sp.html about:blankp2esocks instant access

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shalom, Dec 29, 2004.

  1. shalom

    shalom Private E-2

    I have done all the required steps in the sticky and get to a nice problem free Hjt log until I go on line and in seconds my desktop becomes a big black warning ,a bunch of pages telling me, of course, that i am infected come down the line and the log is now bad .
    sp.html and desktop.html and a startup program called instant access and all the lines below are all recreated within seconds of going on line.

    Below are the juicy parts for your review

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    O4 - HKLM\..\Run: [xBwu] C:\WINNT\jmjpvc.exe
    O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
    O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1018.dll,InstantAccess
    O4 - HKCU\..\Run: [mslagent] C:\WINNT\mslagent\mslagent.exe
    O4 - HKCU\..\Run: [SearchSetter] C:\WINNT\System32\searchsetter[1].exe
    O4 - HKCU\..\Run: [Hhsc] C:\Documents and Settings\Administrator\Application Data\rddt.exe
    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    After doing ALL of the above if you still have a problem

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ,

    Shalom already stated that all the required steps of the sticky have been run.


    Shalom,

    Goto Add/Remove programs and uninstall the below two programs. They are rogue/suspect spyware removal tools doing you more harm than good (they are really the same program with different names):
    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan

    After that post your version 1.99 HijackThis log as an attachment to your next message. Do not post your log inline and post the complete log (which includes the process list) not a partial?
     
  4. shalom

    shalom Private E-2

    The 2 programs do not appear among the add/remove list and they were brought in by the owner of the computer (it's my neighbor's) after the initial infection.
    Attached are 2 logs - the first after doing all the required steps and the second right after reconnecting,.
    If I don't reconnect the log stays as the first but that means no internet.
    So I assume something waits for the connection and then ...wammo.
    What is it?
    Good luck to all
    Shalom
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    FIRST, Make sure "System Restore" is temporarily disabled

    Now, lets have HJT fix a few entries. Please close all browsers before fixing anything with HJT. Remove the below entries:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
    O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1018.dll,InstantAccess
    O4 - HKCU\..\Run: [mslagent] C:\WINNT\mslagent\mslagent.exe
    O4 - HKCU\..\Run: [SearchSetter] C:\WINNT\System32\searchsetter[1].exe
    O4 - HKCU\..\Run: [Hhsc] C:\Documents and Settings\Administrator\Application Data\rddt.exe
    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan


    After you remove these entries, download the following tools.

    About:Buster 4.0

    HSRemove 2.40



    Run both of these tools, reboot and post new HJT log.

    NOTE: Probably would be a good idea to download the latest security updates for you OS. Microsoft Windows Updates
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ,

    You must remember to complete the cleanups! You cannot just fix items in HJT and leave the files and folders on the computer. Finish deleting all the malware files to avoid reinfection.

    Also, the wrong version of HJT is being used and the READ ME FIRST WAS NOT RUN (at least not completely).
     
  7. shalom

    shalom Private E-2

    BJ - it's windows 2k -there is no system restore.
    Chaslang - I deleted the temp...sp.html and all the temporary internet files and instant access files.
    I believe there is a dll somewhere in system32 that keeps regenerating the stuff,but have no ideahow to locate it.
    I used about buster 3 with list 21, I'll get v.4 and try again but I don't think that's the key.
    What did I miss in the read me first (you write "at least not completely")
    Let you know in about 12 hours.
    Shalom
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Sorry, Have posted many times today most of which were WinXP sorry for the mix up. I will get back with you on this tomorrow if I dont chaslang will be back, I must get some rest!
     
  9. shalom

    shalom Private E-2

    Using HJT 1.99 and buster 4 list 21 and hsremove 2.40 and all else updated the results were the same. I believe I removed any problem related file and reg entry .
    Upon reboot the registry changed and upon connection we were back to the big black warning screen and spyware windows popping up as before.
    Perhaps from the log you will find an 023 service or something else to be handled to solve this.
    I also searched any dlls in the system folder that changed in the last week and moved them. Did not help.
    names of shortcuts that crop up are "protect your data!" "Protect yourself"
    and a desktop.html in c:\winnt that can be temporarily neutralized by erasing the web page for it in active desktop.
    Many thanks
    Shalom
     

    Attached Files:

  10. shalom

    shalom Private E-2

    Smart security infection (was sp.html about:blank p2esocks)

    Seems the infection is caused by Smart-Security spyware (manufacturers) .
    It takes over the desktop with an active desktop (security.html), makes your homepage "about:blank" (sp.html) and adds mstasks1-4 to your computer.
    A bogus removal tool adds freescan.exe which makes matters worse.
    An indecisive discussion of this appears in the following link:
    http://www.thetechguide.com/forum/index.php?showtopic=10600&st=80
    This is a major part of the problem with my neighbor's computer.
    Anyone out there have suggestions as how to remove it?
    Thanks in advance
    Shalom
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Smart security infection (was sp.html about:blank p2esocks)

    Go back and look at what I said in message number 3.
    You never removed them when I asked.
    They are still in your HJT log. In fact based on your HJT log it does not look like you made any of the changes I or BJ requested.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Smart security infection (was sp.html about:blank p2esocks)

    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O4 - HKLM\..\Run: [xBwu] C:\WINNT\jmjpvc.exe
    O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
    O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1018.dll,InstantAccess
    O4 - HKCU\..\Run: [mslagent] C:\WINNT\mslagent\mslagent.exe
    O4 - HKCU\..\Run: [SearchSetter] C:\WINNT\System32\searchsetter[1].exe
    O4 - HKCU\..\Run: [Hhsc] C:\Documents and Settings\Administrator\Application Data\rddt.exe
    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
    O15 - Trusted IP range: (HKLM)

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Administrator\Local Settings\Temp <--- delete all files in this folder
    C:\WINNT\jmjpvc.exe
    C:\Program Files\Windows ServeAd <--- the whole folder
    C:\WINNT\\system32\p2esocks_1018.dll
    C:\WINNT\mslagent\mslagent.exe
    C:\WINNT\System32\searchsetter[1].exe
    C:\Documents and Settings\Administrator\Application Data\rddt.exe
    C:\spywarevanisher-free <--- the whole folder
    C:\freescan <--- the whole folder

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    I don't understand why HijackThis is showing all those standard Windows services. They do not normally show.
     
  13. shalom

    shalom Private E-2

    Re: Smart security infection (was sp.html about:blank p2esocks)

    Except for rddt.exe (which I keep erasing) all the other files don't show and so cannot be erased.
    Yes, I have set per tutorial for all directories:
    Show Hidden files and folders .
    Show File extensions for known types .
    Show System files .
    I'll check tomorrow on the infected computer for the files "mstasks1 thru 4" (that are referred to in an article from a different forum) and if they show will delete them.
    It's extraordinary that when I am offline and in safe mode I can try to change the registry,say,delete the entries for sp.html, using either HJT-fix or using regedit and even before reconnecting the entry reappears and the page doesn't. When I connect the page does show,so it seems it's coming from the internet.
    And no, I'm not on drugs.
    Thanks,
    Shalom
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Smart security infection (was sp.html about:blank p2esocks)

    That is typically of the about:blank hijack. You more than likely have an AppInit_DLL or another hidden DLL we need to find.

    You should have posted your HJT log as requested after the last set of instructions so we could continue with the cleanup.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Smart security infection (was sp.html about:blank p2esocks)

    Go here and download Registrar Lite and install it: http://www.majorgeeks.com/download469.html

    1) Run Registrar Lite
    2) Copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls and tell me exactly what you see in the Value field:
     
  16. shalom

    shalom Private E-2

    Re: Smart security infection

    value field is empty.blank.
    Aside from:
    Network Security Service
    Workstation Netlogon Service
    Remote Procedure Call (RPC) Helper
    could there be a different service that kicks in when an internet connection is made?
    If not I think the bastards have won and we'll re-install, much as it hurts.
    Thanks for your time, effort and patience
    Shalom
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Smart security infection

    You still have not posted that HJT log I asked for.

    Anything is possible, it originally was only Network Security Service in the very beginning.
    Don't re-install yet.

    Download FINDnFIX from here: http://downloads.subratam.org/FINDnFIX.exe

    Run FINDnFIX.exe, it will extract some files to a folder called c:\findnfix
    Use Windows Explorer to bring that directory up. Now if necessary print the remaining instructions because you will be disconnecting from the Internet in the next step. I want you to physically unplug your analog modem phone line or ADSL/Cable modem ethernet cable to your PC so that there is no way any running program get get access to the Internet from your PC.

    Disconnect your network connection now and exit all browser sessions!

    In the c:\findnfix directory double click on the file !log!.bat
    This will run the program and it will create a log.txt file (it will also pop up in notepad when done). Be patient, it takes a little while for it to scan thru all the files it needs to look for.

    When it is finished, reboot your PC and reconnect your network connection.
    Come back here and post as an Attachment your log.txt file from FINDnFIX


    Also download GetService.zip from here: Getservice.zip

    Extract the file to a folder where you can find it, then go to the folder and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad file as an attachment too. Call it service.txt.
     
    Last edited: Jan 3, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds