Pest Trap

Discussion in 'Malware Help (A Specialist Will Reply)' started by skd44, Feb 8, 2006.

  1. skd44

    skd44 Private First Class

    I recently had written you guys about trouble I was having with Spyware Strike and a few other malware and spyware problems. I followed all of your advice and thanks to you guys the problems were fixed. I just have been infected with a new problem called Pest Trap. It has made my computer slower and has caused my machine to lock up a few times. I did what I always do when I have a problem, I ran the Read and Run me first steps that I always do before posting or asking for help. It seems to have no effect and the virus seems to be slowing the computer down evern more. I was wondering what I might do and if I should run the steps in the running hijack this thread. Let me know what I should do and as always, thank god you guys are here.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete ALL steps in the READ ME. That includes step 6 and attaching the two requested logs and then complete step 7 and attach the HJT log.
     
  3. skd44

    skd44 Private First Class

    OK, I was having trouble running step 6 but I will start all over and run all the steps again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The steps are meant to be run from beginning to end without interruption. If you have just completed (within the last couple days) steps 0 to 5, then just do steps 6 & 7. If it was longer ago then a couple days, yes start over again.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. skd44

    skd44 Private First Class

    I apologize for the delay in response, I haven't been able to get online for the past few days, we had a problem with our ISP. In response, I ran the steps in my last thread that you provided and my computer resumed working without any problems but I do see that I forgot to do everything that you told me, hence I guess I did not remove everything and do everything that you asked, and I apologize for that. Should I go back and do all you said to do in my spyaxe thread instead of doing what you stated to do in this thread? I am extremely sorry for the inconvenience as you guys have been such a great help to me and I have learned alot from this site, but I know I need to follow through on all your steps and recommendations.
     
  7. skd44

    skd44 Private First Class

    I also wanted to let you know that in running spybot the last few times I have run it, the same 3 things keep coming up even after I have them fixed. They are as follows:
    Windows Security Center.AntivirusDisableNotify 1 Entries
    Windows Security Center.FirewallDisableNotify 1 Entries
    Windows Active Desktop 1 Entries
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete what I gave you in the previous thread just in case any of it still applies. However since you waited so long to continue working on the problems you need to run the READ & RUN ME sticky again from beginning to end too. It has been almost a month since my last post in that thread. A lot can happen in a month. You must work thru all steps and you must do exactly what we instruct you to do without skipping any steps. You must also complete the steps in a timely manner. If you do not complete them quickly, you are just wasting your time and ours.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are not problems. They are informational only. The just let you know you have changed from the Windows system defaults. This occurs when you use an application (like McAfee, Symantec, etc) to control all of your system security.
     
  10. skd44

    skd44 Private First Class

    I have not been on my computer in over a week as I live in New York and my cable and cable modem were knocked out of service during the bad snow storm we had last sunday, so I have no surfed or done anything since your last post to me. I have run the steps in the read and run me first and I continue to see smitfraud, pest trap, and now spyware strike in my search and destroy results. I realize that it is now a week after your last post but I have not used the computer since then and have not done anything, although my machine was off due to power loss and the cable being out. I began the read me and run first steps last night and finished this morning. I am not able to shut system restore off nor am I able to open mutliple pages on my IE as every time I do the error report message comes up and my IE closes. I was wondering how I should proceed. If I do not provide a response quickly it is not due to a lack of action but my internet and cable problems have not been fixed completely as we are still having problems. I have someone coming tomorrow to fix it completely, so if I do not respond promptly, that is the reason.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete what I gave you in message number 2. Until you have done that, you have not completed the READ & RUN ME and there is nothing I can do to help you without this information.

    Also note, step 1 of the READ ME does not tell you to disable system restore right now. It is informing you that when cleanup of malware is completed, you will then need to toggle system restore to flush bad restore points.
     
  12. skd44

    skd44 Private First Class

    I have run all the steps in the read me up until I am supposed to run bitdefender. I begin using it and as the scan progresses the time remaining goes from a little more than an hour when it starts to over 70 hours after it has only scanned 1000 of over 40000 files and the time just keeps getting longer as it progresses. I am not sure if this is normal as it doesn't seem that it should take so long. Is this normal???
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What kind of connection do you have to the internet (dial-up, cable, DSL)?

    It does take a long time to run the scans but not normally 70 hours.

    Skip both BitDefender and PandaActiveScan and run the below procedure instead. Make sure you attach the Spy Sweeper log later.

    Running Spy Sweeper
     
  14. skd44

    skd44 Private First Class

    I have a cable connection, so thats why I was so surprised that it said it would take that long for bitdefender to run, but I guess the viruses have also affected the speed of my machine. I have run into another problem. I downloaded and ran spysweeper but there is no option to remove what it found and there is no option to save the log on the version I downloaded. It says I have to purchase the actual program to do any of that. It aalso does not allow me to copy the session log.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to download Spy Sweeper from the link given in the thread. Then there will be an option to remove the problems.
     
  16. skd44

    skd44 Private First Class

    I downloaded it again from the link in the thread and again ran it but again it is only the scan version of the program. I went onto the site homepage and downloaded it again from the main homepage and again it says its only the scan version and I am unable to delete what it finds and there is no option to copy the log session. My machine is really starting to have some problems. I can't open more than one page at once, as soon as another link opens the IE error message stating that it must shut down comes up and then the send error report message keeps coming up.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you at some other time had SpySweeper install on this PC? If so, your 15 day trial has already ended. That's the only thing I can think of that will cause this. Downloading from their website is not what you want to do because that version is a scan only version. Is that what you did the very first time or did you download it from the link I gave you the first time.

    Depending on your answers to the above, one last thing with SpySweeper could be tried. Uninstall what you have now then Reboot your PC and after reboot delete the C:\Program Files\Webroot folder (or whereever you installed it, delete that folder). Then reinstall but make sure you are use the file from the download link in the thread I gave to you. The installation file name should be SpySweeperTrialSetup_EN-MajorGeeks.exe

    Now see if it can scan and clean. If not then uninstall it and leave it uninstalled and try the below tool instead (hopefully you have not installed it before):

    Running Ewido Anti-Malware

    Attach the log from Ewido and then move on to step 7 of the READ & RUN ME.
     
    Last edited: Feb 21, 2006
  18. skd44

    skd44 Private First Class

    I have had spysweeper on my machine before but it was a paid version that I purchased in the store. I sent them an email and they said that my subscription was only good for one year and I no longer have the disk to reinstall it on my machine, as I took the program off last year due to some problems it was giving me. I tried using different email addresses for the trial version but it will not allow me to do so as it still gives me just the scan version. I also tried Ewido and I had the same problem this time that I had a few months back when you told me to use it. I select the options you recommend in the ewido thread and begin running it. The scan starts and then stops right after the scan completes about 20% of scanning. It stops at 20.8%, 20.5%, 20.6% and never gets any further. This occurs at about 4 mintues in and no matter how many times I try, it won't make it past 20% completion.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you running Ewido in safe mode or normal mode? Try both boot modes!

    Did you ever finish the instructions I gave you in your old thread?

    Attach a current HJT log?
     
  20. skd44

    skd44 Private First Class

    I only tried it in safe mode, but I will try it now in normal mode. I ran all the steps you told me to run in the spyaxe thread, which I believe is the last time I asked for help before this pest trap problem, but I know you said that if I had not finished those steps in a timely manner that it would have not done any good. I will try ewido in normal mode now and then if it works post both the ewido and hjt logs. I apologize that I did not finish everything last time as I know you said it is just a waste of both of our times and you guys have been such a great help to me whenever I have asked. I am sorry for any inconvenience I might have caused.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's get an installed programs list from HijackThis too!

    Run HijackThis, click Open the Misc Tools section
    Click Open Uninstall Manager
    Click Save List (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment too.
     
  22. skd44

    skd44 Private First Class

    I tried running ewido in normal mode and are running into the same problem I was in safe mode, except now it only makes it to 18% completion. I know in my previous thread that you were talking about before that part of my problem was I never have run the updates to my computer that microsoft provides us with for free, and my laptop is several years old so things like service pack 2 and all the security updates have not been added. I ran the steps you recommended last time like smitrem and getrunkey and provided those logs to you last month, but I know that is ancient by now. I will provide you with both requested hjt logs as soon as I can.
     
  23. skd44

    skd44 Private First Class

    here are my logs.
     
  24. skd44

    skd44 Private First Class

    My computer won't let me attach the logs. Every time I try and upload the internet explorer message that states IE has encountered a problem and must shut down keeps coming up as soon as I hit upload on the manage attachments screen. My message made it through the last time as you can see below this reply but there is nothing attached. It keeps saying download in progress and then that IE message pops up and both windows shut and I have to come back on and try again but the same thing keeps happening.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post your log inline this time and I will convert it but you should do the below to see if it will help:

    Use Mozilla FireFox in place of Internet Explorer.
     
  26. skd44

    skd44 Private First Class

    here are the logs. It looks as if firefox will help and work.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure you have uninstalled Spy Sweeper if any of it is left around.

    For now we will leave Ewido install in hopes that we can get it to run.

    Your version or SpywareBlaster is old. You should uninstall it and download and install the latest version from: SpyWare Blaster

    Goto Add/Remove programs and uninstall the below too.

    PartyPoker
    PartyPoker.net
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    I need to finish looking at your HJT log. Tell me when you complete the above.
     
  28. skd44

    skd44 Private First Class

    Okay, I removed all the programs that you said to remove and I also uninstalled the old version of spyware blaster and downloaded the one you put a link for. I also searched my computer for any leftover spysweeper files and found 3 files that said they were prefetch files and I deleted those also so there are no traces of spysweeper left.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing what is in my last message continue here.

    Run the steps in the below link:

    Virtumonde aka Trojan Vundo Removal

    Make sure you attacht the log from the above.


    Now make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:80
    R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
    O2 - BHO: (no name) - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - (no file)
    O2 - BHO: (no name) - {B060F203-E035-4C8D-B6CD-C67B2B810723} - (no file)
    O2 - BHO: MFCOptimizeClass Object - {C25FA7CE-23EA-4271-A66D-06C4D5C22F78} - C:\WINDOWS\System32\efeda.dll
    O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
    O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/1814171a99ecb3bb9006/netzip/RdxIE601.cab
    O20 - Winlogon Notify: dvd4free - dvd4free.dll (file missing)
    O20 - Winlogon Notify: efeda - C:\WINDOWS\System32\efeda.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if still found):
    C:\Program Files\PartyPoker <--- The whole folder
    C:\WINDOWS\System32\efeda.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  30. skd44

    skd44 Private First Class

    I have to go to work, can I leave my machine on like this and finish when I come back or should I bring my laptop to work and try and work on it?
     
  31. skd44

    skd44 Private First Class

    here is the vundo log
     

    Attached Files:

  32. skd44

    skd44 Private First Class

    Here is my most current hjt log after I followed all your steps in safe mode. There were two lines that you told me to remove after I ran HJT that did not show up when I ran it. The two lines were:
    02-BHO MFCOptimizeClass-Object
    020-Winlogon Notify: efeda
    I don't know if thats a problem. The computer seems to be better so far as I was able to upload the hjt log without any error message as I am using IE now, not Firefox.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem! The HJT steps were just a backup in case Vundofix did not get them.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link (the first step in the below is Windows Update). You need to do ALL of these steps ASAP:

    How to Protect yourself from malware!
     
  34. skd44

    skd44 Private First Class

    I disabled and enabled system restore. I left my computer on since the last step for about 4hrs but have not done anything. I am now going to run the steps in the How to Protect Yourself from Malware thread.
     
  35. skd44

    skd44 Private First Class

    I have a question about firewalls. I completed downloading service pack 2 and restarted my machine. When I did this a message came up from windows security center saying the my firewall is off and it gave me an option to enable the firewall for all network connections. I chose to enable it and a message came up that said I will have to manually enable it myself by going into control panel and enabling the windows firewall. When I went into the control panel and windows firewall I am also not able to enable it from there. There is an option to turn it on and one to turn it off and the off option is checked but both options are light grey and I am unable to change them. How can I fix this or is there another way to get or enable a firewall for my computer.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read step 3 in the How to protect thread. You do not want Windows firewall enabled. It does not provide adequate protection. You need one of the tools mentioned in step 3 to be your firewall.
     
  37. skd44

    skd44 Private First Class

    sorry about that, I hadn't moved down that far in the thread to notice that, I was trying not to get ahead of myself. Thanks again. I'm continuing on.
     
  38. skd44

    skd44 Private First Class

    I see that in step 7 of the how to protect your computer from malware you suggest that we use mozilla instead of internet explorer. I know we don't have to do this but if we do use mozilla instead how can I get my outlook express and all of that tool bars I use on IE on mozilla, or is this not possible?
     
  39. skd44

    skd44 Private First Class

    I have a quick question regarding the AVG antivirus program, which is the one I chose to use. It scans and picks up some trojans and viruses present on the computer but I do not see any options to remove or fix these trojans. ARe you familiar with this program and if so would you know how I should proceed?
     
  40. skd44

    skd44 Private First Class

    I have one more question regarding AVG and Zone Alarm, the antivirus program and the firewall that I chose to install. Both of them have been scanning my emails and have not been allowing my outlook express to open. I have tried everything, including entering my username and password for my email and yet both programs say they are scanning outlook express and then an error occurs and I can't get my mail. Should I uninstall both and try using the other suggested antivirus and firewall programs on the how to prevent malware thread?
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to allow Outlook Express access to the internet thru your firewall. You probably blocked it when ZoneAlarm first popped up about it.

    AVG should have an option to repair/fix normal this is the default. I have not used the free version recently. It could be that you just need to register with them via email to get the free version properly activated.

    As far as FireFox and toolbars.....check the Software Forum to see what can be done. There are lots of addons for FireFox. I don't use addons or any toolbars. I personally see no need for them and don't like the impact they all have on PC performance.
     
  42. skd44

    skd44 Private First Class

    I am mainly experiencing problems with my outlook express. I can't seem to view any photos or any pictures that are cotained in my emails the I have received.........there is the little box with the red x through it in place of where photos, maps on my readreceipts, or mapquest maps would normally be. I don't know if installing these components changed some of my preferences or settings but I am afraid to try and make more changes as I don't know what the affects will be. I will try plugging away at the problems myself but any suggestions would be appreciated.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is a setting in Outlook Express itself! You need to change the Security settings to allow viewing of attachments. Take a look at the below and see if it helps you:

    http://www.updatexp.com/blocked-outlook-express-attachments.html
     
  44. skd44

    skd44 Private First Class

    Thanks again, I know some of my questions are probably quite assanine and maybe self explanatory but I am just trying to protect myself from malware the best way possible while trying to maintain my settings and machine as they were pre-infection.
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Is everything working okay now?
     
  46. skd44

    skd44 Private First Class

    Everything seems to be working fine, I am just trying to work through a couple of kinks that seem to have occurred after installing zone alert and avg but other than that things seem fine. The only thing I am a little unsure of is my computer keeps making noise like its trying to run something or like something is running or trying to open except I am not working on anything nor trying to open anything. Usually when I am idle the computer is silent and it hasn't been silent at all..........could that be the firewall running or something?
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The spyware protection tools and ZoneAlarm could be monitoring possible attempts (incoming or out going) and just blocking them. It is possible that is what you are noticing. You could check what you observe in safe mode and also in normal boot mode with your cable to the internet disconnected. You could also shutdown ZoneAlarm while the cable is unplug and see what happens.
     
  48. skd44

    skd44 Private First Class

    Okay, as I said, everything seems to be working fine so I may just be making a mountain out of an ant hole but I will try what you said and see what happens. I have also been tinkering with the settings on zone alarm and avg and things seem to be improving with my outlook express. I had to shut off the email scanning on both of those programs so I can receive my email and I read and ran the steps in the outlook express thread you gave me last night and are now receiving my msgs ok. Again, thank you very much and I will keep you up to date on my progress.
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds