The Trojans are having a PICNIC.. HELP!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by gofergal, Jul 3, 2007.

  1. gofergal

    gofergal Private First Class

    Hi
    I have a friend that has discovered several trojans and crap on his computer.. and we cannot figure out how to get rid of them.
    Can someone help me please?
    Thank you
    GoferGal

    Edit remove inline Hijackthis log

    and ... here are a few of the bugs his AV picked up.

    [INFO] The file was moved to '46ed9a04.qua'!
    C:\WINDOWS2\system32\fzoobjxy.dll
    [DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen
    [WARNING] An error has occurred and the file was not deleted. ErrorID: 16003
    [WARNING] The file could not be deleted!
    C:\WINDOWS2\system32\ijjbijj.dll
    [DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen
    [WARNING] An error has occurred and the file was not deleted. ErrorID: 16003
    [WARNING] The file could not be deleted!
    C:\WINDOWS2\system32\ipv6mons.dll
    [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
    [WARNING] An error has occurred and the file was not deleted. ErrorID: 16003
    [WARNING] The file could not be deleted!
    C:\WINDOWS2\system32\drivers\secdrv.sys
    [DETECTION] Contains signature of the rootkit RKIT/Agent.DQ.31.A
    [INFO]
    C:\hiberfil.sys
    [WARNING] The file could not be opened!
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\Documents and Settings\eurom.EUROM-GFP6AWXXP\Local Settings\Temp\sscaa.exe
    [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
    [INFO] The file was moved to '46ed825e.qua'!
    C:\Documents and Settings\eurom.EUROM-GFP6AWXXP\Local Settings\Temp\vcyks.exe
    [DETECTION] Is the Trojan horse TR/Crypt.Morphine.Gen
    [INFO] The file was moved to '47038266.qua'!
    C:\WINDOWS2\$NtServicePackUninstall$\secdrv.sys
    [DETECTION] Contains signature of the rootkit RKIT/Agent.DQ.31.A
    [INFO]
     
    Last edited by a moderator: Jul 4, 2007
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    A few are in temp files, so the steps below, clean out the temps and give the malware experts here some more logs to work from in IDing the malware as Hijackthis is only a small part of scanning for malware.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. gofergal

    gofergal Private First Class

    Ok we have been somewhat hampered and do not know if you will be able to help us or not. First of all, he was not able to run many of those scans.. because his windows xp OS is crippled... and he now has lost the use of his keyboard... He already lost his windows installer.
    Here is what we have.......



    ==============================
    We tried running Ad-Aware, Spybot S&D, McAfee Stinger, SuperAntiSpyware, Vundo and KillBox and either nothing showed up or it did not delete the ConHook Trojan.
    We have tried safe mode, and regular. We were unable to run combofix since it requires a "keyboard"
    We have tried to get his drivers for the keyboard but we get an error messgae saying it cannot download them to his system. We still cannot upgrade to SP2. I actually had him try and delete that stupid ijjbijj.dll both from HJT and from System32 and it came back in HJT and said it was protected or locked and could not delete it. It wouldnt even let us change it's name LOL.
    I am sorry I dont have any other logs but most of them were clean or with "negligible" problems.
    At this point we wanted to do a reformat but .. without a keyboard he cannot type the key code for his windows. grrrrrrr no repair, no clean install, and no reformat at this point.
    I hope someone can give us more guidance and suggestions where we should go from now......
    Thanks
     
    Last edited by a moderator: Jul 14, 2007
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This could be tricky without a keyboard.....let's try this.
    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard (ON YOUR COMPUTER- then copy to a cd or thumb or floopy disc and drag it to his desktop) by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Tell me how that went.

    Note: HJT should be downloaded to C:\HJT
    analyse.exe---> change the name!!
     
  5. gofergal

    gofergal Private First Class

    Thanks TimW
    We were able to follow your very clear instructions and everything went ok.. but it appears the lil' varmint is still there. It looks like 3 out of 4 were removed... A few days ago there were about 8-10 of those ijjbijj.dll BHO's listed so we must be making progress.
    Any other suggestions.???


    We did not get that message PendingFileRenameOperations prompt you asked us to report - the reboot was automatic.
     
    Last edited by a moderator: Jul 15, 2007
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to install HJT properly ..as in not on the desktop. Create a folder in the C drive: C:\HJT\....unzip it there and rename it again. And please, follow the instructions for attaching the HJT log ...do not paste it into your replies.

    I really need you to do the other scans as well ..ShowNew, GetRun and Counterspy.
    I can't remove the nasties if they are still residing in your registry.

    Are you still unable to access the web? If so ...proceed as we did earlier by downloading and then copying the notepad text from your computer over to the other.

    Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:


    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRun
    HJT
    ComboFix
    Avenger
     
  7. gofergal

    gofergal Private First Class

    Ok here are the first 2 scans... we are having a hard time getting all of them to run.. his computer restarts every little while.
    He is unable to install CounterSpy. I will have more posts for you later this afternoon.
    Thanks
     

    Attached Files:

  8. gofergal

    gofergal Private First Class

    Ok here are the other 2 scans we were able to do. He still cannot get SP2 installed, and it seems when he tries it... more things go wrong.

    Without the Windows Installer working we cannot run CounterSpy. I hope this is enough info for you to help figure out what we need to do to get rid of the trojans.
    Thanks for all your help
     

    Attached Files:

  9. gofergal

    gofergal Private First Class

    Here is the Avenger log file. For some reason that did not show up until this morning when he rebooted his computer.
    Thanks
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    While I look at your logs:
    DO NOT attempt to install SP2 - it will always fail and give you more problems when there is malware on your system.
    Re-Run avg antispyware and have it fix/quarantine all it finds!

    I will post a new fix shortly.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Could you not run ComboFix?

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    J2SE Runtime Environment 5.0"
    Java 2 SDK, SE v1.4.2_13
    Windows XP Service Pack 2

    Reboot and install:
    Java Runtime 6

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, exit HJT

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now:
    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    Now reboot into normal mode and attach this new rapport.txt log here.
    Now attach new logs from:

    * GetRunKey
    * ShowNew
    * HJT
    * ComboFix --> if you were able to run it.
    * Avenger
    How are things working now?
     
  12. gofergal

    gofergal Private First Class

    He Ran ComboFix but it did not generate a log, or he didnt know where to find it.... ??

    Since his installer is damaged he cannot uninstall the files you asked us to remove.

    Do you still want us to do all of the other things you suggested... even if we cannot uninstall the Java files, or do they need to go in sequence?

    Also.... he is unable to boot to safe mode.. He tried F8 and also BOOT.INI in MSCONFIG. Any suggestions.... if we have to do any of this stuff in safe mode we are going to have more problems.. UGH!!!

    Another thing.. he now has BitDefender and everytime he reboots it pops up with a message saying the ConHook was blocked .. I am not sure if it is trying to come from the outside or if its blocking the spread internally?? any ideas? confused


    thanks for your patience.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do all that I posted that you are able to do ....and try this for the installer:
    Unregister Windows Installer, and then reregister Windows Installer. To do this, follow these steps:

    1. On the "Start" menu, click "Run:.

    2. In the "Open" box, type "msiexec /unreg", and then press ENTER.

    3. On the "Start" menu, click "Run".

    4. In the "Open" box, type "msiexec /regserver", and then press ENTER.

    If this doesn't work ....download this http://www.majorgeeks.com/download4899.html
    and do the installer fix.
     
  14. gofergal

    gofergal Private First Class

    Ok he got this error "an event was unable to invoke any of the subscribers" when he tried that Dial-A-Fix. We will continue with the other suggestions..
    Thanks
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to start>control panel>admin tools>services BITS should be on that list .. make sure it is started and set to automatic.

    Then try this Installer Cleanup.
     
  16. gofergal

    gofergal Private First Class

    Ok.. I assume BITS is the same as Background Intelligent Transfer SErvice.... and he has it listed there but under status it is blank. When he tries to start it he gets an error saying: "Could not start the BITS service on local computer. Error 126: The specified module could not be found."
     
  17. gofergal

    gofergal Private First Class

    Here are the 2 logs we have so far.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Were you able to run SmitFraud?

    To reinstall the Background Intelligent Transfer Service, follow these steps:
    1. Click Start, click Run, type the following command, and then click OK:
    2. If you are prompted to insert your operating system CD, type the following path in the Copy files from box, and then click OK:
    Note This location contains the most recently updated service pack files. If you cannot use this path to copy the required files from, insert your operating system CD, and then click OK.

    Run Process Explorer 10.21

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    ijjbijj.dll.

    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    ijjbijj.dll.

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    ijjbijj.dll.

    After you have killed all instances of any of the above DLLs under iexplore click ok.

    Now just exit Process Explorer.

    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Tell me how that went and attach the avenger log and any other that you have not yet attached.
     
  19. gofergal

    gofergal Private First Class

    Ok the instructions you gave us to run this...

    will not work. I even tried it on my system and it gave an error that it could not find it.

    We cannot complete smitfraud since he cannot boot to safe mode. We did the first step. Is it possible to run that in normal mode or does it have to be done from safe mode?
    I am including the file for that one. Also find the new avenger file attached. It appears we still have that lil stinker!!

    Update: It is interesting when he runs processor explorer those little varmints move around.. It is almost like they are trying to avoid the "mousetrap" Although they show "killed" *or rather they dont show up*... they reappear after rebooting.
    I am becoming convinced that we need to find a fix for his safemode... before we can conquer the spyware..
     

    Attached Files:

    Last edited: Jul 17, 2007
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Stubborn indeed .....right click start / explore / scroll to C:\Windows\system32 ...find the ijjbijj.dll. and try to delete it. You can right click it and see if it has any unusual properties.

    Go ahead and run smitfraud in normal mode ....

    Did you ever try a system restore? Is your keyboard working now?
    Have you gone to start / run / type in "sfc /scannow" without quotes?

    Have you tried a repair install?

    Where did the file keep re-appearing when you ran Process explorer? And are you sure it was stopped in each instance.

    Let's also try this:
    Download Dr.Web CureIt and save it to your desktop.
    • Doubleclick the cureit-beta.exe file and allow to run
    • If it prompts you about getting any updates, get the update and then rerun the cureit-beta.exe installation.
    • When it finishes you will have a green window with a Start and and Update selection. Click Start
    • the Express Scan of your PC window will come up. Click OK to scan main memory to detect infected process in memory.
    • If anything is found in memory, click the yes button when it asks you if you want to cure it. This is only a short scan.
    • You may see a popup window to Buy or get a discount on the program. Just click the X at the top right to close this popup. The scan will continue.
    • Once the short scan is completed, click the Custom Scan radio button. Then Select each of your hard disk drives (that is if you have more than one). A red dot shows which drives have been chosen.
    • Click the green arrow at the right under the Dr.Web logo, and the scan will start.
    • Click 'Yes to all' if it finds any problems and asks if you want to cure or move the file.
    • When the scan has finished, look if you can click next icon next to the files found:
      http://users.telenet.be/bluepatchy/miekiemoes/images/check.gif
    • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
      http://users.telenet.be/bluepatchy/miekiemoes/images/move.gif
    • This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
    • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
    • Save the report to your desktop. The report will be called DrWeb.csv
    • Close Dr.Web Cureit.
    • Reboot your computer!! This is necessary because there could be files in use that will be moved or deleted during reboot.
    • After reboot, attach the log from Dr.Web to your next reply
     
  21. gofergal

    gofergal Private First Class

    Ok.. here is the latest report:

    1. The ijjbijj.dll file does not show up in system32 when he goes to expore but it did a few days ago and we tried to just delete it from there.. it gave us an error saying file could not be deleted since it was in use.

    2. We were able to get into safe mode last night and I am attaching the second report from it.

    3. We tried to do a system restore awhile ago, but we have eliminated that opportunity when we did a repair install of WINXP. That is how we were able to get his keyboard back.

    4. We ran the sfc /scannow before, and I cannot remember what happened then, but we tried it tonight and his computer rebooted in the middle of it. Is there a log that is generated when it completes?

    5. We stopped all the processes of ijjbijj in all 3 folders: winlogon, explorer, and iexplorer. They did not show up after the kill. We closed the program and reopened it and all instances showed up as before the kill.



    We downloaded Dr Cureit and during the express scan it stalled after 380 files were scanned. We tried it a couple of other times but it seems to be stalling or at least shows no progress in the bar nor under statistics: the files scanned.

    I wonder if we should try and run it in safe mode??? or if it would make a difference.

    I believe I am sending you the last scan reports that you have not had yet.

    We are going to keep trying to get these tools to complete. I feel we are making progress... thanks to your great suggestions.. I just wish they would hold up the white flag before we wear out LOL..
    Thanks
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now that you can get into safe mode ....run the scan. Also, can you now run Counterspy?
    Please attach new logs for:
    ShowNew
    GetRun
    HJT
     
  23. gofergal

    gofergal Private First Class

    Ok I had lost contact for awhile...and I thought perhaps this had been resolved but my friend contacted me again.... and it appears he is not even able to boot at all now. We were planning on reformatting but he gets an error... Error loading operating system. He cannot even get into BIOS. Can someone help with this problem?
    I cannot believe that we were unable to resolve the trojan problem with all the help that was given... those are stubborn lil' devils!!! He has finally resigned himself to reformat if we can only figure out how.

    Thanks
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If he can't even get into the bios ..then it is more than likely a hardware issue (which may account for alot of the problems trying to download and run the fixes...).
    He may have to take it to someone to check the processor / ram/ etc. Or you could try posting in the hardware section.:)
     
  25. gofergal

    gofergal Private First Class

    Hi TimW
    We are back!! I belive we made some progress in the hardware forum... but I had a couple of things I wanted to run past you.
    We finally got things running and we were about to do a windows reinstall but decided to check for those little trojans. We ran HJT and it showed (file Missing) after both the ijjbijj.dll items.. *Both O2 BHO and O20 Winlogon Notify* does that mean they are gone? I had him remove them and they did not show up in the second scan.

    What would you suggest we run now to make sure we are really truly clean?
    Cautiously Optomistic here :D
    Thanks
    Oh .. no.... I spoke too soon.. he cannot get in normal mode... only safe mode. His computer hangs up when it is trying to load the desktop. grrrrrrr and i was so hopeful.
     
    Last edited: Aug 2, 2007
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach new logs from GetRunKey, ShowNew and HJT so we can see where things are at right now.
     
  27. gofergal

    gofergal Private First Class

    Thanks for all your great help.... We did a clean install and he seems to be happy. If you have any good suggestions for keeping the little buggars away then I would appreciate it. We downloaded a TON of utilities... and I am not sure which we need to keep using.
    thanks
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds