Bugs!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ringman, Dec 21, 2005.

  1. ringman

    ringman Private E-2

    I have run Hijack and attached the log file. Can you help?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments. HJT logs must not be posted until the READ & RUN ME has been completed. You must also attach the logs from the two required online scanning tools (BitDefender and PandaActiveScan). You should also be describing your problems. What you did is like dropping a car off at a car dealer and not telling them what is wrong.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. ringman

    ringman Private E-2

    chas,

    The only bitdefender I could find was a virus program that wanted me to uninstall my current program (Office Scan). I don't want to do that.
    I could not find Panda Activescan.
    I've done everything else on your list several times.
    This bug is one I saw mentioned in one of the posts, I have 6 cartoonish icons on my desktop with labels that read Pharmacy, Gambling, Spyware, Dating, etc. They did not appear when I was in safe mode. I turn of the system restore, restarted and they came back. It or something else has taken over my browser.

    Microsoft Malicious finds nothing.
    Microsoft AntiSpyware found 8 items, when I told it to fix them it wanted to go online and I wasn't wired so that went boom. Now the program shoots craps after checking about 900 files. I've reinstalled it and get the same results... shoots craps.
    Spybot is interesting... it seems like it takes forever to finish running and on several occasions it looks like it bothers the bugs... I say this because 3 separate times OfficeScan has popped up with an announcement that it has spotted a bug, each time Spybot was running.
    Officescan had this to say:
    Infected File:
    C:\Winnt\system32\favme.exe
    C:\system volume information\_restore{e03fce5c-a423-4aec-93e5-749b43199ddb}\rp35\a0006137.exe
    C:\system volume information\_restore{e03fce5c-a423-4aec-93e5-749b43199ddb}\rp35\a0006148.exe
    C:\windows\system32\howiper.exe
    C:windows\system32\favset.exe

    I have a fresh hijack log, bug I don't want to piss you off or get chided for doing something the wrong way.

    Hope I have given you enough info to help me out and I apologize for being a dumb ass.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand what you mean. Just click on the links in the READ & RUN ME for these scanners. They take you right to the pages to run them.
     
  5. ringman

    ringman Private E-2

    Well I try that next. Of course I'll have to be online when I do it and it seemed to me that the instructions told me to run without a connection to the internet. I'm confused too.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions for step 6 state (and I'll highlight in bold RED A FEW KEY WORDS):
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to have you download a tool that is better at finding and deleting files than Windows Explorer.

    Download and install: ExplorerXP

    Now reboot into safe mode and use ExplorerXP to delete all the below files if found:

    C:\WINDOWS\system32\insurance.bmp
    C:\WINDOWS\system32\close.bmp
    C:\WINDOWS\system32\spyware.bmp
    C:\WINDOWS\system32\xxx.bmp
    C:\WINDOWS\system32\pharmacy.bmp
    C:\WINDOWS\system32\gambling.bmp
    C:\WINDOWS\system32\dating.bmp
    C:\WINDOWS\system32\idesk.conf
    C:\WINDOWS\system32\rdt.ini
    C:\WINDOWS\system32\ie2cltr.dll
    C:\WINDOWS\system32\idemlog.exe
    C:\WINDOWS\system32\howiper.exe
    C:\WINDOWS\system32\sphlp32.exe
    C:\WINDOWS\system32\favset.exe
    C:\WINDOWS\system32\hgqhp.exe
    C:\WINDOWS\system32\pppcgm.exe
    C:\WINDOWS\system32\fran-hot.exe
    C:\WINDOWS\system32\qurrv.dll
    C:\WINDOWS\system32\filesafer23.exe
    C:\WINDOWS\system32\logo_big.exe
    C:\WINDOWS\rdt.ini


    Now reboot in normal mode. How is everything working now?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In message number three you made references to the below two folders:

    C:\Winnt\system32 and C:windows\system32

    Why do you have both a C:\winnt and a c:\windows folder? Did you have multiple versions of Windows installed? I would suspect that the c:\windows folder is the active one?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing the previous steps continue with the below so we can be sure we got all of this.

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe

    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\system32\msblank.html
    O4 - HKCU\..\Run: [qwe] corrida.exe
    O4 - HKCU\..\Run: [DCC_send] MNTP.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7E3CD446-7E6B-4E43-8D51-DEF2499569F6}: NameServer = 85.255.113.134,85.255.112.119
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A5A9FC2C-7954-4EBF-972C-FE5480643F99}: NameServer = 85.255.113.134,85.255.112.119
    O17 - HKLM\System\CS1\Services\Tcpip\..\{7E3CD446-7E6B-4E43-8D51-DEF2499569F6}: NameServer = 85.255.113.134,85.255.112.119
    O17 - HKLM\System\CS2\Services\Tcpip\..\{7E3CD446-7E6B-4E43-8D51-DEF2499569F6}: NameServer = 85.255.113.134,85.255.112.119

    After click Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, you may need to restart your computer again.

    Now please attach the contents of the logfile C:\fixwareout\report.txt
    Also attach a new HijackThis log.
     
    Last edited: Dec 23, 2005
  10. ringman

    ringman Private E-2

    This PC started out with Windows 2000 and later Upgraded to XP
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Are you working thru all the other steps now?
     
  12. ringman

    ringman Private E-2

    I have worked through everything on the list and everything LOOKS GREAT. I'm going to assume it's fixed for good and add your name to my list of heros.

    FYI: Explorer XP developed a problem while running and my regular Explorer deleted the files from the list you gave me... more... the exe and dll files weren't there.

    Here's something else that may or may not be related:
    You have probably noticed that this PC was part of a domain. When I logon, if I have the network cable attached, it won't log me on either to the domain or "this computer". If I unhook the cable it logs me on to the domain.

    The two files you requested are attached.
    Thanks and Merry Xmas, Happy Holidays or Have a good day! (Your Choice)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange! May or may not be related. But you should not be able to login to a domain if there is no cable connected. It should not be able to verify your login with the domain server with no cable.

    Can you connect the cable afterwards? Do you get connectivity?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you have HJT fix the below lines as in my instructions:
    O4 - HKCU\..\Run: [qwe] corrida.exe
    O4 - HKCU\..\Run: [DCC_send] MNTP.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7E3CD446-7E6B-4E43-8D51-DEF2499569F6}: NameServer = 85.255.113.134,85.255.112.119
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A5A9FC2C-7954-4EBF-972C-FE5480643F99}: NameServer = 85.255.113.134,85.255.112.119
    O17 - HKLM\System\CS1\Services\Tcpip\..\{7E3CD446-7E6B-4E43-8D51-DEF2499569F6}: NameServer = 85.255.113.134,85.255.112.119
    O17 - HKLM\System\CS2\Services\Tcpip\..\{7E3CD446-7E6B-4E43-8D51-DEF2499569F6}: NameServer = 85.255.113.134,85.255.112.119

    They are still in your log and another baddie showed up:
    O4 - HKLM\..\Run: [dmrvh.exe] C:\WINDOWS\system32\dmrvh.exe

    You need to fix these lines and then boot into safe mode and find and fix the below files:
    C:\WINDOWS\system32\dmrvh.exe
    C:\WINDOWS\system32\corrida.exe
    C:\WINDOWS\system32\MNTP.exe

    Then reboot to normal mode and tell me what you found. Also attach a new HJT log? If any of the O4 baddies have come back, we will need to run the below:

    Please download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
    Last edited: Dec 23, 2005
  15. ringman

    ringman Private E-2

    yes! to both.
    I plug in after logging on and the domain is available.
    What's strange is, when I log on with a legitimate username and password it tells me the domain is shutdown, or my name/password are no good.

    I did fix the problems found by hijack. I going in for the "other baddie" now.
     
  16. ringman

    ringman Private E-2

    I have run hijack again and the bad guys don't show up... at least any that you've pointed out. Attached is a copy of the log.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Watch your O4 lines closely! You will see another new one popped up. Actually the same problem but it renamed itself. See:

    O4 - HKLM\..\Run: [dmhqo.exe] C:\WINDOWS\system32\dmhqo.exe

    Fix it the same way and then run the WinPfind program I gave to you and attach the log.
    Also do the steps in the following link and attach the Ewido log:

    Running Ewido Security Suite

    Also please run the WinPfind tool and post its log.

    Note: you must always attach HJT logs from normal boot mode unless otherwise specified.
     
    Last edited: Dec 23, 2005
  18. ringman

    ringman Private E-2

    I have attached the report from Ewido.
    Officescan picked up a bug while it was running. True to form, I didn't make a note of everything, just a filename: csevw.exe. When I went to explorer to delete it, search couldn't find it... I'm buggered!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If that file name is correct, I never heard of it. Looks like Ewido fix a bunch of things, includine the O4 file I mentioned. You forgot the WinPfind log. Also you should attach a new HJT log from normal boot mode so we can see if that reappearing trojan is gone or has renamed itself again.
     
  20. ringman

    ringman Private E-2

    Okay, here is the WinPFind log that I forgot, along with a new Hijack log.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you are finally clean. But there are two other files you need to delete. I forgot to mention these. Delete:
    C:\WINDOWS\SYSTEM32\CSEVW.EXE
    C:\WINDOWS\SYSTEM32\DMRVH.EXE


    After wards, it is time to work through the below link:

    How to Protect yourself from malware!
     
    Last edited: Jan 1, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds