Infestations I can't seem to get rid of

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MarieRochelle, Aug 27, 2006.

  1. MarieRochelle

    MarieRochelle Private E-2

    Hi,

    I've followed all procedures listed under "READ & RUN ME FIRST Before Asking for Support". In doing so, I'm still left with an infected PC.

    I ran all the processes in SAFE mode as requested, and have all the various log files.

    I have various browsers Poping up all the time.

    I am attaching my log files for review. Any help would be greatly, greatly appreciated.

    I will apply the remainder of the log files in a follow-up post.

    Regards,

    Dave
     

    Attached Files:

  2. MarieRochelle

    MarieRochelle Private E-2

    Additional files attached:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you start another thread? You already the below thrad that you never finished:

    http://forums.majorgeeks.com/showthread.php?t=100390

    Obviously you were able to work around the problem with being stuck in safe mode but you should have stayed in that thread.

    Do you know what the below enstart system service is for? It just showed up on August 25th and looks suspicious!
    O23 - Service: enstart - Unknown owner - C:\WINDOWS\System32\enstart.exe


    Also do you know what the below are for?
    O16 - DPF: {29EF91B9-7120-477C-A5CB-2D67F2FD088C} (TeleControl Class) - https://10.8.40.3/rrc.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://teamquest.webex.com/client/v_mywebex/webex/ieatgpc.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab
     
    Last edited: Aug 28, 2006
  4. MarieRochelle

    MarieRochelle Private E-2

    Sorry for starting a new thread. I started a new one since I hadn't properly run all the procedures first. As far as SAFE mode, I had to get someone from my companies help desk to login with Adminstrator to get out of SAFE mode. I then created a local admin account and was able to login to safe mode with that.

    As far as the entires:

    O23 - I do not know what that is, and don't see a new restore point created in my system restore from that day.

    O16... https://10.8.40.3/rrc.cab - is a KVM address
    O16...https://teamquest.webex.com/client/v...ex/ieatgpc.cab - TeamQuest is a vendor I may have done a webex with in the past. Not required anymore though
    O16...https://secure.logmein.com/activex/ractrl.cab - Is a remote access and Desktop Control software. I haven't used it in a while.

    Thanks for looking and sorry for not properly using the site.

    Regards,

    Dave
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2
    Java 2 Runtime Environment, SE v1.4.2_06
    Java Runtime 1.4.2_01 for Borland COM APIs

    You really should also uninstall (or buy the new version) the below old unsupported version of Ad-Aware 6. I'm surprised it did not make you uninstall it when you install Ad-Aware SE Personal.
    Ad-aware 6 Professional


    Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to enstart ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    enstart

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Now let's download two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of appdit.dll once and then click the kill button. After you have killed all of the appdit.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    MSplg7.dll

    Next double click on explorer.exe and again click once on each instance of appdit.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    MSplg7.dll

    Now just exit Process Explorer.


    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\System32\enstart.exe
    C:\WINDOWS\TEMP\LT1E68.EXE

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {1b3dcab3-6093-4782-9e7b-abcc97f29d07} - C:\WINDOWS\system32\appdit.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\system32\kernels8.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://teamquest.webex.com/client/v...ex/ieatgpc.cab
    O20 - Winlogon Notify: appdit - C:\WINDOWS\SYSTEM32\appdit.dll
    O20 - Winlogon Notify: f3dsl - MSplg7.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    • Delete on Reboot

    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    C:\Documents and Settings\dscarani\Favorites\Health
    C:\Documents and Settings\Administrator\Application Data\Install.dat
    C:\Documents and Settings\dscarani\Application Data\Install.dat
    C:\WINDOWS\TEMP\LT1E68.EXE
    C:\WINDOWS\system32\enstart.exe
    C:\WINDOWS\system32\taskdir~.exe
    C:\WINDOWS\system32\_enstart.exe
    C:\WINDOWS\system32\appdit.dll

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!). If Killbox does not reboot just reboot your PC yourself.


    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\dscarani\Local Settings\Temp\



    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
    Last edited: Aug 29, 2006
  6. MarieRochelle

    MarieRochelle Private E-2

    Okay, I performed all steps as instructed.

    You asked for feedback on how the steps went. So all went great.

    In the following steps:
    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    MSplg7.dll
    Next double click on explorer.exe and again click once on each instance of appdit.dll and kill it. (If
    you do not find the dll, just continue on.)
    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    MSplg7.dll


    MSplg7.dll was not found.

    Additionally, in step:

    "Please run HijackThis and click on the Open the Misc Tools Section button on the open page.
    Then select Open process manager on the left-hand side. Look for the following process (or
    processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\System32\enstart.exe
    C:\WINDOWS\TEMP\LT1E68.EXE"


    These files were not found either. Other than that, the instructions were right on and everything ran as you described.

    I have httpwatch installed in my browser and I have not seen one redirect to an unsolicited site yet. I did just run Ad-aware and it said it found 26 tracking cookies.

    I have attached my logs for your review. Please let me know what you think.

    Thanks so much for all your help.

    Dave
     

    Attached Files:

  7. MarieRochelle

    MarieRochelle Private E-2

    After looking in my "task manager" I still see process enstart.exe running. Is this a virus/trojan? Was this supposed to be removed with the processes I followed?

    Thanks.

    Dave
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you were suppose to delete two files with that had enstart in them. One was enstart.exe and the other was _enstart.exe. They are both still in C:\windows\system32

    Boot into safe mode and try deleting the below files. Tell me what happens.
    C:\WINDOWS\system32\enstart.exe
    C:\WINDOWS\system32\_enstart.exe
    C:\WINDOWS\system32\idtcfg.dll
    C:\WINDOWS\system32\trccsc2.dll

    Afterwards, download the current version of ShowNew and attach a new log from it.

    Now download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.
     
  9. MarieRochelle

    MarieRochelle Private E-2

    Okay,

    I deleted the following files while in safe mode:

    C:\WINDOWS\system32\enstart.exe
    C:\WINDOWS\system32\_enstart.exe
    C:\WINDOWS\system32\idtcfg.dll
    C:\WINDOWS\system32\trccsc2.dll

    Additionally, I moved and renamed the following:

    C:\WINDOWS\system32\enstart.sys --> C:\Spyware Tools\enstart.sys_03Sept06
    C:\WINDOWS\system32\trccsc2.dll --> C:\Spyware Tools\trccsc2.dll.sig_03Sept06

    I wasn't sure if I should delete those as well, so I figured I would after I made a copy.

    Anyhow, when I first booted up I did not see enstart running in "task manager", I just checked and I see it out there again. I ran a new shownew and sure enough it shows in that one. The 2 new attachments newfiles.txt contains shownew after I rebooted, the one newfiles03Sept06.txt was 20 minutes later.

    The Blacklight ran clean and did not find anything. The log from that is also attached.

    Dave
     

    Attached Files:

  10. MarieRochelle

    MarieRochelle Private E-2

    Okay, I did a little more research on the enstart.exe. I went into SAFE mode, deleted the enstart.exe, enstart.sys and _enstart files again. When I booted up in normal mode, I browsed the C:\WINDOWS\system32\ directory and sorted by last modified. I kept hitting refresh until those files showed up again. It appears they are being placed there by my company. At bootup time, the company has a cmd.exe run as well as a Trend Micro Office scan. This opens up 2 DOS windows while these are running. It was immediately after these windows closed that the files showed up. So, it appears that program is associated with EnCase which I know our Security group uses.
    So I should be good with that program out there.

    Other than that, how is my system looking? My major problem of having unsolicited browser windows opening has appeared to have gone away. Thank you.

    Each time I login and run ad-aware I appear to find tracking cookies. Is there simply nothing that can be done about them? The latest reboot, I had a tracking cookie from tribalfusion.com. I went under C:\Documents and Settings\... Cookies and deleted the cookie associated with tribalfusion.com, but I suspect it won't be long before I have that as well as others.

    Thanks again.

    Dave
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's good to know!

    Cookies are not problems. You will always have cookies anytime you surf. If you completely block all cookies your surfing pleasure will be greatly diminished and in fact you will not be able to access many sites at all. While doing the final steps (given below), read more about cookies in step 11.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds