You (or a program) are attempting to retrieve information from webnews.somoslosmuchachos.com.ar

Gaard

Diamond Member
Feb 17, 2002
8,911
1
0
This message pops up about every 15 seconds and asks me to log onto the internet.

A little help please. :)
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Sounds like malware. What do you have for these:

  • Operating System
  • Service Pack
  • Internet connection
  • Hardware firewall
  • Software firewall
  • Antivirus
 

ironique

Senior member
May 16, 2002
498
0
76
Download some spyware removal tool (e.g. spybot search and destroy) and run it. Definately sounds like malware.
 

Gaard

Diamond Member
Feb 17, 2002
8,911
1
0
Originally posted by: mechBgon
Sounds like malware. What do you have for these:

  • Operating System - XP
  • Service Pack - 2
  • Internet connection - dialup IE
  • Hardware firewall - nothing
  • Software firewall - nothing
  • Antivirus - Norton's


I've run AdAware and Spybot but it still doesn't kill it.

Suggestions?
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
What version is your Norton (2003, 2004, 2005?) The 2004 and 2005 both can detect certain amounts of spyware/adware if you've gone through and fully configured your options. So start with this:

1) get the latest Intelligent Updater and also run a Live Update so you have the latest defs and engine stuffs

2) make sure the Heuristics are maxed out (aka "Bloodhound") and that it's set to scan within compressed files, no exceptions

3) run a scan with Norton and does it find any threats? If so, what threats?



Also, are Ad-Aware and Spybot finding anything major? If so, what are they finding.

Besides that, please

1) download and run Hijack This and post the text from the logfile here :)

2) open a command-prompt box (Start > Run > cmd) and run this command: net user Administrator Gaard@AT to set your system's hidden Administrator account with the password Gaard@AT, so its powers are protected by a decent password.

3) for gosh sakes enable the Windows Firewall in Control Panel, or install ZoneAlarm or something :confused:



edit: and if you're on dial-up, all that ought to take you a while, so I'm going to the grocery store for a few minutes :)
 

Gaard

Diamond Member
Feb 17, 2002
8,911
1
0
Spybot finds a couple of things. Something like DSO EXPLOIT and I think the other thing was something like MEDIAPLEX or something like that.

I'm a little embarrassed to say my Norton's is 2002. :eek:

I'll go get that Hijack and report back.

I think I'll install ZoneAlarm, too. ;)

I remember the days when you didn't have to worry about this crap. :)
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
You can get a free 15-day trial of Norton Antivirus 2005 from here if you want to start with something free :) Ok, now I really am going to the store :D Lessee... milk... bread... pizza... :p
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
BTW check in Internet Explorer > Tools > Synchronize and click the Setup button and see if there's an entry in the scheduler, that might be where it's all coming from. But still a good idea to close whatever hole it came in through, etc.
 

Gaard

Diamond Member
Feb 17, 2002
8,911
1
0
Here's the log...

Logfile of HijackThis v1.99.0
Scan saved at 6:48:37 PM, on 12/23/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\mssw32.exe
C:\WINDOWS\System32\mssw32.exe
C:\WINDOWS\System32\wpabaln.exe
C:\WINDOWS\System32\CMMON32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.anandtech.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexico Toolbar - {11359F4A-B191-42d7-905A-594F8CF0387B} - C:\WINDOWS\Downloaded Program Files\lexbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-594F8CF0387B} - C:\WINDOWS\Downloaded Program Files\lexbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Start Upping] mediaplayer32.exe
O4 - HKLM\..\Run: [start uploading] crsss.exe
O4 - HKLM\..\Run: [Microsoft Windows W32 Services] mssw32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\RunServices: [Start Upping] mediaplayer32.exe
O4 - HKLM\..\RunServices: [start uploading] crsss.exe
O4 - HKLM\..\RunServices: [Microsoft Windows W32 Services] mssw32.exe
O4 - HKCU\..\Run: [start uploading] crsss.exe
O4 - HKCU\..\Run: [Microsoft Windows W32 Services] mssw32.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\RunServices: [start uploading] crsss.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &amp;Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Search &amp;Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
O8 - Extra context menu item: Search &amp;Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-684FB1C21DBC} - http://dictionary.reference.co...ols/toolbar/lexico.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{125ED11F-555A-4E83-BBC4-9AEDC52670DA}: NameServer = 216.65.160.3 216.65.160.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{125ED11F-555A-4E83-BBC4-9AEDC52670DA}: NameServer = 216.65.160.3 216.65.160.4
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Are you sure you've got Service Pack 2 installed? :confused: Start > Run > winver to check. Your IE and Windows show out-of-date. Not that I'm suggesting installing SP2 until you've got the thing definitely 100% clean...

Ok anyway, my usual solution to system compromise is to Drop The Bomb On It with a complete nuking and reinstallation of Windows. Goes over like a lead balloon with most folks :) but it works 100% of the time and completes in just a few hours without too much hair loss. If you want to do that, just start here, get your resources lined up in advance and burned to CD, back up your data somewhere safe, and off you go :)

If you prefer to stand and fight against the malware, then here goes:

1) get your Administrator-class accounts secured with strong passwords, so that a Microsoft Baseline Security Analyzer scan shows they're not weak/blank. Non-expiring's ok here, but not weak/blank.

2) disable System Restore (how?) so the bugs cannot hide there and come back out later.

3) download LSPFix and WinSockFix from JackMDS's page here to use in case the following procedures break your Internet connectivity

4) Get your ZoneAlarm firewall going, or enable the Windows Firewall (called the Internet Connection Firewall in WinXP RTM or WinXP SP1, see Windows Help if you need help finding where to enable it)

5) Uninstall Norton 2002

6) Reboot into Safe Mode, clear your Internet Explorer cache, and delete the following files that HJT found, if still present:

  • C:\WINDOWS\System32\mssw32.exe
  • C:\WINDOWS\System32\CMMON32.EXE
and fix these items in HJT:
  • O4 - HKLM\..\Run: [Start Upping] mediaplayer32.exe
  • O4 - HKLM\..\Run: [start uploading] crsss.exe
  • O4 - HKLM\..\Run: [Microsoft Windows W32 Services] mssw32.exe
  • O4 - HKLM\..\RunServices: [Start Upping] mediaplayer32.exe
  • O4 - HKLM\..\RunServices: [start uploading] crsss.exe
  • O4 - HKLM\..\RunServices: [Microsoft Windows W32 Services] mssw32.exe
  • O4 - HKCU\..\Run: [start uploading] crsss.exe
  • O4 - HKCU\..\Run: [Microsoft Windows W32 Services] mssw32.exe
  • O4 - HKCU\..\RunServices: [start uploading] crsss.exe
  • O8 - Extra context menu item: Search &amp;Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
  • O8 - Extra context menu item: Search &amp;Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
  • O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-684FB1C21DBC} - http://dictionary.reference.co...ols/toolbar/lexico.cab
  • O17 - HKLM\System\CCS\Services\Tcpip\..\{125ED11F-555A-4E83-BBC4-9AEDC52670DA}: NameServer = 216.65.160.3 216.65.160.4
  • O17 - HKLM\System\CCS\Services\Tcpip\..\{125ED11F-555A-4E83-BBC4-9AEDC52670DA}: NameServer = 216.65.160.3 216.65.160.4
Now search your computer for files with the name HOSTS (it's in C:\WINDOWS\SYSTEM32\DRIVERS\ETC\ and has no extension, just a file called "HOSTS") and check that it has only one entry, for 127.0.0.1 LOCALHOST. If it doesn't, fix it so it does (use Notepad to open this file).


After all that, reboot into normal mode, install your Norton trialware or whatever, thoroughly configure it, update it, and run an exhaustive scan to see how it came out. Also post another HJT logfile and see if it looks better now :)
 

Gaard

Diamond Member
Feb 17, 2002
8,911
1
0
Originally posted by: mechBgon
Are you sure you've got Service Pack 2 installed? :confused: Start > Run > winver to check. Your IE and Windows show out-of-date. Not that I'm suggesting installing SP2 until you've got the thing definitely 100% clean...

Ok anyway, my usual solution to system compromise is to Drop The Bomb On It with a complete nuking and reinstallation of Windows. Goes over like a lead balloon with most folks :) but it works 100% of the time and completes in just a few hours without too much hair loss. If you want to do that, just start here, get your resources lined up in advance and burned to CD, back up your data somewhere safe, and off you go :)

If you prefer to stand and fight against the malware, then here goes:

1) get your Administrator-class accounts secured with strong passwords, so that a Microsoft Baseline Security Analyzer scan shows they're not weak/blank. Non-expiring's ok here, but not weak/blank.

2) disable System Restore (how?) so the bugs cannot hide there and come back out later.

3) download LSPFix and WinSockFix from JackMDS's page here to use in case the following procedures break your Internet connectivity

4) Get your ZoneAlarm firewall going, or enable the Windows Firewall (called the Internet Connection Firewall in WinXP RTM or WinXP SP1, see Windows Help if you need help finding where to enable it)

5) Uninstall Norton 2002

6) Reboot into Safe Mode, clear your Internet Explorer cache, and delete the following files that HJT found, if still present:

  • C:\WINDOWS\System32\mssw32.exe
  • C:\WINDOWS\System32\CMMON32.EXE
and fix these items in HJT:
  • O4 - HKLM\..\Run: [Start Upping] mediaplayer32.exe
  • O4 - HKLM\..\Run: [start uploading] crsss.exe
  • O4 - HKLM\..\Run: [Microsoft Windows W32 Services] mssw32.exe
  • O4 - HKLM\..\RunServices: [Start Upping] mediaplayer32.exe
  • O4 - HKLM\..\RunServices: [start uploading] crsss.exe
  • O4 - HKLM\..\RunServices: [Microsoft Windows W32 Services] mssw32.exe
  • O4 - HKCU\..\Run: [start uploading] crsss.exe
  • O4 - HKCU\..\Run: [Microsoft Windows W32 Services] mssw32.exe
  • O4 - HKCU\..\RunServices: [start uploading] crsss.exe
  • O8 - Extra context menu item: Search &amp;Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
  • O8 - Extra context menu item: Search &amp;Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
  • O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-684FB1C21DBC} - http://dictionary.reference.co...ols/toolbar/lexico.cab
  • O17 - HKLM\System\CCS\Services\Tcpip\..\{125ED11F-555A-4E83-BBC4-9AEDC52670DA}: NameServer = 216.65.160.3 216.65.160.4
  • O17 - HKLM\System\CCS\Services\Tcpip\..\{125ED11F-555A-4E83-BBC4-9AEDC52670DA}: NameServer = 216.65.160.3 216.65.160.4
Now search your computer for files with the name HOSTS (it's in C:\WINDOWS\SYSTEM32\DRIVERS\ETC\ and has no extension, just a file called "HOSTS") and check that it has only one entry, for 127.0.0.1 LOCALHOST. If it doesn't, fix it so it does (use Notepad to open this file).


After all that, reboot into normal mode, install your Norton trialware or whatever, thoroughly configure it, update it, and run an exhaustive scan to see how it came out. Also post another HJT logfile and see if it looks better now :)

Ok, I'll report back in a month. ;)

Seriously, it'll take me a while. I'll do it, but it'll take me a while. :)

One thing before I start, what do you mean by 'fix'?
and fix these items in HJT

Thanks for the help mB.

 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
To give an example, here's my HJT 1.99 window if I run a Scan only. I checkmarked some items in this picture (not really problem items, just for illustration) and then I would click the Fix button down below to remove those. I would be doing this in Safe Mode when fixing, and in regular Windows mode to check that the junk stayed gone.
 

Gaard

Diamond Member
Feb 17, 2002
8,911
1
0
Gaard here...back online with a lean mean fighting machine. :)

I ended up going with Plan A. (I reformatted and reinstalled XP)

Norton's is maxed out. As is XP. ZA is installed.

Clean as a whistle. :)

Thanks for the help.
 

BustaBust

Golden Member
Dec 21, 2001
1,425
2
81
This has nothing to do with the topic, but if you are Indian, then your username is making me smirk.
 

The J

Senior member
Aug 30, 2004
755
0
76
Find your HOSTS file again. Right-click on it and click Properties in the pop-up menu. There should be something that says "[ ] Read-Only" or something like that. Check the box next to it and click Apply, then OK. This should stop some things from getting into that file, which is a common way spyware is put on your system.