EliteBar and possibly others...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Brent H, Jul 31, 2006.

  1. Brent H

    Brent H Private E-2

    I made the mistake of letting my guard down over this one file, and now all hell has broken loose.:rolleyes:

    I believe I have managed to remove most of the malware and other crap via SpySweeper, Ad-Aware, SpyBot and Norton, but there's still some things I need help with...

    Attached is my HJT log.

    Thank you for your kindness, it's much appreciated.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also did you knowingly install SpyHunter? It is not a recommended application due to its history of being a rogue and its poor performance.
     
  4. Brent H

    Brent H Private E-2

    No, SpyHunter and SpyQuake were put on there by whatever hellacious .exe I ran to cause all this.

    I followed all the steps... With one minor problem. The BitDefender log saved as an HTML file with a .txt extension (so all the HTML is still there), and there's a few "clean" entries in there as well for some reason; I'm pretty sure it might be a result of running things in safe mode, but there may have been other causes.

    That log file is 1 meg in size :eek: so I'm going to link it if you really want to see it.

    Aside from that, everything went smoothly. Here are the logs:

    bdscan.txt / bdscan.html
     

    Attached Files:

  5. Brent H

    Brent H Private E-2

    Just a sidenote; when viewing my bdscan logs, I notice that there's quite a few being found in the Norton quarantine folders... I know I emptied the quarantines beforehand though so could this be from the continual barrage of crap that Norton kept fighting after I cleared everything?

    Thank you for your help, I appreciate it greatly.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is exactly what we request in the READ ME. You were just suppose to change the filename to have a .txt extension so it could be uploaded here to MGs! You should not have changed the scanning options. That and the Quarantine folder that was not emptied is why it is so large.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. Brent H

    Brent H Private E-2

    Here you go :)
     

    Attached Files:

  9. Brent H

    Brent H Private E-2

    After starting up this morning, I'm still experiencing major slowdown and Norton is warning me about a "Downloader" Trojan which it says it can't access to delete.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry.....we will get it fixed. You have a bunch of bad stuff we need to work on!

    Let's begin!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now reboot and then attach a new GetRunKeys log (runkeys.txt) and also a new HJT log.
     
  11. Brent H

    Brent H Private E-2

    Here are the new logs! ;)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay as I expected, some items went away and some came back. Also some new stuff showed up. I have to run off for a little while. I will post a fix when I come back but in the mean time please get me the below log.

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay ignore my last request for the uninstall list from HijackThis for now. We may not need it. Let's just try to fix what we see thus far.


    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of gebxu.dll once and then click the kill button. After you have killed all of the gebxu.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    vtusqop.dll
    wintxr32.dll

    Next double click on explorer.exe and again click once on each instance of gebxu.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    vtusqop.dll
    wintxr32.dll

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\ishost.exe
    C:\WINDOWS\system32\ismon.exe
    C:\WINDOWS\DOBE~1\ati2evxx.exe
    C:\Documents and Settings\Brent Hegnauer\Application Data\s?stem32\m?config.exe


    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {887FC6F1-440E-423E-8BB2-25201F35A735} - C:\WINDOWS\system32\gebxu.dll
    O2 - BHO: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
    O2 - BHO: (no name) - {E521797A-22DE-4B46-8B2F-8E98AB77B942} - C:\WINDOWS\system32\vtusqop.dll
    O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
    O4 - HKCU\..\Run: [Mwoe] "C:\WINDOWS\DOBE~1\ati2evxx.exe" -vt yazr
    O4 - HKCU\..\Run: [Pkpz] C:\Documents and Settings\Brent Hegnauer\Application Data\s?stem32\m?config.exe
    O20 - Winlogon Notify: gebxu - C:\WINDOWS\system32\gebxu.dll
    O20 - Winlogon Notify: vtusqop - C:\WINDOWS\SYSTEM32\vtusqop.dll
    O20 - Winlogon Notify: wintxr32 - C:\WINDOWS\SYSTEM32\wintxr32.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit

    You may get an error about the above not existing. Just ignore and continue.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    c:\windows\downloaded program files\gdnUS2339.exe
    C:\WINDOWS\system32\gebxu.dll
    C:\WINDOWS\system32\uxbeg.bak
    C:\WINDOWS\system32\uxbeg.bak2
    C:\WINDOWS\system32\uxbeg.dat
    C:\WINDOWS\system32\uxbeg.dat2
    C:\WINDOWS\system32\uxbeg.ini
    C:\WINDOWS\system32\uxbeg.ini2
    C:\WINDOWS\system32\uxbeg.tmp
    C:\WINDOWS\system32\ishost.exe
    C:\WINDOWS\system32\ismon.exe
    C:\WINDOWS\system32\vtusqop.dll
    C:\WINDOWS\system32\poqsutv.bak
    C:\WINDOWS\system32\poqsutv.bak2
    C:\WINDOWS\system32\poqsutv.dat
    C:\WINDOWS\system32\poqsutv.dat2
    C:\WINDOWS\system32\poqsutv.ini
    C:\WINDOWS\system32\poqsutv.ini2
    C:\WINDOWS\system32\poqsutv.tmp
    C:\WINDOWS\SYSTEM32\wintxr32.dll
    C:\WINDOWS\DOBE~1\ati2evxx.exe
    C:\Documents and Settings\Brent Hegnauer\Application Data\s?stem32\m?config.exe
    C:\Documents and Settings\Brent Hegnauer\Local Settings\Application Data\5b00714.exe
    C:\Documents and Settings\Brent Hegnauer\Local Settings\Application Data\f5e7a00b.exe
    C:\WINDOWS\system32\5b00714.exe
    C:\WINDOWS\system32\f5e7a00b.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot, look for the below folders using Windows Explorer and delete them if found:
    C:\Program Files\ToolBar888
    C:\Program Files\Enigma Software Group
    C:\Program Files\Common Files\{1092EEA7-0708-1033-1209-020312090001}
    C:\Program Files\TClock

    Now run the below procedure and attach the newfiles.txt log.
    Now attach a new HJT log and tell me how the steps went.


    Make sure you tell me how things are working now!
     
  14. Brent H

    Brent H Private E-2

    I ran the steps you instructed me to do, and they all went fine with the following exceptions:

    These two processes could not be killed in HJT:
    When rebooting after performing the killbox steps, I saw a quick error message regarding ishost.exe. It went too fast for me to read it though; it might have been something about it not being able to shut down or a file not found.

    This folder could not be deleted:
    It gives me an error saying
    When opening that folder, I see the DLL and Update.exe, neither of which are write-protected. It won't let me delete Update.exe.

    Here are my logs...
     

    Attached Files:

  15. Brent H

    Brent H Private E-2

    I've got a flashing warning triangle in my taskbar now, that pops up a message bubble saying I'm infected with OHPE ver 4.12_23...
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds