Help with removing stubborn trojan horses

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nostos, Feb 23, 2010.

  1. nostos

    nostos Private E-2

    Gents,

    I have an old and rather slow desktop PC at home. I bought an antivirus (shield deluxe 2009) which I use occassionally (install run virus check) and uninstall because it slows down my computer too much. The last time I run a virus check a few days ago it found about 5 adware and one Trojan.generic.227692 in the system volume information\_restore....which it could not remove.

    I was told to go into my computer properties system and tick off something I have forgotten and try to run the virus check with the operating system in safe mode. Shield could not run in safe mode and so I downloaded hijacjthis, run it, analysed and created the uploaded log file which I hope comes with this message.

    Can somebody look at this file and tell me how I can delete the remaining viruses, trajan horse from my C drive?

    Also can you recommend an alternative to Shield deluxe antivirus that does not take too much proceesing power out of my PC leaving me unable to use it?

    Thank you very much for any help you are able to offer me
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to MG's!

    Do this first>

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Open HJT and do a scan only and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now:

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. nostos

    nostos Private E-2

    Thank you TimW,

    I think I have now followed the advice as best as I could. I did not understand very well the last step about disabling monitoring of the drives in system restore and rebooting.

    What then...., run the super antispyware, malware.... etc from the beginning? or just reboot twice ..once with system restore disabled and once enabled because this is what I understood and did.

    Now I am not sure I have got rid of all the trojan horses. How can I tell? I still detect a funny behaviour in the mozilla browser. Sometimes when I search for something in google it first takes me to another webpage or fires an adverd. Then I have to go back and click on the web page again before it takes me where I want to go. Is this a sign of another malware? How can I eliminate it?

    Finally, once my PC is clean do you recommend I uninstall superantispyware and malwarebites and reinstall Shield deluxe 2010?

    Thank you very much for your help.

    Best regards

    Nostos
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I gave you instructions to first open HJT ( that you attached in your first post ) and check the box for each of the items I listed and then click Fix!

    After doing that, I need you to run and attach to your next reply ( in this order ):
    SAS
    MBAM
    RootRepeal
    ComboFix
    C:\MGTools.exe ---> log is produced at C:\MGLogs.zip.

    That is all I want you to do. Attach those logs and do nothing with system restore until we are sure you are clean.
     
  5. nostos

    nostos Private E-2

    Tim,

    I am sending you the Hijack this log again because no matter what I do following your initial instructions I keep getting the same log back.

    I will upload the combofix log in a minute but I have no SAS file. I have run the SAS program the first time. It found some problems which I asked it to quarantine but I don't know if and where it would save a file. Today I have run it again. it found no more issues. Still no file.

    I have rerun Malwarebites and I am sending you the file it created as well as the other files from the first time I run what you told me.

    Something must still be wrong at least with the Mozilla browser I am using because when I do a search with google it rarely get me to the link first time. I have to go backwards and forwards a few times before I go where I want to go and at the same time it fires up other mozilla windows sometimes with adverds, sometimes with porn sites. Should I uninstall Mozilla and use another browser?

    Thank you for your help

    Nostos
     

    Attached Files:

  6. nostos

    nostos Private E-2

    I am sending the combofix file
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am frankly surprised this system runs at all!! You need at a minumum 4 times the amount of RAM you have:
    Total Physical Memory 256.00 MB
    Available Physical Memory 65.21 MB

    It appears as though you did not run the HJT fix from my first post to you. Plus the MBAM log that you attached indicates that you did not fix what it found. You other logs appear to indicate that you did.

    It is a very bad idea to allow all users to have Admin. privileges!! You will need to run SAS and MBAM on all user accounts now.

    Please take ComboFix out of the folder and put it directly on your desktop, not here:
    c:\documents and settings\Yiannis\My Documents\Downloads\ComboFix.exe

    It should be here:
    c:\documents and settings\Yiannis\Desktop\ComboFix.exe

    Your SAS log is here:
    Code:
    "C:\Documents and Settings\Yiannis\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    supera~1.log  27 Feb 2010        2351  "SUPERAntiSpyware Scan Log - 02-27-2010 - 10-34-21.log"
    
    Now, Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now to be doubly sure:
    Reset Host File


    • Open Notepad.
    • Copy and Paste everything from the Code Box below into Notepad: (Do not include the word Code:)
      Code:
      @Echo off
      pushd\windows\system32\drivers\etc
      attrib -h -s -r hosts
      echo 127.0.0.1 localhost>HOSTS
      attrib +r +h +s hosts
      popd
      del %0
    • Go to File >> Save As
    • Save File name as FixHosts.bat
    • Change Save as Type to All Files and save the file to your Desktop.

    Now double click on the desktop FixHosts.bat to run the batch file. It will self-delete when completed.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\Mlewuyuruw.bin
    c:\windows\Xsepadosexasux.dat
    C:\WINDOWS\Temp\hlktmp
    C:\Documents and Settings\All Users\Application Data\LPBLHKTCG
    
    Folder::
    C:\WINDOWS\Temp\hlktmp
    C:\Documents and Settings\All Users\Application Data\LPBLHKTCG
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=-
    
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters\interfaces\{d8ccfe83-9ea7-4abb-aba1-f1a45f4cc4ef}]
    "DhcpNameServer"=""
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. nostos

    nostos Private E-2

    Thank you for your support Tim,

    I have three accounts in my PC and I have now run SAS and Malware bytes on all of them as well as the other two bat files you told me to run. Finally I run the analyse.exe once more and now I did not see the many O1 lines so I gues I must have made some progress.

    What do you think? Should I reinstall Shield deluxe 2010 instead of SAS and Malware bytes? Is it better? The last time I installed it it was slowing down my PC very much even when I was not running the antivirus. Is there any way to stop these programs working in the background when you do other things and only run them when you want?

    Thank you

    Nostos
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to install an AV program that is not resource hungry. Or install a lot more RAM. ( You can go to crucial.com and have it scan your computer to tell you how much RAM your system can handle.) SAS and MBAM are backup scanners, not AV full time programs ( unless you purchase them). I might suggest that you consider either Avira or Avast.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. nostos

    nostos Private E-2

    Thank you Tim,

    I have done everything up to running the processes of the last link.

    I will do them tomorrow

    Before I close can I ask you to have a look at the processes my PC is running.
    Is it healthy all these svchost.exe processes are running? What do they do?

    I am grateful for all the help you have offered me

    Nostos
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Quite a few processes run on the svchost file. That is quite normal. Nothing to be concerned about. If you want to control your start up programs, you can use this:
    Startup_CPL
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds