Trojan horse dropper.delf.aoy

Discussion in 'Malware Help (A Specialist Will Reply)' started by OpRedDawn, Apr 2, 2008.

  1. OpRedDawn

    OpRedDawn Private E-2

    This is in response to current thread by mediachick. I have the same problem, but it won't let me reply in that thread, so I am forced to make this one.

    I have that virus too, tried to follow those instructions in the thread, but when I ran HijackThis, it didn't have the lines that he said to check/fix.

    Any help / instructions would be greatly appreciated (sorry for having to make a new topic)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks

    That is what you are supposed to do. Posting in another persons thread with your own problems is impolite and considered thread hijacking and that is why we don't allow it.


    All fixes are unique for the user they are being provided too.


    Your starting point is the same as it was for themediachick and that is the below.
    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. OpRedDawn

    OpRedDawn Private E-2

    Okay, I am running through the steps listed. The Spybot S&D found and fixed 10 items, some of them being Virtumonde.

    My question now is for the MGtools program. It says not to download onto the desktop... but when my firefox downloads it, it automatically goes to the desktop. Is it alright to launch it from there, but then install to the right directory?
    _________________________________________________________________

    Prior to running these, after a reboot, an error message popped up saying "error loading c:\windows\system32\qxsspnmo.dll - access is denied"

    Also, I found a few viruses using AVG 7.5 free, and now randomly it pops up with "Threat Detected - when opening file (something) from the temp. internet files - virus found LOP). It was strange, becuase this threat message popped up after running CCleaner, which was supposed to get rid of all of those files.
    _________________________________________________________________

    In the morning I will finish off with the remaining programs for the XP Cleaning procedure
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Change your options in FireFox to ask you where to download. Having FireFox default to downloading to the Desktop is a very bad idea and leads to Desktop clutter which is a great hiding place for malware. In FireFox click Tools, Options, and on the Main icon, check the button that says Always ask me where to save files. This is a much better default setting as it always allows you to save files to folders of your choice which can help you to keep your downloads categorize.

    It automatically installs and runs which is why it is required that it be run from the root folder. Running from the Desktop may work okay, but not always.
     
  5. OpRedDawn

    OpRedDawn Private E-2

    Alright. I did that whole malware guide. I thought my compy was fine - AVG hasn't detected anything in awhile....

    Now today, my AVG detected "Trojan Horse Vundo.f"

    It's located in the system32 folder, under ojkmxlpk.dll.vir



    EDIT: Apparently it was already quarantined? Now it says AVG auto deleted/healed it...
     
    Last edited: Apr 16, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Until you complete ALL of the instructions in the READ & RUN ME and attach the logs that were requested, there is nothing we can do for you.
     
  7. OpRedDawn

    OpRedDawn Private E-2

    Alright, attatched are the logs.
     

    Attached Files:

  8. OpRedDawn

    OpRedDawn Private E-2

    Here is the MGtools attatchment
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {9FA51F68-66A3-40A1-9B0F-C5876FE9B7DC} - C:\WINDOWS\system32\nnnmNHyy.dll (file missing)
    O2 - BHO: (no name) - {EC374A84-6C59-451B-8D2A-5CE78F4DC8BF} - C:\WINDOWS\system32\tuvTnLda.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Windows live Messenger] msn.com
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: jkkICRJy - jkkICRJy.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds