syspools.exe and more

Discussion in 'Malware Help (A Specialist Will Reply)' started by jrjcp, Dec 29, 2006.

  1. jrjcp

    jrjcp Private E-2

    We have two networked computers for our two person business. The infected computer is the one connected to the router and dsl modem. We have not been running good security software for a number of reasons, but have ordered some. The computer not only flashes the syspools.exe has encountered a problem, but also ppl.exe, w.exe, and ss.exe has encountered problems messages. I have spent the past two days following the first seven steps of READ & RUN ME FIRST, including the additional step of generic cleanup for Smitfraud and SpySheriff which were identified along the way. I was unable to save the smitRem.exe to use it. The save button was grayed out. I am not highly versed in tech matters, but followed the directions. Here are the first three files.
     

    Attached Files:

  2. jrjcp

    jrjcp Private E-2

    Here are the other files. The BitDefender file would not upload as it was too large.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    First uninstall CounterSpy now since it is only a trial and we are finished with it. Also it could get in our way during cleanup since you already have Windows Defender install. Uninstall CounterSpy now before continuing. Also you have Spyware Doctort installed (an old version though). Is it a paid version or free trial version?

    I see a bunch of new software just installed on Dec 28 th I'm not including things in the READ ME). What did you just install. Did you install SynthCore COM Server? I see this C:\WINDOWS\syncor.exe file which may be a trojan unless you install SynthCore. I'm going to assume it is bad and put into my procedure steps to remove this file.

    More Questions:
    In the GetRunKey and ShowNew folders I'm seeing a bunch of randomly named files with .t extenstions like below.
    Code:
     "C:\Cleaning Computer\GetRunKey\"
    aaaaaaxj.t    Dec 28 2006       17559  "aaaaaaxj.t"
    aaaaaaxq.t    Dec 28 2006       17559  "aaaaaaxq.t"
    aaaaaynm.t    Dec 28 2006       17559  "aaaaaynm.t"
    dgyrwdkw.t    Dec 28 2006       17559  "dgyrwdkw.t"
    dgyrwexf.t    Dec 28 2006       17559  "dgyrwexf.t"
    getrun~1.bat  Dec 27 2006       51777  "GetRunKey.bat"
    gmxjtlds.t    Dec 28 2006       17559  "gmxjtlds.t"
    grep.exe      Apr 14 2003       80412  "grep.exe"
    jswbqlgm.t    Dec 28 2006       17559  "jswbqlgm.t"
    locate.com    Jan 13 2005       11254  "locate.com"
    ltime.exe     Oct 28 1986       13184  "ltime.exe"
    pfukkyqp.t    Dec 28 2006       17559  "pfukkyqp.t"
    sltchccg.t    Dec 28 2006       17559  "sltchccg.t"
    sltchydx.t    Dec 28 2006       17559  "sltchydx.t"
    vrstehdj.t    Dec 28 2006       17559  "vrstehdj.t"
    Did you notice these. They are coming from your infection.
    Delete all of them. The only files that should be in the GetRunKey folder are these:
    Code:
    "C:\Cleaning Computer\GetRunKey\"
    getrun~1.bat  Dec 27 2006       51777  "GetRunKey.bat"
    grep.exe      Apr 14 2003       80412  "grep.exe"
    locate.com    Jan 13 2005       11254  "locate.com"
    ltime.exe     Oct 28 1986       13184  "ltime.exe"
    The same goes for the ShowNew folder! Only files that should be in the ShowNew folder are these:
    Code:
    "C:\Cleaning Computer\ShowNew\"
    grep.exe      Apr 14 2003       80412  "grep.exe"
    locate.com    Jan 13 2005       11254  "locate.com"
    ltime.exe     Oct 28 1986       13184  "ltime.exe"
    shownew.bat   Dec 25 2006       37649  "ShowNew.bat"
    
    Move on to my next message now!
     
    Last edited: Dec 30, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's get onto the heart of your problems!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to QSS
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteQSS into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O4 - HKLM\..\Run: [system spool] C:\WINDOWS\system32\syspools.exe«qð«q\þ”þ•‘:«qtPÿœš‘:«qðþðþ«q?›‘:ØÀ—:ëš‘:t@ÿÿÐýH+$«q«qX+$ ÿ«qî:íè"$(D«qö€:TU«qA@fhÈ>Üý´úPÿÐýxÿ<$€:<ÿ$€:B$€:€‡xV
    O4 - HKLM\..\Run: [agent] C:\WINDOWS\system32\ppl.exe
    O4 - HKCU\..\Run: [system spool] C:\WINDOWS\system32\syspools.exe
    O4 - HKCU\..\Run: [agent] C:\WINDOWS\system32\ppl.exe
    O18 - Filter: text/html - (no CLSID) - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Jim\GD345Vh.exe
    C:\Documents and Settings\Jim\jO2Qncq.exe
    C:\Documents and Settings\Jim\qA64QG1.exe
    C:\Documents and Settings\Jim\Application Data\aaaaexvp.t
    C:\Documents and Settings\Jim\Application Data\dgyrbcca.t
    C:\Documents and Settings\Jim\Application Data\pfukosbx.t
    C:\WINDOWS\SynCor.exe
    C:\WINDOWS\system32\glquwhot.exe
    C:\WINDOWS\system32\google.png.exe
    C:\WINDOWS\system32\HoMnN60.exe
    C:\WINDOWS\system32\ll4Uh0W.exe
    C:\WINDOWS\system32\PenLLxH.exe
    C:\WINDOWS\system32\ppl.exe
    C:\WINDOWS\system32\se.exe
    C:\WINDOWS\system32\ss.exe
    C:\WINDOWS\system32\syspools.exe
    C:\WINDOWS\system32\Th3dCk3.exe
    C:\WINDOWS\system32\w.exe
    C:\WINDOWS\system32\adir.dll
    C:\WINDOWS\system32\zlbw.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Also delete all files and subfolders in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Jim\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. jrjcp

    jrjcp Private E-2

    Thank you so much for your response.

    I have uninstalled CounterSpy. Spyware Doctor was purchased this past year, but brought the system to such a crawl that we have not been using it except for monthly scans. I have ordered Kaspersky (with a rebate) which should arrive today or Jan. 2.

    I have read most of the sticky notes at MajorGeeks and they seemed to confirm the setup of our system which was done by my son. He said that we only need the firewall on the router (Netgear.) How do I know if the firewall is turned on and working? He also suggested that we only use Firefox, which we do. (Only recently gave in to all of the Windows requests to download IE7.) This computer is used by my husband, who mostly uses GOOGLE to find websites and who is good about not opening things in email. However, he does receive group emails from two professional organizations. Most of the emails do not have attachments.

    I only installed the items from the links at your website as suggested in the READ & RUN ME FIRST; SpywareStrike, Smitfraud, SpySheriff, et. al.; and Downloading, Installing, and Running HijackThis pages. I did not install SynthCore.

    The dgyrwdkw was one of the "has encountered a problem" error messages (from the GetRunKey folder.) I do not recognize any of the others, but will delete them as requested.

    Now I will get to work on all that you sent.
     
  6. jrjcp

    jrjcp Private E-2

    When I clicked on the jre-6-windows-i586.exe file to install Sun Java Runtime Environment, two new files appeared:
    pfukkysx.t
    A88816v.exe
     
  7. jrjcp

    jrjcp Private E-2

    First, could not find the file in HJT with all of the wierd letters after .exe. Did fix all of the rest of the lines.

    After running Pocket Killbox there were no error messages when I rebooted. When I went to the last step of cleaning out temp files there was only one from today. However, all of those .t files were in the C:\Documents and Settings\Jim folder. Should I delete them?

    Outlook and Firefox are opening as usual, although Outlook seemed really slow. (One of the symptoms earlier this week was that the computer would turn off when Outlook was opened. Also Word and Firefox would not open, so I would use the repair on Word and reinstall Firefox.) Right now, all of our MS Office products are opening right up.

    As I gather the log files to attach, I see that the .t files are also in my GetRunKey folder and my ShowNew folder. Aaaaarrrrgggg.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These files are all part of the infection from syspools.exe. It cause a variety of problems like:
    Please follow the steps below!
    • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    • Please download and install and get any updates recommend for Prevx1 DO NOT SCAN YET!!!!
    • Then physically unplug you cable that connects you to the internet! DO NOT plug it back in until I tell you to do so.
    • Now run a full system scan with Prevx1 in normal boot mode. Save a log of what it finds and attach it later.
    • Now reboot into safe mode and run a second scan with Prevx1. Save a second log.
    • Now reboot into normal mode.
    • Use Pocket Killbox to delete the below files:
    • Now look around and delete any of the remaining ".t" files we were seeing in the GetRunKeys, ShowNew, and other folders.
    • Plug in your cable to the internet.
    • Come here and attach the two Prevx1 logs.
    • Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Attach new logs from GetRunKey, ShowNew and HJT.
     
    Last edited: Dec 31, 2006
  9. jrjcp

    jrjcp Private E-2

    Finally have the .t files removed. Prevx1 would not run in safe mode. So I will include the one log that I made. I will now update the registry and create another message for the other 3 attachments.
     

    Attached Files:

  10. jrjcp

    jrjcp Private E-2

    Here are the new logs.
     

    Attached Files:

  11. jrjcp

    jrjcp Private E-2

    In terms of how our computer is working now, when I opened MS Outlook there was a flood of messages that could not be delivered. They were all spam and were not generated by us.

    Kaspersky arrived today and I would like any hints that you may have about installing it, as well as how to know if my router firewall is working and any other suggestions that you have aside from the sticky notes.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your newfiles.txt log in message # 10 it does not appear that you are running Pocket Killbox as requested. No files are showing up deleted by it. And at least one file is still present. You need to either manually delete the below file or use Pocket Killbox to delete it on reboot:

    C:\WINDOWS\system32\zlbw.dll


    Also make sure that the below file has been deleted:
    C:\WINDOWS\system32\taskdir.exe


    Also delete the two below left over folders from CounterSpy:C:\Documents and Settings\Jim\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [taskdir] C:\WINDOWS\system32\taskdir.exe

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now attach a new HJT log.

    Make sure you tell me how things are working now!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still getting these?

    Just make sure no other Antivirus application is installed before installing Kaspersky. Then install it, get any updates, and then immediately run a full system scan with it.

    There are a few websites that help you perform firewall testing and port scanning.


    http://www.hackerwatch.org/probe/?affid=105-17&dtag=1mqj141&langid=1

    http://www.pcflank.com/scanner1.htm

    http://www.auditmypc.com/freescan/prefcan.asp
     
  14. jrjcp

    jrjcp Private E-2

    Thank you for your continued assistance. I did not feel that the Pocket Killbox was saving my files for the delete on reboot, so I manually killed each file individually (probably over 700 of those .t files.)

    We installed the Kaspersky yesterday and it collected a lot of bad guys and a few of the .t files that I missed. Should I uninstall all of the other software: Prevx1, Lavasoft Ad-Aware SE Personal, Spyware Doctor, Spybot, CCleaner, and or Windows Defender?

    I have just completed the tasks from post #12. When I rebooted after deleting the ...taskdir.exe file, the screen came up black and said that Windows did not restart, did I want to start normally? I said yes. When I rebooted after HJT, the computer seemed to reboot as usual.

    We have received 65 of the undeliverable emails that we did not generate. They have gibberish letters @ our domain name and went to unknown people at unknown email addresses.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Keep Ad-Aware SE, Spybot, and CCleaner. They only run when you need to scan with them and use no system resources until then. In addtion Spybot's Immunize feature provides some nice protection.

    As for Spyware Doctor, Prevx1, and Windows Defender, it all depends on you. You need to have realtime active protection from ONE of these. If you are not going to enable Spyware Doctor even though you purchased it, then uninstall it. If you are not going to buy Prevx1, uninstall it and keep Windows Defender which is free but not really as good as Spyware Doctor or Prevx1.


    I have a feeling this is incoming spam mail being sent to you rather than originating from you. Try looking at the time and dates of some of the emails and see if they are at times when your PC is not even running. Do an experiment and shut your PC down for at least a day. Then see when you log back in if messages show as being sent from your PC while it was off.

    However is also possible that this is still an effect of the infection caused by syspools.exe. It has been describe as doing the below.
    However it looks to be removed right now. It is possible that something is still hiding even though your current HJT log is clean.

    Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.

    Also let's run a second rootkit detector, sometimes one will find what another does not.
    Run this AVG Anti-Rootkit and attach a log from it too.
     
  16. jrjcp

    jrjcp Private E-2

    Are you indicating that Kaspersky and Spyware Doctor serve two different functions and can both be used since we own them?

    Neither Blacklight Beta nor AVG Anti-Rootkit discovered anything. The BB log is attached. AVG did not generate a log.

    Next, I hope that you can guide me through the final steps before system restore. Do I need to empty out all temporary files, etc?
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Kaspersky is an antivirus application and Spyware Doctor is an antispyware application.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds