Adwanoc Posted November 30, 2003 Report Share Posted November 30, 2003 Hi. Im running windos ME with IE6and latley ive been experiencing a little annoying problem in Internet Explorer. It happened while I was typing into a text box or filling out a form. When I pushed Enter to start a new paragraph, suddenly the window became unselected. With a little tinkering I found that whenever I pushed the enter key, the window became unselected.So I thought I might as well see what WAS selected. So I Pushed enter, then did Alt+tab and there was a "Phantom window". The window selected was an internet explorer window with the site http://3d-images.org . For some reason I cant seem to get the window to show up anywhere else. I can't see the window. I can't find the window in the close program dialouge. I cant find it on the task bar. It's just hidden from view, like its running in the background. so i decided to go to this 3d-images.org site. It seems like a perfectly normal site, but under close inspection, there are n these strange pornographic links embeded within the sites html code. ... well if anyone has any idea what i could do next to find out how to get rid of this stupid window, or if they have delt with this thing before, please rpely. THank you. Quote Link to comment Share on other sites More sharing options...
Guest Grim Reaper Posted November 30, 2003 Report Share Posted November 30, 2003 hi adwanoc and welcome to the forum......my first questions would be do you have up do date antivirus and a firewall in place,secondly, have you run Ad-Aware available here and / or Spybot S & D from here?It sounds to me like this site MAY have some sort of hijack ware. Quote Link to comment Share on other sites More sharing options...
mark2 Posted November 30, 2003 Report Share Posted November 30, 2003 If still there after running Spybot and Adaware go to http://mjc1.com/mirror/hjt/ to download Hijackthis there is also a short tutorial on the site on how to use it.paste the results into this thread and we can sort it out.Don't attempt to fix until you have posted your log here, a lot you will see will be needed Quote Link to comment Share on other sites More sharing options...
Adwanoc Posted December 1, 2003 Author Report Share Posted December 1, 2003 Well I have Norton Antivirus on, although i dont have a fire wall. I have tried using Hijack this, and have gotten rid of all the out of the ordinary entries. I also tried Spy bot and while it detected tons of spy ware, getting rid of it doesnt seem to fix my problem. I will try ad aware... I hope it works. Quote Link to comment Share on other sites More sharing options...
Guest Grim Reaper Posted December 1, 2003 Report Share Posted December 1, 2003 have you got your hijackthis log that we could have a look at?? Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 1, 2003 Report Share Posted December 1, 2003 Make sure you have the latest version of Hijackthis, v1.97.7 Unzip, doubleclick HijackThis.exe, and hit "Scan".When the scan is finished, the "Scan" button will change into a "Save Log" button.Press that, save the log somewhere, and please show us its contents.Most of what it lists will be harmless or even required, so do NOT fix anything yet.Post your log then we can analyze it.It is also important to close all browser windows when allowing HJT to fix. Quote Link to comment Share on other sites More sharing options...
Adwanoc Posted December 2, 2003 Author Report Share Posted December 2, 2003 Well ad aware did nothing...anyways, heres my log. It seems that most of it is taken up by google toolbar and some other harmless stuff. I had already gotten rid of the most obvious spy ware stuff, such as the ever annoying mysearch.com "tool" and ezula top text. See what you can figure from this.Logfile of HijackThis v1.97.7Scan saved at 7:58:51 PM, on 12/1/2003Platform: Windows ME (Win9x 4.90.3000)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\SPOOL32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\STIMON.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXEC:\WINDOWS\SYSTEM\LEXBCES.EXEC:\WINDOWS\SYSTEM\RPCSS.EXEC:\WINDOWS\SYSTEM\LEXPPS.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\RESTORE\STMGR.EXEC:\WINDOWS\SYSTEM\DDHELP.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\SYSTEM\SYSTEMIE.EXEC:\WINDOWS\TASKMON.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\WINDOWS\SYSTEM\WMIEXE.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXEC:\WINDOWS\LOADQM.EXEC:\PROGRAM FILES\CANON\BJPV\TVMON.EXEC:\WINDOWS\SYSTEM\QTTASK.EXEC:\PROGRAM FILES\OPTIMUM ONLINE\NETSURF.EXEC:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXEC:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXEC:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXEC:\PROGRAM FILES\INSTAN-T\INSTANT.EXEC:\HIJACKTHIS.EXER1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.netO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCXO2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLLO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCXO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorunO4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exeO4 - HKLM\..\Run: [systemTray] SysTray.ExeO4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrSchemeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"O4 - HKLM\..\Run: [LoadQM] loadqm.exeO4 - HKLM\..\Run: [bJPD HID Control] C:\Program Files\Canon\BJPV\TVMon.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottimeO4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -trayO4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrSchemeO4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exeO4 - HKLM\..\RunServices: [stillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXEO4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"O4 - HKLM\..\RunServices: [scriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -regO4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /backgroundO4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXEO4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXEO8 - Extra context menu item: Read By Natural Voice Reader - C:\Program Files\Natural Voice Reader Standard\read.htmlO8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.htmlO8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.htmlO8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.htmlO8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.htmlO8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.htmlO9 - Extra button: Related (HKLM)O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)O9 - Extra button: Natural Reader (HKLM)O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/Template...nloads/outc.cabO16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cabO16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cabOne more important note: I notice now that besides making forum posts and emails more annoying than ever, today it started poping up opt ins for dowloading some file called "3dimages.htm". This is making me more confident that whatever this thing is is harmful. Additionally I have noticed my computers resources are all out of whack. It says out of my 500 mb of ram, only 20 megs is availible. When I try to open a simple program like paint, it will give me "out of memory" error messages, although most of the time the computer runs fine. Infact I ran adobe photoshop 7 just fine yesterday despite my critically low memory.Thank you so much for your help everyone. I hope together we can solve this mystery. Quote Link to comment Share on other sites More sharing options...
Adwanoc Posted December 2, 2003 Author Report Share Posted December 2, 2003 oh no, its just gotten worse. Ive been getting run time errors in german. Yes german. It says run time error on the top, and the rest of the message is in german. I DONT SPEAK GERMAN! Now my programs wont open, and I get an error message about some thing called ei timer, with some crap about countdowns. Im scared for my computers life! lol this thing is driving memore crazy than I already am! I cant find anything on google about these strage virus like symptoms! I hope none of my files become deleted or what not... for that would suck. Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 2, 2003 Report Share Posted December 2, 2003 This could possibly account for some of your ads.O4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -trayPacman's portal has this to say about itOptimum OnlineNetsurf.exeOptimum Online ISP software. Not required, just window dressing & advertising from Optimum That's the only one there I can see that will load ads for you.to get some of your resources back the following are optional fixes.close all browser windows and allow HJT to fixO4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottimeO4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /backgroundO4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeDisableC:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXEC:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE using msconfigME is not very good with memory management unfortunately. :down: See how it goes with those fixes. Quote Link to comment Share on other sites More sharing options...
Adwanoc Posted December 3, 2003 Author Report Share Posted December 3, 2003 Amazing. Once I got rid of netsurf and find fast my computer runs flawlessly. The memory problems are gone, although I still get that annoying 3d-images.org thing. I suppose I will never know what it is exactly... Could it be something new that just came out? Some new sort of spy ware that noone has heard of? Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 3, 2003 Report Share Posted December 3, 2003 Post the latest HJT log, lets have another look see if there's something more in there to be found Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 4, 2003 Report Share Posted December 4, 2003 C:\WINDOWS\SYSTEM\SYSTEMIE.EXE is a new(ish) one, a keylogger trojan.You'll need to change all your passwords or sensitive information you have typed into online forms.REBOOT into safe mode.And find and remove the files below:systemie.exesysie.dllsystemie.dllsystemie.dat .If this doesn't work we may need to go into the registry. :( Quote Link to comment Share on other sites More sharing options...
Adwanoc Posted December 4, 2003 Author Report Share Posted December 4, 2003 WOW! That fixed it! THank you so much for your help! How did you ever find out about this? Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 5, 2003 Report Share Posted December 5, 2003 AdwanocHow did you ever find out about this?I lurk in some strange places :D It was in http://forums.tomcoyote.org/index.php?act=idxyou might have a look at http://www.windowsforum.org/support/forum/...?showtopic=3702 and http://www.windowsforum.org/support/forum/...php?showtopic=5 to begin to prevent similar problems in the future.Glad it's fixed :thumbup: Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.