Advice for suspicious activeX?

Discussion in 'Malware Help (A Specialist Will Reply)' started by NoGeekMe, Mar 28, 2008.

  1. NoGeekMe

    NoGeekMe Private E-2

    No malware symptoms that I've noticed, BUT, I found this entry in my HJT log:

    O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxresearch.com/Preloader.dllan

    Looked it up in Spyware Blaster, it's identified as:

    TrojanDownloader.OTXloader.A - {084F552D-19EB-4668-9788-984CBC781A8F}

    It was in a log MG looked at for me last December but wasn't noted as an issue.

    Wondering if it really is bad, and if it is do I take care of it by running HJT and checking it off for removal?

    (Should I start at the beginning and do the R&RMF, even though it wasn't discovered by anything, except HJT, the last time I did the R&RMF?)

    Many, many, thanks for your advice!
     
    Last edited: Mar 28, 2008
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Yes please do the R&RMF and attach the logs.
     
  3. NoGeekMe

    NoGeekMe Private E-2

    Thanks for your reply! Did the RRMF, logs attached.

    When I went through Add/Remove Programs I found My Way Search Assistant, but without a remove button or a last date of use.

    Searched hard drive for it but couldn't find it.

    Do you think what's in Add/Remove could be left over from an incomplete uninstall? (I inherited this computer last December and don't know it's whole history.)

    I also tried an uninstall program from Dell that's specifically for My Way, but I didn't notice anything different.

    Thanks again.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not really a problem. Yes you will see many people removing it just due to the name and the fact that it is referred to as downloader. It is from http://www.otxresearch.com/ which is a marketing research company. You can simply fix any 016 lines in HJT logs anyway since it does not cause any problems if you do. The active x controls will just get downloaded again if the the site gets used again. Obviously you would not want to remove active x files for things that you use since you would have to waste time downloading them again.

    According to your logs, My Way Search Assistant is not installed anymore.

    You don't appear to have any active malware; however, you do need to delete the below files:

    C:\Documents and Settings\Tova\Local Settings\Temp\0fa7iuoh.exe
    C:\Documents and Settings\Tova\Local Settings\Temp\61vq6p2u.exe
    C:\Documents and Settings\Tova\Local Settings\Temp\8pv9puzu.exe
    C:\Documents and Settings\Tova\Local Settings\Temp\AUInst.log
    C:\Documents and Settings\Tova\Local Settings\Temp\IMT59.xml
    C:\Documents and Settings\Tova\Local Settings\Temp\IMT5A.xml
    C:\Documents and Settings\Tova\Local Settings\Temp\IMT5B.xml
    C:\Documents and Settings\Tova\Local Settings\Temp\IMT60.xml
    C:\Documents and Settings\Tova\Local Settings\Temp\IMT61.xml
    C:\Documents and Settings\Tova\Local Settings\Temp\IMT62.xml
    C:\Documents and Settings\Tova\Local Settings\Temp\ju26klgo.exe
    C:\Documents and Settings\Tova\Local Settings\Temp\l001yeps.exe
    C:\Documents and Settings\Tova\Local Settings\Temp\lcdqmjrn.exe
    C:\Documents and Settings\Tova\Local Settings\Temp\mjfhbwqr.exe
    C:\Documents and Settings\Tova\Local Settings\Temp\pcf28.tmp
    C:\Documents and Settings\Tova\Local Settings\Temp\pycj5pyx.exe
    C:\Documents and Settings\Tova\Local Settings\Temp\REGSCRIPT.REG
    C:\Documents and Settings\Tova\Local Settings\Temp\_tf2C.tmp


    Let me know if you have problems deleting any of these.
     
  5. NoGeekMe

    NoGeekMe Private E-2

    Thank you! No problem removing the files. More of the .xml files have popped into the folder since the logs were created. Just delete them?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about them. They are likely for something you run. The main worries were the randomly named EXE files.



    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    2. If we had you run Avenger, you can delete all files related to Avenger now.
    3. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    4. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    5. After doing the above, you should work thru the below link:
     
  7. NoGeekMe

    NoGeekMe Private E-2

    Thanks!

    Just one more question.

    You'd helped me delete combofix in a previous thread. Just noticed a cf folder in main directory, with a bunch of cf files inside. Is this normal after uninstalling?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may be a issue due to renaming ComboFix.exe to cf.exe but we need to do this because some new malware blocks combofix.exe from being run. Just delete the cf folder.
     
  9. NoGeekMe

    NoGeekMe Private E-2

    All done.

    Thanks for your help and information, you guys are such a terrific resource!!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds