1. I continue to receive a message from Spybot S&D "Resident denied the change of Bandook"

    Although I believe this pop-up message means S&D si working, how do I get rid of this message and continue to operate without fear of this trojan?

    Can anyone help?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

  3. I followed the Malware removal guide and attached are the requested logs.
    I obviously no longer see the pop-up for bandook since I disabled tea timer, but how can I be certain that is resolved.
    Thank you for your assistance. Please advise on the next step.
     
    Last edited: Mar 29, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    After you do the below, it will be gone. You will be able to re-enable Teatimer afterwards to double check.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [*Bandook] C:\WINDOWS\system32\msdll.exe
    O4 - HKCU\..\Run: [Bandook] C:\WINDOWS\system32\msdll.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Joel\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  5. HijackThis went well.
    I ran Avenger and performed the required tasks (log attached).
    I deleted all files (except todays date) from:
    C:\WINDOWS\Temp
    C:\Documents and Settings\Joel\Local Settings\Temp
    but was unable to delete file "CmdLineExt02.dll" from 3/6/2007.
    I ran CCleaner.
    I ran C:\MGtools\GetLogs.bat (log attached)
    I re-enabled Teatimer but as soon as I did it produced the same pop-ups for blocking bandook and also asked about registry permissions for the "FIX" items from HijackThis. I have attached the resident.log file from Spybot S&D.
    Do I really need to keep teatimer enabled?
    Thanks again for your assistance.
     
  6. sorry....here are the attachments.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not while we still need to fix anything. You still need to get the logs attached. Try refreshing your browser or using another browser.
     
  8. ...attachments.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Teatimer seems to be getting things messed up. Please uninstall Spybot now. Then delete the below folders:

    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    C:\Program Files\Spybot - Search & Destroy


    Do not reinstall until requested.

    Now do the below.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [Bandook] C:\WINDOWS\system32\msdll.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  10. Spybot is uninstalled.
    Requested folders are deleted.
    I ran MGtools\analyse.exe, but line *O4 - HKCU\..\Run: [Bandook] C:\WINDOWS\system32\msdll.exe* does not exist.
    Please advise.

    Thank you.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue thru all steps and attach the requested logs when you finish.
     
  12. All steps have been completed and the logs are attached.

    Please advise if and when I should reinstall Spybot S&D and if I should enable teatimer.

    Thanks again for all your assistance.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing the below. ;)

    First uninstall SUPERAntiSpyware since we are finished with it now.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Now you can reinstall Spybot and if you are not going to install any other realtime antispyware blocking tool, you can enable Teatimer.

    How are things working now?
     
  14. Everything seemed to be successful.
    Attached is the log file *C:\MGlogs.zip*
    I installed Spybot S&D and enabled Teatimer. I have also attached *Checks.080402-2150.log* as a result of the findings from S&D.

    Please let me know if anything else is required based on the info from the logs.

    Again, all your help is greatly appreciated.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs do not show any signs of what Spybot is reporting. However our scans do not look in three folders where the Banker.ANV trojan could put files. Those folders and files are:

    C:\WINDOWS\Media\WinetWork.exe
    C:\WINDOWS\system32\inetsrv\messengger.exe
    C:\WINDOWS\Config\amsn.exe

    Please run Spybot again and get a full logs to attach. After it finishes running, just right click in the window and save the log. Then attach it here.
     
  16. This time Spybot S&D found no immediate threats. I chose *fix the selected problems* from those found last night. I have attached the logs from this latest session.

    Please let me know if anything else is required based on the info from the logs.

    Thank you again for all your help.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you run Avenger, you can delete all files related to Avenger now.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. Thanks again for your help. I have been reading through *How to Protect yourself from malware!* The advise regarding Windows firewall is helpful and I'm sure I will be selecting an alternate, but am uncertain if I need to disable any of my currrent virus protection and spyware (AT&T Yahoo! Online Protection)that was provided with my service. How good is this and should I disable it and use one from the recommended list?

    Thanks.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before commenting on it, let me first clarify something. You would not disable it! You must uninstall it, reboot, and then install which ever antivirus you were going to switch to.

    Comments:

    You may be a better judge of whether you like it or dislike it. Personally I have never used it but I know some people who have and they did not give it high marks. Also some reviews online say the same. Like:

    http://www.software-antivirus.com/program/ez-antivirus-review.html


    But you have to also consider the version numbers used during a review. AV software changes all the time. Sometimes for the better and sometimes for the worse. You can get just about any range of opinions under the sun about a particular application by surfing around and it can be quite confusing and often misleading. I will only say that the free programs we have listed in the How to protect youself perform quite well and have typically shown us that they find and remove things many big name products do not.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds