Iexplore Hack help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MGII, Nov 24, 2005.

  1. MGII

    MGII Private E-2

    Hello!

    Let me first say that I have tackled many spyware and malware problems before, always with the excellent help of this site, and that I am very appreciative of any help that may now be offered to me.

    I am something of a spyware veteran, but I have found myself with a rather different problem. The traits of this particular hack are as follows.

    1. It completely obscures my "processes" tab and prevents any running system processes from being ended.
    2. It continually respawns itself in my registry as "msvcsnpn.exe" under the key "component player."
    3. It runs several "iexplore" programs in the background, complete with an unnerving constant clicking noise and a greatly deprecated system performance.
    4. It disables the windows firewall.
    5. It prevents me from running AdAware or Norton Antivirus.
    6. It is present even in diagnostic modes.

    I have searched high and low for help with this particular hack and have found nothing! Please, any help would be much appreciated... I am a music producer and this problem is greatly hampering my work!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures as best as you can with the problems you are having. These are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments. Note anything that you cannot do and also the results of things you can do, and tell us when you come back.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. MGII

    MGII Private E-2

    Followed the above instructions...

    Logfile attached.

    Thanks!
     

    Attached Files:

  4. MGII

    MGII Private E-2

    BTW... Bitdefender returned some infected files and reported them as deleted.


    I've attached the log.
     

    Attached Files:

    • btd.txt
      File size:
      1.8 KB
      Views:
      2
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying you were able to run ALL steps of the READ ME with no problems?

    You forgot that the below is supposed to be disabled (per the HJT instructions):

    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
     
  6. MGII

    MGII Private E-2

    I followed these instructions... Msconfig appears disabled... it is in normal startup and all the services are checked... is there something else I need to do before running HJT?
     
  7. MGII

    MGII Private E-2

    I restarted my computer after disabling the msconfig utillity and now things have gotten really serious! Everytime I boot up my computer I am automatically logged out now. It is impossible for me even to reach the desktop! Is there anything I can do now?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How are you getting here?

    Do you know what was disabled before?
    Can you boot in safe mode?
     
  9. MGII

    MGII Private E-2

    I have an addtional computer in my home for recreational use... the one that is infected is my music PC is is infinitely more important.

    All I have to describe the running services are the logfiles attached here to the posts in this thread.

    Is there a way I can boot to safe mode without actually entering Windows since everytime I turn the computer on I am instantly logged off to the user screen?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you have an option like safe mode with command prompt!

    Also try another user account if possible.

    Do you have a bootable Windows XP CD for your system?

    I see several bad things in your HJT log that we can fix. And I question another. Do you know what the below is:

    O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
     
  11. MGII

    MGII Private E-2

    That line was the one that I had thought would cause this problem as well... I have no idea what it is at all.

    There are no other user accounts on this computer, and I assume that I cannot create one without getting to the desktop.

    When I press f8 at startup I am brought to the bios setup, and it doesn't seem like there is any option for safe mode... If I can get to a command prompt, is there some way I can make the system bypass the user logon? I don't have a Windows XP cd... none of my two Vaio PCs came with one... will I need to bite the $200 for an XP cd to run a repair install? Is there another way?

    Thanks
     
  12. MGII

    MGII Private E-2

    I managed to find a way into safe mode, and yet I experience the same problem at the user screen...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These PC manufactures should be shot for not shipping CDs with the PCs.

    If you can get to a Safe Mode with command prompt option we should be able to delete the files causing problems at the command prompt level. Also if you can get your hands on a Windows XP SP2 boot CD we can fix them to from the Recovery Console. You do not want to do a Repair/Install unless absolutely necessary.

    You have more problems then the one line I questioned. Here are items that I would fix if we can get to it:

    F2 - REG:system.ini: Shell=explorer.exe
    F3 - REG:win.ini: run=C:\WINDOWS\inet20002\services.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
    O21 - SSODL: IEFilter - {F93EB1E5-D999-4C3D-958D-85DE304F94E3} - C:\WINDOWS\system32\IEFilter.dll

    Then I would delete the following files:
    C:\WINDOWS\inet20002\services.exe (possibly the whole inet20002 folder)
    C:\WINDOWS\SYSTEM32\VESWinlogon.dll <--- but not 100% sure it is bad
    C:\WINDOWS\system32\IEFilter.dll
     
  14. MGII

    MGII Private E-2

    Thank you a bunch for this help...

    I will try to get my hands on a SP2 cd... there must be someone I know who has one I can borrow to do the Recovery option.

    One question... do you believe it is those lines causing this boot difficulty as well, in addition to the other problems? Is there some line I should look for in particular, either in presence or absence that could cause such a thing? Would the Recovery option be able to automatically at least restore boot functionallity to my PC?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    With Recovery Console we can get to a command prompt and delete the bad files I mentioned. Then I suspect that you PC may boot okay. Unless there is something else that was hiding in your Startups that I could not see because msconfig was masking it. We will see. You have to know your Administrator password to do this. If you never set one, it is probably blank, meaning you would just hit the Enter key when asked.

    Here is how Recover Console works:

    Put the Windows CD in the CD drive and reboot the computer. Hopefully it your PC is configure to boot from CD first otherwise you have to change the boot order in your BIOS.

    -You should get a "press any key to boot from CD" message, so you should do that.
    - It will load a bunch of files and eventually give you a menu where you can select the "Recovery Console" by pressing R
    -You'll see your Windows Installation like "C:\Windows", type the number 1 and press enter.
    - Administrator password is next: is probably blank so just press enter, unless you set one in which case enter it.
    -With all that done you'll end up with a C:\Windows> prompt

    Once you can get to this point I will give you some steps to delete the bad files.
     
  16. MGII

    MGII Private E-2

    I have obtained a boot disk and have made it through the Recovery console to the command prompt. Time for those commands.

    Thanks!
     
  17. MGII

    MGII Private E-2

    I have reached the command prompt with an XP cd...
    Should I attempt to delete these files? What are the commands?
     
  18. MGII

    MGII Private E-2

    bump

    Sorry to be such a pain, but all I really need now are those commands you spoke of...
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! From the command prompt here is what you should do. Enter the below commands each follow by the enter key. Keep track of whether you receive any error messages.

    cd c:\windows\inet20002
    attrib -r -h -s services.exe
    del services.exe

    cd c:\windows\SYSTEM32
    attrib -r -h -s VESWinlogon.dll
    del VESWinlogon.dll

    attrib -r -h -s IEFilter.dll
    del IEFilter.dll

    Now remove the CD and see if you can boot normally.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Another thing they may prove useful to do is to capture the output of the LISTSVC command from the command prompt. This will give a list of services that can be enabled or disable from running at startup. I want to see this just incase something bad is in the list.
     
  21. MGII

    MGII Private E-2

    Tried these commands, same problems when booting.

    The "attrib" command on both of the later files said "invalid parameter" and the first file was not found.

    Should I just copy the output from the listsvc command and write it here?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must have typed something wrong. You must not have any spaces between the minus signs and the letters. But there must be a space inbetween each parameter. Here is an example where I'm exagerating the spacing to make it obvious:
    Code:
    attrib	-r -h -s	IEFilter.dll 
    Also do a dir to look for the files. Like
    dir IEFilter.dll
    dir VESWinlogon.dll
    dir c:\windows\inet20002 <--- this should show everything in this folder

    Yes!
     
  23. MGII

    MGII Private E-2

    Ok, the "dir" command shows that both the files are gone and I have used the remove directory command to eliminate the inet20002 folder.

    The problem persists however.

    I'm going to have to copy the listsvc output by hand... I'll post it here soon.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    dir will not show the files if they are hidden or system files. That is why I was using the attrib -r -s -h command first. It disables the read-only, hidden, and system attribute.

    dir /AS IEFilter.dll will show it if it is a system file.
    dir /AH IEFilter.dll will show it if it is a hidden file.

    Same goes for the other file.
     
  25. MGII

    MGII Private E-2

    All these commands, printed exactly as typed, are returning "the parameter is not valid, type /? for help" message.

    Still working on the listsvc log
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you just type dir /? and attrib /? what do you see? Is it a list of valid arguments or do you still get an error message.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  28. MGII

    MGII Private E-2

    There is a list of valid arguements with the /? command.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! And aren't the ones I listed valid?
     
  30. MGII

    MGII Private E-2

    Would seem so but they aren't working.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just try the following (the * represents a wild card to match anything). Make sure you are in the C:\windows\system32 folder first:

    attrib IE*.*
    attrib VES*.*

    What result does this yield.
     
  32. MGII

    MGII Private E-2

    The parameter is still invalid.
     
  33. MGII

    MGII Private E-2

    O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll

    I remember it said in the tutorial that these types of commands in the 020 group run very early in the boot script... would that explain all the trouble I am having?

    Is a reformatting in order?
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's not what I meant. I wanted to know if the
    attrib IE*.*
    attrib VES*.*
    commands gave you any info on the files. Or did they not see the files either?
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I sure wish we could figure out what the root problem is. From the command prompt do the below:

    cd c:\
    attrib -r -h -s boot.ini <--- hope you do not get an error again
    type boot.ini

    tell me the output you get from the type boot.ini command. I want to see the contents of that file.

    We may be next looking at the below option which is not as catastrophic as a format install but it will require some reinstallation of any third party software that was put onto your system after initial Windows Installation. This options reverts you back to the level of the boot disk. Read the below over. It may be the only alternative (then comes format)

    http://www.michaelstevenstech.com/XPrepairinstall.htm

    Do you have your Windows XP activation key code? You will probably need it to reactivate windows.

    Pay special attention to Step 3 of XP Repair Install because this is important and you (as stated) do not want this option. Read the whole thing over before doing anything.
     
  36. MGII

    MGII Private E-2

    Tried both...

    1st try was the same error message.

    I did in fact run an XP repair install and quite remarkably, the problem persists. Now there are two entries at the logon screen, but both immediately log back off when clicked on just like before.
     
  37. MGII

    MGII Private E-2

    type boot.ini returned the following...

    [boot loader]
    timeout=30
    default=multi<0>disk<0>partition<1>\Windows
    [operating systems]
    multi<0>disk<0>rdisk<0>partition<1>\Windows="Microsoft Windows XP Home Edition"
    /noexecute=optin /fastdetect
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let me see if I understand exactly what happens.

    1) When you boot up, you do get to the login screen showing the users without any problem?
    2) You click a user and enter the password and then immediately return back to the login screen? Is this correct?
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure about this line being exactly as written:

    default=multi<0>disk<0>partition<1>\Windows

    I would expect more like:

    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly at what point in this message thread did you do a repair install.
     
  41. MGII

    MGII Private E-2

    That is precisely what happens. It logs in, shows the desktop background without any icons or start menu, then immediately logs out back to the user screen.

    I ran the repair install immediately after trying the type boot.ini command
     
  42. MGII

    MGII Private E-2

    You are correct I mistakenly omitted the rdisk value.

    It is there in the boot.ini file.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How many user profiles are there? Have you tried them all?
    Does safe mode without networking or safe mode with networking work any differently now?
    How about Safe mode with command prompt?

    [Edit: forgot you said only one user account. But in safe mode is there yours and the Administrator account?]
     
  44. MGII

    MGII Private E-2

    There is now only one user profile... my original one.

    In safe mode there are two, mine and Administrator. Both display the problem.

    All the versions of safe mode in the f8 menu still exibit the problem.
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer message # 40.

    Did you disable System Restore at the beginning of the the cleanup steps? If not, maybe we can use a restore point.
     
  46. MGII

    MGII Private E-2

    How can I identify my last restore point without getting to the desktop?
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat my question:
    I'm also still waiting for the output from the listsvc command I requested in message # 20.

    Also, first tell me did you or did you not disable System Restore per the tutorial?

    It would appear that this does not matter anyway as System Restore cannot be run via the command prompt of the Recovery Console.

    Had you installed an updates/patches recently on this PC?
     
    Last edited: Nov 26, 2005
  48. MGII

    MGII Private E-2

    Ok so here's the deal...

    A friend of mine has temporarily installed Linux on my PC so I can access the songs I was working on and move them to a USB hard drive. After completing this I plan on reformatting the computer.

    Thanks a bunch for all the help, I really appreciate the amount of attention my problem got, especially free of charge in a day when few things come free. This site is truly a great resource, and I would pursue the recommendations here further if I were not on such a tight schedule to finish the music.

    Thanks again!
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I was speaking with Adrynalyne (another Mod here) who is very familar with MS Windows issues like this. He had suggested a something to try. If you do want to pursue this further let me know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds