Unknown Trojan after changing AV - regenerates - XPsp2

Discussion in 'Malware Help (A Specialist Will Reply)' started by Franix, Aug 16, 2008.

  1. Franix

    Franix Private E-2

    Hi everyone,

    Here's my story.

    Backgrounder: Since AVG released AVG 8, I started to use Avast for my AV, as AVG 8 was very unstable and caused my system to crash to blue screen. Since I started using avast, Spybot doesn't pick up anything at all, so I've just been using CCleaner.

    Symptoms: On Tuesday or Wednesday I noticed I was getting random pop-ups that appeared in IE windows. Mainly they would appear when my mouse was idle, and I wasn't typing. My system was also running incredibly slow with multiple applications on the go. I checked task manager and there was an odd process running. 1eevsTbt.exe Searched in google and there were no entries for it so I assumed it was a virus or something. A scan with Avast indicates that it was a trojan and if I remove it or vault it, it just regenerates it self.

    What was I doing to cause this: Here are some things that may or may not have relevance to what caused the virus.

    I use Firefox most of the time, but I got the bright idea several weeks back, to install the Stumbleupon plugin for IE. I'm using IE 6.0.29. I love the plug-in and use it on my Mac at work with out worry. Of course, who'd a though IE would have security issues. rolleyes

    As mentioned earlier, I stopped using AVG since 8 came out, and I started using Avast. I have auto-updates off and system tray icon off but update every week and quick scan weekly.

    I started using some database/tracking software that uses PostgreSQL 8.3 shortly after getting rid of AVG. (possible vulnerabilities?)

    I started using MSN messenger after a long hiatus on the evening before.

    Several weeks ago I noticed that I would boot and Hardware Wizard would appear, saying "new hardware found" I would check for drivers and it wouldn't find any. It's listed as "Other Device/unknown device" in my device manager. I try to uninstall what ever it is, but I just comes back every restart. No new hardware was installed, however, I may have unplugged my hard drive at one point. I don't believe the hardware wizard message started until long after I had unplugged and replugged-in my hard drive.

    Aside from that, there are no new pieces of software that I've introduced to the system or no new sites I've been going on other than the stumbleupon oncs.

    Steps taken: I've gone through the Malware removal guide on this site.

    - Uninstalled all programs that are no longer used or unknown apps
    - Ran CCleaner + registry cleaner
    - My startup items had originally been set to very minimal
    - I didn't notice any maleware in add/remove programs but I did remove stumbleupon
    - Uninstalled all old SunJava versions and have yet to install the latest
    - Changed MSconfig to Normal startup mode, which, when I restarted, XP brought up a red X error about DAEMON Tools, which didn't appear in Add/remove, but I had installed previously and must have uninstalled. I deleted the folder from Program Files. I no longer get the error.
    - I ensured there were no quarantined files in Avast, (emptied chest)
    - Emptied recycle bin
    - There is only one user account in my XP

    - Enabled viewing of hidden files

    - Followed steps in XP cleaning procedure
    - Ran all applications as specified and seemed to work properly.

    Once I was done, I waited a bit to see of I still received the pop-ups, and sure enough, I did. I wasn't sure, if maybe I should have toggled restore right after I was done, because I wasn't sure if the issue was resolved.

    I've attached the logs.

    I attempted all of the steps on Thursday, and today (Saturday) I noticed that when I booted, that my resolution is now at 640x480 and I no longer have my usual resolution in my display options, which is something like 1610x1280 for widescreen.

    I have, and am still using old school Omega Drivers (3.8.421) for an ATI 9600 AIW, which had just replaced an ASUS 9600xt (got it for nothing and added some 3dmarks) about two weeks ago. I'm just about to reinstall them.

    My hardware setup is.

    XP SP2
    Asus board with Athlon XP 2500+
    1G of pc3200 memory
    1 80gb WD hard drive (OS + Applications)
    1 200gb Segate hard drive (all other files)
    ATI AIW 9600
    DVD-rw which the CDrom doesn't read or write (dvd is fine)
    Old cdrw
    500w sparkle PSU

    I'll post logs in a minute.

    Thanks for reading.
     
  2. Franix

    Franix Private E-2

    Logs
     

    Attached Files:

  3. Franix

    Franix Private E-2

    MGlogs
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKUS\S-1-5-21-1078081533-963894560-725345543-1007\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'postgres')
    O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe (file missing)
    O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe (file missing)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Franix

    Franix Private E-2

    Before I ran this, I launched Avast and the memory check found a virus running in the memory. It prompted to do a scan from boot, so I restarted, ran the scan from boot, it found the same virus running in the memory, I selected FIX, which was unsuccessful, so I selected, Delete. Which appeared successful.

    I then toggled Restore to delete any restore points. I then rebooted and the virus showed up in the memory scan again. I checked Restore, and it was enabled again. Not sure if it has any relevance.

    Everything (Delete Windows Messenger, HJT, ComboFix, Fixme.reg and Ccleaner) ran successful.

    I ran Ccleaner Cleaner and registry, hope that's what I was supposed to do.

    Once all was done, saw Avast shield hadn't started, so I launched it. It scanned memory and didn't seem to find anything in the memory. I checked the vault and the following are there. Not sure if I was supposed to delete these before trying the steps in this post. (I ensured it was empty for the SCAN / RUN as per the sticky)

    This is what is in the virus vault.

    1eevstbt.exe - system32
    jEE0S1BT.dll - system32
    jee0s1bt.dll - system32
    Tv224G0W.exe - temp

    My Avast doesn't appear in system tray now, but I'll reboot to see if that changes. It shows ON in avast settings. XP shows that I'm not protected against virus's and has been showing that since yesterday, I believe. Even if I update Avast and if the icon appears in the system tray, it still shows the little red shield in system tray as well.

    Need anymore info let me know. Also let me know if and when I should toggle restore again and if it should stay disabled.

    Thanks.
     

    Attached Files:

  6. Franix

    Franix Private E-2

    Seems to be running alright.

    I think we may have deleted some components of Avast, because, XP says "avast reports that it is turned off.

    I launch it and it seems to work properly.

    I ran a quick scan and it came up clean, but it doesn't seem the resident shield is on, for some reason.

    Not getting anymore popups, and seems to be performing normally.

    Should I delete the virus vault stuff?
    What should I do about Avast not appearing to be on?
    Should I toggle restore?
     
    Last edited: Aug 17, 2008
  7. Franix

    Franix Private E-2

    It doesn't appear to be fixed. I ran Malwarebytes again and it found a trojan once more.

    I got all my Windows updates after thinking I took care of this.

    I'm going through the READ/RUN and XP cleaning guide again.

    Is this what I should be doing?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As requested in the READ & RUN ME, once you begin our cleaning procedures, you must only do what we ask you to do and nothing else. Nothing else should be installed or uninstalled and no scans should be run unless we ask you to run them.

    We also did not ask you to do this. And this is a bad idea since no you have no fall back restore points if something went wrong during malware removal.

    No we have not touched anything related to Avast. That does not mean that the infection you had did not do something.


    Unless you attach a log. I cannot comment on what it found. We also did not ask you to run this again.

    No! You need to just follow our instructions and post the follow up logs we request and answer any questions we ask. And then you need to wait for us to respond. Posting multiple messages causes bumping and makes it take longer to get an answer. Info on this is posted in the forum sticky threads. See: Don't Bump! It Only Hurts You!!!


    Your logs show that you are clean. If your only remaining problem is with Avast then uninstall Avast, reboot (do not skip) then reinstall Avast.
     
    Last edited: Aug 18, 2008
  9. Franix

    Franix Private E-2

    Hi,

    You told me to tell you how things were running. It seemed everything was running fine so I proceeded to "No, I’m not having any problems" in the XP Cleaning procedure.

    Once I was done, I felt everything was fine, so I decided to run Malwarebytes, resulting in it finding the same virus.

    The Avast issue is taken care of but it seems I'm back to where I started with the Trojan. Should I start the READ ME / RUN ME guide once more?

    Any special steps I should take since I had done this already?

    I'll ensure to do nothing other than what you advise.

    Thanks again for the help.

    I await your response.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Update Malwarebytes to the new 1.25 version and run a new scan from it. Fix what it finds and attach the new log.

    Also run SUPERAntiSpyware and update first, then run a scan and fix what it finds. Attach a new log from it.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the new C:\MGlogs.zip file.
     
  11. Franix

    Franix Private E-2

    Thanks for the quick reply.

    Here's the logs.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of your logs (including Malwarebytes) are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. Franix

    Franix Private E-2

    That's great.

    I've decided to use BOClean for real time protection and Malwarebytes for scans.

    I'm still going to use Avast. I fixed the issue with it no appearing, by uninstalling and reinstalling.

    I did all the windows updates other than SP3. Some of the non critical ones were drivers, like chipset and video card drivers. Now my monitor won't go to 1650x1050, but I think that's a different thread. I should be able to fix it myself. ;)

    Thanks again for the help.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes that would be an issue for the Software or Hardware Forum. I would avoid hardware updates from Microsoft. Just get the Microsoft Windows and other Microsoft Software crititcal updates from them when available. Many people have run into issues with getting chipset downloads from Microsoft.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds