i can't get rid of 2 win32 trojan downloader

Discussion in 'Malware Help (A Specialist Will Reply)' started by ciarca, Nov 12, 2006.

  1. ciarca

    ciarca Private E-2

    Hi guys i need some help with these virus please.

    • Edit by bjgarrick: Unrequested, Inline HJT log removed!
     
    Last edited by a moderator: Nov 12, 2006
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MajorGeeks.com, please follow our standard cleaning procedures:

    http://www.majorgeeks.com/images/grenade.gif Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    http://www.majorgeeks.com/images/grenade.gif Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    http://www.majorgeeks.com/images/grenade.gifAfter doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    http://www.majorgeeks.com/images/grenade.gif Downloading, Installing, and Running HijackThis
    • Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around..
    http://www.majorgeeks.com/images/grenade.gif In your next post, please make sure you attach the following logs and that you have run these scans in the following order:
    • CounterSpy - ONLY IF you were not able to run Windows Defender
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. ciarca

    ciarca Private E-2

    Hi Bigarric i want apology because i posted a log without following your instructions
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Be sure you complete all the steps in the "READ & RUN ME FIRST", it's made for your benefit. It looks long but it's really not, every step is broken down step by step for users who are not as familiar as others.

    Be sure you run the online scanners if nothing else.
     
  5. ciarca

    ciarca Private E-2

    ok i just want also apology because before i posted a lof without followind you instructions
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It's ok, your new :p
     
  7. ciarca

    ciarca Private E-2

    Bigarrick ccleaner says that This process will permanently delete files from my system.shall i carry on? sorry but as you said i'm new.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, it's ok as the files are only the temporary files from the internet and some other logs that are unnecessary.
     
  9. ciarca

    ciarca Private E-2

    Hi bjgarrick,i have done everything but still got the win32 trojan downloader
    Re panda active scan the window of it was half open and for some reason i wasn't able to enlarge it and save the report,i did run getrunkey and shownew but all the time i closed the log in notepad everything would desapear,tell me what i have to do next
     
  10. ciarca

    ciarca Private E-2

    Hi bjgarrick these are the logs of bitdefender,getrunkey and HIJ,for shownew i have to open another thread what do u suggest?
     

    Attached Files:

  11. ciarca

    ciarca Private E-2

    it looks like that i had some problems to upload the HIJ log whay?
     
  12. ciarca

    ciarca Private E-2

    shownew log
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download HOSTER and then follow the below steps.
    • Unzip HOSTER to a convenient folder such as C:\Hoster

    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.

    • Click the X to exit the program.
    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R3 - Default URLSearchHook is missing

    O2 - BHO: Duplex - {4D8603D1-E19F-4DB9-B841-CF0B3AECF967} - C:\WINDOWS\system32\apparat.dll (file missing)

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe

    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)

    O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/

    O15 - Trusted Zone: *.sony-europe.com
    O15 - Trusted Zone: *.sonystyle-europe.com
    O15 - Trusted Zone: *.vaio-link.com

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\Program Files\VVSN Delete this whole folder if it exist!

    Next, run CCleaner to clean up cookies and temp files.

    After you complete the above, REBOOT and proceed with the rest of this fix...

    Next Reset Web Settings & Default Security Settings

    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK

    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.

    Note for IE 7 users:
    Select Internet Options, then the Advanced Tab and then the Reset button under Reset Internet Explorer Settings.

    After you complete the above, reboot once more and attach a fresh HJT log. Also let me know how things are running.
     
    Last edited: Nov 15, 2006
  14. ciarca

    ciarca Private E-2

    Hi Bjgarrick first of all i want thank u for all your help and your patience,ok
    after i run the HIJ you are ask me to boot into safe mode and navigate to and DELETE the following if they should remain,i don't understand sorry, do i need to run again the HIJ tool in safe mode?
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    What I mean is, after you run HJT reboot into Safe Mode and delete the folder "C:\Program Files\VVSN" if it exist. Afterwards then run CCleaner. After you do that reboot normally and reset the web settings.
     
  16. ciarca

    ciarca Private E-2

    Thank you for your clearness Bjgarrick,i will do tomorrow or thursday,it's has been a long day,i just realize that you are help me from Alabama,it's amazing!
    i will let you know in the next few days.
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Okay, the sooner the better because something may change.
     
  18. ciarca

    ciarca Private E-2

    Hi Bjgarrick,i was trying to run Hoster but i can't find Restore original Host,there is Restore microsoft's file is it the same?
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, it's "Restore Microsoft's HOST file".
     
  20. ciarca

    ciarca Private E-2

    Hi Bjgarrick,well i have run hoster,Hjt,ccleaner,reseted web settings and security settings,after all this i have run ad-awre se personal, and still it detected the 2 win32 trojan downloader!
     

    Attached Files:

  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, attach a fresh HJT log from normal mode. Also, can you attach the log from what is detecting the trojan?
     
  22. ciarca

    ciarca Private E-2

    Hi ok,here i have the logs!!
     

    Attached Files:

  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Let's run two scans with should address that detection which isn't really a thread.

    1. Download, install and run CleanUp!.

    2. Download, install and run MRU Blaster.

    Once you complete this, reboot and run another scan.
     
  24. ciarca

    ciarca Private E-2

    Hi shall i do the scans in safe mode? did u mean it's not really a threat?
     
  25. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Run them in normal mode.

    I meant it's not a thread, it's ok cookies per the log.
     
  26. ciarca

    ciarca Private E-2

    i run MRU-blaster,do i have to clean all the items that's been detected?
     
  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, clean everything both programs find.
     
  28. ciarca

    ciarca Private E-2

    ok,windows cleanup has deleted 15210 files is it ok? do i need to run a scan with both tools again?
     
  29. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I would to be sure it removed everything. Also, there will always find things as everytime you open any browser you will have cookies.
     
  30. ciarca

    ciarca Private E-2

    do i need to do a scan again with both tools?
     
  31. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If your talking about MRU Blaster and CleanUp! I would to confirm it removed everything but like I said you will always have cookies because everytime you open a browser you will have temp files.

    If your talking about Ad-Aware then yes, make sure it didnt come back.
     
  32. ciarca

    ciarca Private E-2

    Bjgarrick i'm afraid they are still there,i've just ran ad-aware,i got a log also
     

    Attached Files:

  33. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

    After you do this, reboot and it should be gone.

     
  34. ciarca

    ciarca Private E-2

    All the time you say reboot,i think to reboot the pc in safe mode,what do you mean exactly with reboot? thanks Bjgarrick
     
  35. ciarca

    ciarca Private E-2

    sorry can you help me to find notepad?
     
  36. ciarca

    ciarca Private E-2

    Bjgarrick unbelievable they are gone,how did u do that?do u think that's clean now?shall i do the toggle system restore?and what about all those tools
    that i have downloaded to clean the pc?which one shall i keep?
     
  37. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Manual registry edits 99% of the time will remove anything. :)

    If you havn't then yes I would toggle SR. Also, any tool/program I had you install/run you can now delete them all.

    Everything you need is here, How to Protect yourself from malware!.
     
  38. ciarca

    ciarca Private E-2

    Hi Bjgarrick, can you tell me why should i change internet explore for Mozzila Firefox?and regarding the tools that i have downloaded,can i keep HJT & fixme.re? can you tell me also if i have sun java? and about the anvirus software
    i do have norton anvirus 2005 shall i keep it?or do u suggest to get rid of it?
    thank you so much for all your help,have a good sunday.
     
  39. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It's up to you, I use both. Before IE7 Firefox was the safest browser but after using it since it's release I've noticed it's a lot better th an IE6 so both are great browsers. The majority of Firefox users use it because you have use "extensions" that will do just about anything.

    They are no longer any good so you can delete them. HijackThis is only for advanced users, it's also updated so what you have may not be the current version if you need it later on.

    If you havn't installed it then see the thread below (How To Protect) on how to install it.

    I will leave this decision up to you however I will recommend AVG AntiVirus simply because it's better.

    You should see this article on How to Protect yourself from malware!
     
  40. ciarca

    ciarca Private E-2

    Hi Bjgarrick,can you explain me please what does mean IE6 or IE7?ragarding the software antivirus do you recommend AVG free edition?
    Re sun java,i have j2se runtime enviroment 5.0,j2se runtime enviroment 5.0 update,and j2se runtime enviroment 5.0 update 9, do i need to keep all these?
    thanks!
     
  41. ciarca

    ciarca Private E-2

    ok i got it, internet explore 7
     
  42. ciarca

    ciarca Private E-2

    What about Mozilla firefox 2.is it that one that i have downloaded from this site?or is the previuos version?
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes AVG free is a very good program!

    You only want the current versuon of Sun Java which is 5.0 update 9. Uninstall all old versions.

    The current version of FireFox (available on MGs) is Mozilla Firefox 2.0 Final
     
  44. ciarca

    ciarca Private E-2

    Hi Chaslang, thanks! i downloaded a firewall, Zone Alarm free,it looks good,but the problem is that a window comes up all the time with all the programs that want be installed,so basically i don't know what programs are allow because most of them are known by codes.how do i know if i have downloaded the last version of Mozzilla Firefox? is it better than the previous one?
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is just part of all firewall behavior. You need to become a little bit of a system administrator and keep track of what you are running on your PC. It is just part of the security aspects that you need to be responsible for. ZoneAlarm will popup a message something like this:

    Do you want to allow xxxxxxx to access the Internet? Where xxxxxxx is the name of the program/process.

    You have to answer Yes or No. But you also need to check the box that says:

    Remember this answer the next time I use this program.

    That way, ZoneAlarm will not ask you anymore. You should normally be able to tell what the process is because most of the time the name will be recognized and also you should know what you just ran and it should ring a bell that it is related to something you are doing and need. If you do not recognize it then Google the process to get more info on it before you tell ZoneAlarm what action to take. When in doubt deny the access but don't click the Remember this answer check box. If you now see that something does not work that you were trying to do, you should realize what was trying to access the internet and you can allow (either rerun the process or manually edit ZOneAlarm's database to allow it).

    The same as in almost every program. From the top menu click Help, and then About Mozilla FireFox
     
  46. ciarca

    ciarca Private E-2

    Thank you,just one more question,in one of my email address i keep receiving
    a kind of spam emails from different address,always about finacial issues,how can i get rid of them?
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spam mail is due to the fact that spammers have gotten your email address. Once you are on one list, you can wind up on many. And if you ever respond to any of them (even to just tell them to remove you from the list) you are confirming your email address is valid and you will be added to more lists. This is discussed in How to Protect yourself from malware!

    There is not too much you can do other that the below:
    • Try some spam filtering programs and attempt to create filters that are not to easily bypassed. This can be tedious. Take a look at some of the tools in the below link. You could get recommendations on these and other tools in the Software Forum:
    • Change your email address and be more careful where you use it and who you give to next time. Never give your email address to people (even friends) who love to click global group replies and forwards. This will get you onto spam lists faster than you can imagine.
     
  48. ciarca

    ciarca Private E-2

    ok thank you so much!!
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds