Malware/trojan hell.....help

Discussion in 'Malware Help (A Specialist Will Reply)' started by vearm01, Nov 22, 2007.

  1. vearm01

    vearm01 Private E-2

    Ok I new to this.....and slowly going mad trying to fix it.
    Here are the symptoms:
    Internet explorer messages telling me that I'm infected and do I want to fix it? Clicking yes takes me to a web page where I can "buy" the anti spyware software to fix it. Clearly a scam
    Eventually my desktop goes red with the message "your privacy is in danger" or similar (sorry logged in in safe mode at the mo so can't check exactly) Any click on the desktop take me to the same old anti spyware pages.
    I've run Smitfraudfix to get rid of this but it comes back eventually.
    Originally the JOKWMP toolbar was installed on internet explorer which I have removed using PREVX (which hasn't come back)
    PREVX is also "jailing" the following files:
    nsduo.dll
    main_uninstaller.exe
    msmdev.dll
    msmhost.dll
    rmv.exe
    edi.exe
    update.bat

    PREVX also stops the CMD.exe accessing most of the above files

    Please help!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. vearm01

    vearm01 Private E-2

    Trojan.zlob other malware help please

    I have run all the "read and run me first" apps and although initially it cleans things up, the problems keep returning nearly immediately
    The symptoms are:
    Norton is picking up trojan.zlob and stops it in some cases and can;t in others.
    A number of different windows pop up over time some as "window security alerts" others sayaing I am being attacked, all link to web pages selling spyware removal software.
    My desktop changes to a red one with a logo saying "Your Privacy is in danger, Download privacy protection now"
    3 icons appear on my desktop called error cleaner, privacy protector and spyware protection

    I've run the AVG antispyware 3 times now and it won't let me save a report, even though I have selected the correct options in settings as instructed. I have uninstalled and then reinstalled it, but always the same.
    it picks up 4 objects (17 traces)
    trackingcookie.netflame
    trackingcookie.doubleclick
    trackingcookie.2o7
    trackingcookie.tribalfusion

    attached are the logs from combofix and mgtools
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan.zlob other malware help please

    Please remember to stay in one thread. I merged you back to your first thread.

    Your MGlogs.zip file is missing a log from HijackThis which should have automatically been run and added to the ZIP file. Did you notice any messages for installing HijackThis and did you allow it to install and run? Also GetRunKeys.bat did not run properly due to something on your PC interferring with it. I will have to give you a different version to use that should work around this issue. I will attach a file to another message and explain what to do.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis. Select Do a system scan and save a logfile. This will default to saving the log into the C:\MGtools folder. The name of the log will be hijackthis.log. Attach this log file to your next message so we can continue.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan.zlob other malware help please

    Download the attached GetRunKeys.zip file into your I:\MGtools folder. Extract the GetRunKey.bat file from the ZIP file into the I:\MGtools folder thus overwriting the current version that is there.

    Now run the I:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new I:\MGlogs.zip file that will be created by running this.
     

    Attached Files:

  6. vearm01

    vearm01 Private E-2

    Hi - hopefully this is right now! it has the hijackthis log in anyway.
    Thanks
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your log you did not download the attached ZIP file into the C:\MGtools folder as I rquested. Also you did not extract the new GetRunKey.bat file that is in the ZIP file into the MGtools folder. Go back to my previous message and download the attached GetRunKey.zip file and save it into the C:\MGtools folder. Then locate this GetRunKey.zip file and extract the new GetRunKey.bat file from it and make sure you extract it into the C:\MGtools folder. You should notice 1 file in the folder named GetRunKey.bat when you finish. And it should have a file date of 11/23/2007 and a time of 10:05 PM also the file size (seen when you right click on it and select properties) will be 85.781 bytes.

    Then you should re-run the C:\MGtools\GetLogs.bat file and attach the new C:\MGlogs.zip file.

    If you are having a problem with any of these instructions please tell me where and I will try to clarify.
     
    Last edited: Nov 24, 2007
  8. vearm01

    vearm01 Private E-2

    sorry - not sure what happened there. This hopefully should be right.
    thanks for your patience
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bingo! That work just like I expected it would. ;)


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03


    Also uninstall the CounterSpy trial program now since we are finished with it.

    You have too many antispyware blocking tools installed.
    • Did you purchase PrevX?
    • What about Spyware Doctor?
    • What about SuperAntiSpyware?
    • What about AVG AntiSpyware?
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: MSVPS System - {31E3F653-ED88-4355-B83E-FB263CD355E3} - I:\WINDOWS\popnetnpr.dll
    O3 - Toolbar: (no name) - {9E004C23-5424-4C79-BAFE-C2B3460ECB56} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\QTTask.exe" -atboottime
    O21 - SSODL: rmvgor - {F2D2EAD6-0F2E-47B4-AB21-0A525021026C} - I:\WINDOWS\rmvgor.dll
    O21 - SSODL: sapnet - {71CF5C72-2E31-4B1D-AF67-51CFFD8643A6} - I:\WINDOWS\sapnet.dll

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: [URL="
     
  10. vearm01

    vearm01 Private E-2

    great...seems to have done the trick. I've been using it an hour now and nothing is poping up.
    Your message seemed a little truncated. There were some errors that came up with avenger.Not sure if you wanted me to post the log but here it is.

    I've removed all the antispyware except avg - running too many when attempting to fix it myself before I discovered you guys.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it was due to a bug in the vBulletin code. Here is what was supposed to be there. Note you already attached the Avenger log so you don't need to attach it again.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  12. vearm01

    vearm01 Private E-2

    heres the mglogs.zip file.
    Everything is running beautifully now. no pop ups, no desktop changes
    thanks for your help - fantastic work!!
    Mark
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some items I asked you to fix did not get fixed. Possibly this is due to all the antispyware programs you were running getting in the way. Many of them still show in your HijackThis log. Did you uninstall them after getting the logs or before. By the way you should not have uninstall Spybot which I don't see in your logs. As long as you don't let its Teatimer activate (as we state in the READ ME) it is not a realtime blocking tool. Also note that AVG Antispyware will not be a realtime blocking tool after the 15 day trial period unless you purchase it. Thus you will need a realtime antispyware tool.



    Shut down Symantec as best as possible before doing the below.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: MSVPS System - {31E3F653-ED88-4355-B83E-FB263CD355E3} - I:\WINDOWS\popnetnpr.dll
    O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - I:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
    O3 - Toolbar: (no name) - {9E004C23-5424-4C79-BAFE-C2B3460ECB56} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [PrevxOne] "I:\Program Files\Prevx2\PXConsole.exe"
    O4 - HKCU\..\Run: [MSMSGS] "I:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] I:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O20 - Winlogon Notify: !SASWinLogon - I:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O21 - SSODL: rmvgor - {F2D2EAD6-0F2E-47B4-AB21-0A525021026C} - I:\WINDOWS\rmvgor.dll
    O21 - SSODL: sapnet - {71CF5C72-2E31-4B1D-AF67-51CFFD8643A6} - I:\WINDOWS\sapnet.dll
    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - I:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - I:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - I:\Program Files\Spyware Doctor\swdsvc.exe

    After clicking Fix, exit HJT.


    Now run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  14. vearm01

    vearm01 Private E-2

    I've run everything as you said. I think the hijackthis log in the mglogs.zip i sent was from before - i.e. with all the bad stuff still .I didn't realise that running getlogs.bat didn't generate a new hijackthis log. Anyway sorry about that and here is the up to date mglogs.zip
    everything is still running fantastically!
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach a new log from Avenger. Did you do what was requested in message # 13???? It does not look like it based on your logs.

    But it does generate a new HJT log. It is just a matter of timing. As in when did you run GetLogs.bat.


    Okay I see that you reinstalled Spybot which is good; however, you allowed it to activate Teatimer contrary to what I had said about not using it. Your log is still not clean and Teatimer may get in our way of fixing it.

    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Now make sure you do ALL of the below and attach the new logs that are requested at the end.

    Shut down Symantec as best as possible before doing the below.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O21 - SSODL: msmhost - {71D071C2-E7F0-41F1-8ED8-DD3A5F2F20BD} - I:\WINDOWS\msmhost.dll
    O21 - SSODL: msmdev - {D605EA43-880A-42FE-838C-B629002CF28A} - I:\WINDOWS\msmdev.dll

    After clicking Fix, exit HJT.


    Now run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  16. vearm01

    vearm01 Private E-2

    sorry - forgot to attach avenger log
    There were a lot of errors that came up before it finally re-booted.

    I have re-installed spybot, but didn't actually open it so haven't changed any settings. I'll sort that as soon as I get home from work

    I did run through all of your last post. However only 3 of the entries you said to delete from the hijackthis scan actually appeared

    I'll follow all of your instructions as soon as I get home and repost
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You needed it to tell it not to enable Teatimer during the install. My info below tells you have to disable it anyway.
     
  18. vearm01

    vearm01 Private E-2

    Hi
    ok.

    Teatimer off
    Hijackthis run and lines deleted
    avenger run and done
    ccleaner run
    new MGlogs.zip attached
    new avenger.txt attached

    thanks
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now your logs are clean!


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds