C:/system.exe?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hellfire500, Nov 19, 2006.

  1. Hellfire500

    Hellfire500 Private E-2

    Today when I accessed the web page zune-uk.net, a DOS window appeared for a few seconds. I then ran a search to see if any files had been created and discovered that it had made C:/system.exe. I ran a full system scan with NAV & Spyware Doctor but nothing was found. I tried to delete it but just got the message: 'cannot delete system: It is being used by another person or program - close any programs that might be using this file and try again'.
    There is nothing listed in add/remove programs, nor is there anything strange listed in the task manager or the startup tab of msconfig. The most similar trojan I found when I searched the net was the Jginko, but I ran regedit and the entries for it were not there.

    Any ideas?
     
    Last edited by a moderator: Nov 20, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the same procedures that I gave to you last time you came here looking for help. But you never followed up! Do you plan on following thru this time?


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
    Last edited: Nov 20, 2006
  3. Hellfire500

    Hellfire500 Private E-2

    I didn't follow up last time because after looking at the number of applications I would have to install, I decided I might as well reinstall xp. Are there any disadvantages to downloading these tools i.e do they carry any unwanted features such as advertising or cause problems with system speed? Surely if I cannot delete this system.exe file manually these tools won't be able to either?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually that is not really true. Here is a list of all things that must be considered and done if a reinstall is chosen:

    • you have to backup all you own data, settings, configurations etc and first you have to know what/where all of these are. And you have to have the medium (burnable media, second hard drive, tape drive [yuck] )
    • then you must make sure you have the necessary disks to reinstall not just your OS but all other software you use especially protection before going online
    • then fdisk, format, reinstall the OS
    • now reinstall all your software especially protection
    • get online (requires some setup and config that novices have problems with)
    • download updates for OS
    • download updates for protection software
    • download updates for all other software
    • tweak all software back the way you like it. Including Desktop settings, icons etc.
    • create all the folders that you use for everything in your normally routines
    • re-load from your backups to get data back, to get settings, Favorites,.....etc back
    • now over the next two weeks you will realize that you forgot to backup some stuff and also you will keep finding something else that you need to reinstall.

    What kind of malware removal forum do you think this is? We don't recommend tools that put more malware on your PC.

    Not true! And if they do not delete it for any reason, our follow up procedures will delete it.
     
  5. Hellfire500

    Hellfire500 Private E-2

    OK - I'll run all those tools and post the results on sat/sun as I won't have time to run them during the week (work etc).
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure you use the current version of the READ ME which was just changed today. I will edit message number 2 to reflect those changes.
     
  7. Hellfire500

    Hellfire500 Private E-2

    Well, I ran all those tools on my pc and no spyware was picked up (apart from a minor one which only affects Windows 95). I ran bitdefender & panda activescan in normal mode as my firewall wouldn't start up properly in safe mode (I didn't want to take the risk of receiving more trojans).

    I have uploaded the logs from bitdefender, counterspy & panda activescan.
     

    Attached Files:

  8. Hellfire500

    Hellfire500 Private E-2

    Here are the logs of getrunkey, shownew & hijackthis.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your copy of Spyware Doctort a paid or free trial version?

    You can uninstall CounterSpy now which you installed while running the READ ME. We no longer need it and it will expire after 15 days anyway.

    Start by downloading a tools we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 7

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\system.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. Hellfire500

    Hellfire500 Private E-2

    I use a paid version of Spyware Doctor - I've gone as far as the killbox stage where I have gone through the deleting temp files, selected delete on reboot & clicked on all files, but no list of file paths has appeared, so I can't see anything to copy to the clipboard.
     
  11. Hellfire500

    Hellfire500 Private E-2

    I also ran Norton Disk Doctor after I rebooted and corrected 2 indexes - this shouldn't affect the process should it?
     
  12. Hellfire500

    Hellfire500 Private E-2

    Sorry - I misread that instruction! Killbox seems to have deleted C:/system.exe - any idea what it was? I've deleted the backup as well as my system restore files. The getrunkey & shownew logs are attached - are there any precautionary tests to carry out?

    Thanks a lot
     

    Attached Files:

  13. Hellfire500

    Hellfire500 Private E-2

    I just ran a search for files created on the day I was infected, and I noticed the following empty folder: C:/WINDOWS/PIF - should I delete this?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is a valid folder used by Windows.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. Hellfire500

    Hellfire500 Private E-2

    Just one last question - does the registry need to be edited to fully remove fixme.reg or is it fine to just leave it as it is?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you don't need to edit the registry. There is nothing you need to remove from it. You just need to remove the fixme.reg file. That was just a tweak to do what should have been done in step 2 of the READ & RUN ME but was not done properly.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds