TR/Crypt - TR/Buzus - TR/Dropper --- Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mtell, Apr 6, 2012.

  1. mtell

    mtell Private E-2

    Hi,

    My computer has recurring viruses. Avira alerts me, I try to remove, computer scans clean, then the viruses come back again in a few days. So they were not removed properly. This is a picture of the viruses I have:
    http://oi43.tinypic.com/jpu6fq.jpg

    So I need some help from MajorGeeks please.

    Please find attached logs, I have done all the requested steps in the sticky.

    Many thanks!!! Happy Easter.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the requested C:\MGlogs.zip file from MGtools.

    Also note that it would be better to attach a log file from Avira rather than a screenshot that has incomplete information. ;)
     
  3. mtell

    mtell Private E-2

    Hi - Please see the MGLogs attached.

    I could not post this 5th attachment until my post was approved sorry about that.

    I dont have an Avira log, I erased all quarantines as the sticky suggested, and I only ran the approved tools. Pic was just for the file names to show what I have. Sorry about that!

    Thanks again!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem. ;)

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  5. mtell

    mtell Private E-2



    • TDSKiller can not be reached. Can you pls recommend an alternative DL link? I dont want to mess up and get the wrong one.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just tried it. It works fine for me. Give it another try.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. mtell

    mtell Private E-2

    Thank you for fast reply. TDSkiller did work from my non-infected computer so I used a USB to transfer it.

    Attached are the logs for:

    TDSSKiller

    MBRCheck

    Thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 20

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! We may need to run some other scan tools if you still have problems.
     
  10. mtell

    mtell Private E-2

    Hi - I have a Windows XP problem with "uninstaller", I dont think its related to the virus, but it gives me errors when uninstalling things. I know you are a not a help desk for XP, so I dont mean to slow things down. Is that okay if I just keep both versions of JAVA for now and proceed with the rest of your post?

    Because I can not uninstall Java(TM) 6 Update 20.

    http://oi42.tinypic.com/2h4l5bs.jpg
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just keep going.
     
  12. mtell

    mtell Private E-2

    Hi - Thanks again for all your help.

    I have turned off all browser windows/anti-vir, and printed the instructions you wrote out, and have completed the ComboFix step.

    Computer is still shutting down, its been about 30min so far in the process of shutting down, so I will give it enough time then post both logs.

    Just if you can let me know, how long does the computer need to shut-down/reboot after a CombFix? Is it okay to wait up to 1hr? It went from the grassy landscape, to the blue windows shutdown, but its taken 30min.

    Thank you.
     
  13. mtell

    mtell Private E-2

    Hi - Please find attached the following logs:

    C:\ComboFix.txt
    C:\MGlogs.zip

    Many thanks!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs look good. You forgot to tell me how things are working.
     
  15. mtell

    mtell Private E-2

    Hi - Thank you very much for getting rid of the virus and helping me, making the stickies and guides, and checking the logs!

    The computer seems fine now, but I think some viruses dont always show right away - but if you think the logs are good, then it must be okay.

    Can I make a donation to you via PayPal for your help? Many thanks happy Easter!
     
  16. mtell

    mtell Private E-2

    Hi - Virus has reappeared when I ran the Avira again.

    Here is a screen shot. I have also uploaded the Avira report log, please see attached.

    Is there anything else I can do to try to get rid of the virus?

    Thank you!

    http://oi44.tinypic.com/md1kit.jpg

    Begin scan in 'C:\' <OS>
    C:\Qoobox\Quarantine\C\Documents and Settings\James\Application Data\rwytsqz.exe.vir
    [DETECTION] Is the TR/Trash.Gen Trojan
    C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1\A0001001.exe
    [DETECTION] Is the TR/Trash.Gen Trojan
    Begin scan in 'G:\'

    From the Avira log file

    Beginning disinfection:
    C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1\A0001001.exe
    [DETECTION] Is the TR/Trash.Gen Trojan
    [NOTE] The file was moved to the quarantine directory under the name '44bbc955.qua'.
    C:\Qoobox\Quarantine\C\Documents and Settings\James\Application Data\rwytsqz.exe.vir
    [DETECTION] Is the TR/Trash.Gen Trojan
    [NOTE] The file was moved to the quarantine directory under the name '5c65e539.qua'.


    Is one virus in the restore? I am positive I already turned off restore as per the sticky, but it was on, so I made sure restore was off again.

    But the other virus is in C:\Qoobox\ I dont know what that means?

    You dont have to work during Easter or anything, maybe next week you can take a look. Many thanks again. Take care.
     

    Attached Files:

    Last edited: Apr 7, 2012
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are false detections of things we already removed and quarantined. Igore Avira until you do 100% of the below.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. mtell

    mtell Private E-2

    Hi chaslang,
    Thanks, I did your clean-up steps!
    I think virus should be okay now.
    Thanks again for all your help and assistance and dedication.
    I really appreciate it.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds