hijacked browser and pop ups

Discussion in 'adware, spyware & hijack cleaning' started by parrothead, Jun 22, 2004.

Thread Status:
Not open for further replies.
  1. parrothead

    parrothead Registered Member

    Joined:
    Jun 21, 2004
    Posts:
    4
    Hey folks,
    My browser keeps getting hijacked and sometimes I can not get into Yahoo or google. Pop ups keep poping up out of no where. I am using hijackthis, cwshredder and xoftspy software. Here is my log...

    Logfile of HijackThis v1.97.7
    Scan saved at 8:29:50 AM, on 6/22/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
    C:\Program Files\Turtle Beach\AudioStation\tbaspi.exe
    C:\WINDOWS\system32\winbh.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\ntoe32.exe
    C:\PROGRA~1\EFFICI~1\TANGOM~1\app\TangoManager.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Owner\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dnevo.dll/sp.html#37049
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dnevo.dll/index.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dnevo.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dnevo.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dnevo.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\dnevo.dll/sp.html#37049
    O2 - BHO: (no name) - {30602B86-1675-1F6A-ED04-04EB4B03BE0A} - C:\WINDOWS\system32\iepx32.dll
    O4 - HKLM\..\Run: [ntoe32.exe] C:\WINDOWS\system32\ntoe32.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DD634154-0349-46B4-B6A3-26B42EA2A270}: NameServer = 166.102.165.11 166.102.165.13
     
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,331
    Location:
    Netherlands
    Hi parrothead,

    Click Start > Run > Services.msc > OK
    In the services window find Network Security Service.
    Rightclick and stop it. Put the Startup type to disabled under Properties > General tab

    Then open TaskManager and stop these two processes:
    C:\WINDOWS\system32\winbh.exe
    C:\WINDOWS\system32\ntoe32.exe

    Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dnevo.dll/sp.html#37049
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dnevo.dll/index.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dnevo.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dnevo.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dnevo.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\dnevo.dll/sp.html#37049
    O2 - BHO: (no name) - {30602B86-1675-1F6A-ED04-04EB4B03BE0A} - C:\WINDOWS\system32\iepx32.dll
    O4 - HKLM\..\Run: [ntoe32.exe] C:\WINDOWS\system32\ntoe32.exe

    Then reboot into safe mode and delete:
    C:\WINDOWS\system32\winbh.exe
    C:\WINDOWS\system32\ntoe32.exe
    C:\WINDOWS\system32\iepx32.dat
    C:\WINDOWS\dnevo.dll

    Read this post for additional instructions:
    https://www.wilderssecurity.com/showpost.php?p=198412&postcount=26

    Regards,

    Pieter
     
  3. parrothead

    parrothead Registered Member

    Joined:
    Jun 21, 2004
    Posts:
    4
    Got everything done except could not find file C:windows\system32\iepx32.dll

    Rebooted and I guess got reinfected. Here is my new file.

    Logfile of HijackThis v1.97.7
    Scan saved at 10:41:27 AM, on 6/22/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
    C:\Program Files\Turtle Beach\AudioStation\tbaspi.exe
    C:\WINDOWS\system32\iepb.exe
    C:\WINDOWS\system32\addpm.exe
    C:\PROGRA~1\EFFICI~1\TANGOM~1\app\TangoManager.exe
    C:\Documents and Settings\Owner\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jvino.dll/sp.html#37049
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://jvino.dll/index.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://jvino.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jvino.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://jvino.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jvino.dll/sp.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {74EE63C1-C2F6-8F52-938B-84D9F1EAC423} - C:\WINDOWS\system32\addpm.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [ScriptSentry] C:\Program Files\Script Sentry\ScriptSentry.exe /check
    O4 - HKLM\..\Run: [addpm.exe] C:\WINDOWS\system32\addpm.exe
    O4 - HKLM\..\RunOnce: [iepb.exe] C:\WINDOWS\system32\iepb.exe
    O4 - HKLM\..\RunOnce: [netuj32.exe] C:\WINDOWS\netuj32.exe
    O4 - HKLM\..\RunOnce: [crra.exe] C:\WINDOWS\crra.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DD634154-0349-46B4-B6A3-26B42EA2A270}: NameServer = 166.102.165.11 166.102.165.13
     
  4. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,331
    Location:
    Netherlands
    The darn thing change names every so often. :(

    Check if the Service is still disabled.

    Then open TaskManager and stop these two processes:
    C:\WINDOWS\system32\iepb.exe
    C:\WINDOWS\system32\addpm.exe

    Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jvino.dll/sp.html#37049
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://jvino.dll/index.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://jvino.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jvino.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://jvino.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jvino.dll/sp.html#37049

    O2 - BHO: (no name) - {74EE63C1-C2F6-8F52-938B-84D9F1EAC423} - C:\WINDOWS\system32\addpm.dll

    O4 - HKLM\..\Run: [addpm.exe] C:\WINDOWS\system32\addpm.exe
    O4 - HKLM\..\RunOnce: [iepb.exe] C:\WINDOWS\system32\iepb.exe
    O4 - HKLM\..\RunOnce: [netuj32.exe] C:\WINDOWS\netuj32.exe
    O4 - HKLM\..\RunOnce: [crra.exe] C:\WINDOWS\crra.exe

    Then reboot into safe mode and delete:
    C:\WINDOWS\system32\iepb.exe
    C:\WINDOWS\system32\addpm.exe
    C:\WINDOWS\system32\jvino.dll
    C:\WINDOWS\system32\addpm.dat

    Regards,

    Pieter
     
  5. parrothead

    parrothead Registered Member

    Joined:
    Jun 21, 2004
    Posts:
    4
    will do Peter and thanks for all you do.....
     
  6. parrothead

    parrothead Registered Member

    Joined:
    Jun 21, 2004
    Posts:
    4
    pieter,
    Looks like this one is gone. Thanks a million. Here is my log file just in case.
    Anything else I need to do?

    Logfile of HijackThis v1.97.7
    Scan saved at 11:57:13 AM, on 6/22/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
    C:\Program Files\Turtle Beach\AudioStation\tbaspi.exe
    C:\PROGRA~1\EFFICI~1\TANGOM~1\app\TangoManager.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\Owner\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [ScriptSentry] C:\Program Files\Script Sentry\ScriptSentry.exe /check
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DD634154-0349-46B4-B6A3-26B42EA2A270}: NameServer = 166.102.165.11 166.102.165.13
     
Thread Status:
Not open for further replies.