Trojaned? Not sure, so . . .

Discussion in 'Malware Help (A Specialist Will Reply)' started by FTWchamp, Jun 21, 2007.

  1. FTWchamp

    FTWchamp Private E-2

    A little bit ago, while my computer was idling, AVG Free Edition, alerted me to a potential threat, a trojan. I opted for heal, which it did successfully. The same warning showed up again, to which I also chose heal. I ran a scan afterward in which AVG claimed there were no threats found. However, C:\\WINDOWS\system32\kernel32.dll is listed as changed.

    I looked back at previous scans and found on 6.19 that previous change, some files from the World of Warcraft downloader and background downloader were deleted, and two files in the C:\System Volume Information\_restore followed by a long list of numbers were also deleted. The details under those listings show Trojan horse PSW.Generic4.TUV listed as infected, with deleted directly under it.

    The last AVG scan I did claimed no threats. Ad-Aware had an update and found nothing. Spybot Search&Destroy had a number of updates and then found nothing on scan.

    I run all of those scans every Tuesday and sometimes throughout the week as well. I've not done anything unusual on my machine, played WoW, checked e-mail, viewed the same sites I always do. So what can I do next to know if I am clean or not? If not, where did this come from and what do I do to get rid of it? I'm not sure if I need to follow the malware guide or not, so any advice is appreciated. I suspect I'll go ahead with those steps so I have the logs ready. :(
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. FTWchamp

    FTWchamp Private E-2

    Seems there is not a current fix for this. Should I switch virus scanners? At least this explains why AVG suddenly noticed a threat when I had not even been actively at my computer much since my last scan. So this could be the entire deal, yet . . .

    I'm still a bit concerned and curious though, as mIRC continues to refuse my connection to that chat system. Is this an effect of this situation? Would a resolution from AVG or Blizzard solve that connection issue, if that be the problem? I ran the other scans, so I can post logs if necessary.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have the latest AVG definitions that just came out? Make sure. If you still have a problem, discuss it with the WoW site. This is not really a malware problem. It is a false detection. You can either delete the files that it has a problem with (and toggle system restore to remove those detected restore points) or you can use a different antivirus.

    I have no idea but I doubt any of this is related nor does it sound like malware. If you have run all of the READ & RUN ME, you can attach the 6 requested logs and we will look at them to see if there is any malware.
     
    Last edited: Jun 22, 2007
  5. FTWchamp

    FTWchamp Private E-2

    I think you are right Chaslang, but I would like to make sure. So I attached the logs. Thanks in advance. If you could walk me through what files I need to delete and the system restore that would be appreciated. I get paranoid when dealing with this stuff.
     

    Attached Files:

  6. FTWchamp

    FTWchamp Private E-2

    Here are the attachments.
     

    Attached Files:

  7. FTWchamp

    FTWchamp Private E-2

    Last log from CounterSpy. I don't like this one because I've no idea where these results came from. :/
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. You just have a few house cleaning & updates to do.


    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (1.5.0.12)
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!
     
  9. FTWchamp

    FTWchamp Private E-2

    Thanks Chaslang. I'm having trouble deleting the version of Mozilla Firefox you listed. Add/Remove programs doesn't remove it, the hourglass spins a bit and stops, then the list of programs is just there, including Firefox. Even the uninstall from the folder does literally nothing. How do I get rid of it then? Should I manually delete the folder?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does 1.5.0.12 still show in Add/Remove Programs. If so, try using this to uninstall it: Your Uninstaller! 2006 If that does not work, just install the new version and continue.
     
  11. FTWchamp

    FTWchamp Private E-2

    Yes the Mozilla entry still showed in Add/Remove Programs. The Your Uninstaller 2006! could not remove it either. So I installed the Sun Java Runtime Environment and Mozilla Firefox versions you listed and rebooted. The initial listing Mozilla Firefox (1.5.0.12) is still there in Add/Remove Programs along with the new version.

    I also ran HJT per your instructions and only found one of your entries to fix:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) -- was there and fixed.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = -- there was only one HKCU entry and it did not match these, so I left it as is.

    R3 - Default URLSearchHook is missing -- no R3 listing at all.

    So do I go on and reset browser settings now or is there something else I need to do?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the below and attach the log:

    Getting Uninstall Programs List From The Registry


    Yes reset web settings now and you are finished other that getting me the above log so we can remove the old Firefox entry.
     
  13. FTWchamp

    FTWchamp Private E-2

    Here is the GetUnKey log.
     

    Attached Files:

  14. FTWchamp

    FTWchamp Private E-2

    In following the Reset Web Settings instructions, I found there is no "Reset Web Settings" option under the Programs tab. I followed the rest of the instructions.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you read the Note for IE7 users?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the below should remove the old version from Add/Remove Programs.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  17. FTWchamp

    FTWchamp Private E-2

    Sorry about the IE7 note, missed that, so I did that now and the registry instructions you posted. Is there anything else I need do? Thanks again for all of your help and patience Chaslang. :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Just the below. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    2. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    3. After doing the above, you should work thru the below link:
     
  19. FTWchamp

    FTWchamp Private E-2

    So hopefully my last questions:

    There are still 8 files listed as infected with Trojan horse PSW.Generic4.TUV (the false positive) in AVG virus vault, listed here:

    C:\Program Files\World of Warcraft\BackgroundDownloader.exe
    C:\Program Files\World of Warcraft\WoW-2.0.12.6456-to-2.1.0.6692-enUS-downloader.exe
    C:\Program Files\World of Warcraft\WoW-2.1.0.6692-to-2.1.0.6729-enUS-downloader.exe
    C:\Program Files\World of Warcraft\WoW-2.1.0.6729-to-2.1.1.6739-enUS-downloader.exe
    C:\System Volume Information\_restore{CBFB9CC5-9963-4FB0-B691-F0E82EF6F198}\RP207\A0049157.exe
    C:\System Volume Information\_restore{CBFB9CC5-9963-4FB0-B691-F0E82EF6F198}\RP209\A0050089.exe
    C:\System Volume Information\_restore{CBFB9CC5-9963-4FB0-B691-F0E82EF6F198}\RP215\A0051712.exe
    C:\System Volume Information\_restore{CBFB9CC5-9963-4FB0-B691-F0E82EF6F198}\RP215\A0051714.exe

    What should I do with these listings? They are all listed as backup copies, so can I empty the vault which I assume deletes the files and empties the quarantine?

    Also, AVG still has C:\WINDOWS\system32\kernel32.dll listed as Change and Changed on a scan. It is not considered a threat. I know there is a way to not list the changes in AVG, just can't find that option.

    Thanks again, hopefully my machine is about back to the original state it was in before all of this.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you flush System Restore as was mentioned two times already (msgs # 4 & 18)? That is what the last five files are from.

    The other 4 are the same as you started with. Either delete or stop playing WoW or ignore the messages if you trust these files relate to it.

    The kernel32.dll being change is not a problem. The last time the file was truly changed was
    Code:
    kernel32.dll  Apr 16 2007      984576  "kernel32.dll
    according to your ShowNew log.
     
  21. FTWchamp

    FTWchamp Private E-2

    Yes I did the system restore. Those listings were already in the AVG virus vault. I just wanted to know if I should delete them. Thanks for your help.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! Yes delete them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds