Trojan Horse created a Login IUSER_Admin

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by KWirtz, Sep 6, 2008.

  1. KWirtz

    KWirtz Private E-2

    I am in need of help. I used the WIN 2000 and 2003 Cleaning Procedure and am still having problems. For about 3 weeks (mid-August) I have been hearing random sounds come out of my computer and then began receiving several pop-ups indicating Trojan Horse Infections. I was using AVG 8.0 & SpyBot as my protection. About 7-10 days ago when I booted up my computer there was a new user on my computer IUSER_Adim. It is password protected and... I have no clue what the password is. I ran the Cleaning Procedures to the best of my ability and am attaching the logs. I no longer hear the noices on my computer but the user is still there. I am hoping someone can help. The next thread has my 4th log.

    Thanks,
    Kathleen
     

    Attached Files:

  2. KWirtz

    KWirtz Private E-2

    Here is my last log.

    Kathleen
     

    Attached Files:

  3. KWirtz

    KWirtz Private E-2

    Yet another post to add to my saga. I went into control panel, user accounts and was able to delete the user that was created due to the Trojan Horse (duh?). My internet activity seems pretty peaceful so I'm praying that the infections are gone. I'm left with some unstable issues, however. When I click on a hyperlink a Windows Explorer window opens but never connects & it is immediately followed by the computer directory window. It is instructing me to "Locate Link Browser". Also, I tried to connect with someone on SKYPE using a video feed and my computer went to a blue screen with lots of writing and then promptly rebooted. It did this twice so I quit trying. Lastly, my AVG scan wants to delete the ComboFix.exe file saying "Potentially harmful program HideExec.EV". Any solutions or comments?

    Thanks,
    Kathleen
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You also still have McAfee VirusScan Enterprise installed. Per the first instructions in the READ & RUN ME, you must uninstall either McAfee or AVG8 immediately and then reboot your PC. If you decide to uninstall McAfee then you should also run the below after the reboot:

    McAfee Consumer Product Removal Tool


    You also need to uninstall the below old version of Sun Java:
    Java(TM) 6 Update 7

    Are all user accounts on this PC password protected? Even the Administrator user account? If not then add a password to all accounts.


    Your logs show that the cleaning procedure removed your malware.

    What browser are you using when you get the message about Locate Link Browser?


    AVG is incorrect about the files from ComboFix. AVG is apparently getting worse with its false detections.
     
  5. KWirtz

    KWirtz Private E-2

    Thanks for your feedback!

    I wote:
    This happens when I am in MS Outlook reading my emails.

    I deleted the McAfee and the Java as recommended and also password protected my users. I was able to completely delete the IUSER_adm user.

    AVG scans -- There were 2 ComboFix files it sent to virus vault and I told it to restore and the problem hasn't been duplicated.

    I am ready for anything else you want to throw my way. Also, I have been trying to use my webcam through SKYPE since my cleaning and while I'm waiting for my camera to start, I get sent to a light blue screen with lots of writing for just a second and then the computer shuts down. It's too quick for me to read anything. I removed and reinstalled SKYPE and my webcam software but the problem was not resolved. I tried the webcam on Windows Live and did not have the same problem.

    Thanks, again,
    Kathleen
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware issue. I will point you to the below link:

    http://support.microsoft.com/kb/821692

    Other than that, I suggest that you post in the Software Forum.

    This is also a topic better discussed in the Software Forum. All I would suggest is more complete uninstall by uninstalling both applications and then rebooting. After reboot delete all folders related to both Skype and your WebCam software. Make sure you look not only in C:\Program Files but also in your user account Application Data folder.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. KWirtz

    KWirtz Private E-2

    Thanks for all of your help. I did have success with the registry integration. I have gone through the additional removal steps you posted. I will be spending some time with your list on protecting myself from malware.

    Your time and instructions have been fantastic!

    Thank you,
    Kathleen
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds