She's Gonna Blow..... Please help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by abern01, Apr 21, 2006.

  1. abern01

    abern01 Private First Class

    So last night my wife finally comes to me and says: "Honey, I think my computer has a problem?" That was an understatement!

    Windows XP Home SP2
    AMD Xp 2000+
    756 MB DDR Ram
    40 GB HD

    AVG (updates usually current)
    Ad-Aware SE Pro (updates usually current)
    SpyBot (updates usually current)

    I have completed the "RUN & READ ME FIRST Before Asking For Support" and the computer is in worse shape than I expected

    She started complaining about pop ups, pages crashing, etc. I ran AVG, HouseCall (Trend Micro), Symantec, Ad-Aware SE Pro, and Spybot. The main culprit appeared to be "E2Give". It just kept popping up and nothing could get rid of it. There was also a Trojan that AVG found PSW.Generic.XAO. After numerous hours of futile efforts I realized I'm out of my league; so here I am.

    -started in safe mode
    -disconnected cable
    -ran CCLEANER
    -ran MS Windows Malicious Software Removal
    -ran Ad-Aware: it found 20 critical objects (E2Give & Prutect) -removed them.
    -ran Spybot: it found 10 problems (9 E2G in registry, 1 in Dir) - failed to remove item from Dir.
    -ran Windows Defender: full scan
    -ran Bitdefender: it found a bunch of Trojans - couldn't clean everything
    -ran Panda ActiveScan: it also found a bunch of Trojans
    -rebooted in normal startup and ran Hijack This

    After it rebooted, I kept getting error messages in Japanese saying certain files couldn't be found in "C". Then it said it couldn't find "C" drive.

    I've attached: Hijack This log, Panda ActiveScan report, Bitdefender report and Ad-Aware log.
    I would be most appreciative if someone could please help. Thank you :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First goto Add/Remove programs and uninstall Viewpoint Manager

    You also need to uninstall this old Sun Java version 5.0 Update 2
    You already have version 5.0 Update 6 installed and do not need the older versions.

    You should delete the below Inbox emails manually yourself:
    Local Folders\Inbox\HSBC bank: PIease Confirm Your Banking Details\~0000001.~
    Local Folders\Inbox\Verify your data with Washington Mutual [Sat,27 Nov 2004 11:21:13 +0200]\~0000001.~


    Note to anyone else reading this thread: The below procedure was specifically created for this user. It is not a generic fix to be used by everyone. If you are not this user, you MUST NOT use this fix on your PC or you could cause damage to your PC.
    • Please download The Avenger by Swandog46 to your Desktop.
    • Double click on Avenger.zip to open the file and extract avenger.exe to your Desktop
    • Copy the below quoted text (which is a script for Avenger) into your clipboard by highlighting it and pressing CTRL+C
    • Now, run The Avenger program by double clicking its icon on your Desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    The Avenger will automatically do the following:
    • It will Restart your computer. (When the script being executed contains "Drivers to Unload", The Avenger will actually reboot your system two times.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the reboot, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    Please attach the c:\avenger.txt file to your next message. Now continue with the below fixes!


    Copy the bold text below to notepad. Save it as fixE2G.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    F2 - REG:system.ini: Shell=
    F3 - REG:win.ini: load=??? ??? ??? ? ? ?????
    O1 - Hosts: 203.161.127.141 www.dcsresearch.com
    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O15 - Trusted Zone: *.mmohsix.com
    O20 - AppInit_DLLs: iniwin32.dll

    After clicking Fix, exit HJT.:

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot your PC (in normal mode) and post a new HJT log.

    Make sure you tell me how things are working now.
     
    Last edited: Apr 22, 2006
  3. abern01

    abern01 Private First Class

    CHASLANG: Thank you, thank you, thank you!!!! I don't care what they say about you...you are THE BEST. LOL

    I followed your instructions and it appears as if we are finally free of that E2G pest and it's associated Trojans. We stayed up till 2:00 AM three nights in a row working on this. Your solution cured it in 90 minutes.

    I've attached logs from the latest HJT.

    Thanks again for all your help. For anyone else reading his that has a similar problem...just follow the instructions EXACTLY and everything will be as good as new! :D
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! I have since made generic solution sticky thread to fix this E2Give issue for everyone.

    You now have two antivirus applications installed. AVG and Bitdefender. You did not have this before. Uninstall one of them.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds