savetheinformation and sec toolbar virus???

Discussion in 'Malware Help (A Specialist Will Reply)' started by klyphud, Nov 25, 2007.

  1. klyphud

    klyphud Private E-2

    Have this darn security toolbar and savetheinformation virus. This is driving me nuts. Have just started using firefox due to this bloody virus shutting all ie windows when i go to another page thats not savetheinformation. Need to know what to do please guys and gals. HJT log is attached. Dunno if its the right type or what, but am willing to do whatever it takes. Cheers. Roy.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. klyphud

    klyphud Private E-2

    Have done most of what was advised. Avg doesnt seem to want to make a bloody log file. Please ignore the HJT log, as it was the on I did b4 the read and run. Sorry.
     

    Attached Files:

  4. klyphud

    klyphud Private E-2

    Hope I have attached the correct files..... Cheers again. Roy.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you were supposed to do was attach the AVG Antispyware log, combofix log and the MGlogs.zip file as requested. You should not be attach the logs individually which is a lot more work that is necessary.

    Please attach the C:\MGlogs.zip file now since you did not attach the log from GetRunKey which is named runkeys.txt

    ALSO the instructions specifically stated that MGtools.exe must be put in your root folder. You put it here;

    C:\Documents and Settings\woounklyph\Desktop\New Folder (4)\MGtools.exe

    This is not exceptable. You must follow the instructions to avoid having problems.
     
    Last edited: Nov 26, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I going to post a fix even though the runkeys.txt log was missing. Please make sure you post the logs that are requested at the end of this procedure.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 2

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Program Files\ContextTool\ContextTool-2.dll (file missing)
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\odavnomv.dll
    O2 - BHO: {762c21b1-ee45-0398-1e04-4d1a2a4209ae} - {ea9024a2-a1d4-40e1-8930-54ee1b12c267} - C:\WINDOWS\system32\bjwnwgqi.dll
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\odavnomv.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [a4ca20d4] rundll32.exe "C:\WINDOWS\system32\jfbnujqr.dll",b
    O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4306] command /c del "C:\WINDOWS\system32\odavnomv.dllbox"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC469] cmd /c del "C:\WINDOWS\system32\odavnomv.dllbox"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7377] command /c del "C:\WINDOWS\system32\odavnomv.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6632] cmd /c del "C:\WINDOWS\system32\odavnomv.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA222] command /c del "C:\WINDOWS\system32\odavnomv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5578] cmd /c del "C:\WINDOWS\system32\odavnomv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7673] command /c del "C:\WINDOWS\system32\odavnomv.dllbox"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8721] cmd /c del "C:\WINDOWS\system32\odavnomv.dllbox"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7837] command /c del "C:\WINDOWS\system32\odavnomv.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2755] cmd /c del "C:\WINDOWS\system32\odavnomv.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6323] command /c del "C:\WINDOWS\system32\odavnomv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1145] cmd /c del "C:\WINDOWS\system32\odavnomv.dll"
    O20 - Winlogon Notify: odavnomv - C:\WINDOWS\SYSTEM32\odavnomv.dll

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now delete all the icoxx.tmp files (where xx is any number) that are in the below folder:
    C:\Documents and Settings\woounklyph\Local Settings\Temp

    Now run Ccleaner!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.


    Make sure you tell me how things are working now!
     
  7. klyphud

    klyphud Private E-2

    Hope I have done it right this time.
     

    Attached Files:

  8. klyphud

    klyphud Private E-2

    :hyper You absolute legend. Looks like we got it. Mostly you of course. Thanks so very much.
     
  9. klyphud

    klyphud Private E-2

    sorry forgot the avenger log
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We have a little more to do.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\odavnomv.dll (file missing)
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\odavnomv.dll (file missing)
    O20 - Winlogon Notify: odavnomv - odavnomv.dll (file missing)

    After clicking Fix, exit HJT.

    Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
    Last edited: Nov 26, 2007
  11. klyphud

    klyphud Private E-2

    Thank you once again. Here's hoping thats it hey? Roy
     

    Attached Files:

  12. klyphud

    klyphud Private E-2

    Just wondering if it looks ok to you??? Its behaving heaps better and everything seems to be back to normal. Thank you very, very much.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Be careful posting unnecessary messages which are considered bumps. It causes you more delay in getting an answer. This message cost you about 12 hours. See this sticky: Don't Bump! It Only Hurts You!!! The best thing to do is post whatever is requested and then just wait until we ge back to you as we work thru the queues.

    While Avenger said it deleted the C:\WINDOWS\system32\drivers\cvx^rwoy.sys file, it still shows in your newfiles.txt log. See if you can locate this file and delete it yourself. Try safe mode if necessary. Let me know what happens. It is possible that this file is truly loading as a driver and you may not be able to delete it so easily.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed something else I want to ask you about before I head off to bed.

    What is in the below file?

    C:\WINDOWS\system32\brss01a.ini

    You can either view it in notepad and then copy and paste here or you can put it into a ZIP file and attach it.
     
  15. klyphud

    klyphud Private E-2

    Twas this....

    [DEBUG]
    LOGFILE=
    PASSWORD=
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay delete the C:\WINDOWS\system32\brss01a.ini file too but what about the other file? Did it delete? Did it come back after a reboot?
     
  17. klyphud

    klyphud Private E-2


    deleted the .ini and the other file didnt come back following a reboot. Cheers once again and sweet dreams.:D
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds