trojanhorse psw.generic3.xxx

Discussion in 'Malware Help (A Specialist Will Reply)' started by beckyliciousboo, Feb 22, 2007.

  1. beckyliciousboo

    beckyliciousboo Private E-2

    trojanhorse psw.generic3.xxx--pls help

    Hello,
    I've followed the instructions from the post [http://forums.majorgeeks.com/showthread.php?t=35407http://hk.yahoo.com/]. I can't seem to get rid of the viruses that keeps popping up with AVG that identifies them as: wl.exe, cs.exe, my.exe, qq.exe, mh.exe...deleteing them and stopping the process and deleting them from the 'run' in regedit have not been successful ways to eliminate them. I've also followed the steps from the post I mentioned...would you be able to help please?
    Best regards,
    Becky
     

    Attached Files:

  2. beckyliciousboo

    beckyliciousboo Private E-2

    avg finds trojanhorse psw.generic3.xxx

    Hello,
    I've followed the instructions from the post [http://forums.majorgeeks.com/showthread.php?t=35407http://hk.yahoo.com/]. I can't seem to get rid of the viruses that keeps popping up with AVG that identifies them as: wl.exe, cs.exe, my.exe, qq.exe, mh.exe...deleteing them and stopping the process and deleting them from the 'run' in regedit have not been successful ways to eliminate them. I've also followed the steps from the post I mentioned...would you be able to help please?

    computer specs: pentium 4 - 2.80ghz - 1.00gb RAM
    Windows XP proversion 2002 service pack2

    Thank you,
    Becky
     

    Attached Files:

  3. matt.chugg

    matt.chugg MajorGeek

    OK Becky, Calm down ;)

    I've merged all 4 (!) of your threads together and deleted the redundant posts 7(!) ;) leaving you with one thread and 2 posts ;)

    Please be patient now until someone is around to help you, our top malware fighter is currently on vacation and we are trying to keep things moving but bear in mind we are all volunteers here.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please uninstall thru add/remove:
    J2SE Runtime Environment 5.0 Update 1

    Reboot and install:
    Java Runtime 6

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Common Files\Microsoft Shared\MSInfo\NewInfo.rxk
    C:\DOCUME~1\dad\LOCALS~1\Temp\zt.exe"
    C:\DOCUME~1\dad\LOCALS~1\Temp\my.exe"
    C:\DOCUME~1\dad\LOCALS~1\Temp\wl.exe"
    C:\DOCUME~1\dad\LOCALS~1\Temp\zt.exe"
    C:\WINDOWS\system32\wsvbs.dll
    C:\WINDOWS\system32\drivers\npf.sys
    C:\WINDOWS\wsvbs.exe

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [upxdn] C:\DOCUME~1\dad\LOCALS~1\Temp\zt.exe
    O4 - HKLM\..\Run: [OYEOYE] C:\DOCUME~1\dad\LOCALS~1\Temp\my.exe
    O4 - HKLM\..\Run: [BaoFeng32] C:\DOCUME~1\dad\LOCALS~1\Temp\wl.exe
    O4 - HKLM\..\Run: [upxdnd] C:\DOCUME~1\dad\LOCALS~1\Temp\zt.exe
    O4 - HKLM\..\Run: [wsvbs] C:\WINDOWS\wsvbs.exe
    O4 - HKCU\..\Run: [svc] C:\DOCUME~1\dad\LOCALS~1\Temp\kwatlog.exe
    O21 - SSODL: mtklefap - {665EF778-CF85-4DE3-E4A0-4E17AC26648D} - C:\WINDOWS\System32\msuc32.dll (file missing)

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  5. beckyliciousboo

    beckyliciousboo Private E-2

    Thank you all for your quick help!
    I followed the instructions but when I ran HJT, the entries I was supposed to delete weren't in there...
    (I also ran it in safe mode a second time)
    But while I was doing this (I had already disconnected the network cable)AVG popped up another virus detection with a similar identifyer (trojanhorse.psw.generic.XXX) but the exe was different (I didn't write it down in time). I ran the programs anyhow, this is what I got.. thanks again,
    becky
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use explorer to delete these:
    C:\5e8.tmp
    C:\678.tmp
    C:\WINDOWS\Downloaded Program Files\vet.da1


    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O21 - SSODL: mtklefap - {665EF778-CF85-4DE3-E4A0-4E17AC26648D} - C:\WINDOWS\System32\msuc32.dll (file missing)


    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Question ...did you download the Java update from our link?
     
  7. beckyliciousboo

    beckyliciousboo Private E-2

    hello,
    Yes I downloaded the java from the link that you instructed me to (i also did not get that prompt that was mentioned). I deleted the files C:\5e8.tmp and
    C:\678.tmp.. I couldn't find the vet.da1 file but I cleared the Download program files folder. Also when I ran JKT, i didn't see the line i was supposed to check and clean. but a new virus name for the same virus popped up from AVG in the system 32 folder "prcsa.exe" and "rpcsb.exe"...Thank you so much for your assistance so far.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know what this is in your add/remove programs list:
    6200
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\xcuexpsh.txt
    C:\xcupol~1.txt
    C:\xcupol~2.txt
    C:\xlmbho.txt
    C:\xlmpol~1.txt
    C:\xlmpol~2.txt
    C:\xlmsha~1.txt
    C:\xmodul.txt
    C:\xmscfg.txt
    C:\xrkey00.txt
    C:\xrkey01.txt
    C:\xrkey02.txt
    C:\xrkey04.txt
    C:\xrkey05.txt
    C:\xrkey06.txt
    C:\xrkey07.txt
    C:\xrkey08.txt
    C:\xrkey10.txt
    C:\xrnotif.txt

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  9. beckyliciousboo

    beckyliciousboo Private E-2

    Hello!
    I'm afraid I don't even see that entry in my programs but I've sent a couple screen shots of what I have in my add/remove...
    i didn't see anything pop up from AVG this time yet (so hopefully...) but these are the latest...thank you so much for your time and efforts
    becky
     

    Attached Files:

  10. beckyliciousboo

    beckyliciousboo Private E-2

    this is what i have installed in my add/remove...
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suspect that the 6200 may refer to your lexmark printer?
    Your logs look clean. You may uninstall any programs we had you download.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  12. beckyliciousboo

    beckyliciousboo Private E-2

    ummm i think i messed up my system while trying to fix my dad's system... what does it mean when using killbox you get the "PendingFileRenameOperations prompt" becasue i just got it and it just cancels the command and kill box is still open.
    symantec says i have the trojan.vundo with a file in c:\windows\microsoft.net\barnifo.dll
    looks like its somehow attached to explorer and winlogon .. is there somewhere i can stop it from launching when i logon?
    --or do you have time to look at logs?
    thank you.
    becky
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...please attach logs for:
    ShowNew
    GetRun
    HJT
    Re-run counterspy and have it fix everything it finds.
     
  14. beckyliciousboo

    beckyliciousboo Private E-2

    thank you...
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First use add/remove to uninstall anything you installed since our last fix.

    Then delete these:
    C:\Documents and Settings\Support\Desktop\mstIsUsedBy20e
    C:\Documents and Settings\Support\Desktop\mstIsUsedBy20e.zip
    C:\Documents and Settings\Support\Desktop\ofinrab.zip
    C:\Documents and Settings\Support\Desktop\winlogon.zip
    C:\Documents and Settings\Support\Desktop\winlogon
    C:\winlogon.exe
    C:\testy.dll

    Use Pocket kill box to delete these: (remember to check the unregister dll's box):
    C:\Windows\system32\dtohpnua.dll
    C:\WINDOWS\system32\vsppplwb.ini
    C:\WINDOWS\system32\ftpujalk.ini
    C:\WINDOWS\Microsoft.NET\barnifo.dll
    If you get the pending file notice just reboot the computer yourself.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Attach new logs for:
    ShowNew
    GetRun
    HJT

    And don't download anything in the meantime!!
     
  16. beckyliciousboo

    beckyliciousboo Private E-2

    Hello, looks like the barnifo.dll is still stuck :cry
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of barnifo.dll once and then click the kill button. After you have killed all of the barnifo.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of barnifo.dll and kill it. (If you do not find the dll, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of barnifo.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\ftpujalk.ini
    C:\WINDOWS\system32\vsppplwb.ini
    C:\WINDOWS\Microsoft.NET\barnifo.dll

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {28EAB122-FE8B-4866-BE47-62A647FB4E35} - C:\WINDOWS\Microsoft.NET\barnifo.dll
    O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/installers/cab/SystemDoctor2006FreeInstall.cab
    O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/installers/cab/WinAntiVirusPro2006FreeInstall.cab
    O20 - Winlogon Notify: barnifo - C:\WINDOWS\Microsoft.NET\barnifo.dll

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  18. beckyliciousboo

    beckyliciousboo Private E-2

    i think it might actually be gone!!
     

    Attached Files:

  19. beckyliciousboo

    beckyliciousboo Private E-2

    I did a scan and it wasn't found!!! thank you so much... now i'm going to put up a fort for these computers!
    becky
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like we are not finished.

    Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of bovrlrke.dll once and then click the kill button. After you have killed all of the bovrlrke.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of bovrlrke.dll and kill it. (If you do not find the dll, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of bovrlrke.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\bovrlrke.dll
    C:\WINDOWS\system32\vsppplwb.ini
    C:\WINDOWS\system32\syajcais.ini

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click on the box to unregister .dll's. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now re-run HJT and have it fix this entry:

    O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - C:\WINDOWS\system32\bovrlrke.dll

    Reboot and attach new logs for:
    ShowNEw
    GetRun
    HJT
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds