Big problem (beginning with hldrrr.exe)

Discussion in 'Malware Help (A Specialist Will Reply)' started by wglmb, Sep 27, 2006.

  1. wglmb

    wglmb Private E-2

    Hi, here's what's happened:
    (running XP SP2)

    -- Started up PC, & after ~1 minute everything slowed down
    -- no programs would launch, including task manager and start-->run
    -- right-clicking anything (e.g. task bar) wouldn't work
    -- suddenly eveything started working again
    -- later (~3 mins) it happened again
    -- kept on hapening. I think it hapened only when connected to the internet, so unplugged from the network at this point
    -- searched for the names of all the running processes in Google (on a different PC), and found that hldrrr.exe was the only suspicious one. This process only popped up once into the task manager, and only for a moment.
    -- tried to delete it from where websites said it was (c:\windows\system32\hldrrr.exe) but it wasn't there
    -- I noticed that AVG Antivirus Free Edition wouldn't load. Found that some of its files had been deleted
    -- Tried to reinstall AVG, but it failed to copy some files into the install folder
    -- started following instructions here: http://forums.majorgeeks.com/showthread.php?t=35407
    -- Spybot wouldn't install. Found that some of its files were deleted immediatley after install (I saw them appear in the install folder for a second, and then go)
    -- tried to reboot into safemode. Got as far as the list of options of startup methods (safe mode, safe mode with networking etc.)
    -- selected safe mode
    -- computer restarted itself and returned to the list of options
    -- selected each of the options in turn, but all just made the computer restart
    -- AHH can't start up computer PANIC!
    -- used XP cd to boot the computer into this command-prompt-thingy it has ('recovery console'?)
    -- from there, saw that c:\windows\system32\hldrrr.exe did exist, and deleted it
    (-- got a bit stuck for ideas, was waiting for my registration with this site to send me an email to confim registration)
    -- found that hldrrr.exe is from trojan.tooso.exe (according to symantec)
    -- STUCK FOR IDEAS
    -- registration for this site finished...

    ... and here I am.

    Any ideas? i never got as far as a HJT log or anything, so nothing there...

    Any help will be welcomed!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Are you still having problems? If so, you should definitely complete the READ ME and attach all the requested logs.

    If you are not having any problems, you should still consider completing the READ ME and attaching the logs. If you had this trojan, you could have other issues and it is worth checking. Especially since this trojan is not known as one that deletes files. Thus you may have other problems.
     
  3. wglmb

    wglmb Private E-2

    Yep, still problems.

    If by the readme you mean the thread I referred to in my first post, I can't complete it, because I CAN'T TURN ON MY COMPUTER!
    It's as I said in my first post: I just get a list of start-up, methods when I try to turn on (that's safe mode, normal, etc.). If I select one the computer restarts and returns to the list of options again.

    I have no logs or anything to post, because I got to step 5 of the readme & tried to boot into safemode before runnning any scans, as it suggested, and now can't do anything because I can't turn on my computer.

    Please, can anyone help? If you can just get my computer to turn on, I'll be able to run some scans & stuff, so then it'll be easier to sort out the problem.
    But for now, I imagine that I need to restore some importent system files or something. How can I do that?

    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you use the F8 method or the MSconfig method to boot into safe mode?

    I would guess that you used the MSconfig method and perhaps now it is stuck trying to boot in safe mode but safe mode does not work? Is this correct?

    If the above is true, you may need to follow the steps in the below link from Microsoft to rebuild a boot.ini file without the command that is forcing you into safe mode.

    See this: http://support.microsoft.com/default.aspx?scid=kb;en-us;330184
     
  5. wglmb

    wglmb Private E-2

    Thanks alot!!
    Yes, I used the MSConfig method, and yes rebuilding boot.ini worked!

    I will do some scans and post the logs.

    Bear with me while I do that...
     
  6. wglmb

    wglmb Private E-2

    Right, here are a load of reports from scans.

    I still cab't get into safemood, just normal startup, so that's what they were all done in.

    Hope they're useful... thanks for the help so far!

    (I'll have to make a few posts beacuse I can only attach 3 files per post...)
     

    Attached Files:

  7. wglmb

    wglmb Private E-2

    ...and the other 3
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow the directions for using ShowNew and upload the file that was requested. The log file is newfiles.txt. All other file created while the program is running are just temporary files.

    Do you know what the below two process are for?O4 - HKLM\..\Run: [PeepShowLite] C:\Program Files\Progency\PeepShowLite\pslite.exeO4 - HKCU\..\Run: [FlashMute] C:\Program Files\FlashMute\FlashMute.exe

    You also need to disable MSconfig as per step 7 (that is, you must be in Normal Startup mode). Then get a new HJT log and a new GetRunKey log and attach them.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Now look for the below and delete them if found (let me know what you find)!
    C:\Documents and Settings\MB\Desktop\mms1001.exe
    C:\windows\system32\hldrrr.exe
    C:\windows\exefld <--- the whole folder if found

    Then reboot your PC into normal mode just to make sure everything works okay!

    Also look in your registry and make sure the FirstRRRun key is gone! Do you know how to do this?


    Let me know the results!
     
  10. wglmb

    wglmb Private E-2

    Sorry I posted the wrong ShowNew file. I re-scanned & here's the proper one.

    PeepShowLite is a program I uninstalled a while ago. It lets you 'cut holes' in windows so you can see what's under them.
    FlashMute is a program I still use, which mutes internet explorer & firefox, or just flash plugins in the two browsers.

    I already disabled MSConfig, but here's another HJT log & GetRunKey log anyway.

    Thing with the .reg file: done.

    Hidden files and folders already displayed

    Deleted: C:\Documents and Settings\MB\Desktop\mms1001.exe
    Not found: C:\Windows\System32\hldrrr.exe
    Folder deleted (it was empty): C:\Windows\exefld

    Rebooted (still in normal mode) & yes, the FirstRRRun key is gone.

    Thanks alot!
     

    Attached Files:

    Last edited: Sep 30, 2006
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so how are things working?

    Also did you know you have the below installed which are WAY out of date:
    Ad-aware 6 Professional
    J2SE Development Kit 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6

    You do have the current Sun Java ( J2SE Runtime Environment 5.0 Update 8 ) installed already so the above can all be uninstalled. You really shoud buy the new version of Ad-Aware SE to properly protect your PC. Ad-aware 6 is not going to help you too much since it is so old.
     
  12. wglmb

    wglmb Private E-2

    Sorry, forgot to say: everything is working fine, including when connected to the internet.

    I have uninstalled those Java things, and will look into getting a newer version of Ad-Aware. I didn't realise it was that old!

    Thanks for the help :) . Do you reckon that's it now? Can you see anything dodgey left on the computer?
     
  13. wglmb

    wglmb Private E-2

    (hmm, there's no edit button on my post...there was one there yesterday...)

    I take that back: AVG AntiVirus still won't install (error message attached).
    But it may be an AVG problem not a virus problem, so if you think my computer's OK then I'll beck things up (knowing that I'm not backing up any viruses) and format the disk & re-install Windows.
    That's if I can't get AVG to install. I'm looking on Google for solutions right now. Let me know if you have any ideas.

    Other than that, I just need to know if my computer's clean or not.

    Thanks again!
     

    Attached Files:

  14. wglmb

    wglmb Private E-2

    Well it's not an AVG-problem.
    I tried to install Kaspersky AntiVirus, and its main exe got deleted as soon as install finished...!
     
  15. wglmb

    wglmb Private E-2

    I also just tried to intall Norton AV, but it had its exes deleted too.

    As an experiment, I renamed a .txt file to one of the .exe files that got deleted when Norton was trying to install, and that got deleted to. No matter where it was when I renamed it.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. wglmb

    wglmb Private E-2

    Sophos found loads of stuff. I had to split it into 4 files otherwise it broke the max. file size.
    Most look OK to my untrained eye, but I noticed my old friend hldrrr being referred to! (nothing deleted yet, though, like instructed)

    Avast found nothing.
     

    Attached Files:

  18. wglmb

    wglmb Private E-2

    4th part of the log
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why Sophos is detecting all those registry keys as hidden! Do you use some kind of encryption software to hide things on your PC.

    If you look fro the below registry keys, before running the following process, can you actually see them. Or are the hidden as Sophos implies! If they are really hidden the registry patch may not work.

    HKEY_USERS\S-1-5-21-117609710-1326574676-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run\drvsyskit
    HKEY_USERS\S-1-5-21-117609710-1326574676-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run\hldrrr

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Did you run the Avast scanner? Did it find anything?

    The Bagle infection does delete any security related files when they are opened.

    Configure Windows Search as below and search for all of the below files to see if found. First I will give the file/folder list to search for:
    • hidr.exe
    • hidires <--- this is a folder
    • ldr64.dll
    • m_hook.sys
    • wintems.exe
    • filesnamec001.exe
    • filesnamec002.exe
    • filesnamec003.exe
    • filesnamec004.exe
    • filesnamec005.exe
    • filesnamec006.exe
    And here is how to configure Windows Search:

    Click Start and select Search
    Now Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    • Search system folders
    • Search hidden files and folders
    • Search subfolders
    Then click the Search button.

    Thus replace filename with one of the filenames and click Search. This will take awhile to look for all filenames. Let me know what you find.

    The below link contains information of this infection and includes the list of things I'm searching for:

    http://www.f-secure.com/v-descs/bagle_ge.shtml

    We may be better off running F-secure's Blacklight program to detect rootkits. We shall see.
     
    Last edited: Oct 1, 2006
  20. wglmb

    wglmb Private E-2

    Nope. I didn't even know it was possible to do that!

    No, I can't see them. I used the .reg file as suggested & it said it was succesfully entered into the registry. Does this mean it worked? Or does it mean it couldn't find them to delete them, so just said it had deleted them?

    (I said 2 posts ago ;) ) I ran it, but it found nothing.

    Windows search found NONE of those files & folders!

    Thanks for the help so far...
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may or may not have worked!

    Sorry! I missed that sentence right above the logs!


    Download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.
     
  22. wglmb

    wglmb Private E-2

    That's OK! I imagine your eyes glaze over reading all the posts you do, helping so many people!

    Here's the log for BackLight.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you notice that two of the files I ask you to look for were found:

    c:\Documents and Settings\MB\Application Data\hidires\hidr.exe
    c:\Documents and Settings\MB\Application Data\hidires\m_hook.sys

    Allow Blacklight to fix these two and then reboot and get a new log from BlackLight.
     
  24. wglmb

    wglmb Private E-2

    Those files are fixed, and after rebooting & rescanning, nothing was found (& no log file was made).

    However, hldrrr reappeared in msconfig-->startup items, trying to run c:\windows\system32\hldrrr.exe.
    I removed its 'run' entries in the registry & restarted & it hasn't put itself back. I couldn't find c:\windows\system32\hldrrr.exe to delete it.

    Edit: AVG AntiVirus has succesfully installed now! I'm updating & scanning at the mo.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's typical of program like this. The rootkit was hiding all of this from you. Once it was fixed you could not see this entry.

    Sounds like our work is done here!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  26. wglmb

    wglmb Private E-2

    Wow. Thanks ALOT for all the help! :D Now I can relax... :cool:
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds