Trojan on PC (i even know where it is!)

Discussion in 'Malware Help (A Specialist Will Reply)' started by KaisorSoze, May 3, 2010.

  1. KaisorSoze

    KaisorSoze Private E-2

    Hello

    Was searching for a recent anime series and went to some anime online site. For whatever reason, spyblaster was not activated to protect Firefox and got a trojan. It kept saying i need software to fix problems. It block internet access, changed IE to proxy setting, stopped me from playing online MMO, and would not allow me to use task manager. I know location of file (C:\Users\Name\AppData\Local\vjcnkmmtl\vjcnkmml.exe). Currently have CCleaner tools option is blocking it from booting. Logs are attached.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTM by Old Timer and save it to your Desktop.




    Code:
    :Processes
    explorer.exe
    
    :Services
    
    
    :Files
    C:\Users\Dansey\AppData\Local\vjcnkmmtl
    C:\Users\Dansey\Local Settings\TEMP\+EnLGc9q.exe.part
    C:\Users\Dansey\Local Settings\TEMP\fuBm.exe
    C:\Users\Dansey\Local Settings\TEMP\tmpqalkzf
    C:\Users\Dansey\Local Settings\TEMP\V3BSmXAJ.exe.part
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  3. KaisorSoze

    KaisorSoze Private E-2

    Sorry for the long delay. Had an extended vacation from pc. I thought it would be helpful to rerun the malware scans, as others have been using my pc while i was enjoying the sun. Attached are the logs.

    Thanks again and I am sorry for the delay
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you set this:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:54912

    If not, see these instructions:
    Change Proxy Settings.

    Tell me what issues you are having.
     
  5. KaisorSoze

    KaisorSoze Private E-2

    Thanks for fast response. I did not set any proxies. My antivirus program, Avira AntiVir Personal, continues to show the following messages, I would say about once an hour, and within 2-3 minutes of booting up:

    Virus or unwanted program 'TR/Spy.ZBot.akeb [trojan]'
    detected in file 'C:\Users\Dansey\AppData\Roaming\Suhyr\xyefo.exe

    Virus or unwanted program 'TR/Spy.ZBot.akds [trojan]'
    detected in file 'C:\Users\Dansey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ntuser_mssec.exe.

    The first one is seen the most. When i "deny access", it pops up again immediately around 2-3 times, then stops for like 30 minutes to an hour. It seems to show slightly more when closing a browser and reopening a browser. There are other actions to take other than "deny access" which include "ignore", "quarantine," and something else i cannot remember. I tried "quarantine" once, but it didn't improve situation.
     
  6. KaisorSoze

    KaisorSoze Private E-2

    A little more info. With the original post, the trojan horse or virus blocked my internet access. I do not have an issue with blocking internet access. Also, i had pop-up issues as well, which seem to be opening up in IE, which I don't use, but probably came from a different user in my household. Currently, internet is working fine and no pop-up issues, just the repeated pop-up warning about the trojan present.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MBAM found it, but you didnt have it fix it. See your last MBAM log you posted. If these are the only two files that are giving you trouble, then please:




    Code:
    :Processes
    explorer.exe
    
    :Services
    
    :Files
    C:\Users\Dansey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ntuser_mssec.exe
    C:\Users\Dansey\AppData\Roaming\Suhyr\xyefo.exe
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
  8. KaisorSoze

    KaisorSoze Private E-2

    Here is the log. Now, when all is done, can i just delete the programs i was asked to download to fix my problem? And i didnt get the antivirus pop on boot up!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, we will have you remove the various programs, though we suggest you keep SAS and MBAM.

    Good to know you are running well now.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  10. KaisorSoze

    KaisorSoze Private E-2

    Okay, I am going thru the "how to protect yourself from Malware" thread, and I am having trouble finding a firewall for windows 7. any suggestions? also, Microsoft C++ Visual sends me a message everyone and then. Something about it had to be terminate. Should I be worried?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you post in the software forum for those issues. I am not familiar enough yet with Win7 to suggest any firewall software that may be compatible. You may just have to try them out one at a time to see which will work for you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds