This is topic Spyware problems; hijackthis help in forum Books, Films, Food and Culture at Hatrack River Forum.


To visit this topic, use this URL:
http://www.hatrack.com/ubb/main/ultimatebb.php?ubb=get_topic;f=2;t=028945

Posted by Gosu (Member # 5783) on :
 
A week ago, my computer was absolutely flooded with spyware. I started looking up everything on this kind of stuff, and I fixed basically everything I could with normal deleting, ad-aware, msconfig, etc. However, there's some file, registry value, something that makes Internet Explorer randomely connect to some poker/"anti-adware"/advertisement page even when my browser is closed. And it keeps going, so if I leave my computer for like 5 minutes, I come back to find that 10 IE windows are open.

So obviously, the last thing I need to do is fix it with hijackthis. I ran a scan, analyzed what it gave me, then deleted some stuff. I thought I'd won. I didn't. The ads keep popping up, and what's even more annoying is that one of the files that comes up on the report is called "Extra button: Your computer is infected with spyware." Every time I try to have hijackthis fix this, it reappears next time. There's something I'm not doing. I think it has to do with either the registry edit or another file I'm not deleting in the report. So if someone could either tell me what to delete, I'd appreciate it. Here's my report:

Logfile of HijackThis v1.98.2
Scan saved at 5:57:55 PM, on 11/6/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSGLOOP.EXE
C:\WINDOWS\SYSTEM\MSG32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\WINVVX32.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\AIM\AIM.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MY DOCUMENTS\HTML FILES\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\Program Files\DirectCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [Sys29] C:\WINDOWS\SYSTEM\WINVVX32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
O9 - Extra button: Your PC is infected with Spyware - click here to fix your PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} - https://www.spydeleter.com/order2.php?KBID=1062https://www.spydeleter.com/order2.php?KBID=1062[/URL] (file missing)
O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab]http://objects.compuserve.com/chat/RTCChat.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cabhttp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab]http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab[

[ November 06, 2004, 06:03 PM: Message edited by: Gosu ]
 
Posted by Alucard... (Member # 4924) on :
 
Hey, my boy Joe helps moderate WindowsXPCentral.com and there are several XP gurus there. I have forwarded on this page to have them find a solution, hopefully.
 
Posted by Gosu (Member # 5783) on :
 
No, I still use Windows 98...don't ask why.
 
Posted by Phanto (Member # 5897) on :
 
Do ctrl-al-dlt. What programs are running?
 
Posted by Alucard... (Member # 4924) on :
 
Micron is the man, and I am sure he knows 98 as well...
 
Posted by quidscribis (Member # 5124) on :
 
Go to here and download Spybot Search and Destroy. Run it on your computer. It will get rid of all your adware/spyware for you.

It also has an immunize feature that I'd strongly advise you use afterwards to protect your computer from future adware/spyware.

Good luck and let us know how it goes.
 
Posted by TMedina (Member # 6649) on :
 
When you run Ad-Aware and Spybot S&D, do it from a "safe mode" boot.

Also, try and close "WINVVX32.EXE" - I have a sneaking suspicion this is the sneaky bastard responsible.

Although, to be fair, I'm not sure what "MSGLOOP" is, either.

I see you're running a "hijack this" program - does your machine have a firewall running? That can be useful for tagging specific program files trying to access the 'net.

Also, just purge your Temporary Internet Files - when I had to trouble-shoot my aunt and uncle's machine, there were 8 trojans lurking.

-Trevor
 
Posted by newfoundlogic (Member # 3907) on :
 
I would use ad-aware, its possible the anti-adware you're currently using is part of the problem. I would also recommend against Spybot because I've heard bad things about that.
 
Posted by Boris (Member # 6935) on :
 
Okay, kill these

C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSGLOOP.EXE
C:\WINDOWS\SYSTEM\MSG32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WINVVX32.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE

O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Sys29] C:\WINDOWS\SYSTEM\WINVVX32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

You also have a Virus on your system. Norton won't catch it, but
AVG probably will. I've used it to get rid of similar problems on over 100 computers. There is a free version (You may have to dig through the site a little to find it, though), it works better than Norton IMO. It is slightly crippled (Won't run in safe mode(, but that shouldn't affect you too much. With Win98 it has a boot scanner that is kind of annoying, so you can keep that on or turn it off. Anyway, good luck.
 
Posted by Gosu (Member # 5783) on :
 
A virus....how?
 
Posted by Chris Bridges (Member # 1138) on :
 
The best way to use HijackThis is to run it, and open a browser window. Look for any program or file name you don't recognize and type it into Google. Odds are that some of them will bring up links to anti-virus or anti-spyware sites talking about them.

You can also check here: http://www.answersthatwork.com/Tasklist_pages/tasklist.htm for a list of programs you might see and whether or not you need/should fear them.
 
Posted by quidscribis (Member # 5124) on :
 
See? You ask a little question, and all of a sudden, all the geeks come out. Don't put the light on, though, or they'll all scatter. Shh!
 
Posted by Boris (Member # 6935) on :
 
quote:
A virus....how?
It isn't "technically" a virus, which is why Norton won't grab it. I've seen programs that are downloaded automatically from certain websites which will change the way your web browser works. One required a scan with Ad-Aware, a virus-scan, and a change in home-page for IE. It was a pain to get rid of because it pointed IE's homepage to a page that downloaded the program if it wasn't detected.
 
Posted by TMedina (Member # 6649) on :
 
You have to carry a massive bag of tricks just to catch the spyware, never mind the bugs.

-Trevor
 
Posted by Tammy (Member # 4119) on :
 
Thanks for the link Chris.

I looked up everything currently running on my computer and found everything except this...mnyexpr.exe.

Does anyone have any idea what it is?
 
Posted by quidscribis (Member # 5124) on :
 
It looks like a Microsoft Money executable.

Whenever I find programs on my taskmanager that I don't know what they are and need to know, I google them. The results tell me whether it's friendly or malicious.
 
Posted by Tammy (Member # 4119) on :
 
Thank you! I'll google next time. [Smile]

I forget how wonderful Google is!
 
Posted by Nato (Member # 1448) on :
 
quote:
O9 - Extra button: Your PC is infected with Spyware - click here to fix your PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} - ]https://www.spydeleter.com/order2.php?KBID=1062https://www.spydeleter.com/ order2.php?KBID=1062[/URL] (file missing)
That looks like a problem. (info) Get rid of it.

Also, be careful disabling a lot of tasks as Boris woudl have you do. I imagine you want your system tray to run when your computer starts up, and don't kill taskmon, that's just the task monitor.

[ November 07, 2004, 08:45 PM: Message edited by: Nato ]
 
Posted by Boris (Member # 6935) on :
 
system tray runs without systray.exe. It's a waste of memory, taskmon is the same way.
 


Copyright © 2008 Hatrack River Enterprises Inc. All rights reserved.
Reproduction in whole or in part without permission is prohibited.


Powered by Infopop Corporation
UBB.classic™ 6.7.2