Help please! Trojan Horse LopZ keeps appearing in WINDOWS/system32

Discussion in 'Malware Help (A Specialist Will Reply)' started by marro, Aug 30, 2006.

  1. marro

    marro Private E-2

    Hi, hoping desperately someone out there can help me! I acquired some viruses a couple of days ago, having accidentally opened WINANTIVIRUSPRO2006 (it was hiding behind another window and I clicked the wrong one). I normally use AVG, and I also ran several different spyware removal programs on it – they all picked up various problems and healed them, but they just kept coming back – mainly Trojan Horses of various descriptions.

    In looking for help I came across your site, and have now followed the procedure in READ & RUN ME FIRST. In safe mode everything was fine, and no problems were found. I couldn’t connect to the internet in safe mode to run bitdefender and panda, and as soon as I re-booted in normal mode and went online I started having a different problem. Whatever is still in my system is now putting dlls, all the same size (561kb) into my WINDOWS/system32 folder, all infected with Trojan Horse LopZ. This started while I was running bitdefender. AVG picks them up, heals them, and 2 minutes later it happens again. If I leave them unhealed, within 10 minutes there are about 30 new dlls created!

    I’m normally ok at sorting out problems with my system, but I don’t know what to do with this one. I've attached logfiles as suggested and I'd be grateful for any advice or help available.

    Cheers, Marilyn
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to attach the other two logs that were requested in the READ ME.

    runkeys.txt - the log from GetRunKey.bat
    newfiles.txt - the log from ShowNew.bat


    Is your copy of Spyware Doctor a paid version or a free trial version?
     
  3. marro

    marro Private E-2

    Thanks for the reply. The two other logs are attached here. It's a paid version of spyware doctor. Since original post I've run several spyware scans again, and the spyware programs aren't picking up anything now, but whatever it is is still creating these dll files in the system32 directory, which are picked up by AVG as LopZ. It mainly happens while i'm connected to the net. Hope you can help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are your copies of Spyware Doctor and Ewido free trials or paid versions?

    When you obtained your HijackThis log you did not follow the directions in step 7 of the READ ME. You are using MSconfig and are in Selective Startup mode. You must be in Normal Startup mode. Do not confuse the words Normal Startup with normal boot mode. They do not mean the same thing. My procedure below should automatically correct this, but from now on do not use MSconfig unless requested to do so.
    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of cbxyaba.dll once and then click the kill button. After you have killed all of the cbxyaba.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    pmkhh.dll

    Next double click on explorer.exe and again click once on each instance of cbxyaba.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    pmkhh.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {668B1E21-4DE0-450A-AB10-121220442EA6} - C:\WINDOWS\system32\cbxyaba.dll
    O2 - BHO: (no name) - {D044F908-B5C5-4304-A851-5FC67C6B4332} - C:\WINDOWS\system32\pmkhh.dll (file missing)
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O20 - Winlogon Notify: cbxyaba - C:\WINDOWS\SYSTEM32\cbxyaba.dll
    O20 - Winlogon Notify: pmkhh - C:\WINDOWS\system32\pmkhh.dll (file missing)
    O23 - Service: Inpppma - Unknown owner - (no file)


    After clicking Fix, exit HJT.


    Now we need to remove about 165 files on you PC that are infected by Virtumonde and Winlogonhook
    • Please download the attached Vfix.zip file and extract it to your Desktop.
    • Open the Vfix Folder on your Desktop and DoubleClick on Vfix.bat to run the fix.
    • A log file named vfixlog.txt will be created in the Vfix folder. I will ask you to attach it later.
    Now run Ccleaner!

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Windows\system32\cbxyaba.dll
    C:\Windows\system32\fcccdba.dll
    C:\Windows\system32\fccywuv.dll
    C:\Windows\system32\nnnkiji.dll

    If Killbox does not reboot or if you get a Pending Operations type error message just click OK to continue and then just reboot your PC yourself.


    After reboot also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\HP_Owner\Local Settings\Temp\



    Now attach the below logs to your next message.
    - thevfixlog.txt log.
    - a new log from ShowNew
    - a new log from GetRunKey
    - a new HJT log

    Please tell me how the steps went.

    Make sure you also tell me how things are working now!
     

    Attached Files:

    Last edited: Sep 2, 2006
  5. marro

    marro Private E-2

    Thanks so much for your reply - sorry, I'd forgotten I was in se;ective startup. I've worked through the steps up to where I have to use Vfix, but you don't seem to have attached the Vfix file. I've searched on the site to see if I can find a download, but can't, so i've come to a bit of a full stop! Just to keep you informed of progress so far - there were no instances of cbxyaba.dll and pmkhh.dll found when I ran Process Explorer and when I ran Hijack This 2 of the lines you quoted didn't appear either:
    O2 - BHO: (no name) - {668B1E21-4DE0-450A-AB10-121220442EA6} - C:\WINDOWS\system32\cbxyaba.dll
    and
    O20 - Winlogon Notify: cbxyaba - C:\WINDOWS\SYSTEM32\cbxyaba.dll
    Hope to hear back from you soon so I can finish the process.
    And thanks a lot again
     
    Last edited by a moderator: Sep 2, 2006
  6. marro

    marro Private E-2

    Also, I forgot to say - Spyware Doctor is a paid version, Ewido is a free trial version. Things seem to be a bit more settled, but there are still about 20 or 30 of these strange dlls again in the system32 folder - as soon as I open the folder AVG pops up again and tells me I have LopZ in these files. They all have strange names like the two you mention in your post which I couldn't find. Will this affect what I need to do next when I get the VFix? Wondered if I needed to paste all of them into Killbox, or just the ones mention in your instructions? Once again, thanks a lot for your help
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! I have attached it to that procedure now. Please complete the whole procedure.
     
  8. marro

    marro Private E-2

    Hi there and thanks for attaching the file. I've now run through the procedure. The files cbxyaba.dll and pmkhh.dll weren't found when I ran Process Explorer. All the dlls you asked me to delete with VFix were there and have been deleted, and I've attached the vfix log and a new log from ShowNew and GetRun Key. I'll send another message following this with the HijackThis Log.

    There are still about 10 - 20 of these DLLs in the system32 folder and every time I open the system32 folder AVG still pops up to say it has detected LopZ in the files. They all have these names with several repeated letters and they're all the same size - 561KB. Even after rebooting, having followed the procedure, I looked in system32 and they were still there - or maybe even some new ones. Do I need to go through the same process and delete all these with Killbox as well?

    I really appreciate your help - I feel as though something is happening, but I'm not quite getting rid of everything! Look forward to hearing from you again soon
     

    Attached Files:

  9. marro

    marro Private E-2

    Here is the HJT log to go with the previous post
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Inpppma ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Inpppma

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Since you have a paid version of Spyware Doctor, uninstall both of the below:
    ewido anti-spyware 4.0
    Windows Defender

    Also while in Add/Remove programs also uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0
    Mozilla Firefox (1.5.0.1)

    Then install the current version of FireFox from: Mozilla Firefox

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to
    "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {F98F4A7D-E361-4316-845E-A31866D92752} - C:\WINDOWS\system32\geede.dll (file missing)
    O23 - Service: Inpppma - Unknown owner - (no file) <--- this should be gone already if the above steps worked


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\\Common Files\{00A9EB8B-0C81-2057-0930-05051005002c} <--- the whole folder:
    C:\WINDOWS\system32\ddcyv.dll
    C:\WINDOWS\system32\jkhhh.dll
    C:\WINDOWS\system32\jkkjg.dll
    C:\WINDOWS\system32\pmkjh.dll
    C:\WINDOWS\system32\pmnli.dll
    C:\WINDOWS\system32\ssqpp.dll
    C:\WINDOWS\system32\ssqpq.dll
    C:\WINDOWS\system32\ssttu.dll
    C:\WINDOWS\system32\vtsqo.dll
    C:\WINDOWS\system32\vtstr.dll
    C:\WINDOWS\system32\vtstu.dll
    C:\WINDOWS\system32\hhkmp.ini

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\HP_Owner\Local Settings\Temp


    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now reboot in normal mode and post a new HJT log.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. marro

    marro Private E-2

    Hi again

    Have followed all the new steps and attach the 3 logs you've asked for. I did an AVG full scan afterwards and it didn't pick anything up at all - which all seemed really promising, until about 10 minutes after it finished, and then I started getting AVG messages that this same LopZ was in various system restore files. So I turned off system restore and rebooted, and am hoping this has now sorted it out! Please let me know if there's anything else I need to do. And thanks so much again for giving up your time to help
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that was going to be part of my final steps (as mentioned in the READ ME). So since you already did it, we can skip it an move on to next stage.

    Your log is clean. If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     
  13. marro

    marro Private E-2

    Thanks again for all your help - all seems to be fine
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds