Troj_Generic.ADV

Discussion in 'Malware Help (A Specialist Will Reply)' started by tdarrah, Mar 27, 2008.

  1. tdarrah

    tdarrah Private E-2

    I ran Spybot, Trojan Hunter, etc. Nothing was found. I also ran CCleaner and got rid of everything it detected (in a panic) and realized that this may have f'ed me. I purchased and ran XoftSpySE to get rid of it, which it did, but Trends Micro is still showing it as unremovable (false positive).

    I recently tried to do a system restore anywhere from 2 months ago to a week ago and it is unable to restore at any point.

    I started with Castlecops about a week ago and no one has responded to my issue. I believe there is a system restore disable, restart, rescan and then enable system restore. Is this my only option.

    Problems I am experiencing...IE 7 is really slow to start and when I have more than a few windows open things start to slow down and programs do not open. The laptop is only about a year old and was working fine before I was informed about the virus. I am tired, frustrated and completely obsessed with it. Could someone please help?!

    I have Norton on an laptop I bought about 4 years ago and have never had an issue with it. I was lured by a cheaper priced company (Trends). Are they the problem? Should I fight to get my money back and download Norton?

    Thanks in advanced. TD
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, tdarrah!

    Please go through the READ & RUN ME FIRST. Malware Removal Guide
    ...then start a new thread here and post your problems and suspected malware infection, and attach the three requested logs. Please be patient - the experts will get to your thread.

    EDIT: I see you have posted in the Malware Removal forum for help.

    dr.m :major
     
    Last edited: Mar 27, 2008
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Moved to Malware, so tdarrah, Please follow the above Read Me guide that Dr M posted and reply with the attached logs in this thread only.

    Many Thanks
     
  4. tdarrah

    tdarrah Private E-2

    Ran the cleaning...please check out the logs.

    Thanks.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    What are the below items on your Desktop? If unknown, delete them. If you know what they are and need them, move them somewhere else as this is a bad place to save them and can add to PC slow downs.
    Code:
    "C:\Documents and Settings\owner\Desktop\"
    data1.cab     Sep  4 2006     1181112  "data1.cab"
    data1.hdr     Sep  4 2006       74888  "data1.hdr"
    data2.cab     Sep  4 2006    53389178  "data2.cab"
    ikernel.ex_   Oct 29 2003      346602  "ikernel.ex_"
    layout.bin    Sep  4 2006         417  "layout.bin"
    setup.exe     Oct  5 2000      165888  "Setup.exe"
    setup.ini     Sep  4 2006         260  "Setup.ini"
    setup.inx     Sep  4 2006      167136  "Setup.inx"
    ymjmsi.log    Feb 27 2008     1434300  "ymjmsi.log"
    Also if you wish to keep the IE7 installer (IE7-WindowsXP-x86-enu.exe) which is also on your Desktop, move it somewhere else too.

    The below files should also not be stored in the C:\Program Files folder. You should not download and save installer files here. This folder should only be used to hold programs that were installed here. Either delete these or move somewhere else if you need them.
    Code:
    "C:\Program Files\"
    aaalog~1.exe  Mar  4 2008     5708176  "aaalogo122-setup.exe"
    adbeid~1.exe  Mar 12 2008   459188632  "ADBEIDSNCS3_WWE.exe"
    atf-cl~1.exe  Mar 18 2008       50688  "ATF-Cleaner.exe"
    ccsetu~1.exe  Mar 18 2008     2733520  "ccsetup205.exe"
    drweb-~1.exe  Mar 19 2008     9343816  "drweb-cureit.exe"
    hjtins~1.exe  Mar 18 2008      812344  "HJTInstall.exe"
    ie7-wi~1.exe  Jan 23 2008    15452536  "IE7-WindowsXP-x86-enu.exe"
    msgr8us.exe   Feb 16 2008      437560  "msgr8us.exe"
    sdsetup.exe   Mar 18 2008    17646136  "sdsetup.exe"
    spybot~1.exe  Mar 18 2008     9722720  "spybotsd152.exe"
    sysclean.zip  Mar 21 2008     4189850  "sysclean.zip"
    t-shir~1.ai   Mar  6 2008      253494  "t-shirt_template.ai"
    traill~1.exe  Mar  4 2008    13202944  "TrailLogoSmartz.exe"
    trendm~1.exe  Mar 11 2008    60410640  "TrendMicro_TAV_16.05TM_1015_x32.exe"
    trojan~1.exe  Mar 18 2008    15804288  "TrojanHunterSetup.exe"
    whatsr~1.exe  Mar 21 2008     1156877  "WhatsRunning2_2_Setup.exe"
    xoftsp~1.exe  Mar 18 2008     3178952  "XoftSpySE433_263.exe"
    And the below looks like something you do not want on your PC. It is probably adware of some kind.
    Code:
    "C:\Program Files\"
    FREEOF~1.COM  Mar  6 2008              "Free Offers from Freeze.com"

    What is in the below folders? Do you know what these are from? They are recent additions.
    Code:
    "C:\Documents and Settings\owner\Local Settings\Application Data\"
    INSTAL~1      Mar  7 2008              "Installer3344"
    INSTAL~2      Mar  7 2008              "Installer3496"
    You just recently installed TrendMicro. Is that also the same point at which your PC slowed down?
    Where is TrendMicro saying this trojan is found? Give me the full path and file name.

    Since you are complaining about browsing being slow, do the below.
    • Uninstall SUPERAntispyware now since we are finished with it.
    • Uninstall Trojan Hunter that you also recently installed.
    You logs are not really showing any malware, but I'm going to give you some non-malware steps to do as generally clean and possible performance improvements.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Java Plug-in 1.5.0_04) -
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  6. tdarrah

    tdarrah Private E-2

    Things seemed to be running very well, thanks. Attached are the 2 log files. I apprecite the timely response. I have been to other sites and have waited over a week for someone to step up. Thanks again.
     

    Attached Files:

  7. tdarrah

    tdarrah Private E-2

    The installer folders you asked about contain information regarding Adobe...

    Installer 3344...
    Folder/payloads
    Folder/redist
    Folder/resources
    File/Deployment.xml
    File/Setup.exe (adobe icon)
    File/WinBootstrapper1.cab
    File/WinBootstrapper.msi

    Installer 3496...
    Folder/payloads
    Folder/redist
    Folder/resources
    File/Deployment.xml
    File/Setup.exe (adobe icon)
    File/WinBootstrapper1.cab
    File/WinBootstrapper.msi

    The Trends Micro Install is when I starting having these issues. Downloaded it on 3/11/08.

    I am running a virus scan right now to see if it picks up the Troj_Generic.ADV. So far it has found 109 potential threats...is this normal?

    Also...when I open up IE it freezes sometimes and you need to open another IE window to get the frozen one going again. This has been happening for quite awhile...any thoughts? This is happening even after all the processes that were just executed.

    Thanks again.
     
  8. tdarrah

    tdarrah Private E-2

    Troj_Generic.ADV Location...

    Path...C:\\WINDOWS\
    Infected File...cfdemo.scr
     
  9. tdarrah

    tdarrah Private E-2

    It is listed as a "Screen Saver"?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is just Toshiba's ConfigFree Demo and is not a problem.

    Is this the only thing that was getting detected? If there were more and they are in System Volume Information then they are also not problems as that is just System Restore and each restore point probably has the same file in them.


    I did not ask you to attach any individual logs from the MGtools folder. I asked you to attach a new MGlogs.zip file after I explained how to get one using GetLogs.bat. I still wish to see this log.
     
  11. tdarrah

    tdarrah Private E-2

    Is this what you are looking for?
     

    Attached Files:

  12. tdarrah

    tdarrah Private E-2

    This was the only Trojan detected. The other threats were just cookies that were removed.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but you did not run C:\MGtools\GetLog.bat You ran GetRunKey.bat. You need to run GetLogs.bat and then attach the new MGlogs.zip file.
     
  14. tdarrah

    tdarrah Private E-2

    Here it is.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you delete the below file for some reason?

    C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    It is showing up as missing in your HijackThis log. This is for Sun Java. You will need to reinstall to get this file back.

    Your logs are clean but you can use analyse.exe to fix the below:
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you run Avenger, you can delete all files related to Avenger now.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  16. tdarrah

    tdarrah Private E-2

    The only issues I still seem to be having is when it comes to having multiple programs open. I run out of RAM and need to reboot the system more often than usual. I also have issues when it comes to listening to online radio or other sounds. At times I get static, but once I reboot the computer it comes back. It just seems that the computer is not working as well as it did just a few months ago, before this all happened. I have also noticed in most cases these issues arise when IE is utilized. Will disabling/enabling the system restore fix these issues or is there still something that needs to be done?


    ***Before seeking professional help I followed the instructions of this website in desperation to edit my hosts file. Don't ask me why I did this as my only response would be late night desperation and ignorance. Is this something that should be addressed or irrelavent at this point?

    http://www.microsoft.com/windows/IE/community/columns/IEtopten.mspx

    Find and edit your HOSTS file

    The correct directory for a HOSTS file depends on what version of Windows you are running:

    Windows XP = C:\Windows\System32\Drivers\Etc
    Windows 2K = C:\Winnt\System32\Drivers\Etc
    Win 98\ME = C:\Windows

    Once you have found your HOSTS file, right-click on the HOSTS file, and then select Open. You will be asked to choose a program to use. Select Notepad, but make sure you that you do NOT turn on any option to always use the same program.

    Examine the content of your HOSTS file, and compare it to the screenshot below. We do not need to worry about any line that begins with an # because is ignored by Windows. Also, the line "127.0.0.1 localhost" can be safely ignored, because it is a standard entry.



    A HOSTS file can be used to control Web page to IP address associations


    Anything else that appears in your HOSTS file without an # at the beginning, apart from the "127.0.0.1 localhost" line, should be viewed with suspicion when we are trying to diagnose the cause of "Page cannot be displayed" errors. The quickest way to test for HOSTS file involvement is to right click the HOSTS file, then select Rename. Add the letter X to the beginning or end of the file name and then ok your changes. By changing the name of the HOSTS file, we stop Internet Explorer from using it, and therefore resolve any issues caused by the file.
     

    Attached Files:

    Last edited: Apr 2, 2008
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are not malware issues. I suggest you post in the Software Forum.

    Did you have TrendMicro installed a few months ago when things were better? If not, try uninstalling it and see if things return to how they were?

    Your hosts file has nothing to do with the problems you are mentioning and if you have it set as shown in the snapshot, that is the Windows default host file which is fine. If you run Spybot and use the Immunize feature as mentioned in the READ ME, it will add several thousands lines to the host file to stop your browser from accessing bad/dangerous sites. Again this is an accpetable thing to do for protection. YOu just don't want an entry put into the host file that blocks you from going to a valid site. For example if you put a line like below into your hosts file:

    127.0.0.1 www.majorgeeks.com

    You would not be able to get here to majorgeeks main web page.
     
  18. tdarrah

    tdarrah Private E-2

    I did the Disable/Enable the system restore. I opened up some IE Windows and Office programs to see how things were running (at the time fine). Then I went back to "How to Protect yourself from malware!" and started by downloading Ad-aware 2007 as the preparing you computer for SP2 section of Windows website suggested. I ran it and when it tried to open it said.

    X An error occurred in Ad-Aware 2007!
    Component: TFormAAW

    Message: Not enough storage is available to process this command.

    Then after hitting the ok button. I try opening up IE and the top row of the header fades in and out as well as other programs do. This also happens when I reboot and then after a short time period try to run SpyBot S&D. As it scans a similar message comes up.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already had Win XP SP2 and did not need to run those steps. I recommend that you do not install Ad-Aware 2007 which came out long after those instructions at Microsoft were created.


    This does not sound like a malware issue. It sounds more like hardware or software issues. You should follow up with this in the Software Forum as it seems related to http://support.microsoft.com/kb/225782

    I notice a fix for XP systems posted here:http://www.pcdoctor-guide.com/wordpress/?p=174
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds