Need Help with Trojan infestation

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Stiina59, Feb 3, 2015.

  1. Stiina59

    Stiina59 Private First Class

    My hubs computer was so buggered up, he was ready to chuck it. I ran the "Run first" process and the first part of the follow up if you still have problems and I do, have the Powelicks Trojan that I read from Tim W, it needs a custom instruction to get rid of it. I am going to attach my logs, but note that I have 3 mb logs because things were so bad, it was the only way I could do the first running, get the two partials. The second log is too large so I need to know how to split it or will zipping it work? The third is the post process running. I don't think I have all of the scan logs, so will follow up with an additional reply with the rest.

    Hope you can help me out. This Powelicks is nasty. At least I have the MB to block it's access to the web. Oops, need to restart that after I stopped it to run a previous scan...



    Thanks from my hubs and I for your help!

    Laura
     

    Attached Files:

  2. Stiina59

    Stiina59 Private First Class

    I had forgotten to run MGTools. Let me know if I didn't run it correctly. Here is that log and the second MB log split into M1 and M2.

    Recap on the MB logs: Original running of MB is in 3 files: MBScan.txt, M1.txt and M2.txt. The MBPost.txt was run before MGTools. This computer is so buggered up, I lost track of where I was at, sorry. If I need to rerun or go back through the sequence, let me know. I will do what it takes to get this thing going again. Seriously, it took an entire hour just to get to the MB logs this morning it was so bad and one of the found infestations changed it's status from Quarantine to ignore and I clicked on Next before I realized it. Massive headache.

    Thanks again.

    Laura
     

    Attached Files:

    • MGlogs.zip
      File size:
      290.7 KB
      Views:
      1
    • M1.txt
      File size:
      248.2 KB
      Views:
      2
    • M2.txt
      File size:
      265.2 KB
      Views:
      1
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your MGlogs.zip file is not a valid file. It is corrupted. Try running MGtools again and make sure you let it finish running. Also do not manipulate/edit or change the ZIP file in anyway.
     
  5. Stiina59

    Stiina59 Private First Class

    Kestral13!

    Thank you but I'm still popping up the malicious website blocked boxes from that
    Trojan. Since we only scanned, that makes perfect sense, duh on my part.

    I'm attaching the 2 logs and Thank you for such a quick reply!

    Off to rerun MG Tools next.

    Laura
     

    Attached Files:

  6. Stiina59

    Stiina59 Private First Class

    chaslang,

    My upload of the MGlog keeps failing...I don't know what to do next. I reran it, I waiting until is said it was done and just above, the MGLog was written and placed on both desktop and in C: drive. Do I need to wait on Kestral13!'s instructions before running it again?

    Thanks!

    Laura
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning. :) We'll get to that soon. I'm just going through your logs and I'm hoping you don't have the infection which encrypts your files... poweliks I can handle, the file encryption I can't, but let me see first... I'll post a fix shortly.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are not attaching the correct log for Malware Bytes! You are attaching protection logs... Please follow the instructions carefully and run it again, attach the correct log for me to check please.


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | {62bac8ef-9549-58f6-aec7-76186374634c} : "C:\Documents and Settings\All Users\Application Data\Microsoft\{62bac8ef-9549-58f6-aec7-76186374634c}\{62bac8ef-9549-58f6-aec7-76186374634c}.exe" -> Found
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | {5a799563-65b4-e689-81ce-1a51d8921b27} : "C:\Documents and Settings\All Users\Application Data\Microsoft\{5a799563-65b4-e689-81ce-1a51d8921b27}\{5a799563-65b4-e689-81ce-1a51d8921b27}.exe" -> Found
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | {62bac8ef-9549-58f6-aec7-76186374634c} : "C:\Documents and Settings\All Users\Application Data\Microsoft\{62bac8ef-9549-58f6-aec7-76186374634c}\{62bac8ef-9549-58f6-aec7-76186374634c}.exe" -> Found
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | {5a799563-65b4-e689-81ce-1a51d8921b27} : "C:\Documents and Settings\All Users\Application Data\Microsoft\{5a799563-65b4-e689-81ce-1a51d8921b27}\{5a799563-65b4-e689-81ce-1a51d8921b27}.exe" -> Found
    • [PUM.Desktop] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore | DisableSR : 1 -> Found
    • [Tr.Poweliks] HKEY_LOCAL_MACHINE\Software\classes\clsid\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32 | a : #@~^A4EAAA==n{F+2i@#@&l{xAPzmOk7+p6(L+1O`r?1.rwDRUtnVsE*i@#@&S4k^+cne'c+b@#@&`@#@&7DDz@#@&i @#@&diWE
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.
    Also at this point, I want to double check the status of Poweliks by having you run another scan with FRST like in my last message and attach the new FRST.txt and Addition.txt logs.
     

    Attached Files:

  9. Stiina59

    Stiina59 Private First Class

    Kestrel13!,

    Here is the correct MB Log and I'm sending the non-corrected report from RogueKiller because this scan results look different and I'm having trouble locating the files you said to delete from the registry tab. I have to leave for about an hour and I thought if you had time to review these and let me know if they are what you need and possibly help me decipher what I'm showing on RogueKiller and what you are telling me to delete are the correct entries.

    Thanks for your help!

    Laura
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just fix these two entries on Reg tab ;)

    • [Suspicious.Path] HKEY_USERS\S-1-5-21-2347551192-1713109559-3450429547-1007\Software\Microsoft\Windows\CurrentVersion\Run | DexzeQkazi : regsvr32.exe "C:\Documents and Settings\All Users\Application Data\DexzeQkazi\AinhAdag.moi" -> Found
    • [PUM.Desktop] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore | DisableSR : 1 -> Found
     
  11. Stiina59

    Stiina59 Private First Class

    Hi Kestrel13!,

    I'm attaching the Fixlog.txt after running the FRST.exe with Fixlist.txt. Unfortunately, MGlogs.zip keeps erring out. I'm going to run the FRST in the mean time and get that log for you. Let me know what I might do to get that MGLogs file to you.

    Laura
     

    Attached Files:

  12. Stiina59

    Stiina59 Private First Class

    Kestrel13!,

    I'm attaching the follow up logs from FRST. I will try again to include the MGLogs just because I like beating my head against hard objects. LMAO! Oh and yes, the upload failed again.

    Now, the pop ups are gone and an old software is suddenly popping up now like it should and may be the reason for the MGtools file failing to upload is our antivius came back on. I've disabled it and will try to again upload the MGtools. If it isnt attached, then I've run out of things to try. And Yes, It did give me another upload error.

    Laura
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you had any pop ups about any of your files being encrypted?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try running MGTools.exe in safe mode.
     
  15. Stiina59

    Stiina59 Private First Class

    Ran MGTools in safemode with networking so I could stay in that mode to try to send the file. I see now why it wont upload, it's size is over 2 MB. What do you want me to do to have it so you can get it? Is there somewhere else I can place it for you to go pick?

    Thanks!

    Laura
     
  16. Stiina59

    Stiina59 Private First Class

    After last MGTools was completed and I rebooted, this is how it comes up, see attached file.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Earlier Kestrel13! stated the below:
    Well that is exactly what you have! It is time to format and reinstall. There is no cure for this. Paying the ransom is not recommended and may not even work and you will have given away your money and credit card info.
     
  18. Stiina59

    Stiina59 Private First Class

    I didn't see that she had said that or I wouldn't have continued on. Sorry about that and I have to say, "Well Crap!" On the reformatting. I can do it but I hate what it takes to reload everything.

    Thanks again for your help.

    Laura:cry
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes Kestrel13! had noticed back in message # 7that some info in your logs displayed signs of this infection, but could not tell at that time whether it really had taken hold. But based on the problems you are having ( like running MGtools ) and the snapshot image you posted, this shows you have a real infection and there are no cures other than a reinstall.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for confirming, Chas. Sorry to hear this Laura. :( Had you made any back ups of your stuff?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before the infection had occurred that is. ;)
     
  22. Stiina59

    Stiina59 Private First Class

    Kestrel13! and chaslang,

    We have backups prior to infestation of anything we want. My problem is, my dear hubs has no clue about software and computer workings and he cleaned up the room that computer is in and all of my manufacturer's disks and software were all together in a marked manilla envelope and he was told that we need to keep it...I cannot find it anywhere and he knows nothing about where it could be. Translation: he threw them away.

    The restore software on it is messed up and I can't get it to make a boot CD, nor will it actually go into the guided recovery software. I tried using the DOS command structure, but either the entire recovery partition is also corrupt or I'm too rusty on my DOS commands to execute it properly. I don't think there's anything wrong with the command: format C: or did I miss some qualifiers? DOS was a loooong time ago, lol. Since the help command won't give me anything either...I'm done unless you guys know of an alternative way to get the thing reformatted and recovered?

    With the age of that computer and the entire situation, I'm going to wash my hands of it unless someone can easily give me some direction on how to proceed. I've already told him that I've done what I can and he can either take it and pay to have it recovered or buy a new one. Since he hates parting with money in any amount, my passive-aggressive method of teaching him to not mess with my disks might work for the next time.

    I appreciate all of your time and effort and I'm sure you understand my frustration. It's hard to accomplish a task with a hand tied behind your back and no tools. I hope you both have a great weekend. I'm going to stop my rant before my blood pressure decides to shoot up.

    You are all an incredible blessing and my thanks again!

    Laura
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not have a Windows Boot CD and your Factory Recovery Partition is corrupted ( which is more than likely true with this infection ) then you are out of luck unless you have a friend who can lone you a full install Windows XP CD. But you still need to have your license key written down somewhere to reactivate Windows. I'm not sure what Microsoft's website will even do now if you try to activate Windows XP since it is not suppored anymore and they strongly advise updating for security reasons.

    All of the programs on your PC and most other files are corrupted with the infection and are not trustworthy and may not even run properly.

    To properly remove partitions, format, and then reinstall you need a Windows Boot CD or you need a set of factory disks for reimaging back to factory ship state.
     
  24. Stiina59

    Stiina59 Private First Class

    chaslang,

    You have pretty much confirmed what I thought after what I was seeing when trying to use the recovery console. Hubs says we got a lot out of that computer and when you consider that is the original OS, you know we've had it for a long time! Since we were just using it to do searches and interface with our Modem and wireless, a replacement doesn't need to be much more than a basic machine. It's nothing like paying $2k for an original Windows computer back in the 80's!

    Thanks for the confirmation that without the disks, it's a total loss. I'm actually laughing because this isn't the first time his sorting methods for the trash can have burned us. I did make sure he wasn't using it for any banking or purchases, lol.

    Take care and thanks again!

    Laura
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds