newb needs help getting rid of trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pistons23, May 6, 2008.

  1. Pistons23

    Pistons23 Private E-2

    i was running webroots spysweeper and it found Troj/Virtum-gen. it fails to quarentine and remove the trojan everytime. it says this file (C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1015\A0070304.DLL) is the infected file. so far ive downloaded Ccleaner and ive updated my java environment file. i also have my msconfig set at normal startup. right now im currently running kaspersky anti virus scan. next im going to try that hijack program i keep seeing everyone posting about. i dont know much about computers, so can someone please help me? thanks in advance
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The file you are mentioning is in System Restore. The only way to remove files from System Restore is by disabling and then reenabling System Restore. However before you do that I would strongly advise you to run the below cleaning procedure. Virtumonde infections can put many other files and registry keys on your PC that most scanneres will never see.
    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Pistons23

    Pistons23 Private E-2

    ok im to the windows xp cleaning procedure. im about to download the mgtools program, but it says to save as a root folder. so when the popup comes up to run or save, i click save, but im not sure where to. the others went to the desktop.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't save it as a root folder. You save it to the root folder which is normal C:\ Just navigate to this folder and save it.

    Thus you would have C:\MGtools.exe after saving it.

    If you are using FireFox, you need to change the options so that it allows you to choose where to download to. FireFox defaults to saving to the Desktop which is not a good default.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just in case you don't know how to do the above, here is how.;)

    If FireFox is what you are using, Click Tools, Options, and on the Main tab select Always ask me where to save files. If for some reason you still have a problem trying to save MGtools.exe properly. You can download it to your Desktop and move it after downloading, or if necessary (but we prefer not) run it from your Desktop.
     
  6. Pistons23

    Pistons23 Private E-2

    here are the first 3 logs. sas removed 6 items. spybot didnt find anything. malwarebytes found 1 item. im not sure what combofix found. also how do i set my clock back? its reading 19:27 instead of 7:27

    first log is super anti spam, next is the malwarebytes and last is the combofix. ill post the mgtools one tommorow.
     

    Attached Files:

  7. Pistons23

    Pistons23 Private E-2

    i thought that the mgtools program would take alot longer than it did. i shouldve done it last night. oh well here is the log.
     

    Attached Files:

  8. Pistons23

    Pistons23 Private E-2

    i also ran vundofix and it didnt detect anything
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now let's remove a left over service from Roxio

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to LiveShare P2P Server 9
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteRoxLiveShare9 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Uninstall SUPERAntiSpyware now since we are finished with it.


    Is your copy of Spy Sweeper a paid version that actually fixes problems? Or is it just a trial? If a trial, uninstall it now and keep Windows Defender installed. If Spy Sweeper is a paid version, keep it and uninstall Windows Defender.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O15 - Trusted Zone: www.winzy.com

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Pistons23

    Pistons23 Private E-2

    alright i just ran C:\MGtools\GetLogs.bat

    so you want me to attach the log that it just created and then run combofix again? correct?

    also, when was i supposed to reboot?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry no you did not need to run ComboFix. I was supposed to edit out that line. And no reboot was needed.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  12. Pistons23

    Pistons23 Private E-2

    well i just rebooted before reading your last post. i forgot to mention that the reg edit was a sucess. i also ran C:\MGtools\GetLogs.bat again. i also ran combofix again. here are the logs.
     

    Attached Files:

  13. Pistons23

    Pistons23 Private E-2

    i just ran webroots spysweeper and it detected no spyware or viruses. boot times have been shortened quite a bit. also load times for programs seems to be better. when browsing the internet, page loads seem to have gotten faster.
     
  14. Pistons23

    Pistons23 Private E-2

    can i get rid of malwarebytes too? all i need to is the disable/enable system restore
     
  15. Pistons23

    Pistons23 Private E-2

    ok i went to run spysweeper again and found that it quarentined trojan-backdoor.gen. i seen the spysweeper notification that something was quarentined last time i ran combofix. do i have another problem?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can uninstall it but I would recommend keeping it and stay updated. It only runs when you run it. It does not use any system resources otherwise.

    You need to complete ALL of my instructions including the System Restore part before you run any other scans or you will possibly be detecting non-problems. Even what you mentioned with Spy Sweeper could just be a non-problem from quarantines or System Restore. If you don't post a log from what Spy Sweeper is detecting, I cannot tell you. Spy Sweeper logs have been quite poor in the past.
     
  17. Pistons23

    Pistons23 Private E-2

    yeah i got everything done now. computer is working great. i just think spysweeper thought combofix was doing something bad. because it only quarentined that trojan-backdoor.gen when combofix would first run and when it uninstalled itself.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great!

    That's why the instructions page for ComboFix given in the READ ME say the below:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds