alright Chas, need your help friend

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Shadowchaser, Sep 19, 2005.

  1. Shadowchaser

    Shadowchaser A Really Great Guy

    Hey chaslang, I am admitting defeat on my own and asking for your help in removing the Aurora malware. Please outline what you need me to do. Thanks in advance.

    Wraith aka Jack

    p.s. - I used to think I was fairly proficient in removing this type of threat. I've been humbled :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not know what you have perform so far so some of the steps are standard operating procedures as required.

    Please follow the steps below:

    - download Nail/Bolder/Aurora Remover 0.3.1 Beta and save it to its own folder like c:\ABIremover

    - Now extract the abiremover.exe file from the ZIP file into the folder you created but do not run the EXE yet. We will run it later.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates for all programs.

    - Now while still in safe mode, run the abiremover.exe but make sure you are physically disconnected from the internet (unplug your cable to be sure). Just click install, wait (explorer window will disapear)

    - When abiremover finishes just reboot into normal and continue with the below steps.


    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.



    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Shadowchaser

    Shadowchaser A Really Great Guy

    Have not forgotten to do this Chaslang, am doing it in my down time between work and school. I'm to the point of getting HJT and running it. Will hopefully have an update and an attachment for you by Saturday night. Sometimes life just gets so hectic!

    Wraith aka Jack
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No rush Jack! ;)
     
  5. Shadowchaser

    Shadowchaser A Really Great Guy

    Alright Chas, here's the HJT log file. Please let me know what you think as I still have this problem.

    Jack
     
    Last edited: Jun 4, 2006
  6. Shadowchaser

    Shadowchaser A Really Great Guy

    Disregard that last post Chas, it was done in safe mode. Below is the actual HJT logfile ran after a standard boot.
     
    Last edited: Jun 4, 2006
  7. Shadowchaser

    Shadowchaser A Really Great Guy

    bump in case Chas forgot me :(
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to System Startup Service (if that is not found, look for: SvcProc) ... Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    System Startup Service

    If that does not work, use the short name: SvcProc

    Now exit HJT and do not reboot if it asks you to do so. Just continue with the below.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O4 - HKLM\..\Run: [pwmxee] C:\WINDOWS\system32\obnxom.exe r <--- this is a randomly named file that may have changed since posting your log. Look for the new process name
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\Nail.exe
    C:\WINDOWS\system32\obnxom.exe <--- this is a randomly named file that may have changed since posting your log. Look for the new process name.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Do not reboot after posting your log.
     
  9. Shadowchaser

    Shadowchaser A Really Great Guy

    Ok did this, but did not find the service entry given in your example here:

     
    Last edited: Jun 4, 2006
  10. Shadowchaser

    Shadowchaser A Really Great Guy

    well I was wrong again, it just took longer to raise it's ugly head. I had to reboot as well so I am posting yet another HJT log file for your perusal. Please let me knwo what you think. Thanks!

    Wraith
     
    Last edited: Jun 4, 2006
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the previous steps! The System Startup Service is there and must be found.

    The random file name is now:
    O4 - HKLM\..\Run: [pjnspe] C:\WINDOWS\system32\sfikpim.exe r

    And nail is back:

    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
     
  12. Shadowchaser

    Shadowchaser A Really Great Guy

    Ok Chas, here we go....

    I run HJT, locate and identify that nail.exe and the other malicious process is running (O4 line). I go into the services.msc window and look to see if System StartUp Service or SvcProc is there. It is not (see image attachment). I start HJT and do not scan but go to misc tools and stop NT service; SvcProc (can't find System Startup Service). System restore is disabled and hidden files are set to show. I then check the boxes to remove Nail.exe and the malicious service. I exit all browsers, notepads, or any other active windows then I click Fix It.

    Boot into safe mode, locate Nail.exe, delete it and use Task Manager to ID the malicious service (it mutates on every boot). I stop the process from running and it instantly migrates to another version of itself but with a different name. I attempt to remove it from C:\windows\system32 but get an error that it is in use. At this point I am lost on what to do next. Any more help from you guys would be highly appreciated. I will post another HJT log for your perusal in the next reply.

    Thanks,

    Jack
     

    Attached Files:

  13. Shadowchaser

    Shadowchaser A Really Great Guy

    Ok here is the latest HJT log. As I understand it the following lines need to be fixed:

    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
    O4 - HKLM\..\Run: [mqwkie] C:\WINDOWS\system32\pizkjm.exe r
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe

    In this log it has started the SvcProc.exe again but I have removed it many times in the many times I've ran HJT and tried to debug this evil program (I HATE spyware and hijackers!!). Anyway, I've done nothing since my last post except to run HJT and scan the system (with the exception of placing this reply in here). Attached you will find the HJT log in it's entirety.
     

    Attached Files:

  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    OK, I've basically been taking a hanmmer to this.

    Please run Panda Online Scan. After the scan attach the log to your next post. Also please follow the below:

    Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    REBOOT

    Now come back here and post both logs as attachments and a fresh HJT log.
     
  15. Shadowchaser

    Shadowchaser A Really Great Guy

    Ok, I've got a 4 lb., 6 lb., 8 lb. or 10 lb. hammer, which one do you wish me to use and on which part of the motherboard? BTW, won't that violate my warranty??

    Attached you will find the logs requested. Here are the Panda online scanner file and the RKTools file.
     

    Attached Files:

  16. Shadowchaser

    Shadowchaser A Really Great Guy

    And my newest HJT log..... Off to school now, will be back in about 3 hours to check for your suggestions. Thanks!

    Jack
     

    Attached Files:

  17. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Panda found all sorts of issues:

    [font=&quot]Run this uninstaller -http://www.bestoffersnetworks.com/uninstall/

    See what is does for Nail.

    Then run Panda Scan and Rkfiles again.

    Post the logs along with a fresh HJT.
    [/font]
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! And it also found left over quarantine items from CounterSpy which no longer appears to be installed. They should be deleted too along with the rest of the stuff reported.

    It may be worthwhile giving Ewido a run since it can fix things.
     
  19. Shadowchaser

    Shadowchaser A Really Great Guy

    ok will delete those and run them when I get home (am at school right now). What is Ewido and where do I get it?

    Jack
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  21. Shadowchaser

    Shadowchaser A Really Great Guy

    Ok ran Ewido and had some strange results as follows:
    found 642 incidences and started to remove them, got to 586 and locked up the program. No chance to save the log. Ran Ewido again, this time found 55 incidences and fixed 56 but would not save the log again. Came up with a error stating not all files were fixed yet? Ran Ewido for a third time. Came up clean and got a saved log file but nothing is in it. Showed a clean system.

    Then I ran Panda, attaching report to this message. Then ran RKtools and got a report from it (also attached). Am going to attach the HJT log to the next message.....

    Oh and during all of this lost my access to the net via my browser so I reset my web settings in IE. All appears to be well now though.....

    Jack
     

    Attached Files:

  22. Shadowchaser

    Shadowchaser A Really Great Guy

    Here is my HJT log. No mention of Nail.exe in it. Thank you guys for your help. You two are really great at this! Hope I can get as good at it as you are. If there is anything else you see that needs to be done please let me know.

    Jack
     

    Attached Files:

  23. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your log is clean. How is your system performing?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you have CounterSpy installed at one time or do you still have it installed? I did not see it running and it would be nice to get rid of the stuff in its Quarantine folder as shown in Panda.

    You should run Ccleaner on all user accounts especially:
    Administrator.SHADOWCHASER
    Gage
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the HJT log is clean but we should try to cleanup all the background stuff Panda is showing.
     
  26. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run Ccleaner and delete all the files in the C:\Windows\Prefetch folder.

    Open Windows Esplorer and Delete the Following:
     
  27. Shadowchaser

    Shadowchaser A Really Great Guy

    could not unregister these, got a "specified module could not be found error."
     
  28. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Were you able to find them and delete them by navibating to the file loaction using Windows Explorer?
     
  29. Shadowchaser

    Shadowchaser A Really Great Guy

    Just did, thanks!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so is everything working properly now? Is a PandaScan now clean?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds