can't grab hjt log file before browser crashes

Discussion in 'Malware Help (A Specialist Will Reply)' started by marthur, Dec 12, 2006.

  1. marthur

    marthur Private E-2

    Hi
    I've tried this 10 times now. I'm trying to grab the hjt log file but the program and the (firefox or IE7) browser crashes before I can even get ctrl a and ctrl c and posibly paste to a word doc.
    I have downloaded shownew and runkey and am attaching the logs from today. I have run spybot search and destroy, AVG is always on, I also run Ad-Aware and Spyblaster. I downloaded and ran Counterspy (which has found: Chode.GM and CSRSS hijack)
    Also cannot run msconfig as the window shuts down immediately. This is getting me pretty confused!
    I tried to start in safemode but I do not get any options for choosing the OS I want and therefore can not access the safe mode choice (I'm running XP professional).
    Really appreciate your help on this problem!
    Max
     

    Attached Files:

  2. marthur

    marthur Private E-2

    Also:
    I have done as much of the tutorial tools as I possibly could. I could not download BitDefender or PandaActiveScan.
    Thanks
    Max
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to do this and we DON'T want it in a Word doc. As soon as you run HijackThis with log, it is created in the HijackThis folder. The file name is hijackthis.log by default. Just attach that file.

    Attach the log as requested.

    Skip it for now! Also if you cannot get in safe mode, we will do what we can in normal mode.


    Now Copy the bold text below to notepad. Save it as RESTORE.VBS to your desktop. Be sure the "Save as" type is set to "all files". Once you have saved it double click it to run it. Click Yes at the prompt of the message box. If your antivirus program detects this script, make sure you allow it to run.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new GetRunKey log.
     
    Last edited: Dec 12, 2006
  4. marthur

    marthur Private E-2

    Thank you for your help!!!
    Ok, all is done.
    I'm attaching the hjt log file (even though I can't read it for more than a fraction of a second). Also attaching the last CounterSpy log (from this morning) and the runkey log from a few moments ago.
    I did copy & save the instructions as written onto notepads. When I ran the RESTORE.VBS, nothing happened. When I tried to run the fixME.reg the error message I received was it is "not a valid win32 application".

    Something else I've noticed: I've tried to get onto the bitdefender website and both of my browsers report that the site is unavailable. Yet I found I can go into all kinds of associated websites (ie: http://kb.bitdefender.com/site/).
    So what's next?
    Max
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install and RENAME HijackThis as requested in step 7 of the READ ME. You have it here:

    C:\Documents and Settings\Max Arthur\My Documents\Max's Stuff\Business Plan briefcase\virus programs\HijackThis.exe

    That is exactly where we indicate not to install it and you did not rename. Do this and continue with the below. Don't attach another HJT log yet until requested..

    Also note that you should not be running LimeWire while getting HijackThis logs and if you are running LimeWire when you PC starts up you should configure LimeWire not to do this.

    Your problems are due to worm known as W32.Chod@mm.


    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\jtkkmefhi\csrss.exe <--- if you don't find this exact match look for another csrss.exe running from another randomly named folder like jtkkmefhi but DO NOT kill C:\WINDOWS\system32\csrss.exe which is valid

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\system32\jtkkmefhi\csrss.exe
    F3 - REG:win.ini: run=C:\WINDOWS\system32\jtkkmefhi\csrss.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Startup: csrss.lnk = ?

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\jtkkmefhi\csrss.exe <--- if you found a different random folder name being used in HJT above. Replace this with that fullpath.
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Dec 13, 2006
  6. marthur

    marthur Private E-2

    Ok I've done what I could. I did indeed download the Hijackthis program before reading the ttorial. I did downloaded it and change the name but the original winzip was downloaded to documents & setting folder. I have since removed it and changed the download location and extracted and renamed per the instructions. I ran it but the screens closes after milliseconds. I did get a copy of the log file and have attached it.
    I have been unable to proceed due to not being able to keep the Hijackthis program running long enough.
    Any suggestions?
    I am attaching another notepad from shownew & hjt.

    Thank you for your help!
    Max
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's approach this a different way to see if we can keep HijackThis running.

    Download - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.


    Now run Process Explorer by double clicking on procexp.exe
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on explorer.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now look in the list of processes for C:\WINDOWS\system32\jtkkmefhi\csrss.exe and right click on it and select Kill Process
    Now let's see if we can run HJT.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\system32\jtkkmefhi\csrss.exe
    F3 - REG:win.ini: run=C:\WINDOWS\system32\jtkkmefhi\csrss.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Startup: csrss.lnk = ?

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\jtkkmefhi\csrss.exe

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot, locate the below folder and delete it:
    :\WINDOWS\system32\jtkkmefhi

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. marthur

    marthur Private E-2

    Hi
    Well......I did as instructed (printed a copy of instructions, downloaded the Process Explorer, and closed all programs in the systems tray and then unplugged the router cable and rebooted). Then I tried to open the Process Explorer program and it closes with seconds! I tried fifteen or twenty times to go through the first four instructions but I'm not sure that all keystrokes were recorded.
    Not sure what to do next?????????
    Thanks again for all your help!
    Max
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1. Please download The Avenger by Swandog46 to your Desktop.
    • Click on Avenger.zip to open the file
    • Extract avenger.exe to your desktop
    2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
    Code:
     Files to delete:
    C:\Documents and Settings\Max Arthur\Start Menu\Programs\Startup\csrss.lnk
    C:\WINDOWS\system32\jtkkmefhi\csrss.exe
     
    Folders to delete:
    C:\WINDOWS\system32\jtkkmefhi
    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

    3. Now, start The Avenger program by clicking on its icon on your desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    4. The Avenger will automatically do the following:
    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    5. Please attach the c:\avenger.txt too your next reply!

    Also try to run HijackThis now and follow the below if it runs!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\system32\jtkkmefhi\csrss.exe
    F3 - REG:win.ini: run=C:\WINDOWS\system32\jtkkmefhi\csrss.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Startup: csrss.lnk = ?

    After clicking Fix, exit HJT.



    Now attach new logs from HJT and ShowNew and don't forget to attach the c:\avenger.txt log too.
     
    Last edited: Dec 15, 2006
  10. marthur

    marthur Private E-2

    Ok all is done! And it worked!
    Here are the logs you asked for. I could not find this: O4 - Startup: csrss.lnk = ?
    So it was not deleted while I was in hjt.
    I'm sending you a before and after for the hjt logs.
    Thank you for your help! Should I continue onto Bitender and Panda?
    Or what is next?
    Thank you again for your help!
    Max
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes it would be a good idea to run those scans now (if possible) to be sure everything has been fixed.
     
  12. marthur

    marthur Private E-2

    HI tried to get into bitdefender but was not able to. The website is "unavailable" both in firefox and IE7. Also noticed the home page was hijacked to "www.virushelpzone.com".
    What to do?
    Thanks
    Max
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the PandaActiveScan link work?

    I wonder why you would be hijacked to that site. Is it a site you used to use? It seems legit but rather out of date.

    Please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now Go to Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    Now if you are still having problems, please attach new logs from GetRunKey, ShowNew, and HJT. Make sure you download the current versions of GetRunKey and ShowNew before getting new logs. Both of them have been updated!!
     
    Last edited: Dec 18, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds