Trojan malware? Unable to remove..help

Discussion in 'Malware Help (A Specialist Will Reply)' started by wifeymvp, Jul 26, 2010.

  1. wifeymvp

    wifeymvp Private E-2

    I have followed the READ ME FIRST instructions to a tee, but Trojan virus won't go away. I have most logs ready to be reviewed...please help me!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Until you have attached the logs we requested, you are not finished. ;) So please attach them. Not sure what you mean by "most logs"????
     
  3. wifeymvp

    wifeymvp Private E-2

    By most, I meant rootrepel, MGtools, and malware bytes....l was unable to run combofix because I got an error that said access is denied....logs that I was able to save are:

    MGTOOLS====ATTACHED

    ROOTREPEAL

    ROOTREPEAL (c) AD, 2007-2009
    ==================================================
    Scan Start Time: 2010/07/23 22:52
    Program Version: Version 1.3.5.0
    Windows Version: Windows XP SP3
    ==================================================

    Hidden/Locked Files
    -------------------
    Path: C:\hiberfil.sys
    Status: Locked to the Windows API!
    ________________________________

    DEFROGGER

    defogger_disable by jpshortstuff (23.02.10.1)
    Log created at 00:36 on 24/09/2002 (Ortiz)

    Checking for autostart values...
    Unable to open HKCU\~\Run key (5)
    HKCU\~\Run values retrieved.
    HKLM\~\Run values retrieved.

    Checking for services/drivers...


    -=E.O.F=-

    ___________________
    SUPER ANTI SPYWARE====ATTACHED

    _______________
    MALWARE BYTES-ANTI MALWARE====No log created....no malicious software found
    _______
    WILL ATTEMPT TO RUN COMBOFIX AGAIN AND POST RESULTS....THANKS FOR YOUR HELP!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you did get a log from MGtools as you just attached it?

    Access denied to running ComboFix.exe or when you ran ComboFix you started seeing errors saying this? Did you have Spy Hunter and Symantec shutdown as requested ( all protection should be disabled when trying to run ComboFix and even MGtools to avoid problems).

    Why is the clock on your PC set to the below?
    It's Tue September 24, 2002 12:02:32 AM

    You can have lot's of non-malware problems by not having the correct date and time. This even has made your logs from MGtools not that useful since there is too much in the logs because you date was not properly set. And if the date was incorrect when you got infected, it will be even harder to find any malware when the date is corrected since it would make the malware files appear to be very old which means they would not show in the logs. Also having the date wrong could even stop ComboFix from running properly. However based on your MGtools logs, I can see that ComboFix actually was run at some point in time and removed pieces of a TDSS infection. Was this something you did a long time ago and never cleaned up by uninstalling ComboFix which you should have done?


    You don't appear to be having malware problems since your logs are clean. What I see as your problems are inadequate amounts of memory and almost no free hard disk space is available. Your logs show the below:
    Code:
    Total Physical Memory 512.00 MB 
    Available Physical Memory 210.80 MB
     
    Drive C: 
    Description Local Fixed Disk 
    Compressed No 
    File System NTFS 
    Size 18.64 GB (20,012,072,960 bytes) 
    Free Space 218.61 MB (229,228,544 bytes) 
    
    You need to at a MINIMUM, double your memory and you need to either delete alot of unneeded files from your harddisk or you need to upgrade to a much larger hard disk. 20 GB is way too small by todays standards. You simply cannot run any version of Windows from Win 2K or above with only 218 MB free. It will run slower than a sleeping snail.
     
  5. wifeymvp

    wifeymvp Private E-2

    I attached the MGtools log....for some reason, but computer keeps setting to the wrong date and time and I'm constantly updating it....also, do you have any suggestions to free up memory until I'm able to upgrade? Not sure where to go to begin the process or what files/programs will be safe to delete....thanks for your help!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you need to replace the BIOS backup battery.

    Actually what I would be suggesting would be using more since you do not have proper protection installed. You have no antivirus and are using the inadequate Windows firewall when you need a real firewall.

    However you could uninstall all the toolbars like Google and MSN and uninstall Google Desktop. Also uninstall Roxio as mentioned below. Remove unnecessary startups like Adobe, Blackberry, PowerDVD, and Comcast\Desktop Doctor.

    You will have to figure out what you are saving on the PC that is using all the space. This is not a topic for the Malware Forum. Perhaps you are saving too many things you download like AVI, MPG, JPG, MP3, etc. I see you have LimeWire and perhaps you are download and saving too much with it. Remove all these unnecessary files from your PC or backup them up to CD or DVD first and then delete them. Uninstall any programs you don't use or need. For example I see you have Nero installed so why in the world would you want Roxio installed which is not as good as Nero and Roxio is wasting memory and diskspace.

    You also have left overs from uninstalling Symantec which did not uninstall completely and you should run the below removal tool:

    Norton Removal Tool (SymNRT)

    In reality, you really need a much larger harddisk these days. 20GB is just too old and too small.



    Since you are not having malware problems, it is time to do our final steps, this will also free up some space but only a little:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds