Anyone been successful removing Virtual Bouncer spyware yet?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BluesMan, Aug 6, 2004.

  1. BluesMan

    BluesMan Sgt. Snot Bubble

    Tried adaware and it finds it, deletes it, but it keeps popping back up in the registry as soon as the computer reboots. I have found some info (googling) that tells you what registry entries to delete manually. I have deleted these entries numerous times but the "vurl" "durl" "curl" entries keep coming back under Local machine\microsoft\....\cryptography\..

    Computer is WinXP pro with all updates and patches. Its running NortonAntivirus, which does not find anything after scanning all the files on the box.

    Any help is greatly appreciated.


    Thanks :D
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  3. BluesMan

    BluesMan Sgt. Snot Bubble

    Thanks Tim. Will give it a shot tonight when I get home.
     
  4. BluesMan

    BluesMan Sgt. Snot Bubble

    Well, no dice. Completed all steps fromthe PestPatrol website. Scanned with adaware and was all clean. Rebooted and now its back again. Sounds like I may need to try another tool. What;s the next logical step when Adaware doesn't work? HiJackThis? :confused:
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hijack This would show us what is running and might give us some insight. Heck, you might find the problem yourself. Im assuming something is running at startup, so run Hijack This through the tutorial and get back to us with a log if needed.


    P.S Symantec gives different steps, including uninstalling Virtual Bouncer from add\remove programs, I asusme you did this?
     
    Last edited: Aug 6, 2004
  6. BluesMan

    BluesMan Sgt. Snot Bubble

    I see a few things im not sure of. Maybe you can point out some things that you think are wrong. Will check back in a bit, gotta get my oldest to sleep LOL. He's not cooperating very well tonight.
     

    Attached Files:

    Last edited by a moderator: Aug 6, 2004
  7. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Heres some pointers, stuff to remove, etc:

    Have not seen C:\WINDOWS\goidr.exe before, looks like a trojan:
    http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=126656

    C:\WINDOWS\System32\nvsvc32.exe
    Go to your control panel, administrative tools, services and disable Nvidia driver helper service. That ends that one :)

    Remove:
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

    Woops, heres the problem:
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL
    Theres a folder there, you might want to try and delete the folder from safe mode, delete these lines in Hijack This and verify add\remove programs as well as not in startup.

    Trojan again, same as first mention:
    O4 - HKLM\..\Run: [goidr] C:\WINDOWS\goidr.exe




    UNSURE, hopefully Chaslang or someone recognizes them. Searched, found nothing either:
    O4 - HKLM\..\Run: [hxdebc] C:\WINDOWS\System32\hxdebc.exe
    O4 - HKLM\..\Run: [izonax] C:\WINDOWS\izonax.exe
    O4 - HKLM\..\Run: [aqadcup] C:\WINDOWS\aqadcup.exe
    O2 - BHO: SDWin32 Class - {78F8226C-86D7-4892-9CBE-3B584AE70A16} - C:\WINDOWS\System32\hxdeb.dll
    O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe


     
    Last edited: Aug 6, 2004
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You found them all Major! I agree. Even the ones you said "Unsure" have to go. One of them (C:\WINDOWS\aqadcup.exe )
    is on PestPatrol's unknow trojan list.

    The omniscient.exe file is a Search Assistant. See:
    http://www.pestpatrol.com/PestInfo/s/search_assistant.asp

    BluesMan,
    You had more than VirtualBouncer problems. I'm sure you will have no problem following the PestPatrol info for omniscient.exe removal. But before beginning to remove any of these first check Add/Remove programs. The MyWay Search Assistant stuff may be removable from there and so might be WindowsSA.
    If not, do it manually.

    Kill all the EXE processes from Task Manager (if found):
    goidr.exe
    hxdebc.exe
    izonax.exe
    aqadcup.exe
    omniscient.exe

    Then you should try to unregister MYSRCHAS.DLL and hxdeb.dll first (using regsvr32 /u dllfilename) from the run dialog box.

    Now fix all the recommend lines with HijackThis (first select the lines then exit all browser sessions before fixing).

    After that reboot to safe mode and delete:
    C:\Program Files\MyWay\SrchAstt <--- the whole directory in Add/Remove did not do it
    C:\WINDOWS\goidr.exe
    C:\WINDOWS\System32\hxdebc.exe
    C:\WINDOWS\izonax.exe
    C:\WINDOWS\aqadcup.exe
    C:\WINDOWS\System32\hxdeb.dll
    C:\Program Files\WindowsSA <--- the whole directory in Add/Remove did not do it

    Now reboot in normal mode. If still having Virtual Bounce problems, try this:
    • step 1: Remove these registry items (if present) with RegEdit:

      HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services\durl

    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\virtual bouncer​

    • step 2: Remove this file (if present) with Windows Explorer from your profile path:

      start menu\programs\startup\virtual bouncer.lnk
    • step 3: Remove this directory (if present) with Windows Explorer from your profile path:


      \start menu\programs\virtual bouncer
    Let us know how this all works out. If still having a problem, tell us and give us a new HJT log attachment.
     
    Last edited: Aug 7, 2004
  9. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Cool, do I like get a cookie or something?! Log files are tough to analyze for sure because these parasites are getting trickier. Finding theres a new variant to this didnt make me too happy either, just means more, random filenames. Let us know Bluesman.
     
  10. BluesMan

    BluesMan Sgt. Snot Bubble

    Thanks fellas. Chaslang, great info and MUCH APPRECIATED :D.

    Have to add some though, found more stuff while poking around. I wanna list them here incase someone runs into the same problem.

    HXDEBC.exe - was in c:\windows\system32 like you said but I noticed it had more files then just the .dll and .exe. There were also:
    hxdeba.xml
    hxdebb.xml
    hxdebc.exe
    hxdebd.exe
    hxdebe.eml
    hxdebf - application

    And one other note. When looking for HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services\durl
    there are also
    HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services\curl
    HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services\vurl
    HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services\rurl

    For whatever reason, the curl-vurl-rurl entries show up as well as the durl.

    Anyway, again many thanks for the help. Its been a while since I've had a bad instance of spyware such as this. My neighbor will be very happy. :D
     
  11. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    FYI, Hijack This was updated minutes ago, everyone using it, get a new copy.
     
  12. BluesMan

    BluesMan Sgt. Snot Bubble

    Thanks , I'll nab a copy for my box. Im done working on hers.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BluesMan,

    Did we get everything fixed?
    And thanks for feeding back the additional info on the other items you found.

    Major,
    Yeah! I got a big fat chocolate chip cookie waiting for you. ;) You just have to ride down here and get it. :p
     
    Last edited: Aug 7, 2004
  14. BluesMan

    BluesMan Sgt. Snot Bubble

    As far as I know everything is good. If I get a chance, I'll run the new HJThis on her machine again and see if it finds anything. I left it on for over an hour yesterday and no popups and it was surfing like a champ. Got a big show today and have to get back on the home remodling thing tonight...not enough hours in the day anymore LOL.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds