BeverlyL
Topic Starter
I've been trying to clean up a spyware infestation on my dad's Win98 laptop. He noticed the popups starting a couple of weeks ago. Here's a Hijack This log, what I've done so far, and what I'm now seeing and questioning. Any help or guidance will be greatly appreciated, as I'm stumped!
Logfile of HijackThis v1.99.1
Scan saved at 1:42:01 PM, on 6/19/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HJT\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = gopher=LocalHost:1
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.yahoo.com"); (C:\Program Files\Netscape\Users\edjulia2\prefs.js)
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\RunServices: [MSNIA] C:\PROGRA~1\MSN\MSNIA\MSNIASVC.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKLM\..\RunServices: [ccProxy] c:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Dell Home - {6D6C5880-398F-11D3-9068-006008F53D0D} - http://www.dell.com/ (file missing) (HKCU)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
The popups start trying to appear right after I start up the system, even before establishing an internet connection (receiving dialog box about no internet connection, asking to work offline or try again - I'm just closing the dialog). I'll have this dialog pop up periodically if I continue without an internet connection. And once I do establish a connection the pop-ups start appearing, usually starting off with www.loadingwebsite.com then progressing to ads2.revenue.net and others.
I've run both AdAware SE and Spybot Search & Destroy with updated definitions in safe mode and let them clean up what they found. Both are now not showing me any further problems, but I'm still getting popups. Between the 2 of them they identified NikTech Networks.Zestyfind (and its desktop shortcuts), Alexa, ClearSearchNet, HuntBar and VX2/Virtual Bouncer. I ran AdAware's VX2 Cleaner add-in and it came up clean. I also went on my own search and destroy mission, finding and (hopefully) removing WToolsA, EliteToolBar, and the Yahoo Toolbar just based on my knowledge of what shouldn't have been on the system and what I was seeing installed.
I ran a full virus scan with Norton. No problems found. TrendMicro's Housecall also didn't find any problems. And I've installed the latest Win 98 and IE 6 SP1 updates.
I'm currently seeing the following files on the computer that I'm suspicious of.
C:\exStub.exe (file properties indicate it's from BundlewareWO)
C:\InstallEx.exe
C:\Windows\Temporary Internet Files\…\pcs_0026[1].exe
And I've got a whole host of files whose properties indicate they're coming from NicTech Technologies. The following are the executables I've noted:
C:\Windows\icont.exe (SpyBot had removed an iconu.exe - I'm guessing they're related)
C:\Windows\Temp\bw2.com
C:\Windows\Temp\upd204.exe
C:\Windows\Temporary Internet Files\…\upd204[1].exe
C:\Windows\Temporary Internet Files\…\AppWrap[1].exe (many copies of this one in different folders under Temporary Internet Files)
C:\Windows\System\UpdInst.exe (assuming it's from NicTech since it has the same date/time stamp as the dll's discussed below)
I've also got a set of dll's in C:\Windows\System from NicTech. All have the same date/time stamp and file size (222 kb). The names of the files vary. I have found that one of the set appears to be the "ringleader" in that it has entries in the registry and the file itself can't be deleted, even when running in safe mode. Yesterday I tried removing the registry keys associated with the dll in safe mode. It looked like they removed fine. Then I attempted to delete the dll but couldn't because it was in use. I booted to safe mode with just a command prompt, hoping to delete it there, but could not see the file at all in C:\Windows\System. And the next time I booted in normal mode, the registry keys for the file were back. Today it appears that the files have morphed into another set, I'm sure as a result of my actions trying to get rid of them. Today I've got a different dll that has the registry keys. And the file that appeared to be in control yesterday had nothing in the registry today, plus I was able to delete it. Something appears to be controlling generation of these files and firing one of them up, but I can't figure out what the source is or how I can stop it.
Many thanks in advance for any help.
Beverly
Logfile of HijackThis v1.99.1
Scan saved at 1:42:01 PM, on 6/19/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HJT\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = gopher=LocalHost:1
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.yahoo.com"); (C:\Program Files\Netscape\Users\edjulia2\prefs.js)
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\RunServices: [MSNIA] C:\PROGRA~1\MSN\MSNIA\MSNIASVC.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKLM\..\RunServices: [ccProxy] c:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Dell Home - {6D6C5880-398F-11D3-9068-006008F53D0D} - http://www.dell.com/ (file missing) (HKCU)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
The popups start trying to appear right after I start up the system, even before establishing an internet connection (receiving dialog box about no internet connection, asking to work offline or try again - I'm just closing the dialog). I'll have this dialog pop up periodically if I continue without an internet connection. And once I do establish a connection the pop-ups start appearing, usually starting off with www.loadingwebsite.com then progressing to ads2.revenue.net and others.
I've run both AdAware SE and Spybot Search & Destroy with updated definitions in safe mode and let them clean up what they found. Both are now not showing me any further problems, but I'm still getting popups. Between the 2 of them they identified NikTech Networks.Zestyfind (and its desktop shortcuts), Alexa, ClearSearchNet, HuntBar and VX2/Virtual Bouncer. I ran AdAware's VX2 Cleaner add-in and it came up clean. I also went on my own search and destroy mission, finding and (hopefully) removing WToolsA, EliteToolBar, and the Yahoo Toolbar just based on my knowledge of what shouldn't have been on the system and what I was seeing installed.
I ran a full virus scan with Norton. No problems found. TrendMicro's Housecall also didn't find any problems. And I've installed the latest Win 98 and IE 6 SP1 updates.
I'm currently seeing the following files on the computer that I'm suspicious of.
C:\exStub.exe (file properties indicate it's from BundlewareWO)
C:\InstallEx.exe
C:\Windows\Temporary Internet Files\…\pcs_0026[1].exe
And I've got a whole host of files whose properties indicate they're coming from NicTech Technologies. The following are the executables I've noted:
C:\Windows\icont.exe (SpyBot had removed an iconu.exe - I'm guessing they're related)
C:\Windows\Temp\bw2.com
C:\Windows\Temp\upd204.exe
C:\Windows\Temporary Internet Files\…\upd204[1].exe
C:\Windows\Temporary Internet Files\…\AppWrap[1].exe (many copies of this one in different folders under Temporary Internet Files)
C:\Windows\System\UpdInst.exe (assuming it's from NicTech since it has the same date/time stamp as the dll's discussed below)
I've also got a set of dll's in C:\Windows\System from NicTech. All have the same date/time stamp and file size (222 kb). The names of the files vary. I have found that one of the set appears to be the "ringleader" in that it has entries in the registry and the file itself can't be deleted, even when running in safe mode. Yesterday I tried removing the registry keys associated with the dll in safe mode. It looked like they removed fine. Then I attempted to delete the dll but couldn't because it was in use. I booted to safe mode with just a command prompt, hoping to delete it there, but could not see the file at all in C:\Windows\System. And the next time I booted in normal mode, the registry keys for the file were back. Today it appears that the files have morphed into another set, I'm sure as a result of my actions trying to get rid of them. Today I've got a different dll that has the registry keys. And the file that appeared to be in control yesterday had nothing in the registry today, plus I was able to delete it. Something appears to be controlling generation of these files and firing one of them up, but I can't figure out what the source is or how I can stop it.
Many thanks in advance for any help.
Beverly