Trojan.Downloader.Small.CML Need HELP

Discussion in 'Malware Help (A Specialist Will Reply)' started by ROADRUNNER420, Mar 15, 2007.

  1. ROADRUNNER420

    ROADRUNNER420 Private E-2

    i got this trojan :cry need help getting reid of it. here is my hijackthis file.

    i dont know if i'm doin this right but here it is..


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Mar 15, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. ROADRUNNER420

    ROADRUNNER420 Private E-2

    Hello again i'm back from the long READ & RUN ME FIRST MISSION:major .
    Will post everything that was ran in order as asked.
    :( CounterSpy - could not run it.
    :) AVG Antispyware log - could not run counterSpy so i ran this.
    zzz BitDefender - it ran for a long time.
    :) PandaActiveScan.
    :) GetRunKey - done NP.
    :) ShowNew - done NP.
    :) HijackThis log - did it after all the above.
     

    Attached Files:

  4. ROADRUNNER420

    ROADRUNNER420 Private E-2

    :major here is the res of the logs
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run AVG Antispyware again and this time fix what it finds. The purpose of running the tools is to fix the problems and to make manual cleanup easier. Attach a new log from AVG Antispyware that shows the results of fixing (i.e., Quarantining, Cleaning, or Deleting).

    Then run this Virtumonde aka Trojan Vundo Removal and attach the requested log.

    The continue with the below:
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also then attach new logs from ShowNew and HJT.

    To itemize the logs required
    1. new AVG Antispyware log
    2. VundoFix
    3. ComboFix
    4. ShowNew
    5. HJT
     
  6. ROADRUNNER420

    ROADRUNNER420 Private E-2

    here it is redone. after running the vundofix had all kinds of problem -- it would not load anything i had to use task manager to run the rest of the programs. i dont have a toolbar @ all . like i said i been using windows task manager to run and open files :major
     

    Attached Files:

  7. ROADRUNNER420

    ROADRUNNER420 Private E-2

    the rest
     

    Attached Files:

  8. ROADRUNNER420

    ROADRUNNER420 Private E-2

    ok my rundll32 is gone it can find it
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must follow the directions on the download pages for both ShowNew and GetRunKey. You are not running them properly or you are getting one of the mentioned error messages that must be addressed. Do you see any messages in the command prompt window that comes up??? You must makes sure that you extract ALL files from the ZIP file and run the .bat files from outside of the ZIP file. Do not attach new logs yet though! First do the below!

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03
    Java 2 Runtime Environment, SE v1.4.2_06
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winbjv32.dll once and then click the kill button. After you have killed all of the winbjv32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ddcyx.dll
    gebyx.dll
    cbxvtss.dll

    Next double click on explorer.exe and again click once on each instance of winbjv32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ddcyx.dll
    gebyx.dll
    cbxvtss.dll
    Next double click on iexplore.exe and again click once on each instance of winbjv32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ddcyx.dll
    gebyx.dll
    cbxvtss.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - (no file)
    O2 - BHO: (no name) - {14118322-94AE-4E9D-8305-97CFCD5578Aa} - C:\WINDOWS\system32\jahojosp.dll
    O2 - BHO: (no name) - {3A7467BE-208F-4827-B22E-BBCBD1CDA90E} - (no file)
    O2 - BHO: (no name) - {3AB9E19E-5075-7ED9-7361-75B26B69849D} - C:\WINDOWS\system32\efehfc.dll
    O2 - BHO: (no name) - {4A23487A-F321-4648-297C-05E10205658F} - C:\WINDOWS\system32\wsjgczc.dll (file missing)
    O2 - BHO: (no name) - {593E7D90-5F97-4309-A76C-2739FA33BB4A} - (no file)
    O2 - BHO: (no name) - {9CC9CF27-E0DC-44CF-B76C-0C3C70F0B074} - C:\WINDOWS\system32\opnmnmk.dll (file missing)
    O2 - BHO: Internet Security Class - {A75E294E-C047-4D29-B07E-37B792881BEF} - C:\WINDOWS\SecureWin31.dll (file missing)
    O2 - BHO: (no name) - {E6C54560-D0D2-4CE1-95D2-C06FBD036A1D} - C:\WINDOWS\system32\mlljk.dll (file missing)
    O2 - BHO: (no name) - {F6643D11-1B9D-400C-AE29-404B4E6E2469} - (no file)
    O3 - Toolbar: (no name) - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\cxxhsaxb.dll",setvm
    O4 - HKCU\..\Run: [Nmoa] "C:\DOCUME~1\ROADRU~1\APPLIC~1\YSTEM~1\services.exe" -vt yazb
    O4 - HKCU\..\Run: [Mkbz] "C:\WINDOWS\system32\?dobe\?serinit.exe" 99001162
    O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
    O4 - HKCU\..\Run: [ofuq] C:\PROGRA~1\COMMON~1\ofuq\ofuqm.exe
    O20 - Winlogon Notify: cbxvtss - cbxvtss.dll (file missing)
    O20 - Winlogon Notify: ddcyx - C:\WINDOWS\
    O20 - Winlogon Notify: gebyx - C:\WINDOWS\
    O20 - Winlogon Notify: winbjv32 - C:\WINDOWS\SYSTEM32\winbjv32.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\cxxhsaxb.dll
    C:\WINDOWS\system32\ddcyx.dll
    C:\WINDOWS\system32\efehfc.dll
    C:\WINDOWS\system32\jahojosp.dll
    C:\WINDOWS\system32\opnmnmk.dll
    C:\WINDOWS\system32\winbjv32.dll
    C:\WINDOWS\system32\wnscpsv32.exe
    C:\WINDOWS\system32\xsmicdbj.dll
    C:\WINDOWS\system32\yayvvst.dll
    C:\WINDOWS\svchost.exe
    C:\xgsljlcc.exe
    C:\vwws.exe
    C:\uwfqp.exe
    C:\tmlkv.exe
    C:\hmpoi.exe
    C:\gqefdh.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\Program Files\Common Files\ofuq
    C:\Program Files\Ipwindows
    C:\Program Files\VSAdd-in
    C:\WINDOWS\ofuq

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey - make sure you install and run properly
    2. ShowNew - make sure you install and run properly
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. ROADRUNNER420

    ROADRUNNER420 Private E-2

    Well here is the new logs. One thing that i get is this error when i run GetRunKey and ShowNew but i still can get the log----

    16 bit MS-DOS Subsystem
    c:\windows\system32\cmd.exe
    c:\progra~1\\Symantec\s32evnt1.dll. An installable Virtual Device Driver failed DLL initialization.
    choose 'close' to terminate the application.

    how is my pc running? not good i have no toolbar , pc wont connect to printer anymore, missing my Network Connections so i can not get online. I been opening everything by window task manager - ctrl, alt,delete.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but they are incomplete. Read the download pages for GetRunKey and ShowNew again. This error message is explained and must be fixed. Then attach new logs.

    What toolbar or do you mean Taskbar and Start button.

    Does c:\windows\system32\rundll32.exe exist? If not, search your PC for rundll32 (without the .exe) and tell me what you find.
     
  12. ROADRUNNER420

    ROADRUNNER420 Private E-2

    correct i dont have Taskbar and Start button plus i'm missing My Network Places so i cant connect to the internet.Printer has something missing it wont let me print. Let me fix the last post . i was missing rundll32 but fond and put it in c:\windows\system32\rundll32.exe .. I will rerun your last post just to be safe and get it right..
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, just attach the new logs after you rerun everything. Make sure you fix the errors because we need complete logs.

    Based on your problem description, it sounds like your Windows shell (explorer.exe) is not running at startup. But I do see it in your HJT log. Use Task Manager to run explorer.exe Does that bring back your Desktop or is explorer.exe not found?
     
  14. ROADRUNNER420

    ROADRUNNER420 Private E-2

    ok here are the new logs now i did not have any error when i run GetRunKey and ShowNew . When you say
    i hope i have it done this time, if not then i'm not sure how to fix them confused .
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you did it right this time! However you need to address the question in my last message:
     
  16. ROADRUNNER420

    ROADRUNNER420 Private E-2

    explorer.exe is in the files but i don't get my start taskbar. it seams that my pc is running really slow. I can see my desktop but not my start taskbar.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {DEC99D6A-BDDD-48D7-87F8-C1E020A615CB} - C:\WINDOWS\system32\tuvwurq.dll (file missing)
    O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvgad.dll,startup
    O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O20 - Winlogon Notify: tuvwurq - tuvwurq.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure you verify that you get a message stating that the above registry patch was added into the registry successfully. Tell me what happens when you return!!


    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\Downloaded Program Files\WinStatX.dll
    C:\WINDOWS\svchost.exe
    C:\WINDOWS\system32\drvgad.dll
    C:\WINDOWS\system32\bxashxxc.ini
    C:\WINDOWS\system32\moemcqka.ini
    C:\WINDOWS\system32\v6.exe
    C:\Program Files\Common Files\svchost.exe
    C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Common Files\{28477A88-074E-1033-1224-200312220001}

    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  18. ROADRUNNER420

    ROADRUNNER420 Private E-2

    Ok back again, i ran everything with out a problem. one thing that i should of mention is that pc is running slow, it load really slow. After doing the last tasks, i reboot and took like 10 min or more to load my desktop but without my start taskbar. i still cant run my printer-error
    but i did have my printer install. One thing that i notice on my desktop is
    .
    Well i'm not sure what els is wrong right now but the new logs are her.
     

    Attached Files:

  19. ROADRUNNER420

    ROADRUNNER420 Private E-2

    I forgot to mention the other error -
    . i'm still missing my files in My Network Places
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Add/Remove programs and uninstall the below malware:
    OIN
    Outerinfo

    Also uninstall SUPERAntiSpyware.com (not malware but you are complaining about performance and already have AVG Antispyware running).

    What is in the below folder?
    Code:
    C:\Documents and Settings\
    WINUPD~1      Mar  6 2006              "win update"
    Delete the below folders since you don't have Symantec installed anymore.
    C:\Program Files\Symantec
    C:\Program Files\Common Files\Symantec Shared

    Run HJT and fix the below unnecssary startup from Sun Java:
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"


    Anything else impacting speed is probably not malware but just rather what you are running at startup especially all the McAfee stuff. And McAfee may even be the root of your problems. You may want to try uninstalling it at least as a test.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oops! I forgot the below!


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure you tell me whether you get a success message about the above being added to the registry. Some fixes do not seem to be working. I'm wondering if McAfee is blocking them.

    Attach a new log from GetRunKey.
     
  22. ROADRUNNER420

    ROADRUNNER420 Private E-2

    Here is the log. One thing i notice is that in add/remove that alot of my programs dont have the side of the program. So it means that they are not install anymore? including sp2.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you are trying to say by the "side of the program". Please explain more clearly what you are trying to tell me; however, note I really believe you have a lot more problems with your OS that are not malware related. You seem to have all kinds of issues cropping up.

    It may be best if you work up a full list of your current problems and post them in the Software Forum. But I would like to have you run the below first.


    Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.


    Then also run sfc /scannow from a command prompt window (click Start, Run and enter cmd and click OK to open a command prompt window). Does this find any missing or corrupted files. It may ask for your Windows CD so have it ready.


    There are also 2 registry keys that sometimes cause this problem with Explore.exe not running. We are going to look for and delete these keys (if found).

    Press CTRL-ALT-DEL to bring up Task Manager. And click File, New Task (Run..) and enter regedit and click OK. This will run the registry editor. Now look for the below registry keys (navigate thru the registry). Make sure you only look for and delete the exact keys listed below.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplorer.exe

    After deleting these keys the desktop and explorer.exe should reappear if this is the cause of your problems. You may need to reboot after doing this. Let me know the results.


    Also check this link out: Taskbar Is Missing When You Log On to Windows
     
  24. ROADRUNNER420

    ROADRUNNER420 Private E-2

    here is the log . the regedit registry keys not found @ registry.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my question about running sf /scannow

    Also did you look at that other link I gave you on missing Taskbar?
     
  26. ROADRUNNER420

    ROADRUNNER420 Private E-2

    Well i did go to the other site you gave me. Anyway, I thank you for the help. I'm goin to reinstall everything so i'm starting to back my files. One thing i would like to ask you --- to better protect my pc from viruses, trojans etc.. what programs do you recommend? What program should i ran in a everyday or week task. Ones more i thank you for the help..:)
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds