Dropper Trojan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by roberts663, Oct 23, 2004.

  1. roberts663

    roberts663 Private E-2

    Is it safe to delete this manually with system restore off and logged on safe mode with networking? Yes or No? Another problem i am having is some anti virus programs not working properly. Could this be due to this trojan, or a trojan that appears every so often called the ByteVerify trojan. I have done every step and now I'm just waiting.
     
  2. roberts663

    roberts663 Private E-2

    specifically, TrojanDropper.Win32.Small.gt Kaspersky's definition.
     
  3. roberts663

    roberts663 Private E-2

    nwywonoc.exe - packed with UPX
    nwywonoc.exe - infected by TrojanDownloader.Win32.Small.oe
    from program files/internet explorer
     
  4. roberts663

    roberts663 Private E-2

    about a million of these showing up with avast.
    avast! Virus Cleaner Tool - version 1.0.203 Unicode

    C:\Documents and Settings\PR\Local Settings\Temp\Temporary Internet Files\Content.IE5\USYSNYB8\1998753524@HeaderSpon,PageSpon,PageSpon2,LocalAd,Explore1,Explore2,Explore3,Explore4,Explore5,Explore6,LocalSite1,LocalSite2,LocalSite3,LocalSite4,LocalSite5,LocalSite6,LocalS[1]... file could not be scanned!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you posting in multiple threads for the same problems? You are going to find it more difficult and slower to resolve issues this way.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you had run the READ ME FIRST, you would have run CCleaner which should have deleted all this alread. You said you ran the READ ME in the other thread.

    Do not run scans with Internet Explorer windows running.
     
  7. roberts663

    roberts663 Private E-2

    Sorry about the multiple threads dude, anyways, i ran CCleaner again with IE turned off, still didn't delete those files.
     
  8. roberts663

    roberts663 Private E-2

    About the other thread about Norton, I bought the software and they told me at the store that I can legally use it on one other computer. If it keeps giving me problems, I'll drop it because I've noticed it doesn't really work as good as some of the free ones.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your other thread said,

    "Does the ByteVerify disable anti virus software or could there be another trojan or virus on the computer or could it just be that my CD isn't copying on his computer right?"

    That sounds to me like your installing your software on someone else's PC. Not legal! Unless you bought it for your friend and gave the CD to him and did not install it on another PC (like your own).
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have multiple user accounts on this PC? Is PR the account you were logged in as when you ran CCleaner and other scanners?
     
  11. roberts663

    roberts663 Private E-2

    Yes, there is multiple accounts. I was logged in as the Administrator when i ran CCleaner and all of the scans.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So you need to run all the steps (including CCleaner) of the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal thread for each user account. If you cannot run certain steps in safe mode when not logged on as the Administrator then run them in normal boot mode.
     
  13. PhilliePhan

    PhilliePhan Guest

    Hey Chas,

    What is the DEFAULT setting for the cleaning of Windows Temp files in CCleaner? I seem to remember that it was set to clean only those folders older than 48 hours. Of course I could be wrong - Wouldn't be the first time! ;)

    Best,
    PP
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I believe the default setting is to delete files in Windows Temp folder older than 10 days.
    But note, that's only Windows Temp. It does not have options for things like:
    C:\Documents and Settings\PR\Local Settings\Temp\Temporary Internet Files
     
  15. roberts663

    roberts663 Private E-2

    Those files were deleted using CCleaner on that particular account. I'm having troubles with adaware SE on another account that is picking up a lot of bad files and keys. It won't finish the scan, the program freezes up at conditional scan and I can't finish cleaning those bad files.
     
  16. roberts663

    roberts663 Private E-2

    Also, his internet explorer home page on this account is hijacked, and it is difficult to get around on the internet. However, i managed to get to the bitdefender home page in Spanish, which i don't understand very well, and I'm running a scan right now.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First make sure you updated to today's Ad-Aware SE reference file. Then click Scan now and on the next screen uncheck the Search for negligible risk entries selection. Now make sure you have Perform smart system scan selected, then click next. See if that helps.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you run all of the steps from READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal on this user account?
     
  19. roberts663

    roberts663 Private E-2

    I accidentally deleted a key in regedit called 404upd which was in the HKLM software section of the registry i believe. Was this file spyware? If not, is it important to the computer?
     
  20. roberts663

    roberts663 Private E-2

    I haven't done all the steps yet, spyware blaster does not work, cwshredder does not work, I am just manually deleting the files and registry keys that adaware brought up, I'm pretty much done, and internet explorer home page is back to normal.
     
  21. roberts663

    roberts663 Private E-2

    It still freezes, even on smart scan, I haven't tried to see if spyware blaster or cwshredder works yet, i'm still deleting all the bad registry keys.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless you really know what you are doing you should not be editing the registry. You can totally break your computer. And first you should perform a registry backup.

    You could be deleting entries that you see there that the spyware blocking (immunize feature) of Spybot put there on purpose.

    Please stop skipping around and follow directions. When you selected smart scan did you disable negligible risk entries?
     
  23. roberts663

    roberts663 Private E-2

    It still freezes up, everything i deleted is not back because my roommate got home and nothing that i did in the registry was saved, i'm back to 0.
     
  24. roberts663

    roberts663 Private E-2

    Negligible objects are ignored, and the adaware freezes at the very end of the scan.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand what this means. If everything you deleted is not back (and it was bad) then what's the problem. Also you don't need to save the registry. As soon as you edit it with regedit the changes are already made.

    What version of Ad-Aware SE are you using and what is the reference file version.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or from a sub-folder of C:\Documents and Settings, or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you follow the above directions!!
     
  27. roberts663

    roberts663 Private E-2

    Here is my HJT.
    I meant to say that the bad files are now back, I'm not sure what he did, maybe pressed restart on the computer?
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post your full un-edited log. There must be more running processes than that on any WinXP system. Follow directions!! This C:\Program Files\Internet Explorer\iexplore.exe should not be running. We specifically ask for browsers to be shut down.

    This C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe should not be running either.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Add/Remove programs and uninstall
    WebRebates
    or
    WebSavingsfromEbates

    Also uninstall: BearShare

    You have a bunch of trojans on this PC. That's your problem.
     
  30. roberts663

    roberts663 Private E-2

    For some reason your system denied write access to the hosts file. If any hijacked domains are in this file, HijackThis may NOT be able to fix this.
    I get this message with HJT.

    I know there are a bunch of trojans on this computer, I've been deleting a bunch manually, and antivirus finds some, how do i get antivirus to find more?
     
  31. roberts663

    roberts663 Private E-2

    web rebates and web saving is not under the list, can i reinstall bear share at a later time?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I wouldn't but that's up to you. Do you like having problems like this?

    Read this from PestPatrol:

    P2P: Any peer-to-peer file swapping program, such as Audiogalaxy, Bearshare, Blubster, E-Mule, Gnucleus, Grokster, Imesh, KaZaa, KaZaa Lite, Limewire, Morpheus, Shareaza, WinMX and Xolox. In an organization, can degrade network performance and consume vast amounts of storage. May create security issues as outsiders are granted access to internal files. Often bundled with Adware or Spyware.

    But it's your decision in the end. If you want to live with the potential problems it can cause (and it may be the reason for all your trojan problems), don't uninstall it.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still need your FULL unedited HJT log so we can work on removing the trojans.
     
  34. roberts663

    roberts663 Private E-2

    Well, it's my roommates computer, so I'll leave it up to him to reinstall.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'll assume you uninstalled it and that you are having a problem posting full HJT logs. Do the following exactly:

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them (if found) :
    BROWSELC.exe
    hpalyab.exe
    winmgm32.exe
    mscvb32.exe
    svrhost.exe <--- be careful of the spelling this is not svchost.exe
    svphost.exe <--- be careful of the spelling this is not svchost.exe
    urpo.exe
    wnstsit.exe
    webclnt.exe
    slmss.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS10
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hkcu
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://server224.smartbotpro.net/7search/?003
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - (no file)
    O4 - HKLM\..\Run: [7d62dcdd86ec] C:\WINDOWS\System32\BROWSELC.exe
    O4 - HKLM\..\Run: [hpalyab] C:\WINDOWS\System32\hpalyab.exe
    O4 - HKCU\..\Run: [WindowsMGM] C:\WINDOWS\winmgm32.exe
    O4 - HKCU\..\Run: [System MScvb] C:\WINDOWS\mscvb32.exe
    O4 - HKCU\..\Run: [svrhost.exe] C:\WINDOWS\system32\svrhost.exe
    O4 - HKCU\..\Run: [svphost.exe] C:\WINDOWS\system32\svphost.exe
    O4 - HKCU\..\Run: [Ncao] C:\Documents and Settings\Paul Ragozine\Application Data\urpo.exe
    O4 - HKCU\..\Run: [WNSA] C:\WINDOWS\System32\wnstsit.exe
    O4 - HKCU\..\Run: [webclnt] C:\WINDOWS\System32\webclnt.exe
    O4 - HKCU\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\WebRebates\System\Temp\topr1150_script0.htm
    O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\BROWSELC.exe
    C:\WINDOWS\System32\hpalyab.exe
    C:\WINDOWS\winmgm32.exe
    C:\WINDOWS\mscvb32.exe
    C:\WINDOWS\system32\svrhost.exe <--- be careful of the spelling DO NOT delete svchost.exe
    C:\WINDOWS\system32\svphost.exe <--- be careful of the spelling DO NOT delete svchost.exe
    C:\Documents and Settings\Paul Ragozine\Application Data\urpo.exe
    C:\WINDOWS\System32\wnstsit.exe
    C:\WINDOWS\System32\webclnt.exe
    C:\Program Files\Common Files\slmss <--- delete the whole directory

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  36. roberts663

    roberts663 Private E-2

    Okay, I did all the steps, except some of the files were not in the process list in the task manager, and some files were not found that i was to delete. Specifically, file winmgm32.exe, mscvb32.exe, svphost.exe, urpo.exe, wnstsit.exe, webclnt.exe, Common Files\slmss were not found in the listed locations. My home browser is now about: blank from the hijacked page, remember that the registry changes I made were not saved. Here is my HJT, I don't know why I can't get a full log.
     

    Attached Files:

  37. roberts663

    roberts663 Private E-2

    I'm amazed this computer still works...all the other accounts work pretty well with no pop ups, but the speed of the computer doesn't really match 2.4 gigs
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I see you did not remove BearShare yet.

    I also see these are still present did you fix these last time:
    O4 - HKLM\..\Run: [7d62dcdd86ec] C:\WINDOWS\System32\BROWSELC.exe
    O4 - HKLM\..\Run: [hpalyab] C:\WINDOWS\System32\hpalyab.exe
     
  39. roberts663

    roberts663 Private E-2

    bearshare is removed, i noticed that too in HJT, i'm not sure, maybe it's on a different account?
     
  40. roberts663

    roberts663 Private E-2

    as for the other ones, i almost positive i did, but i'll try it again.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We also need to clean up remnants of the W32.Sobig.A@mm worm.

    1. Click Start, and then click Search.
    2. Click All files and folders.
    3. In the "All or part of the file name" box, type, or copy and paste, the file names: dwn.dat sntmls.dat.
    4. Verify that "Look in" is set to "Local Hard Drives," or to (C:\)
    5. Click "More advanced options."
    6. Check "Search system folders."
    7. Check "Search subfolders."
    8. Click Search.
    9. Delete the displayed files.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check all accounts for this and also for the other stuff too.

    Have you run the McAfee Stinger program on each account. If not, please do so.
     
  43. roberts663

    roberts663 Private E-2

    Alright, i just ran Stinger on another account that i think i already ran on it, nothing. sntmls.dat was not found with search. I also couldn't find the other files on each account. I did come accross a suspicious file in system32 however. Updaterinstall.dat. Should i get rid of this file?
     
  44. roberts663

    roberts663 Private E-2

    Alright, i'm gonna get some sleep, i have a lot to do tommorow. Here's another HJT log, i hope it helps. I don't know why that bear share thing is still there, i did a search and deleted every single file on this whole computer that says bear share. Maybe it has something to do with mini bug, i got rid of most of the files for it, but i think there might be a few more.
    Good night and thanks for the help.
     

    Attached Files:

  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause


    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\BearShare <--- the whole directory


    You may need to repeat the above for each user account.

    Now reboot in normal mode and post a new HJT log.

    If BearShare is still in your HJT log, you will need to search the registry for it.

    I'm not sure about Updaterinstall.dat. Is could be part of one those annoying Casino programs. Try right clicking on it and get Properties, Version information.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds