Hijack -- Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by arcueil_1, Aug 29, 2005.

  1. arcueil_1

    arcueil_1 Private E-2

    Hi. I'm new on the forums and I'm OK with computers but not great, so I hope you guys can help out with a hijack I've had for a the last few days. I'm on XP SP2. I have AntiVir (maxed out settings) with its Guard running at all times. I have Ad-Aware (with maxed out settings). I update everything regularly. I also have automatic updates on XP always turned on, as well as the MS Firewall.

    Symptoms:

    1) WinFix keeps popping up, wanting to install, then its site pops up.
    2) Another very similar thing to WinFix also wants to install, followed by its site popping up.
    3) A site named MatchService keeps popping up.
    4) Something called TrafficExplorer comes up, related to something called Forex Capital Markets (I think).
    5) Two instances of pop up hell (up to around 55 windows popping up!).

    I did the following steps, as per instructed on the post DO NOT POST UNTIL YOU HAVE READ THIS: How to: Spyware, Trojan And Virus Removal, by Major Attitude:

    1) Disabled System Restore.
    2) Enabled viewing of hidden files and folders and extensions (three steps).
    3) Turned off AntiVir Guard.
    4) Rebooted to Safe Mode with Networking Support.
    5) Logged in as Administrator.
    6) Scanned with AntiVir (positive: file TR/Dldr.ConHook.I to quarantine folder).
    7) Scanned with BitDefender (negative).
    8) Scanned with RavAntivirus (negative).
    9) Scanned with McAfee AVERT Stinger (negative).
    10) Cleaned up by: a) deleting cookies, b) clearing temporary files (on-line and off-line files), c) cleared internet history, d) ran CCleaner (I also fixed issues), e) ran MS Disc Clean on all partitions (4), f) defragmented all partitions, and g) flushed the prefetch.
    11) Scanned with Ad-Aware (positive: Alexa/Data Miner and two other objects that I forgot to write down went into quarantine).
    12) Scanned with Ad-Aware for ADS (negative).
    13) Ran the Ad-Aware VX2 Cleaner Plug-In (negative).
    14) Ran CWShredder (positive: VX2.Look2Me/removed CWS.Look2Me [the program told me to restart, but I did that after the next few more steps]).
    15) Ran Kill2Me.
    16) Ran Look2Me Uninstaller (negative).
    17) Immunized system with Spybot.
    18) Scanned for problems with Spybot (negative).
    19) Rebooted to normal mode.
    20) Enabled AntiVir Guard.
    21) Enabled System Restore.
    22) Disabled viewing of hidden files and folders and extensions (three steps).
    23) Rebooted to normal mode.
    24) Went on-line.

    After all this, I'm still experiencing some or all of the symptoms listed above. I think I may have to post a HJT log here. Please help. Thanx. :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do not re enable System Restore until your malware problems are completely fixed.

    There is no need to ever Disable viewing of hidden files etc at all. But if you want to, you again must not do it until all malware problems are resolved.

    So please disable system restore and enable viewing of hidden files again per the READ ME.

    Follow the below steps exactly as written:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).- Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. arcueil_1

    arcueil_1 Private E-2

    Hi. Here's my HJT log, via attachment.
     

    Attached Files:

  4. arcueil_1

    arcueil_1 Private E-2

    I forgot to metion that the XP that I use is the official MS Chinese language (PRC) version (Home Edition) that came with my Toshiba laptop. I don't know if that affects your HJT interpretation, but I thought that I should point that out. Cheers.
     
  5. arcueil_1

    arcueil_1 Private E-2

    BTW, I did the HJT scan on Safe Mode w/Networking. Is that OK?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! As per the HJT sticky thread, all HJT logs should be from normal boot mode unless specifically requested otherwise.

    Please post a new HJT log from normal boot mode.
     
  7. arcueil_1

    arcueil_1 Private E-2

    Sorry about that! :eek: Here's the new HJT log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know how CWShredder got installed as a service?
    O23 - Service: CWShredder Service - InterMute, Inc. - C:\Program Files\CWShredder\CWShredder.exe

    This is not required, normal or probably wanted. I have been seeing a bunch of these and it just makes no sense at all.

    You have a Virtumundo infection. I'm working on a fix.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see AVPersonal and AVG in your log. You must only use one antivirus application. It looks like AVG is either incompletely installed or incompletely uninstalled. Does it still show in Add/Remove programs? If so, uninstall it.
     
  10. arcueil_1

    arcueil_1 Private E-2

    AVG doesn't show up on the Add/Remove. What is AVG? I don't recall ever installing anything like that, but I guess I could have by accident.

    I got CWShredder here, downloaded it to the program files folder and got it started the normal way, so I don't know what happened.

    Virtumundo :eek:
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AVG is an antivirus application. But it was my mistake when I noticed the below in your log:
    O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min

    This is not AVG it is part of AV Personal.

    For some more info on Virtumundo you can see the sticky thread about it. But I will be posting a fix for you soon:

    READ ME: Virtumundo Problems/Resolution Threads


    That's strange about CWShredder. I never had this happen before. I have to try installing it on a new machine where it has not been installed on before and see what happens.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's start by downloading two tools we will need:

    - Process Explorer 9.2

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later.

    Reboot in Safe Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of urqpo.dll once and then click the kill button. After you have killed all of the urqpo.dll 's under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of urqpo.dll then click the kill button. Once you have done that click ok again. (If you do not find the dll, just continue on.)

    Also in process explorer look for:
    C:\WINDOWS\system32\conime.exe or just conime.exe

    And right click on it a select Kill Process.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\urqpo.dll
    O20 - Winlogon Notify: urqpo - C:\WINDOWS\system32\urqpo.dll



    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.

    C:\WINDOWS\system32\urqpo.dll
    C:\WINDOWS\system32\conime.exe

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log.
     
    Last edited: Aug 30, 2005
  13. arcueil_1

    arcueil_1 Private E-2

    I'm glad that you noticed that AVG was part of the AVPersonal. It's probably the AntiVir Guard (which I had turned off prior to the HJT scan).

    I'm going to read the Virtumundo page now. Thanx.
     
  14. arcueil_1

    arcueil_1 Private E-2

    Whoa, that was fast! Let me read your big post. Give me a few minutes.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have some mistakes in the post that I'm going to fix. I hope you have not run it yet.

    I'll but the changes in bold green so you can identify them. I had two DLLs listed that did not apply to you. You only have one so I changed the name and deleted references to the second dll.
     
  16. arcueil_1

    arcueil_1 Private E-2

    I thought that something was odd because I found nothing with Process Explorer. I did the two HJT fixes, merged fixVundo.reg with the registry and took the KillBox steps. I then rebooted and saved a new HJT log. I'll post it anyway, just in case. I'll come back to check the corrected instructions.
     
  17. arcueil_1

    arcueil_1 Private E-2

    Forgot the log...
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    RUn thru the steps again as they are written now. Make sure you find and delete that conime.exe file because it came back too.

    By the way I double checked CWShredder on a couple PCs where it was never installed. It does not come up running as a service. So I have no idea how you got it to be on your system like that. We will fix that later too. Do you remember exactly what you did with it?
     
  19. arcueil_1

    arcueil_1 Private E-2

    I just checked your corrections. I'm going to do it again now. I couldn't find conime before, but I'll try.

    I really don't know how CWShredder got there. :confused: I only downloaded it about three days ago and have only used it for this problem.

    I'll come back in about twenty minutes.
     
  20. PhilliePhan

    PhilliePhan Guest

    Hey Chas,

    Could this be legit? Microsoft Console IME (for use with foreign characters)?

    It might be worth checking in this case.

    Just a thought - Sorry to butt in!

    PP :)
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    arcueil_1,

    Do not delete the conime.exe file! It more than likely is not a problem because of where it is running from (the system32 folder).
     
  23. PhilliePhan

    PhilliePhan Guest

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    He indicate he was using the Chinese version in message # 4.

    That link is also giving false info for the conime.exe that is in system32. Perhaps you need to tell them to fix those two links and be more specific that the one in system32 is a valid Windows file.
     
  25. arcueil_1

    arcueil_1 Private E-2

    Hi, guys. Interesting what you said about conime because I couldn't find it at all with Process Explorer, so maybe it's indeed OK for it to be in the computer, in view that I use XP in Chinese, but please make sure. :)

    I think urqpo is gone. Here's the HJT log. Should I fix the CWShredder thing?
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes leave conime.exe alone. The CWShredder fix will not be as simple as fixing the line in HJT because it is running as a service. Follow the steps below to fix it. (I would still like to know how you got it running like this.)


    Now click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.

    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service


    Now scan with HJT and make sure the below entry is gone:

    O23 - Service: CWShredder Service - InterMute, Inc. - C:\Program Files\CWShredder\CWShredder.exe
     
  27. arcueil_1

    arcueil_1 Private E-2

    OK, let's see. Here's the new HJT log.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good! How is everything working now?
     
  29. arcueil_1

    arcueil_1 Private E-2

    So far, so good! Thanx a lot for the help. My wife and I really appreciate it. If something happens in the future, I'll be sure to post here. :)
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds