Trying to get rid of Trojan.ByteVerify

Discussion in 'Malware Help (A Specialist Will Reply)' started by amdtap, Jan 31, 2005.

  1. amdtap

    amdtap Private E-2

    I ran Symantec (detected and deleted byteverify) and Spybot Search and Destroy. I got rid of Internet Explorer (use Mozilla) with IEradicator. I then ran the Trendmicrohouse Java Scan (nothing detected).

    I have a HiJackThis log. There are 2 rundll.exe programs running. Let me know if I should post the log.
     
  2. amdtap

    amdtap Private E-2

    ...and I have Windows Me
     
  3. amdtap

    amdtap Private E-2

    Here is my log. Thanks for the help!

    Logfile of HijackThis v1.97.7
    Scan saved at 2:29:33 PM, on 1/31/2005
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Unable to get Internet Explorer version!

    Edit by chaslang: Unrequested, inline, very old HJT version log deleted. Please follow forum guidelines. Read the sticky threads.
     
    Last edited by a moderator: Jan 31, 2005
  4. TheOldThug

    TheOldThug First Sergeant

    Welcome

    The inline log will probably be deleted. Do the tutorial and then please wait to be asked to submit HJT. Your HJT is out of date and you will need to look at the tutorual for HJT when asked. You must place it in it's own folder not from desktop or temporary folders. All browsers should be closed also.

    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try this... you may find it's all you need. If not post your results and I am sure one of the PROS can help you. These guys are quite busy, as you can see by the number of posts, so hang in there. Good Luck!! :)

    TheOldThug
     
  5. amdtap

    amdtap Private E-2

    Thank you for your help - I appreciate it.

    I did everything again as close as I could to what the instructions say. I wasn't able to run anything in safe mode as it didn't give me the option to safe mode with networking - so I did it in normal mode.

    Using the update patch to Spybot I found DSO exploit and Spybot said it fixed it. I ran all other programs you mentioned (including Spybot again) and nothing came up after that. I ran a log on an updated HijackThis and saved it. From the little I understand of all this it seems like SPybot has disabled bad stuff but the stuff is still in my computer. Can it be removed? Let me know if I should submit the log.

    Again, thanks a lot for your help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can submit it, but make sure that you have followed all of the below guidelines.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  7. amdtap

    amdtap Private E-2

    Thank you, Chaslang. I followed the guidelines. Here is my log. From the information you gave me, I didn't find any line on the log that seemed bad. But it would be great to know for sure.

    Appreciate the help.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just a couple of things I see:


    Did you have SpywareDoctor and uninstall it? Part of it still shows (see the below O2 - BHO entry). You should have HJT fix this line (while all browsers are closed).

    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL (file missing)

    You appear to be using msconfig to control certain items from loading at startup as indicated by the below line:
    O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder

    It is not a good to used msconfig permanently for this purpose. Also I would like to know what else may load if you did not disable them. Could they be a malware problem.

    A better solution than using msconfig is to use a startup manager program like Startup CPL

    Are you still having any problems on your system
     
  9. amdtap

    amdtap Private E-2

    Thanks, Chaslang. I had SpywareDoctor before. I will fix it with HiJackThis as you said.

    I did have several programs disabled by msconfig. Here is a list of them (with name in parenthesis):

    - C:\WINDOWS\SYSTEM\bpcpost.exe (bpcpost.exe)
    - C:\WINDOWS\taskmon.exe (taskmonitor)
    - C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s (PCHealth)
    - C:\WINDOWS\SYSTEM\MDM.exe (Machine Debug Manager)
    - "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (TkBellExe)
    - C:\WINDOWS\SYSTEM\STIMON.exe (StillImageMonitor)
    - mstask.exe (Scheduling Agent)
    - ati2plxx.exe (ATIPOLAB)
    - \annclist.exe (Announcements)
    - \vidsvr.exe /Automation (VidSvr)
    - c:\PROGRA~1\SYMANT~1\SYMANT~1rtvscn95.exe (rtvscn95)
    - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe (Picture Package VCD Maker)
    - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe (Picture Package Menu)
    - C:\PROGRAM~1\WINDOW~3\ENCODER\WMENCAGT.EXE (Encoder Agent)
    - C:\PROGRAM~1\WINZIP\WZQKPICK.EXE (WinZip Quick Pick)

    Where the last 4 on the list are loaded from Startup and all prior ones from Registry.

    I don't have any apparent problems at this point. I would like to be sure.

    Thanks.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you don't have any apparent problems but let's discuss what you want to load at startup and don't want.

    Allow your system to boot normally with msconfig controlling the startups and then we can work on having some items removed from ever loading at all and we will discuss what you want to do with others. But I'll repeat StartCPL is much better approach then using msconfig.
     
  11. amdtap

    amdtap Private E-2

    Thanks, chaslang and star17. So, should I use HiJackThis to get rid of TKBell.exe and the 4 unnecessary start-up programs? What do you suggest I do with the others?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First as I said below, stop using msconfig like you are to disable loading of items and boot normally. The give us a HJT log from that boot. Now we can go thru all the items that can be either fix using HJT to remove them from the registry or you can even decide to uninstall them if desired. Most people never use RealPlayer so a choice can also be to uninstall it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds