Pesky Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by keith466, Jun 12, 2007.

  1. keith466

    keith466 Private E-2

    Hello,

    I am running a 1.6 GHz Toshiba laptop with Windows XP (SP 2). My anti-virus and anti-spyware package is provided by Adelphia, the ISP, which had been showing the "Banker" trojan. I upgraded to the MacAfee AV suite, but it
    has solved helped the trojan problem.

    I ran the full set of diagnostics in the "Run & Read Me First" guide (logs attached) with several spyware and trojan indicated on my system. The only sympton I can see is a recurring "joke of the day" popup when I'm using IE, but I am concerned about the privacy trojans.

    Can you help me clean out the system?

    Thanks,

    Keith
     

    Attached Files:

  2. keith466

    keith466 Private E-2

    And here are the final three logs. Thanks!
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not attach the other logs in your last reply ....which we need to help you.
     
  4. keith466

    keith466 Private E-2

    Tim,

    Sorry about the missing attachments. Let's try again.

    Thanks,

    Keith
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You ran AVGAntispyware and neglected to have it fix what it found.
    Please run it again!

    Please use add/remove programs to uninstall:
    Viewpoint Media Player
    J2SE Runtime Environment 5.0 Update
    Re-boot and install:
    Java Runtime 6

    Do you know what these are:
    C:\stdtsa ----->?
    C:\14290921.exe ---->?
    C:\399x.exe---->?
    If not, delete then along with:
    C:\Program Files\Ofb11

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt


    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
    * Avenger

    Be sure to tell us how things are running.
     
  6. keith466

    keith466 Private E-2

    Tim,

    Ran the procedures as you directed. After running AVG I found that several items originally identified by HJT had "disappeared;" the O2 class objects and the O4 object weren't there any more.

    The only other odd thing I'm finding is that my IE settings no longer allow me to log into my www.iwon.com email site. It tells me that I have a Javascript and/or cookies restriction in place, although I have gone into the privacy tab and am allowing all cookies and, on the security tab, have gone through all four zones and enabled Java scripting. Outside of this everything appears to be running normally.



    Here are the requested logs, # 1-3.
     

    Attached Files:

  7. keith466

    keith466 Private E-2

    Here is the final Avenger log.

    Keith
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    IEFix:
    http://www.majorgeeks.com/download4467.html

    If that doesn't help try the Mcrepair Tool below.

    http://download.microsoft.com/download/msninvestor/patch/1.0/win98/en-us/mcrepair.exe

    Just download and run it. Be sure to answer "yes" to everything, that's important. When it's done restart your computer.


    Now ...do you use the Vradio toolbar?
    If not use add/remove to uninstall:
    Virgin Radio Toolbar 4.0.0.20

    Then run HJT and have it fix:
    O2 - BHO: VRadioBar BHO - {5A074B21-F830-49de-A31B-610C4B5FACA7} - C:\Program Files\VRadioBar\bar\bin\askBar_VirginRadio.dll
    O3 - Toolbar: Virgin Radio - {5A074B29-F830-49de-A31B-610C4B5FACA7} - C:\Program Files\VRadioBar\bar\bin\askBar_VirginRadio.dll
    O8 - Extra context menu item: &Save Image to Folder - res://C:\Program Files\VRadioBar\bar\bin\askBar_VirginRadio.dll/saveimagestofolder.html G
    O8 - Extra context menu item: &Save Image to MyStuff - res://C:\Program Files\VRadioBar\bar\bin\askBar_VirginRadio.dll/saveimages.html G
    O8 - Extra context menu item: &Save Link to Folder - res://C:\Program Files\VRadioBar\bar\bin\askBar_VirginRadio.dll/saveltof.html G
    O8 - Extra context menu item: &Save Link to MyStuff - res://C:\Program Files\VRadioBar\bar\bin\askBar_VirginRadio.dll/savelink.html G
    O8 - Extra context menu item: &Save Page to Folder... - res://C:\Program Files\VRadioBar\bar\bin\askBar_VirginRadio.dll/savepagetofolder.html G
    O8 - Extra context menu item: &Save this Page to MyStuff - res://C:\Program Files\VRadioBar\bar\bin\askBar_VirginRadio.dll/savewebpage.html


    Do you know what these are?
    O23 - Service: WPEServ - Unknown owner - C:\Program Files\Common Files\WPE\wpeserv.exe?
    C:\Documents and Settings\Keith\Application Data\.rdr.ini?


    You will need to do a reg edit to remove the rest of the VRadio --->
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Otherwise you look good.
    Tell me what is happening after the above is answered.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds