Trojan -- bitten by Proxy.Small.ck

Discussion in 'Malware Help (A Specialist Will Reply)' started by jbadenius, Mar 29, 2007.

  1. jbadenius

    jbadenius Private E-2

    I have the trojan: PROXY.SMALL.CK
    It sends out emails but Norton blocks it and then puts up a window which really does not tell me much. It says to make sure that I have the right address, etc. But I am not sending out these emails, the trojan is.

    I ran AVG Anti-Spyware and it identified Proxy.Small.ck. It quarantined it. But it is still there. In safe mode AVG does not see it. Norton never finds it. With the Internet on or off in normal mode AVG still shows it.

    If I turn off outgoing email scanning in Norton, I don't get the popup Symantec Windows (different each time) and everything works just fine so I can do my work just fine. AVG always comes up with the trojan at about 3 minutes scanning Memory/Processes. The [xxxx] VM_003B0000 indicates to me that since the [xxxx] changes each time, the trojan is writing to memory in different places. But then again, it could be one of my processes.
    So I continue to look for clues on the Internet and found SDFix which I might try. Of course redoing the system is always an option. However my PC is over 5 years old and runs like a top.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. jbadenius

    jbadenius Private E-2

    Whew, I followed your 7 steps. Could not run Bit Defender, nor Panda. I have 4 txt reports and 1 Analyse log (i.e. HijackThis). I'll now have to wait to see if the trojan starts again sending out emails, in which case I'll have to stop Norton from running Outgoing email scans. Just now it started again; the problem is back!

    The first two scans are attached.

    JB
     

    Attached Files:

  4. jbadenius

    jbadenius Private E-2

    Here are the runkeys, newfiles, and Analyse files.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see very much in your logs! Just a few things to do.

    What problems did you have with BitDefender and Panda?


    Do you know what the below folder is for/from
    C:\Documents and Settings\Jeff Baumwell\Local Settings\Application Data\gmx62xW8qL

    Uninstall the below using Add/Remove programs:
    J2SE Runtime Environment 5.0 Update 11 <-- this is out of date and you have the current version!
    MetaCrawl.WS Toolbar <-- this is malware! It installs malware or is bundled with malware.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.metacrawl.ws
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.metacrawl.ws
    O3 - Toolbar: (no name) - {7754C418-F62E-44aa-B169-E719E718BCFD} - (no file)
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
    O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
    O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_03) -
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.

    Then reboot and attach a new logs from HJT.

    I noticed that you have CA's Pest Patrol and also Spyware Doctor installed in addition to AVG Antispyware. Are any of these paid versions?
     
  6. jbadenius

    jbadenius Private E-2

    Clicked on BitDefender. Went to a page on the net but there was nowhere to download it. It also had Internet Explorer to download. Confusing.

    When I tried Pand, it scanned but only after I had to download manyu Active x programs and then there was no way I saw to save a report.

    I sure do not know what gmx62xW8ql is.

    I followed your instructions on the uninstalls and ran Analyse.exe to remove the metawcrawl, toolbar and java files.

    No, I do not have paid versions of AVG, e-TRust Pest Patrol and the other one you mention.

    Attached is the new Hijack log file.

    JB
     

    Attached Files:

  7. jbadenius

    jbadenius Private E-2

    GOOD NEWS!!!!
    Firstly, I applied your latest suggestions and now for the first time when I did a scan with AVG Anti-Virus, proxy.small.ck was NOT there.

    I was getting desperate before I joined the Forum and was getting all these spyware programs to see if it could help. I suppose I can delete most of them.

    I'll sign off now with this message and see what you think and I'll let you know if I get re-attacked.

    MajorGeeks for the whole planet. You are GREAT.

    JB
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is in this folder?

    Uninstall Pest Patrol and Spyware Doctor. You can keep AVG Antispyware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. jbadenius

    jbadenius Private E-2

    PC running perfectly. Your advice was Excellent with a capital E.

    Thank You,
    JB
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome; however you did not answer my question about what is in that strangely named folder.
     
  11. jbadenius

    jbadenius Private E-2

    Just went to that folder and there is only one file in it. It is: IbuHY2Mvr.dtc and it is only 408 bytes and was saved on 01/05/05. Here is what I found out about it on the Net:

    This entry has not yet been verified by FILExt. It was submitted to the list and appeared to be accurate; however, no verification links have so far been found on the Internet. Please use this association data with that in mind.

    JB
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would move the whole folder into a temp folder. And if you don't notice any problems on you PC after rebooting and running things for a day or two, then delete the folder permanently.
     
  13. jbadenius

    jbadenius Private E-2

    That is exactly what I was going to recommend to myself.

    Not only do I thank you for your help in solving my problem, but also for your great perseverance.

    JB
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds