Trojan Dropper Msil.T: preventing me moving in READ FIRST guide...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Little Wolf, Jan 19, 2011.

  1. Little Wolf

    Little Wolf Private E-2

    Hey there, I recently ended up with said Trojan Dropper Msil.T and have tried to complete your READ FIRST instructions.
    Everything was going well until the Rootsrepeal stage, when the scan would get stuck at C:/WINDOWS/winsxs/Manifests, failt o progress, and continue to rise in Physical Memory usage until it shut itself.
    In case of messing up recovery, I have not advanced from this stage
    I have, however, after combining thoughts and advice from other similar situations from people online, have found 1192 files in this directory which begin 'msil' (manual searching) and I suspect these are the files in question. I have no however acted on this yet as I know deleting/changing even the slightest wrong thing can be fatal.

    Here is what has happened so far (details slightly dodgey at earlier stages)

    17.01.11/18/01/11
    >Sony Vegas Movie Studio HD Platinum 10.0 downloaded and installed. No apparent problems

    >Bejeweled 3 installed. No apparent problems

    >Scheduled scan usually reveals between 40 and 70 removed tracking cookies if internet has been used. On this ocassion, I told me it had also found infections/rootkits but had failed to remove or heal them. My worry rears.

    >Runs Malwarebytes. It finds two files which it deletes. I think problem is solved

    >> details here are a little hazy, as I were a little panicy. I think at this stage I ran another scan through AVG and it either found two similar (but different) trojan named files which it removed, or the same files were found/not removed.

    >Knowing by this stage that I have a backdoor trojan, I set to find out how to eradicate this

    >At this point I downloaded Prevx after good scoring and recommendation around a number of sites. This indeed found one or two extra files that AVG has missed, however the free version would not allow me to do anything about them. Malwarebytes were claimnig my computer were clean, as was AVG

    >Asks a friend with some knowledge of this type of situations and he warns me that the multiple anti-virus software will collide and to get rid of all but one, avoid the internet where possible and give the scanning another go. This tried, and failed.

    >End up here

    >Followed READ FIRST instructions up until Rootrepeal. Hit said brickwall.
    Have installed AVG back onto the computer after removing to complete tests.
    There's been so physical signs of the virus yet as such in terms of affecting the system in a noticable way, but I cringe to think what it COULD be doing.

    Find attached the logs from the tests I did complete.
    Thanks in advance for any help.

    p.s. I sincerely believe that neither the mentioned installations previous to acquiring the trojan dropper are the cause.
     

    Attached Files:

  2. Little Wolf

    Little Wolf Private E-2

    Also, Java(TM) 6 update 5 refused to uninstall; gave me the error

    "Error opening installation log file. Verify that the specified log file location exists and is writable"


    And I run a 32-bit computer
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I still need the log from running C:\MGTools.exe ---> C:\MGlogs.zip
     
  4. Little Wolf

    Little Wolf Private E-2

    Ah sorry! My bad.
    Here it is, better late than never.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Give me the exact file path of the folder containing the files you describe.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Why, what happens when you tru to uninstall one of them? Which one do you wish to keep? According to your logs unless you made changes after posting I see both avg 2011 and MSSE installed.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    jnv4_mib
    File::
    c:\users\STACEY~1\AppData\Local\Temp\jnv4_mib.sys
    Folder::
    C:\Windows\1C4551A64743409391E41477CD655043.TMP
    C:\Windows\D56B0E274A3E46C9B5C1D93D580C099C.TMP
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{773AB9C0-905B-4131-A1D5-6CE9E8160E67}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{8BB952FC-FAA9-4D57-B2F7-F73F3DDE020A}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Run Ccleaner. Not the registry section, simply the cleaner.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. Little Wolf

    Little Wolf Private E-2

    Thanks again so much for this, so appreciate all the time you're putting in.:)

    C:\WINDOWS\winsxs

    C:\WINDOWS\winsxs\Manifests

    Both Directories feature files beginning 'msil': in the first directory they are folders, and in the second they are MANIFEST files.
    I have attached a printscreen of each.

    Oh sorry for the confusion: there was no difficultly uninstalling the antivirus', I just mean that scanning again with just the one anti-virus didn't help to detect the trojan files.
    And yeah I was using AVG, but seen as this is the programme that let this trojan in, and considering various warnings from a friend, I switched to MSE.
    Sorry if this is a problem.

    Anyways, down to business. I have followed the instructions you gave me. Only thing to note really was there were no complications, and also just to note that during the Combofix process I got a Windows error saying that 'PEV' has stopped working.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The folders you described are fine! Leave them alone. You can read more about them here

    AVG 2011 is still showing as being installed and that IS a problem because you also have MSSE! Uninstall avg, then run this
    AVG Remover(32bit) 2011
    (avg_remover_stf_x86_2011_1165.exe)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. Little Wolf

    Little Wolf Private E-2

    Thank you so much :) I've followed the instructions, just going to read through the "How to Protect...." now.

    Computer seems fine - glad you ended mystery of the msil files haha. Should that winsxs folder be so big though? I kinda get fromt he article that it can be a space hog but is there no way to condense this? ;o
     
  9. Little Wolf

    Little Wolf Private E-2

    Ahh, I know this will move me down the pile, but I'm a bit concerned.

    Not all of the features are loading on my facebool (e.g. the logo and some of the images) and there ahs been no change in internet speed or anything objective like that. This is happening on Opera but not Firefox (as far as I can see)
    Also when I click to create a shortcut in a folder, nothing is happening

    Could these be effects of the malware removal process? Or possibly the change in registry or something?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No.
    No. This is something to work out in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds