Trojan Horse

Discussion in 'Malware Help (A Specialist Will Reply)' started by SandraS, May 26, 2005.

  1. SandraS

    SandraS Private E-2

    Avast is constantly telling me I have a virus on my computer..Trojan Horse Found.. Can you help me to get rid of it? :( Once again I believe my children have totally bogged down this computer. What would you like me to do first.
     
  2. AbbySue

    AbbySue MajorGeeks Administrator

    Hi Sandra. For starters it would be helpful if you let us know what the trojan is...your AV software should display the name of it when it shows you the alert. Also, when you get the alert is avast giving you the option to quarenteen or delete the trojan? Please double check this and if the option to remove it is given, do so.

    Then please move on to running ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates. This hopefully will clean out anything else you may have lurking based on the previous problems with your computer.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above if you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. SandraS

    SandraS Private E-2

    OK, I spent yesterday running scans. The Virus that the AVAST software keeps telling me I have on the computer is WIN 32: Trojano- (and then followed by numbers, usually 1375 but also 1092,1152,1373 etc.) I select the delete option and sometimes I get the error message c:\Windows\System32\DrPMon.dll cannot find the file. Another virus it says I have is WIN 32: Qoologic-D. When I ran Trend Micro, it said I was infected with:
    Troj Small.Amt Programfiles\Windows Media Player exe.tmp
    Troj Agent.NJ C:\Windows\System32\Cache\adl_ath.exe
    Troj DLoader.MG C:\Windows\System32\installer_Marketing30.exe
    Troj Agent.NH C:\Windows\System32\main.exe
    Troj Small.ZH C:\Windows\System32\PlayBingoOnLine.exe
    Troj Stervis.c C:\Windows\System32\SVCproc.exe
    AEE.A C:\Counter.Cab*Counter.exe*

    They indicated that they were not cleanable so I selected delete. All were deleted with the exception of this error message: AEE.A unable to delete cab'iA

    I think I have completed all the suggested scans. I will attach a hijack this log for your review. Let me know how that looks. In the meantime, I am going to reboot back into normal mode to see how it's running and to see if I still continue to get the Avast warning window popping up ever few seconds.

    Let me know what I should be doing now.
    Thanks
     

    Attached Files:

  4. SandraS

    SandraS Private E-2

    Unfortunately the Avast virus warnings are still popping up. I rebooted after all the scans (which I did in safe mode) and the minute i was booted up I got the first warning. Same virus indicated, Trojano, I proceeded to delete, less than a minute later another warning for a trojano, different file location. I deleted that. Then 30 seconds later another warning but this time the virus was called Qoologic-D. Again deleted. I am sure you appreciate the frustration. Please let me know what my next step should be. Thanks
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to post a HijackThis log from normal boot mode but before doing that, run the below steps.

    Fisrt, download Nail/Bolder/Aurora Remover 0.3.1 Beta and save it to its own folder like c:\ABIremover

    - Now extract the abiremover.exe file from the ZIP file into the folder you created but do not run the EXE yet.

    - Reboot into Safe Mode with no network suppost and do not run anything else but what I tell you to run!

    - Run the ABIRemover.exe, press install, wait (explorer window will disapear)

    - When it finishes just reboot into normal mode get a new HJT log and attach it.
     
  6. SandraS

    SandraS Private E-2

    I installed ABIRemover rebooted and am attaching a new HJT log. Thanks for your help. Let me know what you would like me to do next!
    Sandra
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must remember to exit browsers ( C:\Program Files\Internet Explorer\IEXPLORE.EXE ) before running HijackThis.

    Open Control Panel and select Add/Remove programs. Uninstall the below if found.
    WeirdOnTheWeb
    WeatherBug
    wildtangent

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\psoft1.exe
    C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe
    c:\windows\system32\wqbjwej.exe
    C:\WINDOWS\inscdm\xwteieicnv.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://103.nowfind.biz/pps.php
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://103.nowfind.biz/pps.php
    R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://103.nowfind.biz/pps.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://103.nowfind.biz/pps.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://103.nowfind.biz/pps.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://103.nowfind.biz/pps.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://103.nowfind.biz/pps.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://103.nowfind.biz/pps.php
    O1 - Hosts: auto.search.msn.com 127.0.0.1
    O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr52.dll
    O2 - BHO: (no name) - {E044EE05-0045-FC30-A800-728758F6B6BE} - C:\WINDOWS\inscdm\xwteieicnv.dll
    O4 - HKLM\..\Run: [PSoft1] C:\WINDOWS\System32\psoft1.exe
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitepya32.exe
    O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
    O4 - HKLM\..\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"
    O4 - HKLM\..\Run: [pdeptc] C:\WINDOWS\System32\pdeptc.exe
    O4 - HKLM\..\Run: [eienitg] c:\windows\system32\wqbjwej.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O13 - DefaultPrefix: http://103.nowfind.biz/gall.php?url=
    O13 - WWW Prefix: http://103.nowfind.biz/gall.php?url=
    O13 - Home Prefix: http://103.nowfind.biz/gall.php?url=
    O13 - Mosaic Prefix: http://103.nowfind.biz/gall.php?url=
    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.19/ttinst.cab

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\WeirdOnTheWeb <--- the whole folder
    C:\Program Files\AWS <--- the whole folder
    C:\WINDOWS\cfgmgr52.dll
    C:\WINDOWS\inscdm\xwteieicnv.dll
    C:\WINDOWS\System32\psoft1.exe
    c:\windows\system32\wqbjwej.exe
    C:\WINDOWS\inscdm\xwteieicnv.exe
    C:\WINDOWS\System32\pdeptc.exe
    C:\windows\system32\elitepya32.exe <-- also delete all other filenames beginning with elite and ending with exe in the system32 folder.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and continue with the below.

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixIE.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixIE.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add into the registry, click YES!
    Now post a new HJT log. And tell us how things are working.
     
  8. SandraS

    SandraS Private E-2

    Went through the to do list here are few glitches:

    Control panel, Add/Remove programs. I uninstalled WeirdOnTheWeb however weatherbug and wildtangent was not listed.

    On Hijack "Open process manager" these two files were not listed
    c:\windows\system32\psoft1.exe
    c\program files\weirdontheweb\weirdontheweb.exe

    On the scan section these two lines were not on the list
    04-HKLM\\Run:[weirdontheweb] c:\program files\weirdontheweb\weirdontheweb.exe"
    04-HKLM\\Run:[eienitg] c:\windows\system32\wqbjwej.exe

    After fixing booted into safe mode could not find in Windows Explorer to delete:
    c:\WINDOWS\inscdm\xwteieicnv.dll (found the file with extention .dat or .log)
    c:\windows\system32\wqbjwej.exe
    c:\windows\system32\elitepja32.exe (or any file starting with elite)

    Ran Ccleaner then went to c:\windows\prefetch and deleted ALL files (there were 280 of them is that ok?)

    Reset websettings as instructed
    rebooted in normal mode copied quote box to notepad and added it to registry

    Ran a new HJT log which I will attach. I was excited hoping we were all clean but all of a sudden the Avast warning started up again telling me I have a virus on my computer. again stating trojano. Let me know how the log looks and if there is anything else I should do. Thanks
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is critical that you remember to exit browsers before running HijackThis. You had:

    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    Also notepad.exe was running. Did you have it open for some reason?

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to System Startup Service or SvcProc ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    System Startup Service

    If that does not work, try using the short name of the service: SvcProc

    Now exit HijackThis!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    c:\windows\system32\xwlsxuo.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [kvxhmp] c:\windows\system32\xwlsxuo.exe
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\system32\xwlsxuo.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    If any of these problem entries have reappeared with new names, do not power down or reboot your PC after posting your log. Just wait until after you receive my next instructions. You can physically disconnect from the internet for security.
     
  10. SandraS

    SandraS Private E-2

    Went to start, run, scrolled down to System Startup Service, right clicked, selecteted properties. I didn't need to select 'Stop Service' because it was already stopped. I did however, change start-up type to disabled.

    I opened HJT, opened program selected delete an NT service. It could not find System Startup Service so I used SvcProc. this it found and the message box asked "are you absolutely sure you want to delete" These kinds of message boxes always scare me. I am so afraid I will delete something wrong. However, I said yes. Now it said I need to reboot to take effect. I did not do that I just proceeded to HJT. Should I have?

    My hidden files are enabled so I moved to the kill process part. the file c:\windows\system32\xwisxuo.exe was not present. I clicked back without killing anything and ran scan
    O4 - HKLM\..\Run: [kvxhmp] c:\windows\system32\xwlsxuo.exe
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

    Was not present. So, I obviously couldn't fix anything.

    I did not move forward to reboot in safe mode because I thought i would check with you first to see if I did something wrong that these files were not present. Should I have rebooted in normal mode first before running HJT? Did I delete SvcProc incorrectly? (god I hope not, sorry my computer paranoia is setting in :rolleyes: ) or is it good that they were not present and I should just move forward.

    Let me know. Thanks!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Everything should be OK! The SvcProc is not something your wanted on your PC. That is why we were trying to disable and delete the file. Just reboot and post a new log. But are you sure that there are no other lines similar to:
    O4 - HKLM\..\Run: [kvxhmp] c:\windows\system32\xwlsxuo.exe

    These malware items have a tendency to rename themselves.
     
  12. SandraS

    SandraS Private E-2

    OK, I rebooted in safe mode. did not find the file c:\windows\system32\xwlsxuo.exe in windows explorer so I rebooted normal and did an HJT scan. the file that seems to look suspicious is O4 - HKLM\..\Run: [vrekas] c:\windows\system32\ojpufm.exe There always seems to be a similar line just with different letters. this time it was ojpufm. a scan i did previously had the same line with bsqacg. maybe this file name keeps changing letters?

    OK, I ran Ccleaner and deleted the items in the Prefetch folder. What the heck is Prefetch anyway? I have posted a new HJT log. Let me know how I'm doing. As I was writing this the Avast warning came up again. The file name where the virus was located is C:\WINDOWS\System32\DrPMon.dll the malware name is Win32:Trojano-1375 [Trj] I selected delete. Immediately after a new warning popped up C:\DOCUME~1\James\LOCALS~1\Temp\D2652\aurora.exe, name Win32:Trojano-1373 [Trj] again selected delete.

    OK, let me know what you think. Thanks!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's a poor choice for color selection! :eek:
    Did all of those files get deleted? It does not look like it because your nail/aurora problem has already come back. See the SvcProc is back too.

    I hope you did not reboot (as I requested) after posting your log! Because the problem file will probably have renamed again. Before I can post a fix, I need to know that you have not rebooted or powered down your PC.
     
  14. SandraS

    SandraS Private E-2

    Sorry about the color choice. After I posted I thought the same thing but I was so tired I didn't edit it. As you requested I did not power down awaiting your next post. As soon as I get my kids out the door to school I will check to see if the files deleted and recheck the SvcProc too and I'll let you know. Thanks
     
  15. SandraS

    SandraS Private E-2

    I checked on the SvcProc and it was still there. The service status was "stopped" however I did have to change the start-up type to disabled (from automatic) again. I then went again to HJT , delete an NT Service and proceeded to to delete SvcProc. It again indicated that I needed to restart for the action to take effect. I did NOT restart. I did not want the file names to change again on the HJT log until I got instruction from you. While I was doing this the Avast warning popped up with that same file name. C:\WINDOWS\System32\DrPMon.dll (better color? ;) ) I again deleted and then it popped up immediately again. this time when I went to delete it I got a message box that stated The system cannot find the file specified. Cannot process C:\WINDOWS\System32\DrPMon.dll So I went into Windows explorer to see if I could find the file. I could not find it so I ran a search on the C drive and it came up with:
    DrPMon.dll.2.vir -- in folder: c:\Program files\Alwil Software\Avast4\Data\moved. and DrPMon.dll.vir -- in same folder

    I also went into the Avast program to look into the chest. One of the options when a virus is found is to "move to chest" (my kids probably do that every once in a while) I went to the chest and deleted all the infected files.

    I will await further instruction from you. Thanks
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! What is the current status on the SvcProc service? Is it still disabled? Does it show in your HJT log? In fact post a current HJT log right now. Do not power down yet. What I will probably want you to do, is to pull the power plug to prevent a graceful shutdown. Quite often malware makes use of Windows shutdown procedures to recreate themselves. Just continue to wait until I look at the current HJT log before doing anything.
     
  17. SandraS

    SandraS Private E-2

    I went in to disable SvcProc I hit apply and it showed that it was disabled but it also said that i needed to reboot to complete the process. I did not reboot. I did close out of everthing and run a new HJT log. So here it is.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    c:\windows\system32\ojpufm.exe


    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [vrekas] c:\windows\system32\ojpufm.exe

    Now exit HijackThis.

    Download Pocket KillBox and extract it to its own folder.

    IMPORTANT: Now print these instruction or copy them locally. I want you to run all of the below steps while physically disconnected from the internet. Do not reconnect until I say to do so. And do not open a browser until I say to.

    OK! Disconnect now before continuing.

    Now run killbox.

    Now, Copy and Paste c:\windows\system32\ojpufm.exe into the box – If it exists, it will show up in Blue. Check the option to Replace on Reboot and also check the Use Dummy option and also check the End Explorer Shell While Killing File option too. Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    At this point, I want you to pull the power chord to your PC (yes you read that correctly). I want to try to prevent it from spawning on shutdown.

    Wait a couple minutes and plug your power chord back in and then reboot your PC.

    Now get a new HJT log. Reconnect to the internet, run your browser and come back here and post the HJT log. Tell us how the above steps went and where things stand now. Remember, if there is still a problem, do not reboot or power down after posting you HJT log.
     
  19. SandraS

    SandraS Private E-2

    SHOULD I PANIC? I followed your instructions. I unplugged the computer. When I plugged it back in and booted up I got a blank page that says "operating system not found". I am a little paniced. I am contacting you from a different computer. What should I do? Am I sunk? :(
     
  20. SandraS

    SandraS Private E-2

    PHEW! I unplugged again and this time when I booted up I hit F8 and it came up in safe mode. I rebooted in normal mode and it booted up. Phewey. I think my heart skipped a beat there for a moment. I will run a HJT log and post it. But I wanted to get back to you asap so you knew I could boot up. Back soon!
     
  21. SandraS

    SandraS Private E-2

    Looks like we didn't get rid of that process it looks like it's back just with different letters O4 - HKLM\..\Run: [vfdbfp] c:\windows\system32\gzpmxr.exe What is the deal with this thing. It's one tough buzzard! Should I try killing the process again and re-doing your last instructions?
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Download Nail FIX to a folder that you can locate. Then extract the files from the ZIP files into the folder you downloaded to. This should create a subfolder call NailFix with two files in it.

    Now exit all browser windows and use Windows Explorer to locate the folder and double click on nailfix.cmd. DO NOT BE ALARMED when your desktop blanks out and your Win Explorer window will close. After doing this, look at your HJT log and see if the F2 line with nail.exe and the O23 line with SvcProc on them are gone. If not, run the same process again after booting to safe mode.
     
  23. SandraS

    SandraS Private E-2

    OK, I downloaded nail fix. Followed your directions. When I checked the HJT log the F2 line was still there but no 023 line with SvcProc. So, I booted in safe mode. When I rebooted I received an message box that said that windows could not find C\Windows\nail.exe. I hit the ok button and preceeded to the nail fix file and again double clicked on the nailfix.cmd file. the computer responded as you said it would then I rebooted in normal mode ( received the same message box upon reboot, that windows cannot find C\Windows\nail.exe, I just clicked ok again) and did a HJT scan. The log still showed the F2 line: F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe but the 023 line was still gone. Did I do something wrong that I was getting that error message?

    While typing this the avast warning popped up again with the same virus: Win32 trojano found in that same file that I can't seem to delete or locate: C:\WINDOWS\System32\DrPMon.dll

    should I try the nail fix thing again? Or something else?
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think we need to get a firewall installed on your PC before trying to fix anything else. Go to How to Protect yourself from malware! and install one of the free firewalls. Make sure if you ever see a message from the firewall about nail.exe svcproc.exe or those strange file names from the O4 lines, that you block it from having any access and tell it to always do that.

    Also please do the following and tell me if all items are set as indicated:
    Right Click Start.
    Select Explorer.
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.
     
  25. SandraS

    SandraS Private E-2

    OK, Firewall is installed. I double checked the hidden file settings and they are set as they should be. I'm ready for my next assignment.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which firewall did you install and has anything popped up with warnings about any of the problem files we have been working on?
     
  27. SandraS

    SandraS Private E-2

    I installed Sygate. Some things have been popping up as being blocked but not anything that looks real familiar. The last two blocks that I saw pop up indicated ndisuio.sys
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The file is okay but I do not think it needs internet access. See: http://www.liutilities.com/products/wintaskspro/processlibrary/ndisuio/

    If you can figure what needs to be fix (you should be an expert by now ;) ) by yourself, try repeating some of the cleaning steps like in messages numbers 22, 18, and 9 as may apply.


    Is SvcProc running anymore? Did it reappear in your HJT log?

    Post a new HJT log after trying some fixes. Remember to always double check the fixes by rebooting to make sure that they are really fixed.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do one more thing for me! If that strange looking filename (the O4 line one) has come back, put a copy of it into a ZIP file and upload it here as an attachment. I want to look at it.
     
  30. SandraS

    SandraS Private E-2

    OK, I've been working on this. I can't seem to get rid of that strange 04 line. It seems to keep changing it's "letters" so I did step 18 again "killbox" I put in the box the current letters on the file name. (I hope I know what I'm doing!) it is currently showing up as c:\windows\system32\vjtdobr.exe. the file name showed up in blue. followed your instructions, did not reboot instead unplugged. When I booted back up I got an error message that read:
    c:\windows\system32\vjtdobr.exe the NTVDM CPU has encountered an illegal instruction CS:0562 IP:ffe2 OP:fe ff 1e 09 4f choose 'close' to terminate the application. it gave me the option to close or ignore. I didn't know what to choose so I chose close. When I ran the HJT log it was still there. Should I have chosen "ignore"?

    OK so I went into windows explore and found the file. I'm not sure if I'm doing this right but i told it to send to compressed (zipped) file. Now I will see if I can attach this. If I was to do this differently let me know. I will also attach the newest HJT log

    Also, with the firewall running there is an application that it asks me about. what is LSA Shell (export version) should this be unblocked?
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The file you compressed and uploaded is now only the dummy file the Pocket Killbox created.

    Have HJT fix the below line:
    O4 - HKLM\..\Run: [npimwo] c:\windows\system32\vjtdobr.exe

    Reboot into safe mode and run what we ran in message number 5:

    Nail/Bolder/Aurora Remover 0.3.1 Beta


    Then reboot into normal mode. Let's see it anything comes back. If it does, it would mean there is another hidden process around that is regenerating this crap. If a new O4 line does appear, upload that file for me (in a ZIP file).
     
  32. SandraS

    SandraS Private E-2

    Whoo Hoo! I think we finally got rid of it. I don't see it on the HJT log. I am attaching the current log. Let me know what you think. The only other question I had was about the LSA Shell (Export Version) which is showing up on the firewall as a running application but keeps asking if I want to block it. I'm not sure what it is and if it is a safe application. Do you know?

    Other than that if things look good to you I will turn my System restore back on and redo the hidden file stuff. Thanks for all your help and for being so patient! ;)
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  34. SandraS

    SandraS Private E-2

    I think I'm doing ok. I ran the sasser remover. While it was running Avast popped up 4 times telling me I had a virus and they were in those same files as before. I selected delete. After it was done running I rebooted and checked the HJT log and that strange 04 line did not reappear. This is a good thing. I ran a full Avast scan and it came up with 0 infected files. This is also a good thing. I asked my kids how it was running and they said they were not getting all the avast warnings anymore. so, I'm hoping we're good. Phew... Do you think I'm clear to put system restore back on? Is there anything else you think I should do? Thank you very much for all your help on this stubborn problem.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds