possible fake windows security message leading to problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tylerjohns18, Apr 28, 2005.

  1. tylerjohns18

    tylerjohns18 Private E-2

    I've read some posts on a number of sites that detail a problem very similar to this one. Lately I've been getting a pop-up message from "Windows Security Center." (Sure) It reads: WARNING: Windows Firewall detected suspicious network activity on your computer. Malicious software codes try to steal your privacy information, such as credit card numbers, electronic mail accounts, financial date or passwords. Do you want to learn how to protect your computer?...... If you click yes like i did (unfortunately) it even comes up with a small red shield icon with an x in it... seemingly a legit windows security icon. I probably should have realized the bad grammar and punctuation was a little fishy as far as windows alerts go. I've been getting this popup quite often over the last 3 or so days. Now, everytime I run ad-aware, it finds a new .exe file in system32 that it identifies as malware. as often as i remove them i can run adaware again a moment later and it has a new one... the .exe's have a variety of names: javahd32.exe, appsd32.exe, d3dsm32.exe, etc, etc. When I restart my computer, I get popups right before reboot that tell me that these files I've deleted with adaware "cannot be found." Every time I run adware I have a new one, it never fails. My internet explorer browser will no longer open, it always errors, and when i try to open an instant message window with aol instant messenger it crashes, etc. I won't include a hijackthis log in my post until requested. I hope someone out there can offer some help, it would be much appreciated!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like a few thing including an HSA hijack. Do as much of the below as you can and finish with the HijackThis log:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. tylerjohns18

    tylerjohns18 Private E-2

    Every program seemed to find something and remove it. I had no trouble installing or running any of them. The touch micro's online scan found 52 infections and was able to remove all but 3 or 4 of them i believe it said. my aol instant messenger still crashes when i open an instant message window. microsoft internet explorer no longer seems to exist on my computer (i use mozilla firefox) ad-aware still always finds an .exe in system32. here's my hijackthis log.
     

    Attached Files:

  4. tylerjohns18

    tylerjohns18 Private E-2

    ps. im still getting the fake windows security popup
     
  5. tylerjohns18

    tylerjohns18 Private E-2

    pss. my recycle bin includes the following items: drvupd.inf, addhj.dll, hpsysdrv.exe, iexplore.exe (that explains the absence of internet explorer), and rtvbq.dll.... don't know if this was worth posting, just wondering if i should restore or delete any or all of it.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should definitely undelete (restore) hpsysdrv.exe and iexplore.exe.

    I'm surprized they are still in Recycle Bin. When you ran the READ ME FIRST steps, Ccleaner should have emptied the Recycle Bin.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you stop and disable the below service per step 2 in the READ ME FIRST?

    Remote Procedure Call (RPC) Helper

    If not, you must go do that.

    Then do the below:


    Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:

    Remote Procedure Call (RPC) Helper

    If that does not work try entering the short name: 11Fßä#·ºÄÖ`I
    You will need to cut and paste the short name since the characters are not easily typed.
    Then exit HJT (I will restart HijackThis again below).

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\atlxs32.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\svcpack.exe
    O2 - BHO: (no name) - {A519ABD5-0403-D86B-DED9-9E0905A175C1} - C:\WINDOWS\crev.dll
    O4 - HKLM\..\Run: [atlxs32.exe] C:\WINDOWS\system32\atlxs32.exe
    O4 - HKCU\..\Run: [li-rcash00001] c:\program files\Webdialer\qpaeesv0.exe -m
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
    O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\appxg.exe" /s (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\svcpack.exe
    C:\WINDOWS\crev.dll
    C:\WINDOWS\system32\atlxs32.exe
    C:\WINDOWS\appxg.exe
    c:\program files\Webdialer <--- the whole folder
    C:\Program Files\Ebates_MoeMoneyMaker <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    I expect the HSA hijacker to return and if it does we will use a different approach. You had other items we needed to fix first anyway.
     
  8. tylerjohns18

    tylerjohns18 Private E-2

    I disabled the Remote Procedure Call (RPC) Helper before I did anything, however I wasn't able to delete it with HJT using the regular name or the short name. I fixed all of the problems with HJT, booted into safe mode. Several of what you told me to delete I was unable to find with windows explorer. What I did find I deleted successfully (only 2 of what you said to delete) I ran ccleaner and reset the web settings. this is my new HJT log. (my internet explorer now opens without error, but the aol instant messenger is still crashing when i try to open an instant message box.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All browsers ( C:\Program Files\Mozilla Firefox\firefox.exe ) must be closed before using HijackThis.

    Please try to Stop and Disable the Remote Procedure Call (RPC) Helper service again.

    Then please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:

    Remote Procedure Call (RPC) Helper

    If that does not work try entering the short name: 11Fßä#·ºÄÖ`I

    You will need to cut and paste the short name since the characters are not easily typed.

    After doing the above exit HijackThis.

    Make sure you have both about:Buster and HSremove downloaded from the READ ME FIRST. And make sure you have UPDATED the database for about:buster. I believe it is up to number 26.

    You need to print or save these instructions locally because after this reading this sentence you will need to physically unplug your connection from your cable, ADSL, or dial-up modem to your PC and then you MUST exit all browsers and DO NOT run any again until requested.

    Okay, unplug your internet connection and exit browsers now!!!!

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them (if found) by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\appxg.exe
    C:\WINDOWS\system32\mfcor.exe
    C:\WINDOWS\system32\mstn32.exe


    After killing all the above processes, click "Back" button that is just under the process list next to the Run button.

    Select the "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK (I'm just double checking to make sure it has not restarted because sometime it does).

    Remote Procedure Call (RPC) Helper

    If that does not work try cutting and pasing in the following short name: 11Fßä#·ºÄÖ`I
    You must use cut and paste since the characters cannot be easily typed.

    Tell me what happens while doing the above. If you are told that the service must be stopped. You need to go back up to where we stopped and disabled this service as mentioned previously. Then repeat the above steps to have HJT Delete this NT Service.

    After killing all the above processes and deleting the NT Service, click "Back" on the lower right. Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (DO NOT OPEN ANOTHER BROWSER UNTIL AFTER POWER DOWN AND POWER UP, see below):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lviod.dll/sp.html#14044
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lviod.dll/sp.html#14044
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lviod.dll/sp.html#14044
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lviod.dll/sp.html#14044
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lviod.dll/sp.html#14044
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lviod.dll/sp.html#14044
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lviod.dll/sp.html#14044
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {2AB82D18-1F50-1D53-2351-F77A7397088E} - C:\WINDOWS\apivn32.dll
    O4 - HKLM\..\Run: [mstn32.exe] C:\WINDOWS\system32\mstn32.exe
    O4 - HKLM\..\RunOnce: [mfcor.exe] C:\WINDOWS\system32\mfcor.exe
    O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\appxg.exe" /s (file missing)



    Then exit HJT after clicking FIX


    Run Windows Explorer and look for and try to delete (sort the listing in windows explorer by Modification dates and look for possibly other similarly name files from the same date - let me know if you find others even if they have different 3 character extensions like .dat, .ini, .dll, .exe but DO NOT delete anything on your own.):
    C:\WINDOWS\lviod.dll
    C:\WINDOWS\apivn32.dll
    C:\WINDOWS\system32\mfcor.exe
    C:\WINDOWS\system32\mstn32.exe
    C:\WINDOWS\appxg.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. If you cannot find or delete them, note which ones and continue (tell me the results when you come back here).

    - Run about:Buster and save the log to ab1.log (make sure you let it do the second scan).

    - NOW PULL THE POWER PLUG TO YOUR PC! Yes, you read that correctly. This is very important! I do not want you to power down the normal way.

    - After that wait a minute or two and then power up into safe mode (still with no internet connection available and do not open any browsers). Only run what I request.

    - Now try again to delete any of the above files that would not delete previously while in normal boot mode.

    - Empty your Recycle Bin and delete all files in the c:\windows\prefetch folder. In fact as an additional measure do the following, run Ccleaner that you installed while running the READ ME FIRST.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    - Run HSremove and then run about:Buster again and save the log to ab2.log (let it do second scan)!

    - Immediately after about:buster completes, reboot in normal mode. (you do not need to pull the powser plug here. Just reboot.)

    - Plug your cable to the internet back in now.

    - Open and close a couple of IE sessions and then with IE closed get a new HJT log.

    - Now come back here and post both about:Buster logs and the new HJT log. And tell me what happened during the procedure.

    Let me know anything else that you notice.
     
    Last edited: Apr 30, 2005
  10. tylerjohns18

    tylerjohns18 Private E-2

    Most of this process went fairly well. I disabled the RPC helper again, but whenever I try to delete it, using either the normal or short name, I'm told it cannot be found in the registry. When I went to kill processes, appxg.exe wasn't there, but I killed the other two. Again, I tried to delete an NT service with HJT, but was told the RPC help couldn't be found in the registry even though I tried both names. (I did note that the last time I rebooted, right before I started posting this reply, I went to run, services.msc, and saw that RPC Helper is still there, and disabled at the moment.) I fixed everything with HJT next that you detailed I should EXCEPT: O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\appxg.exe" /s (file missing), because the line was not present. I then went to delete the files you told me to, but apivn32.dll, and appxg.exe weren't there. The others were deleted without a problem. (Around the date modified for these files were several similar, such as: mskw.exe, mfcgi32.exe, winqy32.exe, apirp.exe, apiyk32.dll, d3jq32.exe, javapc.exe, wintj.exe, orun32.ini, sdknf.exe, mozver.dat, javahv32.dll, mfcnf.exe, crva.exe, apiyk32.exe, apick32.exe, winej32.exe, ipin.exe, netsn.exe, msjx.exe, javafi.exe, crgd.exe, addar32.exe, msou.exe, crwh.exe, d3ki.exe, addvw.exe, etc.) I followed the next steps exactly, removed 8 items with HSremove, and completed the steps. AIM works again without crashing!! Here are my logs.
     

    Attached Files:

    • ab1.log
      File size:
      507 bytes
      Views:
      2
    • ab2.log
      File size:
      392 bytes
      Views:
      1
  11. tylerjohns18

    tylerjohns18 Private E-2

    My HJT log.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the hijacker appears to be gone. Now the last two remaining items I would suggest fixing are the use of Ares (know to contain adware) and Limeshop (known to be bundled with a variety of adware and spyware).
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm

    After that, you are in serious need of an antivirus application and a true firewall application (the one in Win XP SP2 is not sufficient and should be disabled after getting one of the recommended ones installed). Complete the steps in the below link:
    How to Protect yourself from malware!

    Also from the files you mentioned, delete these
     
  13. tylerjohns18

    tylerjohns18 Private E-2

    Everything seems to be in order, I took the steps you detailed to protect my computer. As soon as I installed avast it told me limeshop was on my computer and it suggested i send it to "the chest" so i did... what exactly does that mean? I appreciate all your help very very much!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    The chest (some others call it a vault) is just a place where they lock away files that they delete just incase they need to be restored. After a short time you should normally empty the "chest" (usually as soon as you are sure you do not need anything in it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds