it must be Trojan.Win32.VB.boh

Discussion in 'Malware Help (A Specialist Will Reply)' started by nigga_bl, Jan 20, 2008.

  1. nigga_bl

    nigga_bl Private E-2

    please help me. infected file with pass "virus"! now cant run any exe's! even in safe mode. so i cant use removal guide. kav says its "Trojan.Win32.VB.boh"
    dr web says:"Trojan.Luzya"

    msconfig, regedit not runing. right mouse button blocked. task maneger "blocked by admin"
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you cannot run anything to help us see some logs, there is nothing we can do for you accept say repartition, format and reinstall. If you cannot run and EXEs, how are you running Kaspersky and DR Web to get a report about malware. Have you tried running EXE files from a command prompt and also instead of double clicking on them from Explorer have you tried right clicking and selecting Open?

    What did you attach in that ZIP file that is password protected? Why did you attach it? Are you trying to get others infected?
     
  3. nigga_bl

    nigga_bl Private E-2

    "how are you running Kaspersky and DR Web to get a report about malware" i just scaned it on-line via IE activeX.

    "Have you tried running EXE files from a command prompt and also instead of double clicking on them from Explorer have you tried right clicking and selecting Open?" right button not working and cmd also:\

    "What did you attach in that ZIP file that is password protected? Why did you attach it? Are you trying to get others infected?"

    no i attached infected file for your scaning. maybe you'll scan it and then you'll know what to do with that malware. pass:virus

    thank you
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please use quote boxes around parts of my messages when you want to comment on certain things. It make it much easier to read and find your replies. At first I thought you just repeated my message without replying.

    I cannot give you a fix based upon what you have given me. All I can suggest is that since you implied you could run online scans that you try the below tools and save logs to attach here for use to see what is going on:

    Using BitDefender Online Scan

    Using PandaActiveScan

    Trend Micro Housecall


    Also see if you can somehow manage to do the below.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
    Last edited: Jan 22, 2008
  5. nigga_bl

    nigga_bl Private E-2

    [Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.]
    it helped. now everything run, so i'll try to use removal guide...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay just attach the requested logs when you finish.
     
  7. nigga_bl

    nigga_bl Private E-2

    comp feels much better, but still not inviable "forward" and 'back' button in win explorer. spybotsd not running. while working in inet sometimes have a problem like "generic host 32". it closes.

    while running mgtools there's an error "error initialization"...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does Spybot run OK when not connected to the internet. You really should not run a scan with browsers open anyway as it will block certain things from being fixed.

    That occured because you do not have all the recommended updates from Microsoft. You are missing the .NET Framework software.

    Please attach the requested log from running ComboFix!!

    There are lots of places in your logs where information looks like gibberish to me. Here is one example:
    Code:
    "C:\Documents and Settings\All Users\"
    0016~1        Nov 17 2007              " ¡®ç¨© á⮫"
    5D29~1        Nov 17 2007              "ƒ« ¢­®¥ ¬¥­î"
    91BD~1        Nov 17 2007              "ˆ§¡à ­­®¥"
    AF40~1        Nov 17 2007              "„®ªã¬¥­âë"
    APPLIC~1      Nov 17 2007              "Application Data"
    DRM           Nov 17 2007              "DRM"
    ˜€‹Ž›       Nov 17 2007              "˜ ¡«®­ë"
    Is the above how it looks to you when you look at the All Users folder? There are many more places that look like this in your logs. Even in your Uninstall programs list I see things like below:
    Code:
    "DisplayName"="Ž¡­®¢«¥­¨¥ ¤«ï Windows XP (KB898461)"
    "DisplayName"=" ª¥â ¤à ©¢¥à®¢ Windows - Nokia (WUDFRd) WPD  (06/01/2007 6.84.33.0)"
    "DisplayName"=" ª¥â ¤à ©¢¥à®¢ Windows - Nokia Modem  (02/15/2007 3.1)"
    "DisplayName"=" ª¥â ¤à ©¢¥à®¢ Windows - Nokia Modem  (02/15/2007 3.1)"
    "DisplayName"=" ª¥â ¤à ©¢¥à®¢ Windows - Nokia Modem  (05/24/2007 6.84.0.1)"
    And in your HijackThis log, some services look like this too:
    Code:
    O23 - Service: Æóðíàë ñîáûòèé (Eventlog) - Êîðïîðàöèÿ Ìàéêðîñîôò - C:\WINDOWS\system32\services.exe
    O23 - Service: Ñëóæáà COM çàïèñè êîìïàêò-äèñêîâ IMAPI (ImapiService) - Êîðïîðàöèÿ Ìàéêðîñîôò - C:\WINDOWS\system32\imapi.exe
    O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - Êîðïîðàöèÿ Ìàéêðîñîôò - C:\WINDOWS\system32\mnmsrvc.exe
    O23 - Service: Äèñïåò÷åð ñåàíñà ñïðàâêè äëÿ óäàëåííîãî ðàáî÷åãî ñòîëà (RDSessMgr) - Êîðïîðàöèÿ Ìàéêðîñîôò - C:\WINDOWS\system32\sessmgr.exe
    O23 - Service: Ñìàðò-êàðòû (SCardSvr) - Êîðïîðàöèÿ Ìàéêðîñîôò - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Æóðíàëû è îïîâåùåíèÿ ïðîèçâîäèòåëüíîñòè (SysmonLog) - Êîðïîðàöèÿ Ìàéêðîñîôò - C:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: Òåíåâîå êîïèðîâàíèå òîìà (VSS) - Êîðïîðàöèÿ Ìàéêðîñîôò - C:\WINDOWS\System32\vssvc.exe
    O23 - Service: Àäàïòåð ïðîèçâîäèòåëüíîñòè WMI (WmiApSrv) - Êîðïîðàöèÿ Ìàéêðîñîôò - C:\WINDOWS\system32\wbem\wmiapsrv.exe
    Is this a non-English version of Windows? If not, something is really corrupted in your OS or with your fonts.

    You need to put your PC into Normal Startup mode using MSconfig as was requested in step 1 of the READ & RUN ME.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=:0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ññûëêè
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  9. nigga_bl

    nigga_bl Private E-2

    anyway does run. when i launch its just scratching with floppy and thats all. theres such a process, but not working.

    installed it. mgtool ran fully

    yes, its

    i think its workin better. aviable "back" and "fwd".:)... attachin all requested
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  11. nigga_bl

    nigga_bl Private E-2

    the only problem i have is that sometimes when im on-line and working with opera, firefox or ie there a pop-up error about generic host(or something like that)

    technical is:

    EventType : BEX
    P1 : svchost.exe
    P2 : 5.1.2600.2180
    P3 : 41107ed6
    P4 : netapi32.dll
    P5 : 5.1.2600.2180
    P6 : 41228ea9
    P7 : 0000a3c0
    P8 : c0000409
    P9 : 00000000
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    svchost.exe is a valid Windows process. I'm not sure what you mean by popup. Do you mean error message or do you mean a popup from your firewall? If you mean error message, post the exact word for work error message and attach an Eventlog in a new thread in the Software Forum. If you mean from your firewall then do not block svchost.exe when it is running from the system32 folder.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds