completed read and run me and simplified removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by kris pyro, Dec 14, 2005.

  1. kris pyro

    kris pyro Private E-2

    trying to remove search assit. and other virus and malware, trojans,spyware. been working on the problem as per instructions since yesterday, with a little sleep. Iam posting hjt as per instructions becouse still having problems with highjacking, redirecting, trojans still showing up on virus scans.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have a load of problems that need to be fixed not just an HSA problem. Give me a few minutes.

    Did you run both HSremove and About:Buster?

    Do you have the log from About:Buster?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you look at and perform the 0: Preliminary House Cleaning step?
    I see this in your log and it is one of the items we have on the remove list:

    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.EXE 1
     
  4. kris pyro

    kris pyro Private E-2

    yes i ran everything, and no i have no log for about buster but have other logs from other tools. and by the way hello, i havent had to talk to you in a while.
     
  5. kris pyro

    kris pyro Private E-2

    yes, i guess i missed it in the add remove programs.
     
  6. kris pyro

    kris pyro Private E-2

    also i was having a hard time staying on line becouse of the trojans and virus's
     
  7. kris pyro

    kris pyro Private E-2

    these are the saved log files i have. Shall i post for you?
    AB logfile,kasper,bitdef,virus scan,active scan.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First uninstall Weatherbug!

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the xfire_lsp_9425.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move xfire_lsp_9425.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    Let's try the procedure below.

    Start by downloading the following tool: Pocket KillBox

    Extract Pocket Killbox to its own folder but do not run it yet. We will need it later.

    Now run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINNT\system32\crkc.exe
    C:\WINNT\apiqj32.exe

    Now just under the white window in HJT click the Back button (the one just to the right of the Run.. button). Now just leave HJT runnning.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Remote Procedure Call (RPC) Helper (or if you cannot find that name, try the short name: 11Fßä#·ºÄÖ`I ) ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Repeat the above services.msc step for hpdj7700

    Now return to your HijackThis window and select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Remote Procedure Call (RPC) Helper

    If that does not work, copy and paste in the short name: 11Fßä#·ºÄÖ`I

    You have to copy and paste because these characters are not easily entered. Also important NOTE. There is a space in front of the 11F so add the space too or HJT will not find the service.

    Now repeat the Delete NT Service using HJT for: hpdj7700

    After doing that exit HijackThis but do not reboot if it asks you to do so. We will be restarting HJT to run some additional steps.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis again and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes. (They may or may not be there again. We are double checking.)
    C:\WINNT\system32\crkc.exe
    C:\WINNT\apiqj32.exe


    After killing all the above processes, click "Back" (the button all the way to the lower right).
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\oowhv.dll/sp.html#77035
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\oowhv.dll/sp.html#77035
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\oowhv.dll/sp.html#77035
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\oowhv.dll/sp.html#77035
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\oowhv.dll/sp.html#77035
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\oowhv.dll/sp.html#77035
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\oowhv.dll/sp.html#77035
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {31798A3D-D307-BBEF-8A67-2FB34EABA8BC} - C:\WINNT\system32\msxh32.dll
    O4 - HKLM\..\Run: [alij] C:\WINNT\system32\run228.exe dummy
    O4 - HKLM\..\Run: [160.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\160.tmp.exe
    O4 - HKLM\..\Run: [161.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\161.tmp.exe
    O4 - HKLM\..\Run: [sdkza32.exe] C:\WINNT\sdkza32.exe
    O4 - HKLM\..\Run: [160.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\160.tmp.exe
    O4 - HKLM\..\Run: [161.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\161.tmp.exe
    O4 - HKLM\..\Run: [syspr32.exe] C:\WINNT\syspr32.exe
    O4 - HKLM\..\Run: [crkc.exe] C:\WINNT\system32\crkc.exe
    O4 - HKLM\..\Run: [uvjb] C:\WINNT\dxzj.exe
    O4 - HKLM\..\Run: [pnaot] C:\WINNT\swpiiad.exe
    O4 - HKLM\..\Run: [fnptsiii] C:\WINNT\bypslggyd.exe
    O4 - HKLM\..\Run: [ezbmhyrj] C:\WINNT\dfdk.exe
    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.EXE 1
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O10 - Broken Internet access because of LSP provider 'xfire_lsp_9425.dll' missing
    O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\apiqj32.exe
    O23 - Service: hpdj7700 - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\hpdj7700.exe (file missing)



    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now run Pocket Killbox.

    Now, Copy and Paste C:\WINNT\syspr32.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\crkc.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\dxzj.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\swpiiad.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\bypslggyd.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\dfdk.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\system32\run228.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\system32\msxh32.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and also check the box to Unregister DLL before deleting (if it is active) and Click the RedX and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\apiqj32.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    If you get an error message about Pending Operations, just reboot your PC yourself but either way please boot into safe mode. And while in safe mode do nothing but the below:

    - Run Windows Explorer and double check for the below files and delete if found (some of these are double checks to make sure they are gone):
    C:\WINNT\system32\msxh32.dll
    C:\WINNT\system32\run228.exe
    C:\WINNT\sdkza32.exe
    C:\WINNT\syspr32.exe
    C:\WINNT\system32\crkc.exe
    C:\WINNT\dxzj.exe
    C:\WINNT\swpiiad.exe
    C:\WINNT\bypslggyd.exe
    C:\WINNT\dfdk.exe
    C:\WINNT\apiqj32.exe
    C:\Program Files\AWS <--- the AWS whole folder
    C:\Documents and Settings\Owner\Local Settings\Temp <--- delete all files in this folder that it allows you to delete (make sure you do delet 160.tmp.exe, 161.tmp.exe, and hpdj7700.exe )


    Now reboot (whether you find them or not) into normal mode.

    Now get a new HJT log and attach it here. And tell us how these steps went and how things are working.
     
  9. kris pyro

    kris pyro Private E-2

    yes i found the log for about buster (AB log)
     

    Attached Files:

  10. kris pyro

    kris pyro Private E-2

    i cant find weather bug in add remove programs
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not right now! Just try to work thru my procedure. Read thru it first before starting to make sure you understand it. Ask questions first.
     
  12. kris pyro

    kris pyro Private E-2

    during hjt trying to kill c:\winnt\apiqj32.exe i got error message,"could not kill, may have allready closed or protected by windows or may be a service applet in admin. tools." " to load this window, click start, run and enter 'services.msc' ".

    how shall i proceed? also how come i cant find weatherbug to remove?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue with my steps. It is a service and my next steps address stopping, disabling, and then deleting.
     
  14. kris pyro

    kris pyro Private E-2

    here is my new hjt log file.
    everything went well. in window explorer nothing was found about 160.tmp or 161 or hpdj7700.

    only thing that was found in the kill box was apiqj32.exe
    everything is working good so far, thank you chaslang i hope you have a Marry Christmas:)
     

    Attached Files:

  15. kris pyro

    kris pyro Private E-2

    antivir xp is still finding trojans "TR/Small.ga.7" about 9 of them. 11 alerts with 10 deletions and is still running
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Okay! But did you delete all file you could in that temp folder anyway?

    Looks clean! Now to help you stay clean make sure you follow the below:

    How to Protect yourself from malware!

    Merry Christmas! Enjoy the holidays malware free.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post a log of what it is finding and deleting or not deleting.
     
  18. kris pyro

    kris pyro Private E-2

    here is the log. i cant make head or tails if it says what its finding or deleting. i will keep looking.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing in that log that reports anything being scanned.
     
  20. kris pyro

    kris pyro Private E-2

    i am running another report
     
  21. kris pyro

    kris pyro Private E-2

    here is the new report. i think its finding problems in the archives, shall i delete these archives?
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually it did not find any malware. It just reported files that it could not open. That does not necessarily mean anything is wrong.

    But yes you can dump backups from SpyBot unless you think you will need them.
     
  23. kris pyro

    kris pyro Private E-2

    Chaslang so far so good i havent found anything upon running scans.:) how do you think i got infected? i keep my programs updated. my wife said she was surfing that day. maybe she opened something she shouldnt have or allowed something to download? could it be a web site she visited? :confused: is there something else i should be running to prevent this from happening again?

    by the way hows the weather in jersey, cold and snowy???
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure how you got infected but care must be taken before clicking on anything while surfing.

    Everything you need to do is covered in: How to Protect yourself from malware!

    Yes it is very cold! This morning it was 7 degrees F where I live. Not snowing today though.
     
  25. kris pyro

    kris pyro Private E-2

    I am back. I am getting detection when i run my scan it says "the file process.exe contains signatures of SPR/Processor .20 do you want to delete it" ? and I do, but it keeps happening. i can tell my system is not working right. it locks up easily and when i close my documents the desk top icons will all reset and flash. what your recommendation?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What scan?
    Where is the file located?
     
  27. kris pyro

    kris pyro Private E-2

    antivir xp, located system32 process.exe down at the bottom of scan log
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When and why did you run L2MeFix?

    That is what this particular process.exe file is from. It is not a problem. But no L2MeFix will not run because the file was deleted.

    If it were not from L2MeFix, you could have been in for some possible financial related problems (like banking info and passwords for accounts being stolen).
     
  29. kris pyro

    kris pyro Private E-2

    i dont remember running it . but i did download it because i had a scan that showed the vx2 infection.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It must have been extracted from the ZIP and it must have been run or the file would only have been in the L2MeFix folder. When the l2mefix.bat file is run it copies the process.exe file (and a few others) to the system32 folder for use during the scanning procedure. When the second phase is run (second.bat) they cleanup by deleting the files copied into the system32 folder but the one in the L2MeFix folder would still exist.
     
  31. kris pyro

    kris pyro Private E-2

    ok, shall i remove the program and all of its contents?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can keep the L2MeFix.zip file if desired but delete the below folder on your desktop

    C:\Documents and Settings\Owner\Desktop\virus tools\l2mfix


    In fact it would be better to even delete the ZIP unless you are planning on running it now. Because by the time you may need it again, a different version will probably exist and you will not need the old one. It is always better to download small tools like this when needed to make sure you have the proper version.
     
  33. kris pyro

    kris pyro Private E-2

    I added sygate firewall, and now iam trying to figure out what needs to connect. For example i just had windows explorer try to connect to Sa.windows.com. how do i know whats ok?
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sa.windows.com is 207.46.248.249 which is Microsoft (sort of strange for Microsoft to use that URL). Not a problem! But was it Windows Explorer or Internet Explorer trying to connect.
     
  35. kris pyro

    kris pyro Private E-2

    I am pretty sure it was windows explorer I wrote it down as it popped up.

    Also is "WINNT\system32\DRIVERS\ndisuio.sys" this a normal application that should be running, it keeps trying to access through the firewall?
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  37. kris pyro

    kris pyro Private E-2

    i am sure it was windows explorer. so what do you think?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem!
     
  39. kris pyro

    kris pyro Private E-2

    okay i have two more about the firewall, "application winnt\system32\ntoskrnl.exe " and "winnt\system32\sass.exe" should these be allowed? I looked at the link you sent me for the last question and could not find anything.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sygate typcially has problems when blocking or allowing ntoskrnl.exe (which is a valid Windows program). Try blocking it and tell it to always do the same. And see what happens.

    You must be very careful with filenames. This: winnt\system32\sass.exe is not valid but winnt\system32\lsass.exe is valid. Which did you mean?

    I'm really surprised that Sygate does not do many of these settings automatically like ZoneAlarm does.
     
  41. kris pyro

    kris pyro Private E-2

    lsass.exe was correct. why would i block ntoskrnl.exe if its a valid windows program?
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just because programs are valid does not necessary mean you have to grant them internet access and also some time you may give them acces but you do not want them to act as a server. ntoskrnl.exe is a critical process in the boot-up cycle of your computer but should not need internet access.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  44. kris pyro

    kris pyro Private E-2

    okay thanks for all of your help, and maybe i wont have anymore problems for a while. and by the way we have a snow advisory... stay warm, and dry.
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What the heck are you doing getting snow way down there? Aren't you about as far south as El Paso? What's the altitude there?
     
  46. kris pyro

    kris pyro Private E-2

    haha the altitude is about 3000 or so.... where in the high plains.
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah! No wonder.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds