Bicololo trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by coenraad, Aug 28, 2013.

  1. coenraad

    coenraad Private E-2

    I have been infected by the Bicololo Trojan
    Found it through Superantispyware.
    It keeps coming back.
    Followed your anti Malware program.
    Didn't help.
    Did an extra scan with roguekiller.
    and then did a full scan with malwarebytes anti-malware.
    (Maybe a bit stupid of me).
    Could you help me out?
    Added the logs of the programs as an attachment.
    Last logs are not added, because apparently more is not allowed.
     

    Attached Files:

  2. coenraad

    coenraad Private E-2

    The last log of Roguekiller
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you attach a log showing this please.

    bl <--- This shows as an installed program. Do you recognize it? If not uninstall it. What is the ph installed too?

    Also uninstall the IMinent Toolbar.

    Re run Hitman and have it delete this entry under the heading Malware:

    • C:\$RECYCLE.BIN\S-1-5-21-785611319-2695111717-4160720005-1000\$R5VTV6Q.exe

    Also have it remove Potential Unwanted Programs.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKLM\[...]\Run : 61768 (C:\PROGRA~3\LOCALS~1\Temp\ccabqurt.scr [-]) -> FOUND
    • [RUN][SUSP PATH] HKLM\[...]\Wow6432Node\[...]\Run : 61768 (C:\PROGRA~3\LOCALS~1\Temp\ccabqurt.scr [-]) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Delete this
    C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  4. coenraad

    coenraad Private E-2

    I think the problem is solved. I'm sending the latest reports from the malware removal programs (Tdsskiller didn't give a log as he hasn't detected any problems).
    The last reg test (with the notepad) you asked me to do in your post worked.

    I believe i found the files in my last scan with malwarebytes before you send me the post.
    So I couldn't find the files you asked me to search for in hitmanpro and rogue killer.

    There are only a few strange things still:
    1 malwarebytes now keeps finding one and the same trojan.
    2 Rogue killers keeps getting stuck on his first scan but then afterword it seems to work.
    3 superantispyware alwys finds the same amount of adware.tracking cookies (123)

    So it still seems to be a bit fishy.
     

    Attached Files:

  5. coenraad

    coenraad Private E-2

    Ok the virus came back.
    on your notes you gave me to do. and things I had to delete

    Bl I am not sure but it could be beeline. I acn't find the progam on the program list
    If it is BeeLine, then we are talking about a program my internet provider gave me for my
    router.

    I must say I have been suspicious about my router anyhow. Ever since I got a new internet connection (router). There seemed to be something wrong with my computer.
    But without it i have no internet.

    IMinent Toolbar -can't find it

    Re run Hitman and have it delete this entry under the heading Malware:
    C:\$RECYCLE.BIN\S-1-5-21-785611319-2695111717-4160720005-1000\$R5VTV6Q.exe
    Cant find it

    [RUN][SUSP PATH] HKLM\[...]\Run : 61768 (C:\PROGRA~3\LOCALS~1\Temp\ccabqurt.scr [-]) -> FOUND

    [RUN][SUSP PATH] HKLM\[...]\Wow6432Node\[...]\Run : 61768
    (C:\PROGRA~3\LOCALS~1\Temp\ccabqurt.scr [-]) -> FOUND

    Can't find them

    C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com

    Deleted.

    REGEDIT4

    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}]

    The test worked last night but now superantispyawre found the same virus again.

    Ps I am living in Russia. Could that make the situation more difficult?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it remove Potential Unwanted Programs as I previously asked you to do in post #3.



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [RUN][SUSP PATH] HKLM\[...]\Run : 61768 (C:\PROGRA~3\LOCALS~1\Temp\ccabqurt.scr [x]) -> FOUND
    • [RUN][SUSP PATH] HKLM\[...]\Wow6432Node\[...]\Run : 61768 (C:\PROGRA~3\LOCALS~1\Temp\ccabqurt.scr [x]) -> FOUND
    • [V2][SUSP PATH] EPUpdater : C:\Users\coenraad\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\PROGRA~3\LOCALS~1\Temp\ccabqurt.scr
    C:\Users\coenraad\AppData\Roaming\BABSOL~1
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    When you re run Malware Bytes and Superantispyware does it still find the trojan?


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. coenraad

    coenraad Private E-2

    I got the virus deleted. I would like to thank you on your expertise and willingness to help other people (like me) solving problems. Thank you
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Attach the logs so that I can see it is really gone. Don't want you popping back in a week's time ;)
     
  9. coenraad

    coenraad Private E-2

    Well here are the logs of the last scans. I am still waiting for the last superantispyware log. But, I believe with this you can already do a good check up.

    I deleted them all and re installed them on the computer.

    They don't report any critical problems anymore. (Malware reported one problem, but I didn't have to restart my computer for that.

    So I'll send the superantispyware log a bit later.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Plenty to do! :)

    Uninstall this junk ---> IMinent Toolbar


    Re run Hitman and have it delete Potential Unwanted Programs.





    Code:
    :Files
    C:\ProgramData\Babylon
    C:\ProgramData\BrowserDefender
    C:\ProgramData\ParetoLogic
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    
    :services
    BrowserDefendert
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.





    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  11. coenraad

    coenraad Private E-2

    I again tried everything you said.
    I have to make a note that I had to delete everything manually.
    I could not find the IMinent Toolbar, so i deleted this through regedit (which I know is not right as I have not enough nowhow about computers).

    I also had to use regedit for almost all the hitman potential malware scan.
    The ones which are on the last report I could not delete them through regedit or find them on my computer).

    Otm I understood only afterwards how it worked. after already trying it a few times. So I many of the files which say that they are not there i deleted them in a previous run.

    And this is the result. (see the logs attached).

    If I need to fix the files which hitman showed: you would have to explain it to me.

    Everything seems to work fine. But you never know. Trojans are very tricky.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    MGTools did not run to comepletion, either because you let AV software get in the way, you did not run it as admin or you cancelled out early. Please re run and attach a hopefully fuller MGlogs.zip. :)
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also, make sure to get this reg patch done and dusted:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  14. coenraad

    coenraad Private E-2

    the last report of MGtools and the fixME.reg was succesfull.

    Could you advise me a site on where to learn the basics of computers?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    MGlogs.zip did not attach.

    What do you want to know about in paticular? I started off knowing next to nothing in about 2006 and I just joined this website (MG's) and learnt everything I know! What I couldnt absorb through other posts, I would ASK, never shy to ask. The people are so friendly and are very willing to help out :)
     
  16. coenraad

    coenraad Private E-2

    Sorry here it is.
     

    Attached Files:

  17. coenraad

    coenraad Private E-2

     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Being familiar with the registry happens once you are familiar with Windows. If you would like to learn more about malware removal in general I can point you towards a few forums who train people.

    How are things running now, ready for final steps? :)
     
  19. coenraad

    coenraad Private E-2

    what's the final step?

    It seems to work ok

    hitman pro keeps on showing the same 3 registry problems as before

    which we replaced with a new registry
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Code:
    
    :reg
    [-HKLM\SOFTWARE\Classes\c]
    [-HKU\S-1-5-21-785611319-2695111717-4160720005-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKU\S-1-5-21-785611319-2695111717-4160720005-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Now re run Hitman again, is it still hitting on those items?
     
  21. coenraad

    coenraad Private E-2

    Did al that.

    Hitman pro now found one problem less

    but we still have 2 :major
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Code:
    :reg
    [-HKU\S-1-5-21-785611319-2695111717-4160720005-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKU\S-1-5-21-785611319-2695111717-4160720005-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    • Run JRT again.
    • Re run Hitman yet again and let's see what the result is now.
     
  23. coenraad

    coenraad Private E-2

    they still don't budge.:confused
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you delete them yourself and then re run Hitman again and let me know please? If this fails, we'll just try another tool.
     
  25. coenraad

    coenraad Private E-2

    I couldn't delete the registry's.

    But I could delete the link (I don't know if that's good but it seems t work.

    The problem is gone.:yum
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. Ready for final steps?
     
  27. coenraad

    coenraad Private E-2

    Yep, I am ready.
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  29. coenraad

    coenraad Private E-2

    thank you and done it. I guess I'm safe now.
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds