Unknown Trojan popups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mom25grls, Mar 22, 2008.

  1. mom25grls

    mom25grls Private E-2

    This started Wednesday when my daughter was online (probably on YouTube). The following popup message appears every time I open IE or Explorer, plus every new page that opens in IE or Explorer:
    "Your computer was infected by unknown trojan.
    It's dangerous for your system (critical files can be lost)!
    Click OK to download the antispyware program to clean your system! (Recommended)"
    I also noticed that no matter what topic you Google, the result page contains a porn pic. Needless to say, the computer is offlimits to my kids until I get this fixed.

    Went thru the READ ME process:
    Nothing obvious found in add/remove programs
    Only 1 (latest) version of java installed
    MSconfig setup for normal
    Can't find a quarantine area (Norton 2008)?
    Emptied recycle bin
    Ran CCleaner on every account
    Ran XP Cleaning procedures:
    1. SuperAntiSpyware - found couple adware.tracking cookies
    2. SpyBot - removed some temp files (smitfraud-C) and registry keys (troj.PrintSpool)
    my particular concern would be the recent reg entries coinciding with appearance of popup:
    win32.agent.gvu
    HKEY_USERS\PE_C_ERIN\Software\Microsoft\Bind
    HKEY_USERS\S-1-5-21-57989841-789336058-1060284298-1004\Software\Microsoft\Bind
    microsoft.windows.security.internetExplorer
    HKEY_USERS\PE_C_KATIE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKD...
    microsoft.windowSecurityCenter_disabled
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc\Start

    3. combofix.exe - attached combofix.txt

    4. MGTools - attached mglogs.zip

    Hope someone can help! Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just two things to do ...

    Use windows explorer to find and delete:
    C:\WINDOWS\ausctv32a.dll

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Tell me if you are having any other problems. :)
     
  3. mom25grls

    mom25grls Private E-2

    I was having difficulty with posting my original message - I didn't think it posted! So I kept looking around for more info and found that module mentioned too. I used HijackThis to remove that one entry and it seemed to clear up all my problems. Would that be the same/similar to the approach you suggested?
    Thanks!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....but you have to make sure that the .dll is removed and the registry key ...if that was what you fixed with HJT.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds