Trogen HorsePSW Banker Q.........

Discussion in 'Malware Help (A Specialist Will Reply)' started by boneyeye, Feb 20, 2007.

  1. boneyeye

    boneyeye Corporal

    Hi, Does anyone know anything about this as I surf safely. Computer clean now with the good help of your"stickeys" Quarentied and deleted. As I do some banking on the net. I would like to know where and how this comes in.
    Specs.Wins XP2 Home Ed. IE6, AVG Free Virus Scanner, Zone Alarm Firewall, SpywareGuard, On Guard, Weekly maintainance and cleaning schedule, with CCleaner, Adware, Spybot, 2mthly schedule with, Defrag, RegSeeker, Checkdsk. All program versions and definitions up to date. Thank You very much.

    Boneyeye
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How do you know you are totally clean? Do you know how to interprete everything shown in the logs from GetRunKey, ShowNew, and HijackThis? The only way we could say that you are clean is by us seeing all of the logs.

    As far as that Trojan is concerned, I would also like to see the log reporting it and what files were cleaned up. If you had that infection, your first step needs to be the below:

    You second step need to be running the complete READ & RUN ME and attach all 6 requested logs so we can verify that you are clean.
     
  3. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    TY for answering. Did as you advised. Avg picked it up and quarentined it . Then I deleted it. Please bear with me as I am a Senior Citizen and we do have our senior moments. 3logs requested enclosed . I hope. Boneyeye
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the other required logs requested in the READ ME:
    CounterSpy
    AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
    Bitdefender - from step 6
    Panda Scan - from step 6

    Also you attached a GetRunKey log twice and must have manually renamed one of the runkeys.txt logs to newfiles.txt. Thus you did not attach a log from ShowNew.bat. However even worse is that you are not using the current versions of the programs. You need to follow the directions in the READ ME and download the current versions of both GetRunKey.zip and ShowNew.zip and follow the directions for installing/extracting and running them.

    Also you must not use MSconfig like you are doing to control startups. As requested in step 0 of the READ & RUN ME, you MUST be in normal startup mode. You are also disabling part of your AVG antivirus program from running at startup. Why?????

    Also you need to follow the directions in step 7 for properly installing and renaming HijackThis.exe. You have this:

    C:\Program Files\HijackThis\HijackThis.exe

    and it must be this:

    C:\Program Files\HijackThis\analyse.exe


    Make sure that you are always using the current online version of the READ & RUN ME and all files/tools listed in it are current versions.
     
  5. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    I have done my genuine best in all this, so please be patient with me.
    Online scans were in normel boot mode. Could not connect to net. in "safe mode". I have"Dial Up". I could not remove the 1spyware in Panda unless I pay a fee, Which I can ill afford , being an OAP. TY For your patience. Hope the logs are ok.
    Boneyeye
     
  6. boneyeye

    boneyeye Corporal

    Sorry failed in previous post
     

    Attached Files:

  7. boneyeye

    boneyeye Corporal

    and these. There has been No trace of any PSWBanker unless it is hidden somewhere, and I cannot recognise it.
    Boneyeye
     

    Attached Files:

  8. boneyeye

    boneyeye Corporal

    Hi, 2By the way, I have uninstalled Java5 and installed Java 6, since posting the files. I can send you screenshot of it, if you require same.
    B.
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox
    - ExplorerXP

    You are using MsConfig to prevent several items from loading at Windows start. MsConfig is a diagnostic tool, and not intended to be used in the manner you are using MsConfig.

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop; make sure File Type: is set to All Files (*.*).
    Close Notepad.

    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files
    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:

    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post the following logs:
    1. ShowNew
    2. GetRunKey
    3. HijackThis
     
  10. boneyeye

    boneyeye Corporal

    Hi Shadow Puter Dude,
    TY for replying I have the 3Keys copied to Notepad and will continue with same after you answer this for me. Ialways like to show file extensions as it has learned and helped me to remember file pathways. Please let me know if this is wrong or rightI gather by some of the 2nd Key that some of this merged with the registry would change that. TY again for your help and clear directions.
    Boneyeye
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The second reg key will make everything show on the system including file extensions.
     
  12. boneyeye

    boneyeye Corporal

    Hi,
    TY again. WhenI click "yes" when asked if I want to merge with the registry I get an error saying"cannot importC;\Documents and Settings\Windows User\Desktop\FixReg.reg. The specified file is not a registry script. You can only import bianry registry files from within the registry editor." Is there an alternative way of completing this. Hijack this has worked out OK .This is as far as I have got. TY Boneyeye
     
  13. boneyeye

    boneyeye Corporal

    Hi, I am able to edit the registry and I could change the values on those 3Keys to what you have said for notepad, with care of course if you approve. Boneyeye.
     
  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run Regedit and try importing the patch.
     
  15. boneyeye

    boneyeye Corporal

    Hi,
    Sorry, but, you will have to tell me step by step how to complete that. Thanx. Boneyeye.
     
  16. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Start -> Run
    type regedit
    click 'OK'

    Click-on Registry in the Menu
    Select Import Registry File...
    Navigate to FixReg.Reg and import the file.
     
  17. boneyeye

    boneyeye Corporal

    Hi,
    Sorry again. Same error as in Post 12. Would you look at Post 13 and give your opinion on it as I am familiar with carrying out this . TYagain for your time and patience. boneyeye
     
  18. boneyeye

    boneyeye Corporal

    Hi,
    Have eventually got all Registry Keys as you described. Got all other files deleted I hope in safe mode and normal mode as you described. Did not need to use ExplorerXP as the files were deleted. Please find enclosed new logs.
    Boneyeye
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have a few things to fix in the registry. Let's try the patch again but I will give it to you in a ZIP file that is attached (see fixME.zip). Extract the fixME.reg file from it to your Desktop overwriting any previous file of the same name. Then double click on the file and allow it to add into the registry. Let me know if you get a success message.


    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Counterspy
    C:\Program Files\Sunbelt Software


    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    How are things running now?
     

    Attached Files:

  20. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    TY for coming back again and for spending so much time on my problem. The fixme.zip worked and was succesful. I got the success message. I uninstalled Counterspy via Add/Remove in Control Panel since it does not have its own uninstall file. But I am left with the last folder.C:\Program Files\Sunbelt Software. I was able to remove it from Add/Remove in Control Panel, rebooted and it was gone. What I cannot do is remove it from Program Files. I get an error saying" cannot delete SBAP.dll. Access is denied. Make sure the disk is not full or write protected and that the file is not currentlyin use" Hope you can help here. The disk is not full or half full .Thanx again.
    Boneyeye.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the requested logs and then I will see what needs to be done.
     
  22. boneyeye

    boneyeye Corporal

    Hi,
    See new scans below. I hope. Boneyeye.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall CounterSpy or did you delete files? I still see part of it running in your HJT log.

    Try reinstalling CounterSpy. Then reboot your PC. After reboot try uninstalling and then deleting the folders as requested.


    Also tell me if you are still having any malware problems.
     
  24. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    I have explained in Post 20 exactly how . Boneyeye.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I just wanted to be sure.

    Did you try what I said (reinstall, reboot, uninstall) yet?

    Attach new logs from HJT and ShowNew now!
     
  26. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    REinstalled CounterSpy, rebooted, uninstalled via add/remove in Control Panel. Sucessful this time, all is gone. New scans included. Boneyeye
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay looks good now! Just have HJT fix the below line:

    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

    Are you having any other malware problems?

    If not, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Mar 3, 2007
  28. boneyeye

    boneyeye Corporal

    Hi,
    TY again Chaslang, I dont seem to be having any malware problems at all. Evarything seemes quicker starting off Programs/Int Sites,, but Internet Sites seem to take longer to finish loading. Boneyeye
     
  29. boneyeye

    boneyeye Corporal

    Hi Chaslang/Shadow Puter Dude,
    I want to thank you both specially, but as I am not able to afford a donation I will say a special prayer for you all at Mass on Sunday and light some candles for my friends in MG. By the way Chas. I completed all as advised in post 27 with no probs. Bye for now. Boneyeye
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! And thanks for the prayers! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds