Help - Search - Members - Calendar
Full Version: Http 400 Bad Request
BleepingComputer.com > Security > Am I infected? What do I do?
   
Momentum
When I go logging in into hotmail I get this error -HTTP 400 Bad Request- It does not only happens with hotmail, it also appears on some other websites too.

I run on Windows Vista Home Premium 32Bit


Can anyone please give me some help? What to do?
it also happens when I go to you tube i only can play videos that appear in the home YouTube page, but it wont allow me to search videos as I'd get the error.

I can login into gmail and chech my email but when I logout the error comes up again.
It also happens in so many other websites most of which I cannot even remember, but in example some of them displays the whole site but in some windows within the site it displays the error too.
I have done a System Restore but it didn't help.

My browser is Windows Internet Explorer
I have deleted all my cookies and temp files too
I've done a full antispyware & antivirus scan. Only the antispyware found 3 threats that it corrected itself without any problems. Antivirus did not found anything, all ok.

I have downloaded and installed the latest java.

The problem is still there though...

I must mention that my computer has become so slow lately. I also have some other problems I've could never get rid of:

-Internet Explorer has stopped working
-Windows Explorer has stopped working

These 2 above could happen anytime especially if I switch between screens or download something new I think

And recently, when starting my machine:

-Application failed to initialize properly (0xc0000022) and then if cliking ok it will lead to:
-System File has stopped working properly

and a suspicious one but low level risk according to trendmicro antivirus:
-rwwnw64d.exe
Trend Micro still blocks this one above all the time, but I dont know how to get rid of this one

I must be so bloody infected.
Should I trust and buy one of these programs on the web, like errorsmart.com (trendmicro doesn't like this one, it wont allow me to download it)
And actually after I tried some of this free errors scan programs from the web my pc has become slower and non responsive, freezing up sometimes specially if I download music or stuff with limewire.
Is there some program that could really fix all of this problems as they promise on the web? Something you could recommend me?

HTTP 400 Bad request is still there. I cannot get into my email or youtube and many others.
Please some Help! Glup!

Many thanks in anticipation
ruby1
Hi; I suggest you ARE infected; whcih is your installed antivirus program and can you please name your other protection programns?


you use Limewire ? if you seek help on cleaning you will need to remove it as there is little point in running cleaning programs while you continue to download most probably infected materials via a P2P program


can you please run this tool which is vista compatible if the computer will let you ; it can give us a clearer picture of what is on the computer infection-wise

do you have your computer cd and licence key to hand if you do need to do a reformat?

Superantispyware; guide on how to install and run


If you have not already got a Downloads folder , I suggest you create a new folder in My Documents, and name it Downloads ;

Installing superantispywareSuperantispyware is found here


http://www.superantispyware.com/index.html

Download to the Downloads folder the free exe to superantispyware from here


http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

you install superantispyware by clicking on the icon in the downloads folder ;
it will launch the installation process;
follow the instructions and I suggest you ask for a default installation ;
ensure it creates a desktop icon for you ;
once the program has been installed it should ask you if you wish to update the program ; say YES

if it does not ask you , you need TO fully update the definitions by opening the program and find the ‘check for updates ‘tab in the bottom left of the menus you see; click on it and it will do the update for you ;
I suggest you ask it to check for updates again once the first update is complete just to be sure


please then reboot your computer ; it is preferable to run the scan in your computers safe mode;

please open this program from the desktop icon
please run the scan while you are OFF line and do not have the computer doing any other work while the scan runs

go to the preferences tab on the right
on the General tab I suggest you disable the scan on start up

on the Hijack protection tab I suggest you tick BOTH items; this enables the program to give you a Hijack home page alert if your home page gets changes ; if you DO get a home page hijack, when you boot up the computer superantispyware will open and tell you the home page has changed and will ask you if this is a legitimate change;

in statistics/logs- go to the bottom and you will see two boxes asking about keeping a log of scanning results and saving empty logs?

Tick both of them

Then go back to the main screen and see the tab that says scan your computer? Do you see that ?

Click on it

A screen will open ;on the left hand side ensure your FIXED drive ( most probably the C drive) is ticked;
Also tick in there any other section that is used and attached .
On the right had side you see three scanning options?; please click the Complete scan option

OK; you are now set to scan

Please then click on the ‘next’ tab and let the scan run please run the scan while you are OFF line and do not have the computer doing any other work while the scan runs

From my experience running this program the complete full scan CAN take many hours to run depending on how much is on your computer so be patient and let it run; maybe go for a cuppa or watch a favourite program while this one runs

Once the scan IS complete you will be presented with a box telling you what the scan has found ( if anything); if harmful objects have been found click on the OK button ; on the next screen all the harmful objects should have a check mark beside them, ; click ‘next’


A notification should appear that

‘quarantine and removal is complete’

click ‘ok’
and then the Finish button to get returned to the main menu


If you have run the scan in computers safe mode you will need to reboot to computer normal mode

If you have run in computer’s normal mode I suggest you reboot to enable the ‘fix’ the program has performed to consolidate

You then need to retrieve the scan result

Open the program and return to the statistics /logs section ; locate the most recent log ; left mouse click on it to highlight it and click the ‘view log’ tab

The log should appear in maybe note pad ; you need to copy and paste that log for examination
Once you have posted the log please close the superantispyware program

Momentum
Hi thank you so much...

I have followed the instructions and here I got the log for examination:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/14/2008 at 08:30 PM

Application Version : 4.0.1154

Core Rules Database Version : 3460
Trace Rules Database Version: 1451

Scan type : Complete Scan
Total Scan Time : 00:25:14

Memory items scanned : 208
Memory threats detected : 0
Registry items scanned : 8228
Registry threats detected : 25
File items scanned : 21270
File threats detected : 43

Adware.AdSponsor/ISM
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83C35173-E029-42f1-9692-0341EE379A0D}
HKCR\CLSID\{83C35173-E029-42F1-9692-0341EE379A0D}
HKCR\CLSID\{83C35173-E029-42F1-9692-0341EE379A0D}
HKCR\CLSID\{83C35173-E029-42F1-9692-0341EE379A0D}#AppID
HKCR\CLSID\{83C35173-E029-42F1-9692-0341EE379A0D}\InprocServer32
HKCR\CLSID\{83C35173-E029-42F1-9692-0341EE379A0D}\InprocServer32#ThreadingModel
HKCR\CLSID\{83C35173-E029-42F1-9692-0341EE379A0D}\ProgID
HKCR\CLSID\{83C35173-E029-42F1-9692-0341EE379A0D}\TypeLib
HKCR\CLSID\{83C35173-E029-42F1-9692-0341EE379A0D}\VersionIndependentProgID
C:\PROGRAM FILES\QDRDRIVE\QDRDRIVE16.DLL
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{10B64BDF-2E05-4a8a-B470-A3C651D0AD00}
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}#AppID
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}\Implemented Categories
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}\InprocServer32
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}\InprocServer32#ThreadingModel
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}\ProgID
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}\TypeLib
HKCR\CLSID\{10B64BDF-2E05-4A8A-B470-A3C651D0AD00}\VersionIndependentProgID
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Speed Monitor
C:\Program Files\QDRDRIVE\QdrDrive15.dll
C:\Program Files\QDRDRIVE\qdrloader.exe
C:\Program Files\QDRDRIVE

Adware.AdRotate/System
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a517930a-59c2-0273-c20d-c51ab1db38f0}
HKCR\CLSID\{A517930A-59C2-0273-C20D-C51AB1DB38F0}
HKCR\CLSID\{A517930A-59C2-0273-C20D-C51AB1DB38F0}
HKCR\CLSID\{A517930A-59C2-0273-C20D-C51AB1DB38F0}\InProcServer32
HKCR\CLSID\{A517930A-59C2-0273-C20D-C51AB1DB38F0}\InProcServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\{A7916B82-35AC-82DF-9CB0-76D137E8837F}.DLL

Adware.Tracking Cookie
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\esteban@ads.e-planning[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\esteban@ads.us.e-planning[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\esteban@oas.directaclick[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@rotator.adjuggler[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@account.fotolog[2].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@ehg-warnerbrothers.hitbox[2].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@imrworldwide[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@videoegg.adbureau[2].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@adbrite[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@microsoftwga.112.2o7[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@metacafe.122.2o7[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@questionmarket[2].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@ads.bleepingcomputer[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@www.googleadservices[2].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@www.googleadservices[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@www.googleadservices[4].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@atdmt[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@doubleclick[2].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@warnerbros.112.2o7[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@ads.apn.co[2].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@cbs.112.2o7[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@xiti[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@finda.co[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@tracker.mediatracker.co[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@apnonline.112.2o7[1].txt
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Cookies\Low\esteban@mediaonenetwork[1].txt
C:\Users\Francisca\AppData\Roaming\Microsoft\Windows\Cookies\Low\francisca@imrworldwide[2].txt
C:\Users\Francisca\AppData\Roaming\Microsoft\Windows\Cookies\Low\francisca@doubleclick[1].txt

Adware.ClickSpring/Outer Info Network
C:\Program Files\Outerinfo
C:\Users\Esteban\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outerinfo

Trojan.Unclassified/BrowserDriver
C:\$RECYCLE.BIN\S-1-5-21-2577533132-3360665580-315308475-1002\$RAHNJIJ.EXE
C:\WINDOWS\ONE11111.EXE

Adware.ClickSpring-Variant
C:\WINDOWS\??STEM32\RUNDLL32.EXE

Adware.AdRotator/AdsSite
C:\WINDOWS\SYSTEM32\ADSSITE-REMOVE.EXE

Adware.AdRotator/RightOnz
C:\WINDOWS\SYSTEM32\RIGHTONADZ-UNINST.EXE


----

My protection programs:

Antivirus : Trend Micro Internet Security Pro
Firewall : Trend Micro Internet Security Pro
Ex-AntiSpyware : Spybot Search & Destroy (I've unistalled this one and replaced it for SuperAntiSpyware)

Thanks for helping me, I hope we can fix this problems and all this to be helpful for everyone...
Thank you
hillbillygreek
Hey ruby1, Momentum has an HJT log posted here. Since I have no capabilities of locking this thread, I will make a friendly suggestion to now patiently wait & get help from someone there.
ruby1
QUOTE(hillbillygreek @ May 15 2008, 05:32 AM) *
Hey ruby1, Momentum has an HJT log posted here. Since I have no capabilities of locking this thread, I will make a friendly suggestion to now patiently wait & get help from someone there.

the forum facility here
http://www.bleepingcomputer.com/forums/topic137145.html
'enables' such requests to be made thumbup2.gif
garmanma
Since the OP has posted a HJT lg, this thread is now closed
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.