Trojan.Win32.BHO

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kkwilson5, Jan 2, 2008.

  1. kkwilson5

    kkwilson5 Private E-2

    I have a couple viruses that popped up on my computer. I'm not sure what to do. I'm normally very careful about where I go on the net, but I finally got infected. I'm on WinXP Home edition. I'm using PC Security Shield antivirus software and it is up to date.

    I have three different dropper.agent viruses and five trojan.win32.bho viruses.

    Most of them say that they were repaired during a scan but if I reboot and do a scan again, the come up again. One of the trojan.win32.bho says that my computer needs rebooted to remove it. If I reboot, it still doesn't work.

    I've read in various places about the trojan.win32 virus but there are so many out there that I want to make sure that I'm doing the correct thing.

    Any ideas or help would be GREATLY appreciated!!!

    Thanks in advance!!!
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!


    Your best option at a complete resolution to this malware is to run the below and attach the requested logs for the malware experts to review, if needed after the guide they will issue you some tailored removal insttructions to get rid of the remaining pest.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. kkwilson5

    kkwilson5 Private E-2

    Ok...so I did all the steps and I still have a virus found. It's in c:\windows\system32\vturs.exe. I have tried deleting it in safe mode but it comes back up upon startup time. I'm sure there are entries in the registry.
    Also, I looked into the startup and I see two instances of troy44.exe is starting up. I tried disabling it but it kept coming back up. I don't want to delete anything out of the registry unless I'm for sure what I'm doing. I'm attaching some of the logs.

    Any help you could provide would be much helpful.

    Thanks!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run follow the instructions in the READ & RUN ME link that Halo gave to you from beginning to end and attach ONLY the logs that are requested. For your Windows version this will be the below logs:

    • C:\ComboFix.txt
    • AVG Antispyware log
    • C:\MGlogs.zip
    Don't try to fix things on your own. You will only make the problem mutate, spread and thus become worse. If you follow our instructions properly we will be able to get you cleaned up faster.
     
  5. kkwilson5

    kkwilson5 Private E-2

    I reran everything from the beginning and the logs are attached. I didn't get a log for the AVG anti-spyware. I didn't attach it previously because it asked to restart and then when I went back into it, there wasn't a log. I ran it a second time and it didn't generate a log. I have attached the MG Tools log and the Combo Fix logs. I hope you can help from these logs. I'm still getting viruses.

    Thanks!!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have been infected by several things the main two are PurityScan and a newest form of Vundo. The Vundo infection has actually infected many of your startup processes including infecing your antivirus and firewall programs. Pretty bad considering this is exactly the kind of thing they should be protecting you from!

    We are going to start working on your cleanup but this will take some iteration to try and recover from. Also I will be asking you to download some additional tools we will need. One of these will also be a newer version of MGtools. But wait until I ask. Also up front let me warn you not to download or install ANYTHING else on your PC unless we requested. Anything you download or run could get infected and just compound the removal steps. Also DO NOT REBOOT or POWER DOWN, unless specified in our instructions. Those actions will cause this infection to spread and will make it harder to remove.

    I'm looking thru your logs now and will post a starting fix soon.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is a starting fix!

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\system32\vturs.exe
    O2 - BHO: (no name) - {33A6ECAD-B06A-4EFB-A8B8-BD4781F153C1} - C:\Program Files\Messenger\qugavan.dll (file missing)
    O2 - BHO: (no name) - {CF60A3B3-68A4-460F-83AB-631D32A56443} - C:\WINDOWS\system32\vturs.dll
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" -startup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
    O4 - HKLM\..\Run: [troy44] C:\WINDOWS\troy44.exe
    O4 - HKLM\..\Run: [troy44 ] C:\WINDOWS\troy44 .exe
    O4 - HKCU\..\Run: [Sen] "C:\DOCUME~1\Kim\APPLIC~1\ICROSO~1\winspool.exe" -vt yazb
    O4 - HKCU\..\Run: [Imebwe] C:\WINDOWS\system32\??crosoft.NET\?vchost.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now we need to collect some more information and get some new tools.
    • Now download and save to RenV.exe to your Desktop (must be on the Desktop)
    • Doubleclick RenV.exe
      • When finished, it will produce a new log named Log.txt on the Desktop.
      • We will attach this log later.
    • Now download the newest version of MGtools.exe and save it to C:\MGtools.exe as requested in the READ ME.
    • Now double click C:\MGtools.exe to install the new version and generate a new log.
    • Now attach the below new logs:
      • C:\avenger.txt
      • Log.txt (on your Desktop)
      • C:\MGlogs.zip
     
  8. kkwilson5

    kkwilson5 Private E-2

    When I get down to run the Avenger.exe...my antivirus software pops up and says it's a virus and won't let me run it. I can't stop the antivirus software either. It won't let me run the executable. It's normally in the system tray dock but it isn't there anymore since I've gotten the virus. Any ideas?

    Thanks.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your antivirus program is so poorly designed as to not allow you the option you need to run tools to fix your PC, you will have to uninstall your antivirus and then run the fix. Do not reinstall your antivirus until we have finished removing malware because we may need to repeat steps multiple time.
     
  10. kkwilson5

    kkwilson5 Private E-2

    Ok...so I uninstalled my antivirus software and I installed Symantec antivirus and did all the updates. It did find the vundo virus and it also found 7 or 8 viruses and cleaned them. I rebooted my pc and ran the scan again and it didn't find any viruses. (MY old antivirus software would keep finding them after a reboot of my pc). So I uninstalled Symantec and installed McAfee antivirus and did all the updates, scanned my pc and it didn't find any viruses either. Ok...I know this is a stupid question, but is my computer free of viruses?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not if you did not do what I requested in my previous fix!! And you need to attach the follow up logs that were requested after doing that fix. Also I suggest that you stop installing/uninstalling antivirus programs like this because you are going to cause youself problems. McAfee and Symantec rarely uninstall properly of completely. So you may have traces of both of them now. And if PCSecurityShield did not uninstall properly, you could have traces of all 3.
     
  12. kkwilson5

    kkwilson5 Private E-2

    Ok...I ran everything and the logs are attached. Thanks for all your help.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Now let's fix some more malware issues.
    • Open Notepad and copy/paste the text in the below quote box into it. Save it as Log.txt to your desktop
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a log names Log.txt on your Desktop which will overwrite the one you just made. Attach the new Log.txt to your next reply.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created
     
  14. kkwilson5

    kkwilson5 Private E-2

    Here are the logs.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now your logs are clean but you can run analyse.exe to fix the below line from Yahoo Toolbar.

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds