This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Recurring Hijacks, Please See Log

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I have run spybot, cwshredder, no luck, and we keep getting hijacked! Really do not know what to do, any help would be most welcome. Bonu. Logfile of HijackThis v1.98.2 Scan saved at 8:01:26 PM, on 10/1/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\scagent.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2 - BHO: (no name) - {9ED34910-F937-47EC-B66F-D27884129962} - C:\WINDOWS\system32\jilha.dll O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winmik32.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\httpfilter.dll O18 - Filter: text/plain - {68F92345-0F97-4124-A7B4-511348C006B5} - C:\WINDOWS\system32\jilha.dll
Welcome to the forum.

Could you please do this for me:


Step #1

This variant of CWS often installs a hidden dll file which causes the infection to reinstalled every time you Restart the computer.

1. Please download DllCompare

http://download.broadbandmedic.com/DllCompare.exe

2. Start the Program with its default settings and put a check mark in the include subdirectories. Click the Run Locate.com and wait until the scan says complete.

3. Click the Compare button to start the next process.

4. Files in the upper portion have been verified to "exist", Files in the bottom section were not able to be accessed. Very few files should be listed in the bottom section when the Compare scan is complete.

5. Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan.

6. This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files)

7. Click the Make a Log of what was found button, and post the log here in this thread using Add Reply to receive further instructions.

MrC
Hi Mr. Charlie, Here is the log from the dll compare, when I right clicked and rescanned the bottom entry, it said zero items found and this log was posted on my desktop, Thankyou very much, Bonu. * DLLCompare Log version(1.0.0.125) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\WINDOWS\SYSTEM32\wdmmhjp.dll Fri Jun 11 2004 7:05:28p A…R 57,344 56.00 K ________________________________________________ 1,530 items found: 1,530 files, 0 directories. Total of file sizes: 341,472,317 bytes 325.65 M Administrator Account = True ——————–End log———————
Thankyou Mr Charlie :wub:


Step #2

1. Click here to download and install Registrar Lite. Install, run, copy and paste this line to reglite's address bar:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

2. Click the "go" tab. Find the: "Appinit_Dlls" key in the right hand pane and and double click to find the "Value" data. Confirm that C:\WINDOWS\SYSTEM32\wdmmhjp.dll appears in the 'Value' field.

3. Using Windows Explorer, go to your root drive: C:\ and create a new folder called 'Hijack' and within that folder, create two new folders, one called 'Backups' and one called 'Junk'.

4. Use the Registrar Lite program. Copy and paste the key below into reglite's address bar and click 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\


5. Click on the Windows key to highlight it in purple, and use the top menu File>Export and save as (in the C:\Hijack\Backups folder):

1) Winkey.reg (Save as type: regedit4 .reg type)
2) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)


6. Navigate to C:\Hijack\Backups and confirm both files have been successfully saved.

7. Use the Registrar Lite program again. Copy and paste the key below into reglite's address bar and hit 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

8. Right-click on the Windows key in the left pane and rename it to notwindows. Then double-click "Appinit_Dlls" value in right pane and erase the data in the 'Value' box at the bottom of the new pane.

The data to remove will be:

"C:\WINDOWS\System32\wdmmhjp.dll", hit 'Apply' and 'Ok' to set.


9. Rename 'NotWindows' back to 'Windows' in the left pane

10. close Registrar Lite and reboot the computer. If everything works the hidden process will not run at startup and you should now be able to find and *see* the wdmmhjp.dll in

C:\WINDOWS\System32.

11. Unzip and run Winfile from Winfile.zip. Open it up, click File > Move

12. Copy and paste this into the 'From' box:

C:\WINDOWS\system32\wdmmhjp.exe


13.Copy and paste this into the 'To' box:

C:\Hijack\Junk\wdmmhjp.exe


14. Click OK. Close Winfile and check in C:\Hijack\Junk for that file and report back the contents of the junk folder.
Hi, Everything went smoothly till instruction 11 on your list. When I click on Winfile.zip, it doesn't open and says "You are not authorized to view this page". I was able to view wdmmhjp.exe in the system 32 folder, though which was great, Thanks, Bonu.
Hi again, Can I get winfile from some other source to complete your instructions? I was looking for it on the web and it seemed a possibility. Thanks, Bonu
Hi, Got Winfile to open following your tip. Tried Winfile but it said it was unable to find the file C:\WINDOWS\system32\wdmmhjp.exe to move to the junk folder. What I do see in system32 is the file with a dll extension, does that make a difference? Thank you, Bonu.
Step #3

You have made changes to your Registry with Regedit/RegLite and the security permissions have been lowered when you renamed the Windows Key folder.

To repair the security permissions please do the following:

1)Please navigate to C:\Hijack\Backups and double click on the winkey.reg file and merge the information into the registry.

2)Now open Regedit/RegLite and go to File > import Winkey.hiv into the registry.

3)Copy and Paste the following bold text into the address bar of Reglite (navigate to this location with Regedit)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

4)Delete the entry in the AppInit_DLLs Value key which will look like: C:\Windows\System32]wdmmhjp.dll and then close Regedit/RegLite. (the file no longer exists at that location so the registry entry is an orphan entry)


Step #4

Please Download the most recent version of CWShredder, from CWShredder.exe Download into it's own folder.Check for Updates, then run and fix anything that it finds.


Step #5


1. CLOSE ALL WINDOWS (even this one) AND PROGRAMS

2. Run Hijack This! and put a check mark beside the following entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {9ED34910-F937-47EC-B66F-D27884129962} - C:\WINDOWS\system32\jilha.dll

O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winmik32.exe

O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\httpfilter.dll
O18 - Filter: text/plain - {68F92345-0F97-4124-A7B4-511348C006B5} - C:\WINDOWS\system32\jilha.dll

3. Click fix checked

4. Delete the following files:

C:\windows\system32\winmik32.exe
C:\WINDOWS\system32\jilha.dll

5. Reboot and post a new log file.



Step #6

Please run disk cleanup and delete your Temp and Temporary Internet Files and Empty your Recycle Bin.

Please also reset System Restore to remove the backed up infected files.

Also make certain you check through your Internet Explorer Favorites to remove the links that were added by the malware.


Once you are completely clean, please delete the C:\Hijack\junk folder.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI