pernicious smanager.7.exe infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tfelix, May 19, 2007.

  1. tfelix

    tfelix Private E-2

    hello friends

    i won't post any hijackthis logs off the bat since it appears those are the ground rules for the forum.

    my computer has come down with a baaad case of the scaries today. i've made a firm decision never to use a key site again for the rest of my life. i downloaded what i thought was a legitimate keygen from a site reported to be clean by asta-killer.com. i soon discovered i had a rampant vundo/mundo/whatever-it-is infection.

    searching around on google i downloaded all the tools recommended (vundofix, virtumundobegone, hijackthis) and as of right now i've been working on killing creepy-crawlies in adaware, kapersky, spybot s&d, ccleaner, and hijackthis for about five hours.

    a while ago i reached the point where only two processes were left, and i'm convinced these two are very new and VERY mean. i'm not a n00b by any means, and i've been actively using computers for over 20 years... but i've NEVER seen any spyware this mean before. who knows, maybe i've just been lucky so far?

    anyway, i've got it bad this time. there's a particular process called smanager.7.exe (which never seems to be anywhere in particular and always seems to be dynamically renaming itself to things in some temp folder somewhere) and another one called win32.alphabet.gen. these are turning my life into a living nightmare. i've been in and out of safe mode running every possible cleaner i can think of and just praying that they will DIE somehow. it really feels like i'm in some horrible b-monster movie.

    i've read a bunch of threads on this that seem very recent (last 10 days or so) and very much like my situation, but i haven't been able to get clean here.

    if anyone could guide me through the process of killing these things i will sing your praises till the end of time.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. tfelix

    tfelix Private E-2

    sorry about not following the instructions right away... that was a lot to process..!

    but i did it. i tried my best to follow the whole procedure step by step.

    the first time i ran counterspy i couldn't figure out how to save a log... i realize now i was supposed to copy the text out manually. i did write down the names of the two files it found and neutralized... one under 'files' was called HermanAgent1.0 Trojan.; the other, under 'registry', was called Trojan.Win32.Agent.qt. Counterspy told me it quarantined these, but i didn't know how to save a log the first time...

    I tried it again so I could save a .log for this site, but counterspy came up clean, and i couldn't figure out how to save a log from that. but the results were mem:664/0; files:36414/0; registry:93720/0; cookies 0/0.

    bit defender also came up clean, and i'm attaching the .txt file for that here... i'm sorry that there's a few files listed in there that were found to be clean... some .mp3s and stuff... i clicked on the tab to watch while it was running, and i didn't know it would save that stuff in the log.

    panda thinks it found two "rootkits," but i don't think that's what they are. the files it found were "vBeGone.exe" (which i renamed from virtumundobegone.exe) and "PowerReg SchedulerV2.exe," which i believe came with my game splinter cell chaos theory.

    then i rebooted into normal mode and ran the two batch files. i'll attach those logs in this post or the next.

    finally i ran hijackthis as "analyse.exe," which i carefully followed your instructions about.

    i think my system is almost clean now, thanks to you. it is still exhibiting some disturbing behavior.... kaspersky gives me alerts that something bad is happening whenever i attempt to open windows explorer or internet explorer.

    now i'm exclusively using firefox with adblock+ and noscript, but i'd still like to kill whatever's still living in the depths of my machine.

    thanks for your support, and here are my pertinent .log files. i hope that this will be able to help other people who are having this issue, too.
     

    Attached Files:

  4. tfelix

    tfelix Private E-2

    here are the rest of my logs.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may have called them rootkits while the scan was running but the log shows they are just potentially unwanted applications.


    Okay first you must go back to step 2 of the READ ME and follow those steps properly. You still have system files and also file extensions hidden which may prevent you from finding files I will be asking you to delete.

    Now Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\counterspy

    The below items we are fixing with HJT are not malware but they are just an unnecessary waste of system resources

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - Startup: PowerReg SchedulerV2.exe

    We don't believe in letting anyone be put into the Trusted Zone and it is rarely necessary to do that just to connect to a site. I suggest you also fix the below line with HJT but it is your choice.
    O15 - Trusted Zone: http://care.alltel.com

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\klnmp.bak1
    C:\WINDOWS\system32\klnmp.ini

    Now run Ccleaner

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  6. tfelix

    tfelix Private E-2

    chaslang,

    thanks for the detailed and quick response. i'm a little bit more concerned all of a sudden because you seem so sure i'm running with hidden files and extensions not displayed..... I always have extensions displayed because it bothers me not to see them, and i did follow step 2 precisely in making sure that hidden files were visible, both before i submitted my original reports and just before i followed your recent instructions. i thought "maybe the setting change when i boot into safe mode??" but i checked it there, too, and hidden files and extensions were still visible.

    here's the play-by-play as i wrote it down while i was following your instructions:

    1. double-checked extensions and hidden file settings
    2. uninstalled counterspy, rebooted into normal mode at its request
    3. checked for the two folders you named to delete... they were already gone.
    4. did a windows search for "sunbelt" which yielded no results
    5. ran HJT with no other apps open (unless you count kaspersky on the tray) and selected and selected the items requested, including removing alltel from the trusted zone (i agree with your philosophy, and thanks for the recommendation)
    6. clicked "fix" and exited HJT
    7. rebooted into safe mode (with no networking and no ethernet cable)

    Here's where it gets WEIRD

    8. i looked in C:\WINDOWS\system32\ for klnmp.bak1 and klnmp.ini... they weren't there!! i checked again right on the spot for the extensions and hidden file settings, they were set to display all hidden files and not hide file extensions.
    9. i did a windows search for "klnmp". no results.
    10. ran ccleaner anyway (both tabs)
    11. rebooted in normal mode
    12. created fixME.reg (all files / ANSI) from your quote
    13. double-clicked fixME.reg and allowed it to merge with the registry
    14. i ran your batch file "GetRunKey.bat"... at the very start of the process, in the black cmd/dos window, the program reported "Error: the system was unable to find the specified registry key or value" twice.
    15. i ran "shownew.bat"
    16. i made sure everything (except kaspersky) was closed and ran HJT.

    i think i can see where you're coming from... in shownew.bat, those klnmp monsters are there.... but as i reported, i can't see them or delete them in windows.

    i'll attach my logs here and then give you a short report of any weirdness that is happening in another post.
     

    Attached Files:

  7. tfelix

    tfelix Private E-2

    ok. things with the computer are generally running a lot better now, especially since i ran counterspy according to the instructions and it killed the two things no other program had been able to touch.

    last night i was in full freakout mode because warnings were popping up on my screen literally every 2 seconds, so i set all of kaspersky's settings to HIGH. i believe that some of the warnings i'm getting now may be false alarms because of those "high" settings.

    In general, the system feels quite a bit more sluggish than it did, say, 30 hours ago, but i think that may be because Kaspersky has the system on such a tight leash... i'm not sure.

    just to give you an idea, i've made a few screen captures of some of the error messages, so you'll know what's going on.

    the first is a capture of some of the Events tab on Kaspersky's "Protections" screen.

    the others are warnings that Kasperksy generates when i try to use windows explorer or internet explorer, or when windows boots and something happens with "inkmonitor" or "motiveSB" i think those two in particular may be normal, but it freaked me out the way the alerts were reported..."trying to inject module into all processes"!?!? sounds scary. i hate inkmonitor anyway, and i'd love to make it stop putting itself on the taskbar and re-creating its start menu program group after i delete it, every time the computer boots.

    i understand that motiveSB is alltel checking the DSL connection or something, but i was just scared that the virus/spyware thing was smart enough to use startup processes to hide itself... so i've been habitually denying those processes/alerts.

    other details.... i see in HJT and the other logfiles that there are still traces of bitdefender on the system? also, in HJT (O23) apparently there's a file missing for kaspersky? i know that avp was one of the bad processes that i think got killed in combat, but kaspersky itself seems to be running properly. what should i do about these?

    i'm sorry to take up so much of your time with my long posts..... i can't thank you enough for what you've done so far to help me out. i'll be waiting for your response when you have time. thanks!
     

    Attached Files:

  8. tfelix

    tfelix Private E-2

    another mugshot (see attachment):

    the "explorer.exe" alert doesn't appear as a pop-up window anymore because i think i somehow set a rule for it to be always denied. now i can't figure out how to make it come back and smile for the camera, but the events are still occurring and getting logged in kasperksy > protection every time i open windows explorer (by right-clicking on Start)

    thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I misread your previous log, extension were not hidden but system files were and they still are. The below registry keys from your GetRunKey log prove it:
    Code:
    ----------------------------------------------------------------------------
        Listing HKCU Explorer\Advanced//Hidden and SuperHidden Registry Keys    
            if Hidden = 0 then Hidden Files and Folders are not shown           
            if SuperHidden = 1 is the desired default value.                    
            if ShowSuperHidden = 0 then System Files are not shown              
            if HideFileExt = 1 then File Extension are not shown                
        We want their values to be (from top to bottom) 1,1,1,0                 
    ----------------------------------------------------------------------------
     
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
    "Hidden"=dword:00000001
    "SuperHidden"=dword:00000000
    "ShowSuperHidden"=dword:00000000
    "HideFileExt"=dword:00000000

    Not true. You just cannot see them due to the hidden files setting being incorrect. The files can be seen in your current ShowNew log. See for yourself.

    Windows Search will not show hidden files and system files unlese properly configured and these are different settings than the one use for Windows Explorer. See this for searching: Searching for Hidden Files on WinXP

    See the download page for GetRunKey as this was explained there.


    Let's set the hidden files info the way I want it to be set!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now look for the files I asked you to delete. Did you find them now?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing wrong with IEFRAME.DLL. It is part of IE7 that you chose to install. Stop blocking it and you should not be blocking the software from your ISP (MotiveSB.exe) unless you don't need it and you probably don't but you have to determine if you would ever use it. As far as I'm concerned it is something you can stop from loading using HJT since I doubt you would ever use it. You can read a little about it here:

    http://www.liutilities.com/products/wintaskspro/processlibrary/motivesb/

    Also InkMonitor is something you need to decide if you want the feature. See: http://www.bleepingcomputer.com/startups/InkMonitor.exe-2202.html
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds