BHO.CVX Trojan / Downloader.Small.33.BS

Discussion in 'Malware Help (A Specialist Will Reply)' started by vedder45, Dec 23, 2007.

  1. vedder45

    vedder45 Private E-2

    Hello-
    I'm hoping someone is looking for a break from all the holiday cheer long enough to help a novice. Last night I was hit with what I believe is the BHO.CVX Trojan Horse. I'm gathering that from the AVG scan results (after Norton didn't find anything wrong) and I learned of AVG after my first panic search of the web. I was just surfing the internet and some website must have run an installer to pass it on to me - I did not open any strange attachments. Also mentioned in my results was the Trojan Horse Downloader.Small.33.BS. What also came along with this was a disabling of my connectivity on the infected machine. I'm writing this from my laptop which is still able to pickup my wireless network although the desktop is now incapable. (Let me know if you need more symptoms of that issue as I'm focusing now on removal of the infection but will certainly need to regain control of my connection.)
    I came across this Forum and tried my best to follow the cleaning instructions before posting. So attached are the logs from ComboFix, MGTools and AVG. Note: I may have a newer version of AVG from the version on which your instructions were based. I got confused following that and saved the only log I could figure out. I did write down some additional AVG info so just ask and I'll try to provide.
    The good news is that after following the procedures, AVG says that the BHO is now quarantined and there were no more signs of the Downloader.Small.33.BS in the scan results.
    Other symptoms I should point out besides the identified trojan(s) and loss of connectivity are that I have a bunch of suspicous active Processes such as:
    smss.exe
    csrss.exe
    winlogon.exe
    lsass.exe
    numerous 'svchost.exe' listings
    (others available on request)
    I say these are suspicious per my search results at sysinfo.org.

    My current status is that I'm sitting at the desktop in Normal mode after performing the cleaning steps. I have not rebooted nor have I wiped the quarantined files from AVG. I thought I would wait for someone to tell me to do so.

    So I ask...OK, I BEG...would someone be so kind as to help me clean my computer and restore my ability to pick back up my connection on my desktop? Again, it's not the router as I'm using the same network with a clean laptop. I really appreciate the assistance - I'm really disappointed that I got myself into this - I've been so lucky and careful for so long!

    Thanks in advance.
     

    Attached Files:

  2. vedder45

    vedder45 Private E-2

    Sorry...meant to include another funny thing:
    Don't know what this file is, but I now have in my Startup a v8m3.exe which is something I didn't get any results for when searching the web. Don't know what this is for and I get an error message about it when rebooting now.

    Thanks again!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is quite possible that your tcpip.sys file has become corrupted. The date I see on it is 12/23/2007 which is probably the date your problems began.

    Click Start, Run and enter sfc /scannow and click OK. This will perform a System File Check to look for missing or corrupt Windows files and will attempt to repair them. It may ask for your Windows CD, so be prepared to insert it into your CD drive if requested.

    No matter what happens while trying to do the above, continue on with the below anyway.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ccApp] -
    O4 - HKLM\..\Run: [v8m3] C:\WINDOWS\system32\v8m3.exe
    O4 - HKCU\..\Run: [v8m3] C:\WINDOWS\system32\v8m3.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!


    Once you have internet access back, you need to do the below.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  4. vedder45

    vedder45 Private E-2

    Thank you very very much!

    I'm posting this from my desktop now as I have regained my connection due to your help! My startup process seems faster than it was before my first post and the v8m3 error is gone. (I did see that Avenger successfully deleted it along with the other file you suggested.)

    The only hangup I had on your instructions is that during the sfc /scannow process, it did ask for my Windows CD. I inserted the disc provided by Dell labeled 'Reinstallation DVD', 'Microsoft Windows XP Media Center Edition 2005 with Update Rollup 2'. That was sufficient for the scan process for about 90% of the way until it asked me to 'Insert XP Professional Disc 2'. Dell only provided 1 disc and I was confused as I don't have XP Professional. I tried a 'Drivers and Utilities' disc but that of course didn't work. So I just hit 'Cancel' and said 'Yes' when asked if I wanted ot skip that file. This happened about 4 or 5 times so I guess I skipped that many files. Unfortunately, it did not identify the files that were skipped or would have submitted those to you. The good news is that it must not have skipped the tcpip.sys file since I'm reconnected again!

    So...as you requested, I've attached the new MGlogs.zip and the Avenger log for your review. I have also uninstalled my old Java and installed the Sun version.

    Again, THANK YOU VERY MUCH for your help on this. I really appreciate it! I'll look forward to your next set of instructions if necessary.
     

    Attached Files:

  5. vedder45

    vedder45 Private E-2

    Sigh...need to give another update...

    With the excitement from my renewed internet connection returned, I did a Windows Update and installed the latest version of ZoneAlarm. Upon restart after installations, AVG found a Trojan Horse named 'Agent.MEU'. I selected the 'Heal' option and it seemed to take that OK. I next ran a full scan with AVG and now I see this:
    'authzw.dll.vir' - 'Virus identified Obfustat.ADNN'. The path seems to show it as quarantined: 'C:\qoobox\Quarantine\C\WINDOWS\system32\authzw.dll.vir.
    Also see the above mentioned 'Agent.MEU' as being in the Virus Vault and associated with the filename 'wnl32.dll'.

    Perhaps I was a little over anxious by running the Windows Update or the ZoneAlarm upgrade? :eek:
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a problem. It is just something in the Quarantine folder created when ComboFix was run. My final steps below will remove all of this.

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  7. vedder45

    vedder45 Private E-2

    Chaslang-

    I can't thank you enough!!

    I'll do the steps as outlined, but have one last quirk to ask you about. Maybe it's unrelated to Malware and you can refer me to a different forum section, but it just began today so I wanted to run it past you.

    My CPU Usage meter is through the roof. It's constantly over 60% and many times at 100%. The fan is working overtime and it's concerning me. Never noticed this before. If it helps, the top two culprits for the usage in the 'Processes' tab are 'explorer.exe' and 'System Idle Process', respectively.

    Doesn't seem normal for the computer to be running at capacity and the fan to be going bonkers even when I have no applications open.

    Can you help just a bit more?:confused

    Thanks once again for sharing your time and knowledge. You are certainly appreciated.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Idle Process is not a real process. It is a measure of the time your CPU is doing nothing. Thus the larger the number for System Idle Process the better.

    However explorer.exe should not normally be using lots of CPU time unless you are actively running things that are accessing the system shell.

    Questions:
    1. Does it happen if no browsers are open?
    2. Does it happen if no browsers are open and you have physically unplugged your cable to the internet?
    3. Does it happen if you shut down your AVG Antivirus which could be actively running a scan at various times of the day based on what you scheduled it to do?
    4. Does the samething happen in safe mode?
    5. Have you uninstalled/deleted the MGtools folder yet? If not, don't. I may be asking you for a new MGlogs.zip file if issues still remain.
     
  9. vedder45

    vedder45 Private E-2

    Thanks again!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I would like two copies of MGlogs.zip.

    • Please get one after booting in safe mode and attach it first.
    • Then reboot into normal mode and run C:\MGtools\GetLogs.bat which will create a new MGlogs.zip file and attach it.
     
  11. vedder45

    vedder45 Private E-2

    Logs attached.

    Please note: Safe Mode started up with minimal CPU Usage as described previously. However, as soon as I started the MGTools file, I heard the fan kick on and after the log file was completed, I check the CPU Usage which was in the 50-59% range and remained there for a few minutes until I restarted to Normal Mode. (If it means anything, the PF Usage was still low in Safe Mode even with the big spike in CPU Usage.)

    So it appears that it DOES happen in Safe Mode as well, just not immediately after startup.

    Thank you.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to be a malware issue. It is more than likely just due to what you are running.

    I would begin by uninstalling the below and then tell me how things look. Make sure you have the CD or files required for reinstalling (later) Norton Ghost if you really use that program. Make your you reboot after uninstalling.

    AVG Antispyware
    LiveReg (Symantec Corporation)
    Norton Ghost 10.0
    ZoneAlarm Spy Blocker
    ZoneAlarm

    Then run this to make sure Norton is properly removed because often it is not: Norton Removal Tool (SymNRT)


    Now reboot. How are things now? Attach a new MGlogs.zip file now!
     
  13. vedder45

    vedder45 Private E-2

    Uninstalled each of the below programs except for LiveReg which wasn't listed in the Add/Remove Programs window. I did run the Norton Removal tool so hopefully that got it all cleaned up that way.

    Rebooted after all those steps and it's still running at the same %'s as before. Attached the new log.

    Feeling a little uneasy without the AVG or ZoneAlarm. OK to reinstall prior to next steps?

    Many thanks.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AVG Antispyware is only a trial program and does not provide any realtime protection after the trial is over. It then becomes an after the fact scanner/removal tool. You can reinstall the ZoneAlarm items now but leave Symantec out for a bit longer. And do the below.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Automatic Updates
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Any change in the response/CPU useage right now?


    Now Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp

    After clicking Fix, exit HJT.

    Then reboot and after reboot run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created
     
  15. vedder45

    vedder45 Private E-2

    My updates again in blue...
    Thank you a million times more for such quick responses and your continued support!​
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have gone as far as we can go in this forum. You either have hardware or software issues.

    Based on the below quote of yours from message # 4, I would expect software issues:
    You should post in the Software Forum. Other alternatives are to get a real full copy of Windows XP Media Center since I believe the OEM version is not adequate because it is customized by the manufacturer. You could be looking at a reinstall or maybe a repaid would work but a repair will not work without a proper original copy of Windows Media Center.

    Note: You can enable and set to automatic, the Automatic Updates service that I had you stop and disable.
     
  17. vedder45

    vedder45 Private E-2

    OK. Well, I really appreciate your help in getting the system clean. Can I feel confident proceeding with my daily computing routines without concern of malware/virus/spyware based on the information you have been able to access? I'll keep AVG (my new replacement for Norton) and ZoneAlarm running and I'm also now armed with SpyBot in addition to AdAware for routine scans.

    I can put up with the noisy fan and usage meter until another good samaritan in the Software forum can review that issue. May I reference this thread in my post there?

    Thank you one last time for donating your time to help me. If an 'Internet Citizen of the Year' award exists, please post a link to the voting site so that I may check your name on the ballot! :wave
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    You also need a realtime antispyware blocking tool per the information in How to Protect yourself from malware!

    Yes you should definitely put in a link for this thread because someone is more than likely going to tell you that you have a malware problem. ;)

    You're welcome and thanks. ;)
     
  19. vedder45

    vedder45 Private E-2

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about missing that one! You will need to get Avenger and MGtools.exe again if already deleted.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  21. vedder45

    vedder45 Private E-2

    Good news! My CPU Usage is hovering around 1-2% as I type this!! The fan is finally able to relax!! The 'System Idle Process' is at 99 just as 'thefool' said it should be!!

    Avenger was a bit concerning, though. After clicking the traffic light the first time, I got a message that said this:
    Location of startup: FILE
    C:\Windows\System32\Drivers\NFQCDPBK.SYS
    This trojan horse program was found on your machine. It has been shut down, but the FILE from which it started still remains and can be started up again. Do you want the file removed also?

    I selected 'Yes'. Then told it to go ahead and reboot. Upon restart, there was no avenger.txt log to be found and the AppCert folder had not been deleted. So I started over.

    2nd Try:
    After clicking the traffic light, I got 3 messages:
    - 'Error: cound not create zip file. Press OK to log error and continue or Cancel to abort.' (I clicked OK.)
    - 'Error Code: 0'
    - After restart, this came up: 'Exception Processing Message C0000013 Parameters 75b6bf9c 4 75b6bf9c 75b6bf9c'

    It did, however, produce an Avenger log and showed that the AppCert directory was deleted. I looked for it myself and it was not in the system32 directory. The CPU Usage and fan returning to normal is further evidence that it worked.

    While I was confirming the AppCert directory was deleted, I noticed a few other items in the system32 directory that were modified on 12/23 when my issues began. Just wanted to list them for you in case they mean something:
    tmp.txt
    tmp.reg
    \config
    \restore

    Maybe they're nothing, but that date modified scares me. Wonder why AVG or SpyBot didn't recognize this?

    Logs are attached for your review. Also wanted to ask you about Toggling System Restore at some point - I haven't done that yet (probably a good thing) but when you think I'm ready to do so, would you mind pointing me to those instructions? Is it typical for Malware to monkey with System Restore so that you don't have an earlier Restore Point? Before I found you, I tried to do that and 12/23 was the earliest it would show me.

    Thanks again for the help. Looking forward to next steps! We're making more good progress!!
     

    Attached Files:

  22. vedder45

    vedder45 Private E-2

    One new update:

    While passing the time, I ran a SpyBot and it came up with the most results yet - 13 listings with a total of 39 issues. Most of these were found in a \ZoneMap directory within \Internet Settings.

    Is this \ZoneMap a regular directory or should it be 'Avenged' also? ;)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This was the wrong answer. Avenger was trying to install a driver inorder to properly get the malware deleted. Your antivirus or antispyware program was warning you about something it did not recognize but this was due to what we were doing. The net result as you noticed was there was no avenger.txt file and the folder was not deleted.

    Again some of this could have been caused by existing protection software. Tools like Avenger and ComboFix are kernel level type tools and are going to be viewed by all protection software as potentionally dangerous/malicious.

    You can delete tmp.txt and tmp.reg which may be files from Avenger. The other two folders are normal and part of Windows.

    As long as things are working better now then all is good. Now your logs should really be clean. ;) Sorry I missed that folder last time. As I stated I had already clean up PCs with this problem folder and files but did not notice the folder in yours since the DLL files had not shown up anywhere in your original logs.

    I would need to see a Spybot log to see exactly what it is finding. Often times, things in ZoneMap are things in the Restricted Zone and they are typically added by programs just like Spybot's Immunize to protect you. Zonemap is not a directory/folder. It is part of your registry.
     
    Last edited: Dec 31, 2007
  24. vedder45

    vedder45 Private E-2

    Bummer that I picked the wrong answer with Avenger. Pretty confusing, though, when it says "This trojan horse program was found on your machine. It has been shut down, but the FILE from which it started still remains and can be started up again. Do you want the file (that starts a trojan horse) removed also?". Makes it sound like 'the file from which (the trojan horse program) started still remains', so I said 'Yes. I want the file removed'. Not familiar enough with Avenger and what it does - was just thinking it is a really powerful delete button. :confused So since I answered incorrectly on that portion, do I still have an outstanding issue with C:\Windows\System32\Drivers\NFQCDPBK.SYS?

    I'll forget about the SpyBot findings I described earlier. Sounds like it's not a big concern.

    Aside from my one remaining question above, seems like I'm in great shape. Would you advise me to toggle System Restore? (Have a link handy for instructions on that?)

    Thanks again!!
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes it can be confusing. That is why very often we have to ask people to shutdown and even uninstall other protection software to get things fixed. They get in the way of removing the real malware.

    No. That file was created by Avenger and was being loading as a driver to make it possible for Avenger to load very early in your boot process and delete the malware files before they could run.

    It's up to you. If you want to be sure, just attach the Spybot log (right click in the scan window to see save options).

    You should not do all of what was in my final steps given in message number 6.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds