Author Topic: Possible Tojan  (Read 27137 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Possible Tojan
« Reply #15 on: November 07, 2007, 09:59:27 PM »
I suggest AVG or Trend Micro RootkitBuster (for XP/Vista). For XP: Panda (for XP). They're more simple.
The best things in life are free.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #16 on: November 07, 2007, 10:23:22 PM »
The infection is W32/Mitglieder.HT as per F-Prot

To fix the safeboot:
 
Download & run this tool > SafeBootKeyRepair-CF http://www.techsupportforum.com/sectools/sUBs/SafeBootKeyRepair-CF.exe
It shall only take a short moment for it to finish running. A log shall be produced at C:\SafeBoot_Repair.txt. Please post that in your next reply and let me know if you can access Safe Mode now?

Please re-open HiJackThis and scan.  Check the boxes next to all the entries listed below.

O20 - Winlogon Notify: ldr64 - C:\WINDOWS\system32\ldr64.dll (file missing)
O20 - Winlogon Notify: mmx432 - C:\WINDOWS\system32\mmx432.dll (file missing)

Now close all windows other than HiJackThis, then click Fix Checked.  Close HiJackThis. 

THEN

Please download the OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe by OldTimer.
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\system32\ldr64.dll
C:\WINDOWS\system32\mmx432.dll


Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply with a new Hijack log.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

The files will be quarantined

One service I am unable to find any decent information about is
O23 - Service: E4M service (e4mservice) - Unknown owner - C:\WINDOWS\system32\e4mserv.exe

Jotti File Submission:
  • Please go to Jotti's malware scan

  • Copy and paste the following file path into  the  "File to upload & scan"box on the top of the page:

    • C:\WINDOWS\system32\e4mserv.exe
  • Click on the submit button
  • Please post the results in your next reply.

ecotack

  • Guest
Re: Possible Tojan
« Reply #17 on: November 07, 2007, 10:54:31 PM »
SafeBootKeyRepair-CF text file reads:

Reg export of safeboot key after repair:
=============================

Just that, nothing else.

Won't go into safe mode
HJT didn't re-boot this time, but those files where not in the list.  "hidr.exe" was so I Fixed it.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #18 on: November 07, 2007, 11:16:12 PM »
What was the location of hidr.exe as that file needs to be quarantined it is Trojan W32.Beagle.DZ

It looks like the trojan stopped the cf fix from working but I have another way around it


Download & run the safe mode fix here
Extract to your desktop, now you have a new file on your desktop called SafeBoot.reg
Double click and allow it to merge into your registry.

Try Safe Mode now.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #19 on: November 07, 2007, 11:17:40 PM »
Just found a reference it may be here %Userprofiles%\Application Data\hidires\hidr.exe

where %Userprofiles% is your user name

ecotack

  • Guest
Re: Possible Tojan
« Reply #20 on: November 08, 2007, 12:17:30 AM »
OK, will start in Safe mode now, can't find any of the two dlls in system23 or the hidr.exe.

E4M - Encryption for the masses, one of the projects merged in with drive crypt

Just re-booted and run RootKitBuster, nothing found
SuperAntiSpyware found nothing to

Re-installed Avast, chose a boot time scan, re-booted, it worked, no more message about Avast being changed.  Its found a Small-BXN [trj] up to now, I’ll let it finish, do a through scan, also with SuperAntiSpyware and once more with RootKitBuster for good luck.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #21 on: November 08, 2007, 09:54:13 PM »
Sounds good could you post the SAS log, just extract the log file method from the following

 

  • On the first page select Check for Updates
  • On completion select SCAN YOUR COMPUTER
  • On the next page select COMPLETE SCAN and tick ALL your drives
  • The next stage will take a while as your entire drive(s), memory and registry are scanned
  • When it has completed click NEXT
  • The next screen shows the problems found click OK
  • On the next screen place a tick against all items and select NEXT
  • Now to get the log Go to the PREFERENCES button on the right bottom
  • Select the STATISTICS/LOG tab
  • Highlight the scan just completed and click VIEW LOG
  • This will open a notepad text file copy and paste this to your next reply

ecotack

  • Guest
Re: Possible Tojan
« Reply #22 on: November 12, 2007, 09:54:25 PM »
Back to square one  >:(

I just lost all network access, so did a scan with RootKitBuster (RKB) and the hidr.exe file had re-appeared.  I used the safe mode fix again, went into safe mode, ran HJT, checked the hidr.exe file and clicked fix.

Once rebooted I checked with RKB, which found hidr.exe and srosa.sys.  I highlighted the two files and selected delete, then re-booted the PC.  Avast had been deleted again so I reinstalled and set a boot time scan.

Is there anything I can do to detect if these Trojans install again? I had Avast home installed and Comodo firewall.  I also checked with RKB and SAS every day and found nothing 

ecotack

  • Guest
Re: Possible Tojan
« Reply #23 on: November 13, 2007, 09:45:09 AM »
No network access  ???

Gone through all network settings, re-installed drivers, re-booted router, swapped cables, disabled the firewall, un-installed the firewall, re-installed the firewall, but still can not access the LAN.  I could yesterday before the Trojan re-appeared.

I think the Trojan may have changed something or left something behind.  Any suggestions?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Possible Tojan
« Reply #24 on: November 13, 2007, 11:48:06 AM »
I think the Trojan may have changed something or left something behind.  Any suggestions?
As a last resource, maybe http://www.majorgeeks.com/download4372.html (WinSock XP Fix 1.2) or, less probably, any function of http://www.majorgeeks.com/download4899.html (Dial-a-fix 0.60.0.24).

WinSock: Fixes the winsock settings on your Windows XP machine. This tool is recommended for IT professionals only. Please read license.

It can often cure the problem of lost connections after the removal of Adware components or improper uninstall of firewall applications or other tools that modify the XP network and Winsock settings.

If you encounter connection problems after removing network related software, Adware or after registry clean-up; and all other ways fail, then give WinSock XP Fix a try.

It can create a registry backup of your current settings, so it is fairly safe to use. We actually tested it on a test machine that was having a Winsock problem due to some Adware removal, and after running the utility and rebooting, the connectivity was restored.
The best things in life are free.

ecotack

  • Guest
Re: Possible Tojan
« Reply #25 on: November 13, 2007, 12:28:07 PM »
Thanks, I'll put them on a memory stick and try them this evening.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Possible Tojan
« Reply #26 on: November 13, 2007, 12:36:08 PM »
Thanks, I'll put them on a memory stick and try them this evening.
You're welcome. Other users will be here and trying to help.
I'll be on an one-week trip 8)
The best things in life are free.

ecotack

  • Guest
Re: Possible Tojan
« Reply #27 on: November 13, 2007, 10:19:28 PM »
I'll be on an one-week trip 8)

Its alright for some, my last holiday was 14 years ago. 

Tried the two programs but network still won't work.  It says Status: Connected, Duration: <increasing>, Speed 100.0 Mbps, Sent: 0 and received: 0.

Anymore suggestions? Anyone??
Can't ping the router, or any other PC on the network.  Can't view workgroup computers.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #28 on: November 13, 2007, 10:27:01 PM »
Try this
http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FxBeagle.exe

Locate the file that you just downloaded.
Double-click the FxBeagle.exe file to start the removal tool.
Click Start to begin the process, and then allow the tool to run.
Restart the computer.
Run the removal tool again to ensure that the system is clean.


Then run
Download WinPFind3u.exe  to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. If, after posting, the last line is not < End of Report > then the log is too big to fit into a single post and you will need to split it into multiple posts.

ecotack

  • Guest
Re: Possible Tojan
« Reply #29 on: November 13, 2007, 10:54:27 PM »
As I was sat here reading this I noticed the Avast icon disappear on my infected PC.  A quick scan with RootKitBuster and the two files are back (hidr.exe and srosa.sys).  I scanned it less than two minutes ago and it was clean.

W32.Beagle removal tool is now running, lets keep our fingers crossed.