Unidentifyable and Pesky - ttesrp.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hey nerd, Sep 3, 2004.

  1. hey nerd

    hey nerd Private E-2

    Major Brownie Points for whoever can help with this one.......

    I seem to have picked up a gnarly little bugger of a browser hijacker. Every time I launch IE or navigate to a new page in the browser I get a new IE window featuring assorted legitimate (so far) product and presidential campaign ads.

    I have run up to date versions of Norton AV, Ad-aware, Spybot, and HijackThis and seem to have cornered the culprit - ttesrp.exe. A little bit about this ttesrp application......

    Google it and you find nothing, but there it is - and it won't die.

    It created the file C:\WINDOWS\System32\ttesrp.exe and also adds it to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\

    I fed it to Norton AV and NAV didn't flinch. Ad-aware, Spybot, and HijackThis all flag it as a problem and delete it...... but it keeps coming back. I even deleted it manually from the 2 locations mentioned above.......but it keeps coming back.

    Each time it returns under a different randomly generated Value Name in the Registry..... when I first found it the name was gfarwse, then when I ran HijackThis it was hhdssiby, and now it is kkqkgbderziqs...... there have been many other names in between.

    If I delete it from the Registry; a new Registry entry appears immediately. If I delete it from C:\WINDOWS\System32\ first, and then from the Registry; it seems like IE needs to be launched for it to resurrect itself.

    Anyway.... here is my HijackThis log file:

    EDIT by chaslang: Log changed to attachment!

    I'm also curious about what the 3 ControlSet TCPIP Registry entries are and do I need them?

    Thanks for your help!
    The Nerd
     

    Attached Files:

    Last edited by a moderator: Sep 3, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have guidelines about posting HJT log that must be followed.

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    NOTE: You should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File > Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message.

    Update! Due to Hijack This logs destroying search engine and web site searches, we now ask you do not post your Hijack This log file unless requested by us. It is for advanced users, so if you do not understand how to use it, you do not need it....yet. Instead, please tell us in your post what symptoms you are experiencing so we can try and resolve it that way. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First the simple part:
    207.172.3.8 = [ ns1.dns.rcn.net ] 207.172.3.8 = [ ns2.dns.rcn.net ]
    OrgName: RCN Corporation
    OrgID: RCN
    Address: 105 Carnegie Center
    City: Princeton
    StateProv: NJ
    PostalCode: 08540
    Country: US

    Do you recognize RCN?

    192.168.1.1 is most likely your router
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this:

    Enable viewing of hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650
    Disable System Restore: http://forums.majorgeeks.com/showthread.php?t=31668
    But do not reboot when asked to. We will do that later.

    Bring up Task Manager by hitting CTRL-ALT-DEL and click processes. Find and end the following if it exists:

    ttesrp.exe

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\multimpp.dll

    then click OK. If a dialog box confirming this action appears, click OK.

    Then run HijackThis and put check marks on the following items but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading this in:
    O2 - BHO: MultimppObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
    O4 - HKLM\..\Run: [hhdssiby] C:\WINDOWS\System32\ttesrp.exe

    Now reboot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam
    Use Windows Explorer to find and delete:

    C:\WINDOWS\multimpp.dll
    C:\WINDOWS\System32\ttesrp.exe

    Reboot normal mode and come back and tell me how things are working.
    If everything is okay enable your system restore.
     
  5. Viceroy

    Viceroy Private E-2

    I got rid of it once but a few days later it has come back and now I can't seem to get rid of the problem. This is something labelled as VX2 when scanned with Ad-Aware yet Ad-Aware is unable to remove the problem. I also notice the following files have some connection with the multimpp.dll file which is the main cause of the problem.

    I do not have the ttesrp.exe file on my system. Anways here are the following files in which are tied in with multimpp.dll :

    preInMPP.exe
    multimpp.inf
    multimpp.zip

    Anyhow, using the steps provided here I am still unable to to get rid of this problem.

    Absolutely sick of getting spam e-mails? If so, check out http://spamarrest.com/affl?121449 . This may be the perfect solution for you. I use it myself!
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Please start your own thread if we can help you. Also, you want to read privacy policies if spyware is a concern since Spam Arrest does collect information on you and run advertising:

    WHAT PERSONAL INFORMATION DO WE COLLECT
    Although the majority of information obtained through this Site is business related, we may also collect personal information (i.e., individual information that may be used to personally identify or contact you) from Customers, Senders, and other users of this Site. Collection is done both actively (information you voluntarily submit to us) and passively (information automatically gathered from your computer).

    There are paragraphs more after that.....

    I prefer a free, spy free spam program like SPAMfighter http://majorgeeks.com/download4316.html
     
  7. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    It also helps if you add emails, especially on the type of spam email program your using that requires authorization. Case in point, you register for a forum which sends you an email, you should add that website to your trusted zone or the email program should have some sort of override to allow email addresses and domains to be safe. Otherwise it is garbage. Your automated email to me which was to verify your email to complete registration here (through the forums) went to my spam box and almost never saw it. Be careful where you put your email and spam will go down. I have one email I have had for 6 years and it gets no spam at all, whereas emails I use frequently, do get their fair share.

    "Hello there, you are recieving this e-mail message because I am recieving so much spam e-mails each and everyday that I now use SpamArrest to cut down on the number I receive each and everyday.

    If you would like to take advantage of this service then please go to http://spamarrest.com/affl?121449 . Thanks!

    P.S. - Note that you will only have to do this just once.

    Just this once, click the link below so I can receive your emails. You won't have to do this again."
     
  8. Viceroy

    Viceroy Private E-2

    Yep which is why I added your domain to my safe senders list :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds