Need help with removing adware.websearch and trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by telomere, Mar 31, 2011.

  1. telomere

    telomere Private E-2

    Hi All,
    I think my system is infected with adware.mywebsearch and a trojan.I was suspecting it for more than two weeks. I went through your read me and malware removal procedure for vista and win7. I downloaded the tools but I could not run rootrepeal and combofix as they both showed errors. Rootrepeal was showing device control error while combofix when clicks on run was restarting the system.I have attached the following logs along with this message. I suspect I still have spyware problem.:(
    1. MGtools.zip
    2. SAS.txt
    3. Mbam.txt
    Kindly go through the same and any help will be appreciated.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, telomere.

    I am reviewing your logs and will get back to you with instructions as needed. Please be patient!

    *Our queue is working the oldest threads first.

    dr.m
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, telomere

    *You need to run MSconfig and put your PC into normal startup mode as requested in step 4 of the READ & RUN ME guide.

    Use MSconfig to setup for Normal Startup Mode

    You're in need of a RAM upgrade:
    Question: What can you tell me about this file "C:\YBCZP"?

    Step 1:
    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Step 3:
    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything inside the Quote box below, and paste it into the "Input script here:" part of the window.
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 4:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 5:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 6:
    Now install the latest Sun Java Runtime Environment

    Step 7:
    Please run this and attach the results.

    Using ESET's Online Scanner

    Step 8:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file and the ESETscan.txtto your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  4. telomere

    telomere Private E-2

    Hi Dr.M,
    First of all I thank you for taking the time to analyze my attachments and posting the instructions.
    I followed your instructions (step 1 thru 8). I have no idea what C:/YBCZP is.
    I couldn't find user/chipset/local~/temp.I could find local settings inside chipset folder but was getting access denied error even though I was the administrator. But I deleted the temp files manually.

    I ran eset online scan and it found one threat inside win32 and it says it deleted the threat. After that I ran MGTools. Since eset deleted that one threat it found, I guess I am ready to go and I hope there are no more infections. I would do an mbam and sas scan just to make sure everything is ok.

    I am attaching the eset scan log and MGTools.zip along with this as you have mentioned. Once again thanks for all your help Dr.M.:)
     

    Attached Files:

  5. telomere

    telomere Private E-2

    Hi,
    Just attached SAS.txt after scan.It again found seven threats of adware.funwebsearch.:(
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    What program do you have from BillP Studios or is this a left-over folder?
    C:\Program Files\BillP Studios

    Step 1:
    Please go to VirusTotal.com and upload the following file for analysis.
    C:\YBCZP

    Then post the URL link to the file scan report.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    Let's again use Avenger
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything inside the Quote box below, and paste it into the "Input script here:" part of the window.
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file and post the URL link to the VirusTotal scan result to your next reply.

    *What malware problems are you still experiencing?
     
  7. telomere

    telomere Private E-2

    Hello Dr.M,
    I have no idea what BillPStudio is .I have never downloaded such a thing and dont know how it came there.
    I did a memory upgrade today. So now memory shows I have 1.75GB.

    I am attaching the virustotal scan result link along with mgtools.zip

    I also did a SAS quick scan. It did not detect any threats. So I guess I am good to go. At last my system is free of all spyware I guess. Just one doubt, do I need to reinstall windows to remove that ybzcp?(Cos my system sometimes has startup problems and gets restarted itself. After doing avenger fix, when rebooted the syste, system was checking for startup problems and was asking me for a system restore. I said no to that)

    Thanks a lot Dr.M for all your help!:)
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, telomere

    Only 1 out of 41 of the anti-virus engines flagged C:\YBCZP ; I wouldn't be concerned with it.

    WinPatrol is produced by BillP Studios but I find no references to it in your logs. *If the folder [ C:\Program Files\BillP Studios ] is empty, you can just delete it.

    Good choice as that might have negated our cleaning.

    Your logs look good! I suggest that you post in our Software Forum for help diagnosing your Startup issues. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  9. telomere

    telomere Private E-2

    Hello Dr.M,
    I reinstalled my windows and I dont have any start up problems now. I have updated my PC with all the necessary softwares and turned on windows updates, One doubt though. I am unable to decide between avira anitivir and comodo. Both look equally good to me. Does avira have a firewall too?Which one do you suggest? Once again thanks a lot for all the help!:)
    Regards,Telo
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    No, Avira doesn't include a firewall. *My personal selection includes Avira AntiVir Personal - Free and Comodo Personal Firewall 5.3.50343.1237.

    You're welcome & Safe surfing!
     
    Last edited: Apr 7, 2011
  11. telomere

    telomere Private E-2

    Hey Dr. M,
    I have downloaded and installed comodo and avira. I used to use process guard and outpost firewall with XP and I loved it. I have a feeling that comodo will be better than any other firewall. Now I am all good, many thanks to you for your useful suggestions and help!:)
    Feel like singing (which I hardly do :))
     
    Last edited: Apr 7, 2011
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're very welcome!
    PS: I sing in private.. that eliminates the complaints.
     
  13. telomere

    telomere Private E-2

    Dr M,
    I just ran an SAS scan, n it found some adware tracking cookies(adware yuupsearch,ferret toolbar, which i never installed and is not there on add/remove programmes. SAS detected 80 threats :(
    God I did a re installation of windows with the help of a local tech here but still this malware is not going :(
    After re installation of windows, I installed the necessary softwares but all from good sites
     

    Attached Files:

  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Well, let's start all over again and see what we can find -

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and then attach the requested logs to your next reply when you finish these instructions.
     
  15. telomere

    telomere Private E-2

    Hi Dr.M,
    I did the following steps in read and run me first.
    1. AFT cleaning
    2. TDS Killer-It did not find anything
    3. Dns flush
    4. Uninstalled yahoo and googletoolbar and ask toolbar
    5. Ccleaner.
    6. SuperAntiSpyware
    7. MBAM
    8. Combofix
    9. Rootrepeal-Was Showing “FOPS-Device Io Control Error” .It did not run
    10. MGtools.
    I am attaching the logs here.
    Last time I forgot to uncheck “use this programme option in Windows defender. May be that’s why combofix restarted and was showing blue screen. But this time combofix ran smoothly(I made sure that I disabled all the firewalls,antivirus and antispyware programmes).
    Attaching the logs, kindly go through and let me know if the infections are gone!
     

    Attached Files:

  16. telomere

    telomere Private E-2

    I am attaching the TDSKiller log also here.
     

    Attached Files:

  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *You need to run MSconfig and put your PC into normal startup mode as requested in step 4 of the READ & RUN ME guide.

    Use MSconfig to setup for Normal Startup Mode

    * ComboFix shows you have multiple anti-virus and firewall applications installed:
    You MUST uninstall one of each type application!

    Also - ComboFix reports "- REDUCED FUNCTIONALITY MODE -" indicating that you did not allow it to update when prompted.

    Move MGTools.exe directly onto your desktop, not here:
    C:\Users\admin\Desktop\malware removl\MGtools.exe

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Please run this and attach the results.

    Using ESET's Online Scanner

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file and the ESETscan.txtto your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  18. telomere

    telomere Private E-2

    Hi Dr.M,
    I had no idea that my system was at selective start up. Thats why I dint check my start up mode before. Probably the tech guy who had reinstalled windows made it in selective start up.

    I am from India and regarding the IP, while installing comodo, it was asking whether I want to include some dns protection to block phishing sites and I said yes. That probably changed the IP. I fixed it as you had directed me to do so.

    As for combofix, it did not ask for an update last time, so this time I installed a new combofix again and ran. Before that I uninstalled kaspersky.

    I did run eset scan, It found nothing.
    I ran MGtools.
    Attaching the logs of combofix, eset and MGtools.(log.txt is eset log.)

    I think all the malware things in my system are gone.

    I would run an SAS scan just to make sure everything is OK this time. (I guess downloading the vlc might have reinfected my system. Last time when I downloaded vlc, some shopping reports and click potato was getting downloaded and kaspersky was warning me. So I uninstalled it and again I installed vlc from a secure site. But I guess all the vlc.exe files might be corrupt).

    (I also have a dual boot, so when my windows is in unprotected mode, I use my Linux(Ubuntu) to get on to the internet. I'll enable all protection now as suggested by You. My windows was not happy when I disabled the defender and the firewall.)
     

    Attached Files:

  19. telomere

    telomere Private E-2

    Hi Dr M,

    SAS Found 2 threats and quarantined it. MBAM did not find any.

    Attaching the logs here.
     

    Attached Files:

  20. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    Your logs look good!
    Not something to be concerned with, as you will read about in the last link that I'll give in this reply.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  21. telomere

    telomere Private E-2

    Hello dr.moriarty,
    I have uninstalled combofix.There was no hijackthis in programmes and features.I ran MGclean.bat and mgtools is gone. Did read how to protect your computer from malware .. have downloaded the firewall n antivir before itself.

    Now Thanks sooooooooo much for being sooo patient with me n helping me out DR.M.:)
    Regards, Telo


    P.S.I did sing in private
     
  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're very welcome, telomere.

    :major
     
  23. telomere

    telomere Private E-2

    One more thing Dr.M,
    Avira today found one trojan TR/Crypt.XPACK.Gen and quarantined it. Is there anything to worry about?
     
  24. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The detected infection isn't harmful at this point. Now to investigate!
    • Right click on your Avira AntiVir icon located near your clock at the bottom right of your screen and click on the Admininstration tab
    • Choose "Quarantine" then left click on the file shown in the large pane on the right side to high--light it
    • Now, right click and select from the drop down menu "open quarantine directory"
    • The quarantined file will be shown in the right pane
      • NOTE the filepath to the quarantined file (and it's name ending in ".qua")- it'll show something similiar to
        C: > ProgramData > Avira > AntiVir Desktop > INFECTED >
    • CLOSE both the "INFECTED" file folder and the Avira application window

    Please go to VirusTotal.com and upload the quarantined file pathway for analysis.

    *When the scans complete, you will now have the information needed to determine how the file needs to be dealth with, using Avira:
    • Delete object
    • Restore object to

    COMMENT: Since your machine has been re-formatted, a clean install performed, given the "All Clean" from running our cleaning procedure, but now have concerns about a trojan ...please "Re-examine" your recent activities using your pc. ;)
     
    Last edited: Apr 12, 2011
  25. telomere

    telomere Private E-2

    Lol Dr.M,
    Thanks a lot!( I trust You guys )
    I try downloading movies and songs ,may be that is the reason my system is prone to infection. By the way this trojan I think is from an old software which I downloaded 1-2 years ago.
    I'll upload it in virustotal. I already had gone to avir site and found out about this and it was showing danger level as low.
    Next time I browse n download any movies, I'll make sure I'll do it from my linux so that my windows stays unaffected :)
    Thanks a lot for being so patient and helpful. I tried to close this thread but unable to.


    If you need any assistance, and if I can be of help, definitely I 'll help you!:)
     
  26. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!

    ;) If you followed our recommendations in the "Final Steps", you do have the tools available to scan any downloads for malware before installing them, simply by right-clicking them - you then have the options to scan them with either MBAM or AntiVir.

    *You could even "OPEN" SUPERAntiSpyware > "Scan your computer" > click on "Perform Custom Scan" > tick "Selected Folders" ONLY > choose "Add" > navigate to the folder containing your download > next choose "Close" > then "Next".

    Practice - "Safe... downloading"! LOL
     
  27. telomere

    telomere Private E-2

    Yes Dr.M:),
    I do have the tools to scan and I did that yesterday, after downloading when clicked on installation, avira's luke filewalker(I like that name, just like starwars' luke skywalker :)) gave me a warning that it is a malware and I quarantined it and deleted it. Comodo, Avira, MBAM, SAS all are really good.
    My system is armed with cool safety tools now:cool
     
  28. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please re-read my reply in post #26... scan suspect downloads before attempting their installs. That could keep your blood pressure a little lower.

    :wine
     
  29. telomere

    telomere Private E-2

    LOL..Will follow it (Have actually followed it b4 installation of a software. Scanned it with both sas n mbam.) Thanks:) Good day Dr.M!
     
  30. telomere

    telomere Private E-2

    Hey Dr. M,
    I want to know if ganged or unganged memory is better for my PC. I recently upgraded my RAM. Where do I post it? In hardware forum or in overclocking?
    When I googled for it, I found mixed responses for it. Unable to decide. Before making it ganged wanted to ask the experts which one is better. You are the only person I know in major geeks. :)
     
  31. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :wave

    Your question is outside my specialty, telomere. However, this seems to explain it rather well.
    *I think that you would receive some great advice from the knowledgeable members who post in our Overclocking Forum. Why not also make an introductory thread in our Welcome Centre, then ask for some opinions in your Overclocking thread? Either way, you'll find that friends are easily made here, and there's a wealth of helpful information shared among us!

    Hope to see you around the forums,
    dr.m http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  32. telomere

    telomere Private E-2

    I know You are a malware super sleuth and not an overclock expert :). Was just asking whether to post it in hardware or overclocking forums. Thanks a lot Dr. M, See You around :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds