A Unique Glitch Found...Possible Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ottomated, Apr 21, 2006.

  1. Ottomated

    Ottomated Private E-2

    To all the elite folks at Majorgeeks;

    I have read a couple of your posts and they are very helpful. I just want to congratulate you guys on this excellent forum. I think I will be contacting you for a long time.

    A couple of month ago, I started realizing a strange spike in my CPU usage. As this progressed, the situation became worse. The problem here is that, when ever I execute a internet related programs such as, Steam, MSN, AIM, Internet Explorer, Windows Media Player, iTunes, and some of the plugins that IE offers, my CPU usage for those particular programs sky rocket to 100% usage. For example, when I execute IE, the CPU usage for it sky rockets to 100%, completely slowing down the computer. The weird thing about this is that, no trace of other misc programs are present in anyway before the 100% over flow. When the CPU over flows only the mentioned programs are using the CPU resource. These programs all seem to behave the same way. These listed programs over flows the CPU to 100% a moment after their execution.

    All of the above programs have not caused my CPU to go above 30% in any case what so ever before this incident. This is a very irritating problem because when ever I require these programs, my computer performs like a POS.

    Another intriguing thing about this is that, when these programs are completely exited out of the task list, the CPU stays at close to 0%. Executions of word processing programs and other internet non-related programs do not cause the CPU to over flow. The computer without the execution of the internet related programs, performs perfectly fine.

    As for the treatment, I first realized it was possibly a corruption on the HDD. I have ran wizards to look for corrupted files and have found nothing.

    I have also ran varieties of virus scans such as Norton 2006, Ad-aware Professional, Stinger, Trendmicro Housecall, Highjackthis, and MacAfee. All of these scanners have returned several minor issues but failed in pinpointing the main problem described here.

    I have been looking all over the internet for similar situations like these and found nothing. This is very rare and it is very hard to determine where the problem is located at.

    Thanks for your time and patience,

    Looking forward to your help and guidance,

    Thanks in advance once again, Ottomated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Are you saying that the CPU usage remains at 100% or does it jump to 100% and go down?

    Have you installed or updated anything on the PC within the time frame of where this began. Even doing something like installing Windows updates etc? Do you have any programs (including Windows) set to do automatic updates in the background that could have installed something without you know it?

    Did you install, update, or change an antivirus or security application (like a firewall) recently?

    Do you by any chance use McAfee or worse Norton/Symantec?

    Did you try a temporary disable of your firewall to see what happens?

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. Ottomated

    Ottomated Private E-2

    Hey Chaslang

    thanks for replying. I have followed your instruction and used those tools to scan my computer in safe mode. despite the attemmpt, none of the scanners returned me with a major infection, it has found some cookies but that is about it.

    the cpu remains at 100% all the time while those programs are running. it no longer does a extreme spike. I don't think another virus software is launched to caused this as the programs themselves become 100%. IE does not work and I'm currently using firefox for all my internet activities. others are working but work very slowly and it over heats my CPU as to using uneeded electric currents being wasted.

    I have looked into format but I have alot of programs installed and I don't want to back down and let the hackers win. I want to beat this malware from the source.

    waiting for your reply, thanks

    otto
     
  4. Ottomated

    Ottomated Private E-2

    I've updated my OS before while the virus was infecting my PC.

    Norton seem to stop working since the infection and a couple of other windows related A/V will not update because of this infection. Sounds like I have a tough one because no trace of the .exe can be found.

    I've used Norton/Symantec and MacAfee, none of which found the problem.

    I have disabled and renabled my firewall, the situation remains the same.

    thanks again,

    otto
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need to see the logs from the READ & RUN ME as requested. Otherwise you are leaving me in the dark and I cannot help you.

    What I was requesting was "with the firewall disabled" what is your CPU usage?
    The way you answered, it just sounds like you toggle the firewall on and off and then retested which is not what I requested.

    If you updated your OS while infected, that could be the root of you problems as updating Windows with infections does not normally work very well.

    You must not run multiple antivirus applications (step 3 of the READ ME).

    My point about Norton and McAfee is that their security suites can often bring a CPU to its knees. You could try uninstalling them. But as I said at the beginning, without the requested logs, I'm only guessing. Post the logs or all I can say is you have no malware and to try the Software Forum.
     
  6. Ottomated

    Ottomated Private E-2

    Hey chaslang,

    thanks for your reply. sorry about the lack of logs, let me attach them right now.

    as for the firewall, nothing changes with the firewall off. I have updated the OS with this glitch so I'm not sure what to do next. I've ran all the scanners you suggested in the read me file seperately and nothing came up.

    as for the logs, I could only use hijackthis because bitedefender and panda scan all require the IE browser and my IE is completely destroyed and not functional.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see multiple obvious issues! For example the below processes are all malware.
    c:\windows\system32\dllcache\win32\winlogon.exe
    c:\windows\system32\dllcache\win32\services.exe
    c:\windows\system32\dllcache\win32\winlogon.exe
    c:\windows\system32\dllcache\win32\csrss.exe

    After we fix the above, if your problems with IE not working do not clear up, uninstall IE 7 and go back to IE 6. IE 7 is a beta and should not be used by any one but true beta testers or very experienced users.

    We need to fix a few rogue services related to the above malware. One or more of these services may not be found during the procedure. Since your log did not show all of the typical bad services, I'm going to include a fix for them anyway just incase it shows up later.

    We need to get these three services removed:
    O23 - Service: NTBOOTMGR (NTBOOT) - Unknown owner - C:\WINDOWS\SYSTEM\DRIVER\ntuser.exe
    O23 - Service: NTLOAD - Unknown owner - c:\windows\system32\dllcache\win32\winlogon.exe
    O23 - Service: NTSVCMGR - Unknown owner - c:\windows\system32\dllcache\win32\winlogon.exe

    Here is the procedure to remove these bad services! (You probably will not find the first one - just continue).

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to NTBOOTMGR... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above stop and disable for the following services:
    NTLOAD
    NTSVCMGR

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    NTBOOT

    Now repeat the Delete NT Service steps for:
    NTLOAD
    NTSVCMGR

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Some items below (like processes and services) may not be seen anymore since the above should have fixed them. Just ignore if not found and continue.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O18 - Protocol hijack: its - >IT14H2N1HBIH8-1HT0GAIT{-H000H8IH49PH}
    O18 - Protocol hijack: tv - {HBIH08PH-MG4I-11H2-MHDIH00PH4MGBIT6P}
    O18 - Protocol hijack: wia - >I3{3HANMH9IH7-4H0MGAI76-H2NMHAIHW{PH}
    O23 - Service: NTLOAD - Unknown owner - c:\windows\system32\dllcache\win32\winlogon.exe
    O23 - Service: NTSVCMGR - Unknown owner - c:\windows\system32\dllcache\win32\winlogon.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\system32\dllcache\win32 <--- the whole folder
    C:\WINDOWS\SYSTEM\DRIVER\ntuser.exe <--- probably does not exist

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. Ottomated

    Ottomated Private E-2

    Hey chaslang,

    sorry for the late reply. I was away for almost the entire weekend.

    the other day however, I was chatting with compaq to see if other people were expeirencing the same problem, i told them about the situation and told them about what was going on. They suggested that I made room on the HDD by deleting software that I didn't use....they also said disable all the start up programs and defragment your HDD. I did, and boom there was no sign of that problem.

    today, when i was browsing the web, the problem occured again! this is really irratating me as to now, I dn't know what caused it. All I could remenber is that I had my firewall down for a couple of hours to try out the live streaming program I got for my PSP.

    This is irratating me so much! Right now, I'm going to attach the log of hijackthis scan in normalmode after your great little tutorial. also, I'm going to boot in safe mode and do a scan again to see if anything's wrong. Thanks, waiting for your reply.

    otto
     

    Attached Files:

  9. Ottomated

    Ottomated Private E-2

    Great news,

    when I chatted with the compaq assistance, she recommended me to use this internet history eraser.

    http://www.privacyeraser.com/free-internet-eraser.htm

    and right then, after I wrote reply above this post, I used the eraser. it took probably 4 seconds and BRILLIANT! the symptoms are gone again! amazing, truely amazing because this simple eraser just out did 95% of other A/V scanners and spyware scanners.

    I'll keep you updated on what is happening. I think this is a form of the LSASS vulnerability exploit with a tweated internet temp file.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to work with Compaq tech support that's fine. Then work with them.

    If you want to work here in this forum then please follow my instructions and do not work anywhere else since it only confuses the situation. You still have malware and you have not done what I requested.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds