Poller.exe & vmnkql.exe Trojan Removal Guide

Operating Systems
Windows, Linux, Solaris, Red Hat, etc.....32 bit or 64 bit.
If its an OS, its here.
Post Reply
User avatar
Apoptosis
Site Admin
Site Admin
Posts: 33941
Joined: Sun Oct 05, 2003 8:45 pm
Location: St. Louis, Missouri
Contact:

Poller.exe & vmnkql.exe Trojan Removal Guide

Post by Apoptosis »

A Bad Message: Access Denied
Image

I went to a site off Google while looking up some song lyrics and was infected by a couple trojans last night. I also had many pop up windows with the name Aurora in the popup window. I then ran Norton 2005 with the 6-22-2005 definition file was unable to remove the infected files. It basically said "Failed To Repair This File". Next I ran Spybot and Ad-Aware with no such luck. I even rebooted and let it scan the files before Windows loaded... Failure! :|

I then did the standard removal methods...

Step One: Disabling the System Restore Utility (Windows XP Users)

1. Right click the My Computer icon on the Desktop and click on Properties.
2. Click on the System Restore tab.
3. Put a check mark next to 'Turn off System Restore on All Drives'.
4. Click the 'OK' button.
5. You will be prompted to restart the computer. Click Yes.

You must always turn off the system restore feature before removing a variant.

Step Two:

1) Boot into safe mode (hit F8 on reboot)
2) Kill the process (Poller.exe)
3) Manually remove Poller.exe from Windows startup & other parts

Sadly this couldn't be done... Not like the old days eh?

I next downloaded Stinger from McAfee Inc., which is a free software tool that removes 53 specific trojans and other variants. My scan came up clean, meaning that nothing was found wrong. Nothing wrong my ass... :finga:

I then downloaded HiJackThis and ran a scan. If you think you are infected with Poller.exe or vmnkql.exe you need to look for the following files after you run a system scan:
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll

O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
Once these files are found go download the 14 day trial version of Ewido Security Suite. Install it, and update the definitions to the newest files. Do NOT run a scan yet. When you update it might automatically detect an issue, but just ignore it and move on.

Next you need to open the Windows Notepad and copy the following text into a new file:
@ECHO OFF
cd %windir%
Nail.exe /FULLREMOVE
sc config SvcProc start= disabled
sc stop SvcProc
sc delete SvcProc
attrib -s -r -h nail.exe
attrib -s -r -h svcproc.exe
del nail.exe
del svcproc.exe
cd %windir%\system32
attrib -s -r -h DrPMon.dll
del DrPMon.dll
exit
Save the file to the desktop as remove.bat and make sure the "Save as type" field says "All files". This will remove the nail.exe file and clean up your system...

Next, reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.
Once in Safe Mode, please double-click on remove.bat. A window should open and close very quickly --- this is normal.

Then run HijackThis, click Scan, and check:
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll

O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
Close all open windows except for HijackThis and click Fix Checked.

Restart your computer in normal mode and see if everything has been removed and fixed.

I was determined not to format my system and after several hours of research I found that it could be done. No one on the internet really has a guide on how to fix these problems as they are new, so here is a guide that will help you. It worked for my desktop system with Windows XP SP2, so hopefully it will work for you.

If you found this information to be a help in removal please join the forums and let us know it helped. Feedback is always good!
matheyus
Legit Little One
Legit Little One
Posts: 1
Joined: Tue Jul 12, 2005 10:31 pm

Post by matheyus »

I Was able to remove all but Nail.exe
User avatar
Apoptosis
Site Admin
Site Admin
Posts: 33941
Joined: Sun Oct 05, 2003 8:45 pm
Location: St. Louis, Missouri
Contact:

Post by Apoptosis »

Matheyus,

Welcome to the forums and sorry to see you had the same trojans/virus that i once had. Did you follow the guide and run the remove.bat file that you made in safe mode and then Ewido after the .bat file was run and remove the unwanted programs? It should work let me know if you tried this method and it still failed.
User avatar
bubba
Staff Writer
Staff Writer
Posts: 4765
Joined: Sun May 01, 2005 10:24 am
Location: STL

Post by bubba »

you can try this to, topher posted this link over on warfactory after fighting it.

http://www.globalhauri.com/html/support ... TRW3000730
User avatar
sbohdan
Legit Extremist
Legit Extremist
Posts: 1306
Joined: Sun Jul 17, 2005 9:33 am
Location: Canada
Contact:

Post by sbohdan »

hi, just saw the struggle you had with trojans apoptosis. in this field I guess I could repay for the help with my prescott. you see I had the same problems a year ago: my pc was infected with the CWS (CoolWebSearch) spyware that I couldnt remove no matter what I did (its the nastyest spyware ever created)-see here: http://cwshredder.net/cwshredder/cwschronicles.html .
here I got the info what to get and it helped but to be totally secure -this was just the beginning. I spent an extensive amount of time researching the subject and came up with a little bundle of my own of programs that compliment each other. what one cannot see the others solve. my 1 year experience is:
1. after 3 years of using norton antivirus I switched to nod32. it is the best anti virus, spyware and trojan remover that actually prevents 99% of the mentioned ever entering the computer in the 1.st place.

2. I use a free program that imunizes the system spywareblaster http://www.javacoolsoftware.com/

3.I use just in case the 3 best spyware removal apps. that is out there Xoftspy (http://www.paretologic.com ) NoAdware ( http://www.noadware.net/ ), & Spysubtract ( http://www.intermute.com ) (beforehand I tried all the others including ad-aware and spybot s&d but these actually find everything and do really remove them period.)

3.at last but not least I stopped using IE and switched to Firefox ( http://www.mozilla.org/products/firefox/ ) becase IE is the most vulnerable browser and gets all the spyware and viruses since 99% are made to get through IE - Firefox on the other hand is the most secure (again: tried them all) if it comes to windows and resists spyware, malicious scripts and popups. I hope I was able to help some people with this post because what I most hate on internet is spyware and am spywaer free for almost a year now
:)
Main rig: NZXT Phantom modded case with Danger Den WC, Gigabyte B550 Aorus Elite, Ryzen 5800X @ stock, 32GB Patriot Viper DDR4 3200Mhz 16-18-18-36-1T, AMD RX 5700XT + AlphaCool WC, ACER Nitro XV2 27", SP 1TB nvme PCiE GEN3, Samsung 2TB; Cooler Master MW Gold 650W, Win10 Pro 64
my complete GFX tuneup & cooling mod: http://forums.legitreviews.com/viewtopi ... highlight=
Post Reply