TROJ_CHOPHAR.A : I've Posted Everywhere, and I can't get help..

Discussion in 'Malware Help (A Specialist Will Reply)' started by megaholic, Dec 29, 2005.

  1. megaholic

    megaholic Private E-2

    Hi guys, it seems that i have been infected by a myspace profile page.

    Trend Micro alerts me that the uncleanable infected file is: c:\windows\inet20041\alg.exe
    Virus name: Troj_chophar.a

    Trend Micro also alerts me that outgoing mail is also being sent.

    Winlogon.exe is constantly tryin to install a BHO.

    My computer keeps restarting as well.. so before it does that again, here is my hijackthis log.

    Thanks to anyone who can help.
     
    Last edited: Dec 29, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's!

    Please follow our standard cleaning procedures which are necessary and required for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. megaholic

    megaholic Private E-2

    Hi,

    I've went through all the procedures listed in the thread you sent me.
    And now that I've reached the Online scans... I'm receiving Windows Explorer errors, screen shots are attached below.
    (These windows explorer errors continue to occur each time my computer boots up)

    Also, an error that has been happening on and off all along.. is that my machine RESETS without warning. Therefore, not allowing me to finish these online scans.

    Very odd though, because my machine never reset during my Microsoft Anti-Spyware.. or any other prior to my Online scans.

    Attached are my screenshots.. and my latest Hijackthis log.

    Please Help.

    P.s: just as i was clicking submit on this post, my computer shut down... luckily i had my msg copied and pasted in notepad just in case.
     
    Last edited: Dec 30, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! HJT is unable to get your IE version! Something is wrong with your install. When is the last time you went to Windows Update and got your required updates.

    I see errors posted for BitDefender but it appears that you did not try PandaActiveScan. Is there a reason?

    Is the version of SpySweeper you are running a paid version? Does it scan as well as fix? What version is it?

    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)
    O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll
    O20 - Winlogon Notify: msupdate - C:\windows\SYSTEM32\msupdate32.dll
    O20 - Winlogon Notify: ssldr - C:\windows\SYSTEM32\ssldr32.dll


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\browsela.dll
    C:\windows\SYSTEM32\msupdate32.dll
    C:\windows\SYSTEM32\ssldr32.dll

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now reboot in normal mode. And continue on to run the steps in the below link and post the Ewido log:

    Running Ewido Security Suite

    Afterwars make sure you are in normal boot mode and attach a new HJT log. Also tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. megaholic

    megaholic Private E-2

    Months ago during another spyware attack.. I removed internet explorer as much as i could. I think IE6 is removed, but a lesser version of IE remains.
    Because i'm currently typing this in IE. I access IE through windows explorer, as it is the only way i can at the moment. I'm pretty sure removing internet explorer is a no no, but I did it at the time because I had no where else to turn. My computer has worked fine since than (until now)... and I use FireFox instead.


    I stopped trying anymore because my computer was reseting so much... but last night after I fixed the lines in HJT you told me:
    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)
    O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll
    O20 - Winlogon Notify: msupdate - C:\windows\SYSTEM32\msupdate32.dll
    O20 - Winlogon Notify: ssldr - C:\windows\SYSTEM32\ssldr32.dll

    and deleted these files:
    C:\WINDOWS\system32\browsela.dll (won't delete for some strange reason)
    C:\windows\SYSTEM32\msupdate32.dll
    C:\windows\SYSTEM32\ssldr32.dll

    I was able to reboot my computer and scan with Panda.. and than later BitDefender with no restarts. So the logs are attached as well.

    The last things I have done were running the Ewido scan.. and finally my last HiJackThis log. Both reports are attached.

    Again my computer is working, but is still not perfect.. I still recieve kernell.32 Windows Explorer errors.. as i showed u before. My computer hasn't restarted without warning since, but I will let you know if it does.

    Here are my reports and logs... thanks for all the help, and any more is appreciated.
     
  6. megaholic

    megaholic Private E-2

    Here's my logs.

    My bitdefender log will need to be renamed to html.. because html's can't be uploaded.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Removing IE is definitely a no no! You will not be able to get your Windows updates. IE is an integral part of the OS and ties into Windows Explorer. Possibly a reason for your errors. You should get IE reinstalled and just not use it except as necessary. This however is not a malware forum topic.

    You are still infected!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some of the items you have are keyloggers know to steal passwords. You really need to use a different PC or the telephone to change all passwords for all user accounts. Especially (obviously) financial institutions. See: Malware - Bancos.LU

    This stuff shows in your Panda log. I'm surprised that Ewido is not finding it and deleting. You must have an outdated version or the definitions are not current.

    Manually delete all the files shown in the Panda log and then do a new Panda scan and attach the log.
     
  9. megaholic

    megaholic Private E-2

    okay.. i'll give it a try.. thanks for the quick reply
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also have HJT fix the below line:

    O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll

    You also need to empty your Trend Micro\Internet Security QUARANTINE folder. That is why your BD log is so long.

    Also even though we are not finished, you should go to step 1 of the READ & RUN ME and disable System Restore (do not reenable yet). We need to get rid of all the bad stuff you have saved in System Restore.
     
  11. megaholic

    megaholic Private E-2

    Thanks again for everything so far.

    Here's the latest:

    I disabled System Restore.
    I've decided that i will reinstall the latest version internet explorer when you instruct me to, lol.

    I cleared my Quarantine, and it seemed to delete a lot of the infected files from the Panda scan. I manually deleted the rest of the infected files that were left in the log as well.

    But, I still can't delete Browsela.dll. It says that it is in use.
    I tried deleting the entry from hijackthis.. but when i scan again, it's just comes back. Very weird.

    attached is my latest panda scan.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you delete the below that were in the Panda log. If not, please delete them.

    Adware:adware/adsmart Not desinfected C:\WINDOWS\SYSTEM32\vx.tll
    Adware:adware/cashdeluxe Not desinfected C:\WINDOWS\SYSTEM32\wlo32.ini
    Adware:adware/cws.searchmeup Not desinfected C:\WINDOWS\ms1.exe
    Adware:adware/secure32 Not desinfected C:\WINDOWS\secure32.html
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if we can fix the problem with:

    O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll


    Okay let's use my older manual approach. Start by downloading two tools we will need:

    - Process Explorer 9.2

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later. You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of browsela.dll once and then click the kill button. After you have killed all of the browsela.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of browsela.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filename into KILL BOX. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click YES and it will reboot.

    C:\WINDOWS\system32\browsela.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log and tell me how the steps went. If it does not work this way, we may need to try the procedure from safe mode.
     
  14. megaholic

    megaholic Private E-2

    Everything worked fine, except for KillBox freezing when i clicked the red X.
    I reset the computer manually when that happened, and browsela.dll has been killed.

    I ran a HiJackthis scan, and browsela.dll did come back but it simply said "(file missing)"... so i Fixed that in hijackthis... restarted, ran another HiJackThis and it seems to be gone completely.

    Here is my latest log.
     

    Attached Files:

  15. megaholic

    megaholic Private E-2

    Happy New Year ChasLang!.. heh, it's not a bump i swear.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it looks like you're in good shape now. To help keep you clean, work thru the below. The first step in this link is Windows Update and maybe that will fix your IE problem with no version info. Otherwise you may need to reinstall. The Software Forum would be a better place to discuss a reinstall of IE.

    How to Protect yourself from malware!
     
  17. megaholic

    megaholic Private E-2

    Hey ChasLang,

    I have installed all the windows updates.. and i've installed Service Pack 2, as well as an IE 6 sp2 update.

    How do i know IE is working fully now? What log couldn't detect my version in?

    Thanks.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well if it runs and you can surf I would say it is working?

    You can get the version from inside of IE. Just click Help, About Internet Explorer

    Also you can see it in a HijackThis log. Look at how your log previously looked. The 3rd and 4th lines were:
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Unable to get Internet Explorer version!
     
  19. megaholic

    megaholic Private E-2

    Logfile of HijackThis v1.99.1
    Scan saved at 12:48:14 AM, on 1/2/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Unable to get Internet Explorer version!



    still no change
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well you got Win XP SP2 to install. You just did not get your IE fixed. You should look at it when you run IE and see what it says. Also you show pursue getting this fixed in the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds