Please Help with Trojan.Win32.Generic!BT

Discussion in 'Malware Help (A Specialist Will Reply)' started by emidac, Sep 8, 2012.

  1. emidac

    emidac Private E-2

    Various spyware and malware freeware that I've downloaded has been showing that I have Trojan.Win32.Generic!BT on my system.

    The symptoms I noticed beforehand included many redirects from google search links.. often to pages such as click.get-amazing-results.

    I've tried editting the registry as well as specialized programs on other threads on this site / other forums such as RogueKiller, ComboFix, Malwarebytes Anti-Malware, SuperAntiSpyware, TDSSKiller etc.

    Please help!

    I will be so so so grateful
     
  2. emidac

    emidac Private E-2

    I've attached some customary logs to assist with potential assistance
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  4. emidac

    emidac Private E-2

    Thank you for your concern TimW, but I wouldn't be posting a new thread if I hadn't already exhausted those options.


    Also, here's another log, although it was unsuccessful at finding anything.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In can only help you if you attach the requested logs.
     
  6. emidac

    emidac Private E-2

    Sorry TimW if I was attaching the logs out of order. Here are more of the logs.

    All of these programs found nothing, except some seemingly minor Registry stuff for RogueKiller.

    However it is the MalwareBytes software that blocks 91.218.121.57 (type:eek:utgoing).. whenever I go to Google.com.
     

    Attached Files:

    Last edited: Sep 9, 2012
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach a log that shows this infection.
     
  8. emidac

    emidac Private E-2

    I'm now re-downloading and installing all of the programs that the guide told me to remove. If what you wanted was a log that detected the Trojan, I could have told you before that the 'requested' logs were not picking up on it. Hopefully I'm able to detect it again but maybe there's a possibility that the virus or person behind it is now aware that I'm after it?

    To reiterate, the main symptoms were redirects on google search links, most commonly to click.get-amazing-results

    Thank you again for your help
     
  9. emidac

    emidac Private E-2

    It seems that none of the programs, AVG, SuperAntiSpyware, MalwareBytes, RogueKiller, TDSSKiller, MGTools, Combofix, etc. are detecting this Trojan in a normal scan anymore. :cry

    However, MalwareBytes still blocks outgoing IP requests when I go to Google and if I turn off MalwareBytes, I still get redirected to links such as click.get-amazing-results


    Any suggestions? :confused
     
  10. emidac

    emidac Private E-2

    There is now a secondary IP being blocked:

    195.16.88.141
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It sounds like MBAM is doing it's job. You can add those IP addresses to your hosts file to stop them in the future. Otherwise, as you know, we are not finding any malware in the logs.
     
  12. emidac

    emidac Private E-2

    Thank you for your help Tim. Just wondering for the future, though, do you recommend I purchase the full version of MB Anti-Malware?

    Also, shouldn't there be a way I could prevent redirects outside of relying on constantly having spyware software running? Optimally, I'd rather not have extra processes such as MB Anti-Malware running, but maybe this is highly recommend by MajorGeeks?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't usually advise buying any software. Your version is doing it's job at present. Just be sure to keep it all updated.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  14. emidac

    emidac Private E-2

    I would greatly appreciate some more assistance as it seems that in following the automated guide, nothing was actually solved. Although MalwareBytes does block 2 IPs and this has resulted from certain redirects happening less. Other redirect sites have simply taken its place.. namely "http://www1.aquaso.info/uoon/info.html" WHICH fakes to look exactly like forex.com. Then the first time I tried to click the real link for forex.com, I was redirected to this link: ea-boss.com

    I looked this up on some other sources / forums and it seems like a RootKit is most likely the culprit.
    http://forexrevealednow.com/forex/forex-course-forex/help-with-a-redirect-virus-please.htm
    Would you recommend following the suggestions put forth in the first comment by Pulsar?
     
    Last edited by a moderator: Sep 13, 2012
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download Rootkit Unhooker from HERE.
    Save it to your desktop.
    Now double-click to run RootkitUnhooker.
    Click the Report tab, then click Scan.
    Select the pages Drivers, Stealth, Files, Code Hooks. Uncheck the rest. Click OK.
    Wait till the scanner has finished and then click File, Save Report.
    Save the report somewhere where you can find it. Click Close.
    Attach the report to your next reply.
     
  16. emidac

    emidac Private E-2

    So, to start off, the link you sent me did not work. Maybe the malware is blocking my access to the site. Anyways, I found another place to download the Unhooker at this link:

    http://www.bleepingcomputer.com/forums/topic359586.html

    Then I ran the Unhooker and, although there was a slight error that came up when it first started scanning, something about a supporting service of the scanner not being able to run, but then the scan went through and it found a whole lot of things it seems. Did not unhook anything just as you directed, and am waiting for how to proceed.

    Thanks again for your help!
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please explain which browser the redirects occur in.
     
  18. emidac

    emidac Private E-2

    I, practically exclusively, use Firefox and that is where I've been noticing redirects. I just tried to search and surf a bit on Internet Explorer and it didn't seem to have problems but I can't be fully sure yet that it's redirect-free.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are only being redirected in FireFox, do the following:

    We are going to be uninstalling your old version of FireFox and installing the new version. (except use Revo to uninstall) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:

    C:\Documents and Settings\UserAccount\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Is FireFox working okay now?
     
    Last edited by a moderator: Sep 14, 2012
  20. emidac

    emidac Private E-2

    So far, this fix seems to be working. However, it seemed like Rootkit Unhooker found many many things that it wanted to unhook. Shouldn't I still go through with some sort of removal so that I don't get the same issues again?

    Thank you again for all of your help!
     
  21. emidac

    emidac Private E-2

    By the way, while I was in my Application Data folder, where I deleted the Mozilla folder for the full delete of Firefox, I noticed some very strange, potentially suspicious looking things.

    One of them is just a file called GDIPFONTCACHEV1.DAT

    Seemingly more suspect is a folder called IsolatedStorage

    Inside of which follow these folders (each one contains the following one):
    4rcmuwbp.i45
    nsahu3bz.odl
    StrongName.3yqjbweocx5bndmde5t0452my53l3ktv

    Then inside of this last StrongName 'sketch supreme of a folder', I find:

    folder named AssemFiles, which is empty, and a file called identity.dat

    Any idea what this could be? Malicious?
     
    Last edited: Sep 15, 2012
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I wouldn't worry about those. Are you having any other malware issues?
     
  23. emidac

    emidac Private E-2

    Albeit with less frequency, yes I am still experiencing Malware Issues :\.

    For example I just got a redirect when clicking on the google link for linkedin and it sent me to monster.com.
     
  24. emidac

    emidac Private E-2

    infoswish.com is another place I have been getting redirected..

    also, often it is impossible to use the Back button to navigate back to Google.. I instead have to close the tab and re-open a new window
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download the latest version of MGtools and save it to your root folder. Run the exe and attach a new C:\MGLogs.zip.
     
  26. emidac

    emidac Private E-2

    There ya go! Thanks for the continued help
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Does the redirects happen in all browsers? If not, which one (s).
     
  28. emidac

    emidac Private E-2

    I only use Firefox.. and it happened in Firefox before you had me reinstall it and after, albeit they are now slightly different.

    I get redirected to different sites now than before and with somewhat less frequency.


    Is it crucial that I start using IE or Chrome to test whether it occurs in other browsers?
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try using IE and see if it happens.
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    FYI this is a recognised issue with Internet Explorer 9
     
  31. emidac

    emidac Private E-2

    Thanks Kestrel but I was mentioning the Back button issues with regard to Firefox not IE. And after about 10 minutes on Internet Explorer I did not seem to run into malware issues. I will keep checking though. So far seems to be a Firefox specific problem.
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you may need to go back through the process of uninstalling FireFox. Let me know.
     
  33. emidac

    emidac Private E-2

    Thanks for all of the help so far TimW. What did you want me to let you know? Honestly I just reinstalled Firefox and severely doubt that will fix the problem.. Any other suggestions? Why should I not run the Unhooker?
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and run Unhooker and remove those items listed under "Hooks". Let me know how that goes.
     
  35. emidac

    emidac Private E-2

    I looked over the results of Unhooker again and they were definitely benign. The only things in the list that had a yes under code hooks were Sophos Anti-Virus and Super Anti-Spyware.. Guess I'm still stuck.

    Although it is strange, I definitely noticed less redirecting after some of the initial scans and a reinstall of Firefox. It now is a lot less frequent and it's usually different sites than before although I'm wary that the frequency will ramp up over time.
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I've looked over your logs and am not finding anything. This is a puzzler. Let me consult with my colleagues.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still expect that this issue is related to Firefox needing to be uninstall completely. Thus we will be doing this again but wih a little different procedure this time. I'm going to assume that you still have the bookmarks.html backup from the previous fix and I will not have you save them again. If you deleted that file, you should save it again per how you did it in message #19

    You will need to shutdown Firefox right now and then open up Internet Explorer to continue. Please DO NOT reinstall Firefox until I ask you to do so.

    Please uninstall Firefox right now and when/if it prompts you about saving settings make sure that you say no. This is very important!!!

    Now also uninstall the below two outdated Sun Java versions:
    Java(TM) 6 Update 20
    Java(TM) 6 Update 24


    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Please download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
     
    :Files
    C:\Documents and Settings\TDS\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox
    C:\Recycler\S-1-5-21-1417001333-920026266-839522115-1003\desktop.ini
    C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini
    C:\Documents and Settings\TDS\Local Settings\temp\lilo.3248
    C:\Documents and Settings\TDS\Local Settings\temp\svsw15z.tmp
    C:\Documents and Settings\TDS\Local Settings\temp\_iu14D2N.tmp
    C:\Documents and Settings\TDS\Local Settings\temp\{5B25CA6F-7180-472C-9930-D5FFCF5891D8}
    C:\Documents and Settings\TDS\Application Data\AVG                                                      
    C:\Documents and Settings\All Users\Application Data\AVG
    C:\Documents and Settings\All Users\Application Data\Max Secure
    C:\Documents and Settings\All Users\Application Data\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
    
    
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Remember to not reinstall Firefox yet. I need to verify your logs before we can do this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds