benpao virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by T03J4M, Apr 14, 2007.

  1. T03J4M

    T03J4M Private E-2

    i got this norton alert about a program called "e.exe"
    i searched google and found nothing about it, except for this page saying its called benpao
    how do i get rid of this benpao virus?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Indeed that is a trojan and to remove this trojan and any associated malware it may have brought with it please follow the below guide then attach all the logs requested.



    Our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. T03J4M

    T03J4M Private E-2

    ok, after the norton alert popped up, i clicked "block always" for e.exe

    i did part of the avg scan (which found nothing)
    some of the other scans just found cookies and some programs i was using
    here are some log files
    i didnt run all of panda + bit scan, because it said it would take 20 hours
    i still have a log for panda

    but i followed a tutorial online in symantec.com, that showed how to get rid of benpao. i located e.exe, deleted it, checked the registry (as the tutorial said), and to my suprise the registry keys that the tutorial said benpao was going to change werent changed. i guess e.exe really didn't do anything?

    i couldnt run getrunkey + shownew, because when i clicked on the batch files it said "locate.com, grep.com, ltime.com werent located" and they're in the same directory as getrunkey + shownew

    ok heres a log file for panda + hijackthis. on the panda log, theres a thing in the path c\dwh\emulator\evi422path. that's a program i just use.

    sorry i kinda busy right now, so i dont have too much time
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the logs. I see no sign of AVG Antispyware being run!

    You need to run them and attach the logs. Without logs, we cannot help you remove your malare!

    That means you did not follow the directions in the download links for the tools. Again, we need the logs to be able to help you.

    So are we! Sorry no logs no help!

    You even skipped step 2 and step 3 of the READ ME! Did you install AVG Antivirus instead of AVG Antispyware?? If so, uninstall AVG Antivirus and install what we requested in the READ ME. And run a scan and attach a log.
     
    Last edited: Apr 14, 2007
  5. T03J4M

    T03J4M Private E-2

    ok, i did the all the scans, one by one. here are the logs.

    here are some notes:
    -ran in safe mode
    -counterspy didnt have a setting for quarantining what it finds in safe mode
    -spybot: fixed microsoft.windowsscuritycenter.AntiVirusDisableNotify
    microsoft.windowsscuritycenter.FirewallDisableNotify
    microsoft.windowsscuritycenter_disabled
    left SpyArsenal.Homekeylogger (i use this program for my computer)
    -counterspy: ignored homekeylogger, family logger, and event 2442 (i use them for my computer)
    -ran in safe mode with network
    -bitdefender: deleted some of my stuff...
    -panda: all the found stuff had status "not disinfected"
    -getrunkey didnt work
    -shownew didnt work

    getrunkey + shownew didnt work. i read the whole download page, it says "do not open from inside the zip" well i downloaded the programs to one same folder, extracted them both to their own separate folders, i even deleted the zip files, and opened getrunykey/shownew. still says locate/ltime/grep not found, with an empty logfile. i went to the dl page, downloaded the xphome fix, still didnt work. the 2nd error message doesnt happen to me.
     

    Attached Files:

  6. T03J4M

    T03J4M Private E-2

    the hijack this log
     
  7. T03J4M

    T03J4M Private E-2

    ok... whys there no log i already uploaded
    ok heres the hijackthis log
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to be more explicit! We need these logs! You must explain what problems you are having. They are just DOS batch files that will normally run without a problem as long as you follow the directions on the download pages. And also you need to watch for the possible documented error messages.

    You also need to follow the directions in the READ ME.
    • You did not empty your Norton AntiVirus Quarantine as rquested in step 0!
    • You still are violating step 3 of the READ ME. You have both AVG and Symantec antivirus applications installed. You must uninstall one.
    • And I still suspect you did not do step 2 of the READ ME properly which is why your HijackThis executable is named with double extensions (analyse.exe.exe) instead of one extension (analyse.exe). But I cannot tell for sure until I get the GetRunKey log.
     
    Last edited: Apr 16, 2007
  9. T03J4M

    T03J4M Private E-2

    ok i:
    emptied norton antivirus quarantine
    uninstalled AVG
    renamed analyse.exe to analyse (i did step 2, its just that it doesnt show the extension)

    no matter how many times i try getrunkey/shownew, it doesnt work. i've already dl'ed + unzipped + tried them out like 15 times, still shows the same thing.

    picture of error:
    http://img250.imageshack.us/img250/4496/proofyj1.png

    if you want a youtube link showing what i did, ill post the link when it's done processed
    (heres wat i did: went to the dl page - dl'ed program - went to directory - extracted - deleted zip file - double clicked getrunkey)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not show the extension because you did not follow ALL of the directions in step 2! Go back and see for yourself. You are still hiding file extensions!

    That message indicates that you did not extract all the files from the ZIP file or that you are trying to run the batch file from inside of the ZIP file. What folder do you think you extracted all the files to? Right click Start and select Explore. Now in the Windows Explorer window, navigate to the folder where you believe that you extracted GetRunKey.zip to. What files are in the folder? (DO NOT double click on the ZIP file, that will only show you what is in the ZIP file. I want to see what folder you extracted to and what files are in the folder.)
     
  11. T03J4M

    T03J4M Private E-2

    oops double post
     
  12. T03J4M

    T03J4M Private E-2

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the attached MGtools.exe file to your Desktop. And then double click on it to run it. If it works properly you should have the two log files now.


    Note: just close the newfiles.txt log that should popup when it completes. Then look for c:\newfiles.txt and c:\runkeys.txt
    Are the files there? If yes, attach them. If not, did you receive any error messages.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the snapshots you are showing. What is the folder name where you have Ccleaner, GetRunKey, Logfiles, ShowNew and Spybot Search & Destroy showing? Is is C:\DWM2
     
  15. T03J4M

    T03J4M Private E-2

    no it's C:\DWH2

    k downloaded mgtools.exe to desktop, double clicked, and an ms-dos window pops up and disappears 1/2 of a second. i took a snapshot of it, and it just tells the description of the program with no other text. i looked in c:\, but found no newfiles.txt or runkeys.txt. i didnt recieve any error messages
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was a C:\MGTools folder created? And if so, what files do you see in that folder.

    Goto the link for Using GetRunKey and run the fix for the first possible error message (the one with the XPfiles fix). Make sure you allow the program to extract the files in the default folder which is the C:\windows\system32 folder
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also make sure you are not blocking the scripts from running. You antivirus program could be doing that. Shut down Symantec and see what happens.

    Also attach a current HJT log?
     
  18. T03J4M

    T03J4M Private E-2

    yes an MGTools folder was created it contains: GetLogs.bat, Getrunkey.bat, grep.exe, locate.com, ltime.exe, shownew.bat

    i tried the xp fixes (both home and pro) with no success. am i suppose to restart the computer after extracting them?

    i shut down symantec, programs still dont work.

    heres a new hijackthis file
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes a reboot afterwards is recommended?

    What is the below service for?
    O23 - Service: SysEnforce - Unknown owner - C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE (file missing)

    Also what is the below?
    C:\PROGRA~1\Alibaba\TRADEM~1\TradeManager.exe

    From a command prompt, type the below:
    set > c:\env.txt

    This will create a c:\env.txt file. Attach this file here.

    Also please uninstall CounterSpy since we are finished with it now!


    Note: In case you don't know how to get a command prompt:
    click Start, Run and enter cmd and click OK.
     
  20. T03J4M

    T03J4M Private E-2

    O23 - Service: SysEnforce - Unknown owner - C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE (file missing)[/B] is a spyware program i downloaded when i got e.exe, but i uninstalled it the day i installed it. how do i remove it?

    C:\PROGRA~1\Alibaba\TRADEM~1\TradeManager.exe is a program

    heres the txt file

    k i uninstalled counterspy. should i stil work on trying on getrunkey
     

    Attached Files:

    • env.txt
      File size:
      1.2 KB
      Views:
      1
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SysEnforce
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSysEnforce into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot
    After reboot, check your HJT log! Is the below line now gone?

    O23 - Service: SysEnforce - Unknown owner - C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE (file missing)

    I'm still baffled why GetRunKey and ShowNew will not run. Unless for some reason it runs now after uninstalling CounterSpy and fixing the above!

    Are you having any problems at the current time?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In your environment Path, I see the below:

    C:\PROGRA~1\COMMON~1\MUVEET~1\030625;C:\PROGRA~1\COMMON~1\MUVEET~1\030625

    Do you know what these are for? What is MUVEET~1 which is an abbreviation for a longer folder name. The folder is in c:\Program Files\Common Files What is it and what is in the folder? Also there is a space in your PATH which is not allowed! We need to fix this and also maybe delete the above if they are unknown.
     
  23. T03J4M

    T03J4M Private E-2

    when i went to sysnenforce properties, service was already stopped.
    yes 23 service: sysenforce is now gone
    after rebooting, i still have no luck with getunkey

    C:\PROGRA~1\COMMON~1\MUVEET~1\030625;C:\PROGRA~1\COMMON~1\MUVEET~1\030625
    it's a pogram called Muvee Technolgies, it's a movie maker that came with my xp media center

    right now, i dont have any problems. thanks for your time and help! :cool
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds