ALTEvents trouble

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jnylund, Dec 7, 2004.

  1. jnylund

    jnylund Private E-2

    Ok, I've read through the posts on this, and completed the steps outlined in them.
    The problem: popups for winxxx spyware and antivirus ads, system slowdowns, and browser freezes.

    The solutions tried: symantec virtumonde tool (found several files and reg entries and it supposedly deleted the, subsequent scans are clean)
    • deleted files in /windows/prefetch directory
      ran HJT (in a dedicated directory BTW) and identified oledb.exe as culprit. Fix won't stay fixed, even upon "delete upon reboot"
      Booted into safe mode, but oledb (and its brother, bdelo.*) still runs, and will not allow itself to be deleted.
    I have tried killbox.exe and BHODemon, but to no avail. The trouble seems to be that it still runs in safe mode, so I never get a chance to delete it.

    Absolutely the toughest POS I have ever had to get rid of. All because I forgot to turn Zone Alarm back on for 3 days! Doh!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. joshua cross

    joshua cross Private E-2

    i need help with the error 20
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have no idea what you are talking about and please start your own thread. Provide proper details on what you are talking about and what you are running. Give full error messages.
     
  5. jnylund

    jnylund Private E-2

    I have the latest version of symantec's Virtumonde cleaner (downloaded it today). It initially found 4 files and 3 registry items it cleaned, and subsequent scans are clean.

    I have completed all the steps in the Read Me First... tutorial with the exception of the additional scans...browsing is becoming difficult.

    Ad-Aware (with VX plug-in) found several items (6 cookies and 3 possible hosts files); Spybot found 4 registry entries for ALTEvents.

    Still, the /Windows/Registration/olebd.exe file runs even in Safe Mode and I cannot seem to get rid of it. It shows up in HJT as a "rerun" item and even runs in Safe Mode. Setting HJT to delete it upon reboot does nothing. There is at least one companion file, bdelo.dat, in a .../Local settings/Temp directory.

    I have completed the exact steps in sequence outlined in several other posts that sound like my infection, but to no avail.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT Version 1.98.2 and follow the guideline on where to install it and how to post a log as an attachment.

    Becareful with spelling the malware names. You said,


    Still, the /Windows/Registration/olebd.exe file runs even in Safe Mode and I cannot seem to get rid of it. It shows up in HJT as a "rerun" item and even runs in Safe Mode. Setting HJT to delete it upon reboot does nothing. There is at least one companion file, bdelo.dat, in a .../Local settings/Temp directory.

    Either olebd.exe or bdelo.dat is not correct. One of them has the bd inverted.
     
  7. jnylund

    jnylund Private E-2

    Ok, here is the HJT scan I ran yesterday after completing all the READ ME FIRST steps. Sorry, the correct process names are oledb.exe, and bdelo.dat.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are the below URLs all something you know and use? Which is your expected start & Search page?
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trafton.org
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/

    Let's try this via a simple approach first. I not sure why the Symantec Tool did not fix it.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    oledb.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: CATLEvents Object - {68132581-10F2-416E-B188-4E648075325A} - C:\DOCUME~1\Owner\LOCALS~1\Temp\bdelo.dat
    O4 - HKLM\..\RunOnce: [*oledb] C:\WINDOWS\Registration\oledb.exe rerun
    O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/313c75cac7a2a28d2522/netzip/RdxIE601.cab


    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\Registration\oledb.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\bdelo.dat <--- make sure you delete this and to be really safe it would be better to delete all files in this temp folder. They should not be needed anyway.


    Make sure you are physically disconnected (unplug cable) from the internet and that you exit all programs.
    Run the Symantec removal tool again. Tell me if it finds anything.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. jnylund

    jnylund Private E-2

    Followed the steps with the following results:
    System restore is confirmed off/ hidden files viewable
    Brought up Task Manager and deleted oledb.exe, but it re-spawned almost immediately.
    Ran HJT and fixed the noted entries.
    Booted into Safe Mode to delete:
    c:\Windows\Registration\oledb.exe ---result: access denied
    c:\Documents and Settings\Owner\Local Settings\Temp\bdelo.dat --- result: access denied.
    Ran Symantec Trojan.Vundo Removal Tool 1.2.4 -- No infection found.

    Rebooted into normal mode and ran HJT. Scan attached. Oledb.exe is still alive and well. :(
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Pocket Killbox from here: http://www.downloads.subratam.org/KillBox.zip

    Unzip the files to the folder of your choice.

    Print these instructions or save locally. You must not be connected (unplug cable) to the internet during this.

    Close all open programs, windows and browsers and run killbox and paste each of the filenames below into the box, select delete on reboot and end explorer shell before deleting. Then press the red X button, when it says reboot now, say no and continue to paste the lines in in turn and follow the above procedure every time, DO NOT let it reboot yet.

    C:\WINDOWS\Registration\oledb.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\bdelo.dat


    Then click Start > Run and type %temp% in the Run box, press OK . The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of that Temp folder. Also, empty the contents of your Recycle bin and c:\windows\Prefetch folder.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: CATLEvents Object - {68132581-10F2-416E-B188-4E648075325A} - C:\DOCUME~1\Owner\LOCALS~1\Temp\bdelo.dat
    O4 - HKLM\..\RunOnce: [*oledb] C:\WINDOWS\Registration\oledb.exe rerun


    Now reboot and after your PC comes back up (note: you should still be disconnected from the internet)
    Run HijackThis and double check to make sure the lines are still fixed and also that they have not mutated into another form.
    Also use Windows Explorer to double check to make sure those two files actually were deleted.

    If clean, reconnect your cable and get a new HJT log before running IE (call it before.log). Then run IE and come back here and post your log. Now exit IE and get a new log (call it after.log) Then run IE again and come back here and post your second log.

    If not clean, repeat all the above but this time do everything while in safe mode and disconnected from the internet.
     
  11. jnylund

    jnylund Private E-2

    Victory! It appears that the "end explorer shell" setting was what I needed on Killbox to finally delete the oledb.exe file, and the others finally deleted on reboot. Here is my second HJT scan, after re-connecting to the internet.

    Thank you and big <salute>
     

    Attached Files:

  12. PhilliePhan

    PhilliePhan Guest

    Please don't salute Chaslang - It'll just go to his head. His ego is big enough already!! :p ;)

    Log looks OK to me!

    PP
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wise arse! :p

    Hey PP! Notice that Symantec's too does not always work.


    Jnylund,

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds