Jump to content

Malwarebytes Can't Remove Two Trojans


Recommended Posts

My computer was running slow and I ran a quick scan with Malewarebytes, which detected two trojan agents. When I clicked on remove, I was directed to re-boot my computer and the trojans would be removed on re-boot. After re-booting, I ran Malewarebytes again, and it detected the same two trojan agents. I've run Malwarebytes a number of times, re-booting after each scan, and the same two trojans appear:

HKey_Local_machine/software

C:\Windows\oqozugitixezo.dll

Here's a scan of Hijack This:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:51:50 AM, on 4/13/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe

C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Macromedia\Flash Media Server 2\FMSEdge.exe

C:\Program Files\Macromedia\Flash Media Server 2\FMSCore.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\ALCXMNTR.EXE

C:\Program Files\twc\medicsp2\bin\sprtcmd.exe

C:\HP\KBD\KBD.EXE

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\twc\medicsp2\bin\sprtsvc.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Winamp3\winampa.exe

C:\Program Files\Viewpoint\Common\ViewpointService.exe

C:\WINDOWS\wanmpsvc.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\windows\system\hpsysdrv.exe

C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\Program Files\America Online 7.0\aoltray.exe

C:\Program Files\hp center\137903\Shadow\ShadowBar.exe

C:\Program Files\hp center\137903\Program\BackWeb-137903.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://*.windowsupdate.com

O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab

O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Flash Media Server (FMS) (FMS) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe

O23 - Service: Flash Media Administration Server (FMSAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe

O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBOID.EXE

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SupportSoft Sprocket Service (medicsp2) (sprtsvc_medicsp2) - SupportSoft, Inc. - C:\Program Files\twc\medicsp2\bin\sprtsvc.exe

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--

End of file - 10641 bytes

And a scan of Malwarebytes:

Malwarebytes' Anti-Malware 1.36

Database version: 1975

Windows 5.1.2600 Service Pack 3

4/13/2009 10:10:44 AM

mbam-log-2009-04-13 (10-10-44).txt

Scan type: Quick Scan

Objects scanned: 95357

Time elapsed: 15 minute(s), 39 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 1

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mfosugupiditemek (Trojan.Agent) -> Delete on reboot.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\oqozugitixezo.dll (Trojan.Agent) -> Delete on reboot.

Link to post
Share on other sites

  • Staff

Hi,

Please update malwarebytes once again and scan with it - reboot and post the log in your next reply :D

Also, I see you have Viewpoint installed...

Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This will change from what we know in 2006 read this article: http://www.clickz.com/news/article.php/3561546

I suggest you remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.

  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
Link to post
Share on other sites

Oops.................since my last scan with Malewarebytes earlier today, I now have more trojans. Here's the log file of my just completed scan:

Malwarebytes' Anti-Malware 1.36

Database version: 1976

Windows 5.1.2600 Service Pack 3

4/13/2009 1:10:57 PM

mbam-log-2009-04-13 (13-10-57).txt

Scan type: Quick Scan

Objects scanned: 95548

Time elapsed: 35 minute(s), 53 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 1

Registry Keys Infected: 0

Registry Values Infected: 1

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 3

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

C:\WINDOWS\mcbyrfi.dll (Trojan.Vundo.VM1) -> Delete on reboot.

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mfosugupiditemek (Trojan.Agent) -> Delete on reboot.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\mcbyrfi.dll (Trojan.Vundo.VM1) -> Delete on reboot.

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\XY1X04IL\aff_15[1] (Trojan.Vundo.VM1) -> Quarantined and deleted successfully.

C:\WINDOWS\iniqucihiciqu.dll (Trojan.Agent) -> Delete on reboot.

Link to post
Share on other sites

Sorry about taking so long to respond. My computer was in the middle of it's scheduled anti-virus (Avira) scan, and it slowed down everything else. I've re-booted and did a scan with Hijack This. I've removed Viewpoint Manager and Viewpoint Media Player. The other program listed is Viewpoint Toolbar and when I clicked on remove, it gave me two options - permanently remove it, or leave some components to manage bookmarks. Which one should I opt for? Here's the Hijack this scan:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 2:03:26 PM, on 4/13/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe

C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Macromedia\Flash Media Server 2\FMSEdge.exe

C:\Program Files\Macromedia\Flash Media Server 2\FMSCore.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\Program Files\twc\medicsp2\bin\sprtsvc.exe

C:\WINDOWS\ALCXMNTR.EXE

C:\Program Files\twc\medicsp2\bin\sprtcmd.exe

C:\WINDOWS\System32\svchost.exe

C:\HP\KBD\KBD.EXE

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe

C:\WINDOWS\wanmpsvc.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Winamp3\winampa.exe

C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\windows\system\hpsysdrv.exe

C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe

C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\Program Files\America Online 7.0\aoltray.exe

C:\Program Files\hp center\137903\Shadow\ShadowBar.exe

C:\Program Files\hp center\137903\Program\BackWeb-137903.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://*.windowsupdate.com

O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab

O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Flash Media Server (FMS) (FMS) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe

O23 - Service: Flash Media Administration Server (FMSAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe

O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBOID.EXE

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SupportSoft Sprocket Service (medicsp2) (sprtsvc_medicsp2) - SupportSoft, Inc. - C:\Program Files\twc\medicsp2\bin\sprtsvc.exe

O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--

End of file - 10426 bytes

Link to post
Share on other sites

I've removed the Viewpoint Toolbar permanently, and removed the item from Hijack This and then ran another Malwarebytes quick scan. It's found no malicious objects!! Did this fix it?

I have a couple of questions - my last Java update a few days ago included the Yahoo Toolbar. I don't use it and can't find a way to remove it as it's not on the Add/Remove Programs list. Is there a way to remove it? Secondly, I'm using Avira Anti-Virus, and wonder if I should be using something else?

Here's the last Malwarebytes scan:

Malwarebytes' Anti-Malware 1.36

Database version: 1978

Windows 5.1.2600 Service Pack 3

4/13/2009 3:00:18 PM

mbam-log-2009-04-13 (15-00-18).txt

Scan type: Quick Scan

Objects scanned: 95427

Time elapsed: 18 minute(s), 41 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

  • Staff

Hi,

I don't even see the Yahoo toolbar installed here though... and if I'm not mistaken, it's unchecked by default during the java install... so not sure if you have installed the Yahoo toolbar after all. Where do you see it? Because it's certainly not in IE.

And yes, Avira Antivir is a great Antivirus, so I would keep that one anyway. :D

I also see some AVG parts present here, so since you can only have one Antivirus, please uninstall AVG.

Please read my Prevention page with lots of info and tips how to prevent this in the future.

And if you want to improve speed/system performance after malware removal, take a look here.

Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.

Happy Surfing again!

Link to post
Share on other sites

Thanks Mieke for all your help! I really appreciate it very much! I am noticing that my computer is running slower than usual, and will read your recommendations.

The Yahoo Toolbar is at the top of my browser (FireFox), and I thought perhaps it was slowing down my computer.

Link to post
Share on other sites

  • Staff

Aah, it's in your Firefox? Then look in your Firefox extensions and uninstall it from there.

Click "Tools -> Add-ons > extensions and look for Yahoo Toolbar.

Please uninstall AVG, because it causes an extra slowdown especially since you already have Avira installed.

And you're most welcome :D

Link to post
Share on other sites

Thanks again Mieke!

I removed the AVG from the Add/Remove programs list, and I've been reading your page on speeding up the computer and removing some items from the start-up. It's already moving a little faster. My computer was a demo computer, the last model that was available in the store (Circuit City), and on sale. So there's items on the programs list that were used for demonstration that I don't use.

I'm finding you page on prevention and how to improve computer speed very helpful! Again, thank you!

Link to post
Share on other sites

  • Staff

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.