Help! Trojan.Win32.BHO.yr

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by luisomar067, Nov 23, 2007.

  1. luisomar067

    luisomar067 Private E-2

    kaspersky finds that trojan in c:\windows\system32\ddem.dll and is not able to delete it. i tried deleting it manually in safe mode but no joy.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. luisomar067

    luisomar067 Private E-2

    here are the logs. counterspy wouldn't let me save a report in safe mode so im running it in normal mode right now. will post the log as soon as is done.
     

    Attached Files:

  4. luisomar067

    luisomar067 Private E-2

    logs
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You ran the wrong procedure. You should have clicked the link I gave you in message # 2 and followed those instructions. It would have saved you a lot of work as it is a newer and faster procedure. Don't worry about it now. I'm reviewing your logs now.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you put all of those JPG image files in your C:\Windows folder on Nov 22? If not, you should delete them. I refer to the below:
    Code:
    "C:\WINDOWS\"
    1-r778.jpg    Nov 22 2007        2351  "1-r778.jpg"
    1-suctb.jpg   Nov 22 2007        2967  "1-sucTB.jpg"
    10-5z5~1.jpg  Nov 22 2007        2609  "10-5z5-r7c.jpg"
    11-ptx~1.jpg  Nov 22 2007        3478  "11-pTX263.jpg"
    12-ys-~1.jpg  Nov 22 2007        2605  "12-ys--rc7.jpg"
    13-ynxp.jpg   Nov 22 2007        2103  "13-ynXp.jpg"
    14-elt~1.jpg  Nov 22 2007        2967  "14-eLTLrX.jpg"
    15-ymvfv.jpg  Nov 22 2007        2920  "15-yMVFV.jpg"
    16-ntw~1.jpg  Nov 22 2007        3581  "16-nTw-8y4.jpg"
    17-8bm~1.jpg  Nov 22 2007        3327  "17-8BM7uy.jpg"
    18-cwj~1.jpg  Nov 22 2007        3082  "18-cwJMpH.jpg"
    19-g7vsd.jpg  Nov 22 2007        3113  "19-G7Vsd.jpg"
    2-al8b.jpg    Nov 22 2007        3050  "2-AL8B.jpg"
    20-8b6b.jpg   Nov 22 2007        2562  "20-8B6B.jpg"
    21-c6exg.jpg  Nov 22 2007        2541  "21-c6eXG.jpg"
    22-7an~1.jpg  Nov 22 2007        3722  "22-7AnBpX6.jpg"
    23-kab~1.jpg  Nov 22 2007        3389  "23-KABMpy.jpg"
    24-b-fzv.jpg  Nov 22 2007        2392  "24-B-FzV.jpg"
    25-ce2k.jpg   Nov 22 2007        2158  "25-ce2K.jpg"
    26-alvvt.jpg  Nov 22 2007        2744  "26-ALVVT.jpg"
    27-6mjhb.jpg  Nov 22 2007        2862  "27-6MJHB.jpg"
    28-jeg~1.jpg  Nov 22 2007        3429  "28-JeGBep.jpg"
    29-887-r.jpg  Nov 22 2007        2317  "29-887-r.jpg"
    3-akr5hm.jpg  Nov 22 2007        3530  "3-AKr5HM.jpg"
    30-rm4~1.jpg  Nov 22 2007        3437  "30-rM47FV.jpg"
    31-bjrj8.jpg  Nov 22 2007        2113  "31-BJrJ8.jpg"
    32-yftnh.jpg  Nov 22 2007        2806  "32-yFTnH.jpg"
    33-rjrbv.jpg  Nov 22 2007        2745  "33-rJrBV.jpg"
    34-rwbm2.jpg  Nov 22 2007        3011  "34-rwBM2.jpg"
    35-r6r~1.jpg  Nov 22 2007        2796  "35-r6rr3p.jpg"
    36-juy~1.jpg  Nov 22 2007        3213  "36-JuycBn.jpg"
    37-ctc~1.jpg  Nov 22 2007        3405  "37-cTcd25.jpg"
    38-g4c~1.jpg  Nov 22 2007        2862  "38-G4crrG.jpg"
    39-ya-~1.jpg  Nov 22 2007        3119  "39-yA-crXJ.jpg"
    4-w-a2w.jpg   Nov 22 2007        2950  "4-w-A2w.jpg"
    40-k27~1.jpg  Nov 22 2007        2353  "40-K27wzu.jpg"
    41-e8j3.jpg   Nov 22 2007        2768  "41-e8J3.jpg"
    42-g83~1.jpg  Nov 22 2007        3276  "42-G8363X.jpg"
    43-knt~1.jpg  Nov 22 2007        2644  "43-KnT-2d.jpg"
    44-lz78-.jpg  Nov 22 2007        2360  "44-Lz78-.jpg"
    45-ebkv.jpg   Nov 22 2007        3011  "45-eBKV.jpg"
    46-stp~1.jpg  Nov 22 2007        2925  "46-sTpFpr.jpg"
    47-rrcw7.jpg  Nov 22 2007        2128  "47-rrcw7.jpg"
    48-u2bh.jpg   Nov 22 2007        2432  "48-u2BH.jpg"
    49-4ft~1.jpg  Nov 22 2007        3519  "49-4FTGBs.jpg"
    5-2wba.jpg    Nov 22 2007        2791  "5-2wBA.jpg"
    50-cp-~1.jpg  Nov 22 2007        2285  "50-cp-z-d.jpg"
    51-krbm.jpg   Nov 22 2007        2568  "51-KrBM.jpg"
    52-chcb6.jpg  Nov 22 2007        2732  "52-cHcB6.jpg"
    53-n2jup.jpg  Nov 22 2007        2801  "53-n2Jup.jpg"
    54-g-p~1.jpg  Nov 22 2007        3395  "54-G-p4e2A.jpg"
    55-n4fd5.jpg  Nov 22 2007        2760  "55-n4Fd5.jpg"
    56-3zct.jpg   Nov 22 2007        2101  "56-3zcT.jpg"
    57-7uchr.jpg  Nov 22 2007        3070  "57-7ucHr.jpg"
    58-78mvj.jpg  Nov 22 2007        2995  "58-78MVJ.jpg"
    59-f6w~1.jpg  Nov 22 2007        2953  "59-F6weyV.jpg"
    6-slpn.jpg    Nov 22 2007        2201  "6-sLpn.jpg"
    60--yr~1.jpg  Nov 22 2007        3136  "60--yrV6V.jpg"
    61-2vu~1.jpg  Nov 22 2007        3669  "61-2Vun5y.jpg"
    62-kv7uw.jpg  Nov 22 2007        2899  "62-KV7uw.jpg"
    63-7xf77.jpg  Nov 22 2007        2890  "63-7XF77.jpg"
    64-7bk6j.jpg  Nov 22 2007        2923  "64-7BK6J.jpg"
    65-p2bt.jpg   Nov 22 2007        2362  "65-p2BT.jpg"
    7-hvj8.jpg    Nov 22 2007        2749  "7-HVJ8.jpg"
    8-z562.jpg    Nov 22 2007        1922  "8-z562.jpg"
    9-ky2tn.jpg   Nov 22 2007        2682  "9-Ky2Tn.jpg"
    And if you did put them here, WHY???

    Do you know what the below folder are for?
    Code:
    C:\Program Files\
    DAMTWPGM      Nov 19 2007              "Damtwpgm"
    WINQFX~1      Nov 22 2007              "winqfx16bit"
    ZRNCRMQX      Nov 22 2007              "Zrncrmqx"
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {33033D4C-A0BD-49CB-AEBE-6A6A694D1787} - C:\WINDOWS\system32\ddem.dll
    O2 - BHO: {e3c56cf2-1891-4a0a-09f4-aaa091bc8d39} - {93d8cb19-0aaa-4f90-a0a4-19812fc65c3e} - C:\WINDOWS\system32\xqjymycr.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NvMainApp] "C:\Documents and Settings\All Users\Application Data\nvapp.exe"
    O4 - HKCU\..\Run: [Microsoft all] C:\WINDOWS\mmall.exe
    O20 - Winlogon Notify: cryptnet32 - C:\WINDOWS\SYSTEM32\cryptnet32.dll
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  7. luisomar067

    luisomar067 Private E-2

    i didnt put those jpgs there, i deleted them. dont know what those folders are, deleted them. the avenger gave me an error when i ran it, i had to click cancel cause try again or continue would not work(pic attached). after doing all the steps kaspersky is still finding the trojan.
     

    Attached Files:

  8. luisomar067

    luisomar067 Private E-2

    rest of the logs.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually Avenger worked but it was not able to remove everything which is why Kaspersky is still seeing the malware. I will work up a different fix to try and remove this.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'm going to need more info before trying to fix this.

    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run this Running GMER to detect rootkits


    Now attach the logs from ComboFix and GMER
     
  11. luisomar067

    luisomar067 Private E-2

    logs. had to compress the gmer log cause it said it was to big.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below procedure assumes that you have combofix.exe on your Desktop as previously requested. If it is not on your Desktop, you must put it on your Desktop.

    Print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFScript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have the below icons on your Desktop (double click the thumbnail to expand it)
    CFScript.jpg
    • Now refer to the above image and use your mouse to drag CFScript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now delete the below folders:
    C:\Temp\abW9
    C:\Documents and Settings\Tammy\Application Data\Sunbelt Software

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now attach the below new logs and tell me how the above steps went.
    1. ComboFix log
    2. new GetRunKey
    3. new ShowNew
    4. new HJT
    Make sure you tell me how things are working now!
     
  13. luisomar067

    luisomar067 Private E-2

    You're the man! Thanks. Trojan seems to be gone. Now im getting a rundll error(pic attached) at start up. also i attached the logs for the other account to make sure its clean too. Again, thanks. appreciate you taking your time to help me and everyone here.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because a file for your Dell printer is missing. It is trying to load at startup. If you need this, you may need to reinstall the software for it.

    Please run HijackThis on the first user account and have it fix the below two lines:
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O20 - Winlogon Notify: cryptnet32 - cryptnet32.dll (file missing)

    I still see the below folder. Did you forget to delete it?
    C:\Temp\abW9

    Then attach a new HijackThis log. I want to finish this user account before looking at the other.
     
  15. luisomar067

    luisomar067 Private E-2

    i did delete the folder, just checked and is not there. new log attached.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this first account is clean.


    For the second user account, have HijackThis fix the below lines:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O20 - Winlogon Notify: cryptnet32 - cryptnet32.dll (file missing)

    Then attach a new HJT log for this account.
     
  17. luisomar067

    luisomar067 Private E-2

    these 2 lines weren't there
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O20 - Winlogon Notify: cryptnet32 - cryptnet32.dll (file missing)
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! Then your clean. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  19. luisomar067

    luisomar067 Private E-2

    Again, Thank You! You're the man!!!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds