I'm Baffled, this junk keeps coming back

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Fuelman, Dec 15, 2004.

  1. Fuelman

    Fuelman Private First Class

    Here's the other filemon and regmon logs
     

    Attached Files:

  2. Fuelman

    Fuelman Private First Class

    I can't seem to upload the .reg file of where I found the offending entries.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    .reg is not an allowable extension to upload. Either change it to a .txt or .log extension or you can put the whole file (the .reg file) in a ZIP file and upload that.

    Those files from Ad-Aware only told us what we already know.

    I have something else to try. Use Registrar Lite again as we did before to do a search but his time search for:

    Ms4Hd

    Give me all the matches (if any).

    If it is found, I expect one of the matches to be something like:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ms4Hd
     
  4. Fuelman

    Fuelman Private First Class

    Found nothing in a search for Ms4Hd, in registrar lite.

    Finally figured out how to save the files I figured may be usefull in a txt format. Here thay are, hopefully they will be of benefit.
    Only one would upload????
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember those files from the findit.bat log that we could not delete for some reason. They are still bugging me. Here is the list (all are in the c:\windows\system32 folder)

    Directory of C:\WINDOWS\System32
    12/26/2004 09:30 AM <DIR> dllcache
    12/16/2004 06:56 AM 0 Copy of atlbr.exe
    12/15/2004 09:26 PM 0 mssg.exe
    12/15/2004 09:26 PM 0 Copy of mssg.exe
    12/15/2004 05:42 AM 0 Copy of msxd.exe
    12/15/2004 05:42 AM 0 msxd.exe
    12/04/2004 08:35 PM 56,320 cfsra.dll
    11/26/2004 10:14 PM 56,320 mgmeq.dll
    11/26/2004 03:00 AM 56,320 zmguv.dll
    11/05/2004 07:38 PM 0 sdksg.exe
    11/05/2004 07:38 PM 0 Copy of sdksg.exe
    10/30/2004 04:58 AM 0 d3mx32.exe
    10/30/2004 04:58 AM 0 Copy of d3mx32.exe
    10/06/2004 04:35 AM 0 Copy of hfxld.dat
    10/06/2004 04:35 AM 0 hfxld.dat
    07/13/2004 01:43 PM 0 Copy of wkyhd.dll
    07/13/2004 01:43 PM 0 wkyhd.dll

    I want to see this link http://support.microsoft.com/?kbid=308421 on taking ownership of files/folders and take ownership of the files and then try to delete then (probably in safe mode). Let me know what happens with that.
     
  6. Fuelman

    Fuelman Private First Class

    I found all the files mentioned, have no idea it they will stay deleted. I still can not get into safe mode and therefore could not take ownership of the files since I'm on XP Home.

    There are lots of empty files in the system32 folder, and a lot of ones that are copies and copy 2 of the same thing.

    I appreciate you sticking with me on this, Now what?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Jan 3, 2005
  8. Fuelman

    Fuelman Private First Class

    Here's the log of the new program you had me download.

    Brian
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That does not look like the correct output. Did you copy what was on the screen or did you copy & paste the output.txt file that was created. You needed to do that before hitting the key to the final prompt because they will erase the file when you hit the key. When they say, "After copying and pasting your logfile, please press a key." The output.txt file should already be created and opened. That is what needs to be copied back here.

    EDIT: Darn! That was my fault for not being clear in my instructions. When I said:
    Extract find.bat and run it. Post the log it creates back here.

    I should have said:
    Extract all files from the ZIP and run find.bat. Post the log it creates back here. That log is call output.txt

    Let's try this again!

    It should begin something like the below, it is much longer though (I have edit out alot):

    Warning! This utility will find legitimate files in addition to malware.
    Do not remove anything unless you are sure you know what you're doing.
    Find.bat is running from: C:\HijackThis\NewDownloads\finditnt2000xp\Find It NT-2K-XP
    ------- System Files in System32 Directory -------
    Volume in drive C has no label.
    Volume Serial Number is B8D1-7A76
    Directory of C:\WINNT\System32
    12/24/2004 06:55 AM <DIR> dllcache
    04/08/2002 08:02 AM <DIR> Microsoft
    0 File(s) 0 bytes
    2 Dir(s) 17,849,364,480 bytes free

    To see an example, look at this thread: http://forums.majorgeeks.com/showthread.php?t=50835

    and read messages # 53 to # 55
     
    Last edited: Jan 2, 2005
  10. Fuelman

    Fuelman Private First Class

    Chaslang,
    I think I have it right this time,
    I have to right click (before hitting any key) the black screen when it finishes running and paste it to a notepad. If Output shows up anywhere else, I have no idea.
     
  11. Fuelman

    Fuelman Private First Class

    Its not letting me upload the file. keeps coming back saying it already exists in this thread. I changed the name a dozen times and it says the same thing.
     
  12. Fuelman

    Fuelman Private First Class

    Try this, finally got it attached
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy and paste the information in the below quote box to notepad. Save it to your Desktop as type "all files" and name it fixvx2.reg. Doubleclick it and grant it permission to merge in the registry entries.
    We have some more files that we need to delete using Killbox. They are all in the c:\winnt\system32 folder:

    C:\WINNT\system32\ieppni.dll
    C:\WINNT\system32\lcuuql.dll
    C:\WINNT\system32\lhuual.exe
    C:\WINNT\system32\wpuukw.dat
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\khggik.exe

    and C:\WINNT\system32\vwuugv.exe

    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Replace on Reboot.

    Now you are going to repeat the below steps for every file except C:\WINNT\system32\vwuugv.exe
    (we will add it separately at the end). Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINNT\system32\ieppni.dll


    1) Now, Copy and Paste fullpathfile into the box
    2) Check the option to Use Dummy.
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click NO.
    5) Repeat for all files except the last one

    For the last file, we will be rebooting when prompted. Here is the final step of the file deletions:

    Now, Copy and Paste C:\WINNT\system32\vwuugv.exe into the box. Check the option to Use Dummy and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to reboot Normally.

    After reboot post another log from this new find.bat program. Let me know if you get any errors when you reboot. Write down the exact message if you do get any.
     
    Last edited: Jan 3, 2005
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also want you to do this:

    Download and this file to your computer where you can find it.

    RemV3.Zip

    Extract all the files to a folder (make it a folder for only these tools).
    Then boot into safe mode and run the remv3.bat file.

    Then, while still in Safe Mode, scan with HijackThis and save the log as safe.log

    Next, Reboot to Normal Windows, scan with HJT again and save that log as normal.log

    Please attach both those logs.

    Now look in your drive C root folder (the c:\ folder) and find log.txt. Upload that file back here as an attachment. (it is the output from remv3.bat )
     
  15. Fuelman

    Fuelman Private First Class

    OK, I ran kilbox as requested, when I clicked yes to reboot, a box popped up saying "Pending file name operations registry data has been removed by external process" then I had to reboot manually.

    could not attach the output log from the new find.bat again.

    Ran the remv3 after extracting it. Tried to boot into safe mode but I still can not boot into safe mode at all. So I ran the remv3 in normal mode, its log is attached.
    Since I could not get into safe mode to run hjt, I just ran it in normal mode.


    Why can I not get into safe mode?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try uninstalling Trojan Hunter, Spybot, SpywareBlaster, Ad-Aware, and anything else installed that may be locking/protecting pages
    and the registry.

    Also you still have both Norton and AVG installed. You must uninstall one. I would dump Norton.

    Have you ever tried using sfc (system file check) from the command prompt.
    See this MS article: http://support.microsoft.com/default.aspx?scid=kb;en-us;310747

    Then repeat those steps. Do not reinstall those programs yet until we get to discuss this.
     
    Last edited: Jan 3, 2005
  17. Fuelman

    Fuelman Private First Class

    I removed the programs you mentioned. did you want me to remove the junk left behind by some of them in hijack this? namely symantic and trojan hunter.

    I still can not boot into safe mode.

    I read the link to system file check, did you want me to run any of those?

    Brian
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post me a HJT log so I can see what's left. Norton stuff can be a pain to get complete cleaned out.

    Yes, run sfc and let's see what it says.
     
  19. Fuelman

    Fuelman Private First Class

    I ran sfc.exe from the command prompt then ran the /SCANNOW. It ran and finished with no logs or any other prompting to do anything.

    Here's the hjt log, old junk we can't seem to get rid of is still there, plus the symantic norton stuff from the uninstalled programs.

    Still can not boot into safe mode.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to post the HJT log.
     
  21. Zaphod 42

    Zaphod 42 Private E-2

    Hey Guys,

    Thought you both might need a little encouragement. It seems that you're doing a hell of a job. I have the same type of crap on my machine and I've been looking to see if anyone has had any success getting rid of it. I have read all of your posts and I'm amazed that you are still hard at it.

    Keep up the fantastic work! If you manage to succeed, I may next!

    Congrats!!

    Zaphod
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have fixed hundreds (if not more) of HSA and about:blank hijacks but this one as some additional new problems deep rooted and does not manifest itself the same way. Also if you look back in the thread, there were hundreds of ADS infected files found by ADSspy. Many were bad some were unknown. Problem is I cannot find any DLLs or EXE files that are loading these. And the two EXE files that show to be loading in the O4 lines never seem to exist.

    If you have problem with HSA, you should post your log and we may be able to fix it. This thread with Fuelman is the first one I have had this much difficulty with. I don't want to give in to the piece of crud. I'm not sure how much longer Fuelman can take it though. To me it's the challenge. To bad I don't live in Michigan, I would drive over and work on it in person! :)
     
  23. Fuelman

    Fuelman Private First Class

    OOPs, you're correct, I neglected to attach the last hjt log. here it is.

    Too many other people may be able to benefit from a remedy to this, I'lll stick with you Chaslang on this till you either throw in the towel or you find a remedy. I have backed up all my data just incase it gets corrupted too, and I need to reload windows.

    I was wondering, If I do my windows upgrade to XP Pro, will that restore the function of being able to boot into safe mode? I'm talking about the upgrade that installs over the existing XP Home.

    Got any business trips planned to MI?
     

    Attached Files:

  24. smith

    smith Private E-2

    I also have a similar problem 5 reinstalls, what I have found out is that I am finding some of the .exe files and others in the hidden dllcache in system32 , also that this thing hides it's files in programs and pagefilling that are on other drives. It also seems to regenerate any time not just at startup.File monitor left on for hours uncovers alot of file links to other drives maybe you could track it down a bit further with that.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks Smith!

    Yes the HSA hijackers have many different things that can cause regeneration and spreading of the infection. There are multiple items scattered around in the registry, files (including EXE, DAT, DLL, HTML, TMP maybe more) all over the place (including the windows rootdir, system, system32, dllcache, rootdir, temp folders). My Generic Solution has worked everytime thus far, although sometimes it may require multiple runs due to the level of contamination that may be in effect. But this infection Fuelman has seems to have some new hidden problems or the depth of the infection is the problem. There were and still are hundreds of ADS files on the disk.

    I have a few more things I want to try. Coming soon.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Brian,

    You forgot to remove Ad-Aware. This is still running:
    O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"

    After doing that go back and run the steps were we attempted the removal of the lines in HijackThis and the delete of the files. Let me know what happens

    Also, check properties info on C:\WINDOWS\System32\RUNDLL32.EXE
    Check the Version tab make sure it is a Microsoft file. What is the file size and what version is it?
     
    Last edited: Jan 4, 2005
  27. Fuelman

    Fuelman Private First Class

    Chaslang,
    I DID REMOVE AD-AWARE !!!!
    Your guess is as good as mine as to why its still showing up on there.
    I even ran cclean and then defraged my hard drive.


    In response to what smith mentioned, yes, I have had a lot of stuff accack my partitioned drive (D: drive). When I was using Ad-Aware, It was constantly picking stuff up in the D: drive. I think it may have gotten corrupted because the system restore function was constantly updating itself just about every time I turned the computer on (I was'nt telling it to, it was doing it on its own). I did'nt realize it untill I went to restore my system and the furthest back I could go in the calander was only a day or two.

    What can be tried next?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kill Ad-Watch.exe if it is running and then have HJT fix the below line.
    O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"

    Then get me the info on the DLL I asked for.

    Wait a few minutes before trying to fixes on the other 4 items, I'll get back to you.
     
  29. Fuelman

    Fuelman Private First Class

    version 5.1.2600.0, 31 KB in size, Microsoft file created in November 2002


    Attempted to remove the lines again through hjt, we'll see if they come back.
    What about the O16 lines that have symantic stuff in there?, is'nt that norton av stuff?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about the O16 lines. They are from the online scanners. If you rescan right now, are the lines still gone from the HJT log.

    Also do the below files actually exist:
    C:\WINDOWS\qkxwe.dll
    C:\WINDOWS\system32\sysmy.exe
    C:\WINDOWS\system32\ieam.exe
     
  31. Fuelman

    Fuelman Private First Class

    Also do the below files actually exist:
    C:\WINDOWS\qkxwe.dll
    C:\WINDOWS\system32\sysmy.exe
    C:\WINDOWS\system32\ieam.exe

    I did a search and it came up with nothing, not showing a darn thing on the above.

    I reran hjt and the 5 files that were fixed have not come back (yet), but then again I have not rebooted. The three above will most surley come back as soon as I reboot the machine.

    gotta get some sleep, 0500 work call comes fast.

    Brian
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't search! Use Windows Explorer and look for them.

    Do not reboot until I say too. I want to try something much different (rather drastic).

    Hang on a little longer tonight.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still here Brian! Need to know if you found the file using Explorer.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well just in case you come back, here is what I wanted to do but you'll have to start over again if you have rebooted to get to the point we were at before this.

    Print these instructions so you have them when offline.
    After reading this message, this is what I want you to do:
    - Exit all browsers
    - exit all other running program or items in your system tray
    - disconnected physically (unplug cable) from the internet
    - run HJT one more time, if lines came back fix them again and exit HJT
    - Okay here is the drastic step: physically pull the power plug to your PC.
    If you have one of those power strip modules where everything is plugged into, shut it off.
    Do not use the power button on the PC.
    - wait a minute
    - power back up, do not run anything and remain disconnected from the internet
    - run HJT get a log hjtlog1.log
    - open & close IE
    - run HJT get a log hjtlog2.log
    - reconnect to the internet and run a IE come here and post logs and tell me what's up
     
  35. Fuelman

    Fuelman Private First Class

    Sorry about that Dr.C, I could'nt stay awake any longer last night. I'm in the military and "O'-Dark- Early" comes every morning that I'm not on leave.

    I did run a search last night and found nothing of the mentioned files. I did look in explorer and came up blank as well.

    I did shut down the computer last night, wish I'd known you needed it left on.
     
  36. Fuelman

    Fuelman Private First Class

    Chaslang,
    I followed your instructions in message 134. Attached are the two hjt logs as requested.

    I did'nt see the stuff there anymore, I think its hiding and going to pop back up as soon as I think its gone.

    I'm gonna see if I can get into safe mode now.
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When that looks better thus far Brian. Keep an eye on it for a while. Each time you open a browser and then exit or after each reboot. Take a look at the HJT log. See if the lines came back.

    Also not that the lines appear to be gone. Look for the files again to see if you can find and delete them (just in case).

    Also, right now while there seem to be no malware problems follow the steps here:
    How to Protect yourself from malware!

    That will get some of the items we uninstall back in place too. (We uninstalled Trojan Hunter, Spybot, SpywareBlaster, & Ad-Aware SE)

    Make sure you have the current version of AVG. They are now at AVG Free Edition 7.300
     
  38. Fuelman

    Fuelman Private First Class

    I'll get acquanted with the anti malware pecautions. I am now running avg and it seems to pick stuff up on a regualr basis.
    Now, what do I do about all the other problems like not being able to boot into safe mode, all the zero byte files in my c:\windows directory, I even found a couple zero byte .exe files in my documents folder.

    I guess what I'm asking is how do I identify what is good and what is bad that I can safely delete?

    Can I now upgrade to my windows XP Pro (I would like to install over the XP Home), without it causing any additional difficulties?


    Appreciate your help very much, anytime you're out this way, I'll buy you a beer or martini or a coffee or something. THANK YOU

    Brian
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is it version 7.3?

    That's going to take some work! Perhaps the going to Windows Update and getting the updates may help the safe mode problem. As far as the zero byte files we are going to think about this first but for most cases I would expect they are not needed but don't go and delete them yet.

    What are the ones in MyDocument and what is the full path to the file?

    Yes, I would believe so.

    You're welcome! Happy I could help. Keep me posted on your progress!
     
  40. Fuelman

    Fuelman Private First Class

    AVG just updated today to 7.0.300

    For the windows update, I am on dial up and most of the updates would tie up a phone line for literally hours. I do download the small files that are less than 5 or 6 mb.

    winlw.exe
    winp32.exe
    winpi.exe
    winpt32.exe
    the path is "C:\Documents and Settings\Owner\My Documents\winpi32.exe"
    the other ones are the same except the last little bit is the same as the file name.
    the autoexec filename is the same for all of them; %SystemRoot%\SYSTEM32\AUTOEXEC.NT

    So is this going to be a problem?

    ALso, should I get rid of my current Java stuff and get teh sunmicro?

    I also did read somewhere that disabling windows messanger will help cut down on pop ups too. How is it disabled, cant figure that one out.

    Thanks
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I added in red comments below. There was a link to get a free SP2 on CD. I don't remember the link. You could drop a message in the software forum and see if someone there has it and if it is still valid.

     
  42. Fuelman

    Fuelman Private First Class

    winpt32.exe..... <--- Delete it
    the path is "C:\Documents and Settings\Owner\My Documents\winpi32.exe"
    the other ones are the same except the last little bit is the same as the file name..... <---What do you mean?
    I was refering to the last part of the path ......\winpi32.exe" would be \winlw.exe, \winpi.exe, etc etc.
    The autoexec file name is from rightclicking on the file, going to properties and hitting the advance tab and getting that information out of there, I figured it would help, guess it did'nt, oh well.

    I am using fire fox now, was actually thinking of using thunderbird too.

    I'll be in touch, thank you.

    Brian
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But I don't know what you mean that autoexec.nt is the same for all of them.
    There is only one c:\windows\system32\autoexec.nt file.

    EDIT: OOOOH! I think you mean when you right clicked on one of those EXE files and looked at something. I think what you meant was you right click on the files, selected the Programs tab and then clicked the Advanced button and looked at the Autoexec filename: field.

    Right? That would be the same.
     
    Last edited: Jan 6, 2005
  44. Fuelman

    Fuelman Private First Class


    yeah, thats it!
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How is she running (other than safe mode boot issue)? Are those entries in the HJT log still gone?

    Get me a list of all the zero byte size file you moved to the temp folder. Remember how to do that from the command prompt?
     
  46. Zaphod 42

    Zaphod 42 Private E-2

    Hi Guys,

    Looks as though you're still at it. Keep it up and Chaslang I'll catch you when you're done with this one.

    Thanks,

    Z
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are done! The problem was fixed! I'm just checking to make sure it still is fixed.

    If you have a problem, start your own thread. Run ALL of the READ ME FIRST before posting and let us know that you did.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds