Some kind of Trojan?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jimmcc, Jul 14, 2009.

  1. jimmcc

    jimmcc Private E-2

    I'm currently experiencing a problem with my PC. When I open Internet Explorer the search window is autofilled with different characters. If I open notepad or word it will again type characters automatically. I've installed Kaspersky which found and deleted 2 trojans, I also installed SuperAntispyware which also found 2 trojans and 6 adware tracking cookies on first sweep then on second sweep another 6 adware tracking cookies. I viewed the HJT log and the auto typing occured. In fact it also tried to fill in the form when I wasregistering for this site! The auto-typing is still happening at what seems to be random times! can anyone shed any light on this?

    BTW I've d/loaded and installed Malwarebytes, gave it a diff name then ran it in Safe Mode. It also found 2 trojans but after a time it also became corrupt.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome.

    I need to see the logs from runing SUPERantispyware and MalwareBytes Anti-Malware. Were you able to run ComboFix and MGTools? If so I need logs from those too, so to summarise, I require logs from:

    • SAS
    • MBAM
    • ComboFix <--- C:\combofix.txt
    • MGTools <--- C:\mglogs.zip

    If you could attach those into your next reply we can make a start on working up a fix for you.

    Thanks
    Kestrel13!
     
  3. jimmcc

    jimmcc Private E-2

    I've uploaded the past three combo logs as I've been running it on a daily basis to try and keep on top of the thing (hope you dont mind!). Yesterday tho when I went to logon it kept trying to auto fill the password - then mysteriously stopped and I could logon!
     

    Attached Files:

  4. jimmcc

    jimmcc Private E-2

    Here's the MGlog and i'll post the SAS and MBAM as soon as I do a full scan again - Can u tell me how to generate a report in SAS?
    BTW Thanks alot for you help Kestrel - its really appreciated
     

    Attached Files:

    Last edited: Jul 17, 2009
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ideally you should have ran things in order: which meant running SAS and MBAM PRIOR to running Combofix and MGTools. Please refrain from running combofix again until I have had a chance to review the logs you have already given to me :) Also attach the log from running RootRepeal.

    Thanks
    kes
     
    Last edited: Jul 17, 2009
  6. jimmcc

    jimmcc Private E-2

    As requested! Soz about not supplying things in order - I actually deleted mbam and SAS originals as I was convinced they were corrupt OOps just noticed loads of tabs at bottom of Root repeal..do u want a report of each?
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ok so run a full scan with mbam and sas and let me have logs as soon as you get round to it. :)

    Thanks
    Kes
     
  8. jimmcc

    jimmcc Private E-2

    As requested - RootRepeal report
     

    Attached Files:

  9. jimmcc

    jimmcc Private E-2

    As requested SAS log - mbam to follow
     

    Attached Files:

  10. jimmcc

    jimmcc Private E-2

    As requested mbam log. Sorry for the delay but (as you'll see by the log) the scan took almost 4hrs, twice as long as usual!
    I'd be grateful if you could answer a cple of questions (with your experience)if you dont mind Kes.

    1. Why does SAS log trap cookies frm sites never visited?

    and

    2. Can trojans be written that will make them kick in at a specified time e.g. 11:30 am and 11:30 pm?

    Thanks again for your help Kes
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    yes they can.

    Blocking third-party cookies prevents sites leaving cookies on your browser. Most browsers (e.g. IE and Firefox) have the option to block third-party cookies from within the browser options menu.

    1. Before we can continue you must use msconfig to put the machine back into normal mode as requested per the R&R

    2. Please go to Add/Remove Programs and uninstall the below software:

    • Java(TM) 6 Update 13

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    4. Now we need to use ComboFix to remove some remnants from older anti-virus and kill off a few dead BHO's.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\local.user\ByNRaLvhyS.exe
    
    Folder::
    c:\documents and settings\LocalService\Local Settings\Application Data\ESET
    c:\documents and settings\local.user\Local Settings\Application Data\ESET
    c:\documents and settings\All Users\Application Data\ESET
    c:\documents and settings\All Users\Application Data\avg8
    c:\program files\Alwil Software
    
    DirLook::
    C:\9438159368392f0f7cafc8d28f
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    6. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    7. Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    8. Run the new MGTools.exe and attach the mglogs.zip that it generates.

    9. Also attach the log from ComboFix.

    10. Let me know how things are running now!

    Thanks
    Kes13!
     
    Last edited: Jul 21, 2009
  12. jimmcc

    jimmcc Private E-2

    Hi Kes
    Things got kinda worse! I followed the previous steps although I couldnt delete a few Temp items. I removed Java but couldnt install from the link, kept giving me a server timeout error so I downloaded the exe and tried installing that way, halfway through the installation the installer reported that it couldnt open core files. Anyway after that everything went crazy again - as a result I'm posting from a different machine because soon as I logon to the laptop windows are opening everywhere with bleeps a plenty!! - I await your treasured advice.

    PS Sorry for not getting back to you sooner I was away for a cple days
     
  13. jimmcc

    jimmcc Private E-2

    Hi Kes,
    Please find attached the requested files
    Thanks for your support
    Jim
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks like you installed Java SDK 6.14 not the Java that I asked you to install. Did you need SDK?

    When you refer to windows opening, what are the windows for? (like what do they say in them)?

    Thanks
    Kes
     
  15. jimmcc

    jimmcc Private E-2

    The windows opening automatically are random e.g. My Documents. My Computer, My Network Places - seems any icon on my desktop will open randomly! whilst trying to logon to this site v
    .,m#m,.#
    z
    cz
    txcz

    m,.#
    vxcz
    m.#

    vxcz


    m,.#
    cxvz

    m,.#

    xczm,.#
    vm,.#
    vxczmm,.#
    m,.#
    vxcz
    m,.#
     
  16. jimmcc

    jimmcc Private E-2

    Sorry about that post below! but thats the auto typing I told you about earlier the virus or whatever it is kicked in. what I was trying to say was...when I went to logon to this site I was prevented putting my password in as it kept typing itself!!

    I got the java version you requested finally installed
     
    Last edited: Jul 28, 2009
  17. jimmcc

    jimmcc Private E-2

    Hi Kes,
    I was able to get a Hijackthis log during that last episode which i've attached if its any use to you - notice 'Clean.exe' thats what I called Hijack This when I reinstalled it - also

    XCZ
    m,.#
    m,.#
    vvm,.xcz


    #.,xcz
    vxczvxcz

    XCZm#
    m,.#
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I doubt this is an infection especially since none of the logs every revealed any problems. Sounds more like broken hardware or something else you installed. I suggest checking the below

    • does it happen if the keyboard is replaced
    • does it it happens in safe boot mode.
    • does it still happen if Kaspersky is uninstalled. It is somewhat strange to see the below when a keyboard issue is being mentioned:
    • o O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
     
  19. jimmcc

    jimmcc Private E-2

    Hi Kes
    I tried reinstalling Super AS yesterday when I went to rename it the virus kicked in - wouldnt let me install at all. I tried running Malwarebytes but the "Are you sure you want to abort scan?" dialogue appeared repeatedly then automatically stopped the application. Notepad opened up with a load of random characters apart from 'Do Not Steal Our Software' in the middle ( I was glad to see that come up coz I was able to ban my teenage son from the computer!;). I tried to install another antivirus trial that supplied a code to enter when installing, when I tried to enter the code the field auto filled with "iama-ninv-isib-le?f" - i am invisible! Anyway I was able to run Dr Web Cureit via a USB pen and it reported 7 infections, 4 that I knew where false 1 I wasnt sure about (Infected A00???98.exe) and the following 2

    1. Trojan.lowzones.2036
    2. Trojan.Vundo.variant

    This morning (so far) the system is stable (I hope!). I've noticed that Microsoft downloads are downloading automatically again and Kaspersky actually flagged up the following event a few times as I write -
    Detected: PDM.Hidden object C:\DOCUMENTS AND SETTINGS\LOCAL.USER\LOCAL SETTINGS\TEMP\RARSFX2\5QYCD.EXE 5QYCD.EXE
    it has never done anything like that since I installed it! Sooo I'm not sure if the system is clean but I hope the information I've given you will in some way help your battle against Malware etc.
    You're help has been greatly appreciated to date
    Jim
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What exactly occurred during attempting installation?
    Let's try this: Go to the C:\MGtools folder and locate the RunMB.bat file and double click on it to run it. This will attempt to make a renamed copy of the Malwarebytes program (named mgmb.exe) and then it will attempt to run this re-named version. If this runs, it will try to perform a QuickScan. Allow it to finish, then fix all the malware it finds. Then save the log. Attach this log if it does run.


    Be careful doing this as you already have KIS so if you install another AV, trial or not, there are going to be conflictions betweeen the softwares.

    Please attach the log from Dr Web CureIt, I would like to see the full file path of where it is reporting it.

    You can delete this.

    1. answer my question about what happened when trying to install SAS
    2. attach the log from MBAM if you were able to run it following my instructions.
    3. attach the log from Dr Web Cureit

    Thanks
    Kes :)
     
  21. jimmcc

    jimmcc Private E-2

    What exactly occurred during attempting installation?

    First off multiple installations occured at least 12 then when I tried to set the destination folder for SAS the random typing would fill the 'name directory' window then automatically OK it with the result that Windows would return the error dialogue that the folder could not be created because of the filename - I hope that make sense to you lol!

    Let's try this: Go to the C:\MGtools folder and locate the RunMB.bat file and double click on it to run it

    When I doubleclick RunMB.bat the DOS window flickers momentarily then nothing occurs - I tried downloading and overwriting the existing MG tools but the DOS window still flickers and disappears - could you upload the link to uninstall and I'll try a new installation?

    I didn't save a log from Cureit as I thought I had solved the problem :-o please dont be too sore on me!

    At the moment I have a fresh Malwarebytes running a full scan I'll let you know how I get on
     
  22. jimmcc

    jimmcc Private E-2

    Hi Kes
    Well I was able to run a full MBytes scan and it returned no threats. My system has been stable all day today.

    FYI during a restart yesterday CHDSK kicked in automatically and reported Volume on C: was dirty then completed a cleaning - I havent a clue if this is/was associated with the problems I was experiencing but I thought u'd like to know.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi ya :)

    Please refer back to message #18 and answer my questions

    Thanks
    kes13!
     
  24. jimmcc

    jimmcc Private E-2

    Hi again Kes

    1. I cant really replace keyboard as I'm using a Laptop

    2. Auto form filling was happening long before I tried Kaspersky - it was the auto typing that alerted me to the possibility of a virus, my original AV was AVG.

    I have switched my browser to Firefox to see if that helps. I've had no instances of autotyping however, last night when I went to open a program from the desktop at least 6 other applications around that application on the desktop also opened.

    FYI I'm using a wireless mouse - not sure if it's that that may be malfunctioning?

    Hope this information is helpful - Thanks again for your interest and brilliant support
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Laptops can use external keyboards. Would it be an option to try one of those?

    And you should try removing the wireless mouse to see what happens. Other than this, as it is not a malware issue there is nothing else I can suggest for you here. If you wished to you could take it up in the software forum.

    and finally... your logs are clean :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  26. jimmcc

    jimmcc Private E-2

    Thanks a million for your help Kes it really was appreciated - Keep the battle going!;)

    Jim
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    hey you're very welcome! :) safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds