Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved]HijackThis cannot permanently delete unidentified BHOs and DPF files

[Fixed] Hijackthis! Logs - [Resolved]HijackThis cannot permanently delete unidentified BHOs and DPF files posted in the Security & Safety forums; Hi, I have been trying to fix a host of problems on my computer for weeks. I figured out that there was some kind of Malware/Spyware/Hijacker causing all kinds of ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 07-10-2005
ladygreenwitch's Avatar
HR Director
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,499
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default [Resolved]HijackThis cannot permanently delete unidentified BHOs and DPF files

Hi,
I have been trying to fix a host of problems on my computer for weeks. I figured out that there was some kind of Malware/Spyware/Hijacker causing all kinds of problems, so I used AdAware SE, Spybot S&D, and HijackThis, but alot of the problems persisted. So I got Adware Spy and Spyware Doctor, which showed a whole lot more infections, as I was running the unregistered version of each of these they would not "clean" the files so I manually deleted them only to discover that Adware Spy is a notorious rogue which returns false positives in an attempt to scare people into buying the product. It appears that I removed only part of a malware infection because I am left with two problems.

1. HijackThis and Spybot show two unidentified BHOs and a slew of unidentified Active X (DPF files) which cannot be deleted in Spybot, and when I delete them in HijackThis they come right back, even without rebooting.

and

2. Every time I reboot my computer I lose internet connectivity. The computer redirects the startpage to http://www.microsoft.com/isapi/redir...r=6&ar=msnhome, which should be a legitimate site but returns with Page could not be found error. The network connections show that an IP has been asigned, but it won't work. To fix it I have to run WinsockxpFix which releases the IP and then I get a pop up which takes me to the LAC status, where I have to run the repair, then NOT restart as WinsockxpFix wants. Then I get connection again. VERY FRUSTRATING

Any help would be appreciated. I found HijackThis.de and ran the analysis, it coincided with? the same files I have been trying to delete. So I am including the analysis file as an attatchment. Thanks ahead of time.

Teresa


  #2  
Old 07-10-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: HijackThis cannot permanently delete unidentified BHOs and DPF files

Hi there Teresa.

Have you also tried to scan and remove in safemode? Re-start youre comp ,hit f8 when booting up and select safemode (without networking).
Disable system restore (if you use it) and delete the old restore points , then delete all youre temp files and the content of the windows/prefetch folder.
Then scan youre comp with all the apps you have and fix all the bad stuff again , then reboot scan youre comp with some AV ,see a link for free online scans below also have a look at the "tools" link and see if there is something there you haven't tried yet.

After that can you post a new "full" hijackthis log?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 07-11-2005
ladygreenwitch's Avatar
HR Director
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,499
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: HijackThis cannot permanently delete unidentified BHOs and DPF files

Hi,

Thanks for the ideas, I had tried scanning in safe mode to no avail. But I had not tried deleting the prefetch files and disabling System Restore, (it never works any way), unfortunately, that didn't help either. I still have the exact same problem. However, HijackThis did find a couple of things that were different in Safe Mode. I am going to try to attach both the safe mode version and the version after reboot. If the system won't take two at a time, I will reply again with the reboot report (71105 4)

Thank you so much for trying to help me.

Sincerely,

Teresa


  #4  
Old 07-11-2005
ladygreenwitch's Avatar
HR Director
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,499
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: HijackThis cannot permanently delete unidentified BHOs and DPF files

Hi,

Well I found out two things, First, the system will not take two files and Second, the second file replaces the first. So here is the HijackThis log from Safe Mode (71105 3)

T.


  #5  
Old 07-11-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: HijackThis cannot permanently delete unidentified BHOs and DPF files

The only prob seems to be alot of "absolete" entry's , nothing that points to a real prob but still there is something strainge going on...


First scan and fix in normal mode and fix these:

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {001F2570-5DF5-11d3-B991-00A0C9BB0874} - (no file)
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
O23 - Service: MacFormatService - Unknown owner - C:\Program Files\Conversions Plus\FORMATM.EXE" /SERVICE (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
And all the 016 can be fixed EXCEPT these: KEEP these and fix all the rest:

O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co.../client/wuweb_ site.cab?1117758433813
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/def...ploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab

Then boot in safe mode and cleanup everything (temp/prefetch enz) again and run hijackthis again and see what entry's from the list above are still there and fix them again.


then see if you can find this entry in hijackthis and fix it and then go to youre system32 folder and remove , don't delete , "tscupgrd.exe" and paste it to a temp folder on youre desktop:

O4 - HKCU\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe

Then reboot and see if they stay gone.



PS; you know that there is a VPN client running on youre comp?

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #6  
Old 07-11-2005
ladygreenwitch's Avatar
HR Director
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,499
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: HijackThis cannot permanently delete unidentified BHOs and DPF files

:cry: Hi Joe,

Thanks for trying to help. I really thought we had it that time, the HijackThis log in safemode showed everything GONE!!! But as soon as I rebooted everything was back and sameol' sameol' with the internet connection. This is so goofy, all I can think of is that there is a dll or something trying to reestablish the malware/spyware/hijacker. I'm going to try the whole thing again, only this time I am going to check the runonce locations in regedit in safe mode. Maybe something sneaky will show it's ugly face.

Any other ideas of where to look, the answer is obviously not in HijackThis. I've deleted the same files about 50 times. :x

Wish me luck and put your thinking caps on, thanks again for helping me. Here's the hijack log from safemode the other one is the same as the others. By the by, the tscupdate.exe line wasn't in hijack, but I moved it from system32 and stored it on the desktop anyway. And, yes, I know that I have Cisco VPN on my machine, I have no idea why, and it won't let me delete or unistall it, so I disabled it. Thanks again.

Teresa


  #7  
Old 07-11-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: HijackThis cannot permanently delete unidentified BHOs and DPF files

I think if you can get rid of "tscupgrd.exe" in youre reg and do a manuall search for copys of the file and delete those(also search hidden and system files) , and get rid of that VPN client that youre machine should be clean. If you didn't install it then it must be used for something nasty i would think. It could be that that is whats being used to reinfect you , that is like an open door to ...?? who or whatever is in controll at the other end.

It isn't in add and remove programs? There should be a (hidden) folder in youre program files folder called "cisco systems" atleast.

O4 - HKCU\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

To see if the re-infection comes from the net , pull the network cable out of youre comp (when its off) and then remove everything again and re boot without internet acces and see what happends.




__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 02:30 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top