Persistent win39.tmp.exe dialer trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by aikox2, Mar 27, 2006.

  1. aikox2

    aikox2 Private E-2

    I keep getting warnings about this file from Ewido and/or Avast:

    c:/windows/temp/win39.tmp.exe

    I was able to find a little info online, but nothing helpful, and was surprised that a search here did not yield anything.

    This reared its ugly head the other day, the same time I got struck with SpywareQuake. I was able to remove the SpywareQuake, but this bugger keeps coming back after it is cleaned by Ewido.

    It is more an annoyance than anything else, so far, but I would like to remove it for good.

    Any suggestions would be appreciated.

    WinXP SP2, Avast, SpywareBlaster, SpyBot S&D, AdAware, Ewido, etc.

    Thanks,
    Aiko
     
  2. aikox2

    aikox2 Private E-2

    As a follow up, the warning I get from Avast is for win32:dialer-520.

    I don't know if these are related, but they seem to pop up together.

    Thanks.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just need to know what to search for. There are many links related to fixing this. The file names are always different and also the search capabilities of vB (used for the forums) is very limited. If you search for winlogonhook, here and on Google, you will find plenty of hits.

    You need to start the same place as every one else. And that is with our cleaning procedures.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  4. aikox2

    aikox2 Private E-2

    Thanks for the reply.

    I followed all the instructions and ran all the various software in the order specified. Most of them were in my arsenal already, but the two MS products were not.

    I was not able to get Panda to run. It kept failing after the ActiveX download, and repeated retries did not help.

    Most of the scans came up clean or found only one nasty.

    Attached are the BitDefender and HJT logs.

    Thanks for your analysis and suggestions,
    Aiko
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are running an outdated Sun Java version. You must get updated.

    Did you install WinPcap? Possibly to use with Ethereal?
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: winbug32 - winbug32.dll (file missing)

    After clicking Fix, exit HJT.

    It would be a good idea to delete all files and subfolders in: C:\Windows\Temp
    This is where those dialer trojan files are hiding.

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Mar 27, 2006
  6. aikox2

    aikox2 Private E-2

    Thanks for the analysis. So it wasn't too bad?

    The Windows/Temp folder is now empty, and I don't seem to have any problems at this time, though I don't know if anything will pop up again.

    I will follow your instructions and post a new HJT log on the XP box later (when I can get on that machine).

    I don't know what the WinPcap is; it is also on my Win2K pc. I have attached the HJT log for this box; maybe you would be so kind as to scan this one as well?

    I try to be careful and proactive, and try to resolve these issues myself, but this seems to be the place to go when it comes to HJT.

    Thanks for all your help.
    Aiko
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    WinPcap is a valid product. It is not malware. See: http://www.winpcap.org/
    However most people have no need for it. That is why I asked if you installed it for something. If you are sure you do not need it, just go to Add/Remove programs and uninstall it. It can always be reinstalled if later you find you needed it for something.


    It would be a better idea to only work on one PC at a time. Otherwise this thread could get to confusing. So let's finish the first PC before looking at a second one. And when we do look at the second PC, all the same full cleaning procedures must be followed first and then the logs from the two online scanners must be obtained and posted before using HijackThis.
     
  8. aikox2

    aikox2 Private E-2

    Thanks for all the help with the XP box. I haven't had time to follow up, but it isn't doing anything evil anymore. I will try to follow up this weekend.

    Thanks again for the help.

    Aiko
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! After we finish the first PC, we can start on your second one. But it would probably be a better idea to start another message thread for it. When you do start this new thread, make sure you run the whole READ & RUN ME on your second PC and attach the three required logs.
     
  10. aikox2

    aikox2 Private E-2

    Okay, here is the HJT log from after I fixed the last few items you identified:

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: winbug32 - winbug32.dll (file missing)

    NOTE: The last item (020) was not there to fix; must have been cleaned out already.

    Attached is a HJT log from after I fixed the items. I haven't had any warnings or problems for several days; however, for unknown reasons, the pc rebooted itself while I was away from it, and I have no idea what caused that to happen. I do not have it set to allow automatic updates and reboot itself. After it rebooted, it indicated that it had a serious error that required the reboot, but I don't know what the error was. I ran the last HJT fix after the forced reboot, and then ran again to create the log.

    Thanks again,
    Aiko
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well maybe that's not true. You have kept the below on your PC.

    http://www.bleepingcomputer.com/startups/BIGFIX.EXE-568.html

    As soon as I get any new PCs this is about the second thing that gets deleted (AOL is first). Third is McAfee or Norton. Fourth is all other junk demo/trial software.

    You're log is free of malware. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  12. aikox2

    aikox2 Private E-2

    Thanks. I usually don't run crap like that (as you can see); I don't know why I left it on the pc. The XP box is basically my son's, though I use it for burning DVDs, as his pc has a DVD burner, and mine does not.

    I did not realize what a resource hog BigFix is, and I have since disabled it.

    Thanks for all the help. Next time I get around to rebooting my pc, I will post a HJT log in a new thread.

    Aiko
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Please do not post a HijackThis log without having run the READ & RUN ME sticky and without having first posted the two online scanner logs from step 6.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds