kpwn1.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by ashpash@i12.com, Aug 1, 2006.

  1. ashpash@i12.com

    ashpash@i12.com Private E-2

    I located this here "C:\WINDOWS\Temp\kpwn1.exe", hope that is the right place for it. I ran the scan at Jotti's and got this message:

    File: kpwn1.exe
    Status:
    MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.)
    MD5 2653ee441972db3b9475b07f08c990b2
    Packers detected:
    PE_PATCH.UPX, UPX
    Scanner resultsAntiVir Found nothing
    ArcaVir Found nothing
    Avast Found nothing
    AVG Antivirus Found nothing
    BitDefender Found nothing
    ClamAV Found nothing
    Dr.Web Found nothing
    F-Prot Antivirus Found nothing
    Fortinet Found nothing
    Kaspersky Anti-Virus Found nothing
    NOD32 Found nothing
    Norman Virus Control Found nothing
    UNA Found nothing
    VirusBuster Found nothing
    VBA32 Found nothing
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I took a look inside this executable file. It appears to be an adult content web dialer. I want to look at a few registry keys for some additional information. I will create a small tool to dump this information to a file for us to look at. Hopefully I can do this sometime today.

    How do you connect to the internet (analog modem, cable, DSL)???

    Comment: When our instructions say things like download such and such to its own folder or extract the contents of to its own folder. We really mean that you need to use a new folder for them. You are downloading and extracting tools to the root folder of your boot drive. This is a VERY BAD IDEA. Here is what you have thus far (I'm only showing new files too):

    C:\
    cwshre~1.exe 2 Aug 2006 532480 "cwshredder.exe"
    getrun~1.bat 1 Aug 2006 41695 "GetRunKey.bat"
    getrun~1.zip 9 Aug 2006 47345 "GetRunKey.zip"
    hijack~1.zip 29 Aug 2006 212849 "hijackthis.zip"
    hoster.zip 3 Aug 2006 234855 "hoster.zip"
    kill2me.zip 2 Aug 2006 13726 "kill2me.zip"
    newfiles.txt 9 Aug 2006 2149 "newfiles.txt"
    runkeys.txt 9 Aug 2006 11836 "runkeys.txt"
    shownew.bat 5 Aug 2006 22180 "ShowNew.bat"
    shownew.zip 9 Aug 2006 54487 "ShowNew.zip"
    window~1.exe 2 Aug 2006 2599840 "Windows-KB890830-V1.18.exe"
    winpfind.txt 9 Aug 2006 21944 "WinPFind.Txt"
    winpfind.zip 9 Aug 2006 204131 "WinPFind.zip"
    xpprof~1.exe 9 Aug 2006 94208 "XPProfiles.exe"

    None of these should be located in this folder. They should be in another folder where you save downloads to and then you should extract things to there own folder names so you know what they are later. For example we suggested that you create C:\MGTools and download ShowNew.zip and GetRunKey.zip there. Then also extract the contents of those two zip files into the same folder. The same logic applies to other tools. Also DO NOT use your Desktop unless it is requested.

    By the way, you need to go to Add/Remove programs and uninstall LinkOptimizer

    Also while in Add/Remove programs, can you tell me what the below are all for:
    Copy
    Readme
    Scan
    ScannerCopy
    TrayApp
    Unload

    I also don't see a firewall installed! Why not???? I thought BJ asked you to run the How to protect thread a while back. You must install one now if you have not already done so.
     
    Last edited: Aug 16, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached GetDialer.zip file. Extract the contents to its own folder (you can put this in the same place as GetRunKey and ShowNew, but this should not be the root folder of drive C)

    Then locate and run the GetDialer.bat file. This will create a file names c:\dialer.txt
    Attach this file to you next message.
     

    Attached Files:

  4. ashpash@i12.com

    ashpash@i12.com Private E-2

    Thanks for looking at that file. I connect to the net via ADSL Netgear Modem/Router. It is a firewall also and a while back I checked my ports to see if it was doing a good job, the reports say its doing a great job. I will install one if you think it's needed.

    Sorry about the files in the wrong place, I must have misunderstood. All the files I have used for this clean up I have put under C:, I didnt know you could put them within a folder. Would this set up be good? "C:\MGTools\GetRunKey\GetRunKey.bat" as this is how I have them now and will from now on. I have only used my Desktop for RegSrch.vbs as this is where the instructions said to put it. Again, I hope this is correct.

    I went to Add/Remove programs and found LinkOptimizer, when tried to uninstall it IE opens up with an uninstall button to click, when clicked amessage "Thank You" comes up and nothing happens. It's still there the same if I try do remove it using CrapCleaner. I do not see any of the other items listed there either, however, when I look in uninstall through CrapCleaner they are all listed there along with some other weird stuff I know nothing about. I have attached the log of this for you to see, I have markes all the ones I know about with a double asterisk, there maybe some that I do know but just dont recognise the name.

    BJ I have attached the dialer.txt also. I put this file here "C:\MGTools\GetDialer.zip\GetDialer.bat". Thanks for the help and patience, some times I need a sledge hammer upside my head to make stuff go in.:)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it was doing a great job you would not be infected. ;) Yes you still need to install a Software firewall. It may even help block this dialer from being able to respawn, See step 3 in the below link which was recently updated:

    How to Protect yourself from malware!

    That is what was suggested in the instructions for using them, so yes that would be good.

    You really need to understand better what you install on your system. There is way too much stuff that you don't recognize. It is very important in this day & age to keep track of this for your own security.

    Download and install this: Your Uninstaller! 2006
    Use it to uninstall LinkOptimizer

    Let me know if this works to uninstall it.

    Now for this kpwn1.exe file, I did not see what I expected in the registry key. I will try to work up a new fix for you to try tomorrow. In the mean time, make sure you have installed a software firewall, I suggest you use ZoneAlarm as a starting point. It is more user friendly on initial startup and recognition of valid programs, It is important that you install ZoneAlarm before continuing. It will ask you to reboot after installation. So after rebooting, come back here and attach a current HijackThis log and a new log from ShowNew. Then I will post a fix to try.
     
    Last edited: Aug 17, 2006
  6. ashpash@i12.com

    ashpash@i12.com Private E-2

    This seemed to do the trick, it appears to have gone. I have attached the requested files. Is there any way I can find out what the items in CrapCleaners Uninstall menu are? I am pretty aware of the programs I install as they are only the exact programs I need for the work I do. I tend not to just install programs willy nilly and try to really work out if I need the program before I do. However, I have a Husband who downloaded a mainframe tool (which was infected) that started this whole mess, so I cannot fully say what he does but He wont be in such a hurry to try that again after the roasting I gave him ;)

    As per post #45 this is still a problem and I cant delete that C:|RECYCLERS file as I get a "Cannot delete RECYCLERS: Access is denied. Make sure the disk is not full or write protected or file is not in use" I did do this in safe mode and cant get rid of it.

    Dont know if this is related but thought I would let you know.
     

    Attached Files:

  7. ashpash@i12.com

    ashpash@i12.com Private E-2

    Oh and I installed ZoneAlarm, I wont interfere with Avast will it?
     
  8. ashpash@i12.com

    ashpash@i12.com Private E-2

    I have found out tha Scan, ScannerCopy, TrayApp and Copy are all to do with my HP All-in-One Printer. Still trying to find out the rest.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! ZoneAlarm is a firewall and Avast is an antivirus program! Did you see kpwn1.exe come up in ZoneAlarm. If so, make sure you block it. If you did not see it, then look thru ZoneAlarm to make sure that if the process appears in any list that it is blocked (denied access).


    Now please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes. (If it restarts, just ignore it and continue!)

    C:\WINDOWS\Temp\kpwn1.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [kpwn1.exe] C:\WINDOWS\Temp\kpwn1.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Administrator\Local Settings\Temp\1.tmp
    C:\Documents and Settings\Administrator\Local Settings\Temp\3.tmp
    C:\Documents and Settings\Administrator\Local Settings\y7ir73cd.exe
    C:\Documents and Settings\Administrator\Local Settings\BHO2.tmp
    C:\WINDOWS\desktop.html
    C:\WINDOWS\xpupdate.exe
    C:\WINDOWS\temp\kpwn1.exe
    C:\WINDOWS\temp\kpwn1.zip
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locat the below folder and delete it if found:
    C:\Program Files\BraveSentry


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp\
    C:\Documents and Settings\Administrator\Local Settings\Temp\
    C:\Windows\Prefetch <--- delete ALL files in this folder.


    Now attach a new HJT log and tell me how the steps went.
    Also attach a new log from ShowNew and a new log from GetRunKey.
     
    Last edited: Aug 17, 2006
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not supposed to delete the Recyclers folder (it is not a file, it is a folder. Think of a folder like the drawer of a filing cabinet and the files are the items in the drawer.). It is a required system folder. BJ just wanted you to delete all files in the folder. The proper way to do that is to just right click on the Recycle Bin icon on your Desktop and select Empty Recycle Bin. If the Empty Recycle Bin item is grayed out (i.e., not selectable), it means it is already empty.
     
  11. ashpash@i12.com

    ashpash@i12.com Private E-2

    Yes ZoneAlarm picked it up and I have blocked it.

    When I go to the file menu and choose paste, nothing happens. If I try to continue and delete I get a message telling me that I have not specified any files to delete, and I definatly copied it before pasting as I can copy and paste them individually. Can I do it indiviually?

    As per the RECYCLERS thing there is a hidden file inside it which I"m not too sure should be there or not, I cant seem to delete it so maybe it's supposed to be there but I'm not too sure. If I try to delete it I cant as I have to "Make sure the disk is not full or write protected or file is not in use". The file name is "S-1-5-21-1960408961-1979792683-839522115-500" see post #43 and #44, its just that it was there when BJ asked me to delete everything in it.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot in safe mode and look for the file yourself. If found, delete it! Let me know the results!

    You need to attach the followup logs I requested!
    That folder belongs there. Leave it alone! I repeat....... The proper way to remove files from the Recycler is to right click on the Recycle Bin and select Empty. Do not try to delete them by hand!
     
  13. ashpash@i12.com

    ashpash@i12.com Private E-2

    Attached files as requested. When I looked for the files you listed I didnt find any but I did follow your instructions to the end. I also didnt find BraveSentry. The deleted files deleted fine apart from the files from today (as you said).
     

    Attached Files:

  14. ashpash@i12.com

    ashpash@i12.com Private E-2

    Zone Alarm has just popped up with an alert, "kpwn1.exe is trying to acess the internet. This program has changed since the last time it ran." I have blocked it again just thought I would let you know. This is one persistant little bugger.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not see the process or file in any of your logs! Were they all obtained before it came back. If you get new logs, does it show in them now?

    After deleting it, does it ever come back if you only reboot in safe mode?

    When it did come back (ie ZoneAlarm poppep up), when was this? Was it right after boot, was it only after running a browser or something else?
     
  16. ashpash@i12.com

    ashpash@i12.com Private E-2

    The logs I attached in Post #63 where from straight after the clean up and was immediatly sent after I had finished following your instructions. It wasnt there then. The second post was immediatly after the Zone Alarm pop up wich was approx 5 hrs later, so it wasnt straight after boot up. I have attached new logs and I checked HJT straight after the alert from ZA and it was running in the processes then. I had done some surfing straight after the cleanup and had closed my browser, I was painting in Photoshop when the alarm popped up.

    I havent tried running my PC in safe mode for that amount of time so I cant answer that one but it certainly goes then comes back some time later, never straight away.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thinking of some stuff to try! While I'm doing that, please answer a question.

    Is the clock/calendar on your PC setup properly? Look at the data on the two below files:
     
  18. ashpash@i12.com

    ashpash@i12.com Private E-2

    Yes it is, although I am in Australia an probably showing a different time from most people but that date is certainly correct. Saturday, 19th August 2006. Cant think if why that would be.
     
  19. ashpash@i12.com

    ashpash@i12.com Private E-2

    Sorry, not that date but MY date is correct.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I wonder how they got set to the wrong dates!

    Follow the below directions EXACTLY!
    1. Create a new folder on drive C name C:\fixkp
    2. download the attached patch.zip file to the fixkp folder
    3. Extract all files from the patch.zip file into the fixkp folder
    4. Run the runfix.bat file by double clicking on it.
    5. Upload the C:\fixkp\fixlog.txt file that will be created here as an attachment.
    6. Now get a new logs from ShowNew, and HJT and attach them too
    7. Now reboot your PC. Get me a second set of logs from ShowNew and HJT (attach them in a second message).
    Let me know if you are still getting any warnings from the firewall. If not, let's see if you get any at a later time. What I'm doing is trying to prevent the file from recreating itself by making a dummy file with the same name that is protected (hopefully) and by also using the same registry key to have it call the patch to fix the problem again on each reboot. While this is not a fix, I want to see if it at least blocks the problem or if whatever is creating this, tries to make a new filename to spawn the problem.
     

    Attached Files:

  21. ashpash@i12.com

    ashpash@i12.com Private E-2

    Havent had a warning as yet but I have only just finished with your instructions.
     

    Attached Files:

    Last edited: Aug 20, 2006
  22. ashpash@i12.com

    ashpash@i12.com Private E-2

    After I rebooted I got a dos prompt window pop up. It wasnt up for long and I didnt get a good look at it but it said somthing like:

    Searching......
    .......system32\cmd.exe
    File not found - c:\windows\temp\kpwn1.exe

    If I rebooted a few more times I may get the whole message if you need it but its not up for long enough to get it word for word in one sitting ;)

    In Zone Alarm, kpwn1.exe is listed in the program control as "ask" so I will know if it tries to get access.

    If you need more info on the reboot pop up then just let me know and I will reboot a few times.
     

    Attached Files:

  23. ashpash@i12.com

    ashpash@i12.com Private E-2

    Zone Alarm has just popped up and asked permission for kpwn1.exe to access the net. Just ovet half an hour after the patch. Denied as per usual.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! The runfix.bat file did not quite do what I wanted. During the procedure it should have deleted the real kpwn1.exe file and replace it with a dummy file that is smaller in size (which would make it easy for me to tell it was replace). The problem is that it did not replace the file. Probably because the process was running. So here is what I want you to do. Kill the kpwn1.exe process like we did in the past using HJT (see message # 59) and then manually get the file deleted yourself. Try deleting it as soon as you kill the process. If you cannot delete it, boot into safe mode and delete it. As soon as you get it deleted, run the steps in message # 70 starting at step 4. And upload the logs again.

    When/if the firewall popups up again, attach a new (second) HJT log.
     
  25. ashpash@i12.com

    ashpash@i12.com Private E-2

    Heres the logs after the fix
     

    Attached Files:

  26. ashpash@i12.com

    ashpash@i12.com Private E-2

    After the reboot.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Something is not right! The patched file is not being copied to the C:\windows\Temp folder.

    Run the Runfix.bat file right now and attach a new log from ShowNew!
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also quickly goto the below folder and delete all files (a few from files may not be deleteable because Windows will block them from being deleted):

    C:\Documents and Settings\Administrator\Local Settings\Temp


    If you wait too long to get the instructions in message number 77 & 78 done. You may have to start message # 74 all over again because the real file may have come back.
     
  29. ashpash@i12.com

    ashpash@i12.com Private E-2

    Hope this was soon enought, I had to go out, if not I'll do it again from #74. Just let me know.
     

    Attached Files:

  30. ashpash@i12.com

    ashpash@i12.com Private E-2

    Nothing from Zone Alarm so far.
     
  31. ashpash@i12.com

    ashpash@i12.com Private E-2

    Spoke too soon. Just came to use the computer and there is a Zone Alarm pop up saying the kpwn2.exe is trying to access the net. No one was using it st the time either.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this is what I was expecting would happen. There is definitely something else hiding that is creating this process. I will probably have to workup a procedure using MSconfig to only load certain processes and services at startup to see if anything you have installed is respawning this. Attach a new ShowNew & HJT log now.

    Let's also do some more hunting!

    Let's get a Startup List with Hijack This.

    Generating Startup Lists with HijackThis
    • Run HijackThis, click Open the Misc Tools section
    • Put a check in the List also minor sections (full) check box.
    • Now click the Generate StartupList Log button.
    • This will create a file named startuplist.txt in the same folder that HijackThis is installed into.
    • Also a notepad file will open with this startuplist in it.
    • Attach the startuplist.txt file to your next message.
    Now download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.


    Download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on explorer.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
    • Now repeat the above steps but get a log after clicking on iexplore.exe
    You will have to use a couple messages to attach all the above logs!


    By any chance are you on a wireless network? Does the below link mean anything to you?
    http://www.kpwn.4t.com/
     
    Last edited: Aug 20, 2006
  33. ashpash@i12.com

    ashpash@i12.com Private E-2

    Here's the first set of log, after the alarm but not before following your new instructions. I'm about to do them now.


    I am not on a wireless network and as far as I know it not networked to anything, this PC it the only one in the house and doesnt even have a wireless mouse or keyboard. I had a look at the site and have never seen it before.
     

    Attached Files:

  34. ashpash@i12.com

    ashpash@i12.com Private E-2

    Attached is the startup list from HJT.

    I couldn't get BlackLight Beta to install. I just got the following message:
    "F.Secure BlackLight could not acquire the necessary privileges (SeDebugPrivilege).
    - Your computer settings may prevent acquiring these privileges.
    - a malicious program might have disabled these privileges.

    I continued with Process Explorer and have attached the explorer.exe log, I couldn't find iexplore.exe on the list of processes and therefore couldnt do this log.
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Look2Me VX2 Removal it should hopefully fix that setting. Attach the Look2Me-Destroyer log.

    Just open one IE browser window and then get me the log.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see that kpwn2.exe is running. Use Process Explorer the same way you did for explorer.exe and iexplore.exe and select kpwn2.exe and get me a log too.
     
  37. ashpash@i12.com

    ashpash@i12.com Private E-2

    Still cant use BlackLight. Same message comes up.
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you using an account that has administrator priviledges? Look2Me Destroyer successfully enabled SeDebugPrivilege so it should work now.

    How many user accounts on this PC? If you login to other user accounts, does this kpwn1 or kpwn2.exe file also appear.

    If you don't have other user accounts, create one. And then login to the new account and see if kpwn shows up.



    Download these two tools and extract them to a folder!
    - Filemon for WinNT/2K/XP
    - Regmon for WinNT/2K/XP


    Run Filemon

    When it comes up, change the *.* in the Include box to say kpwn*.exe Then click Apply and OK. The Filemon window now comes up and will monitor for anything accessing kpwn*.exe Now just leave this running and continue.

    Run Regmon

    When it comes up, click the icon that sort of looks like a diamond with some blue color on top. This is the Regmon filter. In this filter, enter the following:
    kpwn*.exe

    Then click Apply and then OK. It will ask if you want to apply the filter to the current output. Say yes


    Now use procedures like we did in the past to stop any kpwn files from running and then delete the kpwn2.exe file in the c:\windows\temp folder. Also run HJT and have it fix the O4 line related to kpwn2.exe

    This may help us see if anything runs to to restart it. You can go back to the Filemon screen and click File and then uncheck the Capture Events selection to stop the capture process. Then use File, Save As to save the log to a file like filemon.log and post it back here as an attachment.



    Also after you fix the kpwn stuff and after it pops back up again, Regmon will show the activity. It should also show if anything else is putting the entry back into the registry. So go back to the Regmon screen and click File and then uncheck the Capture Events selection to stop the capture process. Then use File, Save As to save the log to a file like regmon.log and post it back here as an attachment.


    Let me know if you don't understand any of the above proceudre or have a problem getting them to work as desired.
     
    Last edited: Aug 21, 2006
  39. ashpash@i12.com

    ashpash@i12.com Private E-2

    I am the only user set on this PC and it is set up as an Administrator. I went to the users to set up an account to test with and could only set up another Admin account :confused: . I set it up and switched to this account. I then set up a limited account within that Admin account and went into this. Within about 5 minutes of opening both these accounts kpwn2 popped up. I then went to switch back to my original account (with all my settings) and it wasnt available as an account to use :eek: . I went to the Help & Technical Forums/Software forum and found ctrl-alt-del entered twice would work. Signed on as my original account and deleted the two test account via the Management Console.

    Whilst in this second admin account I did try to run BlackLight and still couldn't - same message. I also tried Filemon and Regmon in both account with no luck at all. I dont have the Debug programs privileges (filemon). I had a error message when trying to run Regmon but when I tried again I get the message its already running. Btw those links to those two tools dont work. I had to go to the Sysinternals site and download from there. I hope I got the correct version.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now that's interesting!


    Hmmm! I'm not sure what is going on here but something has your permissions all disabled.

    Download and install Microsoft's Debugging Tools for Windows 32-bit Version:
    http://msdl.microsoft.com/download/s...86_6.4.7.2.exe

    Then see if you can get Regmon and Filemon to run. Meanwhile I'll see if I can figure out why your SeDebugPrivilege is not getting enabled.

    Do you have WinXP Pro, or Home, or Media?

    Thanks! Looks like they changed their pages. You probably have the correct versions, but here they are just in case (and also for anyone else that reads this thread):

    Filemon v7.03

    Regmon v7.03
     
    Last edited: Aug 21, 2006
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached setrights.zip files to the same folder where you have ShowNew installed. Then extract the two files from setrights.zip. Now locate the setrights.cmd file and double click on it. Let me know if you get any error messages.

    Now try to run Filemon and Regmon. Any luck?
     

    Attached Files:

  42. ashpash@i12.com

    ashpash@i12.com Private E-2

    Finally!! Still wouldnt work so I did a reboot and bingo!! Cant seem to upload the filemon log though, I have had a look at it and there is absolutely nothing on it. Is that right?
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was the log from Regmon stopped (i.e., saved ) after you had deleted the stopped the kpwn2.exe process (if running), deleted the file, and killed the O4 line with HJT and then waited for it to reappear. What we need to capture is when it reappears. Both Filemon and Regmon should be saved after the file has come back but they obviously need to be running before it comes back. If the logs get to large to upload, compress them into a ZIP file and upload them.
     
  44. ashpash@i12.com

    ashpash@i12.com Private E-2

    I realised my mistake, in my joy of finally getting them to work I typed kpw*n.exe into filemon....hence no report. I have fixed this now and am waiting for it to start running again. Should the capture events be cheched with a tick?
     
  45. ashpash@i12.com

    ashpash@i12.com Private E-2

    Sorry to answer your question, yes. the log from Regmon was saved after killing the process, deleting the file and killing the o4 with HJT.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but what you need to do is save it after it comes back.
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it needs to be checked or it will not capture anything. That is how you basically enable and disable the capture.
     
  48. ashpash@i12.com

    ashpash@i12.com Private E-2

    Ok, all correct....now we wait......
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and also hope that they give us some incite into where this is originating from.

    After you get these logs, give BlackLight another try!

    I'll check into tomorrow morning....... well that is later today. Need to get some sleep now.
     
  50. ashpash@i12.com

    ashpash@i12.com Private E-2

    Have a good nights sleep, hope I didnt keep you up too long ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds