Trojan Malware Battle

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by futurerush, Dec 23, 2007.

  1. futurerush

    futurerush Private E-2

    I've been getting threats of Trojan horse PSW.OnlineGames.K; Trojan horse PSW.Legendmir.JAX; Trojan horse PSW.OnlineGames.STP; and Trojan horse PSW.OnlineGames.XIL on several system32 files since 12/20/07. They continue to spawn after healing or moving to the virus vault. I followed the steps to run scans with Combofix (Ccleaner), Spybot, AVG, and MGtools. AVG Anti-Spyware, however, would not give me a report for some reason. I've attached what I got. What further instructions can I take?

    Thanks in advance.
    Julie
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 3"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 9"
    Java 2 Runtime Environment, SE v1.4.2_03"
    Java(TM) 6 Update 2
    Viewpoint Media Player

    Please re-run combofix and save the log.

    Please disable all anti-virus and anti-spyware programs while we do the following:
    Open notepad and copy and paste the following text in the quote box into the window:

    sc stop CB7B4470
    sc delete CB7B4470

    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  3. futurerush

    futurerush Private E-2

    Most of the lines in HijackThis that were listed in the reply were not available for me to select. The first three listed were all I was able to select. (R3 - URLSearchHook...; ...SSLDyn.exe; ...LotusHlp.exe). When running Avenger.exe, I pasted all that was in the quote box, but it wouldn't allow me to green-light it, giving me an error about the file not being valid. So I tried again, pasting just the two lines I recognized: ssldyn.exe, and lotushlp.exe, and then it went as expected in the reply. (I actually tired to do that first, but after reboot, the log file was blank. For some reason it wasn't blank on my last try, I don't know what I did different.)
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok ....let's try again.
    Boot into safe mode and disable your security programs.

    Go to start / run / type "services.msc" without quotes and see if this is still there:
    CB7B4470
    then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.
    Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste CB7B4470 into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to.

    (assuming you have unziped avenger to the desktop):
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt


    Now reboot into normal mode and re-run ComboFix ...saving the log.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  5. futurerush

    futurerush Private E-2

    Here's the new logs.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't tell me if the NT service was found.

    Go to start / run / type "services.msc" without quotes ...does this service exist:
    CB7B4470 ? If so can you stop it and disable it?

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now attach a new HJT log (from clicking on MGTools analyse.exe) and the avenger log.
     
  7. futurerush

    futurerush Private E-2

    Sorry, I didn't realize it was a question.

    Yes, the NT Service, CB7B4470, was found, and it was already stopped, I just had to disable it, and followed the steps to delete it with HJT that were given. I double checked later to make sure it was gone. Today, however, I noticed it had returned when following the steps from the most recent reply. So I disabled it again, clicked Apply, and re-did the steps to delete the NT service: CB7B4470.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well....I'm not happy to see that a lot of the nasties are back....

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now go to Bitdefender.. agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

    After that run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and the Bit Log.
     
  9. futurerush

    futurerush Private E-2

    i got a message that bdscan.txt was still way to big to upload. if i can't attach it to a second reply, which i will try right now (and if it fails there will be no second reply), what do you suggest?
     

    Attached Files:

  10. futurerush

    futurerush Private E-2

    So I replied again anyway, it's 1.14 MB in txt. I can't attach more than 250 KB. I did not select "Show all files scanned." I guess I'm just that badly infected.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Zip it and then attach it ...I really what to see what it reported and fixed...or didn't fix. I can't believe it is that big a file ...if you can, maybe just copy and paste into notepad the items that it could not fix.
     
  12. futurerush

    futurerush Private E-2

    Zipping it works for me. I didn't even think of that.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well that was a major clean up .....run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and we will see if there is anything else that needs doing. :)
     
  14. futurerush

    futurerush Private E-2

    Here's hoping.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run another Bitscan and attach that log also.
     
  16. futurerush

    futurerush Private E-2

    I'm getting this message from Avenger: Error: selected file does not appear to be a valid script.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have run it before without errors ....did something change?
    Can you use windows explorer to manually find and delete those files?
     
  18. futurerush

    futurerush Private E-2

    I searched for each file to delete, but they weren't in my system with the exception of one, but the path was a little different for it: C:\WINDOWS\system32\drivers\bsabdqqu.sys. I wasn't sure if I should still delete it through avenger.

    Last night I ran an AVG complete scan that picked up three threats, those affecting LYMANGR.DLL. They must have been deleted upon detection. This morning the scheduled AVG scan picked up no threats. But as I was running Bitdefender today, AVG was detecting threats again.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure when you follow the instructions for using Avenger that you are copying the first line of text which is Files to delete:

    If you do not have that line, you will get the error message you mention.
     
  20. futurerush

    futurerush Private E-2

    Yes, it was included. I copied/pasted everything in the quote box perfectly.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try leaving out the starting blank line. Make the first line the Files to delete:

    Also make sure you did not include the line that says Quote:

    Then try running the procedure with Avenger.
     
  22. futurerush

    futurerush Private E-2

    That did the trick! So minute, yet so important.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which one was it? The blank line or did you include the Quote: by mistake.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also need to get the below new log for Tim!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created
     
  25. futurerush

    futurerush Private E-2

    It was the blank line. Taking out that blank line allowed it to work.
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet ....sorry about the problem with Avenger ...my mistake for leaving in the space ...
    And yes : C:\WINDOWS\system32\drivers\bsabdqqu.sys --> needs to go bye bye.

    Otherwise how are things running?
     
  27. futurerush

    futurerush Private E-2

    It seems to be running fine. I don't know what happened to the threats that were popping up today. I didn't touch the window, so I assume they were ignored. I'll post here again if they come around. Thank you for your help in this. :)
     
  28. futurerush

    futurerush Private E-2

    Here's the new one from early today, and just a moment ago: Trojan horse PSW.OnlineGames.XJP, and the path affected: C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP551\A0050894.DLL, filename: A0050894.DLL

    It might be handled by healing, or maybe not.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's in your system restore files ...which you need to toggle as directed in the final cleanup which I will give you now:
    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!

    Let me know if you still have problems. :)
     
  30. futurerush

    futurerush Private E-2

    Thank you.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome ....and have a safe New Year ...:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds