Getting a new trojan every few days

Discussion in 'Malware Help (A Specialist Will Reply)' started by wheat, Mar 28, 2011.

  1. wheat

    wheat Private E-2

    Hi there. About two weeks ago I was having Google redirect issues, but your helpful guide solved the issue. But, my heart sunk the next day when my AV found another trojan, though it did not have any obvious effects on my system like the virus before it. Things would look ok for a few days after removing it, then my AV would pop up with another and so on so I finally decided to get around to following your removal procedure.

    I found a few baddies along the way; however, something went wrong when I tried to run RootRepeal. After it tried to initialize for a little while, a small window popped up with nothing but a red circle with an 'X' and an 'OK' button underneath. Not really thinking, I pressed the 'OK' and my machine quickly rebooted. On startup Windows gave me a prompt saying the system recovered from a 'serious error.'

    The contents of the error report Windows asked me to send were these two files:

    Code:
    ...\LOCALS~1\Temp\WEReb38.dir00\Mini032811-01.dmp
    ...\LOCALS~1\Temp\WEReb38.dir00\sysdata.xml
    Now I'm a bit antsy about proceeding and wanted to come to you guys before doing anything else. Hoping this is a good enough start & you guys can work your magic.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You also need to attach the C:\MGLogs.zip.
     
  3. wheat

    wheat Private E-2

    Here is the MGLogs.zip. Sorry for the delay.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Download Registry Search (see the link titled RegSearch Download Link )

    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independent) and click Ok... option, enter the below bold string (use copy and paste)

    • itlperf
      itlsvc
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.


    Now download and install Registrar Lite

    • Open up the program and from the menu at the top select "search"
    • In the "search in" box choose/navigate to HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
    • In the "what to look for" box ensure that key names, value names, and data boxes are checked.
    • In the "text or data to search for" box copy and paste itlperf into it and press enter. The software will run a search, be patient, eventually after a few moments the results will be displayed. If anything *is* found you should be able to click on "export results" from the menu at the bottom (little disk icon) and save to a text file to attach here.
    Let me know how you get on.
     
    Last edited: Mar 29, 2011
  5. wheat

    wheat Private E-2

    The fixME.reg was successful.
    RegSearch went smoothly; however, Registrar Lite told me I couldn't export the results (1 result) unless I used the Pro version. :(
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wrong link to Registrar Lite was given. Uninstall that version and use the one at Registrar Lite
     
  7. wheat

    wheat Private E-2

    This version didn't have the disk icon to export results. :-o
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it does! 4 buttons to the left of the magnifier glass button ( used for searching ). But you can also just use the menus rather than the buttons too. Just click File, Export
     
  9. wheat

    wheat Private E-2

    Ahh, I see, thank you. I hope I did this right...
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks like you forgot the below step:
    Repeat the search for itlsvc too and attach those results also.
     
  11. wheat

    wheat Private E-2

    Sadly I'm having a difficult time getting this down right. Unlike the first version I used, this version doesn't have a disk icon at the bottom of the search window. I see the disk icon in the main window, but it says 'export key' when I hover over it and when I save it, it produces the same result that I attached above, I'm guessing because the search action isn't recognized in the main window. Basically I can't seem to pin down the search results. :confused

    Is there any way to get the search results from the search window to the main window? (I attached a pic of both windows as I doubt I wrote all of that clearly enough)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not need to export anything. Nor is a search necessary either. Just do the below.


    Copy the bold text below to notepad. Save it as fixIT.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Are you currently having any malware problems?
     
  13. wheat

    wheat Private E-2

    The merge was successful.

    As far as my system goes, I think things are looking very good. My AV hasn't detected any new trojans ever since running the initial malware removal procedure. :)
     
  14. wheat

    wheat Private E-2

    Sorry for bumping, but I wanted to mention that I just ran a scan and detected a virus named Gen:Variant.Buzy.2749. That's the first virus I've seen that didn't have some generic trojan name.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Silly names that scanners give are just about useless. What we need to know is exactly where and what was detected? Like file and folder names ( full paths ) or registry keys...etc. This may be a false detection or could be just a detection of what we already removed. This is part of the reason the READ & RUN ME instructions ( right at the start ) state not to do anything we don't ask you to do. Not even other scans. You need to wait until we are 100% finished and have performed final instructions. So let's do this now and then see what happens.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. wheat

    wheat Private E-2

    Will do. Hopefully this will keep me out of your hair for a long while. Thank you very much, guys.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds