iun6002.exe malware - is it gone?

Sheza

New member
Local time
11:41 PM
Messages
20
Hi there,

The other day I had some networking problems, services such as the Network List Service were failing to start etc. Then after I ran some commands to fix this, Windows Firewall was disabled and couldn't started.

I ran ComboFix (I admit, I have only now just seen the warning to only run it after being given expert advice) and it deleted one file (but also did some stuff in the registry I think, relating to TCPIP). After this, Windows Firewall works again.

That file was iun6002.exe. At the time I didn't think anything of (after all, my network connection was back!) it but I decided to do some further digging today because these two strange events has occurred:

1. Two programs that were ' Click Once Application Manifests' (You know, download a 800Kb file and it'll download the rest later on and store it in AppData) had been un-installed / all that was left was the standard application manifest icon. These were 'Wunderlist 2' and 'rdio'. I have since re-installed them.

2. My installation of Office 2013 Consumer Preview was completely gone. The icons are un-clickable and almost everything in the Office 15 folder was been deleted.

So I read up about iun6002.exe and how malware disguises itself as this .exe especially in the location of C:\Windows and that's where mine was found. I read that it's a pretty nasty spyware tool. Not content with it sitting in ComboFix's quarantine folder with .vir added to the end of it, I ran these scanners:

Windows Defender Spyware Removal (The Windows 7 out-of-the-box one) [CLEAN]
Rogue Killer [No suspicious processes, but some registry suspicions, 2 Wunderlist related, 1 Asus-Xonar audio driver related and two Microsoft looking ones]
Sophos Virus Removal Tool (IN PROGRESS) [Say's it's found 2 threats so far, hmm]

So my question to you after this hopefully understandable explanation is: Am I free from the iun6002.exe spyware? Or is it still on my PC, doing bad things? Any way to check for this? The proccess is definitely not running.

Cheers.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
So my question to you after this hopefully understandable explanation is: Am I free from the iun6002.exe spyware? Or is it still on my PC, doing bad things? Any way to check for this? The proccess is definitely not running.

There's no way to know with 100% certainty if your machine is malware free. No anti-malware product is 100% effective 100% of the time (if there was such a thing we'd all be using it.) But the more scans you run that come back "no malware found" the greater the probability that your computer is malware free. Here are a few more free on demand scanners you could try.

Windows Defender Offline (different than the Windows Defender you ran, and this tool must be created on a known malware free computer.)

Malwarebytes

ESET Online Scanner

SuperAntispyware

Kaspersky TDSSKiller (link is under Step 1: How to disinfect...)

Many people recommend that once a computer becomes infected, the best solution is to do a clean reinstall of the operating system and all other installed programs. If you built your computer yourself (you don't have any system specs listed) you could use this tutorial:

http://www.sevenforums.com/tutorials/1649-clean-install-windows-7-a.html

If you have a store bought computer that had Windows 7 installed by the computer manufacturer, then one of the Forum experts prepared this tutorial that shows how to do a clean reinstall of a factory OEM computer:

http://www.sevenforums.com/tutorials/219487-clean-reinstall-factory-oem-windows-7-a.html
 

My Computer My Computer

At a glance

Win 7 Pro 64-bitIntel i5 2.4 Ghz8GB DDR3Intel HD 3000
Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
Alas, I think I may do just that. (Did run Malwarebytes at the first sign of trouble, it didn't find anything, hmpf!)

I'm used to re-installing Windows - last time I did it was Christmas Day to celebrate some new hardware going in haha.

The only thing I get worried about is when Windows Install says there's 'no readable partition' or something, which is fixed by removing my secondary hard drive and installing with just 1. It doesn't seem to make any sense to me why it does that though...

Thanks for your help
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
The only thing I get worried about is when Windows Install says there's 'no readable partition' or something, which is fixed by removing my secondary hard drive and installing with just 1. It doesn't seem to make any sense to me why it does that though...

Chalk it up to "confusion" (for lack of a more technical explanation.) Choosing between multiple hard drives seems to make all versions of Windows take a couple of steps back and go ... huh? :)
 

My Computer My Computer

At a glance

Win 7 Pro 64-bitIntel i5 2.4 Ghz8GB DDR3Intel HD 3000
Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
Sheza,

Let's do some 'soul searching' for iun6002.exe...

>>> Show hidden files

Next, please download SystemLook:
64-bit:
http://jpshortstuff.247fixes.com/SystemLook_x64.exe
Save to your Desktop.
Right-click on SystemLook.exe, and select: Run As Administrator

Copy the content inside the following quote box into the main textfield (do not copy the word "quote"):
:filefind
iun6002.exe

:regfind
iun6002.exe
Click the Look button to start the scan.

When finished, a notepad window opens with the results of the scan.

Please post the SystemLook.txt (found on the Desktop) in your reply.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Hey there,

Firstly - thanks for your help! In should note that I know what this program is and can only assume it's because it installs with Setup Factory. The program was installed way before anything started to go wrong.

Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 11:52 on 09/02/2013 by Sheza
Administrator - Elevation successful

========== filefind ==========

Searching for "iun6002.exe"
No files found.

========== regfind ==========

Searching for "iun6002.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WYSIWYG_Web_Builder_8]
"UninstallString"="C:\Windows\iun6002.exe "C:\Program Files (x86)\WYSIWYG Web Builder 8\irunin.ini""

-= EOF =-
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
That file should be OK.


However, if you like, you can also upload the file to VirusTotal for a security check: http://www.virustotal.com/


Select: Choose File, and a prompt opens for you to locate the file.

Then, click the Scan it! button.


If the file is listed as already analyzed, click on: Reanalyse file now.


When done, please post the http://[COLOR=red] link[/COLOR] to the scan results.
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Quick question... how can I upload a file if there's no file?

The only iun6002.exe that I have is located in ComboFix's quarantine.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
See if you can get the C:\QooBox\ComboFix-quarantined-files.txt and attach it here.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
See if you can delete the file: right-click > Delete
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
The iun6002.exe.vir file?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
Yes.

It should be in the C://QooBox/Quarantine


Also, when you uninstall ComboFix it removes all backups and quarantines created when ComboFix scanned.

To do so...
Click Start and the R key, simultaneously.

Copy/paste the text inside the quote box into the Open field of the Run prompt.
Combofix /Uninstall
(Note that there is a space between combofix and /uninstall.)

Click: OK

A security warning appears, asking if you are sure you want to run ComboFix.

Click the Run button to start.

ComboFix now uninstalls itself from your computer and removes any backups and quarantined files.
When it finishes, a dialog box stating that ComboFix was uninstalled appears.

You can now delete the ComboFix.exe program from your computer, if still there.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Back
Top