followed advice in "read this first"

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chloe2198, Oct 4, 2004.

  1. chloe2198

    chloe2198 Private E-2

    Hi,
    I started out by having this huge problem where I could not even access IE anymore without it telling me that it could not connect to server. It had nothing to do with a connection problem, rather I had some trojans on comp which downloaded things like elitebar, searchmiracle, about:blank, etc. I was not even able to register on this website because I was constantly redirected to a not-able-to-connect-to-server page. I don't know what happened but all of a sudden I could register, so here I am.
    So I read the "read this before you post". Initially, I was only able to do steps 1 through 3 because I wasn't able to download any of the virus scanners in step 4 (for same reason as couldn't register). In step 2 I found none of the exact services listed... I did find RPC on its own, and RPC locator but deleted neither as you specifically said to delete only exact matches (RPC helper). I also followed step 3 and did all as specified. As I was unable to download anything I used the virus scanners I already had, which did included ad-aware and spybot as well as Norton and AVG. THe last two found nothing, spybot found the usual (elitebar and other pests) and ad-aware found over 400 bugs once the hidden files were unhidden. When I rebooted I was finally able to download the other programs listed in step 4 and followed the instructions. I rebooted in safe-mode with networking support, however for some reason I was unable to access the internet as my connection program said it failed to load a driver... So I could not scan with trend micro or symantec in safe mode. I was able to scan with all the other programs. Everything came back clean. I rebooted back to normal, scanned with trendmicro and symantec, found nothing. Then I read the hijackthis tutorial on this web-site. I followed the instructions but there were many things in section 04 that I could not find using the search on sysinfo and look fishy.... So to conclude this long post (my apologies), may I post the hijackthis log so someone can tell me if there are other things in 04 I should delete? Searchmiracle and elitebar seem to be officially killed. The only thing I dont understand is how come all the websites i go to with javascript tell me my java is disabled when it clearly isn't according to the settings in internet tools. So then I need help with two things, 1-the 04 items in hijackthis, and 2-how to enable java again, or to get it to stop telling me its disabled. Thanks very much... eagerly waiting for a response. And by the way those spyware tutorials (including hijackthis) were very very helpful. Nancy in Montreal.
     
  2. Kodo

    Kodo SNATCHSQUATCH

    attach your log to a post please.
     
  3. chloe2198

    chloe2198 Private E-2

    Here it is: thanks Kodo.

    [Log file removed]
     
  4. Kodo

    Kodo SNATCHSQUATCH

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, but exit all the Internet Explorer sessions first.
     
  6. chloe2198

    chloe2198 Private E-2

    how do i attach?
     
    Last edited: Oct 4, 2004
  7. Kodo

    Kodo SNATCHSQUATCH

    Try it again with all your browser windows closed..

    don't run it from your desktop either.. put the exe into its' own folder like C:\HJT\Hijackthis.exe


    to attach, scroll down where it says MANAGE ATTACHMENTS
     
  8. chloe2198

    chloe2198 Private E-2

    here it is
     

    Attached Files:

  9. chloe2198

    chloe2198 Private E-2

    I thought the trojans were gone. For the last few hours everything was working fine but now they've popped up again. Both AVG and Norton tell me I have a trojan in C:/for.exe. Was i supposed to hide those files again from step 3 in read-this-before-u-post.... Should I try booting in safemode and scan again? Argh. Am I correct in thinking the trojans were related to me getting all those elitbar-searchmiracle things on my comp to begin with?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Chloe,

    Please read and follow directions:
    You still have 4 browsers sessions running and you have HijackThis running from your Desktop. All of which we specifically requested you not to do several times.
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Nancy\Desktop\downloads\HijackThis.exe
     
  11. Kodo

    Kodo SNATCHSQUATCH

  12. chloe2198

    chloe2198 Private E-2

    I had closed all the IE windows, I have no clue why it said I had 4 open. I misunderstood about the folder. HJT isnt on the desktop, it was in a different folders with all the other stuff asked to download in the read-this-before-you-post. I created a separate HJT folder in C:.. .hope it works this time.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the A-squared program that Kodo gave you. And then run the two online scans again. If you cannot run them in safe mode, run them both in normal boot. Also run these scans:

    http://tools.zerosrealm.com/PeperFix.exe
    http://www.memorywatcher.com/uninst.exe

    Then post a new HJT log as an attachment. The lines I see in your log that are of concern are (I added comments next to these and hopefully some get fixed by these scans):
    C:\WINDOWS\system32\msnmsgrr.exe see http://es.trendmicro-europe.com/consumer/security_info/ve_detail.php?Vname=WORM_RBOT.PZ
    C:\WINDOWS\system32\servicelog.exe <---- unknown
    C:\WINDOWS\System32\clbcatex.exe <---- unknown - maybe peper trojan
    C:\WINDOWS\System32\audiosrv.exe <---- unknown - maybe peper trojan
    C:\Documents and Settings\Nancy\Application Data\iuwo.exe <--- unknown trojan
    C:\Program Files\Internet Explorer\iexplore.exe <--- if you are not running these, a trojan must be
    C:\Program Files\Internet Explorer\iexplore.exe <--- if you are not running these, a trojan must be
    C:\Program Files\Internet Explorer\iexplore.exe <--- if you are not running these, a trojan must be
    c:\uninstall.exe <---- unknown
    C:\Program Files\Internet Explorer\iexplore.exe <--- if you are not running these, a trojan must be

    O4 - HKLM\..\Run: [Windows XP Service Pack 2] sp2update.exe <--- trojan?
    O4 - HKLM\..\Run: [ati control panel] atiphexx.exe <---- http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.CC
    O4 - HKLM\..\Run: [USB Device] servicelog.exe <---- unknown
    O4 - HKLM\..\Run: [Ksyd] C:\documents and settings\nancy\local settings\temp\Ksyd.exe <---- unknown
    O4 - HKLM\..\Run: [qu8RB] C:\documents and settings\nancy\local settings\temp\qu8RB.exe <---- unknown
    O4 - HKLM\..\Run: [fd4767843c33] C:\WINDOWS\System32\clbcatex.exe <---- unknown - maybe peper trojan
    O4 - HKLM\..\Run: [e80c19c28c15] C:\WINDOWS\System32\audiosrv.exe <---- unknown - maybe peper trojan
    O4 - HKLM\..\RunServices: [Windows XP Service Pack 2] sp2update.exe <--- trojan
    O4 - HKLM\..\RunServices: [ati control panel] atiphexx.exe <--- WORM_SDBOT.CC
    O4 - HKLM\..\RunServices: [USB Device] servicelog.exe <---- unknown
    O4 - HKLM\..\RunOnce: [USB Device] servicelog.exe <---- unknown
    O4 - HKCU\..\Run: [USB Device] servicelog.exe <---- unknown
    O4 - HKCU\..\Run: [ati control panel] atiphexx.exe <--- WORM_SDBOT.CC
    O4 - HKCU\..\Run: [Tsal] C:\Documents and Settings\Nancy\Application Data\iuwo.exe <--- unknown trojan
    O4 - HKCU\..\Run: [Vjilur] C:\WINDOWS\System32\?ttrib.exe <---- unknown
    O4 - HKCU\..\RunOnce: [USB Device] servicelog.exe <---- unknown
     
  14. chloe2198

    chloe2198 Private E-2

    ok, i'm going to redo the read-this-before-you-post tutorial. You never told me if I should set back system restore and hidden files after I'm done. I can't do the symantec online scan because it says I have no java. I still don't know how to fix the java problem (like i said, doesn't appear to be disabled in internet tools). About the line you pointed out with microsoft updates, i recently reinstalled microsoft security pack 2... isn't that it? (i had to reinstall all after comp was emptied with sys restore). Anyway, I will be back later when this is all done. Thanks for all your help so far chas and kodo.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do not re-enable system restore until we are positive all problems have been resolved. You can always leave viewing of hidden files enabled it does not hurt anything. Did you try to install Sun Java as shown in the Read Me. No I do not believe the line with sp2update.exe on it is really for Win XP SP2. I think it is a trojan of some form.

    Finish the A-squared scan, the online scans, and the two peper trojan scans I gave you and then tell us what (if anything) these all found and post a new HijackThis log as an attachment.
     
  16. chloe2198

    chloe2198 Private E-2

    Ok, I did everything as indicated. The a-square program found 4 probs. I didn't know I had to write the stuff down so I only remember one sdbot.worm.gen.t... I remember it said it deleted stuff in the c:/for and c:/sys. The worm name doesnt match any of the other worm/trojan norton and AVG keep telling me about, but it does match the c:/for folder I norton/avg told me it was in. Odd thing, norton changed some things when I was in safe mode- neither email scan nor automatic update were working anymore. I've checked now and it seems to be fixed. Other thing, I can't run the AVG program anymore (technician guy told me this program was much better then Norton... dont know how true that is) because I'm apparantly missing the Core driver. It was working fine until now. I ran all the other programs in the read-this-before and everything came back clean, including ad-aware. I also used the two other programs, nothing to report there either. I still can't do a virus check on symantec because of the scripting prob. I dont have java virtual machine, I installed javasun myself some time ago as comp didnt come with java because of some issue with jvm manufacturer i think. Anyway, thats pretty much all I can say right now. I'm attaching the new HJT log. All IE windows were closed and I didn't run it from desktop so if it says otherwise its not me! Thanks again guys (or gals?). I'm gonna stay online a few more hours to see if anyone replies tonight, or else I'll be back in the morning.
     

    Attached Files:

  17. chloe2198

    chloe2198 Private E-2

    I noticed a maxspeed thing in my IE tools section. I don't recall that ever being there before and I notice that its in the HJT log... perhaps thats something that shouldn't be there?
     
  18. jarcher

    jarcher I can't handle a title

    @chase
    she's got norton and avg running would those clash?
     
  19. chloe2198

    chloe2198 Private E-2

    I did. Peperfix found nothing. In safe mode unists just opened up a grey window a few second then dissapeared. I ran it again and it sais it "memory watcher installing files", stayed on perhaps 5 seconds and dissapeared again.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of the programs I listed before are still there. We will have to do this manually.
    Make sure system restore is still disabled and viewing of hidden file is enabled.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them (if found):
    servicelog.exe
    clbcatex.exe
    audiosrv.exe
    iuwo.exe
    ?ttrib.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\SearchBar.htm
    O4 - HKLM\..\Run: [Windows XP Service Pack 2] sp2update.exe
    O4 - HKLM\..\Run: [ati control panel] atiphexx.exe
    O4 - HKLM\..\Run: [USB Device] servicelog.exe
    O4 - HKLM\..\Run: [Ksyd] C:\documents and settings\nancy\local settings\temp\Ksyd.exe
    O4 - HKLM\..\Run: [qu8RB] C:\documents and settings\nancy\local settings\temp\qu8RB.exe
    O4 - HKLM\..\Run: [fd4767843c33] C:\WINDOWS\System32\clbcatex.exe
    O4 - HKLM\..\Run: [e80c19c28c15] C:\WINDOWS\System32\audiosrv.exe
    O4 - HKLM\..\RunServices: [Windows XP Service Pack 2] sp2update.exe
    O4 - HKLM\..\RunServices: [ati control panel] atiphexx.exe
    O4 - HKLM\..\RunServices: [USB Device] servicelog.exe
    O4 - HKLM\..\RunOnce: [USB Device] servicelog.exe
    O4 - HKCU\..\Run: [USB Device] servicelog.exe
    O4 - HKCU\..\Run: [ati control panel] atiphexx.exe
    O4 - HKCU\..\Run: [Tsal] C:\Documents and Settings\Nancy\Application Data\iuwo.exe
    O4 - HKCU\..\Run: [Vjilur] C:\WINDOWS\System32\?ttrib.exe
    O4 - HKCU\..\RunOnce: [USB Device] servicelog.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

    Reboot in safe mode and use Windows Explorer to find and delete or rename as indicated (rename by right clicking on them and selecting Rename):
    C:\WINDOWS\system32\servicelog.exe ----> rename to servicelog.badexe
    C:\WINDOWS\System32\clbcatex.exe ----> rename to clbcatex.badexe
    C:\WINDOWS\System32\audiosrv.exe ----> rename to audiosrv.badexe
    c:\windows\system32\atiphexx.exe ----> rename to atiphexx.badexe
    C:\Documents and Settings\Nancy\Application Data\iuwo.exe <---- delete
    C:\documents and settings\nancy\local settings\temp\Ksyd.exe <---- delete
    C:\documents and settings\nancy\local settings\temp\qu8RB.exe <---- delete
    C:\WINDOWS\System32\?ttrib.exe <---- delete
    c:\windows\system32\sp2update.exe ----> rename to sp2update.badexe

    If atiphexx.exe and sp2update.exe are not found in system32, look in c:\windows, c:\windows\system, and C:\Documents and Settings\Nancy\Local Settings\temp.

    Now reboot in normal mode and post a new HJT log and tell us how all this went and how things are working.
     
  21. chloe2198

    chloe2198 Private E-2

    Im still trying to figure out this java thing so I downloaded it again from the website listed in read-this-first... still doesnt work. I checked in javasun control panel and it is indeed set to IE. In my internet tools, in browsing, both "disable script debugging (IE)" and "disable script debugging (other)" are checked. Scolling down javasun is checked as well (thus enabled...) and it says "javasun2 v.1.42_05 for <applet> (requires restart)". Is that normal?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! We'll get to that later. And it's Chas!
     
  23. chloe2198

    chloe2198 Private E-2

    Ok. Did exactly like you told me. Everything went fine until came time to delete/rename stuff.... I only found 3 of the names. So I was successful at renaming servicelog.exe, clbcatex.exe and audiosrv.exe. All the other files were nowhere to be found. So I did a search, here's what I found:

    1-?ttrib.exe does not exist, however the search returned "attrib.exe" and it was created on the 1st of october as all these other nasty things have (thats the day system restore happened, 110$ of hard-earned student money down the drain)

    2-sp2update.exe and atiphexx.exe do not exist

    3-qu8RB.exe, ksyd.exe and iuwo.exe exist but their name doesn't end at exe. For example, qu8RP.exe is called qu8RP.exe-ID303586.pf. The two other files are also "pf" files and all three are in windows/prefetch. I did not delete them yet, want to be sure its ok.

    As a sidenote, the computer no longer takes 5 minutes to load up all the icons on the desktop (I'm not exagerating for the time). That's very good. However, I just about uninstalled AVG as everytime i reboot it tells me i'm missing that core driver. So I click uninstall and it asks me if I want to take care of the "virus vault" first, I click yes. This window opens up with all these names of things I dare not disturb as I have no instructions on what to do with them. Interestingly, atiphexx is sitting right there.

    Lastly, I've attached my new HJT log.

    Chas, I'm sending you a big virtual kiss for all your help so far. For a lack of icon, I'll let you imagine it.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you do a Windows search you have to set it up to find hidden files and search all folders too. Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so for example enter sp2update.exe
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.

    Note: attrib.exe is a valid Windows command prompt program if it is in c:\windows\system32. You should do a search for *ttrib.exe which finds any filename ending in ttrib.exe.


    For the AVG stuff, let it uninstall and let it remove/delete the virus vault. If they were viruses and put into the vault, you do not want any of them anyway.

    The files ending in pf are in your c:\windows\Pretch folder they should be deleted to and you should empty your recycle bin when done.
     
  25. chloe2198

    chloe2198 Private E-2

    Ok, again did as instructed. There are no changes in the results, i still can't find ?ttrib.exe or sp2update.exe, even with hidden file option. I deleted the three files in prefetch. I've uninstalled AVG. I deleted the files in the virus vault but when I ran uninstall it still told me that virus vault was not empty, run yes/no. I clicked no and it uninstalled. I don't know where all the avg viruses went but they aren't in recycle bin. I've tried to uninstall norton because I want to put the new 2005 version... it won't budge. It tells me that uninst.isu is not valid or the data has been corrupted. I tried reinstalling my old version of norton (i got rid of system works but can't get rid of utilities) and it tells me I can't install because old files still on computer. So now I have neither norton nor avg. I was finally able to do a scan on symantec, it came back negative. I figured out my java script problem, i checked "allow active content to run in files on my computer" and now all is fine. Microsoft update sp2 is very very security conscious... I kept having this bar showing up on top of all websites saying it wouldnt allow active content from the website. Having clicked allow active content, that bar is now gone, I don't know if that's a bad or good thing. Lastly, I found a folder called "mui", i recall having to delete this folder some time back when I had trojan problems... does that ring a bell?
    thanks again and again.
     
  26. Kodo

    Kodo SNATCHSQUATCH

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. For your problems with uninstall/install of Norton, you may want to talk to Symantec or you could try posting your question for this in the software forum. EDIT: Kodo gave you a link to try.

    If it were me, I would just manually edit the registry to get rid of all the Norton & Symantec stuff but there could be a lot. Do not do that on your own and if you do decide to edit the registry you should first do a backup with a program like Erunt (see the registry directory on Majorgeeks). I see Kodo already mentioned the mui folder.
     
  28. chloe2198

    chloe2198 Private E-2

    Thanks for the link kodo. I will check it out after this message. As for mui, there is indeed a mui in srchasst but also in windows/syst32/oobe, programfiles/commonfiles/system, windows/syst32, programfiles/moviemaker, programfiles/internetexplorer, and in windows..... the mui folder in windows has nothing in it.
     
  29. chloe2198

    chloe2198 Private E-2

    Was finally able to uninstall norton. I installed the free version of norton 2005 which will last 15 days... is it really worth the 50$ investment or will all the other programs I've downloaded since my problem occured be enough? Should i be uninstalling any of them (there are so many!)? I know I've said thank you many times but I just wanted to tell you I really really appreciate all the help you've given me. Seriously, I was just about to go out to buy a new computer (and when I do, it WILL be a Mac). You guys are great, your website is very informative, even for those computer illiterate people like me. Your staying in my favorites. All the best! Mwaaa!
     
  30. Kodo

    Kodo SNATCHSQUATCH

  31. chloe2198

    chloe2198 Private E-2

    Ok, cool. Will do. Did u see what i wrote about mui?
     
  32. chloe2198

    chloe2198 Private E-2

    I take it i can put back system restore right?...
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After a few reboots and some opening and closing of Internet Explorer sessions, if you still look clean (no problems) then enable system restore.
     
  34. chloe2198

    chloe2198 Private E-2

    Me again.... I have this IE window that pops up in the toolbar at the bottom of the screen called media4.fastclick.... if i click on it nothing happens (no IE window opens up)... should i redo again the steps in read-this... looks like something fishy.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! These do happen! They are typically pop unders. I see them sometimes too. I just right click the and select close.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds