Unsolved
This post is more than 5 years old
1 Message
0
1228
December 22nd, 2005 21:00
HJT log file - possible unknown Trojan?
I am having no luck removing this thing from one of my file servers.
There are two unwanted files in a directory:
readme.htm
folder.htt
When users access this directory, Norton pops up targeting the readme.htm as being a Trojan that it cannot delete.
If I delete these files manually they are quickly recreated by one of four applications:
pcc2003sw100.pif
recover.pif
setup.exe
important.exe
These applications appear quickly and then vanish.
When they appear they are caught by NOD32 running on this machine and identified as Threat: probably unknown NewHeur_PE virus
Any help would be greatly appreciated. -Tim
Logfile of HijackThis v1.99.1
Scan saved at 1:05:20 PM, on 12/22/2005
Platform: Windows 2003 SP1 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP1 (6.00.3790.1830)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ServerAppliance\appmgr.exe
C:\Program Files\Dell\OpenManage\dataeng\bin\dcevt32.exe
c:\Progra~1\Dell\LEDSVC\dcledsvc.exe
C:\Program Files\Dell\OpenManage\dataeng\bin\dcstor32.exe
C:\WINDOWS\system32\ServerAppliance\elementmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\sfmprint.exe
C:\Program Files\Dell\OpenManage\Array Manager\mr2kserv.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Dell\OpenManage\oma\bin\omsad32.exe
C:\Program Files\Dell\OpenManage\iws\bin\win32\omaws32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\ServerAppliance\srvcsurg.exe
C:\Program Files\Dell\OpenManage\Array Manager\VxSvc.exe
C:\msnfs\mapper\mapsvc.exe
C:\WINDOWS\system32\nfssvc.exe
D:\VERITAS\Backup Exec\NT\beremote.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Eset\nod32kui.exe
D:\VERITAS\VxUpdate\VxTaskbarMgr.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://support.dell.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://support.dell.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/
F2 - REG:system.ini: UserInit=C:\\WINDOWS\\system32\\userinit.exe,
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PRONoMgrWired] c:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [VxTaskbarMgr] D:\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O14 - IERESET.INF: START_PAGE_URL=http://support.dell.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1135280096859
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - https://eefs:1279/tsweb/msrdp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F2455F1-A2D0-47D4-B6B5-A938DF5DE7B3}: NameServer = 198.6.1.146,198.6.1.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{2F2455F1-A2D0-47D4-B6B5-A938DF5DE7B3}: NameServer = 198.6.1.146,198.6.1.3
O17 - HKLM\System\CS2\Services\Tcpip\..\{2F2455F1-A2D0-47D4-B6B5-A938DF5DE7B3}: NameServer = 198.6.1.146,198.6.1.3
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Systems Management Event Manager (dcevt32) - Dell Inc. - C:\Program Files\Dell\OpenManage\dataeng\bin\dcevt32.exe
O23 - Service: Dell NAS LED Service (DCLEDSvc) - Unknown owner - c:\Progra~1\Dell\LEDSVC\dcledsvc.exe
O23 - Service: Systems Management Data Manager (dcstor32) - Dell Inc. - C:\Program Files\Dell\OpenManage\dataeng\bin\dcstor32.exe
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: mr2kserv - Unknown owner - C:\Program Files\Dell\OpenManage\Array Manager\mr2kserv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: OM Common Services (omsad) - Dell Inc. - C:\Program Files\Dell\OpenManage\oma\bin\omsad32.exe
O23 - Service: Secure Port Server (Server Administrator) - Unknown owner - %SystemDrive%\Program Files\Dell\OpenManage\iws\bin\win32\omaws32.exe (file missing)
O23 - Service: Disk Management Service (VxSvc) - VERITAS Software Corp. - C:\Program Files\Dell\OpenManage\Array Manager\VxSvc.exe


RKinner
2 Intern
•
5.9K Posts
0
December 22nd, 2005 23:00
F2 - REG:system.ini: UserInit=C:\\WINDOWS\\system32\\userinit.exe,
is the only thing in your logfile that looks funny. Normally this would be:
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
Haven't run Hijackthis on a 2003 so can't say if this is normal or not. Double slashes would usually mean an invisible folder name but again can't say with 2003.
Where do these files live? Example to find important.exe:
Start, Run, cmd. OK then in the black screen type:
c:
cd \
dir /a /s important.exe
Any chance these are false positives?
Have you tried submitting them to one of the testing services like:
http://www.malwareupload.com/index.php?lang=en
Trend Micro uses a file:
pcc2003sw100.exe
I suspect if 2003 has the same prefetch folder as XP:
c:\windows\prefetch
and you ran Trend at one time there might be a .pif in there.
folder.htt
is a template file. The master is in C:\windows\web
http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q181689
Can you see if these are the same size? You can open them in notepad or wordpad and look at them to see what they do.
There is normally a recover.exe in your system32 folder so there could also be a recover.pif in prefetch.
No telling about setup.exe. Pretty common name. Important.exe is a worm if found in C:\ and is called w32/Mirsa.
http://us.sophos.com/virusinfo/analyses/w32mirsab.html
I did find one example of a bug that used both names:
http://vil.nai.com/vil/content/v_135302.htm
Did you try the rootkitrevealer from:
http://www.sysinternals.com/Utilities/RootkitRevealer.html
or BlackLight:
Download and run blacklight
F-Secure Blacklight: http://www.f-secure.com/blacklight/try.shtml
leave scan through windows explorer checked,
click > scan then > next,
If any items show have blacklight rename them except for wbemtest.exe"
Do not rename "wbemtest.exe" its a windows file
The tool will ask if you want to reboot (restart) choose yes.
you can try mwav.exe from:
http://www.spywareinfo.dk/download/mwav.exe
and install it and check for updates then
Download the Killbox.
http://www.downloads.subratam.org/KillBox.exe
or
http://www.bleepingcomputer.com/files/spyware/KillBox.zip
Save it to the desktop. Unzip it to the desktop if using the second link.
reboot into Safe Mode (F8) and run the escan(mwav) program. Select Drive and All Files then Clean Scan (or Scan Clean?) and let it run for a few hours (like maybe overnight!). It will eventually create a log file. It will remove anything it finds that it considers a virus or try to. Adware it just flags in the log. You have to go through the log for entries like:
Fri Jul 29 10:25:26 2005 => File C:\WINDOWS\System32\06wu29rd.exe tagged as not-a-virus:AdWare.F1Organizer.g. No Action Taken.
(hint use Wordpad's Edit, Find to search for: not-a-virus)
then use killbox to clean the adware manually. Double-click Killbox.exe to run it.
Select "Delete on Reboot".
Place the full path in the "Full Path of File to Delete" box in Killbox:
example: C:\WINDOWS\System32\06wu29rd.exe
Press the red button, agree you want to delete the file but do not let it reboot yet. Repeat for every not-a-virus entry then let it reboot after the last one.
Files removed by killbox are stored in a folder C:\!Submit or !killbox.
Ron