Problem with trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by skow, Jun 8, 2007.

  1. skow

    skow Private E-2

    Hey, thx for the very nice guide you guys have made!

    I am having a problem with several trojans, which i can only pick up using xsoftspyse, i have tried using spybot, adaware and the trial of spysweeper, but none of them were able to pick them up.

    So i did youre guide, all steps, unntil number 7.
    I did both the scans in safe mode, on the administrator acount and my normal account.

    The only step i havent got logs from is the panda step, i couldnt get it to work in the safe mode, so i did it in normal mode, an it to was unable to find the trojans.(or any infections, so no log)
    One of the trojans is a vundo (i actually had 2 vundo, but spysweeper got rid of one of them) so i did the vundofix i downloaded from your site, it removed a series of files, but the xsoft still says i have atleast 1 vundo trojan.

    Now i could buy the xsoft, but i read (either on youre forum or some other that xsoft finds a couple of files to be trojans which are not, and that it is not the best anti-spyware program out there) so i figured that spysweeper would be the best buy, but seing it being unable to deal with the problems ( i stil have pop-ups when i op my browser) it seams that it does not clean 100 %.

    So i hope you can help me, i will attach all the logs i have (no panda log), the picture of xsoft and the log from vundofix. (got 2 logs from counterspy)

    In advance, thx for any help you can give me !!
     

    Attached Files:

  2. skow

    skow Private E-2

    the next logs:

    Forgot to say it all started with the Driver Cleaner popup, which constantly tells you to install their program to clean youre pc, i havent done so, and havent seen the pop in a while.(it might have been caught by some of the scans, but still have a couple of other pop-ups thats annoying me)
     

    Attached Files:

  3. skow

    skow Private E-2

    the vundo log an picture of the 3 trojans found by xsoft
     

    Attached Files:

    Last edited: Jun 8, 2007
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the Spy Sweeper & Sunbelt CounterSpy trials now to avoid having them get in the way of cleanup. Then delete the below two folders that the CounterSpy uninstall may leave behind.
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Programmer\Sunbelt Software

    You also should really uninstall the below two items since they are more than like the root cause of your Vundo infection. This was mentioned in the uninstall programs list given in step 0 of the READ ME.
    Messenger Plus! 3
    Messenger Plus! Live

    You also need to uninstall the below old Sun Java version as requested in step 6 of the READ ME.
    J2SE Development Kit 5.0 Update 9
    J2SE Runtime Environment 5.0 Update 7
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_12
    Java 2 SDK, SE v1.4.2_12


    What are these EBJ.... files for?
    Code:
    "C:\"
    ebjkey~1.sto  28 May 2007        1072  "EBJKeystore.store"
    "C:\WINDOWS\Downloaded Program Files\"
    ebjsec~1.dll   3 May 2007      446464  "EBJSecurity_2.dll"
    Do you know what the below files are? If you do, then move them someplace else if you need them. They DO NOT belong here and will always be suspected as malware if they are here.
    Code:
    "C:\WINDOWS\"
    inhiq.exe     28 May 2007       70460  "inhiq.exe"
    lv01.bmp      30 Apr 2007      829494  "lv01.bmp"
    lv02.bmp      22 Apr 2007      829494  "lv02.bmp"
    lv02.mpg      22 Apr 2007    90853380  "lv02.mpg"
    lv03.avi      22 Apr 2007   287819776  "lv03.avi"
    lv04.bmp      23 Apr 2007      829494  "lv04.bmp"
    lv04.mpg      23 Apr 2007    72392708  "lv04.mpg"
    lv05.bmp      30 Apr 2007      829494  "lv05.bmp"
    lv05.mpg      30 Apr 2007    25853956  "lv05.mpg"
    lv06.bmp       1 May 2007      829494  "lv06.bmp"
    lv06.mpg       1 May 2007    48996356  "lv06.mpg"
    lv07.bmp       2 May 2007      829494  "lv07.bmp"
    lv08.bmp       3 Jun 2007      829494  "lv08.bmp"
    lv08.mpg       3 Jun 2007    22321156  "lv08.mpg"
    lv09.bmp       6 Jun 2007      829494  "lv09.bmp"
    lv09.mpg       6 Jun 2007    57960452  "lv09.mpg"
    lv10.bmp       6 May 2007      829494  "lv10.bmp"
    lv10.mpg       6 May 2007    52725764  "lv10.mpg"
    lv11.bmp       6 May 2007      829494  "lv11.bmp"
    lv11.mpg       7 May 2007    84135940  "lv11.mpg"
    lv12.bmp       7 May 2007      829494  "lv12.bmp"
    lv12.mpg       7 May 2007    39393284  "lv12.mpg"
    lv13.bmp       9 May 2007      829494  "lv13.bmp"
    lv13.mpg       9 May 2007     6842372  "lv13.mpg"
    lv14.bmp      11 May 2007      829494  "lv14.bmp"
    lv14.mpg      11 May 2007    15546372  "lv14.mpg"
    lv15.bmp      11 May 2007      829494  "lv15.bmp"
    lv15.mpg      11 May 2007    47269892  "lv15.mpg"
    lv16.bmp      12 May 2007      829494  "lv16.bmp"
    lv16.mpg      12 May 2007    37070852  "lv16.mpg"
    lv17.bmp      16 May 2007      829494  "lv17.bmp"
    lv18.bmp      16 May 2007      829494  "lv18.bmp"
    lv18.mpg      16 May 2007    30046212  "lv18.mpg"
    lv19.bmp      21 May 2007      829494  "lv19.bmp"
    lv20.bmp      31 May 2007      829494  "lv20.bmp"
    lv20.mpg      31 May 2007    39407620  "lv20.mpg"
    lv21.bmp       5 Jun 2007      829494  "lv21.bmp"
    lv21.mpg       5 Jun 2007    38758404  "lv21.mpg"


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {09F1E408-8875-4888-98F4-F2D2E108DE62} - C:\WINDOWS\system32\xxyvw.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\pmnmlll.dll (file missing)
    O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\lasohyel.dll (file missing)
    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
    O4 - HKLM\..\Run: [smgr] smgr.exe
    O4 - HKLM\..\Run: [ApachInc] "rundll32.exe" "C:\WINDOWS\system32\wodkpiee.dll",realset
    O4 - HKLM\..\Run: [uhkxefqh.exe] "C:\Documents and Settings\All Users\Application Data\uhkxefqh.exe"
    O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat
    O20 - Winlogon Notify: winrpf32 - winrpf32.dll (file missing)

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jun 8, 2007
  5. skow

    skow Private E-2

    first of all thx for taking the time to help me!

    sry i didnt remove the programs as said in step 0(not all the concentrated effort from my side). But i have removed the spysweeper and counterspy. I got rid of the 2 messneger programs. As for the java, i checked the version with java's homepage and it said that i had the new version( so i thought that it didnt matter with the other old ones) But i got rid of them to.

    The Ebj are the files for my homebanking systems, and it is the only place they can function, so cant touch them.

    All the other files was pictures and clips ive recorded with my tv (have tv on the computer), but i have no idea why it saves the files in the windows directory. (the program is absolute rubbish anyways) Saved the ones i wanted, and deleted them all.

    Hijack this noticed me about the AppInit_DLLs, dont know i you want to se the log, lookes pretty standard.

    The avenger was not able to find some of the files, thats any way what i got out of the report, but you can check it out for yourself.
     

    Attached Files:

  6. skow

    skow Private E-2

    and the hijack this report

    according to xsoft, i got rid of the 2 alphabet trojans, but the vundo one is still there.(you can see it on the previous picture from xsoft that i attched)
     

    Attached Files:

    Last edited: Jun 8, 2007
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! My instructions said that it would. But even though Avenger deleted the file that AppInit_DLLs line is still there. Run HJT again and have it fix the below lines:


    O4 - Startup: PowerReg Scheduler.exe
    O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat

    Now attach a new log from HJT.

    If the AppInit_DLLs line is still there now, we will use another method to remove it.

    Note: I don't recommend running Ad-Aware 2007. It is too buggy, adds an unnecessary service into the free version and wastes a ton of memory for now reason at all. In addition, it is really not much better than the old version which was not very good at removing real malware problems.
     
  8. skow

    skow Private E-2

    It came with the same warning about applnit_dll, but as far as i can see, its gone from the hijack this log.

    What would you recommend instead of adware ?

    And xsoft still says that i have the vundo trojan.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless you purchase Ad-Aware, it is only an after the fact scanner so it does not provide you any protection anyway. You need realtime antispyware protection. My final instructions will give you a link on How to protect yourself and there will be many tools listed. Some provide realtime blocking.

    Attach a log! Hopefully it is text. I remember seeing the stupid bad idea XML reports from Xoft in the past. Did you purchase XoftSpy?


    I asked you to uninstall CounterSpy in message #4 but I still see it running. Did you uninstall it? If you did, then just have HJT fix the below line:

    O4 - HKLM\..\Run: [SBRegRebootCleaner] C:\Programmer\Sunbelt Software\CounterSpy\SBRC.exe
     
  10. skow

    skow Private E-2

    Apparantly xsoft dosnt do logs,
    http://www.paretologic.com/resources/definitions.aspx?lid=EN&remove=Vundo Trojan
    thats what it says when i click on it, but you can see it in the jpg i attached earlier, its just the top one in that picture(the other 2 is gone thx to you).

    I havnet bougth xsoft, as i read it was not the best spyware program out there.

    I did uninstall counterspy, and i checked for the folders (which were gone), but ive fixed the line now.

    And i think i have looked through the guide on how to protect yourselfe against malware, but adaware is on it, so just thought that you had youre on personal favourit amongst them?

    I got SpywareBlaster and spybot S&D now, perpahps Comodo BOClean Anti-Malware with its realtime protection ?
     
    Last edited: Jun 9, 2007
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall it now! It is not something we recommend and is well known to show many false positives. Your PC is clean from Vundo and you would know if you had an active vundo infection.

    That link was put there when it was Ad-Aware SE Personal and it was only used as a backup scanner. Thanks for reminding me that it is still there. I will be removing it.

    Those are good choices.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Jun 9, 2007
  12. skow

    skow Private E-2

    Once again thx alot for your help! With the amount of post you have, you have probably helped more people than mother Theresa!

    Just found 2 mistakes in your guides, i know its not much, but when youre working with things that you havent got that good an understading of, its annoying if its not all clear.

    Under point 6c:
    Request help - you should post a message requesting help, but make sure you indicate in your post that you've already followed the instructions on this page so we don't waste your time and our time by posting a link to it in your thread. Also, it would be helpful to indicate what kind of problems the above steps have found and fixed (and failed to fix). Also you must attach the all the logs from the previous steps:

    Under the hijack guide, it says:
    This is a self extracting executable which will default to installing it where want want it.
    The default install folder is C:\Program Files\HijackThis. DO NOT CHANGED ( the D..)THIS


    know its not much, but now you know.

    thx again for all the help youve given me!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Thanks for pointing out the typos! I fixed them and a few others while I was editing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds