Pls help on "About:Blank and Only the Best" spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by joeigurl, May 11, 2005.

  1. joeigurl

    joeigurl Private E-2

    Hello everyone,

    I'm trying to remove the About:Blank and Only the Best spyware in my computer and I need your help. I've already ran the following:

    Ad-aware SE
    about:Buster
    SpyBot S&D
    Ccleaner
    HijackThis

    I've attached the HijackThis log for interpretation. Please help as I have a deadline to meet. Thanks so much!

    Thanks,
    Joei.
     

    Attached Files:

  2. Publius

    Publius Sergeant

  3. joeigurl

    joeigurl Private E-2

    I know and I've read it already. Thanks for the help! But unfortunately, I really am clueless about HijackThis logs hence I opted to ask for more inputs so as not to damage my computer further. Hoping for a favorable response. Thanks!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a pretty bad HSA infection going there and whatever you have been doing to trying to fix it, you must stop doing because it is only spreading it and making it worse. You have a ton of bad process running. You need to run the thru the cleaning procedures and make sure you follow ALL steps especially the ones mentioning about:blank and HSA (Only the Best) hijackers. Make sure you stop & disable the service mentioned in step 2 (you'll see when you do the steps). Please follow the steps below. If I were you, I would run about:Buster (when you get to that step) let it do a secondary scan and then immediately reboot into safe mode again. And then run about:Buster again.


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. joeigurl

    joeigurl Private E-2

    Hello,

    I just wanted to update you, I'm still in the process of scanning using the Trend Micro online check. It's been running for almost 4 hours now. Initial results show Troj_Dloader.GE and that it's non-cleanable. Should I delete these files as per the advice in Trend Micro's website?

    The results from the Norton check: 822 infected files. These are all infected by Adware.CoolWebSearch. But it doesn't look like Norton has the option of removing or cleaning these files online. Any ideas?

    I'll just keep on running the Trend Micro and continue on with the cleaning...

    Thanks,
    joei.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you can manually clean them, do so. You may need to be in safe mode to do so. Safe the logs if you can. Are you scanning with Symantec and TrendMicro in safe mode?
     
  7. joeigurl

    joeigurl Private E-2

    Yes I'm running in safe mode right now. I've saved the Norton results in a file. I'm still waiting for the results from Trend Micro but it's taking quite a while. =(
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attached is a list of some of the baddies that should be getting detected. I extracted these from your HJT log. There may be duplicate filenames in the list.

    Having all of these processes running is probably why your scanning is taking so long. They have brought your processor to its knees.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should not be doing anything else (like connecting here) while these scans are running. You should only have the one browser session open that the scan is running in.
     
  10. joeigurl

    joeigurl Private E-2

    Yes, I see these files as Trojans in Trend Micro. Can I delete them after the scan runs?
     
  11. joeigurl

    joeigurl Private E-2

    I am logged in at another computer. See the thing is, I just encountered this issue yesterday when I looked at the computer. I just arrived here in Nevada from LA yesterday. It looks like somebody in our NV office has been going to some "bad" websites that got these spyware in our system in the first place. Good thing I have my laptop here with me which I'm using right now to get help =) Unfortunately, I have to go back to LA in a while as it is a long drive back. Sorry, I don't mean to pressure you or anything but I really need your help on this. =(
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can delete all those files; however, there is going to be a bunch more to do in order to fix this. We need to get thru the initial cleaning procedures first. And then we have a bunch more to do. Deleting those files is part of it and the registry key values need to be fixed too using HijackThis. There will be a service to be stopped too as indicated in step # 2 of the READ ME FIRST.

    We need to take this one step at a time. These hijackers are difficult to remove and if not done properly will just mutate and spread. Your PC is witness to that problem.
     
  13. joeigurl

    joeigurl Private E-2

    I agree with you. I am diligently following the steps in "READ ME FIRST" and as I've mentioned, I am only in the Trend Micro scanning stage of it. After which, I'll disconnect from the Net and run the spyware cleaners and finally Hijack This. Should I go ahead and attach the log here afterwards so you can see it?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before attaching another log, we need to make our job a little easier and get rid of some of the many problem line first. Try to delete all the files in the attachment I gave in message # 8 (the baddies.txt file). Some of them may not be deleteable if the process is running and you will need to end the process first using Task Manager. You also need to make sure hidden and system file viewing is enabled per the READ ME FIRST. Then run HijackThis and with NO browsers open select all of those O4 lines and then click fix. Then reboot the PC and get a new HJT log after reboot. Post that log.
     
  15. joeigurl

    joeigurl Private E-2

    Finally my Trend micro scan has finished! Just to clarify, after all the main and secondary spyware scans, do I:

    1. Run Hijack This (while still in safe mode)
    2. Delete O4 entries as you mentioned
    3. Reboot (in normal mode?) and re-run Hijack This
    4. Post log here

    Is this correct?
     
  16. joeigurl

    joeigurl Private E-2

    Ok here's my new Hijackthis log after running everything. I'm now back in safe mode and I've already connected to the Internet again to attach this file. Prior to normal reboot earlier, the only line in O4 I fixed in the HijackThis log is the one that has the bad file "crsi32.exe".

    I still see some of the bad urls in the new log like this though:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\tjobn.dll/sp.html#37049

    Also, when I open my browser, it still goes to the about:blank homepage. Help plssssssssss
     
  17. joeigurl

    joeigurl Private E-2

    Sorry I forgot to attach the file. =)
     

    Attached Files:

  18. joeigurl

    joeigurl Private E-2

    Sorry, I forgot to put in the details:

    In a fit of frustration earlier, I've done many of these steps repeatedly and have lost track of some of the details.

    Adaware SE, found Cool Web Search, removed.

    Spybot found nothing.

    CW Shredder and Kill2me found nothing.

    HSRemove seemed to have removed something but it doesn't show what.

    There are still some strange apps in Add/Remove programs. Home Search Assistant, My Way Search Assistant and Shopping Wizard. Can not remove.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to stop and disable the below Service per step 2 of the READ ME FIRST.


    O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysxh.exe" /s (file missing)


    See if you can do this and make sure it does not restart. If it does restart, let me know. Typically if it restarts it can be immediately to within a few minutes.
     
  20. joeigurl

    joeigurl Private E-2

    Ok I've already disabled it. I know I disabled it before I ran the scans earlier. Maybe it got turned on again after the normal reboot. Should I disconnect from the Net again and run Hijack... and post the log here?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The services can restart themselves. Just run the steps below and make sure where indicated you check again. Do not skip any steps and make sure that you do not run any browsers during this process and make sure you physically unplug your cable to the internet as and when directed below.

    Make sure you have both about:Buster and HSremove downloaded from the READ ME FIRST. And make sure you have UPDATED the database for about:buster. I believe it is up to number 26.

    You need to print or save these instructions locally because after this reading this sentence you will need to physically unplug your connection from your cable, ADSL, or dial-up modem to your PC and then you MUST exit all browsers and DO NOT run any again until requested.

    Okay, unplug your internet connection and exit browsers now!!!!

    We need to stop and disable the service indicated below. You should have already done this during the execution of the READ ME FIRST in step 2.
    O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysxh.exe" /s (file missing)


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Workstation NetLogon Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Workstation NetLogon Service

    If that does not work try entering the short name: 11Fßä#·ºÄÖ`I
    You will need to cut and paste the short name since the characters are not easily typed.

    Now exit HijackThis.

    Now restart HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\atlva.exe


    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (DO NOT OPEN ANOTHER BROWSER UNTIL AFTER POWER DOWN AND POWER UP, see below):

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\tjobn.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\tjobn.dll/sp.html#37049
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\tjobn.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\tjobn.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\tjobn.dll/sp.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\tjobn.dll/sp.html#37049
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {8F6EB89B-594D-E5B7-F18D-1A0ABB1957C2} - C:\WINDOWS\system32\msyt32.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [atlva.exe] C:\WINDOWS\system32\atlva.exe
    O4 - HKLM\..\RunOnce: [sysxh.exe] C:\WINDOWS\sysxh.exe
    O4 - HKLM\..\RunOnce: [mfcan.exe] C:\WINDOWS\mfcan.exe
    O4 - HKLM\..\RunOnce: [ipue32.exe] C:\WINDOWS\ipue32.exe
    O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysxh.exe" /s (file missing)

    Then exit HJT after clicking FIX

    Run Windows Explorer and look for and try to delete (sort the listing in windows explorer by Modification dates and look for possibly other similarly name files from the same date - let me know if you find others. If not sure, if they are bad or good, do nothing except write the filenames down and tell me what they are later.):
    C:\WINDOWS\tjobn.dll
    C:\WINDOWS\system32\msyt32.dll
    C:\WINDOWS\system32\atlva.exe
    C:\WINDOWS\sysxh.exe
    C:\WINDOWS\mfcan.exe
    C:\WINDOWS\ipue32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. If you cannot find or delete them, note which ones and continue (tell me the results when you come back here).

    - Run about:Buster and save the log to ab1.log (make sure you let it do the second scan).

    - NOW PULL THE POWER PLUG TO YOUR PC! Yes, you read that correctly. This is very important! I do not want you to power down the normal way.

    - After that wait a minute or two and then power up into safe mode (still with no internet connection available and do not open any browsers). Only run what I request.

    - Now use the same procedure as above to try to delete any files that would not delete in the above step. Note any that still do not delete and continue.

    - Empty your Recycle Bin and delete all files in the c:\windows\prefetch folder. In fact as an additional measure do the following, run Ccleaner that you installed while running the READ ME FIRST.

    - Run HSremove and then run about:Buster again and save the log to ab2.log (let it do second scan)!

    - Immediately after about:buster completes, reboot in normal mode. (you do not need to pull the powser plug here. Just reboot into normal mode.)

    - Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    - Plug your cable to the internet back in now.

    - Open and close a couple of IE sessions and then with IE closed get a new HJT log.

    - Now come back here and post both about:Buster logs and the new HJT log. And tell me what happened during the procedure.

    Let me know anything else that you notice.
     
    Last edited: May 11, 2005
  22. joeigurl

    joeigurl Private E-2

    I can't seem to find the RPC Helper in the Services menu nor delete it in the HJT app.


    When deleting this file, this message comes up:

    "The selected process could not be killed. It may have already closed, or it may be protected by Windows. This process might be a service, which you can stop from the Services applet in Admin Tools. (To load this window, click Start Run and enter "services.msc.")

    ** Note that I'm typing this msg from my laptop. I've already removed the Ethernet cable from my pc.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check your a new HJT log on the problem PC a make sure that the O23 Service line has not mutated into something else using the atlva.exe file.

    The previous service could have been seen as either
    Remote Procedure Call (RPC) Helper
    or
    11Fßä#·ºÄÖ`I
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about this. I guess I have too many threads going. It was my mistake. Look at the procedure again. I edited it see the edits in this color. It was Workstation NetLogon Service you should be looking for.

     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'll be back in an hour or so. Got to do a 30 mile ride home right now.
     
  26. joeigurl

    joeigurl Private E-2

    It's ok. I didn't find the Workstation Netlogon Service in the services.msc anyway. Here's that happened:

    1. At first, I was able to delete only mfcan.exe, tjohn.dll, ipue32.exe and atlva.exe. After the forced shutdown (unplug cable) and reboot to safe mode, I was able to delete sysxh.exe and myst32.dll. I also saw a myst32.exe file so I deleted this as well.

    I also see that there are

    2. Ran HS Remove and found 8 items removed.

    3. Reset all web browser settings as instructed and rebooted to normal mode.

    4. After opening the first browser, it did show majorgeeks.com already so I thought everything was ok. But when I refreshed the page, the "Only the Best" popup came up again. When I opened another browser, the "about:blank" webpage was in set again. =(

    5. In the Add/Remove Programs, I can still see the following programs:
    Home Search Assistant
    My Way Search Assistant
    Search Extender
    Shopping Wizard
     

    Attached Files:

    • ab1.log
      File size:
      1.5 KB
      Views:
      2
    • ab2.log
      File size:
      422 bytes
      Views:
      2
  27. joeigurl

    joeigurl Private E-2

    Here's the Hijack This log. As you can see, the Network Logon service is still there. There are also a lot of files with a ____32.exe extension - I don't know if this is related to the problem or not. I'll wait for your return. So sorry to bother you this late. We are still here in NV - we postponed our trip back to LA for early morning tomorrow so I can have some more time to fix this pc problem. Again, thank you for your help. I really appreciate it! I hope you have a safe drive home.
     

    Attached Files:

  28. joeigurl

    joeigurl Private E-2

    While you're driving home, I'll also be going out to get a room reservation for tonight else I won't have a place to sleep in. =) Feel free to post away as soon as you're ready and I'll message you when I get back. I'll leave my computer on (with normal startup).
     
  29. joeigurl

    joeigurl Private E-2

    I am getting careless! I did disable the Workstation Netlogon Service. Sorry about my first statement.
     
  30. joeigurl

    joeigurl Private E-2

    Hi I'm back. Listen, I know it's late already so I don't wanna bother you any further. My companions here are begging me to leave already so I guess I'd have to put this off another day. However, as I've mentioned, I am actually based in LA but I come in every 2 weeks here in our Nevada office to check on things. Unfortunately, this incident occurred so I had to delay my trip back to LA. But I do have to leave for LA tomorrow early in the morning so we have to pack up tonight. My request is, what do you suggest we do for now? I'll tell my co-workers not to do any surfing at all in the infected computer and just do their normal work (there's no internet connection required anyway). The thing is, I have to see my schedule when I can come back. Maybe in another month or so ('coz I got jury duty in 2 weeks). My questions are:

    1. Can this wait for a month? Else, I have to schedule a special trip next week.
    2. Can they still continue using our accounting software (Quickbooks) for office operations as long as they don't do any surfing?
    3. Since it looks like I'm still back to Square 1, do I have to post a new message the next time to continue fixing this problem or can I just continue this thread?
    4. I don't mean to monopolize your time but can I set up an appointment with you on when it's most convenient for you to help me with this issue? I really feel bad about having to ask you this but I guess I have to try my luck. I'm sorry to have to bother you like this. I'll try to schedule my trip around when you're available to maximize time.
    5. Do you know anyone who can help me with this problem? Like an 800 toll number I can contact just in case?

    I'm really desperate to get this problem fixed. Thanks so much for all your help! I really appreciate it! I'll check back in tomorrow when I get back to LA.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, it can wait but I would recommend not surfing. In fact if possible make sure a browser is not opened on the PC. Also since the hijacker typical spawns new processes and mutates at reboots and power downs, I would avoid rebooting or shutting down. You will have to post a new HJT log when you come back and if the people using the PC do start surfing you may find yourself with additional problems that require starting the cleanup process over.

    I'm around quite a bit as you can tell from the number of threads I answer, but we do this in spare time. So just come back and look up this thread when you are able to sit in front of the PC again.
     
  32. joeigurl

    joeigurl Private E-2

    What a big mess huh. I did instruct them not to do any surfing at all. Thanks for all your help! I'll log on next time when I go back to Nevada.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I assume that may take a month or so.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds