Help - Protection Bar / Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by gav1980, Aug 20, 2006.

  1. gav1980

    gav1980 Private E-2

    I'm a complete novice at this but with a couple of days searching and following advice I've ended up here I have followed the READ and RUN ME FIRST sticky up to but not including HijackThis - worried I'll do something wrong with this.

    PROBLEM: I have a toolbar on internet explorer called Protection Bar which I can't get rid of. Have had some pop-ups and also some of those dodgy balloon messages (from bottom right of screen) telling me to download various spyware removal programs (possibly SpyAxe) which I have ignored and seem to have got rid of so far.

    I'm running Tesco internet Security - an F-secure derived internet security program. WIN XP SP2.

    Ran C-Cleaner, MS Windows Malicious Software Remover, Spybot S&D, MS Windows Defender in Safe Mode and then did the online checks with Bit Defender and PandaActive Scan (Did My Computer by accident instead of Local Disks - sorry if that causes any problems, it took ages)

    MS Malicious software remover found some stuff I wrote down but I don't know how to get the results back now to post - any suggestions? I'm sure it said it had fixed these though. They were:

    Backdoor:Win32/SdBot!36B4
    Trojandownloader:Win32/Zlob.DA
    Trojandownloader:Win32/Zlob.EG
    Trojandownloader:Win32/Zlob.EL
    Trojandownloader:Win32/Zlob.EZ

    Attached are the first newfiles, runkeys and bdscan results (hopefully!), see next message for PandaActive result.

    Please Help!!!

    Thanks in advance
     

    Attached Files:

  2. gav1980

    gav1980 Private E-2

    Hope this is the correct way to do next message with PandaActive result.

    Thanks
     

    Attached Files:

  3. gav1980

    gav1980 Private E-2

    Just a few additional questions:
    Are my passwords safe? Can I safely use internet banking? and can I use paypal without risk of my money being nicked?
    To be safe I haven't done any of these since I realised the computer was infected and it's getting annoying now!
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Post your HijackThis log. As long as you don't try to fix anything with HijackThis, without expert guidance you'll be OK.
     
  5. gav1980

    gav1980 Private E-2

    OK, the HJT log is now attached.

    Also report.txt is a system summary from Everest, hope that helps solve any problems.

    Thanks in advance
     

    Attached Files:

  6. gav1980

    gav1980 Private E-2

    Just been checking some more threads - one I've found has the same problem with protection bar on IE. The thread is titled Spyware etc. and was started by bwood00, chaslang has been sorting it out.

    I'm presuming the solution for me will be slightly different depending on what you find in the logs I attached but just thought it might help you to help me if I pointed out a similar problem.
     
  7. gav1980

    gav1980 Private E-2

    PLEASE HELP - I'm getting worried this thread is being ignored, sorry if anyone is working on a solution - I don't know how long it takes!

    Anyone???
     
  8. gav1980

    gav1980 Private E-2

    More info: My internet security program keeps finding the same thing, it is trojandownloader.win32/zlob.afi it tells me that it has renamed it and then sometime later it finds the exact same thing again with the same result.

    What should I do about this? Is this part of the same problem i have with Protection Bar or is it something different?

    Please help me!
     
  9. gav1980

    gav1980 Private E-2

    Sorry if I'm being annoying now but here is a new hijackthis log, just incase you need it, Just thought you might - with reference to my last update about trojandownloader.win32/zlob.afi

    Please tell me to shut up and wait if you like!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the below file you downloaded on August 17th?
    C:\Documents and Settings\eric\Desktop\malware removal\f-spyaxe.zip

    You need to get your Sun Java version updated as mentioned in the READ ME. You are way of date. First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    Java 2 Runtime Environment Standard Edition v1.3.1_17

    I'm looking at your logs now and will post something in a couple minutes.

    {Edit] I see you have updated Sun Java now! So just uninstall the above old version.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you planning on keeping all this ridiculous stuff from Tesco Internet Security installed? They are just using the F-secure software and it is a massive resource hog which in all cases that I have seen thus far, have slowed users PCs down to a crawl. Just look at all the stuff related to it showing in your log. And it obviously did not work very well anyway.

    Another question! Do you use PureSight Internet Content Filter - http://www.puresight.com/bin/en.jsp?enPage=PSPage&enZone=Solutions
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note: process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!

    Now attach new logs from GetRunKey, ShowNew and HJT so we can continue with your cleanup.
     
  13. gav1980

    gav1980 Private E-2

    I'll have to do everything you said tomorrow - as I don't have time right now. Here's a few answers to questions you asked and some more questions from me:

    The file
    C:\Documents and Settings\eric\Desktop\malware removal\f-spyaxe.zip
    is something I used to get rid of spyware, I linked to it from F-secure website when I first started to fight my problems with dodgy balloon messages advertising anti-spyware - it is a .reg file which I ran (is that the right term) and seems to have worked - I stopped geting the messages anyway. now I just have the protection bar in IE.

    Tried to uninstall sunJava but get unspecified error message - Should I try to remove it with CCleaner uninstall feature?

    I don't use puresight internet content filter - should I?

    Should I get rid of Tesco Internet security and use something else in future?
    My folks and grandparents have it too so no doubt they're infected aswell - something I'll sort out when I'm clean.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give it a try and let me know if it works. Remember to only uninstall the old version I gave. Do not uninstall the new 5.0 update 8 version.

    No! But it was installed at one time and appears to be broken and is messing up your LSP chain. If you do not use this software we need to fix your LSP chain (see the O10 line in HijackThis). DO NOT ATTEMPT to fix it with HijackThis. You could break your Internet connection. We will fix this later with another tool.

    That's up to you. If you are happy with it and are not noticing that your PC is running very slow, then by all means keep it. It was probably provided for free by your ISP. F-secure is a reputable company but these internet security suite packages (like yours, and Symantec, McAfee, etc) are just big pigs and are just not necessary. A few free tools will work just as well and they will not be so resource hungry. But again, this is your decision. If your happy, then sticky with it.


    Oh and by the way, that f-spyaxe.zip file contains and much smaller registry patch and not as globally useful version of what I have posted in the below link. Nor does it go thru and delete all the bad files.

    SpywareQuake & SpyFalcon Removal Procedure
     
    Last edited: Aug 23, 2006
  15. gav1980

    gav1980 Private E-2

    rapport.txt as requested, going to get other logs you want now and attach them to next message

    Should I have booted in safe mode to be doing all this?
     

    Attached Files:

  16. gav1980

    gav1980 Private E-2

    OK I've run SmitFraudFix - took literally seconds so not sure if it worked properly???

    new logs for getrunkey, shownew and HJT attached as requested.

    By the way, I managed to uninstall old Sun Java with CCleaner.

    thanks
     

    Attached Files:

  17. gav1980

    gav1980 Private E-2

    I just ran through all the steps in the SpywareQuake and SpyFalcon Removal Procedure you suggested.

    I found none of the files that it says to look for in Windows\System32 folder although there were some very close matches eg. it says to look for

    cfgmngr32.dll - I have cfgmgr.dll
    appmagr.dll - I have appmgr.dll
    autodisc32.dll - I have autodisc.dll
    dcomcfg.exe - I have dcomcnfg.exe

    There are other close matches too but I figured that malware writers did this intentionally so I didn't do anything with any of them - Is this correct??? do you want me to tell you the other close matches?

    The only other thing i did was to delete jusched.log from c:\documents and settings\eric\local settings\temp as this was the only file in there.

    The Protection Bar I had has now gone - what was this by the way?

    Here is the smitfiles.txt log as per above procedure.
    Oh, and another new HJT log for you - (sorry if i wasn't meant to do this!)
     

    Attached Files:

    Last edited: Aug 23, 2006
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the SpywareQuake procedure did fix some stuff that you did not even notice. But let's be safe and finish the SmitFraudFix program process.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.


    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the winsflt.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move winsflt.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.



    Also locate the below file and delete it:
    C:\23100247.0XE

    How are things working now?
     
  19. gav1980

    gav1980 Private E-2

    Attached is rapport.txt as requested

    LSP-Fix ran OK, no hitches

    Deleted C:\23100247.0XE although when I right clicked on the file, Tesco Internet Security window popped up with virus message - something like

    "trojandownloader.win32.small."

    I finished deleting the C:\23100247.0XE file then I told Tesco Internet Security to delete "trojan....small" and nothing has happened since so I'm guessing it's fixed?

    Everything working just fine now - actually seems better than it was before I noticed anything wrong. Thanks
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    But we still have a little more to cleanup!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\RunServices: [msnsched] msnsched.exe
    O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba2218.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    (you may or may not find the below file):
    C:\windows\system32\msnsched.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  21. gav1980

    gav1980 Private E-2

    Ok then, all steps followed.

    I didn't find the file you said to delete but as you said I might/might not find it I didn't consider this to be a problem

    I already had CCleaner before I did READ ME FIRST sticky, I used to clean up every so often with it but I'd changed the settings - anyway I couldn't remember what the defaults were (and couldn't see a default tab anywhere) so I ran it on everything except advanced. Hope that was OK???

    Attached is the new HJT log you wanted.

    Everything is working fine still, (except for a slowish boot up but that's been happening ever since I installed tesco internet security package - the one you called a resource hog and a big pig!!! I'll uninstall it and use something else in future - any recommendations?)

    I am aware of and will disable System Restore but only when you tell me it's safe to do so!!!

    Thanks again - your help is much appreciated
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Your log is clean. Everything we recommend is in the below link which is part of your final steps. You will notice that there are no internet security suites (from anyone) recommended. ;)

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  23. gav1980

    gav1980 Private E-2

    Thanks so much for your help, will recommend you to anyone I know who has problems in the future, I've done the disable/enable system restore and just off to follow "How to Protect yourself from malware!"
    Thanks Again!!!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds