VX2 and IE redirect issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by Deleted member 28874, Jan 31, 2005.

  1. Hi all, I would greatly appreciate some direction for the following.

    I have read and followed in exact order Major Attitudes' guideline of 6/22/04 23:20 on How to: Spyware, Trojan and Virus Removal. I am running Win 2000, downloaded the full range of downloading tools, went into safe mode and ran Trend, Symantec and McAFee as well as CCleaner, Ad-Aware (with VX2 plugin) as well as Spybot (with DSO explot patch) and the secondary removal tools CWShredder, Kill2Me, about:Buster and HSRemove. With the exception of Ad-Aware, things seems to proceed properly. Ad-aware detects VX2 and some IE redirect issues. The VX2 add-in seems to not only not correct the problem, but doesnt even seem to run. I have tried in both safe mode and regular mode to no avail. Can someone please provide some direction on both the VX2 issue as well as the ie.autosearch problems? Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also, please download this tool to your Desktop:

    L2MeFix Tool
    Don't run it yet. I'm just getting ready incase we need it.
     
  4. Dr. C, thank you for prompt response. Log file is attached as indicated. I will download the software you suggested in preparation. Thanks

    steve
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Whose program is the below:

    C:\Program Files\Anti-Spyware Blocker\Anti-Virus.exe

    If it really is an antivirus application, you need to uninstall it because you must only have one antivirus application on your PC and you already have Symantec.

    I'm a little concerned that you have gone over board with your spyware protection. There can be to much of a good thing. Does this PC appear to run very slow?
    You should definitely uninstall SpyHunter! It is not very useful and has been on a rogue/suspect spyware removal tool list for a long time. It was recently remove from the rogue list but is still consider to be not useful.

    And yes you do have a VX2 problem we need to work on. We'll get to that.
     
    Last edited: Feb 1, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-D4E9-ED6AA787AD2D} - (no file)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/049f2072aaf732db3917/netzip/RdxIE601.cab

    Now with the L2MeFix Tool on your Desktop, and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE:Please do not run any other options or files in the l2mfix Folder!

    Please save the l2mfix logand attach it like you did with your previous HJT log.

    TRY NOT TO REBOOT or POWER DOWN after running L2MeFix. Problems could spread and mutate if you do.
     
  7. Dr. C,

    I uninstalled both the Spyhunter and Anti-Spyware Blocker per your suggestion. I was asked to reboot after one of them, but have yet to as I went directly into the Hiacj This issue. he computer didnt really run slow. I have also run the HijackThis utility and have attached the report log. I will leave the computer on and not reboot for now.

    Steve
     

    Attached Files:

  8. Correction, I attached the L2MeFix Tool log file.
     
  9. PhilliePhan

    PhilliePhan Guest

    Hi Steveraustin,

    Since Chas isn't here, I'll give the next steps:

    Please make sure ALL Browser Windows are Closed for this step!

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go a little crazy for a bit, but just let it run. It should eventually produce another log in Notepad. Please attach that log.

    Again, don't run any other files in the L2MFix folder.

    Then, please download Generic Detection Tool - NT/2000/XP

    I didn't see Qoologic/Narrator in you HJT log, but this measure will tell for sure.
    Unzip the Generic Detection Tool to a safe folder of your choice and run "find.bat" - Allow it as much time as it needs to run. You may get an error message of "File Not Found," but just let it go.

    The tool should generate a long text file. Please attach that Log along with the L2MeFix Log.

    I imagine Chas will check back soon.

    PP :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PP,

    I'm just popping in for a minute of two but L2MFix was already downloaded and run. See messages 6 & 7.
     
  11. Well, not sure I did this right, but I did run the fix, option 2, seemed to work ok, rebooted automatically. i went back and ran option 1 again to create the report though. I didnt see the report generated automatically outside of me brute forcing it. it is attached. I will follow up on the 2nd half of the post shortly. but here is the log as report2.txt.
     
  12. forgot to attach
     

    Attached Files:

  13. Here is the output from the generic detection tool find.bat.
     

    Attached Files:

  14. PhilliePhan

    PhilliePhan Guest

    Hey Chas,

    No! It wasn't. You ran the find.log - (Option #1).

    I asked Steveraustin to run the FIX - (Option #2). This fix removes VX2 DLLs, guard.tmp, Desktop.ini, User Agent, etc . . . Saves the hassle of entering everything into KillBox. Unfortunately, it doesn't look for Narrator Trojan/Qoologic.

    Looking at new Find.bat log, some items were missed by the tool. Really needed to see the fix log.
    Don't have time right now to address fix - cooking dinner ;)

    PP :)
     
    Last edited by a moderator: Feb 1, 2005
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry PP! I was in a rush! I did not notice you said option number two.

    It appears that the second report shows lots of stuff still there. Only one DLL file was deleted for a registry key entry. But a new CLSID has shown up for guard.tmp.
     
  16. PhilliePhan

    PhilliePhan Guest

    I saw it too. Steve didn't attach the fix log, but I suspect something messed up along the way. We can always revert back to Plan A (Original Method of fixing this) or rerun the fix option #2 . . . . . .

    PP :)
     
  17. I reran L2mfix option #2 and added the log file. Not sure where it stands and if you want me to do anything at this point or not.

    steve
     

    Attached Files:

  18. PhilliePhan

    PhilliePhan Guest

    Looks better, Steve. I think the tool got it all this time. You don't have the Narrator Trojan to deal with either. This ought to finish it up for you:

    First, please download these two tools:

    VX2.BetterInternet Finder XP/2k - Version Msg126

    Pocket KillBox


    Please print out these instructions so that you can operate with All Browser Windows CLOSED.


    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.


    NOW:
    Please check your Recycle Bin to make sure that no problems remain.
    If all is NOT well with Recycle Bin, please run Pocket KillBox and Copy & Paste the Following into the box: C:\RECYCLER\Desktop.ini - Click Red X to delete it using Standard File Kill.


    After checking on your Recycle Bin:
    Open VX2.BetterInternet Finder XP/2k and Click on the "Find Vx2.Betterinternet" button.

    Then click on these buttons in the right pane unless they are not enabled:

    UserAgent$ Button to remove the UserAgent from the registry

    Guardian.reg

    Restore Policy

    Allow Machine to Reboot.

    NEXT:
    Please download HOSTER and open it, select Restore Original Hosts > Press OK and then exit program.

    Finally, reboot and attach a fresh HijackThis Log and tell us how things are running. Hopefully, all will be clear!

    PP :)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's better more stuff was fixed.

    (PP, notice two explorer.exe sessions that could not be killed! Normally explore.exe is killed. I wonder what's up with that? Looks okay otherwise.)
     
  20. PhilliePhan

    PhilliePhan Guest

    I saw that too - Had a thread not too long ago where the fix ran into all sorts of errors, but when I had the user run Find.bat, all the VX2 had been removed. Do you think we should ask for another Find.bat log?

    PP :)
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That may be a good idea.

    I not sure if the VX2.BetterInternet Finder or Hoster stuff was needed at this point though. It does not hurt anything but I wonder if it is really required after the L2Mfix.
     
  22. PhilliePhan

    PhilliePhan Guest

    Better to be safe - Need it for Guardian.reg and Restore Policy, if I remember correctly.
    Also, sometimes the Desktop.ini removal doesn't take, so I ask about recycle bin and give the bit with Pocket Killbox.

    The bit with Hoster is necessary. See my go2ri2l thread. The user gave me a copy of Hosts file by mistake and the entries were there after the L2MeFix had been run.

    PP :)
     
  23. Hi guys,

    I didnt seem tohave a recycle bin issue. I ran Killbox anyway and it came back empty. I then ran the VX2.BetterInternet Finder and have attached the log for that. It did come back with some files but Im not sure what Im supposed to do with them. The Restore Policy was enabled after the scan, but not the User Agent or the Guradian. I did click on the Restore Policy button and am about to reboot (automatically). No files showed up in the lower box..so I didnt delete anything as far as i know. I will move on to the Holster section after the reboot.

    steve
     

    Attached Files:

    • vx2.log
      File size:
      256 bytes
      Views:
      3
  24. Well, I noticed my previous posting got lost. Must not have hit send or something. Ill try to recap. I ran the Pocket KillBox but didnt see anything in the recycle bin and also did the C:|recycler\desktop.ini. I then ran the VX2.Betterinternet. From what I recall, only the Restore Policy button was enabled which I did use. It then rebooted automatically and I went onto Hoster. I did run into one issue, but I dnot recall at what step it was. I ran into an error and a physical memory dump, I just dont recall at what step. In any case, it rebooted automatically. I have attached the HijackThisLog and I also reran the find.bat and posted it here as there were some comments about this in the previous postings. Right now, things seems to be running ok. I havent run into anything noticeable other than some outside port scanning attempts (via Nortin Int. Sec). I did a web-based security check and it indicated I had 3 ports open. If you know how to turn those off, I would be interested. Still getting alot of spam, but maybe not an internal issue. And I likely have too much antivirus software running concurrently. But no obvious browser redirects. I will do some conventional infection searches shortly, but i suspect they will come up empty. Please advise if i need to take another step based upon logs. Thanks
    Steve
     

    Attached Files:

  25. disregard my comments about posting getting lost. 2 pages to the thread...go figure.. steve
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs look clean now and yes you do (as I said in message #5) have too much malware protection stuff running. Do you have a preference of which programs you like? Did you by Spysubtract?

    Are you running a firewall? It can protect ports?


    We normally fix lines like below in logs because files are missing but can you first check to see if the file is really missing:

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll (file missing)
     
  27. Dr. C, I use Norton Internet Security for my firewall. I have protection set as high as it will go on it, but the online Symantec Security Check still tells me I am vulnerable.

    I also checked for the msjava.dll file and it is not within the specified directory nor anywhere else.
     
  28. I also ran Spysubstract. Nice layout. Did come up empty. I generally have Prevx, Spyware guard, Spybot, Spysweeoper and Spy Subtract as well as the Norton Internet Security and Antivirus running upon windows startup.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did you purchase SpySubtract and SpySweeper.
    Without buying Spysweeper it will work to block, scan and clean but you only get the one time update to definitions. It is a good program.

    Without buying SpySubtract, I think you get a 30 day trial.
    Did you buy Prevx?

    Don't forget you also have Spybot installed too. And what about SpywareBlaster? You probably have Ad-Aware SE now too.

    Which ports does it say are open?
     
  30. You are correct. I only have the trial versions for spysweeper and spysubtract. . I do have the additional programs you mentioned as well. I have not purchased any of them.

    The Symantec Security check wont tell me which specific ports are open, but my notes say ports 443, 25 and 80 were open when i ran another security check cant dont recall what app i used to get this info. Cant seem to locate it offhand.
     
  31. Was mistaken, symantec did show which ports..and the ones reported above were correct.
     
  32. Not sure if anything else needs to be done, re: ports or spyware. Thanks for all the help though. Can take a few deep breaths now.....and then its taxes..ugggh
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should get rid of a few tools to alleviate the load on your processor. Here is what I would remove (based some what on the fact that certain items are free):
    - uninstall SpySubtract
    - uninstall either Spysweeper or MS Antispyware (since MS Antispyware is free and you will get updates you may want to keep it but it has a few bugs right now)
    - uninstall Anti-Spyware Blocker\Anti-Virus.exe whatever it is. You already have Symantec
    - uninstall (if you didn't already) SpyHunter
    - disable Spybot's Teatimer but keep Spybot
     
  34. well guys, its back to the fight Im afraid. While spybot, adaware,arent showing anything, a package called scanspyware indicates viewpoint, isearch, virtual bouncer, real bar, gohip and grokster infections. I would appreciate any help in getting rid of these.

    thanks
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Scanspyware is on a list of rogue/suspect spyware removal tools. See: http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Main reason:
    You do not need this program!

    I guess you did not listen to my previous messages about what to remove, what to keep, etc.

    What you should have is covered here: How to Protect yourself from malware!

    Make sure you update both Ad-Aware SE and Spybot because updates just came out within the last 24 hours for both. Also make sure you get the new HijackThis 1.99.1

    Let's see a current HJT log.
     
  36. Hi dr C, Actually, I had uninstalled it...but then spaced and reinstalled in later. But i did get rid of it now. I did update both other apps late last night and checked to make sure I had latest versions. Both are coming back clean. I also d'loaded the latest HJT and the logfile is attached. I appreciate the help. i realize you guys are quite busy.

    steve
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still using the free version of Spyware Doctor? I see these lines:
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~3\tools\iesdsg.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~3\tools\iesdpb.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~3\tools\iesdpb.dll

    The free version will not fix anything and may send you on some unecessary goose chases.

    Why do you use C:\Program Files\Free Surfer\fs20.exe ?
     
  38. It was on the computer, but I wasnt using it. i have since removed both freesurfer and spyware doctor. Do you recommend I do anything else?

    thanks
    steve
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes go thru the this link and make sure you have done all those steps or the equivalent:

    How to Protect yourself from malware!


    By the way I don't particular care for MS Antispyware at this stage of its development. It's only a beta. It still has too many problems and has been known to break some things.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds