Warning! Spyware Detected On Your Computer...blue Desktop!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ssonu, Aug 9, 2008.

  1. ssonu

    ssonu Private E-2

    Hello...

    I am Ssonu. This is my first mail here on MajorGeeks.com. I am in trouble. My computer got infected by deadly spyware called Antivirus XP 2008. It captured by desktop screen and when I connect my PC to the internet, it terrorize me by showing a popup message as "Trojan.spy.HTML.BankFroud.dp is trying to steal information and sending on the internet. Every half an hour or so, the computer shows black screen with message "KMODE_EXCEPTION_NOT_HANDLED" and many more kmode errors. It also says something like memory trap and tries to restart. When I press escape it goes off and the previous screen is presented back.When the computer is started and booted completely, it shows a message saying "database log is not found"!.

    I have used SuperAntispyware to remove some spyware and then I have tried to remove some manually like rhe4edjoe7er.exe and lphcaedjoe7er.exe. I then used Hijackthis and removed viruses like FlashGuard.exe. Then I scanned using Hijackthis and save a log. Below is that scan log. Please go through that and help me please........................ I am not able to access my bank account sites and many more :(.



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:46:38 PM, on 8/9/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2900.2180)
    Boot mode: Normal


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Aug 10, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.



    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:
    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. ssonu

    ssonu Private E-2

    Hello....

    I read that document and followed all the steps in that file. During the process, I saw many malwares and trojans being caught by the tools. When running MalwareBytes, it was showing that 4 malwares were still in memory so it was unable to delete, so it asked me for restart. Even after the restart , it gave the same message and it did not delete those malwares. When I was running Combofix, nothing went correct. It show that it had completed and preparing for the log and then it asked me for restart and after restart, it did not change the clock format and did not connect internet back. It did not save the log :( This might be for the reason that after restart some programs were active like my antivirus, antispyware(they start automatically after start) and all. Meanwhile My antivirus detected a trojan in my computer!!! Rest all tools worked fine and got logs from them. My computer is still infected i think. I got the trojan message again from the scanner now!

    Please help me by suggesting next important steps. I have attached the log files. Please go through them.

    Thanks,
    SSonu..
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not update SUPERAntiSpyware and Malwarebytes Anti-Malware to the current definitions as was requested in the instructions. Please run them (one at a time) and first make sure you update the program first before running the scan. The run the scans again and have them fix all that they find. Save new logs and attach them. Then move on with the below.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.2_14
    Java 2 SDK, SE v1.4.2_14
    Java(TM) 6 Update 3
    Java(TM) SE Development Kit 6
    Java(TM) SE Runtime Environment 6

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - ~EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Policies\Explorer\Run: [CzYVK1XbYa] C:\Documents and Settings\All Users\Application Data\jclibmpq\lizwrozi.exe
    O21 - SSODL: cmduien - {2BC3C43D-A90E-88B3-EAA7-08BF1B01B0A7} - C:\Program Files\tuyidgc\cmduien.dll

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • new SUPERAntiSpyware log
    • new Malwarebytes log
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. ssonu

    ssonu Private E-2

    Hello...

    Thanks for the reply and your help. I do not need Java anymore, so I did not install those. I just followed the steps in the mail YESTERDAY and my desktop was free of blue wallpaper! It is far better than the earlier state. But I found three trojan alert by macfee virusscan today again!. Details of one of the alerts is as follows
    Name--> A0413544.scr
    In Folder-->C:\System Volume Information\_restore{1AA3F24A-C5B3-443C-A436-6DF49615AA34}\RP512
    Detected As-->Generic FakeAlert.a
    Detected Type-->Trojan
    Status-->Deleted
    Application-->svchost.exe
    Username-->NT AUTHORITY\SYSTEM

    I think my computer is still infected... :(

    I need to ask some few questions please...

    1) All hidden icons, which were made visible are still floating on my computer, so do you want me to make them invisible?

    2)During bootup it asks for options, which has Microsoft Windows Recovery console in it. As combofix did not run well on computer, do you want me to run it again or want me to unistall recovery console?

    3) Combofix starts running every time I boot the system. What do you suggest? Do you want me to remove it or keep it?

    4)Do you want me to uninstall firefox and install back again?

    5)which tools should I uninstall and which of them should be used for a long term?

    6)Can I use my bank websites to access my accounts now?

    Thanks,
    Ssonu...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask you to install those Java programs. I asked you to uninstall them.

    You should have at least one (and it should be the lastest) version of Java installed or you will eventually have problems on certain websites that use Java scripts.

    No it is not! That is just in System Restore and will be gone when we get to my final instructions. However before we can get to those instructions, you need to attach the follow up MGlogs.zip file that I requested in my last fix.


    They will go away during final instructions.

    The Recovery Console could save you from major issues at some point in time, so it is a very good idea to just have this installed. This was one reason for installing it before a ComboFix scan was run. The act of removing certain infections can actually cause your PC to crash or become unbootable once the malware is removed. The Recovery Console may be the only way to avoid a total reinstall in cases like this.


    We normally cover this in final instructions but do the below:


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    All other questions should be addressed by final steps which I cannot post yet since you did not give me a log I needed.
     
  7. ssonu

    ssonu Private E-2

    Hello chaslang,

    Thanks for replying again. After sending 3 logs, I sent one more mail attaching that last log. I think I might have did something wrong while sending that mail. Sorry... Here is the attachment.


    Thanks,
    Ssonu..
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Let's do final cleanup which will also repeat the ComboFix removal just incase you did not do it yet.

    But first, copy the bold text below to notepad. Save it as fixCF.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixCF.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. ssonu

    ssonu Private E-2

    Hello Chaslang,

    Everything worked out well. I got success message, when i added an entry into the registry. Now my pc is free of malwares and viruses. THANKS A LOT FOR ALL YOUR HELP AND TIME. I AM VERY THANKFUL TO MAJORGEEKS.COM for helping people like me.

    Thanks once again,
    Ssonu...
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds