Asking For Help Per The FAQ's

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by indyattic, Aug 24, 2004.

  1. indyattic

    indyattic Corporal

    This computer came from my husband's office, and it wasn't clean when it got here. I spent all weekend reading your site and running programs. A bunch of stuff was cleaned off, including "winshow" which was just annoying the heck out of me.

    I still have a pop-up problem though - can I please post my hijackthis log (as an attachment, of course!) for review?

    So far, I have run Panda, Trend Micro, Norton and E_Trust anti-virus programs. I have System Restore turned off. "Network Security Service" is disabled. Doxdesk doesn't see anything. I have updated and run Ad-Aware, SpyBot, About:Buster, HSRemove, CWShredder, Kill2Me, and CCLeaner. I ran all those programs in Safe Mode, as well as regular ol' mode.

    But, I still get pop-ups (not "Messenger") - albeit not nearly as many as I was getting. The Hijack This file has a couple of items that look like they shouldn't be there, but if I just "fix" them they come right back.

    So, please? Can I have a little help?
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    They come back because Hijack This is not a removal tool.

    Looks like you did everything, so please do post your Hijack This log file. Also, if these items you remove keep returning, search Google for their names, that what Hijack this is for, to identify these things :) Let us know!
     
  3. indyattic

    indyattic Corporal

    Thank you for helping me with this.
     

    Attached Files:

  4. indyattic

    indyattic Corporal

    I forgot to add that, per your suggestion. I Googled some of the things that look odd. Like the XudY.exe file, plus the others that seem to be random character generations.

    I did not get any hits on them though.

    Angie
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A big part of your problem is Kazaa. Do you really need to use this? You are going to have problems keeping you PC clean with this on your PC? You have a bunch of trojans/problems (I lump the Kazaa stuff in here too):

    C:\WINNT\System32\P2P Networking\P2P Networking.exe
    C:\WINNT\System32\XudY.exe
    C:\WINNT\System32\Txma1mq.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\ljsws.dll/sp.html#37049
    O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
    O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
    O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\LgnJ8V3.exe
    O4 - HKLM\..\RunServices: [scvhost.exe] scvhost.exe
    O4 - HKLM\..\RunServices: [System Log Event] csrss32.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] Microsoft.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O18 - Filter hijack: application/octet-stream - {6585E5B4-4D2A-4A1D-A219-4102C64BA999} - C:\WINNT\chp.dll

    You need to kill these processes with Task Manager:

    LgnJ8V3.exe
    scvhost.exe
    csrss32.exe
    Microsoft.exe

    Enable viewing of hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650
    Then boot in safe mode and use Windows Explorer to delete:
    C:\WINNT\System32\LgnJ8V3.exe
    C:\WINNT\System32\XudY.exe
    C:\WINNT\System32\Txma1mq.exe
    The next three files could be in any of four directories: C:\windows, c:\windows\system, c:\windows\system32, c:\documents and settings\current user\ Local Settings\Temp (where curren user is your user login name):
    scvhost.exe
    csrss32.exe
    Microsoft.exe

    You may have to enable Advanced search options and search for them. If you have a problem deleting any of the files, bring up Task Manager (CTRL-ALT-DEL) and end the process if it is running. Then delete the file.

    I see remnants of HSA hijack there too. Which may need more work?

    Let's see where we get with what I gave you so far.
     
  6. indyattic

    indyattic Corporal

    No, I don't need Kaaza. DH was downloading music, but I don't. How do people download stuff without messing up their computers, if Kaaza is such a horror?

    I will get started on the list you gave me, and post again later.

    Thanks again - I really, really appreciate this!

    Angie
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. indyattic

    indyattic Corporal

    You said to end 4 processes: LgnJ8V3.exe, scvhost.exe, csrss32.exe and Microsoft.exe, but they were/are not running. (At least, when I open Task Manager they are not listed there.)

    Then, per your suggestion, I went into safe mode and looked in several directories for 3 files to delete, but I did not see them in any of the directories you cited. So, I did a search on them, and did not come up with any results.

    I only got results when I searched for files containing those words. Besides Ad-Aware logs and the HijackThis.txt, those file names appeared in backup.reg, CollectedData_3495 XML, and regLocal.reg.

    Last night, I noticed that the XudY file was running when I was in Task Manager, but this a.m. it is not.

    Also, I just had a thought - I have only been logging in as "Owner." Do I need to log in as "Administrator?"
     
  9. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Try logging in as Administrator yes. Did you make sure you can view hidden files as Chaslang requested and try this from safe mode? The answer to your question "How do people download stuff without messing up their computers, if Kaaza is such a horror" is they dont. Theres used to be a Kazaa Lite, but it was killed off, I hear theres a program called Kazaa resurrected or similar, try searching Google for that.
     
  10. indyattic

    indyattic Corporal

    I think I'll hold off on installing anything new for the time being :). I don't need Kaaza - DH used it at his store, but I'm on dial-up. It takes me forever just to download pictures.

    Can you give me the name of a file that should be hidden so I can be sure I'm viewing hidden files? I promise not to delete it.

    Angie
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just look in (with Windows Explorer) the root directory of drive C as you switch between Show hidden file and Do not show hidden files. You should see several things change one of which is pagefile.sys
    You should also notice directories like Recycler and System Volume Information come and go. Also, make sure you do not have checks on Hide extensions for known file types or on Hide protected operating system files.
     
  12. indyattic

    indyattic Corporal

    Yes, they toggle on and off. And, the icons look faded compared to the regular ol' files. I was ok then - not forgetting anything.

    I ran the searches again, and I do not have those files. I *do* have LgnJ8V3.exe though. But the instructions didn't say to look for or reomve it - I accidently was reading the wrong part of the message second time around.

    Is that supposed to be there, or should I delete it?

    Angie
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They certainly did say to delete it. I repeat part of that message:
    "
    Then boot in safe mode and use Windows Explorer to delete:
    C:\WINNT\System32\LgnJ8V3.exe
    C:\WINNT\System32\XudY.exe
    C:\WINNT\System32\Txma1mq.exe

    "

    You need to start telling us what you have been doing! Did you uninstall Kazaa? P2P Networking? Did you fix the lines in HijackThis?
     
    Last edited: Aug 25, 2004
  14. indyattic

    indyattic Corporal

    YIkes - looks like my brain cells were hijacked.

    Up until now, I had not done anything, but now I have.

    I deleted the LgnJ8V3, the Xudy and the Txma1mq files. I also uninstalled Kazaa. I have not fixed any lines With HijackThis.

    Is removing the P2P Networking a different step than removing the Kaaza? If it is, I have not done that.

    What next?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    P2P Networking may or may not have been uninstalled with Kazaa. Check Add/Remove programs and uninstall if still there.

    Run HijackThis and fix the below lines if still there:
    O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\LgnJ8V3.exe
    O4 - HKLM\..\RunServices: [scvhost.exe] scvhost.exe
    O4 - HKLM\..\RunServices: [System Log Event] csrss32.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] Microsoft.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O18 - Filter hijack: application/octet-stream - {6585E5B4-4D2A-4A1D-A219-4102C64BA999} - C:\WINNT\chp.dll

    Then run a new scan with HijackThis and post it back here as an attachment. Make sure you exit all browser (Internet Explorer) sessions before running the scan.
     
  16. indyattic

    indyattic Corporal

    Attached is the new logfile. I think something is changing names. I am going to try your "Generic Solution For "Only The Best" " advice, since your initial post specifically mentioned that it looked like some pieces of that were still around.

    I uninstalled the P2P Networking thing.

    I also am going to uninstall the "Musicnotes" thing - it is shareware. (Who knows where he got it). I figure if it is bringing me problems it needs to go, and if it isn't then I can just re-download it.

    I am also going to find and run the program that removes the Kazaa spyware.

    Let me know if there's anything else you want me to do.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run this and let me know if it finds anything (you may have a peper trojan):

    http://www.memorywatcher.com/uninst.exe

    You only show one symptom line from Only the Best. It may be a remnant. Just the O2 line with ljsws.dll. Don't bother trying the Generic Solution right now. You don't need it.

    Also, fix these line with HJT:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\ljsws.dll/sp.html#37049
    O18 - Filter hijack: application/octet-stream - {6585E5B4-4D2A-4A1D-A219-4102C64BA999} - C:\WINNT\chp.dll

    Then reboot in safe mode and delete:
    C:\WINNT\system32\ljsws.dll
    C:\WINNT\chp.dll

    Reboot normal and post a new HJT log attachment.
     
  18. indyattic

    indyattic Corporal

    The MemoryWatcher didn't flag me as finding anything. It just opened and then disappeared - I didn't see a report telling me it didn't find anything.

    I fixed and deleted, but the chp.dll entry won't leave the HijackThis file. The searches say that it is gone from my computer, I even deleted it from my recycle bin.

    I've been in and out of Safe Mode several times, and last night I saw about 50 files in the System32 directory that look suspicious, but I'm certainly not sure about anything.

    I googled every one, and two of them appear to me to be spyware related: appsys.exe, and amcompat.tlb. Am I right?

    THere's a "StopzillaBHO.dll" that looks suspicious, because I haven't downloaded "Stopzilla." (Remember, my DH had this computer before I did. Argh.)

    The rest of them scored no Google hits, with an occasional exception of other people's posted "HijackTHis" logs. They all look like random character names, like Vva6i.exe, bhote.dll, and Tsd13Q.exe. None of them have any significant information in the hover box, just a version (usually 1.0.0.0) and an installation date.

    Anyway. I ran Spybot and the Ad-Aware deep scan a couple of times, in both modes. Here's the most recent HijackThis log.

    Angie
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

     
  20. indyattic

    indyattic Corporal

    That would make sense - this had Norton on it before I took it off.

    I ran the Trend-Micro scan again, and it deleted all those suspect files this time.

    I deleted the StopzillaBHO.dll.

    I do have system and hidden files visible - I check that all the time (but I checked again too.) I do not have the System Restore turned back on.

    I ran Ad-Aware in Safe mode, "Scan Volume For Ads." It found 7 things - I am attaching a log.

    about:Buster will not run now, in either mode. I get a message "Run Time error '339'. Component 'mscomctl.ocx' or one of its dependencies not currently registered: a file is missing or invalid."

    I had already run 3about:Buster early on - prior to my initial post - so I tried that for kicks. It now gives me the same error.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was Ad-aware able to fix those items it found? Especially the 4 related to CWS (2 of which were using ADS)?
     
  23. indyattic

    indyattic Corporal

    Wow - You're fast! I am convinced it is because you are a god.


    I found a MajorGeeks FAQ that told me how to fix my file, so I did that. Yes, Ad-Aware claimed to fix the problems it found.

    I ran Buster once in Safe and once in Normal. The logs are attached, #1 is in Safe. The first scan found more.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yeah! That's me! I'm the god of anti-spyware. :D

    The stuff About:Buster found is most likely left over from an about:blank or HSA hijack.

    Can you fix that O18 line in HJT now:
    O18 - Filter hijack: application/octet-stream - {6585E5B4-4D2A-4A1D-A219-4102C64BA999} - C:\WINNT\chp.dll

    And then delete the file after booting in safe mode.
     
  25. indyattic

    indyattic Corporal

    Grrr...Nope. Can't find the file to delete it. c as in Charlie, h as in horse, p as in Paul (dot) d as in David, ll as in llama - no hits in either Safe or Normal mode, logged in as both Adminisrator and Owner (the only 2 ID's set up.)

    I checked the box in Hijack this, pressed "fix" and it still appears. I tried rebooting before scanning again...basically every combination of modes, boots and scans I could think of.

    I didn find and delete it several steps ago...

    Maybe unistall/reinstall HijackThis?

    Angie
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1) Go here and download Registrar lite and install it: http://www.resplendence.com/reglite
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls and tell me what you see in the Value field.

    Then use the search function of Reglite (the spy glass) and search for chp.dll .
    Report back all the addresses (the full path registry key) where each one occurs.

    Also please double check that you have these set correctly (let me know):
    • Click Start.
    • Open My Computer.
    • Select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Under the Hidden files and folders heading select Show hidden files and folders.
    • Uncheck the Hide protected operating system files (recommended) option.
    • Uncheck Hide Extensions for know file types
    • Click Yes to confirm.
    • Click OK.
     
    Last edited: Aug 30, 2004
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If still having a problem after doing what was in my previous messages copy all the information below into a file called chpfix.reg and save it to a place you can find it. After saving it, locate the file with Windows Explorer and double click on it. Answer yes to merge it into your registry. What is does is deletes a bunch of registry keys this hijacker puts into the registry.

    REGEDIT4
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Chp.CallThrough]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Chp.CallThrough.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6585E5B4-4D2A-4A1D-A219-4102C64BA999}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\application/octet-stream]
    "CLSID"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D962EF38-5FB0-4761-8638-C86F085E25E6}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8427BD70-5444-46CE-B15D-19E9CB49DF64}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\application/octet-stream]
     
    Last edited: Aug 31, 2004
  28. indyattic

    indyattic Corporal

    After I click "go" the address line drops the "\\AppInit_DLLs". No AppInit.DLLs value exists on the right side

    I searched function the entire registry for chp.dll . Attached is a screen shot - hope that's ok? My tpying sucks.

    Also included a screen shot to show you that I swear I am viewing all the files. (It's like that in Safe Mode too.)

    I am going to try the registry thing in the next post now, and will post again after that.

    Angie
     

    Attached Files:

  29. indyattic

    indyattic Corporal

    :) - I swear it's just like magic!

    Atached is my HIjackthis.log - seems that I might actually be cured.


    How can I thank you?

    Angie
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good Angie! Good work! Fun wasn't it. It's great to have that one out of the way.

    Your log looks good but one question: do you have a SmartLink Modem. I noticed a new line that was not in your previous log:
    C:\WINNT\slrundll.exe

    From what I can tell it is supposed to be related to that modem.

    You're welcome! And thank us by sending your friends to MG's!
     
  31. indyattic

    indyattic Corporal

    We seem to have a big difference in defining "fun" :)


    Yes, I do have a SmartLink modem.


    Really, the whole reason I made DH bring this one home was because the local repair shop screwed up mine so badly. It was a rebuilt machine, that started shutting down spontaneously. (I always kept my machine so clean - I didn't even open my mail in HTML.) I took it to the shop we bought it from, where they dx'd a bad motherboard. THey couldn't get an exact replacement, so they put "one that would work" in, but it didn't....they ended up formatting and restoring the C: drive, which awakened an amazing amount of viruses and trojans that the previous owner had apparently downloaded. ( I couldn't deny that DH might possibly have downloaded the porn, but I know darned well he didn't download massive amounts of rap and 70's disco tunes.)


    I tried at least three other help-boards to get past the virus and spy stuff, finally just gave up and told DH to bring me his so I can get his books caught up. I just about *died* when I saw this one had issues too.

    THANKS CHASLANG! YOU'VE SAVED MY MARRIAGE!

    Seriously - you're a God!

    Angie
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome Angie! Happy I could help and I think that is the first marriage I have saved. :D
    Thanks for the complements!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds