Collected.5.L trojan, elitebar, spymonkey,etc.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by computermom, Sep 28, 2005.

  1. computermom

    computermom Private E-2

    Hi. I am trying to clean up viruses and spyware on a Sony Vaio running Windows XP Home SP2 (240 gh pentium 4, 512 mb memory, 80 gig hard drive). I have run Bitdefender, RAV, Avert Stinger, Ad Aware (and the VX2 plugin), Spybot, HS remove, A-squared, AVG Antivirus, Trend Micro Housecalls, CCleaner, CW Shredder, HS Remove, Panda activescan, ewido, trojan hunter, and bazooka. I've run most of these products at least twice. Unfortunately, I still am having problems with errors that seem to be related to Collected.5.L, Elitebar, and spymonkey (Earthlink TotalAccess is being used on this machine)...there may be some others.

    I think it is time to have someone help out with a HJT log. I've downloaded the program into a folder in Program Files, so I'm ready to go. I did attempt to copy a HTJ log to htj.iamnotageek.com auto analizer, but I get an error message.

    I think I've done everything I can possibly do from this end. Can someone help out!

    Thanks!

    Karen
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    Download and run the following:

    EliteToolbar Remover


    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program

    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. computermom

    computermom Private E-2

    Thanks for the info. I ran the elite toolbar remover and the hoster programs. I am attaching my HJT log. The other problem was surfmonkey (sorry...I typed spymonkey). I understand that it may have been installed with Earthlink TotalAccess. Do you see any other problems in this log. This computer was pretty well run over by viruses, trojans, worms, etc!

    Let me know where to go next.

    Thanks.
    Karen
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are running multiple antivirus applications (AVG7 and Symantec) but you must only run one. Choose the one you prefer and uninstall the other. Do that now before continuing and while I look at your HJT log.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way SurfMonkey is considered adware by most people and you are right it came with EarthLink. It is probably something you do not want anyway unless you are forcing it on your kids. What you wish to do with it is upto you. It can be uninstalled using Add/Remove programs. See:

    http://www.cexx.org/surfmonk.htm
    http://www.earthlink.net/about/press/pr_surfmonkey/

    Also you have the below running from Sony Vaio:
    O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs

    Check out what the below states and decide if you want or need this:
    http://castlecops.com/startuplist-4638.html


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKLM\..\Run: [MediaXPServicePack] mxpsp.exe
    O4 - HKLM\..\Run: [Media-XP-Service-Pack3] msnzx.exe
    O4 - HKLM\..\RunServices: [MediaXPServicePack] mxpsp.exe
    O4 - HKLM\..\RunServices: [Media-XP-Service-Pack3] msnzx.exe
    O4 - HKCU\..\Run: [MediaXPServicePack] mxpsp.exe
    O4 - HKCU\..\Run: [Media-XP-Service-Pack3] msnzx.exe
    O4 - HKCU\..\RunServices: [MediaXPServicePack] mxpsp.exe
    O4 - HKCU\..\RunServices: [Media-XP-Service-Pack3] msnzx.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\system32\mxpsp.exe
    c:\windows\system32\msnzx.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. computermom

    computermom Private E-2

    Chaslang:

    Thanks! Things are running much quicker now.

    A few notes:
    I was unable to find mxpsp.exe and msnzx.exe in the system32 folder. I ran a search for them, but still couldn't see them. They are not running in my task manager either.

    I have checked the Add/Remove programs list for Surf Monkey, but it doesn't appear.

    Attached is my latest HJT log. Let me know if you think there is anything else I need to fix or if I look good!

    Thanks again.

    Karen
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What did you decide about:

    O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs


    Do you use or do you want Surfmonkey?
     
  8. computermom

    computermom Private E-2

    Let's get rid of them both...they're not used!

    What do I need to do?

    Karen
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we will stop them from loading but we will not delete the files. Just incase later you decide you need them. You can always restore the registry entries we delete using HJT's backup/restore capability. (one reason we insist on it being installed properly)

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\surfmonkey\smproxy.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
    O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
    After clicking Fix, exit HJT.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  10. computermom

    computermom Private E-2

    Everything seems to be working great now.

    Here's my latest HJT Log. Do you think I'm set?

    Thanks for all your help!

    Karen
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Hmmm? I still see this running: C:\WINDOWS\surfmonkey\SMProxy.exe
    But I do not see anything loading it.
    Reboot your PC and let me know if this process still shows up in your HJT log.
     
  12. computermom

    computermom Private E-2

    Don't know why it was there before. Seems to be gone now. Here's the latest. Everything good?

    Have a great weekend! Hope the weather is as beautiful there as it is here.
    Karen
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I still see the below. Did you forget to fix it or did you run HSremove again? You do not need to use HSremove for the problems you were having.


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    Fix it again using HJT.

    Weather here is great yesterday & today?

    How is the pottery factory down there (I don't remember the name)? Is that place still in business?
     
  14. computermom

    computermom Private E-2

    The pottery place is called "The Williamsburg Pottery" (or "The Pottery" to locals). It's still around! Williamsburg has really grown a lot in the two years we've been here. Not so much of a small town anymore.

    Anyway, I don't know how the HSRemove line got there. I'm 99% sure I checked it for removal, and I didn't run the program again.

    I think it is gone now...here's my log.

    Hopefully we're finally there!

    Karen
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now you are all clean! It's time to work thru the steps in the below link to help keep you clean. You must get a real firewall installed and then disable the one in WinXP SP2 which does not provide adequate protection. A list of firewalls is in the below link too.

    How to Protect yourself from malware!
     
  16. computermom

    computermom Private E-2

    Glad it's all cleaned up. Thanks again for all your help!

    Karen
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds