Virus - HijackThis log (J.exe)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Geezer99, Jun 2, 2010.

  1. Geezer99

    Geezer99 Private E-2

    Hi, I'm currently running Comodo internet security & recently updated to the latest version which includes the Sandbox. Every so often (at least every hour) it informs me that a prog called 'J.EXE' is running in the sandbox and do I want to keep it in the sandbox or not.

    I've ran a complete virus scan using several antivirus progs available on the market and none find anything. Comodo isn't actually recognising it as malware as it prompts me each time a new prog tries to run that I haven't previously ok'd. Even it I OK J.EXE to run out of the sandbox, it again prompts me on the next occasion which obviously means that J.EXE is being recreated each time - hence its probably a new and different file each time.

    I also run Threatfire, and on examination of its history, I noticed that it had caught and deleted a virus which seems to have been the main part of J.EXE in December of last year, it had found (B.EXE, C.EXE etc.) so I'm assuming this J.EXE is the remnants of the old virus. But still seems strange that none of the antivirus progs I've ran have found anything.

    I've uploaded 2 files (HijackThis.Log & StartupList.txt).

    Any advice and guidance would be appreciated.

    Many thanks

    Graham
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.


    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Geezer99

    Geezer99 Private E-2

    Here's the logs for SuperAntiSpyware, mbam & ComboFix.

    Wasn't able to run RootRepeal and I've included the log file for that. MG Tools didn't appear to run, but I'm going to reboot & try that again.

    Many thanks

    Graham
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see an MGtools folder in your ComboFix log which means MGtools at least extracted. You have to make sure you follow the instructions for using it with Vista. For example, you had to disable UAC and you had to reboot after disabling UAC. Also you have to right click on MGtools.exe and select Run As Administrator.
     
  5. Geezer99

    Geezer99 Private E-2

    Was able to run MGTools in Safe mode and I've attached the log.

    Still was unable to run RouteRepeal even in safe mode.

    I've currently uninstalled Comodo Security Suite and Threatfire. I've also uninstalled many of my hardware drivers (nvidia system board and graphics), sound etc. As I initially thought as I stepped through trying to locate this problem - the less stuff that was installed the better.

    In reply to your post: UAC was off and I'd selected to Run As Admin.

    Thanks for prompt reply.

    Graham
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on all of your logs, you are not having malware problems. The only item I question at all is the below folder:
    Code:
    "C:\Windows\System32\"
    WAT           18 May 2010              "Wat"
    You should cleanup the below left over folders from things you have uninstalled:
    Code:
    "C:\ProgramData\"
    ALWILS~1       1 Jun 2010              "Alwil Software"
    COMODO~1      30 May 2010              "Comodo Downloader"
      
                                                                                  
    "C:\Program Files\"
    ALWILS~1       1 Jun 2010              "Alwil Software"
    AVG           31 May 2010              "AVG"
    REGIST~1      31 May 2010              "Registry Watch"
    TRENDM~1       2 Jun 2010              "Trend Micro"
    And then you should delete the below folders from ComboFix
    Code:
    32788R~1       3 Jun 2010              "32788R22FWJFW"
    32788R~2.TMP   2 Jun 2010              "32788R22FWJFW.1.tmp"
    32788R~3.TMP   2 Jun 2010              "32788R22FWJFW.2.tmp"
    COMBOFIX       3 Jun 2010              "ComboFix"

    Then since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  7. Geezer99

    Geezer99 Private E-2

    OK, I'll start doing as you ask and putting my pc back together. but the question still stands with regards 'J.EXE'. What is it? Where's it come from? and whats it doing? It seems very strange that no av prog will pick it up. I even ran Threatfire set to maximum warings which prompts on even the most minor issues - and then allowed J.EXE to run outside of the sandbox and still nothing. The leftover directories are testiment to the other av progs I've used but to no avail.

    I'll reinstall my drivers and av software and take a screenshot when J.EXE pops up. Its certainly becoming a pain in the proverbial butt.

    I can only assume its a bit of a leftover virus which isn't actually doing anything apart from executing several times a day. The downside is that even telling Comodo to let it run externally from the Sandbox so that it doesn't keep prompting me doesn't work - as Comodo see's it as a new file each time - and therefore prompts me.

    Thanks very much for your prompt replies and assistance, its massibly appreciated.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not in any of your logs nor in any of the process running so I cannot tell you. You should have run scans while j.exe was trying to load. Also I you should look in Task Manager and enable it to show Image Paths ( the path to where a program is running from ) so that you can see exactly where the file is located. That may help you identify what it is from.

    If you have a problem identifying where the file is on your PC then don't reload Comodo initially and see if you can find the file. After all you have no protection right now and the process is not running and obviously even if it did run and terminate before you ran the scans, it obviously is not doing anything to cause problems. I would bet that right now it is not running at anytime, which would seem to imply it was related to something you may have uninstalled while uninstalling everything.
     
  9. Geezer99

    Geezer99 Private E-2

    It reappeared as soon as I had Comodo installed & running. I've tried running various av progs as soon as I let it out of the sandbox. I've also checked task manager & processes to see if I can identify it at the moment it runs. Also tried searching for it by name as soon as I've released it to run on the pc. All to no avail. I tried installing a prog that took a snapshot of the system prior to allowing J.EXE to run then seeing what had changed on the pc, but the prog I used didn't display the info in the manner I expected it to (ie. filenames changed etc). So I'll keep looking for a snapshot viewer that might do the job.

    I can only assume it is only running for a split second while its doing something, then deletes itself until the next time when something flags it to run again. I managed to capture a screeny, but also managed to screw it up when cropping into paint. I'll get it next time & post it. In fact I'll reboot now & it should show up within maybe 5 minutes.

    The only certainty is that 'J.EXE' is still there and has been running whilst Comodo hasn't been installed.

    Very weird I reckon.

    Thanks for your feedback. I gotta admit to tearing my hair out on this one, I've been battling with it now on & off for a few days.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to in the past or are you referring to right now.

    Did you see it in Task Manager.


    Then perhaps you need to investigate more deeply where Comodo is finding it and then also just allow it to run. I doubt it is a problem since no malware is showing in your logs. If it is really running, it is more likely something that you run. As I said before, it was not running at the time you ran any of our scans and nothing in your logs shows any signs of any hidden processes,services, drivers...etc.
     
  11. Geezer99

    Geezer99 Private E-2

    Here you go, within a minute of rebooting.

    Its appearance hasn't changed from previously. I'd systematically uninstalled drivers and it still appeared. Even after uninstalling all nVidia drivers, sound driver and anti-virus software (+ a few more utils I run), I'd only have to reinstall Comodo for it to appear. Unless its actually a part of Comodo which of course it can't be. When Comodo displays it, it doesn't show where the file is/was, only that its trying to run. I've let it run numous times out of the sandbox and don't appear to have anything detrimental take place, but thats not necessarily a reason to allow it to continue on its merry way.

    Wierd eh?
     

    Attached Files:

    Last edited: Jun 2, 2010
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see my last message?

    Is it in Task Manager? You need to have a log while this is trying to run that shows a full path process list like MGtools does. If it does not show in Task Manager, you need a better tool like Process Explorer or you need to get Comodo to provide you with more information on where the file is. Click on the j.exe which is blue and underlined. It may give more info.
     
  13. Geezer99

    Geezer99 Private E-2

    I've installed Process Explorer. Am going to try to grap screenshots as soon as I allow J.EXE out of the sandbox so that I'll have a 'Before & After' image.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A screen shot is actually of no use to us unless it is identifying where the process is running from. In addition, Process Explorer can easily dump things to a log and it can show full image name paths. Below is an example that select explorer.exe but you could select j.exe. Also it shows you how to setup PE to show things and to save a log.



    Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on explore.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
     
  15. Geezer99

    Geezer99 Private E-2

    I don't think that will work. It seems to me that whatever is running is only running for a split second before it self deletes and goes away to hide until the next time it rears its ugly head.

    Seems to me the only way it could be done is if I can record the desktop with some video software while Process Explorer is running and when J.EXE pops up. then (in theory) I'd record whatever processes started & stopped at that time.

    the screenshots I've taken which are probably equally useless are a before and after. The only thing that appeared to show up was DLLHOST.EXE listed as COM SURROGATE. But obviously its certainly not the most scientific method of stabbing PrntScn to catch a problem.

    Your thoughts?

    Graham
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you setup PE as I suggested to show Image Path? If so, then just leave PE open so you can watch it and see where the j.exe file is located. After all you said it occurs frequently. You can also put PE into your Startup folder so that automatically loads at startup to try and catch this early during bootup.

    Also did you try clicking on the blue underlined j.exe in Comodo to see if it gives more info. Normally there is a way to get more info when things like this popup.

    Another few questions to answer are:
    1. Does this happen if you do not open any browsers or run any application? Just simply boot up and do nothing?
    2. Does it happen if your connection to the internet is physically unplugged?
    3. Does this also appear if you boot in safe mode?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also after seeing if you can catch it in PE and trying the steps to answer my questions, run the below in normal boot mode and attach the log.


    GMER - running with a random name
     
  18. Geezer99

    Geezer99 Private E-2

    Here's a screen cap of what shows after clicking on J.EXE and after booting up & just waiting to see if it appeared. I also unplugged my network (but stupidly forgot to disable the wifi - will do that next boot).

    I don't believe it happens with a safe boot - but will also test that next also.

    Will also run GMER.

    Thanks again for taking the time to try sorting this. I think I'm probably heading to a reformat and reinstall of Windows.

    Graham
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that shows you that the j.exe file does not even exist. What you need to find out is what other process is trying to find and load j.exe
     
  20. Geezer99

    Geezer99 Private E-2

    I was thinking along the lines that something is creating it & running it & its being deleted straight after? Otherwise Comodo wouldn't be flagging it (maybe).

    I've attached the log file requested. Just had a BSOD, first one in quite a while, tells me something is certainly not a happy little bunny in the pc.

    I've also put a question on Comodo's forum concerning Sandbox, will keep you informed as to replies.

    Graham
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The problem is that Comodo is not identifying what is running but rather it is identifying something that a program that is already running is trying to run which is fairly useless.


    Not helpful! You have Disk Emulation Software cluttering up the log. See step 6 of the READ & RUN ME and disable Daemon Tools. Also Comodo is cluttering up the log too with its files. And then you added Threatfire on top of it which I would strongly not recommend. I suggest that you uninstall Threatfire and anything else from PCTools and then Run step 6 of the READ & RUN ME to disable Daemon Tools and then rerun GMER and attach a new log.

    Is the below file name what GMER was randomly named?
    C:\Users\Graham\Desktop\4jrhzqbl.exe
     
    Last edited: Jun 3, 2010
  22. Geezer99

    Geezer99 Private E-2

    Many thanks for your time and assistance. But in the end I gave up & reinstalled Windows. Finally "J.EXE' is no more!

    Whatever it was & whatever it did it certainly hid itself well.

    Thanks again.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Sorry to hear you had to reinstall. What I question now is have you reinstalled everything that I previously saw running like all of the below which I saw in your logs? It would be interesting to see if after reinstalling to have the exact same setup, whether this reoccurs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds