Master Chaslang, I need your help again.

Discussion in 'Malware Help (A Specialist Will Reply)' started by griggi63, Jun 8, 2006.

  1. griggi63

    griggi63 Private First Class

    I am trying to repair one of my wife's friends computers. this was in bad shape. I found no antivirus on it. To the best of my ability i have already done the read this first part of advice (except for the online scans because i don't have this pc online.
    Problem 1 that is left now. Kept getting a recurring VISUAL C++ RUNTIME LIBRARY ERROR---C\WINDOWS\SYSTEM32\TYPWPHK.EXE.

    I had installed my norton 2004 and ran it and it only found one baddie. i tried to install the update file from MG after burning it to a cd from my pc, but it would not let upload the file saying it was no signed. I then unistalled norton (also used the removal tool from MG). And then loaded AVG-Free with the updated defs. Found a bunch of baddies and cleaned them all out. except one. It comes up as C:windows\system32\twpR32.dll. And it will not let me delete it , quaranteen it or anything. I tried to do a search for the file and came up empty. Any advice to get rid of this? So far the Visual C++ has stopped popping up.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That file is: http://castlecops.com/o20list-172.html

    Download: HSFix.zip

    Extract the tool from the ZIP File to a folder you can easily find (preferably in its own folder - like C:\HSFix).

    Now please boot to Safe Mode and DoubleClick hsfix.bat to run the tool.

    Allow it as long as it takes to run, then Reboot to Normal Windows and look for a log at C:\hslog.txt . Please attach that log when you come back.

    Now please download & run Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the Blacklight log file here.


    How much of the READ ME have you actually been able to run? See if you can run more now after doing the above. I would like to see the online scans run and then get a HijackThis log.
     
  3. griggi63

    griggi63 Private First Class

    ok, problem number one....after downloading to cd and installing hsfix on the infected pc, it starts to run and stops at number 5 and does nothing more. so i rebooted into normal mode and installed the blbeta. i ran this, it found 177 things and dropped the text on the desktop. i went to send this file to a cd so i could send it too you, but for some reason the cd writing wizard is telling me there is no blank cd in the drive to write to no matter how many times and different cds i use. I'm totally lost at the moment.

    oh yeah, the visual c++ error is intermittent now, but avg is picking up the twpr32.dll error stating "trojan horse backdoor.generic2.rox" cant do anything to this, and now another was popping but i didn't get a good look at it.

    got the 2nd one. C:\windows\system32\twpR64.sys
    trojan horse backdoor generic2.RLI

    #3
    c:\windows\system32\2q.dll
    trojan horse backdoor deneric2.ROX
     
    Last edited: Jun 9, 2006
  4. griggi63

    griggi63 Private First Class

    got part of it to work here is the log.
     

    Attached Files:

  5. griggi63

    griggi63 Private First Class

    right now i am in the middle of installing service pack 2 for xp. some things i wanted to make you aware of. there is no sound and no little speaker in the lower system tray...it has huge icons on the desktop and you cannot change the resolution or screen size. also only has one option for color (16bit). i did manage to get online with dial-up, painfully slow to begin with , but seemed abnormally slower than dial up usually is. I was going to wait until xp sp2 installs, then redo the whole "read and run me first". and go from there. good idea or no?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    VERY BAD IDEA! Installing SP2 while infected can be worse than the malware itself. I realize that you just want to get your PC running, but if you do not follow only our directions and nothing else, it will be impossible to help you. We said nothing about installing SP2.

    Your Blacklight log showed you are still infected with Haxdoor. I have no idea where things will stand now after trying to install SP2 but I would expect that you are going to have problems with the SP2 install and that will not be a topic for this forum.

    Since I don't know your current status anymore, I'm not sure what to tell you to do.

    I would recommend you do the below and attach the log.

    AproposMedia Fix

    Also see if you can delete the below foder in safe mode:

    c:\Program Files\Onlngent
     
    Last edited: Jun 10, 2006
  7. griggi63

    griggi63 Private First Class

    you are absolutely right and i apologize for jumping the gun. when i did get it onto a dial up connection, it was trying to automatically update. I did get sp2 installed, but knocked out a bunch of drivers. had the resource cd and got sound and video drivers reinstalled and have 2 setting of resolution instead of the gigantic one that was there before. again i apologize and will not jump the gun again. i'm am going to do run the program you have just previously mentioned and will post the results and will wait for further help.
     
  8. griggi63

    griggi63 Private First Class

    ok, here are the files. i will do nothing till i hear from you. I do want you to know that for some reason now the visual c++ errors have stopped and avg hasn't popped up with the 3 virus detections like before...not sure why.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because of the AproposFix I had you run. It removed a bunch of problem. See for yourself in the log.

    Did you delete the c:\Program Files\Onlngent folder? (I'm not sure if AproposFix removed it.)

    Now rerun Blacklight as a double check.
     
  10. griggi63

    griggi63 Private First Class

    i could not locate that folder anywhere. am running the blb now.
     
  11. griggi63

    griggi63 Private First Class

    ok, here is the log.
     

    Attached Files:

  12. griggi63

    griggi63 Private First Class

    ok, things seems to be running ok, was getting ready to put it back on the net. I found the orginal dell cd that came with the pc to install norton2003, i was going to take the avg off, and put this back on. needed to know if there was anything else for me to do first. The avg resident shield popped up again while i was just leaving the pc run, but i couldnt get to it fast enough to see what the the virus that it had detected said other than something like c\window\system\volume...something or other. I popped open avg and opened the resident shield, and it is set for scanning all files instead of just "infectible files". Do you think it would be ok to uninstall the avg and put back on the norton that came with the pc? or do you think it better to leave it avg?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would not reinstall an Norton 2003. It is out of date and a resource hod anyway. Do you actually have a paid license that still allows you to get updates for it.

    At anyrate we were not done! Your final steps are below:

    It is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  14. griggi63

    griggi63 Private First Class

    Ok, as per your instructions, i have not reinstalled the norton because i do not know if the owner has the subscription update and will leave it with avg.

    I have created a new clean restore point.

    When going through the (how to protect yourself from malware)...i downloaded "zonealarm" to a disc to install on that pc. When i went to the control panel of the pc to turn off the window firewall in the security center, the security center window opened displaying this...

    SECURITY ESSENTIALS
    The Security Senter is currently unavailable because the "Security Center" service has not started or was stopped. Please close this window, restart the computer (or start the "Security Center" service), and then open the Security Center again.

    restarted the pc and got the same message.

    on the 3 icons that appear below, i can open the automatic updates, the internet options...but when trying to open the window firewall it states (due to an unidentified problem , windows cannot display windows firewall settings.)

    I have not yet installed the zonealarm firewall, waiting for your instructions.
     
  15. griggi63

    griggi63 Private First Class

    ok, the owner is on their way to pick up this pc, anything else should do? i am about to install zone alarm even with the security problem.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just install ZoneAlarm. It will be your firewall! You do not want or need the Windows firewall. ZoneAlarm would more than likely have disabled your Windows firewall during the install anyway.
     
  17. griggi63

    griggi63 Private First Class

    i tried, but it does not work. i tried to uninstall it to see if so i could reinstall it, but now it gives me an error that it cannot find some file. i tried to manually through ad/remove programs, had problems there to. did an explore to find anything zone alarm and trying to get rid of it manually, didn't help.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you still have some malware problems! Attach a new HJT log and let's see.
     
  19. griggi63

    griggi63 Private First Class

    i am actually using the pc i am trying to fix, i have it on a dial up connection. here is the log
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay looks like there is a Qoologic infection and some items from Haxdoor are still present.

    Download FindQool by LonnyRJones
    • Extract the files and place the FindQool folder into root folder of your hard disk. This is usually C:\
    • Open the folder and run Qlocate.bat
    • attach the contents of the txt.log which will open when the scan is finished.
    FindQool is not a removal procedure. It is a scan that helps us to locate hidden files and registry keys so we can work up a fix for the Qoologic infection.
     
  21. griggi63

    griggi63 Private First Class

    ok, here is the log. I'm really sorry for all this trouble, i thought i did it right, but that xpsp2 screw up .
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    FindQool did not run because you have another problem with your OS installation.

    Run one of the below (choose the one that is correct for your OS):

    For Windows XP Pro: download and run XPproFix
    For Windows XP Home: download and run XPHomeFix

    Now run the FindQool steps again and attach a new log from it.
     
  23. griggi63

    griggi63 Private First Class

    ok, got the xphomefix and unzipped it. I tried to burn the results to a cd, but i'm getting that error from the cd-writing wizard saying either there is something wrong with the cd, or no cd in the drive no matter which cd i use. so i tried to get online, i got the connection, but it would not let me access a webpage, kept saying server not found.

    So here are the results, i hope i dont make any mistakes typing this.

    Report.txt notepad

    Mon 06/12/2006
    Running from: c:\findqool\FindQool
    Please note: legit filess might be listed. if you are unsure of what is listed leave them alone

    known file names

    MD5 check....

    files found with locate com.
    re-check using dir /a:-d
    d:\documents and settings\all users\start menu\programs\startup
    ...

    HKEY_Local machine\software\classes\folder\shellex\columnhandlers\{ce3q44d8-bc88-4d62-a890-42d9625f8d6}

    ...
    runs, listed here as doublecheck for locate com results
    HKLM
    HKCU
    ...

    files in winlogo shell and userinit
    listed here as doublecheck for locate com results
    shell REG_SZ explorer.exe, c:\windows\system32\klyph.exe
    suereinit REG_SZ c:\windows\system32\userinit.exe, vggtrni.exe

    ...
    SWReg utility...
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\System32\klyph.exe
    C:\WINDOWS\SYSTEM32\vggtrni.exe
    C:\WINDOWS\SYSTEM32\twpR32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\klyph.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,vggtrni.exe
    O20 - Winlogon Notify: twpR32 - C:\WINDOWS\SYSTEM32\twpR32.dll

    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):
    C:\WINDOWS\System32\klyph.exe
    C:\WINDOWS\SYSTEM32\vggtrni.exe
    C:\WINDOWS\SYSTEM32\twpR32.dll

    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log

    Also tell me how things are working!
     
  25. griggi63

    griggi63 Private First Class

    here are the 2 logs. i still cant get a webpage to open, just get the "the page cannot be displayed" warning no matter which website i try to go to.

    when i right click to send a file to somewhere, for some reason it is coming up with 2 cd drives with the same letter one says "direct cd drive (D)"and the other says "cd-rw drive (D)"

    It wont let me burn anything to a cd, no matter which of the 2 i pick.

    Still cant get into the windows firewall to see if it is on or off. and cant install or uninstall zonealarm.

    But at least it is running a lot faster than before.

    waiting for your next instructions....or do i shoot it?
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may all be a loosing cause. The upgrade to SP2 may have cause all kinds of problems that cannot be addressed in this forum.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to TrueVector Internet Monitor ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    vsmon

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.

    After reboot delete the below:
    C:\WINDOWS\system32\ZoneLabs <--- the whole folder
    C:\Program Files\ZoneLabs <--- the whole folder or C:\Program Files\Zone Labs

    Now try to install the below firewall:
    Outpost Firewall Free
     
  27. griggi63

    griggi63 Private First Class

    k, before i go any further, when i went to services.msc and found the TRUEVECTOR INTERNET MONITOR...and right clicked properties...the process is already stopped. should i hit start, and see if i can connect to a webpage before doing anything else?
     
  28. griggi63

    griggi63 Private First Class

    ignore that...last statement. when i change the startup type to disabled and try to hit ok, or apply, it says access denied, i think the only way out of that window is to hit cancel. do you still want me to do the rest?


    and actually i'm not real sure that the sp2 has anything to do with it, i have had it online after that whole melee occured and the cd-rw was writing yesterday.
     
  29. griggi63

    griggi63 Private First Class

    i cant seem to get this zonealarm out. everything i do is "access denie" or is being used by another program.
     
  30. griggi63

    griggi63 Private First Class

    ok, just wanted to let you know, i got the truevector to stop. i had to do it in safemode then took out the vsmon (think i did that in safemode too). still a bunch of ZoneAlarm files on there that it wont let me take out. their website was totally no help at all. while trying to take a lot of them out, i kept getting a message that the files were in use possibly by another user? that confuses me a bit. Well the internet is up and functional. not sure about outlook express, not sure if it was set up before i got the pc, there was so much damage when it was brought to me that there were no programs responding too well, and never checked the outlook. I still cant seem to get the cd-rw to write. it reads fine, it just wont write. i went into the device manager and uninstalled it, and reboot to have it pick it up again, hoping maybe it was just a driver issue that would resolve itself. but same thing. like i said before, if i right click on a file to "send to" a location. the option brings me up 2 (D) drives....one says cd direct drive, and the other cd-rw drive. weird huh. might try taking a cd-rw out of one of my other pc's just to see if it will write. ( well i guess i shouldn't say it wont write, it tells me that the cd i'm using is no good, or full, or something to that effect. I'm a Little nervous about installing that other firewall...do you think i should still try it?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of your remaining issues are topics for this forum. You will have to discuss them in the Software Forum.

    You need a firewall or you are extremely susceptible to new infections. You need to complete ALL steps in the below since you also have no antispyware blocking tools installed.

    How to Protect yourself from malware!
     
  32. griggi63

    griggi63 Private First Class

    Just wanted to let you know how things are.

    !. i tried to install the other firewall, gave me a huge warning not continue with the installation because ZA was installed and could create serious conflicts and possibly cause the pc not to even be able to boot. I took this warning seriously and decided not to do it as yet.

    2. i uninstalled xp sp2 and all is fine with the cd-rw now. the drivers stayed so there was nothing i had to reload ( that kind of shocked me)

    3. back to the firewall problem. did some research on the web of how to get rid of the zonealarm. had to go into the registry and delete the vsdatant folder ...i have the specific location at home, can post it if you need it. anyway, after i removed that folder, i was able to delete all the zone alarm files except for vsmon.exe. But it was still enough to install the other firewall.

    So with that all problems are fixed wanted to thank you for all your help and patience. I have one recurring warning from the firewall about a "dedicated.hideout.net" from the svchost and what to do with it. when i blocked it the first time, after that it would not let me load a webpage, it would keep saying "this page cannot be displayed". so i went back into the controll panel of the firewall and removed it from the blocked list and i could access webpages again. i went to windows update to get all the updates for the xp that is running on that machine , and while it was downloading , the window popped up again asking me what to do with "dedicated.hideout.net". I didn't do anything, i just let the window stay there while the update was running. do you have any idea what that is or how to stop it if it is dangerous?
     
  33. griggi63

    griggi63 Private First Class

    correction dedicated.thehideout.net
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It sounds like something you are connecting to. If you block it and then cannot connect, then you are the one going there. What website are you actually going to when you run into a problem?
     
  35. griggi63

    griggi63 Private First Class

    that is the weird part. the first time, i had just opened IE and the homepage is set to YAHOO. after a minute or so, the firewall window opened up and asked about "dedicated.thehideout.net" and what i wanted to do with it. i had it block it because i didn't know what it was. then when i went to go from Yahoo to MG , it came up with the "page not found" screen and i looked down and the little monitors that indicate internet activity were not blinking anymore. i still had connection, but nothing could come or go. i actually rebooted to see if maybe something just fouled up for a second. the connection went through, but still could not access a webpage. I opened up the firewall and looked to see what was blocked. it didn't say "dedicated.thehideout.net" it said svchost was blocked. so i removed that from the list and proceeded to open up a webpage and it opened fine.

    Later when i was on windowsupdate, it did it again, only i just let the window hang there until i was finished letting windows do its thing.

    Then just a little bit ago, i was back on windowsupdate, finishing up the rest of the downloads (there were 48 critical that the system needed-or so it said) and a window popped up with an IP address this time, well i let it hang there until windows update was done, and rebooted. it wouldn't let me on the webpage again, i opened the firewall, and sure enough, svchost was on the block list again. not sure what is going on....oh yeah, i tracked the IP address and came back as "Sandy.thehidout.net" located somewhere in washington state, or lower alaska, it couldn't pinpoint it.

    any clues?

    Is it possible, i have the firewall settings wrong? i left at the default settings so far.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    svchost is a valid process and requires internet access.

    What IP address was in the window? I don't see any match for Sandy.thehideout.net but I did see the below for the other you mentioned. Does Hurricane Electric mean anything to you?


    Let's get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
    Last edited: Jun 15, 2006
  37. griggi63

    griggi63 Private First Class

    hurrican electric means nothing, have never seen anything like that on the pc. i don't have the ip address anymore.


    i ran all the windows updates, installed spyware blaster as the spy catcher. and rebooted. did some surfing to see what would happen and i did not receive anything from the firewall after that.

    I had the girl come get her pc lastnight before i received your latest message. if needed i can go and get the info you need if you think that it is necessary. I gave her a quick rundown on the programs installed for security, and gave her the info to your website. and told her to quit downloading junk ( she is a big bearshare, and limewire fan).

    Like i said, if you think it's necessary, i can get the info that you request if you do not feel the system is completely clean.

    let me know.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not necessary as long as everything is running properly.
     
  39. griggi63

    griggi63 Private First Class

    well, not totally properly, seems to be some kind of glitch with the outpost, seems after you have been on the web and shut down the pc, the nesxt time you restart the pc and go to surf, you cannot get on a webpage. have to open up the firewall and remove the svchost from the blocked applications list. any clue as to why this would happen? other than having to go in and unblock it, it seems to be running fine.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds to me like you are not configuring the firewall properly to always allow svchost.exe to have access. This is not a malware problem but rather a user configuration issue.
     
  41. griggi63

    griggi63 Private First Class

    i kind of figured it was me. will get it taken care of. As always, you guys are the greatest. Thank you for your time, patience , and may god bless you everyday.

    Sincerely, a greatful follower of MG

    Gino


    PS. i gave her explicit instructions to visit the forums...especially the malware, and if she has any problems to come to you. Have great day, and a wonderful life.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Gino! And I wish the same for you!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds