Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old January 4th, 2005, 04:04 PM
Leone Leone is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 7 Leone User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
nyam-nyam.biz?search hijack

I also got this nasty bugger, here is the hijackthis file, as you can see there is nothing suspicious in it. BTW the about.htm mentioned at R0 did not exist.


Logfile of HijackThis v1.99.0
Scan saved at 21:33:57, on 04.01.2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Programme\ScanSoft\OmniPagePro11.0\opware32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Spyware Doctor\swdoctor.exe
C:\Programme\Palm\HOTSYNC.EXE
C:\WINDOWS\system32\proquota.exe
C:\WINDOWS\system32\logon.scr
M:\Box\CWS\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.ch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bluewin.ch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Omnipage] C:\Programme\ScanSoft\OmniPagePro11.0\opware32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Programme\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: HotSync Manager.lnk = C:\Programme\Palm\HOTSYNC.EXE
O4 - Global Startup: HotSync Manager.lnk = C:\Programme\Palm\hotsync.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.bluewin.ch
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1104149457625
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = bcj.ch
O17 - HKLM\Software\..\Telephony: DomainName = bcj.ch
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = bcj.ch
O23 - Service: Norton AntiVirus Auto-Protect-Dienst - Symantec Corporation - C:\Programme\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe

I have done some manual cleaning of the root in C: and deleted any suspicious files, even non executables and 0 byters that are not part of the OS. There was even a 0 byte ntldr with a different extension. Additionally I found a suspicious dll in "%program files%\PPC Advertor" directory called ppc.dll, which was alone in its own directory. Also I found that there was an odd wmplayer.exe.tmp file in the Windows Media Player directory which I also deleted as a version check showed empty spaces. Strange enough the wmplayer had been renamed on 21.12.2004 (most likely the day of the infection)! I have not done anything in the registry. After this the browser came up with about:blank in the address field and a browser error (the nyam-nyam page was gone). After re-setting the startpage everything was fine and the hijack did not reappear.

Sorry if I cannot give the specific file that caused this however it must have been one of the three above.

Leone

Reply With Quote
  #2  
Old January 7th, 2005, 02:29 PM
Evil_666 Evil_666 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 3 Evil_666 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
i can confirm you that this ****ing spyware is the lonely dll called "ppc.dll".
i had the same problem and since i deleted this file, the search engine startpage nyamnyam.byz do not reappear.

Reply With Quote
  #3  
Old January 10th, 2005, 11:04 AM
Leone Leone is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 7 Leone User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Thanks for confirming this. Now the big question remains, how on earth is this file being called anyway. There are no traces in the registry so it must be called through another file. I mean you cannot find any trace in AppInitDLLs nor in the run sections of the registry, nor does the actual filename ever appear in the registry. So how did they do it, that is the big mistery? It appears that hijack programmers have found a new exploit. Maybe someone can shed some light on this.

Leone

Reply With Quote
  #4  
Old January 11th, 2005, 01:02 PM
Evil_666 Evil_666 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 3 Evil_666 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
The only thing that i know about this file its you cant delete it while u are connected to internet, because it used by a another program.You have to turn off ur internet connection before, if you want to kill it.
So, it can detect when your internet connection is on.

Reply With Quote
  #5  
Old January 11th, 2005, 01:52 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Quote:
Originally Posted by Leone
Thanks for confirming this. Now the big question remains, how on earth is this file being called anyway. There are no traces in the registry so it must be called through another file. I mean you cannot find any trace in AppInitDLLs nor in the run sections of the registry, nor does the actual filename ever appear in the registry. So how did they do it, that is the big mistery? It appears that hijack programmers have found a new exploit. Maybe someone can shed some light on this.

Leone

Hi Leone,

I have done some more research and this hijack may be related to the CWS findmenow.

Please download CWShredder from Here Save it to a convenient location such as your Desktop

Close ALL browser windows or it may not work! Run CWShredder and select "Fix" (do not just Scan). It will automatically remove the infections.

Please post your results.

Tom
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
  #6  
Old January 12th, 2005, 01:48 AM
Leone Leone is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 7 Leone User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Quote:
Originally Posted by Evil_666
The only thing that i know about this file its you cant delete it while u are connected to internet, because it used by a another program.You have to turn off ur internet connection before, if you want to kill it.
So, it can detect when your internet connection is on.


You see I was able to delete the file without having to recourse to safe mode. IE was not started at that time. But internet connection was over the LAN so always open. So I guess it must be the IE that calls the dll though as said above no traces in the registry. I have also no possibility to check it again as when deleting the dll the problem's gone and I would not know how to get infected again.

Leone

Reply With Quote
  #7  
Old January 17th, 2005, 02:18 PM
xmas xmas is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 2 xmas User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
same hijack

I've got the same hijack on a cutomers machine.

I alread yfound the ppc.dll yesterday and deleted. Now whenever I run Internet Explorer it crashes. The crash doesn't happen in safe mode.

It's a fully updated Windoiws XP Home.

I found this in the registry, didn't help with anything by deleting it.

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\TypeLib\{53B95204-7D77-11D2-9F81-00104B107C96}]

[HKEY_CLASSES_ROOT\TypeLib\{53B95204-7D77-11D2-9F81-00104B107C96}\1.0]
@="About 1.0 Type Library"

[HKEY_CLASSES_ROOT\TypeLib\{53B95204-7D77-11D2-9F81-00104B107C96}\1.0\0]

[HKEY_CLASSES_ROOT\TypeLib\{53B95204-7D77-11D2-9F81-00104B107C96}\1.0\0\win32]
@="C:\\Program Files\\PPC Advertor\\ppc.dll"

[HKEY_CLASSES_ROOT\TypeLib\{53B95204-7D77-11D2-9F81-00104B107C96}\1.0\FLAGS]
@="0"

[HKEY_CLASSES_ROOT\TypeLib\{53B95204-7D77-11D2-9F81-00104B107C96}\1.0\HELPDIR]
@="C:\\Program Files\\PPC Advertor\\"

Reply With Quote
  #8  
Old January 17th, 2005, 04:00 PM
xmas xmas is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 2 xmas User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
get THIS

Ok so I uninstalled Service Pack 2, reinstalled IE6, and then reinstalled SP2 and Internet Explorer is still crashing, but not in safe mode.

ANYONE!?!? HELP!?!?!

Reply With Quote
  #9  
Old January 17th, 2005, 06:28 PM
xmas xmas is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 2 xmas User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
fixed...! (?)

had to delete this:

C:\Windows\System32\lsd_f3.dll

And then cleared the registry using Sytem Mechanic.

Seems to be going fine.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > nyam-nyam.biz?search hijack


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway