Trying to get rid of ps1.exe and potentially boodhound.W32.EP

Discussion in 'Malware Help (A Specialist Will Reply)' started by jbclayton42, Jun 13, 2005.

  1. jbclayton42

    jbclayton42 Private E-2

    Hello,

    I have been trying to work on cleaning my computer for weeks and I have now gone as far as I can go without some expert advice.

    I have been experiencing viruses, trojans, spywares... you name it, and it all appears to be coming from the bloodhound.W32.EP virus and the winnt\system32\ps1.exe (aka Aurora?).

    When I go onto the internet (internet explorer) many popups constantly open giving me more problems. I have been cleaning many viruses and spyware but the two that seem to persist despite my efforts are the bloodhound and the ps1.exe. At least, this is what my untrained eyes are catching.

    If I can have any help cleaning my system it would be much appreciated.

    So far here is what I have done to clean my system...

    I have followed everything several times in your "do not post until you have read this: how to: Spyware, Trojan and Virus Removal."

    I am using Windows 2k Professional.

    1) I prepared my system and I don't have about:blank or home search hijack.

    2) I installed the virus, spyware, and trojan cleaners as you asked.

    3) I ran Trend Micro's Free Online Virus Scan and Symantec Security Check. I tried them both in "safe mode with networking support" but they did not work in that environment.

    For Micro's virus scan, the windows would not work correctly and I would get blank screens, but it did work in normal mode. It pointed out that I have the ps1.exe but could not clean it.

    For Symantec Security Check, I was able to get it to work about a week ago in normal mode, but now after I tried cleaning things over and over it does not work. When I try to run it an Alert pop-up says:

    "Redirection limit for this URL exceeded. Unable to load the requested page. This may be caused by cookies that are blocked."

    I tried this in different internet browsers, Mozilla, Firefox, and finally Internet Explorer. When I tried it in Mozilla and Firefox, I got this same error. When I tried it in Internet Explorer the error did not show, but it never loaded.

    I do have a week-old symantec log when it did work.

    I ran McAfee AVERT Stinger in safe mode and it worked fine, and no viruses were found.

    4) I then followed the rest of the instructions, running CCleaner, Ad-Aware SE and the VX2 plugin, Spybot and the others in the order you suggested.

    Nothing seems to be cleaning the two problems I have encountered. At least the ps1.exe. The bloodhound error has not shown up for the last few times, but I don't know if it is cleaned because when I found the error was everyonce and a while when in internet explorer, but now I can not use internet explorer without the pop-ups and it is too slow.

    I ran a HijackThis log and have it available if you would like to see it. I only ran the log, and did not try to fix anything using it.

    I don't want to bog you down with too much information, and I tried to read everything in your website before posting this. If there is anything else I need to give you, I have the log files from Hijack This, my first Symantec log, and some error messages.

    Thank you for your help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt you tried everything on this website. In fact I would bet you did not run the below two tools:

    Please follow the steps below:

    - download Nail/Bolder/Aurora Remover 0.3.1 Beta and save it to its own folder like c:\ABIremover

    - Now extract the abiremover.exe file from the ZIP file into the folder you created but do not run the EXE yet. We will run it later in safe mode.

    - Now reboot into safe mode and run the abiremover.exe but make sure you are physically disconnected from the internet (unplug your cable to be sure). Just click install, wait (explorer window will disapear)

    - When abiremover finishes just reboot into normal and continue with the below steps.


    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program

    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. jbclayton42

    jbclayton42 Private E-2

    You are correct. I did not try that. When I get home this evening, I will try the steps you recommended. Thanks for your advice. I will tell you how it works out.
     
  4. jbclayton42

    jbclayton42 Private E-2

    I still think I have problems.

    When I re-boot there is a Runtime Error! stating that Program: C:\WINNT\System32\ps1.exe has an abnormal program termination.

    I attached my HJT log.

    Thanks for looking into this.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must use only one antivirus application. Pick the one you prefer and uninstall the others.

    You have a load of problems and you need some Windows Updates too.

    This is going to require a few steps and a couple other tools to locate some hidden files. I'll post some starting fixes in this message and in my next message I'll give you some other tools to run and post logs from.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINNT\System32\thesnap.exe
    C:\WINNT\System32\soranui2.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.maxifiles.com/toolbar/sidebar.php?tid=%toolbar_id&aid=%AffiliateID
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINNT\cfgmgr52.dll
    O2 - BHO: SDWin32 Class - {BA0D16D9-150B-4CEE-B810-9205EA40090E} - C:\WINNT\System32\vsdpc.dll
    O4 - HKLM\..\Run: [PS1] C:\WINNT\System32\ps1.exe
    O4 - HKLM\..\Run: [xujpigl] c:\winnt\system32\xujpigl.exe
    O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
    O4 - HKLM\..\Run: [C:\WINNT\VCMnet11.exe] C:\WINNT\VCMnet11.exe
    O4 - HKLM\..\Run: [KavSvc] C:\WINNT\System32\urpvml.exe reg_run
    O4 - HKLM\..\Run: [o8EX37e] thesnap.exe
    O4 - HKCU\..\Run: [Zzx7RXKmV] soranui2.exe
    O4 - Global Startup: rdin.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\System32\thesnap.exe
    C:\WINNT\System32\soranui2.exe
    C:\WINNT\cfgmgr52.dll
    C:\WINNT\System32\vsdpc.dll
    C:\WINNT\System32\ps1.exe
    c:\winnt\system32\xujpigl.exe
    C:\WINNT\VCMnet11.exe
    C:\WINNT\System32\urpvml.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdin.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. jbclayton42

    jbclayton42 Private E-2

    This seems to be doing the trick. I don't see any major problems. There are a few curious things however in the since that I could not find some of the files that you wanted me to delete:

    C:\WINNT\cfgmgr52.dll (but there was a C:\WINNT\cfgmgr52.ini)
    C:\WINNT\system32\xujpigl.exe
    C:\WINNT\VCMnet11.exe
    C:\WINNT\System32\urpvml.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdin.exe

    But I did find everything in the first section of fixing.

    I also noticed that when I reset my web settings, that in the homepage window it said "about:blank." Does that mean I have that now?!?

    Thanks again for your help! This is already giving me peace of mind.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes HJT is able to delete problem files and sometimes not. When it does delete them you will not find them to delete yourself. The steps are still provided to be sure that the files are deleted (sort of a backup step since we cannot be sure what HJT will delete).

    No, you do not have about:blank problems. And now your home page is set to Majorgeeks.


    I mentioned before that additional problems would require a couple other scans so we can locate some hidden files.

    The HijackThis line with KavSvc is an indicator of Ad-behavior problems.

    Please follow the steps below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, doubleClick Find-Qoologic.bat to run the tool. It should produce a log. Please attach this log to your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder - C:\Program Files\RKTOOL. Then, please boot to SAFE MODE and doubleClick rkfiles.bat to run the tool. Allow it sufficient time to run and when it finishes, it will create a log file named C:\Log.txt Please attach that log.


    After doing these scans and posting the logs, it is critical that you do not power down or reboot your system. Otherwise files could change names making the fix that will follow ineffective. For security, you can always unplug your cable to the internet.
     
  8. jbclayton42

    jbclayton42 Private E-2

    Thanks again,

    I will be able to get to this either late this evening or tomorrow morning.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Just post the logs when you complete the steps and remember to not power down or reboot after posting.
     
  10. jbclayton42

    jbclayton42 Private E-2

    Here are the two logs created by the Quoologic and RKTOOL.

    I will not shut down or reboot.

    I am curious however, that I followed your directions and after the Quoologic Tool I did have to reboot in safe mode to run the RKTOOL. Was I not supposed to reboot after that? Or was I supposed to do both in safe mode?

    I will do it again if you need me to.

    Thanks again,
     

    Attached Files:

    • file.txt
      File size:
      1.1 KB
      Views:
      1
    • log.txt
      File size:
      565 bytes
      Views:
      1
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you needed to boot into safe mode for RKfiles and then reboot to normal to post logs. After that, no reboots. Sounds like you did it correctly.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to hripyap Now right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    hripyap

    After doing that exit HijackThis. We will be restarting HJT in a couple of lines though.

    Now please download the following tool: Pocket KillBox

    Extract Pocket Killbox to its own folder but do not run it yet. We will need it later.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes. (These probably will not show since they did not in your last HJT log).
    C:\WINNT\System32\urpvml.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdin.exe
    C:\WINNT\system32\hripyap.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: SDWin32 Class - {BA0D16D9-150B-4CEE-B810-9205EA40090E} - C:\WINNT\System32\vsdpc.dll (file missing)
    O2 - BHO: (no name) - {} - (no file)
    O4 - HKLM\..\Run: [KavSvc] C:\WINNT\System32\urpvml.exe reg_run
    O4 - Global Startup: rdin.exe
    O23 - Service: hripyap - Unknown owner - C:\WINNT\system32\hripyap.exe

    After clicking Fix, exit HJT.

    Now run Pocket Killbox.

    Now, Copy and Paste C:\WINNT\SYSTEM32\mc-58-12-0000079.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\System32\WQKPB.DAT into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\System32\urpvml.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\system32\hripyap.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdin.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    If you get an error message about Pending Operations, just reboot your PC yourself.

    Now get a new HJT log and post it here. And tell us how these steps went and how things are working.

    PLEASE DO NOT REBOOT after posting your log. If you are still infected, it could mutate making the next steps I would post ineffective.
     
  12. jbclayton42

    jbclayton42 Private E-2

    I went through the steps and here is the HJT log file.

    It seemed to be working, a few things did not show up

    such as to fix in the HJT log:

    O4 - Global Startup: rdin.exe
    O23 - Service: hripyap - Unknown owner - C:\WINNT\system32\hripyap.exe

    also in the pillbox tool:

    C:\WINNT\System32\urpvml.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdin.exe

    I was a little worried in the first part when I "Delete an NT Service" (hripyap) when I finished I accidentally chose the option to reboot. I rebooted in "safe mode" and continued.

    I hope that did not create any problems.

    Here is my HJT log file regardless.
     

    Attached Files:

  13. jbclayton42

    jbclayton42 Private E-2

    One more thing, and I don't know if this is related, but it is new.

    I am not logging off, so I am locking my computer until I here a response from you. When the computer is locked, after a little bit of time, an error message pops up on the screen:

    "SSMARQUEE.SCR Application Error
    The application failed to initialize properly (0xc0000142)
    Click on OK to terminate the application."

    When I pressed OK, it returned to the logon window, and then about five minutes later the error message popped up again.

    Is this related?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That error is related to your screen blanker item that was selected. I doubt there is any relationship. Try a different screen blanker to see if it does the same thing.

    You one item in your HJT log that seems to be refusing to go away. Are you sure your have NO BROWSERs running when you use HijackThis to fix items?

    Also you have a few new problems that sprung up.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:

    regsvr32 /u C:\WINNT\System32\vsdpc.dll

    then click OK. If a dialog box confirming this action appears, click OK. If you get an error message, just OK it and continue.

    Run HijackThis do a scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: SDWin32 Class - {BA0D16D9-150B-4CEE-B810-9205EA40090E} - C:\WINNT\System32\vsdpc.dll (file missing)
    O4 - HKLM\..\Run: [vsdpcc] C:\WINNT\System32\vsdpcc.exe
    O4 - HKLM\..\Run: [guarnset] C:\WINNT\System32\guarnset.exe

    After clicking Fix, exit HJT.

    Now run Pocket Killbox.

    Now, Copy and Paste C:\WINNT\System32\vsdpc.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\System32\vsdpcc.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\System32\guarnset.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    If you get an error message about Pending Operations, just reboot your PC yourself.

    Now get a new HJT log and post it here. And tell us how these steps went and how things are working.

    PLEASE DO NOT REBOOT after posting your log. If you are still infected, it could mutate making the next steps I would post ineffective.
     
  15. jbclayton42

    jbclayton42 Private E-2

    I am sure that I had no browsers open, but I triple checked this time.

    the "regsvr32 /u C:\WINNT\System32\vsdpc.dll" was not found when I ran the command.

    I fixed the three items in the HJT log.

    When I ran the Pocket Killbox, only one was found: "C:\WINNT\System32\vsdpcc.exe" and I deleted that and rebooted.

    Here is my new HJT log, and I am not shutting down or rebooting.

    Everything seemed to work out, but when I tried to shutdown after the PocketKillBox, it never shut down, or did it give me an error message. So I powered down as you suggested.

    Thanks.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. jbclayton42

    jbclayton42 Private E-2

    Thanks, You Rock! I have already been spreading the word about your site. I appreciate what you guys do.

    I will now proceed with the next steps.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Complete those other steps ASAP.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds