Logfile of HijackThis v1.99.1
Scan saved at 4:26:58 PM, on 2/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
A potentially dangerous Request.QueryString value was detected from the client (p1="…l'pYo'C-:(
Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case.
Exception Details: System.Web.HttpRequestValidationException: A potentially dangerous Request.QueryString value was detected from the client (p1="…l'pYo'C-:(
Source Error:
An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.
Stack Trace:
[HttpRequestValidationException (0x80004005): A potentially dangerous Request.QueryString value was detected from the client (p1="…l'pYo'C-:(
System.Web.HttpRequest.ValidateString(String s, String valueName, String collectionName) +230
System.Web.HttpRequest.ValidateNameValueCollection(NameValueCollection nvc, String collectionName) +99
System.Web.HttpRequest.get_QueryString() +122
System.Web.UI.Page.GetCollectionBasedOnMethod() +85
System.Web.UI.Page.DeterminePostBackMode() +47
System.Web.UI.Page.ProcessRequestMain() +2106
System.Web.UI.Page.ProcessRequest() +218
System.Web.UI.Page.ProcessRequest(HttpContext context) +18
System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute() +179
System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously) +87
Version Information: Microsoft .NET Framework Version:1.1.4322.573; ASP.NET Version:1.1.4322.573
Download Ewido Security Suite it is a trial version of the program.
Install ewido security suite
Launch ewido, there should be an icon on your desktop double-click it.
The program will now go to the main screen
You will need to update ewido to the latest definition files.
On the left hand side of the main screen click update
Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido. Ewido manual updates
Once the updates are installed do the following:
Click on scanner
Click on Complete System Scan and the scan will begin.
During some scans with ewido it is finding cases of false positives.
You will need to step through the process of cleaning files one-by-one.
If ewido detects a file you KNOW to be legitimate, select none as the action.
DO NOT select "Perform action on all infections"
If you are unsure of any entry found select none for now.
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
Click Save report.
Save the report .txt file to your desktop.
Now close ewido security suite and post the results here.
I downloaded the Ewido and it found 1 infected file called mozilla something or other. I remembered it from my spybot S&D program so I cleaned it. I'm attaching the saved report. Why didn't my spybot pick it up though? Nor my beta or spysweeper? Should I run another hijack this because when I rebooted after loading ewido, my spysweeper came up saying my home page had been hijacked? Meanwhile, I'll try my banking rewards page again to see if the error is still coming up. Thanks for this program too.
———————————————————
ewido anti-malware - Scan report
———————————————————
+ Created on: 10:45:02 PM, 2/14/2006
+ Report-Checksum: BD60C8F5
+ Scan result:
:mozilla.7:C:\Documents and Settings\FELISCHA\Application Data\Mozilla\Profiles\default\71m102ki.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
::Report End
Still getting the same error message as before. Ran spybot and it found coolwwwsearch.dreplace but was unable to fix it. Said it was unable to find start page. This is exactly what it looked like:
CoolWWWSearch.Dreplace: IE start page (Registrychange, nothing done)
HKEY_USERSS-1-5-21-558522827-163748893-4247568029-1006\Software\Microsoft\Internet Explorer\Main\Start Page=about:blank
Also, my microsoft antispyware beta 1 has two of its agents in-active and I'm unable to activate them. It runs with 3 agents and now there's only 1. Spysweeper found nothing nor did beta 1. Thanks for all your help.
Please download and run CWShredder here
Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.
We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine.
Detailed instructions from here
Downloaded and ran cwshredder in both safe mode and normal mode but it didn't find anything. So I reran my spybot S&D and it didn't find it again either. My spysweeper might have taken care of it because when I turned on the computer, a warning message from spysweeper popped up saying my IE settings and browser had been hijacked do I want to repair the problem? so I said yes. However, my microsoft antispyware beta 1 is still showing agents as inactive on one page and active on the other. Should I run another hijackthis scan? Thanks a bunch for the help. And I'm still getting that same error message when trying to logon to view my banking rewards. What's next?
Click start > control panel > user accounts > change the way users log on or off > uncheck fast user switching > restart you computor.
Download, unzip and run 'RootkitRevealer' from Sysinternals:
http://www.sysinternals.com/Utilities/RootkitRevealer.html
Once the program has started, press Scan and let it run.
When the scan is done, use 'File > Save' to place the logfile in a convenient location (such as the desktop). The default filename will be 'RootkitReveal.txt'.
Save your Log File
Copy/Paste the contecnts of that logfile into your next reply
NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !
That way you should have a much simpler and clearer log file in which to peruse and evaluate.
Did what you asked. Here's the file:
C:\RECYCLER\NPROTECT\00158741.bmp 12/29/2005 12:17 PM 2.66 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158742.bmp 12/29/2005 12:17 PM 2.66 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158743.bmp 12/29/2005 12:17 PM 2.66 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158744.bmp 12/29/2005 12:17 PM 2.66 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158745.bmp 12/29/2005 12:17 PM 2.66 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158746.bmp 12/29/2005 12:17 PM 2.66 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158747.bmp 12/29/2005 12:17 PM 2.66 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158749.bmp 12/29/2005 12:17 PM 20.04 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158750.bmp 12/29/2005 12:17 PM 6.03 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158751.bmp 12/29/2005 12:17 PM 6.03 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158752.bmp 12/29/2005 12:17 PM 6.03 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158753.bmp 12/29/2005 12:17 PM 6.03 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158754.bmp 12/29/2005 12:17 PM 6.03 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158755.bmp 12/29/2005 12:17 PM 6.03 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158756.bmp 12/29/2005 12:17 PM 6.03 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158757.bmp 12/29/2005 12:17 PM 6.03 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158758.png 12/29/2005 12:17 PM 588 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158759.PNG 12/29/2005 12:17 PM 494 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158760.PNG 12/29/2005 12:17 PM 465 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158761.PNG 12/29/2005 12:17 PM 499 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158762.PNG 12/29/2005 12:17 PM 460 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158763.PNG 12/29/2005 12:17 PM 609 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158768.bmp 12/29/2005 12:17 PM 1.23 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158769.bmp 12/29/2005 12:17 PM 1.23 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158770.bmp 12/29/2005 12:17 PM 1.23 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158771.bmp 12/29/2005 12:17 PM 1.23 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158776.bmp 12/29/2005 12:17 PM 1.18 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158777.bmp 12/29/2005 12:17 PM 1.18 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158778.bmp 12/29/2005 12:17 PM 1.18 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158779.bmp 12/29/2005 12:17 PM 1.18 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158780.bmp 12/29/2005 12:17 PM 1.18 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158781.bmp 12/29/2005 12:17 PM 1.18 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158782.bmp 12/29/2005 12:17 PM 1.18 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158783.bmp 12/29/2005 12:17 PM 1.18 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158784.bmp 12/29/2005 12:17 PM 1.18 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158912.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158913.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158914.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158915.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158916.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158917.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158918.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158919.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158920.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158921.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158922.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158923.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158924.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158925.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158926.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158927.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158928.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158929.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158930.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158931.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158932.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158933.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158934.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158935.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158936.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158937.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158938.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158939.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158940.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158941.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158942.png 12/29/2005 12:17 PM 366 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158943.png 12/29/2005 12:17 PM 486 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158944.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158945.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158946.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158947.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158948.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158949.BMP 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158950.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158951.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158952.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158953.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158954.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158955.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158956.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158957.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00158958.bmp 12/29/2005 12:17 PM 5.30 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00159040.bmp 12/29/2005 12:17 PM 536 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00159042.bmp 12/29/2005 12:17 PM 3.80 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00159043.bmp 12/29/2005 12:17 PM 536 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00159045.bmp 12/29/2005 12:17 PM 3.80 KB Hidden from Windows API.
C:\RECYCLER\NPROTECT\00159046.bmp 12/29/2005 12:17 PM 536 bytes Hidden from Windows API.
Run 3S under “Items To Clear” tab place a checkmark in all of them but the last.
Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves now.
Okay I downloaded 3S and rebooted and reran with HJT. Here's the file below. Also, computer seems to be a little faster so what exactly does 3S do? Still not running at optimum but is a little better. HJT didn't seem to find as much as before. I uninstalled microsoft beta 1 and am going to reinstall later after computer is cleaned. Haven't gotten any more alerts from spysweeper about my IE settings being hijacked, but am getting an alert about a "ctfmon.exe" that keeps trying to run. Otherwise, computer seems to be getting back to normal slowly but surely. Thanks.
Logfile of HijackThis v1.99.1
Scan saved at 7:48:04 PM, on 2/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
ctfmon.exe is a part of the Microsoft Office suite, log looks clean
so what exactly does 3S do
System Security Suite (3S) is the program to remove internet tracks and junk files from your computer. It allows you to delete Cookies, clear Internet Explorer Cache, delete index.dat Files, clear Typed URLs, Windows Temp Folder and much more. You can also specify custom folder locations with file masks, which will be cleaned in addition to the selected items. In addition, the program allows you to view and optionally remove programs that launch automatically at Windows startup as well as Browser Helper Objects.
Thanks for all the help. Couple of last questions. How often do I run these programs: 3S, HJT? And how do I know what is safe to clean, remove, etc. once they've been run? Or should I just post them and wait for a reply if I'm not sure. when it comes to some of these things.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.