Author Topic: cawajanga.biz  (Read 35463 times)

0 Members and 1 Guest are viewing this topic.

mauserme

  • Guest
Re: cawajanga.biz
« Reply #45 on: April 28, 2007, 07:12:23 PM »
Didn't you fix this as we previously mentioned ?
O2 - BHO: (no name) - {dd9bc689-1df2-4d5a-b3e7-62ace31641f7} - C:\WINDOWS\system32\EXSMgr.dll (file missing)
O20 - Winlogon Notify: EXSMgr - EXSMgr.dll (file missing)
If you look back through the thread everyone expressed suspicions about these but no one explicitly stated what to do in HijackThis.
« Last Edit: April 28, 2007, 07:22:17 PM by mauserme »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89202
  • No support PMs thanks
Re: cawajanga.biz
« Reply #46 on: April 28, 2007, 07:55:33 PM »
I beg to differ I did suggest they should be fixed

Run HJT again and put a tick in the boxes to the left of the entries and click the Fix button.

Check that the files aren't in the locations mentioned this one mainly.
- C:\WINDOWS\SYSTEM32\EXSMgr.dll

There might have be en no explicit fix and  the exact entries but Susz fixed some of the others, the 016s but these didn't appear to have been fixed. That doesn't matter so much, my concern was if Susz had fixed them then they appear again, that was also my question.

If as Susz mentions there is still hijacking of IE going on yet there doesn't appear to be anything in the HJT log to indicate this, so perhaps we have a hidden element to this.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

mauserme

  • Guest
Re: cawajanga.biz
« Reply #47 on: April 28, 2007, 09:03:07 PM »
I beg to differ I did suggest they should be fixed

Well, almost no one ...

If as Susz mentions there is still hijacking of IE going on yet there doesn't appear to be anything in the HJT log to indicate this, so perhaps we have a hidden element to this.
Let's see what happens after that 016 I mentioned is fixed.  I think the adware was related to this one

O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4058/ftp.coupons.com/r3302/KelloggCompany/Coupons.cab

and currently is still related to this

016 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://clubgames.pogo.com/online2/pogop/zuma/popcaploader_v5.cab


I believe the latter is a variety of this

http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW%5FPOP%2EA

There may also be a downloader component to this.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: cawajanga.biz
« Reply #48 on: April 28, 2007, 10:07:39 PM »
Hi DavidR and Mauserme,

Apparently Susz has/had some hidden malware through a common exploit, she had no defense against, because she had not updated or fully patched her System and Programmes.
I gave links how she could easily start up in SafeMode, and asked her to perform a smitfraud detoxification, because this is the realm of malware that makes her IE go berserk. It has a strong foul smitfraud kind of malicious adware stench i.m.h.o. Like to see what you all come up with at the end of this cleansing routine. It is getting more and more interesting for us, not so much for Susz, but she is not alone in this battle against the malicious bytes.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

mauserme

  • Guest
Re: cawajanga.biz
« Reply #49 on: April 28, 2007, 11:35:56 PM »
Hey guys - what I posted at the top of this page was in SUSZANNAH's defense.  It wasn't meant to be a statement against anyone.

Sorry if I've offended  :)


EDIT:  

2 SUSZANNAH - Did you ever have a program called EXS Manager installed?  Its something to do with music file management.
« Last Edit: April 28, 2007, 11:50:33 PM by mauserme »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: cawajanga.biz
« Reply #50 on: April 28, 2007, 11:58:10 PM »
Hi Mauserme,

Nobody said that, we all are only trying to help this victim. You are doing a great job, be assured of that. Maybe we all waited for the decisive comment about that EXSMgr.dll. Suspicious because there is absolutely no info on it online. It is a pity Susz cannot analyze what that dll's overflow buffer hole is:

polonus's Technical Details on another similar dll problem:
The buffer overflow bug exists in a part of USER32.DLL involved in handling ANI animated cursor files. A partial ANI file format is given below:

"RIFF" {(DWORD)Length_of_file}
"ACON"
"LIST" {(DWORD)Length_of_list}
"INFO"
"INAM" {(DWORD)Length_of_title} {szTitle}
"IART" {(DWORD)Length_of_author} {szAuthor}
"anih" {(DWORD)Length_of_AnimationHeader} {AnimationHeaderBlock}

Generally, the length of AnimationHeaderBlock shoule be 36 bytes (0x00000024). The vulnerability is in the handling of the Length_of_AnimationHeader field. This value will be passed as the length argument of memcpy(), in order to copy the contents of AnimationHeaderBlock, but the value is not checked appropriately. The buffer intended to hold the AnimationHeaderBlock is located on the stack, so we can overwrite the return address and exception handler on the stack and jump into the buffer containing our code.

This vulnerability is a separate vulnerability from the ones discovered by Xfocus.

Protection:
Retina Network Security Scanner has been updated to identify this vulnerability.

Vendor Status:
Microsoft has released a patch for this vulnerability. The patch is available at:
http://www.microsoft.com/technet/security/bulletin/MS05-002.mspx

Anyway an ounce of protection is worth more than a kilo of cleansing afterwards, if you see what we are up against,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

mauserme

  • Guest
Re: cawajanga.biz
« Reply #51 on: April 29, 2007, 01:10:15 AM »
I may have misunderstood but I thought avast! was successfully preventing the malicious ani files from downloading.

... Avast blocks it no problem ...

Looked in Warning Log all it says is:

SYSTEM  1240 sign of CVE-2007-0038 has been found in http://cawaj...... and that it.


Possibly the situation has changed since those initial posts.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: cawajanga.biz
« Reply #52 on: April 29, 2007, 01:22:33 AM »
Hi Mauserme,

That is also a bit confusing to me. Avast should have protected Susz against the consequences of the ANI-hole, on the other hand she was vulnerable because she did not have a fully updated and patched system. She must have (had) some nasty adware/spyware infection that is re-directing the results of her IE browser. If she worked toolbar cop as I suggested, she is free of those in her hjt logs, but she has not told us what actions she actually has taken out, just asking a lot of questions. Yes, my friend Mauserne,  the situation is a little confusing, this cleansing routine begins to look a little bit like goose ladders, if you grasp what I mean to say,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

mauserme

  • Guest
Re: cawajanga.biz
« Reply #53 on: April 29, 2007, 01:49:16 AM »
... this cleansing routine begins to look a little bit like goose ladders, if you grasp what I mean to say,
Someting to do with those "nylon pantyhose games"?  I think I've missed some inide jokes  ;D

Offline SUSZANNAH

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1954
  • There We Are Then
Re: cawajanga.biz
« Reply #54 on: April 29, 2007, 02:14:33 AM »
thank you all for the help, have followed everything to the letter you advised me to do. run the scan in safe mode,  after an hour and finding 42 infected files spyware doctor decided they wanted payment to remove them.

... but in safe mode could not access the net to buy the program....

so will have to start over again tomorrow....... :'(

mauserme

  • Guest
Re: cawajanga.biz
« Reply #55 on: April 29, 2007, 06:24:53 AM »
Try the free version of SuperAntiSpyware instead

http://www.superantispyware.com/

This plus AVG AntiSpyware (mentioned earlier) will miss very little.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: cawajanga.biz
« Reply #56 on: April 29, 2007, 10:03:41 AM »
SpywareDoctor found a lot of "infected files" even on my clean system when I tested it, many of them strange false positives.  :-X

Susz, have you tried a quick check for rootkits? The new scanners from AVG and Panda are very user friendly, as is the tried-and-trusted BlackLight.

http://free.grisoft.com/doc/avg-anti-rootkit-free/lng/us/tpl/v5

http://research.pandasoftware.com/blogs/research/archive/2007/04/02/Panda-AntiRootkit-Released.aspx

http://www.f-secure.com/blacklight/

What exactly are the symptoms now? Ads for games? Do these appear only in IE? Are you taken to a web address, if so, what is it? Is there a company name on the adverts, and if so, what is it?

     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: cawajanga.biz
« Reply #57 on: April 29, 2007, 01:32:55 PM »
Hi SUSZANNAH, I would definitely get rid of the EXSMgr.dll from all locations in HJT and remove the file from System32. If you wish I can do a winpfind analysis

This file is legitimate and OK igfxsrvc.dll as a winlogon

Offline SUSZANNAH

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1954
  • There We Are Then
Re: cawajanga.biz
« Reply #58 on: April 29, 2007, 02:14:55 PM »
Thank you Frank and essex..... now for recap

Ran SUPERAntispyware it found

Adware Vundo variant 5 in registry and 1 in files

Adware tracking cookie 5

Trojan Downloader WinFLyer

says it has removed it, then I ran HJK again and it allowed me to remove BHO and and
EXSMgr.dll

Would like to thank everyone who helped in this mission, I just hope its clean now..... :)

But I would like to know why Avast is not picking up on these   ???

Offline SUSZANNAH

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1954
  • There We Are Then
Re: cawajanga.biz
« Reply #59 on: April 29, 2007, 02:18:13 PM »
To answer the other question Frank it was displaying full page ads for bingo sites and games every few minutes only though IE have all security patches in place........ :)

Have installed Firefox now still afraid to launh IE    :(