka for a first effort (would you be interested in joining our Classroom to become an expert responder?). However, there is always time to advance your skills and attract my interest in the future.
I'm also not even a tiny fan of Stopzilla, despite all the gleaming reviews it gets from CNET. If you want to remove it, kill the 016 line and uninstall it in Control Panel/Add Remove Programs.
All the best,
Texruss www.russelltexas.com Spyware Fighter Wilders Forum Slyware Warrior Tom Coyote Forum Expert Malware Responder Dell Forum
Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley.
Thank you Texruss! This is the latest hijackthis log.
Logfile of HijackThis v1.97.7 Scan saved at 10:47:33 PM, on 6/16/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
You look clean and hearty congratulations! Now to stay that way:
Cleanup Programs and Procedures
(the four free programs in Items 2, 3, and 4 bolded below are a MUST in my opinion)
1. Spybot Search&Destroy, Ad-aware Run weekly - or after a heavy internet session. Download at the following link.
Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.
Follow the directions in this detailed guide for Spybot and Adaware...g
o slow on the directions for the custom setup of Adaware and print it out as a hard copy. It will take five minutes to set up the custom scanning options for Adaware, but it's worth it as these settings will be retained and you won't have to re-enter them again.
Please note the free Spybot 1.3 does have a slight bug...it detects some DSO exploits falsely. Hopefully an upgrade will fix this.The problem is not serious and should not deter people from using Spybot.
I also like to run Windows Disk Cleanup after cleaning with those two tools. Make sure you reboot if any reboot cleanup functions of Spybot and Adaware are advised by these tools (this may happen at the end of their cleanup).
Reboot and click on Start/Run/ type:
cleanmgr
If you have problems with Disk Cleanup hanging and not completing see this page for XP users:
From MS Help: "
Disk Cleanup helps free up space on your hard drive. Disk Cleanup searches your drive, and then shows you temporary files, Internet cache files, and unnecessary program files that you can safely delete. You can direct Disk Cleanup to delete some or all of those files."
I check all the selected categories and click OK at the end of Disk Cleanup.
If you have any problems with Disk Cleaner completing...XP users can fix it here:
2. Proactive programs: Spywareblaster & Spywareguard, first sets kill bits to stop known bad MSIE ActiveX scripts from installing, second acts like your AV to stop browser hijacks and installing of known baddies.
3. IE-Spyad, puts 4000 bad sites in your restricted (banned) sites list, to stop you accidentally getting sent to a bad site, it has optional list of "bad" adult sites to install as well.
The MVPS Hosts file replaces your current HOSTS file with one that prevents your computer from connecting to hostile sites by redirecting them to 127.0.0.1 which is your local computer. This is an easy way to prevent one of the most common hijackings computer users will face on the Internet! Do it now.
5. Don't forget keeping Windows updated. The automatic updates frequently fail so run it manually once a week or when new updates are publicized.
You can also start Windows Update by running Internet Explorer, pulling down
Tools on top Menu bar and selecting
Windows Update. Install ALL critical updates! Always!
If LiveUpdate fails (and it is prone to on MANY machines) download each patch manually from the MS advisory pages and install manually. Works for me!
6. Keep your antivirus updated.
Free AVG Antivirus for home users:
http://www.grisoft.com
7. Beg, borrow, or buy a Software Firewall if at all possible. I use Norton Internet Security 2004 and it has saved my bacon more times than I can count. For a free software firewall turn on the fairly lame firewall in Windows XP (I say it is lame because it does not monitor or block outgoing traffic...only incoming...a serious omission if the threat occurs inside your network). Hopefully with the upcoming Service Pack 2 this flaw will be addressed.
8. Practice safe computer habits. Don't click on strange email attachments thinking your AV will defend you. Usually it will. Sometimes it won't when a new virus hits the Net and definitions take hours to create by the AV vendors. There is only one defense that works 100% for the safe protection of your machine's personal data and that is timely and accurate backups of your files. Hard drives die, viruses ruin your files, and other bad things can happen (fire, theft, etc..). Offsite backups are the best.
9. Don't forget our great analysis tool Hijackthis. We have a lot of gratitude we need to show towards the author Merijn. I hope he does great things in his future endeavors and is richly rewarded for his time and expertise in providing this super program.
Hijackthis (to analyse your system and submit a log file to expert forums):
http://tomcoyote.com/hjt
(for Hijackthis logs...please copy to and run Hijackthis.exe into a new folder you create in the root level of the C: drive. Name this folder HJT for best and safest results). (don't put in a Local Settings Temp folder, or the Windows desktop, etc...as it needs a safe folder to keep backup logs). Also when XP and W2K users post here and place it in the Local Settings, the log usually shows their full name since their Windows user profile is commonly named with their full name. We try not to disturb your privacy. *;-)
Texruss
www.russelltexas.com Spyware Fighter Wilders Forum
Slyware Warrior Tom Coyote Forum
Expert Malware Responder Dell Forum
Please be aware only the following DellForum members were trained at
TomCoyote.com and SpywareInfo.com to help with Hijackthis logs:
Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley.
illukka
4 Posts
477
0
Posted June 12th, 2004 20:00
close all windows except hijackthi, tick the boxes next to these lines and click FIX( it's a long list, might help to print it):
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchexe.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchexe.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchexe.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchexe.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchexe.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seekseek.com/quicksearch.asp?session=304CB2EA-A468-49CC-9C91-562DF4B0EB30&version_id=18
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-AB2D-8D32436313D9} - C:\WINDOWS\bsx5.dll (file missing)
O2 - BHO: (no name) - {40E13BDE-361A-436F-86E9-CE10DC4263B9} - C:\WINDOWS\System32\avikcap32.dll (file missing)
O2 - BHO: DefaultSearch.SeekSeek - {5074851C-F67A-488E-A9C9-C244573F4068} - C:\WINDOWS\ieasst.dll
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: (no name) - {69EB272B-AFC1-2FB2-586F-2AE51DAA139B} - C:\PROGRA~1\MULTIC~1\DeadHold.dll
O2 - BHO: (no name) - {8D91ECD1-2A29-41B8-9988-FD892F07F859} - C:\WINDOWS\ip.dll
O2 - BHO: (no name) - {BA25708B-154D-4D40-8607-67AA5190C395} - C:\PROGRA~1\INTELL~1\ISengine.dll (file missing)
O3 - Toolbar: Roamsoftcopy - {CA5D97F0-1C73-3AE3-61D9-562222687792} - C:\PROGRA~1\MULTIC~1\DeadHold.dll
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
for the next part you need to download lspfix from http://www.cexx.org/lspfix.htm
direct download http://www.cexx.org/LSPFix.exe
run it, chekmark the box i know... and fix all instances of inetapt.dll
post a fresh hjt log when done