My first time here - Have you heard of this?

Discussion in 'Malware Help (A Specialist Will Reply)' started by gcljlamb, May 9, 2005.

  1. gcljlamb

    gcljlamb Private E-2

    First, thanks for your help in advance!

    :eek: I'm in the midst of a deluge of adware attacks. Mostly from "banners", "searchingbooth", "terp17", and I've followed your tutorial to get the computer in a position to "start over." I'm running both AdAware SE and Spybot. In the last few days, the attacks have been continuous with windows opening at a rate of more than one every second. For every one I would close, it opens two or more.

    Today, as one was happening, I opened up processes and discovered a correlation between the number of IE windows opening and a particular process with the title iqiqaa.exe . (I know this is obvious, but) Can you tell me if that particular program is one that could be the source of the problem or is it simply a catalyst that gets everything started and I still need to be looking for others. One thing is certain. The moment I "end process" on that program, the ads stop cold in their tracks.

    Additionally, Terp17 seems to be the most stubborn of all the ones I have seen. Is there a program that recognizes it yet? Spybot and AdAware don't seem to see it to remove it. Also, I do have my HJT log available if you want to see it. Let me know and I'll attach it to my next e-mail. Big-time kudos for the site! Much appreciated!!

    Thank you again,

    George
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run ALL the steps in the READ ME FIRST, follow the steps below.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. gcljlamb

    gcljlamb Private E-2

    Here's my HJT log as an attachment.

    Thank you again,

    George
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you must disable Spybot's Teatimer because it could get in the way of making the fixes we need to do.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    You must remember to exit browsers ( C:\Program Files\Internet Explorer\iexplore.exe ) before running HijackThis. Not doing so can make it difficult to impossible to repair certain problems.

    Do you have any idea what the below two processes are for? The seem questionable to me.
    C:\WINDOWS\GAWTDLL.EXE
    C:\WINDOWS\GAWTENC.EXE


    We need to stop, disable and remove a few bad services. They show in your HijackThis log as:

    O23 - Service: ilaxrjiiaaexw - Unknown owner - C:\WINDOWS\system32\iiaaexw\ilaxrj.exe (file missing)
    O23 - Service: lkdvsngrdeyo - Unknown owner - C:\WINDOWS\system32\sngrdeyo\lkdv.exe (file missing)
    O23 - Service: njbprhmxxfpvsqex - Unknown owner - C:\WINDOWS\system32\xfpvsqex\njbprhmx.exe (file missing)
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
    O23 - Service: syaufgcicm - Unknown owner - C:\WINDOWS\system32\cicm\syaufg.exe (file missing)


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to System Startup Service or SvcProc ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above for the below services:
    ilaxrjiiaaexw
    lkdvsngrdeyo
    njbprhmxxfpvsqex
    syaufgcicm

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    System Startup Service

    If that does not work, try using the short name of the service: SvcProc

    Now repeat the HijackThis step to delete the other NT services:
    ilaxrjiiaaexw
    lkdvsngrdeyo
    njbprhmxxfpvsqex
    syaufgcicm

    Now exit HijackThis and then move on to my next message.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing the steps in my previous message continue with these steps.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system\iqiqaa.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [njbprhmx] C:\WINDOWS\system32\xfpvsqex\njbprhmx.exe
    O4 - HKLM\..\Run: [blgugj] C:\WINDOWS\system32\wycpv\blgugj.exe
    O4 - HKLM\..\Run: [ilaxrj] C:\WINDOWS\system32\iiaaexw\ilaxrj.exe
    O16 - DPF: {C0B285F6-DB2B-4908-9C58-F6D95397D747} - http://www.pacimedia.com/install/pcs_0006.exe
    O23 - Service: ilaxrjiiaaexw - Unknown owner - C:\WINDOWS\system32\iiaaexw\ilaxrj.exe (file missing)
    O23 - Service: lkdvsngrdeyo - Unknown owner - C:\WINDOWS\system32\sngrdeyo\lkdv.exe (file missing)
    O23 - Service: njbprhmxxfpvsqex - Unknown owner - C:\WINDOWS\system32\xfpvsqex\njbprhmx.exe (file missing)
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
    O23 - Service: syaufgcicm - Unknown owner - C:\WINDOWS\system32\cicm\syaufg.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system\iqiqaa.exe
    C:\WINDOWS\svcproc.exe
    C:\WINDOWS\system32\xfpvsqex <-- the whole folder
    C:\WINDOWS\system32\wycpv <-- the whole folder
    C:\WINDOWS\system32\iiaaexw <-- the whole folder
    C:\WINDOWS\system32\sngrdeyo <-- the whole folder
    C:\WINDOWS\system32\cicm <-- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. OC Drew 2658

    OC Drew 2658 Private E-2

    I was wondering if i could get some similar advice as i am having a similar problem. I also preformed all of the read me first steps as indicated and have a log in another thread entitled "help for a computer illiterate" . Thank you in advance
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post requests for help in a thread that is not yours. Just wait for your thread to be answered. This is a very busy forum but we will get to you eventually.
     
  8. gcljlamb

    gcljlamb Private E-2

    chaslang,

    here's the latest HJT log. As I mentioned yesterday, when I deleted the process iqiqaa, I stopped running into the severity of problems I had. Let me know your thoughts on the latest HJT log.

    Thank you again very much, now I can get back to my work!

    George
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your log is clean but I still wonder about what I asked in message # 4:

     
  10. gcljlamb

    gcljlamb Private E-2

    Chaslang,

    I don't recognize them. Properties doesn't yield any help either. I'll see how things transpire and let you know if anything else develops.

    George
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! Do you see anything in Add/Remove programs that you do not recognize?

    How large are those two files? What kind of PC brand do you have?
     
  12. gcljlamb

    gcljlamb Private E-2

    Chaslang,

    In Add/Remove Programs, the only thing I don't recognize is Sentinel System Driver.

    For the other exe's you asked about, this is what I found.

    GAWTDLL.EXE 60K "UpdateMonitor" by Update Monitor

    GAWTENC.EXE 96K SysMon by System Service

    Are these "red flags" to you?


    Incidentally, should I turn System Restore back on? I didn't notice that mentioned it the e-mails you sent me. My thought is it should be safe but I defer to your judgment.

    Thanks again,

    George
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may be okay to enable system restore but I would like to find out more info on these to files. Can you put them into separate ZIP files and then upload them here? Do you know how to do that?

    Is your PC a Gateway PC? Could these be Gateway processes?


    As far as the Sentinel program, does the below look familar.

    http://www.safenet-inc.com/support/tech/sentinel.asp
     
  14. gcljlamb

    gcljlamb Private E-2

    On Sentinel, no that doesn't ring a bell.

    On the computer, it is a custom PC from Microtech, Inc. in Lawrence, KS
    They're a government contractor. Win XP Pro, 3GHz P4 processor, 1GB Ram.

    Seems like to me that with the word monitor in the program description but no reference to the computer monitor that these must be some form of "gentle" or "safe" spyware watching the updates that come across. Is that possible?

    Regarding ZIP files, it's been a while. Could you give me a little "in service" on the right way to do that?

    Thanks,

    George
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have WinZip installed? If not, then download and install it.

    Then all you have to do is run Windows Explorer and right click on the file and select Add to Zip it will create the zip file for you using the name from the file itself.

    Then just repeat for the other file. Then upload both of them as attachments.
     
  16. gcljlamb

    gcljlamb Private E-2

    Chaslang,

    I've attached the two files. Let me know your thoughts.

    Thanks,

    George
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what they are but they do seem strange. Are there anymore files around with the same old creation dates?
     
  18. gcljlamb

    gcljlamb Private E-2

    Chaslang,

    At this point, with the results I've gotten from what you instructed me to do, I'm perfectly happy to leave them alone for now. I guess I would think that if they were anything malicious, they would have been detected (possibly famous last words). Anyway, if you come across anything about them that's bad, let me know.

    Again thank you for all your hard work,

    George
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds