HijackThis Log re: about:blank, sysnet, Malwarewipe

Discussion in 'Malware Help (A Specialist Will Reply)' started by drstrangefunk, Jun 23, 2006.

  1. drstrangefunk

    drstrangefunk Private E-2

    Hi,

    thank you for your forum, this is my problem.

    my problems started after i downloaded a codec for Windows Media Player. my homepage was highjacked - the Tools > Internet Options page says about:blank, but the page that actually comes up in IE diercts me to sysnet and Malwarewipe pages.

    also, my McAfee sends up 'found and deleted trojan' prompts. It also found trojans that i could not delete or quarantine.

    and there are pop-ups.

    intially, following directions from another site (i hadn't settled on you guys yet, it was the first thing i tried - i'm sticking with you guys now) i looked in the register (and possibly another place - i'm not sure as it has been a long week of studying online what i should do about this and getting organized to scan according to your specifications), but i did not find anything Malwarewipe or sysnet related.

    here are my attachments for the scanning you had me do.

    if i left anything out, please ask as i took extensive notes during this week and during the scan processes.

    also a question. if i turn off the computer, will the HighjackThis log/check-boxes still be in the HijackThis window/box when i reboot ? i'm unplugging my internet connection for now, but leaving the computer on til i hear from you.

    i am aware of your about:blank removal instructions and plan to try it after hearing your suggestions.

    thank you.

    ps:

    Panda ActiveScan

    my ActiveScan attachments for some reason came out individually rather than in one file. there are two to attach, but i could only load one because of your limit of 3 attachments per post - rather than send one in another post, i chose to send both in second post so as not to split them up. there were actually 4 or 5 INDIVIDUAL scans made by Panda ActiveScan, but for some reason i neglected to note what they were. one was Floppy drive, which i never use, so i didn't bother to scan it (i didn't have the floppy disk it asked me to insert. and the other was Other Media. Other Media had me choose Browse to pick a file to scan. i chose KazaaLite and CD Drive (E:). neither would scan. there MAY have been another scan that i don't remember what it was, but it didn't work, if there was another.

    Windows Defender

    Windows Defender would not run when i attempted it during the scanning processes. when i finished scanning and attempted to run it in normal mode after reboot, the My Computer > HP_PAVILION (C:) > WINDOWS > system32 window was open and i noticed some of the file titles were blue in color (the font was blue). i went UP one file to WINDOWS and found the same thing. when i scrolled through the file, i noticed that some of the file icons were changing. they were chaniging so fast, i couldn't tell if only the icon changed, as i did not have a chance to see what the file title used to be called before the change (if indeed there was a change). here are two (of many) of that the icons that changed.

    nvuaudio.exe and nvue.net

    continuing on to run Windows Defender, it failed to run again, and i got this prompt - "Application failed to initialize: 0x800106ba. A problem caused Windows Defender to stop. To start the service, restart your computer or search Help and Support on how to start service manually.' when i rebooted and tried again, it failed once more and i got the same prompt. i did not search Help and Support.

    there were 3 .exe files in the WD folder. i tried them all, but only one even attempted to load.

    sorry for rambling. my next post will be more concise. (hopefully) : )
     
  2. drstrangefunk

    drstrangefunk Private E-2

    these are the Panda ActiveScan attachments.

    thank you.
     

    Attached Files:

  3. drstrangefunk

    drstrangefunk Private E-2

    i forgot to mention that ever so often, i get a prompt at the top bar that says you have been blocked from this website by adware on your computer. click here for System Doctor to remove it. that's only happened three times this week. my problems started on Monday June 19, 2006, today is Friday June 23, 2006.

    thank you
     
  4. drstrangefunk

    drstrangefunk Private E-2

    i just noticed that the BitDefender and Hijackthis did not attach to my first post.

    please find them here.

    thank you.
     

    Attached Files:

  5. drstrangefunk

    drstrangefunk Private E-2

    also a couple of times there were sounds coming from my speakers. every 8 seconds there was a metal 'tink' and ever so often there was a big "glonk".

    i have never heard of anyone having audio problems with viruses/malware.

    thank you.
     
  6. drstrangefunk

    drstrangefunk Private E-2

    another problem major just popped up. i attempted to change the name of an mp3, i was given the prompt 'If You Change The File Name You May Render The File UNUSABLE' i figured it would probaly be ok...i have never had any problems when i get that prompt whe re-sizing pictures.

    but sure enough, when i clicked on it, the icon changed and when i clicked on it, it would not load.

    help, please.

    the unwanted sounds from the speakers has stopped and otherwise, the computer is doing very well. my homepage is still hijacked and the messengers are slow to load, but i have recieved no pop-ups of Mcafee prompts in a while, although there were still pop-ups when i rebooted. (i still haven't shut down the computer, since my initial reboot to check my results.)

    but being unable to change a file name is a major problem, i think.

    as the record shows, i've probably forgotten to mention something, or will experience a new problem (it seems one problem ends and another worse one begins...sigh). i will respond again.

    thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. drstrangefunk

    drstrangefunk Private E-2

    hi, sorry for the delay. i've been out of commision for the last few days. turns out i've been sick for a long time.

    i have read your instructions for SpywareQuake and SpyFalcon Removal Procedure, and i believe i'm ready to begin.

    before i begin, i want to verify that the path i take to get to %system32% is:
    My Computer > C: > WINDOWS > system32

    thank you.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is the correct path. But make sure you have enabled viewing of hidden files, system files, and extensions as instructed in the READ & RUN ME.
     
  10. drstrangefunk

    drstrangefunk Private E-2

    Re: Hallelujah !!!

    Hallelujah !!!

    i appear to be fixed !!!

    here's my smitfiles log.

    i downloaded and ran both fixquake.exe and smitRem.exe as directed with the exception that i did not save it to my desktop. i knew from experience that i could not access some files on my desktop while in safemode, so i saved it to another folder. i had no trouble running either in safemode.

    i did not find SpywareQuake or SpyFalcon in Add/Remove Programs.

    i did not find any of the files or folders that you asked me to delete if found.

    thank you for your guidance.

    anything else i need to do ?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hallelujah !!!

    Yes please attach a new HJT log. I just notice in your previous log something very dangerous.


    IMPORTANT NOTE: You have been infected with a Password Stealing Trojan: Trojan.W32.Torpig

    See this links for what you have: http://www.liutilities.com/products/wintaskspro/processlibrary/ibm00001/
    http://www.liutilities.com/products/wintaskspro/processlibrary/syshost/

    Since you appear to use this PC for financial related matters, you must take this possible threat seriously.

    You are strongly advised to do the following immediately:
    1. Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned. If you have network compters, start checking them for problems too.
    2. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    3. From a clean computer, change *all* your online passwords -- for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
    Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.

    Now Run the below procedure and attach the runkeys.txt log.
    This will help be look for malware files. It will not fix or remove anything.
     
    Last edited: Jun 30, 2006
  12. drstrangefunk

    drstrangefunk Private E-2

    Re: RunKeys log

    here is my runkeys log.

    should i repeat all of the pre-scanning that you had me do, or should i just run HijackThis ?

    thank you.
     

    Attached Files:

  13. drstrangefunk

    drstrangefunk Private E-2

    Re: My 2nd HijackThis Log

    here is my second HijackThis log.

    thank you.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: My 2nd HijackThis Log

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Miscrosoft Updates Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    MsUpdate

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.



    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {6B7792F2-2E50-F48F-5CC3-0402B595ADFC} - (no file)
    O2 - BHO: (no name) - {7B41AE7E-158D-2DBE-6894-FF58760D8CC3} - C:\WINDOWS\system32\xwlxnlxg.dll (file missing)
    O2 - BHO: (no name) - {8D982D51-011B-AAA2-C7DB-C5C444EA01ED} - C:\WINDOWS\system32\jkljyhfh.dll (file missing)
    O4 - HKLM\..\RunServices: [Windows Workstation Service (32-bits)] wkssvc32.exe
    O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.exe"

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\WINDOWS\system32\jkljyhfh.dll
    C:\WINDOWS\system32\wkssvc32.exe


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Sep 22, 2006
  15. drstrangefunk

    drstrangefunk Private E-2

    Re: Trojan Removal Procedure

    thank you for your help.

    i ran your procedure without incident. i did not find the files you wanted me to delete in safemode, but i did find files in the c:\windows\Prefetch folder. i deleted them all as requested.

    the computer is running much better although i was REALLY scared on reboot - the computer screen turned purple and although i could hear the Windows music starting up, the page got hung and the computer kept turning on and off by itself, with a purple screen. i shut the computer off manually and turned it back on, and it booted up fine.

    my SP2 is once again blocking pop-ups and i even got the address bar to search Yahoo. (that hasn't worked for 3 years.)

    1) the C:/WINDOWS/system32 window is gone from my boot up. that's good, but this time [what appeared to be a DOS-type black window] briefly opened and closed. is this ok ?

    2) but my .mp3 and .wma files still show the file designation after the title, and when i try to rename a music file, i get the prompt that "changing the title could render the file unusable".

    3) and there are icons labelled Album Art that have appeared in my music folders along with the .mp3's and .wma's. they are pinkish in color and half faded out as if they are not really there.

    any ideas on how to fix these 3 problems ?

    thank you.

    please find attached my new HijackThis log.
     

    Attached Files:

  16. drstrangefunk

    drstrangefunk Private E-2

    Re: Nvidia Twin-View window

    ps: also when i shut down my computer a prompt says that Nvidia Twin-View window will not shut down and asks me to 'end now' or wait for Windows to end it.

    any thoughts ?

    thank you.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Nvidia Twin-View window

    The below are all still present. Did you remember to click fix?


    O2 - BHO: (no name) - {6B7792F2-2E50-F48F-5CC3-0402B595ADFC} - (no file)
    O2 - BHO: (no name) - {7B41AE7E-158D-2DBE-6894-FF58760D8CC3} - (no file)
    O2 - BHO: (no name) - {8D982D51-011B-AAA2-C7DB-C5C444EA01ED} - (no file)
    O4 - HKLM\..\RunServices: [Windows Workstation Service (32-bits)] wkssvc32.exe
    O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.exe"download/mnviewer.cab

    Try again and let me know it they go away. If not, then disable Windows Defender's realtime protection:

    Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.

    Also disable and protection being run by McAfee because it could be blocking fixes.

    After disabling Windows Defender and McAfee, try fixing those lines again.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan Removal Procedure

    Not sure! Let me know if it always happens. Is it full screen or just a small window that appears?

    Normal behavior when you change any file extension.

    I doubt this is malware. It is more than likely something to do with some software you have installed. Maybe something like the below:

    http://reviews.cnet.com/4520-11319_7-6361302-10.html
     
  19. drstrangefunk

    drstrangefunk Private E-2

    Re: 02 - BHO's and HijackThis log

    i re-ran HijackThis.

    i closed out McAfee, and all my messengers and Quicktime from the taskbar [the one with the clock].

    Windows Defender has never run for me, so i was unable to adjust the settings the way you suggested. i could uninstall it if that would help.

    (2) of the items appear to have been fixed, but the (3) O2 - BHO's appear to be still there.
     

    Attached Files:

  20. drstrangefunk

    drstrangefunk Private E-2

    Re: 3 Side Problems

    3. i haven't installed any new music-related software.

    thank you.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: 02 - BHO's and HijackThis log

    Yes! Uninstall Windows Defender since it is not working anyway. Then continue on to the below steps. We need to approach this differently since it appears that you do not have permission to remove those O2 - BHO entries from the registry.

    Download and Install Registrar Lite (Make sure you select a download link from Majorgeeks and not the Author's)

    Run Registrar Lite navigate to the following keys and take ownership of them:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

    To take ownership of teh key do the following:
    Click-on the above Registry Key
    Click-on Security in the Menu
    Select Take Ownership
    Now locate each of the below keys under the Browser Helper Objects key and select them (one at a time) and right click on them and select Delete

    {6B7792F2-2E50-F48F-5CC3-0402B595ADFC}
    {7B41AE7E-158D-2DBE-6894-FF58760D8CC3}
    {8D982D51-011B-AAA2-C7DB-C5C444EA01ED}


    After deleting them exit Registrar Lite and attach a new HJT log, Let me know if you had any problems following this procedure.
     
  22. drstrangefunk

    drstrangefunk Private E-2

    Re: Registrar Lite & HijackThis log

    i uninstalled Windows Defender.

    i had no problems running Registrar Lite.

    please find my latest HijackThis log attached.

    thank you.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Registrar Lite & HijackThis log

    Good job! Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  24. drstrangefunk

    drstrangefunk Private E-2

    Re: Thank You's

    thank you so much for your help.

    if you think the NVIDIA refusing to close is NOT a malware problem, i guess i will begin to close up the computer.

    could you direct me to a forum which might be able to help me with the NVIDIA-Twinview window that doesn't want to end when i shut down the computer ?

    the http://forums.majorgeeks.com/showthread.php?t=44525 link was very helpful. i plan to implement the knowledge there immediately. i definitely need a 2-way Firewall and i definitely need to get off of IE.

    i didn't see any Anti-Hacker software [if there is such a thing] on the page.

    can you recommend some ?

    thank you so much.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Thank You's

    That's correct! It is not Malware. Someone in the Hardware Forum (possibly Software Forum) should be able to help you.

    Good Antispyware & Antivirus programs are anti-hacker programs. The stuff in the How to protect thread is very good and covers protection very well. And as it indicates, the PC user is the first and last line of defense. Nothing will protect you from yourself. You need to be better educated and take more care in what software you download and use, where you surf, and what you click on. Never click without closely reading.

    If you are willing to purchased tools, I would recommend Spy Sweeper or Ewido (you don't need both).

    Note: We missed the below. They are left overs from Symantec. Have HJT fix the below lines:
    O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds