The retnsrp toolbar

Discussion in 'Malware Help (A Specialist Will Reply)' started by IanC2, Dec 13, 2007.

  1. IanC2

    IanC2 Private E-2

    Hi

    My PC seems to have become infected with malware. In particular, Internet Explorer has acquired a new toolbar, called "The retnsrp".

    I've followed all the instructions posted for initial cleaning procedures, but the offending toolbar is still in evidence.

    For some reason I wasn't able to save a report the first time I ran AVG and applied the actions, so I ran it again. All logs are attached.

    Any suggestions as to what I need to do next? Thanks for your help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: OFK System - {2F0D1D4D-3B73-4426-8155-4494A3543703} - C:\WINDOWS\blopenvdol.dll
    O3 - Toolbar: The retnsrp - {39623167-B4A7-42CA-A799-D03C5A103B36} - C:\WINDOWS\retnsrp.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O21 - SSODL: leorop - {487C826D-B703-4A23-B02F-509A479B905D} - C:\WINDOWS\leorop.dll (file missing)
    O21 - SSODL: nopzet - {724050BA-3B33-4A9E-BEC4-0ACB2B3A506E} - C:\WINDOWS\nopzet.dll

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
    Last edited by a moderator: Dec 13, 2007
  3. IanC2

    IanC2 Private E-2

    Hi

    Thanks for your help. I followed your instructions and have attached the MGlogs. When I ran Avenger I got a message saying avenger.txt couldn't be located, and it didn't create the avenger.txt file.

    The retnsrp toolbar has gone now, and Internet Explorer seems to be running as normal. Do I need to do anything else?
     

    Attached Files:

  4. IanC2

    IanC2 Private E-2

    Since I posted that last message I've been getting popups inviting me to download AdwareRemover2007, and Symantec AntiVirus has been catching some downloaders that have been attempting to run.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the previous procedure again and this time make sure you extract Avenger.exe to your Desktop as requested. Based on your logs, it was not on your Desktop. You only put the Avenger.zip file there but the instructions said to extract the avenger.exe to your Desktop. You cannot run avenger.exe from inside of the ZIP file. You must extract the EXE file to your Desktop.
     
  6. IanC2

    IanC2 Private E-2

    I'm pretty sure Avenger.exe was extracted to the desktop when I ran it before, as the file is still there.

    Anyway I've run the instructions again, but this time logged on as Administrator (although my own account does have admin rights), and that seems to have done the trick. I've attached the logs. The popups and downloaders seem to have stopped (so far)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the files were deleted according to your logs but I cannot tell if your account had everything in the HJT log and registry properly fixed because you attached the MGlogs.zip file for the Administator account not yours. The Administrator account logs are clean, but that does not mean yours are. You need to attach a new MGlogs.zip file from your account.
     
  8. IanC2

    IanC2 Private E-2

    Here's the log from my account. Hope it's all OK!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean too. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  10. IanC2

    IanC2 Private E-2

    That's great - all seems fine now. Thanks a lot for your help.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds