Help! No idea whats wrong

Discussion in 'Malware Help (A Specialist Will Reply)' started by Quinndrew5, Dec 1, 2004.

  1. Quinndrew5

    Quinndrew5 Corporal

    error loading filemon: access denied

    Make sure that your account has load driver and debug privileages and that FILEMON is not already running
     
  2. Quinndrew5

    Quinndrew5 Corporal

    tried to rename it as you said with no such luck
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Darn! Okay but you said you got ProcessExplorer running. Do the following:

    Run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    Now click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can kill things that Task Manager cannot.
     
  4. Quinndrew5

    Quinndrew5 Corporal

    Here it is
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I see a process named vayvay.exe running. The full path is C:\WINNT\system32\vayvay.exe

    Use Process Explorer to kill it and then see if you can run Filemon. Also keep ProcessExplorer open to see if the process restarts. It may even restart using a different name.

    Also there is a DLL I would like to get more info on: muvfw32.dll
    I assume it is c:\windows\system32\muvfw32.dll
    See if you can locate it with Windows Explorer and right click on it. Select Properties and then the version tab and go thru the Item name list looking for company, version etc.
     
  6. Quinndrew5

    Quinndrew5 Corporal

    completed the process explorer task, and i located the dll file but i only have a general and security tabs for that file, other things located in my system32 have the version tab but not this one
     
  7. Quinndrew5

    Quinndrew5 Corporal

    also i was not able to open filemon
     
  8. Quinndrew5

    Quinndrew5 Corporal

    vayvay.exe has returened a few times and i kept deleted it but it keeps comiing back
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try this:

    - Disconnect physically (unplug cables) from the internet.
    - reboot in safe mode.
    - do not run anything but ProcessExplorer and Windows Explorer (not internet explorer)
    - Kill the vayvay.exe process using ProcessExplorer
    - Use Windows Explorer to delete C:\WINNT\system32\vayvay.exe

    Reboot normal and tell me the results of this and also indicate if it came back.
     
  10. Quinndrew5

    Quinndrew5 Corporal

    The vayvay.exe was not present in the Process explorer which leads me to believe that it is probabley associated with the problem because the internet was off. But i was able to delete it manually, but now i have paypay.exe in its play, plus dr. watson
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay first check with ProcessExplorer to see what the name of this damn process is now. I will assume it is still paypay.exe. This time do the following:

    - Disconnect physically (unplug cables) from the internet.
    - reboot in safe mode.
    - do not run anything but ProcessExplorer and Windows Explorer (not internet explorer)
    - Kill the paypay.exe process using ProcessExplorer (if still running)
    - Use Windows Explorer to delete C:\WINNT\system32\paypay.exe
    - Use Windows Explorer to locate c:\windows\system32\muvfw32.dll (I'm assuming it is in system32). Now right click on the muvfw32.dll file and select rename. Rename it to muvfw32dll.bad

    Reboot normal and tell me the results of this and also indicate if it came back. I have a feeling it only comes back after running IE.
     
  12. Quinndrew5

    Quinndrew5 Corporal

    did as you said, but it came back after i rebooted
    Also i dont no if these means anything, but if i run chwshredder as soon as i reboot, and then delelte the 01 files in hijack this, it goes away for a while only to return, but everything seems to get better for that little while
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.

    Now run HJT and fix the O1 - Hosts lines and the O15 - Trusted Zone: http://*.frame.crazywinnings.com line if still there. Then reboot your computer and get a new HJT log to post here.
     
  14. Quinndrew5

    Quinndrew5 Corporal

    heres my log
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it isn't! :) Did that merge help?
     
  16. Quinndrew5

    Quinndrew5 Corporal

    oopps forgot to attach it
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So that merge fixed the O15 - Trusted Zone problem. At least we have that issue resolved. The O1 - Hosts problem is spreading like a plague and we have no fix yet.
     
  18. Quinndrew5

    Quinndrew5 Corporal

    yep, let me know if you need me to give anything at try
     
  19. Quinndrew5

    Quinndrew5 Corporal

    ok update, things are dramatically worsening, i am see sursidekick in my hijack this log i and i cant remember how i previously deleted it. Now the computer just randomly shuts down and now when i search at yahoo.com i get a bunch of bogas search results (it still looks like the yahoo search page except the results are far from right)
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  21. Quinndrew5

    Quinndrew5 Corporal

    Havent had the time to run through those steps quite yet, but when i downloaded the new CWShreder, but everytime i run it, it finds two things and then says that it has performed an error and that the program needs to be restarted. it happens over and over again.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you give more detail on what it is finding and the error? And you do mean you have version 2.12, right?
     
  23. Quinndrew5

    Quinndrew5 Corporal

    yea, i have the new one listed on the majorgeeks main page, the previous version worked fine but this one everytime i run it lists the first CWS file and says i do not have it and the lists the second one and then crashes. The Program Erorr says "CWSINSTAL.exe has generated errors and will be closed by Windows. You will need to restart the program. An error log is being created." And then i restart it over and over and nothing changes.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are all your browser windows closed before you run it?

    Did you download the new file or did you use update?
     
  25. Quinndrew5

    Quinndrew5 Corporal

    I tried it with all browsers closed and that didnt help and im not sure what u mean about update or download but i just clicked on the link at majorgeeks.com
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you downloaded it. Try running it in safe mode.
     
  27. Quinndrew5

    Quinndrew5 Corporal

    I was just looking at some of the new posts in the forum and i saw philliephan jump into a post saying that he had fix for the problem regarding the hosts... whether or not that person tried it or not im not sure(they said they were gonna erase their hardrive).... im not quite sure how to ask philliephan for the information without making a new thread... so i posted again in hopes of getting myself to the top of the list and getting chaslangs attention. Hopefully u can help me get in touch with PhilliePhan. Thanks!
     
  28. PhilliePhan

    PhilliePhan Guest

    No Fear! PhilliePhan sees ALL!!! ;)

    Bear in mind that this is a "Do at your own risk" proposition. If you want to try it, just let me know. If so, download the following and have them handy:

    Generic Detection Tool

    Pocket KillBox

    PP :)
     
  29. Quinndrew5

    Quinndrew5 Corporal

    im willing to take a risk or two
     
  30. PhilliePhan

    PhilliePhan Guest

    AllRightyThen!

    Please run a scan with HJT v1.99 and attach that log.

    Then, unzip the Generic Detection Tool to a safe folder of your choice and run "findit.bat" - Allow it as much time as it needs to run. You may get an error message of "File Not Found," but just let it go.

    The tool should generate a long text file. Please attach that along with the HJT log.

    I will try to check back tonight or tomorrow as time permits.

    PP :)
     
  31. Quinndrew5

    Quinndrew5 Corporal

    Alright, here are the logs....
     

    Attached Files:

  32. PhilliePhan

    PhilliePhan Guest

    The findit.bat log is incomplete. I don't know if this is due to your machine being Windows 2000 or something else.

    Please try running it one more time. Doublecheck when you save and attach it that you include everything.

    PP :)
     
  33. Quinndrew5

    Quinndrew5 Corporal

    I dont no if it changed but here it is.
     

    Attached Files:

  34. PhilliePhan

    PhilliePhan Guest

    For some reason, it is not completing - Maybe there is nothing for it to find. I don't want to start deleting that list of DLLs willy-nilly without proper confirmation!

    However, you should print this out and do the following:

    1) Disconnect from the internet

    2) Click START > RUN > type services.msc and ENTER.
    Then, locate Security Agent service and RightClick it. Now choose STOP. Then, DoubleClick it and choose Disable and then OK.

    3) Now, Reboot and run HJT v1.99 and Check the boxes for the Following:

    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch

    O4 - HKLM\..\Run: [kalvsys] C:\winnt\system32\kalvtnf32.exe

    O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINNT\httpfilter.dll

    O23 - Service: Security Agent - Unknown - C:\WINNT\system32\scagent.exe


    Make sure All Browser Windows are Closed when you Click FIX.

    4) Now, Copy and Paste the following into Pocket KillBox and have it Delete them on reboot:

    C:\WINNT\system32\scagent.exe

    C:\winnt\system32\kalvtnf32.exe

    C:\WINNT\System32\tibs3.exe

    C:\WINNT\httpfilter.dll


    After the last entry has been pasted, allow computer to Reboot. Then, reconnect to the internet and attach a fresh HijackThis Log and we'll see if it did any good. I'll try to check back tonight.

    PP :)
     
  35. Quinndrew5

    Quinndrew5 Corporal

    quick queston... does browser windows mean just IE windows or does that include my computer ect.
     
  36. PhilliePhan

    PhilliePhan Guest

    It means EVERYTHING. The only thing running should be HijackThis.

    PP :)
     
  37. Quinndrew5

    Quinndrew5 Corporal

    Ok... tried to perform the task..... but that ended farely quickly... when i went to stop the security agent services it started to stop it but it then gave me an error message saying it could not stop it
     
  38. PhilliePhan

    PhilliePhan Guest

    Okay, then. Try to run through the instructions as best you can - Fix what you can with HJT and try to Delete all of those files on reboot with killBox. This will clean up some of the additional items.

    EDIT PP: Erroneous info removed.

    PP :)
     
    Last edited by a moderator: Dec 30, 2004
  39. Quinndrew5

    Quinndrew5 Corporal

    Still strugelling with my problem.... just figured i throw something out there.... this line in the hijack this log of running processes.

    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\svchost.exe

    I later did some searches using the 01 lines at google.com and found people with the same problem at other sites.... they seemed to have those running processes as well.
     
  40. PhilliePhan

    PhilliePhan Guest

    svchost is legitimate. You should have 3-5 running at a given time, sometimes more. The only time you should be concerned is when the spelling is different or they are running from a place other that the System32 folder.

    Yous should try to do as many steps from post# 84 as possible and then attach a fresh HJT Log. Also, try running a Fresh Findit.bat plus a Fresh DLL Compare and attach them. I am rarely here much these days, but will try to check back when I can.

    PP :)
     
    Last edited by a moderator: Dec 30, 2004
  41. Quinndrew5

    Quinndrew5 Corporal

    alrighty.... just figured id ask.... i just saw the word host in there and thought it might be something to be concerned about.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PP,

    Quinndrew5 is running Windows 2000. It is more like XP than it is like Win9x. I don't believe the above tools are meant for an NT based (Win NT, Win2K, WinXP) system.
     
  43. PhilliePhan

    PhilliePhan Guest

    Where did I get the idea he was running Windows 98?? Earlier I recognized Win 2000 . . . Man, I must be losin' it!

    You're right, the usual set of tools are designed for 2K and XP.

    We could probably knock this out with a fresh Findit.bat and DLL Compare!

    PP :)
     
    Last edited by a moderator: Dec 30, 2004
  44. Quinndrew5

    Quinndrew5 Corporal

    I saved the log for you of findit.dat and posted it... but im not quite sure what the DLL Compare thing you are talking about is
     

    Attached Files:

  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  46. Quinndrew5

    Quinndrew5 Corporal

    I know have all four.... thanks for getting me a step ahead while you had the chance.... philliephan has commented that he hasnt been around the forum lately, so anything i can get inbetween his posts is great!
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well let me see if I can get your started. Here are the files that we need to delete using Killbox. They are all in the c:\winnt\system32 folder:

    Directory of C:\WINNT\System32
    12/30/2004 10:15a 222,564 houi.dll
    12/30/2004 10:15a 222,631 jt6007jme.dll
    12/30/2004 12:18a 226,151 aza00chmef4a0.dll
    12/29/2004 10:51p 222,564 azao0793e.dll
    12/29/2004 10:40p 223,034 n2n6lc5s1f.dll
    12/29/2004 10:31p 226,151 tOpi3.dll
    12/29/2004 10:31p 223,183 aza6le3s1h.dll
    12/29/2004 03:54p 226,151 hr8405lqe.dll
    12/29/2004 03:13p 226,151 l2n40c5qef.dll
    12/28/2004 10:38p 226,151 mvlol9331.dll
    12/28/2004 09:17p 222,674 fplu0339e.dll
    12/28/2004 09:00p 222,860 f40oled31h0.dll
    12/28/2004 07:48p 222,546 p6p60g7se6.dll
    12/28/2004 04:48p 226,151 mvv1_0.dll
    12/24/2004 11:04p 225,744 mv2ml9f11.dll
    12/23/2004 07:30p 224,715 azamli1118.dll
    12/23/2004 05:13p 224,724 lv0009dme.dll
    12/23/2004 12:08p 224,715 wlwfaxui.dll
    12/23/2004 12:08p 225,158 fp4403hqe.dll
    12/23/2004 11:31a 226,102 kt8ol7l31.dll
    12/23/2004 11:00a 224,715 mhpmsnsv.dll
    12/23/2004 11:00a 224,825 e0jm0a11ed.dll
    12/23/2004 10:50a 224,715 rXsrad.dll
    12/23/2004 10:50a 224,747 f2l00c3mef.dll
    12/23/2004 09:43a 223,133 p0n8la5u1d.dll
    12/21/2004 12:10p 223,183 q0nula591d.dll
    12/21/2004 11:58a 224,732 jtj0071me.dll
    12/21/2004 11:35a 225,388 fpp6037se.dll
    12/20/2004 02:32p 225,463 n84s0ih7e84.dll
    12/19/2004 07:30p 226,179 m464lejq1hoe.dll
    12/19/2004 04:33p 223,000 jt4207hoe.dll
    12/19/2004 12:51p 223,000 dvskperf.dll
    12/19/2004 12:51p 223,923 fp2u03f9e.dll
    12/19/2004 12:31p 224,865 ir68l5ju1.dll
    12/19/2004 12:00p 223,132 g2lm0c31ef.dll
    12/19/2004 12:15a 225,896 mv2sl9f71.dll
    12/17/2004 11:29p 225,639 e8jmli1118.dll
    12/17/2004 02:52p 223,087 mvnsl9571.dll
    12/16/2004 10:00p 224,601 mvrol9931.dll
    12/16/2004 07:24p 223,150 ir88l5lu1.dll
    12/16/2004 07:12p 224,989 n88o0il3e8q.dll
    12/16/2004 03:44p 226,301 azaolel31hq.dll
    12/15/2004 10:19p 224,374 fpjq0315e.dll
    12/15/2004 02:26p 224,374 drconfig.dll
    12/13/2004 07:31p 224,079 g440lehm1h4a.dll
    12/12/2004 10:09p 225,740 j46mlej11ho.dll
    12/12/2004 02:58p 223,153 t0r8la9u1d.dll
    12/12/2004 12:38p 222,759 gp0ml3d11.dll
    12/12/2004 12:08p 222,749 gp80l3lm1.dll
    12/12/2004 12:03a 225,740 jtro0793e.dll
    12/11/2004 01:17p 225,740 i406leds1h06.dll
    12/10/2004 11:53p 225,740 fpj4031qe.dll
    12/10/2004 02:27p 225,740 n48olel31hq.dll
    12/09/2004 10:09p 224,086 jt6207joe.dll
    12/09/2004 05:16p 225,941 irn8l55u1.dll
    12/09/2004 05:06p 225,655 mv6ql9j51.dll
    12/08/2004 03:03p 225,733 kt46l7hs1.dll
    12/08/2004 02:20p 224,086 syc.dll
    12/07/2004 10:04p 222,737 l4l6le3s1h.dll
    12/07/2004 08:38p 222,874 jtlm0731e.dll
    12/07/2004 08:20p 223,137 g0040adqed0e0.dll
    12/07/2004 08:07p 222,737 mfisip.dll
    12/07/2004 08:07p 222,979 i2420choef4c0.dll
    12/07/2004 08:00p 223,893 i6nmlg5116.dll
    12/07/2004 05:40p 222,737 muvfw32dl.bad
    12/06/2004 10:13p 225,885 m2820cloefqc0.dll
    12/04/2004 12:24p 222,916 ktj4l71q1.dll
    12/04/2004 11:53a 224,220 mtvideo.dll
    12/03/2004 03:06p 224,327 jt0m07d1e.dll
    12/03/2004 02:43p 224,999 kt6sl7j71.dll
    12/02/2004 08:42p 223,232 skfilshr.dll
    12/02/2004 08:42p 223,274 g2400chmef4a0.dll
    12/02/2004 08:32p 223,232 n64s0gh7e64.dll
    12/01/2004 07:22p 223,232 wmhirda.dll
    12/01/2004 06:25p 223,232 mhconf.dll
    11/22/2004 06:58p 512 NuzK63G.h8p
    11/21/2004 08:00p 254,038 TqzU35W3.exe
    11/21/2004 08:00p 254,038 AthffaH.exe
    11/21/2004 07:59p 499,798 QjlrXhe2.exe
    11/21/2004 07:59p 499,798 MtyJ63F.exe
    11/21/2004 07:59p 499,798 Npw5p.exe
    09/12/2004 04:53a 10,993 ipqu32.exe

    and c:\winnt\system32\guard.tmp

    And here is how you need to do it.

    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Replace on Reboot.

    Now you are going to repeat the below steps for every file except C:\WINNT\System32\guard.tmp (we will add it separately at the end). Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINNT\System32\houi.dll


    1) Now, Copy and Paste fullpathfile into the box
    2) Check the option to Use Dummy.
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click NO.
    5) Repeat for all files except the last one

    For the last file, we will be rebooting when prompted. Here is the final step of the file deletions:

    Now, Copy and Paste C:\WINNT\System32\guard.tmp into the box. Check the option to Use Dummy and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to reboot Normally.

    After it reboots get another findit.bat log and post it. Also run DLL Compare – Click Run Locate.com then click the Compare button. Follow the prompts and allow time for it to complete and make a log. Please attach that Log.
     
    Last edited: Dec 31, 2004
  48. Quinndrew5

    Quinndrew5 Corporal

    Before i do all these different files... it tried the first.... i clicked yes and then no as you said.... but i got a message saying that it could not be deleted.
     
  49. Quinndrew5

    Quinndrew5 Corporal

    my fault... i was jsut in need of an updating of killbox.... im set now.
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Were you able to delete all those files?

    Did you reboot? Where's are the logs?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds