What is HMPTBKR?

Discussion in 'Malware Help (A Specialist Will Reply)' started by songdongnigh, Apr 5, 2009.

  1. songdongnigh

    songdongnigh Private E-2

    Hello all,

    I am running Windows XP home, SP2, with current updates. HP Pavilion 750n with 80G HD with 45G free and second 118G HD with 89G free.

    As a matter of curosity, I ran a HijackThis scan and found the following entry:

    O23 - Service: HMPTBKR - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\HMPTBKR.exe (file missing)

    I get no hits from Google for HMPTBKR.

    AVG, Spybot S&D, Ad-Aware, and Malwarebytes Quick Scan all come up clean, and do not detect HMPTBKR.

    With the exception of not installing Microsoft Netfamework, I have run all the steps in "Windows XP Cleaning Procedure" and saved the logs.

    As can be seen from the HijackThis log created under MGtools, the HMPTBKR entry is still there.

    So the question is, what is HMPTBKR? and does it need to be removed as Malware?

    The only symptom may be a very long shutdown when doing a complete Shutdown or Reboot. Otherwise all seems pretty normal.

    Thanks much for any help on this issue.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It could be from malware or it could be a randomly named service left over from some SysInternal applications that are known to not cleanup after themselves properly. We can fix is.


    First two observations:
    1. You AVG8 antivirus appears to be broken because many processes and the services required for it to protect you are not loading or showing in your logs.
    2. AVG8 is out of date anyway and you need to update to AVG8.5 if you plan on keeping AVG.
    Uninstall the below old versions of software:
    Java(TM) 6 Update 11

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/frontiersidebar.jsp?p=CI
    O23 - Service: HMPTBKR - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\HMPTBKR.exe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner to clean out only temp files and nothing else!

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. songdongnigh

    songdongnigh Private E-2

    Hi chaslang,

    Thanks for looking into this mystery. Here's what has happened so far:

    1. Removed Java, although since posting I had already updated to Java 6 rev 13. Will re-install when this cleanup is finished.
    2. Stopped AVG anti-virus & firewall (PC Tools Firewall Plus)
    3. Ran MGtools but got the following error message:

    ProcessDll.exe Application error
    The application failed to initiate properly. (0xc0000135). Click OK to terminate application.

    4. At this point, have stopped cleanup & am now letting you know the situation.

    FYI, I checked with my ISP tech & the reference to "msearch.myway" was their old integrated search engine. They now use Yahoo. I'll remove "mysearch" when the Application error is fixed.

    As for AVG errors, I do have the automatic updates turned off as updating is the first thing I do every day upon booting up. Will Update to 8.5 after fixing current items. Thanx.

    Secondary question: Would it be good to flush (turn off, turn on) the Windows Restore after cleaning up the above issues?

    Have attached MGtools log FYI.

    Cheers
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask you to run MGtools after uninstalling Java. I asked you to run C:\MGtools\analyse.exe which is HijackThis. Also the error message you received and the fix was explained in Using MGtools given in the READ & RUN ME. Please follow my instructions as written from the point of running C:\MGtools\analyse.exe thru to the end.

    The best way to update to 8.5 is to first uninstall 8.0 and then reboot. Then install 8.5.

    We will get to this when we are finished.
     
  5. songdongnigh

    songdongnigh Private E-2

    Hello again chaslang,

    I think I've got cleaned up now. All went as you laid out.

    It was my error on running MGTools, I misread the path.

    As to the error message, it seems that when "OK" is clicked (which I did), it kills the process, but when you "X" out, the process continues.

    As for AVG broken items, it seems to work and the main scren is all "green". I looked at the AVG forum and there's lots of shake-out problems with 8.5, & I want to think about it. I do not want to give up PC Tools firewall, as AVG 8.5 now has it's own firewall. I'll remember to uninstall 8.0 first if I upgrade. Thanks.

    Java 6, rev 13 is now downloaded and running.

    Thank you so much for your help, I'm always amazed at the wealth of knowledge provided by the volunteers at the various help forums.

    Cheers
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. songdongnigh

    songdongnigh Private E-2

    Hello chaslang,

    I've completed the final steps you outlined and all seems well with the computer.

    Thanks again for your time and help. It's been a good learning experience.

    Cheers.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds