Help for a novice please?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sje, May 7, 2005.

  1. sje

    sje Private E-2

    :confused:
    Hi- I am a bit of a novice, so please forgive me if I am asking stupid questions! I have recently had problems with pop ups, that I have cured by using Spyblaster and Ad-Aware. I also have Norton firewall and antivirus installed. Although no pop ups now happen, I do get constant messages from Norton stating that "fbpeynskmb.exe" is attempting to connect to a DNS server.

    Please can you tell me if this is another adware problem? If so, I shall follow the detailed instructions posted by Sticky to try to solve the problem- but as these look a bit scary I wanted to know whether this would help before I attempt it!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you have a piece of malware trying to call home. Yes, you should run the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. sje

    sje Private E-2

    Hi- Thanks very much for your reply. I have followed the instructions about scanning my system (as best as I could), and downloaded all the suggested tools, with updates.
    The results were that the trend Online Virus Scan initially found 3 problems:
    Troj Agent.ABS, Troj Buddy.F, Troj Nail. A and said all of them were uncleanable so I opted to delete these files.
    The Symantec security scan was "Safe".

    I had no problems or messages when I ran the other spyware tools.

    I also notice that when I am in safe mode on the internet a program called Aurora pops up- I assume because my firewall is not working.

    Everything seems to be OK until I reboot and go on the internet, when I still get the initial problem of fbpeynskmb.exe trying to access.

    Please can you advise me further? I have not attempted the Hijack This step yet, until you tell me to do so.

    Thanks for your help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Run HJT as indicated in my previous message.
     
  5. sje

    sje Private E-2

    Hi- here is the HJT log file. Thanks for your help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Click Start > Run and type: cmd and then click OK! This brings up a command prompt window.
    - At the command prompt opens, type the below command and then hit the enter key:

    nail.exe /FullRemove

    Close the command prompt window.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    C:\WINDOWS\eqblnmdt.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\eqblnmdt.exe
    C:\WINDOWS\Bolger.dll
    C:\WINDOWS\qhepcxcj.exe
    c:\windows\system32\ispxmee.exe
    C:\WINDOWS\svcproc.exe
    c:\program files\180solutions <-- the whole folder
    C:\Program Files\ISTsvc <-- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell me how things are working.
     
  7. sje

    sje Private E-2

    I followed your instructions, however I was unsure about what I should do after the "kill process" step. I clicked "scan" but as you had no lines listed to after this step I did not click "Fix". Sorry- I have probably misunderstood the process.

    Booted in safe mode and deleted what I could, but was unable to locate:
    C:\WINDOWS\qhepcxcj.exe
    c:\windows\system32\ispxmee.exe
    C:\WINDOWS\svcproc.exe
    c:\program files\180solutions <-- the whole folder
    C:\Program Files\ISTsvc <-- the whole folder

    Ran Ccleaner and HJT.

    My firewall still says that there are 3 programms trying to run: fbpeynskmb.exe, thnall1a.exe and auroreco.exe.

    I have posted the HJT log, and apologise for my inept skills!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's my fault! I forgot to include the lines for HJT to fix. I'll write a new procedure. Did you run the fix I gave you for nail. That step normally works without a problem but I see you still have it in your log.

    Try this again:
    Then also do the below:

    Download and run the uninstaller: Aurora Uninstaller
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After running the steps in message # 8, run these (now the complete procedure with nothing missing this time ;) )

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    C:\WINDOWS\eqblnmdt.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll
    O4 - HKLM\..\Run: [oHqXn] C:\WINDOWS\eqblnmdt.exe
    O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
    O4 - HKLM\..\Run: [qhepcxcj] C:\WINDOWS\qhepcxcj.exe
    O4 - HKLM\..\Run: [Á³# K"h'þ9Óœ÷3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\eqblnmdt.exe
    O4 - HKLM\..\Run: [nkuefb] c:\windows\system32\ispxmee.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\eqblnmdt.exe
    C:\WINDOWS\Bolger.dll
    C:\WINDOWS\qhepcxcj.exe
    c:\windows\system32\ispxmee.exe
    C:\WINDOWS\svcproc.exe
    c:\program files\180solutions <-- the whole folder
    C:\Program Files\ISTsvc <-- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell me how things are working.
     
  10. sje

    sje Private E-2

    Yes, I ran the fix for nail that you sent me originally, and found that when I type run-cmd-OK the prompt window is:
    C:\Documents and settings\Sue> (we have 4 accounts set up on this PC, one of them being for Sue).
    So I typed in nail.exe/FullRemove and hit enter,not sure if anything happened though. I remember from very old computing lessons that typing cd\ here will take you to the c prompt, so I have done that too and then ran the nail fix from C:\. Not sure if this has had the desired effect this time!

    I have followed your instructions from message 8 and 9, and I think the aurora fix worked. Also, so far I am clear of any pop ups, so very hopeful that we have solved the problems I was getting.

    I am so grateful for all the help you have given me, and sorry for taking up so much time!

    I have attached another HJT log and hope you will be rid of me shortly!

    Many thanks :eek:
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds