Malware problems: ljighig.dll, mediamotor, vundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by rain19c, Sep 19, 2006.

  1. rain19c

    rain19c Private E-2

    I was having some malware problems, and read through the Majorgeeks "read & run me first" thread and it was very helpful. It solved many of my problems, but some other things remained. I run Windows XP, SP1.

    Some notes I took:

    *I could not get Counterspy to work, if would always freeze when opening, whether in safe or normal boot mode.
    *I ran into a lot of problem with the online scanning, both IE and mozilla froze in sfae mode, and the first time I ran bitdefender in normal mode, services.exe was using up all my CPU and I couldnt save the scan. I was able to save it the 2nd time, and I believe it picked up the malware from the first scan in the System Restore files.
    *Pandascan was a similiar problem, it would detect 2 problems and then would not let me export the scan, the computer just froze. The Panda scan I attached is one I stopped after it detected the 2 problems.
    *I tried to use Vundofix, but it didn't find anything. Maybe I did something wrong?

    My current problems:

    *on startup, i get the message: "windows cannot find c:\program files\common files\microsoft shared\web folders\ibm00013.exe"

    *I constantly get the internet explore message even when my dsl is not connected: "work offline - no connection to the internet is currently available - trying to connect." I am guessing this is vundo's doing?

    *on shutting down, I ocassionally get a quick runtime error or initialization error that I'm not able to read in time.

    *internet connection is twice as slow as usual

    *after restarting from freezes, chkdsk will occasionally run and delete index entries.

    *Services.exe (or something else?) will often eat all my CPU, according to task manager.

    I would definitely appreciate any help. This is a very informative and helpful site!
     

    Attached Files:

  2. rain19c

    rain19c Private E-2

    Don't know if you need these other scans yet, but here they are.
     

    Attached Files:

  3. rain19c

    rain19c Private E-2

    Can anyone here help me out or give me some sort of advice on what to do? I am feeling lost here.

    I still have the Hijackthis results open after running the scan last night, I didn't know if I should close it.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have not had a chance to look thru all of your logs yet but I did want to give you an important heads up:

    The file is probably no longer present and that is why you get the message about it at startup; however, it was there at one time and the above should really be done for your own financial security. I repeat DO NOT change any passwords by using this PC.

    Now to get ready for the fixes, you must remember to not use MSconfig to control startups. This was requested in step 7 of the READ ME and you HJT and GetRunKey logs show you are using MSconfig. Make sure you remain in Normal Startup mode not Selective Startup mode.
     
    Last edited: Sep 20, 2006
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now let's get started on your malware removal steps. You have a bunch to remove.

    First goto Add/Remove programs and uninstall Enhanced Browser Overlay if found.

    Now continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of jkhhf.dll once and then click the kill button. After you have killed all of the jkhhf.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ljjghig.dll

    Next double click on explorer.exe and again click once on each instance of jkhhf.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ljjghig.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (some of these may no longer be found if the uninstalls above worked):

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00013.exe"
    O2 - BHO: Iconizer - {AA1A4F83-B4AC-4859-8C91-21DBE6C5625B} - C:\WINDOWS\System32\nodeipproc.dll (file missing)
    O2 - BHO: (no name) - {B7672BAF-E9A3-49B6-86B2-C81719A18A4C} - C:\WINDOWS\System32\nhjxjjmf.dll
    O2 - BHO: (no name) - {D4EC7B4D-6497-4E6F-8BEE-A2EF928CBDC9} - C:\WINDOWS\System32\jkhhf.dll
    O2 - BHO: (no name) - {D6EC03D8-438B-4C5C-AC83-1B73C429041A} - C:\WINDOWS\System32\ljjghig.dll
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O15 - Trusted Zone: http://ilx.p3r.net
    O18 - Protocol: advert - {7DC356B2-7366-4F19-BF7A-4875F6AABEA0} - C:\WINDOWS\System32\nodeipproc.dll (file missing)
    O20 - Winlogon Notify: jkhhf - C:\WINDOWS\System32\jkhhf.dll
    O20 - Winlogon Notify: ljjghig - C:\WINDOWS\SYSTEM32\ljjghig.dll
    O21 - SSODL: msvcrt64.dll - {5085AEB5-DAA1-4D28-946E-BC23C97FF537} - msvcrt64.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Program Files\Common Files\{9856991A-0957-1033-0924-020402200001}\Update.exe
    C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00013.exe
    C:\WINDOWS\System32\msvcrt64.dll
    C:\WINDOWS\System32\nodeipproc.dll
    c:\windows\system32\stonedrv.exe
    C:\WINDOWS\pop06ap2.exe
    c:\windows\system32\iexplorer.exe
    C:\WINDOWS\media_motor_bundle.exe
    C:\WINDOWS\system32\adrot-uninst.exe
    C:\WINDOWS\system32\aw3.exe
    C:\WINDOWS\system32\icon_mediamotor.exe
    C:\WINDOWS\system32\tdopicoy.exe
    C:\WINDOWS\system32\ts_mediamotor.exe
    C:\WINDOWS\system32\TheMatrixHasYou.exe
    C:\WINDOWS\system32\uninstIcn.exe
    C:\WINDOWS\system32\jkhhf.dll
    C:\WINDOWS\system32\ljjghig.dll
    C:\WINDOWS\system32\nhjxjjmf.dll
    C:\WINDOWS\system32\nstB5.dll
    C:\WINDOWS\system32\fhhkj.ini
    C:\WINDOWS\system32\fhhkj.ini2
    C:\WINDOWS\system32\inistone.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete it if found:
    C:\Program Files\Common Files\{9856991A-0957-1033-0924-020402200001}

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner.MICHAEL-V6ZQ7A2\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.

    Now download the current versions (yours are old) of ShowNew and GetRunKey from the links in the READ ME and attach new logs from ShowNew and GetRunKey.

    Make sure you tell me how things are working now!
     
  6. rain19c

    rain19c Private E-2

    Thank you so much for your help! Things seems to be working better now. I've attached the new logs. I'm kind of worried about the stolen passwords but I will deal with that on my own.

    A couple of notes:

    *When I originally clicked on the threads tab in Process Explorer, it said that I needed to download "microsoft debugging software" because it did not support this dll. But after I clicked ok, the program worked fine and I disregarded the message.

    *When Pocket Killbox finished after clicking "Delete Selected Temp Files," it came up a text box that said "error 6," but the program worked ok afterwards, so I disregarded it as well.

    *** After reboot locate the below folder and delete it if found:
    C:\Program Files\Common Files\{9856991A-0957-1033-0924-020402200001} -


    I did not find this folder.

    *I noticed there are still entries for stonedrv and ibm00013.exe in the Hijackthis log, but I did not touch them.

    ***Now download the current versions (yours are old) of ShowNew and GetRunKey from the links in the READ ME and attach new logs from ShowNew and GetRunKey.

    These are the threads where I downloaded Getrunkey and Shownew, please let me know if these are not the newest versions:

    Getrunkey: http://forums.majorgeeks.com/showthread.php?t=83087
    Shownew: http://forums.majorgeeks.com/showthread.php?t=95941

    Thanks again for your help! Let me know if I need to do anything else.
     

    Attached Files:

  7. rain19c

    rain19c Private E-2

    Things were doing good but I did just have another freeze. Something took up all my CPU or such again and I could not save anything or connect to the internet. The two messages that came up when I tried to shut down were:

    "There is a serious disk error on ~WRD4084.tmp"

    "Microsoft Visual C++ Runtime Library - Runtime Error - Program : C:\program files\hp\hpcoretech\hpcmpmgr.exe" - this application has requested the runtime to terminate it in an unusual way"

    The HP file has to do with my printer I believe, which is not plugged in at the moment. Maybe I should reinstall the driver for it? Or maybe this is something unrelated. Anyway, thank you for reading.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you remember to click Fix Checked in the below steps.

    Save the below instructions locally on your PC or print them to refer to while offline.
    Disconnect from the internet and close ALL browsers.
    Exit all unnecessary programs (shut down things in your tray).

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (some of these may no longer be found if the uninstalls above worked):

    O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
    O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00013.exe"
    O15 - Trusted Zone: http://*.oink.me.uk

    After clicking Fix, exit HJT.
    Now reboot in safe mode and run Windows Explorer to delete the below if found:
    c:\windows\system32\stonedrv.exe
    C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00013.exe
    C:\WINDOWS\System32\safe.tlb

    Tell me whether these are found or not.

    Now reboot into normal mode.

    Now attach a new HJT log and a new log from GetRunKey and tell me how the steps went.
     
  9. rain19c

    rain19c Private E-2

    Thanks again for your help!

    All the steps worked well.

    In safe mode, the only file I found was:
    C:\WINDOWS\System32\safe.tlb

    I did not find:
    c:\windows\system32\stonedrv.exe
    C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00013.exe

    I've attached the new logs.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where is the below item in your Trusted Zone appearing from:

    O15 - Trusted Zone: http://*.oink.me.uk

    Are you adding this to the TZ? If so, what is it for and is it really required.

    In your first log, you had a different address there:
    O15 - Trusted Zone: http://ilx.p3r.net
     
  11. rain19c

    rain19c Private E-2

    I did manually add those two sites to the trusted zones awhile back, they are mainly just discussion/forum groups. I added them there because I was having trouble loading links or something from them one day. They don't have to remain in the trusted zone.

    Should I clear out the system restore using the on/off toggle? Do you think I am able to updgrade to XP SP 2 now?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As long as your WinXP has a valid license you should be able to.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link (the first step in this link is Windows Update)

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds