Wilders Security Forums  

Go Back   Wilders Security Forums > Browser Hijacks and Spyware Problems > adware, spyware & hijack cleaning
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 10th, 2003, 11:32 AM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default System1060 virus

Hi
My first visit to your site, so if I make any mistakes or am a bit slow on the uptake, my apologies

My question is this: For a few weeks now I have been plagued with a ?virus which is detected by the excellent Spybot.

This ?virus is called (by Spybot) System1060:auto run settings and System1060:program file (yep there are two!

They disguise themselves as Microsoft system files Taskmgr.exe and Twunk 64 and when one looks at the file it looks exactly like the proper Microsoft file (wording as well).

What it actually does is to dial home (I do not know which home) every time you start up the computer.

Sorry this is so long but am coming to the end shortly.

unfortunately it keeps coming back even after Spybot has deleted it. Soooooo I was wondering if you had any solution for keeping this at bay.

Thanx a lot, and many thanx for providing this site!

Mikul :'(
  #2  
Old November 10th, 2003, 11:36 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,298
Default Re:System1060 virus

Hi mikul,

Welcome at Wilders.
Please follow the steps described here (obviously you can skip the one where you have to scan with Spybot S&D):
http://www.wilderssecurity.com/showthread.php?t=15913

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #3  
Old November 10th, 2003, 12:21 PM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default Re:System1060 virus

Many thanx Pieter I will let you know what happens

Kind regards Mikul
  #4  
Old November 13th, 2003, 11:30 AM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default System 1060 virus

Hi

My question is this: For a few weeks now I have been plagued with a ?virus which is detected by the excellent Spybot.

This ?virus is called (by Spybot) System1060:auto run settings and System1060:program file (yep there are two!

They disguise themselves as Microsoft system files Taskmgr.exe and Twunk_64.exe and when one looks at the file it looks exactly like the proper Microsoft file (wording as well).

What it actually does is to dial home (I do not know which home) every time you start up the computer.

I have run Spybot which detects and deletes these files.
Unfortunately it keeps coming back even after Spybot has deleted it.

Adaware does not seem to find them (but I have only just started using it so it may be me)

Hijackthis finds one of the files which is: O4 - HKLM\..\Run: [TaskMgr] C:\PROGRA~1\INTERN~1\tskmgr32.exe.

I have attached a Hijackthis log file. Please help!

Thanx a lot, and many thanx for providing this site!

Mikul
Attached Files
File Type: txt Hijackthis_log.txt (5.6 KB, 0 views)
  #5  
Old November 13th, 2003, 11:41 AM
Unzy's Avatar
Unzy Unzy is offline
Spyware Expert
 
Join Date: Nov 2003
Location: Belgium
Posts: 1,098
Default Re:System 1060 virus

Hi mikul,

That is indeed a baddy, a homepage hijacker.

Have hijackthis fix it while staying offline :

O4 - HKLM\..\Run: [TaskMgr] C:\PROGRA~1\INTERN~1\tskmgr32.exe

Reboot after doing so and remove manualy :

C:\PROGRA~1\INTERN~1\tskmgr32.exe <- this file

Hope this helps,

Cheers,
  #6  
Old November 14th, 2003, 03:00 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re:System 1060 virus

Is this a trojan ? if you still have it, send it to submit@diamondcs.com.au for analysis

This might be a good idea for ALL unknown things in peoples logs We are happy to provide the analysis and then detection of course
  #7  
Old November 14th, 2003, 06:14 AM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default Re:System 1060 virus

Hi

For your information regarding ?virus system 1060.

This little devil sits in the C:\Program files\Internet explorer folder and is called tskmgr32.exe. What it does is to dial home every time you start up your computer, (I do not know where 'home' is except that it isn't mine!) however I, (and anyone unlucky enough to get infected with it) will be charged for the calls. Following instructions I attempted to get rid of it with Spybot SD, Hijackthis, and Adaware.

There are actually two files 1. System1060: autorun settings which is in the Registry at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmgr32.exe and the second is in C:\ Program files\Internet explorer folder on my C drive.

Spybot SD managed to pick up the files and appeared to fix the problem, however the 'virus' kept coming back. Hijackthis is exactly the same result.

As instructed I attempted to get rid of this file by getting Hijack this to eradicate it however the file was still there. (I did this both online and offline) I then rebooted and attempted to get rid of the file manually, the system would not allow me to do this so I deleted it via DOS apparantly successfully.

I also manually deleted the line HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmgr32.exe.

Spybot SD does get rid of both files. However I am still losing my hair because the second I went back online it instantly reinfected my computer.

Help! What can I do to get rid of this parasite!

I use Mcaffee antivirus program which doesn't stop it either, nothing appears to stop this.

I am sure there must be an answer somewhere, so anyone reading this I would appreciate an answer to this very annoying (not to mention costly) problem.

Thanx for your help thus far

Mikul
  #8  
Old November 14th, 2003, 11:14 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re:System 1060 virus

Try disabling system restore first, and perform the cleaning actions once more. After doing so, you can safely enable system restore again.

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #9  
Old November 14th, 2003, 07:22 PM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default Re:System 1060 virus

Hi Paul

I have tried all of the above and its no longer a problem to get these files off my hard drive. Spybot SD does that perfectly.

however, as soon as I log onto the Internet back they come!

I would be grateful if anyone reading this has some idea of how I can stop this happening.

Cheers Mikul
  #10  
Old November 15th, 2003, 10:01 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,087
Default Re:System 1060 virus

Here are some tips on prevention:

So how did I get infected with all that spyware in the first place?

Cheers,
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #11  
Old November 17th, 2003, 04:40 AM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default Re:System 1060 virus

Hi

Attached is an answer I received from Symantec after I sent them a copy of the System1060. In short they determine this to be a Trojan.

IMPORTANT! Spyguard will block this from executing should you be infected with it.

My thanx to all who have helped me in this and I sincerely hope this will help anyone else unfortunate enough to get infected with this.

Recommended reading: "So how did I get infected with all that spyware in the first place?" from Tony Klein which also has all the necessary links for Spyguard and a host of other programs - thanx Tony!


Cheers Mike
Attached Files
File Type: txt letter_from_symantec.txt (2.7 KB, 0 views)
  #12  
Old November 17th, 2003, 07:37 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,087
Default Re:System 1060 virus

You're welcome, Mikul.

Glad to hear the information in the article was useful to you.
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #13  
Old November 18th, 2003, 10:51 AM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default Re:System1060 virus

Hi

Sorry folks in my first attempt to make a reply to above subject, I made it a 'new topic' instead, so there are two of these running, covering the same topic.

THE OTHER ONE HAS MORE INFORMATION AND SOLUTIONS!

Cheers Mikul
  #14  
Old November 18th, 2003, 11:00 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,298
Default Re:System1060 virus

Quote:
quoting: mikul link=board=17;threadid=16290;start=0#msg102339 date=1069170692]
Hi

Sorry folks in my first attempt to make a reply to above subject, I made it a 'new topic' instead, so there are two of these running, covering the same topic.

THE OTHER ONE HAS MORE INFORMATION AND SOLUTIONS!

Cheers Mikul

I merged the two threads, so everything is in one place. It may look a bit odd, because they were sorted according to the time they were posted.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #15  
Old November 18th, 2003, 11:39 AM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default Re:System1060 virus

Hi

Thanks for merging the two threads.

I noticed at the bottom of my Hijackthis.log was this line: O17 - HKLM\System\CCS\Services\Tcpip\..\{E2C125D2-1E74-43ED-8A3F-103FB0C68150}: NameServer = 195.50.80.131 195.50.80.132

I ran a search of my Registry which could not find this line...does anyone know what this is for or if it could be dodgy?

Thanx again, and again, and again...ad infinitum!

Mikul
  #16  
Old November 18th, 2003, 11:43 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,298
Default Re:System1060 virus

You will probably find these DNS servers in the properties of your internet-connection.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #17  
Old November 18th, 2003, 12:27 PM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default Re:System1060 virus

Its me again re the hklm line above.

I used a program called nslookup to check the IP address and it worked beautifully and came up with the address of my ISP.

Anyone any idea why the ISP would have its address in my Registry, or is that just normal on installing?

One does hear of some ISPs doing dodgy things. Would this enable them to be able to read my hard drive?

Cheers Mikul
  #18  
Old November 18th, 2003, 02:53 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,087
Default Re:System1060 virus

It resolves to BOLTBLUE-UK, which I take it is your provider.

No harm there...
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #19  
Old November 18th, 2003, 05:24 PM
mikul mikul is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 10
Default Re:System1060 virus

Aggggh!

It goes on and on etc...

I had deleted the file from my computer BEFORE switching off.

I then switched on again and BEFORE going on to the internet I thought I would just check to see if it was still gone... and lo and behold, there it was, as bold as brass, sitting in my Internet explorer folder.

So I now have to assume that somewhere there is another file on my computer which is reinstalling this on startup, even after it has been deleted.

Anyone any ideas?

Mikul
  #20  
Old November 18th, 2003, 05:42 PM
subratam's Avatar
subratam subratam is offline
Spyware Fighter
 
Join Date: Nov 2003
Location: Issaquah, WA
Posts: 1,254
Default Re:System1060 virus

if u think something else is autostarting and installing the syware or mayb trojan... i think you can try this

1-) Autostart Folder Methode :-

The Autostart folder is located in C:\Windows\Start Menu\Programs\start
and any file put there will start automatically when windows start

2-) Win.ini Methode :

open the win.ini file and if you found
[windows]
load= trojan
run= trojan
NullPort=None
BaseCodePage=1256
so your PC is batched and you have trojan , so delete anything after the "="
sign

3-) System.ini Methode :

Same as win.ini file .. open up system.ini
if you find shell=Explorer.exe trojan.exe , the trojan will start after
explorer start
and as your desktop is an explorer , so it will start every time windows
start

4-) The registry methode :

Registry is often used in various auto-starting methods. Here are some known
ways:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
"Info"="c:\directory\Trojan.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"Info="c:\directory\Trojan.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Info"="c:\directory\Trojan.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Info"="c:\directory\Trojan.exe"

- Registry Shell Open

[HKEY_CLASSES_ROOT\exefile\shell\open\command]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]

A key with the value "%1 %*" should be placed there and if there is some
executable file placed there, it will be executed each time you open a
binary file. It's used like this: trojan.exe "%1 %*"; this would restart
the trojan.
__________________
Malware Researcher | Microsoft Corporation

These postings are provided "AS IS" without warranty, and confer no rights.
 

Wilders Security Forums > Browser Hijacks and Spyware Problems > adware, spyware & hijack cleaning « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 09:13 PM.


Powered by vBulletinŪ Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright Đ2002 - 2009, Wilders Security Forums