4 Trojan virus, help me please ? [cleaned, thanks a lot essexboy and all of you]

Ok Borlan is now proving to be a pain you must have one of the later versions so I will try another tool to kill it.

First disable Prevx by going Start>run then type in MSconfig press enter. On the dialogue that appears got to start up and remove the ticks next to all related Prevx items. then Apply. On restart a dialogue will appear just tick do not show this again

First re-run Killbox again

[*] Please double-click Killbox.exe to run it.
[*] Select:
[*]Delete on Reboot[*] then Click on the All Files button.

[*]Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\system32\updstdup

[*] Return to Killbox, go to the File menu, and choose Paste from Clipboard.

[*]Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).[/list]

If your computer does not restart automatically, please restart it manually.

If you receive a message such as: “Component ‘MsComCtl.ocx’ or one of its dependencies not correctly registered: a file is missing or invalid.” when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

We will now use the latest version of combofix, combofix new link is http://download.bleepingcomputer.com/sUBs/...aB/combofix.exe save to your desktop

Could you please download and run via the start > run box pasting in “%userprofile%\desktop\combofix.exe” /wow-drv albus

Be advised it took about 8 goes to finally kill it in my last encounter. But it can be killed…

First disable Prevx by going Start>run then type in MSconfig press enter. On the dialogue that appears got to start up and remove the ticks next to all related Prevx items. then Apply. On restart a dialogue will appear just tick do not show this again

Please, what do you mean ? Do I have to start Prevx to find this menu ?

(And, I’m sorry, but there’s a lot of virus which are coming since I’m following your advises. As Avast! seems to be able to take care of these, it’s not a real problem but still it’s quite annoying… is it normal ?)

I have just noticed you do not appear to have a firewall is this correct. If so please download ZAFree from here http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp

(And, I'm sorry, but there's a lot of virus which are coming since I'm following your advises. As Avast! seems to be able to take care of these, it's not a real problem but still it's quite annoying... is it normal ?)

No it is not unless they are dcom exploits being blocked

Please, what do you mean ? Do I have to start Prevx to find this menu ?

No, it is the windows start button press that and on the right you will see an icon marked run. Select that and then type msconfig on the box that appears then press enter

This is the same place that you will need to paste the following when you get the lates version of combofix

“%userprofile%\desktop\combofix.exe” /wow-drv albus

Hm, that link doesn’t exist : 404 file not found :confused:

Thanks for warning me. I was begining to desespair but, could you please tell me what dos combofix ? I’m following your advises as if I were blind, but I trust you.

Combo fix cures a variety of malware items in one go rather than dowloading 4 or 5 tools to do the same job. Plus it also shows me recently added files which may be associated with known malware and any new malware files. I will recheck the link with the author to confirm it is correct.

As an Interim fix while I wait for a reply please reboot into safe mode
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Then run the Boran removal tool again

Here:

06/11/2006 @ 19:49:09,29

Found C:\WINDOWS\system32\drivers\albus.sys

Rebooting…

Attempting to disable albus.sys…
Unsuccessful; may still be active.

Attempting to remove files and directories:
C:\WINDOWS\system32\drivers\Albus.SYS . . . FAILED
C:\WINDOWS\system32\Albus.DAT . . . FAILED
C:\WINDOWS\system32\alsmt.exe . . . FAILED
C:\WINDOWS\system32\std.ini . . . FAILED
C:\WINDOWS\system32\stdd.ini . . . FAILED
C:\WINDOWS\system32\updadini.ini
C:\WINDOWS\system32\updstdex.ini
C:\WINDOWS\system32\updstdup.ini . . . FAILED
C:\WINDOWS\system32\stdcache
C:\WINDOWS\system32\updadini
C:\WINDOWS\system32\updstdex
C:\WINDOWS\system32\updstdup . . . FAILED

Rebooting…

Attempting to disable albus.sys…
Unsuccessful; may still be active.

Attempting to remove files and directories:
C:\WINDOWS\system32\drivers\Albus.SYS . . . FAILED
C:\WINDOWS\system32\Albus.DAT . . . FAILED
C:\WINDOWS\system32\alsmt.exe . . . FAILED
C:\WINDOWS\system32\std.ini . . . FAILED
C:\WINDOWS\system32\stdd.ini . . . FAILED
C:\WINDOWS\system32\updstdup.ini . . . FAILED
C:\WINDOWS\system32\updstdup . . . FAILED

Unable to remove infection; giving up.

Did you try avast boot time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot.

Please download Sophos anti rootkit http://www.sophos.com/products/free-tools/sophos-anti-rootkit/download/ filling in the requested details at the bottom of the page and then clicking submit, this will then take you to the download page .

Then run the programme it will create a folder in C:\sophtemp locate the file sarqui and run. When the programme has finished go to START > RUN and paste in the following into the window %TEMP%\sarscan.log and click OK to execute.

A textfile will open. Save it to your desktop

Rename Killbox.exe to Gotcha.exe by right clicking the file and selecting re-name

[*] Please double-click Gotcha.exe to run it.
[*] Select:
[*]Delete on Reboot[*] then Click on the All Files button.

[*]Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\system32\drivers\Albus.SYS
C:\WINDOWS\system32\Albus.DAT
C:\WINDOWS\system32\alsmt.exe
C:\WINDOWS\system32\std.ini
C:\WINDOWS\system32\stdd.ini
C:\WINDOWS\system32\updadini.ini
C:\WINDOWS\system32\updstdex.ini
C:\WINDOWS\system32\updstdup.ini
C:\WINDOWS\system32\stdcache
C:\WINDOWS\system32\updadini
C:\WINDOWS\system32\updstdex
C:\WINDOWS\system32\updstdup

[*] Return to Killbox, go to the File menu, and choose Paste from Clipboard.

[*]Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).[/list]

If your computer does not restart automatically, please restart it manually.

Post the content of that file.

Excuse me for that late replie due to my work. And, is it sarcli or sargui ?

No problem it is

SARGUI. a blue shield icon
I have been reviewing the recent successful removal of my last victim and you appear to have a later version than him which is why it seems, confusing to you. I am having to try variations on a theme. Chin up though it can be beaten. 8)

I can’t start what doesn’t exist …

There’s no SARQUI in it.
I’d like to send you a screencap to proove it but, unfortunatelly, the Inernet is being worse and slower than ever. I’ve been trying 10 times before that post can be sent~ it’s pure luck when a window is open correctly.

and… there’s now 26 programm in Prevx Jail or which aren’t allowed to run by this programm.

Look for the blue shield icon

To give you a feel for how bad this trojan is here is a small analysis

This infection uses multiple layers of protection to keep itself loaded. There is one driver and two services -- Albus (albus.sys), JMediaService (mmssver.dll), and StdService (stdsver.dll). Albus watches itself and the %programfiles%\MMSAssist directory (where JMediaService lives). StdService will regenerate missing pieces of this infection. Trying to stop any of the three services using normal means is futile. You cannot delete any of the critical files while the infection is active. Additionally, Albus watches for registry changes against itself and will block changes. This can lead to a deadlock if you try to edit the registry to remove it while it is active.

There is now an updated version of the boran removal tool at http://deckard.be/tools/beta/boran-remover-26.exe Please download and run

Close all open windows.
Double-click boran-remover-26.exe to start the tool.
Your computer will reboot if an infection is found.
If the tool is unable to neutralize the infection, it will reboot again for another attempt.
When the tool is finished, it will save a log called boran.log in the boran-remover folder on your Desktop. Please include this log with your next post.

Found C:\WINDOWS\system32\drivers\albus.sys
Found C:\WINDOWS\system32\stdupnet.dll

Rebooting…

Attempting to disable albus.sys…
Successful!

Attempting to remove files and directories:
C:\WINDOWS\system32\albus.dll
C:\WINDOWS\system32\alstd.dat
C:\WINDOWS\system32\std.ini
C:\WINDOWS\system32\stdact.ini
C:\WINDOWS\system32\stdd.ini
C:\WINDOWS\system32\stdplay.dll
C:\WINDOWS\system32\stdstub.dll
C:\WINDOWS\system32\stdup.uni
C:\WINDOWS\system32\stdupnet.dll
C:\WINDOWS\system32\stdvote.dll
C:\WINDOWS\system32\updstdup.ini
C:\WINDOWS\system32\exupstd
C:\WINDOWS\system32\stdcache
C:\WINDOWS\system32\updadini
C:\WINDOWS\system32\updstdex
C:\WINDOWS\system32\updstdup
C:\WINDOWS\Temp\insshell
C:\WINDOWS\Temp\winnt1

Searching for possible unknown Boran files
Not all files listed will be bad - do not remove unless instructed!
C:\WINDOWS\system32\drivers\aliide.sys
C:\WINDOWS\system32\spool\drivers\color\stdpyccl.icm

Cleaning Registry…
Done!

Excellent please now post a new HJT log ;D

nice work EB :wink:

Ah Clossau I had practice on my last victim which prepared me for several failures before success. All I should need to do now is tidy up and delete the restore points

Scan saved at 22:52:19, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\AOL\1154804588\ee\AOLSoftware.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Leïla Chihab\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://haschishin.livejournal.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM..\Run: [ATIPTA] “C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe”
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM..\Run: [BO1HelperStartUp] C:\PROGRA~1\BUTTER~1\BO1HEL~1.EXE /partner BO1
O4 - HKLM..\Run: [FSASWREG] “C:\Program Files\Securitoo\Av_Fw\Anti-Spyware\fsaswreg.exe”
O4 - HKLM..\Run: [TkBellExe] “C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe” -osboot
O4 - HKLM..\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1154804588\ee\AOLSoftware.exe
O4 - HKLM..\Run: [IPHSend] C:\Program Files\Fichiers communs\AOL\IPHSend\IPHSend.exe
O4 - HKLM..\Run: [PrevxOne] “C:\Program Files\Prevx1\PXConsole.exe”
O4 - HKCU..\Run: [msnmsgr] “C:\Program Files\MSN Messenger\msnmsgr.exe” /background
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU..\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: wkcalrem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Lancement rapide d’Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra ‘Tools’ menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)

Once again, sorry for the late and thanks for taking care of me bows I’m in your debt!