Clkoptimizer and Narrator

Discussion in 'Malware Help (A Specialist Will Reply)' started by Djay, Jan 15, 2005.

  1. Djay

    Djay Private E-2

    On 12/31, I was hijacked. After completing everything on "...you have read this", and installing Spy Sweeper, which btw picked up 29 known threats, Clkoptimizer and Narrator (wiwrku) keep coming back. I removed narrator with hijack this several times in safe mode with the restore off. Btw, Norton got 2 viruses, and the other on-line sweeps picked up 3 more. All Trojans. I always update all the spy detection tools and Norton.

    Info that may help: Ad-aware picks up coolweb and VX2 after narrator reinstalls. they are located in windows/system32/eoebap.dll (I did do the VX2 plug-in)

    Spysweeper picks up huhtng.exe after narrator reinstalls. It is also running in start. Could this be related?

    Just for fun, I ran the search files for the date and time the virus hit me and it came up with 234 .exe apps or prefetch installed or modified at that time. Now I run it and it comes up with six or so.
    They are: stcupdt.exe in Recyle Bin (second thought?), bundles.exe in recycle bin, sahagent.exe in C:/temp, secure.exe C:windows/system32 and the secure uninstaller.exe

    Also, two items on the hijack this log that we do not recognize and can't find are: C:\windows\system32\fmwgyc.exe and C:\windows\system32\ottljc.exe.

    My sister, a geek, help me with most, but we need help with this one. Thanks in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run all steps from READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal then do the below.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Also for the VX2 problem (you may have the new type) do the below to get ready to fix it:

    Download the below tools (but only run what I tell you to run):

    Pocket KillBox

    VX2.BetterInternet Finder XP/2k - Version Msg126

    Generic Find It Tool - NT/2000/XP

    Extract all the files from the Generic Tool into its own folder ( like c:\FindIt )
    Then run find.bat. Post the log it creates back here as an attachment. Make sure you wait long enough. The log will popup when it completes.
     
  3. Djay

    Djay Private E-2

    Thanks for responding, I did work through "Read this first . . ." Time consuming, but very effective. Makes me appreciate the amount of time and energy you and your counterparts put into this support forum. I will run the HJT log and the find.bat log and post according to the instructions. I will try to get back to it tonight. Thanks again. Later.
     
    Last edited: Jan 16, 2005
  4. Djay

    Djay Private E-2

    Ok, here are the two logs. Very interesting. You should know that I ran through the "Read me first..." steps several weeks ago. I did not do it again, so you can see all the stuff that keeps coming back. Thanks again and again.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First look in Add/Remove programs for an uninstall related to WildTangen and use it if found.

    Okay here is the first part of the clean up! My next message will be part 2.

    PART 1:
    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\huhtng.exe


    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: SDWin32 Class - {340B7310-B7E6-48C0-A600-6D73A5C33237} - C:\WINDOWS\system32\fmwgy.dll
    O2 - BHO: SDWin32 Class - {DB56D7ED-70F7-473A-889C-5DC730F8B781} - C:\WINDOWS\system32\ottlj.dll
    O4 - HKLM\..\Run: [HPGamesActiveMenu] C:\Program Files\WildTangent\ActiveMenu\HP\Games\ActiveMenu.exe
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\huhtng.exe
    C:\WINDOWS\system32\fmwgy.dll
    C:\WINDOWS\system32\ottlj.dll
    C:\Program Files\WildTangent <--- the whole folder if it still exists

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.


    The below two are up to you but they are not necessary and my personal preference is for no automatic updates. I'll do them myself when I want and install only what I want and need.

    backweb-8876480.exe is a process that comes with the Logitech products software. It manages the automatic update check as well as providing you with new for the latest offers and products from Logitech. This is a non-essential process.
    LDMConf.exe - Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech

    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
     
    Last edited: Jan 17, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PART 2: Make sure you do the other steps in Part 1 first

    Here is a list of files that we need to delete using Killbox (directions on how to are later - just read thru first before doing anything)

    C:\WINDOWS\SYSTEM32\cycopu.dllom
    C:\WINDOWS\SYSTEM32\eoebap.dll
    C:\WINDOWS\SYSTEM32\hzhwqu.exe
    C:\WINDOWS\SYSTEM32\papbvu.dat
    C:\WINDOWS\SYSTEM32\wiwrku.exe
    C:\Documents and Settings\All USers\Start Menu\Programs\Startup\huhtng.exe


    And here is how you need to do it.

    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Delete on Reboot.

    Now you are going to repeat the below steps for every file. Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINDOWS\SYSTEM32\cycopu.dllom

    1) Now, Copy and Paste fullpathfile into the box
    2) Check the option to Use Dummy.
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click NO.
    5) Repeat for all files

    DO NOT Allow your machine to Reboot until the last item has been entered:

    When the last item has been entered and you are prompted to reboot, allow Pocket KillBox to Reboot your computer.

    Reboot in normal mode. Tell me if you get any error messages on reboot and tell me the exact messages. (I expect there will be some related to some of the filenames above).

    Now get another find.bat log and also post a new HijackThis log.
     
  7. Djay

    Djay Private E-2

    OK, so far, so good. However, the C:\documents and Setting\All Users\Start menuPrograms\startup\huhtng.exe was not in processes. Also, the two files ending in fmwgy.dll and ottlj.dll were gone by the time I went to them through explorer.
     

    Attached Files:

  8. Djay

    Djay Private E-2

    I worked through the Killbox procedure, deleting the files you identified on reboot. The box for dummy was not active, so could not check. Here are the two logs, but I am afraid the pesty wiwrku.exe is still there. Very stubborn. Any suggestions?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let'e try again with some different options and a different approach. This time we will boot to safe mode first and want your connection to the internet phyiscally unplugged (pull the cable). Thus you need to print these instructions or save them in a notepad file. I also want you to make sure no browsers are opened until I request it.

    So print now, disconnect (unplug), and reboot in safe mode now before continuing.

    Copy and paste the below quoted information below to notepad. Save it to your Desktop as type "all files" and name it fixvx2.reg
    Now doubleClick on the fixvx2.reg file you made and allow it to merge the registry entries into the registry.

    Here is a list of files that we need to delete using Killbox (directions on how to are later - just read thru first before doing anything)

    C:\WINDOWS\SYSTEM32\cycopu.dll
    C:\WINDOWS\SYSTEM32\eoebap.dll
    C:\WINDOWS\SYSTEM32\hzhwqu.exe
    C:\WINDOWS\SYSTEM32\papbvu.dat
    C:\WINDOWS\SYSTEM32\wiwrku.exe
    C:\Documents and Settings\All USers\Start Menu\Programs\Startup\huhtng.exe

    And here is how you need to do it.

    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Delete on Reboot.

    Now you are going to repeat the below steps for every file. Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINDOWS\SYSTEM32\cycopu.dll

    1) Now, Copy and Paste fullpathfile into the box
    2) Check the option to Delete on Reboot is selected
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click NO.
    5) Repeat for all files

    DO NOT Allow your machine to Reboot until the last item has been entered (Please tell me if you get any error messages especially one about Pending Operations being canceled).

    When the last item has been entered and you are prompted to reboot, allow Pocket KillBox to Reboot your computer.

    Reboot in normal mode. Tell me if you get any error messages on reboot and tell me the exact messages. (I expect there will be some related to some of the filenames above).

    Now before reconnecting you internet connection and before opening a browser do the below:
    - get another find.bat log and get a new HijackThis log (call these before.txt and hjtbefore.txt)

    Now reconnect your interent connection and open a browser. Then exit the browser and repeat:
    - get another find.bat log and get a new HijackThis log (call these after.txt and hjtafter.txt)

    Now come back here and post the results of all the steps, any error messages, and the four logs. It will take two messages because you can only attach 2 files per message.

    IMPORTANT: DO NOT REBOOT AFTER POSTING. This could cause the problem to mutate possibly making the logs not valid.
     
  10. Djay

    Djay Private E-2

    Thanks, I have an appointment tonight, but am off tomorrow so will do tomorrow morning. I have already printed and am ready to unplug in the morn. I will not reboot after the two postings.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Talk with ya tomorrow!
     
  12. Djay

    Djay Private E-2

    All went well. No messages. While in Killbox, I was able to find all the files through its browse feature, whereas last time most were not there - I had to paste in. That was good. Here are the two before. Once again thanks for taking the time.
     

    Attached Files:

  13. Djay

    Djay Private E-2

    Here are the two after logs.
     

    Attached Files:

  14. Djay

    Djay Private E-2

    One more thing, I ran a file search and the following .exe files are still there. If you note the date and time, 12/31, 4:46 p.m., this is the exact time I was infected. I double checked to ensure these files were actually created (instead of modified) at that time. My sister suggested I send to you just in case. I ran the search after this last clean out process. If it is nothing, just let me know. Thanks, Djay.
     

    Attached Files:

  15. Djay

    Djay Private E-2

    Sorry, I meant 6:46 p.m.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete all files in your C:\windows\prefetch folder and then empty your Recycle Bin.


    How is everything working? Your logs look clean now.
     
    Last edited: Jan 20, 2005
  17. Djay

    Djay Private E-2

    I think we did it! clkoptimizer is gone and so far so good. Things are running fine, although it takes me five refreshes to pull up the MajorGeeks site. I cleared out the prefetch and the recycle bin. My only question is what about that secure.exe and the uninstall for the same? When I go to it, it says created on 12/31. The Norton index lists this name as a potential nasty - using the same name as a good file. What do you think? Once again, your help has been invaluable. My sister says you are very knowledgable and nice.
     
    Last edited: Jan 20, 2005
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying that when you enter www.majorgeeks.com in your address field and click go, it does not come up unless you click refresh multiple times? Is this always true? Does it happen for other addresses. Have you tried entering this instead: 67.19.72.100

    Those two other files can more than like be deleted. They are not part of the default windows system files. You could take a different approach to be safe. Either rename them and leave them were they are. Or move them to a temporay holding folder before deciding whether you need them or not.

    Try this using Windows Explorer right click on the files and select Rename.
    Rename------secure.exe to secure.xxx
    and-------------uninstaller.xxx to uninstaller.xxx

    Thank your sister for the complement.
     
  19. Djay

    Djay Private E-2

    Thanks, I did rename those two files. The internet site issue is mainly when I go to MajorGeeks home page. It happens about 3 out of 4 times. Part of it loads, but only the top part. I first get the message that "Avenue A" wants in and when I click no to stop it, the page stays green. I only have the Avenue A prompt on the home page. Today it did not happen, because I went to the support forum first. I will try putting in the IP address and see what happens.

    It has really been enlightening working through this whole process. Hopefully, I won't have to do this again (for a while anyway). I did install Zone Alarm too. Peace brother and thanks for all the help!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Djay! Happy to help! Check going to www.majorgeeks.com now. It may be that you were experiencing so problems we were having. Let me know if you still have problems loading our home page.
     
  21. Djay

    Djay Private E-2

    This is the first time in a week I could get to the Major Geeks site. Spybot kept sending the warning messages, so I changed it to block all pages silently and so far, so good. My only residual problem is when I send an e-mail with an attachment, the attachment shows up as unreadable at the other end. Other than that, everything is running great.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Glad to here things are running better.

    As far as email attachments being corrupted, I don't believe that is a malware issue. You may want to check in the Software Forum for help on that one. Have you tried sending a compressed ZIP file to someone to see if it arrives okay? ZIP files have CRCs that verify their integrity.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds