Another about:blank case

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Maggie79, Nov 2, 2004.

  1. Maggie79

    Maggie79 Private E-2

    I'm infected with the about:blank spyware...
    1- Homepage is always reset to about:blank
    2- When I go to Yahoo or Google, it opens another search page (http://search-to-find.com) and gives me unwanted pop-ups.
    I have search the web extensively in search for a cure to that problem. I have scan/reboot several times with Ad Aware, SpyBot, and CWShredder, but the problem is still there. Could you help me? Below you will find the logfile done with Hijack this.

    Any help would be very very appreciated!!!

    Thank you,
    Maggie

    Edit by chaslang: Inline log changed to an attachment
     
    Last edited by a moderator: Nov 3, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Maggie,

    Welcome to MGs. Please note HijackThis is the last step and we have rules about how and when to post a log. Please read this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting You also MUST shut down your browsers before running HJT and you must put it into the proper directory as indicated in that thread. You currently had 1 IE session running and you also had HJT running directly from the ZIP. Unzip it to a directory of its own like C:\Program Files\HJT or C:\HJT. You MUST get HJT installed correctly before continuing. From now on please do not post logs unless we ask for them and then only post as a .txt file attachment.

    While you do have the about:blank hijacker, there are some other issues in shown in your log too. That we need to address first.

    First, we need to get rid of this WebSearch Toolbar: O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
    Click Start, Run, and in the open box enter the below and hit OK!
    C:\PROGRA~1\Toolbar\TBPS.exe uninst

    Let me know if that works or not.

    Second, please follow all the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Take special note of step 2 in the section titled Getting Prepared; Steps to be sure your system is ready to be scanned and steps 4 and 5 in the section titled Scanning And Cleaning Steps. Step 5 may become necessary at some point if the above steps do not work.

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing all the above do the following to cleanup some trojan problems I saw:

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    taps.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [Pewd] C:\Documents and Settings\Magali Le Roux\Application Data\taps.exe
    O4 - HKCU\..\Run: [Jabqclf] C:\WINDOWS\System32\w?wexec.exe

    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Magali Le Roux\Application Data\taps.exe
    C:\WINDOWS\System32\w?wexec.exe

    Now reboot in normal mode and post a new HJT log as an attachment. And tell me how things are working.
     
  3. Maggie79

    Maggie79 Private E-2

    Thank you very much for these specific instructions. You are right, I shouldn't have post my logfile at that time - especially considering that I am quite clueless about computers. I want to take time to do this correctly, and I will do exactly as told on your messages and stricky threads. I don't have much time right now, but tomorrow night (in +/- 20 hours), I'll work into that and follow all the instructions. My reply/comments will be posted then.

    Maggie
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Maggie! But note one additional thing. If you get all the way thru those steps and still have a problem with the hijack. Post your HJT as requested but DO NOT reboot. These problems have a habit of mutating of reboots and this would make your log not useful to me. You can disconnect your connection to the internet and shut off your monitor but do not reboot until I get back to you with instructions. Those instructions would involve a long complex procedure documented in: When all else fails - Generic Solution to HSA (Only the Best) & About:Blank hijack
     
  5. Maggie79

    Maggie79 Private E-2

    Hi again!!!

    I am now back from work and will follow all the steps in the standard procedure. This will take me a long time as I am quite clueless about computers. I'll be posting on updates asap!

    Maggie
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But note that if you do get to the point where the Generic Solution is require you must work thru the entire procedure as written. You should not stop in the middle and under no circumstances connect to the internet during it and don't run anything else but what is specified during that procedure. It tells yo when to disconnect and when to reconnect.

    If you have to run it, read it first and ask question you may have before beginning it.
     
  7. Maggie79

    Maggie79 Private E-2

    First steps

    I didn't get to the Generic Solution yet. I'm not even done with step 1 of the "general comments"!

    The first instruction you gave me was this one: First, we need to get rid of this WebSearch Toolbar: O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
    Click Start, Run, and in the open box enter the below and hit OK!
    C:\PROGRA~1\Toolbar\TBPS.exe uninst

    I did exactly that, and Windows give me this mesage: "C:/PROGRA~1/Toolbar refers to a location that is unavailable. It could be on a hard drive on this computer, or on a network. Check to make sure the disk is properly inserted, or that you are connected to the Internet, or your network, and then try again. If it still cannot be located, the information might have been removed to a different location".

    So I guess the uninstall didn't work :(

    Now about "Disable System Restore" temporarily (point 1). I understood that this should restart your computer. In my case, it doesn't! I right click on My Computer, System Restore tab, Check box "Turn off system restore". Once this is done I click yes and I receive a message from Windows:

    "You have chosen to turn off system Restore. If you continue, all existing restore points will be deleted, and you will not be able to track or undo changes to your computer. Do you want to turn off System Restore"? I answer YES to that question, and it doesn't do anything visible. No restart of the computer. What am I doing wrong in this step?

    Thank you for helping me,
    Meanwhile waiting for this answer, I am reading the instructions, but I am not doing anything until you tell me to.

    Maggie
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: First steps

    First did you get HijackThis install into the proper directory yet? If not, you MUST do that first.

    For the first problem, are you sure you entered
    C:\PROGRA~1\Toolbar\TBPS.exe uninst
    and not
    C:/PROGRA~1/Toolbar/TBPS.exe uninst

    If you did it right, skip this step and continue.

    For the system restore problem, that's okay I believe that many times you are not asked to reboot. Just double check that the disable system restore box is still checked and continue with the other steps.
     
  9. Maggie79

    Maggie79 Private E-2

    UPDATE ABOUT SITUATION

    I've gone through all the required steps as per the sticky named "How to: Spyware, Trojan And Virus Removal".

    Firstly, I have:

    * Disabled system restore temporarily
    * Stopped the service of "Workstation Netlogon Service" found with a services.msc search. ["Remote Procedure Call (RPC) Helper" was not found, but "Remote Procedure Call (RCP)" and ""Remote Procedure Call (RCP) Locator" were found. I did NOT delete them (not exact same name). Is that normal and ok?]
    * Enabled viewing of hidden files
    * Downloaded and/or Installed all the Required Tools as per Tutorial
    --> Everything went ok.

    Then I did an online scan with Trend Micro : no viruses found.
    With Symantec Security Check: everything ok (ie safe) expect "Antivirus Product: Warning, no known virus protection found". I do have an anti-virus, AVG 7.0, which I have dowloaded yesterday (after sending you the first HJT file - thats why it doesn't appear on my initial log). AVG 7.0 is perfectly fine!! [Maybe Symantec doesn't recognize other antivirus than Norton? Please advice me about this step.]

    Then in "Safe Mode with Networking":
    * Stinger : All files appear to be clean
    ... Reboot in safe mode
    * Ad-aware: 40 new critical objects found (all of them are with Vendor: CoolWebSearch), delete those
    ... Reboot in safe mode
    * SpyBot: "Problems found" with DSO Exploit and Winpup, delete those
    ... Reboot in safe mode
    *Ad-aware another time : no critical objects found
    ... Reboot in safe mode
    *SpyBot another time: "Problems found" with DSO Exploit, Advertising, Avenue A Inc.

    I didn't try Secondary Spyware Scan because it says that is only for the about:blank hijack removal. I didn't seem to have this problem anymore because all the CoolWebSearch things are not there anymore. I then switch back to normal mode, and I don't have the about: blank symptoms anymore. No more about:blank homepage and no more search-to-find.com redirection. [Is the problem gone for good now?]

    QUESTIONS:

    - Check the brackets [ ] for my questions about the specific tasks?
    - What my inability to run C:\PROGRA~1\Toolbar\TBPS.exe uninst (ref: My reply at Nov 2 19:06)?
    - Are the problems found with SpyBot (DSO Exploit, Advertising, Avenue A Inc.) dangerous?? What should I do about them?
    - Are the instructions you gave me about my INITIAL HJT log (in your first reply, you tell me lines to remove, etc etc) still valid??? Since I made updates and new scans, I am unsure if your first instructions are still valid. So I will wait for your answer.
    - Should I post a new HJT log? It is advised in the tutorial not to do that unless we are asked for it.

    Thanks in advance for your help. That was a LONG work for me but I think the situation will be good in a short while!!!! And I learn new things! :)

    Gotta get some sleep now. I'll be checking for more news from you tomorrow morning (around 6:30 Eastern Time).

    Maggie
     
  10. Maggie79

    Maggie79 Private E-2

    Re: First steps

    It appears we were writting at the same time!!!
    So..... quick replies to your queries :

    1 - YesI'm sure I have entered
    C:\PROGRA~1\Toolbar\TBPS.exe uninst

    I have put this slash / in my comments because I was typing too fast. The command really tells me that is refres to a location that is unavailable. Why does this mean?

    2 - I made sure that the disable system restore box is still checked.

    I will wait for more news from you about my general "update about situation" that I have just posted.
     
  11. Maggie79

    Maggie79 Private E-2

    just to make sure

    I just want to make sure that you see my TWO answers that I have just made. One of them is short and answering about the first steps small query. The other long one is about my updated situation - I went through all the steps of the tutorials and I have tried to explain the situation as best as I can.
     
  12. Maggie79

    Maggie79 Private E-2

    one last thing

    One last thing: Yes, Hijack This is on his own directory under
    C:\Program Files\HJT\ with ONLY the hijackthis.exe file in there.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: one last thing

    Just want to let you know I reading your stuff now. To answer one question and ask another:

    You said,
    Yes the other RPC's are normal. As stated in the directions, you must only see the EXACT name. When you found Workstation Netlogon Service, what was the Path to executable.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: one last thing

    Uninstall the version of Spybot you have and download, install and repeat your safe mode scan with: SpyBot-Search & Destroy 1.3.1tx

    The DSO Exploit problem (a bug in Spybot) should be gone.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: one last thing

    I don't know the cause of : [Maybe Symantec doesn't recognize other antivirus than Norton? Please advice me about this step.]

    Since you do have one, ignore it for now.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: one last thing

    Yes, I think we do need a new HJT log attachment before deciding whatelse we must do.
     
  17. Maggie79

    Maggie79 Private E-2

    Re: one last thing

    Allright!!! Other RPC's were not stopped or deleted. I have no idead what was the Path to executable for Workstation Netlogon Service (I'm not sure what you mean??). When I run the services.msc command again, "Workstation Netlogon Service" is not shown anymore in the list. How can I find the "path to executable"?
     
  18. Maggie79

    Maggie79 Private E-2

    Re: one last thing

    OK, I will uninstall Spybot and put the version you tell me, plus I will do the scan and new HJT file. I will do this tonight, at around 5pm Eastern Time.

    Thanks again,
    Magali

     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: one last thing

    Okay, don't worry about it now. We will figure it all out later after seeing the new HJT log.
     
  20. Maggie79

    Maggie79 Private E-2

    Hi again!

    I have uninstalled my SpyBot and downloaded the 1.3.1 version. Also did the "Immunize this system" thing upon installation. (It said 0 bad products found).

    I have then reboot in safe mode and it said "Congratulations! No immediate threats were found". I have to say though that the scan was much much faster than the previous scans I did with SpyBot. I am not sure this is normal?

    As asked, you will find below the HJT log which was done after the scan.
    And just to let you know, I will be back here at around 11pm Eastern Time and I will be ready to follow other instructions that you might have add.

    PS: I am not good enough with computers to read the HJT files, but I checked it just out of curiosity and I have found the about:blank words again somewhere as a default webpage of some sort... When I start IE though, my real homepage (http://www.courriel.polymtl.ca) is the one that is being opened?! I didn't see that about:blank thing today.

    Thanks,
    Maggie


    Edit by chaslang: Inline log changed to an attachment
     
    Last edited by a moderator: Nov 4, 2004
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    taps.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\wttrc.dll/sp.html#12802
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\wttrc.dll/sp.html#12802
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\wttrc.dll/sp.html#12802
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\wttrc.dll/sp.html#12802
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\wttrc.dll/sp.html#12802
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\wttrc.dll/sp.html#12802
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {F6C9627E-9AEA-C653-5C38-FBA709684853} - C:\WINDOWS\system32\apixt.dll (file missing)

    I'm guessing that this Security iGuard, program is not legitimate. Do you know what it is? If not, fix the next line with HJT to, otherwise skip it.
    O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe

    O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
    O4 - HKCU\..\Run: [Pewd] C:\Documents and Settings\Magali Le Roux\Application Data\taps.exe
    O4 - HKCU\..\Run: [Jabqclf] C:\WINDOWS\System32\w?wexec.exe


    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\wttrc.dll
    C:\Program Files\Security iGuard <--- the whole directory if you decided it was bad.
    C:\PROGRA~1\Toolbar <---- the whole directory
    C:\Documents and Settings\Magali Le Roux\Application Data\taps.exe

    Now run About:Buster, that was referenced in the READ ME FIRST. Save its log.


    No reboot in normal mode and post a new HJT log as an attachment and do the same for the About:Buster log.. And tell us how things are working.
     
  22. Maggie79

    Maggie79 Private E-2

    Hello again,

    Firstly I have run HJT and fixed the lines you told me. I have removed the Security iGuard program and fixed the HJT line related to it. I don't know what is that software, I think I've downloaded it from a pop-up add linked with the about:blank spyware. Shouldn't have done that - now I will only download TRUSTED antispyware things!

    Now about this part:
    None of these files/folders were found after the computer was rebooted.

    AboutBuster log gives me this (sorry for not attaching, but it was said to be in Progress for a long time when trying to upload and couldn't attach it properly somehow):

    Scanned at: 11:55:41 PM on: 04/11/2004

    -- Scan 1 ---------------------------
    About:Buster Version 3.0
    Reference List : 15

    ADS not scanned System(FAT)
    Attempted Clean Of Temp folder.
    Pages Reset... Done!

    -- Scan 2 ---------------------------
    About:Buster Version 3.0
    Reference List : 15

    ADS not scanned System(FAT)
    Attempted Clean Of Temp folder.
    Pages Reset... Done!

    As requested, the new HJT file is attached.
    The HJT log was done in Safe Mode.

    I'll check again soon for the next steps,
    I'm learning new things while doing this work :)
    Maggie
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  24. Maggie79

    Maggie79 Private E-2

    Great!! I don't have any noticeable problems right now - everyhing is running smoothly. I will enable system restore now that we are finished. I read the sticky and will do those steps you mention.

    Two last questions though (not answered in stickied - I did check!):

    1. I was thinking about putting back the " don't show hidden files" option. This way I could avoid deleting an important file that is hidden. Is this a good idea?

    2. A friend told me to browse with Mozilla Fire Fox instead of Internet Explorer to avoid pop-up and spyware. Do you think it is a good idea, provided that I would use the spyware + anti-virus softwares in both cases?

    3. I download music from Morpheus software. I have been told that this program is particularily prone to spyware. True? Any better options?

    PS: If you can't / don't have time to answer my questions, maybe you could tell me where to search for the info?

    THANKS A LOT FOR YOUR HELP.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's 3 questions! It will cost you extra! :)

    1) It's up to personal preference. If you feel safer hiding those files, disable viewing. But remember you will have to do it anytime you run into a problem. It does make it harder sometimes to see legitimate stuff too. The first thing I do on any PC I get is to enable viewing of everything. But that's me.

    2) Did you read step 8 of the How to Protect yourself from malware!

    3) I don't know too much about Morpheus. You may want to ask in the Software Forum. But just be aware that ALL of these file sharing programs open doors into your PC. Some of those sharing sites just happen to be worse than others. For example, Kazaa is really bad. I know we have Emule for download on MGs (eMule) and some people use it. I do not use any of these kind of programs. I have also seen eDonkey mentioned. I also know nothing about it.

    And you're welcome!
     
  26. Maggie79

    Maggie79 Private E-2

    Thank you very much for answering my questions and being so helpful. It's really appreciated. I hope I won't have to post again though because it would mean I have other problems. :p But I'll keep reading.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You'e welcome Maggie! Happy I could help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds