Need help removing a trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by km7100, Oct 19, 2007.

  1. km7100

    km7100 Private E-2

    i downloaded a file from someone I don't know and ended up getting a trojan. I've run all the cleaning procedures listed on the site here but can't seem to get rid of it. I keep getting flooded with popups and my system is running very slow. Seems to be a little faster after all the cleaning procedures but still getting the popups.

    I've uploaded the log files as requested...

    Thanks,
    Matt E
     

    Attached Files:

  2. abri

    abri MajorGeek

    hi km7100!
    Welcome to Major Geeks!
    I'll be posting you some initial instructions in a bit. The thing which is probably slowing down your computer the most is your Symantec Internet Security Suite. How long have you been running it? Your computer is also still infected. It will take some time to go through the logs, so thanks in advance for your patience.

    Please go to add/remove programs and uninstall:
    - J2SE Runtime Environment 5.0 Update 6
    - Java 2 Runtime Environment, SE v1.4.2_03

    REBOOT your computer now.

    After you've rebooted, please install Java Runtime Environment vs. 6.3

    Thanks!
    abri
     
  3. km7100

    km7100 Private E-2

    It's actually my friend's computer. She downloaded a file she thought was a picture from someone on AIM. I don't know how long she's used Symantec. I already told her to get rid of it and get something else.

    FYI... I ran vundofix.exe and it couldn't get rid of one file for some reason.
     
  4. abri

    abri MajorGeek

    Hi km7100!

    I'm missing your hijackthis.log attachment, which I thought would be in the zip file. The MG Tools are being delivered in a new way and we don't quite have them in their final form yet. If you haven't done so already, please go to the MG Tools folder and see if there is a copy of analyse.exe there. If not, do a search for it on your C drive. When you find it, please double click on it and let it run a scan for you. It should produce a log called hijackthis.log. Please attach that log. If you've already run it, please post the log to me as an attachment.

    After you do that, please go to add/remove programs and see if you can find WildTangent. If so, please uninstall it.

    Thanks.
    abri
     
  5. km7100

    km7100 Private E-2

    ok, here's the hijackthis log. I deleted the old java programs and installed the one you asked. I already deleted wild tangent during the intial cleaning procedures.

    Thanks
    Matt
     

    Attached Files:

  6. km7100

    km7100 Private E-2

    i've also noticed 2 desktop icons pop up "online security guide" and "live safety center" are they part of the trojan and how should I get rid of them?
     
  7. abri

    abri MajorGeek

    Hi km!
    You do have malware still, quite a bit, and I want to get back to you as soon as possible with a set of instructions to remove it. Unfortunately, the folder you ran hijackthis from is not the correct one. You ran it from here: C:\Documents and Settings\Jen\Desktop\MGtools\analyse.exe

    Please tell me, for my own information, how you installed it and how you are working on our cleaning procedures? Because you submitted your initial logs in a zip file, I thought you must be working from the new MGTools download, which places the tools in a certain folder under C:\Program Files, however, hijackthis doesn't seem to have been part of the steps you did. In the old procedure here: READ & RUN ME FIRST the instructions for how to properly install and run hijackthis can be found in step 7. You renamed hijackthis.exe to analyse.exe correctly, as per our instructions, but it needs to be run from a HijackThis folder under C:\Program Files. If you don't have a HijackThis folder there, please make one and move analyse.exe to that location. Then rerun it and post the hijackthis.log again. The information we get if you run it from the Desktop isn't adequate. Sorry for this inconvenience.

    abri
     
  8. km7100

    km7100 Private E-2

    hi abri,

    i originally ran hijackthis thru MGtools. I re-ran it from C: rather than desktop, like you asked. Here's the log.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is an issue in the new tools with how the self extracting, autorunning program works. Right now, it will only run properly if the MGtools.exe file is downloaded to the C:\ folder. If downloaded to the Desktop, files will be extracted to and MGtools folder on the Desktop and will run from there but all of the processes and procedures will not work because they need MGtools to be in the root folder of the Windows boot drive (which is normally C:\ ).

    km7100,

    Please move (or redownload) the MGtools.exe to C:\MGtools.exe
    Then double click on the C:\MGtools.exe program to run it.
    This will install it properly and will allow all logs to be automatically obtained including HijackThis. The logs will be in the C:\MGlogs.zip file so attach this new copy.

    Then anytime there after that you need to get logs, just goto the C:\MGtools folder and run the GetLogs.bat file by double clicking on it and it will put all new logs into the MGlogs.zip file.
     
  10. km7100

    km7100 Private E-2

    have mgtools in c: now and reran it. Here are the logs...

    Matt
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks! Sorry for the problems with this! We are still working out the kinks in the new procedures! ;) Now to help you get things fixed on this PC. Continue onto the below.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Remote Logon
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteRLPsvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
    O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0002.exe
    O16 - DPF: {444B911E-6E55-4A11-B3E9-0D3E21AE0437} - http://www.exfol.com/v/1/i/eins005.exe
    O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0002.exe
    O20 - Winlogon Notify: pmnkifg - pmnkifg.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and also the log from Avenger.


    Make sure you tell me how things are working now!
     
  12. km7100

    km7100 Private E-2

    it won't let me stop the Remote Logon Service... the start, stop, pause, resume buttons are greyed out. It will let me change the start-up type... What should I do - should I change the startup type anyways or continue with the rest of the instructions you posted??? Or something else?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below and even if it does not work, just continue on with all other steps.

    Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the quote to Notepad. Save it as "All Files" and name it DelServ.bat Please save it on your desktop.
    Double click DelServ.bat . A window will open and close. This is normal.
     
  14. km7100

    km7100 Private E-2

    ok, ran the DelServ.bat it didn't stop the Remote Logon either but it's gone now after going thru the rest of the steps.

    Here are the logs. The computer seems to be running ok so far. What's the next step?

    Thanks,
    Matt
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks quite a bit better. While I look thru all of the logs (alot to look at), do the below.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.
     
  16. km7100

    km7100 Private E-2

    norton has started popping up messages about finding vondu
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because we are not done yet. We only removed the first wave that was showing in your first set of logs. There was another set of Vundo infections hiding under the surface. The below should finish them off. ;)

    Continue by downloading a tool we will need

    - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    khfeccb.dll
    pmkhi.dll
    xxyaxvw.dll

    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    khfeccb.dll
    pmkhi.dll
    xxyaxvw.dll

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    khfeccb.dll
    pmkhi.dll
    xxyaxvw.dll
    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on lsass.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    khfeccb.dll
    pmkhi.dll
    xxyaxvw.dll
    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on rundll32.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    khfeccb.dll
    pmkhi.dll
    xxyaxvw.dll
    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {05B8F635-1F07-42D0-BAE9-9626F3B618C7} - C:\WINDOWS\system32\khfeccb.dll
    O2 - BHO: (no name) - {50FABE41-5B11-41BC-96E9-BB6E68368FBC} - C:\WINDOWS\system32\pmkhi.dll
    O20 - Winlogon Notify: khfeccb - C:\WINDOWS\SYSTEM32\khfeccb.dll

    After clicking Fix, exit HJT.
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and also the log from Avenger.


    Make sure you tell me how things are working now!
     
  18. km7100

    km7100 Private E-2

    Ok, ran process explorer and killed all the ones you listed. Only problem is that there was no rundll32.exe

    I finished the rest of the steps. Here's the logs. The computer seems to be running much better now.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can find and delete the below two files. Let me know the results.

    C:\WINDOWS\system32\vpzvrjpk.dllbox
    C:\WINDOWS\system32\ihkmp.bak1


    If you get them deleted without any problems then your logs are all clean and you can move on to the below.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    5. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    6. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    7. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    8. If we had you run Avenger, you can delete all files related to Avenger now.
    9. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    10. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    11. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    12. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    13. Go to add/remove programs and uninstall HijackThis.
    14. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    15. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    16. After doing the above, you should work thru the below link:
     
    Last edited: Sep 4, 2008
  20. km7100

    km7100 Private E-2

    Ok, deleted those 2 files. I removed all the extra programs we used to clean the computer. I cleared the restore points. I made sure Spybot S&D, Spyware Blaster, and BOClean are all updated.

    Everything seems to be running great, but when I just ran Spybot S&D it found 2 Vundomonde files. I clicked on fix the problems and it deleted them. Now when I re-scan it with Spybot S&D, it doesn't show any problems. Is the computer still infected or were they just some final left overs from the whole process? I want to make sure it's all clean before I give it back to my friend (she's not very computer literate). Do you need new HJT logs to look at?

    Thanks,
    Matt
     
    Last edited: Oct 21, 2007
  21. abri

    abri MajorGeek

    Hi km!
    Just to make sure, please run Combofix again as per the instructions in the box..
    After you've rerun Combofix, please get another log from ShowNew. The newfiles.txt log from ShowNew is more helpful for this than HijackThis. If you've already uninstalled all the tools, you can download just this one from Step 4 of the READ & RUN ME FIRST, Then please post these logs:

    -combofix.txt
    -newfiles.txt

    abri
     
  22. km7100

    km7100 Private E-2

    Ok, ran combofix. Here are the logs.

    I don't see a "newfiles.txt" log anywhere. It only made the combofix.txt file.
     

    Attached Files:

  23. abri

    abri MajorGeek

    If you've already uninstalled all the tools, you can download ShowNew from Step 4 of the READ & RUN ME FIRST. Then post a fresh ShowNew log which is called newfiles.txt.

    Thanks.
    abri
     
  24. km7100

    km7100 Private E-2

    ok, here's the shownew log

    thanks,
    Matt
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If Spybot is the program reporting Vundo, then you need to see what Spybot is reporting. Often times Spybot just reports some left over registry keys which do not seem to have anything to do with Vundo, and for some reason Spybot cannot remove them while manual steps can. However if Spybot is no longer reporting any issues then there is nothing to be concerned with. Perhaps Spybot was only reporting the two files I asked you to delete in message # 19. They may have still been in your Recycle Bin after deleting them.
     
  26. km7100

    km7100 Private E-2

    Hi....i'm still having problems with Norton and Spybot Search Destroy. Its still saying i have trojan.vundo....i ran combofix and shownew and im going to attach the log. Thanks for your help!
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you definitely have become reinfected. I'm going to give you something to do below, but it will not be a complete fix since we would have needed a whole set of logs to do that. So do the below.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  28. km7100

    km7100 Private E-2

    Well i got to the point where i downloaded The Avenger, but when i copied and pasted everything from the quote box into the box that opened up and i clicked done, an error came up saying, "syntax error in line - does not appear to be a valid registry path. Line will be ignored."
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue with all steps.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds