Trojan Horse, Generic & Dropper & Back Door

Discussion in 'Malware Help (A Specialist Will Reply)' started by wildflowergal, Jul 25, 2012.

  1. wildflowergal

    wildflowergal Private E-2

    Dear experts, I have all the troubles of the trojan generic, trojan dropper generic_c.MMI and the trojan horse back door.generic.AXLA

    RogueKiller - Malwarebytes Anti-Malware - HitmanPro - MGtools
    Please let me know if I'm missing something.

    I also have the google redirect issue, which I've done some of the cleaning to no avail.

    I have read the pre-malware info and downloaded all the things, ran the CCleaner etc... Now I will post the RK Log and proceed to the next step.

    [edit by chaslang] Inline MBAM and MBRcheck logs deleted. RK log attached[/edit]

    Then whatever steps I need to take after these things and logs, thank you Deborah Wildflowergal
     

    Attached Files:

    Last edited by a moderator: Jul 26, 2012
  2. wildflowergal

    wildflowergal Private E-2

    Ok now there's no answers from anyone, so maybe I did something wrong. Did I?
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to ATTACH all logs. We do not want inline logs like you posted in your first message. Inline logs will normally be deleted. You need to attach logs from the below scans.
    • Hitman Pro
    • MGtools
    I deleted your MBRcheck and Malwarebytes logs since there was nothing in them of concern and I attached the RogueKiller log in your first message just incase anything was different from the second one that you attached.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also would like you to run the below.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  5. wildflowergal

    wildflowergal Private E-2

    Yes I realized after I pasted all that, there was a better way. I've been downloading all the malware things from the read this first post on the malware forum. So I'm attaching the new RKlog and the other one you mentioned now. a coulple of virus scans have ran and since then and before I read the do nothing part. So I'm running the RK, Hit man and the MGtools again and will attach the logs. Thank you so much for paying attintion to me and helping :0)

     
  6. wildflowergal

    wildflowergal Private E-2

    Ok thank you for your help. Here attached is a redo of RK Log and the other two you instructed me to attach. Please review and let me know whats next. Thank you again, Deborah :)

     

    Attached Files:

  7. wildflowergal

    wildflowergal Private E-2

    I have a win 7 fujitsu life book and I did what you said to a point where it didn't have the options you said and no command prompt at all.

    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    Restart the computer. tapping the F8 key until Advanced Boot Options appears.
    Use the arrow keys to select the Repair your computer menu item. Etc etc...

    Got to here >>> System Recovery Options menu you will get the following options:

    Startup Repair
    and Recovery and Utility options, then under this prompt after clicking it had a box with tabs.
    System Restore
    Windows Complete PC Restore
    Windows Memory Diagnostic Tool
    But not >>>>> Command Prompt anywhere, I searched every which way I could think of under each tab and subject till, I just had to get out of there and write you back.

    Thanks Deborah
     
    Last edited: Jul 26, 2012
  8. wildflowergal

    wildflowergal Private E-2

    Re: Trojan Horse, Generic & Dropper & Back Door, not working

    Can't follow through on your instuctions, I've tried over and over again :(
     
  9. wildflowergal

    wildflowergal Private E-2

    :wave Yippee! I found another way to get to the command prompt. Love that windows help section. Here's the link for anyone who lacks all the menu choices in the system repair area. C:\Windows\system32\cmd.exe

    Ok so below attached is the log for frst64 that I was able to finally run.

     

    Attached Files:

    Last edited: Jul 27, 2012
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you check again. I have not yet really seen a version of Windows 7 that does not support this.

    This is of no use to us. You MUST run it from the command prompt of the System Recovery Environment not the command prompt of Windows. Notice at the top of the log you posted it even state the below
     
  11. wildflowergal

    wildflowergal Private E-2

    It only had the two menu choices. tap tap F8 at restart, choose repair, goes to US to choose, then user name ok... pics attached of what comes up. Sorry I have a stupid computer :(
     

    Attached Files:

  12. wildflowergal

    wildflowergal Private E-2

    Yes I did notice when you brought it to my attintion. I sent you pictures of the only options it gave me. Is there any hope?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rescan with HitmanPro
    • When it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.
    • Leave any other detections alone (Ignore them).
    • Afterwards, click the Next button.
    • HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    • After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log. (See[COLOR=blue[/URL]] How to attach files[/COLOR][/URL])
    See if you can get RogueKiller to run. If you can then run a scan and after it finishes, select the Files tab and if the below exist, click the Delete button again.[/B]

    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in original instructions and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the new Hitman log
    • the new RogueKiller log
    • C:\MGlogs.zip
     
  14. wildflowergal

    wildflowergal Private E-2

    Well in the results for hitmanpro, I did not see anything or words that said "services.exe - Virus" log attached.

    Then on the RK, I did find the 2 files you said and deleted them, rebooted the computer and have attached the files. Thank you again.

     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Something must have already fixed it.

    See if you can find and delete the below two folders.
    C:\Windows\installer\{2866e762-6a40-e9a4-3466-3797a275df6a}
    C:\Users\TEST\AppData\Local\{2866e762-6a40-e9a4-3466-3797a275df6a}


    Also tell me how things are working?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds