Trouble getting rid of Troj_Agent.fz

Discussion in 'Malware Help (A Specialist Will Reply)' started by radiohead_1, Apr 26, 2005.

  1. radiohead_1

    radiohead_1 Private E-2

    I've recently been experiencing the odd popup (~ every 40 minutes or so), and decided to scour my computer for possible malware. I've followed the instructions listed here (http://forums.majorgeeks.com/showthread.php?t=35407), and though all the spyware tools have been pretty clean, Trend Micro detected the virus Troj_Agent.fz. It's located in the file c:\windows\inf\binras.dll, which I've tried to delete. Unforutunately, it seems to have managed to merge with winlogon, and I've been having trouble deleting it (mostly attempted through HJT and killbox, in safe mode). It's been pretty malignant except for earlier today, when it seemed to make a (deletable) copy of itself in a folder it created, c:\1sumbit.

    Any help would be greatly appreciated. HJT logs will be posted at request.

    Thanks in advance.
     
  2. radiohead_1

    radiohead_1 Private E-2

    Scratch that - HJT log attached.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the Announcement at the top of the every page. Please do not post HijackThis logs unless they are requested.

    The c:\!submit folder is a backup folder created by Pocket Killbox to protect you against improper deletes an also it is used to save file for submission to people to look at.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:

    regsvr32 /u C:\WINDOWS\inf\binras.dll

    then click OK. If a dialog box confirming this action appears, click OK. If you get an error message, just OK it and continue.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - (no file)
    O20 - Winlogon Notify: binras - C:\WINDOWS\inf\binras.dll

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\inf\binras.dll

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. radiohead_1

    radiohead_1 Private E-2

    Thanks for the quick response. All steps done, word for word, until this point. It won't let me delete the file (used by another person or program). I can provide you with a list of running processes at your request, but nothing seems out of the ordinary.

    On a side note, I seem to be having trouble booting up explorer.exe on normal safe mode. Is safe mode with network support sufficient for this step?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm don't understand what you mean by the above.

    Are you saying you cannot click Start and select Explore to run Windows Explorer.

    What happened when you tried to unregister the file.

    Try booting into safe mode and just try a rename of the file. Rename binras.dll to binras.ddd (that is if it let's you).
     
  7. radiohead_1

    radiohead_1 Private E-2

    - When attempting to boot up (regular) Safe mode everything seems normal, past the drivers and user log-on, until the desktop begins to load. The pop-up window stating that i'm in safe mode (with the yes/no to continue option) comes up, and immediately disappears. I'm left with the cursor, and the "safe mode" writing in the corners, with the OS version info at the top. When I try to re-run explorer from the task manager, it does the same thing - pops up the "you are running in safe mode" message, and then disappears. explorer.exe isn't an active listed process. There is no task bar, desktop, or start menu. Interestingly enough, I can boot up in Safe mode with Network Support with no problems. Everything seems to work fine.

    - Unregistering the file gave me a successful message.

    - My attempt to rename the binras.dll file (from safe mode with network support) gave me the same error message: "Cannot rename binras: It is being used by another person or program. Close any programs that might be using the file and try again."

    Once again, thanks for the continued help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I think I understand now. But when you boot in normal mode (not safe mode) everything works okay...right?

    Please run in normal mode and locate the c:\windows\inf\binras.dll file and right click on it from Windows Explorer. Then select Properties and then the Version tab (if it has one) and if it has a Version tab work you way thru the Item name list and let's see what other info we can get on this file. Also tell me how big it is.

    Download ProcessExplorer from: http://www.sysinternals.com/files/procexpnt.zip
    Unzip it to its own folder like c:\SysInternals and now run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    Now click on File and then Save As. And save the process list. Post it back here as an attachment.

    Now with one Internet Explorer window open, go back and repeat the above but instead of select explorer.exe, select iexplore.exe and save a second process list. Post that back here too as an attachment.

    Now repeat the above a third time but select winlogon.exe. This third process list will need to be posted in a second message (only two attachments per message are allowed).
     
  9. radiohead_1

    radiohead_1 Private E-2

    Instructions followed.

    - binras.dll did not have a version tab - only a general and summary. It's 409 KBs.

    - Attached are the process lists from explorer.exe and iexplore.exe.
     

    Attached Files:

  10. radiohead_1

    radiohead_1 Private E-2

    - Attached is the process list from winlogon.exe.

    ninja edit: yes, everything works fine when run in "normal" mode.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmm! binras.dll has hook itself into all three of the programs check against. It may be hooked into everything.

    I'm not sure if the below will work but let's give it a try.

    Make sure you exit ALL Internet Explorer sessions before continuing so print or save these instructions locally.

    Please run Pocket KillBox (you said you already have it)

    Below you will be entering items into Pocket KillBox. Please read thru all of the instructions so that you understand the steps and do not do something we do not want. Okay! Now select the “Delete on Reboot” and “End Explorer Shell While Killing File ” Options. Now Copy&Paste this filename C:\WINDOWS\inf\binras.dll into the box, making sure Delete on Reboot and End Explorer Shell While Killing File are checked. Click the Red X to Delete the file, but and then answer yes to allow your machine to Reboot.

    If you get a Pending File operations type error message, just reboot your PC yourself.
     
  12. radiohead_1

    radiohead_1 Private E-2

    Thanks for the reply Chaslang.

    Did as you asked, and did indeed get the PendingFileRenameOperations message, after which I manually rebooted. Upon reboot, the file still exists in the /windows/inf directory, and is still listed in the (updated) logs of HJT and procexp, which can be posted at your request.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot into safe mode (with no network connectivity - unplug cable to be sure) and do not run anything else. Then repeat the steps using Pocket Killbox. When it reboots, let your system reboot to normal mode.

    Tell me the results.
     
  14. radiohead_1

    radiohead_1 Private E-2

    Ok, instructions followed.

    Cable removed, but as above, I had a problem booting up safe mode (without network support). However, once the loading processes stopped (with the lack of a desktop or start menu), I ran killbox through the task manager. I once again got the PendingFileRenameOperations message, and rebooted manually.

    Though I haven't run any programs or made any logs since the reboot, I've confirmed through windows explorer that the file binras.dll is indeed still there, in the same /WINDOWS/inf directory. Steps will be followed and logs posted, at your request.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download the following tool: L2MeFix Tool

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Get a new HijackThis log.
    Now come back here and post the l2mfix log and the new HJT log as attachments.

    Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  16. radiohead_1

    radiohead_1 Private E-2

    Thanks for the continued support Chaslang, it's much appreciated.

    Attached are the l2mfix log (report.txt) and the HJT log.

    Have not rebooted, and await further instructions.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixbad.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixbad.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.
    Print or save these instructions locally now because you will have to be disconnected with no browsers open in the next step.

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log later when the remaining steps are completed.

    Again, don't run any other files in the L2MFix folder.
     
  18. radiohead_1

    radiohead_1 Private E-2

    Did as you asked.

    Notepad contents saved as a .reg file, and added to registry.
    All browser windows closed, cable unplugged.
    Ran l2mfix.bat, and selected option 2.
    Computer did indeed go bazonkers, and spat out the attached log.
     

    Attached Files:

    • log.txt
      File size:
      9.1 KB
      Views:
      1
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the below entry still in your HJT log?
    O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - C:\WINDOWS\inf\binras.dll

    If so, can it be fixed now. Does that file still exist? If so, is it deletable now?

    If not, do the below again:

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixbad.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixbad.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.
    Then pull the power plug to your PC. Yes, that's what I said. I do not want a graceful shutdown. Then wait 2 minutes and power backup into safe mode. Look for the C:\WINDOWS\inf\binras.dll file and see if you can delete it.
    Now reboot in normal mode and tell me what happened. Is the log clean now.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One other question. Look in the C:\WINDOWS\inf folder for other similar named files. Like binras.exe or binras.ini or binras.dat.

    Do you see any? Are there any other files which similar dates to binras.dll
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the other steps do not work (probably will not), try this.

    Reboot in Safe Mode (do not open any other processes)
    - Run Process Explorer

    In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.
    Once you see this screen click on each instance of binras.dll once and then click the kill button.

    After you have killed all of the binras.dll's under winlogon click ok.
    Next double click on explorer.exe and again click once on each instance of binras.dll then click the kill button. Once you have done that click ok again.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - C:\WINDOWS\inf\binras.dll
    O20 - Winlogon Notify: binras - C:\WINDOWS\inf\binras.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad.
    Save it as fix.reg to your desktop.
    Ensure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.
    In Killbox - put a check next to "Delete on Reboot"
    Copy & paste the following line in bold into the "Full Path of File To Delete" box:
    C:\WINDOWS\inf\binras.dll
    Then click the red button with the X and allow Killbox to reboot then post a new HijackThis log.
     
  22. radiohead_1

    radiohead_1 Private E-2

    Yes, it's still in the log. I still can't delete it.

    Instructions followed, and the log is still not clean.

    There are no other binras files. binras.dll was created on April 10th, and the closest any other file comes to it, by modified dates, is April 12th.

    Steps followed, and it seems to have worked. Attached is the HJT log. I believe it is fixed, and if so, thanks tons. :) But, awaiting your confirmation regardless.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Looks like it is gone to me! Are you still clean? If so, let try to stay that way by following all steps not yet completed that are given in the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds