Various problems, /recycler/ trojan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TaneMarduk, May 6, 2009.

  1. TaneMarduk

    TaneMarduk Private E-2

    The problems I've noticed are these:

    1.) Viewing hidden files and folders were locked OFF, and changing the setting in Folder Options wasn't permanent. Changing it and opening the options dialog right afterwards showed it labeled 'Do Not View.' (Running either SUPERAntiSpyware or MalwareBytes fixed this, at least currently)

    2.) Some programs deny access to running them. 'Windows cannot acces the specified device, path, or file. You may not have the appropriate permissions to access the item.' I'm running on an Admin account, so that shouldn't be happening with things like ComboFix and MGTools, right? No matter what I renamed them, it wouldn't run. It also wouldn't run the MalwareBytes installer, but I had a previous version installed, so I used that in the read and run me. It wouldn't let me run the Rootkit Revealer or Avast! either. (I forgot to try safe mode, but I have to get online at the library, so it's a bit too late right now. I'm going to try again after I get home, but for now I thought I'd post what I have.)

    3.) The OnlineArmor logo disappeared from my Welcome screen a while back, I apologize that I can't remember exactly when. Not sure what that means about the program's integrity on my system, but I bet it's not meant to do that.

    4. Occasionally, the (optical) mouse cursor will jump around the screen in a random direction. This causes a lot of frustration on programs like Blender3D (that don't ask if you want to save) when it jumps to the close button just as I click, and makes me have to start over.

    5.) The computer likes to restart all by itself. It doesn't happen often, but it does happen. There's no freezing or anything beforehand, it just reboots.

    6.) Avira has found trojans in the %root%/RECYCLER/ folder of both of my jump drives, and quarantining the files made the drives fail to operate.

    I haven't been doing anything outrageous, really, seeing as my infected PC isn't connected to the Internet. I download games and stuff from the library's connection, and bring it to my computer on a jump drive. I don't download off the wall things, just games from the yoyogames community, I save text files of game walkthroughs and things like that, and the occasional picture coming from a trusted friend. I scan pretty much everything with at least Avira AntiVir, but I'll scan things that are a bit more suspicious with both SUPER and Malwarebytes as well. I wish I could still use AVG, but they don't allow manual updates anymore so I was forced to switch to Avira. (Looking now, I see that you have a forum for this. I have a question regarding that. Do I need to download every item in the AVG thread, or just the latest one?)

    I have to admit, though, that I didn't read the instructions for running SUPER or MalwareBytes because I've run this check before. I ran a quick scan with SUPER and a full scan with MalwareBytes.

    Anyway, I think that's all of it, and I hope there's some solution to each problem, although 2 and 6 are the most bothersome. Thank you for your time and consideration, I will be awaiting your answer.
     

    Attached Files:

  2. TaneMarduk

    TaneMarduk Private E-2

    My apologies, but I cannot seem to find the edit post button anywhere.

    I started in safe mode and ran ComboFix, but like an idiot, I let the computer restart normally, and CF was blocked from finishing. I rebooted back into safe mode and ran it again, hoping it would fix the problem. Hopefully the CF log has something useful on it.
    I also ran MGTools, and have both programs' logs.
    As for the trojan problem, the drives themselves are easy enough to clean, just explore the folder instead of executing it and delete the /RECYCLER/ folder as well as the autorun.inf file and you're set. (as far as I am aware.) The computer, on the other hand... Now I have a recycler folder in my D partition of my hard drive, and it's protected. Should I remove it in safe mode, or use something like FileAssassin, or some other course of action?

    Remaining logs attached, including the actual version of the mbam log, after the scan was finished completely:
     

    Attached Files:

    Last edited by a moderator: May 7, 2009
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this:

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 6

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\Smab0.dll
    c:\windows\system32\sz390agk.dat
    c:\windows\system32\shroegm.dll
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    I dont know what this is:
    C:\see-eff ---> if you don't, then delete it.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  4. TaneMarduk

    TaneMarduk Private E-2

    See-eff is ComboFix, it evidently created a directory in C:\. I renamed it because I couldn't get it to run. MGTools and ComboFix I have to run in Safe Mode, because of the problems stated in my previous posts.
    I'll be back tomorrow, hopefully, with the results from this step. Thank you for the reply and the help.
     
  5. TaneMarduk

    TaneMarduk Private E-2

    HJT seemed to be successful, there were no error messages or anything. I've never used it before, though, so is the list window supposed to go blank after you click 'fix checked?'

    The registry fix was successful.

    ComboFix, though, ran fine until the computer rebooted... It actually ran from Windows normally, but was denied when it started back up. Should I run it again from Safe Mode?

    The logon screen is also lagging, and has been for about as long as the other problems have been around, I'm guessing.

    I tried to install Java, but it said, "Error 1721. There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor." I tried to install it in Safe Mode, and it said "Your Administrator has taken steps to prevent this installation." or something to that effect.

    Here's the MGTools log, but I don't have the CF log because it didn't finish.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system. I would suggest that you post in the software section for any other issues.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  7. TaneMarduk

    TaneMarduk Private E-2

    Thanks for your time and help. =)
    I really appreciate it.

    My only problem left aside from things that are probably software issues since you said you didn't see anything, is the /recycler/ trojan that Avira is detecting. It's put a hidden, protected folder on both my drives and every portable USB drive I have. Is that a software problem, then, since nothing was detected here?

    I'll run a few of the extra scanners at the end of the process to see if they can do anything about it, but I'd like to know if there's a definite solution.

    Again, thank you for your time, I'm sure you've got lots of other people to deal with. :p
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run this with all usb drives attached:
    Disabling AutoRuns

    and please give me the exact path that avira is reporting.
     
  9. TaneMarduk

    TaneMarduk Private E-2

    From when I try to run my USB drive? Because it doesn't report anything when I scan normally or when I access the /recycler/ folders on my hard drives.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to disable autoruns on both your computer and the usb devices.
     
  11. TaneMarduk

    TaneMarduk Private E-2

    The autorun disable has worked so far to keep it from reinfecting any drives, thankfully, and I'm very grateful for that. But, the folders are still irremovably on my hard drives. Now that I've stopped it from spreading, is there a way to remove the files completely?

    I've attached the screenshot for the detection containing the full path. It's only the one for the drive, though, not the same sequence of numbers as the one that's the same on my HDs.

    The text file is the files that were in the folder, as well as the long number sequence that was the folder names. C:\ had one folder, 1004, and D:\ had four. All but the 1004 in both C and D have stayed gone, but four folders named d9 - d12 I think have appeared with nothing inside.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only way to remove things like that is to empty the recycle bin. The folders will remain, which is normal. Please post in the software section if you have questions about doing that in an external drive.
     
  13. TaneMarduk

    TaneMarduk Private E-2

    All right, so one last question:
    I need to delete everything in the folders, then immediately empty the recycle bin, and it'll stay gone? Unfortunate that the folders can't be removed...
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Emptying the recycle bin will remove the items in those folders.
     
  15. TaneMarduk

    TaneMarduk Private E-2

    Previously, I tried (unsuccessfully) to remove the folders/files using MalwareBytes' FileAssassin, and they turned into folders with files I hadn't posessed/deleted in them. Also, one of my drives was infected again after I had already run the auto run disable on all my drives and the computer at the same time

    Again, thank you for your time, this is probably an annoying task to do all day. :p
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What drive was infected and from doing what? You might try downloading this:
    Autoeater
     
  17. TaneMarduk

    TaneMarduk Private E-2

    Well, one of my USB drives was infected, but it hasn't happened again. I can see the folder and the autorun.ini file, and I can just delete them to fix the drives, but I thought that it was supposed to be unable to do that anymore.
    I'll give autoeater a try, as it seems to be exactly what I need. Thank you.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds