Adware Generic2.OQO

Discussion in 'Malware Help (A Specialist Will Reply)' started by klbreeze, Jul 31, 2008.

  1. klbreeze

    klbreeze Private E-2

    Hi,

    Our church ran a community center that was closed because our lease ran out and the city decided not to sign another :( Anyway, my niece and nephew were given 2 of the computers from the computer center. These computers were donated by a business. So we don't have any info about them or backup or restore, etc. We have not connected either of them to the Internet.

    We went through the procedures listed in the READ and RUN--very helpful, thank you. BTW XP Serivce Pack 1 and these were connected to the Internet at the center. Some files, Trojans, were deleted.

    Now AVG popped up a Resident Shield alert. Accessed file in unwanted. Potentially Unwanted Program.

    File name C:\System Volume Information\_restore{74A39E9A-083E-40E0-A6A1-C9695E11FD2DF}\RP211\A0031270.exe

    Threat name: Adware Generic2.OQO
    Detected on open
    Process name C:\Windows\System32\svchost.exe
    Process ID 884

    So I guess this means it is still infected? I moved it to the vault. What to do now?

    I am attaching the log files.

    Thanks,
    klbreeze
     

    Attached Files:

  2. klbreeze

    klbreeze Private E-2

    Attached is the other log file.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your malware problems were resolved by running the READ & RUN ME. You just need to do the below to finish everything off and cleanup.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  4. klbreeze

    klbreeze Private E-2

    Did this.

    I got a success message.

    But AVG keeps giving me Resident Shield alerts.
    I have Trojan Horse Downloader Generic6.ESI​
    I have Adware Generic.KGZ​
    I have 2 Trojan Horse Lop3.AE​
    These are in the AVG vault. I got these alerts all today. I believe all of them after I did the above procedures.

    Help :confused
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you toggled system restore as requested?

    This is not helpful. I need to know what files and in what folders. If it is registry keys, I need to know what registry keys.
     
  6. klbreeze

    klbreeze Private E-2

    I'm sorry about that :eek: Here are the names of the files.

    WinFixer.GD in
    C:\System Volume Information\_restore{74A39EA-083E-40E0-A6A1-C9695E11FD2DF}\RP211\A0031272.exe

    WinFixer in
    C:\System Volume Information\_restore{74A39EA-083E-40E0-A6A1-C9695E11FD2DF}\RP211\A0031273.sys

    Trojan Horse Downloader.Generic6.ESI in
    C:\System Volume Information\_restore{74A39EA-083E-40E0-A6A1-C9695E11FD2DF}\RP211\A0031274.exe

    Adware Generic.KGZ in
    C:\System Volume Information\_restore{74A39EA-083E-40E0-A6A1-C9695E11FD2DF}\RP211\A0031275.exe

    Trojan Horse Lop.3.AE in
    C:\System Volume Information\_restore{74A39EA-083E-40E0-A6A1-C9695E11FD2DF}\RP211\A0031276.dll

    Trojan Horse Lop.3.AE in
    C:\System Volume Information\_restore{74A39EA-083E-40E0-A6A1-C9695E11FD2DF}\RP211\A0031277.dll

    I am confused:confused I thought I was only supposed to toggle system restore if I were not having any problems? Do you want me to toggle it?

    I really appreciate all your help :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I asked you to toggle it in message # 3. And you still need to finish those instructions. You are not having active malware problems. You are only having problems because you did not toggle system restore as I requested.
     
  8. klbreeze

    klbreeze Private E-2

    Duh! I finally got it.;) I finished the rest of the instructions Everything seems to be peachy :celebrate

    Is anything else I need to do?

    Thank you:clap:clap:clap:clap:clap:clap
    Thank you:clap:clap:clap:clap:clap:clap
    Thank you:clap:clap:clap:clap:clap:clap
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just make sure that all of those final instructions have been followed and surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds