About:Blank hijack on Win98SE with a network...

Discussion in 'Malware Help (A Specialist Will Reply)' started by asklater, May 8, 2005.

  1. asklater

    asklater Private E-2

    Okay, first off, let me say that I have read both the Spyware, Trojan And Virus Removal and Hijack This tutorials. However, being a Win98SE user, there were some things that I couldn't follow to the letter. (For example, the services.msc program doesn't exist, and safe mode with networking support is impossible.)

    I also have been a fairly long-time user of Ad-Aware, and have also recently downloaded and ran Spybot and Hijack This. None of them could solve my problem, which I assume you are accustomed to hearing by now.

    My problem all started on April 10th, when searching for song lyrics, (I can't say I remember which song, though) I came across a lyric site that asked me if I wanted to install something. I said No, but it seems it put the About:Blank hijack on my cpu anyways. When I start up my browser, the homepage is About:Blank, naturally, and it takes me to something that appears to be a search engine (not Coolweb, though). In addition, a variety of pop-ups telling me that my system's infected with Spyware appear. (Occasionally, there's a single casino one as well.) Clicking on them takes me to a search result page of Anti-Spyware programs, all of which are either malware in their own right or stuff you hafta pay for.

    In addition, it seems that this hack has made the Rundll32 application (which normally is associated with power management) into a pop-up generator. Even when no internet windows are open, pop-ups for random things, (Expedia, Orbitz, casinos, etc) will appear unless I close Rundll32 with the Task Manager. (It reopens itself eventually, however...)

    Now, running Ad-Aware seems to detect the problem, (or at least I thought it did) but is unable to delete it. While the program doesn't tell me that it can't delete, all the symptoms of the hijack are still present, and my next scan shows that the objects which I thought to contain the problem are still present.

    Then, today I installed and ran Spybot for the first time. It picked up a lotta things that Ad-Aware didn't, but it was unable to delete 3 items. Upon restarting my computer, it deleted those three, but still, the About:Blank hijack didn't go away.

    Then, I installed Hijack This! I was able to figure out the difference between malicious and regular commands, etc. from using the tutorial, and I've even located the problem areas, but when I ask Hijack This to fix them, it doesn't. Mind you, it doesn't return an error message, but the problem hasn't disappeared, and my next Hijack This scan shows that the problem areas are still there.

    From that, however, I have been able to locate the problem file as MFNJ.DLL in the C:\WINDOWS\SYSTEM folder. However, when I try to delete that file, it tells me that it's in use by Windows, and can't be done.

    Now, I've read some other threads, and seen the suggested solutions, but they all seem to be really, really long. And, in addition, I didn't see any of those people who were running Win98SE through a home network. I dunno if it makes a difference, but my home network consists of three computers, which all access the internet through the network hub. If the hub computer is turned off, the other two are unable to access the internet or the other computers on the network.

    The network hub is not the computer that's infected, however, but would the fact that the infected machine needs the hub to access the internet make any difference in solving the problem?

    Anyways, I'm hoping that someone out there can help me; after 3 weeks, this About:Blank thing has gotten pretty annoying...
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are literally hundreds of threads here with fixes for Win9x systems. And yes the fixes are typically long. It is a difficult problem to fix and requires complex procedures.

    HijackThis is actually fixing the lines you selected but you are not getting all the problem files removed and the hijacker is just respawning itself at one of three points:
    1) at shutdown
    2) at power up
    3) when a browser is run.

    Make sure you have run all steps in the READ ME FIRST. Did you download, update and run about:Buster?

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. asklater

    asklater Private E-2

    Well, other than CCleaner, I've run all the steps in the tutorial. Is CCleaner all that important? I figured that I could probably just skip it... I did run about:Buster, and CWShredder too, although neither seemed to have much of an effect. Granted, this was after I ran Hijack This for the first time, as I had been told to use it before stumbling upon this forum. Would it have made any difference if I had ran them first?

    Anyways, I'm a n00b around here, so if something goes wrong in attaching the log, that's why... (And yes, I know that I have waaay too many applications running all the time, so it is kinda long.)

    Alright, done. So, what next?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing should be skipped! Ccleaner will typically clean lots of unnecessary garbage off your PC and while cleaning some of the temp folders it also removes lots of bad stuff.

    about:Buster does find and remove certain items but it will not totally fixed the hijackers. Immediately after running about:Buster, it is necessary to reboot and then do the same in same mode. But do not worry about that now. We will work up a procedure for you to fllow. HijackThis on it's own does not fixed anything. You must tell it what to fix.

    Note we do tell you in the stickies to shutdown unnecessary items before posting logs so we do not have to wade thru so many lines.

    Uninstall WeatherBug!

    You're IE verson is out of date. When is the last time you went to Windows Update to get your updates? BUT,DO NOT DO IT RIGHT NOW.

    Download this file: SpSeHjfix109

    Unzip it to your desktop or to a folder.

    Boot into Safe Mode

    Start SpSeHjfix, click on " Desinfecton starten" (the other button means close) then it will reboot and finish the cleaning.

    Run SpSeHjfix one more time.

    Reboot in Normal mode.

    Run HijackThis again and post a new log. Also post the log from SpSeHjfix, the log should be on your desktop or the same folder as SpSeHjfix.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what the below is and why it loads at Startup?

    O4 - Startup: warning.pif = C:\MYDOCU~1\WARNING.BAT
     
  6. asklater

    asklater Private E-2

    Alright, I've done as you've suggested, and I seem to have solved the problem. Thanks for your help! (Yes, it is about 24 hrs later; I'm not on my computer all the time...)

    The thing is, while I'm now able to access the internet without the about:blank page showing up and without popups, it seems that something I've done has messed up my network settings, as I can no longer access any of the other computers on my network! Do you know what might've done this, and how I can fix it?

    For the record, yes I do know what Warning.Bat is, it's a personal message that I put there to run at startup... And no, I don't think I've ever gone to Windows Update... Should I do that now?

    Anyways, here are the logs, as you requested. Note that I took the liberty to fix the R1 lines. It seems to have worked, although, as I've said, I now have an issue with my network settings. Is this something that normally happens?

    Don't ask me how I can access the internet on this computer when the internet connection is supposed to run through the network hub, which I am not able to access...
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did the R1 lines stay fixed? I'm including them in a todo list below anyway.

    Look in Add/Remove programs for an uninstall to WinTools and uninstall if found.
    Do the same for WildTangent.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/spage.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/spage.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLST.DLL
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Common Files\WINTOOLS
    C:\Program Files\WildTangent

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. asklater

    asklater Private E-2

    Hey, things are working great now! Thanks so much for your help! (As you may have noticed, I'm posting earlier tonight! :D )

    Yes, the R1 lines did stay fixed, and it turns out that after fixing the other things you suggested me to, my network is running fine again. However, there were a couple of minor issues that came up along the way...

    For one thing, neither WinTools or WildTangent showed up on the Add/Remove programs list, although I suppose that's not too big of a deal. However, it turns out there was no WildTangent folder in Program Files at all, and doing a search of my drives for WildTangent only turned up a .cab file in a folder related to Java. I do remember getting rid of WildTangent a while ago using Ad-Aware, so is it possible that its command was just outdated? Either way, it didn't seem too big a deal...

    The only thing that caused some concern was that I couldn't get CCleaner to work. Trying in both safe and normal mode, whenever I clicked on the desktop icon, a message box popped up saying:

    Run-time error '429':

    Active X component can't create object


    Know what this means?

    But, other than not being able to use CCleaner, everything on my machine is working fine. I'm posting the HJT log so you can see that everything's been fixed. Thanks again!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds