stubborn TROJAN / steps complete

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by edwata, May 13, 2009.

  1. edwata

    edwata Private E-2

    You guys saved me back in January when I came across your site and Malware Removal Guide. I followed the steps and everything worked out. I believe it was my first virus. I am SOOO thankful.

    About 2 weeks ago, one of those fake alerts popped up. I was able to rid it by following the steps again. However, there is a stubborn Trojan that Malware Bytes repeatedly picks up but I can't seem to rid. I don't trust doing my usual financial business and purchasing while it's still hanging around -- even tho nothing appears functionally disrupted.

    I believe I've been careful about following your recommended removal procedures, but I must be mis-stepping somewhere. Have tried to repeat/redo several procedures/scans/etc. I would most appreciate any recommendation you make.

    Am attaching malwarebytes/combofix/MGtools logs.
    I think it's amazing that you folks are willing to look thru these threads and see where you can help. Thanks so much.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, edwata.

    Please attach the last requested log so we can get started:
    SASlog.txt log from SuperAntiSpyware.

    dr.m
     
  3. edwata

    edwata Private E-2

    greetings, Dr M

    so good to hear from you :) ... thanks for reviewing

    attaching the Superantispyware log earlier omitted

    also, an F-Secure log if that is at all useful ... came across it this week while looking for other cues.

    Music files have been found infected with Trojan Gen just yesterday/today :-o limewire was uninstalled months ago


    Ready to follow any Rx you prescribe
    thanks!
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You're welcome, edwata.

    ...beginning my review of your logs - please be patient.

    dr.m
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, edwata


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 2:
    Now we need to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 3:
    Open Ccleaner - select "Cleaner" > "Run Cleaner" <---use this ONLY

    Step 4:
    Now install the latest Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  6. edwata

    edwata Private E-2

    so excited to get your fix ... :wave
    I believe everything went smoothly.
    Malware is no longer indicated on the Malware Bytes scan.

    I have attached the logs to see if things look good to you. I will run another full scan from F-secure tomorrow and see how that looks also.

    Dr. M ~ extreme gratitude for your time and helpfulness.
    Please let me know if you have more suggestions.

    edwata
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Just a couple more things to do....

    Step 1:
    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 2:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this ONLY

    Step 3:
    *You missed doing this step: Install the latest Sun Java Runtime Environment

    Step 4:
    Then attach the below logs to your next reply:
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  8. edwata

    edwata Private E-2

    more thanks ... here's my attached CF report

    Regarding the Sun Java download ...
    I did attempt last time and again. It seems to download, but during the installation process I get a msg asking if I want to re-install? "Yes".
    Quoted response: This action is only valid for products that are currently installed.
    When I hit "OK," it just cycles thru the same and eventually the window closes.
    Add/Remove does not display any Sun Java related programs, nor does Window Install Cleanup.

    When I completed a full system F-secure scan after following your last instructions, the following "virus" was detected:
    wurgyxxh.sys
    Identified as "Trojan.Win32.BHO.ext"
    Location: C:\Qoobox\Quarantine\C\Windows\SYSTEM32\DRIVERS\_wurgyxxh_.sys.zip\wurgyxxh.sys

    Appreciate your kind attention,
    edwata
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds