trojans remain after READ & RUN ME

Discussion in 'Malware Help (A Specialist Will Reply)' started by prillernut, Jun 19, 2009.

  1. prillernut

    prillernut Private E-2

    Hi guys,

    Our computer is not exhibiting notably different performance, but our AVG AV has found a couple of trojans. I’ve completed READ & RUN ME, but the infections appear to remain.

    This computer is has 5 user accounts, all Limited Access except for one which I only use for maintenance. Two days ago, upon logging in, a user immediately received an AVG window warning of the trojan infections. Apparently, a previous user picked up an infection somewhere earlier that day – I have been unable to secure a confession :) I immediately ran a full AVG scan, resulting in finding the trojan infections. Attempting to remove failed, receiving the message “Moved object is bigger than the archive size limit”.

    Yesterday I ran all the steps of Malware Removal “READ & RUN ME FIRST”, including the “Windows XP Cleaning Procedure”. I discovered and unsuccessfully attempted to uninstall “MyWay SA” via Add/Remove Programs - received RUNDLL error message “specified module could not be found”. The other steps appeared to run well. After completion of the READ & RUN, a new scan with AVG shows 2 trojan infections remain, and MyWay SA is still in the Add/Remove Programs list.

    Thanks for your time,
     

    Attached Files:

  2. prillernut

    prillernut Private E-2

    and here's the MG log -

    Thanks for your time :)
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Since your logs are basically clean, you will have to give us a log showing exactly what and where AVG is finding problems. If it is in System Volume Information then it is just in System Restore and you need to toggle system restore to remove them.


    In the meantime, you need to do the below.

    Uninstall all of the below:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    Spybot - Search & Destroy 1.5.2.20
    Viewpoint Media Player


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Please run the below to cleanup left overs from Symantec then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)
     
  4. prillernut

    prillernut Private E-2

    thanks chaslang :)

    I uninstalled the listed items, did the fixme.reg entries and got a Registry Editor window indicating sucess, then ran NRT with reboot twice.
    I just ran a new AVG scan, and it found nothing http://img241.imageshack.us/img241/6611/banane01rp0.gif

    I checked Add/Remove Programs, and "MyWay SA" is still there -
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it sounds like the registry patch really was not successful. Did you have any protection software running that may have blocked the change to the registry.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the new C:\MGlogs.zip file
     
  6. prillernut

    prillernut Private E-2

    Thanks for your continued help, chaslang,

    I'm not sure if any of the protection software I'm running would have been a problem -
    AVG A-V Free 8.5.339 (it shows it's Anti-Spyware component active - hmmm?)
    Ad-Aware (just a scanner, right?)
    Spybot 1.6.2 (Teatimer was disabled)
    SpywareBlaster 4.2 (just for Internet protection?)
    SpywareGuard (IIRC, I had exited SG so it should not have been a factor)
    and the 2 new apps SAS and Malwarebytes - I'm not familiar with them, only their use as specified in the WinXP Cleaning Procedure -

    I didn't receive any messages showing a blocking of our attempted registry change, but I take it that doesn't necessarily mean it took -

    I downloaded the current MGTools, replacing the existing copy. Hovering the cursor over the new icon, it showed the same "Date Created: 6/18/09 6:14 PM", so I assume it's unchanged.

    It would not open with right click, "Run As...", so I went ahead and double-clicked it (the user account I'm working under is an admin account). I didn't know if it would create new MGTools or MGlogs.zip folders - it didn't - it starting running immediately, so UAC did not get disabled, nor the Spybot Teatimer, nor SpywareGuard. I'm running WinXP - FWIW, it didn't complain -

    Hope I didn't bugger it up, here's the new zip file -
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to the logs you just attach, MyWay is not there.

    No it is newer! And there is an even newer version now. ;)

    The Run As instructions are for Vista users as stated. Also UAC only pertains to Vista as stated.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. prillernut

    prillernut Private E-2

    thanks chaslang!

    I've been out of town, and finally got back to finish up - everything appears to be fine :) The MyWay SA still is shown in the Add/Remove Programs list, but clicking on it gives only the indication that it's been used rarely - no other info or buttons - so I assume it's some sort of benign leftover.

    Thanks again, and I really do appreciate your time and help! http://img26.imageshack.us/img26/7696/yourockk.gif
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

     
  10. prillernut

    prillernut Private E-2

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds