may have a few trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by djalb28, Sep 4, 2006.

  1. djalb28

    djalb28 Private E-2

    hi there ive been getting messages from norton and ewido telling me i have trojans. The ones listed are nebular, pakes and instantaccess.k. Ive read through and followed out your instructions regarding what to do before posting but to no avail. So i was wondering if i could get some help as im pretty clueless about all this. Im not sure if you want me to post my hijackthis file yet so i will wait til you reply before doing so thanks in advance....
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. djalb28

    djalb28 Private E-2

    thanks for getting back to me chaslang here are my logs all except panda scan cause it came back as all clear for some reason...it wont let me upload hijackthis list and bdscan list because i uploaded them on a previous post (djalb help needed) post
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to use the current version of ShowNew. Please get a new log after downloading the current version.

    Your log from PandaActive scan is right on your desktop. Please attach it. It would not be 13988 bytes in size if it was clear.
    Your other thread showed that you did not follow the directions for installing, renaming and running HijackThis in normal boot mode. Go back to step 7 and follow the directions exactly as written and then attach a new log.


    Do you have logs from Ewido and Norton? Please attach them (especially Ewido).

    What is the below file on your Desktop? It was just downloaded recently. It is a bad idea to save things to your desktop like this. You will forget what they are and it is just not a safe place and causes desktop clutter.
     
    Last edited: Sep 5, 2006
  5. djalb28

    djalb28 Private E-2

    chaslang here is the files you have requested i couldnt figure out how to save a report with norton but im sending you my new hijackthis log my ewido report panda scan and my new shownew file ive got pretty basic knowlege of computers so excuse my ignorance lol
     

    Attached Files:

  6. djalb28

    djalb28 Private E-2

    the other thing chaslang i couldnt figure out how to save a norton scan file so i hope all ive sent is as you have requested
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please refer to step 7 in the READ ME again. You have installed HJT here:

    C:\Documents and Settings\ALB\Desktop\hijackthis\Analyse.exe

    That is exactly where we indicate that it should not be installed. Please install it so that it looks like the below:

    C:\Program Files\HijackThis\Analyse.exe

    And then make sure you delete the below folder:
    C:\Documents and Settings\ALB\Desktop\hijackthis


    Also you must remember to obtain HijackThis logs from normal boot mode as requested in step 7. Logs from safe boot mode are rarely of any use to us. I will give you a fix to run in my next post but it may not be complete due to the log from safe mode.


    Questions:
    1. Is your copy of Ewido a free trial version or a paid version?
    2. Why do you allow Ares to load at startup? Do you really want to allow others to have access to your PC anytime you have it turned on? This is a bad idea.
    3. Do you know what the below two files are:
      • C:\WINDOWS\iun6002ev.exe
      • C:\Documents and Settings\ALB\Desktop\sdsetup.exe <--- is this Spyware Doctor and is it the trial version. If so, you don't need it.
     
    Last edited: Sep 7, 2006
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winmxw32.dll once and then click the kill button. After you have killed all of the winmxw32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    pmkhi.dll
    xxyawtu.dll

    Next double click on explorer.exe and again click once on each instance of winmxw32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    pmkhi.dll
    xxyawtu.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: tisa.MyBHO - {9B053E00-78D3-47AE-B763-60FF36FF2886} - C:\WINDOWS\system32\tisa.dll (file missing)
    O2 - BHO: (no name) - {CF4FB63D-127D-4356-893F-B379C5E23ADC} - C:\WINDOWS\system32\pmkhi.dll
    O20 - Winlogon Notify: pmkhi - C:\WINDOWS\system32\pmkhi.dll
    O20 - Winlogon Notify: winmxw32 - C:\WINDOWS\SYSTEM32\winmxw32.dll

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit

    If you get an error message while doing the above command prompt step, just ignore it and continue!

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\ALB\Local Settings\Temporary Internet Files\Content.IE5\15IFHHIA\srvakj[1].exe
    C:\Documents and Settings\ALB\Local Settings\Temporary Internet Files\Content.IE5\15IFHHIA\srvlle[1].exe
    C:\Documents and Settings\ALB\Local Settings\Temporary Internet Files\Content.IE5\AB672RGN\srvjdy[1].exe
    C:\Documents and Settings\ALB\Local Settings\Temporary Internet Files\Content.IE5\U7BY3NZD\srvnsl[1].exe
    C:\Documents and Settings\ALB\Local Settings\Temporary Internet Files\Content.IE5\UD8LYZUP\srvbey[1].exe
    C:\Program Files\Common Files\{34E81410-0D3F-2057-1013-05050622002c}\Update.exe
    C:\svchost.exe
    C:\WINDOWS\system32\pmkhi.dll
    C:\WINDOWS\system32\winmxw32.dll
    C:\WINDOWS\system32\xxyawtu.dll
    C:\WINDOWS\system32\ihkmp.ini
    C:\WINDOWS\Temp\win110.tmp.exe
    C:\WINDOWS\Temp\win113.tmp.exe

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete it if found:
    C:\Program Files\Common Files\{34E81410-0D3F-2057-1013-05050622002c}

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\ALB\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
  9. djalb28

    djalb28 Private E-2

    hi chaslang i believe ive followed your instructions to the letter so find attached my new logs during process explorer there was one instance of winmxw32.dll 3 instances of pmkhi.dll and no instances of xxyawtu.dll. In the command prompt window i got the message the system cannot find the path specified apart from that everything went fine.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need responses to my questions in message number 7!

    You also need to redo the first part of message # 8 related to the

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    registry key. You did not get it deleted. Follow those steps exactly and make sure you double check as requested and delete the key manually if required. Also tell me if you run into any problems or get any error messages.


    Now run Pocket Killbox and select File, Cleanup, Delete All Backups!

    Also use HJT to fix the below remnant of winlogonhook:
    O20 - Winlogon Notify: winmxw32 - winmxw32.dll (file missing)
     
    Last edited: Sep 7, 2006
  11. djalb28

    djalb28 Private E-2

    Hi chaslang i get the feeling we are nearing the end here as ive not had a single message from either norton or ewido all day but hey musnt get too cocky anyway to answer your questions....In registrar lite after i go through the process step by step as detailed and then click on view then refresh all evidence of the file HKEY_LOCAL_MACHINE\software\microsoft\mssmgr has gone and there was no error messages during this. to answer your earlier questions
    1. my copy of ewido is the free version
    2. ive since stopped ares from loading up when windows starts up
    3. it was spydoctor but ive deleted it. and i dont know what C:\WINDOWS\iun6002ev.exe is but it says suf60 runtime indigo rose corporation. hope this is of help to you
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes we are getting close! ;) Okay attach a hopefully final log from GetRunKey so I can verify that all traces of winlogonhook are gone.

    Okay then uninstall Ewido! Leave the iun6002ev.exe file alone it is okay. I thought it may be for Indigo Rose but needed to verify.
     
  13. djalb28

    djalb28 Private E-2

    Right chaslang here it is tell me its good news.......
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good news! Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  15. djalb28

    djalb28 Private E-2

    Chaslang ive done as you have said and i would like to take this opportunity to thank you for your time and effort to help me get my system back to its original state. I dont have a credit card but i would like to donate to the site is there any way to do this if so i would be grateful if you could supply me with the details....Anyway im off now to enjoy my clean pc and i just want to thank you again i would like to say i will speak to you later but in this case i hope i dont have to all the best mate.....Alb
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MG's does not have any methods in place to accept donations! You can support MGs by sending your friends here and by buying Geek-Wear (see the main page links are in the right side under INFO) or you can donate using Pay-Pal to me personally if you would like. It's your choice whether you do or you don't.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds