FacebookTwitter
Hatrack River Forum   
my profile login | search | faq | forum home

  next oldest topic   next newest topic
» Hatrack River Forum » Active Forums » Books, Films, Food and Culture » Spyware problems; hijackthis help

   
Author Topic: Spyware problems; hijackthis help
Gosu
Member
Member # 5783

 - posted      Profile for Gosu   Email Gosu         Edit/Delete Post 
A week ago, my computer was absolutely flooded with spyware. I started looking up everything on this kind of stuff, and I fixed basically everything I could with normal deleting, ad-aware, msconfig, etc. However, there's some file, registry value, something that makes Internet Explorer randomely connect to some poker/"anti-adware"/advertisement page even when my browser is closed. And it keeps going, so if I leave my computer for like 5 minutes, I come back to find that 10 IE windows are open.

So obviously, the last thing I need to do is fix it with hijackthis. I ran a scan, analyzed what it gave me, then deleted some stuff. I thought I'd won. I didn't. The ads keep popping up, and what's even more annoying is that one of the files that comes up on the report is called "Extra button: Your computer is infected with spyware." Every time I try to have hijackthis fix this, it reappears next time. There's something I'm not doing. I think it has to do with either the registry edit or another file I'm not deleting in the report. So if someone could either tell me what to delete, I'd appreciate it. Here's my report:

Logfile of HijackThis v1.98.2
Scan saved at 5:57:55 PM, on 11/6/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSGLOOP.EXE
C:\WINDOWS\SYSTEM\MSG32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\WINVVX32.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\AIM\AIM.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MY DOCUMENTS\HTML FILES\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\Program Files\DirectCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [Sys29] C:\WINDOWS\SYSTEM\WINVVX32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
O9 - Extra button: Your PC is infected with Spyware - click here to fix your PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} - https://www.spydeleter.com/order2.php?KBID=1062https://www.spydeleter.com/order2.php?KBID=1062[/URL] (file missing)
O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab]http://objects.compuserve.com/chat/RTCChat.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cabhttp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab]http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab[

[ November 06, 2004, 06:03 PM: Message edited by: Gosu ]

Posts: 102 | Registered: Oct 2003  |  IP: Logged | Report this post to a Moderator
Alucard...
Member
Member # 4924

 - posted      Profile for Alucard...   Email Alucard...         Edit/Delete Post 
Hey, my boy Joe helps moderate WindowsXPCentral.com and there are several XP gurus there. I have forwarded on this page to have them find a solution, hopefully.
Posts: 1870 | Registered: Mar 2003  |  IP: Logged | Report this post to a Moderator
Gosu
Member
Member # 5783

 - posted      Profile for Gosu   Email Gosu         Edit/Delete Post 
No, I still use Windows 98...don't ask why.
Posts: 102 | Registered: Oct 2003  |  IP: Logged | Report this post to a Moderator
Phanto
Member
Member # 5897

 - posted      Profile for Phanto           Edit/Delete Post 
Do ctrl-al-dlt. What programs are running?
Posts: 3060 | Registered: Nov 2003  |  IP: Logged | Report this post to a Moderator
Alucard...
Member
Member # 4924

 - posted      Profile for Alucard...   Email Alucard...         Edit/Delete Post 
Micron is the man, and I am sure he knows 98 as well...
Posts: 1870 | Registered: Mar 2003  |  IP: Logged | Report this post to a Moderator
quidscribis
Member
Member # 5124

 - posted      Profile for quidscribis   Email quidscribis         Edit/Delete Post 
Go to here and download Spybot Search and Destroy. Run it on your computer. It will get rid of all your adware/spyware for you.

It also has an immunize feature that I'd strongly advise you use afterwards to protect your computer from future adware/spyware.

Good luck and let us know how it goes.

Posts: 8355 | Registered: Apr 2003  |  IP: Logged | Report this post to a Moderator
TMedina
Member
Member # 6649

 - posted      Profile for TMedina   Email TMedina         Edit/Delete Post 
When you run Ad-Aware and Spybot S&D, do it from a "safe mode" boot.

Also, try and close "WINVVX32.EXE" - I have a sneaking suspicion this is the sneaky bastard responsible.

Although, to be fair, I'm not sure what "MSGLOOP" is, either.

I see you're running a "hijack this" program - does your machine have a firewall running? That can be useful for tagging specific program files trying to access the 'net.

Also, just purge your Temporary Internet Files - when I had to trouble-shoot my aunt and uncle's machine, there were 8 trojans lurking.

-Trevor

Posts: 5413 | Registered: Jun 2004  |  IP: Logged | Report this post to a Moderator
newfoundlogic
Member
Member # 3907

 - posted      Profile for newfoundlogic   Email newfoundlogic         Edit/Delete Post 
I would use ad-aware, its possible the anti-adware you're currently using is part of the problem. I would also recommend against Spybot because I've heard bad things about that.
Posts: 3446 | Registered: Jul 2002  |  IP: Logged | Report this post to a Moderator
Boris
Member
Member # 6935

 - posted      Profile for Boris   Email Boris         Edit/Delete Post 
Okay, kill these

C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSGLOOP.EXE
C:\WINDOWS\SYSTEM\MSG32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WINVVX32.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE

O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Sys29] C:\WINDOWS\SYSTEM\WINVVX32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

You also have a Virus on your system. Norton won't catch it, but
AVG probably will. I've used it to get rid of similar problems on over 100 computers. There is a free version (You may have to dig through the site a little to find it, though), it works better than Norton IMO. It is slightly crippled (Won't run in safe mode(, but that shouldn't affect you too much. With Win98 it has a boot scanner that is kind of annoying, so you can keep that on or turn it off. Anyway, good luck.

Posts: 3003 | Registered: Oct 2004  |  IP: Logged | Report this post to a Moderator
Gosu
Member
Member # 5783

 - posted      Profile for Gosu   Email Gosu         Edit/Delete Post 
A virus....how?
Posts: 102 | Registered: Oct 2003  |  IP: Logged | Report this post to a Moderator
Chris Bridges
Member
Member # 1138

 - posted      Profile for Chris Bridges   Email Chris Bridges         Edit/Delete Post 
The best way to use HijackThis is to run it, and open a browser window. Look for any program or file name you don't recognize and type it into Google. Odds are that some of them will bring up links to anti-virus or anti-spyware sites talking about them.

You can also check here: http://www.answersthatwork.com/Tasklist_pages/tasklist.htm for a list of programs you might see and whether or not you need/should fear them.

Posts: 7790 | Registered: Aug 2000  |  IP: Logged | Report this post to a Moderator
quidscribis
Member
Member # 5124

 - posted      Profile for quidscribis   Email quidscribis         Edit/Delete Post 
See? You ask a little question, and all of a sudden, all the geeks come out. Don't put the light on, though, or they'll all scatter. Shh!
Posts: 8355 | Registered: Apr 2003  |  IP: Logged | Report this post to a Moderator
Boris
Member
Member # 6935

 - posted      Profile for Boris   Email Boris         Edit/Delete Post 
quote:
A virus....how?
It isn't "technically" a virus, which is why Norton won't grab it. I've seen programs that are downloaded automatically from certain websites which will change the way your web browser works. One required a scan with Ad-Aware, a virus-scan, and a change in home-page for IE. It was a pain to get rid of because it pointed IE's homepage to a page that downloaded the program if it wasn't detected.
Posts: 3003 | Registered: Oct 2004  |  IP: Logged | Report this post to a Moderator
TMedina
Member
Member # 6649

 - posted      Profile for TMedina   Email TMedina         Edit/Delete Post 
You have to carry a massive bag of tricks just to catch the spyware, never mind the bugs.

-Trevor

Posts: 5413 | Registered: Jun 2004  |  IP: Logged | Report this post to a Moderator
Tammy
Member
Member # 4119

 - posted      Profile for Tammy   Email Tammy         Edit/Delete Post 
Thanks for the link Chris.

I looked up everything currently running on my computer and found everything except this...mnyexpr.exe.

Does anyone have any idea what it is?

Posts: 3771 | Registered: Sep 2002  |  IP: Logged | Report this post to a Moderator
quidscribis
Member
Member # 5124

 - posted      Profile for quidscribis   Email quidscribis         Edit/Delete Post 
It looks like a Microsoft Money executable.

Whenever I find programs on my taskmanager that I don't know what they are and need to know, I google them. The results tell me whether it's friendly or malicious.

Posts: 8355 | Registered: Apr 2003  |  IP: Logged | Report this post to a Moderator
Tammy
Member
Member # 4119

 - posted      Profile for Tammy   Email Tammy         Edit/Delete Post 
Thank you! I'll google next time. [Smile]

I forget how wonderful Google is!

Posts: 3771 | Registered: Sep 2002  |  IP: Logged | Report this post to a Moderator
Nato
Member
Member # 1448

 - posted      Profile for Nato   Email Nato         Edit/Delete Post 
quote:
O9 - Extra button: Your PC is infected with Spyware - click here to fix your PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} - ]https://www.spydeleter.com/order2.php?KBID=1062https://www.spydeleter.com/ order2.php?KBID=1062[/URL] (file missing)
That looks like a problem. (info) Get rid of it.

Also, be careful disabling a lot of tasks as Boris woudl have you do. I imagine you want your system tray to run when your computer starts up, and don't kill taskmon, that's just the task monitor.

[ November 07, 2004, 08:45 PM: Message edited by: Nato ]

Posts: 1592 | Registered: Jan 2001  |  IP: Logged | Report this post to a Moderator
Boris
Member
Member # 6935

 - posted      Profile for Boris   Email Boris         Edit/Delete Post 
system tray runs without systray.exe. It's a waste of memory, taskmon is the same way.
Posts: 3003 | Registered: Oct 2004  |  IP: Logged | Report this post to a Moderator
   

   Close Topic   Feature Topic   Move Topic   Delete Topic next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:


Contact Us | Hatrack River Home Page

Copyright © 2008 Hatrack River Enterprises Inc. All rights reserved.
Reproduction in whole or in part without permission is prohibited.


Powered by Infopop Corporation
UBB.classic™ 6.7.2