setthetrend.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by dsiebenh, Feb 18, 2008.

  1. dsiebenh

    dsiebenh Private E-2

    Sad to say I'm a computer professional and this is the first time I've been infected with anything. Popups and new tabs or browser sessions, many to setthetrend.com, fubar.com (org?), antispyware tools.

    From what I've read, setthetrend.com looks nasty. Please point me to the proper procedures for removal. I'm currently running the AVG prodcucts and tried ad-aware as well, with no results.

    Thanks for your help!
     
  2. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

  3. dsiebenh

    dsiebenh Private E-2

    OK Geeks,

    Thanks for your extremely detailed and accurate instructions. I executed all steps in a couple of hours. I have not seen any recurrance of popups but right now I have popups totally blocked in IE.

    I've attached the 3 log files for your review and look forward to your assessment.

    I'm running AVG Antivirus and AntiSpyware right now; I also ran Ad-Aware prior to starting this process. What do you guys recommend as a (hopefully free) suite to run in the future?

    Thanks for assisting me in this!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some leftovers from your Virtumonde (aka Vundo) infection.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {0E0A2AD5-1ADC-4EC3-90FC-0FB793C9259E} - C:\WINDOWS\system32\xxyxwtr.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O20 - Winlogon Notify: xxyxwtr - xxyxwtr.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    DirLook::
    C:\temp
    C:\VXIPNP
     
    File::
    C:\WINDOWS\system32\awvvs.dll
     
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxyxwtr]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DD71C2C9-C019-4F54-81F8-BC81F52FEA69}]
    [HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\Explorer\ShellExecuteHooks]
    "{0E0A2AD5-1ADC-4EC3-90FC-0FB793C9259E}"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. dsiebenh

    dsiebenh Private E-2

    Geek / Chaslang:

    Here you go. All is working normally today, as it was yesterday before you saw some stray stuff still hanging aroung. Attached are the logfiles requested. Please take a look. Thanks again for your help!

    Dave
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless you know what the below file is, I suggest you delete it:

    C:\temp\ext45874\install.exe

    Other than that, your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  7. dsiebenh

    dsiebenh Private E-2

    All I can say is WOW and THANKS! I've been on a lot of forums and you guys are the best. My problem is solved, not thanks to commercially-produced antispyware software, but thanks to the Geeks at MajorGeeks.com.

    Your concern is appreciated, and most of all your assistance is appreciated. Your clear and concise directions and hands-on analysis of my problem were the only things that could have saved me, and you did it!

    Now if you can point me to somewhere I can make a donation to majorgeeks.com, I'll do so. I can't find a Donate button anywhere.

    Thanks again and keep up the good work.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad we could help. And thanks for the cudos. :)

    We don't have one. You can send an email letter of appreciation for hosting these forums to the owners. They appreciate happy emails. ;) You can find their addresses on the www.majorgeeks.com main page in the right column under the About link or just click this: About Look under the cartoon pictures of their alter egos. :)

    You could also purchase Geek-Wear if you like (also on the main page).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds