annoying and invisible internet explorer

Discussion in 'privacy problems' started by Name, Aug 8, 2003.

Thread Status:
Not open for further replies.
  1. Name
    Offline

    Name Guest

    there's an invisible internet explorer that's keep on popping up on my computer. its not visible on my computer screen but you can tell its there because if you press alt+tab, it's icon appears. its also not visible on my taskbar or the windows task manager. ever few seconds or so it'll pop up and then it'll close automatically. its real real annoying because it prevents me from playing my fullscreen online game because ever second it'll pop up again and i end up on my desktop. and while i'm browsing through the interent, i have to click on the taskbar to return to where i last was. someone please help.

    i used Hijack This and i was wondering if anyone can tell me what my problem is.

    Logfile of HijackThis v1.96.0
    Scan saved at 3:28:59 AM, on 8/8/2003
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\brss01a.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\System32\S3apphk.exe
    C:\WINDOWS\wt\updater\wcmdmgr.exe
    C:\PROGRA~1\Save\Save.exe
    C:\WINDOWS\System32\kernel32.dlI
    C:\WINDOWS\System32\CMMON32.EXE
    C:\Program Files\WinMX\WinMX.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\AnVir Virus Destroyer\AnVir.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.search-explorer.net/search_page.php
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxycfg.marketscore.com/gencfg.asp?id1=El$ejvwjNh7&id2=U280wbz8Xb9&lp=1&nsv=5.2.4.5
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
    R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)
    N2 - Netscape 6: user_pref("browser.startup.homepage", "about:blank"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\796yrcno.slt\prefs.js)
    O1 - Hosts: 64.14.40.138 www.searchalot.com
    O1 - Hosts: 64.14.40.138 searchalot.com
    O1 - Hosts: 66.218.71.198 yahoo.com
    O1 - Hosts: 216.109.125.66 www.yahoo.com
    O1 - Hosts: 207.68.173.245 www.hotmail.com
    O1 - Hosts: 64.4.52.7 hotmail.com
    O1 - Hosts: 207.68.172.234 www.msn.com
    O1 - Hosts: 207.68.172.246 msn.com
    O1 - Hosts: 64.12.187.24 aol.com
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
    O3 - Toolbar: BONZI.COM Web Compass - {71B8AB7E-CB3F-4471-878E-8E1DFDF49B8B} - C:\Program Files\BONZI.COM Web Compass\WebCompassBar.dll (file missing)
    O3 - Toolbar: &Search Toolbar - {702AD576-FDDB-4d0f-9811-A43252064684} - C:\Program Files\Common Files\OE\toolbar.dll (file missing)
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
    O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
    O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
    O4 - HKLM\..\Run: [FSW] C:\Program Files\FSW\FSW.EXE
    O4 - HKLM\..\Run: [OrbitUpdate] C:\Program Files\Orbit\update.exe
    O4 - HKLM\..\Run: [OrbitView] C:\Program Files\Orbit\view.exe
    O4 - HKLM\..\Run: [win32app] C:\WINDOWS\System32\winpup32.exe
    O4 - HKLM\..\Run: [kernel32] C:\WINDOWS\System32\kernel32.dlI
    O4 - HKLM\..\Run: [SysComp] C:\WINDOWS\System32\msmrra.com
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Zero Knowledge Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [AIM] C:\Program Files\aim95(3)\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [AnVir Virus Destroyer] "C:\Program Files\AnVir Virus Destroyer\AnVir.exe" Minimized
    O4 - Startup: ModemBoost.lnk = C:\Program Files\ModemBoost\mboost.exe
    O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
    O4 - Global Startup: QuickLink Desktop.lnk = C:\Program Files\QuickLink Desktop\QuickLink Desktop.exe
    O9 - Extra button: MktBrowser (HKLM)
    O9 - Extra 'Tools' menuitem: MarketBrowser (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: HuntBar (HKLM)
    O9 - Extra button: Popup Eliminator (HKLM)
    O9 - Extra 'Tools' menuitem: Popup Eliminator (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: MoneySide (HKLM)
    O10 - Broken Internet access because of LSP provider 'csloa.dll' missing
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F96A5A76-3D9B-41C5-828B-2738B0045ED9}: NameServer = 216.194.28.33 216.194.28.69
  2. LowWaterMark
    Offline

    LowWaterMark Administrator

    Hello Name,

    There are potentially a number of problems in that log, but, I'll leave the hijacks and such to others who are more familiar with that type of thing. One thing has caught my eye and that is this:

    Running processes:
    C:\WINDOWS\System32\kernel32.dlI

    and...

    O4 - HKLM\..\Run: [kernel32] C:\WINDOWS\System32\kernel32.dlI

    Notice that the last character in that is an "i" (eye) not an "l" (el). That most likely is a serious infection (likely a Netdevil trojan). I strongly recommend ending that kernel32.dli process and running a few different malware scans. Perhaps starting with the Panda Online scan at:

    http://www.pandasoftware.com/activescan/activescan.asp?Language=2&Country=63&Partner=1&Ref=EN-PR-AS-107

    Other will be along to help with the rest of the log and to make other suggestions, such as running an Anti-Trojan product like TDS-3 or Trojan Hunter.
  3. LowWaterMark
    Offline

    LowWaterMark Administrator

  4. Pieter_Arntz
    Online

    Pieter_Arntz Spyware Veteran

    Hi Name,

    Assuming you already got rid of the trojan, check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.search-explorer.net/search_page.php
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxycfg.marketscore.com/gencfg.asp?id1=El$;ejvwjNh7&id2=U280wbz8Xb9&lp=1&nsv=5.2.4.5

    R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)

    O1 - Hosts: 64.14.40.138 www.searchalot.com
    O1 - Hosts: 64.14.40.138 searchalot.com
    O1 - Hosts: 66.218.71.198 yahoo.com
    O1 - Hosts: 216.109.125.66 www.yahoo.com
    O1 - Hosts: 207.68.173.245 www.hotmail.com
    O1 - Hosts: 64.4.52.7 hotmail.com
    O1 - Hosts: 207.68.172.234 www.msn.com
    O1 - Hosts: 207.68.172.246 msn.com
    O1 - Hosts: 64.12.187.24 aol.com

    O3 - Toolbar: BONZI.COM Web Compass - {71B8AB7E-CB3F-4471-878E-8E1DFDF49B8B} - C:\Program Files\BONZI.COM Web Compass\WebCompassBar.dll (file missing)
    O3 - Toolbar: &Search Toolbar - {702AD576-FDDB-4d0f-9811-A43252064684} - C:\Program Files\Common Files\OE\toolbar.dll (file missing)

    O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch

    O4 - HKLM\..\Run: [OrbitUpdate] C:\Program Files\Orbit\update.exe
    O4 - HKLM\..\Run: [OrbitView] C:\Program Files\Orbit\view.exe
    O4 - HKLM\..\Run: [win32app] C:\WINDOWS\System32\winpup32.exe
    O4 - HKLM\..\Run: [kernel32] C:\WINDOWS\System32\kernel32.dlI <= if still present
    O4 - HKLM\..\Run: [SysComp] C:\WINDOWS\System32\msmrra.com

    O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe

    O9 - Extra button: MktBrowser (HKLM)
    O9 - Extra 'Tools' menuitem: MarketBrowser (HKLM)

    Reboot after doing so, preferably into safe mode
    and delete:
    C:\Program Files\Common Files\OE <= entire folder
    C:\Program Files\Orbit <= entire folder
    C:\WINDOWS\System32\winpup32.exe
    C:\Program Files\Common Files\GMT <= entire folder

    Could you please mail this file to the address in my profile:
    C:\WINDOWS\System32\msmrra.com
    I will have it analyzed and will let you know what to do with it.

    Regards,

    Pieter
  5. TonyKlein
    Offline

    TonyKlein Security Expert

    This one needs to go as well:

    O4 - HKLM\..\Run: [FSW] C:\Program Files\FSW\FSW.EXE

    http://www.doxdesk.com/parasite/FreeScratchAndWin.html

    After rebooting, delete the C:\Program Files\FSW folder itself.

    Cheers,
Thread Status:
Not open for further replies.