Need next steps!

Discussion in 'Malware Help (A Specialist Will Reply)' started by scrub, Jul 25, 2005.

  1. scrub

    scrub Private E-2

    Hi everyone, I got hit with a nasty trojan (I think) last night. Basically, it seemed like IE blocked a pop-up and then the browser windows (2) just closed and I got a Windows Explorer error dialog box asking if I wanted to send the report to Microsoft. At first I didn't think anything of it but then every time I clicked send or don't send it seemed Windows Explorer would restart and I'd get the error anew. After restarts nothing happened until suddenly I got a bunch of pop-ups (which cleared up the Windows Explorer errors) and the desktop told me I had spyware and possible viruses so I knew that I'd been hit with something nasty.

    This morning I got up and purchased TM PC-Cillan and installed it. It seemed to detect nothing in particular which was disappointing since my desktop was still trying to sell me stuff. In desparation I went and bought a copy off the pctools.com website of Spyware Doctor and it found 150+ infections -- I cleaned them and everything seemed hunky dory. After a reboot, the annoying red exclamation mark that was appearing (from PSGuard I assume) came back. I posted on the PCTools site asking how to get rid of this and then all hell broke loose again.

    Now the Windows Explorer crashes were back and I was getting more infections. PC-Cillin's firewall was up (Windows was not -- I'm running WinXP Pro w/ SP2 fully updated) and Spyware Doctor's immunization and guard programs were running so I cannot explain what happened.

    I happened upon Major Geeks in the middle of all this and tried the suggestions on the stickied post on how to deal with malware and spyware. I ran everything as described in the list that I could, rather, that my computer which was crashing hard (BSODs) intermittently would allow me to. I am not sure how I got to this point... SpybotSD runs on reboots now and can only find "logs" which it sometimes can or can't remove. I've run everything else in that stickied post backwards and forwards inbetween reboots from crashes and nothing is fixing the problem. I know that the problem is not hardware related necessarily as the little red exclamation mark from PSguard still perks up on startup everytime.

    So my situation is this:

    1. Running WinXP Pro, SP2
    2. Computer starts up with Explorer crashing and asking to send an error report to Microsoft. I say yes or no it makes no difference, Explorer restarts and crashes again immediately.
    3. Occasionally Explorer crashes and Dr Watson shows up and that's the end, no more interaction with the OS and I have to reset.
    4. Occasionally I get hard BSODs. The error messages vary, kernal_inpage_stack_errors to something like "unknown_hard_error".
    5. These crashes are preventing the longer scans by BitDefender et al. from totally completing. However, BitDefender and the like do catch infections and weird files from C: before they go kaput with the computer.
    6. I have not run HijackThis as you guys asked me not to.
    7. Safe Mode doesn't really help, the Explorer crashes persist.
    8. Microsoft's automate error reply says its a trojan and the Malicious Tool comes up empty handed.

    My suspicions and observations:

    1. Am I in a unique position of being the first to experience a new improved trojan or other malware? I doubt this but who knows.
    2. Not 100% positive that the Explorer crashes are related to the malware but the behavior is linked to their first appearance and they persist.
    3. Each time a utility scanned and found infections they were different. At first it was Puper, then Dropper.Joiner, then Downloader, then Smitfraud-C. etc. Now, nothing shows up on scans, PC-Cillin, Spyware Doctor, SpybotSD (only finds logs after reboot), AdAware SE (nothing), etc.

    Like most people I need that computer running and I am going to attempt removal of critical data (burning to CD) tomorrow morning after getting some sleep. I would appreciate any help. I foresee a HijackThis suggestion coming but that will have to wait til morning. Last question, assuming I successfully migrate the critical data off the machine will a Windows reinstall fix things? Yes, it's come to that... though with my luck it probably wouldn't do anything other than waste my time.

    Wow, this is long but so was my day... Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm assuming you ran all of the READ ME FIRST. Is that correct?

    If so, follow the steps below:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. scrub

    scrub Private E-2

    Hi, thanks for the quick response. Here's the log file.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the xfire_lsp_8742.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move xfire_lsp_8742.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    Now look in Add/Remove Program for PSGuard and uninstall if found.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\intell32.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [RegSvr32] C:\WINDOWS\system32\msmsgs.exe
    O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\system32\intell32.exe
    O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
    O20 - Winlogon Notify: style2 - C:\WINDOWS\q1667187_disk.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\PSGuard <--- the whole folder
    C:\WINDOWS\system32\intell32.exe
    C:\windows\system32\intell32.exe
    C:\windows\system32\oleext.dll
    C:\windows\system32\oleext32.dll
    C:\windows\system32\wppp.html
    C:\windows\uninstIU.exe
    C:\WINDOWS\q1667187_disk.dll <--- this one can be problems sometimes. If you cannot remove it or it comes back after reboot. Rename the file to q1667187_disk.ddd and use Windows Explorer and right click on it an drag to your Desktop and select Move. Then reboot and delete the file on your Desktop.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Jul 26, 2005
  5. scrub

    scrub Private E-2

    Ok, followed the steps you posted to the best of my ability. Here are the notes...

    Done, no problems.

    Did not find this program in the Add/Remove Menu. Went to next step.

    No problem, done.

    Done, no problem.

    Did not find. Rechecked hidden files and such, no luck. Went to other files next.

    Not sure why you posted WINDOWS and windows directories but intell32 was wiped, oleext.dll had to be removed using the method for q1667187. oleext32.dll, wppp.html, uninstIU.exe were not found so I skipped. Again, I double checked that hidden files and extensions and such were all visible. No go.

    Done.

    Here it is attached...

    By the way, THANKS!!!! :D
     

    Attached Files:

  6. scrub

    scrub Private E-2

    Meant to add that the crashing of Explorer disappeared sometime after rebooting in Safe Mode and deleting some of those dll/exe files. MUCH MUCH easier to get things done now.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have HJT fix the below line:


    O20 - Winlogon Notify: style2 - C:\WINDOWS\q1667187_disk.dll (file missing)


    Then reboot your system and then get a new HJT log and tell me if that O20 line is gone.

    How are things running? Any problems?
     
  8. scrub

    scrub Private E-2

    Ok, deleted that one line. HJT log attached.

    Everything has been running super great since yesterday after doing all that stuff. I've just been a bit gunshy about doing too much on the Internet though. I'm still not sure how I acquired that lovely trojan malware. I never installed or loaded any program from any site. Is it possible just to get this crap from visiting a site? Or was I "hacked"?

    Anyways, my wife and I want to thank you chaslong (and majorgeeks.com) for all the assistance. You rock! :)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can get stuff from jsut visiting sites too. You log is clean now but I have a question about the below line. Do you use software from Stardock and are you having any problems with it?


    O20 - Winlogon Notify: MCPClient - C:\Program Files\Common Files\Stardock\mcpstub.dll (file missing)


    You should follow any steps in the below thread that you have not already done the equivalent of:

    How to Protect yourself from malware!
     
  10. scrub

    scrub Private E-2


    I have Stardock software installed but have never had problems with it. It's Stardock Central and I used it primarily to get access to all the games they were distributing. Do you think it is safe to remove the entry with HJT?

    As for the steps in the "Protect yourself from malware!" link my wife and I had done virtually all of those things before we were victimized the other night.

    If I haven't already made it clear -- thanks very very much.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome!

    Well HJT seems to think the mcpstub.dll file is missing? You should check for yourself. It is not necessary to fix the line but it is possible that if that file is missing, something you may need sooner or later may not work.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds