Antispyware-reviews etc.

Discussion in 'Malware Help (A Specialist Will Reply)' started by David Lewis, Mar 30, 2008.

  1. David Lewis

    David Lewis Private E-2

    I've tried everything from a multiple-step process for removing malware from my computer (Windows Vista operating system), but the two versions (red and blue) of the Security System Protection Control Panel keep popping up. One says I have Abebot, the other says I have TrojanDownloader.XS; each directs me to a website, http://antispyware-reviews/biz/?wmid=(etc.), which tries to sell me software to fix. There is also a version that tries to get me to install PC-Fixit or some other program. The malware has also attached itself to the yellow triangle "click here to fix problem" icon.

    The steps include downloading 4 tools, disabling UAC, installing tools and running scans.

    Attached are the following logs created per the above:

    -SASlog.txt
    -Malawarebytes Anti-Malware log
    -MGLogs.zip

    What should I try now? Thx.

    David
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks David!

    Your forgot to acually attach your logs. ;)
     
  3. David Lewis

    David Lewis Private E-2

    My mistake - thought I had attached the three items - let's try again.

    David
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below software as requested in step 1 of the READ ME:
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Now run this: Norton Removal Tool (SymNRT)

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [NOD32_Registration] c:\powrspec\nod32\registration\Register NOD32.exe
    O4 - HKLM\..\Run: [ASM] "C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe" HIDEMAIN
    O4 - HKCU\..\Run: [errtakgn] C:\ProgramData\errtakgn\hyxebyto.exe
    O4 - HKCU\..\Run: [0oBSolc2Go] C:\ProgramData\hytypyha\bohynkzq.exe
    O4 - HKLM\..\Policies\Explorer\Run: [0oBSolc2Go] C:\ProgramData\hytypyha\bohynkzq.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  5. David Lewis

    David Lewis Private E-2

    Thanks for your help. It is probable that Viewpoint Media Player was the culprit, although without it there are a few noncritical things that I cannot do with AOL. Whatever, the worm/trojan has been gone for the past couple hours!

    Here are the two logs in question.

    Is there any dowloaded software and/or reports that I should now delete?

    Thanks again.

    David
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that you missed a couple items and also Viewpoint did not completely uninstall. Let's try again.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Viewpoint Manager Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [NOD32_Registration] c:\powrspec\nod32\registration\Register NOD32.exe
    O4 - HKCU\..\Run: [errtakgn] C:\ProgramData\errtakgn\hyxebyto.exe

    After clicking Fix, exit HJT.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  7. David Lewis

    David Lewis Private E-2

    OK, have proceeded as recommended. Had not been having any problems with worms/trojans since the last fix, but of course it is best to be completely safe.

    I have MGtools.exe rather than \analyse and/or \GetLogs so used it, having to use as administrator.

    Log attached.

    David
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The fixes are not working properly. It is possible that either or both McAfee and Windows Defender are getting in the way. Let's run another tool. Be sure to read all the instructions and follow the steps properly.

    Run this Running ComboFix and then attach the requested log from ComboFix.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds