Norton spoof resulted in constant spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by thai_american_42, Dec 27, 2010.

  1. thai_american_42

    thai_american_42 Corporal

    Well, here I am again. A person, who shall remain nameless, saw a popup saying something like "OH MY GOD! YOUR COMPUTER NOW IS BEING INFECTED BY MALWARE AND SPYWARE. CLICK HERE IMMEDIATELTY TO FIX! LOVE, NORTON." They click, just like before (see my May 23, 2009 thread: http://forums.majorgeeks.com/showthread.php?t=190352), and I'm again working to fix.

    Current question: How much longer should I give MGTools to finish?
    I'm going through the READ & RUN ME FIRST. Malware Removal Guide. I'm running MGtools. For the past few hours, MGTools has been stuck on "Running processdll.exe to find loaded DLLs". How much longer should I give MGTools to finish?
     
    Last edited: Dec 27, 2010
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then refer to error message type 4
     
  3. thai_american_42

    thai_american_42 Corporal

    I'm not receiving any MGTools error messages. As for .NET, not only do I have it installed, I have:

    Microsoft .NET Framework (English) v1.0.3705
    Microsoft .NET Framework 1.0 Hotfix (KB928367)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1

    installed. I don't know whether I need all those. Also, it looks like .NET Framework 4 is out. Would it help MGTools if I delete any of these .NET files?
     
    Last edited: Dec 27, 2010
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Stop MGTools from running. Rename it to magpie.com and see if it runs properly then and creates a C:\MGlogs.zip
     
  5. thai_american_42

    thai_american_42 Corporal

    I attached the logs I have so far. RootRepeal error was "Eorror-Invalid PE image found!" and RootRepeal got stuck on my G:/FlipShare Data/previews/, so I only ran RootRepeal on the C: directory.

    I renamed MGTools to magpie.exe and ran again. Sorry, I now remember that I did get errors the last time I ran MG Tools. The error I got then (and now got running magpie.exe) is:


    ProcessDll.exe - Common Language Runtime Debugging Services
    Application has generated an exception that could not be handled
    Process id=0x12ac (4780), Thread id=0x17a8 (6056)
    Click OK to terminate the application.
    click CANCEL to debug the application.

    Should I click OK or CANCEL?
     

    Attached Files:

    Last edited: Dec 27, 2010
  6. thai_american_42

    thai_american_42 Corporal

    Another person had a similar problem. Per chaslang 03-09-08, 22:47 "What should I do next? Just attach the 3 requested logs. MGlogs.zip will sill exist even if Processdll.exe did not run properly."
    (See http://forums.majorgeeks.com/archive/index.php/t-153822.html)

    Here is what I now have for MGlogs.zip.

    P.S. I Uninstall ALL old Sun Java versions, but missed the instruction part about get updated. I don't have any java version installed at the moment. Also, when we're done, I was thinking of reinstalling my Norton becuase my Add/Remove list showed it installed on December 26, 2010, the date this problem started. I installed Norton 360 v 4.0 well before that date, so I figure the bugs did something to Norton.

    I renamed MGTools to magpie.exe and ran again. Sorry, I now remember that I did get errors the last time I ran MG Tools. The error I got then (and now got running magpie.exe) is:


    ProcessDll.exe - Common Language Runtime Debugging Services
    Application has generated an exception that could not be handled
    Process id=0x12ac (4780), Thread id=0x17a8 (6056)
    Click OK to terminate the application.
    click CANCEL to debug the application.

    Should I click OK or CANCEL?
     

    Attached Files:

    Last edited: Dec 27, 2010
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well I have studied those logs and I am not seeing any malware.

    No don't bother. Those dates in add/remove programs are not always accurate.

    Let's just do this to tidy up from some dead BHO's.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - AutorunsDisabled - (no file)
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
    • O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - (no file)

    After clicking Fix exit HJT.

    What problems remain?
     
  8. thai_american_42

    thai_american_42 Corporal

    Hi Kestrel13!

    I acted before I saw your above 17:25 message:

    1. I removed, and then reinstalled Norton 360 v. 4.0
    2. I then installed the latest version of Sun Java
    3. I then ran F-Secure (free online scanner) detailed scan and went out for a few hours. F-Secure found:

    Gen.Trojan.Heur.Lp - SPYWARE (Gen:Trojan.Heur.LP) was found in: system
    CATONLINEW2K.DLL - Malware (Gen.Trojan.Heur.LP.ymTfaSaqBBI) was found in: C:\WINDOWS\DPWNLOADED PROG RAM FILES\CATONLINEW3K.DLL

    4. F-Secure was able to clean Gen.Trojan.Heur.Lp
    5. F-Secure was NOT able to clean CATONLINEW2K.DLL

    Then I saw your 17:25 message above and

    6. I exited all browser sessions including the one I was reading in right now:
    7. I then disable Norton 360.
    8. I then ran C:\MGtools\analyse.exe by double clicking on it.
    9. I then selected Scan
    9A. NOTE: The option "Do a system scan only" was not presented to me
    10. I then selected the following lines:

    * O2 - BHO: (no name) - AutorunsDisabled - (no file)
    * O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    * O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - (no file)

    10A. NOTE: O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file) was not present after the scan.
    11. I then selected "Fix Checked" to fix the 3 selected items. The screen within the Trend Micro Hijackthis frame went completely white.
    12. I then ran "Scan again"
    13. The following file was not deleted: O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - (no file)
    14. I selected it, selected Fix Checked, and the screen within the Trend Micro Hijackthis frame went completely white.
    15. I exited HJT
    16. I re-enable Norton 360.
    17. I attached the fsonlinescanner_report2010-12-27.html to this message

    What problems remain?
    1. CATONLINEW2K.DLL - Malware
    2. MGtools could not fix: O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - (no file)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most likely not a problem at all. Do you use Ameriatrade? This DLL is for Confidence Online Portal Edition for Ameritrade
     
  10. thai_american_42

    thai_american_42 Corporal

    Ameritrade was installed a while ago but I don't really use it anymore. As for the last issue, should I be concerned about not being able to delete O18 - Protocol: symres?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is part of Norton.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Only reason I included it in the fix was the fact it was a (no file) - a dead BHO.
     
  13. thai_american_42

    thai_american_42 Corporal

    I ran through the final steps. Thanks Kestrel13! and chaslang for all your help.
     
  14. thai_american_42

    thai_american_42 Corporal

    OK, here I am again. :banghead This same person was using my computer today and clicked on a link that brought up the banner message "Caution! Your computer contains a variety of suspicious programs. Your System requires immediate checking! The system will perform a fast and free check your PC for malicious programs. OK. Cancel." (see attached)

    After seeming me spend two days cleaning up the prior mess (see first post in this thread), the person selected Start, Turn Off Computer instead of selecting OK in response to the banner. Several terminate program options appeared and the shut down took much longer than normal.

    I ran a quick scan via F-Secure and there were no issues. Is there any easy way for me to tell whether spyware or malware was installed on my computer? (I really don't want to spend another two days going through the READ & RUN ME FIRST. Malware Removal Guide.) Thanks.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not in any certainty without running the full cleaning process. Try running scans with both SUPERAntiSpyware and Malwarebytes which we recommended keeping and see if they find anything. Also see if any problems are occurring. If you are still having malware problems, you need to complete the other scans and attach all logs. Since it is such a short time frame, you can attach them here in this thread. But after another week or more, you would have to start a new thread.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds