PDA

View Full Version : Problem With Spywear!



junkyardking
11-17-2003, 10:38 PM
Somewhere along the line i have downloaded some particulary nasty spywear which trys to connect to 216.127.94.107 Everyones Internet, Inc <_< , it&#39;s particuly hard to track down as it uses windows files - windows exploer and Run dll as an App to connect, now i have currently blocked it using kerio firewall but would like to remove it, i have ran both adaware pro and spybot with the latest updates but to no avail. :(

I have tracked down at least one file in C:&#092;Documents and Settings&#092;GuessWho&#092;Local Settings&#092;Temp the file name being "osfhiqf" which i cant seem to delete it as it hooked itself to windows exploer,
Now how do i delete this file?

I have also used a program called startuplist to list files in use if thats any help

here&#39;s the list


Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:&#092;WINDOWS&#092;System32&#092;smss.exe
C:&#092;WINDOWS&#092;system32&#092;winlogon.exe
C:&#092;WINDOWS&#092;system32&#092;services.exe
C:&#092;WINDOWS&#092;system32&#092;lsass.exe
C:&#092;WINDOWS&#092;system32&#092;svchost.exe
C:&#092;WINDOWS&#092;System32&#092;svchost.exe
C:&#092;WINDOWS&#092;Explorer.EXE
C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe
C:&#092;WINDOWS&#092;System32&#092;CTHELPER.EXE
C:&#092;PROGRA~1&#092;Grisoft&#092;AVG6&#092;avgserv.exe
C:&#092;WINDOWS&#092;System32&#092;nvsvc32.exe
C:&#092;Program Files&#092;Kerio&#092;Personal Firewall&#092;persfw.exe
C:&#092;WINDOWS&#092;system32&#092;NOTEPAD.EXE
C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE
C:&#092;Program Files&#092;Kerio&#092;Personal Firewall&#092;PFWADMIN.EXE
C:&#092;WINDOWS&#092;system32&#092;NOTEPAD.EXE
C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE
C:&#092;Program Files&#092;WinRAR&#092;WinRAR.exe
C:&#092;DOCUME~1&#092;GuessWho&#092;LOCALS~1&#092;Temp&#092;Rar&#036;EX00.897&#092;StartupList.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:
[C:&#092;Documents and Settings&#092;All Users&#092;Start Menu&#092;Programs&#092;Startup]
Microsoft Office.lnk = C:&#092;Program Files&#092;Microsoft Office&#092;Office10&#092;OSA.EXE

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM&#092;Software&#092;Microsoft&#092;Windows NT&#092;CurrentVersion&#092;Winlogon]
UserInit = C:&#092;WINDOWS&#092;system32&#092;userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Run

NvCplDaemon = RUNDLL32.EXE C:&#092;WINDOWS&#092;System32&#092;NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
WINDVDPatch = CTHELPER.EXE
UpdReg = C:&#092;WINDOWS&#092;UpdReg.EXE
Jet Detection = "C:&#092;Program Files&#092;Creative&#092;SBLive&#092;PROGRAM&#092;ADGJDet.exe"
AVG_CC = C:&#092;PROGRA~1&#092;Grisoft&#092;AVG6&#092;avgcc32.exe /startup
NeroCheck = C:&#092;WINDOWS&#092;system32&#092;NeroCheck.exe
QuickTime Task = "C:&#092;WINDOWS&#092;System32&#092;qttask.exe" -atboottime
CloneCDTray = "C:&#092;Program Files&#092;SlySoft&#092;CloneCD&#092;CloneCDTray.exe" /s
osfhiqf = rundll32 C:&#092;WINDOWS&#092;System32:osfhiqf.dll,Init 1

--------------------------------------------------

Autorun entries from Registry:
HKLM&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;RunOnce

*osfhiqf = rundll32 C:&#092;WINDOWS&#092;System32:osfhiqf.dll,Init 1

--------------------------------------------------

Autorun entries from Registry:
HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Run

ProxyCap = C:&#092;PROGRA~1&#092;PROXYL~1&#092;ProxyCap&#092;proxycap.exe
Steam = C:&#092;Program Files&#092;Steam&#092;Steam.exe -silent

--------------------------------------------------

Shell & screensaver key from C:&#092;WINDOWS&#092;SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU&#092;..&#092;Policies: Shell=*Registry key not found*
HKLM&#092;..&#092;Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:&#092;Program Files&#092;Adobe&#092;Acrobat 6.0&#092;Reader&#092;ActiveX&#092;AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:&#092;WINDOWS&#092;iDonate.dll - {397D7D63-816E-4ECF-8761-775C932C5CF1}
(no name) - C:&#092;Program Files&#092;NetLeech&#092;IEExt.dll - {F4A27D22-E603-4B1B-B8D0-1CF7D57E56F2}

--------------------------------------------------

Enumerating Download Program Files:

[Update Class]
InProcServer32 = C:&#092;WINDOWS&#092;System32&#092;iuctl.dll
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/...7863.7639467593 (http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37863.7639467593)

[Shockwave Flash Object]
InProcServer32 = C:&#092;WINDOWS&#092;System32&#092;macromed&#092;flash&#092;Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab (http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab)

--------------------------------------------------

Enumerating Winsock LSP files:

Protocol #1: C:&#092;Program Files&#092;NetLimiter&#092;nl_lsp.dll
Protocol #2: C:&#092;Program Files&#092;NetLimiter&#092;nl_lsp.dll
Protocol #3: C:&#092;Program Files&#092;NetLimiter&#092;nl_lsp.dll
Protocol #4: C:&#092;Program Files&#092;NetLimiter&#092;nl_lsp.dll
Protocol #5: C:&#092;Program Files&#092;NetLimiter&#092;nl_lsp.dll
Protocol #6: w2pxdrv.dll (file MISSING)
Protocol #7: w2pxdrv.dll (file MISSING)
Protocol #8: w2pxdrv.dll (file MISSING)
Protocol #9: w2pxdrv.dll (file MISSING)
Protocol #10: w2pxdrv.dll (file MISSING)
Protocol #16: C:&#092;Program Files&#092;NetLimiter&#092;nl_lsp.dll
Protocol #36: w2pxdrv.dll (file MISSING)

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:&#092;WINDOWS&#092;system32&#092;SHELL32.dll
CDBurn: C:&#092;WINDOWS&#092;system32&#092;SHELL32.dll
WebCheck: C:&#092;WINDOWS&#092;System32&#092;webcheck.dll
SysTray: C:&#092;WINDOWS&#092;System32&#092;stobject.dll

--------------------------------------------------
End of report, 5,630 bytes
Report generated in 0.090 seconds

Command line options:
&nbsp; /verbose&nbsp; - to add additional info on each section
&nbsp; /complete - to include empty sections and unsuspicious data
&nbsp; /full&nbsp; &nbsp; - to include several rarely-important sections
&nbsp; /force9x&nbsp; - to include Win9x-only startups even if running on WinNT
&nbsp; /forcent&nbsp; - to include WinNT-only startups even if running on Win9x
&nbsp; /forceall - to include all Win9x and WinNT startups, regardless of platform
&nbsp; /history&nbsp; - to list version history only
:swear: :swear: :angry: :( :(

Monkeee
11-17-2003, 10:39 PM
try using spybot search and destroy :)

junkyardking
11-17-2003, 10:47 PM
Originally posted by Monkeee@17 November 2003 - 22:39
try using spybot search and destroy :)
I already did that


i have ran both adaware pro and spybot with the latest updates but to no avail

LTJBukem
11-17-2003, 10:48 PM
It&#39;s a trojan.

http://ses.symantec.com/content.cfm?articleid=2949&EID=0

http://www.trojanscan.com/

Don&#39;t worry, you&#39;ll be fine. ;)

:)

EDIT :- The moral of this story is, don&#39;t use Internet explorer.

Get mozilla firebird free here (http://www.mozilla.org/products/firebird/).

junkyardking
11-17-2003, 11:09 PM
Well i tried the scan and it came up with nothing, the file is still there, i tried deleting the reg keys with reg cleaner and they just reapear.

LTJBukem
11-17-2003, 11:20 PM
There&#39;s a removal tool here. (http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html)

:)

junkyardking
11-17-2003, 11:45 PM
I dont think this is the same as i ran the tool and it came up with nothing, is there a way to delete this file without going into the actualy directory?

Johnny_B
11-17-2003, 11:46 PM
Check out www.spywareinfo.com (http://www.spywareinfo.com).
You can post your HijackThis log in their forum, and they will help you solving the problem.
They seem to have plenty of complaints about Everyones Internet.

junkyardking
11-18-2003, 01:43 AM
Thanks for that site Johnny found out it was the Aflooder trojan very nasty, if anybody got this check out http://forums.spywareinfo.com/index.php?showtopic=10456&st=0 :D

sparsely
11-18-2003, 02:13 AM
/me loves spywear&#33;

http://www.brakpage.com/spywear/img/friendly.gif