JS:Iframe-DHY [Trj] problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Rightfulstone, Jan 22, 2014.

  1. Rightfulstone

    Rightfulstone Private E-2

    Hello,
    Let me start off by saying that I'm not that amazing with computers and I believe I have completed all the files I need in order to post, but if not I will gladly run/re-run. That being said, the problem I am having is similar to what I have been seeing around the forums and online this pesky JS:iframe problem, however mine is -DHY at the end, and therefor I am not able to find it in several of the forums telling me to locate this and that in regedit etc. I do have an actual screenshot of the error message from the avast program if needed (though I doubt it is) as I'm sure by now you guys are very familiar with this trj. Anyways, luckily I believe to have a good amount of protection since nothing is being moved, hidden, deleted etc. (that I know about) the reason that I am coming here is because I know how dangerous trojans can be if unchecked and rid of. At the moment it has been about 5 days having this trj, and only when starting up web-browsers (IE and Firefox). From there every extension I use via the http:xxxx is followed by another pop-up from avast. Thank you for taking your time to read this, and any help that will be provided to me.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [V2][ROGUE ST] 4560 : wscript.exe - C:\Users\Jeff\AppData\Local\Temp\launchie.vbs //B -> FOUND

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Re run Hitman and have it remove Potential Unwanted Programs. (Conduit, rocketfuel, babylon etc)

    Give Ccleaner a run, not the reg scanner, just the cleaner itself to be rid of a chunk of temp files.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.




    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. Rightfulstone

    Rightfulstone Private E-2

    I completed all the steps, and I am sad to report that I'm having the same problems upon start-up of the browsers. I DID get the confirmation notification for the Regedit file. I had no complications with any of the steps or programs running or deleting files.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you click on the "More details" tab please and screenshot what else it says next time it pops up.

    Also, I suggest running a full system scan with Avast and see if it finds anything.

    Does it happen with both Internet Explorer and Firefox? :confused
     
  5. Rightfulstone

    Rightfulstone Private E-2

    I have a generic screenshot of the more details tab. What is happening is this (and this is why the one tab opened is a different website than the one you see in the bottom corner) when I initially open Firefox, it is popping this avast message, everything done from that point on pops this message (same error) the JS:iframe etc. however the site changes to X site I go to, so what you are seeing in this picture is me clicking the "more options" and it went to the Avast website, therefore I now got an Avast website error message with the same JS:iframe problem. It seems to be random on when and how often it does it, meaning it always happens at the start of Firefox, but once I've opened the browser the first time, close it all the way down, re-open it again, it may or may not re-pop the error. However when I reset the computer it will always 100% re-pop the message. Also some days it will tag every single website as "error found" sometimes it's only the first website that pops (which is google). Let me restart the computer and see if I get the message with IE.
     
  6. Rightfulstone

    Rightfulstone Private E-2

    It does not happen when I use I.E. at least not when I just tried, I went to a few websites to make sure, and could not trigger the Trj message from avast, I've ran a full avast scan a few times since this Trj has come into my computer and have never found anything. I will run another one (maybe the other installed programs from earlier did something that will allow it to be found this time). I took another couple screenshots to maybe help with understanding what is going on. The first screenshot is simply, I opened Firefox, got the error I clicked "more details" and took the picture of what the message was. The 2nd picture is the message I got when I clicked "more details" and opened a 2nd tab in Firefox (because new tabs mean new errors, just like new website URL's mean new errors).
     

    Attached Files:

  7. Rightfulstone

    Rightfulstone Private E-2

    I updated my avast virus detection definitions, and alas, it found something!!! I was so excited that it found the file, I clicked the recommended fix (move to chest) like an idiot, reboot required, ok no problem, rebooted just fine. Started back up, wait a minute.....no display, ok simple enough let me just re-restart maybe it just had a hic-up in the coding to process the display or something silly (being a trj was just deleted). So i hard shut-down, disconnected the power source to allow a full refresh of the motherboard, restarted the computer, and still no display anymore. I have tried AVI, and the other connection type (the blue one, vga i think) however neither are now working. Please tell me a solution to this exists, the keyboard is loading up, so i think i'd be able to get into the bios still, and navigate it blindly if, I don't know, that was the only possibility. Sorry this rather simple problem turned so complex so suddenly. At the moment I am letting my computer just run, and seeing if there is any possibility that the display is just taking some HUGE delay or something (it has delayed to the display a few times in the past, just nothing like this, more like 10 seconds, or no display until its already loading windows so you don't get that hit FX for these options). I really thank you for your continued efforts and patience in helping with this problem. I am currently using a laptop now, forgot to mention this in the earlier post, although I'm sure you would have caught on to me not being on the other computer :)
     
    Last edited: Jan 24, 2014
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    I am so sorry the troubles just got worse. Firstly, I'd like to comment that although I'm not specifically blaming avast for your display dying like that, I DO think it's starting to get a little over aggressive these days. I personally stopped using it some months ago. It was actually flagging every file on my machine as being infected. It was utterly untrue, my files were fine.

    As to the display issue, that is simply not my area, if you will. I deal with malware removal and that's that. However, do feel free to post in the software forum, or perhaps the hardware forum, wherever applicable. :)
     
  9. Rightfulstone

    Rightfulstone Private E-2

    No problem at all, I really appreciate all the help thus far. As far as posting into the other forums I will try that, and I may or may not be back here once I have the display back up and running (probably still an underlying problem). :wave
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Indeed, feel free. I'll be floating about somewhere not far away. :)
     
  11. Rightfulstone

    Rightfulstone Private E-2

    Hey, so I just realized that I was using the motherboard display and not the actual video card. I switched to the video card, and now I am getting this screen below. I posted in the other forums about not having a video and what to do now, but have not recieved any replies since having stated getting my video back up and working. Can me and you now continue to address this, now that I have the display again? Or do I need to post in a different location before coming back here? Sorry for any trouble this may cause, or time taken away from others. Thank you in advance for your response. Also the pictures I'm trying to upload will not upload because they are posted in my other forums thread http://forums.majorgeeks.com/showthread.php?p=1857326#post1857326. Thank you for your continued patience, it is greatly appreciated.
     
  12. Rightfulstone

    Rightfulstone Private E-2

    Update to the update :) I'm back on the main P.C. with what seems to be no problems currently, I adjusted my web browsers security so that it "connects securely" and got a strange message (but not the TRJ message) here is a screenshot. It seems to be a program called "visual-bee" that flagged Google as a possible untrusted site, and when I clicked "get me out of here" it took me to visual-bee search engine. I won't do anything further until I hear back from you guys, but since I do all of my college on this computer and all my work was on here, I didn't have a choice but to go ahead and try and get back into the P.C. Will say that I don't have visual-bee installed into the addons or extensions, or plug-ins for the browser so I'm sure this is another problem. Thanks again. Take that back, just got the TRJ popup again. :D frustrating lol
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run all of the programs again please and attach the requested logs. We'll take another fresh look. :)
     
  14. Rightfulstone

    Rightfulstone Private E-2

    Sorry for the delayed post, I got kind of caught up with college stuff, I will do my best to have all the programs ran again by the end of tomorrow. Again sorry for the delay, and thank you for your continued patience.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome. Soon as you're ready I'll be along shortly afterwards. :)
     
  16. Rightfulstone

    Rightfulstone Private E-2

    Hello again, I am re-uploading the files that I was able to download again. Note: there was a problem installing TDSSkiller, no matter how I tried to get the download via your website, manufacturers website, google searches for just the zip file etc. Every time I tried downloading the file it would appear to give me a kind of like timeout connection problem error. Also, my Firefox is now re-directing me every which direction, so I have switched to IE for the time being until we can resolve all these issues. I wasn't sure if you wanted me to re-download the other files that we did before (since they were after the initial DL's) so I didn't. Anyways, again very sorry for the long delay and I sincerely appreciate all you are doing for me :)
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it remove items under the heading Malware, and Potential Unwanted Programs.


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [V2][ROGUE ST] 4560 : wscript.exe - C:\Users\Jeff\AppData\Local\Temp\launchie.vbs //B -> FOUND

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now explain how things are running.
     
  18. Rightfulstone

    Rightfulstone Private E-2

    Man this is such a pesky problem to fix it seems. Ok I ran the Hitman program and deleted the file that you told me to delete, rebooted my computer and then ran roguekiller again, once again following your prompt. Rebooted for the 2nd time (I guess as a just in-case). Added the code that you gave me into the registry, that was accepted fine. Restarted the computer for the 3rd time (thank god my computer starts fast lol) opened firefox, still have the same problem. Same pop up message as before, to be fair it has only been coming up the first page being opened, not every tab etc. like before. I did however experience redirecting recently and I took all the precautions and fixed that problem so I would stop being redirected, not sure if that is relevant. I'm to the point of just installing like team viewer and letting you control my computer :D When did these codes become so G.D. complicated. Oh well, I guess with technology etc. etc. thanks again, ttys.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except we will be using Revo Uninstaller to do so) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bookmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    ================

    Any better? :confused
     
  20. Rightfulstone

    Rightfulstone Private E-2

    Well for the first time in over a month, when I started Firefox it didn't give me a warning about malicious TRJ being on my computer. For that I have you to thank! You mentioned before that you don't use Avast any longer, may I ask what you use these days? And I guess on an ending note, I really appreciate all the time that you have put towards helping me fix my problem, I know that it was probably frustrating, or fun, depending on how you view these kinds of challenges :) Anyways thank you so much. On a side note, I can't find where I can donate, would you mind posting the link for me? It is much appreciated.
     
    Last edited: Feb 11, 2014
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am so glad to hear that. :)

    Certainly. I use Microsoft Security Essentials.

    It definately wasn't frustrating, I very much enjoy what I do.

    You are most welcome. :) We do not accept donations per se, however, if you see at the end of all my posts (in one of the signatures I have) that you can browser around the geek store and see if anything takes your fancy. Or simply just spreading the word to family and friends about us would be awesome!


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  22. Rightfulstone

    Rightfulstone Private E-2

    I honestly just can't thank you enough, and I will be telling everybody that has a computer problem, or that doesn't yet :) to favorite your website. Keep up the good fight :major Take care.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks! Take care! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds