Can't kick this VX2 Aurora malware..(All steps done)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Quagmire02, May 26, 2005.

  1. Quagmire02

    Quagmire02 Private E-2

    I completed all the steps in the sticky. Ad-Aware finds 30-40 files of this VX2 Aurora malware, I delete them all and it says it cant delete ALL of them. THis one particular file C:\Windows\System32\drPMon.dll will not go away. After I rescan with Ad-Aware, its still there. Restart my comp and the 30-40 VX2 cohorts are back.

    I tried delting the .dll file itself, and it says access is denied because it may be in use. Ad-Aware detecs the file twice, once as a process. Im guessing its running somewhere, but it doesnt show up in task manager either. I can post a HJT log file with a reviewer's request. I know how to post the way you guys like it (running the exe from the HJT folder, not from desktop and closing down all open programs before scanning).

    So, do I have the go ahead to post the log or does someone already have an answer. Thanks a million times in advance!
     
  2. Quagmire02

    Quagmire02 Private E-2

    I see. So the "wiggygirl" makes a post for help and everyone jumps to be the knight in shining armour to save her PC from spyware.

    Just kidding. Well, no I am not. Guys, plz help. This VX2 thing is really annoying.

    And I know this is a big request...but if you could not only post steps to removing this from my comp but explain WHY it is particularly difficult for me to remove? That would help for future reference and I wont clutter this board with spyware problems :)
     
  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  4. Quagmire02

    Quagmire02 Private E-2

    Thanks!
     

    Attached Files:

  5. Quagmire02

    Quagmire02 Private E-2

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Fisrt, download ABIremover and save it to a location like C:\ABIremove

    NOW:
    Reboot into Safe Mode, be sure you have ALL browsers closed while running this removal tool.

    Next, start the ABIRemover.exe, press install, wait (explorer window will disapear)

    Reboot and procede with the following online scans:

    TrendMicro Online Scan
    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan

    After you have completed the above online scans reboot and post a fresh HJT log.
     
  7. Quagmire02

    Quagmire02 Private E-2

    thanks for responding. i did all that you said. Here is the HJT log and also screen shot of the scan results for the RAV and BitDefender scans.

    The Trend Micro came up with these:

    C:\WINDOWS\svcproc.exe
    C:\WINDOWS\zwttmdhwkx.exe

    And the TrojanScan came up with these:

    C:\WINDOWS\System32\DrPMon.dll
    C:\WINDOWS\System32\tct101.dll

    the other scans I will post as an attachment (screen shots)
     

    Attached Files:

  8. Quagmire02

    Quagmire02 Private E-2

    scans
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Reboot into Safe Mode and run the AVI Remove again. After you install the program reboot and post a fresh HJT log.

    Also, be sure you have System Restore disabled!
     
  10. Quagmire02

    Quagmire02 Private E-2

    System restore is always disabled on my PC

    Here is the new log.
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    O3 - Toolbar: (no name) - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)

    O4 - HKLM\..\Run: [Uninstall_TBPS] C:\WINDOWS\Temp\TBuninst.exe /remove
    O4 - HKLM\..\Run: [tewobq] c:\windows\system32\zfnwaze.exe

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} -%windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Navigate to and DELETE the following if they should remain:

    C:\WINDOWS\System32\zfnwaze.exe

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Good Luck!:)
     
  12. Quagmire02

    Quagmire02 Private E-2

    When I scanned the first time I noticed the nail.exe thing was back. Then I did ther ABI thing again, scanned again, and it was gone. So was that other exe file you told me to remove. Upon the third scan, there is a new exe file in there. I went to the system32 folder and removed the first file you told me to delete.

    Is it possible that whatever is doing this is renaming itself?
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    1) Download TrojanHunter

    2) Install TrojanHunter, At the end of the install setup will prompt you to update definitions. Please do so!

    3) Once installed and updated, select drive C:\ and do a Full Scan. Remove all found infections.

    After you complete the above, reboot and post your results along with a fresh HJT log.

    You MUST get the update for this to successfully remove this pest!
     
  14. Quagmire02

    Quagmire02 Private E-2

    Here is the new log.


    NOTE: I ran the scan and it surely found trojans. When I cleaned them, my spybot S&D alerted me of registry changes: randomly named .exe files added to my system32 folder.

    My guess is that this thing keeps renaming itself and reinstalling once its cleaned. This has happened every time ive scanned, purged, or ran any of this software that is supposed to remove spyware. As I'm typing this, the Aurora window is popping up in my face.

    Thanks for you help, and I hope this information gives you more insight as to what to suggest for me.
     

    Attached Files:

  15. Quagmire02

    Quagmire02 Private E-2

    Also, everytime trojanhunter cleans, It pops right back up saying it found Agent.167 and Spybot aalerts me of a registry change (new .exe file added).
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Reboot into Safe Mode and run the ABI Remover again, after you do this run TrojanHunter once more.

    Before you run TrojanHunter, download the updates below. After download is complete, extract the contents to the installation directory of TrojanHunter.

    Updates!
     
  17. Quagmire02

    Quagmire02 Private E-2

    I rebooted in safe mode. Did exactly what you said. TrojanScanner found one file to be recurring. Its this file:

    O4 - HKLM\..\Run: [duaqiml] c:\windows\system32\iutaydf.exe

    that iutaydf.exe file kept coming back. I had TrojanScanner clean the 19 or so files it came up with, then I rescanned and it showed that same file again.

    I navigated to my windows/system32 folder in the command prompt and i tried deleting it manually (del iutaydf.exe /f /s /q) and it deleted. Ran the scans again and it didnt show up. Ran adaware, spybot and cclean once more before i reboot into regualr mode

    Once in regular mode, I ran TrojanScanner and it didnt see that file. However, I ran HJT right after after and the log came up with that file again.

    O4 - HKLM\..\Run: [duaqiml] c:\windows\system32\iutaydf.exe

    So, I guess it's back. Im posting the log for you. I am stumped at this point.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    FIrst I would disable Spybot's Teatimer because it can sometimes make it difficult to remove problems.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    After doing the above follow the below steps but note that if you have rebooted or powered down the problem may have already mutated and these steps may no longer apply. If that is the case, post a new HJT log and do not power down or reboot afterwards:

    Download Pocket KillBox and extract it to its own folder.

    IMPORTANT: Now print these instruction or copy them locally. I want you to run all of the below steps while physically disconnected from the internet. Do not reconnect until I say to do so. And do not open a browser until I say to.

    OK! Disconnect now before continuing.

    Now run killbox.

    Now, Copy and Paste c:\windows\system32\iutaydf.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    At this point, I want you to pull the power chord to your PC (yes you read that correctly). I want to try to prevent it from spawning on shutdown. Again make sure no browsers are opened and that you are physically disconnected from the internet.

    After reboot run HJT and look for the below line and fix it:
    O4 - HKLM\..\Run: [duaqiml] c:\windows\system32\iutaydf.exe

    Now get a new HJT log. Reconnect to the internet, run your browser and come back here and post the HJT log. Tell us how the above steps went and where things stand now. Remember, if there is still a problem, do not reboot or power down after posting you HJT log.
     
  19. Quagmire02

    Quagmire02 Private E-2

    Did what you said, however KillBox could not find the file!

    I rand my trojanscanner again and nothing is seeing this file anymore except for HJT. I scanned with HJT again and it still shows it. I have not reboot since my last post. It is also not there when i navigate to the folder with win explorer.

    Maybe this thing is waiting to spawn? What do you recommend?
     
  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Procede with Killbox blue or not it will remove it. If you have rebooted dont waste your time because its already mutated.
     
  21. Quagmire02

    Quagmire02 Private E-2

    OK, I have not run into any effects from that file supposedly still being on my computer. Nothing can detect it besides HijackThis, yet I have not had a single aurora popup since. I have not rebooted since either.

    Do you still suggest that when I do finally shut it down that I pull the plug?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would like to see you complete the steps from message # 18 (whether Pocket Killbox finds the file or not).
     
  23. Quagmire02

    Quagmire02 Private E-2

    I completed those steps. I dont seem to have the aurora or nail.exe stuff anymore. Pulling the plug on my system may have broken my DVD burner, however. Upon startup, my system sometimes hangs at the windows loading screen. It just loads forever. Sometimes I get in, however.

    My dvd drive will not open. I press the button and the led flashes and nothing happens. I can open it by sticking a pin in the little hole, but when I put in a new disc it reads nothing. Device manager detects the drive fine, and I've tried uninstalling it both manually and in the device manager. Nothing. Im guessing pulling the plug on sytem might have broken something? I have to remove the drive completely to make windows boot smoothly now.

    Getting power, IDE detecting it, but the damn thing wont open or read discs. All out of the blue since yanking the power cable.

    So, Aurora is gone, and my DVD burner with it.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I cannot say for sure that pulling the power chord did not break the DVD burner, I would not expect that it would. If it has I apologize for that. We have had to use procedures like this many times to kill stubborn malware and we have never had a problem like this occur.

    Did you actually try:
    - uninstalling the drive from Device Manager
    - power down and physically remove the IDE and power cables to the drive
    - now reboot with no drive available
    - now power down and reinsert the IDE and power cables to the DVD drive
    - power backup and enter your system BIOS and make sure it is set to autodetect drives
    - exit BIOS and boot to Windows, does it detect new hardware
    - if so install any drivers necessary from your original disks

    Does any of that help?
     
  25. Quagmire02

    Quagmire02 Private E-2

    So far I have tried all of those things, though not in succession. I uninstalled in device manager but then reinstalled. I unplugged the physical connections and then reinstalled the physical connection. I unplugged the physical connections and reboot with no CD/DVD drive (this is the only way my computer would boot into windows smoothly). I have also checked BIOS.

    In all cases, my computer detected the hard drive perfectly in BIOS, Device Manager, My Computer etc. Also, in all cases, my drive had the same problem: it does not respond to the open/eject button other than the flashing led. It stops flashing and does nothing after about 3 seconds. Even when I force the drive open with the pin, and i insert a disk, the eject button is totally unresponsive. Also, right clicking on the drive in My Computer and seecting "eject" does absolutely nothing. It seems its mechanically unresponsive to eject (other than flashing led) in every facet. And maybe as a result of this, its not reading discs as well. I do not know exactly what triggers CD/DVD drives to work.

    I will try doing what you said in that successive order, but I cannot do the last step because I only have one CD drive.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the CD drive on the Secondary or Primary controller?

    You could also try making it a slave drive with the Hard disk the master both on the Primary Controller. That is assuming you have a cable that has both connectors on it.

    Who makes the DVD burner?
     
  27. Quagmire02

    Quagmire02 Private E-2


    HP dvd writer 200i

    I should note that upon a google search i learned that many people have had a similar problem with the other version of this drive, the 200e, but they all experienced it after installing HPs latest firware...(not my case)

    The drive is on my primary IDE, and its the master. It has worked totally fine like this. My boot order is Floppy>HDD>DVD/CD.

    How do you configure the HDD as the master and the CD ROM as slave on one IDE cable? The physical structure of most ATX cases has bays for CD drives higher than the bays for 3.5" drives, which means you have to use the black connector on the higher device and the grey on the lower..
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your DVD drive is the master on the Primary Controller, I would then assume your hard disk is either a SATA drive or a SCSI drive which means you cannot tie them together. Try putting your burner as the master on the Secondary also try changing the IDE cable, if you have another.
     
  29. Quagmire02

    Quagmire02 Private E-2

    No, my hard disk is IDE. It has worked fine as the slave.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the normal way to set things up. And it slows down your hard disk. Your hard disk should be the master on your primary controller and your CD/DVD drive should be the master on your secondary. However this does not explain why it does not work anymore at all but it does explain why your PC will not boot with the DVD player installed. This is because it is the master. Changing it around will allow your PC to boot properly even if the DVD drive is damaged.
     
  31. Quagmire02

    Quagmire02 Private E-2


    I think I remember doing this because my 2nd IDE channel doesnt detect cd drives. It only seems to detect hard disks.

    Anyways, I had it set up like that before, and windows alway boots fine. Im just attributing it to being a crappy drive. Or maybe my mobo is crappy. I dunno, I bought the mobo brand new. I already ordered a SATA DVD burner as its really a necessity for me to have one. Provided my SATA controllers work, it will kill 2 birds with one stone (HDD can then be the master on Pri IDE and DVD drive will be on SATA and SATA is supposedly hot-swappable [no damaging it from unplugging]).
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That sounds like a defective mother board and could it be that now the Primary does not detect CD drives either?

    I would still suggest that you change the current HD to the master (it must be a master already or you are using cable select) and then set your DVD drive to the slave and put them on the Primary Controller. This will allow Windows to boot and then you can see if the DVD drive will work as a slave.
     
  33. Quagmire02

    Quagmire02 Private E-2

    How do you physically do this when most ATX cases are set up with 5.25 bays higher than 3.5 bays? I HAVE to put the black (master) on the 5.25 and the blue (slave) connector on the 3.5....unless I turn my drives upside down....
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The physical design problem can always be a pain. Sometimes just having properly designed cables and correct cable lengths for you cabinet is the only real easy solution. To first test whether it will even help at all, you can just try leaving the drives in some temporary configuration (however you can safely accomplish this without shorting anything out) that will work to have both drives connected.

    Do you have access to another PC where you can plug in your DVD drive to see if it still functions?
     
  35. Quagmire02

    Quagmire02 Private E-2

    Not readily, but I will sometime this week. Trying it in another PC sounds more do-able. I'm really banking on SATA being an interface that encounters less problems than IDE...

    To me it sounds like a mechanical problem rather than a configuration problem. It's like whatever triggers the little gears to open/close the tray is dead. If it were a config problem, I can't see anything causing the drive to act this way.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be that your Flash firmware took a hit too. That's why I wanted to boot from the hard disk with the DVD drive as a slave ..... so we can check to see if it is seen by the OS and if the firmware version is readable.
     
  37. Quagmire02

    Quagmire02 Private E-2

    I got my SATA drive and hooked it up. Would you believe that the same problem was happening? Everything detected it, but the tray would not open. So I go to the plextor site and troubleshoot the problem. I was getting 5 amber blinking codes when i pressed eject, and that said it was a power problem. So, I open my case, unplug the sata power adapter off the reg power cable and notice i already have sata power cables on my PSU. I plug that in, problem solved. Then I realize that the blinking my HP drive did was also probably a code.

    Im guessing that maybe one of my power cables coming from the PSU is messed. Im going to try reinstalling the HP Drive using a different plug on the PSU, then I will just try using it in another PC.

    What do you think?



     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give it a try. I still do not like the idea of the DVD drive being the master on the HD being a slave on the Primary Controller. Thre recommended configuration for these two items would be:

    Hard Disk master on Primary Controller
    DVD drive master on Secondary Controller.

    Second Choice:
    Hard Disk master on Primary Controller
    DVD drive slave on Primary Controller
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds