Major Cleanup Headache

Discussion in 'Malware Help (A Specialist Will Reply)' started by jtpiano, Mar 27, 2005.

  1. jtpiano

    jtpiano Private E-2

    I was asked to help get a computer working that couldn't get on the internet. Little did I realize it would be the worst infestation of spyware and viruses I have ever seen. Trend reported 25 viruses the first time through. Symnatec had nearly 100. I have followed all the steps in the sticky thread at least one time through. I ran into a few bumps along the way as well. I had to use an LSP tool after removing some items. Now I wanted to go back and try to run through the list a second time from top to bottom because so many viruses and spyware were found in the first round. Now I can't get the Symantec online scan to run. I have followed the directions verbatim and made sure the Active X and Scripting settings are correct. Symantec tells me my settings are wrong and wont allow the scan to continue despite checking my settings twice. Also, when trying to run Ad Aware it freezes up halfway through the scan. I have the same problem with Stinger. Anyhow I tried some of the alternative scanning sites listed and they all report I am virus free now. So my last big problem is some spyware though I have that 95% cleaned up too. HijackThis is detecting some nasties yet but I am unsure of how to get rid of the last few bits. I have noticed a few .exe files that aren't legit. If I try to browse to them using the GUI they are hidden. (I have showing of hidden files and folders enabled.) However, if I use the command line I can find the file. I tried to delete the file in safe mode from the command line but no luck. I hope someone can shed some light on what I have and how to get rid of it. Thanks for your help!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Windows OS and IE are seriously out of date and must be update after fixing any current problems. Leaving them as they are now is a security risk.

    Are you sure the TrendMicro scan was run? I see no signs of it in your log. Did you run the Java version?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\ikpipz.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {E1350B8F-4B65-DEC1-0898-E24ACCBECEB5} - (no file) <-- will probably come back. We see many of these they cannot be fixed!
    O2 - BHO: (no name) - {F48312F2-C1ED-120D-8550-B91A6EF46E60} - (no file) <-- will probably come back. We see many of these they cannot be fixed!
    O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\ikpipz.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\ikpipz.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).
    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  4. jtpiano

    jtpiano Private E-2

    I did use the Trend Micro online scan. After it came up clean the second time around I deleted the corresponding entries using HJT so the log looks a little neater. No sense in looking at clutter, if possible, in my book. Anyhow, I followed the steps you listed below and am posting my new log. Some things I've noticed though- You can't see the offending exe file using windows explorer. You can only get to it by using the command prompt. I had trouble deleting the file (even in safe mode). When I looked at the attributes only the A flag came up. I was only able to delete the file when I booted into safe mode command prompt. Even safe mode didn't seem to work though. I also tried one of my Linux rescue discs to try and remove the file. The CD I have allows you to mount and edit an NTFS file system without booting the OS. It should have worked, right? Not this time! When I rebooted the file reappeared. There must be some other hidden file that is causing this exe and process to spawn.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running a couple other online scanning tools:

    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan

    If these scans detect anything, tell me what they say, what file and where it is located.

    Also download this: Generic Detection Tool - NT/2000/XP

    Extract all the files from the Generic Detection Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment.
     
  6. jtpiano

    jtpiano Private E-2

    I had already tried the Bitdefender online scan before my last post and it came up clean. I hope you'll pardon me because I skipped ahead a little. I didn't do the other two scans. (I was able to do the initial online scans using DSL where I work after hours. I now have the computer at home and only have dial up). I also had a strong suspicion I had some type of Vx2. Your last post seemed to confirm that for me. I used Pocket Killbox, Dll Compare, and Vx2 Finder as well as Find It to get rid of a lot of junk. I think??? I have it clean now. Posted below is the log you asked for. If you do confirm all is clean, why does the registry entry under HKLM run still show the offending exe file? Maybe it's not clean just yet... I have a fair amount of experience with malware, just not very much with the Vx2 variant.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not jump ahead. Just follow the steps I'm giving you! I'm hoping these next two will remove that last exe file.

    Download L2MeFix Tool

    Print or save these instructions locally now because you will have to be disconnected with no browsers open in the next step.

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.


    First Step:
    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log. Save this log to log1.txt

    Second Step:

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Save this log to log2.txt

    Third Step:

    Reboot your PC and reconnect your internet connection. Get a new HijackThis log.

    Come back here and post both logs from running L2MFix and the new HJT log.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure these scans are going to fix this.

    Tell me something! If you use Windows Explorer to look for C:\WINDOWS\System32\ikpipz.exe do you actually find it. If so, then use either Task Manager or the Process Manager in HijackThis and kill the following process:
    C:\WINDOWS\system32\ikpipz.exe

    Are you able to kill it without it coming back right away? Just keep watching the Process list for awhile.
     
  9. jtpiano

    jtpiano Private E-2

    The logs you requested
     

    Attached Files:

  10. jtpiano

    jtpiano Private E-2

    Here's the HJT log
     

    Attached Files:

  11. jtpiano

    jtpiano Private E-2

    I can not "see" this file using explorer. I can only get to it from the command prompt. (see previous posts). The process is not listed in HJT under the misc tools.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That fix a few stray problems from VX2 issues but not this bad exe file. Did you see message number 8?

    Okay! I see your answer...hang on a second.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please check again right now. Notice that it shows in your HJT log. If it shows in your log and not in the process list that would be unusual.
     
  14. jtpiano

    jtpiano Private E-2

    run HJT again?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't want a log! I want you to look in HJT's process manager to see if the file is listed there. In this particular instance it is okay if you leave Internet Explorer running while you do this.
     
  16. jtpiano

    jtpiano Private E-2

    OK, ran HJT again and looked in Misc section the file is back.
     
  17. jtpiano

    jtpiano Private E-2

    Excuse me, I meant the process came back
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay close all browsers and kill the process using HJT. Then run the steps below.

    At the command prompt if you goto the c:\windows\system32 folder and enter the following commands tell me what happens:

    cacls C:\WINDOWS\System32\ikpipz.exe /g Everyone:f
    <-- answer yes to any prompts for the above command
    cd C:\WINDOWS\System32
    attrib -r -h -s ikpipz.exe
    del ikpipz.exe

    dir /AH *.exe > ikpipz.exe
    cacls ikpipz.exe /g Administrator:f
    <-- answer yes to any prompts for the above command
    attrib +r +h +s ikpipz.exe

    exit

    Tell me if all those command executed without any error messages. If not, tell me the errors.
     
  19. jtpiano

    jtpiano Private E-2

    Here's the results
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you able to end the process with HJT before starting that procedure?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hello! Are you still here? Also can you see that file using Windows Task Manager?
     
  22. jtpiano

    jtpiano Private E-2

    Yes, I was able to end the process first. I'll check again tonight to see if it is in the process list in task manager.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try a differnent tool to manage processes and maybe another tool too. Download the below:

    - ProcessExplorer for Win NT/2K/XP
    - Filemon for WinNT/2K/XP
    - Regmon for WinNT/2K/XP

    1) run ProcessExplorer -
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".

    Now click on C:\WINDOWS\System32\ikpipz.exe. Now click on File and then Save As. And save the process list. Post it back here as an attachment.

    Use ProcessExplorer to observe what processes are running and to kill them rather than Task Manager or HijackThis's process manager. Also watch it to see if we can determine if any other processes run to restart the C:\WINDOWS\System32\ikpipz.exe process.

    2) run filemon -
    When it comes up, change the *.* in the Include box to say ikpipz.exe. Then click Apply and OK. The Filemon window now comes up and will monitor for anything accessing ikpipz.exe. After you use Process Explorer to kill the process, see if anything runs to to restart it. Also when trying to access ikpipz.exe from the command line, what else references this file. You can come back to the Filemon screen and click File and then uncheck the Capture Events selection to stop the capture process. Then use File, Save As to save the log to a file like filemon.log and post it back here as an
    attachment.

    3) run regmon - When it comes up, click the icon that sort of looks like a diamond with some blue color on top. This is the Regmon filter. In this filter, enter the following:
    ikpipz.exe

    Then click Apply and then OK. It will ask if you want to apply the filter to the current output. Say yes.

    After you use HJT to fix the O4 line with this file on it, regmon will show the activity. It should also show if anything else is putting the entry back into the registry. So come back to the Regmon screen and click File and then uncheck the Capture Events selection to stop the capture process. Then use File, Save As to save the log to a file like regmon.log and post it back here as an attachment.


    These attachments could get very long sometimes. If they do, you may need to put them into a ZIP file to upload them.
     
    Last edited: Mar 29, 2005
  24. jtpiano

    jtpiano Private E-2

    I was able to check for the process running in task manager, it did not show up there. I will download the files you listed toninght and start working on the task list you gave me tomorrow after work.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That is typically of TaskManager. Quite often it does not show all processes that are running and even when it does, it does a lousy job of ending some of them.

    ProcessExplorer is very good and has some nice additional features.
     
  26. jtpiano

    jtpiano Private E-2

    Here's the new logs you wanted. I ran process explorer and then killed the process. It did not come back until I tried to fix it using HJT in step #3. I didn't see any other process start the bad process. I ran filemon. The bad process was already killed so nothing tried to restart it. (until using HJT in step #3). I'll add the other log in a seperate post.
     

    Attached Files:

  27. jtpiano

    jtpiano Private E-2

    Here's the third needed log.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can locate the following file: srisiyb.dll
    It may be in c:\windows or c:\windows\system32

    Right click on it and select Properties and then the Version tab. See what info you can get on it.

    Try the following:
    - kill the ikpipz.exe process using process explorer
    - fix the O4 line in HJT
    - rename that srisiyb.dll file to srisiyb.ddd
    - delete c:\windows\system32\ikpipz.exe
    - delete C:\WINDOWS\Prefetch\IKPIPZ.EXE-145336BD.pf
    - delete C:\WINDOWS\system32\ikpipz.exe.Manifest if found




    Then reboot and post a new log. If you have problems doin the above, repeat the steps in safe mode.

    Also does the below file exist:
    C:\WINDOWS\MZOMO.DLL

    Get properties info on it too. What is the File date?

    Also does the below file exist:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rikr.exe
     
    Last edited: Mar 31, 2005
  29. jtpiano

    jtpiano Private E-2

    I am unable to get any information on the srisiyb.dll file. The only info given is the modified and created date. All dates are within the last week (when I started working on the system) I was able to rename the file to a ddd extension. When trying to rename the file back to dll I am unable to do so because a file already exists by that name. I was able to do these steps in order (already in safe mode from the start)

    Try the following:
    - kill the ikpipz.exe process using process explorer
    - fix the O4 line in HJT
    - rename that srisiyb.dll file to srisiyb.ddd - delete
    all done no problem

    - delete c:\windows\system32\ikpipz.exe
    I still could not "see" the file ikpipz.exe in explorer I can only delete from command prompt (even in safe mode)

    -delete C:\WINDOWS\Prefetch\IKPIPZ.EXE-145336BD.pf
    I deleted with no problem

    There was no manifest file found

    Also does the below file exist:
    C:\WINDOWS\MZOMO.DLL
    yes

    Get properties info on it too. What is the File date?
    I couldn't get properties. It was hidden except from command line. The date is today.

    Also does the below file exist:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rikr.exe
    Yes, you can only get to it from the command line.

    So you want another filemon, regmon and process log?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot into save mode and kill the ikpipz.exe & rikr.exe processese if running:
    Fix the O4 line in HJT (and any line that mentions rikr.exe)

    Open command prompt windows and do the below:
    delete C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rikr.exe
    if you cannot delete rikr.exe, try renaming it to rikr.xxx
    delete C:\WINDOWS\Prefetch\IKPIPZ.EXE-145336BD.pf
    Rename C:\WINDOWS\MZOMO.DLL to MZOMO.DDD
    Rename that srisiyb.dll file to srisiyb.ddd
    Delete c:\windows\system32\ikpipz.exe

    Reboot and then post a new HJT log and tell me the results of the above steps.
     
  31. jtpiano

    jtpiano Private E-2

    I followed all directions and it looks like my log is clean! :) I don't see the process in HJT anymore.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kool! But please reboot one more time and open and close some browsers to double check.
     
  33. jtpiano

    jtpiano Private E-2

    Ok, I celebrated too early. I also noticed before reboot that I could get to the srs.dll file at the command prompt. :( After the reboot the process is back. I am going to work on this tomorrow. Gotta be into work at 7AM!
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To quote some steps from my friend PhilliePhan, run the below.

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFILES Tool.Zip Tool to its own folder - C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.


    Now also post a new HJT log.
    This will require two message to post the three attachments.
     
    Last edited: Apr 1, 2005
  35. jtpiano

    jtpiano Private E-2

    The logs you requested. I shut the PC off after getting them.
     

    Attached Files:

  36. jtpiano

    jtpiano Private E-2

    and the HJT log.
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Pocket Killbox and save it to its own folder where you can find it.

    Read thru the below steps and make sure you understand them before starting. Ask questions if you have any before starting.

    Run Killbox by double clicking on the killbox.exe file.

    Check the following boxes:

    Standard File Kill
    End Explorer Shell While Killing file

    Copy & paste (you must use copy & paste - typing will give an error) the full path of each of the files below (one at a time - see directions after the list) into the Full Path of File to Delete box.
    C:\WINDOWS\SYSTEM32\EGAUTH.dll
    C:\WINDOWS\SYSTEM32\p2esocks_1026.dll
    C:\WINDOWS\SYSTEM32\dukdk.dll
    C:\WINDOWS\SYSTEM32\winup2date.dll
    C:\WINDOWS\SYSTEM32\wkawa.dat
    C:\WINDOWS\SYSTEM32\wmconfig.cpl
    C:\WINDOWS\System32\SRISIYB.DLL
    C:\WINDOWS\System32\DMNDNAQ.EXE
    C:\WINDOWS\icont.exe
    C:\WINDOWS\UNADBEH.EXE
    C:\WINDOWS\SYSTEM32\ikpipz.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rikr.exe

    With the full path to the file name in the Full Path of File to Delete textbox. The filename will appear under the box in a blue color to indicate it was found. Now Click the Red X and for the confirmation message that will appear, you will need to click Yes. If the file is successfully delete you will get a message of confirmation. Just click OK!
    Do this for each of the files listed. Some will not be deleted. Make sure you keep a list of them.

    Now for any files not delete properly above (the ones you wrote down), do the below (if all of them deleted, skip these steps):
    - in Killbox select the option to Delete on Reboot
    - uncheck the option to End Explorer Shell While Killing file

    Copy & paste the full path of each of the files you could not delete above into the box and then click the Red X and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? You will need to click No (since you are not finished adding all related files in yet).

    When you do enter the last file name that needs to be deleted, click Yes on the last file.
    Note: Killbox will let you know if the file does not exist.

    Okay so now your PC should be reboot.

    After the reboot run nothing else but HijackThis and select and Fix the below:
    O2 - BHO: (no name) - {E1350B8F-4B65-DEC1-0898-E24ACCBECEB5} - (no file)
    O2 - BHO: (no name) - {F48312F2-C1ED-120D-8550-B91A6EF46E60} - (no file)
    O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\ikpipz.exe
    O4 - Global Startup: rikr.exe

    Now reboot your PC one more time and post a new HijackThis log.
     
  38. jtpiano

    jtpiano Private E-2

    Now it looks like log is clean after reboot twice. I can only guess I missed a file earlier when using pocket killbox from post #6. The procedure I used came right from the Lavasoft website. I also wonder, is the Qoologic finder a slightly newer version? I had one previously. The link to the zip you sent had a few more files. Last, if you could give me some good links so I can learn how to use these tools better. All I've gotten is follow the directions as written. I've been doing IT work for the last 2 years and am a quick study. I do well removing most spyware except Qoologic or VX2. That is one area I would like to get better at. Oh, and here's the clean log. :D THANKS for all your help!!!
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All I can say is you will have to search and read!

    Your log is clean (other than the two BHOs - but this happens a lot and the files are gone anyway), but running your system the way you have it right now is dangerous. You have no spyware blocking tools and even worse no firewall. Well okay you now have the one from WinXP SP2 since you upgraded, but it is not good enough. You need to follow all the steps in the below thread to help keep you safe:

    How to Protect yourself from malware!
     
  40. jtpiano

    jtpiano Private E-2

    I knew I would need to do some follow up work once the system was in good shape. I've already added some spyware blocking tools before you replied and am working on several other settings and tweaks. I worked on this system not for the money cause I could have wiped out and started fresh much more quickly. I wanted to learn more about spyware. I haven't found too many sites that give good directions about the tools they make available. Just general concepts about spyware/malware brand "x", which I already know. Oh well, I'll get off my soapbox. Thanks again.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because we don't have time to provide them! Especially for free!!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds