Various Trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by craigy_b, Feb 27, 2006.

  1. craigy_b

    craigy_b Private E-2

    Hi,
    I've followed the "Read First...." thread. The only thing I couldn't do was install windows defender for some reason.
    The other scans found trojans etc but none of them have been able to remove or disinfect them.
    I also ran trojan scan but no joy.

    I also keep getting McAfee blocking a program called rdgus2406.exe.
    Any help would be appreciated.

    Hijack This, Bitdefender and Activescan logs are attatched.

    Cheers
    Craig
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    You cannot install Windows Defender because you have not validated your OS with Microsoft. Until you do that, you cannot get many of their updates and patches. Windows Defender is just one example.

    You did not follow the directions in step 6 for creating a BitDefender log. All you posted was a summary log that is of no use to us. It does not indicate where problems are found nor if they were fixed.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install the below KeyGen to illegally install software? There is a potential root cause of your malware problems.
    C:\[KeyGen] Windows Keygen Pack (APMKPR2).rar[kEyGeN.exe]


    Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later. You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winexz32.dll once and then click the kill button. After you have killed all of the winexz32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winexz32.dll and kill it.


    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - Winlogon Notify: winexz32 - C:\WINDOWS\SYSTEM32\winexz32.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\TEMP\win44.tmp.exe
    C:\WINDOWS\TEMP\win18.tmp.exe
    C:\WINDOWS\TEMP\win44.tmp.exe
    C:\WINDOWS\TEMP\win18.tmp.exe
    C:\WINDOWS\TEMP\win44.tmp.exe
    C:\WINDOWS\SYSTEM32\winexz32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.


    After reboot use Windows Explorer to delete any remaining files in
    C:\Windows\TEMP

    Now attach a new HJT log and tell me how the steps went.
     
    Last edited: Feb 27, 2006
  4. craigy_b

    craigy_b Private E-2

    Ok,
    followed the steps you gave me and there have been a few changes.

    Killbox deleted the files specified but when I tried to delete other files I was left with:
    sqlite_ImF8GSokLZwGKgv
    sqlite_oBlkxL67qdO33in
    sqlite_5itoaICKifQLB5S
    All in C:\windows\temp

    Also, when I connected to internet to post this I got a message saying a program was trying to reconnect me to:
    66.117.37.13 and when I said no it said it was trying to connect to:
    c:\windows\system32\shdoclc.dll

    Attatched the latest HijackThis log.

    Thanks
    Craig
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That IP address is for
    Is this your ISP?

    Note: You never installed HJT properly per step 7. You have it here:

    C:\Documents and Settings\Craig Buchanan\Desktop\HijackThis.exe

    Unless you are still having malware problems, it is too late for this cleanup, but you should get it installed properly just in case you have future need of it.

    You log is clean! How are things working?
     
  6. craigy_b

    craigy_b Private E-2

    Sorry, didn't think it mattered where it was installed, put it on desktop for convenience.

    The IP address is not my ISP, never heard of the company before.

    Everything seems to be running ok. Scanned with McAfee and it found a few new trojans but was able to remove them this time and not really had any bother since.

    Thanks for your help.

    Craig
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! But that is why we emphasize this message in step 7 of the READ ME.


    Okay! But is this still happening?


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds