Trojan fever

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by marysmail, Jun 10, 2009.

  1. marysmail

    marysmail Private E-2

    Today I opened what I thought was a good movie (yes, what a genius, eh?) and suddenly Antivir started popping warnings about trojans (many with different names) one right after the other, non-stop.

    Read & Run all done. Since I finished it, no pop-up messages have come from Antivir, but who knows if I'm safe...

    I'm attaching the logs. (And deleted said movie a couple of hours ago...)
    Thanks in advance to the real genius out there,
    Mar.-
     

    Attached Files:

  2. marysmail

    marysmail Private E-2

    Anyone out there who could please help me with the logs?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should learn to read all of the stickies

    Don't Bump! It only Hurts You!!!

    The above was even given to you in the READ & RUN ME.

    This bump cost you at least 2 more days.


    You are way way out of date with your version of Malwarebytes. You need to always keep your programs updated. Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.


    I strongly recommended you cut down on the use of all the P2P and torrent download programs. Did you know that many forums will not help you at all until all of these are uninstalled. We may soon be demanding this too.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 7



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • the new Malwarebytes log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 18, 2009
  4. marysmail

    marysmail Private E-2

    Hi, C.

    Malware wouldn't let me update the last time. It did now, I ran it again.
    Re torrents etc: I did not know that.
    I ran the Messenger uninstaller. Should I stick to MSN messenger then? I would avoid it completely, but lots of my work contacts are on messenger (Skype's hasn't quite kicked in here in Argentina).

    Also, sorry for the double posting. Had a lapsus.

    I'm attaching the logs.
    A couple of things happened:
    1. I keep getting this message from Antivir warning me about a file named TR/Crypt.XDR.Gen . Got it while running Malware, Ccleaner, MG... and just right now 6 more times.
    The one warning me about the TR/Agent.ANAB went away I think.

    2. This morning when I turned on the computer a window popped up saying it couldn't find the file "csrcs.exe" and that probably some things wouldn't load properly... I accepted and it went away. I'm mentioning it just in case.

    3. Also after rebooting I got a message from windows saying something about an error from "User1.exe" (guess that's me) and needed to be closed. Got 8 or 9 of those messages one after the other.

    I think that's all... thanks
    Mar.-
     

    Attached Files:

  5. marysmail

    marysmail Private E-2

    I don't know if this may or may not help, but I ran a complete scan from Antivir and got a log from it. I'm attaching it just in case. Maybe it's useless, but well... you'll be the judge of that.

    I keep getting warnings about that Crypt.XDR.Gen thing every 2 minutes...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use whatever others are using but that should not be Windows Messenger which was discontinued by Microsoft a very long time ago. Their current messengers are Windows Live Messenger and also Microsoft Communicator.

    If this is a PC used for work, why would you risk using things like BitTorrent, DNA, eMule, and LimeWire. In many companies, this would be grounds for termination You risk having company and/or customer information being stolen and if the later occurs, you risk having a large law suit.

    Many of these infections we are currently removing are probably due to using these programs. If these programs are still on your PC the next time you have to come here for help, we will possibly refuse to help you.

    No! Please do not run anything that we do not ask you to run. This was stated in the READ & RUN ME. It is only finding things we have already removed and confusing the cleanup process. After we finish your cleanup you can run whatever you want. Until then, please run only what we ask you to run. Don't even run MBAM or SAS again unless we ask you to do so.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [User1] C:\Documents and Settings\User1\User1.exe /i
    O4 - HKUS\S-1-5-18\..\Run: [User1] C:\Documents and Settings\User1\User1.exe /i (User 'SYSTEM')
    O4 - Startup: zqosys32.exe

    After clicking Fix, exit HJT.




    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )




    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 18, 2009
  7. marysmail

    marysmail Private E-2

    I'm attaching the logs.

    One thing, after running HJT couldn't find the following:

    O4 - HKCU\..\Run: [User1] C:\Documents and Settings\User1\User1.exe /i
    O4 - HKUS\S-1-5-18\..\Run: [User1] C:\Documents and Settings\User1\User1.exe /i (User 'SYSTEM')

    Weird?

    Apart from that, everything seems normal.

    Thanks,
    M.-
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean. You just need to boot your system into normal startup mode with MSconfig as requested in step 1 of the READ & RUN ME. What are you trying to control in the boot.ini file?

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  9. marysmail

    marysmail Private E-2

    What did you mean by controlling something in the boot.ini? Uh oh... I've got no idea.

    Just before I go and take the final steps... Today I got a warning from Antivir about a TR/Rabbit.HE . I'm sorry, this seems to be neverending. I've barely used this computer over the past days for Internet stuff. Just Illustrator and 3d programmes.

    :confused
    M.-
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See step 1 of the READ & RUN ME and put your PC into Normal Startup mode with MSconfig and it will not be an issue.

    It is a waste of time to just tell us the name of an infection without saying exactly where it is being detected. We need full path file names or registry keys. A log is most useful. However if you have not complete our final instructions which remove things from ComboFix quarantines and toggled System Restore, you could just be finding things that are not issues.
     
  11. marysmail

    marysmail Private E-2

    Ouch, sorry, had no log whatsoever, it was just a message that popped up.
    I went through step 3 of the Read&Run and I haven't gotten any more warnings and everything seems to be running ok.

    Lastly, you said I should put my pc into Normal Startup Mode. Should I keep it like that or should I go back to the Selective Mode, as it was?

    Thank you for your help. So, so very much!
    Mar.-
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Normal Startup means that is how you should normally be running. Selective Startup is only meant for temporary debugging. See the info and link given in step 1 of the READ ME.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds