IE 5.5 suddenly has a mind of it's own….along with popups stating my computer is infected with spyware. Popup blocker catches them but my home page keeps changing to an unfamiliar search page. This page also replaces my viewed page at it's own discretion and appears as "about:blank". AVG shows no infected files. Spybot finds and destroys it but it's back as soon as I open the browser again.
Any advice on what to delete would be appreciated. Thanks!!
Logfile of HijackThis v1.98.2
Scan saved at 3:20:21 PM, on 9/22/04
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.50 (5.50.4134.0600)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\TELEPATH.101\telepath.exe
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\REAL\PLAYPLUS\REALPLAY.EXE
C:\AFTERDRK\ADTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\AIM95\AIM.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\AMERICA ONLINE 5.0\AOLTRAY.EXE
C:\EPSTYLUS\EPSAG595.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\DESKTOP\HIJACKTH.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F1 - win.ini: load=c:\afterdrk\adw30.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {E6182A81-057B-11D9-9264-6096E247BD1B} - C:\WINDOWS\SYSTEM\FNFLHEA.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [TIPS] C:\MSINPUT\tips\mouse\tips.exe
O4 - HKLM\..\Run: [POINTER] C:\MSINPUT\POINT32.EXE
O4 - HKLM\..\Run: [RealTray] C:\REAL\PLAYPLUS\REALPLAY.EXE SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ADQuickAccess] C:\AFTERDRK\ADTRAY.EXE
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [Welcome] C:\WINDOWS\Welcome.exe /R
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\RunServices: [TelePath] C:\WINDOWS\SYSTEM\TELEPATH.101\telepath.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - Startup: America Online 5.0 Tray Icon.lnk = C:\America Online 5.0\aoltray.exe
O4 - Startup: EPSON Instant Solutions.lnk = C:\EPSTYLUS\EPSAG595.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O13 - WWW. Prefix: http://
O16 - DPF: Win32 Classes - file://C:\WINDOWS\Java\classes\win32ie4.cab
O18 - Filter: text/html - {E6182A80-057B-11D9-9264-60968D0B1880} - C:\WINDOWS\SYSTEM\FNFLHEA.DLL
O18 - Filter: text/plain - {E6182A80-057B-11D9-9264-60968D0B1880} - C:\WINDOWS\SYSTEM\FNFLHEA.DLL
Do this for me.
Download StartDreck from
here . Unzip to its own folder and start the program:
Press 'Config'
Press 'Unmark All'
Check the following boxes only:
Registry -> Run Keys
System/drivers> Running processes
Press 'Ok'. Press 'Save' and select the location to save the log file (default is the same folder as the application). Post the log in this thread.
Click
here to download DllCompare. Start the Program with and click the
Run Locate.com - be sure the \Windows\System directory is in the box and wait until the the blue text says it has 'completed the scan'.
Click the
Compare button to start the next process. The results appear in two panes - files in the upper pane have been verified to
'exist' , files in the lower pane were
'not able to be accessed' . Very few files should be listed in the lower pane when the Compare scan is complete. Click on each of the listed entries in the lower pane to select them. Right-click on the file and use the option
Rescan . This will cause Windows Find to see if the file does exist, and then if so it will be removed from the list to reduce the number of identified files.
Click the
Make a Log of what was found button and post the log here in this thread and wait for further instructions.
Thanks so much for your help! Here are the logs:
StartDreck (build 2.1.7 public stable) - 2004-09-24 @ 14:30:41 (GMT -05:00)
Platform: Windows 98 (Win 4.10.1998 )
Internet Explorer: 5.50.4134.0600
Logged in as bob002 at SHOP
»Registry
»Run Keys
»Current User
»Run
*MSMSGS=C:\Program Files\Messenger\msmsgs.exe /background
*AIM=C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
*Spyware Begone=C:\FREESCAN\FREESCAN.EXE -FastScan
*PopUpStopperFreeEdition="C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
»RunOnce
»Default User
»Run
*MSMSGS=C:\Program Files\Messenger\msmsgs.exe /background
*AIM=C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
*Spyware Begone=C:\FREESCAN\FREESCAN.EXE -FastScan
*PopUpStopperFreeEdition="C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
»RunOnce
»Local Machine
»Run
*SystemTray=SysTray.Exe
*TIPS=C:\MSINPUT\tips\mouse\tips.exe
*POINTER=C:\MSINPUT\POINT32.EXE
*RealTray=C:\REAL\PLAYPLUS\REALPLAY.EXE SYSTEMBOOTHIDEPLAYER
*ADQuickAccess=C:\AFTERDRK\ADTRAY.EXE
*mdac_runonce=C:\WINDOWS\SYSTEM\runonce.exe
*Welcome=C:\WINDOWS\Welcome.exe /R
*ScanRegistry=C:\WINDOWS\scanregw.exe /autorun
*TaskMonitor=C:\WINDOWS\taskmon.exe
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*AVG_CC=C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
»RunOnce
»RunServices
*TelePath=C:\WINDOWS\SYSTEM\TELEPATH.101\telepath.exe
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*SchedulingAgent=C:\WINDOWS\SYSTEM\mstask.exe
*Avgserv9.exe=C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»Files
»System/Drivers
»Running Processes
+FFCFBF23=C:\WINDOWS\SYSTEM\KERNEL32.DLL
+FFFF88B7=C:\WINDOWS\SYSTEM\MSGSRV32.EXE
+FFFFFE47=C:\WINDOWS\SYSTEM\MPREXE.EXE
+FFFFE523=C:\WINDOWS\SYSTEM\mmtask.tsk
+FFFFC67F=C:\WINDOWS\SYSTEM\TELEPATH.101\telepath.exe
+FFFFC777=C:\WINDOWS\SYSTEM\MSTASK.EXE
+FFFE716F=C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
+FFFE394F=C:\WINDOWS\EXPLORER.EXE
+FFFE8E53=C:\WINDOWS\SYSTEM\SYSTRAY.EXE
+FFFD260B=C:\REAL\PLAYPLUS\REALPLAY.EXE
+FFFE9153=C:\AFTERDRK\ADTRAY.EXE
+FFFD5F23=C:\WINDOWS\TASKMON.EXE
+FFFDB16B=C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
+FFFD9043=C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
+FFFDF2E7=C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
+FFFC3FB3=C:\AMERICA ONLINE 5.0\AOLTRAY.EXE
+FFFFC51B=C:\EPSTYLUS\EPSAG595.EXE
+FFFAA043=C:\WINDOWS\SYSTEM\DDHELP.EXE
+FFF998A7=C:\WINDOWS\SYSTEM\SPOOL32.EXE
+FFF9B23F=C:\MY DOCUMENTS\STARTDRECK\STARTDRE.EXE
»Application specific
* DLLCompare Log version(1.0.0.125)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
O^E says: "There were no files found
"
________________________________________________
771 items found: 771 files, 0 directories.
Total of file sizes: 117,551,799 bytes 112.11 M
——————–End log———————
Good. Click
here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.
Click
here to download Ad-Aware SE and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Then click the gear wheel at the top and make sure these options are checked green:
General>: "Automatically save log-file" and "Automatically quarantine objects prior to removal".
Scanning>: "Scan within archives", "Scan active processes", "Scan registry", "Deep-scan registry", "Scan my IE Favorites for banned URLs" and "Scan my Hosts file".
Tweaks> Scanning Engine>: "Unload recognized processes during scanning", "Ignore spanned files when scanning cab archives" and "Scan registry for all users instead of current user only".
Tweaks> Cleaning Engine>: "Automatically try to unload modules before deletion", "During removal, unload Explorer and IE if necessary", "Let Windows remove files in use at next reboot" and "Delete quanatined objects after restoring".
Click "Proceed" to save your settings, then click "Start", select "Perform Full System scan" and "Next" to start the scan. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".
Reboot when done. Rescan with HJT and post a new log here so that any remnants can be removed manually.
Done. Just a couple things to mention, when selecting preferences in ad adware (tweaks) "ignore spanned files when scanning cab archives" was checked but not in green, could not change that or uncheck it by clicking on it. Also I could not change the x to a check under cleaning engine "during removal unload explorer and IE is necessary". Also AVG virus alert came up on two different files, I selected yes to allow ad aware access to the infected files, OK?? Here's the new log:
Logfile of HijackThis v1.98.2
Scan saved at 7:34:31 PM, on 9/24/04
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.50 (5.50.4134.0600)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\TELEPATH.101\telepath.exe
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\REAL\PLAYPLUS\REALPLAY.EXE
C:\AFTERDRK\ADTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\AIM95\AIM.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\AMERICA ONLINE 5.0\AOLTRAY.EXE
C:\EPSTYLUS\EPSAG595.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\MY DOCUMENTS\HJT\HIJACKTH.EXE
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [TIPS] C:\MSINPUT\tips\mouse\tips.exe
O4 - HKLM\..\Run: [POINTER] C:\MSINPUT\POINT32.EXE
O4 - HKLM\..\Run: [RealTray] C:\REAL\PLAYPLUS\REALPLAY.EXE SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ADQuickAccess] C:\AFTERDRK\ADTRAY.EXE
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [Welcome] C:\WINDOWS\Welcome.exe /R
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\RunServices: [TelePath] C:\WINDOWS\SYSTEM\TELEPATH.101\telepath.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - Startup: America Online 5.0 Tray Icon.lnk = C:\America Online 5.0\aoltray.exe
O4 - Startup: EPSON Instant Solutions.lnk = C:\EPSTYLUS\EPSAG595.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O13 - WWW. Prefix: http://
With only HJT running, have it fix:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan
Reboot and you should be good to go. How is it running now?
Looks good so far! I can't thank you enough, you are amazing!! Think about how many hours of wasted time "about:blank" has caused, it boggles the mind.
Thanks again!!
Bob
You're welcome - glad to help
To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
The subject of the email must be "Reopen" . Include your post username and details about why you need it reopened, with a valid link to your post.