1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Whitesmoke Trojan

Discussion in 'Malware Removal' started by jennb, Dec 7, 2010.

  1. jennb

    jennb Private E-2


    It would appear that my husbands laptop has gotten this nasty virus. We have Malwarebytes, and Spybot on the laptop as well as McAfee. Malwarebytes and Spybot both found something and corrected itself. All was good.....
    I can't find a program to uninstall. But I was going to download and use AVAST instead. I can not connect to the internet on that laptop...I get a red screen saying no virus detected. It does this for any site.

    So I came here and wanted to know the best way to go through the DO ME FIRST post when I can't get to where I need to be.

    Thank you so much for any help you can give! I greatly appreciate it!

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You mean you are trying to uninstall Mcafee?

    Do not install avast until mcafee is definately gone.

    Well you can transfer the tools needed in the Read and Run me first to the sick computer using a flashdrive or a disk.
  3. jennb

    jennb Private E-2

    I'm sorry I realize now looking back at my original post that some of it did not make much sense.

    Whe he first ran a scan and it popped up whitesmoke, I could click on start and it showed up on my list of programs. My first thought at that point would be to uninstall it. There was not anything there. I have since removed McAfee from that laptop.

    I will download everything to a flashdrive and try that. I just didn't know how that would work with not being able to update the definitions and all.

    I will go through all of that and come back and see what lovely things pop up. Thank you, I really appreciate you taking the time.

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If necessary, as stated in the R&R:

    Manual update files that you can transfer over if needed. You will need to transfer the installer and update files over, install the software and then run the update files.

    You're most welcome. I will be here waiting.
  5. jennb

    jennb Private E-2

    Still working through it.....sorry its taking so long....so far everything is popping up with nothing but but I keep getting redirected to a particular site. I am not finished yet.....once I do I will upload the logs. Thank you again for your patience. :)
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't worry, just go at your own pace, and post again once you have got the logs. :)
  7. jennb

    jennb Private E-2

    Ok....after much arguing with my computer....the holidays....and a case of MRSA....I am back.....I finally got through the read and run thread. Right now I am not seeing further "whitesmoke" issues but I am still having problems....I am getting redirected about half the time on the internet regardless of the browser. I am also getting some error messages saying I am not authorized because I am not admin, but there is only one account.


    at your leisure.....I hope you all had an EXCELLENT CHRISTMAS!!!!!

    Also I am a 64 bit so I did not run RootRepeal....I think that is everything....


    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Jennifer.

    Let's continue on

    First of all the below needs to be done as it could interfere with the fix.

    How to disable Spybot's TeaTimer

    Java(TM) 6 Update 22 <--- Uninstall outdated Java

    Using windows explorer, delete these pair of folders:
    • c:\users\Household\AppData\Roaming\Gosy
    • c:\users\Household\AppData\Roaming\Syxee

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Now you must describe to me how things are running! :)
  9. jennb

    jennb Private E-2

    Ok....I turned off teatimer....and updated the Java per your instructions. After the TDSSKILLER ran and I rebooted per instructions it popped up with another box Windows defender saying I had some bad mojo.....I would tell you specifically what that mojo is but the box disappeared after running the MGtools. Anywho....

    Here are the logs for the MGTools and the TDSSKiller

    I am looking and looking and I CAN NOT FIND THE LOG for MGTools. I know where its supposed to be I found it before. But its not there. I even did a search on the entire computer for it. I hate that.....It did all kinds of yummy goodness that it didn't do before. I am running it again......to try and got some kind of log but I can't find it.....GRRRRR......
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just attach the TDSSKiller log (as it did not attach) and then re-run C:\MGTools.exe. THEN there should be a C:\MGLogs.zip
  11. jennb

    jennb Private E-2

    ok I just finished running it again and I still can't find the zip file either by just freaking looking or by searching for the name.....should I uninstall MGtools and re-install and then run again? I will wait for further guidance....

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget to attach the TDSSKiller log!

    No, try this first.

    Please do this, click Start, Run and enter cmd and click OK. This will open a command prompt window. In the command prompt window, enter the below commands each followed by the enter key. Note there is a space after the cd

    cd \MGtools

    You got a C:\MGLogs.zip now? If not...

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Got a C:\MGLogs.zip now?
  13. jennb

    jennb Private E-2

    ok here is the tdsskiller log and I will redo the MGTools as directed!

    Attached Files:

  14. jennb

    jennb Private E-2

    I am in the process of doing the instructions for the MGTools....I was able to run a scan which is what your instructions ultimately had me do.....getlogs.bat what I can't find now like I did the FIRST time is once the scan is complete...and it says to press any key to continue (once I press the key) I go to get the zip file....and its not there.... that is the problem I am having...it runs the scan fine but the file isn't there....I will try both of your thoughts and see whats shaking when I'm done....

  15. jennb

    jennb Private E-2

    Ok I finally got one....but it put it in some really weird RANDOM place....the comand prompt even says C:\MGtools.zip

    it put it in c:\\Users\Household\AppData\Local\VirtualStore


    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    :confused I don't know.

    Now before I review those logs, and while you are still online, please run TDSSKiller again for me and attach the log.

    (Getting late for me, almost 3am)
  17. jennb

    jennb Private E-2

    I am so sorry....I had gotten so irritated that I closed my pc's down for the night.... I did the scan I got one more log.. I changed it from cure to copy to quarantine as instructed on the page. Here is the log.

    Thank you again for all of your help! I really appreciate it.

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Was there an option to cure rather than quarantine? (Try that again) I am going to have you run it one more time and attach the log. That last log still shows a rootkit infection.
  19. jennb

    jennb Private E-2

    There was an option to cure but it said to copy to quarantine. I thought that odd myself. ANyway I did the scan again left it at cure. Rebooted as instructed here is the log but now when the computer boots up I get an error message that says the following.


    There was a problem starting

    i have no idea what this means. I am on my way out the door to work. I will check in and do what I can while I am at work. I didn't realize there was such a significant difference in time.

    Thanks again.

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It means there is still malware present, but we will find it!

    That last TDSSKiller log looks more promising. I will have you run it yet again after this next fix to see the new results.
    Yes, I'm in the UK. However I enjoy the peaceful hours of the early morning so I am often still about and posting at that time. Night owl. Okay, I'll post a fix in a moment.

Share This Page

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds