Issue with username.exe trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Cluniac, Sep 2, 2009.

  1. Cluniac

    Cluniac Private E-2

    Hello,

    I have an issue with a trojan that masks itself as your "username", and runs as username.exe, from the Document and Settings\username\ directory. This process starts automatically on startup, and sometimes eats a lot of CPU power. I have run all of the scans recommended, and several of them indicated they were removing it... although after rebooting and following all of the scan instructions, it seems to still be there.

    Can someone take a look at my logs and let me know if you have any ideas?

    Thanks for your help!

    Matt
     

    Attached Files:

  2. Cluniac

    Cluniac Private E-2

    And here is my hijackthis log from the last scan :)

    Thanks,
    Matt
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome to the forums. We are currently reviewing your logs and will get back to you with a set of instructions as soon as we can.

    Thanks for your patience during this time.
    Kes13!
     
  4. Cluniac

    Cluniac Private E-2

    Hi Kes,

    Thanks for your reply.

    After I posted this, I decided to do some more checking, and I realized that stupidly I had forgotten to scan my external harddrive that I use almost every day... sorry!

    So, of course username.exe was also there, and I removed it with SuperAntiSpyware.

    I have run more scans with Malwarebytes every few days and it comes up clean. Computer seems to be running better as well, so I think for now i'm OK. If you see anything else "strange" in my logs, let me know, otherwise thanks for your support.

    Kind Regards,
    Cluniac
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please go to Add/Remove Programs and uninstall the following older versions of Java:

    • J2SE Runtime Environment 5.0 Update 1
    • Java Runtime Environment 1.5.0
    • Java(TM) 6 Update 13
    • Java(TM) 6 Update 3
    2. Are you set up to use the below proxy? If not then please include it in our below list of fixables in HJT.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Not wise to place ANY site into your TZ so fix these lines at your option.

    After clicking Fix exit HJT


    3. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\msprojecthotfix
    
    File::
    d:\documents and settings\matthew.dow\Local Settings\Application Data\mqqcioo.exe
    D:\Documents and Settings\matthew.dow\matthew.dow.exe
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "matthew.dow"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif



    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    6. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    FYI: You should consider upgrading to service pack 3: You are running:

    • Platform: Windows XP SP2 (WinNT 5.01.2600)
     
  6. Cluniac

    Cluniac Private E-2

    Hi,

    Thanks a lot for your help.

    I have followed the instructions.

    I was unable to delete one of the Java versions, 1.5.0, as I get an error when I try to do it, "a suitable JVM could not be found".

    In any case, I attached the logs.

    Thanks again, everything seems to be running fine now,

    Matt
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there :)

    There has been an update to ComboFix meaning that you will have to re-run my script in order to get rid of the malware that still remains.

    1. Delete the ComboFix.exe on your desktop and then download the new version:

    ComboFix.exe

    2. Refer back to my post #5 step #3 and re-run the script.

    3. Then...

    Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    4. Run the new MGTools.exe and attach the C:\mglogs.zip that it generates into your next reply, as well as the C:\combofix.txt from running CF.

    Thanks
    Kes13!
     
  8. Cluniac

    Cluniac Private E-2

    Hi,

    Here are the updated logs.

    Thanks again for all your help. Everything seems to be running fine on the computer, it is quite fast for most things now.

    Thanks,
    Matt
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Can you tell me what you know of this file please:


    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    D:\Documents and Settings\matthew.dow\matthew.dow.exe
    D:\Documents and Settings\matthew.dow\Local Settings\temp\uYbodDa7.exe.part
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\matthew.dow]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif



    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    4. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
    :)
     
  10. Cluniac

    Cluniac Private E-2

    Hi,

    Computer still running fine.... here are the logs.

    Thanks,
    Matt
     

    Attached Files:

  11. Cluniac

    Cluniac Private E-2

    Oh yes, and as for the file you mentioned, C:\WINDOWS\system32can4d, I have no idea what it is....

    Regards,
    Matt
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please rename this file C:\WINDOWS\system32can4d to system32can4d.old and tell me how your PC behaves for the next few days after doing this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds