Can't remove crypt.xpack.gen and patched.BU.6

Discussion in 'Malware Help (A Specialist Will Reply)' started by GCWesq, Jun 21, 2008.

  1. GCWesq

    GCWesq MajorGeek

    Hi Geeks.

    I'm having trouble removing crypt.xpack.gen in gdimnt.dll and patched.BU.6 in dmserver.dll (picked up by Antivir (free)). I have tried several things, including your Read & Run Me First - although I couldn't download "MGtools.exe" - it kept coming out as "attachment.php", so I haven't been able to run that. I have attached the logs from three other malware cleaning programs. Spybot SD detected a change in the Registry and deleted the key.

    I need to get rid of these as I am having a 1606 problem that I have been having for months - I can't install Office updates (although Windows updates are OK). I need to eliminate these bugs as the cause, although I don't think they are as I think I had the other problem first - although I was using AVG at that stage, and I don't think AVG detects these bugs.

    Very grateful for any help.

    Thanks

    Geoff
     

    Attached Files:

  2. GCWesq

    GCWesq MajorGeek

    Found MGtools.exe on another site and ran it. Zipped log folder attached.

    Thanks

    Geoff
     

    Attached Files:

  3. GCWesq

    GCWesq MajorGeek

    Also ran SDFix in Safe Mode. Trojans still there. Log attached.

    Thanks

    Geoff
     

    Attached Files:

  4. GCWesq

    GCWesq MajorGeek

    Also tried SmitfraudFix. No improvement. Log attached.

    Thanks

    Geoff
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please hangon while I look thru your logs. You should not just be randomly running things without guidance. Tools have very specific uses.

    You first need to download and use the current version of MGtools. You are way out of date. Then attach a new log. Make sure you Save it to your PC. DO NOT attempt to Run or Open it from the download link.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I decided to continue with the logs you posted for now.

    You need to uninstall NetMeter 1.1.3 now. See this: http://www.bleepingcomputer.com/startups/NetMeter.exe-3644.html


    You need to move the below files into a proper folder for the application or delete the below. The do not belong in the root C:
    \Program Files folder.
    Code:
    2007-03-12 23:17 882,264 ----a-w C:\Program Files\HyCam2.exe
    2007-03-12 23:17 87,656 ----a-w C:\Program Files\UnHyCam2.exe
    2007-02-23 01:54 69,632 ----a-w C:\Program Files\CamRes2.dll
    2007-02-23 01:54 57,344 ----a-w C:\Program Files\MClick2.dll
    2007-02-23 01:54 5,272 ----a-w C:\Program Files\HyCam2.tlb
    2006-12-14 03:13 113,628 ----a-w C:\Program Files\HyCam2.chm
    2006-12-14 00:18 3,274 ----a-w C:\Program Files\agreement.txt
    2004-05-05 02:57 2,018 ----a-w C:\Program Files\readme.txt
    2004-04-16 04:07 675 ----a-w C:\Program Files\HyCam2.cnt
    1999-06-24 01:49 587 ----a-w C:\Program Files\8-44100d.wav
    1999-06-24 01:49 421 ----a-w C:\Program Files\8-44100u.wav
    1999-06-24 01:47 317 ----a-w C:\Program Files\8-22050d.wav
    1999-06-24 01:47 225 ----a-w C:\Program Files\8-22050u.wav
    1999-06-24 01:46 183 ----a-w C:\Program Files\8-11025d.wav
    1999-06-24 01:46 135 ----a-w C:\Program Files\8-11025u.wav
    1999-06-24 01:44 127 ----a-w C:\Program Files\8-8000u.wav
    1999-06-24 01:43 151 ----a-w C:\Program Files\8-8000d.wav
    1999-06-24 01:41 220 ----a-w C:\Program Files\16-8000u.wav
    1999-06-24 01:40 260 ----a-w C:\Program Files\16-8000d.wav
    1999-06-24 01:38 956 ----a-w C:\Program Files\16-44100u.wav
    1999-06-24 01:37 1,186 ----a-w C:\Program Files\16-44100d.wav
    1999-06-24 01:34 652 ----a-w C:\Program Files\16-22050d.wav
    1999-06-24 01:34 442 ----a-w C:\Program Files\16-22050u.wav
    1999-06-24 00:54 340 ----a-w C:\Program Files\16-11025d.wav
    1999-06-24 00:50 326 ----a-w C:\Program Files\16-11025u.wav
    Did you knowingly install the below Pando Toolbar stuff. This application is not recommended since it is considered adware.
    Did you knowingly install Crawler Toolbar with Web Security Guard? This is normally seen with Spyware Terminator but you do not have Spyware Terminator installed. Did you uninstall it but decide to keep Crawler Toolbar?



    The below show that you are having frequent crashes. You may want to post about this in the Software Forum. Include information on an error messages you may be seeing.
    Code:
    "C:\WINDOWS\"
    dump3393.tmp  18 Jun 2008       94208  "DUMP3393.tmp"
    dump34bc.tmp  14 Jun 2008       94208  "DUMP34bc.tmp"
    dump3875.tmp  14 Jun 2008       94208  "DUMP3875.tmp"
    dump38c3.tmp  12 Jun 2008       94208  "DUMP38c3.tmp"
    dump3901.tmp  12 Jun 2008       94208  "DUMP3901.tmp"
    dump3a59.tmp  17 Jun 2008       94208  "DUMP3a59.tmp"
    dump3ad6.tmp  18 Jun 2008       94208  "DUMP3ad6.tmp"
    dump3c1e.tmp  20 Jun 2008       94208  "DUMP3c1e.tmp"
    dump3d09.tmp  13 Jun 2008       94208  "DUMP3d09.tmp"
    dump48a1.tmp  19 Jun 2008       94208  "DUMP48a1.tmp"
    dump5ec9.tmp  10 Jun 2008       94208  "DUMP5ec9.tmp"
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right
    click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following
    lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading
    in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.



    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all
    files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now download and SAVE the current version of MGtools.exe to your C:\ folder. Get it here: MGtools.exe Then run it by double clicking on it.



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. GCWesq

    GCWesq MajorGeek

    Hi chaslang. Thanks for your time on this. Greatly appreciated. I see you have been busy with many requests.

    I have done all you requested and I have attached the two logs. I had trouble downloading MGtools - it would open a panel headed Opening MGtools, that would close after about a tenth of a second, then FreeDownload Manager would open and download a thing called "attachment.php" - about 25 KB in size. I finally managed to find a workaround where I used a "built in" option in FDM which went to a Runescape folder (?) and there downloaded a thing called "attachment.php" (same name - but this time it was the same size as the old MGtools I used yesterday - about 1.2 MB). That ran, and seemed OK.

    The trojans are still there - I have found the quickest way to test is by running SuperAnti Spyware - when I'm running that, Antivir brings up a panel warning about them.

    My son downloaded Pando. I have removed it.

    Yes, I had Spyware Terminator which included Crawler toolbar, and I removed Terminator. I have now removed Crawler in case that's what you meant for me to do.

    Thanks for the info about crashes. It may be due to a bad RAM stick which seems to need to warm up at the start of the day before it will operate properly (tested it by removing it and running on one stick alone - many tests done with different combinations and positions in the slots on the MB). Should I pursue the crashes at this stage or wait until I have replaced the RAM?

    I did receive a success message about adding the registry stuff
    to the registry.

    Thanks again,

    Geoff
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds to me like your download manager is causing problems.

    Show me a log or a snapshot then. This sounds like a false positive if it is occurring when SAS is running.

    It was really optional. It is not malware but some people just don't like excessive tool bars.

    If you know you have bad RAM, you should address that issue first.

    You did not uninstall NetMeter. Did you read the link I gave you?

    You said you uninstalled Pando but I still see it in your logs. Did you uninstall after getting the logs rather than at the point I asked the question about it?

    Other than NetMeter, your logs are clean.
     
  9. GCWesq

    GCWesq MajorGeek

    H i chaslang. Thanks for the responses.

    I did do everything in the order listed, including removing Netmeter and Pando. I used Netmeter's own uninstall - perhaps it left some stuff behind. I'll have a look. Same for Pando, I think. I'll have a look at that too.

    Is there a good alternative to Netmeter that you know of?

    Re Download Manager - I haven't had any probs with downloading anything else - only MGtools.

    I have attached the log from an Antivir scan I did this morning. I have also attached a screen print of one of the pages that comes up when I run SuperAnti Spyware. It comes up other times too - when I was uninstalling Pando, for example.
    How are things in New Jersey? I'm in Australia (near Melbourne, down south east corner). Our time-of-day is quite different, hence the slow responses from me. I am at work during the day.

    Many more thanks for your time,

    Geoff
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But perhaps as I stated, you did not uninstall them before getting the new logs. They were still installed in your last logs.

    Is there a good alternative to Netmeter that you know of? [/quote] Why do you even need it? Whatever you install, don't run it all the time at startup. Only run it when you really need it.

    You are better off asking this in the Software Forum but take a look at the below:

    Netstat Live


    Okay but I can say that no one else is having problems downloading MGtools but you. ;) And since you keep mentioning Download Manager and attachment.php sounds to me like it is related. The only time that others have an issue downloading MGtools is when you do not put a check in the Remember Me box while logging into MGs. So if you checked that button, either you have an issue with which browser you are using or an addon to the browser. It really does not matter at this point since you managed to get the proper tools.

    Thunderstorm season. :) Yes there is a significant time difference but I'm often on until 2 or 3 AM my time which is 4 to 5 PM for you I believe.

    Can you put copies of these two DLL files that are being detected ( C:\WINDOWS\system32\dmserver.dll and C:\WINDOWS\system32\gdimnt.dll ) into a ZIP file and attach the ZIP file here? dmserver.dll is a valid Microsoft file called Logical Disk Manager service and I want to see if you have a valid copy. Since the detection mentions Patched.BU.6 maybe something has patched the file.
     
  11. GCWesq

    GCWesq MajorGeek

    Hi chaslang.

    Don't look now, but I just picked up your msg on my work computer. No big deal - I put in a lot of extra hours here, so it's ok.

    I can't understand why Netmeter was still installed - I followed your directions to the letter, including the order. It should have been uninstalled in my final logs. There was still some Netmeter stuff still there when I checked - maybe that was enough to make it register as still installed. Anyway, it's all gone now.

    We used Netmeter all the time, as we spend a lot of time on the net, and we have a slow connection speed, so sometimes you can't tell if you're still connected (nothing happens for a while). Netmeter chomping away would reassure us that something was happening. Hence, we had it on all the time (it only appeared when on the net though). It also showed us when we were getting up to our download limit for the month, so it was useful for that too. BTW, slow over here means 8 KB/s. Before we pass the limit, we are at 26 KB/s.v Thanks for the link.

    I don't know if I checked the 'remember me' box - I'll try that when I get home.

    I don't get home until 7:30 or 8pm usually, so you should be tucked into bed and snoozing by that stage. In fact, what are you doing up until 2 or 3 am??? (I know - answering questions for troublesome people like me http://forums.majorgeeks.com/images/smilies/rolleyes.gif
    rolleyes)!!! I note from your thread times that you might even be up until after that on occasion!!! Come and live in Aussie - you could be up at the same time, but it would be daylight!

    I will re-message tonight when I get home and attach those .dll files.

    Additional heartfelt thanks for your time and advice. It's very comforting to have someone there who knows what he (? chas) is talking about.

    Geoff
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's it! Malware never sleeps nor does it take a vacation. ;) We have to stay awake 24-7-365 just to keep up. :-D:-D
     
  13. GCWesq

    GCWesq MajorGeek

    Hi chaslang.

    OK, I checked the remember me box, and MGtools download worked. Then I logged off and logged on again without checking the box, and it still worked. I tried to retrace the steps I took originally, and it worked. It now works all the time - now that I don't need it!!! Typical computer.:eek: (I did change some options, but it seemed to just change them back again. Beats me.)

    I have attached the zip file containing the .dll files. It was fun trying to make a copy of them - Antivir didn't like it - kept objecting. Fortunately, I was more stubborn! Bad news is, the dmserver.dll file is exactly the same size as the one on my computer at work, which makes me think you are going to say there's nothing wrong with it. We shall see. (I suppose an option might be to get a copy and replace them, but I'll leave the bright ideas up to you.)

    Thanks some more. Hope you slept well.

    Geoff
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is what should happen. When you check the Remember Me box a cookie is saved with your login information and you no longer have to login manually. It is automatic. If you delete cookies, you would then have the same problem again.

    Size does not matter. It's what is in the file.

    That may be the next step but it may not be necessary. It could be that the other file is the root of the problem.

    I'll check these files out and get back to you.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay these files do appear to be infected and even though the dmserver.dll file is the same size as the valid Microsoft file and it even shows information stating it is a Microsoft DLL, it is not the valid file. It has been changed.

    Please download this View attachment findfile.zip to your C:\MGtools folder. Then extract the findfile.bat file from the ZIP into that same folder. Now run the findfile.bat file by double clicking on it. It will search your hard disk for other copies of the dmserver.dll file and will create a log file named C:\flist.txt

    Attach the c:\flist.txt file to your next message.

    Then go to the C:\WINDOWS\system32\gdimnt.dll file and right click on it and select rename. Rename it to gdimnt.dll.bad Tell me if you are able to rename this file.
     
  16. GCWesq

    GCWesq MajorGeek

    Good evening.
    It's kinda good to know there is something wrong with dmserver.dll - gives me hope. (How do they do that???)
    I have attached the flist.txt file (found it under C:\), and I did manage to rename gdimnt.dll to gdimnt.dll.bad.
    Multiple thanks.
    Geoff
    P.S. Ha! Put C\: in brackets by mistake and it turned into :)! That's one way of highlighting an error.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Reboot into safe mode and rename the C:\WINDOWS\system32\dmserver.dll file to dmsever.dll.bad. A new dmserver.dll file will probably show up soon afterwards. This is normal since the system will try to restore it from the copy here C:\WINDOWS\system32\dllcache\dmserver.dll

    We are trying to see if this copy is also infected.

    Double check to make sure that no new copies of gdimnt.dll showed up. Let me know if it did.


    Then reboot normally. Does AntiVir still have detections? If it only finds the files we renamed with .bad then it is okay since we will soon delete them if AntiVir does not.
     
  18. GCWesq

    GCWesq MajorGeek

    We meet at last. How is yesterday going?
    I'm on it.
    geof
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    :-D I need to go home and get some dinner.
     
  20. GCWesq

    GCWesq MajorGeek

    Sound like a good idea.
    Neither file has recreated. I rebooted in safe mode but still nothing. Then I rebooted normally, and still nothing. It's been over half an hour.
    Bob appetit.
    Geoff
     
  21. GCWesq

    GCWesq MajorGeek

    That was supposed to be Bon appetit.
    BTW, do you show up as online when you are? You don't seem to.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Too many people were always bothering me when they see me online so I hide it.;)

    Does this file still exist? C:\WINDOWS\system32\dllcache\dmserver.dll

    If yes, copy it from there to C:\WINDOWS\system32\dmserver.dll
     
  23. GCWesq

    GCWesq MajorGeek

    G'day.
    Thought that might be the case (not showing when online) - you're obviously popular! I can see why.
    The cache file does exist (I already checked). I'll copy it when I get home.
    Continued thanks,
    Geoff
    P.S. Wondering if Pando was the source of the problem - Antivir went berserk when I uninstalled Pando - came up with about 50 detections of the two recalcitrants (not exaggerating). Does that say something?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Pando is not known to be malware or a problem. And just because AntiVir detects a "potential" problem, it does not mean it is a problem. The behavior of a program can sometimes trigger a red flag to an antivirus, antispyware, or firewall program but is does not always mean it is a problem. Any P2P program will typically cause red flags. All that being said, if you don't need Pando, uninstall it.
     
  25. GCWesq

    GCWesq MajorGeek

    Ok. Thanks. It is already uninstalled. Actually, I should have said Pando Toolbar, which you advised me to uninstall earlier, as it has Adware in it. I probably didn't know there was a difference, but I have uninstalled everything Pando anyway.

    BTW, did you notice we have achieved Hot Thread status. I guess others are having problems with the same stuff.

    I also noticed that the record for visitors to Major Geeks was on 21 June last year - which is the Winter solstice. I guess people turn to their computers when the sun goes down.

    I'll be back,

    Geoff
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only for your side of the world. ;)
     
  27. GCWesq

    GCWesq MajorGeek

    Good point. In that case, the reverse must be true for the majority of the world. Northern-hemisphere people turn to their computers when the sun is shining and it's glorious weather:cool. That makes sense... Um... (thinks) looks like I'd better go back to the drawing board on this one.:confused
     
  28. GCWesq

    GCWesq MajorGeek

    Ok. Long, hot days in the northern half = computers overheating = lots of crashes = HELP!

    Southern half - long nights and short days with little sun = people depressed = not much action with the missus = might as well go and annoy MajorGeeks.

    QED.:clap
     
  29. GCWesq

    GCWesq MajorGeek

    Hmmm...
    Just thought I'd better check what day I started this thread.
    Might have put my foot in it, ever so slightly.:eek:
     
  30. GCWesq

    GCWesq MajorGeek

    dmserver.dll duly copied. Checked it with Antivir - seems ok. (No new one automatically created.)

    Antivir picked up the two 'bad' boys and quarantined them. Still no sign of a new gdimnt.dll

    Are we there yet?

    Thanks still more.

    Geoff
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like we are finished.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  32. GCWesq

    GCWesq MajorGeek

    Ok. Will do.
    Many many thanks for your help on this.
    May the bluebird of happiness... how does that go again 99?
    See you next time.
    Geoff :wave
    P.S. If you need any ergonomics advice, you can look me up on ergonomics.com.au
     
  33. GCWesq

    GCWesq MajorGeek

    O, a final question.
    Should I replace gdimnt.dll?
    Geoff
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No! It is not a Windows system file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds