Apparent trojandowloader.XS, Adebot, PCSAntispyware etc.

Discussion in 'Malware Help (A Specialist Will Reply)' started by MarcellusF, Mar 31, 2008.

  1. MarcellusF

    MarcellusF Private E-2

    I'm a complete noob at this kind of stuff, so I'll quote someone else on this site who had exactly the same problem.

    "My machine appears to be infected with a spyware causing a number of different popups claiming System integrity Scan wizard and linking to a web site for PCantispyware, and also alerting me about a trogandownloader.XS [sic.] and again trying to get me to but a new virus scanner. Also a system warning abopout Adebot virus."

    I have scanned Spybot S&D, Avast, and windows Defender. And I have done a Hijack This scan and have saved the log. While it's not a vicious infection, it's starting to wear thin. Any help would be much appreciated folks. :)

    MarcellusF
     

    Attached Files:

  2. MarcellusF

    MarcellusF Private E-2

    Below are logs of the scans performed today as per instructions for Vista users.

    Thanks again for anyone taking the time. I'm gonna reboot and see what happens.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Uninstall the below old versions of software:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Java(TM) SE Runtime Environment 6

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [djqcaiaj] C:\ProgramData\djqcaiaj\ehadkzgz.exe
    O4 - HKCU\..\Run: [Z0lfa1XkUC] C:\ProgramData\apsxgnip\gxehspax.exe
    O4 - HKCU\..\Run: [tktmhwmk] C:\ProgramData\tktmhwmk\wfubkngp.exe
    O4 - HKLM\..\Policies\Explorer\Run: [Z0lfa1XkUC] C:\ProgramData\apsxgnip\gxehspax.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Users\Marcello\AppData\Local\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  4. MarcellusF

    MarcellusF Private E-2

    Thanks so much for getting back to me.

    I think I followed all your instructions to the letter.

    I've attached the two log files you asked for.

    So far the virus hasn't manifested itself again, but I'll keep monitoring it -- it's only been 30 minutes since I started the process.

    I'll let you know should things start to happen again.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run GetLogs.bat again and make sure you allow it to finish running. Your last MGlogs.zip file was incomplete which normally means you stopped the program from running before it was finished. When you run GetLogs.bat, right click it and select Run As Administrator.


    Attach a new MGlogs.zip file.
     
  6. MarcellusF

    MarcellusF Private E-2

    Oops.

    I ran it as administrator even though I was sure I'd done it that way before -- though I may be hallucinating.

    Update: Everything is runnning fine. The virus/malware/whatever hasn't appeared since I carried out your instructions the other day, which is mint-tox ('80 Aussie slang for "wicked", "awesome", "great", "jolly-good", you get the idea...)

    Thanks again for your time.

    Please find attached the log you requested.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is still not running properly for some reason. I really want to see the logs to make sure everything was removed and is not just waiting to popup again. Are you sure that you are not getting any error messages like those mentioned on the Using MGtools download page? Is UAC still disabled? When it has run properly the size of MGlogs.zip should be more like what you attached in message # 2 which was 66.8 KB in size. The last two were only 14.2 and 13.4 KB.

    You could also try doing the below:

    • run C:\MGtools\GetRunKey.bat by double clicking on it (what happens? Any error message? )
    • run C:\MGtools\Shownew.bat by double clicking on it (what happens? Any error message? )
    • if both of the above ran with no errors, check the size of the C:\MGlogs.zip file and if it is larger than the previous 13.4 KB, attach the log since the new logs from the above two programs may have been added.
    I'm happy to hear you are not having any problems but still wish get proper logs.
     
  8. MarcellusF

    MarcellusF Private E-2

    I've attached a copy of two messages that came up when I ran GetRunKey.bat, and the following came up when I ran Shownew.bat

    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    ** GetRunKey.bat does not exist ** You must follow directions on the download
    page for GetRunKey! All files must be extracted from the GetRunKey.zip file.
    Do not run GetRunKey.bat from inside the ZIP file.

    ** grep.exe does not exist ** You must follow directions on the download
    for GetRunKey! All files must be extracted from the GetRunKey.zip file.
    Do not run GetRunKey.bat from inside the ZIP file.

    ** ltime.exe does not exist ** You must follow directions on the download
    for GetRunKey! All files must be extracted from the GetRunKey.zip file.
    Do not run GetRunKey.bat from inside the ZIP file.

    GetRunKey.bat failed to execute because it was not installed and run as
    instructed. Also check possible error messages and fixes on the download
    page for GetRunKey. GetRunKey will terminate now!


    Looks like I may have stuffed up?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not quite sure what is causing this problem. Is UAC still disabled?


    Try the below different methods:
    • click Start, Run, and enter cmd and click OK. This will open a command prompt window. In the command prompt window enter the below commands and hit the enter key after each. There is a space after the cd
      • cd C:\MGtools
      • getrunkey.bat
    • What happens with the above?
    • Now if the above did not run properly continue with the below.
    • Goto to this link Using MGtools and download the current version of MGtools.exe to your C:\ root folder. Follow the instructions for Vista users.
    • Attach the new MGlogs.zip file
     
  10. MarcellusF

    MarcellusF Private E-2

    Now I think it ran properly. UAC was definitely off this time.

    I've attached the runkey.bat log as well as the text that was displayed whiloe getrunkey.bat was running. Anything else you need?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Now that you have UAC disabled (or at least know how to disable it - and don't forget that a reboot is necessary after disabling it), I now need the full MGlogs.zip file create bey doing the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created
     
  12. MarcellusF

    MarcellusF Private E-2

    Ok here's the MGlogs.zip. :)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah! That's better. ;) Now I can say this. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    2. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds