Author Topic: Somebody knows about rekgggems.exe ?  (Read 5794 times)

0 Members and 1 Guest are viewing this topic.

Offline Hezad

  • Sponsor
  • Pentium
  • *******
  • Posts: 613
  • Karma: 44
  • I believe .. in Patrick.
    • View Profile
    • Hezad.com Web hosting
Somebody knows about rekgggems.exe ?
« on: December 07, 2008 »
Heya :)

I just noticed a process running on my PC, called rekgggems.exe

Obviously, I googled it but didn't find anything. Well, if it doesn't appear on the indexed pages, it must be relatively unknown lol but I really want to know what it is. I can't close it, it starts with windows, and some minutes ago, it ate all my CPU cycles, I had to reboot.

Anyone ever saw this process ?

Thanks


edit -> some more informations :

The process is always running, but he ate my CPU cycles only when I try to read a CD from my DVD drive with WinAmp. In fact, I'm wondering if it couldn't simply be some sort of an anti-copy protection on the CD ? (As I said, it runs with windows, but in the cases I checked, there was always the CD in the drive)


To be continued ..  ;D
« Last Edit: December 07, 2008 by Hezad »

Offline Clyde

  • A Little Fuzzy Wuzzy
  • DBF Aficionado
  • ******
  • Posts: 7271
  • Karma: 71
    • View Profile
Re: Somebody knows about rekgggems.exe ?
« Reply #1 on: December 09, 2008 »
I tried to find some info for you dude, sadly no luck at present.

A few suggestions that might help you.

You could try searching for where the exe is from on your HD, also perform a virus scan see if it's slipped through the net. And try ending the process in Task Manager, and see what it affects.

Plus you could go to control panel, and add / remove programs, and see if its listed there.
Still Putting The IT Into Gravy
If Only I Knew Then What I Know Now.

Challenge Trophies Won:

Online va!n

  • Pentium
  • *****
  • Posts: 1435
  • Karma: 109
    • View Profile
    • http://www.secretly.de
Re: Somebody knows about rekgggems.exe ?
« Reply #2 on: December 10, 2008 »
@hezad:
why not boot in safe mode and use free tools like autoruns to see if you can disable starting the program somewhere and/or find out its location on the drive and deleting in safe mode.

To find where its located and what tasks are running and sometimes being able to kill tasks (where taskman failed), is the free tool called ProcessExplorer

good luck.
 
[edit]
btw, just try this great programm for scanning malware: webadress

- hp EliteBook 8540p, 4 GB RAM, Windows 8.1 x64
- Asus P5Q, Intel Q8200, 6 GB DDR2, Radeon 4870, Windows 8.1 x64
http://www.secretly.de
Challenge Trophies Won:

Offline Hezad

  • Sponsor
  • Pentium
  • *******
  • Posts: 613
  • Karma: 44
  • I believe .. in Patrick.
    • View Profile
    • Hezad.com Web hosting
Re: Somebody knows about rekgggems.exe ?
« Reply #3 on: December 10, 2008 »
Thanks mates :)

@Clyde :

Quote
try searching for where the exe is from on your HD
Tried :S Nothing found.

Quote
perform a virus scan
'didn't do it yet. I'll give it a try :)

Quote
And try ending the process in Task Manager
Tried (often :P). Most of the time it quits normally and it reloads itself and opens the C:/ folder at the same time in which I noted two new files were present :

Autorun.inf
Quote
[AutoRun]
open=quseqdnec.exe
shellexecute=quseqdnec.exe
shell\Auto\command=quseqdnec.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkfk1

and quseqdnec.exe

Sometimes, the process can't be closed. Right now it seems that the process has been closed and didn't reload itself (I ran a SpyBot scan/repair in the night. It didn't detect that process or the files I found in C:/ but it did actually detected some stuff.


Quote
go to control panel, and add / remove programs, and see if its listed there
Tried, nothing's here


@Vai!n :
Thanks for all those links, I didn't know those programs. I'll check my system with them too :)

Offline Jim

  • Founder Member
  • DBF Aficionado
  • ********
  • Posts: 5301
  • Karma: 402
    • View Profile
Re: Somebody knows about rekgggems.exe ?
« Reply #4 on: December 10, 2008 »
That has all the hallmarks of a malware infection.
I suggest running Hijackthis from Trend
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
It produces a log of all the things that run on your machine.  If you post the log here I will help you clean it up.

One simple thing to try would be to boot to safe mode and delete the autorun.inf file.  Then reboot and see if the unknown exe is still running.  It probably will be, but it's worth a try.

Another great program is Spybot SD. http://www.safer-networking.org/index2.html.  If the malware will let you install it, boot to safe mode and run a full scan with this program.

Jim
Challenge Trophies Won:

Online va!n

  • Pentium
  • *****
  • Posts: 1435
  • Karma: 109
    • View Profile
    • http://www.secretly.de
Re: Somebody knows about rekgggems.exe ?
« Reply #5 on: December 11, 2008 »
@Jim:
yes the hijackthis tool is a a nice one too... btw, i used spybot destroy for a long time too... but personally i have to say, that the malware tool i posted the url for... seems to do his work a lot better...  but at least i would prefer to use both tools be on the right side ;)
- hp EliteBook 8540p, 4 GB RAM, Windows 8.1 x64
- Asus P5Q, Intel Q8200, 6 GB DDR2, Radeon 4870, Windows 8.1 x64
http://www.secretly.de
Challenge Trophies Won:

Offline Hezad

  • Sponsor
  • Pentium
  • *******
  • Posts: 613
  • Karma: 44
  • I believe .. in Patrick.
    • View Profile
    • Hezad.com Web hosting
Re: Somebody knows about rekgggems.exe ?
« Reply #6 on: December 11, 2008 »
thanks Jim for your proposition :)

I already made a spybot analysis but it just found some ad cookies. For now the process didn't show up again though, so for now, I'll wait to see how its going before generating a HiJack this report.

I didn't launched a Malware Bytes soft analysis yet, I'll do this this night.

Offline Shockwave

  • good/evil
  • Founder Member
  • DBF Aficionado
  • ********
  • Posts: 17426
  • Karma: 499
  • evil/good
    • View Profile
    • My Homepage
Re: Somebody knows about rekgggems.exe ?
« Reply #7 on: December 11, 2008 »
From bitter experience Hezad, I would recommend that you generate and post a Hihack This log anyway. You never know what it will show.
Shockwave ^ Codigos
Challenge Trophies Won:

Offline Hezad

  • Sponsor
  • Pentium
  • *******
  • Posts: 613
  • Karma: 44
  • I believe .. in Patrick.
    • View Profile
    • Hezad.com Web hosting
Re: Somebody knows about rekgggems.exe ?
« Reply #8 on: December 11, 2008 »
Well, here it is :D I'm feeling like I'm showing my computer totally nude :S


Quote
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:17:13, on 11/12/2008
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP3 (5.00.2920.0000)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\internat.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MSI\Common\RaUI.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\aMSN\bin\wish.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fr.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fr.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1036,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Win32 SDK] C:\WINNT\System32\igxpnajht.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Vidalia] "C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe"
O4 - HKCU\..\Run: [Icon Phile] C:\Documents and Settings\Patrick Duffy\Bureau\Iphile.exe -trans
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: MSI Wireless Utility.lnk = C:\Program Files\MSI\Common\RaUI.exe
O4 - Global Startup: Privoxy.lnk = C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.fr.msn.com
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.fr.msn.com
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 5567 bytes

 :cheers:

Offline Jim

  • Founder Member
  • DBF Aficionado
  • ********
  • Posts: 5301
  • Karma: 402
    • View Profile
Re: Somebody knows about rekgggems.exe ?
« Reply #9 on: December 12, 2008 »
Quote
O4 - HKLM\..\Run: [Win32 SDK] C:\WINNT\System32\igxpnajht.exe
Quote
This one scares me.

Also, do you know what VMN Toolbar and EoRezoBHO are?

Try to use Hijackthis to remove any of these you don't recognise.  If it cannot, try booting to Safe Mode and removing them.  Sometimes as soon as you remove things, the malware spots that and automatically reinfects your PC.  That's why sometimes you need to go to safe mode, and why google knows nothing about these files - the filenames/infection paths get randomly generated each time you reboot or get reinfected.

If you can clear these out, repost a new hijackthis log.  Once you're cleaned up you should change any important passwords.

Jim
Challenge Trophies Won:

Offline Hezad

  • Sponsor
  • Pentium
  • *******
  • Posts: 613
  • Karma: 44
  • I believe .. in Patrick.
    • View Profile
    • Hezad.com Web hosting
Re: Somebody knows about rekgggems.exe ?
« Reply #10 on: December 12, 2008 »
thanks for your analysis  :buddies:

In fact, igxpnajht.exe was precisely the application bothering me (rekkgems didn't appeared again yet, it was replaced very soon by igxpnajht.exe and for now, I don't have any weird application running. But it may be because I didn't rebooted for some days. Once I'll reboot, I'll recheck that.

Thanks again :)

Offline Hezad

  • Sponsor
  • Pentium
  • *******
  • Posts: 613
  • Karma: 44
  • I believe .. in Patrick.
    • View Profile
    • Hezad.com Web hosting
Re: Somebody knows about rekgggems.exe ?
« Reply #11 on: December 20, 2008 »
Okay, it starts again ><

I analysed my network inputs/outputs with WireShark and I found something ...

A computer is querying stuff on my PC with an IRC protocol (??!!) from a server called irc.maninthemiddle.net (erm.. like a man in the middle attack ? Scary ...). There's also an information about a channel called #xwar

First, I tried to connect to this server using an irc client but it didn't work (can't connect).

there was also some information about the irc MOTD command :
Quote
Response: :Irc.ManInTheMiddle.Net 372 FRA|2K|LAN|10|762182129 :- Float like a butterfly , STING like a bee .. hands cant hit what eyes cant see

...

I did a nslookup with the IP which queries my PC and I found that :

Quote
Nom :    80-184-19-234.adsl.kems.net
Address:  80.184.19.234

After some researches, it looks like "kems" is an adsl provider from Kuweit.

I don't know what to do next ... Of course, I'd like to protect my data and my logins/passwords, but before that, I'd like to know what's this all about (I should be afraid, but all that investigation is pretty funny in fact) !

Any ideas to pursue the investigations ?

Offline Jim

  • Founder Member
  • DBF Aficionado
  • ********
  • Posts: 5301
  • Karma: 402
    • View Profile
Re: Somebody knows about rekgggems.exe ?
« Reply #12 on: December 24, 2008 »
This means your box is totally owned and desperately needs cleaning.  It's probably part of some guy's botnet.  First check with hijackthis what the dodgy exe is called, then boot to safe mode and manually delete it.
Boot to safe mode again, and see if hijackthis shows you anything new.
Next, try Root Kit Revealer from Microsoft. http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx  It will hopefully tell you if something is hiding.

Jim
Challenge Trophies Won: