Reoccuring trouble with msdirectx.sys file on boot up and disabling firewall

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gtackett, Dec 23, 2005.

  1. gtackett

    gtackett Private E-2

    On about Monday of this week, my son was on AOL IM and hit a link he should not have. Ever since I have been having trouble every time I boot up the computer.

    Here are some of the startup symptoms:

    • The firewall is disabled each time I log on and I have to turn on again
    • I get a message from Avast! Antivirus that the following file exists: c:\Documents and Settings\[by name]\msdirectx.sys (BTW I have four users on my XP Home OS and no matter who I log in as, I get the same message execpt the folder corresponds to the person logging on)
    • Sometime I get an error message that says something about 'strtas'
    • Sometimes I have been having problems just tuning the computer off when I hit 'Shutdown' or 'Restart' and I have to do a warm shutdown by holding the on/off button in for a few seconds.

    I have read the 'READ & RUN ME FIRST Before Asking for Support' thread and have followed as closely as possible. Here are some comments for each of the steps:

    Step 0: Went thru that list. None of the items were listed in Control Panel / Add Remove Software so I did nothing.
    1: I haven't messed with the Disable System Restore at all
    2: Done
    3: The only Antivirus Software I am running is the free version of Avast! v4.6Home
    4: Downloaded, installed and updated all software except CounterSpy since I am running Windows XP and CAN run MS AntiSpyware.
    5: Rebooted into Safe Mode. Did a bunch of cleaning on this. I had to log onto each user to use CCleaner but all other applications I ran from the Administrator user in Safe Mode. Ad-Aware caught a few items. Spybot caught a few. MS Antispyware didn't find anything. I didn't run CWShredder or Kill2Me because they did not seem to apply.
    6: Ran Bitdefender and that log is attached.
    6 cont: Ran Panda ActiveScan and had an interesting problem. About half way thru the scan, a window popped up and it asked me to "Choose a Profile". My choices were PstLoadTmp000 and PstLoadTmp001. I chose the first one and the entire application shut down. The log file from this first running of Panda ActiveScan is attached. I went ahead and ran this scan again. Same thing happened but this time, under my choices for profiles, there were two additional choices PstLoadTmp002 and PstLoadTmp003. I hit the cancel button and got out completely. I did not attach the second log to this posting. I then rebooted into Normal Mode
    6 cont: I looked thru the Special Removal Procedures but none of them seemed to apply to me so I didn't run.
    7: I ran HiJackThis and the log is attached.
    8: I have not tried any of the Alternate Scans

    Thank you for this service.

    BTW - I think I attached the files correctly but I'm not sure. My have to do a second post if they are not attached.
     
  2. gtackett

    gtackett Private E-2

    Sure enough, I didn't get the attachments quite right. Here they are. Thanks for you patience.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you follow the posted steps for creating the BitDefender log? It has annoying spacing in it making it excessively long and hard to follow. We need to determine if our procedure is the problem. Please let me know. Thanks!

    Are you running CYBERsitter 2000 or 2001? If so, they are pretty stupid for putting there EXE into the Windows folder.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\l071.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O4 - HKLM\..\Run: [mpW1oa.exe] c:\documents and settings\garland tackett\local settings\temp\mpW1oa.exe
    O4 - HKLM\..\Run: [strtas] l071.exe
    O4 - HKLM\..\Run: [LonPS2] c:\windows\system32\norml\repcale.exe c:\windows\system32\norml\palsp.exe
    O4 - HKLM\..\RunServices: [strtas] l071.exe
    O4 - HKCU\..\Run: [strtas] l071.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {886DDE35-E955-11D0-A707-000000521958} -
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} -
    O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} -

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\SYSTEM32\bUS.dll
    C:\TEMP\salmau.dat
    C:\un.exe
    C:\PROGRAM FILES\Kudd.com
    C:\WINDOWS\INF\biU.inf
    C:\WINDOWS\package_MARKETING27.exe
    C:\WINDOWS\SYSTEM32\datastore.dll
    C:\WINDOWS\SYSTEM32\l071.exe
    c:\windows\system32\norml <--- the whole folder
    c:\documents and settings\garland tackett\local settings\temp\mpW1oa.exe <--- remove all file in this temp folder that it allows you to.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Dec 24, 2005
  4. gtackett

    gtackett Private E-2

    Yes, I ran the program and then created the html file on my desktop. I then went to my desktop, opened the file and then saved as a text file. Thought it was pretty straight forward but I could have messed up.

    Yes, I'm running CYBERsitter. Having a filter is not an option. Which one I use is.



    I do have a couple of questions. You said:

    I thought the tutorial told me not to do this.

    I'll disable as you have instructed but that is a little confusing.

    Another question - you said ...

    I noticed that when I ran CCleaner in Safe Mode, I had to run for each individual user (i.e. I could not run CCleaner just logged in as Administrator and clean up all users.) If you're telling me to run CCleaner again, should I run for all four users and the Administrator before I delete all the files in the Prefetch folder? Or, should I just run from Administrator? just from Garland Tackett user? Is there any way to have CCleaner clean up all users at one time instead of individually?

    Thanks for the prompt reply. I'll get cracking on it today and will get back with you. Again, thank you for this service.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is a link to click on in the READ ME that gives a procedure to do it properly. Don't worry about it now.


    You are correct. I need to fix that boiler plate message since we have changed how we recently changed the READ ME to not disable System Restore until after fixing everything. It is not a problem if you already did it.

    It is best to run Ccleaner for all users, however, if you are only cleaning up one account (the steps I gave you are for a single log related to a single user) just work on that account. You can do cleaning steps on the other accounts later as necessary. But to see what prolems they may have, you would need HJT logs for each one. All users have common items as well as individual items that may load.
     
  6. gtackett

    gtackett Private E-2

    done

    done

    done

    no problems here

    I booted into Safe mode as the Administrator. I deleted all the files but the last (mpW1oa.exe) because I couldn't find. I double checked that all hidden files and folders were viewable. Even did a 'search' and couldn't find. When I couldn't find under Administrator, I switched to Garland Tackett user and still couldn not find. I did delete all the .tmp files in this folder as directed.

    Additional comments: I found a C:WINDOWS\INF\biU.PNF file but did not delete since it was not on your list.

    I found the C:\WINDOWS\SYSTEM32\l071.exe file under the Garland Tackett user but not the Administrator (just an interesting note).

    I ended running CCleaner for both the Admin and the GT user since I knew I had put deleted files to the recycle bin in each. I deleted the files in the Prefetch folder but I did not delete the folder itself since you didn't mention.

    Question: I'm curious why I deleted files after I had run CCleaner. Why weren't Prefetch files deleted before I ran CCleaner?

    I did this for the Admin and all four of my users.

    File is attached and everything seems to be working fine. I booted up in normal mode under my user name.
     

    Attached Files:

  7. gtackett

    gtackett Private E-2

    Should I now enable the System Restore? (probably not - you probably need to look at my most recent HJT log.)

    If I understand you correctly, I need to now use the cleaning proceedure on each account and and not just the Admin (in Safe mode) or just my user. Interesting. This will take longer than I thought. Those pesky teenagers. Messing up my Christmas. :) I really need to make them fix this mess.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean!

    I would not run ALL of the steps of the READ ME for each account. Many of the tools will clean all areas independent of the user account. Don't worry about the online scans. I would just recommend running Ccleaner, Spybot, and Ad-Aware on each account and see how the look. Make sure none of the other accounts have any problems. After you have done this and things look clean, I would then enable System Restore.

    After that, it is time to look at: How to Protect yourself from malware!
     
  9. gtackett

    gtackett Private E-2

    Taking your advice, I did check out one more of my XP users (my son - his initials are MGT). When I logged into his user name, I got an error message from MS AntiSpyware indicating that there was a Comet Adware (not quite sure of the name but it was "Comet" something). MS AS asked me if I wanted to remove and I said yes. This is only coming up under my son's user login. So ...

    I went thru the cleaning procedure again as outlined in your READ ME FIRST post and had these comments:

    Adaware SE didn't find anything
    Spybot indicated that the Security Center.Firewall needed to be fixed. I didn't fix this since I had (Per the "How to prevent malware" thread) installed a second firewall (Kerio) and turned off the MS firewall.

    The Bitdefender log is attached.
    I had trouble with the Panda ActiveScan. I tried to run three times and each time it failed. I couldn't ever get a log file from this scan.
    The HJT file for MGT is attached.

    One note - when I logged back onto the MGT user, the Comet Spyware message from MS AS did not pop up. Maybe it's gone?

    Thanks for your help.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should verify that BitDefender actually deleted all those files it indicated in the log.

    You have that l071.exe showing in this account to. You may need to fix this in all accounts.

    Have HJT fix the below lines:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
    R3 - Default URLSearchHook is missing
    O4 - HKCU\..\Run: [strtas] l071.exe

    Then boot into safe mode to delete C:\WINDOWS\SYSTEM32\l071.exe (it may already be gone since we deleted it previously).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds