Trojans keep coming back

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cruiser1968, Jun 15, 2010.

  1. cruiser1968

    cruiser1968 Private E-2

    The problem started about a week ago. A popup said there was an infection on the computer. I tryed to close the window but the popup persisted. I went thru the steps to remove malware one by one. It got rid of the popups about the infection but the other trojans that were found keep coming back after a short while. I have all the logs. Help Please!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then please attach them to your next reply.
     
  3. cruiser1968

    cruiser1968 Private E-2

    It looks like I have been able to git rid of the malware but in doing this it seems there is another issue. When the computer is re-booted a message comes up saying Windows can not open this file (sqlmangr.exe.vir). Windows needs to know what program created it.I did a search and found it in Program Files\Microsoft SQL Server\80\Tools\Binn. Another message comes up about sgsqh.dll. I found this at C:\Qoobox\Quarantine\c\Windows\System32. I guess this is a folder that Combofix creates. If you still need the logs I will attach them on my next post. Thanks for the help!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can't do anything unless I can see your logs.
     
  5. cruiser1968

    cruiser1968 Private E-2

    Here are the first 3.
     

    Attached Files:

  6. cruiser1968

    cruiser1968 Private E-2

    Here are the other 2.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, let's see what we can do.
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\kbduqlu.dat
    c:\windows\system32\adrehc.dat
    c:\documents and settings\srs103095\Local Settings\Application Data\vvketnxvk
    c:\windows\system32\kqggjleijuyye.exe
    c:\windows\system32\wpdmtsdr.dat
    c:\windows\system32\nmmkceit.dat
    C:\WINDOWS\system32\kbduqlu.dat
    C:\WINDOWS\system32\wpdmtsdr.dat
    
    Rregistry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "skb"=-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. cruiser1968

    cruiser1968 Private E-2

    This got rid of one of the problems but I still get the popup saying "Windows cannot open this file sqlmangr.exe.vir. Attached are the logs you asked for.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    sqlmangr.exe is not a virus. It is part of the Microsoft SQL Server Service Manager and therefore, you probably need to uninstall the C:\Program Files\Microsoft SQL Server, run CCleaner and then re-install it if you use it.

    One other file that needs to go is this:
    c:\documents and settings\srs103095\Local Settings\Application Data\vvketnxvk

    I am not seeing any other malware in your system, so I suggest you post in the software forum for assistance with your Microsoft SQL Server issue.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  10. cruiser1968

    cruiser1968 Private E-2

    Tim,

    Thanks for the help. Sorry I didn't get back to you sooner but I had to go out of town. Thanks again.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. And you are most welcome. Safe surfing. :)
     
  12. cruiser1968

    cruiser1968 Private E-2

    I don't know how but they came back. I went through the steps again and everything seemed ok but AVG said it found 2 problems. It showed the same thing twice (Windows\system32\bxtgv.dll). I told AVG to remove them. One was sent to the virus vault but the other said it was inaccessible. Any ideas?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If this is the full path to the file:
    C:\Windows\system32\bxtgv.dll --> then you can use Avenger to remove it.

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Then attach the below logs:

    * C:\Avenger.txt
     
  14. cruiser1968

    cruiser1968 Private E-2

    Here is the log.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It says the file does not exist.
     
  16. cruiser1968

    cruiser1968 Private E-2

    Thats what I am seeing now, the message doesn't come up any more. AVG is still popping up and telling me there are trojans. I went through the whole process again and I am attaching the logs.
     

    Attached Files:

  17. cruiser1968

    cruiser1968 Private E-2

    Here are the rest.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs now show you to be very compromised! Let's try this all over again. Or else you sent me the wrong Combo log.

    Please do the following:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now reset your router back to factory settings. If you had it specially configured, you will have to reconfigure it after we are done.

    Now follow these instructions to remove your proxy settings:
    Change Proxy Settings.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\Fqaqeham.dat
    C:\WINDOWS\Ocikesagubinagog.bin
    c:\windows\system32\fgsqh.exe 
    c:\windows\system32\sgsqh.dll 
    c:\windows\system32\ogsqh.dll
    c:\windows\system32\kbduqlu.dat
    c:\windows\system32\adrehc.dat
    c:\windows\system32\kqggjleijuyye.exe
    c:\windows\system32\wpdmtsdr.dat
    c:\windows\system32\nmmkceit.dat
    c:\windows\system32\jboeycse.exe
    c:\windows\system32\inetpin.dat
    c:\windows\system32\powrprmf.dat
    
    Folder::
    C:\Documents and Settings\srs103095\Local Settings\Application Data\vvketnxvk
    C:\Documents and Settings\srs103095\Local Settings\Application Data\wnswtpbks
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    "QuickTime Task"=-
    "AppleSyncNotifier"=-
    "iTunesHelper"=-
    "SunJavaUpdateSched"=-
    "skb"=-
    "MChk"=-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!

    Also attach the log from AVG showing what it is reporting.
     
    Last edited: Jul 8, 2010
  19. cruiser1968

    cruiser1968 Private E-2

    Here are the latest logs. A message stating rootkit activity was detected. So far everything seems to be OK but it took a couple of days before the problems came back last time. I am going to send the AVG log in my next post. Thanks again for all the help.
     

    Attached Files:

  20. cruiser1968

    cruiser1968 Private E-2

    I tried to send the AVG log but when I try to upload it I get a message "Invalid File". I looked at the contents and it said 0 infections. What I saw before didn't come up during a scan but would just pop teling me it found something (whatever it was) and I would tell it to move it to the vault.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds