PSWBanker

Discussion in 'Malware Help (A Specialist Will Reply)' started by gottlieb, Jan 5, 2008.

  1. gottlieb

    gottlieb Private E-2

    Has anyone seen this malware? There is very little about it on the web. I have it on my system and my cox security suite cannot remove it. Here is the description: "Type of spyware: Emailer
    Description: PSWBanker attempts to capture logins and passwords related to financial institutions. Once PSWBanker has collected logins and passwords it connects to a Google SMTP server and attempts to return collected data to its controller and further spread itself through mass emailing.
    Threat: ELEVATED

    Spyware Pieces:
    HKEY_CURRENT_USER\software\microsoft\ms setup (acme)"
    I have manually deleted the registry entry but it returns with a reboot.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    Many malwares have various guises, so best way to see whats going on is to run the below and attach the requested logs so our malware experts can diagnose and issue you some cleanup steps.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. gottlieb

    gottlieb Private E-2

    The key is still present in the registry. I have performed all the steps and no malware was found. There was no log generated by AVG Anti-spyware. I am attaching the combofix.txt, mglogs.zip
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a valid registry key. You should not be touching it and neither should your Cox Security Software which is wrong.


    Your logs are clean but I do have a few things you should do as given below. Some are necessary updates and security issues and some are for performance improvements.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: Cox Popup Blocker - {2C0A5F28-48D8-408B-9172-9C6121025BCE} - (no file)
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O9 - Extra button: Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta (file missing)
    O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta (file missing)
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -

    After clicking Fix, exit HJT.
     
  5. gottlieb

    gottlieb Private E-2

    thank you very much for spending your time on this. I will leave that registry key alone......that's why it keeps coming back after a reboot! Is there such a thing as the PSWBanker? I wonder why Cox is picking it up. It doesn't on my laptop where it is also installed.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    Does that same registry key exist on your laptop? Have you checked?
     
  7. gottlieb

    gottlieb Private E-2

    I will check my laptop. From your investigation, am I correct in saying that you did not find any evidence of PSWBanker on my system?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is correct! You should check to see if Cox Security is giving more information. Perhaps they believe they are finding something under the registry key. What you gave is just the main key. There are values and subkeys under the HKEY_CURRENT_USER\software\microsoft\ms setup (acme) too. Is it complaing about only the main key or something under it?

    Typically this key will look like the below when exported to a file:
     
  9. gottlieb

    gottlieb Private E-2

    Yes the key is on my laptop. I tried exporting the key to a file but the info on the right side of the screen is not included. Here's what it says:
    Name: ab Default Type: Reg-sz Data: (value not set)
    I just ran Cox Security Suite on my laptop: NO PSWBanker!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should run a full scan and save a proper log and attach it here. That is assuming their software has the ability to create proper and useful logs.

    To export a the registry key so you can see information like I posted, you would:
    • use the Registry Editor to navigate to HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)
    • then click File, Export, and save the information to a file.
    You could then either put the resultant .reg file into a ZIP file to attach it here or you could rename the .reg file to have a .txt extension which can be directly attached. If you do this on both PCs we could easily look at them to see if there is any difference.
     
  11. gottlieb

    gottlieb Private E-2

    Cox does not have any logs at all. I checked the keys in both registries and have attached them as laptoppsw and desktoppsw as txt files
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess Cox is a poor excuse for a security program. They may have even deleted part of the registry key entries. Let's fix them and see what happens. We will make your Desktop exactly the same as your laptop.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  13. gottlieb

    gottlieb Private E-2

    That was successfully done. Reboots fine. Cox still says I have PSWBanker:cry
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are wrong. You even see it on your other PC and it is not detected as a problem so i'm not sure what they are detecting but this registry key is not PSWBanker. You can either ignore it or you can get a better set of protection tools.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds