Trojan.Obfuscated.en & LOP etc.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by petecigales, Oct 6, 2007.

  1. petecigales

    petecigales Private E-2

    Hi,

    Great site ! A few days ago, I found that my daughter's rather aging laptop was infected with a trojan and that there were at least 2, sometimes 3, iexplore connections open at the same time, without Internet Explorer being opened of course. I ran AVG Anti-Spyware and it found and zapped Trojan.Obfuscated.en and funnily enough, NOD32 did the same thing thing ! Then I found this site and ran all the scans in the install and run sticky and it appears to have done the trick : no more iexplore connections. However, when I boot the PC, I get a window entitled "ERROR" with an OK button in the middle. I have to click on the OK button 4 or 5 times before it stops appearing so all it not completely well.

    All the scans were carried out with System Restore disabled (I only saw later that I was supposed to leave it on !).

    Attached are the HJT and BitDefender logs. I couldn't save the PandaScan log because in Safe Mode, I couldn't open its window enough to be able to proceed further after the scan, but the scan WAS done !

    In a second post, I'll attach the RunKeys and NewFiles logs.

    Please let me know if there anything I have to do.

    Cheers

    Pete
     

    Attached Files:

  2. petecigales

    petecigales Private E-2

    And here are the RunKeys and NewFiles logs.

    Cheers

    Pete
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Do you have the log from AVG Antispyware as requested?

    Also it appears that you skipped step 2 of the READ ME. Please do that step now.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.azjfxewopztullerwrtexpgr...JZubPUwypMSBgzBEO/jtOGgZTRbATwQtMBdeqTls.html
    O2 - BHO: (no name) - {75BFB461-1AD5-4F89-511D-8414FFF867CB} - C:\DOCUME~1\Samantha\APPLIC~1\SECOND~1\bookoption.exe (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Bat Wave Base Dale] C:\Documents and Settings\All Users\Application Data\Link Axis Bat Wave\Okay Nurb.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKCU\..\Run: [FORKCAST] C:\DOCUME~1\Papa\APPLIC~1\SITESE~1\Inter Mess Corn.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. petecigales

    petecigales Private E-2

    Hi Chaslang,

    Thanks for your response. Step 2 is the show hiden files step right ? This is always activated on all of my PCs.

    • Remove Messenger : done
    • AVG log, sorry I forget to attach it : here it is
    • Hijack this scan only + fixes : done
    • Avenger : done
    • CCleaner : done (this is regularly run on all PCs anyway)
    • GetRunKey: new scan done
    • ShowNewFiles : new scan done
    • HJT : new scan + log done

    You will find attached on this and on the following message the various logs. The PC appears to be clean, ie no more error messages. The key to all this appears to have been the BitDefender scan which leads to me think what is AVG Anti-Spyware for ? And NOD32 ? And the Agnitum Outpost anti-spyware extension ? Cause for concern !

    Please let me know whether all is in order.

    Cheers

    Pete
     

    Attached Files:

  5. petecigales

    petecigales Private E-2

    Chaslang,

    And here are the remaining two logs.

    During the whole procedure, system restore was disactivated as I saw too late that I was supposed to do this at the end. Playing with fire there !

    Cheers

    Pete
     

    Attached Files:

  6. petecigales

    petecigales Private E-2

    Chaslang,

    I may have spoken too fast. The various scans etc were carried out on my admin account. When I log into my daughter's limited account, I get the 7 "Error" windows with the button in the middle. Nothing else appears wrong however. I have therefore changed her account into an admin one and run avenger, getrunkeys, new files and HJT. You will find attached the logs.

    What to do ?

    Cheers

    Pete
     

    Attached Files:

  7. petecigales

    petecigales Private E-2

    ...and here are the 2 others.

    Cheers

    Pete
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not on this one for the user account that you are using. Check the instructions in step 2 again. There are multiple things to do. You only did one of them. You are still hiding system files and also extensions.

    All of the logs (for both user account) are clean. If you are still having problems you will have to give more specifice details of them and possibly attach a snapshot of the messages you are referring too. It is possible that this it not a malware issue?
     
  9. petecigales

    petecigales Private E-2

    Hi Chaslang,

    Sorry, I'm a fool. I've unchecked the two boxes as instructed. FWIW, I attach new RunKey, ShowNew and HJT logs. You will also find attached to the next message the error message I receive when I start the windows session with my daughter's limited account + the task manager list of applications. She doesn't get the same message when she opens as an admin account. There are 7 such windows and every time I click on OK, another application opens in Task Manager but I don't have the time to see which one. The only ones I did manage to see was "imapi.exe" which I think was for Incredimail which I uninstalled the other day and "hvideo.exe" (?). Perhaps the cleanup process has deleted some dlls required by some programs ? If this is not your domain, please tell me and I'll go and look elsewhere but thanks anyway for all your help !

    Cheers

    Pete
     

    Attached Files:

  10. petecigales

    petecigales Private E-2

    Chaslang,

    Here is the error message and task manager. Sorry, I had to reduce the size of the image to able to upload it but you get the message so to say !

    Cheers

    Pete
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Task Manager list does not show any problems. The error message is not legible. You need to capture only the error message window not the full desktop. Also it would be better to capture the snapshots to a JPG not a Word document which will always be way to larger. Programs like FastStone Capture 5.8 are great for doing this.

    I'm still not sure this is malware. You will have to be much more specific and provide the EXACT names of processes that you think you are seeing.

    imapi.exe is a process associated with CD burning software

    hvideo.exe is unknown but could be malware related. You need be sure of the file names and also there location which Task Manager is totally useless for. You would be better off using the below procedure with Process Explorer to capture a detail running process list to a file that you can attach.

    Download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on explorer.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
    • Also, from now on if you have to kill any processes and you cannot kill them with Task Manager, use Process Explorer instead. Sometimes ProcessExplorer can kill things that Task Manager cannot. And Task Manager will not always show all running processes.
    Also please run the below from your daughter's account.

    Using Silent Runners and attach the log.
     
  12. petecigales

    petecigales Private E-2

    Thanks Chaslang,

    Here the two logs - Process Explorer and Silent Runners (both run from my daughter's account. Please let me know if you see anything.

    Cheers

    Pete
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing of interest in your logs! I tend to doubt these popups are related to malware. Please get a better snapshot of the error message popup only using the tools I gave a link too and save it as a JPG file. Then attach the JPG. ALSO, do not close the popup window.. While it is still open, run the same procedure I gave you with Process Explorer again and attach a new log.

    Is you daughter's account the only one this happens on? If you boot into safe mode and login to your daughters account do these still occur.
     
  14. petecigales

    petecigales Private E-2

    Hi Chaslang,

    Thanks for the reply. Here is the jpeg of the error message and the two logs for process Explorer and Silent Runner both of which were run when the first error message was on the screen (NB : "accès refusé" means "access refused" in case your French isn't up to scratch!).

    Please let me know what you see

    Cheers

    Pete
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer my questions asked in message # 13
     
  16. petecigales

    petecigales Private E-2

    Chaslang,

    In safe mode, my daughter's account doesn't show up if the account is restricted/limited. In admin mode, its starts up without any problem but then it would. If I start the session with my own account but "restricted" instead of "admin", I have the same problem, ie error messages, as with my daughter's account.

    What to do ?

    Cheers

    Pete
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you are trying to run things that require administrator priviledges and that is the reason for access denied. Try changing either your account or your daughters account to be and admin account and then see what happens.
     
    Last edited: Oct 12, 2007
  18. petecigales

    petecigales Private E-2

    Hi Chaslang,

    When I open any session with an admin account, I don't get the error messages. Its when the account is limited that I get them. Wierd, I wonder what it is that needs admin priviledges ? Do the Process Explorer and Silent Runner logs not give you any indication ?

    Anyway, as you say, this doesn't appear to be a malware issue - the computer's clean thanks to your help and your great site. Thanks:wave

    Pete
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to experiment with using the Startup and Services tab on MSconfig. You can disable various startups from loading and by process of elimination may be able to determine what processes are causing this. This is what MSconfig was designed for. That is to do temporary debugging.

    As a quick test to see what happens, you can run MSconfig and choose Selective Startup, then uncheck the Load Startup Items checkbox. Then click Apply, OK. And then reboot and see if the error windows either go away or are reduced in number.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds