Something's trying to connect to internet.

Discussion in 'Malware Help (A Specialist Will Reply)' started by melee28, Aug 26, 2006.

  1. melee28

    melee28 Private E-2

    Hey all, my laptop is not acting the way I'd like it to at the moment. Some process is trying to start IE without my approval (I typically use FF) and when I shut off the network interfaces, I get the "Work Offline" box popping up every couple of minutes. I can watch IExplore.exe open in the process tab of Task Manager, but I'm not sure what's accessing it. I went through the Sticky instructions and have attached my scan results below.

    Any help would be greatly appreciated.

    Thanks,
    melee28
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install and name HijackThis as requested. You have it here: C:\Program Files\analyse.exe.exe

    Why did you add a second exe extension? Perhaps you did not do step 2 of the READ ME correctly (showing extensions for known file types).

    It should be here in its own folder and named as follows: C:\Program Files\HJT\analyse.exe
    Move it there or put a new copy here and delete the old copy.

    Also you need to attach the GetRunKey and ShowNew logs that were requested in step 6 of the READ ME.
     
  3. melee28

    melee28 Private E-2

    Done and done.

    Here is my new Hjt log (after moving and renaming analyse.exe.exe to analyse.exe) and my runkeys and newfiles logs. (I thought I had uploaded the runkeys and newfiles, but apparently goofed up somewhere.)

    Thanks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please goto Add/Remove programs and uninstall the below:
    Safety Bar

    Also install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_05


    Also a warning note. The below programs are dangerous and both of them often come with bundled malware:
    LimeWire PRO 4.10.5
    SoulSeek 157 test 8


    Now please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winpsa32.dll once and then click the kill button. After you have killed all of the winpsa32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    sstqo.dll
    opnlmji.dll

    Next double click on explorer.exe and again click once on each instance of winpsa32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    sstqo.dll
    opnlmji.dll

    Now just exit Process Explorer.


    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\a6ae70c7.exe
    C:\Program Files\Common Files\{6C40871F-0C80-1033-0910-040405270001}\Update.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5A3E97DD-2A08-48BC-8F43-C0DEABC90266} - C:\WINDOWS\system32\opnlmji.dll
    O2 - BHO: (no name) - {A61D8E57-5394-4B1F-914D-E1E43D664FD0} - C:\WINDOWS\system32\sstqo.dll
    O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\Safety Bar.dll (file missing)
    O4 - HKLM\..\Run: [a6ae70c7.exe] C:\WINDOWS\system32\a6ae70c7.exe
    O4 - HKCU\..\Run: [a6ae70c7.exe] C:\Documents and Settings\w00t!\Local Settings\Application Data\a6ae70c7.exe
    O4 - Global Startup: Commander.lnk.disabled
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O20 - Winlogon Notify: opnlmji - C:\WINDOWS\SYSTEM32\opnlmji.dll
    O20 - Winlogon Notify: sstqo - C:\WINDOWS\system32\sstqo.dll
    O20 - Winlogon Notify: winpsa32 - C:\WINDOWS\SYSTEM32\winpsa32.dll


    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit

    If you get an error message while doing the above command prompt step, just ignore it and continue!

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Commander.lnk.disabled"
    C:\Documents and Settings\w00t!\Local Settings\Application Data\a6ae70c7.exe
    C:\Program Files\Common Files\{6C40871F-0C80-1033-0910-040405270001}\Update.exe
    C:\Program Files\Common Files\svchost.exe
    C:\WINDOWS\svchost.exe
    C:\WINDOWS\system32\a6ae70c7.exe"
    C:\WINDOWS\system32\wapisvit.exe"
    C:\WINDOWS\system32\opnlmji.dll
    C:\WINDOWS\system32\sstqo.dll
    C:\WINDOWS\system32\winpsa32.dll
    C:\WINDOWS\system32\oqtss.ini


    If Killbox does not reboot or if you get a Pending Operations type error message just click OK to continue and then just reboot your PC yourself.

    After reboot locate the below folders and delete them if found:
    C:\Program Files\Common Files\{6C40871F-0C80-1033-0910-040405270001}
    C:\Program Files\Safety Bar

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\w00t!\Local Settings\Temp


    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
    Last edited: Aug 27, 2006
  5. melee28

    melee28 Private E-2

    Done
    Done, Done

    Uninstalled both.
     
    Last edited by a moderator: Aug 27, 2006
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about this! I thought your logged off for the night. I edited the previous post to add the complete fix. Just ignore the stuff you already did and complete the rest of it.
     
  7. melee28

    melee28 Private E-2

    Phew!
    Ok, first of all...THANKS!

    I followed the instructions completely. No error messages when running Registrar lite. I did have a question about the killbox step though. As is, I pasted the file name into killbox as you suggested...however, should these three files:

    Menu\Programs\Startup\Commander.lnk.disabled"
    C:\WINDOWS\system32\a6ae70c7.exe"
    C:\WINDOWS\system32\wapisvit.exe"

    end in quotes? I left them in, but I can always go through again and re-enter them without the quotes.

    Otherwise, everthing went smoothly.

    Here's my new logs.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But it did not work. Go back into Registrar Lite and check for that registry key again and delete it from within Registrar Lite. Make sure you refresh and then double check to make sure it really gets deleted.


    No! The quotes were typos. Please delete those files using Pocket Killbox.


    Also run HJT and fix the below left over:
    O20 - Winlogon Notify: winpsa32 - winpsa32.dll (file missing)


    After doing the above attach new GetRunKey and ShowNew logs.
     
  9. melee28

    melee28 Private E-2

    Go back into Registrar Lite and check for that registry key again and delete it from within Registrar Lite. Make sure you refresh and then double check to make sure it really gets deleted.

    Done.

    Please delete those files using Pocket Killbox

    Done.

    Also run HJT and fix the below left over:
    O20 - Winlogon Notify: winpsa32 - winpsa32.dll (file missing)

    Done.

    After doing the above attach new GetRunKey and ShowNew logs.

    Done.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. How is everythings working now?

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  11. melee28

    melee28 Private E-2

    well, I haven't given it a thorough testing yet, but so far it looks great! Thanks again for your help. I'll go through your malware protection post while I'm waiting and I'll post again in a couple of days to confirm everythings ok.

    Thanks chaslang for the help!

    melee28
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  13. melee28

    melee28 Private E-2

    Hi again. Just wanted to post a follow-up. Everything still seems to be running smoothly, and I even notice a bit of a speed increase now that IE isn't constantly trying to open in the background. Thanks again for your help chaslang!!

    p.s. consider this thread closed.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We don't close threads accept for special circumstances (like dupicate posts)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds