Virus Toolbar, and Blinking Triangle

Discussion in 'Malware Help (A Specialist Will Reply)' started by musiK, Nov 24, 2007.

  1. musiK

    musiK Private E-2

    I need some serious help. I believe there is a trojan running on my computer and it has made a toolbar and is sending constant website redirections using IE. There is a flashing Triangle in my system tray that tells me that I am at risk and shows me that there is a decrease in performance. It says that there are black door trojans in my computer which is stupid because they are back door trojans so I know for sure something is wrong. Another thing the computer is doing, is that the desktop toolbar is actually disappearing but the computer still runs fine. Sometimes, my applications will close and I am left with a blank desktop background and no icons or anything whatsoever but everything is running dandy. Here is my hijackthis.txt

    P.S. I have already run ATF-Cleaner, and run VundoFix and cleared out 2 Vundo files. And I have made a ComboFix log... hope this is a start...
     

    Attached Files:

    Last edited: Nov 24, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. musiK

    musiK Private E-2

    Thank you for that but I have already read and tried all of those procedures. I have been working on this issue all day because I am only 15 and I do not want to tell my parents that I got a trojan. They would be extremely mad and my gaming days would be over. I am willing to buy a Security Suite when this dilemma is fixed.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We don't consider the procedures to be complete until ALL of the logs are properly attached. HijackThis is the very last thing needed and it must be installed and renamed properly per the instructions or it is of no use to us.

    In addition you ignored the step about uninstalling multiple antivirus applications.

    You don't need to and do not want to buy a security suite. They will slow your PC down too much. We have plenty of free tools that work better.
     
  5. musiK

    musiK Private E-2

    Ok. That is very useful information tell me what I should do and what I shouldn't do at this point. If you wouldn't mind a step-by-step procedure would be very appreciated... I am greatly thankful that you are helping me.

    EDIT: I cannot uninstall anything because I have lost the use of the windows toolbar on the desktop at this point and none of the security suites are active. They are installed but only McAfee is actually active. The others like BitDefender and TrojanHunter are installed but are completely off.

    (Sorry for the mix up and I hope I didn't offend you.)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the instructions in the link I gave you in message number to. Click that link.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you get Task Manager to run. If so run appwiz.cpl from Task Manager's run box and that should bring up add/remove program unless malware has broken it.
     
  8. musiK

    musiK Private E-2

    Ok. I got the Add/Remove programs and none of the programs I have installed are on the list of malicious programs. I downloaded CCleaner into My Documents but I cannot get to the file like this... How can I through Run?

    I can restart my computer at this point to gain access to my bar. Restarting helps and I think it will be more productive for me and you.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When CCleaner is installed the default is to put an icon on your Desktop. Did you not allow it to do this or is your Desktop not accessible? Or do you mean that you cannot find what you downloaded???
     
  10. musiK

    musiK Private E-2

    Don't worry I have it installed... I rebooted and I can access everything now. I couldn't even reach my Start or any of that. I couldn't even view my taskbar.
     
  11. musiK

    musiK Private E-2

    Ok. Sorry for the longish reply I am performing all of the scans and I am attaching the files asap.
     
  12. musiK

    musiK Private E-2

    I finally complete each of the scans using ComboFix, SpyBot, AVG, and MGtools. ComboFix and MG both made a log but AVG did not. I even checked the box that says 'Create a log after a scan completes' and no log was created. I was not sure what was wrong or wasn't? Here are the logs.
     

    Attached Files:

  13. musiK

    musiK Private E-2

    This morning I was clear of the toolbar and the triangle and other symptoms except the slowing of my computer. I have noticed a program running in the background: 'rundll32.exe'. I have never seen this process running before now and when I try to terminate it, another one appears. It is a never ending cycle of trying to stop this process.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First let's remove the services from Bitdefender!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to BitDefender Desktop Update Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • BitDefender Communicator
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste LIVESRV into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • XCOMM
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Per the instructions in the READ ME, you must not use Spybot's Teatimer.

    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Now uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    Java 2 Runtime Environment, SE v1.4.2_13
    Java(TM) 6 Update 2

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {158A95B4-1F79-3B06-78BF-0424CDB17C2E} - C:\Program Files\Umjbdpib\mubjmndo.dll (file missing)
    O2 - BHO: (no name) - {214F0EF9-56A3-4BD0-97EB-97A30CEC8AF6} - C:\WINDOWS\system32\mlljg.dll
    O2 - BHO: (no name) - {2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F} - C:\Program Files\Outerinfo\Outerinfo.dll (file missing)
    O2 - BHO: (no name) - {73E00092-5539-4661-9B61-3A66FC0D772E} - C:\WINDOWS\system32\gebyyyy.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} -
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} -
    O16 - DPF: {CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA} (Java Plug-in 1.4.2_13) -
    O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
    O20 - Winlogon Notify: gebyyyy - C:\WINDOWS\SYSTEM32\gebyyyy.dll

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  15. musiK

    musiK Private E-2

    All I have to say is thank you. You are the man and you should be proud that you have learned this skill. You make me want to help people in this profession/art... my computer runs like it did when it was brand new and I have you to thank for that. Congrats you fixed my computer... here are the logs in case there are a few errors left.

    BTW - tell me what you recommend on free downloads from this site for the best security protection i.e. what you use :)
    (So I can uninstall my McAfee SecCenter)
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but we are not quite finished yet.

    When we get to my final instructions (after you are clean) I will give you a link explaining How to protect you.

    It looks like you may not have run the tool I gave you to remove Windows Messenger. Did you miss that part?

    Goto Add/Remove programs and uninstall BitDefender Internet Security 2008. This did not show as installed in your previous log so I removed it manually in the last fix. I wonder why it is showing now.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {001C6719-EFAC-44DA-8163-4BD4D4243D87} - C:\WINDOWS\system32\mlljg.dll (file missing)
    O2 - BHO: (no name) - {73E00092-5539-4661-9B61-3A66FC0D772E} - C:\WINDOWS\system32\gebyyyy.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll (file missing)
    O4 - HKLM\..\Run: [wudwyaii] C:\bbxqhaca.bat
    O4 - HKCU\..\Run: [Windows Update] C:\WINDOWS\ms32ba.exe

    After clicking Fix, exit HJT.

    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  17. musiK

    musiK Private E-2

    There were a couple errors during Avenger.

    I ran the app to remove Messenger but I guess it didn't work the first time.
    I also uninstalled BitDefender once but the name came back in the Add/Remove so I uninstalled after my latter logs.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Avenger fix did not work properly. Let's see if we can finish this off manually.

    Delete the below files:
    C:\bbxqhaca.bat
    C:\WINDOWS\system32\drivers\ebuaapor.sys

    Also delete the below folder:
    C:\Program Files\Common Files\BitDefender


    Other than those you should be fine. If they all deleted, then it is time for my final steps below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\newfiles.txt, C:\runkeys.txt, C:\GetUnKey.txt, and C:\MGlogs.zip logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  19. musiK

    musiK Private E-2

    Thank You very much sir! :clap
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds