Two Trojan Horse Downloader.Generic3.QA Found during V-Scans

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tom K, Jan 21, 2007.

  1. Tom K

    Tom K Private First Class

    Hello MajorGeeks,
    Earlier this week, there were slight indications that something was causing a minor slowdown on the computer. I ran a Virus Scan and it found a Trojan Horse Downloader.Generic3.QA which was deleted. Following this, I ran SpyBot Search & Destroy which found five tracking cookies. This was unusual considering that during the past several months, all scans found nothing. I removed everything that was found.

    This morning, the AV ran an automatic scan and again a Trojan Horse Downloader.Generic3.QA was found and deleted. Once again, I ran SpyBot Search & Destroy which found two of the same tracking cookies as it had during the prior scan. As I did prior, I removed what was found.

    I completed all of the steps in the READ and RUN ME, and the scan results are attached.
     

    Attached Files:

  2. Tom K

    Tom K Private First Class

    Here is the BitDefender Scan. There was a problem before running it, though. A message warned of an inaccurate result if the scan was performed because BitDefender was unable to gather new definitions. I have a screenshot of the message, but it is too large to attach here and I cannot reduce its size any further. I ran the scan anyway and have attached it here.

    Please review these logs when you can and advise me if there is anything malicious that they have found. Thank you so much for your assistance.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You skipped step 3 and step 6b!

    Please complete those two steps and then attach the requested logs from GetRunKey and ShowNew and also a new HJT log. Make sure the logs you are attaching have been obtained AFTER step 3 has been completed.

    Is there a reason you chose to have CounterSpy ignore everything rather than Quarantine or Delete? Did you want to keep WeatherBug installed? It is not really malicious but it is adware and does have an impact on PC performance.
     
  4. Tom K

    Tom K Private First Class

    Hey Chaslang,
    Thank you for the prompt reply.

    I unistalled the old McAfee AV several months ago, but have not uninstalled the remaining components from the suite package. I am only using one Anti-Virus application, and that is AVG.

    I had printed out the instructions early last year and was referring to that paper while I was completing the steps. At that time, step 6b was not part of the READ & RUN ME. I apologize for overlooking the update. I have completed step 6b and both logs are attached.

    It appears that with CounterSpy, I do not have a choice. Each time I open CounterSpy, it requests a Registration Key. I do not have a paid version of it, and I presume that is why all the options are not accessible. It appears that I can only run scans, but cannot quarantine or delete anything with CS.

    This is the only scan that picks up this WeatherBug, and the funny thing is that I did not install any such thing and do not even see anything that shows up weather information. I would like to remove it, as you say it is adware and does have an impact on PC performance, however, I cannot seem to do so with CS and I do not even know where it is located to remove it without CS.

    Thank you again, Chaslang, for checking the logs and providing the assistance.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not really a good idea. You have two applications installed that both really want to be your security center. Also it is probably causing you more excessive use of system resources doing this.


    You must always work from the online copy of the READ & RUN ME. It is constantly evolving just like malware does.

    This probably means you have already past the expiration date of your CounterSpy trial. You may have used it before in the past. Thus you should uninstall it now because it will be of no use anymore and will just slow your PC down. You would have been better off using AVG Antispyware.

    We will fix it manually with the below.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now delete the below folder:
    C:\Program Files\Common Files\Real\WeatherBug


    NOTE: You need to go back and follow the directions for installing and obtaing the GetRunKey and ShowNew logs. You did not do what was requested and the logs are not valid. You MUST extract the files from the ZIP file and you must run the .bat files from a Windows Explorer prompt. Also be sure to check it you are receiving any of the error messages listed. Then attach new logs from the two tools.
     
  6. Tom K

    Tom K Private First Class

    Hey Chaslang,
    Having been extremely busy the past several days, I have not had as much time as necessary to address this issue. I have also not used the computer as much either. But I want to follow up with this and let you know where things stand now.

    I have uninstalled CounterSpy.
    I installed AVG Anti-Spyware. I scanned the computer and it found several issues. I am including a log.
    I manually removed WeatherBug with the Registry merge and file removal as you provided.
    And tonight, I have installed both GetRunKey and ShowNew according to the procedures outlined here and have included logs for both.
    Finally, I ran HijackThis and have included a log since it has been a few days.

    Please tell me how these logs appear as of now. Also, has CS left anything in the registry that should be removed? I know some programs tend to leave their remnants once uninstalled.
     

    Attached Files:

  7. Tom K

    Tom K Private First Class

    Here is the HijackThis Log.

    Please let me know how these logs look and what else I should do.

    Thank you so much, Chaslang, for providing the manual procedure to remove Weatherbug, and for helping me on this issue.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean! But you have a couple things to take care of.

    Uninstall the below old versions of software:
    Microsoft AntiSpyware <--- this has been discontinued by Microsoft
    Mozilla Firefox (1.5.0.1)

    Make sure you reboot after uninstalling the above!

    Then install the current version of FireFox from: Mozilla Firefox


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds