Need help with a trojan issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by Maddie422, Apr 23, 2007.

  1. Maddie422

    Maddie422 Private E-2

    Hi. I am having some issues with malware. Started with a flashing question mark icon on the toolbar at the bottom of the screen and progressed to the flashing question mark along with a flashing yellow triangle alert. When I pulled up my browser, instead of my homepage coming up, a "security alert" page comes up with the address being asafetywarning.com. I have never clicked on any of these or the things they tell you to, repeatedly having to close them.

    I have read and followed your READ & RUN ME FIRST document, and through following the steps have gotten rid of the flashing question mark and yellow alert triangle, however, I am still getting directed to the "security alert" page when I open my browser. The scans seem to have gotten a lot of stuff, but looks like there is still some hanging in there.

    Can you help me get rid of this? (Attached are the requested log files)

    Thanks!
     
  2. Maddie422

    Maddie422 Private E-2

    Not sure if the files got attached so resending...others on the way too...
     

    Attached Files:

  3. Maddie422

    Maddie422 Private E-2

    More files...
     

    Attached Files:

  4. Maddie422

    Maddie422 Private E-2

    and the HijackThis log...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your Windows version is way out of date and is a major security risk! After we remove any current malware problems, you must get your system updated.

    Please see steps 0 and 1 of the READ ME.

    Step 0:You are using MSconfig to control startups! You must put your system in Normal Startup mode.
    Step 1: You have item showing in C:\Program Files\Yahoo!\YPSR\Quarantine You must empty all quarantines. Also delete the below folder:

    C:\Program Files\Microsoft AntiSpyware

    Microsoft AntiSpyware has been discontinued.

    After doing all of the above, continue on to the below.


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  6. Maddie422

    Maddie422 Private E-2

    Hi Chaslang - thanks for the reply. I already have a question. It has to do with using Msconfig to control startups. Last year sometime, we had a tech from the Geek Squad come out to look at a problem we were having on the computer. We were having to run it in Safe Mode as that was the only way it would work. When we attempted Normal Startup, it would get stuck on something and hang indefinitely. They believe it was a corrupt file somewhere but were unable to get to it. They created a workaround that had to do with controlling the startup. So, I am worried about going into Normal startup mode. Is that a requirement to procede with fixing my current problem?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What they should have done was removed all the malware and then determine which process (if any) was really causing the hang. It is not that difficult to do. You just use process of elimination by enabling and disabling various items until the offending item it found. What they did even disabled your antivirus program from loading and running properly.

    Yes we need to be able to have you boot in Normal Startup mode to properly fix your problems. If at any time you windup not being able to run in Normal Starup mode, you can then just boot into safe mode and disable the startups again to work around the problem. But don't set Normal Startup yet! I will tell you when to do this! Let's use a registry patch to remove a few things first! This may help resolve your boot problem! We shall see.

    I will post some steps in my next message!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First goto Add/Remove programs and uninstall the below:
    Security Messenger
    Spam Blocker Utility ShopperReports
    If they do not uninstall or you don't see them, just tell me later but continue on with the below steps.

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {D34F5D71-99E4-4D96-91CA-F4104F69B8AE} - C:\Program Files\Protection Tools\bpvol.dll
    O3 - Toolbar: Protection Bar - {F0993251-2512-4710-AF6E-0A13EA199D02} - C:\Program Files\Protection Tools\splug.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GStartup.lnk
    C:\Program Files\Common Files\GMT\GMT.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
    C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkCommon Startup
    C:\\WINDOWS\\pss\\GStartup.lnkCommon Startup
    C:\Program Files\MYWEBS~1\bar\1.bin\MWSOEMON.EXE
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\SpamBlockerUtility\Bin\4.7.1.0\SbOEAddOn.exe
    C:\Program Files\Protection Tools\bpmini.exe
    C:\Program Files\Protection Tools\bpunst.exe
    C:\Program Files\Protection Tools\splug.dll
    c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf
    c:\windows\inf\imgiant.inf
    c:\windows\usta33.ini
    C:\WINDOWS\imggg.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Common Files\GMT
    C:\Program Files\MyWebSearch or
    C:\Program Files\Microsoft AntiSpyware
    C:\Program Files\Protection Tools
    C:\Program Files\SpamBlockerUtility

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. Maddie422

    Maddie422 Private E-2

    Hi, Chaslang. Attached are the new logs as requested. As far as how everything went:

    1) In the first step, when I went to Add/Remove programs, I was unable to delete either Security Manager or Spam Blocker Utility ShopperReports. Both came back with an "error during uninstall" saying something about how it might have already been removed. Spam Blocker remained, but I could no longer see Security Manager - I think I might have accidentally removed it from the list even though it wasn't deleted.

    2) I continued on, following all your steps with no problems. I did NOT get the PendingFileRenameOperations prompt after the Killbox steps.

    3) After the reboot, I looked for the folders you listed. I did NOT find the Common Files/GMT, the MyWebSearch or the Microsoft AntiSpyware. But I did find both Protection Tools and the SpamBlockerUtility folders and deleted both.

    4) Ran Ccleaner, attached the logs, and here we are...

    I don't seem to be getting redirected to the security pages anymore, though while I was reading your post (before following your directions) AVG Anti-Spyware notified me that it had found a few more things. (Zlob trojan downloader avb & avc). I selected clean and quarantine, then just now went back and emptied the quarantine.

    I really appreciate your help! What's next? :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the logs!
     
  11. Maddie422

    Maddie422 Private E-2

    That's weird...that's the first thing I did - it really looked like they were there when I hit submit. Anyway, here they are again...
     

    Attached Files:

  12. Maddie422

    Maddie422 Private E-2

    I am a little confused here. First, I got an email notification that you posted a reply but I am not seeing it here.

    Second, you asked me not to go into Normal Startup mode until you told me to, that we were going to try the Registry patch to see if that would fix a couple of things first. Which is why I haven't done that. As I had mentioned, the Geek Squad set up a work around for us last year that bypassed/changed Normal startup because of a hang problem we were having.

    So, this is the point you are telling me to go into Normal Startup mode? Or are you saying I did the last stuff wrong?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was starting to put my ideas together for the next courses of action and I had offline for awhile. Since I was creating these next steps while away from my own PC, I needed to save them even though they were incomplete. What I did was save them in this thread and then I soft deleted them. That allows me to still see them but no one else can. The downside of doing this is with users who use email notification. You get a copy as soon as it is first created. I basically never recommend anyone to work from email notifications since they don't allow for conditions like above and they don't even allow for the fact that an initial post may require editing to make it correct. In short, you can use the email notification, as a indication that some activity may have occurred on your thread, but always come to the forum to get the real current instructions.

    I still thinking about how I want you to proceed. I think that I may give you a couple of items at a time to enable and see what happens. And then keep doing that until we either locate the item that cause you to hang or we get everything loading and we don't have a problem. I will work something up and post it in my next message.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run MSconfig and click the Startup tab. Locate the below Startup Items and put a check mark on them (they are unchecked right now):

    CAVTray
    CAVRID
    ybrwicon
    yop


    Then click Apply and OK!

    Now reboot your PC!

    If it boots up OK in normal mode, attach a new GetRunKey log.

    If it does not boot up in normal mode or hangs as you described previously, then boot into safe mode and uncheck those 4 items again. Then you should be back where you started.

    Let me know the results.
     
  15. Maddie422

    Maddie422 Private E-2

    ok, I ran MSconfig and checked the 4 items you asked me to, applied and rebooted my PC. It did NOT hang. Here is the new GetRunKey log.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's good! That's 4 down and 5 to go. Now put checks on each of the below in MSconfig and see what happens:


    2PortalMon
    IPMon32
    PicasaMediaDetector
    PRISMSVR
    ypager

    If it does not boot up in normal mode or hangs as you described previously, then boot into safe mode and uncheck the first 3 of the 5 and try to boot again.
    If you still have a problem, uncheck the remaining 2. Tell me the results.
     
  17. Maddie422

    Maddie422 Private E-2

    Ok, I checked the additional 5 and restarted....still didn't hang. Which really surprised me. Was that normal startup mode? Do you need any logs?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well as I said earlier, Geek Squad did not take the proper steps to fix your problems. They just tried to hide the problem and messed up other things while doing that.

    Now run MSconfig and make sure Normal Startup mode is selected. If it is, just attach new logs from GetRunKey & HJT. If it is not in Normal Startup mode, select it and then reboot your PC and then attach new logs from GetRunKey & HJT.


    Tell me how things are running in Normal Startup mode.
     
  19. Maddie422

    Maddie422 Private E-2

    ok, I checked Normal Startup in MSconfig and restarted with no problems. Everything appears to be running fine. Here are the new GetRunKey & HJT logs.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  21. Maddie422

    Maddie422 Private E-2

    I followed all the directions here - and everything seems to be back on track. Just wanted to say "thank you so much!!" for your help - it was invaluable. It's awesome that you guys are here.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds