This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

6810180.net Removal

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I am experiencing problems much the same as posted at http://www.forums.tomcoyote.org/index.php?showtopic=13362 and http://www.forums.tomcoyote.org/index.php?showtopic=13802 .

Have followed the instructions given and removed various trojans. However, I am unable to find the .exe. files mentioned, even with the hidden files visible.

The hijackthis report is below:

Logfile of HijackThis v1.98.2
Scan saved at 12:23:30, on 12/08/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Nortel Networks\Shared Files\NTSPInit.exe
E:\ITSupport\Adaware\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SDWin32 Class - {5159C6FF-3CDD-4079-86DB-98A17B020BC3} - C:\WINDOWS\System32\binrr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [binrrc] C:\WINDOWS\System32\binrrc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: TSP Launcher.lnk = C:\Program Files\Nortel Networks\Shared Files\NTSPInit.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = charitypeople.co.uk
O17 - HKLM\Software\..\Telephony: DomainName = charitypeople.co.uk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = charitypeople.co.uk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = charitypeople.co.uk


:scratch:

Thanks,

Danny
Greetings and welcome to TomCoyote.com!

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This! and fix these items:

O2 - BHO: SDWin32 Class - {5159C6FF-3CDD-4079-86DB-98A17B020BC3} - C:\WINDOWS\System32\binrr.dll

O4 - HKLM\..\Run: [binrrc] C:\WINDOWS\System32\binrrc.exe


Reboot in "safe" mode. Use the link in my signature to tell you how if necessary.

Find and delete:

C:\WINDOWS\System32\binrr.dll <— file

C:\WINDOWS\System32\binrrc.exe <— file

Some malware files may be "hidden". Use the link in my signature to explain how to show "hidden" files if necessary.

Reboot in normal mode and post a new log file. :)

Greetings and welcome to TomCoyote.com!

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This! and fix these items:

O2 - BHO: SDWin32 Class - {5159C6FF-3CDD-4079-86DB-98A17B020BC3} - C:\WINDOWS\System32\binrr.dll

O4 - HKLM\..\Run: [binrrc] C:\WINDOWS\System32\binrrc.exe


Reboot in "safe" mode. Use the link in my signature to tell you how if necessary.

Find and delete:

C:\WINDOWS\System32\binrr.dll <— file

C:\WINDOWS\System32\binrrc.exe <— file

Some malware files may be "hidden". Use the link in my signature to explain how to show "hidden" files if necessary.

Reboot in normal mode and post a new log file. :)

Thank you Micah,

I have run Hijackthis and deleted the entries. I have also deleted binrrc.exe in safe mode. Though I couldn't find binrr.dll.

The problem is still occurring.

The hijackthis log is below.

Logfile of HijackThis v1.98.2
Scan saved at 17:56:02, on 16/08/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Nortel Networks\Shared Files\NTSPInit.exe
C:\WINDOWS\System32\wuauclt.exe
E:\ITSupport\Adaware\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: TSP Launcher.lnk = C:\Program Files\Nortel Networks\Shared Files\NTSPInit.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = charitypeople.co.uk
O17 - HKLM\Software\..\Telephony: DomainName = charitypeople.co.uk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = charitypeople.co.uk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = charitypeople.co.uk




Cheers,

Danny
I am unable to locate any malware in your last log file. Are the problems you are experiencing exactly the same as before any of the fixes? Can you describe the pop-ups? What do they advertise? What site do they try to take you to? :unsure:
Thanks Micah, The malware has now gone and the 6180180.net popups have stopped. I think the mistake I made was to leave the binrr.exe in the deleted items folder where it was still able to retrieve websites. I had actually previously deleted the binrr.dll which was also in the deleted items folder (must have already suspected it). There were also some binrr xml files, which I also deleted. This has been a great resource and source of information for getting rid of malware. I will definitely be recommending it to anyone who has similar problems. I will also make a dontation. Best wishes, Danny :D
Okie dokie!!!

Thank you very much for any donations made to this site, and any future referrals.

I am thankful we were able to help. :thumbup:

I will leave you with my list of things to consider to help prevent future infections.

GOD bless!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?" here:

http://boards.cexx.org/viewtopic.php?t=957

Download IE-Spyad here:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings here:

http://browsercheck.qualys.com/index.php

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI