And it's Still...About Blank

Discussion in 'Malware Help (A Specialist Will Reply)' started by Julian West, Feb 28, 2005.

  1. Julian West

    Julian West Private E-2

    Machine: Athlon XP 2800
    OS: Microsoft XP

    OK, guys, I need your wizardry. :eek:

    Was hijacked by about:blank two days ago. Concurrently, upon every boot-up I get an "abnormal program termination" message for msHotkey.exe. Then, I get Windows Installer searching for MS Office (it always fails b/c I didn't install MS Office). Then another "abnormal program termination" message.

    Since IE got jacked, I've been using my SBC browser instead of IE, but today something blocked SBC browser from loading (solved that by using Adware Away, which gives me a partial fix until the next reboot).

    I've followed all instructions on "Read Me First Before..." Done everything to a "T", in the correct order. Everything worked fine, though I had to try twice to get the DSO Fix to patch to Spybot. Here's what was found in the scans:

    AdAware:

    1 "Alexa" reg key (data miner)
    10 "Alexa" reg values (data miners)
    11 "Tracking" IE cache files (data miners)
    2 "WinFavorite" Malware files: c:\\windows\system32\brdge.dll
    c:\\windows\system32\jao.dll
    2 "Click Spring" files (data miners)

    SpyBot:

    --several Alexa-related files on startpage
    --CoolwwwSearch.aff.winshow

    CWShredder: clean
    Kill2me: nothing found
    about:Buster: no ADS found. Removed 2 random key entries
    HSRemove: 8 files removed

    Also ran AdWare Away, which identified (and falsely claimed to have eliminated) Variant 5 of about:blank.


    After doing all this, the original problem persists...same as before.


    Is it time to send a Hijack This report???? If so, how would you like it sent? Thanks for your help...
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an ATTACHMENT. All instructions are covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting


    Now post a Hijack This log as an ATTACHMENT to your message (Do NOT copy/paste the log into your post). Please close unnecessary running programs before you run HijackThis. You must close each of the following: your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc.

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. Julian West

    Julian West Private E-2

    Thanks for the quick get-back. Here's the log. One thing I forgot to mention: this bug has also disabled my SBC self support tool. Thanks...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm looking at your log but why do you have about:buster running when using HJT?
     
  5. Julian West

    Julian West Private E-2

    Sorry, Dr. C, I'd dragged it almost offscreen and didn't see it when I was shutting everything else down. Should I run a new log?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:

    Remote Procedure Call (RPC) Helper

    If that does not work try entering the short name (use cut & paste for this):
    ? 6QÔõ'ª´ÆÐ8

    Then reboot and let's see if the service is truly gone.

    After go back to the normal HJT scan screen ans select the below items if still present but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {4D3F045A-9870-CF55-CF30-851993A3AF6F} - C:\WINDOWS\appwf.dll
    O23 - Service: Remote Procedure Call (RPC) Helper (? 6QÔõ'ª´ÆÐ8) - Unknown owner - C:\WINDOWS\d3aq.exe (file missing)


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\appwf.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now:
    Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin
    And Click OK.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No just do what I gave you below. I'm not sure if this will work this time because some of the items normally seen with an about:blank hijack were missing and may resurface after reboot.
     
  8. Julian West

    Julian West Private E-2

    OK, I'll let you know how it turns out...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Be sure to post the follow up HJT log.
     
  10. Julian West

    Julian West Private E-2

    OK, done...plus a break for a really good Daily Show episode. Everything went well. Deleted the RPC helper and it was indeed gone after reboot. Also used HJT to fix the O2-BHO and O23-RPC files.

    I think that got rid of the c:\WINDOWS\appwf.dll, because once I restarted and switched to safe mode, I and couldn't find it despite multiple searches.

    Now, I'm up and running in normal mode. After booting I still get the "abnormal termination" messages for mHotkey.exe, and the Windows Installer still tries to access my non-existent MS Office application. BUT...the SBC self support tool seems to be working, and the IE seems OK...new homepage comes up w/ no problem.

    Here's the new HJT log. and more thanks coming your way....
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you need mHotkey.exe (that is do you use this feature)? See below:

    mhotkey - mhotkey.exe - Process Information
    Process File: mhotkey or mhotkey.exe
    Process Name: Chicony Multimedia Console

    Description:
    mhotkey.exe is used for configuring additional keys on Chicony keyboards. This is a non-essential process. Disabling or enabling this is down to user preference, however disabling may disbale the special keys.


    For the Windows Installer problem, you may want to check this out:

    Windows Installer CleanUp Utility
     
  12. Julian West

    Julian West Private E-2

    Thanks for the utility...I'll try it out as soon as I send this post. I checked and I see no good reason to keep MHotkey.

    Does the HJT log look okay to you??
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you do not need the mhotkey.exe program, you can have HJT fix that line and may fix the "abnormal termination" messages.
     
  14. Julian West

    Julian West Private E-2

    Millions of props to you Dr. C. Next time you're in New Haven, beers are on me!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Just don't tell me your a Red Sox fan. ;)
     
  16. Julian West

    Julian West Private E-2

    Oh hell no. And not the damned Patriots either. I just moved out from San Diego... I've noticed this town is 50/50, yankees and sox...makes for some interesting scenes at the sports bars....
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL! A Padre's and Charger's fan then? (That's acceptable! ;) )
     
  18. Julian West

    Julian West Private E-2

    Hey, you gotta play the hand you're dealt. It could be worse...I could be from Cleveland! Talk about suffering...

    I'm passing out now. Talk to you later, and thanks again. :cool:
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds