Symptoms/HijackThis Log

Discussion in 'Malware Help (A Specialist Will Reply)' started by .Pixel, Sep 4, 2005.

  1. .Pixel

    .Pixel Private E-2

    My computer has a virus. What else is new. :p It will not allow me to view specific URL's such as...

    *=wildcard

    - grisoft.com/*
    - trendmicro.com/*
    - sophos.com/*
    - *agobotgh*
    - I can't download the CWshredder...
    - I cannot log into hotmail or log onto MSN Messenger
    - I cannot use GoogleTalk or check my email anymore because I cannot go to mail.google.com/*
    - I cannot log onto AIM
    - I cannot log onto YIM
    - I don't use ICQ but I am sure I can't go onto it either :p

    It disabled Norton AutoProtect and will not let me enable it.
    I cannot remove "Altnet" with Spybot
    If Norton detects something when I scan the remove will always fail
    Ad-Aware detects DataMminers and other small things but not what I am looking for

    Due to it disallowing me to go to any url containing "agobotgh" and the fact that I have the process "csrss.exe" (Backdoor.IRC Trojan I think but am not sure) I have come to beleive I have the AGOBOT.GH worm but I'm not certain.

    I cannot end "csrss.exe" because it is a critical process and I also cannot stop it from loading on startup either because it says it is in use. It shows as a process in safemode as well.

    This is one hardcore virus it seems... :(

    PS: These smileys are extremely similar to those on DeviantArt... The eye roll is a combination of the :no: smiley and the eye rolling smiley... The Big Grin and Confused smileys are recolors...
     

    Attached Files:

  2. .Pixel

    .Pixel Private E-2

    Also, Cannot use any Mozilla browser... Firefox, Deer Park Alpha 1/2, etc.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    csrss.exe is a valid Windows process depending on where it is running from. c:\windows\system32\csrss.exe is valid.

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Have HijackThis fix the below lines (but make sure no browsers are open when you click Fix):

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O3 - Toolbar: (no name) - {20929603-21DB-477C-BA6F-0B8E70B3C8A0} - (no file)
    O4 - Startup: csrss.lnk = ?
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    You currently are using MSConfig to control startups. We need to see everything. Please run MSconfig and select Normal Startup and then reboot. Now post a new HJT log.

    Did you install WhatPulse? I'm not saying it is bad! It's just a question.
    O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
     
  4. .Pixel

    .Pixel Private E-2

    I got an error. I couldn't fix the csrss.exe shortcut...

    See for yourself...

    Unexpected error occurred!
    Error #52 (Bad file name or number) in Sub GetLongPath(?.exe).

    Please send a report to merijn@spywareinfo.com, mentioning what you were doing, and what version of Windows you have.

    This message has been copied to your clipboard.

    And...

    Unable to delete the file
    O4 - Startup: crss.Ink = ?

    This file may be in use. Use Task Manager to shutdown the program and run HijackThis again to delete the file.

    I can't end because it is a critical process. Whatpulse is a program I installed. It tracks mouseclicks and key strokes...

    It's a HUGE community of people that use it.

    Anyways...

    Here is my log file...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in your c:\windows\win.ini file for a line (or lines) similar to the below:

    load=C:\WINDOWS\System32\ovclvvdti\csrss.exe

    run=C:\WINDOWS\System32\ovclvvdti\csrss.exe

    Let me know what you find.
     
  6. .Pixel

    .Pixel Private E-2

    Nope... Nothing. This is all I found:

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [MCI Extensions.BAK]
    aif=MPEGVideo
    aifc=MPEGVideo
    aiff=MPEGVideo
    asf=MPEGVideo
    asx=MPEGVideo
    au=MPEGVideo
    m1v=MPEGVideo
    m3u=MPEGVideo
    mp2=MPEGVideo
    mp2v=MPEGVideo
    mp3=MPEGVideo
    mpa=MPEGVideo
    mpe=MPEGVideo
    mpeg=MPEGVideo
    mpg=MPEGVideo
    mpv2=MPEGVideo
    snd=MPEGVideo
    wax=MPEGVideo
    wm=MPEGVideo
    wma=MPEGVideo
    wmv=MPEGVideo
    wmx=MPEGVideo
    wpl=MPEGVideo
    wvx=MPEGVideo
    [hkjhk]
    nnhjhkj15=1102786513
    [hkjhkW]
    nnhjhkj15=1102786558
    [MSUCE]
    Advanced=0
    CodePage=Unicode
    Font=Arial
    [PCDRWIN]
    CurrentLanguage=0
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Do you see the below file:

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\csrss.lnk

    If so, boot to safe mode and see if you can delete it.

     
  8. .Pixel

    .Pixel Private E-2

    Nothing...
     
  9. .Pixel

    .Pixel Private E-2

    UPDATE!

    Ever since I did that host thing, I can access grisoft.com again and housecall.trendmicro, etc. I cannot access email sites such as mail.google.com or log into hotmail.com though.... At least the problem isn't as big now!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try booting in safe mode and do not run anything except HJT. Have it try to fix that O4 line while in safe mode. Let me know what happens.

    If that does not work, download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside c:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
    Last edited: Sep 8, 2005
  11. .Pixel

    .Pixel Private E-2

    Hmm...

    When I ran HijackThis in safe mode, csrss.exe was not there at all. It did not run this time. I had previously deleted a folder called ykzljbhjj or something with two files called csrss except with different extensions. One had a .ini extension and the other was a shortcut. I found those files along with a startup shortcut and another shortcut in the backup of Hijack This. I deleted them. I'll attach my log anyways.

    Okay, I'm scanning with WinPFind now...

    Another thing I forgot to add which is REALLY bad is the fact that it changed my Windows Validation so now I cannot download certain microsoft files. It uninstalled my MS Antispyware...

    WinPFind popped up and said FILE NOT FOUND or something similar wgile I was typing... It says it is now scanning registry... I'll post the log ASAP.
     

    Attached Files:

  12. .Pixel

    .Pixel Private E-2

    Okay, I'm going to bed now.... It never really finished so I just copied the status log... It's attached. Thanks for the help so far! It's better than it was before so I'm sure it will get fixed. Especially with your expertise. Thanks again and good night! :)
     

    Attached Files:

    • log.txt
      File size:
      21.5 KB
      Views:
      2
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is what I was referring to in message number 5. Normally a process his hidden somewhere like the one in message 5 and yours was probably in the folder named ykzljbhjj. It could still be around or it could be named something else.

    You also must remember that c:\windows\system32\csrss.exe is valid!

    You must allow Pfind to run to completion. The more files on a system and also dependent on the processor speed and if you are running anything else at the time, the longer it will take. However I think you were at the end and just a message like below was missing to indicate it finished:

    »»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    WinPFind v1.3.5 - Log file written to "WinPFind.Txt" in the WinPFind folder.



    Boot into safe mode and look for the below file and delete it:

    C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\csrss.lnk

    It shows in the log so it must be there!! If you cannot delete it, try renaming it to csrss.bad. Then try dragging it to your Desktop. Then reboot and delete it from your Desktop.

    Also from the log it looks like MSconfig is being used to control startups. Run MSconfig and make sure you select Normal Startup. Then reboot and post a new HJT log.
     
    Last edited: Sep 8, 2005
  14. .Pixel

    .Pixel Private E-2

    It didn't finish the scan so I restarted (the scan). It's back at the same spot. I did however find the shortcut and delete it... :) I'm going to restart my computer and see if it still runs it.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Let me know the current status!
     
  16. .Pixel

    .Pixel Private E-2

    "Runner Error

    Runner file name (Compaq Connections.exe) lacks a '-' (the app id separater)"

    That happens at the beginning of startup. Compaq Connections is a feature my computer has but I dodn't know why it wouldn't work now...

    Anyways...

    The log is attached. I will re-scan and see if it works. I'll keep you updated... :)
     

    Attached Files:

    • log.txt
      File size:
      21.3 KB
      Views:
      2
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What's a "Runner Error"?

    I have no idea what the message about Compaq Connections is about. We did not touch any of that.

    You should also delete the below file:
    C:\WINDOWS\SYSTEM32\wbdbase.deu


    Are you having any other malware problems?
     
  18. .Pixel

    .Pixel Private E-2

    Okay, it changed my windows certification so that it seems unregistered. I can't log onto hotmail/messenger or any other mail/instant messaging...

    Btw, what was that one file?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What changed your windows certification? The original malware problems.

    That file is something that was getting reported as a WinSync malware problem. But now after further checking, I do not think it is malware. Did you already delete it? If so, see if you can restore it from the Recycle Bin. Sorry about that!
     
  20. .Pixel

    .Pixel Private E-2

    No I can't restore it and about my indows, it says it's not a registered copynow. I can't downlaod the programs of microsoft where you need the validation anymore...
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean you had emptied the Recycle Bin and the file is gone? Look for a c:\i386 folder or a c:\windows\i386 folder on you system. Let me know if you find it. Otherwise use Windows Search to look for matches to WBDBASE.ENU Let me know the results of where it is found.

    Was your copy of Windows valid to begin with. And when did you notice you cannot download from Microsoft anymore?

    If you have your license key, you should be able to just re-validate.
     
    Last edited: Sep 13, 2005
  22. .Pixel

    .Pixel Private E-2

    My dad decided that he is going to reformat the computer... Sorry for wasting your time but thanks anyways... Now I have to research on Anti-Virus programs to replace Norton... :p
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds