This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Continuation of Closed Post

4 min read

This thread's last reply is from July 5, 2009, 3:20 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

I want to first reference my original post, which was viewtopic.php?f=12&t=43585 That post was closed because of 5 days of inactivity as I was traveling and was unable to work on the affected computer.

Briefly, the next steps were:

0. Instlall Anti-Virus
1. Remove bad Hijack this entries
2. Clean Temp Files
3. Kaspersky Online Scan (log wanted in reply)
4. Run Hijackthis (log wanted in reply)
5. Status Check with logs + description of current performance

The performance before this was that I thought everything had been removed. At first, an Internet Explorer window was always opening but the page it was trying to load was no longer available. After the first set of changes in the original post, that problem went away.
But as the logs below will show, it hadn’t been completely removed. I’m guessing that is the case now but am posting the logs below to confirm.

My Actions
1.
I installed Avast Anti-Virus. It seems to have found four infected files, which were all deleted. That log file is here.
6/22/2009 10:15:09 AM 1245690909 daisy 3624 Sign of "JS:ScriptIP-inf [Trj]" has been found in "C:\Users\daisy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A076YT5C\popup[1].htm" file.
6/22/2009 10:16:01 AM 1245690961 daisy 3624 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Users\daisy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VC6C3BEZ\index[1].htm" file.
6/22/2009 10:16:14 AM 1245690974 daisy 3624 Sign of "JS:FakeAV-AI [Trj]" has been found in "C:\Users\daisy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XJNTEDCU\flist[1].js" file.
6/22/2009 10:16:14 AM 1245690974 daisy 3624 Sign of "JS:FakeAV-W [Trj]" has been found in "C:\Users\daisy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XJNTEDCU\scan4area_info[1].htm" file.

2.
I deleted the temporary files using the recommended program.

3.
I ran the online Kapersky scan

KASPERSKY ONLINE SCANNER 7.0 REPORT
Tuesday, June 23, 2009
Operating System: Microsoft Windows Vista Ultimate Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Tuesday, June 23, 2009 06:19:56
Records in database: 2382141

Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area My Computer
C:\
D:\
F:\
G:\
H:\
I:\

Scan statistics
Files scanned 85774
Threat name 1
Infected objects 1
Suspicious objects 0
Duration of the scan 01:12:33

File name Threat name Threats count
C:\Program Files\Alwil Software\Avast4\DATA\moved\index[1].htm.vir Infected: Trojan-Downloader.HTML.FraudLoad.a 1

The selected area was scanned.

4. Here is the new Hijack This log file
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:26:54 PM, on 6/16/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\daisy\Downloads\RSIT(2).exe
C:\Program Files\Trend Micro\HijackThis\daisy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{95A2BCFB-4492-4EDF-83A0-EE3D02F27485}: NameServer = 66.75.164.89,66.75.164.90
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

--
End of file - 4638 bytes
[3days:26yjeyb8][/3days:26yjeyb8]
Hi,

Looks pretty good. One thing that should be done is to update Adobe Reader to 9.1.2 with an update here.
Thanks for the help.
Hi,

Actually, let's get rid of a few hjt entries too.


Disable Ad-Watch.


Start hjt (right click daisy.exe and select run as administrator), check following entries (if found):
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>


Make sure browser windows are closed before clicking "fix checked".

Reboot and post a fresh hjt log.
inactivity