Unsolved

This post is more than 5 years old

1228

December 22nd, 2005 21:00

HJT log file - possible unknown Trojan?

I am having no luck removing this thing from one of my file servers.

 

There are two unwanted files in a directory:

 

readme.htm

folder.htt

 

When users access this directory, Norton pops up targeting the readme.htm as being a Trojan that it cannot delete.

 

If I delete these files manually they are quickly recreated by one of four applications:

 

pcc2003sw100.pif

recover.pif

setup.exe

important.exe

 

These applications appear quickly and then vanish.

 

When they appear they are caught by NOD32 running on this machine and identified as Threat: probably unknown NewHeur_PE virus

 

 

 

Any help would be greatly appreciated. -Tim

 

 

Logfile of HijackThis v1.99.1

Scan saved at 1:05:20 PM, on 12/22/2005

Platform: Windows 2003 SP1 (WinNT 5.02.3790)

MSIE: Internet Explorer v6.00 SP1 (6.00.3790.1830)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\ServerAppliance\appmgr.exe

C:\Program Files\Dell\OpenManage\dataeng\bin\dcevt32.exe

c:\Progra~1\Dell\LEDSVC\dcledsvc.exe

C:\Program Files\Dell\OpenManage\dataeng\bin\dcstor32.exe

C:\WINDOWS\system32\ServerAppliance\elementmgr.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\inetsrv\inetinfo.exe

C:\PROGRA~1\Iomega\System32\AppServices.exe

C:\WINDOWS\system32\tcpsvcs.exe

C:\WINDOWS\system32\sfmprint.exe

C:\Program Files\Dell\OpenManage\Array Manager\mr2kserv.exe

C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe

C:\Program Files\Eset\nod32krn.exe

C:\Program Files\Dell\OpenManage\oma\bin\omsad32.exe

C:\Program Files\Dell\OpenManage\iws\bin\win32\omaws32.exe

C:\WINDOWS\System32\snmp.exe

C:\WINDOWS\system32\ServerAppliance\srvcsurg.exe

C:\Program Files\Dell\OpenManage\Array Manager\VxSvc.exe

C:\msnfs\mapper\mapsvc.exe

C:\WINDOWS\system32\nfssvc.exe

D:\VERITAS\Backup Exec\NT\beremote.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

c:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe

C:\Program Files\Eset\nod32kui.exe

D:\VERITAS\VxUpdate\VxTaskbarMgr.exe

C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

C:\WINDOWS\System32\svchost.exe

c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

C:\HJT\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://support.dell.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://support.dell.com/

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/

F2 - REG:system.ini: UserInit=C:\\WINDOWS\\system32\\userinit.exe,

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [PRONoMgrWired] c:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe

O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKLM\..\Run: [VxTaskbarMgr] D:\VERITAS\VxUpdate\VxTaskbarMgr.exe

O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

O14 - IERESET.INF: START_PAGE_URL=http://support.dell.com/

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1135280096859

O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - https://eefs:1279/tsweb/msrdp.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2F2455F1-A2D0-47D4-B6B5-A938DF5DE7B3}: NameServer = 198.6.1.146,198.6.1.3

O17 - HKLM\System\CS1\Services\Tcpip\..\{2F2455F1-A2D0-47D4-B6B5-A938DF5DE7B3}: NameServer = 198.6.1.146,198.6.1.3

O17 - HKLM\System\CS2\Services\Tcpip\..\{2F2455F1-A2D0-47D4-B6B5-A938DF5DE7B3}: NameServer = 198.6.1.146,198.6.1.3

O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll

O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\beremote.exe

O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\benetns.exe

O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\pvlsvr.exe

O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\bengine.exe

O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\benser.exe

O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\beserver.exe

O23 - Service: Systems Management Event Manager (dcevt32) - Dell Inc. - C:\Program Files\Dell\OpenManage\dataeng\bin\dcevt32.exe

O23 - Service: Dell NAS LED Service (DCLEDSvc) - Unknown owner - c:\Progra~1\Dell\LEDSVC\dcledsvc.exe

O23 - Service: Systems Management Data Manager (dcstor32) - Dell Inc. - C:\Program Files\Dell\OpenManage\dataeng\bin\dcstor32.exe

O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - D:\VERITAS\Backup Exec\NT\ECM\ECM.exe

O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe

O23 - Service: mr2kserv - Unknown owner - C:\Program Files\Dell\OpenManage\Array Manager\mr2kserv.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe

O23 - Service: OM Common Services (omsad) - Dell Inc. - C:\Program Files\Dell\OpenManage\oma\bin\omsad32.exe

O23 - Service: Secure Port Server (Server Administrator) - Unknown owner - %SystemDrive%\Program Files\Dell\OpenManage\iws\bin\win32\omaws32.exe (file missing)

O23 - Service: Disk Management Service (VxSvc) - VERITAS Software Corp. - C:\Program Files\Dell\OpenManage\Array Manager\VxSvc.exe

 

 

 

2 Intern

 • 

5.9K Posts

December 22nd, 2005 23:00

F2 - REG:system.ini: UserInit=C:\\WINDOWS\\system32\\userinit.exe,

is the only thing in your logfile that looks funny.  Normally this would be:

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,

Haven't run Hijackthis on a 2003 so can't say if this is normal or not.  Double slashes would usually mean an invisible folder name but again can't say with 2003.

 

Where do these files live?    Example to find important.exe:

 

Start, Run, cmd. OK then in the black screen type:

c:

cd \

dir /a /s important.exe

 

 

Any chance these are false positives?

Have you tried submitting them to one of the testing services like:

 

http://www.malwareupload.com/index.php?lang=en

 

Trend Micro uses a file:

pcc2003sw100.exe

I suspect if 2003 has the same prefetch folder as XP:

c:\windows\prefetch

and you ran Trend at one time there might be a .pif in there.

folder.htt

is a template file.  The master is in C:\windows\web

http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q181689

 

Can you see if these are the same size?  You can open them in notepad or wordpad and look at them to see what they do.

 

There is normally  a recover.exe in your system32 folder so there could also be a recover.pif in prefetch.

 

No telling about setup.exe.  Pretty common name.  Important.exe is a worm if found in C:\ and is called w32/Mirsa. 

http://us.sophos.com/virusinfo/analyses/w32mirsab.html

I did find one example of a bug that used both names:

http://vil.nai.com/vil/content/v_135302.htm

 

Did you try the rootkitrevealer from:

http://www.sysinternals.com/Utilities/RootkitRevealer.html

or BlackLight:

Download and run blacklight
F-Secure Blacklight: http://www.f-secure.com/blacklight/try.shtml
leave scan through windows explorer checked,
click > scan then > next,
If any items show have blacklight rename them except for wbemtest.exe"
Do not rename "wbemtest.exe" its a windows file
The tool will ask if you want to reboot (restart) choose yes.

you can try mwav.exe from:

http://www.spywareinfo.dk/download/mwav.exe
and install it and check for updates then
 Download the Killbox.
http://www.downloads.subratam.org/KillBox.exe

or


http://www.bleepingcomputer.com/files/spyware/KillBox.zip
Save it to the desktop.  Unzip it to the desktop if using the second link.


 reboot into Safe Mode (F8) and run the escan(mwav) program.  Select Drive and All Files then Clean Scan (or Scan Clean?) and let it run for a few hours (like maybe overnight!).  It will eventually create a log file.  It will remove anything it finds that it considers a virus or try to.  Adware it just flags in the log.  You have to go through the log for entries like:
Fri Jul 29 10:25:26 2005 => File C:\WINDOWS\System32\06wu29rd.exe tagged as not-a-virus:AdWare.F1Organizer.g. No Action Taken.


(hint use Wordpad's  Edit, Find to  search for: not-a-virus)

then use killbox to clean the adware manually. Double-click Killbox.exe to run it.
Select "Delete on Reboot".
Place the full path  in the "Full Path of File to Delete" box in Killbox:
example:  C:\WINDOWS\System32\06wu29rd.exe
Press the red button, agree you want to delete the file but do not let it reboot yet.  Repeat for every not-a-virus entry then let it reboot after the last one.

 

Files removed by killbox are stored in a folder C:\!Submit or !killbox.

 

Ron

 

No Events found!

Top