Exe with Random name start with windows

Discussion in 'Malware Help (A Specialist Will Reply)' started by pawankr_recd, May 27, 2005.

  1. pawankr_recd

    pawankr_recd Private E-2

    Hi,

    I have found very useful content in this site.

    I have cleaned my system for spywares with the instruction provided, also i have used hijack this and cleaned according to the tutorial. But still i have this problem -

    Whenever i start my system, an exe with some random name (e.g. asddghjf.exe) starts and tries to access the internet(Zone alarm prompt). I can kill this exe by going in task manager and then it won't start unless i restart my system. Other than this i don't see any unusual behaviour (as far i know).

    Please help.

    Thanks

    Pawan
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    if not, please run them. If you already did then complete the steps below.

    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. pawankr_recd

    pawankr_recd Private E-2

    Hi,

    Yes i followed all the steps in the Spyware Removal and Hijack This tutorial and cleaned my system accordingly.

    Please find the attched log.


    Thanks & Regards

    Pawan
     

    Attached Files:

  4. Icelander

    Icelander Private First Class

    I am still learning to read HJT logs, am I right that this is not right?

    O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
    O23 - Service: OracleOraHome92HTTPServer - Unknown owner - C:\oracle\ora92\Apache\Apache\apache.exe" --ntservice (file missing)
    O23 - Service: OracleOraHome92PagingServer - Unknown owner - C:\oracle\ora92/bin/pagntsrv.exe
    O23 - Service: OracleOraHome92SNMPPeerEncapsulator - Unknown owner - C:\oracle\ora92\BIN\ENCSVC.EXE
    O23 - Service: OracleOraHome92SNMPPeerMasterAgent - Unknown owner - C:\oracle\ora92\BIN\AGNTSVC.EXE
    O23 - Service: OracleOraHome92TNSListener - Unknown owner - C:\oracle\ora92\BIN\TNSLSNR.exe

    and

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

    A yes or no will do :p
     
  5. Icelander

    Icelander Private First Class

    Pawan, dont do anything i say. Do only what Chaslang tells you to.

    I am just wondering iff my geusses where right, so i can get better at reading HJT logs.
    I took another look over the log and i think this is not right either:

    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

    Chas, iff you could kindly tell me iff i am right or wrong.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis has a bug that makes it sometimes indicate many O23 items to be (file missing) when they are not. These lines should not be fixed unless they are malware service which is not the case here.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Windows OS and IE versions are way out of date and represent a major security risk. After we fix your current problems you must get updated.

    You MUST remember to exit your browsers before running HijackThis. You had two IE's running:
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKCU\..\Run: [Clock] C:\WINDOWS\xcopy.exe
    O4 - HKCU\..\Run: [wave copy] C:\DOCUME~1\Kumar\APPLIC~1\DUMBEN~1\Seek 32.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\xcopy.exe (note: only delete this one, not the one in c:\windows\system32)
    C:\DOCUME~1\Kumar\APPLIC~1\DUMBEN~1\Seek 32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Do not reboot or power down your PC after posting this HJT log.
     
  8. Icelander

    Icelander Private First Class

    Was i wrong about the oracle things?
     
  9. pawankr_recd

    pawankr_recd Private E-2

    Thanks a lot guys,

    The problem is fixed now. I am attaching my hijack this log again.

    Hey, Cheslang, I want to ask two questions, if you please don't mind.

    1. You mentioned that i should update my OS and IE, can u please give me the url or version number?

    2. Just a little background about me - I am working as a java programmer and have good experience in programming. I really really want to learn about all this and want to help people like me - out there. I want to learn about these spywares, how they get downloaded from the site and how they get activated? about viruses, trojans, worms etc. Can you pls suggest me some good start about this? I am sure you know a lot about this.

    Thanks a lot again.


    Thanks & Regards

    Pawan
     

    Attached Files:

  10. Kiesta

    Kiesta Private E-2

    Responding to question 1:

    There are two ways to check for updates on Windows XP and IE:
    1. Run Windows Update (open Internet Explorer, click the Tools menu, click Windows Update); or
    2. Enable Automatic Updates (right-click My Computer, click Properties, click the Automatic Updates tab).
     
    Last edited: May 30, 2005
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You can update by following the steps in the below thread (you need to make sure you have done all of them). The first step gives the link to Windows Update.

    How to Protect yourself from malware!

    There are many ways to become infected.
    - via a java or vbs script
    - malware downloaded unknowingly
    - via software that contains unwanted malware
    - P2P sites that contain all kinds of infected software
    - the list goes on and on

    The 1st step to prevent problems is to have a properly updated PC that has good protection in place.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Did you read message # 6?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds