Stubborn Trojan Help:

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TheCthulhu, Jun 25, 2012.

  1. TheCthulhu

    TheCthulhu Private E-2

    Hello,

    I'm hoping you can help me with a stubborn trojan. I don't know how I got it as I'm very careful and always visit the same safe sites. I hadn't been doing anything - just watching a video I've watched (and is clean) many times and the PC restarted on its own. It continued to restart again and again, telling me "Windows has encountered a critical problem and will restart in one minute". The only thing I had done recently is run Windows Update and updated Microsoft Security Essentials.

    So at this point I uninstalled MSE and that stopped the restarting issue. I tried reinstalling it and the restarting issue began again. So I once again uninstalled it and grabbed Anti-Malware. I ran that and it found a trojan in two places in the registry. It would not, however, remove them.

    I then ran ESET online scan and that also found the trojan but could not remove it.

    I have now uninstalled all virus software and am hoping you can help me remove this.

    The infected file is:

    800000cb.@

    And I believe it is the Zero Access trojan.

    If anyone could give me a hand it would be much appreciated.

    Thank you!
     
  2. TheCthulhu

    TheCthulhu Private E-2

    I've tried posting a log from TDSSkiller but it is too big to post as an attachment so I'll copy and paste it here I suppose........
     

    Attached Files:

    Last edited by a moderator: Jun 26, 2012
  3. TheCthulhu

    TheCthulhu Private E-2

    Oh, and also when I run TDSSkiller it gives me a message "couldn't load driver" but continues on anyway. I right-clicked TDSSK and ran as admin.
     
  4. TheCthulhu

    TheCthulhu Private E-2

    RogueKiller report
     

    Attached Files:

  5. TheCthulhu

    TheCthulhu Private E-2

    HitmanPro log
     

    Attached Files:

    • log.zip
      File size:
      1,018 bytes
      Views:
      1
  6. TheCthulhu

    TheCthulhu Private E-2

    MGLog
     

    Attached Files:

  7. TheCthulhu

    TheCthulhu Private E-2

    Anti-Malware log......
     

    Attached Files:

  8. TheCthulhu

    TheCthulhu Private E-2

    Hey all,

    Just got ComboFix to run (wouldn't before) in safe mode and it seemed to work. It removed the offending files (that I know of - 800000cb.@ and 800000.@) and now scans by Anti-Malware come up clean. If there is anything else you think I should do, let me know. And thanks either way.......great forum you've got here for helping people......
     
  9. TheCthulhu

    TheCthulhu Private E-2

    Or not.......everything seemed to be coming up clean but I now tried reinstalling and running Security Essentials and while it doesn't constantly restart like before, something is preventing me from turning on real-time protection as well as from downloading updates. I ran a scan with it without the updates and it is seeing a trojan. Said it removed it ok, but upon restart it is back. Nothing else seems to be finding it.......
     
  10. TheCthulhu

    TheCthulhu Private E-2

    Yeah, now MSE is reading:

    TrojanDownloader:Win32/Cutwail.BE

    Combofix doesn't seem to find it, nor does Anti-Malware.......
     
  11. TheCthulhu

    TheCthulhu Private E-2

    Ok, so I removed the other one now with HitmanPro. I reinstalled MSE, however, I still cannot turn on real-time protection. I've also noticed I am now denied access to my Documents and Setting folder among other thaings - it says I do not have permission. I tried changing the permissions in the properties, but it doesn't allow me to.

    At this point MSE, Anti-Malware, HitmaPro, and ComboFix are all coming up completely clean.

    Just keeping you updated on my progress while I wait.....
     
  12. TheCthulhu

    TheCthulhu Private E-2

    Well it seems that everything is clean at this point but I'm left with some problems.

    Windows Update is gone from the services and because of this obviously won't update.

    Security Essentials installs and scans fine, but will not turn on real-time protection.

    I DID get the firewall on and working again by replacing registry entries, then turning the service back on. Working fine now.

    If anyone could assist me in getting update and MSE running again it would be most helpful........
     
  13. TheCthulhu

    TheCthulhu Private E-2

    Well this was.......ummm......helpful. Hmmm.........
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Did you happen to see the warnings about Don't Bump! It Only Hurts You!!! '

    Continually posting in your own thread cause your thread to be missed as it looked like it was already in process to everyone.

    I suggest that you do the below so we can see if your PC still has infections. Previous logs showed at least one system file was infected.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds