Malware, Possible Trojan logs attached

By Jacal
Jun 17, 2007
1. Norton died on me one day and when i checked back this computer, it was filled with virus.

I did the virus removal process and so far it is cleaned up alot, also have renewed norton subscription.

The rootkit program found nothing.

2. kitty500catTS EvangelistPosts: 2,154   +6

Your system is infected with malware.

Very important: Before deciding whether to clean or reformat your system, read this thread and decide what you want to do.

Go and read the Viruses/spyware/malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT, ComboFix, and AVG Antispyware logs as attachments into this thread, only after doing the above. Also post here the results of the AVG Antirootkit scan.

This thread is for the use of Jacal only. Please dont post your own virus/spyware problems in this thread. Instead, open a new thread in our Security and the Web forum.

3. JacalTS RookieTopic StarterPosts: 83

ummmm lol it never auto saved the report >.< ... i have to run a new scan sorry

4. kitty500catTS EvangelistPosts: 2,154   +6

OK, but please post an AVG Antispyware log.

5. JacalTS RookieTopic StarterPosts: 83

here is the AVG log.

6. kitty500catTS EvangelistPosts: 2,154   +6

Run HijackThis with no other programs open. Place a tick in the little boxes next to the following entries (if there):

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present

O16 - DPF: {413D6754-BFD4-47FE-9346-319559290BFA} (HTECtrl Class) - [http]www.webpcfos.com/webpcfos/websabre/HTEweb_new.cab

O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} - [http]update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe

Click the Fix Checked button.

Go into Add/Remove Programs in your Control Panel and remove anything having to do with VideoEgg, MyWebSearch, or FunWebProducts.

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, start The Avenger program by double clicking on its icon on your desktop.

Under "Script file to execute" choose "Load script from file".
Now click on the folder icon which will open a new window titled "open Script File"
navigate to the file you have just downloaded, click on it and press open
Now click on the Green Light to begin execution of the script

4. The Avenger will automatically do the following:

It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the restart, it creates a log file that should open with the results of Avenger's actions. This log file will be located at C:\avenger.txt
The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

Do the following yet.

Enter the following in to the text box at the top of the page

C:\WINDOWS\Matrix Code.exe

Click Submit.

Do the same with the following two files, one at a time:

C:\WINDOWS\matrix code.scr
C:\WINDOWS\mickey32.dll
.

Please post fresh HijackThis, ComboFix and AVG Antispyware logs, as well as the Avenger log (located at C:\avenger.txt). Also post here the results of the Jotti virus scan.

This thread is for the use of Jacal only. Please dont post your own virus/spyware problems in this thread. Instead, open a new thread in our Security and the Web forum.

7. JacalTS RookieTopic StarterPosts: 83

Sorry took so long went to sleep xD

matrix code.exe found to be ok.
C:\WINDOWS\matrix code.scr found to be ok
C:\WINDOWS\mickey32.dll. found to be ok
by the jotti website.

Here are the logs.

8. kitty500catTS EvangelistPosts: 2,154   +6

Have HJT fix the following entries (if there):

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present

Now run The Avenger again as per the instructions, but use the script file attached to this post instead.

The attached script is only for this user. If you are not this user, do NOT follow the instructions as they could damage your system.

9. JacalTS RookieTopic StarterPosts: 83

The two files that you told me to fix in hijackThis are not going away but i will still attach the logs.

And avenger is not finding a majority of those files due to the address in place.

10. howard_hopkinsoTS RookiePosts: 24,177   +19

Delete this bold folder.

C:\DOCUME~1\DIVERS~1\APPLIC~1\FunWebProducts

Other than that, your system looks ok.

If youre still having problems, post fresh Combofix and HJT log.

11. JacalTS RookieTopic StarterPosts: 83

Ok i will howard...and thanks

