I have a trojan - help

Discussion in 'Malware Help (A Specialist Will Reply)' started by sharonwebb19, Feb 7, 2007.

  1. sharonwebb19

    sharonwebb19 Private E-2

    I have done everything in your read and run me first section.
    I have done the counterspy scan and quarantined the detections but I didnt view the scan history and copy it. Can I do this now? if so how? or do i have to run it again?
    I had to use normal mode for bitefender etc. Spybot could not fix zlob.activexobject
     

    Attached Files:

  2. sharonwebb19

    sharonwebb19 Private E-2

    Really hope you can help, thanks very much :)
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go to Add\Remove in the control panel and uninstall: MarketResearch


    Continue by downloading a tool we will need - Pocket KillBox
    Save it to its own folder somewhere that you will be able to locate it later.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video ActiveX Object\isadd.dll (file missing)
    O21 - SSODL: exemplars - {2acf3add-34a1-4f2f-99cf-cc69785d1e90} - C:\WINDOWS\system32\cwgppb.dll

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\windows\keyboard171.dat
    C:\Documents and Settings\WocUser\Favorites\Free stuff
    C:\Program Files\AntiVermeans\AntiVermeans.exe

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  4. sharonwebb19

    sharonwebb19 Private E-2

    Thanks soo much for this.
    Marketresearch was not in add and remove programs, so i could not uninstall it.
    I didnt notice that I had to double click and merge fixme.reg until after I ran pocketkill, hope this hasnt ruined anything!! really sorry!!!
    Everything else went ok. Had no message after the reboot.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run Pocket Kill again and add this file:
    C:\WINDOWS\system32\cwgppb.dll

    Now for the hard part:
    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Repeat these steps for all of the registry keys given above before continue to the next steps below.
    • Now leave RegistrarLite running and continue
    • Now run the fixME.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    • If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Quote:
    PART 2 - Setting Permissions for Everyone

    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    Quote:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    Now run GetRunKey again and attach a new log!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The keys should read:



    Take ownership of the keys and then use this as the patch as posted in #3

     
  7. sharonwebb19

    sharonwebb19 Private E-2

    The fixme.reg caused no error message :)
    However registar lite process I didnt do so good :cry ! the only keys that deleted were the ones with controlset002 in them. All the others are still there, tried taking control in normal and safe mode, also did permissions thing in normal and safe mode. When I pressed delete i got the error 'access denied'
    I have run the getrunkey log which is attached. I will await your reply!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes they are stubborn.

    Did you do this?
    Are you in as administrative account?

    Did you do the second part (setting permissions to everyone?)
    Save it as fixME.reg to your desktop. Be sure the ''Save as'' type is set to ''all files''. Once you have saved it double click it and allow it to merge with the registry.

     
  9. sharonwebb19

    sharonwebb19 Private E-2

    I did the setting permissions. How do you add to pocket kill? I followed previous instructions but looking back I think that was to delete files? Can you give me precise instructions on how to add to pocket kill, so I can make sure I done it right. Sorry to be a pain!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.


    IMPORTANT: Do NOT run any other options until you are asked to do so!
    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now reboot into normal mode and attach this new rapport.txt log here.
    Now after attaching the above two logs, you need to continue with attaching new logs for:
    ShowNew
    GetRun
    HJT
     
  11. sharonwebb19

    sharonwebb19 Private E-2

    1st attachment
     

    Attached Files:

  12. sharonwebb19

    sharonwebb19 Private E-2

    2nd rapport log
     

    Attached Files:

  13. sharonwebb19

    sharonwebb19 Private E-2

    Remaining logs.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is going to take awhile, so have patience.
    Sophos Anti-Rootkit will scan your computer for files that have been hidden using rootkit technology.

    Many of the newer malware infections use this technology to hide themselves and to make them more difficult to remove.

    Installation
    Download Sophos Anti-Rootkit 1.1 and save to a location you will be able to find such as your desktop

    Run sarsfx.exe by double clicking on it.

    Click Accept to agree to the EULA

    Click Install (if you wish to change the default installation location do so here but remember where you install to, the default is C:\SOPHTEMP)

    Once it finishes copying files, exit the installer​
    Running the scan
    Navigate to the location that you installed the software to (Default: C:\SOPHTEMP)

    Run sargui.exe by double clicking on it.

    Ensure that all three of the options are checked

    Click Start Scan

    Once the scan is complete, close Sophos Anti-Rootkit by closing the scan window and clicking Exit in the main window

    DO NOT CLICK 'CLEAN UP CHECKED ITEMS' OR ATTEMPT TO HAVE SOPHOS ANTI-ROOTKIT FIX ANYTHING UNLESS SPECIFICALLY INSTRUCTED TO IN THE THREAD YOU ARE WORKING ON
    Finding the logsClick on Start --> Run

    Type in %TEMP%\sarscan.log and press enter

    The log file will open in the default editor (probably Notepad)

    Click File --> Save As and save the file to your desktop or other location for easy retrieval.

    Then also attach new logs for:
    ShowNew
    GetRun
    HJT
     
  15. sharonwebb19

    sharonwebb19 Private E-2

    Here is sarscan log
     

    Attached Files:

  16. sharonwebb19

    sharonwebb19 Private E-2

    This thing is a bastard, but I know we will get there eventually! thanks for your persistence :)
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The malware has messed with your privileges.
    Then run Sopho's again.
    If it is successful, attach the other logs.
    If not, let me know.
     
  18. sharonwebb19

    sharonwebb19 Private E-2

    Not sure if you wanted this one but here it is, seemed to work ok.
     

    Attached Files:

  19. sharonwebb19

    sharonwebb19 Private E-2

    and here are the others :)
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Most of the problem is from a bad activex download.
    Please uninstall thru add/remove:
    Market Research

    Also Download win32delfkil.exe
    Save it on your desktop.
    Close all windows.
    Double click on win32delfkil.exe to start the removaltool.
    The computer will reboot automatically.
    After reboot a logfile will open: c:\windelf.txt
    Post the contents of the logfile, in your next reply.


    Run PocketKillBox and delete these files:

    C:\\Program Files\\Video ActiveX Object\\pmsnrr.exe
    C:\\Program Files\\Video ActiveX Object\\isamntr.exe
    C:\WINDOWS\system32\servmswin.exe


    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Please attach the logs for:
    windelf
    showNew
    GetRun
    HJT
     
  21. sharonwebb19

    sharonwebb19 Private E-2

    When I did pocket kill it said files does not exist, I also tried the delete on reboot and it said Pending filerenameoperations Registery Data has been removed by external process!
    the win32 kill thing said it found no files.
     

    Attached Files:

  22. sharonwebb19

    sharonwebb19 Private E-2

    hijack this log attached
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you uninstall MarketReasearch?

    Where you able to delete:
    C:\Program Files\Video ActiveX Object\pmsnrr.exe
    C:\Program Files\Video ActiveX Object\isamntr.exe
    C:\WINDOWS\system32\servmswin.exe
    Is this (servmswin.exe) running in taskmanager? (kill it if it is.)

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Attach new logs from the below:
    GetRunKey - Please download the current version of GetRunKey first. You have an old version.
    ShowNew
    HJT
     
    Last edited by a moderator: Feb 15, 2007
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Be sure you have done this before doing the above:

    Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    Quote:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDSERVICE

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NETWORK_MONITOR

    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Now right click on each registry key listed above and select Delete. Then click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!
     
  25. sharonwebb19

    sharonwebb19 Private E-2

    I cant find market research it isnt under add remove programs.
    I think the registrar life thing worked.

    Where you able to delete:
    C:\Program Files\Video ActiveX Object\pmsnrr.exe
    C:\Program Files\Video ActiveX Object\isamntr.exe
    C:\WINDOWS\system32\servmswin.exe

    I remember doing this but we have done loads! I couldnt find them so presume they are deleted.

    Is this (servmswin.exe) running in taskmanager? (kill it if it is.) - No it is not.

    I have download a new getnew but no idea if its the latest version!
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are looking good except for the
    Market Research

    Locate the GetUnKeys.bat file using Windows Explorer (right click the Start button and select Explore to open Windows Explorer) and double click on it to run it. It will create a file named GetUnKey.txt in the root of drive C: (C:\GetUnKey.txt) . This log will also popup in a notepad window which you can just close. Upload the GetUnKey.txt file here as an attachment.


    Or you could scroll to this key and expand it and if the folder is there, delete it.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MarketResearch

    Let me know which you do ..or just attach the GetUnKey.txt.
     
  27. sharonwebb19

    sharonwebb19 Private E-2

    I am confused by this. I have right clicked the start menu and choose Explore but all that happened was a box opened called start menu. I didnt know what to do next!! sorry for being dim!!
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried a search for it? Start/ search /files and folders / advanced/ search subfolders ....
     
  29. sharonwebb19

    sharonwebb19 Private E-2

    I have searched for market research and getunkey in the whole C drive. Found nothing. :(
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try this:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Tell me how things are running.
     
  31. sharonwebb19

    sharonwebb19 Private E-2

    I have been away, so have only just had chance to do this. Everthing seems to be ok but then it was before I did this anyway! How do I know its gone. Do you need me to attach some logs?
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...please attach new logs for:
    ShowNew
    GetRun
    HJT

    Just so we know you are clean and can do the final steps.:)
     
  33. sharonwebb19

    sharonwebb19 Private E-2

    Fingers crossed confused
     

    Attached Files:

  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds