Trojan-SPY.Win32@mx

Discussion in 'Malware Help (A Specialist Will Reply)' started by djgen, Jul 26, 2007.

  1. djgen

    djgen Private E-2

    Hi guys,

    You have helped me before. I just started receiveing mesages that I have a Trojan-SPY.Win32@mx virus running on my PC.

    I follow the Read & Run instructions all the way through. The following steps have been taken.

    I used CC cleaner
    I used Get run and Show New
    I ran Spybot
    I ran counterspy
    I ran bitdefender, but after, I couldn't get PandaActive to run
    Then finally I ran Hijacker.

    I am posting GEt run, show new and bit defender logs. i will follow it up with the hijacker pst for your review.

    Can you please help me?

    Thank you,

    Dino
     
  2. djgen

    djgen Private E-2

    hey guys,

    this is my follow up with my Hijackthis log.

    Please help.

    Thank you,
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must follow all steps in the READ ME and attach all the requested logs which were:

    • CounterSpy - only for Windows XP, 2K, & NT users
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
    Also since you did not run HJT after completing all the steps and also since you did not rename HijackThis.exe as is required, you will need to attach a new HJT log.
     
  4. djgen

    djgen Private E-2

    Thank you for the fast turn around. I apologize if I was not clear in my original email.

    I use Windows XP and "was" able to use counterspy.

    I did use bitdefender, but, was unable to use panda because i kept getting errors stating that it couldnot get Active X to install for the panda scan.

    I ran runkeys.txt and newfiles.txt. i thought i attached them,but apparently not so they will be included in this strand.

    I apologize for the Hijack this error. totally my bad. I renamed it and am attaching all posts via the attachment manager tool below.


    Thank you again,

    Dino
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but where are the logs from CounterSpy and BitDefender? And did you run the BitDefender Online scan as requested or did you install BitDefender's V10 Antivirus program that I see in your HJT log? We did not ask you to install their antivirus program which is only a trial too! If that is what you did, it means you had no antivirus of your own installed before coming here which is a bad idea.

    Is the below something you installed?
    "UpsellTool"="C:\\Documents and Settings\\Administrator\\Application Data\\UpSellTool\\ut.exe"
     
  6. djgen

    djgen Private E-2

    Chas,

    Thank you for your reply.

    Attached is the counterspy log. I could not find where the log was created in counterspy so i printed it and scanned it as a .txt I hope that is okay.

    Also attached is the bitdefender log.

    As for the Upsell.exe. I found that in my Windows task manager when I hit alt-ctrl-dlt and have never seen it before. I deleted it with Hijack this and i have not seen it again.

    Thank you in advance for your help.

    Dino
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you had it Ignore everything it found. You need to run it again and Quarantine everything this time. Save a new log (observe where you save it and what you name it so you can attach it).

    Since you don't know what UpSellTool is, delete the below folder.
    C:\Documents and Settings\Administrator\Application Data\UpSellTool


    I have another question. Do you know what the below folder is for?
    C:\Documents and Settings\All Users\Application Data\SalesMonitor

    If not, what do you see in this folder?

    Your BitDefender log is not from the online scanner as requested. Did you just install this program? It is not what we asked for.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing what was in message # 7 (and answer my question about BitDefender), continue with the below.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9

    Run this Disable/Remove Windows Messenger to remove Windows Messenger.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [SecurityUpdate] rundll32.exe C:\WINDOWS\system32\gtpkzmf.dll,TurnOn2
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. djgen

    djgen Private E-2

    Chaslang,

    My apologies for forgetting about the bitdefender. I was unable to run bitdefender, so I downloaded a trial version to accomplish the goal. Do I need to delte this now?

    As for my response to your last response:

    I deleted the three JSE Runtime files
    disabled/Removed Windows Messenger
    delted the three HKLM files, (though when I reran Hijack This, the "Security Update file was still there)

    Copied the HKEY file and saved it asa fixme.reg and ran

    downloaded and ran The Avenger

    copied the C: files into Avenger and hit done and rebooted

    Ran:

    Ccleaner
    GetRunKey
    ShowNew
    HJT

    The logs are attached, though I will have to reply with another since there are four files to attach.

    The system appears to be running back to normal. You guys are miracle workers.

    Please let me know if I need to check the system Restor box now.

    Once again, thank you,

    Dino
     

    Attached Files:

  10. djgen

    djgen Private E-2

    Chaslang,

    Attached is my HJT log

    Please let me know if you notice anything I need to remove, change or etc.

    Thank you again,

    dino
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is only a trial so uninstall it now before continuing. My final steps (when we get to them) will give you a list of free antivirus tools you can choose from.

    You forgot to answer my other question:
    Try fixing the below line again:
    O4 - HKLM\..\Run: [SecurityUpdate] rundll32.exe C:\WINDOWS\system32\gtpkzmf.dll,TurnOn2

    Then reboot and attach a new HJT log. I want to make sure it stays gone after a reboot.

    I will tell you when to toggle system restore.

    I still see the below folder! Did you forget to delete it:
    C:\Documents and Settings\Administrator\Application Data\UpSellTool
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way you never re-ran CounterSpy to fix what it finds as requested in message # 7. I asked for a new log showing that things were Quarantined.
     
  13. djgen

    djgen Private E-2

    Chaslang,

    Attached is the counterpy log. it still shows a Trojan virus. I located the C:/Program files/popsmedia Site adviser. It is a .log file, but, I didn't open it or anything. I wanted to wait to hear back from you.

    I uninstalled bit Defender

    I looked in the C:Documents and Settings/all Users/Application Data/ Sales Monitor In the File was a folder lnamed "data". Inside that was nothing. What should i do with it?

    I deleted the HKLM file and rebooted. I did not appear to see it.

    As for the C:...Upsell Tool file. I deleted if from HJT, but not the C: file. i just deleted it and did not see it in the new HJT file (attached)

    the system is running well when it is up, however, two new things have happened. it takes a while to boot up now. just before it comes up, I get two messages:

    RUNDLL(in the blue header) in the box it reads, " error loading C:/Windows/system32/gtpkzmf.dll" isn't this a file that I copied to delte in Avenger? what should I do now.

    The second message is:
    Wireless configuration (in blue header) in the box it reads, " Incorrect MFCDll version installed on the system, minimum requirement is MFC SP4 Dlls"

    Suggestions?

    Thanks,

    Dino
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I stated in message number 7, you must not Ignore what it finds. You need to Quarantine or Delete what it finds. Run it again and Quarantine the problems. Attach a new log.


    Delete it.

    I'm not sure what this is saying. Did you delete the folder I listed at the end of message # 11 or not?


    This is also the line that you were supposed to be fixing in your HJT log. It does not show in the last HJT log that you posted so perhaps it will not occur anymore after another reboot. Let me know.


    Has nothing to do with malware. You will have to work this in the Networking Forum.
     
  15. djgen

    djgen Private E-2

    Chaslang,

    Attached is the new counterpy log. I re ran, quarantined, then deleted the the Trojan and WinAntivirus, then reran counterspy. the attached counterspy log is after deleting the trojan and winantivirus.

    I deleted the C:/Documents and Settings/all users/application data/sales monitor file

    I ran HJT and did not see the C:/windows/system32/gtpkzmf.dll file, although, I did see:

    C:/windows/system32/igfxsrvc.dll and
    c:/windows/system32/ wfalogon.dll files

    Are these anything to worry about?

    What next?

    Also attached is the new HJT log for your review

    Thank you,

    Dino
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No they are valid.

    Your log is clean.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below folders which may be left behind by the uninstall:
    C:\Documents and Settings\Administrator\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds