Trojan and Adware: AVG detected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mongooseba, May 30, 2008.

  1. mongooseba

    mongooseba Corporal

    Hi All:

    I believe my computer is infected with some Adware and Trojan Generic 10. The AVG detected the Trojan and this problem keeps appearing. I have performed all the tests on my computer as requested prior to posting. Kindly check my log, and I believe there are some entries that need to be removed. Please advise and thanks in advance.

    Mongooseba:cry
     

    Attached Files:

  2. mongooseba

    mongooseba Corporal

    Hi All:

    This is the last attachment that is needed to complete the analysis. Thanks again.

    Mongooseba
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly where is it finding the problems?
     
  4. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    The following appeared when the AVG did the scan. Kindly see the attachment. Thanks.

    P.S. Do you need to see my AVG 8 scan?

    Mooseba

    *
    c:\system volume information\_restore{62521AD4-A7BC-4858-9F42-847559715419}\RP427\A0051612.exe
    Trojan Horse Generic10.ABZR
    Process Name: c:\windows\system32\svshost.exe
    Process ID: 1212
     

    Attached Files:

    Last edited: May 31, 2008
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is System Restore. Nothing can be cleaned from System Restore. You have to toggle System Restore. But first you have some other things to do.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 2

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - Startup: PowerReg Scheduler.exe
    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Thanks for the quick reply. The following were performed.

    1. Unistalled the old Java (what happens if you do not update to the latest version of Java?)
    2. Ran C:\MGtools\analyse.exe and removed

    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - Startup: PowerReg Scheduler.exe

    3. Ran ComboFix from desktop (under ComboFix.exe not CF.exe) with script: CFscript.txt
    4. Updated the Java
    5. Ran the fixme.reg and this was successfully incorporated into registry
    6. Enlcosed the two log files

    Looking forward to your instructions. Do you need the latest scan from AVG?

    Mongooseba
    6. Ran CCleaner (should I update this as well prior to using it?)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are susceptible to security holes. Older versions of Java have been thought to also leave the door open for Vundo infections.

    No! We have not toggle System Restore yet so it would still find the same thing.

    You should keep all of your software current but it is not a major issue for us if it was not updated.

    Are you using Spybot or some other program to control startups? I'm referring to the below which are being blocked from loading and I tried to clean them up in the last fix but they did not get fixed and you said the fixME.reg patch was successfull.
     
  8. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Thanks for all the explanations.

    As far as I know the fixME.reg patch was successfull. There was a box that came up after running the patch indicating it was successful. I do not believe I am controlling the start-ups. How can I check that Spybot is not controlling the start-ups? I did look under Adv/Tools/Start-up and Spybot indicated all processes as checked. However, I did run "Start-up.exe" previously and it did control some. What should I do? Manually remove the entries in the registry? Please advise.


    Mongooseba
     
    Last edited: Jun 1, 2008
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is where you would check Spybot.


    Then you contradict your earlier statement that you are not controlliong startups.

    Undo whatever you did. We already tried manual removal so it looks like something you are running is just putting them back into those registry keys.
     
  10. mongooseba

    mongooseba Corporal

    All items on Spybot and Start-up are checked. What should I do next? Please advise.:wave

    Mongooseba
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you familar with using the Windows Registry Editor?
     
  12. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    I presume I am capable of modifying the registry especially with detailed instructions. I have navigated into the "Regedit" and have deleted items before. I have ERUNT to back-up the registry in case I have a problem. However, I have never restored a defective registry before. Looking forward to your directions. I'm ready.

    Mongoosebarolleyes
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What I want you to do with the registry editor is to navigate to the below keys and select them (one at a time)

    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-

    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-

    And once you have it selected (it should be highlighted) right click on it and select Delete. Make sure that you have selected the key that end with a minus sign. It is run- DO NOT delete the one that says run

    You will have to say yes to the prompt Are you sure.....

    After you do this for both keys, download and run the current version of MGtools (recently updated) and attach a new MGlogs.zip file.
     
  14. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Followed your instructions.

    1. Did not find the key in the registry: no run-
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-

    2. Deleted this in the registry
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-

    Updated the MGtools from this thread: http://forums.majorgeeks.com/showthread.php?t=139313

    Ran MGtools from C: directory and enclosed is the recent file. Thanks and look forward to your help and instructions.

    Mongooseba:eek:
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's better. How are things working?
     
  16. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Things seem to be doing fine with no pop-ups. Should I rescan the computer now with AVG? Thanks for taking care of my computer issues.

    Mongoose:-D
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You can do that if you wish but do not do a rescan until after you have done all of the below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  18. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Tried to remove the ComboFix but was unsucessful. Kindly provide instructions as to how I can remove this completely. Thanks in advance.

    Mongooseba:wave
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the cf.exe file is still on your Desktop, then step 3 of the instructions I gave you should work.
     
  20. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Sorry about the delay in replying. I attempted to retry per your instructions on removing combofix. I check the name and it is labelled as cf.exe on my desktop. Disabled the ZoneAlarm to allow the cf.exe to communicate with the internet. However, I am still not able to run the script.

    The following pop-up error box appeared.

    "You cannot rename combofix as cf
    Please use another name, preferably made up of alphanumeric"

    What should I do next?

    Thanks again.

    Mongooseba
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try renaming the cf.exe file to combo-fix.exe and then try using the below to uninstall.

    Start, select Run.. and Copy and Paste the below exactly as written into the Run box and then click the OK button

    "%userprofile%\desktop\combo-fix.exe" /killall
     
  22. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Renamed the cf.exe file to combo-fix.exe. Did the run command as instructed. The program ran and generated a log again. Is this normal? I'm also having some registry program and notepad trying to access the internet. Is this normal as well. Enclosed is the log generated. Please advise.

    Thanks.

    Mongoosebarolleyes
     

    Attached Files:

    • log.txt
      File size:
      35.8 KB
      Views:
      2
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! I gave you the command to get a new log. Here is what I wanted you to run to see if it would uninstall.

    Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required


    "%userprofile%\Desktop\combo-fix" /u
    • Notes: The space between the combo-fix" and the /u, it must be there.
     
  24. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    It worked! :-D

    Should I proceed with the remaining items? Why does combo-fix try to access the internet before it works? Is my log clean? Thanks.

    Mongooseba
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    As far as I know it does not. When running a scan it actually disconncects you from the internet. What were you seeing and are you referring to during the scan or during the uninstall? The uninstall may be accessing the internet to send bug reports...etc but I never checked.

    Yes!
     
  26. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Thanks for looking at my log again and clearing it. I have removed the MGTools folder e.t.c. I guess you are right about Combo-fix trying to access the internet b/c of the log transmission.

    I wish to know whether I should remove the following under my C:\.

    Adobe Acobat Speed Launcher (shortcut)
    Adobe Gamma Loader (shortcut)
    Bug (text document)
    Google Update (shortcut)
    PA Manager (shortcut)
    Quickbooks Update Agent (shortcut)
    Web Sync Reminder (shortcut)

    What do all these programs do? Are they important or a whole bunch of useless shortcuts? (Attachment enclosed)

    Please advise.rolleyes

    Mongooseba
     

    Attached Files:

    • MG.jpg
      MG.jpg
      File size:
      24.1 KB
      Views:
      3
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All but bug.txt are shortcuts to run programs that you or someone else put there. There is no need to have shortcuts in this folder. You can delete them if you don't use the shortcuts from this folder. The bug.txt file can be viewed with notepad to see what it is. It is probably nothing you need.
     
  28. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Removed all shortcuts and the bug.txt as recommended. Should I proceed with the other "protection" list? Thanks.

    Mongooseba:)
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should complete all of my final instructions.
     
  30. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Meanwhile, ZoneAlarm spyware detected some Trojan on my computer. I have deleted the Kazaa folder from the registry. I have encloed the jpeg file for you to analyze. Should I be concerned?

    Thanks.

    Mongooseba;):major
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log is not useful since it does not show exactly what is being found. Logs with just names of malware are not helpful at all especially since every program uses their own naming convention. No you don't need to worry. It may have just been the below registry key which is added by mistake due to a bug in ComboFix that is adding the key rather than deleting it.

    HKEY_CURRENT_USER\Software\Kazaa

    There is another key improperly added by ComboFix. You can use the below patch to remove both keys.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  32. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Successfully executed. Checked that these files or folders are not present in the registry. Should I proceed with the remaining items on your list on 6/5/08 16:15? Thanks again for being so thorough.

    :wave
    Mongooseba
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Yes!
     
  34. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    I believe the computer is clean and have not had any problems. Thanks for all your assistance and time. You're are the best.

    Regards,
    Mongooseba:wave:wave:wave
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds