Wilders Security Forums  

Go Back   Wilders Security Forums > Browser Hijacks and Spyware Problems > news, general information and FAQs
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Spyware Cleaning Section Closed!!
Notice: The spyware cleaning (HijackThis) section is closed. Wilders Security no longer provides one on one spyware cleaning assistance. Please see this announcement for a list of websites that provide such services.
 
 
Thread Tools Search this Thread
  #1  
Old April 20th, 2004, 06:56 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default CWS Variants

Lately a new strain of cws variants are following eachother very rapidly.

They are becoming harder and harder to clean because they are using all sorts of tricks to prevent scanning tools from detection or proper removal (like re-infection).

It's getting more difficult now for Merijn to update CWShredder both because of the more complex coding and the amount of new types/variants that appear on a very regulary basis.

Bare in mind that experts are working around the clock looking for successfull removal tips and prevention fixes.

This means however, that as long as the shredder is not updated, victims will be advised to clean their infection manually. Although experts and more savy computer people are used working in the registry, and all sorts of tools which involves editing in windows it will be more and more difficult for the normal computer user to clean up once he/she is infected. Advise given by expert people may look rather complex, when having any doubts whatsoever, don't hesitate to ask for more advise.

Expertised people in this area (on this board) who are more closely involved in analysing and know the latest details are :

Pieter Arntz (aka Metallica on other numerous boards)
dvk01
shadowwar


Feel free to contact one of the mod's if any questions. They are all very knowledgable and will at least be able to point you in the correct direction :

dave38, puff-m-d, wizard, Technodrome, JacK, Dan Perez, MickeyTheMan, Detox, Unzy, snowbound, snapdragin, rodsoto, bigc73542

Below follows a summation of those new strains of more complex CWS variants, beginning with the drxcount one,which seems to be the first one to introduce a whole new set of invisible CWS hijacks and tricky coding. I will try to give the most common instructions summed by experts. Some of them work very well, other are a bit complex. Some work for user X, while user Y complains of a re-infection, after following the exact same instrucions.

Note :

After cleaning a CWS infection always check your 'Favorites' folder for added porn links***

A list of all known CWS domains can be found here :

http://users.skynet.be/bk136527/CWS/CWSdomains.htm

Last edited by Unzy : May 27th, 2004 at 02:25 PM.
  #2  
Old April 20th, 2004, 06:59 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

drxcount.biz / real-yellow-page.com

A very great place to start, where we gathered all info together with infected users is a topic started by Pieter Arntz (Metallica). It shows investigation of expert people nicely evolving from sleepless nights to succesfull removal instructions! If you are interested in reading the developments you can check it here :

Click Me

Usually, the following instructions are given now :

Quote:
If your browser has been hijacked to drxcount.biz, real-yellow-page.com or list2004.com:
We are working on a fix for this one and drawing near to a solution. This is by far the most sophisticated CWS variant seen to date, and it will take some time before CWShredder will be able to remove it automatically.

So far, the following manual fix should work:

Download PrcView here: http://www.spywareinfoforum.com/~merijn/files/pv.zip, unzip it to the desktop.

Be sure to have at least 1 Internet Explorer window open, then double click on the runme.bat.

Notepad will open with a log in it. Look for a line with this file, size and beginning to it.
The filename will always be different:
winajbm.dll 61c00000 61440 c:\windows\system32\winajbm.dll

This part indicates the bad file:
61c00000 61440
It will always start with that header.

Write down the filename behind it.

Now download KillBox:
http://download.broadbandmedic.com/VbStuff/KillBox.zip

Unzip and run it.

Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot".

On the next screen, click on the File menu and choose "Add File". The file you copied earlier should now show up in the window. If that's successful, choose the Action menu and select "Process and Reboot". You'll be prompted to reboot, do so.

After rebooting, make sure the file is gone

Last edited by Unzy : April 22nd, 2004 at 10:50 AM.
  #3  
Old April 20th, 2004, 07:00 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

CWS.Systeminit variant - (hijacks to your-search.info, in some cases to another CWS domain)

Note* : CWShredder takes care of this successfully so far

Responsible entries in a HijackThis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = hxxp://www.your-search.info/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.your-search.info/start.html

O4 - HKLM\..\Run: [system32.dll] C:\WINDOWS\system\systeminit.exe

O4 - Global Startup: sytem32.exe (note the spelling!)

O19 - User stylesheet: C:\WINDOWS\sstyle.css
O19 - User stylesheet: C:\WINDOWS\sstyle.css (HKLM)

Log examples :

HERE
HERE

Last edited by Unzy : April 20th, 2004 at 07:45 AM.
  #4  
Old April 20th, 2004, 07:03 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

about:blank / linklist.cc

This is a very complex hijack to solve for now, as only manual instructions are given. Please only follow instructions when you are guided by an Advanced or Expert member!

Responsible entries in a HijackThis log :

R0 and R1 entries pointing to the following similar looking location : res://C:\WINDOWS\System32\kfiokk.dll/sp.html

O2 - BHO: (no name) - {54DDBEA0-AAE2-43A1-9076-3F064D0DEA55} - C:\WINDOWS\System32\kfiokk.dll*

* the dll is randomly named for each victim, and is showed as a 02 - BHO in a HijackThis log.

Although the entries in a HijackThis log are pretty obvious, the tricky part of this variant is a cleverly disguised re-infection method, after a certain amount of time when the victim connects again to the internet.

The methods so far all failed to give a 100% clean result, even with an updated shredder for this particular variant, so I'm not gonna bother to list them here, as experts are now in the middle of looking for answers, as we speak. As soon as we have a successfull removal method, this topic will be updated.

For those interested I can inform what we gathered so far :

It all comes down to these two files :

Quote:
1. The randomly named BHO file (a .dll) in the system (win9x/ME) or system32 (win2k/XP) folder with the corresponding ClassID's (in some logs there were up to 11 morphed ones!)

2. The AppInit_DLLs entry, a registry key which points to a hidden dll located in the system/system32 folder, responsible for the re-infection.

The key is :

Trying to make this superhidden dll visible so it's removable! Lately, it seems best to start with the removal of this dll, before following other instructions!

*UPDATE!

Shadowwar has pulled dllfix, too many bugs and variants within the hijack itself are making it impossible to work properly.

It's best to post your problem at the corresponding forums, and wait untill you get a responce from an expert, for further guidance.

Download and run AdAware : http://www.lavasoft.de/software/adaware/ (make sure you have latest updates) and run it, after doing so post your HijackThis log.

Old fix : (keeping this here, just in case)

As we are drawing near a successfull removal method, this is the canned fix of procedures to follow :

(Note that at this time only manual instructions are given and they can be somewhat complex)

Đ freeatlast :

*for win2k / XP (win98 is at bottom)

Quote:
1.)
***Identifying the file***

http://freeatlast.100free.com/index.html

Download find-all.exe (win2k/xp only!)

run findall.cmd and post log

At this point, based on "output.txt"
and "windows.txt" we should have the file name:

***Removal***

Based on the "System info" header in
"Find-All", 'Fat32/NTFS', can pick the best course of action.
--2K/XP/Pro/home/Fat32/Ntfs ALL can use Recovery console.
I will not list the steps, some users would need guidance
and for some it may not be an option .
--2K/XP/Pro/home/Fat32< only (minority, most likely)
Can go to bootdisk.com make Win95/98 startup disk, and
nuke the file by accessing the partition with
basic known good ol' dos commands!
=============================================

***If NOT using Dos/RC option***:
The only known working way, currently is by
renaming the 'Windows' key-- Applies to both fat/ntfs
supported sys.

Tools:
1.) Registrar Lite
2.) RegAlyzer By PepiMK, (also known from SpyBot S&D!)

Same procedure in both tools to
rename the key, erase data, rename back, followed
by RESTARTING the computer! :

Quote:
-Run reglite : type--
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
into the address bar, or expand the same key.

-Rename the Folder Windows
to NotWindows highlighted as a purple folder
in the left hand pane of reglite.

-Click "AppInit_DLLs" again and clear the data value:
C:\WINDOWS\System32\xxxxxxx.dll (random named dll) <- delete this line ,
'Apply' and 'ok' to set.

-Rename the NotWindows folder back to its
original name Windows

-Restart computer

Check in the system32 folder if the culprit dll is visible

***Delete File***

Only needed for:
--2K/XP/NTFS< !

--Move file+Modify it's permissions:

1.) Go to your root drive: C:\ and create
new folder,
Name it: "junk"

Download, unzip to folder and run WinFile.zip (note : for win2k/xp!)
Expand and navigate to System32 folder.
You need to navigate by Double clicking to expand.

When in System32 click top menu: File>Select files
Copy and paste to the box:
xxxxx.dll hit select-
Find and hilite that file.

Lastly, try this: Menu -File>move...
In From: Copy/paste:
C:\WINDOWS\System32\xxxxxx.dll
To: Copy and paste:
C:\junk\xxxxxx.dll
And hit ok.
Close Winfile and check in C:\junk for that file.

2.)
RightClick on the
junk\"xxxxxxx.dll"/Properties/Security/permissions\
advanced,
and take ownership giving yourself-> 'Full control'.
(Preferably to Administrators 'group')

3.)
Shadowwar wrote:
Quote:
-Right click the "junk folder" folder itself.
-hit properties.
-go to the security tab and click the advanced button.
-check the box-
to reset permissions on all child objects.
Hit apply.
ok your way out.
File can now go bye bye!

4.)
Delete file+junk folder.
-------------------------------------------------------------------------
--WinXP home edition/NTFS (only!):
Must Follow last Steps# 2-4 in Safe Mode
in order to access security tab.
(Alternatively run cacls.exe, if familiar)

--2K/XP/All-versions/Fat32< only,
Can simply find and delete the file after
restart! (skip all 'winfile' &onward steps!)
=======================================
***ALL platforms/sys that
renamed the 'Windows' key:***
--Because we renamed it, Windows REMOVED defaults
security settings on this key and
allowed the 'everyone' group read access!
(Just as if new key was created)
(regedt32 started alerting me that the "new" key
settings are incomatible with windows! )
***Repair***:
--*WinXP/Pro/Home:
-> regedit.exe-> RightClick 'Windows'->
->Security/permissions/Advanced
*Win2K ->regedt32-> hilite 'Windows' key->
->top menu->Security
->permissions->Advanced tab
--------------------------------------------------------------
UNcheck: "inherit permissions" box,-> Select
COPY on next prompt!
(That will restore last saved settings in database)
-Hilite "Everyone" (group/only!)->Select-> REMOVE!
-Hit 'Apply and 'ok' on all check boxes.
*Sample pix correct/incorrect settings added to \'Find-All\' link.

*WIN98

Tools :

Win98Fix
StartDreck

Quote:

**Identify file:**
Download: "StartDreck", unzip!
DoubleClick: 'StartDreck.exe'
Hit: config
hit: Unmark all
Check these boxes only:
Registry->run keys
System/drivers> Running processes
hit >ok.

Check specificly for this entry in the log :

Quote:
ŧLocal Machine
ŧRunServicesOnce
**ozkc=rundll32 C:\WINDOWS\SYSTEM\XXXXX.DLL,StreamingDeviceSetup

After identifying the dll, proceed with :

-Download: "Win98Fix.zip", Unzip!
-DoubleClick on: 'RunFix.reg' file, hit 'yes'
on the prompt!
-Restart computer!
-File should be visible!
-Do 'find files' for dll listed on log, delete.
*Note: Be sure to Save the StartDreck log before, so
you you'd be able to find the file later!
If lost (Since nothing else will find it when not hooked)
Simply run the included: "who.bat", file
will be found & listed
in "Badfile.txt".

It should be located in C:\WINDOWS\SYSTEM\XXXXX.dll


Note* Please follow instructions carefully, doublecheck before you delete and make sure you have a backup of your registry : HERE's How

Last edited by Unzy : June 20th, 2004 at 10:55 AM.
  #5  
Old April 20th, 2004, 07:04 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

enjoysearch

Responsible entries in a HijackThis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.enjoysearch.info/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.enjoysearch.info

O4 - HKLM\..\Run: [jushed32] C:\WINDOWS\jushed32.exe <- win9x/ME
O4 - HKLM\..\Run: [jushed32] C:\WINDOWS\system32\jushed32.exe <- win2k/XP

Other variants have also been spotted, responsible for the enjoysearch hijack :

O4 - HKLM\..\Run: [xvwiz32] C:\WINNT\system32\xvwizard32.hta
O4 - HKCU\..\Run: [xvwiz32] C:\Documents and Settings\{user's name}\{folder name}\xvwizard32.hta

O4 - HKLM\..\Run: [xxxvid] C:\WINDOWS\system32\xxxvideo.hta
O4 - HKCU\..\Run: [xxxvid] C:\Documents and Settings\{user's name}\{folder name}\xxxvideo.hta

Shredder should take care of this when updated

Log examples :

HERE
HERE
HERE
HERE


Edit by DVK01: main problem with this one is that the O4 entry doesn't show in the HJT log.
The jushed32.exe does show in running processes and once you have stopped it running and deleted it then the O4 appears so it can also be fixed

Last edited by dvk01 : April 20th, 2004 at 09:45 AM.
  #6  
Old April 20th, 2004, 07:06 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

wholeworldmarket (CWS.Systeminit.2)

Responsible entries in a HijackThis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.wholeworldmarket.com/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.wholeworldmarket.com/search/top/

O4 - HKLM\..\Run: [system32.dll] C:\WINDOWS\system\sysdll32.exe

O19 - User stylesheet: C:\WINDOWS\sstyle.css
O19 - User stylesheet: C:\WINDOWS\sstyle.css (HKLM)

Note* : CWShredder tackles this one as of version 1.56.3

Log examples :

HERE
HERE

Last edited by Unzy : April 22nd, 2004 at 04:35 AM.
  #7  
Old April 20th, 2004, 09:39 AM
dvk01's Avatar
dvk01 dvk01 is offline
Global Moderator
 
Join Date: Oct 2003
Location: Loughton, Essex. UK
Posts: 3,099
Default Re: CWS Variants

Freednshost

Responsible entries in a HijackThis log :


R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = hxxp://freednshost.info/page/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://213.159.118.226/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://freednshost.info
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = hxxp://213.159.118.226/sp.php

O4 - HKLM\..\Run: [Network Service] C:\WINDOWS\Help\svchost.exe -sr -0
O4 - HKCU\..\Run: [Network Service] C:\WINDOWS\Help\svchost.exe -sr -0

O8 - Extra context menu item: Debt Solutions - hxxp://213.159.118.226/tools.php?qq=Debt+Solutions
O8 - Extra context menu item: Party Poker - hxxp://213.159.118.226/tools.php?qq=Party+Poker
O8 - Extra context menu item: Party Poker.com - hxxp://213.159.118.226/tools.php?qq=Party+Poker.com

O13 - DefaultPrefix: hxxp://freednshost.info/page/
O13 - WWW Prefix: hxxp://freednshost.info/page/

O19 - User stylesheet: C:\WINDOWS\system32\g02q.l24


Not always shown in a Hijackthis log is a hosts file redirect to various porn sites. Some logs do show this hosts file (/edit Unzy) -> example HERE


Log examples :

HERE
__________________
Derek
My website http://www.thespykiller.co.uk For help with spyware & hijacking

Last edited by Unzy : April 24th, 2004 at 01:23 AM.
  #8  
Old April 22nd, 2004, 04:31 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

e-finder.cc, tadstore.cc and rightfinder.net (CWS.Addclass.2)

Note* : The shredder is updated to deal with this particular variant

Responsible entries in a HijackThis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://homepage.com%00@www.e-finder.cc**/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = hxxp://homepage.com%00@www.e-finder.cc**/search/ (obfuscated)

etc...

(I've put ** in the url to disable it)

O4 - HKCU\..\Run: [AddClass] C:\WINDOWS\AddCLS.exe

O13 - DefaultPrefix: hxxp://%65%68%74%74%70%2E%63%63/?
O13 - WWW Prefix: hxxp://%65%68%74%74%70%2E%63%63/?

Log example : (It's on a dutch forum, but log shows in english with a few dutch words, like : 'links' = 'koppelingen' etc)

HERE
  #9  
Old April 22nd, 2004, 04:47 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

start.chm / MSITStore (MasterSearch)

A new type of CWS variant that uses an exploit to reset a user's homepage.

More info HERE

Responsible entries in a HijackThis log :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html

A workaround for this exploit is provided HERE

There should be an official microsoft patch soon, please keep an eye for updated patches at windowsupdate.com

NOTE* : There is offered a removal tool (remove.exe) on their site which seems legit and does work, however it is believed it creates a GUID (Global Unique IDentifier) which can always 'distinguish' a user, meaning : they can track you down and follow your actions on the net, kinda like WMP.

NOTE 2*: CWShredder removes start.chm and start.html as of version 1.56.3 It does not always cure the Hijack (yet).

Log example :

HERE
HERE

EDIT: It seems that there is normally a file in the temp directory that has something to do with this one as well so also clear out the temp folder
on W2K & XP it will be C:\Documents and Settings\user name \Local Settings\Temp

on 9x/ME systems c:\windows\temp

on XP/W2k select and delete eveything in the folder
on 9x systems select everything except temporary internet files folder and cookies folder


You will need to do the cleaning for every account holder on the computer

Update** :

Shadowwar has come up with a fix for this particular hijack :

Quote:
Please download this to fix the start.chm hijack.

http://tools.zerosrealm.com/startchmfix.exe

Download it. Run it and extract the folder to the desktop preferably.

Open the folder after extracted.

Double click the fix.bat

Please make sure all Internet Explorers are closed.

Only run it once or you will lose the backups although they shouldn't be needed.

Notepad will open at the end with a message and the bad file listing at the end. Ask the user to post the contents of that notepad box.

Last edited by Unzy : May 1st, 2004 at 04:58 AM.
  #10  
Old April 22nd, 2004, 12:53 PM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

runwin32.exe, wininet32.exe (write-up by Pieter Arntz)

Hijacks to a CWS domain (searchmeup, easy-search.biz etc)

Responsible entries in a HijackThis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.searchmeup.com/search.php?aid=1057
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchmeup.com/search.php?aid=1057
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.searchmeup.com/search.php?aid=1057

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080

O4 - HKCU\..\Run: [wininet32] C:\WINDOWS.000\wininet32.exe
O4 - HKCU\..\Run: [runwin32] C:\WINDOWS.000\runwin32.exe

The tricky part here is, that it overides your proxy settings! :

Quote:
After removing the files you have to uncheck the proxy to get your internet connection back.

Note* : The shredder should be updated for this soon

Log example :

HERE

Last edited by Unzy : May 20th, 2004 at 12:20 PM.
  #11  
Old April 23rd, 2004, 11:03 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

OsbornTech Popup Blocker

This is a fake entry created by CWS mainly to try and trick HijackThis analysers to not have fix this entry, so re-infection could be easier or clean-up wouldn't be proper

Responsible entry in a HijackThis log :

O2 - BHO: OsbornTech Popup Blocker - {FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} - C:\WINDOWS\System32\mshelper.dll

(Notice the mshelper.dll to identify it)

Note* : The shredder is updated and should take care of this entry.

Log example :

HERE
HERE

Last edited by Unzy : April 23rd, 2004 at 11:14 AM.
  #12  
Old April 23rd, 2004, 11:13 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

nkvd.us

A classic one that is spreading around now again with some more tricky coding added to it, more specificly the mtwirl.dll / mtwirl32.dll file (use killbox to clean that one up).

Responsible entries in a HijackThis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://nkvd.us/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://nkvd.us/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://nkvd.us/

etc...

O13 - DefaultPrefix: hxxp://www.nkvd.us/
O13 - WWW Prefix: hxxp://www.nkvd.us/
O13 - Home Prefix: hxxp://www.nkvd.us/
O13 - Mosaic Prefix: hxxp://www.nkvd.us/

O19 - User stylesheet: c:\windows\my.css

Fix these entries with HijackThis, restart PC in Safe Mode and manually remove mtwirl.dll / mtwirl32.dll (in system/system32 folder)

Use this registry fix after clean-up :

Quote:
Windows Registry Editor Version 5.00

[-HKEY_CLASSES_ROOT\CLSID\{3F143C3A-1457-6CCA-03A7-7AA 23B61E40F}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{3F143C3A-1457-6CCA-03A7-7AA 23B61E40F}"=-

Log examples :

HERE
HERE

Last edited by Unzy : May 2nd, 2004 at 01:35 PM.
  #13  
Old April 23rd, 2004, 07:10 PM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

msole.dll

Hijacks to a CWSdomain (R0 and R1 entries in a HijackThis log), using a 02 BHO

Responsible entries in a HijackThis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.payfortraffic.net**/search.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.payfortraffic.net**/mainsearch.htm

(added ** to disable URL)

O2 - BHO: (no name) - {98DBBF16-CA43-4c33-BE80-99E6694468A4} - C:\WINDOWS\System32\msole.dll

Log example :

HERE
  #14  
Old April 27th, 2004, 06:44 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

searchpage.html

Another variant that has been spotted which looks like a combo of nkvd.us and master-search.

Responsible entries in a HijackThis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = c:\searchpage.html#1504
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\searchpage.html#1504
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\searchpage.html#1504
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = c:\searchpage.html#1504
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = c:\searchpage.html#1504

etc...

O13 - DefaultPrefix: c:\searchpage.html?page=
O13 - WWW Prefix: c:\searchpage.html?page=
O13 - Home Prefix: c:\searchpage.html?page=
O13 - Mosaic Prefix: c:\searchpage.html?page=

Those are the only visible entries in that log.

Still awaiting how shredder deals with this and for more info about the possible culprit of this hijack (dll).

Update* :

The fake OsbornTech has been spotted with this one as well :

O2 - BHO: OsbornTech Popup Blocker - {FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} - C:\WINDOWS\System32\mshelper.dll

Log examples :

HERE
HERE

Last edited by Unzy : May 1st, 2004 at 05:08 AM.
  #15  
Old April 30th, 2004, 05:33 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

CHP.DLL

Symptoms :

-Explorer has caused an error in CHP.DLL, which causes Internet Explorer to crash. (Thnx to bad coding probably )

-Messes with Windows media Player (WMP) (not working properly anymore)

Stripping the UPX packed file revealed the following link : lookingfor.cc/search.php, which is a cws domain

Removal :

Unregister the dll

Visible entries in a HijackThis log :

None

Update* : It's not a random named dll, other people were experiencing the error message as well refering to this dll. Most likely a result of bad coding from one of the variants.

Log Example :

HERE

Last edited by Unzy : May 10th, 2004 at 04:52 AM.
  #16  
Old May 12th, 2004, 05:32 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

IEengine.exe (hijacks to a CWS domain)

Drops the exe in the Internet Explorer folder in Program Files to make it look as legit as possible

Responsible entries in a Hijackthis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://your-searcher.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://your-searcher.com/index.htm

etc.

O4 - HKCU\..\Run: [IEengine] C:\Program Files\Internet Explorer\IEengine.exe

*Shredder should be updated soon for this

For those who are interested, a disassembly report after unpacking the exe(done by Mo) can be downloaded HERE

Log example :

HERE

Also spotted with (not always present though):

O4 - Global Startup: winlogin.exe

CWShredder normally finds and deletes those 2 in XP/W2K but it needs manually fixing in ME/9X

Last edited by Unzy : June 1st, 2004 at 04:42 AM.
  #17  
Old May 15th, 2004, 05:28 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re: CWS Variants

mrhop.dll

Although it looks very similar to the variant described in post 4, it works differently.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {33B13F77-E06C-4C6F-B347-EBF7CE2BC08F} - C:\WINDOWS\mrhop.dll

Download and install APM from: http://www.diamondcs.com.au/index.php?page=apm
In the upper window select explorer.exe
In the lower window find and rightclick mrhop.dll
Select Unload DLL and click OK on the prompts that follow.

Close all windows except HijackThis and fix the lines above.
Reboot and scan with AdAware.
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.

Last edited by Unzy : May 19th, 2004 at 12:57 AM.
  #18  
Old May 19th, 2004, 12:54 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

system32.dll (jksearch.biz , greatsearch.biz)


Responsible entries in a Hijackthis log :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://jksearch.biz/redir.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://jksearch.biz/redir.php

etc.

*NOTE :


As of HijackThis version 1.98.1 a line similar to this will show:
O21 - SSODL: System - {1F0B125B-7C1F-4B45-BAE9-20FEEF841480} - C:\WINDOWS\system32\system32.dll
Fixing that will have the same effect as the first line in the clear.reg fix.


c:\windows\system32\system32.dll (win2k / XP)
c:\windows\system\system32.dll (win9x / ME)

Do watch out for other 04 entries related to CWS

Quote:
Originally Posted by Shadowwar

Copy the contents of the quote box to notepad:

Quote:


REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"System"=-
[-HKEY_CLASSES_ROOT\CLSID\{061646A1-DC57-487D-B023-A938198C174E}]
[-HKEY_CLASSES_ROOT\CLSID\{4E8A9E72-8942-40EF-88DF-A559152F6B41}]
[-HKEY_CLASSES_ROOT\CLSID\{6E94CEC3-0C84-4310-AE20-CD4090178388}]


hit 'save as'
give it the name 'clear.reg'
under the filename set file types to all files.
save it to the desktop.

After done double click the clear.reg
when asked to merge say yes

then find this file:
system32.dll
its probably in one of two locations:
c:\windows\system32\system32.dll
c:\windows\system\system32.dll
and delete it.

Also does the following things! :

1. it drops a hosts file blocking all competitor cws sites.

2. It attacks the updater modules for Antivirus. Please check to make sure the users's Antivirus updates still work.


*NOTE 2 :

We are still waiting if this one uses random CLSID tags (for CWShredder), it looks like it uses random

*NOTE 3 Regfile available as attached txt file: http://www.wilderssecurity.com/attac...hmentid=137126

Log example :

HERE
HERE

Last edited by Pieter_Arntz : August 6th, 2004 at 07:48 AM. Reason: updated by Pieter for new version HijackThis
  #19  
Old May 19th, 2004, 03:56 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re: CWS Variants

CWS related BHO's : (please edit in all cws related BHO's here)

O1 - Hosts: 213.159.117.235 auto.search.msn.com
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000001} - C:\WINNT\System32\msxmlfilt.dll

Also seen, but only once sofar:
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\msxslab.dll

Log example: here

Quote:
Also seen, but only once sofar:
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\msxslab.dll

I've seen it as well Pieter, looks like they are not random

Accompanied with these :

O1 - Hosts: 213.159.117.235 auto.search.msn.com
O2 - BHO: (no name) - {12D02C08-218F-4A11-BDE1-6611ADB7B81F} - C:\WINDOWS\SYS32_~1.DLL

Log example : here
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.

Last edited by Unzy : May 24th, 2004 at 04:55 AM.
  #20  
Old May 26th, 2004, 02:48 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re: CWS Variants

dpe.dll

A new BHO

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%00@www.e-finder.cc/hp/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%00@www.e-finder.cc/hp/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
O2 - BHO: (no name) - {834261E1-DD97-4177-853B-C907E5D5BD6E} - C:\WINNT\dpe.dll
O13 - DefaultPrefix: www
O13 - WWW Prefix:

dpe.dll also comes in these shapes:

O2 - BHO: DOMP Class - {4C1B116F-2860-46db-8E6C-B4BFC4DFD683} - C:\WINDOWS\ietlbass.dll

O2 - BHO: DOMP Class - {4C1B116F-2860-46db-8E6C-B4BFC4DFD683} - C:\IETLBASS32.DLL

CLSID is fixed, original filename is dpe.dll

Log example :

Here
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.

Last edited by Pieter_Arntz : December 25th, 2004 at 06:15 AM. Reason: Added new filenames
  #21  
Old May 27th, 2004, 07:08 PM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

{root dir}:/spad/start.html | myexexex.com

Responsible entries in a HijackThis log :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.myexexex.com/search.php?said=spage&qq=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/spad/start.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.myexexex.com/search.php?said=spage
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/spad/start.html

etc.

Culprit dll :

HPCMDTY.DLL

Most likely in :

C:\WINNT\system32\HPCMDTY.DLL (win2k/xp)
C:\windows\system (win9x/me)

Also been spotted in the temp folder, so watch out for that as well!

C:\DOCUME~1\.....\LOCAL~1\Temp\HPCMDTY.DLL

Fix the entries in HijackThis log (R0 and R1)

Restart PC in Safe mode and remove :

c:/spad/ <- this folder

HPCMDTY.DLL <- this dll

Also do additional search for this file, and remove if present :

c_10230.dll

On win2k / XP systems dropped in the system32 folder!

Use this reg file:


REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B}]
[-HKEY_CLASSES_ROOT\CLSID\{BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B}]
[-HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{237AA178-C3BC-4f67-A8BB-D8BC14BA0B89}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{237AA178-C3BC-4f67-A8BB-D8BC14BA0B89}]
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\{237AA178-C3BC-4f67-A8BB-D8BC14BA0B89}]



Save it in notepad, save it as spad.reg and doubleclick it.
Confirm to merge with the registry.
You can also download this file and rename it to spad.reg

Log examples :

Here

Last edited by Unzy : May 30th, 2004 at 04:05 AM. Reason: Added regfile information
  #22  
Old June 3rd, 2004, 09:35 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re: CWS Variants

sysstartup.exe (hijacks to a cwsdomain)

-drops sysstartup.exe in the system/system32 folder

-accompanied with a randomly named BHO dll but STATIC clsid! :

{A9A674BF-771F-42E5-A440-D20DDA85A862}

-hijacks startpage

-can be spotted with a 016 entry

Responsible entries in a hijackthis log :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9

O2 - BHO: (no name) - {A9A674BF-771F-42E5-A440-D20DDA85A862} - C:\WINDOWS\System32\uubztmiy7mnslh.dll

O4 - HKLM\..\Run: [jopa] C:\WINDOWS\System32\sysstartup.exe
O4 - HKCU\..\Run: [jopa] C:\WINDOWS\System32\sysstartup.exe

Log examples :

Here
Here
  #23  
Old June 9th, 2004, 03:25 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re: CWS Variants

Some BHO's that deliver pornographic content are presumed to be exploited by the CWS crew.

O2 - BHO: ie - {2FF5573C-0EB5-43db-A1B2-C4326813468E} - c:\windows\iehr.dll

O2 - BHO: sr - {FC2593E3-3E5A-410F-AF3D-82613CCE58E5} - C:\WINDOWS.000\SR.DLL

LOG examples
HERE
HERE
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #24  
Old June 15th, 2004, 02:48 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re: CWS Variants

Protocol hijack

Shows in log as:

O1 - Hosts: 213.159.117.235 auto.search.msn.com

O18 - Protocol hijack: about - {53B95211-7D77-11D2-9F81-00104B107C96}

Related file:

MSXSLAB.DLL

Example log: HERE
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #25  
Old June 15th, 2004, 02:51 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re: CWS Variants

This one is pretty straightforward as far as I can tell:

Shows in log as:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.find-online.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.find-online.net/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.find-online.net/index.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.find-online.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.find-online.net/index.htm

O4 - HKCU\..\Run: [ziphelp] C:\WINDOWS\ziphelp.exe

Log example: HERE
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
 

Wilders Security Forums > Browser Hijacks and Spyware Problems > news, general information and FAQs « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:05 AM.


Powered by vBulletinŪ Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Đ2002 - 2010, Wilders Security Forums